Card Chip Authentication for Low-Exposure Identity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional identity verification and transaction authentication methods, particularly in electronic transactions, expose sensitive information to risks of data breaches and identity theft, leading to increased security costs and liabilities for entities handling private data.
Innovation Solution
A system and method utilizing chip-based identity verification, where a card chip is inserted into a user device, encrypted messages are transmitted between the chip and a server for verification, and access privileges are granted based on successful authentication, reducing exposure of private information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional identity verification methods requiring private information are used, then authentication can be performed, but data security risks and exposure to identity theft increase
Solution Approach 1:
The patent extracts the authentication function from the private information itself and relocates it to a separate authentication device (smart card, mobile device). The private information remains securely stored in the authentication device rather than being transmitted or exposed during verification, thus maintaining authentication reliability while eliminating data exposure risks
Solution Approach 2:
The patent introduces an authentication device as an intermediary between the user and the system requiring verification. This intermediary holds the private information securely and performs authentication operations without exposing the actual private data, thereby maintaining security while enabling reliable authentication
2Productivity
If private information is transmitted for verification, then authentication can be completed, but the risk of data breach and exposure increases
Solution Approach 1:
The patent extracts the sensitive private information from the transmission process entirely. Instead of transmitting private data for verification, the system transmits only authentication results or tokens generated by the authentication device, thus maintaining transaction efficiency while eliminating data exposure risk
Solution Approach 2:
The patent uses authentication tokens or digital certificates as copies that represent the private information without being the actual private data. These tokens can be transmitted safely for verification without exposing the underlying sensitive information, enabling efficient authentication without data exposure
3Object-affected harmful factors
If data security measures are strengthened to protect private information, then security risk is reduced, but transaction convenience and ease of operation decrease
Solution Approach 1:
The authentication device performs self-service authentication operations automatically. The device manages its own private information securely, performs cryptographic operations internally, and automatically communicates with verification systems, providing strong security without requiring user intervention or complex user actions
Solution Approach 2:
The authentication device performs preliminary authentication operations and generates tokens or certificates in advance. This preliminary action establishes security credentials that can be used repeatedly for multiple transactions without repeating the full authentication process, maintaining both security and convenience
Data Source
AI summary
Example embodiments of systems, methods, and computer-accessible mediums for identity verification and transaction authentication are provided. An exemplary system can comprise an application, a user device, and a server. The application can prompt a removal of a card chip, prompt an insertion of the card chip into the user device, determine an orientation of the card chip after the insertion of the card chip into the user device, and transmit, to the card chip, a first message. The card chip can encrypt the first message via one or more authentication protocols to generate an encrypted first message, transmit, to the server, the encrypted first message. The server can decrypt the encrypted first message, verify the decrypted first message, and transmit a second message to the application, wherein the application is configured to display a verification notification in response to the second message.


