Two-Factor Authentication via Visual Code Capture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional two-factor authentication methods are vulnerable to SIM card substitution attacks and require additional applications on user devices, leading to inefficiencies in computing resources and user experience.

Innovation Solution

A system that allows users to authenticate via a web interface using a conventional computer and an app on their device, where the app signals the server with a PIN calculated from the device identifier and date/time, eliminating the need for a dedicated app and reducing computational resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional two factor authentication is used with text or phone calls, then additional security is provided, but it requires users to manually copy and enter codes, causing additional computing resources to be used when codes are mistyped

Engineering Contradiction:
Improveauthentication securityVSAvoidcomputing resource efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces the manual copying and typing of authentication codes with an automated optical recognition system. The mobile device captures an image of the code displayed on the server screen, and optical character recognition (OCR) technology automatically extracts and transmits the code to the server, eliminating manual input errors and reducing computing resources wasted on handling mistyped codes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If dedicated authentication applications are installed on mobile devices, then two factor authentication can be implemented, but it takes additional memory space and requires separate application installation

Engineering Contradiction:
Improveauthentication securityVSAvoidapplication installation requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the mobile device's camera and existing messaging capabilities serve the dual purpose of both photography/communication and authentication. The device's camera captures the authentication code, and the device's existing SMS or messaging functionality transmits the code to the server, eliminating the need for a dedicated authentication application and reducing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If SIM card substitution attacks are prevented, then account security is improved, but conventional two factor authentication methods remain vulnerable to such attacks

Engineering Contradiction:
Improveaccount securityVSAvoidSIM card substitution vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary visual display mechanism where the authentication code is shown on the server's screen rather than being sent directly to the user's mobile device. The user visually observes the code on the server display and captures it with their mobile device camera, creating a trusted visual intermediary that prevents SIM card substitution attacks since the code never traverses through potentially compromised communication channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11323434B1System and method for secure two factor authentication
Publication Date: 2022.05.03 CHARLES SCHWAB & CO INC
  • US11323434B1 patent drawing
  • US11323434B1 patent drawing
  • US11323434B1 patent drawing

AI summary

A system and method allows an app to be used to signal a server to authenticate a user using two factor authentication. The app is one previously associated with a user account, optionally using a different form of two factor authentication.