Token-Based Customer Identity Verification for Internet Payments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic payment systems face challenges in securing Internet-based transactions due to the lack of physical presence verification, leading to vulnerabilities such as identity theft and fraud, and existing security measures like EMV chips and multi-factor authentication fail to provide comprehensive transaction approval and non-repudiation.
Innovation Solution
A trusted customer payment system using a token-based identity verification system with asymmetric key pairs, unique hardware IDs, and hardware-embedded passwords, which verifies the user's physical possession of the computing device through a predefined network path, ensuring secure and seamless transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If EMV chip technology is used to secure physical transactions, then fraud is reduced, but it cannot be applied to Internet sales where physical presence is absent
Solution Approach 1:
The patent replaces the mechanical EMV chip verification system with a digital token-based verification system. Instead of relying on physical chip presence, the system uses cryptographic tokens that are generated, transferred, and verified through digital communication channels, enabling secure verification without physical contact.
Solution Approach 2:
The patent creates digital copies of verification tokens that can be transmitted and verified without transferring physical objects. The token serves as a digital representative of the customer's identity and authorization, allowing multiple verifications without physical presence.
2Reliability
If passwords and double key encryption are used for security, then access control is improved, but they fail to provide comprehensive transaction approval and non-repudiation
Solution Approach 1:
The system performs preliminary actions by pre-generating and storing unique tokens with each customer account during registration. These tokens are then used in subsequent transactions to verify identity and authorize specific operations, eliminating the need for complex multi-step authentication during actual transactions.
Solution Approach 2:
The patent introduces a verification server as an intermediary between the customer and the service provider. This server handles the cryptographic verification of tokens and manages the authorization process, simplifying the complexity of secure transactions while maintaining strong security controls.
3Measurement precision
If account authority systems generate and verify certificates for network access, then device identification is improved, but they cannot approve individual communications or transactions
Solution Approach 1:
The patent segments the verification process into two distinct phases: account verification (done by the account authority) and transaction verification (done by the verification server). This segmentation allows each component to focus on its specific function, with the verification server being able to approve individual transactions using tokens generated during account setup.
Data Source
AI summary
Trusted customer identity systems and methods provide secure electronic payment transactions incorporating customer identity verification using cross-referenced multiple data sources. Two distinct authorities provide payment speed, simplicity, and security. A network path-based identity methodology does not require shared information between parties. A first party receives a secure token and has sole access and controls possession of unique data that they append to the token. Before a transaction, a unique identifying characteristic of the party is used to register it on the trusted customer network. Other parties on the network do not possess a copy of the unique data but, based on the registration characteristics of the first party, know when they receive the token that only the first party could have added the unique data to the token. Other parties on the network can trust that the first party is the same party who registered this account to the network.


