Network Authentication via Transaction-Based Shared Secrets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network authentication systems are vulnerable to fraudsters who mimic legitimate networks, allowing them to intercept private information from unsuspecting users, as they do not provide a secure method for establishing dynamic authentication credentials specific to locations.
Innovation Solution
A system that associates a customer's device with a financial transaction record from a merchant, using information from past purchases as a shared secret network authentication credential, which is pre-emptively established and updated, enabling mutual authentication and making it difficult for fraudsters to emulate legitimate networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network authentication methods are used, then network access is simple and convenient, but the system is vulnerable to evil twin attacks and fraudsters can intercept private information
Solution Approach 1:
The system pre-emptively establishes authentication credentials based on past financial transactions before the customer needs to connect to the network. The merchant computing system automatically selects transaction information and establishes it as a shared secret credential, so when the customer requests network access, authentication is already prepared and can be quickly verified without complex real-time authentication procedures
Solution Approach 2:
The patent introduces a merchant computing system as an intermediary that bridges the customer device and the network access point. This intermediary automatically manages the authentication process by selecting transaction information, establishing shared secrets, and verifying credentials, thereby simplifying the overall system architecture while enhancing security through automated intermediary verification
2Reliability
If dynamic authentication credentials are implemented, then security against fraud is improved, but the authentication process becomes more complex and time-consuming
Solution Approach 1:
Authentication credentials are established in advance based on completed financial transactions stored in the customer database. When a customer requests network access, the merchant computing system quickly retrieves the pre-established shared secret from past transactions and verifies it, eliminating the need for complex real-time authentication procedures and reducing authentication time
Solution Approach 2:
The system uses automatically generated authentication credentials derived from past transaction data without requiring manual customer input. The merchant computing system autonomously selects transaction information, establishes shared secrets, and manages credential verification, making the authentication process efficient and minimizing customer effort and time
3Object-affected harmful factors
If shared secret authentication based on transaction information is used, then resistance to evil twin attacks is enhanced, but the system requires access to customer financial transaction records
Solution Approach 1:
The system extracts only the necessary authentication-relevant information from complete financial transaction records. The merchant computing system selectively identifies and uses specific transaction details (such as transaction amount, timestamp, or merchant identifier) to establish shared secrets, rather than processing entire transaction datasets, thereby reducing data processing complexity while maintaining security
Solution Approach 2:
The authentication system uses location-specific and transaction-specific credentials that are uniquely tied to the customer's past interactions with this particular merchant. Each merchant location can establish unique shared secrets based on local transaction history, providing localized security that is resistant to evil twin attacks without requiring centralized processing of all customer data across all locations
Data Source
AI summary
A computing system can associate a customer device of a customer with a financial transaction record and the merchant, the financial transaction record indicative of a first purchase from the merchant by the customer, transmit a first query to the customer device prompting the customer to input information regarding an aspect of the first purchase, the first query including a description of a predetermined product parameter of the financial transaction record indicative of the first purchase from the merchant by the customer, authenticating, by the computing system, the first request by determining that the customer-input response to the first query corresponds to the established aspect of the first purchase in accordance with a predetermined accuracy threshold, and authorizing, by the computing system, connection of the customer device to the network provided by the merchant based at least in part on the first request being authenticated.


