Next-time Password Authentication via SMS Delivery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current two-factor authentication methods, such as one-time password tokens, are expensive, inconvenient, and pose challenges in security and distribution, while credential theft remains a significant threat in electronic commerce, particularly through phishing and fraud.

Innovation Solution

A next-time password system that sends a unique, one-time password to a user's registered cell phone or email address, eliminating the need for physical tokens and allowing access only once, with optional expiry times, and a secure transaction code system requiring additional authentication for sensitive transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If one-time password tokens are used for two-factor authentication, then security against credential theft is improved, but device cost and complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces physical one-time password tokens with a digital copy delivered via SMS message to the user's mobile phone. The authentication code is transmitted as text rather than requiring a physical device, thereby maintaining security while eliminating the need for costly hardware tokens and reducing device complexity

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent substitutes the mechanical/physical token system with an electronic communication system. Instead of relying on physical devices that generate and display codes, the system uses SMS messaging infrastructure to deliver authentication codes digitally, reducing hardware dependencies and overall system complexity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If physical one-time password tokens are distributed to users, then authentication security is improved, but distribution cost and security challenges increase

Engineering Contradiction:
Improveauthentication securityVSAvoiddistribution
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The authentication codes are copied and transmitted digitally via SMS messages rather than being physically manufactured and distributed as tokens. This eliminates production costs, shipping expenses, and the security risks associated with physical token distribution while maintaining authentication security

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent extracts the authentication code generation and delivery function from the physical token device and relocates it to the mobile messaging infrastructure. This separates the security function from hardware requirements, simplifying distribution to any user with a mobile phone capable of receiving SMS messages

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If users carry multiple physical tokens for different banks, then multi-institution authentication is enabled, but user convenience deteriorates

Engineering Contradiction:
Improvemulti-institution authenticationVSAvoiduser convenience
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent creates a universal authentication system where a single mobile phone can receive authentication codes for multiple financial institutions. The SMS-based delivery mechanism works across different banks and services, eliminating the need for users to carry multiple institution-specific tokens while maintaining the ability to authenticate with various providers

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If one-time password tokens are used, then credential theft risk is reduced, but token replacement cost and complexity increase when tokens expire

Engineering Contradiction:
Improvecredential theft protectionVSAvoidtoken replacement
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent replaces expired or compromised authentication codes with new codes delivered via SMS without requiring physical token replacement. The system can issue new authentication codes digitally, eliminating the cost and complexity of manufacturing and distributing replacement physical tokens while maintaining credential theft protection

Inventive Principle:
Principle #26Copying

Data Source

PatentEP1755062B1Methods and systems for secure user authentication
Publication Date: 2016.09.28 CITICORP CREDIT SERVICES INC (USA)
  • EP1755062B1 patent drawingFigure 1
  • EP1755062B1 patent drawingFigure 2
  • EP1755062B1 patent drawingFigure 3

AI summary

A computer-implemented method and system for secure user authentication in electronic commerce involves maintaining electronic information having a first aspect that is accessible over a first electronic communication channel in response to entry of a first credential known to the user and a second aspect that is accessible by the user over the first electronic communication channel in response to entry of a second credential provided to the user at a pre-registered delivery address on a second electronic communication channel. The second credential is provided to the user via the second electronic communication channel in response to entry of a pre-determined user selection during a current session of user access to the first aspect if no change has occurred in the pre-registered delivery address within a pre-determined period of time, and the user is allowed a session of access to the second aspect in response to entry of the second credential either during the current session of user access to the first aspect or during a succeeding session of user access to the first aspect.