Delegated Credential Authentication for Secure Cross-Device Checkout
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face inefficiencies and security risks when using multiple computing devices for transactions due to differing authentication protocols and insufficient security in device communication channels, particularly in financial transactions involving personally identifiable information.
Innovation Solution
A system that enables seamless checkout and payment operations by transferring the transaction process from a primary device to a trusted secondary device using delegated credentials, establishing an authorized authenticated session to secure electronic communications and minimize exposure of payment credentials and PII.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If users authenticate on multiple devices using different authentication protocols, then users can access services on various devices, but the authentication process becomes inefficient and exposes security risks
Solution Approach 1:
The patent introduces a delegated credential mechanism that acts as an intermediary between the user's primary device and secondary devices. The primary device issues delegated credentials that allow authentication on secondary devices without requiring users to manually re-enter credentials or go through different authentication protocols on each device, thus resolving the contradiction between device compatibility and authentication efficiency
Solution Approach 2:
The system performs preliminary authentication on the primary device and issues delegated credentials in advance. These pre-issued credentials enable seamless authentication on secondary devices without requiring real-time verification or additional user actions, thereby improving authentication efficiency while maintaining adaptability across multiple devices
2Adaptability or versatility
If users submit payment information and personal information on multiple devices, then transactions can be completed on any device, but security risks increase and sensitive data is exposed
Solution Approach 1:
The delegated credential mechanism serves as a secure intermediary that enables transaction capability on secondary devices without exposing sensitive payment information or personal data. The credentials delegate authentication authority without transmitting actual sensitive data, thus maintaining data security while enabling cross-device transactions
Solution Approach 2:
The system extracts the authentication function from sensitive data itself. Instead of transmitting or storing actual payment information and personal data on multiple devices, the system extracts only the necessary authentication capability through delegated credentials, thereby enabling transaction capability while minimizing security risks associated with data exposure
3Ease of operation
If communication channels between electronically connected devices are established for data exchange, then convenience is improved, but the security level is insufficient for financial transactions involving PII
Solution Approach 1:
The delegated credential system introduces a secure mediation layer for data exchange between devices. Instead of relying on potentially insecure direct communication channels, the system uses cryptographically secured delegated credentials as intermediaries that enable authenticated data exchange with appropriate security guarantees for financial transactions
Solution Approach 2:
The system creates secure copies of authentication authority through delegated credentials rather than copying sensitive data itself. These credential copies enable authenticated communication on secondary devices while maintaining security, as the credentials are cryptographically protected and can be revoked or limited in scope
Data Source
AI summary
Disclosed herein are methods and systems for electronic authentication using delegated credentials to complete checkout and payment operations on a trusted device of a user. A computing system is structured to perform operations comprising receiving transaction information corresponding to an incomplete checkout operation, transmitting at least a subset of transaction information to a customer device, causing the customer device to generate and display a notification comprising a request for user authorization to complete the incomplete checkout operation, receiving customer input indicative of instructions to complete the incomplete checkout operation, and, responsive to receiving customer input, completing the incomplete checkout operation.


