Biometric Authentication System for Card-Not-Present Transaction Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Online merchants face challenges in verifying the consent of cardholders for remote transactions, particularly in 'card-not-present' scenarios where unauthorized purchases can occur, as existing security measures are often ineffective against unauthorized users who may have access to the cardholder's information.

Innovation Solution

An authentication system that uses a user device associated with the cardholder to generate and verify a challenge response, ensuring that the cardholder approves each purchase by comparing the collected authentication information to a stored profile, thereby authenticating the cardholder for each transaction initiated at a client device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If card-not-present transactions are allowed for online purchases, then convenience and productivity are improved, but security and reliability deteriorate due to unauthorized transactions

Engineering Contradiction:
Improvetransaction speedVSAvoidtransaction security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary authentication by enrolling the cardholder's biometric data and device information before transactions occur. When a purchase is initiated, the system proactively pushes notifications to the cardholder's device for real-time approval, preventing unauthorized transactions before they are completed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication computing device as an intermediary between the client device and payment processor. This mediator verifies cardholder identity through biometric authentication and obtains real-time approval, adding a security layer without significantly impacting transaction speed.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If password-based security measures are implemented, then authentication is improved, but security deteriorates because unauthorized users may already know the password

Engineering Contradiction:
Improveauthentication simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system replaces traditional mechanical authentication methods (passwords, PINs) with biometric authentication (fingerprint, facial recognition). This substitution maintains ease of operation for authorized users while dramatically improving security, as biometric data cannot be easily compromised or shared like passwords.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system creates a digital copy of the cardholder's biometric data during enrollment and stores it securely. This copy is then used for rapid authentication without requiring the physical presence of the cardholder, maintaining convenience while enhancing security verification.

Inventive Principle:
Principle #26Copying

3Reliability

If real-time authentication is implemented for all transactions, then security is improved, but device complexity and processing time increase

Engineering Contradiction:
Improveauthentication accuracyVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements selective authentication rather than requiring full biometric verification for every transaction. Low-risk transactions may use simplified verification, while high-risk transactions trigger full authentication workflows. The system also uses excessive action by pushing notifications to multiple devices simultaneously to ensure capture of cardholder approval.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The authentication system is segmented into modular components: enrollment module, notification module, authentication module, and verification module. This segmentation allows the system to activate only the necessary components for each transaction type, reducing overall complexity while maintaining high security where needed.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10607224B2Systems and methods for secure authentication of transactions initiated at a client device
Publication Date: 2020.03.31 MASTERCARD INT INC
  • US10607224B2 patent drawing
  • US10607224B2 patent drawing
  • US10607224B2 patent drawing

AI summary

A method for authenticating a cardholder for a candidate purchase using an authentication computing device in communication with a memory is provided. The method includes receiving an authentication profile associated with the cardholder during an enrollment process for an authentication service, storing the authentication profile within the memory, and receiving an authentication request for the candidate purchase over a first communication link. The candidate purchase is initiated at a client device. The method further includes retrieving the stored authentication profile from the memory, generating a challenge message based on the stored authentication profile, transmitting the challenge message to a user device over a second communication link, receiving a challenge response including authentication information collected from the user device, comparing the collected authentication information to the stored authentication profile, and authenticating the cardholder for the candidate purchase based on the comparison.