Mobile Payment Authentication via Device ID and Supplemental ID
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile commerce and electronic commerce transaction systems face challenges such as cumbersome user experiences, security vulnerabilities, and the risk of fraudulent transactions due to inadequate authentication methods and data storage practices, particularly on mobile devices.
Innovation Solution
A system and method that authenticates transactions by registering a mobile device with a payment ID and supplemental ID, where the mobile device ID is generated and stored on the server, and only the supplemental ID is required as user input for subsequent transactions, enhancing security and reducing the risk of accidental or fraudulent transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If single-factor authentication (username and password) is used for transactions, then ease of operation is improved, but security is worsened
Solution Approach 1:
The patent segments authentication into multiple independent factors: something the user knows (password), something the user has (mobile device), and something the user is (biometric data). This multi-factor segmentation strengthens security while maintaining operational ease through automated device recognition.
Solution Approach 2:
The system performs preliminary registration where the mobile device is pre-associated with the user account and authentication factors. During transactions, this preliminary setup enables rapid verification without requiring manual entry of all credentials, thus maintaining ease of operation while enhancing security.
2Productivity
If transaction data is stored on the server system for single-click completion, then productivity is improved, but security is worsened due to accidental or fraudulent transactions
Solution Approach 1:
The system performs preliminary registration of the mobile device with the user account and stores encrypted authentication factors. During transactions, this preliminary setup enables rapid verification without requiring manual entry of all credentials, thus maintaining ease of operation while enhancing security.
Solution Approach 2:
The mobile device acts as an intermediary security layer between the user and the transaction system. It holds encrypted authentication factors and verifies user possession through biometric or device-specific credentials, preventing unauthorized transactions even if server data is compromised.
3Ease of operation
If password stores and form wizards are used to store transaction data, then ease of operation is improved, but security is worsened due to insecure storage practices
Solution Approach 1:
The mobile device acts as a secure intermediary that stores encrypted authentication factors locally rather than in insecure server-side password stores. The device uses hardware-backed security and encrypted storage, eliminating vulnerabilities associated with traditional password managers while maintaining ease of use through automatic credential retrieval.
4Ease of operation
If credit card number is used as authentication factor, then ease of operation is improved, but security is worsened as it does not prove possession of the card
Solution Approach 1:
The patent segments authentication into multiple independent factors: something the user knows (password), something the user has (mobile device), and something the user is (biometric data). This multi-factor segmentation strengthens security while maintaining operational ease through automated device recognition.
Solution Approach 2:
The mobile device acts as an intermediary security layer between the user and the transaction system. It holds encrypted authentication factors and verifies user possession through biometric or device-specific credentials, preventing unauthorized transactions even if server data is compromised.
Data Source
AI summary
Systems and methods are provided for providing a more seamless purchasing experience using a mobile device. The mobile device acquires data, such a barcode image, an image of an object or text, or audio data. A non-limiting example of a barcode is a Quick Response (QR) barcode. The acquired data is then used to obtain a network address of a payment website or webpage, which allows a user to make a purchase for a given product or service. The mobile device then launches the payment website or webpage. A user can enter into the mobile device, through the payment website or webpage, a supplemental ID used for authenticating the transaction.


