Rubbing Encryption Algorithm Web-Based OTP Token
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current web-based OTP token solutions face challenges such as high costs, poor interoperability, weak compliance with existing authentication infrastructures, and poor usability, along with vulnerabilities like unauthorized access and security breaches when used in insecure public environments.
Innovation Solution
The Rubbing Encryption Algorithm (REAL) provides a secure web-based OTP token system that uses a non-electronic hardware token to decrypt OTP codes displayed on a screen, ensuring high encryption strength without revealing the encryption key, and is compatible with existing authentication systems, allowing users to securely access systems without carrying multiple tokens.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional hardware tokens are used for OTP generation, then security is improved, but cost and device complexity increase
Solution Approach 1:
The patent uses a visual display of encrypted data (ciphertext image) as a copy representation of the OTP code. Instead of requiring physical hardware tokens with complex electronic components, the system creates a visual copy that can be displayed on standard screens. The encrypted data is rendered as an image that users can view and interact with, eliminating the need for complex hardware while maintaining security through the encryption algorithm itself.
Solution Approach 2:
The patent replaces the mechanical/electronic OTP generation system with an optical/visual system. Instead of electronic tokens generating and displaying codes, the system uses visual display technology to show encrypted data. The 'mechanical' token system is substituted with a software-based visual interface that renders encrypted information as images, simplifying the overall system while maintaining security through cryptographic algorithms rather than physical hardware complexity.
2Reliability
If continuous key updates are implemented, then security is improved, but system complexity and cost increase
Solution Approach 1:
The patent performs preliminary encryption of the OTP code before display. The encryption key is pre-computed and applied to the OTP code to generate the ciphertext image. This preliminary action of encrypting the code before it is displayed or transmitted ensures that even if the code is captured, it cannot be read without the corresponding decryption key. The key update mechanism is built into the encryption process itself, allowing continuous security updates without adding complex system layers.
3Reliability
If data capture and reverse engineering are prevented, then security is improved, but measurement and detection difficulty increases
Solution Approach 1:
The patent employs visual encoding techniques where the encrypted data is displayed using variations in color, brightness, or visual patterns. The ciphertext image uses visual characteristics that make captured data difficult to interpret. By encoding the encrypted information in the visual domain with specific color and pattern characteristics, the system makes reverse engineering more difficult while maintaining ease of display and user interaction.
Data Source
AI summary
The present disclosure proposes a secure way to generate the OTP code by way of a web browser. A user does not need any electronic device on hand to obtain OTP for 2FA login. A new Rubbing Encryption Algorithm (REAL) is proposed as the base technology. Implementation method of such web-based OTP token is presented and analyzed. It operates through a web-browser with a multiple REAL keys. It can be integrated into many secure Internet commerce applications as well. A system is provided for secure access to a software program or website. The system has a first entity with a computing device with a processor and a memory. The first entity provides a plurality of data items. The system also has a second entity with at least one display for displaying the plurality of data items. The data items are arranged in a predetermined format. The display also displays a prompt for a user identification and a prompt for a code. The second entity has a member with a transparent portion. The transparent portion comprises a periphery with a plurality of markings placed around the periphery. The markings point to a first direction or to an opposite second direction. The second entity overlays the member over the data items. The markings point to the plurality of data items to reveal a code. The code is input and permits access of the second entity to the computing device of the first entity.


