Dynamic Authentication Tokens for Secure Contactless Payments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing contactless payment systems using mobile devices and magstripe payment cards face significant security issues due to the risk of sensitive information exposure and unauthorized transactions.
Innovation Solution
The method involves storing pre-authenticated swipes of the magstripe card as dynamic authentication tokens on a mobile device, which are generated using a magnetic fingerprint and can be wirelessly transmitted to a contactless payment terminal for authorization, ensuring secure and one-time use without exposing actual account numbers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional contactless payment systems use mobile devices to communicate account information via radio frequency, then payment convenience is improved, but security risks increase due to sensitive information exposure
Solution Approach 1:
The patent extracts the sensitive account information from the mobile device and stores it only on the magnetic stripe card. The mobile device contains only a reader that captures card data locally without storing sensitive information, thereby eliminating the security risk of mobile device data breaches while maintaining contactless payment convenience.
Solution Approach 2:
The patent introduces a magnetic stripe card as an intermediary between the user and the payment system. The card contains the sensitive account information and magnetic fingerprint, while the mobile device merely reads and transmits data without storing sensitive information, creating a security layer that protects against mobile device compromises.
2Productivity
If mobile devices store pre-authenticated swipes for NFC transactions, then transaction speed is improved, but security vulnerabilities may increase due to stored authentication data
Solution Approach 1:
The patent implements single-use authentication tokens that are generated for each transaction and then invalidated. These temporary tokens provide fast authentication without the security risk of storing reusable credentials, as each token can only be used once and then is discarded.
Solution Approach 2:
The patent uses dynamic authentication tokens that are generated in real-time based on the magnetic fingerprint and transaction context. These tokens change with each transaction rather than being static, providing both speed through automated generation and security through uniqueness and non-reusability.
3Object-affected harmful factors
If dynamic authentication tokens are used instead of static account numbers, then security is improved through single-use tokens, but system complexity increases due to token generation and validation processes
Solution Approach 1:
The patent implements a serverless authentication model where the mobile device autonomously generates authentication tokens using the captured magnetic fingerprint and stored cryptographic keys. The server only validates tokens without generating them, distributing the complexity to the client device and simplifying the server architecture.
Solution Approach 2:
The patent performs preliminary authentication by capturing and validating the magnetic fingerprint during an initial card swipe, storing only the cryptographic hash and public keys on the mobile device. This preliminary action eliminates the need for real-time server communication during transactions, reducing system complexity while maintaining security.
Data Source
AI summary
Systems and methods for conducting contactless payments using a mobile device and a magstripe payment card are provided. One such method includes receiving, at the mobile device and prior to a requested financial transaction, a dynamic authentication token from a server, the dynamic authentication token indicative of a predetermined authentication of a magstripe payment card based on data obtained during a swipe of the magstripe payment card; wirelessly transmitting, in response to a request to facilitate a financial transaction, the dynamic authentication token from the mobile device to a contactless payment terminal; and sending the dynamic authentication token and information related to the requested financial transaction to the server for authorization of the requested financial transaction.


