Mobile Location Matching for In-Person Transaction Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users are hesitant to share sensitive information during transactions due to security concerns, and existing authentication methods lack effective verification of the authorized user's presence at the resource provider, especially in face-to-face transactions.
Innovation Solution
A method and system that uses a user's communication device to authenticate transactions by matching the location of the device with a predetermined threshold distance from an access device, without requiring contactless elements or specialized hardware, and employs tokenization to protect sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If users share sensitive information during transactions, then transaction authorization can be completed, but security risks increase due to potential fraud and interception
Solution Approach 1:
The patent extracts sensitive information from the transaction flow by using tokenization. The primary account number (PAN) is replaced with a token that has no meaningful value if intercepted. This removes the harmful element (sensitive information) from the communication channel while preserving the essential function of transaction authorization.
Solution Approach 2:
The patent introduces an intermediary authentication system that verifies the user's physical presence at the resource provider location before authorizing the transaction. This intermediary layer (location verification system) acts as a mediator between the user and the authorization entity, adding a security checkpoint without blocking legitimate transactions.
2Reliability
If authentication systems verify user presence at resource provider, then fraud prevention improves, but system complexity increases
Solution Approach 1:
The patent implements self-service authentication where the user's mobile device automatically performs location verification and token generation without requiring specialized hardware at the resource provider. The device uses its own GPS and communication capabilities to authenticate itself, eliminating the need for complex authentication infrastructure at the merchant side.
Solution Approach 2:
The patent makes the user's existing mobile device perform multiple functions: it serves as both the payment credential holder and the authentication device. The mobile device's location services, communication capabilities, and processing power are leveraged for authentication, eliminating the need for separate specialized authentication hardware.
3Reliability
If specialized hardware is used for secure transactions, then transaction security improves, but device complexity and cost increase
Solution Approach 1:
The patent creates a functional copy of secure payment capabilities in the mobile device's software environment. Instead of requiring specialized hardware security modules, the system uses software-based tokenization and authentication protocols that replicate the security functions of hardware-based systems while being more accessible and less complex.
Data Source
AI summary
According to some embodiments of the invention, an authentication method is provided. Transaction data for a transaction is received at a communication device from an access device or a resource provider. The transaction data comprises a location of the access device. A location of the communication device is determined by the communication device. It is determined whether a distance between the location of the access device and the location of the communication device is within a predetermined threshold. The transaction is not authorized if the distance between the location of the access device and the location of the communication device is not within a predetermined threshold.


