Secure Multi-Party Authentication via Derived PIN

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In online payment transactions involving multiple parties, existing systems face challenges in authenticating users while maintaining the confidentiality of identification information, particularly when pre-approval mechanisms are used, as they often require revealing sensitive information to unauthorized third parties.

Innovation Solution

A method and system where a user enters an access code, which is converted into a secondary alphanumeric code, allowing authentication without revealing the original access code, thus maintaining confidentiality. This involves a processor-based payment authentication application that receives and verifies the derived PIN from a consumer, enabling secure transactions without exposing the access code.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the payment provider receives identification information from a third party (merchant) for authentication, then the payment provider can authenticate the user for pre-approved payments, but the confidentiality of the user's identification information is breached

Engineering Contradiction:
Improveauthentication capabilityVSAvoidconfidentiality of identification information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a merchant device as an intermediary that holds the user's identification information (PIN) but does not have direct access to the payment provider's authentication system. The merchant device transmits the PIN to the payment provider during pre-approved payment transactions, acting as a mediator that enables authentication while maintaining the user's control over their identification information. This resolves the contradiction by allowing the payment provider to authenticate users through a third party without the user directly revealing their PIN to unauthorized entities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the user enters an alphanumeric PIN for authentication, then the payment provider can verify the user's identity, but the user must repeatedly enter sensitive information and the risk of PIN exposure increases

Engineering Contradiction:
Improveauthentication securityVSAvoidconvenience of repeated authentication
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements pre-approved payments where the user's identification information is securely stored in the merchant device in advance. During subsequent transactions, the merchant device automatically transmits the pre-stored PIN to the payment provider without requiring the user to re-enter it. This preliminary action of storing the PIN in the merchant device resolves the contradiction by enabling secure authentication while eliminating the need for repeated user input, thereby improving both security and convenience.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If the system allows pre-approved payments to facilitate multiple purchases, then transaction efficiency improves, but the risk of fraudulent purchases by unauthorized users increases

Engineering Contradiction:
Improvetransaction efficiencyVSAvoidfraudulent purchases
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authentication system into two distinct components: the payment provider's authentication server that verifies PINs, and the merchant device that securely stores and transmits pre-approved PINs. This segmentation allows pre-approved payments to proceed efficiently (improving productivity) while maintaining security controls at both ends. The merchant device can only transmit PINs for pre-approved transactions, and the payment provider verifies each transaction against its authentication database, thereby preventing fraudulent purchases while maintaining transaction efficiency.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8825548B2Secure authentication between multiple parties
Publication Date: 2014.09.02 PAYPAL INC
  • US8825548B2 patent drawing
  • US8825548B2 patent drawing
  • US8825548B2 patent drawing

AI summary

Systems and methods are disclosed herein to allow a party to a multiple-party transaction to perform authentications using identification information received from another party while allowing the party generating the identification information to maintain confidentiality of information. A user may enter an access code to identify the user to a first party that will be generating identification information to a second party in the transaction. The access code may be entered without requiring the entry of an alphanumeric PIN (Personal Identification Number). The first party may convert the access code to a second code for transmission to the second party so that the access code is not revealed to the second party. The second party may use the second code to authenticate the user, to authenticate a payment transaction or other types of communications from the user or the first party. Thus, parties in a multiple-party transaction may perform authentications while maintaining the confidentiality of information.