OTP Device Authentication with Server Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user authentication methods, particularly those using one-time password (OTP) devices, are cumbersome and insecure, requiring multiple devices, difficult password management, and are vulnerable to hacking and data leakage, especially in open network environments.
Innovation Solution
A user authentication method that combines a personal password with a mechanical unique key using unidirectional functions for primary and secondary conversions, generating and encrypting authentication keys, and performing OTP operations to verify the genuineness of both the user and the authentication server, without storing passwords and using multiple factors associated with time for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple OTP authentication devices are provided for different financial institutes, then authentication capability for multiple institutions is improved, but device complexity and ease of operation deteriorate as users must carry and manage multiple devices
Solution Approach 1:
The patent applies universality by enabling a single OTP device to perform authentication across multiple financial institutes through a universal authentication mechanism. The device stores multiple unique keys and can generate OTPs for different institutions, eliminating the need for separate dedicated devices for each financial institute while maintaining the ability to authenticate with any institution.
Solution Approach 2:
The patent merges the functionality of multiple institution-specific OTP devices into a single unified device. By combining multiple unique keys and authentication functions within one device, the system reduces the number of physical devices users must carry while preserving the ability to authenticate with various financial institutes.
2Reliability
If unique keys are stored in OTP devices, then authentication security is improved, but reliability deteriorates when keys are leaked or devices are lost requiring reissuance
Solution Approach 1:
The patent introduces a server as an intermediary that manages the unique keys rather than storing them directly in the OTP devices. The server securely stores the unique keys and generates OTPs dynamically during authentication. This intermediary approach allows the system to maintain high security while enabling remote reissuance of keys and devices without physical visits to financial institutes.
Solution Approach 2:
The patent implements preliminary action by pre-configuring the OTP device with a mechanism to receive and install new unique keys remotely from the server. When a key needs to be reissued due to leakage or device loss, the system can proactively push the new key to the device without requiring user intervention or physical presence, thereby maintaining continuous authentication capability.
3Ease of operation
If passwords are stored and managed by the server, then authentication functionality is improved, but ease of operation deteriorates due to difficult password management and regular changes required
Solution Approach 1:
The patent extracts the password management burden from the user by eliminating the need for users to perceive, remember, or regularly change passwords. Instead of storing passwords in the OTP device or requiring user management, the system uses unique keys that are managed by the server. This extraction of password management responsibilities simplifies user operation while maintaining authentication functionality.
4Adaptability or versatility
If authentication information is transmitted through open networks, then accessibility is improved, but security deteriorates due to vulnerabilities to hacking and data leakage
Solution Approach 1:
The patent replaces the traditional password-based authentication mechanism with a cryptographic key-based system. Instead of transmitting and verifying passwords that can be intercepted or leaked, the system uses unique keys and OTP generation mechanisms that provide enhanced security. The server-based key management and dynamic OTP generation make intercepted data useless for authentication, thereby reducing the impact of network vulnerabilities.
Data Source
AI summary
Disclosed is a user authentication method including at least: (1) performing a primary conversion to generate a first common authentication key and performing a secondary conversion to provide an encrypted first common authentication key, and registering the encrypted first common authentication key; (2) generating a first server authentication key, and performing an OTP operation on the first server authentication key to generate first server authentication information; (3) performing a primary conversion to generate a second common authentication key, performing a secondary conversion to generate an encrypted second common authentication key, generating a first user authentication key, and performing an OTP operation on the first user authentication key to generate first user authentication information; and (4) performing a user authentication or an authentication of the authentication server for determining a genuineness of the authentication server, based on coincidence of the first server authentication information and the first user authentication information.


