Mobile Device Authentication via Hardware Identifier Registry

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional payment systems, especially those involving mobile devices, face high fraud risks due to the lack of secure authentication methods, leading to increased costs for merchants and higher premiums for non-traditional payment methods.

Innovation Solution

A system and method that utilizes a unique mobile device hardware identifier and a secure processing environment to verify transactions through a trusted certificate authority, associating the device identifier with transaction account information in an electronic registry, ensuring the authenticity of the mobile device and user, thereby reducing fraud risk.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional payment systems are used without hardware identifier verification, then ease of operation is maintained, but fraud risk increases and transaction security deteriorates

Engineering Contradiction:
Improvetransaction securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary registration of mobile device hardware identifiers (IMEI, Android ID, IDFV) and secure environment identifiers before transactions occur. This pre-registration creates an electronic registry that enables automatic verification during transactions, improving security without adding complexity to the transaction process itself.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification system that acts as a mediator between the mobile device and the transaction processor. The system captures hardware identifiers through the mobile network operator and verifies them against the electronic registry, providing security verification without requiring direct complex interactions between the device and payment processor.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If hardware identifier verification is implemented, then fraud risk decreases, but device complexity and processing requirements increase

Engineering Contradiction:
Improvefraud riskVSAvoidsystem processing complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system extracts specific hardware identifier data (IMEI, Android ID, IDFV) and secure environment identifiers from the mobile device and separates them into an electronic registry for verification. This extraction approach allows verification of critical security elements without processing or storing unnecessary device information, reducing processing complexity while maintaining fraud prevention capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system creates and verifies copies of hardware identifiers and secure environment identifiers against registered values. Instead of requiring direct access to or modification of device hardware, the system captures identifier copies through the mobile network operator and verifies these copies against the electronic registry, simplifying the verification process while maintaining security.

Inventive Principle:
Principle #26Copying

3Reliability

If multi-factor authentication using hardware identifiers is used, then transaction security improves, but ease of operation decreases

Engineering Contradiction:
Improveauthentication securityVSAvoidtransaction process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The mobile device automatically performs the authentication function by having its hardware identifiers and secure environment identifiers captured through the mobile network operator and verified against the electronic registry. The user does not need to manually provide additional verification information, as the device itself enables the security verification process, maintaining ease of operation while improving security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system merges the hardware identifier verification process with the existing transaction flow. The capture of IMEI, Android ID, IDFV, and secure environment identifiers occurs through the same mobile network infrastructure used for transaction processing, and verification is performed as part of the standard authorization process, combining multiple security functions without creating separate user actions.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10706404B2Authenticating based on a hardware identifier
Publication Date: 2020.07.07 AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC
  • US10706404B2 patent drawing
  • US10706404B2 patent drawing

AI summary

A system and method are disclosed herein leveraging financial networks standards with mobile device data and secure processing and storage environment knowledge to authenticate a device. For instance, a party to a transaction may utilize these elements of information, not traditionally associated with wireless transactions, to achieve a lower probability of fraud and/or a higher confidence associated with the transaction.