Integrating Financial Services into Merchant Apps via Session Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for integrating first-party services, such as financial institutions, into second-party computer applications, like merchant mobile apps, face challenges in securely and efficiently authenticating users and processing transactions.
Innovation Solution
The method involves a computer processor for the first party receiving customer electronic device information, sending an authentication value to the second party's processor, and using this value to authenticate and authorize transactions within the second party's application.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users authenticate with financial institutions through merchant applications using traditional methods (username/password, biometrics), then security is maintained, but user experience becomes complex and time-consuming
Solution Approach 1:
The system performs preliminary authentication actions by establishing trusted relationships between devices and financial institutions before transactions occur. Device information is registered and authenticated in advance, creating session identifiers and authentication values that enable seamless future transactions without repeated complex authentication steps.
Solution Approach 2:
The patent introduces intermediary elements including device information profiles, session identifiers, and authentication values that mediate between the user device, merchant application, and financial institution. These intermediaries streamline the authentication process by pre-establishing trust relationships and enabling automated verification.
2Productivity
If financial institutions integrate directly into merchant applications, then transaction efficiency improves, but security risks increase
Solution Approach 1:
The system segments the authentication and transaction process into distinct components: device information collection, authentication value generation, session management, and transaction processing. This segmentation allows each component to be securely implemented and managed independently while maintaining overall system efficiency.
Solution Approach 2:
The patent employs multiple intermediary layers including encrypted communication channels, authentication values, and session identifiers that mediate between the merchant application and financial institution. These intermediaries enable efficient direct integration while maintaining security through layered protection mechanisms.
3Productivity
If authentication values are transmitted between systems, then transaction authorization is streamlined, but vulnerability to compromises increases
Solution Approach 1:
Authentication values and device information are established and verified in advance before transactions occur. This preliminary action creates a secure foundation that enables rapid authorization while reducing vulnerability during actual transaction processing, as the authentication framework is already in place and validated.
Solution Approach 2:
The system dynamically changes authentication parameters including generating unique authentication values for each session, rotating encryption keys, and updating device information profiles. These parameter changes ensure that even if one authentication value is compromised, the impact is limited and security can be rapidly updated.
Data Source
AI summary
Systems, methods, and devices for integrating a first party service into a second party computer application are disclosed. In one embodiment, in a financial institution comprising at least one computer processor, a method for integrating a financial services payment service into a merchant computer application may include (1) receiving customer electronic device information from a customer electronic device using a first communication channel; (2) transmitting a passcode to the customer electronic device using a second communication channel; (3) receiving the passcode from the customer electronic device over the first communication channel; (4) sending a session identifier to electronic device over first communication channel; (5) receiving the session identifier from a merchant host; and (6) sending an authentication value to a merchant host. The merchant host may provide the authentication value to the customer electronic device.


