One-Time Encryption Keys for Secure Transaction Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity measures in cyberspace transactions fail to effectively identify and verify parties involved in transactions, leading to security breaches and increased costs for merchants and users, as they lack a reliable method to confirm the presence and agreement of all parties, resulting in unsecured and unfinalized transactions.

Innovation Solution

The implementation of a system that uses one-time-use encryption keys generated by IoT devices and a remote registration server to securely verify and bind parties to transactions, ensuring each party's identity and agreement through a centralized bank platform, eliminating the need for merchants to store sensitive information and reducing fraud.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cybersecurity measures (passwords, encryption) are used to protect transactions, then some level of security is achieved, but security breaches still occur and costs increase without actually securing transactions

Engineering Contradiction:
Improvetransaction securityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a bank or payment network as an intermediary that issues and verifies digital signatures. This intermediary binds the user's identity to the transaction, providing reliable security without requiring complex merchant-side verification systems. The bank acts as the trusted mediator that both parties already trust, eliminating the need for merchants to implement complex identity verification protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables users to self-verify their identity and authorization through digital signatures issued by the bank. The user's device automatically generates and attaches the digital signature to transactions, eliminating the need for external verification systems at the merchant end. This self-service approach simplifies the overall system while maintaining high security.

Inventive Principle:
Principle #25Self-service

2Loss of information

If merchants store sensitive transaction information securely, then transaction data can be retained for record-keeping, but security breaches and data leaks increase the risk and costs

Engineering Contradiction:
Improvetransaction record retentionVSAvoidsecurity breach risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive information (user identity, account details, digital signatures) from the merchant's storage system and keeps it exclusively with the bank or payment network. Merchants only store transaction identifiers and outcomes, not the actual sensitive data. This extraction eliminates the security risk associated with merchant storage while preserving the ability to retain transaction records for business purposes.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The bank serves as an intermediary that securely holds all sensitive transaction information. Instead of merchants storing sensitive data, the bank maintains the master records and can provide verification when needed. This intermediary approach allows transaction records to be retained and verified without creating security vulnerabilities at the merchant level.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If digital signatures are issued by a bank or payment network, then reliable party identification and transaction binding are achieved, but the system requires centralized trust infrastructure

Engineering Contradiction:
Improveparty identification accuracyVSAvoidcentralized infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the existing multi-functional role of banks and payment networks. These institutions already serve as trusted intermediaries for financial transactions, identity verification, and record-keeping. By issuing digital signatures through this existing universal trust infrastructure, the system achieves reliable party identification without building a separate complex verification system. The bank's existing trust relationship with both merchants and users is utilized directly.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If one-time-use encryption keys are generated independently by each party, then security is enhanced without requiring key sharing, but synchronization and verification become more complex

Engineering Contradiction:
Improveencryption securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The bank acts as an intermediary that issues the encryption keys to both parties. Instead of parties generating keys independently (which would require complex synchronization protocols), the bank generates and distributes matching key pairs to the user and merchant. This centralized key distribution through the trusted intermediary simplifies key management while maintaining the security benefits of one-time-use encryption keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10614457B2Secure authorizations using independent communications and different one-time-use encryption keys for each party to a transaction
Publication Date: 2020.04.07 BENEDORTSE LLC
  • US10614457B2 patent drawing
  • US10614457B2 patent drawing
  • US10614457B2 patent drawing

AI summary

A registered provider device encrypts provider input related to a transaction between the provider device and one of many registered user devices to create an encrypted one-time-use provider code (the encryption is performed using an encryption key produced, in part, using a uniquely sequenced number generated by a sequencer maintained by the provider device). Similarly, the user device encrypts user input to create an encrypted one-time-use user code using an encryption key produced, in part, using a uniquely sequenced number generated by a user sequencer maintained by the user device. The provider and user devices independently transmit their different encrypted one-time-use codes to an intermediate entity, which decrypts the encrypted codes. This decryption is performed using one-time-use encryption keys produced using sequencers maintained by the intermediate entity, and this decryption generates an authorization request. The intermediate entity obtains an authorization decision regarding the authorization request from the authorization entity.