Contactless Card Authentication for Faster Secure Call Center Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Call centers face significant security risks due to internal employee theft and external hacking, with existing authentication methods frustrating customers and exposing sensitive information to malicious parties, and the Payment Card Industry Security Standards Council (PCI SSC) mandates robust authentication protocols.
Innovation Solution
A call center system uses a mini-application or code snippet, such as an Apple® App Clip® or Google® Instant App®, to authenticate customers via a contactless card, minimizing download times and storage requirements by leveraging near-field communication (NFC) to securely exchange authentication information without a bulky application.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods (passwords, personal questions, biometric data) are used multiple times during call center interactions, then authentication security is maintained, but customer frustration increases and service quality degrades
Solution Approach 1:
The system performs authentication before the call is fully established by utilizing metadata from the incoming call (caller ID, device information) to pre-validate the customer identity. This preliminary authentication occurs automatically without requiring the customer to provide credentials during the call, thus maintaining security while improving service quality.
Solution Approach 2:
The authentication system operates autonomously by automatically verifying customer identity using pre-collected device metadata and authentication tokens stored on the customer's device. The system self-validates without requiring customer participation beyond the initial call, eliminating repetitive authentication prompts and reducing customer frustration.
2Reliability
If a full authentication application is downloaded to the mobile device, then secure authentication can be performed, but download time increases and storage requirements increase
Solution Approach 1:
The patent extracts the essential authentication functionality from a full application and implements it as a lightweight code snippet or mini-program that runs within the existing call center application. This extracted authentication module contains only the necessary logic to generate and verify authentication tokens, eliminating the need for customers to download and install separate authentication applications.
Solution Approach 2:
The authentication system leverages existing infrastructure and components already present in the call center application and mobile device operating system. By reusing existing security protocols, communication interfaces, and device capabilities, the system achieves secure authentication without requiring additional dedicated application code, thereby reducing download time and storage requirements.
3Ease of operation
If employee access to sensitive customer data is maintained for service purposes, then customer service functionality is preserved, but internal security risks from employee theft increase
Solution Approach 1:
The system performs customer authentication before any sensitive data is accessed or displayed to the employee. The authentication token is validated in advance, and only after successful verification is the customer identity confirmed and data access permitted. This preliminary security check ensures that even if employees have system access, they cannot view or misuse customer information without valid authentication.
Solution Approach 2:
The patent introduces an authentication token as an intermediary between the customer and the sensitive data. The token acts as a mediator that must be present and valid for data access to occur. This intermediary layer decouples employee system access from actual customer data visibility, allowing employees to maintain service functionality while preventing unauthorized data exposure through the requirement of valid customer authentication.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This method enhances security by authenticating customers efficiently and securely, reducing the risk of data exposure while improving user experience by minimizing application size and download times.
Implementation Method 1
leveraging near-field communication (NFC) to securely exchange authentication information
Data Source
AI summary
Techniques and systems to perform authentication utilizing a mini-application.


