RFID Payment Card With One-Time Password Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing payment card systems are vulnerable to security risks as card information can be compromised when the card is out of the owner's sight during processing, allowing unauthorized parties to read or copy card details for fraudulent transactions.

Innovation Solution

A payment card with an embedded RFID device and a cellular telephone or other wireless device generates a one-time password (OTP) that is encrypted with the user's PIN and current time, transmitted to the card, allowing secure transactions without exposing card information, leveraging the 'what you have plus what you know' security principle.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional payment card processing is used where the card is handed to staff for processing, then the transaction can be completed, but the card information becomes vulnerable to unauthorized reading or copying when out of the owner's sight

Engineering Contradiction:
Improvetransaction securityVSAvoidcard information exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by generating and storing the one-time password on the card before the actual transaction occurs. The card is pre-loaded with authentication credentials that are valid only for a single use within a specific time window, eliminating the need to expose permanent card information during processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes the parameter of card information from static (permanent card number and details) to dynamic (one-time password that changes with each transaction and expires after use). This transformation ensures that even if the card data is read during processing, it cannot be reused for unauthorized transactions.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If card information is stored in a readable format on the card, then the card can be easily processed by reading devices, but the information can be copied and misused by unauthorized parties

Engineering Contradiction:
Improvecard processingVSAvoidinformation copying
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The system uses a one-time password that is disposable and short-lived, valid for only one transaction or a limited time period. After use or expiration, the password becomes invalid, making any copied information useless for unauthorized transactions. This approach maintains ease of processing while eliminating the value of stolen card data.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Productivity

If the card contains permanent card information for processing, then transactions can be processed efficiently, but the card owner cannot prevent unauthorized purchases if the card is compromised

Engineering Contradiction:
Improvetransaction processing speedVSAvoidauthorization security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system introduces dynamics to the card information by implementing time-based and usage-based validity for the one-time password. The authentication credentials on the card are not static but change based on time expiration and usage status, allowing the system to maintain fast processing while dynamically controlling authorization to prevent unauthorized purchases.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9916572B2Payment card processing system
Publication Date: 2018.03.13 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9916572B2 patent drawing
  • US9916572B2 patent drawing
  • US9916572B2 patent drawing

AI summary

A method, programmed medium and system are provided for using a payment card with an embedded RFID device. In one example, a cellular telephone or other wireless device is used to generate a one-time password (OTP), which is then transmitted by a read-write RFID in the wireless device to the read-write RFID which is embedded within a payment card. The user's phone or other wireless device then activates the writing of the OTP to the RFID of the payment card. The payment card, with the one time password now saved in the card, is then handed to the waiter or store clerk for payment approval and/or further processing. The user's OTP is then read by the merchant's RFID reader and transmitted to an approving agency/server for approval or disapproval of the user's purchase.