Transaction Restriction Authorization via Dual-Key Security Module
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing payment systems lack secure methods to authorize changes to transaction restrictions, leaving users vulnerable to unauthorized changes when passwords and account numbers are compromised alongside stolen payment instruments.
Innovation Solution
A system comprising a security module that securely stores encryption keys on a designated computer, which validates user authentication using a first encryption key and authorizes changes to transaction restrictions using a second encryption key, ensuring that only the designated computer can modify the restrictions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If online authorization is used to change transaction restrictions, then user convenience is improved, but security is worsened due to risk of password and account number compromise
Solution Approach 1:
The authorization process is segmented into two independent components: authentication (verifying user identity) and authorization (validating computer designation). The security module separates the authentication validation from the authorization decision, requiring both steps to be completed successfully. This segmentation ensures that even if authentication credentials are compromised, unauthorized changes cannot occur without the designated computer's involvement.
Solution Approach 2:
The security module acts as an intermediary between the user's authentication credentials and the transaction restriction changes. It receives authentication information, validates it against stored credentials, checks the computer designation, and only then permits the authorization. This intermediary layer adds a security checkpoint that prevents direct manipulation of transaction restrictions even if authentication credentials are stolen.
2Ease of operation
If authentication credentials are stored centrally, then ease of verification is improved, but vulnerability to theft is worsened
Solution Approach 1:
The system performs preliminary actions by securely storing authentication credentials and computer designation information in the security module before any authorization request occurs. When a user seeks to change transaction restrictions, the pre-stored credentials are immediately available for validation without requiring additional data collection or transmission, thus maintaining verification efficiency while securing the credentials in advance.
Data Source
AI summary
An apparatus, system, and method are disclosed for securely authorizing changes to a transaction restriction. A security module securely stores encryption keys for a payment instrument. The payment instrument electronically transacts payments and includes a transaction restriction. An authentication module receives an authentication from a user of the payment instrument. The security module validates the authentication with a first encryption key. In addition, the security module authorizes a change to the transaction restriction using a second encryption key if the authentication is valid. The security module resides on a computer that the user designates as authorized to validate the authentication.


