Biometric Payment Authentication with Production-Phase Device Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional biometric payment devices face security vulnerabilities due to simple mapping relationships between device codes and signatures, which can be mimicked by unauthorized devices, compromising user account security.

Innovation Solution

A method and apparatus for biometric payment devices that involve generating a signature using a key recognized by a payment authentication server during production, transmitting this signature for verification, and establishing a secure link with the server to ensure the authenticity of biometric data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a simple mapping relationship between device code and signature is used for authentication, then the authentication process is simple and fast, but security is compromised as unauthorized devices can mimic legitimate devices

Engineering Contradiction:
Improveauthentication process simplicityVSAvoiddevice authentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-storing the device code and signature in a trusted execution environment during device production. The signature is generated in advance using a private key and stored securely, so that during authentication, the system only needs to verify the pre-computed signature rather than performing complex real-time authentication. This maintains simplicity while enhancing security through proper key management and trusted execution environments.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If device authentication is enhanced with cryptographic signatures and keys, then security against unauthorized devices is improved, but device complexity increases

Engineering Contradiction:
Improvedevice authentication securityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the cryptographic key pair generation and signature creation functions into a dedicated trusted execution environment or secure element. This separates the complex cryptographic operations from the main device logic, allowing the authentication mechanism to be implemented with minimal complexity in the primary device while maintaining high security. The trusted execution environment handles the complex cryptographic tasks independently.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a payment authentication server as an intermediary that handles the verification of cryptographic signatures. Instead of requiring the device to perform complex verification operations, the server acts as a mediator that receives the signature and device code, verifies them against stored references, and returns authentication results. This shifts the computational complexity to the server side while keeping the device side simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12361412B2Authentication method and apparatus of biometric payment device, computer device, and storage medium
Publication Date: 2025.07.15 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US12361412B2 patent drawing
  • US12361412B2 patent drawing
  • US12361412B2 patent drawing

AI summary

An authentication method of a biometric payment device includes: acquiring a key of the biometric payment device, the key being a key recognized by a payment authentication server and acquired through communication between a manufacturer device and the payment authentication server during a production phase; generating a signature according to the key and device information; transmitting an authentication request to the payment authentication server based on the device information and the signature, the authentication request being used for instructing the payment authentication server to verify the signature according to the device information, and generate an authentication result of the biometric payment device according to a verification result; and receiving the authentication result returned by the payment authentication server, the authentication result causing the payment authentication server to implement a biometric payment based on biometric data transmitted by the authenticated biometric payment device.