Contactless Payment Authentication via Device-Local Reference Values

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional payment systems face challenges in securely authenticating customers during contactless transactions, as offline authentication is hindered by the short interaction time between devices, making online authentication necessary, which complicates system vulnerability and synchronization of reference values.

Innovation Solution

A method where the reference value of customer authentication data is stored exclusively on the customer's device, using a session key generated from a unique device key and variable data, performing one-way conversions and encryption, allowing for contactless transactions while maintaining security by comparing encrypted values through a trusted third party, the customer's bank server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If online authentication is used for contactless payments, then authentication can be completed within the short interaction time, but system vulnerability increases and synchronization of reference values becomes complex

Engineering Contradiction:
Improveauthentication timeVSAvoidsystem security
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The authentication data is segmented into two parts: a reference value stored on the customer's device and a matching value verified by the bank server. This segmentation allows the reference value to remain secure on the device while enabling online verification, thus resolving the contradiction between fast authentication and system security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The bank server acts as an intermediary that verifies the matching value without storing the reference value. The server receives the matching value from the terminal, compares it with the reference value it generated, and returns the verification result. This intermediary role enables online authentication while maintaining security by preventing direct exposure of the reference value.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If reference value is stored on customer's device for offline authentication, then security is improved by avoiding network transmission, but contactless transactions cannot be performed due to short interaction time

Engineering Contradiction:
Improveauthentication securityVSAvoidtransaction speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The bank server pre-generates a reference value and stores it on the customer's device before the transaction occurs. During the contactless transaction, the device uses this pre-stored reference value to generate a matching value that can be quickly verified online, thus enabling both fast contactless transactions and maintained security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system transforms the reference value into a matching value through a one-way function that can be computed quickly. This parameter transformation allows the authentication data to be processed rapidly during contactless transactions while maintaining the security properties of the original reference value.

Inventive Principle:
Principle #35Parameter changes

3Extent of automation

If reference value is stored on bank server for online authentication, then centralized control is achieved, but network transmission of confidential information becomes necessary

Engineering Contradiction:
Improvecentralized authentication controlVSAvoidconfidential data transmission
Core Design Contradiction:
Extent of automationVSLoss of information

Solution Approach 1:

The reference value is extracted from the bank server and stored on the customer's device. The server retains only the ability to generate and verify matching values, not the reference value itself. This extraction eliminates the need for the server to transmit or store sensitive reference values, thus reducing confidential data transmission while maintaining centralized verification control.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11682008B2Method of authenticating a customer, method of carrying out a payment transaction and payment system implementing the specified methods
Publication Date: 2023.06.20 ONETAP2
  • US11682008B2 patent drawing
  • US11682008B2 patent drawing
  • US11682008B2 patent drawing

AI summary

The invention relates to the field of technical infrastructures that ensure the implementation of financial transactions between economic entities, in particular to payment systems that provide ease of use and confidential data security.The present invention is the method of authenticating a customer, the method of carrying out a payment transaction comprising said authentication method, and the payment system implementing the specified methods, which ensure the achievement of a technical effect consisting in expanding the functionality of the payment system and reducing its vulnerability, in particular, by making it possible to conduct a payment transaction in a contactless way, on condition that the reference value of the customer authentication data is stored exclusively on the customer's device, as well as by combining the advantages of online and offline customer authentication procedures.