Paired Personal Devices for Time-Variable Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods are flawed due to architectural weaknesses, reliance on static biometrics, and the need for dedicated hardware, which can be compromised or cumbersome, especially in retail transactions, where secure data handling is critical to prevent financial liability.
Innovation Solution
A system utilizing two user-controlled personal devices capable of generating time-variable encryption keys, with at least one device acting as a coordinating device for authentication, operating with a Certification Authority to ensure secure transactions without revealing sensitive information, and allowing devices to reverse roles for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods (passwords, biometrics, static tokens) are used, then implementation is simple, but security is compromised due to static keys, copying vulnerabilities, and architectural weaknesses
Solution Approach 1:
The patent implements dynamic authentication keys that change over time rather than static keys. The system generates time-variable encryption keys that are automatically updated, preventing replay attacks and key compromise. This dynamic approach transforms the authentication system from a static state to a continuously changing state, resolving the security vulnerability of static authentication credentials.
Solution Approach 2:
The patent divides the authentication system into multiple independent components: a first device holding a first key, a second device holding a second key, and a certification authority. Each component operates independently but contributes to the overall authentication process. This segmentation prevents a single point of failure and eliminates the need for a single vulnerable static key, thereby improving security without requiring overly complex centralized control.
2Reliability
If two-factor authentication is implemented, then security is improved, but user convenience deteriorates due to increased complexity and intrusiveness
Solution Approach 1:
The patent enables the authentication system to automatically manage key generation, distribution, and validation without requiring user intervention. The first and second devices autonomously generate their respective keys, and the certification authority automatically validates the authentication process. This self-service mechanism eliminates the need for users to manually input passwords or manage authentication tokens, thereby maintaining high security while preserving user convenience.
Solution Approach 2:
The patent performs preliminary key generation and distribution before the actual authentication event. The first and second devices pre-generate their authentication keys and establish their roles in advance. When authentication is needed, the system simply validates the pre-established keys rather than requiring users to create or manage credentials at the moment of authentication, significantly improving ease of operation.
3Reliability
If dedicated hardware devices are used for authentication, then security is enhanced, but cost and ease of implementation worsen due to proprietary hardware requirements
Solution Approach 1:
The patent designs the authentication system to work with universal software-based devices rather than requiring specialized proprietary hardware. The first and second devices can be standard computing devices running authentication software, making the system broadly implementable across different platforms and devices. This universality reduces manufacturing costs and simplifies deployment while maintaining security through software-based cryptographic operations.
Solution Approach 2:
The patent uses software implementations of authentication functions that can be replicated and distributed without physical hardware constraints. The authentication logic and key management algorithms can be copied and deployed across multiple devices, eliminating the need for expensive proprietary hardware tokens. This software-based approach maintains security through cryptographic strength rather than hardware exclusivity.
4Ease of operation
If static biometric data is used for authentication, then ease of use is improved, but security worsens because biometric data can be copied and the system compromised
Solution Approach 1:
The patent replaces static biometric authentication with dynamic time-variable encryption keys. Instead of relying on immutable biometric data that can be copied or spoofed, the system uses keys that continuously change over time. This dynamic approach maintains ease of use (automatic authentication) while dramatically improving security by preventing replay attacks and biometric data compromise.
Solution Approach 2:
The patent changes the fundamental parameter of authentication from static biometric characteristics to time-variable cryptographic keys. This parameter change transforms the authentication mechanism from one based on unchangeable physical traits to one based on dynamically generated mathematical secrets, thereby eliminating the vulnerability of biometric copying while preserving user convenience.
Data Source
AI summary
An authentication system is provided for authenticating users in accordance with an encryption/decryption algorithm using first and second separately unique encryption keys that are time variable and are uniquely associated with each user, having a first user controlled computing device under the control of the user for generating said first encryption key using an encryption key generating algorithm. The first user controlled computing device includes a key transmitter for transmitting wirelessly within the immediate vicinity of the user the first encryption key, a second user controlled computing device, operating as a coordinating device under the control of the user, for generating the second encryption key using the encryption key generating algorithm. The second user controlled computing device includes a key receiver for receiving the first encryption key.


