Dynamic Authorization Code Generation for Financial Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures for financial transactions, such as CVV and PIN, are insufficient in preventing fraudulent activities, as they do not provide adequate protection against unauthorized use of financial accounts.

Innovation Solution

A system that utilizes a processor on a wireless communications device to execute an application that communicates with a data stripe reader, requiring a passcode for authorization and dynamically changing account data for each transaction, thereby enhancing security by preventing misuse of account information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures (CVV and PIN) are used for financial transactions, then the system is simple to operate, but the security reliability is insufficient to prevent fraudulent transactions

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into multiple independent components: device identity verification, passcode authentication, and dynamic authorization code generation. Each component operates independently but contributes to the overall security framework, transforming a single-layer security system into a multi-layered approach that enhances reliability without creating a monolithic complex system

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by pre-establishing device identity verification and passcode requirements before the actual financial transaction occurs. The application verifies the device's legitimacy and requires passcode entry in advance, so that when a transaction is initiated, the security framework is already in place, preventing fraudulent transactions before they can complete

Inventive Principle:
Principle #10Preliminary action

2Reliability

If account data is changed dynamically for each transaction, then security against fraudulent transactions is improved, but the complexity of transaction processing increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidtransaction processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamics by making the account data and authorization codes transaction-specific and time-sensitive. Each transaction generates unique authorization codes that are valid only for that specific transaction, preventing reuse for fraudulent purposes. The system dynamically adjusts the security parameters for each transaction while maintaining a standardized processing framework that preserves efficiency

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes parameters by generating different authorization codes and account data representations for each transaction. Instead of using static account information, the application transforms the account data into unique, transaction-specific parameters that are processed through the same efficient transaction pipeline, maintaining productivity while enhancing security

Inventive Principle:
Principle #35Parameter changes

3Reliability

If a passcode is required for authorization, then security against unauthorized use is improved, but the ease of operation is reduced

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces the passcode as an intermediary authentication element between the user and the transaction system. Rather than requiring complex cryptographic keys or biometric verification, the passcode serves as a simple intermediary that the user already possesses and can easily provide, balancing security requirements with operational simplicity

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8430308B2Authorizing financial transactions
Publication Date: 2013.04.30 BANK OF AMERICA CORP
  • US8430308B2 patent drawing
  • US8430308B2 patent drawing
  • US8430308B2 patent drawing

AI summary

A system for authorizing a financial transaction includes a processor operable to execute an application on a wireless communications device, communicate wirelessly with a data stripe through a security enabled wireless communications protocol, receive a request to authorize a financial transaction involving a financial account associated with account data, access authorization criteria for determining whether to authorize the financial transaction, apply the authorization criteria to the financial transaction, generate an authorization code based on the application of the authorization criteria to the financial transaction, and communicate the authorization code.