Dynamic Authentication Tokens for Secure Contactless Payments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing contactless payment systems using mobile devices and magstripe payment cards face significant security issues due to the risk of sensitive information exposure and unauthorized transactions.

Innovation Solution

The method involves storing pre-authenticated swipes of the magstripe card as dynamic authentication tokens on a mobile device, which are generated using a magnetic fingerprint and can be wirelessly transmitted to a contactless payment terminal for authorization, ensuring secure and one-time use without exposing actual account numbers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional contactless payment systems use mobile devices to communicate account information via radio frequency, then payment convenience is improved, but security risks increase due to sensitive information exposure

Engineering Contradiction:
Improvepayment convenienceVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive account information from the mobile device and stores it only on the magnetic stripe card. The mobile device contains only a reader that captures card data locally without storing sensitive information, thereby eliminating the security risk of mobile device data breaches while maintaining contactless payment convenience.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a magnetic stripe card as an intermediary between the user and the payment system. The card contains the sensitive account information and magnetic fingerprint, while the mobile device merely reads and transmits data without storing sensitive information, creating a security layer that protects against mobile device compromises.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If mobile devices store pre-authenticated swipes for NFC transactions, then transaction speed is improved, but security vulnerabilities may increase due to stored authentication data

Engineering Contradiction:
Improvetransaction speedVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements single-use authentication tokens that are generated for each transaction and then invalidated. These temporary tokens provide fast authentication without the security risk of storing reusable credentials, as each token can only be used once and then is discarded.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The patent uses dynamic authentication tokens that are generated in real-time based on the magnetic fingerprint and transaction context. These tokens change with each transaction rather than being static, providing both speed through automated generation and security through uniqueness and non-reusability.

Inventive Principle:
Principle #15Dynamics

3Object-affected harmful factors

If dynamic authentication tokens are used instead of static account numbers, then security is improved through single-use tokens, but system complexity increases due to token generation and validation processes

Engineering Contradiction:
Improveunauthorized transactionsVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements a serverless authentication model where the mobile device autonomously generates authentication tokens using the captured magnetic fingerprint and stored cryptographic keys. The server only validates tokens without generating them, distributing the complexity to the client device and simplifying the server architecture.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary authentication by capturing and validating the magnetic fingerprint during an initial card swipe, storing only the cryptographic hash and public keys on the mobile device. This preliminary action eliminates the need for real-time server communication during transactions, reducing system complexity while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8533123B2Systems and methods for conducting contactless payments using a mobile device and a magstripe payment card
Publication Date: 2013.09.10 MAGTEK INC
  • US8533123B2 patent drawing
  • US8533123B2 patent drawing
  • US8533123B2 patent drawing

AI summary

Systems and methods for conducting contactless payments using a mobile device and a magstripe payment card are provided. One such method includes receiving, at the mobile device and prior to a requested financial transaction, a dynamic authentication token from a server, the dynamic authentication token indicative of a predetermined authentication of a magstripe payment card based on data obtained during a swipe of the magstripe payment card; wirelessly transmitting, in response to a request to facilitate a financial transaction, the dynamic authentication token from the mobile device to a contactless payment terminal; and sending the dynamic authentication token and information related to the requested financial transaction to the server for authorization of the requested financial transaction.