One-Time Passwords for Mobile Wallet Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current payment systems using mobile electronic devices face security concerns due to potential flaws in NFC and RFID technologies, and the need for improved authentication methods, especially in unplanned transactions and online purchases.

Innovation Solution

A system that generates and uses one-time passwords on mobile devices for authentication, which can be created at a mobile wallet server, acquirer system, or the device itself, and communicated via a wireless carrier, ensuring security through time-stamped and randomly generated passwords valid for a predetermined period.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If NFC or RFID components are used for contactless communication, then transaction convenience is improved, but security vulnerabilities increase

Engineering Contradiction:
Improvetransaction convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic password generation where the authentication code changes with each transaction attempt and expires after a predetermined time period. This dynamic approach prevents static credential compromise while maintaining convenient contactless NFC/RFID communication.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the authentication parameter from a static PIN or magnetic stripe data to a dynamically generated password that varies in time and transaction context. This parameter change enhances security while preserving the ease of contactless operation.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If static PIN or CVV codes are used for authentication, then ease of operation is improved, but security against fraud decreases

Engineering Contradiction:
Improveauthentication simplicityVSAvoidfraud risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent replaces static authentication codes with dynamic passwords that are generated anew for each transaction and expire after a predetermined time. This eliminates the risk of static credential compromise while maintaining user-friendly authentication.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication credential (password) has a very short valid lifespan, expiring after a predetermined time or single use. This disposable nature of the credential prevents fraud from compromised codes while keeping the authentication process simple for users.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If biometric scanners and passwords are added to payment devices, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a server-based authentication system that generates and manages dynamic passwords, acting as an intermediary between the mobile device and the transaction system. This externalizes the complex security logic from the device, keeping it simple while maintaining high security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The mobile device itself can generate the dynamic password using its existing processor and clock, eliminating the need for additional security hardware. The device serves its own authentication needs using components already present in standard mobile devices.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If multiple forms of payment are carried by consumers, then payment versatility is improved, but organization and security management deteriorate

Engineering Contradiction:
Improvepayment optionsVSAvoidorganization
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent creates a universal mobile device platform that can handle multiple payment methods and authentication scenarios through software rather than requiring separate physical cards or devices. The mobile device performs multiple functions including wallet storage, password generation, and contactless communication.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent creates a digital copy of payment credentials in the mobile device's memory, replacing physical cards and cash. This digital representation maintains payment versatility while eliminating the organization problems associated with carrying multiple physical payment forms.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8565723B2Onetime passwords for mobile wallets
Publication Date: 2013.10.22 FIRST DATA CORP
  • US8565723B2 patent drawing
  • US8565723B2 patent drawing
  • US8565723B2 patent drawing

AI summary

A mobile wallet and network system using onetime passwords for authentication is disclosed according to one embodiment of the invention. A onetime password may be generated at a mobile wallet server and transmitted to the mobile device. The onetime password may then be used to authenticate the user of the mobile wallet when completing a transaction. Authentication may require entry of the onetime password and confirmation that the onetime password entered matches the onetime password sent by the mobile wallet server. In other embodiments of the invention, a mobile wallet and a mobile wallet server are in sync and each generate the same onetime password at the same time. These onetime passwords may then be used to authenticate the user of the mobile wallet.