Mobile Device Authentication via Credential Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current online transaction systems lack effective device authentication methods, leading to potential fraud and security risks, particularly in mobile payments, where verifying the authenticity of mobile devices and customers is challenging.

Innovation Solution

A system and method for device authentication that involves a financial institution's acquirer, payment network, and issuer portions, which receive and verify mobile device credentials and payment credentials, including operating system data, browser data, and device identifiers, to authenticate customers and authorize transactions, while also employing risk management services to assess transaction risks and deny suspicious activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional online transaction systems are used without device authentication, then transaction simplicity is maintained, but security and fraud prevention are compromised

Engineering Contradiction:
Improvetransaction securityVSAvoidtransaction simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs device authentication and credential verification in advance of the actual transaction processing. Mobile device credentials, payment credentials, and device fingerprints are collected and validated before the transaction is finalized, enabling security checks to be completed preliminarily without blocking the user experience during the purchase moment

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mobile device automatically provides authentication credentials and device fingerprints without requiring manual user input. The device self-attests its identity through embedded credentials and system data, eliminating the need for users to manually verify security measures while maintaining strong authentication

Inventive Principle:
Principle #25Self-service

2Reliability

If comprehensive device credentials and risk management checks are implemented, then fraud detection capability is improved, but system complexity increases

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is divided into distinct functional components: mobile device credential collection, payment credential verification, device fingerprinting, risk management assessment, and transaction authorization. Each component operates independently and contributes to the overall security decision, making the complex system manageable and maintainable

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The payment network portion acts as an intermediary between the acquirer and issuer, facilitating the transmission and verification of mobile device credentials and payment credentials. This intermediary layer centralizes the complex authentication logic and credential management, shielding merchants and users from system complexity while enabling comprehensive fraud detection

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11087304B2Systems and methods for device authentication
Publication Date: 2021.08.10 JPMORGAN CHASE BANK NA
  • US11087304B2 patent drawing
  • US11087304B2 patent drawing

AI summary

Systems and methods for device authentication are disclosed. In one embodiment, a method for authenticating a device includes, at a financial institution comprising an acquirer portion, a payment network portion, and an issuer portion: (1) the acquirer portion receiving, from the merchant, a least one mobile device credential and a payment credential that were received electronically from a mobile payment application executed by a mobile electronic device in conjunction with a transaction, the acquirer portion further receiving transaction data for the transaction from the merchant; (2) the issuer portion receiving, via the payment network portion, the mobile device credentials, the payment credentials, and transaction data from the acquirer portion; and (3) at least one computer processor at the issuer portion identifying and authenticating the customer based on the mobile device credentials and the payment credential.