Biometric Payment Credential Manager for Secure Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Biometric payments face security risks due to potential exposure of user data when merchant systems are compromised, and consumers lack easy control over when merchants can use their biometric data for transactions.
Innovation Solution
A method and system for biometric payments that involve receiving biometric data, determining a biometric identifier, and generating an authorization request message with a payment number and an indication of biometric authentication, allowing users to manage and control the use of their biometric data through a credential manager and biometric orchestration platform.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric data is stored by the merchant system for payment authentication, then payment convenience and security are improved, but the risk of data exposure and fraud increases when the merchant system is compromised
Solution Approach 1:
The patent extracts the biometric data storage function from the merchant system and relocates it to a centralized credential manager operated by the payment network. This separation ensures that even if the merchant system is compromised, the biometric data remains protected in the secure credential manager, eliminating the harmful effect of data exposure while maintaining payment security benefits.
Solution Approach 2:
The credential manager acts as an intermediary between the consumer and the merchant system. It securely stores biometric data and manages the authentication process, allowing merchants to use biometric payments without directly handling or storing the biometric data themselves. This intermediary approach reduces the merchant's security burden and liability while enabling convenient biometric payments.
2Ease of operation
If biometric payments are implemented with passive initiation, then user convenience is improved, but the consumer loses control over when and where biometric data can be used
Solution Approach 1:
The system provides dynamic control over biometric payment usage. Consumers can actively manage their biometric data by enabling or disabling it for specific merchants through the credential manager interface. This dynamic adjustment allows users to maintain convenience during active periods while revoking access when needed, balancing ease of operation with user control flexibility.
Solution Approach 2:
The credential manager provides consumers with feedback about which merchants have access to their biometric data and when. Consumers receive notifications and can review the list of authorized merchants, allowing them to make informed decisions about their biometric payment preferences and revoke access from specific merchants without affecting overall system convenience.
3Measurement precision
If merchants store payment credentials in association with biometric data, then authentication accuracy is improved, but the compliance burden and security investment requirements increase significantly
Solution Approach 1:
The patent extracts the credential storage function from individual merchant systems and consolidates it in a centralized credential manager. This eliminates the need for each merchant to invest in complex secure hardware and data security processes while maintaining high authentication accuracy through secure biometric verification. The credential manager handles the complex security infrastructure centrally, allowing merchants to focus on providing good customer service.
Data Source
AI summary
A method for biometric payments comprises: receiving biometric data obtained by a biometric reader device from a user who is registered for biometric payments with a merchant; determining a biometric identifier that is associated with the biometric data; determining a stored payment credential that is associated with the biometric identifier, wherein the stored payment credential is not stored by the merchant; determining a payment card number or payment token based on the stored payment credential; and generating an authorisation request message for processing by an issuer, wherein the authorisation request message comprises the payment card number or payment token, and a data element comprising an indication that the user was authenticated by a biometric authentication method.


