Digital Identity Binding for Secure Online Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current online authentication processes for financial transactions, particularly in secure remote commerce, require multiple user credentials and authentication steps, leading to inefficiencies and increased risk of data compromise, especially when interacting with multiple systems during online checkout processes.

Innovation Solution

A method of establishing a digital identity by partially enrolling it to computer hardware and using user authentication to bind the identity, allowing a single authentication process to complete enrollment and authenticate for online services, such as Secure Remote Commerce, through mechanisms like 3D Secure, enabling 'backward' or 'forward' trust transfer depending on availability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple authentication steps and credentials are required for online transactions, then security is improved, but user experience and processing efficiency deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines multiple authentication steps into a single unified authentication process. The system performs both enrollment authentication and transaction authentication simultaneously, merging what were previously separate credential verification steps into one consolidated authentication event, thereby maintaining security while improving user experience

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication system is designed to serve multiple functions: it performs both enrollment verification and transaction authorization in a single process. This multi-functional approach allows the same authentication mechanism to handle different security requirements without requiring separate authentication flows for each function

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple authentication steps and credentials are required for online transactions, then security is improved, but processing time and complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges enrollment authentication and transaction authentication into a single simultaneous process. By combining these authentication events, the system eliminates the sequential time required for separate authentication steps, reducing total processing time while maintaining the security requirements of both functions

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system performs preliminary binding of the digital identity to the user's device during the unified authentication process. This preliminary action establishes the authentication context in advance, allowing subsequent transactions to proceed without requiring additional authentication steps, thereby reducing processing time

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple credentials are required for authentication, then security against data compromise is improved, but the risk of credential exposure and system vulnerability increases

Engineering Contradiction:
ImprovesecurityVSAvoidrisk of data compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the credential verification process from multiple separate systems and consolidates it into a single authentication event. By taking out the authentication logic from distributed systems and centralizing it, the system reduces the number of credential exposure points and minimizes the attack surface for potential data compromise

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system merges multiple authentication credentials and verification steps into a single unified authentication process. This consolidation reduces the total number of credential handling operations across multiple systems, thereby decreasing the cumulative risk of credential exposure and system vulnerability

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11449866B2Online authentication
Publication Date: 2022.09.20 MASTERCARD INT INC
  • US11449866B2 patent drawing
  • US11449866B2 patent drawing
  • US11449866B2 patent drawing

AI summary

A method of establishing a digital identity for use of an online service and of subsequently using the digital identity to perform the online service is described. A digital identity for the online service is bound to computer hardware associated with the digital identity. A user associated with the digital identity provides a user authentication at the computer hardware associated with the digital identity. The digital identity is enrolled for the online service, and a first instance of the online service for the digital identity is performed. A common user authentication process result completes enrolment of the digital identity and authenticates the digital identity for performing said first instance of the online service.