Single Sign-On Wallet Authentication Session
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure authentication systems create friction for users during transactions, as they often require multiple authentication processes, challenge questions, and password recalls, leading to delays and potential transaction abandonment.
Innovation Solution
The proposed method leverages a secure authentication infrastructure to streamline transactions by allowing users to link their online banking accounts with digital wallets, using single sign-on data and issuer challenge questions to authenticate transactions without requiring additional password entries.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple authentication processes are implemented to ensure security, then authentication reliability is improved, but transaction time increases and user convenience deteriorates
Solution Approach 1:
The system performs authentication actions in advance by establishing a secure session between the user and the server before the actual transaction occurs. The server pre-validates the user's identity and security credentials, so that when the transaction happens, the authentication is already complete or can be quickly finalized without requiring multiple sequential authentication steps during the transaction itself.
Solution Approach 2:
The patent combines multiple authentication functions into a single integrated secure authentication system. Instead of separate authentication steps for different purposes, the system merges identity verification, security validation, and transaction authentication into one unified process that leverages the existing secure session, thereby reducing total authentication time while maintaining reliability.
2Reliability
If challenge questions are repeatedly asked to verify user identity, then authentication security is improved, but user frustration increases leading to transaction abandonment
Solution Approach 1:
The system performs security verification in advance during the session establishment phase rather than repeatedly during each transaction. The server pre-authenticates the user and establishes a secure context, so that subsequent transactions benefit from this pre-verified state without requiring repeated challenge questions, thereby maintaining security while improving user convenience.
Solution Approach 2:
The system uses feedback from the secure authentication session to determine whether additional verification is needed. Based on the pre-established secure session and risk assessment feedback, the system dynamically decides whether to require additional authentication steps, allowing it to maintain high security for risky transactions while enabling frictionless completion for low-risk transactions within the same session.
3Reliability
If additional authentication steps are required for transactions, then transaction security is improved, but processing complexity increases
Solution Approach 1:
The secure authentication system is designed as a universal platform that handles multiple authentication scenarios through a single integrated architecture. The same server-based authentication infrastructure serves different transaction types, user scenarios, and security levels, eliminating the need for separate complex authentication processing systems for each case and thereby reducing overall processing complexity while maintaining comprehensive security.
Data Source
AI summary
One embodiment of the invention is directed to a method comprising, establishing, by a wallet server computer, a single sign-on link between a user bank account and a wallet application. The method further comprises receiving a transaction request message from a user, wherein the transaction request is for a transaction between the user and a merchant associated with the wallet application. The method further comprises sending sign-on data to an issuer computer using a secure authentication protocol and receiving a confirmation message from the issuer computer confirms initiation through the issuer application. The transaction is processed by the wallet server computer based on the confirmation message.


