One-Time Passcode Device for Secure Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face difficulties in managing numerous passwords and the risk of password theft due to their susceptibility to fraud, making existing password-based security systems inefficient and insecure.
Innovation Solution
A passcode device that generates unique, one-time passcodes based on user-provided identifying information, such as fingerprints, which are used for accessing secure entities, eliminating the need for password storage and reducing the effectiveness of stolen passcodes by ensuring they are only valid for a single use.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional password-based security systems are used, then access control functionality is provided, but users face difficulties in managing numerous passwords and the risk of password theft increases
Solution Approach 1:
The patent extracts the password from the user's memory burden by implementing a passcode generator device that automatically creates and manages passcodes. The device takes out the need for users to remember multiple passwords by generating unique passcodes locally on the user's device, thereby improving ease of operation while maintaining security.
Solution Approach 2:
The patent introduces a passcode generator device as an intermediary between the user and the security system. This intermediary automatically generates passcodes based on user credentials stored locally, mediating the authentication process without requiring users to manually manage or remember passwords, thus resolving the contradiction between security and ease of operation.
2Ease of operation
If passwords are stored for reuse, then user convenience is improved, but the system becomes susceptible to fraud and password theft
Solution Approach 1:
The patent implements disposable, single-use passcodes that are generated locally on the user's device and never stored or transmitted. Each passcode is valid for one authentication attempt only, making them inexpensive and short-lived security credentials that cannot be stolen or reused, thereby eliminating fraud susceptibility while maintaining user convenience.
Solution Approach 2:
The patent performs preliminary authentication by verifying user credentials locally on the user's device before generating a passcode. This preliminary action ensures that only authorized users can generate passcodes, and the passcodes are created in advance of the authentication attempt, eliminating the need to store or transmit sensitive credential information.
3Adaptability or versatility
If multiple passwords are required for different systems, then access control to multiple entities is enabled, but the complexity of password management increases
Solution Approach 1:
The patent implements a universal passcode generator device that can authenticate users to multiple different systems and services. The device generates passcodes based on user credentials stored locally, allowing a single device to provide access control functionality across multiple systems without requiring users to manage separate passwords for each system, thereby reducing management complexity while maintaining versatility.
Data Source
AI summary
The security of an entity is protected by using passcodes. A passcode device generates a passcode. In an embodiment, the passcode is generated in response to receipt of user information. The passcode is received by another system, which authenticates the passcode by at least generating a passcode from a passcode generator, and comparing the generated passcode with the received passcode. The passcode is temporary. At a later use a different passcode is generated from a different passcode generator.


