Dynamic One-Time Passwords for Secure Financial Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current payment systems using mobile electronic devices face security concerns due to potential flaws in NFC and RFID technologies, leading to fraudulent transactions, especially in online purchases where physical verification is absent.
Innovation Solution
A financial transaction card and system that incorporates a processor to calculate and display one-time passwords, which are dynamic and based on time or expiration dates, enhancing security by providing a pseudo transaction account number and dynamic card verification value, and a method for mobile devices to generate and authenticate passwords for secure financial transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If static personal identification numbers (PINs) are used for authentication, then ease of operation is improved, but security is worsened due to potential compromise and fraudulent use
Solution Approach 1:
The patent transforms static PINs into dynamic one-time passwords that change with each transaction and are time-sensitive. The authentication code is no longer fixed but dynamically generated based on transaction-specific parameters and time windows, making each authentication event unique and secure while maintaining user convenience.
Solution Approach 2:
The patent changes the parameters of authentication from static values to dynamic values that vary by transaction, time, and device. The authentication code includes time-based expiration and transaction-specific elements, transforming the authentication mechanism from a fixed state to a variable state that adapts to each authentication event.
2Productivity
If contactless devices with RFID or NFC components are used, then productivity is improved by enabling quick transactions, but security is worsened due to potential flaws and fraudulent transactions
Solution Approach 1:
The patent implements preliminary security actions by generating and validating authentication codes before the actual transaction completes. The system pre-generates time-sensitive one-time passwords and validates them during the transaction process, ensuring security measures are in place before funds are transferred, thus preventing fraudulent transactions while maintaining quick processing.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism between the contactless device and the transaction processing system. The one-time password serves as an intermediary verification layer that mediates between the quick contactless payment initiation and the security verification, allowing fast transactions while adding a secure verification step without significantly increasing processing time.
3Reliability
If dynamic one-time passwords are implemented, then security is improved by reducing fraudulent activities, but device complexity is worsened due to additional authentication mechanisms
Solution Approach 1:
The patent makes the existing contactless device perform multiple functions: it not only handles the contactless payment communication via RFID/NFC but also generates, stores, and presents dynamic one-time passwords. The device's processor and memory are utilized for both traditional payment data transmission and cryptographic operations, eliminating the need for separate hardware and reducing overall system complexity.
Solution Approach 2:
The patent merges the authentication function with the existing contactless payment functionality. The one-time password generation and verification processes are integrated into the same device and transaction flow as the traditional contactless payment, combining multiple security and payment functions into a unified system rather than adding separate complex authentication hardware.
Data Source
AI summary
A financial transaction card is provided according to various embodiments described herein. The financial transaction card includes a card body with at least a front surface and a back surface. The financial transaction card may also include a near field communications transponder and/or a magnetic stripe, as well as a digital display configured to display alphanumeric characters on the front surface of the card body. The financial transaction card may also include a processor that is communicatively coupled with the near field communications transponder or magnetic stripe and the digital display. The processor may be configured to calculate one-time passwords and communicate the one-time passwords to both the near filed communications transponder or magnetic stripe and the digital display.


