One-Time Password Authentication for Settlement Fraud Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current credit card settlement systems face challenges in preventing impersonation fraud due to the fixed nature of credit card numbers, which can be easily replicated or stolen, leading to increased risks of fraudulent transactions.
Innovation Solution
A settlement system that employs a user terminal, a settlement device, and a settlement terminal connected via a network, utilizing one-time passwords (OTPs) generated by both the user terminal and settlement device, which are associated with virtual balance information, to authenticate and authorize transactions, reducing the risk of impersonation by limiting the validity and transferability of the OTP.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If credit card numbers are used for authentication, then settlement transactions can be performed, but impersonation fraud by third parties cannot be completely prevented
Solution Approach 1:
The patent applies dynamics by making the authentication credential dynamic instead of static. The one-time password (OTP) changes with each transaction and has a limited validity period, unlike the fixed credit card number. This dynamic credential system prevents impersonation because even if a OTP is stolen, it becomes invalid after a short time or single use, making fraud prevention more effective while maintaining transaction capability
Solution Approach 2:
The patent uses disposable one-time passwords that are valid only for a single transaction or short period. Each OTP is generated anew for each settlement attempt and discarded afterward. This disposable credential approach eliminates the long-term validity problem of credit card numbers, where stolen information remains useful indefinitely, thereby preventing impersonation fraud while enabling continuous transaction functionality
2Measurement precision
If multiple authentication measures (signature, CVC, CVC2) are added to credit card system, then authentication precision increases slightly, but the system complexity increases
Solution Approach 1:
The patent fundamentally changes the authentication parameter from a static credit card number to a dynamic one-time password with temporal validity. This parameter change achieves high authentication precision without adding multiple layers of static checks like signatures and CVC codes. The OTP system provides strong authentication through its time-sensitive and single-use nature, simplifying the overall system while maintaining high security precision
3Productivity
If credit card numbers are stored in databases, then settlement processing is efficient, but data leakage enables easy impersonation
Solution Approach 1:
The patent replaces long-term valid credit card numbers stored in databases with short-lived one-time passwords. The OTP is generated temporarily for each transaction session and becomes invalid afterward. This eliminates the value of stolen data over time, as a captured OTP cannot be reused after its validity period expires, thereby preventing impersonation even if database leakage occurs, while maintaining efficient settlement processing through automated OTP generation and verification
Data Source
AI summary
A settlement system with higher security which replaces a settlement system using credit cards is provided. The settlement system has a user terminal, a settlement device, and a settlement terminal. First, a user ID, a password, and upper limit amount information identifying an amount are inputted in a user terminal 100 (S912), and sent to the settlement device (S913). The settlement device performs credit determination (S922), generates temporary permission information if credit is possible (S923), and sends the temporary permission information to the user terminal (S924). The user terminal generates a one-time password (S915). The one-time password is inputted to the settlement terminal (S931). If the one-time password sent from the settlement terminal to the settlement device is identical to the one-time password created in the settlement device, the settlement device allows a user's payment (S928).


