Settlement Server Authentication Security via Dynamic Verification Codes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing code settlement systems risk exposing settlement number and timestamp information, compromising security during offline transactions.

Innovation Solution

A settlement server that transmits key information to user terminals, generates multiple authentication pieces based on key information and different time information, and performs settlement processing using verification results from shop terminals, ensuring security by not revealing time information content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the shop POS system acquires settlement number and timestamp information from a code image for settlement processing, then settlement functionality is achieved, but security is compromised because the shop POS system knows sensitive information

Engineering Contradiction:
Improvesettlement securityVSAvoidinformation exposure
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts only the necessary settlement verification functionality from the shop POS system by replacing sensitive authentication data (settlement number and timestamp) with a verification code that contains no exploitable information. The shop terminal reads the verification code from the code image and sends it to the settlement server for validation, removing the exposure risk while preserving settlement capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The verification code acts as an intermediary between the user terminal and shop terminal. Instead of directly exposing settlement number and timestamp information, the system uses this intermediate verification code that the shop terminal can read and transmit without understanding its internal structure, thereby preventing information leakage while enabling authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple pieces of authentication information are generated based on different time information, then security is improved by preventing unauthorized access, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements dynamic authentication by generating verification codes that are valid only within specific time windows. The verification code incorporates time information that changes periodically, making each code unique to its time slot. This dynamic approach enhances security without requiring complex multi-factor authentication systems.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the time parameter dynamically to generate different verification codes. By incorporating time-stamped information into the verification code generation process, the system creates authentication credentials that are valid only for specific time periods, preventing replay attacks while maintaining relatively simple system architecture.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240169346A1Settlement server, settlement method, and storage medium
Publication Date: 2024.05.23 RAKUTEN GROUP INC
  • US20240169346A1 patent drawing
  • US20240169346A1 patent drawing
  • US20240169346A1 patent drawing

AI summary

To improve the security during code settlement, a settlement server includes: a memory storing a program; and at least one processor that, by executing the program stored in the memory, is configured to: transmit key information to a user terminal used by a user; receive from a shop terminal a settlement request containing authentication information generated based on the key information and predetermined time information, and a user identifier of the user; generate a plurality of pieces of authentication information based on the key information and a plurality of different pieces of time information; and that perform settlement processing for the user using a verification result of the plurality of pieces of authentication information and authentication information received from the shop terminal.