Contactless Card Biometric Authentication for Digital Identity Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for user authentication in account provisioning, such as banking and payment accounts, rely heavily on physical identification documents and are inefficient in verifying identities using contactless communication methods, lacking a secure and efficient way to provision digital identities across multiple devices.
Innovation Solution
A system and method that utilizes a mobile application and a contactless card device to authenticate users through biometric comparison, allowing for the provisioning of digital identities on communication devices via a two-factor authentication process, where biometric data is captured and compared to reference data stored on the card device, and if necessary, physical documents are verified to ensure identity validation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If physical identification documents are used for user authentication in account provisioning, then identity verification can be performed, but the process becomes inefficient and requires physical document handling
Solution Approach 1:
The patent creates a digital copy of the physical identification document by capturing an image of the document, extracting relevant identity information, and storing it in a database. This digital copy can then be used for authentication without requiring the physical document, thereby improving efficiency while maintaining verification accuracy
Solution Approach 2:
The patent replaces the mechanical process of physical document handling with an automated optical and digital system. A camera captures the document image, image processing algorithms extract information, and automated systems verify authenticity, eliminating manual physical document handling and significantly improving authentication efficiency
2Adaptability or versatility
If digital identities are provisioned across multiple devices, then user convenience is improved, but security risks increase without proper authentication mechanisms
Solution Approach 1:
The patent performs preliminary biometric authentication and identity verification before provisioning a digital identity to a new device. The system captures biometric data, compares it with stored reference data, and only after successful verification does it provision the digital identity, ensuring security is maintained while enabling multi-device access
Solution Approach 2:
The patent introduces biometric data as an intermediary verification mechanism between the user and the digital identity provisioning process. The biometric authentication acts as a secure mediator that confirms the user's identity before allowing digital identity to be provisioned to a new device, thereby maintaining security while enabling versatility
3Speed
If contactless communication methods are used for identity verification, then processing speed is improved, but the systems lack established secure protocols for digital identity provisioning
Solution Approach 1:
The patent establishes secure communication protocols and provisions digital identities before contactless verification transactions occur. The system pre-configures security parameters, provisions digital identities to authorized devices, and sets up encrypted communication channels in advance, enabling fast contactless verification while maintaining security
Solution Approach 2:
The patent implements self-service digital identity provisioning where the system automatically manages the provisioning process, security parameter configuration, and protocol establishment without requiring manual intervention. This automated approach ensures consistent security standards while enabling rapid contactless communication
Data Source
AI summary
Systems and methods are provided for use in provisioning digital identities for users. One exemplary method includes receiving, at a card device, an authentication request and a captured first biometric of a user, from a communication device associated with the user, and comparing the first biometric and a first biometric reference at the card device, in response to the first biometric reference being stored at the card device. The method also includes capturing, at the card device, a second biometric of the user and comparing the second biometric to a second biometric reference stored at the card device. The method further includes compiling a response to the authentication request including a first indicator of the comparison of the first biometric to the first biometric reference and a second indicator of the comparison of the second biometric to the second biometric reference, and transmitting the response to the communication device.


