One-Click Payment Token Generation for Secure Checkout
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional customer authentication methods for financial transactions are insecure, inconvenient, and fail to leverage biometric factors, leading to a trade-off between security and convenience, particularly in card-not-present transactions, and are inflexible across different transaction types and channels.
Innovation Solution
A one-click payment system that uses mobile devices for authentication through biometric and behavioral data, generating a unique, one-time token for secure online checkout processes, allowing for streamlined authentication and secure storage of payment information in a passbook, adaptable to varying transaction risk levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional single-factor authentication (card swipe) is used for card-present transactions, then the authentication process is simple and convenient, but security is compromised as cards can be lost, stolen, or counterfeited
Solution Approach 1:
The patent combines multiple authentication factors (possession of mobile device, biometric inherence, and knowledge) into a unified authentication system. The mobile device integrates the authentication engine, biometric sensors, and communication capabilities to provide multi-factor authentication that maintains convenience while enhancing security against card loss, theft, and counterfeiting
2Reliability
If two-factor authentication (card + PIN) is used for ATM transactions, then security is improved, but convenience deteriorates as cardholders must carry the card and memorize PIN codes
Solution Approach 1:
The system employs biometric authentication (fingerprint, facial recognition, or iris scanning) that automatically verifies the cardholder's identity without requiring manual PIN entry. The authentication engine on the mobile device or terminal performs self-service verification by comparing biometric data against stored templates, eliminating the need for users to memorize or manually input PIN codes while maintaining strong security
3Reliability
If knowledge factor authentication (passwords, billing information) is used for online purchases, then security is enhanced, but the authentication process becomes complex and inconvenient
Solution Approach 1:
The patent replaces manual entry of knowledge factors (passwords, billing information) with biometric authentication and mobile device-based verification. The authentication engine uses biometric sensors to capture physiological data and compares it against stored templates, substituting the mechanical process of typing passwords and billing information with automatic biometric verification, thereby reducing complexity while maintaining security
4Reliability
If EMV smart card authentication is implemented, then card-present transaction security is improved, but the solution is inapplicable to online purchases and requires card presence
Solution Approach 1:
The patent creates a universal authentication system that works across multiple transaction channels (card-present, card-not-present, online, mobile). The authentication engine can operate with biometric data stored on the mobile device, in the cloud, or on the terminal, allowing the same system to authenticate both in-person and online transactions without requiring physical card presence, thereby providing channel-agnostic security
Data Source
AI summary
Embodiments of the present invention are directed to a “one-click payment” scheme for streamlining customers' online checkout experiences. According to one particular embodiment, a customer can use a computing device to be authenticated and receive a unique, one-time token to make a one-click payment during an online checkout process. The one-time token may be encrypted and directly associated with a payment account which the customer is authorized to access. The online merchant may forward a transaction request including the one-time token and purchase amount to an authorization server which would verify the token and charge the corresponding payment account.


