Dual-Layer Payment Authentication via Proximity Device
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic payment systems, especially those conducted online, are vulnerable to identity theft due to the lack of robust security measures, particularly in environments where mobile networks may be unreliable and user interaction is required for authorization.
Innovation Solution
A dual-layer authentication method using proximity-based communication, such as Bluetooth, RFID, or IrDA, between a user's device and their computer to verify the owner's identity through unique device identifiers and PINs, providing an additional security check beyond traditional card authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional card authentication is used for online payments, then the payment process is simple and fast, but security is insufficient and vulnerable to identity theft
Solution Approach 1:
The authentication process is divided into two independent layers: traditional card authentication and mobile device authentication. Each layer operates separately but both must succeed for the payment to be authorized. This segmentation allows the system to maintain simplicity in the overall flow while adding security through a separate, dedicated authentication mechanism.
Solution Approach 2:
A mobile device serves as an intermediary between the user and the payment system. The mobile device holds a unique identifier and receives push notifications that mediate the authentication process. This intermediary approach adds a security layer without requiring direct complex interactions between the user and the payment processor.
2Reliability
If mobile device authentication is added to enhance security, then identity theft protection is improved, but the authentication process becomes more complex and requires additional steps
Solution Approach 1:
The mobile device authentication system operates autonomously without requiring active user participation. The device automatically receives push notifications, verifies its own identity through the unique identifier, and responds to authentication requests without user intervention. This self-service approach maintains ease of operation while significantly enhancing security.
Solution Approach 2:
The mobile device is pre-configured with a unique identifier and authentication capabilities before the payment transaction occurs. The device is ready to immediately authenticate when presented with a payment request, eliminating the need for users to perform complex authentication steps during the transaction itself.
3Reliability
If proximity-based communication is used to verify device presence, then authentication security is enhanced, but the system becomes more complex and may interfere with existing security structures
Solution Approach 1:
The mobile device serves multiple functions: it acts as an authentication token, a communication device for receiving push notifications, and a proximity verification tool through its built-in transceiver. This multi-functionality consolidates what would otherwise require separate systems into a single device, reducing overall system complexity while enhancing security.
Solution Approach 2:
Instead of using complex cryptographic protocols or additional hardware tokens, the system uses a simplified copy of the user's mobile device identity (the unique identifier) as the authentication mechanism. This copying approach simplifies the system structure by relying on the device's inherent identification capabilities rather than adding complex security infrastructure.
4Reliability
If push notification authentication is implemented, then transaction security is improved, but the process requires network availability and may cause delays
Solution Approach 1:
The authentication system uses periodic push notifications that are sent to the mobile device at specific intervals. The device can respond immediately when notified, and the system can send subsequent notifications if needed. This periodic action allows for rapid authentication when network conditions are good while providing flexibility to handle network delays without causing excessive time loss.
Data Source
AI summary
Increasing the security of online payment requests by introducing a dual-layer authentication system for accessing the funds and/or credit through payment cards is described. An additional check regarding the identity of a card user to be included within a traditional security protocols for these cards, wherein the additional check is based on an authentication channel which is external to the user's card. A device owned by the legitimate card owner certifies that the user of the card at any given instant is the legitimate owner of the card and not someone else. To process this additional information, a connection by means of a proximity based device is established.


