Mobile Device Data-Over-Voice Token Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for validating a consumer's identity during a telephone call with a consumer services representative are inefficient and provide limited security, as they often require security questions or SMS validation, which do not directly validate the consumer's identity and rely on access to consumer profiles.

Innovation Solution

A method using data-over-voice signaling to authenticate a user's identity by generating and sending a token during a telephone call, which is validated by a third-party computer system, incorporating cryptographic keys and local validation at the mobile device to enhance security, allowing for efficient and secure identity verification without additional user actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional SMS validation is used to verify consumer identity, then possession of mobile device is validated, but consumer profile access is required and security questions are still needed

Engineering Contradiction:
Improveidentity validation reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential validation element (token) from the complex SMS validation process and consumer profile system. The token is generated locally on the mobile device using stored cryptographic keys, eliminating the need for server-side consumer profiles and SMS gateways. This extraction reduces system complexity while maintaining validation reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The mobile device performs self-validation by generating and validating tokens locally using cryptographic keys stored on the device itself. This self-service approach eliminates dependency on external consumer profiles and SMS validation infrastructure, reducing system complexity while ensuring reliable identity validation.

Inventive Principle:
Principle #25Self-service

2Reliability

If security questions are used to validate consumer identity, then identity verification is attempted, but the process is lengthy and consumer may not be able to answer

Engineering Contradiction:
Improveidentity validation reliabilityVSAvoidvalidation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The cryptographic keys are pre-loaded onto the mobile device before the validation process begins. This preliminary action enables instant token generation and validation without requiring time-consuming security questions or profile lookups, thus reducing validation time while maintaining reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mobile device independently generates and validates tokens using locally stored cryptographic keys, eliminating the need for time-consuming interactive security questions. This self-service mechanism provides rapid identity validation while maintaining high reliability.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If telephone number validation is used, then caller identification is obtained, but consumer identity is not directly validated

Engineering Contradiction:
Improvevalidation simplicityVSAvoididentity validation reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a cryptographic token as an intermediary that bridges the gap between simple telephone number validation and reliable identity verification. The token, generated and validated locally on the mobile device, serves as a mediator that provides both operational simplicity and high validation reliability without requiring complex profile access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10735580B2Mobile device user validation method and system
Publication Date: 2020.08.04 MASTERCARD INT INC
  • US10735580B2 patent drawing
  • US10735580B2 patent drawing
  • US10735580B2 patent drawing

AI summary

A system including a mobile device, a user of the mobile device, a computer system having a telecommunication module for telephonically communicating with the mobile device, a user of the computer system, and a security server is provided. Also provided is a method, at a mobile device, of authenticating a user of the mobile device during a telephone call having the steps of obtaining a user authentication input, obtaining validation of the user authentication input, initiating a telephone call with, or receiving a telephone call from, the computer system, and if the user authentication input is successfully validated, sending a token generated for the telephone call with the computer system via data-over-voice frequency signaling during the telephone call thereby providing an indication that the user authentication input has been successfully validated to the computer system.