Dynamic One-Time Passcode Generation for ATM Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The static nature of magstripe data and personal identification numbers (PINs) on ATM and debit cards makes them vulnerable to attacks, such as skimming and phishing, allowing attackers to compromise accounts without detection until significant financial loss occurs.

Innovation Solution

A system and method that generates a dynamic one-time passcode (OTP) on a user's mobile device, which is configured to replace the static PIN for single-use transactions, using cryptographic camouflage and algorithms like HOTP and EMV/CAP, ensuring each transaction uses a unique, non-reusable code.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a static PIN is used for transactions, then the system is simple to operate and maintain, but the account becomes vulnerable to attacks such as skimming and phishing

Engineering Contradiction:
Improveaccount securityVSAvoidPIN structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic PINs that change for each transaction or time period, replacing the static PIN with a time-varying authentication code. This dynamic structure ensures that even if one PIN is compromised, it cannot be reused for subsequent transactions, fundamentally addressing the security vulnerability of static PINs while maintaining operational simplicity through automated generation and validation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the parameter of the PIN from static to dynamic by introducing time-based or transaction-based variability. Each authentication event uses a different PIN value, transforming the authentication mechanism from a fixed credential to a variable one, thereby enhancing security without requiring complex user behavior changes.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If the same PIN is used for multiple transactions, then the operation is convenient and fast, but the harmful factor increases as attackers can reuse captured PINs for fraudulent transactions

Engineering Contradiction:
Improvetransaction speedVSAvoidattack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system preemptively counteracts potential attacks by ensuring each PIN is valid for only one transaction or a limited time window. This preliminary security measure prevents attackers from benefiting from captured PINs, as the PIN becomes invalid immediately after use or expiration, eliminating the possibility of reuse attacks while maintaining operational efficiency through automated validation.

Inventive Principle:
Principle #9Preliminary anti-action

3Ease of manufacture

If static magstripe data is used on cards, then the card manufacturing is simple and cost-effective, but the card can be easily cloned using skimming devices

Engineering Contradiction:
Improvecard productionVSAvoidcard cloning
Core Design Contradiction:
Ease of manufactureVSObject-generated harmful factors

Solution Approach 1:

The patent introduces dynamic authentication codes that are generated and updated regularly, replacing the static magstripe data with a dynamic credential system. This dynamic approach ensures that even if card data is skimmed or cloned, the stolen data becomes immediately useless for future transactions, fundamentally undermining cloning attacks while maintaining simple card manufacturing processes.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8843757B2One time PIN generation
Publication Date: 2014.09.23 CA TECH INC
  • US8843757B2 patent drawing
  • US8843757B2 patent drawing
  • US8843757B2 patent drawing

AI summary

A method and system is provided for generating a one-time passcode (OTP) configured for use as a personal identification number (PIN) for a user account from a user device. The OTP may be generated using an OTP generator which may include an algorithm an user account-specific OTP key. The OTP key may be camouflaged by encryption, obfuscation or cryptographic camouflaging using a PIN or a unique machine identifier defined by the user device. Obtaining an OTP from the user device may require inputting a data element which may be one of a PIN, a character string, an image, a biometric parameter, a user device identifier such as an machine effective speed calibration (MESC), or other datum. The OTP may be used for any transaction requiring a user PIN input, including ATM and debit card transactions, secure access and online transactions.