Wireless Device Authorization via Dynamic Data Stripe

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures for financial transactions, such as CVV and PIN, are insufficient to prevent fraudulent activities, as they do not provide adequate protection against unauthorized access and misuse of account data.

Innovation Solution

A system that uses a processor on a wireless communications device to execute an application connected to a data stripe, which requires a passcode entry for enabling data communication, generates an authorization code, and can change account data for each transaction, thereby enhancing security by preventing malicious use of account information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures (CVV, PIN) are used for financial transactions, then the system is simple to operate, but the security against fraudulent transactions is insufficient

Engineering Contradiction:
Improvesecurity against fraudulent transactionsVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security measures where the wireless communications device can dynamically enable/disable the data stripe, dynamically change account data, and dynamically generate authorization codes based on real-time transaction evaluation. This dynamic approach enhances security adaptability while managing system complexity through programmable control.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The application executed on the wireless communications device serves as an intermediary between the data stripe and the transaction authorization system. It mediates by evaluating transaction criteria, controlling data stripe communication, modifying account data, and generating authorization codes, thereby enhancing security without requiring fundamental system redesign.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If passcode security is implemented before enabling data stripe communication, then the security level is improved, but the ease of operation is reduced

Engineering Contradiction:
Improvepasscode securityVSAvoidease of data communication
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary security actions by requiring passcode entry before enabling the data stripe to communicate account data. This preliminary authentication ensures that only authorized users can initiate transactions, balancing security requirements with operational convenience through pre-established security protocols.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If account data is changed for each transaction, then the prevention of fraudulent use is improved, but the processing time is increased

Engineering Contradiction:
Improveprevention of fraudulent useVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements periodic changes to account data for each transaction, creating a rhythm of data modification that prevents fraudulent reuse. This periodic action ensures that even if authorization codes are intercepted, they become invalid after use, balancing security enhancement with acceptable processing time through efficient data rotation.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS8616444B2Authorizing financial transactions
Publication Date: 2013.12.31 BANK OF AMERICA CORP
  • US8616444B2 patent drawing
  • US8616444B2 patent drawing
  • US8616444B2 patent drawing

AI summary

A system for authorizing a financial transaction includes a processor operable to execute an application on a wireless communications device that is communicatively coupled to a data stripe through a wired connection, receive a request to authorize a financial transaction involving a financial account associated with account data, access authorization criteria for determining whether to authorize the financial transaction, apply the authorization criteria to the financial transaction, generate an authorization code based on the application of the authorization criteria to the financial transaction, and communicate the authorization code.