Authenticator Application Biometric Key Generation for Payment Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current two-step verification methods for e-commerce and payment transactions lack robust security, particularly in handling user identifiable information and biometric authentication, which can lead to vulnerabilities in identity theft and unauthorized transactions.
Innovation Solution
The implementation of OS-based and issuer-based authenticator applications that communicate with a support server to facilitate payment authentication, using QR codes to decode user identifiable information and integrating biometric authentication to generate and verify keys for secure transaction processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional two-step verification is used with text or voice call codes, then ease of operation is improved, but security is worsened due to vulnerabilities in identity theft and unauthorized transactions
Solution Approach 1:
The patent introduces an authenticator application as an intermediary component that mediates between the user and the payment system. This application generates time-based one-time passwords locally on the user's device without requiring communication with external servers during the authentication process, thereby eliminating the security vulnerabilities associated with text or voice call codes while maintaining ease of operation.
Solution Approach 2:
The patent replaces the mechanical system of transmitting verification codes via text messages or voice calls with a cryptographic system that generates one-time passwords using time-based algorithms (HOTP/TOTP) and HMAC-based message authentication codes. This substitution eliminates the security weaknesses of the mechanical transmission system while preserving user convenience.
2Reliability
If biometric authentication is integrated with OS-based and issuer-based authenticator applications, then security is improved, but device complexity is worsened
Solution Approach 1:
The patent merges biometric authentication capabilities with the authenticator application by integrating the biometric marker verification process directly into the existing authentication flow. The biometric data is collected and verified within the same application that generates one-time passwords, creating a unified security solution that enhances protection without requiring separate systems.
Solution Approach 2:
The authenticator application is designed to perform multiple functions: generating time-based one-time passwords, verifying biometric markers, and managing authentication credentials. By making the application multi-functional, the patent avoids increasing overall device complexity while achieving enhanced security through the integration of diverse authentication mechanisms.
Data Source
AI summary
Payment authentication using OS-based (operating system-based) and issuer-based authenticator applications is provided. The described authenticator applications perform processes including managing a resource with information about registered users; receiving user identifiable information; authenticating a user using the user identifiable information and the information stored in the resource; upon authenticating the user using the user identifiable information and the information stored in the resource, generating a key tied to existing biometric authentication of the user and mapped to the user identifiable information; and communicating with a support server to provide the key and a notification of a potential transaction.


