One-Time Encryption Keys for Secure Transaction Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity measures in cyberspace transactions fail to effectively identify and verify parties involved in transactions, leading to vulnerabilities and increased costs due to fraud and the need for multiple entities to store and secure sensitive information, which compromises security and efficiency.
Innovation Solution
A system utilizing one-time-use encryption keys generated by unique sequencers on user and provider devices, managed by an intermediate entity, to encrypt and decrypt transaction data, ensuring secure identity verification and authorization without exposing personal or financial information, and maintaining records centrally to reduce storage burdens on parties involved in transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple entities store and secure sensitive transaction information, then transaction verification capability is improved, but security risk and storage cost increase
Solution Approach 1:
The patent extracts sensitive transaction information from multiple distributed storage locations and consolidates it into a single centralized database. Only essential verification data is retained at processing entities, while the actual sensitive information (account numbers, personal details) is stored exclusively in the centralized database, eliminating the security risks of distributed sensitive data storage.
Solution Approach 2:
The patent introduces a centralized database as an intermediary between transaction parties and processing entities. This intermediary consolidates sensitive information storage and provides controlled access through standardized interfaces, reducing the need for multiple entities to directly store and manage sensitive data while maintaining verification capabilities.
2Reliability
If multiple entities store and secure sensitive transaction information, then transaction verification capability is improved, but storage cost and complexity increase
Solution Approach 1:
The patent extracts sensitive information management responsibilities from multiple distributed systems and centralizes them in a single database infrastructure. This reduces the complexity of managing multiple secure storage systems while maintaining the ability to verify transactions through centralized data access.
Solution Approach 2:
The patent merges multiple distributed sensitive data storage systems into a single centralized database. This consolidation simplifies security management, reduces redundant storage infrastructure, and lowers overall system complexity while preserving transaction verification capabilities through centralized data access.
3Loss of information
If traditional encryption methods are used with shared keys, then decryption capability is improved, but security vulnerability increases
Solution Approach 1:
The patent segments the encryption key into multiple parts, with each party (user, provider, intermediate entity) holding a different segment. No single party possesses the complete decryption key, eliminating the security vulnerability of shared keys while maintaining the ability to decrypt transaction data through key segment combination.
Solution Approach 2:
The patent implements different encryption key segments with different access rights and purposes for different parties. Each party's key segment is optimized for their specific role in the transaction process, providing localized security properties that prevent any single party from compromising the entire system while maintaining decryption capability.
Data Source
AI summary
A registered provider device encrypts provider input related to a transaction between the provider device and one of many registered user devices to create an encrypted one-time-use provider code (the encryption is performed using an encryption key produced, in part, using a uniquely sequenced number generated by a sequencer maintained by the provider device). Similarly, the user device encrypts user input to create an encrypted one-time-use user code using an encryption key produced, in part, using a uniquely sequenced number generated by a user sequencer maintained by the user device. The provider and user devices independently transmit their different encrypted one-time-use codes to an intermediate entity, which decrypts the encrypted codes. This decryption is performed using one-time-use encryption keys produced using sequencers maintained by the intermediate entity, and this decryption generates an authorization request. The intermediate entity obtains an authorization decision regarding the authorization request from the authorization entity.


