OTP Gateway Identity Verification for Payment Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing OTP-based electronic payment systems are vulnerable to security breaches when the device used for OTP transmission is compromised, such as through malware or loss/stolen devices, and unauthorized access can occur if an attacker changes the registered mobile number, allowing misuse of OTPs.

Innovation Solution

Implementing an identity verification process that includes user inputs, such as security questions or biometric data, to authenticate the user before displaying or transmitting the OTP, using a processor-based OTP gateway server to control OTP generation and transmission, ensuring only authorized users access the OTP, and storing it transiently to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If OTP is transmitted to a registered mobile device, then authentication is enabled, but security is compromised when the device is lost, stolen, or infected with malware

Engineering Contradiction:
Improveauthentication convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs identity verification through security questions or biometric authentication before transmitting the OTP to the mobile device. This preliminary action ensures that only the legitimate user can access the OTP, even if the device is compromised, because the attacker cannot pass the identity verification step.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary identity verification layer between the user and the OTP transmission. Instead of directly transmitting OTP to any device that claims to be registered, the system mediates through additional authentication factors (security questions, biometric data) to confirm the user's identity before enabling OTP access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If OTP is stored in a database for verification, then authentication functionality is provided, but unauthorized access can occur if the database is breached or OTP is intercepted

Engineering Contradiction:
Improveauthentication functionalityVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs identity verification before transmitting OTP to the mobile device. This preliminary security measure ensures that even if OTP data is intercepted or the database is breached, attackers cannot misuse the OTP without first passing the identity verification check through security questions or biometric authentication.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies preliminary anti-action by implementing identity verification that prevents unauthorized access before the OTP can be effectively used. The security questions and biometric authentication create a barrier that counteracts potential threats of OTP interception or database breaches.

Inventive Principle:
Principle #9Preliminary anti-action

3Productivity

If static PIN is used for authentication, then transaction speed is improved, but security is weakened due to PIN being susceptible to theft and misuse

Engineering Contradiction:
Improvetransaction speedVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system transitions from static PIN authentication to dynamic OTP authentication that changes for each transaction. The OTP is generated freshly for each transaction and is valid only for that specific transaction, making it dynamic rather than static. This dynamic approach maintains security even though it adds slight overhead to the authentication process.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the authentication parameter from a static PIN to a dynamic OTP that varies with each transaction. The OTP includes transaction-specific elements and time sensitivity, changing parameters from static to dynamic to improve security while maintaining acceptable transaction speed through automated generation and verification.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11410170B2Systems, methods and computer program products for securing OTPS
Publication Date: 2022.08.09 MASTERCARD INT INC
  • US11410170B2 patent drawing
  • US11410170B2 patent drawing
  • US11410170B2 patent drawing

AI summary

The invention relates to methods, systems and computer program products for securing one time passwords (OTP) for use in OTP based authorization of electronic payment transactions. The invention involves transmission and display of an OTP at a user device in response to a prior determination that a user operating the user device is authorized to implement a payment transaction through a payment account associated with the payment transaction. The invention implements this through transmission to the user device associated with the identified payment account, a data message initiating a process for verification of identity of a user operating the user device. Responsive to determining that the user operating the user device is authorized to operate the payment account, displaying the OTP on the user device for implementation of the payment transaction.