Biometric PIN Authentication for Secure Network Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods for payment accounts are often cumbersome and susceptible to fraud, as they rely on single biometrics or PINs that can be easily simulated or stolen.

Innovation Solution

A system that uses a biometric personal identification number (PIN) composed of multiple unique biometrics, where each biometric is assigned a character, requiring sequential verification to form an actual PIN for transaction authentication, enhancing security through multi-factor biometric authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If single biometric or PIN authentication is used, then authentication process is simple, but security against fraud is weak

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system segments the authentication process into multiple distinct steps, each requiring a different biometric modality (fingerprint, facial recognition, iris scan, etc.). Each biometric factor is verified separately and sequentially, transforming a single complex authentication into multiple simpler verification steps, thereby enhancing security without overwhelming complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs composite authentication by combining multiple biometric modalities (fingerprint, facial recognition, iris scan, voice recognition) into a unified authentication framework. This composite approach leverages the strengths of each biometric type to create a more robust security system that is resistant to various forms of fraud while maintaining manageable operational complexity.

Inventive Principle:
Principle #40Composite materials

2Reliability

If multiple biometrics are required sequentially, then fraud prevention is improved, but authentication time increases

Engineering Contradiction:
Improvefraud prevention capabilityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary biometric verifications in parallel where possible, and pre-registers multiple biometric profiles in advance. During authentication, the system can quickly switch between pre-registered biometric modes rather than capturing and processing each biometric in real-time, significantly reducing authentication time while maintaining the security benefits of multi-factor verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system dynamically adjusts the number and type of biometric verifications required based on risk assessment, transaction amount, and user history. For low-risk transactions, the system may require fewer biometric factors, while high-risk transactions trigger more stringent multi-factor verification, optimizing the balance between security and speed.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10554409B2Systems and methods for use in authenticating users in connection with network transactions
Publication Date: 2020.02.04 MASTERCARD INT INC
  • US10554409B2 patent drawing
  • US10554409B2 patent drawing
  • US10554409B2 patent drawing

AI summary

Systems and methods are provided for use in authenticating a user in connection with a network transaction, based on a biometric personal identification number (PIN). One exemplary method includes intercepting a request associated with a network transaction. The request includes a series of biometric data associated with a user. The exemplary method also includes verifying the series of biometric data and converting, by the computing device, the series of biometric data to an actual personal identification number (PIN) where the actual PIN includes a series of characters. The method then further includes appending the actual PIN to the request, and transmitting the request to an entity, thereby permitting the entity to authenticate the user, at least in part, based on the actual PIN.