Multi-point Payment Authentication via Mobile Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current payment card security systems are vulnerable to fraud and breaches, as they rely primarily on physical card possession and signature verification, which can be easily compromised, leading to significant financial losses and loss of trust for consumers and merchants.
Innovation Solution
Implementing a multi-point authentication system that requires both physical possession of a payment card and a mobile device associated with the cardholder, using randomized transaction and authentication identifiers to validate transactions, ensuring that hackers without the mobile device cannot complete transactions, even if they have stolen card information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multi-point authentication is implemented requiring both payment card and mobile device, then transaction security is improved, but device complexity and operation steps increase
Solution Approach 1:
The authentication system is segmented into multiple independent verification points: (1) payment card physical possession verification at POS terminal, (2) mobile device authentication via push notification or code generation, and (3) randomized transaction identifier matching. This segmentation allows each component to be simple while the combination provides strong security.
Solution Approach 2:
The mobile device acts as an intermediary between the cardholder and the payment processing system. It receives authentication requests, generates or displays verification codes, and transmits confirmation back to the payment association, serving as a trusted mediator that enhances security without requiring direct complex interaction between the card and payment system.
2Object-affected harmful factors
If randomized authentication identifiers are used, then fraud resistance is improved, but processing time and system complexity increase
Solution Approach 1:
Randomized authentication identifiers and transaction codes are generated and transmitted to the mobile device in advance of the actual payment completion. The mobile device prepares verification codes or push notifications before the transaction finalizes, allowing rapid verification at the point of sale without delaying the payment process.
Solution Approach 2:
The system uses randomized parameters (transaction identifiers, authentication codes, verification tokens) that change with each transaction. These dynamic parameters provide strong fraud resistance while being processed as simple data fields, minimizing processing overhead and time impact.
3Reliability
If additional authentication factors are required, then security against breaches is improved, but ease of operation decreases
Solution Approach 1:
The mobile device provides self-service authentication capabilities where the cardholder independently generates or receives verification codes, approves push notifications, or displays authentication information without requiring assistance from merchants or payment processors. This maintains convenience while enhancing security.
Solution Approach 2:
The mobile device serves multiple functions: it stores authentication credentials, generates verification codes, receives push notifications, displays transaction details, and communicates with both the POS terminal and payment association. This multi-functionality consolidates multiple authentication steps into a single device interaction, maintaining ease of use.
Data Source
AI summary
Authentication includes determining that a cardholder payment account is associated with a mobile device. Authentication includes receiving an indication of physical possession of a payment card. Authentication includes receiving a purchase request for an authorization of an exchange of funds from the cardholder account to the merchant. Authentication includes receiving a randomized transaction identifier to the request for the authorization of the exchange. Authentication includes transmitting to the mobile device, information associated with the request. Authentication includes transmitting to the mobile device, a request for confirmation of the authorization from the cardholder from the account of the cardholder to the merchant. Authentication includes receiving an indication, facilitated by the cardholder, that the exchange is authorized. Authentication includes authorizing the exchange of from the payment account of the cardholder to the merchant.


