Network Authentication via Transaction-Based Shared Secrets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network authentication systems are vulnerable to fraudsters who mimic legitimate networks, allowing them to intercept private information from unsuspecting users, as they do not provide a secure method for establishing dynamic authentication credentials specific to locations.

Innovation Solution

A system that associates a customer's device with a financial transaction record from a merchant, using information from past purchases as a shared secret network authentication credential, which is pre-emptively established and updated, enabling mutual authentication and making it difficult for fraudsters to emulate legitimate networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network authentication methods are used, then network access is simple and convenient, but the system is vulnerable to evil twin attacks and fraudsters can intercept private information

Engineering Contradiction:
Improvenetwork securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system pre-emptively establishes authentication credentials based on past financial transactions before the customer needs to connect to the network. The merchant computing system automatically selects transaction information and establishes it as a shared secret credential, so when the customer requests network access, authentication is already prepared and can be quickly verified without complex real-time authentication procedures

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a merchant computing system as an intermediary that bridges the customer device and the network access point. This intermediary automatically manages the authentication process by selecting transaction information, establishing shared secrets, and verifying credentials, thereby simplifying the overall system architecture while enhancing security through automated intermediary verification

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dynamic authentication credentials are implemented, then security against fraud is improved, but the authentication process becomes more complex and time-consuming

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Authentication credentials are established in advance based on completed financial transactions stored in the customer database. When a customer requests network access, the merchant computing system quickly retrieves the pre-established shared secret from past transactions and verifies it, eliminating the need for complex real-time authentication procedures and reducing authentication time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses automatically generated authentication credentials derived from past transaction data without requiring manual customer input. The merchant computing system autonomously selects transaction information, establishes shared secrets, and manages credential verification, making the authentication process efficient and minimizing customer effort and time

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If shared secret authentication based on transaction information is used, then resistance to evil twin attacks is enhanced, but the system requires access to customer financial transaction records

Engineering Contradiction:
Improveresistance to fraudulent networksVSAvoiddata processing requirements
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system extracts only the necessary authentication-relevant information from complete financial transaction records. The merchant computing system selectively identifies and uses specific transaction details (such as transaction amount, timestamp, or merchant identifier) to establish shared secrets, rather than processing entire transaction datasets, thereby reducing data processing complexity while maintaining security

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication system uses location-specific and transaction-specific credentials that are uniquely tied to the customer's past interactions with this particular merchant. Each merchant location can establish unique shared secrets based on local transaction history, providing localized security that is resistant to evil twin attacks without requiring centralized processing of all customer data across all locations

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11695548B1Systems and methods for network authentication with a shared secret
Publication Date: 2023.07.04 WELLS FARGO BANK NA
  • US11695548B1 patent drawing
  • US11695548B1 patent drawing
  • US11695548B1 patent drawing

AI summary

A computing system can associate a customer device of a customer with a financial transaction record and the merchant, the financial transaction record indicative of a first purchase from the merchant by the customer, transmit a first query to the customer device prompting the customer to input information regarding an aspect of the first purchase, the first query including a description of a predetermined product parameter of the financial transaction record indicative of the first purchase from the merchant by the customer, authenticating, by the computing system, the first request by determining that the customer-input response to the first query corresponds to the established aspect of the first purchase in accordance with a predetermined accuracy threshold, and authorizing, by the computing system, connection of the customer device to the network provided by the merchant based at least in part on the first request being authenticated.