Dynamic Single-Use Authentication Code for Mobile Payment Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Payment cards with cryptographic keys in magnetic stripes are vulnerable to unauthorized capture, allowing nefarious users to withdraw funds before unauthorized activity is detected, compromising both the payment account and the card.
Innovation Solution
A system that generates and uses a single-use authentication code associated with a mobile device to authenticate transactions at a point of sale, enabling secure funds adjustments to a payment account through a communications network, reducing the risk of fraud by providing dynamic funding authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a cryptographic key is included in a magnetic stripe of the payment card, then the card can be used to authenticate payment at a point of sale, but the information in the magnetic stripe may be subject to unauthorized capture, compromising the payment account and the card
Solution Approach 1:
The patent transitions from static magnetic stripe data to dynamic authentication codes that change with each transaction. The authentication code is generated based on transaction-specific parameters and is valid only for a single use, making the authentication mechanism dynamic rather than static, thereby preventing unauthorized capture and reuse.
Solution Approach 2:
The patent employs single-use authentication codes that are disposable after one transaction. Each authentication code is generated for a specific transaction and becomes invalid immediately after use, eliminating the risk of future unauthorized use even if captured, effectively making the authentication credential short-lived and non-reusable.
2Reliability
If a single use authentication code is generated and provided to the mobile device through a communications network, then the mobile device can be authenticated at a point of sale device, but the system complexity increases with multiple components including authentication provider, mobile device, and point of sale device
Solution Approach 1:
The patent divides the authentication system into distinct functional segments: the authentication provider that generates codes, the mobile device that stores and transmits them, and the point of sale device that validates them. This segmentation allows each component to be optimized independently and simplifies the overall system architecture by defining clear interfaces and responsibilities for each segment.
Solution Approach 2:
The patent introduces an authentication provider as an intermediary component that mediates between the mobile device and the point of sale device. This intermediary generates and manages the authentication codes, reducing the complexity burden on the mobile device and point of sale device while maintaining strong security through centralized code management.
3Reliability
If the single use authentication code is used to enable a funds adjustment to the payment account, then unauthorized transactions are reduced, but the processing time may increase due to additional authentication steps
Solution Approach 1:
The patent performs preliminary generation and distribution of authentication codes before the actual transaction occurs. The authentication code is generated in advance and stored in the mobile device, so during the transaction, only verification is needed rather than generation, significantly reducing the time penalty while maintaining strong fraud prevention.
Solution Approach 2:
The patent replaces traditional mechanical authentication methods (such as physical card swiping and magnetic stripe reading) with electronic code verification. This substitution enables faster processing by using digital communication and automated verification algorithms, reducing the time overhead of additional authentication steps while enhancing fraud prevention capabilities.
Data Source
AI summary
An identifier of a mobile device may be accessed. The identifier may be associated with a payment account. A single use authentication code relating to the identifier may be generated. The single use authentication code may be capable of being used to authenticate the mobile device at a point of sale (POS) device and enable a funds adjustment to the payment account. The single use authentication code may be provided to the mobile device through a communications network.


