Virtual Authorization Code for Secure Procedure Approval

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing OTP authentication methods require users to log in every time, leading to inconvenience and security vulnerabilities, especially in non-face-to-face financial transactions where authorization processes need to be repeated, causing user fatigue and potential illegal use of accounts.

Innovation Solution

A method and apparatus for approving procedures using a virtual authorization code generated by a user terminal, which is then verified by a server to authenticate the user and approve the procedure without the need for repeated login processes, ensuring security through unique codes generated at specific time intervals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If OTP authentication is performed by generating a one-time password each time a user logs in, then security is improved, but user convenience deteriorates due to repeated login requirements

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication by storing authentication information (device ID, timestamp, random number) when the user first accesses the system. This preliminary action creates a basis for subsequent authentication without requiring repeated logins, resolving the contradiction between security and convenience

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a virtual authorization code that copies essential authentication elements (device identification, timestamp, random number) into a structured format. This virtual code serves as a substitute for repeated login credentials, maintaining security while improving user convenience

Inventive Principle:
Principle #26Copying

2Productivity

If a deputy is authorized to open a corporation account through non face-to-face verification, then operational efficiency is improved, but security risk increases due to potential forgery and illegal use

Engineering Contradiction:
Improveoperational efficiencyVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system introduces a virtual authorization code as an intermediary that mediates between the deputy and the account opening process. This intermediary contains embedded authentication information that verifies the deputy's authority without requiring physical presence, thus improving operational efficiency while maintaining security through verifiable authentication data

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces the mechanical process of physical seal assignment and document signing with an electronic virtual authorization code system. This substitution eliminates the risks associated with physical document forgery while maintaining the authorization function, thereby improving both efficiency and security

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If authorization processes are repeated for each financial transaction, then security control is improved, but user fatigue increases due to multiple authentication steps

Engineering Contradiction:
Improvesecurity controlVSAvoiduser fatigue
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The virtual authorization code is designed with universal applicability, containing authentication information that can be used across multiple financial transactions. This multi-functional code eliminates the need for separate authentication processes for each transaction, reducing user fatigue while maintaining security control through the persistent valid authentication data

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250193016A1Device and method for virtual authentication code-based process authorization
Publication Date: 2025.06.12 SSENSTONE INC
  • US20250193016A1 patent drawing
  • US20250193016A1 patent drawing
  • US20250193016A1 patent drawing

AI summary

Provided are procedure approval method and system based on a virtual authorization code. The method is executed by a server, and includes receiving, by the server, a virtual authorization code and a request for procedure approval, searching for, by the server, a storage location of user authentication information of a user in a storage location search algorithm, based on the virtual authorization code, extracting, by the server, user authentication information stored in the storage location and authenticating the user based on the user authentication information, and approving the procedure when the user authentication is finished.