Authentication Device Using Environmental Fingerprints for Passive Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Three-Domain Secure (3DS) 2.0 protocol requires users to actively respond to authentication challenges for high-risk card-not-present transactions, which can be burdensome and vulnerable to phishing attacks, as it relies on customer interaction and may not verify the authentication window effectively.

Innovation Solution

Implementing a system that uses active and passive authentication techniques by gathering information from devices connected to or in proximity to the user's device, generating an environmental fingerprint, and having registered devices respond to authentication challenges on behalf of the user, reducing user interaction and enhancing security by verifying the user's presence through device responses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If 3DS 2.0 protocol requires users to actively respond to authentication challenges, then security verification is improved, but user burden and vulnerability to phishing attacks increase

Engineering Contradiction:
Improveauthentication securityVSAvoiduser interaction burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service authentication where the authentication device automatically responds to authentication challenges without requiring active user input. The device uses stored authentication credentials and environmental fingerprints to autonomously verify transactions, eliminating the need for users to manually interact with authentication windows while maintaining security verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The authentication device serves as an intermediary between the user and the authentication system. It stores authentication credentials and automatically manages the authentication process by responding to challenges on behalf of the user, thereby reducing direct user interaction while maintaining security. The device mediates the authentication process by using environmental fingerprints and stored credentials to verify transactions autonomously.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If 3DS 2.0 uses contextual data to assess transaction risk, then authentication accuracy is improved, but customer interaction requirements increase

Engineering Contradiction:
Improvetransaction risk assessment accuracyVSAvoidcustomer interaction
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The authentication device automatically performs risk assessment by analyzing contextual data and environmental fingerprints without requiring customer interaction. The system autonomously determines whether a transaction is high-risk and responds to authentication challenges accordingly, eliminating the need for customers to actively participate in the risk assessment process while maintaining accurate transaction verification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary authentication by storing authentication credentials and environmental fingerprints in advance. When a transaction occurs, the pre-stored information is automatically used to assess risk and respond to authentication challenges, eliminating the need for customers to interact with the system during the transaction process while maintaining accurate risk assessment.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If authentication challenges are required for high-risk transactions, then security verification is improved, but transaction processing time increases

Engineering Contradiction:
Improvetransaction verification securityVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication credentials and environmental fingerprints are stored in advance in the authentication device. When a high-risk transaction occurs, the pre-stored information enables rapid automatic response to authentication challenges without requiring real-time user input or lengthy verification processes, thereby maintaining security while reducing transaction processing time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication device autonomously responds to authentication challenges for high-risk transactions using stored credentials and environmental fingerprints, eliminating the need for user interaction during the authentication process. This self-service approach maintains security verification while significantly reducing the time required to process high-risk transactions.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20240232885A1Devices, methods, computer-readable media, and systems for authenticating users
Publication Date: 2024.07.11 MASTERCARD TECHNOLOGIES CANADA ULC
  • US20240232885A1 patent drawing
  • US20240232885A1 patent drawing
  • US20240232885A1 patent drawing

AI summary

Devices, methods, computer-readable media, and systems for authenticating users. In one example, a computing device includes an electronic processor and a memory. The electronic processor is configured to receive a registration of an authentication device associated with a user, the authentication device connected to and operable to communicate over a first communications network, control the memory to store the registration of the authentication device, receive a transaction request by the user, responsive to receiving the transaction request, request an authentication operation to be performed by the authentication device, receive a result of the authentication operation performed by the authentication device, determine whether the result validates the transaction request by the user, and permit the transaction request by the user in response to determining that the result validates the transaction request by the user.