Multi-Device Transaction Authentication via Push Notifications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current digital security systems lack effective authentication and authorization methods, leading to fraudulent transactions due to inadequate verification processes, which are often burdensome for users and vulnerable to malicious activities.
Innovation Solution
A method that utilizes push-based challenges on mobile devices for real-time authentication and authorization, involving multiple authority devices for transaction verification, including additional agent verification to ensure only authorized users can complete transactions, thereby enhancing security without being intrusive.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional authentication methods (passwords, physical cards, biometrics) are used, then user convenience is improved, but security against fraudulent transactions deteriorates
Solution Approach 1:
The authentication system is segmented into multiple independent authority devices that must collectively verify a transaction. Instead of relying on a single authentication method, the system divides the verification process across multiple devices (e.g., mobile phones, tablets, computers) that the user possesses. This segmentation ensures that even if one device is compromised, the transaction cannot be completed without consensus from multiple authorities, thereby maintaining security while preserving user convenience through familiar devices.
Solution Approach 2:
The patent introduces an intermediary verification process where authority devices act as mediators between the transaction initiator and the final authorization. The intermediary layer communicates transaction details to multiple authority devices, which then independently verify and collectively authorize the transaction. This intermediary mechanism adds a security layer without requiring users to directly manage complex authentication credentials, thus maintaining ease of operation while improving reliability.
2Reliability
If multiple authority devices are used for transaction verification, then security is improved, but device complexity increases
Solution Approach 1:
The authentication system utilizes universal multi-functional devices that users already possess and are familiar with, such as smartphones, tablets, and computers. These devices can serve multiple purposes: daily communication, information access, and security verification. By leveraging the universality of these existing devices, the system avoids introducing specialized hardware, thereby reducing overall system complexity while maintaining high security through multi-device verification.
Solution Approach 2:
The authority devices perform self-service verification by automatically receiving transaction notifications, displaying details, and allowing users to approve or deny transactions through familiar interfaces. The system leverages the device's existing capabilities (display, communication, user interface) without requiring additional specialized components. This self-service approach simplifies the system architecture while enhancing security through distributed verification across multiple user-owned devices.
3Reliability
If real-time transaction confirmation is implemented, then fraud prevention is improved, but response time requirements increase system pressure
Solution Approach 1:
The system performs preliminary actions by proactively notifying authority devices of pending transactions before final authorization is granted. Instead of waiting for all verification steps to complete before notifying users, the system sends advance notifications with transaction details, allowing users to prepare for verification. This preliminary notification approach enables real-time fraud prevention while distributing the time pressure, as users have adequate notice without creating bottlenecks in the overall transaction processing speed.
Data Source
AI summary
A method of completing a transaction that requires authorization by an authority agent includes registering an authority device as associated with the authority agent, receiving a transaction request from a service provider; pushing an authentication notification to the authenticating application of the authority device; displaying the authentication notification, including a prompt to supply agent verification data, on the authority device; collecting and verifying the agent verification data; in response to verification of the agent verification data, transmitting an authority agent response from the authority device to the authentication platform, and, at the authentication platform, authenticating the authority agent response; and in response to authenticating the authority agent response, transmitting a transaction confirmation from the authentication platform to the service provider.


