Secure Transaction Authentication via Real-Time Push Signaling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure transaction methods, such as those using chip-enabled debit cards and mobile apps, are often user-unfriendly and consume excessive battery power, as they require manual app opening and prolonged device activation, making them vulnerable to hacking and inefficient.

Innovation Solution

A method and system that utilize real-time push signaling to send authorization requests to mobile devices, allowing users to provide personal identification codes or bio-credentials for verification, ensuring secure transactions without draining device battery life or requiring manual app opening.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual app opening and prolonged device activation are required for secure transactions, then security verification can be performed, but user convenience deteriorates and battery power is excessively consumed

Engineering Contradiction:
Improvesecurity verificationVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system pre-loads and maintains the authentication application in memory with the authentication module ready for immediate use. The public key infrastructure and cryptographic routines are pre-initialized, allowing the device to perform secure authentication without requiring full app launch or prolonged activation, thus maintaining security while improving convenience and reducing power consumption

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual app opening and prolonged device activation are required for secure transactions, then security verification can be performed, but power consumption increases

Engineering Contradiction:
Improvesecurity verificationVSAvoidbattery power consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The authentication application and cryptographic modules are pre-loaded into memory and kept in a ready state with minimal power consumption. The system maintains only the essential authentication routines in active memory rather than requiring full application execution, significantly reducing battery power usage while ensuring security verification is immediately available when needed

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If real-time push signaling is used to activate mobile devices for authorization, then user-friendly quick transactions are enabled, but device activation complexity increases

Engineering Contradiction:
Improveuser-friendly operationVSAvoidactivation mechanism complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system uses a push notification service as an intermediary between the server and the authentication application. The push notification wakes the device and triggers the pre-loaded authentication module without requiring complex user interactions or device activation procedures. This intermediary simplifies the user experience while managing the underlying complexity of real-time activation through standardized notification protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3559881A1Secure log-in or transaction procedure
Publication Date: 2019.10.30 GL IP PROTECT LLC

AI summary

There is provided a method of facilitating a secure log-in procedure or a secure transaction procedure. The method enables a given user or a person under custody of the given user to log-in to or perform a transaction with a service securely. User details entered by the given user or said person at a user interface presented at a user device associated with the given user or said person are received. Subsequently, an authorization-request message is sent to at least one mobile communication device of the given user, using real-time push signalling. A response message indicating whether or not the authorization has been verified successfully is received from the at least one mobile communication device. If the authorization has been verified successfully, the given user or said person is allowed to log-in to or perform a transaction with the service from the user device.