One-Time Passcode Device for Secure Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in managing numerous passwords and the risk of password theft due to their susceptibility to fraud, making existing password-based security systems inefficient and insecure.

Innovation Solution

A system that employs a passcode device generating unique, one-time passcodes based on user-specific identifying information, which are used for accessing secure entities, and an administrator verifies these passcodes using one-way functions to ensure secure and transient access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional password-based security systems are used, then users can access secure entities, but users face difficulties in managing numerous passwords and the risk of password theft increases

Engineering Contradiction:
ImprovesecurityVSAvoidpassword management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements one-time passcodes that are valid for a single use only. Each passcode generated by the passcode device is transient and cannot be reused, eliminating the need for users to remember multiple passwords while preventing password theft through reuse. This disposable approach to authentication directly resolves the contradiction between security and ease of operation.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Reliability

If passwords are used for access control, then users can authenticate themselves, but passwords are susceptible to fraud and theft

Engineering Contradiction:
Improveauthentication securityVSAvoidpassword theft and fraud
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent employs dynamic passcodes that change with each authentication request rather than static passwords. The passcode device generates a new passcode each time, making the authentication credential dynamic and time-sensitive. This dynamic approach prevents theft and fraud because stolen passcodes become immediately invalid, directly addressing the harmful factors of password theft and fraud.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary validation by checking whether a presented passcode matches the currently expected passcode before granting access. The administrator system maintains the state of the last used passcode and validates incoming passcodes against this state, preventing fraudulent use of stolen or guessed passcodes.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If one-time passcodes are implemented, then security is enhanced and password theft is reduced, but the system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidpasscode generation and verification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The passcode device autonomously generates one-time passcodes based on its internal state without requiring external intervention or complex verification infrastructure. The device maintains its own authentication state and generates passcodes independently, simplifying the overall system architecture while enhancing security through transient credentials.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7707622B2API for a system having a passcode authenticator
Publication Date: 2010.04.27 BIOGY INC
  • US7707622B2 patent drawing
  • US7707622B2 patent drawing
  • US7707622B2 patent drawing

AI summary

Protecting the security of an entity by using passcodes is disclosed. A passcode device generates a passcode. In an embodiment, the passcode is generated in response to receipt of user information. The passcode is received by another system, which authenticates the passcode by at least generating a passcode from a passcode generator, and comparing the generated passcode with the received passcode. The passcode is temporary. At a later use a different passcode is generated from a different passcode generator.