Biometric Transaction Authentication via Dual-Source Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile transaction services face security issues due to the risk of unauthorized transactions when a SIM card is lost or compromised, as PIN codes can be exposed, compromising transaction information security.

Innovation Solution

A method and system for authenticating transaction requests using authentication information generated in both a device and a POS terminal, which includes fingerprint, pupil, voice, or signature data, allowing for secure comparison and verification of user identity before processing transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a SIM card with PIN code is used for mobile transaction service, then transaction convenience is improved, but security is worsened due to risk of PIN exposure and unauthorized transactions

Engineering Contradiction:
Improvetransaction convenienceVSAvoidtransaction security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is divided into two independent parts: the device generates first authentication information from user input, and the POS terminal generates second authentication information from the same user input. Both parts must be presented and verified for transaction approval, creating segmented authentication that prevents unauthorized transactions even if one component is compromised

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The server acts as an intermediary that receives both authentication information from the device and POS terminal, compares them to verify consistency, and then approves or rejects the transaction. This intermediary verification process ensures that neither the device nor the POS terminal alone can authorize transactions, enhancing security while maintaining convenience

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If password input is required to restrict access to mobile device or POS terminal, then security is improved, but ease of operation is worsened and security is still compromised when PIN code is exposed

Engineering Contradiction:
Improveaccess securityVSAvoidaccess convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The traditional mechanical PIN code entry system is replaced with biometric authentication methods such as fingerprint recognition, voice recognition, or facial recognition. These biometric systems provide both enhanced security (as biometric data is harder to steal or share) and improved convenience (as users simply present their biological traits rather than manually entering codes)

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The authentication parameter is changed from a user-created PIN code (which can be guessed, stolen, or forgotten) to unique biometric parameters (fingerprint patterns, voice characteristics, facial features). This parameter change fundamentally improves security while maintaining or enhancing user convenience, as biometric authentication is both more secure and more natural for users

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11232438B2Method and system for authenticating transaction request from device
Publication Date: 2022.01.25 SAMSUNG ELECTRONICS CO LTD
  • US11232438B2 patent drawing
  • US11232438B2 patent drawing
  • US11232438B2 patent drawing

AI summary

A device and method are provided. The device includes a controller, a memory, and a transceiver. The controller generates authentication information based on a user input to the device. The memory stores the generated authentication information. The transceiver receives authentication information, which is generated by a point of sale (POS) terminal based on a user input to the POS terminal, from the POS terminal, when the device enters within a predetermined range from the POS terminal. The controller compares the generated authentication information with the received authentication information, and provides card information which is used in a transaction with respect to an item or a service to the POS terminal based on a result of the comparison.