Secure Mobile Payment via Two-Key Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing online commerce systems require consumers to be redirected to a payment service provider's website for security, which is considered a sub-par user experience by merchants and can be vulnerable to scams, as they need to handle sensitive information.

Innovation Solution

A two-key approach where merchants use a 'collection' key for front-end operations and a 'charge' key for secure back-end transactions, allowing payment processing without redirecting the consumer and keeping the service provider's password secure by using a separate PIN for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If consumers are redirected to the service provider's website for payment, then security is improved, but user experience deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the sensitive authentication function (username and password verification) from the service provider's website and relocates it to the merchant's website. This allows the authentication process to occur locally without requiring consumers to be redirected to the service provider's site, thereby maintaining security while improving user experience by eliminating the redirect step.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If merchants handle sensitive payment information directly, then user experience is improved, but security risk increases

Engineering Contradiction:
Improveuser experienceVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary mechanism where the merchant's website hosts the service provider's login page and authentication logic. This intermediary setup allows the merchant to handle the authentication process locally without directly exposing or managing sensitive payment information, thereby maintaining security through the service provider's trusted interface while improving user experience by eliminating redirects.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the service provider's website is used for authentication, then security is maintained, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the service provider's authentication functionality directly into the merchant's website by hosting the login page and verification process on the merchant's server. This consolidation eliminates the need for separate authentication systems and redirects, reducing overall system complexity while maintaining security through the service provider's trusted authentication mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11216818B2Secure payment made from a mobile device through a service provider
Publication Date: 2022.01.04 PAYPAL INC
  • US11216818B2 patent drawing
  • US11216818B2 patent drawing
  • US11216818B2 patent drawing

AI summary

Methods and systems enable merchants to accept payments through a service provider from a consumer using an app on a mobile device, for example, without redirecting the consumer to the service provider and without collecting the customer's service provider password (a separate PIN may be used). An example of an app on a mobile device is given, but secure payments are also enabled for purchases and other transactions for a website, a merchant, or a service provider who needs to accept payments from customers. A two-key approach allows a merchant, using the two keys—a collection key for merchant apps and general servers and a private, more secure, charge key for merchant “back-end” systems—to collect a user's username and personal identification number (PIN) for acquiring payments through a service provider without compromising the user's service provider username and password (the PIN is distinct from the password).