Multi-OTP Security Key for Granular Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional access control systems face security fragility due to password leaks and ease of duplication of access cards, and existing multi-one-time password systems lack control over various security areas and fail to prevent unauthorized access with lost smart cards.
Innovation Solution
A security key system that includes an interface unit, an OTP module with storage for OTP Seed ID and Algorithm ID, and an OTP generation unit, along with a security service device that generates and manages OTPs, and an OTP authentication server for secure authentication across multiple security domains, using multiple OTPs and fingerprint authentication to enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single OTP method is used for authentication, then the authentication process is simple, but it is impossible to control access to various security areas
Solution Approach 1:
The patent divides the authentication system into multiple OTP modules, each associated with a specific security area or authentication server. Each OTP module can independently generate and verify OTPs for different security domains, enabling fine-grained access control while maintaining operational simplicity within each domain.
Solution Approach 2:
The security key device is designed to support multiple OTP modules that can interact with different authentication servers. This multi-functional capability allows a single device to provide access control across various security areas while each OTP method remains relatively simple to operate.
2Reliability
If a smart card is lost, then the physical security device is compromised, but the system fails to prevent unauthorized access
Solution Approach 1:
The authentication system is segmented into multiple independent OTP modules, each tied to a specific authentication server or security area. If a smart card is lost, an attacker can only access the specific security area associated with that card's OTP module, not the entire system. This segmentation limits the harm from lost cards while maintaining overall system reliability.
Solution Approach 2:
The patent introduces authentication servers as intermediaries between the smart card and security access. Even if a smart card is lost, the intermediary authentication servers can verify OTPs and control access, preventing unauthorized entry. The server acts as a mediator that validates authentication credentials before granting access.
3Ease of operation
If traditional passwords are used for access control, then the system is easy to operate, but password leaks occur easily
Solution Approach 1:
The patent implements One-Time Passwords that are valid for a single authentication event and then become obsolete. Each OTP is generated dynamically and can only be used once, making them disposable security credentials. This eliminates the risk of password leaks affecting future access, as each password is unique and non-reusable.
Solution Approach 2:
The system generates OTPs periodically or on-demand for each authentication attempt, creating a time-based or event-based security mechanism. This periodic generation of fresh credentials ensures that even if one OTP is compromised, subsequent OTPs remain secure, maintaining both operational ease and security reliability.
Data Source
AI summary
A security key including an interface unit that provides an interface with an authentication device installed at a security domain; and an OTP module that communicates with the authentication device through the interface unit mentioned above, wherein the OTP module includes a storage unit that stores at least one OTP Seed ID and OTP Algorithm ID; and an OTP generation unit that generates an OTP by using an OTP Seed value and OTP algorithm that are identified by an OTP Seed ID and an OTP Algorithm ID matching with the OTP Seed ID and OTP Algorithm ID included in the OTP request message, which is received from the authentication device among the OTP Seed ID and OTP Algorithm ID stored in the storage unit, and provides the authentication device with the OTP generated in the process.


