UPAAS Gateway Externalizes Authentication to Issuer Environment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current transaction approval and user authentication methods in the card industry are costly and vulnerable to fraud, with offline PIN verification capturing costs and introducing 'wedge' attacks, while cheque transactions lack user authentication, leading to declining usage.

Innovation Solution

Implementing the UPAAS User Gateway and User Application in an Issuer-controlled environment, allowing users to review and approve transactions on self-controlled devices, externalizing user authentication and approval from Point of Acceptance systems, and enabling real-time Issuer authentication without involving Point of Acceptance, Acquirer, or Network systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If offline PIN verification is implemented at POA, then user authentication reliability is improved, but implementation and maintenance costs increase significantly

Engineering Contradiction:
Improveuser authentication reliabilityVSAvoidimplementation and maintenance cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the user authentication function from the POA environment and relocates it to the Issuer's controlled environment. The Issuer Host performs the authentication by comparing the provided PIN against stored values, while the POA only captures and transmits the PIN securely. This extraction eliminates the need for POA to maintain complex authentication logic and security infrastructure, thereby reducing implementation and maintenance costs while preserving authentication reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary role where the Issuer Host acts as the mediator between the POA and the authentication verification process. Instead of POA directly performing authentication, the Issuer Host receives the captured PIN from POA through secure communication channels and performs the verification. This intermediary approach allows POA to avoid the complexity of maintaining authentication systems while ensuring reliable verification through the Issuer's secure environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If CVM verification is performed at POA, then transaction approval speed is improved, but security vulnerabilities to wedge attacks increase

Engineering Contradiction:
Improvetransaction approval speedVSAvoidsecurity vulnerability to wedge attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the critical authentication function from the POA environment, leaving POA to only perform data capture and transmission. By removing the authentication decision-making process from POA and centralizing it at the Issuer Host, the system maintains fast transaction processing at POA while eliminating the security vulnerability that arises when POA handles sensitive authentication logic and data.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The Issuer Host serves as an intermediary that receives authentication data from POA through secure channels and performs verification in a trusted environment. This intermediary architecture ensures that POA does not store or process sensitive authentication information beyond what is necessary for transmission, thereby preventing wedge attacks while maintaining efficient transaction flow through the Issuer's secure verification process.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If user authentication is not performed for cheque transactions, then processing simplicity is maintained, but fraud risks increase

Engineering Contradiction:
Improveprocessing simplicityVSAvoidfraud risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements self-service authentication where the Issuer Host automatically performs user verification for cheque transactions by comparing account information against its database. The system autonomously validates the cheque drawer's identity and account status without requiring manual verification processes, thereby maintaining processing simplicity while effectively reducing fraud risks through automated authentication.

Inventive Principle:
Principle #25Self-service

4Reliability

If EMV-chip cards with offline PIN are deployed, then authentication security is improved, but cost burden on all parties increases

Engineering Contradiction:
Improveauthentication securityVSAvoidcost burden
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the authentication processing function from the distributed EMV-chip card system and consolidates it at the Issuer Host. Instead of requiring each POA to implement and maintain complex EMV authentication infrastructure, the system uses the Issuer's centralized authentication capability, thereby reducing the overall cost burden on merchants, acquirers, and networks while maintaining the security benefits of offline PIN verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10078841B2User positive approval and authentication services (UPAAS)
Publication Date: 2018.09.18 STANTON MANAGEMENT GRP
  • US10078841B2 patent drawing
  • US10078841B2 patent drawing
  • US10078841B2 patent drawing

AI summary

The invention provides Users of Retail Payment and Identification instruments with the ability to review transaction details and approve transaction by capturing UVM in User controlled environment and Issuers of these instruments with the ability to positively authenticate Users in Issuer controlled environment. The invention accounts for real time legacy or non-legacy processing systems to provide an authorization request from POA to Issuer Host. The invention introduces two UPAAS components—User Gateway and User Application. The UPAAS User Gateway is implemented in an Issuer controlled environment enabling interface between Issuer legacy Host and UPAAS User Applications. The UPAAS User Application can be implemented on any device supporting communication protocol such as TCP/IP without any hardware changes enabling the User to login to UPAAS User Gateway, review and approve or decline a specific transaction in real time by entering UVM, such as PIN, for User authentication purposes.