Biometric Payment Authentication with Production-Phase Device Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional biometric payment devices face security vulnerabilities due to simple mapping relationships between device codes and signatures, which can be mimicked by unauthorized devices, compromising user account security.
Innovation Solution
A method and apparatus for biometric payment devices that involve generating a signature using a key recognized by a payment authentication server during production, transmitting this signature for verification, and establishing a secure link with the server to ensure the authenticity of biometric data transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a simple mapping relationship between device code and signature is used for authentication, then the authentication process is simple and fast, but security is compromised as unauthorized devices can mimic legitimate devices
Solution Approach 1:
The patent applies preliminary action by pre-storing the device code and signature in a trusted execution environment during device production. The signature is generated in advance using a private key and stored securely, so that during authentication, the system only needs to verify the pre-computed signature rather than performing complex real-time authentication. This maintains simplicity while enhancing security through proper key management and trusted execution environments.
2Reliability
If device authentication is enhanced with cryptographic signatures and keys, then security against unauthorized devices is improved, but device complexity increases
Solution Approach 1:
The patent extracts the cryptographic key pair generation and signature creation functions into a dedicated trusted execution environment or secure element. This separates the complex cryptographic operations from the main device logic, allowing the authentication mechanism to be implemented with minimal complexity in the primary device while maintaining high security. The trusted execution environment handles the complex cryptographic tasks independently.
Solution Approach 2:
The patent introduces a payment authentication server as an intermediary that handles the verification of cryptographic signatures. Instead of requiring the device to perform complex verification operations, the server acts as a mediator that receives the signature and device code, verifies them against stored references, and returns authentication results. This shifts the computational complexity to the server side while keeping the device side simple.
Data Source
AI summary
An authentication method of a biometric payment device includes: acquiring a key of the biometric payment device, the key being a key recognized by a payment authentication server and acquired through communication between a manufacturer device and the payment authentication server during a production phase; generating a signature according to the key and device information; transmitting an authentication request to the payment authentication server based on the device information and the signature, the authentication request being used for instructing the payment authentication server to verify the signature according to the device information, and generate an authentication result of the biometric payment device according to a verification result; and receiving the authentication result returned by the payment authentication server, the authentication result causing the payment authentication server to implement a biometric payment based on biometric data transmitted by the authenticated biometric payment device.


