One-Time Passcode Generator for Secure Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in managing numerous passwords and the risk of password theft, leading to security vulnerabilities in accessing secure systems.

Innovation Solution

A passcode device that generates unique, one-time passcodes based on user-identified information, such as fingerprints, which are used for accessing secure entities, and an administrator system that authenticates these passcodes using one-way functions to ensure secure access without storing the actual passcodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional passwords are used for access control, then users can access multiple systems, but users must remember numerous passwords and passwords are susceptible to theft

Engineering Contradiction:
ImprovesecurityVSAvoidpassword management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the password from the user's memory burden by implementing a passcode generator device that automatically creates one-time passcodes. The device takes out the need for users to remember multiple passwords by generating unique passcodes for each access request, thereby improving both security and ease of operation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements disposable one-time passcodes that are valid for a single use only. Each passcode is generated, used once, and then becomes invalid, eliminating the risk of reused stolen passwords. This disposable nature of passcodes directly addresses the security vulnerability of traditional reusable passwords while maintaining user convenience.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Ease of operation

If passwords are stored for future use, then access is convenient, but stolen passwords can be reused for fraud

Engineering Contradiction:
Improveaccess convenienceVSAvoidfraud risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements one-time use passcodes that are discarded after a single authentication. These disposable passcodes cannot be reused even if stolen, eliminating the fraud risk associated with stored reusable passwords while maintaining access convenience through automatic generation.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent makes the passcode dynamic by generating a new unique passcode for each access request rather than using static stored passwords. The passcode changes with each use, making stolen passcodes invalid for future attempts, thus preventing fraud while maintaining convenient access.

Inventive Principle:
Principle #15Dynamics

3Reliability

If one-time passcodes are generated for each access request, then security is enhanced and stolen passcodes are less effective, but the system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service passcode generator device that automatically creates one-time passcodes without requiring complex external authentication systems. The device uses simple user-identified information as input and autonomously generates secure passcodes, enhancing security while minimizing system complexity through self-contained operation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent segments the authentication system into a dedicated passcode generator device that operates independently. This segmentation allows the complex one-time passcode generation functionality to be isolated in a separate device, simplifying the overall system architecture while maintaining high security standards.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7886155B2System for generating requests to a passcode protected entity
Publication Date: 2011.02.08 BIOGY INC
  • US7886155B2 patent drawing
  • US7886155B2 patent drawing
  • US7886155B2 patent drawing

AI summary

The security of an entity is protected by using passcodes. A passcode device generates a passcode. In an embodiment, the passcode is generated in response to receipt of user information. The passcode is received by another system, which authenticates the passcode by at least generating a passcode from a passcode generator, and comparing the generated passcode with the received passcode. The passcode is temporary. At a later use a different passcode is generated from a different passcode generator.