Mobile Account Authentication Service via Intermediary Mediator

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for authenticating account holders in online and mobile transactions are complex, require significant investment, and lack interoperability, leading to increased fraud and security concerns, especially in 'card not present' transactions.

Innovation Solution

A mobile account authentication service that uses a trusted party to verify account holders' identities through various techniques like passwords and tokens, providing real-time authentication and supporting transactions via Internet, voice, and text messaging channels, with a system architecture involving a merchant server, access control server, and merchant plug-in software module.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If prior authentication systems are implemented, then account holder verification capability is improved, but system complexity and implementation cost increase significantly

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication service as an intermediary component that mediates between the merchant server and the account holder. This service handles the complex authentication logic, password verification, and token generation centrally, allowing the merchant system to remain simple while still providing robust authentication. The service acts as a mediator that translates authentication requests into verified credentials without requiring the merchant to implement complex security protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the authentication functionality from the merchant system and places it in a separate, dedicated authentication service. By taking out the complex authentication logic, password management, and verification processes from the merchant server, the system reduces merchant system complexity while maintaining strong authentication capabilities. The extracted authentication service can be independently managed and updated without affecting the merchant system.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If comprehensive authentication systems are deployed, then fraud prevention is improved, but resource investment and implementation costs increase

Engineering Contradiction:
Improvefraud preventionVSAvoidresource investment
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The authentication service implements self-service mechanisms where the system automatically manages password hashing, token generation, and verification without requiring manual intervention. The service autonomously handles authentication challenges, generates session tokens, and manages credential verification, reducing the need for human resources and manual security management while maintaining strong fraud prevention capabilities.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent employs short-lived session tokens that are generated for each authentication session and discarded afterward. These disposable tokens provide strong security for each transaction without requiring long-term storage or management of sensitive authentication data. The use of ephemeral credentials reduces security risks and resource requirements compared to maintaining long-term secure storage of authentication information.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If complex authentication protocols are used, then security is improved, but ease of operation and user convenience deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication process is segmented into distinct, manageable steps: the merchant server initiates authentication, the authentication service verifies credentials, and a session token is generated and returned. This segmentation allows each component to perform its specific function simply, presenting a streamlined interface to users while maintaining strong security. The user experiences a simple workflow despite the complex security measures occurring in the background.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication service creates a simplified copy or representation of the authentication state through session tokens. Instead of requiring users to manage complex credentials or undergo multiple verification steps, the service generates a simple token that represents authenticated status. This token copy allows the user to proceed with transactions using a simple credential while the underlying complex authentication has already been performed.

Inventive Principle:
Principle #26Copying

4Reliability

If real-time authentication is implemented, then transaction security is improved, but processing time and system responsiveness may be affected

Engineering Contradiction:
Improvetransaction securityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authentication service performs preliminary actions by pre-hashing passwords and pre-generating verification mechanisms before actual authentication occurs. The service is ready to verify credentials immediately when authentication is requested, reducing the time required during the actual authentication moment. Session tokens are generated and validated in advance where possible, enabling rapid verification during transactions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9769134B2Mobile account authentication service
Publication Date: 2017.09.19 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US9769134B2 patent drawing
  • US9769134B2 patent drawing
  • US9769134B2 patent drawing

AI summary

A payment authentication service authenticates the identity of a payer during online transactions. The authentication service allows a card issuer to verify a cardholder's identity using a variety of authentication methods, such as with the use of tokens. Authenticating the identity of a cardholder during an online transaction involves querying an access control server to determine if a cardholder is enrolled in the payment authentication service, requesting a password from the cardholder, verifying the password, and notifying a merchant whether the cardholder's authenticity has been verified. Systems for implementing the authentication service in which a cardholder uses a mobile device capable of transmitting messages via the Internet are described. Systems for implementing the authentication service in which a cardholder uses a mobile device capable of transmitting messages through voice and messaging channels is also described.