OTP Gateway Identity Verification for Payment Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing OTP-based electronic payment systems are vulnerable to security breaches when the device used for OTP transmission is compromised, such as through malware or loss/stolen devices, and unauthorized access can occur if an attacker changes the registered mobile number, allowing misuse of OTPs.
Innovation Solution
Implementing an identity verification process that includes user inputs, such as security questions or biometric data, to authenticate the user before displaying or transmitting the OTP, using a processor-based OTP gateway server to control OTP generation and transmission, ensuring only authorized users access the OTP, and storing it transiently to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If OTP is transmitted to a registered mobile device, then authentication is enabled, but security is compromised when the device is lost, stolen, or infected with malware
Solution Approach 1:
The system performs identity verification through security questions or biometric authentication before transmitting the OTP to the mobile device. This preliminary action ensures that only the legitimate user can access the OTP, even if the device is compromised, because the attacker cannot pass the identity verification step.
Solution Approach 2:
The system introduces an intermediary identity verification layer between the user and the OTP transmission. Instead of directly transmitting OTP to any device that claims to be registered, the system mediates through additional authentication factors (security questions, biometric data) to confirm the user's identity before enabling OTP access.
2Adaptability or versatility
If OTP is stored in a database for verification, then authentication functionality is provided, but unauthorized access can occur if the database is breached or OTP is intercepted
Solution Approach 1:
The system performs identity verification before transmitting OTP to the mobile device. This preliminary security measure ensures that even if OTP data is intercepted or the database is breached, attackers cannot misuse the OTP without first passing the identity verification check through security questions or biometric authentication.
Solution Approach 2:
The system applies preliminary anti-action by implementing identity verification that prevents unauthorized access before the OTP can be effectively used. The security questions and biometric authentication create a barrier that counteracts potential threats of OTP interception or database breaches.
3Productivity
If static PIN is used for authentication, then transaction speed is improved, but security is weakened due to PIN being susceptible to theft and misuse
Solution Approach 1:
The system transitions from static PIN authentication to dynamic OTP authentication that changes for each transaction. The OTP is generated freshly for each transaction and is valid only for that specific transaction, making it dynamic rather than static. This dynamic approach maintains security even though it adds slight overhead to the authentication process.
Solution Approach 2:
The system changes the authentication parameter from a static PIN to a dynamic OTP that varies with each transaction. The OTP includes transaction-specific elements and time sensitivity, changing parameters from static to dynamic to improve security while maintaining acceptable transaction speed through automated generation and verification.
Data Source
AI summary
The invention relates to methods, systems and computer program products for securing one time passwords (OTP) for use in OTP based authorization of electronic payment transactions. The invention involves transmission and display of an OTP at a user device in response to a prior determination that a user operating the user device is authorized to implement a payment transaction through a payment account associated with the payment transaction. The invention implements this through transmission to the user device associated with the identified payment account, a data message initiating a process for verification of identity of a user operating the user device. Responsive to determining that the user operating the user device is authorized to operate the payment account, displaying the OTP on the user device for implementation of the payment transaction.


