Mobile Account Authentication Service via Intermediary Mediator
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for authenticating account holders in online and mobile transactions are complex, require significant investment, and lack interoperability, leading to increased fraud and security concerns, especially in 'card not present' transactions.
Innovation Solution
A mobile account authentication service that uses a trusted party to verify account holders' identities through various techniques like passwords and tokens, providing real-time authentication and supporting transactions via Internet, voice, and text messaging channels, with a system architecture involving a merchant server, access control server, and merchant plug-in software module.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If prior authentication systems are implemented, then account holder verification capability is improved, but system complexity and implementation cost increase significantly
Solution Approach 1:
The patent introduces an authentication service as an intermediary component that mediates between the merchant server and the account holder. This service handles the complex authentication logic, password verification, and token generation centrally, allowing the merchant system to remain simple while still providing robust authentication. The service acts as a mediator that translates authentication requests into verified credentials without requiring the merchant to implement complex security protocols.
Solution Approach 2:
The patent extracts the authentication functionality from the merchant system and places it in a separate, dedicated authentication service. By taking out the complex authentication logic, password management, and verification processes from the merchant server, the system reduces merchant system complexity while maintaining strong authentication capabilities. The extracted authentication service can be independently managed and updated without affecting the merchant system.
2Reliability
If comprehensive authentication systems are deployed, then fraud prevention is improved, but resource investment and implementation costs increase
Solution Approach 1:
The authentication service implements self-service mechanisms where the system automatically manages password hashing, token generation, and verification without requiring manual intervention. The service autonomously handles authentication challenges, generates session tokens, and manages credential verification, reducing the need for human resources and manual security management while maintaining strong fraud prevention capabilities.
Solution Approach 2:
The patent employs short-lived session tokens that are generated for each authentication session and discarded afterward. These disposable tokens provide strong security for each transaction without requiring long-term storage or management of sensitive authentication data. The use of ephemeral credentials reduces security risks and resource requirements compared to maintaining long-term secure storage of authentication information.
3Reliability
If complex authentication protocols are used, then security is improved, but ease of operation and user convenience deteriorate
Solution Approach 1:
The authentication process is segmented into distinct, manageable steps: the merchant server initiates authentication, the authentication service verifies credentials, and a session token is generated and returned. This segmentation allows each component to perform its specific function simply, presenting a streamlined interface to users while maintaining strong security. The user experiences a simple workflow despite the complex security measures occurring in the background.
Solution Approach 2:
The authentication service creates a simplified copy or representation of the authentication state through session tokens. Instead of requiring users to manage complex credentials or undergo multiple verification steps, the service generates a simple token that represents authenticated status. This token copy allows the user to proceed with transactions using a simple credential while the underlying complex authentication has already been performed.
4Reliability
If real-time authentication is implemented, then transaction security is improved, but processing time and system responsiveness may be affected
Solution Approach 1:
The authentication service performs preliminary actions by pre-hashing passwords and pre-generating verification mechanisms before actual authentication occurs. The service is ready to verify credentials immediately when authentication is requested, reducing the time required during the actual authentication moment. Session tokens are generated and validated in advance where possible, enabling rapid verification during transactions.
Data Source
AI summary
A payment authentication service authenticates the identity of a payer during online transactions. The authentication service allows a card issuer to verify a cardholder's identity using a variety of authentication methods, such as with the use of tokens. Authenticating the identity of a cardholder during an online transaction involves querying an access control server to determine if a cardholder is enrolled in the payment authentication service, requesting a password from the cardholder, verifying the password, and notifying a merchant whether the cardholder's authenticity has been verified. Systems for implementing the authentication service in which a cardholder uses a mobile device capable of transmitting messages via the Internet are described. Systems for implementing the authentication service in which a cardholder uses a mobile device capable of transmitting messages through voice and messaging channels is also described.


