Anonymous Transaction Authentication via One-Time Password Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for online transactions lack an anonymous payment option for both large and small amounts, as current solutions require revealing identity for credit account allocation and have high transaction fees, making small anonymous payments inconvenient.

Innovation Solution

A method involving an authentication server as a link between a secure element, a payment device, and a service device, using one-time passwords (OTPs) encrypted with a one-way function to facilitate anonymous transactions, allowing secure and anonymous payment of any amount without permanent storage of OTPs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a credit account is opened with the service for fee-based services, then secure allocation between credit account and user is possible, but user identity must be revealed

Engineering Contradiction:
Improvesecure allocationVSAvoiduser identity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces an authentication service provider as an intermediary between the user and the service. This mediator handles authentication and account management, allowing the service to securely allocate credits without directly accessing or storing user identity information. The authentication service provider acts as a buffer that preserves user anonymity while enabling reliable credit allocation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If anonymous payment method with credit card is used, then user identity remains protected, but minimum payment amount is required and user must enter PIN

Engineering Contradiction:
Improveuser identityVSAvoidpayment convenience
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent segments the payment process into multiple components: authentication via OTP, credit allocation by the authentication service provider, and service delivery. This segmentation eliminates the need for users to directly handle credit cards or enter PINs for each transaction. Instead, users receive service credentials that automatically handle payment, making the process more convenient while maintaining anonymity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements self-service through automated OTP generation and validation. The authentication service provider automatically generates one-time passwords, validates them against stored hashes, and processes credit allocations without requiring user intervention beyond initial authentication. This eliminates the manual PIN entry requirement while preserving anonymous payment capabilities.

Inventive Principle:
Principle #25Self-service

3Ease of manufacture

If authentication service provider is used, then service no longer needs to take care of security requirements, but system complexity increases

Engineering Contradiction:
Improvesecurity managementVSAvoidsystem structure
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The authentication service provider serves as a specialized intermediary that assumes all security responsibilities. It manages user credentials, generates OTPs, stores hashed passwords, and handles authentication logic. By concentrating security functions in this dedicated intermediary, the overall system complexity is managed more effectively, as the service provider handles complex security requirements through standardized protocols and procedures.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10839380B2Transaction process
Publication Date: 2020.11.17 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • US10839380B2 patent drawing
  • US10839380B2 patent drawing

AI summary

A method for anonymously carrying out a transaction, wherein one-time passwords encrypted by means of a one-way function are sent by an authentication server to a service device. The non-encrypted one-time passwords are sent by the authentication server to a secure element of a mobile device. In order for a transaction to be effected, the secure element sends the one-time passwords to the service device.