Challenge-Response Transaction Verification With Secure Data Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cybersecurity systems fail to effectively integrate user authentication and transaction verification, leaving a gap that can be exploited by attackers, with existing methods focusing on either user authentication or transaction verification separately.

Innovation Solution

A system and method that unify authentication and verification by fusing biometric data and transaction information into a single data channel, ensuring that modifying transaction data automatically corrupts biometric data and vice versa, making fraud virtually impossible.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user authentication and transaction verification are performed separately using conventional cybersecurity systems, then each process can be simplified and focused, but the system becomes vulnerable to fraud and data manipulation exploits

Engineering Contradiction:
Improvesecurity against fraudVSAvoidintegration of authentication and verification processes
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges user authentication and transaction verification into a single unified process. The system creates a unified data item that combines biometric data and transaction data, allowing both authentication and verification to occur simultaneously in one operation. This eliminates the sequential processing gap that fraudsters exploit and ensures that both processes must succeed together for the transaction to proceed.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a unified data item as an intermediary structure that links authentication and verification. This unified data item contains both biometric and transaction information in an interconnected format, where modifying one type of data automatically affects the other. The unified data item serves as the mediator that ensures both authentication and verification are achieved before the transaction is approved.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If biometric data and transaction data are stored separately, then data management is simpler, but the system cannot prevent correlated manipulation of both data types

Engineering Contradiction:
Improvedata integrityVSAvoiddata fusion and correlation mechanisms
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines biometric data and transaction data into a single unified data item structure. This unified structure maintains the integrity relationship between the two data types, ensuring that any manipulation of biometric data automatically affects the associated transaction data and vice versa. The merging is done in a way that preserves the correlation between authentication and verification without requiring complex external tracking mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If the system allows independent modification of transaction data and biometric data, then data entry and processing is more flexible, but fraudsters can manipulate each data type without detection

Engineering Contradiction:
Improvedetection of data manipulationVSAvoiddata entry and processing flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a feedback mechanism within the unified data item structure. When transaction data is modified, the system automatically generates a feedback effect that corrupts the associated biometric data, and vice versa. This built-in feedback loop makes any manipulation attempt detectable because the correlation between the two data types is broken, allowing the system to identify and reject fraudulent transactions.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12548025B2System, device, and method of transaction verification based on challenge and response messages
Publication Date: 2026.02.10 IRONVEST INC
  • US12548025B2 patent drawing
  • US12548025B2 patent drawing

AI summary

Computerized method for verification of user identity and transaction data authenticity, usable in systems having an electronic device that communicates with a remote server. The method includes: (a) receiving user interactions at a non-secure execution environment of the electronic device, reflecting transaction data entered by a user; and transmitting transaction data from the non-secure execution environment to the server; (b) locally authenticating the transaction data and user identity in a secure execution environment of the electronic device; and encrypting transaction data in that secure execution environment, by utilizing a Cryptographic Private Key of the electronic device as encryption key; and transmitting encrypted version of locally-authenticated transaction data from the electronic device to the server. Then, at the server: (c1) receiving the transaction data that was sent in step (a) from the non-secure execution environment to the server, and delaying transaction execution until arrival and verification processing of the encrypted version; (c2) receiving the encrypted version, and decrypting it by utilizing a Cryptographic Public Key of the electronic device as decryption key; (c3) checking whether or not transaction data obtained in step (c1), match transaction data obtained in step (c2); and if they do no match, then: generating a signal that voids or cancels the transaction.