Transaction Authorization on Shared Displays via Proximity Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Shared devices, such as large-screen TVs, pose security concerns as users must enter transaction authorization credentials in public, risking exposure and allowing unauthorized access by others.
Innovation Solution
A method where a private device is used to authorize transactions on a shared device, enhancing privacy by detecting nearby devices and using them to verify and complete transactions securely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If transaction authorization credentials are entered on a shared device, then the transaction can be authorized, but user privacy and security are compromised due to public exposure
Solution Approach 1:
The patent introduces a mobile device as an intermediary between the user and the shared device. The mobile device receives the authorization request, displays the credentials for user input, and transmits the authorized credentials back to the shared device. This intermediary approach allows transaction authorization to occur without the user needing to directly enter credentials on the shared device, thereby preventing public exposure while maintaining operational convenience.
2Productivity
If transaction authorization credentials are entered on a shared device, then the transaction can be authorized, but other users can see and potentially misuse the credentials
Solution Approach 1:
The mobile device serves as a secure intermediary that handles credential transmission. It establishes a trusted communication channel with the shared device, encrypts the credentials during transmission, and validates the user's authorization before forwarding them. This ensures that credentials are never exposed in plain text on the shared device screen or keyboard, maintaining both processing efficiency and security reliability.
Solution Approach 2:
The system performs preliminary actions by pre-establishing a secure communication channel between the mobile device and the shared device before the actual credential transmission. The mobile device also performs preliminary validation of the user's authorization and encrypts the credentials before they leave the user's device, ensuring security is built into the process from the outset rather than added as an afterthought.
3Productivity
If the shared device continues to use stored credentials after a user leaves, then subsequent transactions are processed automatically, but unauthorized access occurs
Solution Approach 1:
The system implements feedback mechanisms where the shared device continuously monitors for the presence of authorized users and validates credentials before each transaction. The mobile device receives real-time authorization requests and can revoke or confirm credentials dynamically based on current user presence and authorization status. This feedback loop prevents automatic use of stale credentials and ensures only currently authorized users can transact.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Methods and computer systems are used to authorize a transaction. In one aspect, the method includes, at a computer system with one or more processors and memory, receiving a message requesting a transaction of a first media content for display on the public display; detecting one or more devices in proximity to the first device; selecting a second device from the detected one or more devices based on a match of a first user account between the second device and the first device; sending a request for authorizing the transaction to the selected second device; receiving a response to the request for authorizing the transaction from the selected second device; and completing the transaction on the first device using transaction information of the first user account and stored at the first device.