Offline Two-Factor Authentication Using Client ID and Pattern Seeds

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional off-line user authentication systems rely solely on passwords for authentication, offering limited security as they cannot prevent fraudulent access if the password is leaked, and introducing additional authentication factors like one-time-password tokens increases costs and inconvenience.

Innovation Solution

An off-line two-factor user authentication system that uses a one-time-password derivation rule applied to pattern elements in a presentation pattern, combined with client identification information as a second authentication factor, to create a one-time password, enhancing security without the need for additional hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a one-time-password token is used for authentication, then security is improved, but cost and inconvenience increase due to carrying additional devices

Engineering Contradiction:
Improveauthentication securityVSAvoidconvenience of authentication
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines the authentication function with the client apparatus itself by using client identification information (such as hardware ID, device fingerprint, or system parameters) that is inherently present in the device. This eliminates the need for separate authentication tokens while maintaining security, as the client apparatus serves dual purposes: both as the service client and as the authentication credential holder.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The client apparatus provides authentication credentials (client identification information) that are automatically generated and stored within the device itself, without requiring external tokens or additional hardware. The device serves itself by using its own inherent characteristics as the authentication basis, reducing dependency on external authentication components.

Inventive Principle:
Principle #25Self-service

2Reliability

If a one-time-password token is used for authentication, then security is improved, but cost increases due to token procurement and management

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent replaces expensive, physically durable tokens with virtual, software-based client identification information that can be generated at minimal cost. The authentication credentials are essentially disposable in the sense that they can be regenerated or changed without physical token replacement, reducing long-term costs associated with token issuance, distribution, and replacement.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent substitutes the mechanical/physical token system with a software-based solution using client identification information. Instead of relying on physical tokens that require manufacturing, distribution, and physical security measures, the system uses digital identifiers that can be generated and managed through software, significantly reducing hardware costs and logistical overhead.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Device complexity

If conventional off-line authentication is used, then simplicity is maintained, but security is insufficient due to reliance on single password factor

Engineering Contradiction:
Improveauthentication system simplicityVSAvoidauthentication security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent makes the client identification information serve multiple functions: it acts as both a device identifier for service access and as an authentication credential for security verification. This multi-functionality allows the system to maintain simplicity by using a single identifier while achieving multi-factor authentication security, as the same client ID is used for both service identification and authentication purposes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8875264B2System, method and program for off-line two-factor user authentication
Publication Date: 2014.10.28 CSE CO LTD
  • US8875264B2 patent drawing
  • US8875264B2 patent drawing
  • US8875264B2 patent drawing

AI summary

Provided is an off-line two-factor user authentication system. The off-line two-factor user authentication system is designed to use, as a password, a one-time-password derivation rule to be applied to certain pattern elements included in a presentation pattern at specific positions so as to create a one-time password, and further use, as a second authentication factor, information identifying a client to be used by a user. A plurality of pattern seed values each adapted to uniquely specify a presentation pattern in combination with a client ID, and a plurality of verification codes corresponding to respective ones of the pattern seed values, are stored in an off-line two-factor authentication client. A presentation pattern is created based on a selected one of the pattern seed values and a client ID, and an entered one-time password is verified based on a verification code corresponding to the selected pattern seed value.