Portable Device Authentication via Location Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for authenticating portable devices in remote transactions are cumbersome and insecure, particularly as they rely on password-based solutions like 3D Secure, which can be burdensome for users and costly for merchants, and are not effective in distinguishing legitimate from fraudulent interactions.
Innovation Solution
A system that uses a server computer to verify the authentication of portable devices by matching transaction data with location information from access devices and mobile devices, marking the device information as authentication verified, and utilizing digital certificates or tokens for additional security in remote transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If password-based authentication methods like 3D Secure are used for remote transactions, then authentication security is improved, but user convenience deteriorates and implementation cost increases
Solution Approach 1:
The patent replaces the mechanical/password-based authentication system with a biometric authentication system using fingerprint sensors. The fingerprint sensor captures and verifies biometric data, substituting the need for users to remember and enter passwords. This resolves the contradiction by maintaining security through unique biometric identification while significantly improving user convenience as no password management is required.
Solution Approach 2:
The patent introduces a biometric authentication intermediary layer between the user and the transaction system. The fingerprint sensor and biometric verification process act as an intermediary that automatically authenticates users without requiring their direct involvement in password entry or management. This intermediary system maintains security while eliminating the operational burden on users.
2Reliability
If password-based authentication methods like 3D Secure are used for remote transactions, then authentication security is improved, but system implementation and maintenance cost increases
Solution Approach 1:
The patent replaces complex password management infrastructure with simpler biometric authentication hardware and software. Fingerprint sensors are relatively inexpensive components that can be integrated into mobile devices, eliminating the need for merchants to implement and maintain complex 3D Secure password systems. This substitution reduces implementation and maintenance costs while maintaining authentication security.
Solution Approach 2:
The biometric authentication system is self-service in nature, requiring no external password management infrastructure. The user's fingerprint serves as their own authentication credential, eliminating the need for merchants to maintain password databases, handle password resets, or manage authentication credentials. This self-service approach significantly reduces system implementation and maintenance costs.
3Reliability
If pop-up windows are used for password entry in 3D Secure, then authentication security is improved, but user confusion increases due to difficulty distinguishing legitimate from fraudulent pop-ups
Solution Approach 1:
The patent replaces the visual/pop-up-based authentication interface with a biometric sensor-based interface. Instead of displaying password entry fields in pop-up windows that users must distinguish from phishing attempts, the system uses fingerprint sensors to automatically capture and verify authentication data. This substitution eliminates the visual confusion entirely as the biometric process is seamless and cannot be easily replicated by fraudulent sites.
Data Source
AI summary
An embodiment of the invention is directed to a method comprising receiving, at a server computer, information for a portable device that includes a mobile device identifier and storing, by the server computer, the information for the portable device that includes the mobile device identifier in a database associated with the server computer. The method further comprising receiving, by the server computer, transaction data from an access device for a transaction conducted at the access device, determining, by the server computer, from the transaction data that the transaction is associated with the portable device, determining, by the server computer, a location of the access device, determining, by the server computer, a location of a mobile device associated with the mobile device identifier, determining, by the server computer, that the location of the mobile device matches the location of the access device, and marking, by the server computer, the stored information for the portable device as authentication verified.


