Token Terminal Key Code Generation for Secure Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges in setting and updating unique passwords for multiple services, leading to security risks due to password reuse and neglect in updating passwords, which existing authentication systems fail to adequately address.
Innovation Solution
An authentication system that uses a token terminal to securely manage and present a key code for server access, involving a management device and server to register the token terminal, generate a key code based on shared seeds, and verify its consistency for secure sign-in, reducing the need for users to manually manage complex passwords.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users manually manage passwords for multiple services, then they can access each service, but the complexity of password management increases and security risks arise from password reuse
Solution Approach 1:
The patent introduces a password management system that acts as an intermediary between users and multiple services. This system generates, stores, and manages passwords centrally, allowing users to access multiple services without manually handling each password. The intermediary system handles password generation using entropy sources and manages password distribution to various services, thereby improving security while reducing user burden.
Solution Approach 2:
The patent implements self-service mechanisms where the password management system automatically generates passwords using entropy from physical phenomena (radioactive decay, thermal noise), automatically updates passwords across services, and automatically handles password rotation. This eliminates the need for users to manually create, remember, or update passwords for multiple services.
2Ease of operation
If users set the same password for multiple services, then password management becomes easier, but security is compromised when the password is revealed
Solution Approach 1:
The patent segments the password management into two distinct parts: a master secret stored securely by the user and service-specific passwords generated by the system. The master secret is never shared with services, while service passwords are generated deterministically from the master secret and service identifiers. This segmentation ensures that even if one service password is compromised, other services remain secure.
Solution Approach 2:
The patent applies local quality by making each service password unique and tailored to its specific service, while maintaining a uniform secure management approach. Each service receives a password with properties optimized for that service (length, complexity) while all passwords are generated using the same secure entropy-based mechanism, ensuring local adaptability with global security consistency.
3Reliability
If users are required to periodically update passwords, then security is improved, but user convenience deteriorates and users often neglect or simplify passwords
Solution Approach 1:
The patent implements automatic periodic password rotation where the password management system generates new passwords at predetermined intervals and automatically updates them across all services. This periodic action is executed by the system without user intervention, maintaining security through regular updates while eliminating the burden of manual password changes.
Solution Approach 2:
The patent ensures continuous security by implementing ongoing password management where the system continuously monitors, generates, and updates passwords without interruption. The useful action of password security is maintained continuously through automated generation, distribution, and rotation, eliminating gaps where security might be compromised during manual update transitions.
Data Source
AI summary
A management device calculates, from access information transmitted from a token terminal and a site seed assigned to a server, a user seed, and registers the user seed in the token terminal. The token terminal obtains a share seed, calculates a key code from the share seed and the user seed, and presents the key code to the user. When the user enters the key code to an access terminal, the access terminal transmits, to the server, a request having the key code specified. The server obtains access information relating to the transmitted request, calculates a checkup seed from the access information and the site seed assigned to the server, obtains a share seed independently from the token terminal, calculates a checkup code from the share seed and the checkup seed, and sets a necessary condition for sign-in that is consistent between the key code and the checkup code.


