Dynamic Alias Generation for Secure Mobile Payments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing bar code-enabled mobile payment systems lack security, making them unsuitable for high-risk transactions involving financial accounts, as bar codes can be easily copied and used without the owner's permission, leading to potential losses.
Innovation Solution
The method involves generating and using alias information associated with a payment account, displayed on a mobile device, which is unique for each transaction, and updating it after a transaction is processed, ensuring that used alias information cannot be reused for future purchases, thereby enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If bar codes are used for mobile payments, then ease of operation is improved, but security is worsened
Solution Approach 1:
The patent implements dynamic alias information that changes with each transaction. Instead of using static bar codes, the system generates unique alias identifiers for each payment transaction, making the payment token dynamic and time-sensitive. This resolves the security issue while maintaining ease of operation through automated generation and updating of aliases.
Solution Approach 2:
The system changes the parameter of the payment identifier from static to dynamic by generating unique alias information for each transaction. The alias includes transaction-specific parameters such as transaction ID, timestamp, and random elements, transforming the payment token into a one-time use credential that maintains operational simplicity while enhancing security.
2Reliability
If unique alias information is generated for each transaction, then security is improved, but device complexity is worsened
Solution Approach 1:
The mobile device automatically generates, stores, and updates alias information without requiring user intervention. The system self-manages the complexity of generating unique identifiers, tracking used aliases, and updating the display, while the user simply presents the displayed alias for payment. This hides the complexity from the user while maintaining security.
Solution Approach 2:
The patent introduces an intermediary processing system that handles the generation and validation of alias information. The mobile device displays the alias, and the payment terminal or processing system verifies its uniqueness and validity, distributing the complexity across multiple components rather than concentrating it in the mobile device alone.
3Ease of operation
If bar codes are easily copied, then ease of operation is improved, but loss prevention is worsened
Solution Approach 1:
The system takes preliminary anti-action by generating unique, one-time use alias information before each transaction. This prevents copying and unauthorized use because each alias is designed to be used only once and then invalidated. The preliminary generation of unique aliases counteracts the potential harm of copying by making copied aliases useless for future transactions.
Solution Approach 2:
The patent treats each alias as a disposable, short-living payment token. Each alias is generated for a single transaction and then discarded or marked as used. This approach makes copying ineffective because the alias becomes worthless after one use, similar to a disposable payment method that cannot be reused or copied for future transactions.
Data Source
AI summary
Systems and methods are provided that enable purchase and adjustment transactions using a visual indicium displayed on a mobile device. In some embodiments, these indicia are in the form of bar codes, include alias information, and do not include an account number associated with a payment account. A mobile device receives first user input, displays the indicium to a merchant device. The merchant device scans the indicium and sends a transaction request including the alias information to a payment network. The payment network determines an appropriate financial institution for processing the transaction, and sends the transaction request to the appropriate financial institution. Based on the result, the payment network sends an approval to the merchant device. Additionally, a mobile processor system sends new alias information to the mobile device for use in a next transaction.


