Multi-Factor Mobile Authentication via SIM and Hardware IDs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional payment systems, especially those involving mobile devices, face high fraud risks due to the lack of secure authentication methods, leading to increased costs for merchants and higher premiums for non-traditional payment methods.

Innovation Solution

A system that utilizes unique mobile device and SIM card hardware identifiers, combined with public and private key cryptography, to verify the authenticity of mobile devices in financial transactions, thereby reducing fraud risk and enhancing transaction security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If non-traditional payment methods are used, then transaction convenience is improved, but fraud risk increases

Engineering Contradiction:
Improvetransaction convenienceVSAvoidfraud risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system is segmented into multiple independent verification factors: device hardware identifier verification, SIM card identifier verification, and cryptographic key verification. Each factor operates independently to provide layered security while maintaining user convenience through automated multi-factor authentication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary registration and binding of device identifiers and cryptographic keys before actual transactions occur. The fraud prevention system pre-configures the authentication framework, storing device hardware identifiers and SIM card identifiers in a registry, and pre-generates cryptographic key pairs, so that during transactions only verification is needed, not setup.

Inventive Principle:
Principle #10Preliminary action

2Speed

If traditional card present authentication is replaced with mobile device authentication, then transaction speed is improved, but security reliability deteriorates

Engineering Contradiction:
Improvetransaction speedVSAvoidsecurity reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The fraud prevention system acts as an intermediary between the mobile device and the transaction processing system. It mediates authentication by verifying device identifiers against the registry and validating cryptographic signatures, providing security verification without requiring physical card presence, thus maintaining both speed and reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces the mechanical action of physically swiping or inserting a card with electronic verification of device identifiers and cryptographic validation. The mechanical card-present authentication is substituted with electronic-mediated authentication that achieves the same security goal faster, by verifying digital identifiers and cryptographic proofs instead of physical card data.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If multi-factor authentication is implemented, then fraud prevention capability is improved, but system complexity increases

Engineering Contradiction:
Improvefraud prevention capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The fraud prevention system is designed as a universal platform that handles multiple authentication factors through a single integrated architecture. The registry stores and verifies multiple types of identifiers (device hardware identifiers, SIM card identifiers), and the cryptographic module handles both key generation and signature verification, providing multi-functionality that reduces overall system complexity despite implementing multi-factor authentication.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The mobile device itself serves as part of the authentication system by storing cryptographic keys and generating signatures locally. The device's hardware automatically provides its identifier for verification. This self-service approach distributes authentication functions across the device and the fraud prevention system, reducing the complexity burden on any single component while maintaining strong multi-factor authentication.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9681305B2System and method for multi-factor mobile user authentication
Publication Date: 2017.06.13 AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC
  • US9681305B2 patent drawing
  • US9681305B2 patent drawing
  • US9681305B2 patent drawing

AI summary

A system and method are disclosed herein leveraging financial networks standards with mobile device data and SIM card chip knowledge to authenticate a device. For instance, a party to a transaction may utilize these elements of information, not traditionally associated with wireless transactions, to achieve a lower probability of fraud and/or a higher confidence associated with the transaction.