Mobile Device Authentication Token for Secure Payment Registration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The proliferation of online fraud and the complexity of managing multiple user identifiers and passwords pose significant security challenges, as users face increased risks of unauthorized access and difficulty in remembering unique credentials.
Innovation Solution
A system utilizing a mobile device as an authentication token, which registers and authenticates users through asymmetric cryptography and shared-secret key architectures, reducing the need for password management by using the mobile device to verify transactions and sessions securely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users use the same passwords and user identifiers at multiple websites, then ease of operation is improved, but security is reduced
Solution Approach 1:
The patent introduces a trusted third party authentication service as an intermediary between users and multiple websites. This service issues digital certificates and tokens that users can present across different sites, eliminating the need to remember multiple passwords while maintaining security through centralized credential verification and monitoring
2Reliability
If users use different passwords and user identifiers for each website, then security is improved, but ease of operation is reduced
Solution Approach 1:
The patent creates a universal authentication token system that can be used across multiple websites and services. A single token or certificate issued by the trusted third party serves multiple authentication purposes, allowing users to access different systems without managing separate credentials for each
3Ease of operation
If web session interface is used to communicate with users, then ease of operation is improved, but reliability is reduced due to fraud and malware
Solution Approach 1:
The patent implements preliminary authentication before web session communication begins. Users must first obtain digital certificates and establish secure channels through the trusted third party before engaging in web transactions, pre-verifying their identity and establishing encrypted communication paths that protect against fraud and malware interception
Data Source
AI summary
A computer-readable medium embodies a computer program for obtaining information for a payment transaction. The computer program comprises computer-readable program code for: generating a first message including an identifier and a request for the information, sending the first message via a first communication path, receiving a second message including the information and the identifier via a second path different from the first communication path, and processing the payment transaction using the information obtained in the second message.


