Transaction Authorization Service Dual Channel Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing systems for authorizing transactions on emerging global communications and information networks, particularly those involving electronic fund transfers, face security concerns due to the lack of robust mechanisms for verifying the authenticity of transaction initiation and authorization, especially when multiple communications channels are involved.
Innovation Solution
A transaction authorization service that utilizes a dual communications channel approach, where a transaction initiated through one channel (e.g., text messaging) is authenticated and authorized through a separate channel (e.g., voice or cellular telephone), employing security phrases and PINs to ensure the transaction's legitimacy and security, thereby preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single communications channel is used for transaction initiation and authorization, then the system is simpler to operate, but security is compromised due to potential eavesdropping and unauthorized access
Solution Approach 1:
The patent segments the transaction process into two distinct communications channels: a first channel for transaction initiation and a second channel for authorization. This segmentation ensures that even if one channel is compromised, the other remains secure, thereby enhancing overall transaction security without requiring a completely complex multi-layered system.
Solution Approach 2:
The patent introduces an intermediary authorization mechanism where a separate communications channel acts as a mediator between the transaction initiation and final execution. This intermediary channel verifies the authenticity of the transaction request through additional authentication factors (such as PIN or biometric verification), preventing unauthorized access while maintaining system manageability.
2Reliability
If dual communications channels with authentication are implemented, then unauthorized access is prevented, but the transaction process becomes more complex
Solution Approach 1:
The patent implements preliminary authentication actions during the authorization phase on the second communications channel. By requiring users to verify their identity through pre-configured methods (such as entering a PIN, providing a biometric, or confirming via a secondary device) before authorizing a transaction, the system enhances security while keeping the user interface straightforward and familiar.
Solution Approach 2:
The system employs self-service authentication mechanisms where users independently verify their own identity through methods they have previously configured (such as entering a PIN they set up, using their fingerprint, or confirming on their own device). This self-verification approach enhances security without requiring additional manual intervention from support staff, thereby maintaining ease of operation.
3Reliability
If message correction mechanisms are added to handle authentication errors, then system reliability improves, but device complexity increases
Solution Approach 1:
The patent incorporates feedback mechanisms that automatically detect authentication errors (such as incorrect PIN entries or failed biometric verification) and provide real-time guidance to users for correction. The system monitors the authorization process, identifies errors, and prompts users to retry or correct their input through the same second communications channel, thereby improving reliability without adding complex external correction systems.
Data Source
AI summary
A transaction processing and authorization service. A transaction initiation message received from a source entity by the service may include one or more errors. The service may, in response to receiving an incorrect transaction initiation message, contact the source entity via a second communications channel and allow the source entity to correct the faulty transaction initiation message during the communication session. The service may allow the source entity to correct only incorrect or missing portions of the transaction initiation message, and thus the source entity may not be required to re-enter the entire message. Correction of the transaction initiation message may be performed as part of an authorization contact from the service to the source entity on a communications channel, and thus the correction may not require any extra communications attempts or sessions between the service and the source entity.


