Mobile Gateway Authentication via M-PIN and CUID

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices pose security risks for financial transactions due to interception of signals and the risk of lost or stolen devices containing sensitive financial information, necessitating a secure method for initiating and participating in financial transactions.

Innovation Solution

A method and system that utilize a mobile personal identification number (M-PIN) and Customer Unique Identifier (CUID) to generate a Mobile Unique Identifier (MUID), which provides secure access to financial account processors through a gateway, involving enrollment processes, security challenge questions, and SMS activation codes to ensure secure transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If mobile devices are used for financial transactions, then convenience and accessibility are improved, but security risks increase due to signal interception and device loss

Engineering Contradiction:
Improveconvenience of financial transactionsVSAvoidsecurity of financial transactions
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a gateway as an intermediary component that mediates between the mobile device and financial account processors. The gateway receives authentication credentials (M-PIN, CUID) from the mobile device, verifies them against stored enrollment information, and establishes secure connections to financial processors. This intermediary architecture allows mobile devices to access financial services conveniently while the gateway handles security verification, preventing direct exposure of sensitive financial data to the mobile device and mitigating risks from signal interception and device loss.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If extensive security measures are implemented, then transaction security is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity of financial transactionsVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the financial transaction system into distinct functional components: mobile device client, gateway authentication server, and financial account processors. Each component has a specific security responsibility - the mobile device stores credentials securely, the gateway handles authentication logic and enrollment management, and financial processors handle transaction processing. This segmentation allows comprehensive security measures to be implemented in each segment independently without requiring the entire system to become uniformly complex, making the overall system more manageable while maintaining high security standards.

Inventive Principle:
Principle #1Segmentation

3Reliability

If multiple authentication factors are required, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity verificationVSAvoiduser operation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by requiring users to complete an enrollment process beforehand, during which authentication credentials (M-PIN, CUID) are generated and stored securely. Once enrolled, users can access financial services using these pre-configured credentials without needing to repeatedly provide multiple forms of authentication. The gateway has already verified and stored the enrollment information during the initial setup, so subsequent transactions can proceed more smoothly while still maintaining security through the pre-verified credentials.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8364587B2Systems and methods for financial account access for a mobile device via a gateway
Publication Date: 2013.01.29 FIRST DATA CORP
  • US8364587B2 patent drawing
  • US8364587B2 patent drawing
  • US8364587B2 patent drawing

AI summary

Systems and methods for providing secure access of at least one of multiple financial account processors to a mobile device and/or facilitating secure financial transactions initiated from a mobile device via a gateway. One method can include receiving a mobile personal identification number (M-PIN) number and Customer Unique Identifier (CUID) from a mobile device and processing the received M-PIN and CUID to identify a Mobile Unique Identifier (MUID). The MUID identifies an account of at least one financial account processor accessible via a gateway, and the mobile device is provided access to the account through the gateway.