OTP Device Authentication with Server Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication methods, particularly those using one-time password (OTP) devices, are cumbersome and insecure, requiring multiple devices, difficult password management, and are vulnerable to hacking and data leakage, especially in open network environments.

Innovation Solution

A user authentication method that combines a personal password with a mechanical unique key using unidirectional functions for primary and secondary conversions, generating and encrypting authentication keys, and performing OTP operations to verify the genuineness of both the user and the authentication server, without storing passwords and using multiple factors associated with time for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple OTP authentication devices are provided for different financial institutes, then authentication capability for multiple institutions is improved, but device complexity and ease of operation deteriorate as users must carry and manage multiple devices

Engineering Contradiction:
Improveauthentication capabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies universality by enabling a single OTP device to perform authentication across multiple financial institutes through a universal authentication mechanism. The device stores multiple unique keys and can generate OTPs for different institutions, eliminating the need for separate dedicated devices for each financial institute while maintaining the ability to authenticate with any institution.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the functionality of multiple institution-specific OTP devices into a single unified device. By combining multiple unique keys and authentication functions within one device, the system reduces the number of physical devices users must carry while preserving the ability to authenticate with various financial institutes.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If unique keys are stored in OTP devices, then authentication security is improved, but reliability deteriorates when keys are leaked or devices are lost requiring reissuance

Engineering Contradiction:
Improveauthentication securityVSAvoidkey leakage vulnerability
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent introduces a server as an intermediary that manages the unique keys rather than storing them directly in the OTP devices. The server securely stores the unique keys and generates OTPs dynamically during authentication. This intermediary approach allows the system to maintain high security while enabling remote reissuance of keys and devices without physical visits to financial institutes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary action by pre-configuring the OTP device with a mechanism to receive and install new unique keys remotely from the server. When a key needs to be reissued due to leakage or device loss, the system can proactively push the new key to the device without requiring user intervention or physical presence, thereby maintaining continuous authentication capability.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If passwords are stored and managed by the server, then authentication functionality is improved, but ease of operation deteriorates due to difficult password management and regular changes required

Engineering Contradiction:
Improveauthentication convenienceVSAvoidpassword management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the password management burden from the user by eliminating the need for users to perceive, remember, or regularly change passwords. Instead of storing passwords in the OTP device or requiring user management, the system uses unique keys that are managed by the server. This extraction of password management responsibilities simplifies user operation while maintaining authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

4Adaptability or versatility

If authentication information is transmitted through open networks, then accessibility is improved, but security deteriorates due to vulnerabilities to hacking and data leakage

Engineering Contradiction:
Improvenetwork accessibilityVSAvoiddata leakage risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the traditional password-based authentication mechanism with a cryptographic key-based system. Instead of transmitting and verifying passwords that can be intercepted or leaked, the system uses unique keys and OTP generation mechanisms that provide enhanced security. The server-based key management and dynamic OTP generation make intercepted data useless for authentication, thereby reducing the impact of network vulnerabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10270762B2User authentication method for enhancing integrity and security
Publication Date: 2019.04.23 SSENSTONE INC
  • US10270762B2 patent drawing
  • US10270762B2 patent drawing
  • US10270762B2 patent drawing

AI summary

Disclosed is a user authentication method including at least: (1) performing a primary conversion to generate a first common authentication key and performing a secondary conversion to provide an encrypted first common authentication key, and registering the encrypted first common authentication key; (2) generating a first server authentication key, and performing an OTP operation on the first server authentication key to generate first server authentication information; (3) performing a primary conversion to generate a second common authentication key, performing a secondary conversion to generate an encrypted second common authentication key, generating a first user authentication key, and performing an OTP operation on the first user authentication key to generate first user authentication information; and (4) performing a user authentication or an authentication of the authentication server for determining a genuineness of the authentication server, based on coincidence of the first server authentication information and the first user authentication information.