Authentication via EFT Network Question Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for authenticating account holders by service providers other than the issuer require sharing secret information, leading to its proliferation and increased fraud risk, as they need to learn this information from the issuer.
Innovation Solution
A method where the acquirer sends a request for authentication questions to the issuer over an electronic funds transfer network, which are answered by the applicant, allowing the issuer to verify the applicant's knowledge of account-specific information without sharing secret information with the acquirer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the service provider learns secret information from the issuer to authenticate the applicant, then authentication capability is improved, but secret information proliferation occurs increasing fraud risk
Solution Approach 1:
The patent extracts the secret information from the authentication process by using knowledge-based questions about account history and characteristics instead of secret shared information. The issuer asks questions about account details that only the legitimate holder would know, eliminating the need for the service provider to possess any secret information while maintaining strong authentication capability.
Solution Approach 2:
The patent introduces knowledge-based questions as an intermediary mechanism between the issuer and service provider. Instead of directly sharing secret information, the system uses questions about account history, transaction patterns, and personal details as a mediator that enables authentication without proliferating sensitive data to the service provider.
2Reliability
If different service providers use different authentication methods, then each provider can authenticate effectively, but system complexity increases
Solution Approach 1:
The patent creates a universal authentication framework where knowledge-based questions can be used across different service providers and account types. The same question-asking mechanism works for various financial institutions and service providers, eliminating the need for each provider to develop proprietary authentication systems while maintaining effective authentication.
Solution Approach 2:
Instead of having the service provider verify secret information directly, the system inverts the approach by having the issuer verify the applicant's knowledge through questions and then communicate only the verification result to the service provider. This reversal simplifies the service provider's role while maintaining authentication effectiveness.
Data Source
AI summary
Systems and methods for authenticating an applicant. In one implementation, the applicant indicates to an acquirer an existing account for which the applicant wishes to be authenticated. The acquirer sends a message over an electronic funds transfer (EFT) network to an issuer of the account requesting a set of questions to ask the applicant. The issuer replies with a set of questions. The acquirer asks the applicant the questions, and forwards the applicant's answers to the issuer. The issuer compares the answers with known information relating to the account and decides, based on the comparison, whether the applicant is authenticated. The issuer then communicates its decision to the acquirer. Preferably, the messages and their associated replies are added to the set of messages handled by the EFT network, so that authentication may be handled in a standardized way without proliferating applicants' secret information.


