One-Time Passcode Camouflaging via Machine Identifier

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing secure payment infrastructure using smart cards and dedicated card readers is inconvenient for users, requiring physical presence of the card reader and smart card, and is prone to issues like client-server synchronization problems and card locking due to incorrect PIN attempts.

Innovation Solution

A method to securely host a one-time passcode (OTP) generating application on user handheld devices like iPhones and in browsers, using cryptographic camouflaging with a machine-derived identification parameter, eliminating the need for dedicated hardware and enhancing security by associating the OTP generating software client exclusively with the user device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If smart card and dedicated card reader hardware are used to generate OTP, then security is maintained through symmetric key cryptography, but user convenience deteriorates due to requiring physical presence of card reader and smart card

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical hardware system (smart card + dedicated card reader) with a software-based OTP generating application that can execute on general-purpose user devices. The cryptographic functions previously requiring specialized hardware are now implemented as software algorithms, eliminating the need for physical card insertion and dedicated reading devices while maintaining security through proper key management and cryptographic protocols

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The OTP generating application is designed to run on multiple types of user devices (smartphones, tablets, computers) with standard communication capabilities, replacing the need for dedicated card reader hardware. The software client can universally interface with various devices through standard protocols, allowing the same OTP generation functionality to work across different platforms and device types without requiring device-specific hardware

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If OTP generating application is hosted on user handheld devices, then user convenience is improved by eliminating dedicated hardware, but security deteriorates due to potential exposure of keys on general-purpose devices

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transforms the cryptographic keys from their traditional static form into dynamic parameters that are continuously protected by device-specific identification values. The keys are processed through cryptographic functions that incorporate changing device identifiers, making the effective key material different for each device while maintaining the same underlying secret. This parameter transformation ensures that even if keys are exposed on one device, they cannot be reused on another device

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces device identification parameters as an intermediary layer between the stored cryptographic keys and the OTP generation process. These device-specific identifiers act as mediators that bind the keys to particular devices, adding an extra security layer. The device identification values are processed through cryptographic functions to derive device-specific key material, preventing key exposure on general-purpose devices from compromising security on other devices

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If machine-derived identification parameter is used to associate OTP software client with user device, then security is enhanced through unique device association, but device complexity increases due to fingerprint code execution and MESC generation

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the user device automatically generates its own fingerprint code and machine effective speed calibration (MESC) values without requiring external intervention. The device's hardware characteristics are automatically measured and processed into identification parameters during the OTP generation process. This self-service approach binds the cryptographic keys to the specific device's inherent characteristics, enhancing security while minimizing additional complexity through automated processes

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary generation of device identification parameters (fingerprint codes and MESC values) during device initialization or first use. These device-specific identifiers are pre-computed and stored, allowing subsequent OTP generation to use them without repeated complex measurements. The preliminary action of binding keys to device characteristics during setup reduces the operational complexity during normal use while maintaining strong device association security

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9218493B2Key camouflaging using a machine identifier
Publication Date: 2015.12.22 CA TECH INC
  • US9218493B2 patent drawing
  • US9218493B2 patent drawing
  • US9218493B2 patent drawing

AI summary

A method is provided for generating a human readable passcode to an authorized user including providing a control access datum and a PIN, and generating a unique machine identifier for the user machine. The method further includes modifying the controlled access datum, encrypting the controlled access datum using the PIN and/or a unique machine identifier to camouflage the datum, and generating a passcode using the camouflaged datum and the PIN and/or the unique machine identifier. A mobile user device may be used to execute the method in one embodiment. The passcode may be used to obtain transaction authorization and/or access to a secured system or secured data. The unique machine identifier may be defined by a machine effective speed calibration derived from information collected from and unique to the user machine.