Digital Transaction Authentication via Device Attestation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital transaction authentication methods lack secure network-based authentication techniques for card-on-file payments, particularly since they do not require a second factor authentication like PIN, leading to insecure processing and lower payment success rates.

Innovation Solution

A computer-implemented method and system that involves device registration and attestation, enrollment in authentication techniques, and token-based authentication for secure digital transactions, using cryptographic validation and issuer consent to enhance security and success rates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If network-based authentication is used for digital transactions, then authentication time is reduced and payment success rate is improved, but security is worsened due to lack of second factor authentication

Engineering Contradiction:
Improvepayment success rateVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary device enrollment and attestation before actual payment transactions. Device integrity is verified in advance through cryptographic validation, and authentication credentials are pre-configured. This allows fast network-based authentication during transactions while maintaining security through prior verification steps.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system is segmented into distinct components: device attestation module, credential verification module, and transaction authentication module. This segmentation allows the system to use lightweight network-based authentication for transactions while maintaining separate, more rigorous security validation through device attestation and issuer authentication techniques.

Inventive Principle:
Principle #1Segmentation

2Reliability

If issuer authentication techniques are used for digital transactions, then security is improved through second factor authentication, but authentication time is increased and payment success rate is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Device enrollment and attestation are performed in advance before actual transactions. This preliminary setup configures cryptographic credentials and validates device integrity, enabling faster authentication during subsequent transactions without compromising security requirements.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies different levels of authentication based on transaction context. For enrolled devices with verified integrity, it uses partial authentication (network-based without PIN). For unenrolled or suspicious devices, it applies full authentication including issuer techniques. This selective approach reduces average authentication time while maintaining security.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If card-on-file payments are processed without second factor authentication, then ease of operation is improved, but security is worsened due to lack of secure mechanism

Engineering Contradiction:
Improveease of paymentVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The device performs self-attestation by providing cryptographic proof of its own integrity and authenticity. The device enrolls itself with the payment server, storing authentication credentials locally. This self-service mechanism enables easy card-on-file payments without manual verification while maintaining security through cryptographic validation of device authenticity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A payment server acts as an intermediary between the device and payment networks. The server validates device attestation, manages credential distribution, and orchestrates authentication techniques. This intermediary enables simplified user experience while implementing robust security validation that would be difficult to implement directly in the device or payment network.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12045799B2Method and system for authenticating digital transactions
Publication Date: 2024.07.23 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US12045799B2 patent drawing
  • US12045799B2 patent drawing
  • US12045799B2 patent drawing

AI summary

A system and computer-implemented method for authenticating digital transactions. The method includes receiving a device registration request and a device attestation response including at least a device integrity status from a device. In response to the device registration request, the method includes providing a device registration response to the device, based on validation of the device integrity status. Further, the method includes receiving a first payment transaction request and an enrolment request from the device via an application to authenticate a second payment transaction request using a first type of authentication technique. Finally, the method includes enrolling the device to the first type of authentication technique and providing a second token to the device based on a result of the first payment transaction request, wherein the second token is used for authenticating the second payment transaction request.