Smartwatch OTP Generation via Biometric Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods, such as two-factor authentication, can be cumbersome as they require accessing email or phone to retrieve or generate one-time passwords (OTPs), and there is a need for a more convenient method to access computing applications.

Innovation Solution

A method for generating OTPs on a smartwatch that communicates with a smartphone, using a secure wireless connection to retrieve a token list, receive a biometric identifier, and generate an OTP, which is then displayed on the smartwatch with a countdown for expiration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If two-factor authentication is implemented using email or phone, then security is improved, but ease of operation deteriorates due to the need to access additional devices

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines the authentication process into a single device (smartwatch) by integrating biometric sensing, local OTP generation, and communication capabilities. This merging eliminates the need to switch between phone and email devices, maintaining security while improving convenience.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The smartwatch performs self-service authentication by using its own biometric sensor to verify the user and generate OTPs locally without requiring external devices. The watch independently completes the entire authentication process, reducing operational complexity.

Inventive Principle:
Principle #25Self-service

2Reliability

If OTP generation requires accessing a smartphone, then security is maintained through centralized control, but device complexity increases due to inter-device communication requirements

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the OTP generation capability from the smartphone and places it directly in the smartwatch. This extraction reduces the need for complex inter-device communication protocols and simplifies the overall system architecture while maintaining security through local processing.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The smartwatch pre-loads authentication tokens and configurations during initial setup, enabling it to generate OTPs independently without requiring real-time communication with the smartphone. This preliminary preparation reduces operational complexity during actual authentication events.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If biometric authentication is integrated into the smartwatch, then ease of operation is improved through fingerprint scanning, but device complexity increases due to additional hardware requirements

Engineering Contradiction:
Improvebiometric authentication convenienceVSAvoidhardware integration complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The smartwatch uses its existing display and button infrastructure to provide biometric authentication feedback and interaction, making the fingerprint sensor serve multiple functions. This universal use of components minimizes additional hardware complexity while enabling convenient biometric access.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11259181B2Biometric generate of a one-time password (“OTP”) on a smartwatch
Publication Date: 2022.02.22 BANK OF AMERICA CORP
  • US11259181B2 patent drawing
  • US11259181B2 patent drawing
  • US11259181B2 patent drawing

AI summary

One-time password (“OTP”) generation on a smartwatch is provided. OTP generation may include communication between an application on a smartwatch and an application on a smartphone. The request for an OTP may be received at the smartwatch. A biometric identifier may also be received at the smartwatch. The smartwatch application may communicate with the smartphone application. An OTP may be generated within a third-party library within the smartphone application. The generated OTP may be transmitted from the smartphone application to the smartwatch application. The OTP may be displayed on the smartwatch.