Two-Device Transaction Authorization via Encrypted Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing transaction authorization methods, such as m-TAN and PUSH-TAN, face limitations in security and mobility, as they either restrict device usage or may not provide sufficient security when transactions are initiated on a single device, and users are constrained by the need for larger devices for inputting transaction data.

Innovation Solution

A method utilizing two mobile devices, where transaction data are input on a first device, transmitted to a background system, and a password is encrypted and passed through the first device to a second device for authorization, ensuring secure and mobile transaction execution, with the second device maintaining direct encrypted communication with the background system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the user employs a single mobile device for both inputting transaction data and receiving the password, then the ease of operation is improved, but the security is worsened because malware on the device can access the password

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the transaction process into two distinct mobile devices: a first device for inputting transaction data and a second device for receiving and displaying the password. This segmentation ensures that even if malware is present on the first device, it cannot access the password transmitted to the second device, as the password transmission is encrypted and routed through a background system rather than directly through the first device's processing channels.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A background system acts as an intermediary between the first mobile device and the second mobile device. The password is transmitted from the first device through this intermediary to the second device via encrypted over-the-air interfaces. This intermediary approach prevents direct access to the password on the first device, as the data passes through encrypted channels managed by the background system rather than being processed in plain text on the first device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the user must employ a larger device like a computer or tablet PC for inputting transaction data, then the security is improved, but the mobility and ease of operation are worsened

Engineering Contradiction:
ImprovesecurityVSAvoidmobility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments the transaction authorization process across two mobile devices, allowing the first device (which can be a small mobile phone) to handle transaction data input while a separate second device receives the password. This eliminates the requirement for a large device, as the security-critical password transmission is isolated to a separate device, enabling users to perform transactions on compact mobile devices without compromising security.

Inventive Principle:
Principle #1Segmentation

3Device complexity

If the user employs a single mobile device for the entire transaction process, then the device complexity is reduced, but the security level is worsened as sufficient security cannot be attained

Engineering Contradiction:
Improvedevice complexityVSAvoidsecurity level
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

Instead of using a single device with complex security measures, the system segments the transaction process across two simpler mobile devices. The first device handles transaction data input and the second device receives the password through encrypted over-the-air transmission via a background system. This segmentation approach achieves higher security levels while keeping each individual device relatively simple in design and function.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10050790B2Method for authorizing a transaction
Publication Date: 2018.08.14 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • US10050790B2 patent drawing
  • US10050790B2 patent drawing

AI summary

A method for authorizing a transaction has the following steps: inputting transaction data on a first mobile device, transmitting the transaction data from the first device to a background system by means of a first over-the-air interface, transmitting in encrypted manner at least a password to a second mobile device through the intermediary of the first mobile device, and authorizing the transaction by inputting the password displayed on the second device on the first device.