Single-Use Token Authentication to Replace Static Credentials
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for online transactions using static information, such as account numbers and security codes, are vulnerable to fraud and require tedious entry, leading to security breaches and user inconvenience.
Innovation Solution
A system that uses single-use tokens generated by a financial services system to replace static information, authenticated through a digital wallet and payment application, ensuring secure transactions by establishing proximity between devices using short-range wireless connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static information such as account numbers and security codes is used for authentication, then the authentication process is simple to implement, but the system becomes vulnerable to fraud and security breaches
Solution Approach 1:
The patent transforms static authentication information into dynamic single-use tokens that change with each transaction. The token generation system creates unique tokens for each authentication event, making the authentication data dynamic rather than static, thereby preventing fraud while maintaining simplicity.
Solution Approach 2:
The system changes the parameter of authentication data from static (account numbers, security codes) to dynamic (single-use tokens with unique identifiers). This parameter change ensures that each authentication attempt uses different data, eliminating the vulnerability to fraud while keeping the implementation straightforward.
2Ease of operation
If static information is used for authentication, then the implementation is straightforward, but the user experience becomes tedious due to manual entry requirements
Solution Approach 1:
The system performs preliminary action by pre-generating and storing single-use tokens in the user's device before they are needed for authentication. When a transaction occurs, the token is automatically retrieved and used, eliminating the need for manual entry of authentication information and improving user convenience.
Solution Approach 2:
The authentication system enables self-service by allowing the user's device to automatically retrieve and use single-use tokens without requiring manual input. The device itself manages the authentication process, reducing the time and effort needed for users to complete transactions.
3Reliability
If single-use tokens are implemented to replace static information, then transaction security is enhanced, but the system complexity increases due to token generation and management requirements
Solution Approach 1:
The patent introduces an intermediary token generation system that sits between the user and the authentication process. This intermediary automatically generates and manages single-use tokens, handling the complexity of token creation, storage, and retrieval while presenting a simple interface to the user. The intermediary absorbs the system complexity, keeping the user experience simple.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enhances transaction security and convenience by reducing the need for manual entry of static information, providing an additional layer of security and simplifying the transaction process.
Implementation Method 1
a short-range wireless connection between the first user device and a second user device may be established based on the first user device being proximate to the second user device
Data Source
AI summary
In some embodiments, a request to execute, via a first user device, a secure operation with a computing system may be detected (e.g., where the first user device satisfies a proximity condition with respect to a second user device). Authentication data corresponding to a single use token may be retrieved from the second user device based on (i) the request and (ii) the proximity condition being satisfied (e.g., where the single use token corresponds to static information associated with an account used to perform secure operations). The authentication data corresponding to the single use token may be provided to the computing system. An indication that the secure operation has been authorized may be received based on a verification of the authentication data corresponding to the single use token. The secure operation with the computing system may be executed based on the indication being received.


