Location-Based Mobile Transaction Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication methods for transactions, such as 'something you know', 'something you have', and 'something you are', can be inconvenient, especially in remote transactions, and lack an additional layer of security.

Innovation Solution

Implementing location-based authentication that verifies the proximity of a mobile device to a computer during online transactions, using techniques like IP geolocation and cell tower signal strength, to adjust an authentication risk score and determine approval or rejection of the transaction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional authentication methods (password, biometric, etc.) are used, then authentication can be performed, but convenience deteriorates in remote transactions

Engineering Contradiction:
Improveauthentication securityVSAvoidconvenience in remote transactions
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent changes the authentication parameter from static credentials (password, biometric) to dynamic location-based parameters. The system determines device location using GPS, cell tower triangulation, or Wi-Fi positioning, and compares it against pre-stored authorized locations. This parameter change enables remote transactions to be authenticated based on geographic context, improving convenience while maintaining security.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent introduces location information as an intermediary element between the user and the authentication system. Instead of directly authenticating credentials, the system uses location data as a mediator to verify whether the transaction is occurring from an authorized geographic position. This intermediary approach resolves the contradiction by providing a new authentication dimension that is both secure and convenient for remote transactions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If additional authentication layers are added to conventional methods, then security improves, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the location determination capability universal by leveraging existing mobile device functions (GPS receiver, cell tower signaling, Wi-Fi positioning) that are already present in modern smartphones. Rather than adding a separate authentication device, the system uses multi-functional capabilities of the mobile device itself to provide location-based authentication, thereby improving security without significantly increasing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The mobile device performs self-service by using its own built-in location determination capabilities (GPS, cell tower triangulation, Wi-Fi positioning) to provide authentication data. The device automatically determines its location and transmits this information to the authentication system without requiring additional hardware or manual intervention, thus improving security while minimizing complexity increases.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8295898B2Location based authentication of mobile device transactions
Publication Date: 2012.10.23 BANK OF AMERICA CORP
  • US8295898B2 patent drawing
  • US8295898B2 patent drawing
  • US8295898B2 patent drawing

AI summary

Systems, methods, and software for implementing location-based authentication of both online and mobile web-based transactions. This implementation may involve verifying whether a mobile device (such as a cellular telephone) is proximate to a computer from which the transaction is being performed. Depending upon the location of the mobile device, further transactions may be approved or rejected. In further implementations, the transactions may be made from the mobile device itself. In this case, the location of the mobile device compared with one or more pre-stored locations may affect whether further transactions from the mobile device are approved or rejected.