Personal Interface Device Dual Authentication Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Personal interface devices, such as credit card consolidators, lack robust security measures, allowing unauthorized users to bypass security by trying PIN numbers, and provide limited functionality.

Innovation Solution

A personal interface device that requires two types of identification, including a physical identification device like a driver's license and a PIN number, to operate, generating payment authorization data and allowing users to select payment accounts securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a PIN number is required by the device, then security is improved, but an unauthorized user can still bypass security by trying various PIN numbers

Engineering Contradiction:
ImprovesecurityVSAvoidfraud risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The security system is segmented into multiple independent components: a physical identification device (such as a driver's license with magnetic stripe or RFID) and a PIN number. Both components must be present and correct for authorization, so compromising one does not compromise the entire security system. This segmentation prevents brute-force attacks on the PIN alone and requires physical possession of the identification device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A personal interface device acts as an intermediary between the user and the payment system. This intermediary enforces dual authentication by requiring both the physical identification device and PIN number before transmitting payment information. The intermediary protects the underlying system from unauthorized access while maintaining convenient user interaction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple credit card numbers are stored in the device, then functionality is improved, but the risk from theft of the device increases

Engineering Contradiction:
ImprovefunctionalityVSAvoidtheft risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system segments authentication into two separate factors: something you have (physical identification device) and something you know (PIN number). Multiple credit card numbers can be stored in the device, but access to any of them requires both authentication factors. This maintains full functionality while significantly reducing theft risk, as a stolen device alone cannot access the stored payment information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary authentication verification before allowing access to stored payment information. The personal interface device verifies both the physical identification device and PIN number before enabling any payment account access. This preliminary action prevents unauthorized use of stolen devices while maintaining convenient access for authorized users.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If dual identification is required to operate the device, then security is enhanced, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The personal interface device serves multiple functions: it stores multiple payment accounts, reads physical identification devices (magnetic stripe, RFID, or other formats), verifies PIN numbers, and interfaces with various payment terminals. This multi-functionality consolidates what would otherwise require multiple separate devices or systems into a single universal platform, making dual authentication practical rather than cumbersome.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system enables self-service authentication where the user independently verifies their own identity by presenting their physical identification device and entering their PIN. The personal interface device automatically processes both verification steps and makes authorization decisions without requiring manual intervention from bank personnel or complex external verification systems, simplifying the overall process while maintaining high security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7974929B2Personal interface device and method
Publication Date: 2011.07.05 SMITH EMMITT J III
  • US7974929B2 patent drawing
  • US7974929B2 patent drawing
  • US7974929B2 patent drawing

AI summary

A personal device is provided. The personal device includes an identification verification system that receives first identification data from a physical identification device, such as by inserting a driver's license into a card reader that is adapted to receive a driver's license. Second identification data such as a PIN number is also received. Payment authorization data or other suitable data is generated if the driver's license corresponds to the PIN. A payment selection system or other suitable system receives the payment authorization data and displays one or more payment accounts for selection by a user. Where a payment selection system is used, the payment selection system transmits payment account data to a point-of-sale system.