Two-Device Transaction Authorization via Encrypted Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing transaction authorization methods, such as m-TAN and PUSH-TAN, face limitations in security and mobility, as they either restrict device usage or may not provide sufficient security when transactions are initiated on a single device, and users are constrained by the need for larger devices for inputting transaction data.
Innovation Solution
A method utilizing two mobile devices, where transaction data are input on a first device, transmitted to a background system, and a password is encrypted and passed through the first device to a second device for authorization, ensuring secure and mobile transaction execution, with the second device maintaining direct encrypted communication with the background system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the user employs a single mobile device for both inputting transaction data and receiving the password, then the ease of operation is improved, but the security is worsened because malware on the device can access the password
Solution Approach 1:
The system segments the transaction process into two distinct mobile devices: a first device for inputting transaction data and a second device for receiving and displaying the password. This segmentation ensures that even if malware is present on the first device, it cannot access the password transmitted to the second device, as the password transmission is encrypted and routed through a background system rather than directly through the first device's processing channels.
Solution Approach 2:
A background system acts as an intermediary between the first mobile device and the second mobile device. The password is transmitted from the first device through this intermediary to the second device via encrypted over-the-air interfaces. This intermediary approach prevents direct access to the password on the first device, as the data passes through encrypted channels managed by the background system rather than being processed in plain text on the first device.
2Reliability
If the user must employ a larger device like a computer or tablet PC for inputting transaction data, then the security is improved, but the mobility and ease of operation are worsened
Solution Approach 1:
The system segments the transaction authorization process across two mobile devices, allowing the first device (which can be a small mobile phone) to handle transaction data input while a separate second device receives the password. This eliminates the requirement for a large device, as the security-critical password transmission is isolated to a separate device, enabling users to perform transactions on compact mobile devices without compromising security.
3Device complexity
If the user employs a single mobile device for the entire transaction process, then the device complexity is reduced, but the security level is worsened as sufficient security cannot be attained
Solution Approach 1:
Instead of using a single device with complex security measures, the system segments the transaction process across two simpler mobile devices. The first device handles transaction data input and the second device receives the password through encrypted over-the-air transmission via a background system. This segmentation approach achieves higher security levels while keeping each individual device relatively simple in design and function.
Data Source
AI summary
A method for authorizing a transaction has the following steps: inputting transaction data on a first mobile device, transmitting the transaction data from the first device to a background system by means of a first over-the-air interface, transmitting in encrypted manner at least a password to a second mobile device through the intermediary of the first mobile device, and authorizing the transaction by inputting the password displayed on the second device on the first device.

