Acquirer-Based Mobile Device Authentication for Payment Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for online transactions using mobile devices lack effective device authentication methods, leading to potential fraud and security risks, particularly in verifying the authenticity of mobile devices and payment credentials.

Innovation Solution

A payment system that includes an acquirer portion, a payment network portion, and an issuer portion, which communicates to authenticate mobile devices by receiving and validating mobile device credentials, payment credentials, and transaction data, utilizing risk management services to assess the trustworthiness of devices and authorize transactions based on device fingerprints, locale data, and other identifying factors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional online transaction systems are used without device authentication, then transaction simplicity is maintained, but security and fraud prevention are compromised

Engineering Contradiction:
Improvetransaction securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs device authentication and credential verification before the actual transaction processing. The acquirer portion receives and validates mobile device credentials and payment credentials in advance, establishing device trustworthiness prior to authorizing the transaction. This preliminary authentication ensures security without complicating the user experience during the actual payment process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication layer between the merchant and the payment network. The acquirer portion acts as a mediator that receives transaction data from the merchant, obtains device credentials from the mobile device, validates them against stored profiles, and only then forwards authenticated transactions to the payment network for processing. This intermediary layer enhances security while maintaining system simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If device authentication is implemented, then fraud detection capability is improved, but processing time increases

Engineering Contradiction:
Improvefraud detection accuracyVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Device credentials and identifiers are captured and pre-validated before the transaction is submitted to the payment network. The acquirer portion maintains a profile of mobile device identifiers and pre-authenticates them, so that during the actual transaction, the verification process is expedited rather than initiated from scratch. This reduces processing time while maintaining fraud detection accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces manual or step-by-step authentication processes with automated electronic verification. The acquirer portion electronically receives mobile device credentials, automatically compares them against stored profiles, and instantly determines device trustworthiness without requiring manual intervention or sequential verification steps, thereby minimizing processing time delays.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10776785B2Systems and methods for device authentication
Publication Date: 2020.09.15 JPMORGAN CHASE BANK NA
  • US10776785B2 patent drawing
  • US10776785B2 patent drawing
  • US10776785B2 patent drawing

AI summary

Systems and methods for device authentication are disclosed. In one embodiment, a method may include (1) an acquirer portion receiving a device credential and a payment credential that were received from the payment application in conjunction with a transaction, the acquirer portion further receiving transaction data for the transaction from the merchant; (2) the acquirer portion performing a first validation assessment on the transaction based on the transaction data and first data retrieved from a first data source; (3) the payment network portion performing a second validation assessment on the transaction based on the transaction data and second data retrieved from a second data source; and (4) the issuer portion identifying and authenticating the customer based on the device credential, the payment credential, and at least one of the first validation assessment and the second validation assessment.