Dynamic Password Transaction Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
E-commerce sites face challenges in enhancing user experience and security during transactions, particularly in protecting sensitive payment information, as users struggle to share payment instruments without exposing their actual credit card numbers or bank account details.
Innovation Solution
Implementing a transaction system that uses dynamic passwords, such as one-time passwords, linked with identifiers that are free from payment instrument information, allowing users to authenticate transactions securely without revealing sensitive payment details, and employing transaction phrase tokens with associated rules for controlled usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users share payment instrument information (credit card numbers, bank account details) to enable flexible payment methods, then ease of operation and user flexibility improve, but security and risk of exposing sensitive information worsen
Solution Approach 1:
The patent introduces dynamic passwords and transaction phrase tokens as intermediary elements between users and payment instruments. Instead of sharing sensitive payment information directly, users share identifiers coupled with dynamically generated passwords or controlled-access tokens. These intermediaries enable payment authorization while protecting the underlying sensitive data, resolving the contradiction between ease of sharing and security.
Solution Approach 2:
The system employs dynamic passwords that change over time or with each transaction, rather than static credentials. Transaction phrase tokens implement controlled usage rules that dynamically manage access permissions. This dynamic approach allows flexible sharing of payment capabilities while maintaining security through time-limited or condition-limited access, preventing permanent exposure of sensitive information.
2Device complexity
If traditional static passwords are used for authentication, then device complexity remains low, but security and protection of payment information worsen due to reuse and exposure risks
Solution Approach 1:
The patent transitions from static passwords to dynamic passwords that are generated anew for each transaction or time period. This increases security by eliminating password reuse vulnerabilities while maintaining manageable complexity through automated generation and validation systems. The dynamic nature ensures each authentication event is independent and secure.
Solution Approach 2:
The system changes the fundamental parameter of password stability by implementing time-varying or transaction-varying credentials. Instead of a fixed password string, the authentication mechanism uses parameters that change (time, transaction ID, sequence number) to generate unique passwords. This parameter transformation maintains system complexity at acceptable levels while dramatically improving security reliability.
Data Source
AI summary
Techniques for conducting transactions with one-time passwords are described herein. These techniques may include receiving a request to conduct a transaction, as well as a one-time password and an identifier linked with a payment instrument. The identifier may or may not identify the linked payment instrument. In both instances, a transaction processing service may compare the received one-time password with a one-time password stored at or accessible by the transaction processing service. If the passwords match, the service may approve the transaction. Otherwise, the service may decline the transaction or implement one or more additional authorization procedures.


