Separate Device Authentication for Online Payment Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online transactions are vulnerable to fraud and hacking, as personal information is often compromised when entered on computing devices that may be compromised or publicly accessed, lacking effective authentication mechanisms to verify the user's identity and presence.

Innovation Solution

A method that detects sensitive payment information input on a computing device, disables payment processing if suspicious conditions are detected, generates a unique identifier displayed on the device, and requires a separate computing device for authentication through scanning and biometric validation to enable payment processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If payment processing is enabled on the computing device to allow online transactions, then transaction convenience is improved, but vulnerability to fraud and hacking increases

Engineering Contradiction:
Improvetransaction convenienceVSAvoidfraud and hacking vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a separate computing device as an intermediary authentication layer. This secondary device receives a challenge from the first computing device, verifies user credentials independently, and returns an authentication token. This mediator approach allows convenient payment processing on the first device while transferring security verification to a separate, trusted device, thus resolving the contradiction between ease of operation and security vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate computing device authentication is implemented to verify user identity, then security against fraud is improved, but transaction processing time increases

Engineering Contradiction:
Improveuser identity verificationVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication actions by sending a challenge to the second computing device before the actual payment processing occurs. The second device verifies user credentials in advance and generates an authentication token that can be used for the transaction. This preliminary verification ensures reliable user identity confirmation while allowing the subsequent payment process to proceed efficiently without repeated authentication delays.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If payment processing function is disabled to prevent unauthorized transactions, then fraud prevention is improved, but legitimate transaction capability deteriorates

Engineering Contradiction:
Improveunauthorized transaction preventionVSAvoidlegitimate transaction capability
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The payment processing function transitions from a static disabled state to a dynamic conditional state. The system disables payment processing by default to prevent unauthorized transactions, but dynamically enables it when the second computing device provides valid authentication. This dynamic approach maintains fraud prevention while restoring legitimate transaction capability based on real-time authentication status, resolving the contradiction between security and operational capability.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11410160B2Authenticating online transactions using separate computing device
Publication Date: 2022.08.09 WALMART APOLLO LLC
  • US11410160B2 patent drawing
  • US11410160B2 patent drawing
  • US11410160B2 patent drawing

AI summary

A method for authenticating an online transaction on a first computing device using a second computing device including detecting a request to process sensitive payment information input on the first computing device to complete a transaction, determining that a condition is present associated with the transaction, disabling a payment processing function of the website to prevent a payment from being processed and completed, generating a unique identifier to be displayed on the first computing device, wherein the user scans the unique identifier with a second computing device to initiate an authentication function, authenticating the user operating the first computing device, and enabling, by the processor, the payment processing function of the website to allow the payment to process.