One-Time Card Information Generation for Secure Mobile Payments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile payment systems using one-time virtual cards are inconvenient and insecure, as they require additional servers for validation and involve exposing card information, which can be misused by unauthorized parties.
Innovation Solution
A payment method using one-time card information generated by a card company server, where only the Bank Information Number is included, and the remaining card information is encrypted, allowing secure transactions without storing actual card details on payment devices, utilizing a relay server to verify transaction validity within a predetermined time frame.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If one-time virtual card service is implemented using existing payment systems, then card information security is improved, but system complexity increases due to additional issuing servers and validation requirements
Solution Approach 1:
The patent extracts only the necessary Bank Information Number (BIN) from the complete card information, generating one-time card information that includes exclusively the BIN and a one-time code. This eliminates the need to transmit or store sensitive card details while maintaining payment functionality, thereby improving security without requiring complex additional validation servers.
Solution Approach 2:
The patent implements disposable one-time card information that is generated temporarily for each transaction and becomes invalid after use. This one-time card information includes only the BIN and a single-use code, replacing the need for persistent virtual card systems with complex validation infrastructure, thus reducing system complexity while enhancing security.
2Reliability
If complete card information is transmitted for payment verification, then transaction validity is ensured, but card information exposure to unauthorized persons increases
Solution Approach 1:
The patent extracts only the Bank Information Number (BIN) from the complete card information and combines it with a one-time code to create minimal one-time card information. This extracted information is sufficient for transaction verification through the relay server but exposes no sensitive card details, thereby ensuring transaction validity while preventing card information exposure.
Solution Approach 2:
The patent changes the parameter composition of card information from complete card details to a minimized set containing only the BIN and one-time code. This parameter transformation maintains the ability to verify transaction validity through the relay server while eliminating exposure of sensitive card information to unauthorized persons.
3Reliability
If one-time virtual card numbers are generated for each payment, then security is improved, but convenience decreases due to frequent generation and validation requirements
Solution Approach 1:
The patent implements lightweight one-time card information consisting of a BIN and a single-use code that can be generated and used quickly. The minimal structure of this disposable information reduces generation time and simplifies the validation process through the relay server, thereby maintaining high security while improving payment convenience compared to complex virtual card systems.
4Ease of operation
If actual card information is stored on payment devices, then payment processing is simplified, but risk of loss or theft and subsequent unauthorized use increases
Solution Approach 1:
The patent extracts only the Bank Information Number (BIN) from actual card information and uses it to generate one-time card information that is transmitted temporarily for payment processing. This approach simplifies payment processing by providing necessary card data to the relay server while eliminating the need to store sensitive actual card information on payment devices, thereby reducing unauthorized use risk.
Solution Approach 2:
The patent introduces a relay server as an intermediary that receives one-time card information containing the BIN and performs validation without requiring storage of actual card information on payment devices. This intermediary system enables simplified payment processing while maintaining security by keeping sensitive card data centralized and protected.
Data Source
AI summary
Provided is a payment method using one-time information, which is performed by a payment system network-connected to a relay server and a payment device and having actual card information, the method including: receiving a payment schedule message from the payment device; publishing a Bank Information Number in response to the payment schedule message, generating one-time card information not including the actual card information, and providing the generated one-time card information to the payment device; judging validity of a message for approval request transmitted from the relay server according to whether or not a difference between a first time when the one-time card information is returned through the relay sever and a second time when the one-time card information is provided to the payment device satisfies a predetermined reference time; and determining whether or not the message for approval request is approved according to a judgment result of the validity.


