Dynamic Password Transaction Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

E-commerce sites face challenges in enhancing user experience and security during transactions, particularly in protecting sensitive payment information, as users struggle to share payment instruments without exposing their actual credit card numbers or bank account details.

Innovation Solution

Implementing a transaction system that uses dynamic passwords, such as one-time passwords, linked with identifiers that are free from payment instrument information, allowing users to authenticate transactions securely without revealing sensitive payment details, and employing transaction phrase tokens with associated rules for controlled usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users share payment instrument information (credit card numbers, bank account details) to enable flexible payment methods, then ease of operation and user flexibility improve, but security and risk of exposing sensitive information worsen

Engineering Contradiction:
Improveuser flexibility in sharing payment methodsVSAvoidrisk of exposing sensitive payment information
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces dynamic passwords and transaction phrase tokens as intermediary elements between users and payment instruments. Instead of sharing sensitive payment information directly, users share identifiers coupled with dynamically generated passwords or controlled-access tokens. These intermediaries enable payment authorization while protecting the underlying sensitive data, resolving the contradiction between ease of sharing and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system employs dynamic passwords that change over time or with each transaction, rather than static credentials. Transaction phrase tokens implement controlled usage rules that dynamically manage access permissions. This dynamic approach allows flexible sharing of payment capabilities while maintaining security through time-limited or condition-limited access, preventing permanent exposure of sensitive information.

Inventive Principle:
Principle #15Dynamics

2Device complexity

If traditional static passwords are used for authentication, then device complexity remains low, but security and protection of payment information worsen due to reuse and exposure risks

Engineering Contradiction:
Improveauthentication system complexityVSAvoidsecurity of payment authentication
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent transitions from static passwords to dynamic passwords that are generated anew for each transaction or time period. This increases security by eliminating password reuse vulnerabilities while maintaining manageable complexity through automated generation and validation systems. The dynamic nature ensures each authentication event is independent and secure.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the fundamental parameter of password stability by implementing time-varying or transaction-varying credentials. Instead of a fixed password string, the authentication mechanism uses parameters that change (time, transaction ID, sequence number) to generate unique passwords. This parameter transformation maintains system complexity at acceptable levels while dramatically improving security reliability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11328297B1Conducting transactions with dynamic passwords
Publication Date: 2022.05.10 AMAZON TECH INC
  • US11328297B1 patent drawing
  • US11328297B1 patent drawing
  • US11328297B1 patent drawing

AI summary

Techniques for conducting transactions with one-time passwords are described herein. These techniques may include receiving a request to conduct a transaction, as well as a one-time password and an identifier linked with a payment instrument. The identifier may or may not identify the linked payment instrument. In both instances, a transaction processing service may compare the received one-time password with a one-time password stored at or accessible by the transaction processing service. If the passwords match, the service may approve the transaction. Otherwise, the service may decline the transaction or implement one or more additional authorization procedures.