Mobile Device Authentication via Unique Data Strings
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional electronic transactions rely heavily on Auxiliary Security Verification Information (ASVI) which is vulnerable to theft and compromise, leading to fraud and identity theft, as users are required to provide sensitive information for authentication, and existing methods lack robust and user-friendly additional authentication mechanisms.
Innovation Solution
The method involves using mobile devices to authenticate users by generating a unique data string that is sent to both the user's mobile device and the vendor, ensuring that the user's identity is verified through physical possession of the device, thereby reducing reliance on ASVI and enhancing security against fraud.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If ASVI information is used for authentication, then user identity verification is possible, but the system becomes vulnerable to theft and compromise
Solution Approach 1:
The patent introduces an authentication service provider as an intermediary between the user and the vendor. This mediator generates and manages temporary authentication credentials (data strings) that are transmitted through multiple parties without exposing the core identification information. The intermediary architecture prevents direct exposure of sensitive user data while enabling secure verification, thus resolving the contradiction between authentication capability and security vulnerability.
Solution Approach 2:
Instead of using the user's actual identification information directly, the system creates temporary copies in the form of data strings that represent the user's identity for authentication purposes only. These copied credentials can be transmitted and verified without revealing the original sensitive information, thereby maintaining authentication reliability while eliminating the vulnerability to theft of personal data.
2Reliability
If traditional ASVI verification is used, then authentication can be performed, but user convenience is reduced due to requiring card swiping and identification provision
Solution Approach 1:
The authentication service provider enables self-service authentication where the user's mobile device automatically generates and transmits the data string without requiring manual card swiping or identification provision. The system performs verification automatically in the background, allowing users to complete transactions with minimal effort while maintaining strong security through the intermediary authentication process.
3Adaptability or versatility
If ASVI information is stored by vendors and transaction handlers, then authentication verification is enabled, but the information becomes vulnerable to theft and compromise
Solution Approach 1:
The patent extracts the authentication verification function from the vendor and transaction handler systems, centralizing it in a dedicated authentication service provider. This extraction removes sensitive authentication data from multiple vulnerable storage points and concentrates security management in a single controlled environment, enabling authentication capability while eliminating the widespread data storage vulnerability.
Solution Approach 2:
The system uses temporary data string copies instead of storing actual ASVI information at vendors or transaction handlers. These ephemeral credentials enable authentication verification without requiring persistent storage of sensitive user data at multiple locations, thus providing adaptability while reducing theft and compromise risk.
Data Source
AI summary
A method to provide authentication services to third party vendors by a service provider hosting an authentication, authorization and accounting (AAA) server or a similar device that can authenticate users for some other service. This method enables easy and substantially error-free end-user authentication, which forms the basis for enabling electronic transactions (e.g., web-based) that are less vulnerable to fraud.


