One-Time Encryption Keys for Secure Transaction Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity measures in cyberspace transactions fail to effectively identify and verify parties involved in transactions, leading to vulnerabilities and increased costs due to fraud and the need for multiple entities to store and secure sensitive information, which compromises security and efficiency.

Innovation Solution

A system utilizing one-time-use encryption keys generated by unique sequencers on user and provider devices, managed by an intermediate entity, to encrypt and decrypt transaction data, ensuring secure identity verification and authorization without exposing personal or financial information, and maintaining records centrally to reduce storage burdens on parties involved in transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple entities store and secure sensitive transaction information, then transaction verification capability is improved, but security risk and storage cost increase

Engineering Contradiction:
Improvetransaction verification capabilityVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts sensitive transaction information from multiple distributed storage locations and consolidates it into a single centralized database. Only essential verification data is retained at processing entities, while the actual sensitive information (account numbers, personal details) is stored exclusively in the centralized database, eliminating the security risks of distributed sensitive data storage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a centralized database as an intermediary between transaction parties and processing entities. This intermediary consolidates sensitive information storage and provides controlled access through standardized interfaces, reducing the need for multiple entities to directly store and manage sensitive data while maintaining verification capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple entities store and secure sensitive transaction information, then transaction verification capability is improved, but storage cost and complexity increase

Engineering Contradiction:
Improvetransaction verification capabilityVSAvoidstorage and security management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts sensitive information management responsibilities from multiple distributed systems and centralizes them in a single database infrastructure. This reduces the complexity of managing multiple secure storage systems while maintaining the ability to verify transactions through centralized data access.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent merges multiple distributed sensitive data storage systems into a single centralized database. This consolidation simplifies security management, reduces redundant storage infrastructure, and lowers overall system complexity while preserving transaction verification capabilities through centralized data access.

Inventive Principle:
Principle #5Merging (Combining)

3Loss of information

If traditional encryption methods are used with shared keys, then decryption capability is improved, but security vulnerability increases

Engineering Contradiction:
Improvedata decryption capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the encryption key into multiple parts, with each party (user, provider, intermediate entity) holding a different segment. No single party possesses the complete decryption key, eliminating the security vulnerability of shared keys while maintaining the ability to decrypt transaction data through key segment combination.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements different encryption key segments with different access rights and purposes for different parties. Each party's key segment is optimized for their specific role in the transaction process, providing localized security properties that prevent any single party from compromising the entire system while maintaining decryption capability.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9569776B2Secure authorizations using independent communications and different one-time-use encryption keys for each party to a transaction
Publication Date: 2017.02.14 BENEDORTSE LLC
  • US9569776B2 patent drawing
  • US9569776B2 patent drawing
  • US9569776B2 patent drawing

AI summary

A registered provider device encrypts provider input related to a transaction between the provider device and one of many registered user devices to create an encrypted one-time-use provider code (the encryption is performed using an encryption key produced, in part, using a uniquely sequenced number generated by a sequencer maintained by the provider device). Similarly, the user device encrypts user input to create an encrypted one-time-use user code using an encryption key produced, in part, using a uniquely sequenced number generated by a user sequencer maintained by the user device. The provider and user devices independently transmit their different encrypted one-time-use codes to an intermediate entity, which decrypts the encrypted codes. This decryption is performed using one-time-use encryption keys produced using sequencers maintained by the intermediate entity, and this decryption generates an authorization request. The intermediate entity obtains an authorization decision regarding the authorization request from the authorization entity.