Biometric Authentication System for Secure Cardless Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing credit-card and bank card settlement systems face challenges in securely identifying the owner of the card, as the leakage of service user identification information, such as credit card numbers or bank card numbers, allows impersonation, and require physical card presentation, which is inconvenient and insecure.

Innovation Solution

A service providing system that uses biometric authentication through multiple unit devices, integrating equipment certificates and user identification information certificates, with a verifying device to authenticate the user without the need for physical card presentation, utilizing public key encryption and digital signatures to secure the process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If credit card numbers or bank card numbers are used for identification, then authentication can be performed in transactions, but the leakage of this information allows impersonation and security breaches

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidimpersonation risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the identification function from physical cards (credit cards, bank cards) and transfers it to biometric information stored in certificate data. The biometric authentication unit reads certificate data containing biometric information and uses it for authentication, separating the identification capability from the physical card medium that can be lost or stolen.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent replaces the mechanical/card-based identification system with a biometric authentication system. Instead of using physical cards that require manual presentation and verification, the system uses biometric information (fingerprint, face recognition, iris recognition, etc.) stored in certificate data, which is read automatically by the biometric authentication unit and verified through cryptographic protocols.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If physical cards are required for transactions, then authentication can be performed, but users must carry and present cards which is inconvenient and creates security risks

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidtransaction convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the authentication function from physical cards and embeds it in certificate data stored electronically. The terminal device reads certificate data from storage media (smart cards, USB drives, or electronic storage) and performs biometric authentication without requiring the user to physically present a card at the point of sale.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a digital copy of the authentication credentials in the form of certificate data containing biometric information. This certificate data can be stored in various electronic forms (smart cards, USB drives, cloud storage) and read by the terminal device, replacing the need for physical card presence while maintaining authentication security.

Inventive Principle:
Principle #26Copying

3Reliability

If service user identification information is stored on cards, then authentication is enabled, but the card becomes a target for theft and information leakage

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidinformation leakage risk
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent segments the authentication system into multiple components: the terminal device stores public keys and verification algorithms, the certificate data contains biometric information and is stored separately in secure media, and the biometric authentication unit performs the actual verification. This segmentation distributes security risks across multiple components rather than concentrating sensitive information in a single card.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent replaces the card-based storage system with electronic storage of certificate data. The certificate data containing biometric information is stored in secure electronic media (smart cards, USB drives, or encrypted cloud storage) and read by the terminal device, eliminating the need for physical card handling and reducing opportunities for theft or unauthorized access.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This system securely identifies users without the need for physical card presence, reducing the risk of identification information leakage and enhancing security through biometric authentication and public key encryption, allowing secure service provision.

Implementation Method 1

WO 00/18162 A1 describes a method for authenticating embedded software in the memory of a responder over an unprotected channel. The method includes the step of transmitting a verify request and a unique nonce from a challenger to the responder over the unprotected channel. The method further includes the step of processing the embedded software and the nonce using a cryptographic hash function to produce a hash digest

Methodology Applied
Scientific EffectPublic key encryption:

Implementation Method 2

EP 1 944 714 A1 describes methods for ensuring secure authentication of identities of multiple electronic devices using certificates. SCHNEIER B, COMMUNICATIONS USING PUBLIC-KEY CRYPTOGRAPHY, APPLIED CRYPTOGRAPHY, PROTOCOLS, ALGORITHMS, AND SOURCE CODE IN C, JOHN WILEY & SONS, INC, NEW YORK, describes public-key encryption

Methodology Applied
Scientific EffectDigital signature:

Implementation Method 3

a biometric authentication unit, configured to read certificate data and verify the authenticity of the certificate data

Methodology Applied
Scientific EffectBiometric authentication:

Data Source

PatentEP2639726B1Service provision system and unit device
Publication Date: 2019.02.20 KK TOSHIBA
  • EP2639726B1 patent drawingFigure 1
  • EP2639726B1 patent drawingFigure 2
  • EP2639726B1 patent drawingFigure 3

AI summary

According to one embodiment, the verifying device sends, to the service providing device, the user identification information in the user identification information certificate and the execution result that indicates properness when all the verification results are proper. the service providing device reads service user identification information associated with the user identification information in response to user identification information and a verification result. The service providing device sends the service information to the user terminal in accordance with the read service user identification information.