Mobile Transaction Authentication via Location Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Transactions conducted using mobile devices are vulnerable to fraud, as fraudsters can obtain payment credential information, leading to unauthorized transactions, and existing authentication methods may result in unnecessary transaction declines due to caution, necessitating additional forms of verification.
Innovation Solution
A network and method that authenticates transactions by comparing the locations of mobile devices and point-of-sale (POS) devices using a transaction authentication system, which accesses location data from a POS registry and a PAN registry to determine if the mobile device and POS device are at the same location, thereby verifying the authenticity of the transaction.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If additional authentication methods are implemented for mobile device transactions, then transaction security is improved, but device complexity and processing time increase
Solution Approach 1:
The patent introduces a location comparison mechanism as an intermediary authentication layer. Instead of directly verifying payment credentials, the system first verifies that the mobile device and POS terminal are at the same location using location data from service providers. This intermediary check adds security without requiring complex cryptographic verification of every transaction credential.
Solution Approach 2:
The system performs location verification as a preliminary authentication step before processing the actual transaction. By checking location data in advance and comparing it between the mobile device and POS terminal, the system establishes a baseline security check that prevents fraudulent transactions before they reach the credential verification stage, reducing the need for multiple subsequent authentication layers.
2Reliability
If location-based authentication is implemented, then fraudulent transactions are reduced, but data processing requirements and system complexity increase
Solution Approach 1:
The patent leverages existing multi-functional systems to avoid building dedicated location verification infrastructure. It utilizes location data already maintained by mobile service providers for billing and network management purposes, and existing POS terminal location registration systems. By making these existing systems serve the additional function of fraud prevention through location comparison, the patent avoids duplicating infrastructure and reduces overall system complexity.
Solution Approach 2:
The system allows POS terminals and mobile service providers to maintain their own location data registries independently. Each entity manages its own location information without requiring centralized collection or coordination, thereby simplifying the overall system architecture. The authentication system merely compares data that already exists in these self-maintained registries rather than requiring active location reporting from all devices.
3Reliability
If strict authentication protocols are applied to mobile transactions, then transaction security is improved, but transaction approval rate decreases due to false positives
Solution Approach 1:
The patent applies location verification selectively to mobile device transactions rather than uniformly to all transaction types. By identifying transactions initiated from mobile devices and applying location-based authentication specifically to those cases, the system enhances security where needed while allowing traditional authentication methods to handle other transaction types, thereby maintaining higher overall approval rates.
Solution Approach 2:
The system performs a partial authentication check by verifying only the location component rather than requiring complete credential verification for every transaction. This partial action approach allows the system to quickly filter out obviously fraudulent transactions (those with location mismatches) while allowing legitimate transactions to proceed with standard authentication, balancing security with approval rates.
Data Source
AI summary
A transaction authentication system authenticates a transaction by determining whether a mobile device and POS device involved in the transaction are at the same location. A POS registry stores location data for POS devices. A PAN registry stores mobile device IDs corresponding to account numbers. A mobile device ID can be provided from the PAN registry in response to receiving an account number from a POS device. The mobile device ID can then be used to retrieve location information from a home location register maintained by a mobile service provider. The retrieved location data for a POS device and the retrieved location data for a mobile device are compared.


