One-Time Password Authentication via Interchange System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The financial transaction card industry faces challenges with fraudulent activities due to the risk of password compromise, especially in online transactions, as users often reuse passwords or choose easily remembered ones, leading to security vulnerabilities.

Innovation Solution

A method and system for authenticating cardholders using a dynamically generated one-time password (OTP) transmitted via a different communication medium than the transaction initiation, ensuring secure authentication without requiring modifications to existing systems or specialized hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users use easily remembered passwords or reuse passwords across multiple services, then password recall becomes easier, but security is compromised and authentication credentials can be easily stolen or distributed for fraudulent use

Engineering Contradiction:
Improvepassword recallVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic password generation where the password changes with each transaction or authentication event. The system generates a new authentication credential each time, preventing reuse and significantly reducing the risk of fraudulent use. This dynamic approach maintains security while users can still access services through the same interface.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the temporal parameter of password validity, transforming static passwords into time-limited credentials. Each authentication credential has a specific validity period or single-use property, after which it becomes invalid. This parameter change ensures that even if credentials are compromised, they cannot be reused for fraudulent transactions.

Inventive Principle:
Principle #35Parameter changes

2Device complexity

If static passwords are used for authentication, then the authentication process is simple, but once compromised the credentials can be stored or distributed for repeated fraudulent use

Engineering Contradiction:
Improveauthentication processVSAvoidfraudulent activity
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent transforms static authentication credentials into dynamic ones that change with each use. The system generates new authentication data for each transaction, ensuring that compromised credentials cannot be reused. This maintains a relatively simple authentication process while dramatically reducing fraudulent activity risks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication credentials function as disposable, single-use objects. Each credential is designed to be used once and then discarded, preventing repeated fraudulent use. The system generates inexpensive, temporary authentication data that serves its purpose and becomes invalid, eliminating the value of stolen credentials for future fraud.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Ease of operation

If traditional authentication methods are used, then the system is simple to operate, but security measures must be increased to reduce fraudulent activity

Engineering Contradiction:
Improvetransaction processVSAvoidfraud prevention
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent integrates dynamic credential generation into the existing transaction flow, maintaining ease of operation while enhancing security. Users interact with the same interface and process, but the authentication credentials themselves are dynamic and transaction-specific, providing fraud prevention without complicating the user experience.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system introduces an intermediary authentication layer that generates and verifies dynamic credentials between the user and the transaction system. This intermediary process enhances security by validating transaction-specific credentials while remaining transparent to users, maintaining ease of operation without sacrificing fraud prevention capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8527417B2Methods and systems for authenticating an identity of a payer in a financial transaction
Publication Date: 2013.09.03 MASTERCARD INT INC
  • US8527417B2 patent drawing
  • US8527417B2 patent drawing
  • US8527417B2 patent drawing

AI summary

A system and computer-based method for using a one-time password (OTP) to authenticate an identity of a cardholder in a financial transaction initiated by the cardholder with a merchant via a first communication medium. A one-time password is generated at an interchange computer system and transmitted to the cardholder via a second communication medium. The cardholder is prompted to enter access credential information, including the one-time password. When the entered access credential information is verified (e.g., the entered one time password is equal to the generated one-time password), a successful authentication is indicated to the merchant.