Biometric Authentication System for Card-Not-Present Transaction Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Online merchants face challenges in verifying the consent of cardholders for remote transactions, particularly in 'card-not-present' scenarios where unauthorized purchases can occur, as existing security measures are often ineffective against unauthorized users who may have access to the cardholder's information.
Innovation Solution
An authentication system that uses a user device associated with the cardholder to generate and verify a challenge response, ensuring that the cardholder approves each purchase by comparing the collected authentication information to a stored profile, thereby authenticating the cardholder for each transaction initiated at a client device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If card-not-present transactions are allowed for online purchases, then convenience and productivity are improved, but security and reliability deteriorate due to unauthorized transactions
Solution Approach 1:
The system performs preliminary authentication by enrolling the cardholder's biometric data and device information before transactions occur. When a purchase is initiated, the system proactively pushes notifications to the cardholder's device for real-time approval, preventing unauthorized transactions before they are completed.
Solution Approach 2:
The patent introduces an authentication computing device as an intermediary between the client device and payment processor. This mediator verifies cardholder identity through biometric authentication and obtains real-time approval, adding a security layer without significantly impacting transaction speed.
2Ease of operation
If password-based security measures are implemented, then authentication is improved, but security deteriorates because unauthorized users may already know the password
Solution Approach 1:
The system replaces traditional mechanical authentication methods (passwords, PINs) with biometric authentication (fingerprint, facial recognition). This substitution maintains ease of operation for authorized users while dramatically improving security, as biometric data cannot be easily compromised or shared like passwords.
Solution Approach 2:
The system creates a digital copy of the cardholder's biometric data during enrollment and stores it securely. This copy is then used for rapid authentication without requiring the physical presence of the cardholder, maintaining convenience while enhancing security verification.
3Reliability
If real-time authentication is implemented for all transactions, then security is improved, but device complexity and processing time increase
Solution Approach 1:
The system implements selective authentication rather than requiring full biometric verification for every transaction. Low-risk transactions may use simplified verification, while high-risk transactions trigger full authentication workflows. The system also uses excessive action by pushing notifications to multiple devices simultaneously to ensure capture of cardholder approval.
Solution Approach 2:
The authentication system is segmented into modular components: enrollment module, notification module, authentication module, and verification module. This segmentation allows the system to activate only the necessary components for each transaction type, reducing overall complexity while maintaining high security where needed.
Data Source
AI summary
A method for authenticating a cardholder for a candidate purchase using an authentication computing device in communication with a memory is provided. The method includes receiving an authentication profile associated with the cardholder during an enrollment process for an authentication service, storing the authentication profile within the memory, and receiving an authentication request for the candidate purchase over a first communication link. The candidate purchase is initiated at a client device. The method further includes retrieving the stored authentication profile from the memory, generating a challenge message based on the stored authentication profile, transmitting the challenge message to a user device over a second communication link, receiving a challenge response including authentication information collected from the user device, comparing the collected authentication information to the stored authentication profile, and authenticating the cardholder for the candidate purchase based on the comparison.


