Secure Remote Transaction Framework Using Multi-Facilitator Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional remote transaction systems are inflexible and insecure, relying on a single authenticating entity and lacking adaptability to integrate new authentication capabilities, which limits their effectiveness and security in handling multiple parties and devices.
Innovation Solution
A system that allows users to select from multiple accounts associated with different facilitators for authentication, using a facilitator application to generate a transaction-specific token, enabling secure remote transactions over unsecured networks by leveraging multiple authentication entities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single authenticating entity is used in conventional remote transaction systems, then the authentication process is simple and straightforward, but the system lacks flexibility and adaptability to integrate new authentication capabilities
Solution Approach 1:
The system employs multiple authenticating entities (payment networks, wallet providers, data access providers) that can each perform authentication functions. This multi-functional approach allows the system to adapt to different authentication requirements and integrate new capabilities without redesigning the entire system, as each entity can be added or modified independently while serving the universal purpose of authentication.
Solution Approach 2:
The authentication system is divided into separate, independent authenticating entities rather than a monolithic system. Each entity (payment network, wallet provider, data access provider) operates as an independent module that can be selectively engaged. This segmentation allows the system to integrate new authentication capabilities by adding new entities without increasing overall system complexity, as each segment manages its own authentication logic.
2Reliability
If conventional authentication systems are updated to improve security, then security is enhanced, but changes require cooperation from all parties making implementation difficult
Solution Approach 1:
The system dynamically selects which authenticating entity to use based on the transaction context, user preferences, and available capabilities. This dynamic approach allows security measures to be updated independently for each entity without requiring system-wide changes. When a new authentication capability is developed, it can be integrated into a specific entity and activated dynamically when appropriate, avoiding the need for all parties to coordinate updates.
Solution Approach 2:
The system introduces an intermediary layer that manages multiple authenticating entities and coordinates their use. This intermediary handles the complexity of selecting and managing different authentication providers, allowing individual entities to be updated or replaced without affecting the entire system. The intermediary absorbs the coordination burden, making it easier to implement security updates in isolated modules rather than requiring unanimous agreement from all system parties.
3Measurement precision
If users provide personal information for authentication, then authentication accuracy is improved, but user anonymity and security are reduced
Solution Approach 1:
The system applies different levels of information disclosure based on the specific authentication context and entity. Sensitive personal information is only shared with the specific authenticating entity required for that transaction, not broadly distributed. This localized information sharing maintains authentication accuracy for each specific purpose while minimizing overall exposure risk by limiting which entities receive which information.
Solution Approach 2:
The system introduces intermediary layers between users and authenticating entities that manage information flow. These intermediaries (such as tokenization services or proxy authentication services) allow authentication to occur without directly exposing sensitive personal information to multiple parties. The intermediary verifies user identity and then communicates only with the specific authenticating entity, maintaining authentication accuracy while reducing the user's direct exposure to information security risks.
Data Source
AI summary
Embodiments of the invention are directed to systems and methods of providing secure remote transaction (SRT) transactions. In some embodiments, upon selection of a checkout element, a user may be identified with respect to a transaction to be completed. A number of accounts may then be identified in relation to that user. Upon selection of a particular account, the user may be authenticated using a facilitator application installed on a mobile computing device that supports authentication for the selected account. In some embodiments, the system may involve the use of a transaction-specific token generated upon receiving an authentication indicator from the facilitator application.


