One-Time Passcode Device for Secure Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face difficulties in managing numerous passwords and the risk of password theft due to their susceptibility to fraud, making existing password-based security systems inefficient and insecure.
Innovation Solution
A system that employs a passcode device generating unique, one-time passcodes based on user-specific identifying information, which are used for accessing secure entities, and an administrator verifies these passcodes using one-way functions to ensure secure and transient access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional password-based security systems are used, then users can access secure entities, but users face difficulties in managing numerous passwords and the risk of password theft increases
Solution Approach 1:
The patent implements one-time passcodes that are valid for a single use only. Each passcode generated by the passcode device is transient and cannot be reused, eliminating the need for users to remember multiple passwords while preventing password theft through reuse. This disposable approach to authentication directly resolves the contradiction between security and ease of operation.
2Reliability
If passwords are used for access control, then users can authenticate themselves, but passwords are susceptible to fraud and theft
Solution Approach 1:
The patent employs dynamic passcodes that change with each authentication request rather than static passwords. The passcode device generates a new passcode each time, making the authentication credential dynamic and time-sensitive. This dynamic approach prevents theft and fraud because stolen passcodes become immediately invalid, directly addressing the harmful factors of password theft and fraud.
Solution Approach 2:
The system performs preliminary validation by checking whether a presented passcode matches the currently expected passcode before granting access. The administrator system maintains the state of the last used passcode and validates incoming passcodes against this state, preventing fraudulent use of stolen or guessed passcodes.
3Reliability
If one-time passcodes are implemented, then security is enhanced and password theft is reduced, but the system complexity increases
Solution Approach 1:
The passcode device autonomously generates one-time passcodes based on its internal state without requiring external intervention or complex verification infrastructure. The device maintains its own authentication state and generates passcodes independently, simplifying the overall system architecture while enhancing security through transient credentials.
Data Source
AI summary
Protecting the security of an entity by using passcodes is disclosed. A passcode device generates a passcode. In an embodiment, the passcode is generated in response to receipt of user information. The passcode is received by another system, which authenticates the passcode by at least generating a passcode from a passcode generator, and comparing the generated passcode with the received passcode. The passcode is temporary. At a later use a different passcode is generated from a different passcode generator.


