On-Device Biometric Authentication for Secure Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current transaction authentication methods, such as the 3-D Secure Protocol, rely on PINs and lack additional security layers, making them vulnerable to fraud, especially in online transactions, where enhanced security and multi-factor authentication are crucial.

Innovation Solution

A consumer mobile device captures biometric data using integrated sensors and compares it to locally stored templates, providing secure multi-factor authentication by leveraging biometric technologies like fingerprint, facial recognition, and voice biometrics, ensuring that authentication processing is handled locally rather than remotely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional PIN-based authentication is used, then device complexity is low, but security reliability is insufficient

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication factors (biometric data, device credentials, transaction data) into a unified authentication system. The mobile device integrates biometric sensors, secure storage for credentials, and processing logic to evaluate multiple authentication factors simultaneously, creating a merged authentication approach that enhances security while managing complexity through integration.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The mobile device serves multiple functions: it acts as a biometric sensor, secure credential storage, authentication processor, and communication device. The authentication system is designed to be universal, working across different transaction types and integrating with various payment networks, thereby improving security without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Speed

If remote server verification is used, then centralization is high, but processing speed and user experience are reduced

Engineering Contradiction:
Improveauthentication processing speedVSAvoidlocal processing complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The authentication system is segmented into local and remote components. The mobile device locally processes biometric data, evaluates authentication factors, and makes authentication decisions without requiring continuous remote server communication. Only necessary authentication results are transmitted remotely, dividing the processing workload to improve speed while managing complexity through distributed architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Biometric templates and authentication credentials are pre-stored securely in the mobile device. The device is pre-configured with the necessary authentication mechanisms and credentials, allowing immediate local processing of authentication requests without requiring real-time remote verification, thereby improving processing speed.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If biometric data is stored remotely, then security centralization is high, but vulnerability to remote attacks increases

Engineering Contradiction:
Improvedata securityVSAvoidremote attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts biometric templates and authentication credentials from remote servers and stores them locally in a secure environment within the mobile device. This extraction removes sensitive data from vulnerable remote storage, protecting it from remote attacks while maintaining security through local control and secure deletion capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The mobile device acts as an intermediary between the user and remote authentication systems. It locally processes and validates biometric data before any remote communication occurs, preventing direct exposure of biometric data to remote systems and reducing vulnerability to remote attacks while maintaining secure authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11157905B2Secure on device cardholder authentication using biometric data
Publication Date: 2021.10.26 MASTERCARD INT INC
  • US11157905B2 patent drawing
  • US11157905B2 patent drawing
  • US11157905B2 patent drawing

AI summary

A secure on-device cardholder authentication method and system. In an embodiment, a consumer's mobile device uses a mobile application to receive a user authentication request from an entity. A biometric data capture request is then transmitted to a biometric sensor of the mobile device, and a determination made that the mobile application is authorized to use an authenticator API. Next, the mobile device processor prompts the user to provide at least one form of biometric data in accordance with business rules, receives a user authentication response when the user provided biometric data matches locally stored biometric data, generates a positive user authentication response message, and transmits the positive user authentication response message to the entity.