Card Chip Authentication for Secure Identity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional identity verification and transaction authentication methods, particularly in electronic transactions, expose sensitive information to risks of data breaches and identity theft, increasing costs and liabilities for entities handling private data.

Innovation Solution

A system and method utilizing chip-based identity verification, where a card chip is inserted into a user device, encrypted messages are transmitted, and verified through a server, reducing exposure of private information while ensuring secure authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional identity verification methods requiring private information are used, then authentication can be performed, but data security risks increase and exposure to identity theft occurs

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiddata security risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication function from the private information itself and relocates it to a separate secure element (chip or token). The chip contains cryptographic keys and performs authentication operations without exposing the private information, thereby separating the authentication capability from the sensitive data that would otherwise be vulnerable to theft.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a chip or secure element as an intermediary between the user and the authentication system. This intermediary holds the private information securely and performs cryptographic operations, acting as a mediator that enables authentication without requiring the user to directly handle or transmit sensitive private information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If private information is transmitted for verification, then authentication can be completed, but exposure to hackers and fraudsters increases

Engineering Contradiction:
Improvetransaction processing speedVSAvoidexposure to unauthorized access
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive private information from the transmission process and keeps it confined within the secure element. Only cryptographic proofs or authenticated responses are transmitted, not the private information itself, thereby enabling fast transaction processing without exposing sensitive data to potential hackers and fraudsters.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary authentication actions within the secure element before any transmission occurs. The chip verifies credentials and generates authenticated responses in advance, so that when communication with the verification server occurs, only the already-authenticated data needs to be transmitted, not the raw private information.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If data security measures are implemented, then protection against data breaches improves, but transaction convenience decreases

Engineering Contradiction:
Improvedata securityVSAvoidtransaction convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service authentication where the chip automatically performs cryptographic operations and verification without requiring user intervention. The secure element handles all security-sensitive operations autonomously, providing strong data security protection while maintaining ease of operation as users simply need to insert the chip or use the device without needing to understand or manage the security mechanisms.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12118553B2Systems and methods for chip-based identity verification and transaction authentication
Publication Date: 2024.10.15 CAPITAL ONE SERVICES LLC
  • US12118553B2 patent drawing
  • US12118553B2 patent drawing
  • US12118553B2 patent drawing

AI summary

Example embodiments of systems, methods, and computer-accessible mediums for identity verification and transaction authentication are provided. An exemplary system can comprise an application, a user device, and a server. The application can prompt a removal of a card chip, prompt an insertion of the card chip into the user device, determine an orientation of the card chip after the insertion of the card chip into the user device, and transmit, to the card chip, a first message. The card chip can encrypt the first message via one or more authentication protocols to generate an encrypted first message, transmit, to the server, the encrypted first message. The server can decrypt the encrypted first message, verify the decrypted first message, and transmit a second message to the application, wherein the application is configured to display a verification notification in response to the second message.