Transaction Authorization via Private-Key Code Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing transaction security methods, such as one-time passwords (OTPs), fail to protect sensitive data from interception, especially when used on unsecured or unknown networks, and require users to share personal and banking information, which can be vulnerable to interception.
Innovation Solution
A method and system that uses a private key-based code comparison between a trusted terminal and a transaction device, where codes are transmitted via multimedia content, allowing secure authorization without sharing sensitive data on potentially insecure networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If OTP is used for transaction security, then authentication security is improved, but sensitive data remains vulnerable to interception on unsecured networks
Solution Approach 1:
The invention extracts the sensitive authentication data (banking information, personal data) from the transaction flow on unsecured networks. Instead of transmitting sensitive data through the potentially compromised first terminal, the system uses a trusted second terminal to capture and transmit only a one-time code, leaving the sensitive data stored securely in the intermediary's database.
Solution Approach 2:
The invention introduces a trusted intermediary (banking organization or payment service provider) that mediates between the client and merchant. The intermediary securely stores sensitive data and only transmits one-time codes through the unsecured network, acting as a protective intermediary that prevents direct exposure of sensitive information.
2Ease of operation
If sensitive data is transmitted through unsecured terminals or networks, then transaction convenience is improved, but security is compromised
Solution Approach 1:
The invention segments the transaction process into two distinct paths: initialization on the convenient first terminal (unsecured) and authentication on the trusted second terminal (secured). This segmentation allows users to benefit from the convenience of unsecured terminals for browsing while maintaining security through a separate authenticated path.
Solution Approach 2:
The system performs preliminary actions by pre-storing sensitive data securely in the intermediary's database before the transaction occurs. When a transaction is initiated, the system only needs to transmit a one-time code rather than re-transmitting sensitive data, having already prepared the secure authentication mechanism in advance.
3Reliability
If OTP is transmitted through SMS to confirm transactions, then authentication is improved, but the system cannot prevent interception of sensitive data entered before OTP transmission
Solution Approach 1:
Instead of transmitting the original sensitive data through the unsecured network, the system creates a copy in the form of a one-time code that is stored securely in the intermediary's database. This copy can be transmitted safely without exposing the original sensitive information, as the intermediary controls the transmission based on authenticated requests.
Data Source
AI summary
A method for securing a transaction between a terminal, in particular of a first user, and a device, in particular of a second user, via a server, in particular of a third-party entity. The method includes comparing: a first series of codes drawn from a private key and associated with the transaction device transmitted from the server to the transaction device, and a second series of codes received by the server from a terminal, in particular of the first user. The comparison triggers in case of a match between the two series of codes, associating the second terminal, the transaction device and the transaction, making it possible to issue an authorization to continue the transaction between the second terminal and the transaction device associated by the server.

