Authentication Device-Assisted Transaction Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current financial transaction systems lack robust authentication methods, making them vulnerable to fraud, especially when payment credentials are exchanged without secure verification of the user's identity.
Innovation Solution
A financial institution computing system that utilizes an authentication device, separate from the customer computing device, to provide identification codes for authenticating transactions, incorporating biometric data and dynamic codes to ensure only authorized users can complete transactions, thereby enhancing security and fraud prevention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional payment credential exchange methods are used without additional authentication, then transaction ease is improved, but security and fraud prevention deteriorate
Solution Approach 1:
The system performs preliminary authentication actions before the actual transaction occurs. The authentication device captures biometric data and generates authentication codes in advance, ensuring that verification is completed before payment credentials are exchanged or transactions are authorized, thus maintaining both ease of operation and security
Solution Approach 2:
The authentication device serves as an intermediary between the customer computing device and the financial institution computing system. It mediates the authentication process by generating and transmitting authentication codes without requiring direct interaction between the customer device and the financial system, thereby maintaining transaction ease while enhancing security
2Reliability
If separate authentication device is introduced in addition to customer computing device, then security is improved, but device complexity increases
Solution Approach 1:
The authentication function is extracted from the customer computing device and placed into a separate authentication device. This extraction allows the main computing device to remain simple while the dedicated authentication device handles security functions, resolving the contradiction between security enhancement and system complexity
Solution Approach 2:
The authentication device is designed to perform multiple functions including biometric data capture, authentication code generation, and secure transmission. This multi-functionality consolidates security operations into a single device, reducing overall system complexity while maintaining enhanced security
3Reliability
If biometric data and dynamic codes are used for authentication, then fraud prevention is improved, but authentication time increases
Solution Approach 1:
Biometric data is captured and authentication codes are generated in advance before the transaction occurs. This preliminary action ensures that when a transaction needs to be completed, the authentication process is already prepared or can be quickly finalized, reducing actual authentication time while maintaining high fraud prevention standards
Solution Approach 2:
The system replaces traditional mechanical authentication methods (such as physical card swiping or manual PIN entry) with biometric recognition and automated code generation. This substitution speeds up the authentication process while enhancing fraud prevention, as biometric verification is faster and more secure than manual methods
Data Source
AI summary
A computing system includes a customer database and a token vault and is configured to provision a single use token to a customer computing device, receive, from a transaction terminal over a network, a transaction request specifying the single use token and including an identification code generated by an authentication device, detokenize the single use token, authenticate, based on the identification code and the single use token, the transaction request by determining that the identification code is associated with an authorized user and that an authorized financial account is associated with the single use token specified in the transaction request, authorize the transaction request based on the transaction request being authenticated, and transmit a confirmation to the transaction terminal over the network.


