Electronic Signature Token for Secure Online Transaction Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online shopping transactions face security risks, including account and password theft, leading to economic losses for both buyers and sellers, as conventional methods fail to ensure secure trading processes.

Innovation Solution

An information processing method and system that uses an electronic signature token to generate and adjust a joint password, which is verified to ensure secure transmission and non-repudiation of transactions, involving multiple terminals and verification devices to preprocess and confirm operations, thereby enhancing transaction security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional online trading methods are used, then the trading process is simple, but the security of account information and transaction integrity cannot be ensured

Engineering Contradiction:
Improvesecurity of account informationVSAvoidcomplexity of trading system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an electronic signature token as an intermediary device between the user and the online trading system. This token generates and manages joint passwords that are used to verify transaction authenticity. The intermediary handles the complex cryptographic operations and security protocols, allowing the user interface to remain simple while achieving high security standards through the mediator's specialized functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If joint password is transmitted in plaintext, then transmission speed is fast, but security risk increases

Engineering Contradiction:
Improvepassword transmission speedVSAvoidsecurity risk of password transmission
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent changes the fundamental parameter of password representation by introducing joint passwords that are mathematically derived from multiple secret components. Instead of transmitting a single static password, the system transmits joint passwords that are computationally infeasible to reverse-engineer even in plaintext form. The security relies on the mathematical properties of the joint password generation algorithm rather than encryption during transmission.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multiple verification devices are used, then transaction security is improved, but operation complexity increases

Engineering Contradiction:
Improvetransaction securityVSAvoidease of trading operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple verification functions into a unified joint password verification process. Instead of requiring separate verification steps for different security concerns, the system combines identity verification, authentication, and transaction authorization into a single joint password check. This consolidation maintains high security through multiple underlying verification mechanisms while presenting a simple, unified interface to the user.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9369463B2Information processing method and system
Publication Date: 2016.06.14 TENDYRON CORP
  • US9369463B2 patent drawing
  • US9369463B2 patent drawing
  • US9369463B2 patent drawing

AI summary

Disclosed are an information processing method and system. The first terminal sends operation request information to an electronic signature token. The electronic signature token generates a joint password and a signature message, adjusts the joint password to obtain a first processing password, and sends the signature message and the first processing password to the first terminal. The first terminal notifies a first verification device to verify the signature message, and if the verification is successful, the first verification device notifies a background system server to preprocess the operation request information for obtaining preprocessed information. The electronic signature token outputs prompt information. A second terminal obtains the joint password according to the prompt information and notifies a second verification device to verify the joint password, and if the verification is successful, the second verification device triggers the background system server to perform a response process of the operation request information.