Geo-location Authentication for Mobile POS Terminals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional username and password authentication methods for mobile POS terminals are insufficient in security, particularly vulnerable to tampering and complex password management, which compromises the flexibility and mobility of mobile banking.

Innovation Solution

Implementing a geo-location based authentication system using a secure element with real-time location tracking to verify user identity and transactions by comparing the device's geo-location with the retailer's location and analyzing behavior patterns and shopping habits.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If username and password authentication is used in mobile POS terminals, then user access is enabled, but security against tampering is insufficient

Engineering Contradiction:
Improveauthentication securityVSAvoidvulnerability to tampering
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces geo-location data as an intermediary verification factor between the user and the authentication system. Instead of relying solely on username and password, the system uses the device's geographical location (obtained via GPS or other location services) as an additional layer of verification. This intermediary element makes tampering more difficult because an attacker would need to compromise both the credentials and the location data, thereby resolving the contradiction between enabling access and preventing tampering

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the authentication parameters from static credentials (username and password) to dynamic parameters that include geo-location information. By incorporating location-based parameters, the system transforms the authentication process into one that requires multiple changing factors (credentials plus location), thereby improving security against tampering while maintaining user access capability

Inventive Principle:
Principle #35Parameter changes

2Reliability

If complex passwords are required for improved security, then authentication strength increases, but user management difficulty increases

Engineering Contradiction:
Improveauthentication strengthVSAvoidpassword management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements geo-location based automatic verification that reduces the need for users to manually manage complex passwords. The system automatically obtains and verifies location data in the background, performing security checks without requiring user intervention. This self-service approach maintains strong authentication (through location verification) while eliminating the burden of password management for users, thereby resolving the contradiction between authentication strength and ease of operation

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9754255B1Geo-location based authentication in a mobile point-of-sale terminal
Publication Date: 2017.09.05 MAXIM INTEGRATED PROD INC
  • US9754255B1 patent drawing
  • US9754255B1 patent drawing
  • US9754255B1 patent drawing

AI summary

The invention relates to authentication in mobile financial transactions, and more particularly, to systems, devices and methods of employing a location tracking function within a mobile device for the purpose of authenticating a user and a trusted transaction when this mobile device is configured to a mobile point-of-sale (POS) terminal. Authentication is primarily implemented by a secure element integrated within the mobile device based on comparison between captured geo-location data and some known information, such as a retailer address, this user's behavior pattern and shopping habit, that may be derived from the geo-location data. In the secure element, a secure memory stores a plurality of geo-location data from which a secure processor generates information concerning a behavior pattern or a shopping habit of the user. A V/A unit receives a real-time geo-location of the mobile device, and thereby, verifies the user or the trusted transaction according to the generated information.