Multi-factor Identity Authentication via Mobile Device
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional online payment systems face security risks and lack notification and validation features, especially when integrating mobile payments with online stores, which exposes users and retailers to potential theft and liability.
Innovation Solution
A system that requires multiple-step authentication using a mobile device for completing transactions initiated on a client device, involving a commerce server, identity service, and mobile device to ensure user identity verification and notification for mobile payment options, utilizing biometric authentication and unique Device Account Numbers for secure transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional online payment systems are used to allow users to enter credit card information on web forms, then payment convenience is improved, but security risks increase due to exposure to theft and keystroke logging
Solution Approach 1:
The patent extracts the sensitive credit card information from the online payment form and stores it securely in a payment instrument repository. The system then uses tokenization to replace the actual card number with a device account number, removing the harmful exposure of sensitive data while maintaining payment functionality.
Solution Approach 2:
The patent introduces an identity service as an intermediary between the commerce server and the payment system. This service verifies user identity and authenticates mobile devices before allowing payment transactions, acting as a mediator that enhances security without compromising user convenience.
2Ease of operation
If online retailers store credit card numbers to avoid requiring user entry, then payment convenience is improved, but the retailer's security risks and liability increase
Solution Approach 1:
The patent extracts the actual credit card number from the payment process and replaces it with a device account number stored securely in the mobile device. The retailer never receives or stores the actual card number, eliminating their liability while maintaining the ability to process payments.
Solution Approach 2:
The patent creates a copy of the payment instrument in the form of a device account number that functions as a token. This copy allows the retailer to process payments without handling the original sensitive card data, reducing their security burden while maintaining payment capability.
3Object-affected harmful factors
If mobile payments with barcodes are used to complete transactions, then payment security is improved, but notification and validation features are lost
Solution Approach 1:
The patent implements a notification system that sends push notifications to the mobile device when a payment transaction is initiated. The identity service provides feedback to both the user and the commerce server about authentication status and transaction completion, ensuring proper validation and user awareness.
4Object-affected harmful factors
If multi-factor authentication is implemented to verify user identity, then security is improved, but system complexity increases
Solution Approach 1:
The patent creates a universal identity service that handles multiple authentication functions through a single interface. The service can verify user identity, authenticate mobile devices, and manage payment instruments using a standardized protocol, reducing overall system complexity while maintaining strong security.
Data Source
AI summary
Disclosed herein are systems, methods, and non-transitory computer-readable storage media for allowing for payment of transactions initiated with a client device to be completed using a mobile device and requiring multiple-step authentication of the user before completing the transactions.


