Wireless Payment Authentication via PIN and Text Message
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing contactless payment systems using cell phones lack secure authentication, relying on single-factor authentication which increases the risk of fraudulent transactions, and are often inconvenient due to the need for additional infrastructure and complex enrollment processes.
Innovation Solution
A secure transaction payment system that requires users to input a Personal Identification Number (PIN) and sends it via a text message to a pre-determined number, combining this with a device identifier for multifactor authentication, and optionally includes a digital certificate and variable-length transaction codes to enhance security and convenience.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If single-factor authentication is used for contactless payment, then convenience is improved, but security deteriorates
Solution Approach 1:
The authentication process is segmented into multiple independent factors: possession of the mobile device, knowledge of the PIN, and verification through text message confirmation. Each factor operates independently and must be satisfied together, dividing the authentication burden into manageable segments that balance convenience and security.
Solution Approach 2:
A text message intermediary is introduced as a second factor between the user and the payment system. The system sends a verification code via text message to the user's mobile device, which must be entered to confirm the transaction. This intermediary layer adds security without significantly complicating the user experience.
2Reliability
If multifactor authentication with text message verification is implemented, then security is improved, but device complexity increases
Solution Approach 1:
The system leverages the user's existing mobile device and its built-in text message capability to provide the second factor of authentication. The mobile device itself serves as both the payment instrument and the verification channel, eliminating the need for additional hardware or complex authentication devices. The user simply uses their existing phone to receive and enter the verification code.
3Reliability
If PIN input and text message verification are required, then authentication security is improved, but time consumption increases
Solution Approach 1:
The system requires only partial authentication information through the verification code rather than full cryptographic protocols. The verification code is a simplified numeric sequence that provides sufficient security for the transaction context while requiring minimal user input time. This partial action approach achieves adequate security without the time cost of more rigorous authentication methods.
Data Source
AI summary
When purchasing an item or service, a user enters a PIN enter their mobile communication device and send the PIN, e.g., via text message to a payment authority. The payment authority authenticates the user using at least the PIN and the mobile communication device identifier associated with the user's mobile communication device. If the user is authenticated, then the payment authority will send a transaction code back to the user, which will be displayed on the user's mobile communication device. The user can then provide the transaction code to the merchant. The merchant can enter the transaction code into the Merchant's point of sale system and complete the transaction.


