Hands-Free Access Code Authentication System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current fraud prevention techniques for payment credentials are inadequate, as they often require users to enter sensitive information, which can be stolen by fraudsters, and additional authentication methods can slow down transactions, reducing user interactions and increasing vulnerability to skimming devices.
Innovation Solution
A method and system for hands-free interaction using a user device to request and receive a one-time access code for transactions, which is validated and associated with an expiration time, eliminating the need for physical cards and enhancing security through multiple authentication points.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If additional authentication techniques are implemented to protect payment credentials, then security is improved, but transaction speed deteriorates and user interactions are reduced
Solution Approach 1:
The system performs authentication actions in advance by sending access codes to the user's device before the transaction occurs. The user receives and stores the access code, then simply enters it at the access device during the transaction, eliminating the need for real-time complex authentication processes and thereby maintaining both security and transaction speed
2Reliability
If users enter sensitive information during transactions, then authentication is achieved, but vulnerability to fraud and skimming devices increases
Solution Approach 1:
The system extracts sensitive information (account numbers, PINs) from the transaction process entirely. Instead of requiring users to enter sensitive data at the access device, the system uses a separate access code transmitted to the user's device, which can be entered without exposing other sensitive account information, thereby reducing fraud vulnerability while maintaining authentication
Solution Approach 2:
The access code serves as an intermediary element between the user's sensitive account information and the access device. The code is transmitted through a secure channel to the user's device and then used at the access device without exposing the underlying sensitive account data, creating a protective layer against skimming and fraud
Data Source
AI summary
A method is disclosed. One embodiment of the invention is directed to a method. The method comprises: prompting, by an access device, a user to enter an access code; receiving, by the access device, the access code from the user; transmitting, by the access device, the access code to a validation computer, which validates the access code; receiving, by the access device, an access identifier or access token from the validation computer in response to validating the access code; transmitting, by the access device, an authorization request message including the access identifier or the access token to an authorizing computer; and receiving, by the access device, an authorization response message from the authorizing computer.


