Authentication via Visual Pattern Token Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication methods require users to manually enter usernames and one-time passcodes (OTPs), leading to burdensome and error-prone processes, limited OTP length and entropy, and security vulnerabilities due to the use of a single communication channel.
Innovation Solution
A method using a client device and a mobile device, where the mobile device reads a visual pattern from the client device, generates a token message, and sends it to the server for authentication, eliminating the need for manual OTP entry and utilizing separate communication channels for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If manual OTP entry is required for authentication, then the authentication process can be completed using basic devices, but user burden increases and error rates rise
Solution Approach 1:
The patent replaces the mechanical manual typing process with an automated optical scanning system. The mobile device's camera captures the visual pattern (barcode) displayed on the client device, and the system automatically extracts and transmits the OTP through a token message, eliminating manual entry errors and user burden.
Solution Approach 2:
The system enables self-service authentication where the mobile device automatically performs the authentication process without requiring user intervention for typing. The user simply presents the visual pattern to the mobile device camera, and the system handles OTP extraction, token generation, and server communication automatically.
2Ease of operation
If OTP length is limited to a few characters for ease of entry, then user burden decreases, but OTP entropy and security are reduced
Solution Approach 1:
By replacing manual typing with automated optical scanning and machine reading, the system can handle much longer OTP sequences without increasing user burden. The mobile device camera and processing system can accurately capture and read OTPs of arbitrary length, including those with high entropy and non-alphanumeric characters that would be difficult to type manually.
3Device complexity
If the same device and channel are used for accessing the resource and providing authentication, then the process is simplified, but security weak points are created
Solution Approach 1:
The patent segments the authentication system into distinct components: the client device for resource access, the mobile device for authentication, and the server for verification. This separation creates independent security zones where compromise of one component does not necessarily compromise the entire system, eliminating the single point of failure present in unified systems.
Solution Approach 2:
The mobile device acts as an intermediary authentication component between the client device and server. It generates the token message based on the visual pattern and communicates with the server through a separate channel, creating an intermediate security layer that isolates the authentication process from the resource access channel.
Data Source
AI summary
A technique authenticates a user to server equipment. The technique involves reading, by a mobile device, a visual pattern from a client device, the mobile device and the client device being separate and distinct and in possession of the user. The technique further involves includes generating, by the mobile device, a token message based on the visual pattern. The technique further involves providing, by the mobile device, the token message to the server equipment to authenticate the user to the server equipment.


