Multilayer Mobile Credentials for Precise Authentication Failure Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing internet mobile-related transactions face challenges in precise authentication due to the use of multiple input data for generating dynamic credentials, making it difficult for servers to identify the specific input data causing authentication failures, and requiring a dynamic authentication policy that balances security, device configuration, and channel capabilities.
Innovation Solution
A method where internet transactions are authenticated through a set of individual authentications of user's mobile device-generated dynamic credentials, each associated with a given input data, using a mobile device to generate credentials based on input data like PIN, transaction amount, time stamp, and geographic coordinates, and sending these credentials to a multilayer security system for authorization based on predefined authentication rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple input data are used to generate dynamic credentials, then authentication security is improved, but the ability to precisely identify the specific input data causing authentication failures deteriorates
Solution Approach 1:
The patent segments the authentication process by dividing multiple input data into separate, independent dynamic credentials. Each credential is generated from a single input data (e.g., password credential from password only, timestamp credential from timestamp only). This segmentation allows the server to identify which specific credential failed authentication, thereby identifying the problematic input data while maintaining the security benefits of using multiple inputs.
2Reliability
If all dynamic credentials are required for successful authentication, then authentication security is improved, but the adaptability to different transaction types and device configurations deteriorates
Solution Approach 1:
The patent implements dynamic authentication policies that can be configured based on transaction type, device capabilities, and security requirements. The server can dynamically select which credentials are mandatory and which are optional for different transaction scenarios. For example, low-value transactions may require fewer credentials while high-value transactions require all credentials, allowing the system to adapt security requirements to the specific context.
3Measurement precision
If individual authentication of each dynamic credential is implemented, then the precision of authentication monitoring is improved, but the complexity of the authentication system increases
Solution Approach 1:
The patent introduces an intermediary authentication server that manages the complexity of individual credential authentication. The server receives multiple independent credentials, individually authenticates each one, and coordinates the overall authentication process. This intermediary approach enables precise monitoring of which specific credential failed while centralizing the complex logic, thereby reducing the burden on client devices and maintaining system manageability.
Data Source
AI summary
Methods and apparatus to authenticate internet transactions upon a set of authentications of user's mobile device generated dynamic credentials. A mobile device generates dynamic authentication credentials and a transaction terminal transmits at least part of them. One or more providers of authentication services receives from the transaction terminal a first dynamic authentication credential generated by the mobile device using a user's PIN, one or more additional dynamic authentication credentials, calculated by the mobile device upon a different input data, and at least one identifier, and authenticates the first dynamic authentication credential and further authenticates, based on authentication rules and associated authentication parameters, one or more of the one or more additional dynamic authentication credentials, sending the result of the authentication, and the internet transaction being authorized or denied based upon that authentication result, where the transaction being authorized always requires a successful result of the authentication of the first dynamic authentication credential.


