Push-Based Transaction Verification via Validation API

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital security systems lack a solution for authenticating and authorizing ad-hoc requests from internal and external users for sensitive operations, as existing methods are burdensome and do not provide real-time confirmation mechanisms.

Innovation Solution

A method and system utilizing a multi-factor authentication service with a validation API that sends authentication requests to enrolled mobile devices via push notifications, enabling real-time confirmation of transactions through various authentication schemes such as one-time passwords or universal second-factor tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (passwords, physical devices, biometrics) are used, then authentication can be performed, but user burden increases and real-time confirmation is not available

Engineering Contradiction:
Improveauthentication capabilityVSAvoiduser burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables users to authenticate themselves through push notifications on their mobile devices without requiring manual intervention to remember passwords or carry physical devices. The authentication process automatically occurs when a user receives and responds to a push notification, making the system self-serve the authentication function with minimal user effort.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces traditional mechanical authentication mechanisms (physical devices, manual password entry, biometric scans) with electronic push notifications transmitted through communication networks. This substitution eliminates the need for users to physically handle authentication devices or manually provide credentials, reducing user burden while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Loss of time

If push-based authentication is implemented for ad-hoc requests, then real-time confirmation is achieved, but system complexity increases

Engineering Contradiction:
Improvetransaction confirmation timeVSAvoidsystem complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system introduces a validation API as an intermediary component that mediates between the requesting system and the user's mobile device. This intermediary handles the complex authentication logic, message routing, and communication protocols, allowing real-time confirmation without exposing the complexity to the end users or requesting systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The push-based authentication system is designed to handle multiple authentication scenarios (login, access points, ad-hoc requests) through a single unified mechanism. The validation API can serve different purposes (authentication, authorization, confirmation) using the same push notification infrastructure, reducing overall system complexity despite the enhanced functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If multiple authentication schemes are supported, then versatility is improved, but implementation complexity increases

Engineering Contradiction:
Improveauthentication scheme optionsVSAvoidimplementation complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments the authentication process into distinct phases: (1) The requesting system initiates an authentication request, (2) The validation API selects and transmits an appropriate authentication scheme via push notification, and (3) The user responds to the specific scheme presented. This segmentation allows the system to support multiple authentication schemes while keeping each individual implementation simple and modular.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11658962B2Systems and methods of push-based verification of a transaction
Publication Date: 2023.05.23 CISCO TECHNOLOGY INC
  • US11658962B2 patent drawing
  • US11658962B2 patent drawing
  • US11658962B2 patent drawing

AI summary

A system and method of implementing an API of an authentication service includes implementing a confirmation API, wherein the implementing includes: initiating a confirmation API request based on receiving an access request, wherein the confirmation API request operates to perform an authentication of a requestor making the access request; identifying the requestor based on a search of the requestor via the confirmation API; identifying, by one or more API endpoints of the remote authentication service: (i) a subscriber account of the subscriber maintained by the remote authentication service and (ii) identifying a user device of the requestor that is enrolled with the subscriber account based on the confirmation API request; transmitting a confirmation request to the user device; obtaining from the user device a response to the confirmation request and presenting the response to the confirmation request to the subscriber; and granting or denying the access request.