Authentication via EFT Network Question Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for authenticating account holders by service providers other than the issuer require sharing secret information, leading to its proliferation and increased fraud risk, as they need to learn this information from the issuer.

Innovation Solution

A method where the acquirer sends a request for authentication questions to the issuer over an electronic funds transfer network, which are answered by the applicant, allowing the issuer to verify the applicant's knowledge of account-specific information without sharing secret information with the acquirer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the service provider learns secret information from the issuer to authenticate the applicant, then authentication capability is improved, but secret information proliferation occurs increasing fraud risk

Engineering Contradiction:
Improveauthentication capabilityVSAvoidfraud risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the secret information from the authentication process by using knowledge-based questions about account history and characteristics instead of secret shared information. The issuer asks questions about account details that only the legitimate holder would know, eliminating the need for the service provider to possess any secret information while maintaining strong authentication capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces knowledge-based questions as an intermediary mechanism between the issuer and service provider. Instead of directly sharing secret information, the system uses questions about account history, transaction patterns, and personal details as a mediator that enables authentication without proliferating sensitive data to the service provider.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If different service providers use different authentication methods, then each provider can authenticate effectively, but system complexity increases

Engineering Contradiction:
Improveauthentication effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal authentication framework where knowledge-based questions can be used across different service providers and account types. The same question-asking mechanism works for various financial institutions and service providers, eliminating the need for each provider to develop proprietary authentication systems while maintaining effective authentication.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Instead of having the service provider verify secret information directly, the system inverts the approach by having the issuer verify the applicant's knowledge through questions and then communicate only the verification result to the service provider. This reversal simplifies the service provider's role while maintaining authentication effectiveness.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS7979894B2Electronic verification service systems and methods
Publication Date: 2011.07.12 FIRST DATA CORP
  • US7979894B2 patent drawing
  • US7979894B2 patent drawing
  • US7979894B2 patent drawing

AI summary

Systems and methods for authenticating an applicant. In one implementation, the applicant indicates to an acquirer an existing account for which the applicant wishes to be authenticated. The acquirer sends a message over an electronic funds transfer (EFT) network to an issuer of the account requesting a set of questions to ask the applicant. The issuer replies with a set of questions. The acquirer asks the applicant the questions, and forwards the applicant's answers to the issuer. The issuer compares the answers with known information relating to the account and decides, based on the comparison, whether the applicant is authenticated. The issuer then communicates its decision to the acquirer. Preferably, the messages and their associated replies are added to the set of messages handled by the EFT network, so that authentication may be handled in a standardized way without proliferating applicants' secret information.