Settlement Server Authentication Security via Dynamic Verification Codes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing code settlement systems risk exposing settlement number and timestamp information, compromising security during offline transactions.
Innovation Solution
A settlement server that transmits key information to user terminals, generates multiple authentication pieces based on key information and different time information, and performs settlement processing using verification results from shop terminals, ensuring security by not revealing time information content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the shop POS system acquires settlement number and timestamp information from a code image for settlement processing, then settlement functionality is achieved, but security is compromised because the shop POS system knows sensitive information
Solution Approach 1:
The patent extracts only the necessary settlement verification functionality from the shop POS system by replacing sensitive authentication data (settlement number and timestamp) with a verification code that contains no exploitable information. The shop terminal reads the verification code from the code image and sends it to the settlement server for validation, removing the exposure risk while preserving settlement capability.
Solution Approach 2:
The verification code acts as an intermediary between the user terminal and shop terminal. Instead of directly exposing settlement number and timestamp information, the system uses this intermediate verification code that the shop terminal can read and transmit without understanding its internal structure, thereby preventing information leakage while enabling authentication.
2Reliability
If multiple pieces of authentication information are generated based on different time information, then security is improved by preventing unauthorized access, but system complexity increases
Solution Approach 1:
The system implements dynamic authentication by generating verification codes that are valid only within specific time windows. The verification code incorporates time information that changes periodically, making each code unique to its time slot. This dynamic approach enhances security without requiring complex multi-factor authentication systems.
Solution Approach 2:
The patent changes the time parameter dynamically to generate different verification codes. By incorporating time-stamped information into the verification code generation process, the system creates authentication credentials that are valid only for specific time periods, preventing replay attacks while maintaining relatively simple system architecture.
Data Source
AI summary
To improve the security during code settlement, a settlement server includes: a memory storing a program; and at least one processor that, by executing the program stored in the memory, is configured to: transmit key information to a user terminal used by a user; receive from a shop terminal a settlement request containing authentication information generated based on the key information and predetermined time information, and a user identifier of the user; generate a plurality of pieces of authentication information based on the key information and a plurality of different pieces of time information; and that perform settlement processing for the user using a verification result of the plurality of pieces of authentication information and authentication information received from the shop terminal.


