Digital Transaction Authentication via Device Attestation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital transaction authentication methods lack secure network-based authentication techniques for card-on-file payments, particularly since they do not require a second factor authentication like PIN, leading to insecure processing and lower payment success rates.
Innovation Solution
A computer-implemented method and system that involves device registration and attestation, enrollment in authentication techniques, and token-based authentication for secure digital transactions, using cryptographic validation and issuer consent to enhance security and success rates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If network-based authentication is used for digital transactions, then authentication time is reduced and payment success rate is improved, but security is worsened due to lack of second factor authentication
Solution Approach 1:
The system performs preliminary device enrollment and attestation before actual payment transactions. Device integrity is verified in advance through cryptographic validation, and authentication credentials are pre-configured. This allows fast network-based authentication during transactions while maintaining security through prior verification steps.
Solution Approach 2:
The authentication system is segmented into distinct components: device attestation module, credential verification module, and transaction authentication module. This segmentation allows the system to use lightweight network-based authentication for transactions while maintaining separate, more rigorous security validation through device attestation and issuer authentication techniques.
2Reliability
If issuer authentication techniques are used for digital transactions, then security is improved through second factor authentication, but authentication time is increased and payment success rate is reduced
Solution Approach 1:
Device enrollment and attestation are performed in advance before actual transactions. This preliminary setup configures cryptographic credentials and validates device integrity, enabling faster authentication during subsequent transactions without compromising security requirements.
Solution Approach 2:
The system applies different levels of authentication based on transaction context. For enrolled devices with verified integrity, it uses partial authentication (network-based without PIN). For unenrolled or suspicious devices, it applies full authentication including issuer techniques. This selective approach reduces average authentication time while maintaining security.
3Ease of operation
If card-on-file payments are processed without second factor authentication, then ease of operation is improved, but security is worsened due to lack of secure mechanism
Solution Approach 1:
The device performs self-attestation by providing cryptographic proof of its own integrity and authenticity. The device enrolls itself with the payment server, storing authentication credentials locally. This self-service mechanism enables easy card-on-file payments without manual verification while maintaining security through cryptographic validation of device authenticity.
Solution Approach 2:
A payment server acts as an intermediary between the device and payment networks. The server validates device attestation, manages credential distribution, and orchestrates authentication techniques. This intermediary enables simplified user experience while implementing robust security validation that would be difficult to implement directly in the device or payment network.
Data Source
AI summary
A system and computer-implemented method for authenticating digital transactions. The method includes receiving a device registration request and a device attestation response including at least a device integrity status from a device. In response to the device registration request, the method includes providing a device registration response to the device, based on validation of the device integrity status. Further, the method includes receiving a first payment transaction request and an enrolment request from the device via an application to authenticate a second payment transaction request using a first type of authentication technique. Finally, the method includes enrolling the device to the first type of authentication technique and providing a second token to the device based on a result of the first payment transaction request, wherein the second token is used for authenticating the second payment transaction request.


