Dynamic Code Generator for Secure Online Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for securing operations, such as online transactions and account creations, are inadequate due to vulnerabilities in password security, the theft of bank card data, and the limitations of current authentication methods.
Innovation Solution
A method and system for securing operations using a dynamic code generator device associated with a user's key, which involves formulating a request to implement an operation, receiving a request for a dynamic code, generating and transmitting a dynamic code, and verifying its validity to confirm the operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dynamic cryptogram cards with changing CVV codes are used, then online hacking benefit is reduced, but the method does not cover card theft cases and is unsuited for reimbursement operations
Solution Approach 1:
The patent creates a universal securing method that works across multiple operation types including online transactions, physical transactions, account creations, and reimbursements. The method uses a single dynamic code mechanism that can be applied to any operation requiring security validation, making the system adaptable to diverse use cases while maintaining consistent security levels.
Solution Approach 2:
The patent implements dynamic codes that change over time or with each operation, replacing static CVV codes. The code validity is limited to specific time periods or single-use scenarios, ensuring that even if a code is compromised, its utility is severely limited. This dynamic approach enhances security while maintaining versatility across different operation types.
2Reliability
If secure code method with SMS validation is used, then transaction validation is effective, but cost is higher and mobile phone theft does not prevent data theft
Solution Approach 1:
The patent introduces a certification body as an intermediary that issues dynamic codes to users and validates them during operations. This mediator separates the security validation function from both the user's device and the service provider, creating a dedicated security layer that simplifies the overall system architecture while maintaining high security standards across different operation types.
Solution Approach 2:
The patent implements preliminary code issuance where users receive dynamic codes before performing operations. The certification body pre-validates user identities and issues appropriate codes tailored to specific operation types. This preliminary action ensures that security measures are in place before transactions occur, reducing the need for complex real-time validation systems.
3Ease of operation
If bank card data is stored at online merchant, then client experience is simplified, but CVV code theft risk increases
Solution Approach 1:
The patent implements single-use or time-limited dynamic codes that are valid only for specific operations or time periods. Unlike stored CVV codes that remain vulnerable indefinitely, these disposable codes expire after use or after a short time window, dramatically reducing the risk of theft and unauthorized use. This approach maintains simplified client experience while eliminating long-term security vulnerabilities.
Data Source
AI summary
A method for securing operations is described. In this method a user requests that a service provider device perform an operation, the service provider device transmitting to a certification device a request to validate the requested operation while indicating a key associated with the user. The certification device identifies the user associated with the key and transmits a dynamic code request to the user. A device that generates dynamic codes assigned to the user generates a first version of the dynamic code and transmits it to the certification device, which compares it with a second version of the code in order to decide whether it would or would not be appropriate to inform the service provider device that the requested operation has been validated.


