Dynamic Security Code-Generating Device for Transaction Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure online transaction systems face challenges in balancing security and user convenience, as they often require costly data collection and are vulnerable to fraud due to static security measures, limiting flexibility and exposing users to risks like man-in-the-middle attacks.

Innovation Solution

A code-generating device dynamically controls security levels based on transaction risk by encoding sequences of functions in transaction-specific codes, allowing users to interact with their personal devices to input function-related values, such as transaction details or identity verification, which are then used to generate a response code, enhancing security and convenience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional static security measures are implemented, then security level is maintained, but user convenience deteriorates and flexibility is limited

Engineering Contradiction:
Improvesecurity levelVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic security by adjusting the authentication challenge complexity based on real-time risk assessment of transactions. The system transitions from static to dynamic security measures, where the security level adapts to each transaction's risk profile, thereby maintaining high security while improving user convenience for low-risk operations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes security parameters dynamically by modifying the authentication challenge requirements based on transaction risk factors. Parameters such as challenge complexity, verification steps, and authentication strength are adjusted according to the assessed risk level, allowing the system to maintain reliability while enhancing ease of operation.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If harsh security measures are implemented, then risk is reduced, but customer satisfaction deteriorates and customers are lost

Engineering Contradiction:
Improverisk reductionVSAvoidcustomer satisfaction
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamic security adjustment based on transaction risk assessment. For low-risk transactions, minimal authentication is required, maintaining customer satisfaction. For high-risk transactions, enhanced security measures are activated, ensuring risk reduction. This dynamic adaptation resolves the contradiction between risk reduction and customer satisfaction.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system applies different security measures to different transactions based on their specific risk profiles. Instead of uniform harsh security across all transactions, the system tailors security intensity to each transaction's local characteristics, thereby reducing risk where necessary while maintaining customer satisfaction elsewhere.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If lenient security measures are implemented, then customer satisfaction is maintained, but financial loss and customer trust deteriorate

Engineering Contradiction:
Improvecustomer satisfactionVSAvoidfinancial security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements dynamic security that adjusts authentication requirements based on real-time risk assessment. The system maintains lenient measures for low-risk transactions, preserving customer satisfaction, while automatically intensifying security for high-risk transactions, protecting financial security and trust.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops where transaction risk is continuously assessed and security measures are adjusted accordingly. Risk assessment feedback triggers appropriate security responses, ensuring that lenient measures do not compromise financial security while maintaining customer satisfaction.

Inventive Principle:
Principle #23Feedback

4Adaptability or versatility

If data is collected for dynamic security, then security flexibility is improved, but system complexity and administration cost increase

Engineering Contradiction:
Improvesecurity flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent enables the code-generating device to autonomously assess transaction risk and adjust authentication challenges without requiring complex centralized data collection and administration. The device performs self-service risk assessment based on transaction parameters, reducing system complexity and administrative overhead while maintaining security flexibility.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system extracts essential risk assessment functionality from complex centralized systems and embeds it in the code-generating device. This extraction simplifies the overall system architecture by removing the need for intricate data collection and administration infrastructure while preserving security flexibility.

Inventive Principle:
Principle #2Taking out (Extraction)

5Ease of operation

If authentication information is transmitted over internet, then convenience is improved, but vulnerability to fraud and interception increases

Engineering Contradiction:
Improvetransaction convenienceVSAvoidfraud vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a code-generating device as an intermediary that performs local risk assessment and generates authentication challenges without transmitting sensitive authentication information over the internet. The device acts as a trusted mediator that processes authentication locally, thereby maintaining transaction convenience while eliminating internet transmission vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system extracts authentication processing from internet-based transmission and relocates it to local code-generating devices. By taking out the vulnerable internet transmission step and performing authentication locally, the system maintains convenience while removing fraud and interception vulnerabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP2043036B1System, method and device for enabling interaction with dynamic security
Publication Date: 2010.06.09 TDS TODOS DATA SYST
  • EP2043036B1 patent drawingFigure 1
  • EP2043036B1 patent drawingFigure 2
  • EP2043036B1 patent drawingFigure 3~4

AI summary

A code-generating device (6a-c) for enabling interaction with dynamic security between a user (2a-c) and a transaction service provider (3). The code-generating device (6a-c) includes information acquisition means (51, 52) and processing circuitry (60). The processing circuitry (60) is configured to receive, via the information acquisition means (51, 52), a transaction-specific code generated by the transaction service provider (3), evaluate the transaction-specific code, perform, based on the evaluation of the transaction-specific code, a transaction-specific sequence of predetermined functions, each involving prompting the user (2a-c) to indicate a respective function-related value, resulting in a sequence of function-related values indicated by the user, and determine a transaction-specific response code based on the sequence of function-related values, thereby enabling secure authentication of the transaction.