Biometric Token Provisioning via EMV Cryptogram Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for tokenization in payment transactions lack efficient integration of EMV capabilities and biometric authentication, leading to insecure and cumbersome processes for users and merchants.
Innovation Solution
The system integrates EMV-enabled devices with biometric authentication, using a token service provider to validate cryptograms and transaction IDs, and employs EMV chips for enhanced security, allowing users to tokenize payment accounts and perform transactions securely through biometric verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional card-based payment systems are used, then transaction processing is simple, but security is compromised as account numbers are exposed to merchants
Solution Approach 1:
The patent uses tokenization to create a substitute representation (token) of the actual account number. The token serves as a copy that can be transmitted and stored without exposing the real account data, thereby maintaining security while enabling transaction processing
Solution Approach 2:
The patent introduces a token service provider as an intermediary between the user and the merchant. This intermediary generates and manages tokens, replacing the direct exposure of account numbers and adding a security layer without significantly complicating the user experience
2Reliability
If tokenization is implemented without EMV and biometric integration, then system implementation is simpler, but authentication security is insufficient
Solution Approach 1:
The patent merges multiple security mechanisms (EMV chip technology, biometric authentication, and tokenization) into a unified payment system. The EMV chip generates cryptograms that are validated by the token service provider, while biometric data provides an additional layer of user verification, creating a multi-factor authentication system
Solution Approach 2:
The patent performs preliminary validation of EMV cryptograms and biometric data before token generation. The token service provider validates the cryptogram and verifies biometric authentication in advance of the actual transaction, ensuring security requirements are met before committing resources
3Ease of operation
If manual token provisioning processes are used, then system implementation is simpler, but user experience is cumbersome
Solution Approach 1:
The patent enables users to provision tokens themselves through biometric authentication. The user's biometric data serves as the key to generate and store tokens locally on their device, eliminating the need for manual enrollment processes and giving users control over their own token provisioning
Solution Approach 2:
The system performs preliminary token generation and storage on the user's device before transactions occur. Tokens are created and cached locally, allowing for rapid transaction processing without requiring real-time communication with the token service provider during actual purchases
4Productivity
If actual account numbers are shared with merchants, then transaction processing is straightforward, but data protection is compromised
Solution Approach 1:
The patent replaces actual account numbers with token copies for transmission to merchants. The token contains sufficient information to process transactions but cannot be reverse-engineered to reveal the original account number, maintaining transaction efficiency while eliminating data exposure risks
Solution Approach 2:
The patent transitions from a single-dimensional system (account number) to a multi-dimensional system involving tokens, cryptograms, and biometric data. This dimensional expansion allows the system to maintain transaction processing capabilities while adding layers of protection that prevent direct exposure of sensitive account information
Data Source
AI summary
Systems and methods for enabling biometric transactions are provided. One example computer-implemented method includes receiving a request to provision a biometric for biometric transactions to a payment account of a user, where the request includes a cryptogram associated with a transaction to the payment account, and checking with an issuer of the payment account whether the payment account is supported for biometric transactions. In response to the payment account not being supported for biometric transactions, the method includes validating the cryptogram, receiving from the issuer an eligibility code for the payment account, receiving a verification result for the cryptogram, and requesting a biometric from the user. The method then includes receiving biometric data indicative of a biometric of the user and transmitting a request to the issuer to enable biometric transactions for the payment account, where the request includes an identifier of the payment account and the verification result.


