Verified Device Step-Up Authentication for Remote Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems struggle to accurately authenticate user devices in remote transactions, particularly in card-not-present scenarios, where it is difficult to verify that a device is associated with the user.

Innovation Solution

A system that identifies verified devices associated with a user, presents them to the user for selection, and transmits authentication messages to complete interactions, utilizing tokenization services to register devices as authentication wallets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used in remote transactions, then the transaction process is simple, but the authentication security is insufficient

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary device verification and registration before the actual transaction. Devices are pre-verified and stored in a database with their authentication capabilities established in advance, so that during the transaction only a reference check is needed, not full authentication procedures

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A tokenization service acts as an intermediary between the access control system and authentication devices. This service handles the complex device verification, token generation, and authentication logic, shielding the merchant system from complexity while providing secure authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If multiple verified devices are supported, then the user convenience is improved, but the device management complexity increases

Engineering Contradiction:
Improveuser convenienceVSAvoiddevice management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system automatically manages multiple verified devices associated with user accounts without requiring manual configuration. When a user has multiple verified devices, the system automatically presents them for selection and handles the verification process, eliminating the need for users to manually manage device credentials

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The authentication process is segmented into distinct steps: device verification, token generation, and authentication. Each verified device receives its own unique token, allowing independent management and selection without interfering with other devices in the system

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12380449B2Systems and methods for intelligent step-up for access control systems
Publication Date: 2025.08.05 MASTERCARD INT INC
  • US12380449B2 patent drawing
  • US12380449B2 patent drawing
  • US12380449B2 patent drawing

AI summary

Some embodiments may provide systems, methods and computer program code to method to facilitate an interaction involving a user which include determining that a user authentication is required to complete the interaction, identifying at least a first verified device associated with the user, and transmitting an authentication message to the at least first verified device.