Software Authentication Using Dynamic Keys and Turing Tests

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods, especially for connected tokens, face vulnerabilities such as malware attacks and the inability to protect confidentiality, leading to reduced security and high costs associated with hardware-based multi-factor authentication solutions.

Innovation Solution

A software-based authentication method using a computer with a processor and memory to calculate non-invertible functions based on unique identifiers, dynamic secret keys, and user input, ensuring authentication through a combination of device-specific and user-specific data, without relying on hardware devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-based multi-factor authentication is used, then security level is greatly increased, but cost and complexity of implementation increase significantly

Engineering Contradiction:
Improvesecurity levelVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces hardware-based authentication mechanisms with a software-based solution that uses cryptographic functions and dynamic key generation. The authentication system substitutes physical hardware tokens with software implementations that generate one-time passwords through cryptographic operations, eliminating the need for specialized hardware devices while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the parameter of key dynamics from static hardware-stored keys to dynamically generated keys that change with each authentication session. The system uses non-invertible functions with multiple inputs (challenge, secret key, device-specific data, Turing test results) to generate different authentication values, making each authentication instance unique and preventing replay attacks.

Inventive Principle:
Principle #35Parameter changes

2Ease of manufacture

If fully software-based multi-factor authentication is used, then cost and ease of implementation improve, but security level decreases to similar to simple password

Engineering Contradiction:
Improveease of implementationVSAvoidsecurity level
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent segments the authentication process into multiple independent components: device identification, challenge-response verification, Turing test execution, and one-time password generation. Each component contributes a specific element to the final authentication decision, creating a multi-factor system where compromise of one element does not lead to complete system failure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a composite authentication mechanism that combines multiple different types of verification: device-specific identifiers, cryptographic key pairs, challenge-response protocols, Turing test results, and dynamic one-time passwords. This composite approach integrates diverse security measures into a unified software-based authentication system that achieves hardware-level security without the hardware requirements.

Inventive Principle:
Principle #40Composite materials

3Reliability

If dynamic passwords are sent via SMS or callback systems, then authentication security improves, but vulnerability to malware and social attacks increases

Engineering Contradiction:
Improveauthentication securityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary layer of cryptographic computation and Turing test verification between the user and the authentication system. Instead of directly transmitting passwords through vulnerable communication channels like SMS, the system uses the computer's processing capabilities to generate authentication values through non-invertible functions, with the Turing test acting as an intermediary verification step that prevents automated malware attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent converts the potential harm of software-based authentication into a benefit by using the computer's existing processing capabilities and built-in security features. The system turns the computer's ability to execute complex cryptographic operations into a security advantage, and uses the Turing test to convert the potential vulnerability of software execution into a benefit by verifying user presence and preventing automated attacks.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentEP3022867B1Strong authentication method
Publication Date: 2020.03.11 IN WEBO TECH
  • EP3022867B1 patent drawingFigure 1~2

AI summary

The present invention relates to a method of authenticating, with an authentication server, a user having at his disposal a calculator storing at least one unique identifier specific to the calculator and one first secret key (KO) and calculating a non-invertible function (H); the method comprising: • reception of the unique identifier by the authentication server, which sends an item of information (challenge) and an action code; • reception by the authentication server of three results of the non-invertible function, • the first result (R0) depending on at least one item of data specific to a unique or quasi-unique element of the calculator (SN); • the second result (RT) depending on a Turing test, conditioned to the action code, carried out by the user; and • the third result (R1) depending on a second secret key (K1); • authentication of the user if all four of the unique identifier and the first, second and third results are valid.