Time-Based Password Update Cycle Adjustment for Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional TOTP user authentication methods rely on short update cycles (e.g., 30 seconds or 60 seconds) for security, which can be inconvenient for users and may not adapt to changing environments, and they do not allow for secure reuse of passwords across sessions.

Innovation Solution

A user authentication method that uses a time-based password (TP) with a longer update cycle (e.g., 1 week, 30 days, or more) synchronized between a security token and an authentication system, allowing the update cycle to adjust based on the user's environment, enabling secure authentication with reduced frequency of password entry.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If TOTP uses short update cycles (30 seconds or 60 seconds) for security, then security level is improved, but user convenience deteriorates due to frequent password entry

Engineering Contradiction:
Improvesecurity levelVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies dynamics by making the password update cycle adjustable rather than fixed. The authentication system can dynamically set different update cycles (e.g., 1 week, 30 days, or more) based on security requirements and user behavior, resolving the contradiction between short cycles for security and long cycles for convenience

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention changes the parameter of password update cycle from fixed short intervals (30-60 seconds) to variable long intervals (1 week to months). This parameter change allows the system to maintain security while reducing the frequency of password entry, directly addressing the contradiction between security and user convenience

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If TOTP update cycle is extended to long cycle (1 month or more) for convenience, then user convenience is improved, but security risk increases

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system dynamically adjusts the password update cycle based on multiple factors including security policies, user behavior patterns, and risk assessment. This dynamic adjustment allows long update cycles for convenience while maintaining security through conditional overrides and monitoring

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication system incorporates feedback mechanisms that monitor user behavior and security events. Based on this feedback, the system can adjust the password update cycle in real-time, extending it for convenience when risk is low and shortening it when security concerns arise, thus resolving the contradiction

Inventive Principle:
Principle #23Feedback

3Ease of operation

If browser retains login information for automatic entry, then ease of operation is improved, but security control is reduced

Engineering Contradiction:
Improveease of operationVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces the authentication system as an intermediary between the browser's login information retention and the actual authentication process. The system mediates by controlling which information is retained, for how long, and under what conditions, thus enabling automatic entry while maintaining security control through centralized policy enforcement

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10592646B2User authentication method and system for implementing the same
Publication Date: 2020.03.17 PASSLOGY CO LTD
  • US10592646B2 patent drawing
  • US10592646B2 patent drawing
  • US10592646B2 patent drawing

AI summary

There is proposed a user authentication method that uses a time-based password (TP) having a relatively long update cycle instead of a TOTP having a conventional short update cycle (e.g., 60 seconds). The present invention is a user authentication method executed by an authentication system that performs authentication of a user who performs access from an information communication terminal device in order to use a usage target system by using a reference terminal device that includes a security token capable of generating a TP. The authentication method includes setting an update cycle of the TP to a first update cycle of 30 days, 1 month, or a time period longer than 1 month, receiving a user authentication request that includes a time-based password generated by the security token according to the set first update cycle, and performing the authentication based on the TP contained in the received user authentication request.