Next-time Password Authentication via SMS Delivery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current two-factor authentication methods, such as one-time password tokens, are expensive, inconvenient, and pose challenges in security and distribution, while credential theft remains a significant threat in electronic commerce, particularly through phishing and fraud.
Innovation Solution
A next-time password system that sends a unique, one-time password to a user's registered cell phone or email address, eliminating the need for physical tokens and allowing access only once, with optional expiry times, and a secure transaction code system requiring additional authentication for sensitive transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If one-time password tokens are used for two-factor authentication, then security against credential theft is improved, but device cost and complexity increase
Solution Approach 1:
The patent replaces physical one-time password tokens with a digital copy delivered via SMS message to the user's mobile phone. The authentication code is transmitted as text rather than requiring a physical device, thereby maintaining security while eliminating the need for costly hardware tokens and reducing device complexity
Solution Approach 2:
The patent substitutes the mechanical/physical token system with an electronic communication system. Instead of relying on physical devices that generate and display codes, the system uses SMS messaging infrastructure to deliver authentication codes digitally, reducing hardware dependencies and overall system complexity
2Reliability
If physical one-time password tokens are distributed to users, then authentication security is improved, but distribution cost and security challenges increase
Solution Approach 1:
The authentication codes are copied and transmitted digitally via SMS messages rather than being physically manufactured and distributed as tokens. This eliminates production costs, shipping expenses, and the security risks associated with physical token distribution while maintaining authentication security
Solution Approach 2:
The patent extracts the authentication code generation and delivery function from the physical token device and relocates it to the mobile messaging infrastructure. This separates the security function from hardware requirements, simplifying distribution to any user with a mobile phone capable of receiving SMS messages
3Adaptability or versatility
If users carry multiple physical tokens for different banks, then multi-institution authentication is enabled, but user convenience deteriorates
Solution Approach 1:
The patent creates a universal authentication system where a single mobile phone can receive authentication codes for multiple financial institutions. The SMS-based delivery mechanism works across different banks and services, eliminating the need for users to carry multiple institution-specific tokens while maintaining the ability to authenticate with various providers
4Reliability
If one-time password tokens are used, then credential theft risk is reduced, but token replacement cost and complexity increase when tokens expire
Solution Approach 1:
The patent replaces expired or compromised authentication codes with new codes delivered via SMS without requiring physical token replacement. The system can issue new authentication codes digitally, eliminating the cost and complexity of manufacturing and distributing replacement physical tokens while maintaining credential theft protection
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A computer-implemented method and system for secure user authentication in electronic commerce involves maintaining electronic information having a first aspect that is accessible over a first electronic communication channel in response to entry of a first credential known to the user and a second aspect that is accessible by the user over the first electronic communication channel in response to entry of a second credential provided to the user at a pre-registered delivery address on a second electronic communication channel. The second credential is provided to the user via the second electronic communication channel in response to entry of a pre-determined user selection during a current session of user access to the first aspect if no change has occurred in the pre-registered delivery address within a pre-determined period of time, and the user is allowed a session of access to the second aspect in response to entry of the second credential either during the current session of user access to the first aspect or during a succeeding session of user access to the first aspect.