Multi-Factor Authentication Using Device-Specific One-Time Passwords

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication systems are vulnerable to security breaches as attackers continually develop methods to detect and defeat existing authentication techniques, making secure information or goods transfer increasingly difficult.

Innovation Solution

A multi-factor authentication system that employs a one-time password (OTP) generated randomly and customized for each application, requiring users to enter it via non-keyboard techniques such as a spinning wheel or voice input, ensuring that only the correct device can decode and enter the OTP, thereby enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication techniques (username and password) are used, then ease of operation is maintained, but security reliability deteriorates due to vulnerabilities to interception and spoofing attacks

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication process is segmented into multiple independent factors: something you know (password), something you have (mobile device with OTP capability), and something you are (biometric verification). This segmentation ensures that compromising one factor does not compromise the entire authentication system, thereby improving security reliability while maintaining operational ease through the coordinated use of these factors.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by generating and delivering the OTP to the user's mobile device before the actual authentication attempt. The OTP is time-limited and device-specific, creating a preliminary security barrier that must be overcome before password verification, thus enhancing security reliability without significantly impacting ease of operation.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multi-factor authentication with OTP is implemented, then security reliability improves, but device complexity increases due to additional authentication factors

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The mobile device serves multiple functions: it receives the OTP via SMS or push notification, stores it securely, and provides biometric verification capability. By making the mobile device universal and multi-functional, the system improves security reliability without requiring additional separate devices, thereby mitigating the increase in device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system leverages existing capabilities of the user's mobile device (SMS reception, push notifications, biometric sensors) to perform authentication functions. The device essentially serves itself by utilizing its own built-in features for OTP delivery and verification, reducing the need for external authentication hardware and thus limiting the increase in device complexity.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If OTP is delivered via SMS or push notification, then ease of operation is improved, but security reliability worsens due to potential interception through intercepting devices

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system introduces an intermediary layer of security by requiring the OTP to be entered through a specific application interface on the user's device rather than directly through keyboard input. This intermediary interface captures the OTP entry separately from the main application communication channel, making it difficult for intercepting devices to capture the OTP during transmission or entry, thus improving security reliability while maintaining ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system adds a new dimension to OTP delivery by using push notifications alongside SMS. Push notifications provide an additional channel that is more secure against interception than traditional SMS, as they are delivered through encrypted application channels. This dimensional addition improves security reliability while maintaining or even enhancing ease of operation through automated delivery.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Reliability

If keyboard input is used for OTP entry, then ease of operation is maintained, but security reliability deteriorates due to susceptibility to keystroke interception

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system extracts the OTP entry process from the standard keyboard input mechanism and implements a separate, dedicated input interface within the authentication application. This extracted entry method captures the OTP characters through a controlled interface that is isolated from external interception devices, thereby improving security reliability while maintaining ease of operation through a simplified user interaction flow.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The OTP itself is designed as a cheap, short-lived authentication credential that is generated anew for each authentication attempt and expires after a short time window or single use. This disposable nature of the OTP means that even if intercepted, it becomes useless quickly, improving security reliability without requiring complex long-term security measures that would compromise ease of operation.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS10771971B2Secured multi-factor authentication
Publication Date: 2020.09.08 SALLOUM SAMUEL
  • US10771971B2 patent drawing
  • US10771971B2 patent drawing
  • US10771971B2 patent drawing

AI summary

The aspects disclosed herein are directed to systems and methods for employing multi-factor authentication for the transfer of goods or information. By employing the aspects disclosed herein, the authentication may become more secure and less vulnerable to attacks by unauthorized parties. The aspects disclosed herein may be implemented as a thin-client implementation, or a thick-client implementation.