Authentication Device Using Environmental Fingerprints for Passive Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Three-Domain Secure (3DS) 2.0 protocol requires users to actively respond to authentication challenges for high-risk card-not-present transactions, which can be burdensome and vulnerable to phishing attacks, as it relies on customer interaction and may not verify the authentication window effectively.
Innovation Solution
Implementing a system that uses active and passive authentication techniques by gathering information from devices connected to or in proximity to the user's device, generating an environmental fingerprint, and having registered devices respond to authentication challenges on behalf of the user, reducing user interaction and enhancing security by verifying the user's presence through device responses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If 3DS 2.0 protocol requires users to actively respond to authentication challenges, then security verification is improved, but user burden and vulnerability to phishing attacks increase
Solution Approach 1:
The system enables self-service authentication where the authentication device automatically responds to authentication challenges without requiring active user input. The device uses stored authentication credentials and environmental fingerprints to autonomously verify transactions, eliminating the need for users to manually interact with authentication windows while maintaining security verification.
Solution Approach 2:
The authentication device serves as an intermediary between the user and the authentication system. It stores authentication credentials and automatically manages the authentication process by responding to challenges on behalf of the user, thereby reducing direct user interaction while maintaining security. The device mediates the authentication process by using environmental fingerprints and stored credentials to verify transactions autonomously.
2Measurement precision
If 3DS 2.0 uses contextual data to assess transaction risk, then authentication accuracy is improved, but customer interaction requirements increase
Solution Approach 1:
The authentication device automatically performs risk assessment by analyzing contextual data and environmental fingerprints without requiring customer interaction. The system autonomously determines whether a transaction is high-risk and responds to authentication challenges accordingly, eliminating the need for customers to actively participate in the risk assessment process while maintaining accurate transaction verification.
Solution Approach 2:
The system performs preliminary authentication by storing authentication credentials and environmental fingerprints in advance. When a transaction occurs, the pre-stored information is automatically used to assess risk and respond to authentication challenges, eliminating the need for customers to interact with the system during the transaction process while maintaining accurate risk assessment.
3Reliability
If authentication challenges are required for high-risk transactions, then security verification is improved, but transaction processing time increases
Solution Approach 1:
Authentication credentials and environmental fingerprints are stored in advance in the authentication device. When a high-risk transaction occurs, the pre-stored information enables rapid automatic response to authentication challenges without requiring real-time user input or lengthy verification processes, thereby maintaining security while reducing transaction processing time.
Solution Approach 2:
The authentication device autonomously responds to authentication challenges for high-risk transactions using stored credentials and environmental fingerprints, eliminating the need for user interaction during the authentication process. This self-service approach maintains security verification while significantly reducing the time required to process high-risk transactions.
Data Source
AI summary
Devices, methods, computer-readable media, and systems for authenticating users. In one example, a computing device includes an electronic processor and a memory. The electronic processor is configured to receive a registration of an authentication device associated with a user, the authentication device connected to and operable to communicate over a first communications network, control the memory to store the registration of the authentication device, receive a transaction request by the user, responsive to receiving the transaction request, request an authentication operation to be performed by the authentication device, receive a result of the authentication operation performed by the authentication device, determine whether the result validates the transaction request by the user, and permit the transaction request by the user in response to determining that the result validates the transaction request by the user.


