Push Notification Authentication Framework Using Device Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current customer authentication methods are burdensome, time-consuming, and costly due to the need for sensitive data transmission, which can be compromised by fraudsters and malware, especially with the increased use of mobile devices and public spaces.

Innovation Solution

A digital authentication framework utilizing mobile devices with immutable hardware identifiers, processors for encryption, and location awareness, enabling three-factor authentication through touch, microphone, camera, and Bluetooth interactions, allowing for risk-based authentication and reducing the need for sensitive data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods request sensitive data from customers, then authentication can be performed, but the process becomes burdensome and time-consuming for customers while increasing security risks

Engineering Contradiction:
Improveauthentication securityVSAvoidcustomer authentication experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts sensitive data requests from the authentication process. Instead of asking customers to provide account numbers, passwords, or answers to security questions, the system uses device-based authentication where the mobile device itself serves as the authentication credential. The authentication decision is made by the bank system based on device trust and risk assessment, eliminating the need for customers to disclose sensitive information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The mobile device performs self-authentication through its inherent security features. The device's hardware identifiers, encryption capabilities, and location services are automatically used to verify the customer's identity without requiring manual input of sensitive data. The system leverages the device's existing security architecture to provide authentication, making the process seamless for the customer.

Inventive Principle:
Principle #25Self-service

2Reliability

If knowledge-based authentication uses obscure security questions, then authentication can be performed, but customers may forget answers and be locked out, and the process remains time-consuming

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces the mechanical process of asking and answering security questions with an automated device-based authentication system. Instead of relying on human memory and verbal responses, the system uses cryptographic verification and hardware identifiers to authenticate customers instantly. The authentication decision is made automatically by the bank system based on device trust levels and risk assessment algorithms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the authentication parameters from human-based (security questions and answers) to device-based parameters (hardware identifiers, encryption keys, location data). This parameter transformation enables automated, instant authentication without requiring customers to recall or provide knowledge-based responses, eliminating the time loss associated with forgotten answers.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If sensitive data is transmitted during authentication, then authentication can be completed, but the data can be compromised by malware and phishing attacks

Engineering Contradiction:
Improveauthentication completionVSAvoiddata compromise risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent converts the potential harm of data transmission into a benefit by using the mobile device's existing security features as the authentication mechanism. Instead of transmitting sensitive data through vulnerable communication channels, the system leverages the device's hardware security, encryption capabilities, and trusted execution environment to verify identity. The authentication process actually reduces data transmission needs by performing verification locally on the device.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The mobile device serves as a secure intermediary between the customer and the bank system. Rather than directly transmitting sensitive data between unsecured channels, the device's security framework acts as a mediator that verifies authentication credentials locally. The device's hardware identifiers and encryption mechanisms provide a trusted layer that prevents malware and phishing attacks from intercepting or compromising authentication data.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If authentication processes are made more secure, then data protection improves, but the processes become more complex and costly for companies

Engineering Contradiction:
Improvedata protectionVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by using the mobile device's existing multi-functional security capabilities for authentication purposes. The device's hardware identifiers, encryption processors, location services, and communication interfaces are all leveraged as a unified authentication system. Rather than implementing a separate complex authentication infrastructure, the system uses the device's universal security features that are already present for other functions like messaging and browsing.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The mobile device provides self-service authentication using its built-in security features. The device automatically generates and manages authentication credentials, performs cryptographic verification, and communicates security status without requiring additional complex infrastructure from the bank. This self-service approach simplifies the overall system architecture by leveraging the device's existing capabilities rather than adding new complex components.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3975093B1Method for digital authentication using push notifications
Publication Date: 2024.09.25 CAPITAL ONE SERVICES LLC
  • EP3975093B1 patent drawingFigure 1
  • EP3975093B1 patent drawingFigure 2
  • EP3975093B1 patent drawingFigure 3

AI summary

A system and method for push notification authentication includes a communication interface that communicates with a mobile device via a network, a digital security delivery database (754, ... 1154) that stores information about a user that is enrolled in push notification authentication. The information about a user (760) that is enrolled in push notification authentication hardware includes characteristics of the mobile device. An application programming interface (API) framework (751) is coupled to the communication interface (126) that receives information indicating that a transaction requiring push notification authentication. The API framework (751) is receiving (802) a request from a service provider system (855,...,1155) to create an authentication task for a transaction requiring push notification authentication. Steps of transmitting (805), receiving (902), transmitting (906) and receiving (1002) and updating. Therein the API framework updates the digital security delivery database (754) to indicate that the transaction requiring push notification authentication has been approved by the user (760). The API framework (751) notifies (1006) the service provider system that the transaction requiring push notification authentication has been approved.