Biometric Authentication System for Secure Cardless Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing credit-card and bank card settlement systems face challenges in securely identifying the owner of the card, as the leakage of service user identification information, such as credit card numbers or bank card numbers, allows impersonation, and require physical card presentation, which is inconvenient and insecure.
Innovation Solution
A service providing system that uses biometric authentication through multiple unit devices, integrating equipment certificates and user identification information certificates, with a verifying device to authenticate the user without the need for physical card presentation, utilizing public key encryption and digital signatures to secure the process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If credit card numbers or bank card numbers are used for identification, then authentication can be performed in transactions, but the leakage of this information allows impersonation and security breaches
Solution Approach 1:
The patent extracts the identification function from physical cards (credit cards, bank cards) and transfers it to biometric information stored in certificate data. The biometric authentication unit reads certificate data containing biometric information and uses it for authentication, separating the identification capability from the physical card medium that can be lost or stolen.
Solution Approach 2:
The patent replaces the mechanical/card-based identification system with a biometric authentication system. Instead of using physical cards that require manual presentation and verification, the system uses biometric information (fingerprint, face recognition, iris recognition, etc.) stored in certificate data, which is read automatically by the biometric authentication unit and verified through cryptographic protocols.
2Reliability
If physical cards are required for transactions, then authentication can be performed, but users must carry and present cards which is inconvenient and creates security risks
Solution Approach 1:
The patent extracts the authentication function from physical cards and embeds it in certificate data stored electronically. The terminal device reads certificate data from storage media (smart cards, USB drives, or electronic storage) and performs biometric authentication without requiring the user to physically present a card at the point of sale.
Solution Approach 2:
The patent creates a digital copy of the authentication credentials in the form of certificate data containing biometric information. This certificate data can be stored in various electronic forms (smart cards, USB drives, cloud storage) and read by the terminal device, replacing the need for physical card presence while maintaining authentication security.
3Reliability
If service user identification information is stored on cards, then authentication is enabled, but the card becomes a target for theft and information leakage
Solution Approach 1:
The patent segments the authentication system into multiple components: the terminal device stores public keys and verification algorithms, the certificate data contains biometric information and is stored separately in secure media, and the biometric authentication unit performs the actual verification. This segmentation distributes security risks across multiple components rather than concentrating sensitive information in a single card.
Solution Approach 2:
The patent replaces the card-based storage system with electronic storage of certificate data. The certificate data containing biometric information is stored in secure electronic media (smart cards, USB drives, or encrypted cloud storage) and read by the terminal device, eliminating the need for physical card handling and reducing opportunities for theft or unauthorized access.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This system securely identifies users without the need for physical card presence, reducing the risk of identification information leakage and enhancing security through biometric authentication and public key encryption, allowing secure service provision.
Implementation Method 1
WO 00/18162 A1 describes a method for authenticating embedded software in the memory of a responder over an unprotected channel. The method includes the step of transmitting a verify request and a unique nonce from a challenger to the responder over the unprotected channel. The method further includes the step of processing the embedded software and the nonce using a cryptographic hash function to produce a hash digest
Implementation Method 2
EP 1 944 714 A1 describes methods for ensuring secure authentication of identities of multiple electronic devices using certificates. SCHNEIER B, COMMUNICATIONS USING PUBLIC-KEY CRYPTOGRAPHY, APPLIED CRYPTOGRAPHY, PROTOCOLS, ALGORITHMS, AND SOURCE CODE IN C, JOHN WILEY & SONS, INC, NEW YORK, describes public-key encryption
Implementation Method 3
a biometric authentication unit, configured to read certificate data and verify the authenticity of the certificate data
Data Source
Figure 1
Figure 2
Figure 3
AI summary
According to one embodiment, the verifying device sends, to the service providing device, the user identification information in the user identification information certificate and the execution result that indicates properness when all the verification results are proper. the service providing device reads service user identification information associated with the user identification information in response to user identification information and a verification result. The service providing device sends the service information to the user terminal in accordance with the read service user identification information.