Offline Two-Factor Authentication Using Client ID and Pattern Seeds
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional off-line user authentication systems rely solely on passwords for authentication, offering limited security as they cannot prevent fraudulent access if the password is leaked, and introducing additional authentication factors like one-time-password tokens increases costs and inconvenience.
Innovation Solution
An off-line two-factor user authentication system that uses a one-time-password derivation rule applied to pattern elements in a presentation pattern, combined with client identification information as a second authentication factor, to create a one-time password, enhancing security without the need for additional hardware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a one-time-password token is used for authentication, then security is improved, but cost and inconvenience increase due to carrying additional devices
Solution Approach 1:
The patent combines the authentication function with the client apparatus itself by using client identification information (such as hardware ID, device fingerprint, or system parameters) that is inherently present in the device. This eliminates the need for separate authentication tokens while maintaining security, as the client apparatus serves dual purposes: both as the service client and as the authentication credential holder.
Solution Approach 2:
The client apparatus provides authentication credentials (client identification information) that are automatically generated and stored within the device itself, without requiring external tokens or additional hardware. The device serves itself by using its own inherent characteristics as the authentication basis, reducing dependency on external authentication components.
2Reliability
If a one-time-password token is used for authentication, then security is improved, but cost increases due to token procurement and management
Solution Approach 1:
The patent replaces expensive, physically durable tokens with virtual, software-based client identification information that can be generated at minimal cost. The authentication credentials are essentially disposable in the sense that they can be regenerated or changed without physical token replacement, reducing long-term costs associated with token issuance, distribution, and replacement.
Solution Approach 2:
The patent substitutes the mechanical/physical token system with a software-based solution using client identification information. Instead of relying on physical tokens that require manufacturing, distribution, and physical security measures, the system uses digital identifiers that can be generated and managed through software, significantly reducing hardware costs and logistical overhead.
3Device complexity
If conventional off-line authentication is used, then simplicity is maintained, but security is insufficient due to reliance on single password factor
Solution Approach 1:
The patent makes the client identification information serve multiple functions: it acts as both a device identifier for service access and as an authentication credential for security verification. This multi-functionality allows the system to maintain simplicity by using a single identifier while achieving multi-factor authentication security, as the same client ID is used for both service identification and authentication purposes.
Data Source
AI summary
Provided is an off-line two-factor user authentication system. The off-line two-factor user authentication system is designed to use, as a password, a one-time-password derivation rule to be applied to certain pattern elements included in a presentation pattern at specific positions so as to create a one-time password, and further use, as a second authentication factor, information identifying a client to be used by a user. A plurality of pattern seed values each adapted to uniquely specify a presentation pattern in combination with a client ID, and a plurality of verification codes corresponding to respective ones of the pattern seed values, are stored in an off-line two-factor authentication client. A presentation pattern is created based on a selected one of the pattern seed values and a client ID, and an entered one-time password is verified based on a verification code corresponding to the selected pattern seed value.


