Two-Factor Authentication via Mobile SMS Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional second authentication factors, such as signatures, three-digit verification numbers, and debit card PINs, are susceptible to criminal attacks due to their physical presence on cards or reuse in transactions, leading to vulnerabilities in financial transactions.

Innovation Solution

Implementing a two-factor authentication system that uses a mobile phone as a second authentication factor, where a verification indicia is sent via SMS, requiring the user to respond to confirm possession of the phone, thereby enhancing security without relying on physical card presence or reusable PINs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional second authentication factors (signatures, verification numbers, PINs) are used, then authentication is provided, but they are susceptible to criminal attack due to physical presence on cards or reuse in transactions

Engineering Contradiction:
Improveauthentication securityVSAvoidcriminal attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication factor from the physical card by using a mobile phone as the second authentication device. The verification indicia is sent via SMS to the mobile phone, separating the authentication process from the physical card presence. This resolves the contradiction by removing the vulnerable element (card-based authentication) while maintaining the security function.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements dynamic authentication by using one-time verification indicia sent via SMS. The verification code changes with each transaction and cannot be reused, transforming the static authentication factors (fixed PINs, visible signatures) into dynamic, transaction-specific codes. This eliminates the reuse vulnerability while maintaining authentication reliability.

Inventive Principle:
Principle #15Dynamics

2Reliability

If verification indicia is sent via SMS to mobile phone, then authentication security is enhanced, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The mobile phone, which consumers already possess and use daily, provides the authentication function without requiring additional specialized devices. The phone's existing SMS capability is leveraged to deliver verification indicia, making the system self-service rather than adding complex new hardware. This resolves the complexity contradiction by using existing infrastructure.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses SMS as an intermediary communication channel between the authentication system and the user's mobile phone. This intermediary approach simplifies the system architecture by leveraging the existing SMS infrastructure rather than requiring direct complex communication protocols or additional authentication hardware. The SMS message serves as the carrier for the verification indicia, simplifying the overall system design.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7600676B1Two factor authentications for financial transactions
Publication Date: 2009.10.13 CELLCO PARTNERSHIP INC
  • US7600676B1 patent drawing
  • US7600676B1 patent drawing
  • US7600676B1 patent drawing

AI summary

The present invention relates to a method for authenticating financial transactions by using an additional factor which is not present on a physical card, and which is not used in sequential transactions. In one example, a purchaser provides card information to a merchant; the merchant transmits the card information and transaction information to an issuer; the issuer authenticates the card information, and transmits verification indicia to a target address associated with the card information. The purchaser target address may be the telephone number of a mobile telephone of the purchaser or a third party (e.g. parent). The purchaser or third party provides the verification indicia to a merchant; and the merchant transmits the verification indicia back to the issuer. The issuer authenticates that the received verification indicia relative to that sent to the target address, and thus the purchaser is the genuine or authentic person authorized to use card information; and the issuer approves the transaction.