One-Time Password Verification System for Secure Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identification and presence verification systems, such as key card systems and location beacons, are vulnerable to unauthorized access and manipulation, lacking effective solutions to ensure secure verification of individuals.

Innovation Solution

A method and system utilizing an identification tag with an embedded integrated circuit generating a one-time-password (OTP) and Near Field Communication (NFC) technology, coupled with a network connection, to verify user identity and presence through a server-based verification process, eliminating the need for location beacons and enhancing security by displaying user images for verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If key card systems are used for identification verification, then access control is simplified, but security is compromised due to theft and copying vulnerabilities

Engineering Contradiction:
Improveaccess controlVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transforms static identification data on key cards into dynamic one-time passwords that change with each authentication attempt. The OTP generation module creates time-sensitive or usage-sensitive codes that cannot be reused, making stolen or copied cards useless for subsequent access attempts while maintaining simple user interaction.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the authentication parameter from a static card ID to a dynamic OTP that varies with time or usage count. This parameter transformation ensures that even if authentication data is intercepted, it becomes invalid after a single use or time window, fundamentally improving security without complicating the user experience.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If location beacons are used for presence verification, then presence tracking is simplified, but security is compromised due to data copying and beacon relocation

Engineering Contradiction:
Improvepresence trackingVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary OTP verification layer between the presence verification system and the authentication process. Instead of directly trusting beacon data, the system uses OTPs as intermediaries that validate both identity and presence simultaneously, preventing beacon data from being copied or misused while maintaining simplified tracking operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If conventional key card systems are used, then identification verification is straightforward, but unauthorized access is facilitated through card manipulation

Engineering Contradiction:
Improveidentification verificationVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary OTP generation and validation before granting access. By pre-generating time-sensitive or usage-sensitive authentication codes and validating them server-side, the system prevents unauthorized access attempts using manipulated cards, while the user experience remains as simple as presenting the card for verification.

Inventive Principle:
Principle #10Preliminary action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach significantly reduces unauthorized access by ensuring only authorized users can gain access, as the system requires a valid OTP and image verification, thereby enhancing the security and reliability of identification and presence verification processes.

Implementation Method 1

a Near Field Communication (NFC) sub-system that reads data from the identification tag using radio frequency signals

Methodology Applied
Scientific EffectNear Field Communication (NFC): Electromagnetic Induction

Data Source

PatentUS10484366B2Verification of both identification and presence over a network
Publication Date: 2019.11.19 MYTAG LTD
  • US10484366B2 patent drawing
  • US10484366B2 patent drawing
  • US10484366B2 patent drawing

AI summary

A method and system for verifying both identification and presence of a user is provided. The system includes an identification tag containing data associated with a user, a reader for reading said data from the identification tag, communicating data received from the identification tag to the server, and a server configured for receiving the data sent by the reader, accessing a user record that corresponds to the user, determining whether the data it received is verified against data in the user record, and if said data is verified, then generating a data packet and transmitting said data packet to the reader over the communications network, wherein said data packet includes a verification message, a user name and a user image.