Authentication Server for Mobile Transaction Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional remote payment transactions face challenges such as high costs and transaction delays due to the need for substantial resources to verify consumer identity, and mobile wallet providers bear the risk of unauthorized transactions without effective validation methods.

Innovation Solution

A method and system that utilize an authentication server to receive transaction details, initiate authentication requests on a consumer's mobile device, and send authorization messages to the issuer, incorporating personal identifiers and biometric data to validate transactions before authorization, thereby shifting liability and improving security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If issuers devote substantial resources to provide authentication services to verify consumer identity, then authentication reliability is improved, but transaction processing time and costs increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs authentication in advance by sending authentication requests to the consumer's mobile device before the actual transaction processing. The consumer provides personal identifiers (PIN, password, or biometric data) that are verified by the authentication server computer. This preliminary authentication ensures reliability while enabling faster subsequent transaction processing, as the authentication status is already established.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An authentication server computer is introduced as an intermediary between the issuer and the consumer's mobile device. This server receives authentication requests, verifies personal identifiers, and communicates authentication results back to the issuer. By offloading authentication processing to a dedicated intermediary server, the issuer's processing time is reduced while maintaining authentication reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If wallet providers bear the cost of unauthorized transactions without validation methods, then transaction volume can increase, but financial loss increases

Engineering Contradiction:
Improvetransaction volumeVSAvoidfinancial loss
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The system performs preliminary authentication validation before authorizing transactions. The authentication server computer verifies the consumer's personal identifier and returns an authentication indicator to the wallet provider. This advance validation ensures that only authenticated consumers can initiate transactions, preventing unauthorized transactions while maintaining high transaction volume capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication server computer provides feedback in the form of authentication indicators to the wallet provider. These indicators confirm whether the consumer has been successfully authenticated, enabling the wallet provider to make informed decisions about transaction authorization. This feedback mechanism eliminates financial loss from unauthorized transactions while preserving productivity.

Inventive Principle:
Principle #23Feedback

3Reliability

If traditional authentication methods are used for remote transactions, then security can be maintained, but device complexity and integration requirements increase

Engineering Contradiction:
Improvetransaction securityVSAvoidsystem integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication server computer provides a universal authentication service that can be accessed by multiple wallet providers and issuers through a standardized interface. The system supports multiple authentication methods (PIN, password, biometric data) through a single platform, eliminating the need for each entity to develop and integrate separate authentication systems. This reduces device complexity while maintaining transaction security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11978051B2Authenticating remote transactions using a mobile device
Publication Date: 2024.05.07 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11978051B2 patent drawing
  • US11978051B2 patent drawing
  • US11978051B2 patent drawing

AI summary

Embodiments of the invention can combine card not present transaction processing with PIN verification. A merchant or a consumer can initiate transactions using any suitable transaction initiation channel. One aspect of the invention helps facilitate payment card authentication across multiple wallet providers/merchants using an encrypted card PIN and a digital certificate. One aspect of the invention can incorporate the use of different transaction networks to perform authentication and authorization processing.