Secure Limited Use Key Generation for Mobile Payment Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile payment systems face security challenges, particularly in high-value transactions, as they require secure management of partial passcodes without storing the full passcode on devices or third-party servers, while ensuring system robustness and efficiency.

Innovation Solution

A communications device and method that generate and manage a secure limited use key (SLUK) using a subset of passcode characters, determined by a predetermined algorithm involving a secret key and variable code, to authenticate transactions, ensuring only partial passcode entry is required for each transaction, with the full passcode remaining secure at the financial institution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the full passcode is stored on the mobile device or third-party server, then the system operation is simplified, but the security is compromised

Engineering Contradiction:
Improvesystem operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The passcode is segmented into multiple characters, and only a subset of these characters is stored on the mobile device. The full passcode remains secured at the financial institution. This segmentation allows the system to operate with partial passcode storage while maintaining security through the distributed architecture where the complete authentication data resides securely at the issuer.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Only a subset of passcode characters is extracted and stored on the mobile device, while the remaining characters and the full passcode are retained at the financial institution. This extraction approach enables simplified device operation without compromising security, as the extracted portion alone cannot facilitate fraudulent transactions.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If a partial passcode is stored on the mobile device, then the security is improved, but the device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of storing the full passcode or complex cryptographic structures on the device, a simplified copy of only the necessary passcode subset is stored. This copying approach reduces device complexity while maintaining security, as the stored copy is insufficient for fraudulent transactions without the additional data at the financial institution.

Inventive Principle:
Principle #26Copying

3Reliability

If the full passcode is required for each transaction, then the security is maintained, but the ease of operation is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Instead of requiring the full passcode for each transaction, only a partial subset of passcode characters is required. This partial action approach improves ease of operation by reducing the user input burden while maintaining security, as the partial passcode alone cannot be used for fraudulent transactions without the complete authentication data at the financial institution.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20240127236A1Communications Device, Point Of Sale Device, Payment Device and Methods
Publication Date: 2024.04.18 VOCALINK INT LTD
  • US20240127236A1 patent drawing
  • US20240127236A1 patent drawing
  • US20240127236A1 patent drawing

AI summary

A communications device for implementing an electronic payment process, the communications device including a receiver unit operable to receive a secure limited use key (SLUK) from a financial institution that is generated by the financial institution using a first limited use key (LUK) generated using a first key associated with the financial institution, an identifier which identifies a user of the communications device, and a variable code, and a subset of the characters of a passcode associated with the user of the communications device, each character in the subset being identified by its character position in the passcode, and the character position in the passcode of each of the characters in the subset being determined by a predetermined algorithm on the basis of a second key associated with the user of the communications device, the identifier which identifies the user of the communications device and the variable code.