One-Time Token Authentication via Push Notification Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large organizations face information security risks when customers interact with online portals, particularly in online banking, as existing security measures may not adequately protect customer information and accounts from unauthorized access.
Innovation Solution
Implementing a system that uses one-time tokens (OTTs) and push notifications to authenticate and authorize access to online banking portals, ensuring that only registered devices can approve or decline transactions, thereby enhancing security by requiring user verification through biometric authentication and encrypted messages.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods (passwords, email verification) are used for online banking access, then ease of operation is maintained, but information security is insufficient and vulnerable to unauthorized access
Solution Approach 1:
The patent introduces a push notification service as an intermediary between the online banking system and the user's mobile device. This intermediary delivers one-time tokens directly to the registered device, providing enhanced security without requiring the user to manually check email or SMS accounts. The notification service acts as a trusted mediator that ensures secure, convenient delivery of authentication credentials.
Solution Approach 2:
The patent implements one-time tokens that are generated, used, and then discarded after a single authentication event. These temporary credentials provide strong security because they cannot be reused or intercepted for future attacks. Each login session receives a fresh token that becomes invalid immediately after use, eliminating the security risks associated with persistent passwords.
2Reliability
If one-time tokens are sent via traditional SMS or email, then implementation simplicity is maintained, but security is compromised as messages can be intercepted or accessed by unauthorized persons
Solution Approach 1:
The push notification service serves as a secure intermediary that leverages the existing trusted relationship between the mobile operating system and registered applications. Rather than sending tokens through vulnerable channels like SMS or email, the system uses the OS-level push notification infrastructure that is already encrypted and device-specific, providing secure delivery without requiring complex custom implementation.
Solution Approach 2:
The patent leverages the existing push notification infrastructure that is already built into mobile operating systems (iOS APNs, Android FCM). This universal service handles message delivery, encryption, and device registration across different platforms, eliminating the need to build a custom notification system from scratch while maintaining high security standards.
3Reliability
If multiple security layers (device registration, biometric authentication, one-time tokens) are implemented, then information security is significantly enhanced, but device complexity and ease of operation are reduced
Solution Approach 1:
The patent combines multiple security mechanisms into a unified authentication flow: device registration is performed once and stored securely; biometric authentication is integrated into the token generation process; and one-time tokens are automatically delivered via push notifications. This merging of security layers into a cohesive system reduces the operational burden on users compared to implementing each security measure as a separate, manual step.
Solution Approach 2:
The system performs several security functions automatically without requiring active user intervention: the push notification is delivered and displayed automatically; the one-time token is generated and presented to the user; the authentication decision is made based on token validation. This self-service approach to security reduces the complexity of user interaction while maintaining strong security controls.
Data Source
AI summary
Methods, systems, and computer-readable media for ensuring information security using one-time tokens are presented. In one or more embodiments, a computing platform may receive, from a user device, a request to access an online banking portal using a user account. Based on the request, the computing platform may generate and send a notification to a registered mobile device linked to the user account. After sending the notification, the computing platform may generate a one-time token message that includes a prompt for authorizing the user device to access the online banking portal using the user account. The computing platform then may send the one-time token message to the mobile device and receive token response input from the mobile device. Based on the input, the computing platform may prevent the user device from accessing the online banking portal or, alternatively, may provide the user device with access to the online banking portal.


