Cryptogram-Based Payment Authentication via Secure Element

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing text message-based two-factor authentication for payment transactions is prone to failures due to network issues and delays, leading to reduced payment success rates and decreased customer satisfaction.

Innovation Solution

A computer-implemented method and system that uses a user device to generate and verify cryptograms based on a phone number and unique identification values, involving servers associated with the device manufacturer and network servers for authentication, eliminating the need for text message-based OTPs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If text message-based OTP authentication is used, then security is improved, but payment success rate deteriorates due to network failures and delays

Engineering Contradiction:
Improveauthentication securityVSAvoidpayment success rate
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the authentication process from the text message network dependency and implements it locally within the mobile device using hardware-based secure elements and biometric sensors. This removes the vulnerable intermediate step of SMS transmission while maintaining security through local verification of biometric data against stored cryptographic credentials.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a secure element or trusted execution environment as an intermediary between the biometric sensor and the payment processing system. This intermediary securely stores cryptographic credentials and performs verification without requiring external network communication, thus eliminating SMS-related failures while maintaining authentication security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If text message-based OTP authentication is used, then security is improved, but transaction time deteriorates due to network delays

Engineering Contradiction:
Improveauthentication securityVSAvoidtransaction time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-storing cryptographic credentials and user biometric data within the mobile device's secure hardware elements during device setup. This preliminary configuration enables immediate local authentication without requiring real-time network communication, thus eliminating delays while maintaining security through pre-established cryptographic verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service authentication where the mobile device independently verifies biometric data against stored cryptographic credentials using onboard processors and secure elements. This self-contained verification process eliminates dependency on external network services and SMS gateways, reducing transaction time while maintaining authentication security through hardware-based verification.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If SMS-based two-factor authentication is used, then user verification is improved, but customer satisfaction deteriorates due to authentication failures

Engineering Contradiction:
Improveuser verification accuracyVSAvoidcustomer satisfaction
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent replaces the mechanical SMS transmission system with a hardware-based biometric verification system using sensors, secure elements, and cryptographic processing. This substitution eliminates the unreliability of network-dependent SMS delivery while maintaining precise user verification through biometric matching, thereby improving customer satisfaction by removing authentication failures.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the fundamental parameter of authentication from network-dependent SMS delivery to hardware-based biometric verification. This parameter change transforms the authentication mechanism from being susceptible to network conditions to being dependent on reliable hardware components and cryptographic processes, thereby eliminating authentication failures while maintaining verification accuracy.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12112320B2Method and system of authenticating a payment transaction using a user device
Publication Date: 2024.10.08 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US12112320B2 patent drawing
  • US12112320B2 patent drawing
  • US12112320B2 patent drawing

AI summary

A method and system for authenticating a payment transaction. The method includes receiving a request for verifying a phone number associated with a Subscriber Identification Module card from a merchant application installed in the user device. Further, obtaining a first key from at least one of a server associated with a manufacturer of the user device and a network server. Furthermore, generating a first cryptogram based on at least one of the phone number and a unique identification value associated with the user device using the first key, wherein the first cryptogram is provided to the server associated with the manufacturer for verification. Upon verification of the first cryptogram, the method includes receiving a second cryptogram from the server associated with the manufacturer, wherein the merchant application provides the second cryptogram and payment transaction details to an issuer server for authentication of the payment transaction.