Authentication Processor for Secure Contactless Debit Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current debit transaction systems face challenges in security and efficiency, particularly in contactless transactions and the use of mobile devices, which can lead to security issues and complications in real-time fund verification.

Innovation Solution

The system employs an authentication processor that enrolls customers using information from both mobile electronic devices and servers, utilizing contactless presentation instruments and mobile devices for secure debit transactions, with features like one-time passwords and cryptographic keys to enhance security and real-time fund verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If contactless presentation instruments and mobile devices are used for debit transactions, then transaction speed and convenience are improved, but security risks increase

Engineering Contradiction:
Improvetransaction speedVSAvoidsecurity risks
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication by obtaining cryptographic keys from the mobile device and verifying them against keys stored in the authentication processor before authorizing the transaction. This preliminary security check ensures that the mobile device is legitimately enrolled and authorized, preventing unauthorized transactions while maintaining fast processing speed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication processor as an intermediary component that mediates between the mobile device and the financial network. This intermediary verifies cryptographic keys and manages security protocols, isolating the security-critical operations from the transaction processing path and enabling fast transactions without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If real-time fund verification is implemented, then merchant risk is reduced, but system complexity increases

Engineering Contradiction:
Improvemerchant risk reductionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the fund verification function from the mobile device and places it in the authentication processor, which already has access to account information. The mobile device only needs to provide cryptographic keys for authentication, while the authentication processor independently verifies funds availability, reducing the complexity burden on the mobile device while ensuring real-time verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system merges the authentication function and fund verification function into a single authentication processor. This consolidation allows the system to perform both cryptographic key verification and fund availability checks in one centralized location, reducing overall system complexity while maintaining real-time verification capabilities.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If cryptographic key verification is performed, then transaction security is improved, but processing time increases

Engineering Contradiction:
Improvetransaction securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs cryptographic key verification as a preliminary step before transaction processing. The authentication processor obtains cryptographic keys from the mobile device and verifies them against stored keys in advance, establishing security credentials before the actual transaction occurs. This preliminary authentication ensures security while allowing subsequent transaction processing to proceed quickly.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8055581B2Management of financial transactions using debit networks
Publication Date: 2011.11.08 FIRST DATA CORP
  • US8055581B2 patent drawing
  • US8055581B2 patent drawing
  • US8055581B2 patent drawing

AI summary

Methods and systems are disclosed of enrolling a customer to perform an action. A first piece of information is received at an authentication processor from an over-the-air processor. The first piece of information was provided to the over-the-air processor by the customer from a mobile electronic device. A second piece of information is received at the authentication processor from a server different from the over-the-air processor. The second piece of information was provided to the server by the customer. The first and second pieces of information are associated by the authentication processor to enroll the customer.