Mobile Device Multifactor Authentication for Financial Accounts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current multifactor authentication methods for accessing financial accounts via mobile devices are cumbersome and insecure, as they often rely solely on something the user knows, making them vulnerable to unauthorized access by malicious programs capturing usernames and passwords.

Innovation Solution

A computer-implemented method using a mobile device to verify a customer verification code, mobile user identification code, and customer personal identification number, which are sent through a network to securely access a financial account, incorporating a time-limited activation code and unique device identifiers for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multifactor authentication is implemented using mobile devices, then account security is improved, but the authentication process becomes more cumbersome

Engineering Contradiction:
Improveaccount securityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines multiple authentication factors (something the user knows via PIN, something the user has via mobile device with unique identifier, and something the user is via biometric data) into a single integrated authentication process. This merging of authentication methods strengthens security while maintaining user convenience through automated verification.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system enables self-service authentication where the mobile device automatically provides its unique identifier and the user simply needs to input their PIN or provide biometric data. The authentication process serves itself by automatically verifying credentials against the financial institution's system without requiring manual intervention from support staff.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If traditional username and password authentication is used, then ease of access is improved, but security is worsened due to vulnerability to spyware capture

Engineering Contradiction:
Improveaccount accessVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The mobile device acts as an intermediary authentication element between the user and the financial institution's system. Instead of directly transmitting usernames and passwords that can be captured by spyware, the system uses the mobile device's unique identifier as a secure mediator that cannot be easily replicated or stolen, thereby maintaining ease of access while significantly improving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces the vulnerable username-password combination with a copy of the mobile device's unique identifier (such as IMEI or SIM card number) that is automatically provided by the device itself. This copying approach eliminates the need for users to manually enter vulnerable credentials while maintaining authentication functionality.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS7788151B2Systems and methods for accessing a secure electronic environment with a mobile device
Publication Date: 2010.08.31 FIDELITY INFORMATION SERVICES LLC
  • US7788151B2 patent drawing
  • US7788151B2 patent drawing
  • US7788151B2 patent drawing

AI summary

The invention provides a system and methods for multifactor authentication of a mobile device for access to an electronic account. The mobile device may serve as one factor of a multifactor authentication process. A time based activation code may be generated in order to enroll an electronic account for mobile access.