Mobile Authentication via SMS One-Time Passwords
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for secure network access rely heavily on hardware tokens, which are costly, difficult to track, and can be lost or stolen, necessitating a more secure and cost-effective alternative that utilizes a device users already possess.
Innovation Solution
A system and method for authenticating users using their mobile communication devices, such as mobile phones, through SMS messages, email, or voice calls, eliminating the need for hardware tokens by generating and delivering one-time passwords (OTPs) without requiring internet access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware tokens are distributed to each user for authentication, then authentication security is improved, but cost and device tracking difficulty increase
Solution Approach 1:
The patent combines multiple authentication factors (something you know - password, something you have - mobile device, something you are - biometric data) into a unified authentication system. The mobile device serves as both the authentication token and the communication medium, merging the functions of hardware tokens with user-possessed devices they already carry.
Solution Approach 2:
The mobile device performs multiple functions: it serves as the authentication token, the communication channel for receiving OTPs, and the device users already possess and protect. This multi-functionality eliminates the need for separate hardware tokens while maintaining security.
2Reliability
If hardware tokens are used for authentication, then authentication reliability is improved, but cost-effectiveness deteriorates
Solution Approach 1:
Users leverage their own mobile devices for authentication purposes, eliminating the need for the organization to purchase and distribute hardware tokens. The authentication system serves itself by utilizing infrastructure (mobile networks, email servers) that already exists and is widely accessible.
Solution Approach 2:
The system uses inexpensive mobile devices that users already possess rather than expensive hardware tokens. The OTPs are short-lived (time-sensitive), providing security without requiring expensive physical tokens.
3Adaptability or versatility
If hardware tokens are distributed to users, then authentication capability is improved, but security risks from loss or theft increase
Solution Approach 1:
The authentication system is dynamic and adaptable - it can switch between different authentication methods (SMS, email, voice calls) and can be deactivated immediately if a mobile device is reported lost or stolen. The system responds to changing conditions rather than relying on static hardware tokens.
Solution Approach 2:
The system provides feedback mechanisms including loss reporting procedures where users can notify the system of lost or stolen devices. The system then responds by deactivating authentication capabilities for those devices, providing real-time security response to potential threats.
4Ease of operation
If traditional authentication methods are used, then implementation simplicity is maintained, but network resource consumption increases
Solution Approach 1:
The system uses periodic authentication challenges where OTPs are generated and delivered only when needed (during login attempts) rather than continuously. This reduces network resource consumption while maintaining security through time-sensitive codes.
Data Source
AI summary
The invention is a system and method for registering and authenticating a user using a mobile communication device, such as a mobile phone. An authentication server has access to a stored list of authorized mobile phone numbers. Each authorized mobile phone number is associated with a string of text or numeric characters. The server provides a OTP when the user calls or sends a SMS message request from the authorized mobile phone to the server. The verbal or SMS request must contain the stored string, which the server will match against the stored list in order to confirm that the mobile phone is authorized. Once a OTP is provided to the authorized mobile phone, it must be used within a predetermined time limit, or the OTP will expire. The OTP will also be discarded once the server is notified that the OTP has been used. Further, the server will ignore a request for an additional OTP if a previously-provided OTP has not expired or been discarded, or if the server is in the process of generating an OTP for the authorized mobile phone.


