Dynamic Payment Authentication Timeout Adaptation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing payment processing systems have inefficient and fixed timeout periods for authentication sessions, leading to resource wastage and increased vulnerability to fraud, as the timeout period is not dynamically adapted based on the authentication method used.
Innovation Solution
A method and system that dynamically adapt the timeout period for payment transactions by allowing users to select from various authentication options, such as OTP or static password, and configuring the timeout period based on the selected option, usage analytics data, and user profile information, using a set of predefined rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a fixed timeout period is used for authentication session, then simplicity of system configuration is improved, but resource utilization efficiency deteriorates
Solution Approach 1:
The patent implements dynamic timeout periods that automatically adjust based on the selected authentication method. Different authentication types (OTP, biometric, password) are assigned different timeout durations, allowing the system to adapt to varying authentication requirements without manual configuration for each scenario.
Solution Approach 2:
The system changes the timeout parameter dynamically based on authentication method selection. When a user selects a specific authentication type, the corresponding timeout value is automatically applied, optimizing resource utilization by matching session duration to actual authentication needs.
2Ease of operation
If a fixed timeout period is used for authentication session, then ease of operation is improved, but security against fraud deteriorates
Solution Approach 1:
The system dynamically adjusts timeout periods based on authentication method, providing both ease of operation and enhanced security. The automatic adaptation eliminates manual configuration while ensuring appropriate timeout durations for different authentication types, reducing fraud risk without complicating user experience.
Solution Approach 2:
The system incorporates feedback mechanisms that monitor authentication progress and automatically adjust or terminate sessions based on predefined criteria. This ensures that authentication sessions are neither too long (increasing fraud risk) nor too short (causing user inconvenience).
3Ease of operation
If authentication session is extended to accommodate slower authentication methods, then ease of operation is improved, but vulnerability to fraud increases
Solution Approach 1:
The patent applies parameter changes by assigning specific timeout values to different authentication methods. OTP authentication may receive longer timeouts to accommodate SMS delivery delays, while biometric authentication receives shorter timeouts since it occurs instantly. This optimized parameter assignment reduces fraud risk while maintaining operational ease.
Solution Approach 2:
Different timeout qualities are applied to different authentication methods based on their specific requirements. Each authentication type receives a customized timeout duration tailored to its characteristics, ensuring optimal balance between user convenience and security for each local authentication scenario.
Data Source
AI summary
Embodiments provide payment methods, server systems and devices for dynamically adapting a timeout period. The method includes receiving, by a server system associated with a payment network, a payment transaction request from a merchant interface. The payment transaction request includes a payment information and a payment card information of a user. After receiving the payment transaction request, a plurality of authentication options may be presented to the user for authenticating the payment transaction. The user may select an authentication option from the plurality of authentication options. A timeout period for authenticating a payment transaction is determined based on the authentication option selected by the user. The timeout period is determined using a set of predefined rules. Moreover, the timeout period may be dynamically adapted based on the authentication option and one or more of a plurality of timers, a plurality of usage analytics data and a user profile information.


