Bilaterally Generated Variable Instant Passwords for Secure Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems face challenges such as security deficiencies with static passwords, complexity and computational intensity in dynamic password systems, and high costs associated with biometric authentication, as well as the need for ongoing authentication and secure transaction mechanisms.

Innovation Solution

A Bilaterally Generated Variable Instant Password System that uses a Variable Character Set to generate computationally non-intensive encryption keys linked to user identity for secure and flexible authentication, enabling ongoing authentication and secure transactions without the need for memorized pins or biometric data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If static passwords are used for authentication, then the system is simple and widely compatible, but security is compromised because passwords do not change between transactions

Engineering Contradiction:
Improveauthentication system complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements dynamic passwords that automatically generate new authentication codes for each transaction. The system transitions from static to dynamic password generation, where passwords change with each use, eliminating the security vulnerability of reusable static passwords while maintaining system simplicity through automated generation processes

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication system performs self-service by automatically generating and managing dynamic passwords without requiring external encryption systems or third-party authentication services. The system autonomously handles password creation, validation, and rotation, reducing complexity while improving security

Inventive Principle:
Principle #25Self-service

2Reliability

If dynamic password systems are implemented, then security is improved through changing passwords, but the system becomes computationally intensive and complex

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the computationally intensive encryption and authentication functions from the user's device and relocates them to the service provider's server. The user's authentication device only needs to generate and transmit passwords, while the server handles the complex validation and encryption operations, reducing client-side complexity

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The service provider's authentication server acts as an intermediary between the user and the security protocol. The server mediates the authentication process by receiving passwords, performing computational validation, and managing the dynamic password generation algorithms, thereby reducing the computational burden on user devices

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If dynamic password systems are used, then security is improved, but memorization and algorithm knowledge are required making the system difficult to use

Engineering Contradiction:
ImprovesecurityVSAvoiduser friendliness
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication device automatically generates dynamic passwords without requiring user memorization or manual algorithm execution. The system performs self-service by autonomously creating and managing password sequences, eliminating the need for users to remember complex algorithms or patterns

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual password generation methods (requiring user memorization and algorithm execution) with automated electronic generation. The mechanical process of manual password creation is substituted with electronic automation, where the device generates passwords programmatically without user intervention in the generation process

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If third-party authentication systems are deployed, then security is improved, but costs increase due to external services and hardware devices

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements a universal authentication system where the service provider's server performs multiple functions: authentication, encryption, key management, and password generation. This multi-functional approach eliminates the need for separate third-party authentication services and specialized hardware devices, reducing overall system cost while maintaining security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges authentication and encryption functions into a single integrated system operated by the service provider. By combining these security functions rather than using separate third-party systems, the organization reduces costs associated with multiple external services and hardware devices while maintaining comprehensive security

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10313334B2System and method of generating and using bilaterally generated variable instant passwords
Publication Date: 2019.06.04 ABDUL HAMEED KHAN ABDUL RAHMAN SYED IBRAHIM
  • US10313334B2 patent drawing
  • US10313334B2 patent drawing
  • US10313334B2 patent drawing

AI summary

Implementations of a system and method of generating and using bilaterally generated variable instant passwords are disclosed. The system is used to secure electronic transactions (e.g., an auction in which one or more bidders are unknown to the auctioneer). In this system an Internet Service Provider (ISP), on request from a USER (e.g., a bidder), facilitates an authentication process with a SERVICE PROVIDER (e.g., an auctioneer). The SERVICE PROVIDER may send a sub-folder, containing a USER name, a temporary sub variable character set, and a CALL, to the USER through the ISP. The password used to access the sub-folder is transmitted directly to the USER by the SERVICE PROVIDER. The USER gets authenticated to the SERVICE PROVIDER by using the USER name, the temporary sub variable character set, and the CALL retrieved from the sub-folder. After USER's authentication, further transactions (e.g., bids) are performed using a password for each transaction.