Contactless Payment Authentication via Device-Local Reference Values
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional payment systems face challenges in securely authenticating customers during contactless transactions, as offline authentication is hindered by the short interaction time between devices, making online authentication necessary, which complicates system vulnerability and synchronization of reference values.
Innovation Solution
A method where the reference value of customer authentication data is stored exclusively on the customer's device, using a session key generated from a unique device key and variable data, performing one-way conversions and encryption, allowing for contactless transactions while maintaining security by comparing encrypted values through a trusted third party, the customer's bank server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If online authentication is used for contactless payments, then authentication can be completed within the short interaction time, but system vulnerability increases and synchronization of reference values becomes complex
Solution Approach 1:
The authentication data is segmented into two parts: a reference value stored on the customer's device and a matching value verified by the bank server. This segmentation allows the reference value to remain secure on the device while enabling online verification, thus resolving the contradiction between fast authentication and system security.
Solution Approach 2:
The bank server acts as an intermediary that verifies the matching value without storing the reference value. The server receives the matching value from the terminal, compares it with the reference value it generated, and returns the verification result. This intermediary role enables online authentication while maintaining security by preventing direct exposure of the reference value.
2Reliability
If reference value is stored on customer's device for offline authentication, then security is improved by avoiding network transmission, but contactless transactions cannot be performed due to short interaction time
Solution Approach 1:
The bank server pre-generates a reference value and stores it on the customer's device before the transaction occurs. During the contactless transaction, the device uses this pre-stored reference value to generate a matching value that can be quickly verified online, thus enabling both fast contactless transactions and maintained security.
Solution Approach 2:
The system transforms the reference value into a matching value through a one-way function that can be computed quickly. This parameter transformation allows the authentication data to be processed rapidly during contactless transactions while maintaining the security properties of the original reference value.
3Extent of automation
If reference value is stored on bank server for online authentication, then centralized control is achieved, but network transmission of confidential information becomes necessary
Solution Approach 1:
The reference value is extracted from the bank server and stored on the customer's device. The server retains only the ability to generate and verify matching values, not the reference value itself. This extraction eliminates the need for the server to transmit or store sensitive reference values, thus reducing confidential data transmission while maintaining centralized verification control.
Data Source
AI summary
The invention relates to the field of technical infrastructures that ensure the implementation of financial transactions between economic entities, in particular to payment systems that provide ease of use and confidential data security.The present invention is the method of authenticating a customer, the method of carrying out a payment transaction comprising said authentication method, and the payment system implementing the specified methods, which ensure the achievement of a technical effect consisting in expanding the functionality of the payment system and reducing its vulnerability, in particular, by making it possible to conduct a payment transaction in a contactless way, on condition that the reference value of the customer authentication data is stored exclusively on the customer's device, as well as by combining the advantages of online and offline customer authentication procedures.


