Wireless Payment Authentication via PIN and Text Message

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing contactless payment systems using cell phones lack secure authentication, relying on single-factor authentication which increases the risk of fraudulent transactions, and are often inconvenient due to the need for additional infrastructure and complex enrollment processes.

Innovation Solution

A secure transaction payment system that requires users to input a Personal Identification Number (PIN) and sends it via a text message to a pre-determined number, combining this with a device identifier for multifactor authentication, and optionally includes a digital certificate and variable-length transaction codes to enhance security and convenience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If single-factor authentication is used for contactless payment, then convenience is improved, but security deteriorates

Engineering Contradiction:
ImproveconvenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into multiple independent factors: possession of the mobile device, knowledge of the PIN, and verification through text message confirmation. Each factor operates independently and must be satisfied together, dividing the authentication burden into manageable segments that balance convenience and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A text message intermediary is introduced as a second factor between the user and the payment system. The system sends a verification code via text message to the user's mobile device, which must be entered to confirm the transaction. This intermediary layer adds security without significantly complicating the user experience.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multifactor authentication with text message verification is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system leverages the user's existing mobile device and its built-in text message capability to provide the second factor of authentication. The mobile device itself serves as both the payment instrument and the verification channel, eliminating the need for additional hardware or complex authentication devices. The user simply uses their existing phone to receive and enter the verification code.

Inventive Principle:
Principle #25Self-service

3Reliability

If PIN input and text message verification are required, then authentication security is improved, but time consumption increases

Engineering Contradiction:
Improveauthentication securityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system requires only partial authentication information through the verification code rather than full cryptographic protocols. The verification code is a simplified numeric sequence that provides sufficient security for the transaction context while requiring minimal user input time. This partial action approach achieves adequate security without the time cost of more rigorous authentication methods.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUSRE44669E1Systems and method for secure wireless payment transactions
Publication Date: 2013.12.24 STRIPE LLC
  • USRE44669E1 patent drawing
  • USRE44669E1 patent drawing
  • USRE44669E1 patent drawing

AI summary

When purchasing an item or service, a user enters a PIN enter their mobile communication device and send the PIN, e.g., via text message to a payment authority. The payment authority authenticates the user using at least the PIN and the mobile communication device identifier associated with the user's mobile communication device. If the user is authenticated, then the payment authority will send a transaction code back to the user, which will be displayed on the user's mobile communication device. The user can then provide the transaction code to the merchant. The merchant can enter the transaction code into the Merchant's point of sale system and complete the transaction.