Trusted Third Party Authentication System for Consumer Account Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods, particularly single-factor authentication, are vulnerable to identity theft and fraud, leading to increased financial liability for organizations and inconvenience for consumers, who require a secure, convenient, and unified authentication mechanism across various transaction environments.

Innovation Solution

A system that employs a trusted third party to authenticate consumers using multiple security factors and communication bands, requiring possession of a communication device and a PIN for transaction authorization, with the option for additional geographic verification in three-factor authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If single-factor authentication (password only) is used, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a trusted third party as an intermediary that issues digital certificates and public key infrastructure (PKI) to enable secure authentication. This intermediary facilitates secure communication between consumers and organizations without requiring consumers to carry multiple physical devices, thus maintaining ease of operation while improving security through cryptographic verification

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multi-factor authentication with hardware devices is implemented, then security is improved, but device complexity and consumer burden increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple authentication factors into a unified digital certificate system issued by a trusted third party. Instead of requiring separate physical devices for each factor, the system combines knowledge-based credentials (passwords PINs), possession-based credentials (mobile device access), and biometric verification into a single integrated authentication mechanism that consumers access through their existing mobile devices

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The trusted third party's authentication system serves multiple functions: it issues digital certificates, verifies consumer identity, enables transaction authorization, and provides fraud detection across various transaction environments (online, telephone, face-to-face). This universal system replaces the need for multiple specialized authentication devices

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If consumers carry multiple authentication devices for different organizations, then security is improved, but ease of operation is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidconsumer convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a universal authentication system where a single trusted third party issues digital certificates that work across multiple organizations and transaction types. Consumers use their existing mobile devices with a single set of credentials (digital certificate, PIN, biometric) to authenticate with any participating organization, eliminating the need to carry or manage multiple organization-specific authentication devices

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7983979B2Method and system for managing account information
Publication Date: 2011.07.19 DEBIX ONE
  • US7983979B2 patent drawing
  • US7983979B2 patent drawing
  • US7983979B2 patent drawing

AI summary

A method and system for authenticating the identity of a consumer is disclosed. After the consumer is authenticated by a trusted third party, the consumer designates accounts that the consumer wishes to “lock.” When a party requests access to that account, the consumer is notified through the consumer's phone and asked to input a PIN. If the consumer provides the PIN, the requestor is granted access to the consumer's account without requiring further input from the consumer. If the party authorizing the transaction in this “two-factor” authentication does not possess both the phone and the consumer's PIN, or that party elects not to provide the PIN, the request will not be authenticated.