Mobile Terminal OTP Generation via Hardware-Software Module Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The current mobile OTP generation scheme is vulnerable to security threats due to the possibility of hacking and forgery, as it relies on software applications in mobile terminals, which can expose important data and user information to external attacks.
Innovation Solution
A mobile terminal configuration with a first OTP generating module and a second OTP generating module based on a mobile trusted module (MTM), where the second module performs OTP generation using hardware-based cryptographic engines, independent from the software-based first module, to securely manage and process OTP data and identification information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If OTP generation is implemented through software application in mobile terminal, then ease of operation is improved, but security is worsened due to vulnerability to hacking and forgery
Solution Approach 1:
The system is divided into two separate modules: a first OTP generating module implemented as software application for ease of operation, and a second OTP generating module implemented as hardware-based mobile trusted module for security. The second module is segmented as an independent hardware component with cryptographic engines, separate from the software-based first module, allowing each to fulfill its specific function optimally.
Solution Approach 2:
The processor acts as an intermediary between the software-based first OTP generating module and the hardware-based second OTP generating module. It receives requests from the first module, forwards them to the second module for secure processing, and relays the generated OTP back to the first module for output, enabling secure hardware-based generation while maintaining software-based user interface.
2Reliability
If hardware-based mobile trusted module is used for OTP generation, then security is improved, but device complexity is worsened
Solution Approach 1:
The patent merges the software-based first OTP generating module and hardware-based second OTP generating module into a single integrated system within the mobile terminal. The processor coordinates both modules, combining the ease of software implementation with the security of hardware, thereby achieving enhanced security without requiring completely separate devices.
Solution Approach 2:
The second OTP generating module is designed as a universal mobile trusted module that can serve multiple security functions beyond OTP generation, including cryptographic operations and secure data storage. This multi-functionality justifies the added hardware complexity by providing broader security benefits across different applications.
Data Source
AI summary
Provided are a mobile terminal for providing a one-time password (OTP) and an operation method thereof. The mobile terminal includes a first one-time password (OTP) generating module configured to provide identification information regarding each of a plurality of pieces of OTP data to a user, and output an OTP provided according to any one identification information selected by the user, and a second OTP generating module based on mobile trusted module (MTM) configured to transfer the identification information regarding each of the plurality of pieces of OTP data to the first OTP generating module according to a corresponding request from the first OTP generating module, generate an OTP by using OTP data corresponding to the selected identification information, and transfer the generated OTP to the first OTP generating module.


