Authenticator Application Biometric Key Generation for Payment Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current two-step verification methods for e-commerce and payment transactions lack robust security, particularly in handling user identifiable information and biometric authentication, which can lead to vulnerabilities in identity theft and unauthorized transactions.

Innovation Solution

The implementation of OS-based and issuer-based authenticator applications that communicate with a support server to facilitate payment authentication, using QR codes to decode user identifiable information and integrating biometric authentication to generate and verify keys for secure transaction processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional two-step verification is used with text or voice call codes, then ease of operation is improved, but security is worsened due to vulnerabilities in identity theft and unauthorized transactions

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an authenticator application as an intermediary component that mediates between the user and the payment system. This application generates time-based one-time passwords locally on the user's device without requiring communication with external servers during the authentication process, thereby eliminating the security vulnerabilities associated with text or voice call codes while maintaining ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical system of transmitting verification codes via text messages or voice calls with a cryptographic system that generates one-time passwords using time-based algorithms (HOTP/TOTP) and HMAC-based message authentication codes. This substitution eliminates the security weaknesses of the mechanical transmission system while preserving user convenience.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If biometric authentication is integrated with OS-based and issuer-based authenticator applications, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges biometric authentication capabilities with the authenticator application by integrating the biometric marker verification process directly into the existing authentication flow. The biometric data is collected and verified within the same application that generates one-time passwords, creating a unified security solution that enhances protection without requiring separate systems.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authenticator application is designed to perform multiple functions: generating time-based one-time passwords, verifying biometric markers, and managing authentication credentials. By making the application multi-functional, the patent avoids increasing overall device complexity while achieving enhanced security through the integration of diverse authentication mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11715105B2Payment authentication using OS-based and issuer-based authenticator applications
Publication Date: 2023.08.01 MASTERCARD INT INC
  • US11715105B2 patent drawing
  • US11715105B2 patent drawing
  • US11715105B2 patent drawing

AI summary

Payment authentication using OS-based (operating system-based) and issuer-based authenticator applications is provided. The described authenticator applications perform processes including managing a resource with information about registered users; receiving user identifiable information; authenticating a user using the user identifiable information and the information stored in the resource; upon authenticating the user using the user identifiable information and the information stored in the resource, generating a key tied to existing biometric authentication of the user and mapped to the user identifiable information; and communicating with a support server to provide the key and a notification of a potential transaction.