Challenge-Response Transaction Verification With Secure Data Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cybersecurity systems fail to effectively integrate user authentication and transaction verification, leaving a gap that can be exploited by attackers, with existing methods focusing on either user authentication or transaction verification separately.
Innovation Solution
A system and method that unify authentication and verification by fusing biometric data and transaction information into a single data channel, ensuring that modifying transaction data automatically corrupts biometric data and vice versa, making fraud virtually impossible.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If user authentication and transaction verification are performed separately using conventional cybersecurity systems, then each process can be simplified and focused, but the system becomes vulnerable to fraud and data manipulation exploits
Solution Approach 1:
The patent merges user authentication and transaction verification into a single unified process. The system creates a unified data item that combines biometric data and transaction data, allowing both authentication and verification to occur simultaneously in one operation. This eliminates the sequential processing gap that fraudsters exploit and ensures that both processes must succeed together for the transaction to proceed.
Solution Approach 2:
The patent introduces a unified data item as an intermediary structure that links authentication and verification. This unified data item contains both biometric and transaction information in an interconnected format, where modifying one type of data automatically affects the other. The unified data item serves as the mediator that ensures both authentication and verification are achieved before the transaction is approved.
2Reliability
If biometric data and transaction data are stored separately, then data management is simpler, but the system cannot prevent correlated manipulation of both data types
Solution Approach 1:
The patent combines biometric data and transaction data into a single unified data item structure. This unified structure maintains the integrity relationship between the two data types, ensuring that any manipulation of biometric data automatically affects the associated transaction data and vice versa. The merging is done in a way that preserves the correlation between authentication and verification without requiring complex external tracking mechanisms.
3Reliability
If the system allows independent modification of transaction data and biometric data, then data entry and processing is more flexible, but fraudsters can manipulate each data type without detection
Solution Approach 1:
The patent implements a feedback mechanism within the unified data item structure. When transaction data is modified, the system automatically generates a feedback effect that corrupts the associated biometric data, and vice versa. This built-in feedback loop makes any manipulation attempt detectable because the correlation between the two data types is broken, allowing the system to identify and reject fraudulent transactions.
Data Source
AI summary
Computerized method for verification of user identity and transaction data authenticity, usable in systems having an electronic device that communicates with a remote server. The method includes: (a) receiving user interactions at a non-secure execution environment of the electronic device, reflecting transaction data entered by a user; and transmitting transaction data from the non-secure execution environment to the server; (b) locally authenticating the transaction data and user identity in a secure execution environment of the electronic device; and encrypting transaction data in that secure execution environment, by utilizing a Cryptographic Private Key of the electronic device as encryption key; and transmitting encrypted version of locally-authenticated transaction data from the electronic device to the server. Then, at the server: (c1) receiving the transaction data that was sent in step (a) from the non-secure execution environment to the server, and delaying transaction execution until arrival and verification processing of the encrypted version; (c2) receiving the encrypted version, and decrypting it by utilizing a Cryptographic Public Key of the electronic device as decryption key; (c3) checking whether or not transaction data obtained in step (c1), match transaction data obtained in step (c2); and if they do no match, then: generating a signal that voids or cancels the transaction.

