One-Time Password Authentication via Interchange System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The financial transaction card industry faces challenges with fraudulent activities due to the risk of password compromise, especially in online transactions, as users often reuse passwords or choose easily remembered ones, leading to security vulnerabilities.
Innovation Solution
A method and system for authenticating cardholders using a dynamically generated one-time password (OTP) transmitted via a different communication medium than the transaction initiation, ensuring secure authentication without requiring modifications to existing systems or specialized hardware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users use easily remembered passwords or reuse passwords across multiple services, then password recall becomes easier, but security is compromised and authentication credentials can be easily stolen or distributed for fraudulent use
Solution Approach 1:
The patent implements dynamic password generation where the password changes with each transaction or authentication event. The system generates a new authentication credential each time, preventing reuse and significantly reducing the risk of fraudulent use. This dynamic approach maintains security while users can still access services through the same interface.
Solution Approach 2:
The system changes the temporal parameter of password validity, transforming static passwords into time-limited credentials. Each authentication credential has a specific validity period or single-use property, after which it becomes invalid. This parameter change ensures that even if credentials are compromised, they cannot be reused for fraudulent transactions.
2Device complexity
If static passwords are used for authentication, then the authentication process is simple, but once compromised the credentials can be stored or distributed for repeated fraudulent use
Solution Approach 1:
The patent transforms static authentication credentials into dynamic ones that change with each use. The system generates new authentication data for each transaction, ensuring that compromised credentials cannot be reused. This maintains a relatively simple authentication process while dramatically reducing fraudulent activity risks.
Solution Approach 2:
The authentication credentials function as disposable, single-use objects. Each credential is designed to be used once and then discarded, preventing repeated fraudulent use. The system generates inexpensive, temporary authentication data that serves its purpose and becomes invalid, eliminating the value of stolen credentials for future fraud.
3Ease of operation
If traditional authentication methods are used, then the system is simple to operate, but security measures must be increased to reduce fraudulent activity
Solution Approach 1:
The patent integrates dynamic credential generation into the existing transaction flow, maintaining ease of operation while enhancing security. Users interact with the same interface and process, but the authentication credentials themselves are dynamic and transaction-specific, providing fraud prevention without complicating the user experience.
Solution Approach 2:
The system introduces an intermediary authentication layer that generates and verifies dynamic credentials between the user and the transaction system. This intermediary process enhances security by validating transaction-specific credentials while remaining transparent to users, maintaining ease of operation without sacrificing fraud prevention capabilities.
Data Source
AI summary
A system and computer-based method for using a one-time password (OTP) to authenticate an identity of a cardholder in a financial transaction initiated by the cardholder with a merchant via a first communication medium. A one-time password is generated at an interchange computer system and transmitted to the cardholder via a second communication medium. The cardholder is prompted to enter access credential information, including the one-time password. When the entered access credential information is verified (e.g., the entered one time password is equal to the generated one-time password), a successful authentication is indicated to the merchant.


