Biometric Login Authentication Using Secure Enclave Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current user and device authentication methods for transactions, such as those used by payment providers, are insecure and require repeated login credentials across different browsers, leading to inefficiencies and potential fraud.

Innovation Solution

Implementing biometric authentication using IntelĀ® SGX technology to store tokens or public/private key pairs in a secure enclave on the user's device, allowing device-specific identification and secure transactions without the need for repeated login credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cookie-based authentication is used, then user identification across sessions is enabled, but security is compromised as cookies can be copied and used by unauthorized individuals

Engineering Contradiction:
Improveauthentication securityVSAvoidlogin convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that uses device-specific identifiers and biometric data as a mediator between the user and the authentication system. Instead of relying on vulnerable cookies, the system uses an intermediate layer of device identification and biometric verification that cannot be easily copied or stolen, thus improving security while maintaining convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical cookie-based authentication system with a biometric authentication system. Instead of using transferable digital cookies that can be copied, the system uses unique biological characteristics (fingerprint, facial recognition, iris scan) that cannot be replicated, thereby substituting a vulnerable mechanical system with a more secure biometric system.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If repeated login credentials are required across different browsers, then security is maintained, but user experience and transaction efficiency deteriorate

Engineering Contradiction:
Improvetransaction efficiencyVSAvoidauthentication security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements a universal authentication system that works across multiple browsers and devices using device-specific identifiers and biometric data. The authentication mechanism is designed to be platform-agnostic, allowing users to complete transactions efficiently on any device while maintaining strong security through unique biometric verification rather than browser-specific cookies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary authentication by storing device-specific identifiers and biometric data during an initial setup or first login. This preliminary action enables subsequent transactions to be authenticated quickly without requiring repeated credential entry, as the system has already established the user's identity and device association in advance.

Inventive Principle:
Principle #10Preliminary action

3Speed

If secure cookie-based instant checkout is implemented, then transaction speed is improved, but device identification reliability deteriorates as stolen cookies cannot be distinguished from legitimate ones

Engineering Contradiction:
Improvecheckout speedVSAvoiddevice identification accuracy
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The patent changes the identification parameters from mutable cookies that can be stolen to immutable device-specific identifiers and biometric characteristics. By using parameters such as device hardware IDs, fingerprint patterns, or facial geometry, the system achieves both fast checkout speeds and high identification accuracy, as these parameters cannot be replicated or stolen like cookies.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20260099841A1Unified login biometric authentication support
Publication Date: 2026.04.09 PAYPAL INC
  • US20260099841A1 patent drawing
  • US20260099841A1 patent drawing
  • US20260099841A1 patent drawing

AI summary

As disclosed herein, a token and/or a public/private key can be stored in a secure enclave that can be later used when a user logs into the payment provider's website. At that time, the user can simply swipe a fingerprint to complete a transaction. Thus, biometric authentication may be applied to complete the transaction. Moreover, the transaction can be completed across different browsers. In an implementation, a long-term token is not utilized. Instead, when a user opts into the disclosed implementation, a private and public key pair is generated on the client side device. The private key may be stored in the secure enclave and the public key may be sent to the payment provider. Thus, there may be no token involved to complete the transaction.