Portable Mass Storage Device for Automated Two-Factor Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current password management and one-time password (OTP) systems require users to carry multiple dedicated devices, which is inconvenient and limits their acceptance for general public use, especially for online banking and other sensitive applications, as they lack integration with existing portable devices and do not provide a high level of security.

Innovation Solution

A portable mass storage device, such as a USB flash storage device or memory card, integrates OTP generation and password management, allowing users to authenticate with multiple institutions using a single device by storing and retrieving seed and count pairs securely, and automatically performing OTP operations during the user login process, eliminating the need for additional tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated OTP tokens are used for authentication, then security level is improved, but device complexity and user convenience deteriorate due to requiring multiple separate devices

Engineering Contradiction:
Improvesecurity levelVSAvoidnumber of devices
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines OTP generation functionality with a portable mass storage device that users already carry, eliminating the need for separate dedicated tokens. The mass storage device stores seed and count pairs and generates OTP values automatically, merging authentication security with a commonly possessed device.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The mass storage device serves multiple functions: it acts as both a storage device for files and media, and as an authentication device for generating OTP values. This multi-functionality allows the same device to fulfill both data storage needs and security authentication requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If dedicated OTP tokens are carried, then authentication security is improved, but ease of operation deteriorates due to needing to carry and manage multiple devices

Engineering Contradiction:
Improveauthentication securityVSAvoidconvenience of use
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the authentication function into the mass storage device that users already carry for file storage, eliminating the need to carry separate tokens. Users simply use their existing mass storage device for both storage and authentication purposes.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system automatically retrieves the appropriate seed and count pairs from the mass storage device and generates OTP values without requiring user intervention to manually select or switch between different authentication devices. The process is automated and transparent to the user.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If password management devices are used, then password storage is improved, but security level deteriorates compared to OTP systems

Engineering Contradiction:
Improvepassword managementVSAvoidsecurity level
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system pre-loads seed and count pairs into the mass storage device during manufacturing or initial setup, so that when the device is connected to a host computer, the authentication credentials are already in place and ready for automatic OTP generation without requiring users to manually manage passwords.

Inventive Principle:
Principle #10Preliminary action

4Adaptability or versatility

If multiple dedicated devices are used for OTP generation, then security coverage across multiple institutions is improved, but loss of time deteriorates due to managing multiple devices

Engineering Contradiction:
Improvemulti-institution authenticationVSAvoidtime to manage devices
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The mass storage device is configured to store multiple seed and count pairs corresponding to different institutions, allowing a single device to generate OTP values for multiple different authentication systems and institutions, eliminating the need for separate tokens for each institution.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Multiple institution credentials (seed and count pairs) are pre-configured in the mass storage device during manufacturing or initial setup, so the device is ready to authenticate with multiple institutions immediately without requiring users to manually configure each credential separately.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7748031B2Mass storage device with automated credentials loading
Publication Date: 2010.06.29 SANDISK TECHNOLOGIES LLC
  • US7748031B2 patent drawing
  • US7748031B2 patent drawing
  • US7748031B2 patent drawing

AI summary

A portable mass storage device for use in two factor authentication systems and methods. A secure portable mass storage device protects content from being freely copied with security mechanisms and firmware. The security functionality also protects confidential user credentials and passwords, as well as algorithms and seeds needed for two factor authentication or asymmetric authentication methods. A client application residing in the mass storage device acts as both a password manager and an authentication manager that seamlessly performs the authentication procedures in the background while signing a user into various institutions of his choosing. A very high level of security is integrated into a mass storage device the user has for purposes other than two factor authentication, and the convenience of highly secure password management also comes in a convenient pocket sized package easy for the user to transport. This facilitates the acceptance of two factor authentication, and increases security for a wide variety of online transactions.