Mobile Terminal One-Time Password Authentication via Dynamic IP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing one-time password (OTP) authentication methods are vulnerable to security breaches due to the leakage of issuing rules and lack of verification of the service provider's legitimacy, particularly in software-based systems and the financial sector, where hardware-based OTPs are inconvenient and costly.

Innovation Solution

A system and method that uses a user's mobile terminal to generate OTPs based on dynamically assigned IP addresses, allowing users to verify both their identity and the legitimacy of the service provider by comparing generated OTPs with those provided by the service provider, eliminating the need for separate OTP devices and enhancing security against phishing attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software-based OTP is used, then ease of operation is improved, but security is worsened due to vulnerability to hacking and leakage

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges the OTP generation functionality with the mobile terminal itself, combining the convenience of software-based OTP with enhanced security. The mobile terminal uses its existing resources (IP address, processor) to generate OTP locally, eliminating the need for separate hardware devices while maintaining security through dynamic IP address-based generation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces the mobile terminal's dynamic IP address as an intermediary element in the OTP generation process. This intermediary provides a unique, dynamically changing identifier that enhances security while allowing the OTP system to operate seamlessly through the mobile terminal without requiring additional hardware.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware-based OTP device is used, then security is improved, but device complexity and cost are worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the mobile terminal universal by enabling it to perform both communication functions and OTP generation functions. The mobile terminal, already a necessary device for users, is enhanced to also serve as an OTP generation device, eliminating the need for separate hardware OTP devices and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The mobile terminal provides self-service by generating OTP locally using its own IP address and processing capabilities. This eliminates the need for external hardware OTP devices while maintaining security, as the mobile terminal independently performs the OTP generation function that would otherwise require dedicated hardware.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If issuing rule is transmitted between user and service provider, then authentication functionality is improved, but security is worsened due to vulnerability to phishing attacks

Engineering Contradiction:
Improveauthentication functionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent performs preliminary action by generating the OTP locally in the mobile terminal before any communication with the service provider. The OTP is generated using the mobile terminal's dynamic IP address and seed value, and only the final OTP code is transmitted to the service provider, not the generation rules or seed values, preventing phishing attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts the critical security element (the seed value and generation algorithm) from the communication between user and service provider. Only the final OTP result is transmitted, while the generation rules remain securely stored in the mobile terminal, preventing leakage through phishing attacks.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10003595B2System and method for one time password authentication
Publication Date: 2018.06.19 DUALAUTH CO LTD
  • US10003595B2 patent drawing
  • US10003595B2 patent drawing
  • US10003595B2 patent drawing

AI summary

An authentication system for providing an authentication service for a user accessing the same through a communication network includes a seed server for managing a user seed value related to each user identification information, a one time password (OTP) generation device provided in a user's mobile terminal, the OTP generation device generating a user OTP by using at least one portion previously defined in an IP address dynamically assigned to the mobile terminal by a mobile communication operator and a user's user seed value, and an authentication server for, if a user authentication request is received, generating an OTP corresponding to the user OTP by using the at least one portion previously defined in the IP address dynamically assigned to the mobile terminal and the user seed value related to the user identification information, and comparing the user OTP with the corresponding OTP, thereby authenticating the user.