Online Financial Transaction Authorization via Randomized OTP Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for securing online financial transactions are vulnerable to man-in-the-middle attacks, particularly when users input information using image keyboards, as they rely on separate hardware devices for one-time passwords, which are inconvenient and difficult to distribute, and do not effectively prevent hackers from modulating transaction values.
Innovation Solution
A method and apparatus that randomly selects and combines main transaction information to create authorization information, converting it into a form displayed to the user, such as text or image, to ensure user recognition, using secret colors or OTP-based authorization numbers, and determines user recognition through comparison, thereby preventing unauthorized transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a separate hardware device is used for OTP, then transaction security is improved, but device complexity and ease of operation deteriorate
Solution Approach 1:
The patent combines the OTP generation and verification functions into the existing server system, eliminating the need for separate hardware devices. The server generates OTPs using cryptographic algorithms and delivers them through existing communication channels, merging multiple security functions into a unified software-based system that maintains security while reducing device complexity.
Solution Approach 2:
The patent replaces the mechanical hardware OTP device with a software-based cryptographic system. Instead of using physical tokens or hardware generators, the system uses mathematical algorithms to generate one-time passwords, substituting mechanical complexity with computational processes that achieve the same security goals without requiring separate hardware.
2Reliability
If a separate hardware device is used for OTP, then transaction security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent merges the OTP delivery mechanism with existing communication infrastructure such as email or SMS systems. Users receive OTPs through channels they already use for other purposes, eliminating the need to carry or operate separate hardware devices. This integration maintains security verification while significantly improving ease of operation.
Solution Approach 2:
The system enables users to receive and use OTPs through automated delivery mechanisms without requiring manual intervention or specialized hardware operation. The OTP is automatically generated, delivered, and verified through existing user interfaces, allowing users to complete transactions without learning new operational procedures or handling additional devices.
3Reliability
If keyboard security program is used, then input protection is improved, but vulnerability to MITM attack increases
Solution Approach 1:
The patent introduces an intermediary OTP verification step between the user input and the transaction processing. The OTP acts as a mediator that confirms the user's intent independently of the input method used. This intermediary layer prevents MITM attacks by requiring separate verification that cannot be intercepted through keyboard injection or web injection techniques.
Solution Approach 2:
The system performs preliminary verification by requiring users to obtain and enter an OTP before the actual transaction is processed. This preliminary action of generating and verifying a separate authentication code prevents malicious modifications to transaction details, as the OTP is tied to the specific transaction context and cannot be reused or modified by attackers.
Data Source
AI summary
A method and an apparatus for authorizing online financial transactions are provided. The apparatus for authorizing online financial transactions includes: randomly selecting, using an apparatus for authorizing online financial transactions, a portion of main transaction information corresponding to a user and combining the selected information to create authorization information; converting the authorization information into a form displayed to the user through a specific process; providing the main transaction information and the converted authorization information to the user; receiving user select information, which is recognized by the user and is part of the main transaction information, and the converted authorization information provided to the user; and comparing the user select information with the authorization information and determining whether the user recognizes the authorization information based on the comparison results.


