One-Time Passcode Device for Secure Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in managing numerous passwords and the risk of password theft due to their susceptibility to fraud, making existing password-based security systems inefficient and insecure.

Innovation Solution

A passcode device that generates unique, one-time passcodes based on user-provided identifying information, such as fingerprints, which are used for accessing secure entities, eliminating the need for password storage and reducing the effectiveness of stolen passcodes by ensuring they are only valid for a single use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional password-based security systems are used, then access control functionality is provided, but users face difficulties in managing numerous passwords and the risk of password theft increases

Engineering Contradiction:
ImprovesecurityVSAvoidpassword management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the password from the user's memory burden by implementing a passcode generator device that automatically creates and manages passcodes. The device takes out the need for users to remember multiple passwords by generating unique passcodes locally on the user's device, thereby improving ease of operation while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a passcode generator device as an intermediary between the user and the security system. This intermediary automatically generates passcodes based on user credentials stored locally, mediating the authentication process without requiring users to manually manage or remember passwords, thus resolving the contradiction between security and ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If passwords are stored for reuse, then user convenience is improved, but the system becomes susceptible to fraud and password theft

Engineering Contradiction:
Improvepassword reuse convenienceVSAvoidfraud susceptibility
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements disposable, single-use passcodes that are generated locally on the user's device and never stored or transmitted. Each passcode is valid for one authentication attempt only, making them inexpensive and short-lived security credentials that cannot be stolen or reused, thereby eliminating fraud susceptibility while maintaining user convenience.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent performs preliminary authentication by verifying user credentials locally on the user's device before generating a passcode. This preliminary action ensures that only authorized users can generate passcodes, and the passcodes are created in advance of the authentication attempt, eliminating the need to store or transmit sensitive credential information.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple passwords are required for different systems, then access control to multiple entities is enabled, but the complexity of password management increases

Engineering Contradiction:
Improvemulti-system accessVSAvoidpassword management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal passcode generator device that can authenticate users to multiple different systems and services. The device generates passcodes based on user credentials stored locally, allowing a single device to provide access control functionality across multiple systems without requiring users to manage separate passwords for each system, thereby reducing management complexity while maintaining versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7669236B2Determining whether to grant access to a passcode protected system
Publication Date: 2010.02.23 BIOGY INC
  • US7669236B2 patent drawing
  • US7669236B2 patent drawing
  • US7669236B2 patent drawing

AI summary

The security of an entity is protected by using passcodes. A passcode device generates a passcode. In an embodiment, the passcode is generated in response to receipt of user information. The passcode is received by another system, which authenticates the passcode by at least generating a passcode from a passcode generator, and comparing the generated passcode with the received passcode. The passcode is temporary. At a later use a different passcode is generated from a different passcode generator.