Optical Code Authentication for Random Number Leakage Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional FIDO authentication techniques are vulnerable to random number leakage due to malicious code or software during transmission, posing security risks for high-security services like bank transactions and credit card payments.

Innovation Solution

A system and method where a service server converts a random number into an optical code, such as a QR code or barcode, and transmits it to a user terminal, which is then captured by a second user terminal to authenticate the user, thereby excluding the random number from the authentication request message to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a random number is transmitted from the FIDO server to the user terminal for authentication, then the authentication process can be completed, but the random number may be leaked due to malicious code or software

Engineering Contradiction:
Improveauthentication securityVSAvoidrandom number leakage
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the random number from the authentication request message and transmits it separately through an optical code. This separation ensures that even if the authentication message is intercepted, the random number remains secure as it is not contained within the transmitted message structure.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an optical code as an intermediary medium to transmit the random number. Instead of directly embedding the random number in the authentication protocol, it uses an optical representation that requires physical capture and processing, adding a security layer against digital interception and malicious code.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the random number is excluded from the authentication request message to prevent leakage, then security is improved, but the authentication process becomes more complex

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates an optical copy (QR code or barcode) of the random number that can be captured by the camera. This copying mechanism simplifies the process compared to manual entry while maintaining security, as the optical code can be automatically scanned and processed by the authentication application.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system uses the device's existing camera and processing capabilities to capture and decode the optical code automatically. This self-service approach eliminates the need for additional hardware or complex manual procedures, leveraging what the device already has to simplify the overall process.

Inventive Principle:
Principle #25Self-service

3Reliability

If additional hardware is introduced to enhance security during random number transmission, then security is improved, but the device complexity and cost increase

Engineering Contradiction:
Improveauthentication securityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces potential physical security hardware with an optical-based solution using existing camera capabilities. This substitution eliminates the need for specialized hardware while maintaining or enhancing security through the use of optical codes that are difficult to intercept or replicate digitally.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10671718B2System and method for authentication
Publication Date: 2020.06.02 SAMSUNG SDS CO LTD
  • US10671718B2 patent drawing
  • US10671718B2 patent drawing
  • US10671718B2 patent drawing

AI summary

A system and method for authentication are provided. The system for authentication according to one embodiment of the present disclosure includes: a service server configured to: receive a first authentication request message from an authentication server and convert a random number included in the first authentication request message into an optical code; a first user terminal configured to receive the optical code from the service server and display the optical code; and a second user terminal configured to: recognize the random number by capturing an image of the displayed optical code in response to receiving a second authentication request message from the service server and authenticate a user by using the random number, the second authentication request message, and biometric information of the user.