Online Authentication Service Mediator for Fraud Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for authenticating account holders during online transactions are cumbersome, difficult to use, and lack interoperability, leading to increased fraud and security concerns, particularly in 'card not present' transactions, which hinder the growth of electronic commerce.
Innovation Solution
An account authentication service that verifies an account holder's identity using passwords or tokens, allowing a trusted party to authenticate the account holder for a requesting party and shares detailed customer information with value-adding parties, enabling secure transactions and improved customer management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication systems are used for online transactions, then security verification can be performed, but the systems become cumbersome, difficult to use, and lack interoperability
Solution Approach 1:
The patent introduces an authentication service as an intermediary component that mediates between the online merchant and the cardholder. This service handles the complex authentication processes (including certificate verification and challenge-response protocols) in the background, while presenting a simple interface to users. The authentication service acts as a mediator that translates complex security requirements into user-friendly interactions, resolving the contradiction between security reliability and ease of operation.
Solution Approach 2:
The authentication system implements self-service mechanisms where the authentication service automatically performs verification tasks without requiring direct user intervention in complex security protocols. The system handles certificate validation, cryptographic operations, and communication with authentication authorities automatically, freeing users from cumbersome manual authentication steps while maintaining strong security verification.
2Reliability
If certificate-based authentication is implemented, then security can be enhanced, but the complexity of creation, distribution and use of certificates increases significantly
Solution Approach 1:
The patent extracts the complex certificate management functions from the merchant and cardholder systems and consolidates them into a dedicated authentication service. This service handles certificate creation, distribution, storage, and validation centrally, removing the burden of certificate management from individual participants. By taking out the complex certificate management tasks and centralizing them, the system maintains high security reliability while significantly reducing the operational complexity for users.
Solution Approach 2:
The authentication service is designed as a universal system that handles multiple authentication functions (certificate validation, challenge-response protocols, identity verification) through a single integrated platform. This multi-functional approach eliminates the need for separate certificate management systems at each participant location, reducing overall system complexity while maintaining comprehensive security coverage across all transaction types.
3Reliability
If authentication systems are designed for specific transaction types, then security can be tailored, but interoperability across different transaction types is reduced
Solution Approach 1:
The authentication service is designed as a universal platform that supports multiple transaction types (online commerce, mail order, telephone orders, card-not-present transactions) through a single system. The service implements a standardized authentication protocol that can be applied across different transaction contexts, enabling tailored security verification for each transaction type while maintaining interoperability through a common interface and protocol framework.
Solution Approach 2:
The authentication system implements dynamic adaptability where the same core authentication service can adjust its verification processes based on the specific transaction type and risk level. The system dynamically selects appropriate authentication methods and complexity levels according to the transaction context, allowing tailored security verification for different scenarios while maintaining a unified interoperable framework through the standardized service interface.
Data Source
AI summary
An account authentication service where a trusted party verifies an account holder's identity for the benefit of a requestor during an online transaction. The account authentication involves requesting a password from the account holder, verifying the password, and notifying the requestor whether the account holder's authenticity has been verified. An alternative embodiment of the account authentication service includes a value-adding component where information about a customer is shared with a value-adding party. The customer information is rich in detail about the customer since it is collected by each of the parties in the account authentication process. The value-adding party can then use this information in various manners. All of the parties involved can benefit from sharing the customer information. The value-adding party can be, for example, a merchant, a shipper, a security organization, or a governmental organization. A transaction identifier identifies a specific transaction between a customer, a merchant, and the customer information.


