Biometric Money Transfer Authentication via Tamper-Resistant Key Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users are hesitant to use online money transfer services due to concerns about fraud and spoofing, particularly because existing systems require sharing acceptance codes, which complicates identity verification and increases usability issues.

Innovation Solution

A management system that utilizes biological authentication, where user account information and public keys are managed in association with each other, enabling secure money transfer by verifying biological information through a terminal's tamper-resistant storage unit, ensuring that biological data remains secure and reducing the risk of information leakage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biological authentication is implemented for money transfer, then security against fraud and spoofing is improved, but system complexity increases due to integration with social network service and key management

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The management server acts as an intermediary between users and the social network service, handling key management and authentication verification. This mediator approach allows biological authentication to be implemented without requiring direct complex integration between user terminals and the social network service, thus improving security while managing system complexity through centralized coordination

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments authentication functionality into separate components: biological information capture at the terminal, key management at the management server, and verification through signature validation. This segmentation allows each component to be optimized independently, improving overall security while making the complex authentication process more manageable and modular

Inventive Principle:
Principle #1Segmentation

2Reliability

If acceptance code sharing is required for money transfer verification, then fraud prevention is improved, but usability deteriorates due to arbitrary sharing methods required

Engineering Contradiction:
Improvefraud preventionVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical system of manual acceptance code sharing (via telephone or direct communication) with an automated electronic verification system using biological authentication and cryptographic signatures. This substitution eliminates the need for users to manually share verification codes through arbitrary channels, thereby improving fraud prevention while significantly enhancing usability through automated, secure verification

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If public key infrastructure is implemented for biological information authentication, then information leakage risk is reduced, but device complexity increases due to key management requirements

Engineering Contradiction:
Improveinformation leakage riskVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The management server serves as an intermediary that centralizes public key management, storing and managing public keys associated with biological information. This approach reduces information leakage risk by securing key management in a centralized, controlled environment rather than distributing private keys across multiple devices, while the intermediary handles the complexity of key management operations

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10860991B2Management system, control method therefor, and non-transitory computer-readable medium
Publication Date: 2020.12.08 CANON KK
  • US10860991B2 patent drawing
  • US10860991B2 patent drawing
  • US10860991B2 patent drawing

AI summary

A management system manages, for each of a plurality of users who use a social network service, account information, identification information associated with biological information, and a public key; sends, in accordance with an instruction related to money transfer to another user, a demand of authentication processing to the terminal of the user; receives, as a response to the demand, the identification information associated with the biological information and signature data created using a private key held in a storage unit having a tamper resistance in the terminal when the authentication processing using the biological information of the user succeeds; verifies, using the public key corresponding to the received identification information, the received signature data; and generates, based on a result of the verification, a message about the instruction.