Transaction History Challenge Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In electronic commerce and mobile commerce, authenticating consumers without physical presence poses challenges for merchants, as existing methods require significant interaction with issuers and spread sensitive consumer information, increasing risks for fraudulent transactions.

Innovation Solution

A method and system that authenticate applicants by querying their transaction history, asking challenge questions based on patterns or anomalies within this history, allowing the payments network to verify the applicant's identity without issuer involvement, using a 'challenge-response' authentication scheme.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional authentication methods (signature comparison, PIN verification) are used, then consumer authentication can be verified at point of sale, but the merchant cannot authenticate consumers in electronic commerce without physical presence

Engineering Contradiction:
Improveauthentication capabilityVSAvoidauthentication process
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The payments network acts as an intermediary between the merchant and the issuer, performing authentication on behalf of the merchant. The network receives authentication requests from merchants, queries transaction history from issuers, and returns authentication results, eliminating the need for direct merchant-issuer interaction while enabling remote authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service authentication by allowing the payments network to automatically query transaction history and verify consumer identity without requiring merchant involvement in the actual authentication process. The merchant simply initiates the request and receives the result

Inventive Principle:
Principle #25Self-service

2Extent of automation

If payments network performs authentication without issuer involvement, then issuer interaction is eliminated, but the network needs access to transaction history information

Engineering Contradiction:
Improveauthentication processVSAvoidtransaction history access
Core Design Contradiction:
Extent of automationVSLoss of information

Solution Approach 1:

The system extracts only the necessary authentication-relevant information from the comprehensive transaction history. Instead of transferring or storing all transaction data, the payments network queries specific patterns and anomalies that indicate authentic user behavior, minimizing information loss while enabling automated authentication

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If consumer secret information is spread to payments network for authentication, then authentication can be performed, but security risks increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The payments network serves as a trusted intermediary that handles authentication using transaction history patterns rather than direct access to sensitive consumer secret information. This reduces the spread of sensitive data while maintaining authentication capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the authentication parameter from relying on secret information (passwords, PINs) to relying on behavioral patterns in transaction history. This parameter change enables authentication without exposing sensitive consumer information, reducing security risks associated with information spread

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8255318B2Applicant authentication
Publication Date: 2012.08.28 FIRST DATA CORP
  • US8255318B2 patent drawing
  • US8255318B2 patent drawing
  • US8255318B2 patent drawing

AI summary

A method of authenticating an applicant. A history is obtained of transactions performed on an account held by the applicant and for which the applicant has been previously authenticated. The transaction history includes information about each transaction. The applicant is asked one or more questions relating to the information in the history. Answers to the one or more questions are received from the applicant, and a decision is made based on the received answers and the transaction history whether the applicant is authenticated. The applicant may be applying for enrollment in a service, and enrollment may be accepted or declined based on whether the applicant is authenticated. The account may relate to a payment instrument, and the authentication may be performed by an entity other than the issuer of the payment instrument.