Dynamic Transaction Card Multi-Factor Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods are burdensome and vulnerable to fraud, requiring sensitive information that can be compromised by malware and phishing attacks, and are not efficient for multi-factor authentication.

Innovation Solution

A dynamic transaction card system that uses a smart card with a secure memory chip and microprocessor, paired with a user device application, to facilitate multi-factor authentication through wireless connections, such as NFC or Bluetooth, storing validation information and enabling secure login credentials without needing users to enter sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods requiring sensitive information entry are used, then authentication can be performed, but security is compromised due to malware and phishing attacks capable of acquiring such information

Engineering Contradiction:
Improveauthentication securityVSAvoidvulnerability to malware and phishing attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication function from traditional password-based systems and implements it in a dedicated secure element within the smart card. This separation removes sensitive authentication logic from vulnerable network environments and places it in an isolated, tamper-resistant hardware module, eliminating the attack surface that malware and phishing exploits.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The smart card acts as an intermediary authentication device between the user and the system. Instead of directly entering sensitive information into potentially compromised systems, the user presents the smart card which contains embedded authentication credentials. The card itself serves as the mediator that proves identity without exposing sensitive data to external systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If knowledge-based authentication questions are used, then authentication can be performed, but the process becomes burdensome and time-consuming for customers

Engineering Contradiction:
Improveauthentication convenienceVSAvoidtime required for authentication
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The authentication credentials are pre-loaded into the smart card during manufacturing or initial setup. This preliminary action eliminates the need for users to recall or enter sensitive information during authentication. The card already contains the necessary cryptographic keys and credentials, enabling instant verification without requiring user memory or input time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The smart card performs self-service authentication by automatically presenting its credentials to the authentication system. The card contains embedded logic that handles the authentication protocol, generating and presenting proof of identity without requiring the user to actively participate beyond presenting the card. This automation eliminates the time-consuming process of answering knowledge-based questions.

Inventive Principle:
Principle #25Self-service

3Reliability

If sensitive data is requested via telephone in public spaces, then authentication can be performed, but the sensitive data is compromised when customers respond orally

Engineering Contradiction:
Improveauthentication securityVSAvoideavesdropping and oral response compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

Instead of transmitting sensitive authentication data over the telephone network, the system uses the smart card as a physical copy of the authentication credentials. The card contains embedded cryptographic keys that never leave the secure element. During telephone authentication, only non-sensitive verification codes or tokens are transmitted, while the core credentials remain secured in the physical card, preventing eavesdropping attacks.

Inventive Principle:
Principle #26Copying

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Provides a secure and efficient multi-factor authentication process by utilizing the dynamic transaction card as a physical token, reducing the burden on users and enhancing security by eliminating the need for sensitive information entry.

Implementation Method 1

wireless connections, which may include NFC, Bluetooth or BLE connections

Methodology Applied
Scientific EffectNFC (Near Field Communication): Electromagnetic Induction

Implementation Method 2

wireless connections, which may include NFC, Bluetooth or BLE connections

Methodology Applied
Scientific EffectBluetooth wireless communication: Electromagnetic Induction

Data Source

PatentUS10535068B2Smart card multi-factor authentication device
Publication Date: 2020.01.14 CAPITAL ONE SERVICES LLC
  • US10535068B2 patent drawing
  • US10535068B2 patent drawing
  • US10535068B2 patent drawing

AI summary

A dynamic transaction card may be paired with a user application executed on a user device card to facilitate multi-factor authentication of a user by utilizing the dynamic transaction card as a physical token. Various communication technologies may be utilized to create a connection between the dynamic transaction card and the user device application which may include wireless connections and physical connections. Validation information stored in a passive tag on the dynamic transaction card may be received by the user device application, which may evaluate the connection between the dynamic transaction card and the user device, log in credentials of the user, and user information stored in a digital security delivery storage to authenticate the user. This unique pairing of the dynamic transaction card and user device application may automatically facilitate a secure multi-factor authentication by utilizing the dynamic transaction card as a physical token.