One-Time Passcode Device for Secure Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in managing numerous passwords and the risk of password theft due to their susceptibility to fraud, making existing password-based access systems insecure and cumbersome.

Innovation Solution

A system that employs a passcode device generating unique, one-time passcodes based on user-specific identifying information, such as fingerprints, which are used for accessing secure entities, and an administrator verifies these passcodes using one-way functions to ensure secure access without storing the actual passcodes, thereby reducing the risk of theft.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional password-based access control is used, then users can access systems, but passwords are susceptible to theft and fraud, compromising security

Engineering Contradiction:
ImprovesecurityVSAvoidpassword theft and fraud susceptibility
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by generating passcodes in advance based on user-specific identifying information stored in the passcode device. This allows the system to prepare authentication credentials before access is needed, eliminating the need for users to remember passwords while maintaining security through one-time use passcodes

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The passcode device acts as an intermediary between the user and the system. It stores user-specific identifying information and generates passcodes that mediate the authentication process, preventing direct exposure of sensitive authentication data and reducing fraud susceptibility

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple passwords are required for different systems, then access control is possible, but users face difficulty in remembering them, reducing ease of operation

Engineering Contradiction:
Improveaccess control capabilityVSAvoidpassword memorization burden
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The passcode device provides self-service functionality by automatically generating passcodes based on stored user-specific identifying information. Users simply need to present their identifying information (such as fingerprints) to the passcode device, which then handles the complex task of generating unique passcodes for each access attempt, eliminating the need for users to memorize multiple passwords

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by pre-storing user-specific identifying information in the passcode device during setup. This preliminary configuration enables the device to generate appropriate passcodes automatically during subsequent access attempts, reducing operational complexity for users

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7702911B2Interfacing with a system that includes a passcode authenticator
Publication Date: 2010.04.20 BIOGY INC
  • US7702911B2 patent drawing
  • US7702911B2 patent drawing
  • US7702911B2 patent drawing

AI summary

Protecting the security of an entity by using passcodes is disclosed. A passcode device generates a passcode. In an embodiment, the passcode is generated in response to receipt of user information. The passcode is received by another system, which authenticates the passcode by at least generating a passcode from a passcode generator, and comparing the generated passcode with the received passcode. The passcode is temporary. At a later use a different passcode is generated from a different passcode generator.