Mobile Payer Authentication via Device Display Attributes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing volume of 'Card Not Present' (CNP) transactions, facilitated by technological advancements, has led to increased fraudulent activities and monetary losses due to inadequate authentication methods, particularly when using internet-enabled cellular telephones for e-commerce transactions.

Innovation Solution

The system addresses this by obtaining a logical address of a computing device, accessing its display attributes, formatting an authentication request, and validating the received authentication information, which is then digitally signed and transmitted to the merchant, ensuring secure authentication for CNP transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional authentication methods are used for CNP transactions, then transaction convenience is improved, but security and reliability deteriorate due to increased fraudulent activities

Engineering Contradiction:
Improvetransaction convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an access control server (ACS) as an intermediary between the merchant and the cardholder. The ACS receives authentication requests from merchants, validates them against the cardholder's profile, and returns authentication results. This intermediary layer enhances security by centralizing authentication logic while maintaining convenience for cardholders through standardized authentication flows.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication validation before completing the transaction. The ACS validates the cardholder's identity, transaction amount, and account status in advance, and only after successful validation does it authorize the transaction to proceed. This preliminary action prevents fraudulent transactions before they can cause harm.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If simple authentication requests are sent to mobile devices, then ease of operation is improved, but reliability deteriorates because mobile devices have limited display capabilities and may not display authentication information correctly

Engineering Contradiction:
Improveease of operationVSAvoidauthentication accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by customizing the authentication request format specifically for mobile devices. The system detects the device type and adjusts the authentication interface to match mobile display characteristics, ensuring that authentication information is presented in a format optimized for mobile screens while maintaining security requirements.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes parameters of the authentication request based on the receiving device. For mobile devices, it modifies display parameters such as font size, layout, and information hierarchy to suit smaller screens. These parameter changes ensure that authentication information remains accurate and reliable while being easily viewable on mobile devices.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8639600B2Mobile payer authentication
Publication Date: 2014.01.28 VISA USA INC
  • US8639600B2 patent drawing
  • US8639600B2 patent drawing
  • US8639600B2 patent drawing

AI summary

An address of a computing device for conducting a transaction with a merchant on an account of an account holder is used to obtain display attributes of the computing device. An authentication request is formatted using the obtained display attributes of the computing device. The formatted authentication request is sent for delivery to the logical address of the computing device. In response to the formatted authentication request, authentication information for the account holder is received from the logical address of the computing device. A validation attempt is performed on the received authentication information for the account holder. If the received authentication information for the account holder was successfully validated by the performance of the validation attempt, the authentication response is transmitted for delivery to a logical address for the merchant.