Time-Based Password Update Cycle Adjustment for Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional TOTP user authentication methods rely on short update cycles (e.g., 30 seconds or 60 seconds) for security, which can be inconvenient for users and may not adapt to changing environments, and they do not allow for secure reuse of passwords across sessions.
Innovation Solution
A user authentication method that uses a time-based password (TP) with a longer update cycle (e.g., 1 week, 30 days, or more) synchronized between a security token and an authentication system, allowing the update cycle to adjust based on the user's environment, enabling secure authentication with reduced frequency of password entry.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If TOTP uses short update cycles (30 seconds or 60 seconds) for security, then security level is improved, but user convenience deteriorates due to frequent password entry
Solution Approach 1:
The patent applies dynamics by making the password update cycle adjustable rather than fixed. The authentication system can dynamically set different update cycles (e.g., 1 week, 30 days, or more) based on security requirements and user behavior, resolving the contradiction between short cycles for security and long cycles for convenience
Solution Approach 2:
The invention changes the parameter of password update cycle from fixed short intervals (30-60 seconds) to variable long intervals (1 week to months). This parameter change allows the system to maintain security while reducing the frequency of password entry, directly addressing the contradiction between security and user convenience
2Ease of operation
If TOTP update cycle is extended to long cycle (1 month or more) for convenience, then user convenience is improved, but security risk increases
Solution Approach 1:
The system dynamically adjusts the password update cycle based on multiple factors including security policies, user behavior patterns, and risk assessment. This dynamic adjustment allows long update cycles for convenience while maintaining security through conditional overrides and monitoring
Solution Approach 2:
The authentication system incorporates feedback mechanisms that monitor user behavior and security events. Based on this feedback, the system can adjust the password update cycle in real-time, extending it for convenience when risk is low and shortening it when security concerns arise, thus resolving the contradiction
3Ease of operation
If browser retains login information for automatic entry, then ease of operation is improved, but security control is reduced
Solution Approach 1:
The patent introduces the authentication system as an intermediary between the browser's login information retention and the actual authentication process. The system mediates by controlling which information is retained, for how long, and under what conditions, thus enabling automatic entry while maintaining security control through centralized policy enforcement
Data Source
AI summary
There is proposed a user authentication method that uses a time-based password (TP) having a relatively long update cycle instead of a TOTP having a conventional short update cycle (e.g., 60 seconds). The present invention is a user authentication method executed by an authentication system that performs authentication of a user who performs access from an information communication terminal device in order to use a usage target system by using a reference terminal device that includes a security token capable of generating a TP. The authentication method includes setting an update cycle of the TP to a first update cycle of 30 days, 1 month, or a time period longer than 1 month, receiving a user authentication request that includes a time-based password generated by the security token according to the set first update cycle, and performing the authentication based on the TP contained in the received user authentication request.


