One-Time Login Pair Generation for Unsecure Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
When accessing secure services on unsecure devices, such as public computers, users face challenges in ensuring the security of their login credentials due to potential compromises of the system, making it difficult to guarantee the absence of physical keyloggers or other malicious attachments.
Innovation Solution
A system and method for generating one-time use login pairs using a secure mobile communication device, which communicates with a security server to create and present user ID and password pairs for validation on an unsecure communication device, ensuring secure access to services without creating persistent cookies or mechanisms that could compromise security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If users access secure services on unsecure devices, then service accessibility is improved, but security of login credentials deteriorates
Solution Approach 1:
The patent segments the login credentials into multiple one-time use pairs, where each pair can be used only once for authentication. This segmentation allows users to access services on multiple unsecure devices without compromising the security of their main credentials, as each segmented credential pair is disposable and cannot be reused.
Solution Approach 2:
The patent implements disposable login credential pairs that are generated temporarily and become invalid after a single use. These short-living credential objects allow users to safely access unsecure services without long-term security risks, as the credentials automatically expire after one authentication event, preventing unauthorized reuse.
2Reliability
If one-time login pairs are generated and used, then security of credentials is improved, but complexity of authentication process increases
Solution Approach 1:
The system automatically generates and manages one-time login credential pairs without requiring user intervention for complex security protocols. The server handles credential generation, distribution, and validation automatically, while users simply receive and use the provided credential pairs, reducing the perceived complexity for end-users.
Solution Approach 2:
The patent introduces a server as an intermediary that manages the complex credential generation and validation processes. This intermediary handles the cryptographic operations and session management, shielding users from the underlying complexity while providing a simple interface for obtaining and using one-time login pairs.
Data Source
AI summary
A trusted communication device may generate and display a single use user ID and/or password to be utilized for one time validation of a communication session between an unsecure communication device and a secure communication device. The generated single use user ID and/or password may be communicated from the trusted communication device to a security server that handles security for the communication session. The user utilizes the presented user ID and password pairs to log into a communication session on the unsecure communication device. A heartbeat message may be communicated between the trusted communication device and the security server, and whenever the communicated heartbeat message fails, the user ID and password pair and/or one or more corresponding authentication tokens are deauthorized. A communication session that utilizes the presented user ID and password pair may be manually disabled from the trusted communication device.


