Mobile Device Transaction Authentication via Location Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Card-not-present (CNP) transaction fraud is challenging to detect due to the ease of spoofing internet protocol (IP) addresses, making IP address information unreliable for authenticating transactions.
Innovation Solution
A computer-implemented method and system that uses a mobile device to obtain account data from a portable payment device via radio frequency communication, combines this with mobile device location data, and encrypts it for transmission to an authentication system, which compares the location data to IP address-derived location data to assess risk.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If IP address information is used for transaction authentication, then the authentication process is simple, but the reliability of location verification deteriorates due to easy spoofing
Solution Approach 1:
The patent introduces mobile device location data as an intermediary verification mechanism. Instead of relying solely on IP address (which can be spoofed), the system uses GPS, cellular tower, or Wi-Fi based location data from the user's mobile device as a mediator to verify the user's actual physical location, creating a trusted intermediate layer between the transaction system and the user's true location
Solution Approach 2:
The patent replaces the mechanical/network-based IP address verification system with a GPS/satellite-based location verification system. By substituting the IP address location method with satellite-based GPS coordinates, the system achieves more reliable location verification that cannot be easily spoofed, while maintaining automated authentication
2Reliability
If multiple location data sources are combined for verification, then the fraud detection capability is improved, but the device complexity increases
Solution Approach 1:
The patent merges multiple location data sources (GPS coordinates, cellular tower triangulation, Wi-Fi positioning) into a single comprehensive location verification system. By combining these different location determination methods, the system achieves robust fraud detection capability where multiple independent location sources must corroborate the user's actual position, making spoofing significantly more difficult
Solution Approach 2:
The patent creates a multi-functional location verification system that can operate using multiple different location determination methods (GPS, cellular networks, Wi-Fi). This universal approach allows the system to adapt to different environments and maintain reliability even if one location source is unavailable or compromised, while presenting a unified authentication interface to users
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach enhances the reliability of transaction authentication by using actual location data, making CNP transactions less susceptible to fraud and more similar to card-present transactions, thereby preventing fraudulent activities.
Implementation Method 1
obtaining, with the mobile device from a portable payment device, account data via radio frequency communication
Data Source
AI summary
A computer-implemented method, system, and computer program product is provided for authenticating a transaction. The method includes: receiving, on a mobile device associated with a user, a request from an authentication system, the request associated with a transaction requested by the user; obtaining, with the mobile device from a portable payment device, account data via radio frequency communication; obtaining, with the mobile device, mobile device location data including at least one of the following: GPS location data, telephone carrier location data, wireless network location data, or any combination thereof; encrypting, with the mobile device, at least a portion of the account data and the mobile device location data, resulting in at least one encrypted data packet; and transmitting, with the mobile device to the authentication system, the at least one encrypted data packet.


