Anonymous Authentication via Temporary Transaction Numbers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods require prior user registration and involve the risk of misuse due to pre-distributed TAN lists, limiting their ability to authenticate anonymous users and ensuring security.
Innovation Solution
A method where a central point generates and transmits a temporarily valid transaction number for authentication, allowing anonymous users to authenticate without prior registration, with optional personal identification and variable security levels based on parameters like transaction amount or misuse detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If prior user registration is required for authentication, then security can be maintained through known user lists, but anonymous user authentication becomes impossible
Solution Approach 1:
The patent introduces a central point as an intermediary between the user terminal and acceptance point. This central point generates temporary transaction numbers that enable anonymous users to authenticate without prior registration. The central point mediates the authentication process by verifying transaction numbers and coordinating between the user terminal and acceptance point, thus resolving the contradiction between maintaining security and supporting anonymous users.
2Ease of operation
If TAN lists are made available to users in advance, then user convenience is improved, but security risk increases due to potential misuse
Solution Approach 1:
The patent implements dynamic transaction numbers that are generated temporarily for each authentication session rather than providing static TAN lists in advance. These temporary transaction numbers have limited validity periods and are revoked after use, making them useless for future misuse. This dynamic approach maintains user convenience by providing easy access to authentication credentials while eliminating the security risk associated with pre-distributed TAN lists.
Solution Approach 2:
The patent uses temporary transaction numbers that are short-lived and disposable, valid only for a single authentication session or limited time period. After use or expiration, these transaction numbers become invalid, preventing any potential misuse. This approach allows users to have convenient access to authentication credentials without the long-term security risks of reusable TAN lists.
3Ease of operation
If permanently valid transaction numbers are provided in advance, then authentication ease is improved, but security is compromised due to potential theft and misuse
Solution Approach 1:
The patent replaces static, permanently valid transaction numbers with dynamic, temporary transaction numbers that are generated for each authentication session. These temporary numbers automatically expire after use or after a short time period, making them ineffective for theft or misuse. This dynamic approach maintains authentication ease for legitimate users while significantly improving security by rendering stolen credentials useless.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method for authentication of a user (1) to an acceptance point (3), the authentication being performed by comparing a transaction number (TrxlD) with a computed or stored transaction number (TrxlD), wherein the acceptance point (3) and/or a user terminal (2) sends a request message to a central point (4) and the central point (4) provides and transmits a temporarily valid transaction number (TrxlD) by means of which authentication of the user (1) to the acceptance point (3) can be performed, or that the acceptance point (3) provides a temporarily valid transaction number (TrxlD) by means of which authentication of the user (1) to a central point (4) can be performed, an authorization after successful authentication to the central point (4) being performed by the generation and transmission of an authorization message from the central point (4) to the acceptance point (3).