Dynamic Single-Use Authentication Code for Mobile Payment Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Payment cards with cryptographic keys in magnetic stripes are vulnerable to unauthorized capture, allowing nefarious users to withdraw funds before unauthorized activity is detected, compromising both the payment account and the card.

Innovation Solution

A system that generates and uses a single-use authentication code associated with a mobile device to authenticate transactions at a point of sale, enabling secure funds adjustments to a payment account through a communications network, reducing the risk of fraud by providing dynamic funding authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a cryptographic key is included in a magnetic stripe of the payment card, then the card can be used to authenticate payment at a point of sale, but the information in the magnetic stripe may be subject to unauthorized capture, compromising the payment account and the card

Engineering Contradiction:
Improveauthentication securityVSAvoidunauthorized capture
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent transitions from static magnetic stripe data to dynamic authentication codes that change with each transaction. The authentication code is generated based on transaction-specific parameters and is valid only for a single use, making the authentication mechanism dynamic rather than static, thereby preventing unauthorized capture and reuse.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent employs single-use authentication codes that are disposable after one transaction. Each authentication code is generated for a specific transaction and becomes invalid immediately after use, eliminating the risk of future unauthorized use even if captured, effectively making the authentication credential short-lived and non-reusable.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Reliability

If a single use authentication code is generated and provided to the mobile device through a communications network, then the mobile device can be authenticated at a point of sale device, but the system complexity increases with multiple components including authentication provider, mobile device, and point of sale device

Engineering Contradiction:
Improvetransaction securityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the authentication system into distinct functional segments: the authentication provider that generates codes, the mobile device that stores and transmits them, and the point of sale device that validates them. This segmentation allows each component to be optimized independently and simplifies the overall system architecture by defining clear interfaces and responsibilities for each segment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an authentication provider as an intermediary component that mediates between the mobile device and the point of sale device. This intermediary generates and manages the authentication codes, reducing the complexity burden on the mobile device and point of sale device while maintaining strong security through centralized code management.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the single use authentication code is used to enable a funds adjustment to the payment account, then unauthorized transactions are reduced, but the processing time may increase due to additional authentication steps

Engineering Contradiction:
Improvefraud preventionVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary generation and distribution of authentication codes before the actual transaction occurs. The authentication code is generated in advance and stored in the mobile device, so during the transaction, only verification is needed rather than generation, significantly reducing the time penalty while maintaining strong fraud prevention.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces traditional mechanical authentication methods (such as physical card swiping and magnetic stripe reading) with electronic code verification. This substitution enables faster processing by using digital communication and automated verification algorithms, reducing the time overhead of additional authentication steps while enhancing fraud prevention capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8538819B2Method and system for dynamic funding
Publication Date: 2013.09.17 PAYPAL INC
  • US8538819B2 patent drawing
  • US8538819B2 patent drawing
  • US8538819B2 patent drawing

AI summary

An identifier of a mobile device may be accessed. The identifier may be associated with a payment account. A single use authentication code relating to the identifier may be generated. The single use authentication code may be capable of being used to authenticate the mobile device at a point of sale (POS) device and enable a funds adjustment to the payment account. The single use authentication code may be provided to the mobile device through a communications network.