Multi-OTP Security Key for Granular Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional access control systems face security fragility due to password leaks and ease of duplication of access cards, and existing multi-one-time password systems lack control over various security areas and fail to prevent unauthorized access with lost smart cards.

Innovation Solution

A security key system that includes an interface unit, an OTP module with storage for OTP Seed ID and Algorithm ID, and an OTP generation unit, along with a security service device that generates and manages OTPs, and an OTP authentication server for secure authentication across multiple security domains, using multiple OTPs and fingerprint authentication to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single OTP method is used for authentication, then the authentication process is simple, but it is impossible to control access to various security areas

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidaccess control to various security areas
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent divides the authentication system into multiple OTP modules, each associated with a specific security area or authentication server. Each OTP module can independently generate and verify OTPs for different security domains, enabling fine-grained access control while maintaining operational simplicity within each domain.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security key device is designed to support multiple OTP modules that can interact with different authentication servers. This multi-functional capability allows a single device to provide access control across various security areas while each OTP method remains relatively simple to operate.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a smart card is lost, then the physical security device is compromised, but the system fails to prevent unauthorized access

Engineering Contradiction:
Improvesecurity against lost smart cardsVSAvoidunauthorized access with lost smart cards
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication system is segmented into multiple independent OTP modules, each tied to a specific authentication server or security area. If a smart card is lost, an attacker can only access the specific security area associated with that card's OTP module, not the entire system. This segmentation limits the harm from lost cards while maintaining overall system reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces authentication servers as intermediaries between the smart card and security access. Even if a smart card is lost, the intermediary authentication servers can verify OTPs and control access, preventing unauthorized entry. The server acts as a mediator that validates authentication credentials before granting access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If traditional passwords are used for access control, then the system is easy to operate, but password leaks occur easily

Engineering Contradiction:
Improveaccess control operationVSAvoidsecurity against password leaks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements One-Time Passwords that are valid for a single authentication event and then become obsolete. Each OTP is generated dynamically and can only be used once, making them disposable security credentials. This eliminates the risk of password leaks affecting future access, as each password is unique and non-reusable.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The system generates OTPs periodically or on-demand for each authentication attempt, creating a time-based or event-based security mechanism. This periodic generation of fresh credentials ensures that even if one OTP is compromised, subsequent OTPs remain secure, maintaining both operational ease and security reliability.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS9256723B2Security key using multi-OTP, security service apparatus, security system
Publication Date: 2016.02.09 SAFERZONE
  • US9256723B2 patent drawing
  • US9256723B2 patent drawing
  • US9256723B2 patent drawing

AI summary

A security key including an interface unit that provides an interface with an authentication device installed at a security domain; and an OTP module that communicates with the authentication device through the interface unit mentioned above, wherein the OTP module includes a storage unit that stores at least one OTP Seed ID and OTP Algorithm ID; and an OTP generation unit that generates an OTP by using an OTP Seed value and OTP algorithm that are identified by an OTP Seed ID and an OTP Algorithm ID matching with the OTP Seed ID and OTP Algorithm ID included in the OTP request message, which is received from the authentication device among the OTP Seed ID and OTP Algorithm ID stored in the storage unit, and provides the authentication device with the OTP generated in the process.