Single Device One-Time Password Generation with Distinct Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face the challenge of managing multiple hardware devices for generating one-time passwords across various restricted resources, leading to inconvenience and inefficiency, as well as security risks due to the need for different devices for each resource.

Innovation Solution

A method and device for generating one-time passwords using a single hardware device, such as a mobile phone, with distinct password generation parameters for each restricted resource, ensuring secure authentication without interaction between resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple hardware devices are used for generating one-time passwords for different restricted resources, then security is improved, but device complexity and user convenience deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple one-time password generation functions into a single mobile device. The server generates multiple unique secret keys (first secret key, second secret key, etc.) and sends them to the same mobile device, allowing it to generate one-time passwords for multiple restricted resources (first resource, second resource, etc.) without requiring separate hardware devices for each resource.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The mobile device is designed to perform multiple functions: it can generate one-time passwords for different restricted resources using different secret keys stored in its memory. The device universally handles authentication for various resources without needing separate dedicated devices, making it a multi-functional authentication tool.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple hardware devices are used for generating one-time passwords for different restricted resources, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines multiple one-time password generation functions into a single mobile device. The server generates multiple unique secret keys (first secret key, second secret key, etc.) and sends them to the same mobile device, allowing it to generate one-time passwords for multiple restricted resources (first resource, second resource, etc.) without requiring separate hardware devices for each resource.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If a single hardware device is used for generating one-time passwords for multiple restricted resources, then ease of operation is improved, but security deteriorates due to potential unauthorized access

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication credentials by creating distinct secret keys for different restricted resources. The server generates a first secret key for the first restricted resource and a second secret key for the second restricted resource, keeping them separate and independent. This segmentation ensures that compromise of one key does not affect security of other resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning specific secret keys to specific restricted resources. The first secret key is used exclusively for generating one-time passwords for the first restricted resource, while the second secret key is used for the second restricted resource. This localized assignment ensures that each resource has its own security parameters, preventing unauthorized cross-access.

Inventive Principle:
Principle #3Local quality

4Reliability

If distinct password generation parameters are used for each restricted resource, then security is improved by preventing unauthorized access, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication credentials by creating distinct secret keys for different restricted resources. The server generates a first secret key for the first restricted resource and a second secret key for the second restricted resource, keeping them separate and independent. This segmentation ensures that compromise of one key does not affect security of other resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses copying by replicating the secret key storage and one-time password generation functionality within the same device. The mobile device stores multiple secret keys (first secret key, second secret key, etc.) and uses the same generation algorithm for each, copying the authentication mechanism while maintaining parameter distinctiveness for security.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8898749B2Method and system for generating one-time passwords
Publication Date: 2014.11.25 MCAFEE LLC
  • US8898749B2 patent drawing
  • US8898749B2 patent drawing
  • US8898749B2 patent drawing

AI summary

A method for one-time password generation, the one-time password being used for user authentication by a restricted resource. The one-time password is generated by means of a mathematical algorithm in a user-specific device, and the one-time password is generated by the mathematical algorithm using at least one user-specific password generation parameter. A first password generation parameter is used for generating a first one-time password for use in user authentication by a first restricted resource, and a second password generation parameter is used for generating a second one-time password for use in user authentication by a second restricted resource, the second restricted resource being different from the first restricted resource, and the first and second password generation parameters being distinct.