Mobile FIDO Authentication Extension Across Transaction Parties

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods, such as FIDO, are limited to specific parties and do not easily extend across different entities, limiting their applicability and functionality in transactions.

Innovation Solution

A system and method that leverages FIDO authentication for network traffic by using a mobile device to generate key pairs, enroll users with an issuer institution and a processing network, and facilitate biometric transactions, enabling authentication across multiple parties through a unified authentication framework.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If FIDO authentication is used for specific parties, then authentication reliability is improved, but adaptability across different entities deteriorates

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidadaptability across entities
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal authentication framework where FIDO authentication results can be extended and recognized across multiple different entities and systems. The processing network acts as a intermediary that accepts authentication from one entity (e.g., issuer institution) and extends it to other entities (e.g., acquiring bank, third-party services), making the authentication mechanism multi-functional and broadly applicable rather than entity-specific

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The processing network serves as an intermediary layer between different authentication entities. It receives authentication results from one party (such as the issuer institution performing FIDO authentication) and mediates by extending and validating these results for other parties involved in the transaction, enabling trust propagation across multiple entities without requiring direct authentication between each pair

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If authentication is extended across multiple parties, then adaptability is improved, but system complexity increases

Engineering Contradiction:
Improveauthentication extendabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The processing network functions as a centralized intermediary that handles the complexity of authentication extension. Instead of each entity implementing its own complex authentication extension logic, the processing network provides a unified service that accepts authentication results, validates them against established criteria, and extends them to appropriate parties, thereby simplifying the overall system architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication extension process is segmented into distinct functional components: the issuing entity performs initial FIDO authentication, the processing network receives and validates the authentication result, and then extends it to other entities as needed. This segmentation allows each component to focus on specific tasks, reducing individual complexity while enabling overall system adaptability

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250300814A1Systems and methods for extending authentication
Publication Date: 2025.09.25 MASTERCARD INT INC
  • US20250300814A1 patent drawing
  • US20250300814A1 patent drawing
  • US20250300814A1 patent drawing

AI summary

Systems and methods are provided for extending authentication from a third party. An example computer-implemented method includes receiving an authentication request associated with a transaction to an account, from an access control server (ACS), where the authentication request includes an account number for the account, and requesting authentication of a user of the account, from an issuer of the account, at a mobile device. The method also includes receiving an authentication result, from the mobile device, which is signed by a private key, and verifying the signed authentication result, based on a public key associated the mobile device. The method then includes returning the authentication result to the ACS, in response to the authentication request.