One-Time Encryption Keys for Secure Transaction Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity measures in cyberspace transactions fail to effectively identify and verify parties involved in transactions, leading to security breaches and increased costs for merchants and users, as they lack a reliable method to confirm the presence and agreement of all parties, especially in card-not-present transactions.
Innovation Solution
The system generates one-time-use encryption keys for IoT devices and remote registration servers, creating encrypted access codes that verify user identities and transaction data, ensuring secure access and authorization through a centralized bank platform, eliminating the need for merchants to store sensitive user information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional cybersecurity measures (passwords, encryption) are used to protect transactions, then security is partially improved, but security breaches still occur and costs increase
Solution Approach 1:
The patent divides the authentication process into separate independent communications channels. One channel transmits encrypted authorization data from the user device to the merchant, while another channel transmits verification data from the merchant to the user device. This segmentation ensures that even if one channel is compromised, the other remains secure, resolving the contradiction by improving reliability through structural division rather than increasing overall system complexity
Solution Approach 2:
The patent introduces a bank or payment network as an intermediary that issues and verifies one-time use authorization codes. This intermediary acts as a trusted mediator that eliminates the need for merchants to store sensitive user information, thereby improving transaction security without requiring complex security systems at the merchant level
2Reliability
If merchants store sensitive user information to verify transactions, then transaction verification is improved, but security risks and costs increase
Solution Approach 1:
The patent extracts sensitive user information storage from the merchant system and relocates it to the bank's secure environment. Merchants only store and transmit one-time use authorization codes rather than sensitive personal information. This extraction eliminates the security vulnerability of storing sensitive data at multiple locations while maintaining the ability to verify transactions, directly resolving the contradiction between verification reliability and security breach risk
Solution Approach 2:
The patent implements one-time use authorization codes that are valid for a single transaction and then expire. These disposable codes replace traditional stored user credentials, allowing verification without requiring long-term storage of sensitive information. The short-lived nature of these codes eliminates security risks associated with stored data while maintaining verification capability
3Reliability
If independent communication channels are used for authorization and verification, then security is improved, but communication complexity increases
Solution Approach 1:
The patent uses standard existing communication protocols and infrastructure for both authorization and verification channels. The same network infrastructure, encryption standards, and message formats are reused across different communication channels. This multi-functionality approach improves security through channel separation while avoiding the complexity increase that would result from creating entirely new communication systems
Data Source
AI summary
A registered provider device encrypts provider input related to a transaction between the provider device and one of many registered user devices to create an encrypted one-time-use provider code (the encryption is performed using an encryption key produced, in part, using a uniquely sequenced number generated by a sequencer maintained by the provider device). Similarly, the user device encrypts user input to create an encrypted one-time-use user code using an encryption key produced, in part, using a uniquely sequenced number generated by a user sequencer maintained by the user device. The provider and user devices independently transmit their different encrypted one-time-use codes to an intermediate entity, which decrypts the encrypted codes. This decryption is performed using one-time-use encryption keys produced using sequencers maintained by the intermediate entity, and this decryption generates an authorization request. The intermediate entity obtains an authorization decision regarding the authorization request from the authorization entity.


