On-Device Biometric Authentication for Secure Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current transaction authentication methods, such as the 3-D Secure Protocol, rely on PINs and lack additional security layers, making them vulnerable to fraud, especially in online transactions, where enhanced security and multi-factor authentication are crucial.
Innovation Solution
A consumer mobile device captures biometric data using integrated sensors and compares it to locally stored templates, providing secure multi-factor authentication by leveraging biometric technologies like fingerprint, facial recognition, and voice biometrics, ensuring that authentication processing is handled locally rather than remotely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional PIN-based authentication is used, then device complexity is low, but security reliability is insufficient
Solution Approach 1:
The patent combines multiple authentication factors (biometric data, device credentials, transaction data) into a unified authentication system. The mobile device integrates biometric sensors, secure storage for credentials, and processing logic to evaluate multiple authentication factors simultaneously, creating a merged authentication approach that enhances security while managing complexity through integration.
Solution Approach 2:
The mobile device serves multiple functions: it acts as a biometric sensor, secure credential storage, authentication processor, and communication device. The authentication system is designed to be universal, working across different transaction types and integrating with various payment networks, thereby improving security without proportionally increasing complexity.
2Speed
If remote server verification is used, then centralization is high, but processing speed and user experience are reduced
Solution Approach 1:
The authentication system is segmented into local and remote components. The mobile device locally processes biometric data, evaluates authentication factors, and makes authentication decisions without requiring continuous remote server communication. Only necessary authentication results are transmitted remotely, dividing the processing workload to improve speed while managing complexity through distributed architecture.
Solution Approach 2:
Biometric templates and authentication credentials are pre-stored securely in the mobile device. The device is pre-configured with the necessary authentication mechanisms and credentials, allowing immediate local processing of authentication requests without requiring real-time remote verification, thereby improving processing speed.
3Reliability
If biometric data is stored remotely, then security centralization is high, but vulnerability to remote attacks increases
Solution Approach 1:
The patent extracts biometric templates and authentication credentials from remote servers and stores them locally in a secure environment within the mobile device. This extraction removes sensitive data from vulnerable remote storage, protecting it from remote attacks while maintaining security through local control and secure deletion capabilities.
Solution Approach 2:
The mobile device acts as an intermediary between the user and remote authentication systems. It locally processes and validates biometric data before any remote communication occurs, preventing direct exposure of biometric data to remote systems and reducing vulnerability to remote attacks while maintaining secure authentication.
Data Source
AI summary
A secure on-device cardholder authentication method and system. In an embodiment, a consumer's mobile device uses a mobile application to receive a user authentication request from an entity. A biometric data capture request is then transmitted to a biometric sensor of the mobile device, and a determination made that the mobile application is authorized to use an authenticator API. Next, the mobile device processor prompts the user to provide at least one form of biometric data in accordance with business rules, receives a user authentication response when the user provided biometric data matches locally stored biometric data, generates a positive user authentication response message, and transmits the positive user authentication response message to the entity.


