Mobile Terminal Authentication via Synchronized One-Time Passwords
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication systems using mobile terminals lack sufficient security, particularly when member identification information is stored on cards that can be lost, and systems relying on paper media for OTPs are inconvenient and insecure.
Innovation Solution
An authentication system that includes a mobile terminal with a terminal-side OTP generation unit, a shop computer for reading barcode-formatted member identification and OTP, and a head office server for authenticating members by comparing the OTPs and member identification information, ensuring enhanced security through synchronized OTP validity periods.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If member identification information is stored on a physical card, then authentication can be performed, but security is insufficient when the card is lost
Solution Approach 1:
The patent replaces the physical member card with a virtual copy stored in mobile terminal memory. The member identification information is copied from the original card data into the mobile terminal, allowing authentication without the physical card. This resolves the security issue of lost cards while maintaining authentication functionality through the digital copy in the mobile device.
Solution Approach 2:
The patent substitutes the mechanical/physical card system with an electronic information system. Instead of using a physical card that requires manual presentation and reading, the system uses digital data storage and transmission through a mobile terminal. This replacement eliminates the security vulnerability of physical cards being lost or stolen while maintaining the authentication process through electronic means.
2Reliability
If OTP and member identification information are printed on paper medium, then authentication security is enhanced, but paper medium is required and mobile terminal authentication cannot be performed
Solution Approach 1:
The patent converts the paper-based OTP and member identification information into digital format that can be copied and stored in mobile terminal memory. Instead of printing these security elements on paper, the system creates digital copies that can be displayed on the mobile terminal screen and transmitted electronically to the authentication server, enabling both security and mobile device compatibility.
Solution Approach 2:
The patent changes the physical state and format parameters of the authentication data. Member identification information and OTP transition from being printed on paper (static, physical medium) to being displayed as digital images or text on a mobile terminal screen (dynamic, electronic medium). This parameter change enables the same authentication data to be used with mobile devices while maintaining security through the use of OTP.
3Ease of operation
If only member identification information is used for authentication, then authentication process is simple, but security is insufficient when card is lost
Solution Approach 1:
The patent divides the authentication credentials into two separate segments: member identification information and one-time password (OTP). Instead of using only the member ID, the system requires both the member identification and a time-limited OTP for authentication. This segmentation enhances security by adding a second factor that is difficult to replicate, while keeping the authentication process relatively simple through the mobile terminal interface.
Solution Approach 2:
The system performs preliminary generation and storage of the OTP in the mobile terminal before the authentication transaction occurs. The OTP is pre-calculated and stored in the mobile device's memory, ready for immediate use during authentication. This preliminary action ensures that when authentication is needed, both the member identification and OTP are readily available, maintaining process simplicity while enhancing security through the pre-prepared second authentication factor.
Data Source
AI summary
An authentication system is provided that authenticates a member using the member's mobile terminal. The authentication system includes a mobile terminal, a shop computer, and a head office server. The head office server includes an authentication unit. The authentication unit compares member identification information read by the shop computer with member identification information stored in a member database. Additionally, the authentication unit compares a one-time password (OTP) password with the OTP of the mobile terminal generated by the server-side OTP generation unit and received from the shop computer. The authentication unit authenticates a member based on the results of the comparison. That is, the authentication unit authenticates a member as a valid member if the former member identification information and OTP match the latter member identification information and OTP.


