Mobile Cross-Authentication System Using Dual Code Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication methods for online services, such as financial transactions, are vulnerable to fraud due to the theft of accredited certificates, one-time passwords, and SMS authentication codes, and require separate hardware devices, limiting usability and security.

Innovation Solution

A mobile cross-authentication system that generates and verifies online and mobile authentication codes on both computer and portable terminal devices without relying on specific hardware modules, using a three-stage authentication process involving online authentication codes, mobile authentication codes, and portable terminal device identification, ensuring mutual security and usability across various devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital signature authentication based on accredited certificates is used, then authentication security is improved, but the burden of using separate hardware devices increases

Engineering Contradiction:
Improveauthentication securityVSAvoidhardware device burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces physical hardware security tokens with virtual authentication codes (Ocode and Mcode) that can be copied and transmitted between devices. The authentication system generates these codes on either the computer terminal or portable terminal, eliminating the need for dedicated hardware security modules while maintaining authentication security.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent enables authentication to be performed using either a computer terminal or a portable terminal device, making the authentication system universal across different device types. The same authentication protocol works on both desktop computers and mobile devices, removing the requirement for specific hardware modules.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If OTP devices or accredited certificates are used for financial authentication, then authentication capability is improved, but vulnerability to memory hacking and theft increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidvulnerability to hacking and theft
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic authentication codes that are generated in real-time and have limited validity periods. The Ocode and Mcode are continuously updated based on the current time and device state, making them ineffective for replay attacks. Even if one code is stolen, it cannot be used after its validity period expires.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an authentication server as an intermediary that manages the generation and verification of authentication codes. The server acts as a trusted mediator between the user's devices and the service provider, eliminating the need for clients to store sensitive cryptographic materials locally, thereby reducing vulnerability to local hacking and theft.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If SMS authentication codes are used, then authentication method is simplified, but security is compromised due to smishing attacks

Engineering Contradiction:
Improveauthentication method simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent adds a spatial dimension to authentication by requiring code transmission between two different physical devices. The Ocode is displayed on one device (computer or portable terminal) and must be manually entered on the other device, creating a physical transfer step that cannot be replicated through remote phishing attacks.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Ease of operation

If ARS authentication is used, then authentication process is simplified, but security threats arise from call forwarding

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces voice-based ARS authentication with text-based code copying and pasting between devices. The authentication code is displayed as text on the screen and can be copied to the clipboard, then pasted into the authentication field, eliminating reliance on vulnerable voice call systems while maintaining simplicity.

Inventive Principle:
Principle #26Copying

5Reliability

If app card methods with virtual card numbers are used, then security is improved, but usability is reduced due to application download requirements

Engineering Contradiction:
Improveauthentication securityVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a universal authentication solution that works across multiple device types (computer terminals and portable terminals) without requiring device-specific applications. The authentication protocol is implemented through standard web browsers and messaging functions, making it accessible to all users regardless of their device ecosystem.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11966907B2System and method for mobile cross-authentication
Publication Date: 2024.04.23 YOONGNET INC
  • US11966907B2 patent drawing
  • US11966907B2 patent drawing
  • US11966907B2 patent drawing

AI summary

The present invention relates to a system and a method for mobile cross-authentication comprising: generating an online authentication code (Ocode) and a mobile authentication code (Mcode) from an authentication server device when performing online authentication, providing the online authentication code (Ocode) and the mobile authentication code (Mcode) to a computer terminal device and a mobile terminal of the user respectively, receiving and verifying the online authentication code and the mobile authentication code received by the computer terminal device and the mobile terminal to the authentication server device through the mobile terminal and the computer terminal device respectively.