Mobile Terminal One-Time Password Authentication via Dynamic IP
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing one-time password (OTP) authentication methods are vulnerable to security breaches due to the leakage of issuing rules and lack of verification of the service provider's legitimacy, particularly in software-based systems and the financial sector, where hardware-based OTPs are inconvenient and costly.
Innovation Solution
A system and method that uses a user's mobile terminal to generate OTPs based on dynamically assigned IP addresses, allowing users to verify both their identity and the legitimacy of the service provider by comparing generated OTPs with those provided by the service provider, eliminating the need for separate OTP devices and enhancing security against phishing attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If software-based OTP is used, then ease of operation is improved, but security is worsened due to vulnerability to hacking and leakage
Solution Approach 1:
The patent merges the OTP generation functionality with the mobile terminal itself, combining the convenience of software-based OTP with enhanced security. The mobile terminal uses its existing resources (IP address, processor) to generate OTP locally, eliminating the need for separate hardware devices while maintaining security through dynamic IP address-based generation.
Solution Approach 2:
The patent introduces the mobile terminal's dynamic IP address as an intermediary element in the OTP generation process. This intermediary provides a unique, dynamically changing identifier that enhances security while allowing the OTP system to operate seamlessly through the mobile terminal without requiring additional hardware.
2Reliability
If hardware-based OTP device is used, then security is improved, but device complexity and cost are worsened
Solution Approach 1:
The patent makes the mobile terminal universal by enabling it to perform both communication functions and OTP generation functions. The mobile terminal, already a necessary device for users, is enhanced to also serve as an OTP generation device, eliminating the need for separate hardware OTP devices and reducing overall system complexity.
Solution Approach 2:
The mobile terminal provides self-service by generating OTP locally using its own IP address and processing capabilities. This eliminates the need for external hardware OTP devices while maintaining security, as the mobile terminal independently performs the OTP generation function that would otherwise require dedicated hardware.
3Adaptability or versatility
If issuing rule is transmitted between user and service provider, then authentication functionality is improved, but security is worsened due to vulnerability to phishing attacks
Solution Approach 1:
The patent performs preliminary action by generating the OTP locally in the mobile terminal before any communication with the service provider. The OTP is generated using the mobile terminal's dynamic IP address and seed value, and only the final OTP code is transmitted to the service provider, not the generation rules or seed values, preventing phishing attacks.
Solution Approach 2:
The patent extracts the critical security element (the seed value and generation algorithm) from the communication between user and service provider. Only the final OTP result is transmitted, while the generation rules remain securely stored in the mobile terminal, preventing leakage through phishing attacks.
Data Source
AI summary
An authentication system for providing an authentication service for a user accessing the same through a communication network includes a seed server for managing a user seed value related to each user identification information, a one time password (OTP) generation device provided in a user's mobile terminal, the OTP generation device generating a user OTP by using at least one portion previously defined in an IP address dynamically assigned to the mobile terminal by a mobile communication operator and a user's user seed value, and an authentication server for, if a user authentication request is received, generating an OTP corresponding to the user OTP by using the at least one portion previously defined in the IP address dynamically assigned to the mobile terminal and the user seed value related to the user identification information, and comparing the user OTP with the corresponding OTP, thereby authenticating the user.


