Multi-Factor Authentication Using Device-Specific One-Time Passwords
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication systems are vulnerable to security breaches as attackers continually develop methods to detect and defeat existing authentication techniques, making secure information or goods transfer increasingly difficult.
Innovation Solution
A multi-factor authentication system that employs a one-time password (OTP) generated randomly and customized for each application, requiring users to enter it via non-keyboard techniques such as a spinning wheel or voice input, ensuring that only the correct device can decode and enter the OTP, thereby enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authentication techniques (username and password) are used, then ease of operation is maintained, but security reliability deteriorates due to vulnerabilities to interception and spoofing attacks
Solution Approach 1:
The authentication process is segmented into multiple independent factors: something you know (password), something you have (mobile device with OTP capability), and something you are (biometric verification). This segmentation ensures that compromising one factor does not compromise the entire authentication system, thereby improving security reliability while maintaining operational ease through the coordinated use of these factors.
Solution Approach 2:
The system performs preliminary actions by generating and delivering the OTP to the user's mobile device before the actual authentication attempt. The OTP is time-limited and device-specific, creating a preliminary security barrier that must be overcome before password verification, thus enhancing security reliability without significantly impacting ease of operation.
2Reliability
If multi-factor authentication with OTP is implemented, then security reliability improves, but device complexity increases due to additional authentication factors
Solution Approach 1:
The mobile device serves multiple functions: it receives the OTP via SMS or push notification, stores it securely, and provides biometric verification capability. By making the mobile device universal and multi-functional, the system improves security reliability without requiring additional separate devices, thereby mitigating the increase in device complexity.
Solution Approach 2:
The system leverages existing capabilities of the user's mobile device (SMS reception, push notifications, biometric sensors) to perform authentication functions. The device essentially serves itself by utilizing its own built-in features for OTP delivery and verification, reducing the need for external authentication hardware and thus limiting the increase in device complexity.
3Ease of operation
If OTP is delivered via SMS or push notification, then ease of operation is improved, but security reliability worsens due to potential interception through intercepting devices
Solution Approach 1:
The system introduces an intermediary layer of security by requiring the OTP to be entered through a specific application interface on the user's device rather than directly through keyboard input. This intermediary interface captures the OTP entry separately from the main application communication channel, making it difficult for intercepting devices to capture the OTP during transmission or entry, thus improving security reliability while maintaining ease of operation.
Solution Approach 2:
The system adds a new dimension to OTP delivery by using push notifications alongside SMS. Push notifications provide an additional channel that is more secure against interception than traditional SMS, as they are delivered through encrypted application channels. This dimensional addition improves security reliability while maintaining or even enhancing ease of operation through automated delivery.
4Reliability
If keyboard input is used for OTP entry, then ease of operation is maintained, but security reliability deteriorates due to susceptibility to keystroke interception
Solution Approach 1:
The system extracts the OTP entry process from the standard keyboard input mechanism and implements a separate, dedicated input interface within the authentication application. This extracted entry method captures the OTP characters through a controlled interface that is isolated from external interception devices, thereby improving security reliability while maintaining ease of operation through a simplified user interaction flow.
Solution Approach 2:
The OTP itself is designed as a cheap, short-lived authentication credential that is generated anew for each authentication attempt and expires after a short time window or single use. This disposable nature of the OTP means that even if intercepted, it becomes useless quickly, improving security reliability without requiring complex long-term security measures that would compromise ease of operation.
Data Source
AI summary
The aspects disclosed herein are directed to systems and methods for employing multi-factor authentication for the transfer of goods or information. By employing the aspects disclosed herein, the authentication may become more secure and less vulnerable to attacks by unauthorized parties. The aspects disclosed herein may be implemented as a thin-client implementation, or a thick-client implementation.


