One-Time Passwords for Mobile Wallet Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current payment systems using mobile electronic devices face security concerns due to potential flaws in NFC and RFID technologies, and the need for improved authentication methods, especially in unplanned transactions and online purchases.
Innovation Solution
A system that generates and uses one-time passwords on mobile devices for authentication, which can be created at a mobile wallet server, acquirer system, or the device itself, and communicated via a wireless carrier, ensuring security through time-stamped and randomly generated passwords valid for a predetermined period.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If NFC or RFID components are used for contactless communication, then transaction convenience is improved, but security vulnerabilities increase
Solution Approach 1:
The patent implements dynamic password generation where the authentication code changes with each transaction attempt and expires after a predetermined time period. This dynamic approach prevents static credential compromise while maintaining convenient contactless NFC/RFID communication.
Solution Approach 2:
The system changes the authentication parameter from a static PIN or magnetic stripe data to a dynamically generated password that varies in time and transaction context. This parameter change enhances security while preserving the ease of contactless operation.
2Ease of operation
If static PIN or CVV codes are used for authentication, then ease of operation is improved, but security against fraud decreases
Solution Approach 1:
The patent replaces static authentication codes with dynamic passwords that are generated anew for each transaction and expire after a predetermined time. This eliminates the risk of static credential compromise while maintaining user-friendly authentication.
Solution Approach 2:
The authentication credential (password) has a very short valid lifespan, expiring after a predetermined time or single use. This disposable nature of the credential prevents fraud from compromised codes while keeping the authentication process simple for users.
3Reliability
If biometric scanners and passwords are added to payment devices, then security is improved, but device complexity increases
Solution Approach 1:
The patent introduces a server-based authentication system that generates and manages dynamic passwords, acting as an intermediary between the mobile device and the transaction system. This externalizes the complex security logic from the device, keeping it simple while maintaining high security.
Solution Approach 2:
The mobile device itself can generate the dynamic password using its existing processor and clock, eliminating the need for additional security hardware. The device serves its own authentication needs using components already present in standard mobile devices.
4Adaptability or versatility
If multiple forms of payment are carried by consumers, then payment versatility is improved, but organization and security management deteriorate
Solution Approach 1:
The patent creates a universal mobile device platform that can handle multiple payment methods and authentication scenarios through software rather than requiring separate physical cards or devices. The mobile device performs multiple functions including wallet storage, password generation, and contactless communication.
Solution Approach 2:
The patent creates a digital copy of payment credentials in the mobile device's memory, replacing physical cards and cash. This digital representation maintains payment versatility while eliminating the organization problems associated with carrying multiple physical payment forms.
Data Source
AI summary
A mobile wallet and network system using onetime passwords for authentication is disclosed according to one embodiment of the invention. A onetime password may be generated at a mobile wallet server and transmitted to the mobile device. The onetime password may then be used to authenticate the user of the mobile wallet when completing a transaction. Authentication may require entry of the onetime password and confirmation that the onetime password entered matches the onetime password sent by the mobile wallet server. In other embodiments of the invention, a mobile wallet and a mobile wallet server are in sync and each generate the same onetime password at the same time. These onetime passwords may then be used to authenticate the user of the mobile wallet.


