Dedicated Validation Appliances for Secure OTP Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems are vulnerable to attacks due to the centralized storage of secret keys, which can be compromised if accessed or intercepted, and lack effective measures to prevent breaches from both inside and outside attackers.

Innovation Solution

A network of dedicated validation appliances is implemented to generate and manage user profiles for one-time passwords, with highly constrained access and physical security measures to restrict access to secret keys, both at rest and in transit, using cryptographically secure hash functions and hardware-based random number generators to ensure key unpredictability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secret keys are stored in a centralized authentication system for OTP validation, then authentication functionality is enabled, but the system becomes vulnerable to attacks and key compromise

Engineering Contradiction:
Improveauthentication securityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the centralized authentication system into distributed validation appliances, each maintaining isolated secret keys. This segmentation prevents a single point of failure and limits the impact of potential compromises to individual appliances rather than the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces validation appliances as intermediaries between the authentication system and users. These appliances act as secure mediators that handle OTP validation without exposing the central authentication system's secret keys, thereby reducing direct attack surfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If secret keys are made accessible for authentication purposes, then user verification is enabled, but access restrictions and security breaches are compromised

Engineering Contradiction:
Improveauthentication accessibilityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements local quality by assigning different security characteristics to different validation appliances. Each appliance has restricted access to specific secret keys needed for its operational context, enabling localized authentication while maintaining overall system security through differentiated access controls.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9230084B2Method and system for enabling secure one-time password authentication
Publication Date: 2016.01.05 VERIZON PATENT & LICENSING INC
  • US9230084B2 patent drawing
  • US9230084B2 patent drawing
  • US9230084B2 patent drawing

AI summary

An approach for facilitating a one-time password (OTP) authentication procedure is described. A dedicated validation appliance receives a one-time password authentication request via an application programming interface, which is a single point of access to the dedicated validation appliance. The dedicated validation appliance then determines a validity of the request based on the correlating of a submitted OTP against OTP values independently generated by the dedicated validation appliance based on a large secret key exclusive to a client device that initiated the request. The single point of access to the dedicated validation appliance as well as exclusive sharing of the secret key with only another dedicated validation appliance or one-time with the client device reduces the likelihood of attackers discovering the secret keys.