Mobile FIDO Authentication Extension Across Transaction Parties
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods, such as FIDO, are limited to specific parties and do not easily extend across different entities, limiting their applicability and functionality in transactions.
Innovation Solution
A system and method that leverages FIDO authentication for network traffic by using a mobile device to generate key pairs, enroll users with an issuer institution and a processing network, and facilitate biometric transactions, enabling authentication across multiple parties through a unified authentication framework.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If FIDO authentication is used for specific parties, then authentication reliability is improved, but adaptability across different entities deteriorates
Solution Approach 1:
The patent implements a universal authentication framework where FIDO authentication results can be extended and recognized across multiple different entities and systems. The processing network acts as a intermediary that accepts authentication from one entity (e.g., issuer institution) and extends it to other entities (e.g., acquiring bank, third-party services), making the authentication mechanism multi-functional and broadly applicable rather than entity-specific
Solution Approach 2:
The processing network serves as an intermediary layer between different authentication entities. It receives authentication results from one party (such as the issuer institution performing FIDO authentication) and mediates by extending and validating these results for other parties involved in the transaction, enabling trust propagation across multiple entities without requiring direct authentication between each pair
2Adaptability or versatility
If authentication is extended across multiple parties, then adaptability is improved, but system complexity increases
Solution Approach 1:
The processing network functions as a centralized intermediary that handles the complexity of authentication extension. Instead of each entity implementing its own complex authentication extension logic, the processing network provides a unified service that accepts authentication results, validates them against established criteria, and extends them to appropriate parties, thereby simplifying the overall system architecture
Solution Approach 2:
The authentication extension process is segmented into distinct functional components: the issuing entity performs initial FIDO authentication, the processing network receives and validates the authentication result, and then extends it to other entities as needed. This segmentation allows each component to focus on specific tasks, reducing individual complexity while enabling overall system adaptability
Data Source
AI summary
Systems and methods are provided for extending authentication from a third party. An example computer-implemented method includes receiving an authentication request associated with a transaction to an account, from an access control server (ACS), where the authentication request includes an account number for the account, and requesting authentication of a user of the account, from an issuer of the account, at a mobile device. The method also includes receiving an authentication result, from the mobile device, which is signed by a private key, and verifying the signed authentication result, based on a public key associated the mobile device. The method then includes returning the authentication result to the ACS, in response to the authentication request.


