Cryptogram-Based Payment Authentication via Secure Element
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing text message-based two-factor authentication for payment transactions is prone to failures due to network issues and delays, leading to reduced payment success rates and decreased customer satisfaction.
Innovation Solution
A computer-implemented method and system that uses a user device to generate and verify cryptograms based on a phone number and unique identification values, involving servers associated with the device manufacturer and network servers for authentication, eliminating the need for text message-based OTPs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If text message-based OTP authentication is used, then security is improved, but payment success rate deteriorates due to network failures and delays
Solution Approach 1:
The patent extracts the authentication process from the text message network dependency and implements it locally within the mobile device using hardware-based secure elements and biometric sensors. This removes the vulnerable intermediate step of SMS transmission while maintaining security through local verification of biometric data against stored cryptographic credentials.
Solution Approach 2:
The patent introduces a secure element or trusted execution environment as an intermediary between the biometric sensor and the payment processing system. This intermediary securely stores cryptographic credentials and performs verification without requiring external network communication, thus eliminating SMS-related failures while maintaining authentication security.
2Reliability
If text message-based OTP authentication is used, then security is improved, but transaction time deteriorates due to network delays
Solution Approach 1:
The patent performs preliminary actions by pre-storing cryptographic credentials and user biometric data within the mobile device's secure hardware elements during device setup. This preliminary configuration enables immediate local authentication without requiring real-time network communication, thus eliminating delays while maintaining security through pre-established cryptographic verification.
Solution Approach 2:
The patent implements self-service authentication where the mobile device independently verifies biometric data against stored cryptographic credentials using onboard processors and secure elements. This self-contained verification process eliminates dependency on external network services and SMS gateways, reducing transaction time while maintaining authentication security through hardware-based verification.
3Measurement precision
If SMS-based two-factor authentication is used, then user verification is improved, but customer satisfaction deteriorates due to authentication failures
Solution Approach 1:
The patent replaces the mechanical SMS transmission system with a hardware-based biometric verification system using sensors, secure elements, and cryptographic processing. This substitution eliminates the unreliability of network-dependent SMS delivery while maintaining precise user verification through biometric matching, thereby improving customer satisfaction by removing authentication failures.
Solution Approach 2:
The patent changes the fundamental parameter of authentication from network-dependent SMS delivery to hardware-based biometric verification. This parameter change transforms the authentication mechanism from being susceptible to network conditions to being dependent on reliable hardware components and cryptographic processes, thereby eliminating authentication failures while maintaining verification accuracy.
Data Source
AI summary
A method and system for authenticating a payment transaction. The method includes receiving a request for verifying a phone number associated with a Subscriber Identification Module card from a merchant application installed in the user device. Further, obtaining a first key from at least one of a server associated with a manufacturer of the user device and a network server. Furthermore, generating a first cryptogram based on at least one of the phone number and a unique identification value associated with the user device using the first key, wherein the first cryptogram is provided to the server associated with the manufacturer for verification. Upon verification of the first cryptogram, the method includes receiving a second cryptogram from the server associated with the manufacturer, wherein the merchant application provides the second cryptogram and payment transaction details to an issuer server for authentication of the payment transaction.


