Separate Device Authentication for Online Payment Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Online transactions are vulnerable to fraud and hacking, as personal information is often compromised when entered on computing devices that may be compromised or publicly accessed, lacking effective authentication mechanisms to verify the user's identity and presence.
Innovation Solution
A method that detects sensitive payment information input on a computing device, disables payment processing if suspicious conditions are detected, generates a unique identifier displayed on the device, and requires a separate computing device for authentication through scanning and biometric validation to enable payment processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If payment processing is enabled on the computing device to allow online transactions, then transaction convenience is improved, but vulnerability to fraud and hacking increases
Solution Approach 1:
The patent introduces a separate computing device as an intermediary authentication layer. This secondary device receives a challenge from the first computing device, verifies user credentials independently, and returns an authentication token. This mediator approach allows convenient payment processing on the first device while transferring security verification to a separate, trusted device, thus resolving the contradiction between ease of operation and security vulnerability.
2Reliability
If separate computing device authentication is implemented to verify user identity, then security against fraud is improved, but transaction processing time increases
Solution Approach 1:
The system performs preliminary authentication actions by sending a challenge to the second computing device before the actual payment processing occurs. The second device verifies user credentials in advance and generates an authentication token that can be used for the transaction. This preliminary verification ensures reliable user identity confirmation while allowing the subsequent payment process to proceed efficiently without repeated authentication delays.
3Object-affected harmful factors
If payment processing function is disabled to prevent unauthorized transactions, then fraud prevention is improved, but legitimate transaction capability deteriorates
Solution Approach 1:
The payment processing function transitions from a static disabled state to a dynamic conditional state. The system disables payment processing by default to prevent unauthorized transactions, but dynamically enables it when the second computing device provides valid authentication. This dynamic approach maintains fraud prevention while restoring legitimate transaction capability based on real-time authentication status, resolving the contradiction between security and operational capability.
Data Source
AI summary
A method for authenticating an online transaction on a first computing device using a second computing device including detecting a request to process sensitive payment information input on the first computing device to complete a transaction, determining that a condition is present associated with the transaction, disabling a payment processing function of the website to prevent a payment from being processed and completed, generating a unique identifier to be displayed on the first computing device, wherein the user scans the unique identifier with a second computing device to initiate an authentication function, authenticating the user operating the first computing device, and enabling, by the processor, the payment processing function of the website to allow the payment to process.


