Security Server One-Time Password Transaction Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user and transaction authentication methods are either vulnerable to attacks or cumbersome, and current solutions for transaction authentication are costly and inconvenient for frequent use.
Innovation Solution
A security server calculates and transmits a one-time-password based on transaction information and a shared secret between the server and the website, which is then validated by the website, allowing for secure transaction authentication without requiring a user-shared secret and using various hardware and software form factors for communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods (passwords, smart cards) are used, then user authentication can be achieved, but the system becomes vulnerable to MITM and MITB attacks
Solution Approach 1:
The patent introduces a pop-up window as an intermediary component between the user's browser and the website. This pop-up serves as a trusted mediator that independently verifies website legitimacy and provides transaction authentication, preventing MITM and MITB attacks by adding a verified layer of authentication that attackers cannot bypass without compromising the user's entire system.
Solution Approach 2:
The authentication system is segmented into separate functional components: the browser for accessing websites, the pop-up window for security verification, and the security server for authentication. This segmentation isolates the security functions from the browsing functions, allowing the pop-up to independently verify transactions without being compromised by browser-based attacks.
2Reliability
If out of band authentication (voice calls, text messages) is used for transaction confirmation, then transaction security is improved, but usability and cost deteriorate due to inconvenience and expense
Solution Approach 1:
Instead of requiring users to switch to a different communication channel (voice call or text message), the patent creates a visual copy of the transaction information within the browser's pop-up window. The user can review and confirm transaction details directly in the pop-up without leaving the browsing environment, maintaining security while dramatically improving ease of operation.
Solution Approach 2:
The pop-up window serves multiple functions: it authenticates the website's legitimacy, displays transaction information for user review, and provides a confirmation mechanism. This multi-functionality consolidates what would otherwise require separate authentication channels into a single integrated interface, improving both usability and cost-effectiveness.
3Reliability
If out of band authentication is used frequently for transaction confirmation, then transaction authentication is strengthened, but cost increases making it impractical for frequent use
Solution Approach 1:
The patent uses a lightweight pop-up window that operates entirely within the browser's existing infrastructure, requiring no additional communication channels or expensive external systems. The pop-up is a disposable, in-browser component that provides authentication without the recurring costs associated with voice calls or text messages, making frequent use economically viable.
4Reliability
If a security server with pop-up window system is implemented, then transaction authentication and risk management are improved, but device complexity increases
Solution Approach 1:
The pop-up window acts as an intermediary layer that manages the complexity of security server communications. It translates complex authentication protocols into simple user interactions (review and confirm), shielding users from system complexity while maintaining strong authentication. The pop-up serves as a buffer between the user and the complex security infrastructure.
Data Source
AI summary
To provide a user signature on a network transaction, a security server receives transaction information representing a transaction between a network user and a network site, such as a website, directly from the network site. The security server calculates a one-time-password based on the received transaction information and a secret shared by the security server and the network site, but not by the user. The security server transmits the calculated one-time-password for application as the user's signature on the transaction. The one-time-password is independently calculable by the network site based on the shared secret.


