Intermediary Authentication for Digital Wallet Enrollment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital wallet services are vulnerable to spear phishing attacks during the enrollment process, as they automatically direct users to service provider websites, potentially disclosing personal information and increasing the risk of fraud.

Innovation Solution

A system and method that utilize a computing device to assess the authentication confidence level of enrollment requests by applying rules to device attribute data, determining whether to automatically direct the user to a third-party website or prompt a step-up challenge, thereby reducing the risk of fraudulent activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the network based service automatically directs the user to the service provider website to complete registration, then the registration procedure is simplified and made automatic, but personal information of the user is disclosed and the risk of spear phishing attacks is increased

Engineering Contradiction:
Improveregistration procedureVSAvoidspear phishing attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication system that sits between the user and the service provider website. This intermediary evaluates device attributes and authentication confidence levels before allowing automatic direction to the service provider, thereby mediating the information disclosure risk while maintaining ease of use for trusted devices

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the parameter of authentication confidence level based on device attributes. By evaluating multiple device parameters (device type, operating system, browser, location) and assigning confidence levels, the system dynamically adjusts the level of information disclosure and automation accordingly, resolving the contradiction between ease of operation and security

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If the network based service automatically directs the user to the service provider website, then the access procedure is simplified, but personal information of the user is further disclosed and the risk of spear phishing attacks is increased

Engineering Contradiction:
Improveaccess procedureVSAvoidpersonal information disclosure
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The intermediary authentication system evaluates device attributes before allowing automatic direction to the service provider website. This mediator controls information disclosure by only revealing necessary information to trusted devices, thereby simplifying access for legitimate users while preventing information loss for high-risk devices

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system applies partial automation based on authentication confidence levels. For high-confidence devices, full automatic direction is applied; for low-confidence devices, limited automation is applied with additional verification steps. This partial action approach resolves the contradiction by providing simplified access only when safe

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If the digital wallet service automatically directs the cardholder to the issuer's website to complete registration, then the enrollment procedure is simplified, but the identity of the issuing bank is disclosed to fraudulent parties

Engineering Contradiction:
Improveenrollment procedureVSAvoidinformation disclosure to fraudsters
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The authentication system acts as an intermediary that evaluates device trustworthiness before allowing automatic enrollment direction. This mediator prevents harmful information disclosure to fraudulent parties by blocking automatic direction for untrusted devices, while maintaining simplified enrollment for trusted cardholders

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system uses feedback from device attribute evaluation to determine the appropriate enrollment procedure. By continuously assessing device trust levels and adjusting the enrollment process accordingly, the system resolves the contradiction between ease of operation and prevention of information disclosure to fraudsters

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20230368187A1Systems and methods for enhanced cybersecurity in electronic networks
Publication Date: 2023.11.16 MASTERCARD INT INC
  • US20230368187A1 patent drawing
  • US20230368187A1 patent drawing
  • US20230368187A1 patent drawing

AI summary

A computing device for enhancing cybersecurity in electronic networks is provided. The computing device includes one or more processors in communication with one or more memory devices, where the one or more processors are configured to receive, from an authentication webpage executing on a user computing device, a request to enroll into a secure application, and apply a plurality of rules to the device attribute data to determine an authentication confidence level of the request. The one or more processors are further configured to retrieve, from the one or more memory devices and based on the determined authentication confidence level, an enrollment procedure instruction from a plurality of enrollment procedure instructions for enrollment into the secure application, and transmit the enrollment procedure instruction to the user computing device to complete the enrollment into the secure application.