Virtual Machine Dynamic Password Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing online transactions, such as static passwords, dynamic passwords, and USB keys, are vulnerable to interception and attacks, and require additional software for TPM chips, leading to security risks and inconvenience.

Innovation Solution

A computer system with a virtual platform hosting multiple guest operating systems, where one OS generates dynamic security information using a HASH algorithm, isolated from the service application OS, enabling secure authentication with bidirectional verification between client and server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If static password is used for authentication, then ease of operation is improved, but security is worsened due to susceptibility to guessing and interception

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies dynamics by transitioning from static passwords to dynamic passwords that change over time based on a varying parameter (time or event). The password generation module continuously generates new passwords according to an encryption algorithm, making the authentication credential dynamic rather than fixed, thereby improving security while maintaining ease of operation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies parameter changes by introducing a varying parameter (time or event) into the password generation process. The password is generated as a function of this varying parameter, causing the password to change ceaselessly and non-repeatedly, which prevents guessing and interception while keeping the authentication process simple for users.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If dynamic password is used for authentication, then security is improved, but vulnerability to intermediary attacks and unidirectional authentication occurs

Engineering Contradiction:
ImprovesecurityVSAvoidintermediary attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies feedback by implementing bidirectional authentication where both the client and server verify each other's identities. The server authenticates the client using the dynamic password, and simultaneously the client authenticates the server's identity, creating a feedback loop that prevents intermediary attacks and ensures mutual trust.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies intermediary by using the dynamic password generation module as a trusted mediator that both the client and server rely on for authentication. The module serves as an independent security component that generates passwords according to a shared encryption algorithm, acting as a neutral intermediary that neither party can compromise alone.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If USB KEY with certificate is used for authentication, then security is improved, but device complexity and cost increase due to multiple hardware requirements

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies merging by combining the password generation functionality directly into the operating system's virtual machine platform rather than requiring separate USB KEY hardware. The dynamic password generation module is integrated into the virtual machine monitor, merging authentication security with the existing system infrastructure, thereby reducing device complexity and cost while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent applies universality by designing a virtual machine-based authentication system that can serve multiple applications and operating systems simultaneously. The dynamic password generation module in the virtual machine platform provides universal authentication security for various clients and servers, replacing the need for application-specific USB KEYs and certificates.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If TPM chip is used for data encryption, then security is improved, but cost increases due to required software components

Engineering Contradiction:
ImprovesecurityVSAvoidsoftware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling the virtual machine platform to generate and manage its own dynamic passwords independently without requiring external TPM chips or additional software components. The virtual machine monitor itself performs the security function, making the system self-sufficient for authentication while reducing overall complexity and cost.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8261086B2Computer and method for sending security information for authentication
Publication Date: 2012.09.04 LENOVO SOFTWARE
  • US8261086B2 patent drawing
  • US8261086B2 patent drawing
  • US8261086B2 patent drawing

AI summary

The present invention provides a computer and a method of sending security information for authentication, which relate to transmission of data information in computers. The present invention solves the vulnerability of information when a user conducts network transaction activities by a terminal. The computer of the present invention comprises: a virtual system platform; a first guest operating system installed on the virtual system platform, which is for installing a service application module, wherein the service application module generates a security information input interface when it is being executed; a second guest operating system installed on the virtual system platform; the second guest operating system comprises: a dynamic password generation module for generating security information, the security information is input into the security information input interface and is sent to a network server for authentication. The security of network activities conducted by users can be enhanced.