One-Time Password Generator for Secure Computer System Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for preventing unauthorized access to computer systems, such as two-factor authentication, are ineffective in Windows safe mode and can be costly for ordinary users, leaving systems vulnerable to malicious access.

Innovation Solution

A method utilizing a one-time password generator that produces a cipher text from user/system numbers, valid dates/times, and random numbers, which is then decrypted and verified for secure login, with monitoring to restrict usage duration or counts, ensuring secure access even in Windows safe mode.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If two-factor authentication using hardware devices is implemented, then security is increased, but device cost and complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a software-based copy of hardware authentication functionality through virtual machine technology. The authentication key and security functions are replicated in the virtual machine environment, eliminating the need for physical hardware devices while maintaining security. This allows the system to achieve hardware-level security without the cost and complexity of actual hardware tokens or smart cards.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces mechanical hardware authentication devices with a software-based virtual machine system. Instead of using physical hardware tokens, smart cards, or biometric devices, the authentication mechanism is implemented through virtualized software components that run within the operating system, substituting mechanical systems with electronic/software equivalents.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If two-factor authentication using hardware devices is implemented, then security is increased, but ease of operation decreases

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The virtual machine authentication system operates automatically in the background without requiring user intervention to manage physical hardware devices. The authentication key is automatically generated, stored, and utilized by the virtual machine environment, eliminating the need for users to manually handle hardware tokens, insert smart cards, or perform complex authentication rituals. The system serves itself by automatically managing the authentication process.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If traditional password protection is used, then ease of operation is maintained, but security deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges traditional password authentication with virtual machine-based cryptographic authentication. The system combines the simplicity of password entry with the security of hardware-level cryptographic keys stored in the virtual machine environment. This integration allows users to maintain easy password-based operation while benefiting from the enhanced security of virtualized hardware authentication mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8522038B2Method for preventing unauthorized access to the computer system by using one-time password
Publication Date: 2013.08.27 FEITIAN TECHNOLOGIES CO LTD
  • US8522038B2 patent drawing
  • US8522038B2 patent drawing
  • US8522038B2 patent drawing

AI summary

The present invention provides a method for preventing unauthorized access to the computer system, and more particularly, provides a method for preventing unauthorized access to the computer system by using the one-time password. The one-time password is produced by a one-time password generator, and decrypted and verified by the computer logon system, and is used to log on the computer system. The present invention increases the security of the computer system, and protects the computer system from unauthorized access and use in a cost-effective way.