Multifactor Authentication Using Mobile Token Image

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for electronic transactions lack a comprehensive solution for multifactor authentication, leading to increased fraud in ATM, credit card, and online transactions, as they often rely on single-factor approaches that are inconvenient, insecure, or unreliable.

Innovation Solution

A system that uses a mobile application to read user account information from a token, such as a card with a high-density two-dimensional code, combining 'what the user has,' 'what the user knows,' and 'what the bank knows' for authentication, employing public/private key pairs for secure communication and encryption to verify transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If token-based user authentication is employed, then authentication security is improved, but device complexity and user convenience deteriorate due to additional issuance and administration of hardware security tokens

Engineering Contradiction:
Improveauthentication securityVSAvoidhardware security token administration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces physical hardware security tokens with their digital equivalent - a digital image of the token displayed on a mobile device screen. The token data is captured as an image file that can be displayed and shared digitally, eliminating the need for physical token issuance and administration while maintaining security through the same token verification mechanisms

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent substitutes the mechanical/physical token handling system with an electronic/digital system. Instead of physically distributing and managing hardware tokens, the system uses mobile devices to display digital token images that can be electronically transmitted and verified, replacing the mechanical token administration infrastructure with software-based solutions

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If SMS messages are used for authentication, then user convenience is improved, but reliability deteriorates due to SMS attacks and message delivery issues

Engineering Contradiction:
Improveuser convenienceVSAvoidauthentication reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediary mechanism - a mobile device acting as a secure intermediary that hosts the token image. Instead of relying on SMS messages that can be intercepted or fail to deliver, the token image is displayed on the mobile device screen and can be securely shared through controlled mechanisms, with the mobile device serving as a trusted intermediary that verifies and presents authentication credentials

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If credit card information is stored on mobile device, then user convenience is improved, but security deteriorates as the person possessing the phone possesses the maximum value of the credit limit

Engineering Contradiction:
Improveuser convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication process into distinct components: the token image (visual credential), the mobile device (display and transmission medium), and the verification system (backend validation). By separating these functions, the system avoids storing sensitive card information on the mobile device while still enabling convenient access. The token image itself is segmented from the actual card data, providing a visual reference without exposing sensitive information

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10270587B1Methods and systems for electronic transactions using multifactor authentication
Publication Date: 2019.04.23 CITIGROUP TECHNOLOGY INC
  • US10270587B1 patent drawing
  • US10270587B1 patent drawing
  • US10270587B1 patent drawing

AI summary

Methods and systems for performing electronic transactions involve receiving, using a processor coupled to memory, from a mobile application on a user's mobile device processor, a transaction message consisting at least in part of the user's account information obtained by the mobile application reading user account information encoded on a token of the user that is physically distinct from the mobile device processor and a transaction request for the user. Using the processor, the user's account information is verified and a transaction confirmation message is generated and sent to the mobile application on the user's mobile device processor.