Digital Fingerprint Authentication for Mobile Value Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional mobile value transfer authentication methods restrict users to known locations and fail to prevent unauthorized transactions when the mobile device or account is stolen, as they rely on geographical location information and passwords, which are not secure in dynamic or stolen account scenarios.
Innovation Solution
An identity authentication method that generates a digital fingerprint using device and user information, performs virtual-resource data processing authentication based on a user value transfer behavior model, and issues a value transfer token for secure transactions, allowing authentication without geographical restrictions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If geographical location information is used for authentication, then value transfer security is improved, but user convenience deteriorates when users frequently change locations
Solution Approach 1:
The patent changes the authentication parameter from static geographical location information to dynamic digital fingerprint information that evolves with user behavior patterns. The digital fingerprint is updated based on real-time analysis of user's value transfer behaviors, device characteristics, and operational patterns, allowing secure authentication without location restrictions.
Solution Approach 2:
The authentication system transitions from static location-based verification to dynamic behavior-based verification. The digital fingerprint continuously adapts to reflect the user's current behavior patterns, making the authentication system flexible and convenient for users who frequently change locations while maintaining high security.
2Device complexity
If password-based authentication is used, then implementation simplicity is improved, but security deteriorates when the mobile device or account is stolen
Solution Approach 1:
The patent introduces a behavior analysis server as an intermediary that generates the digital fingerprint. This server collects and analyzes various user behavior data, device information, and transaction patterns to create a comprehensive authentication credential that is much harder to steal or replicate than a simple password.
Solution Approach 2:
The digital fingerprint is composed of multiple heterogeneous elements including device characteristics, user behavior patterns, transaction history, and real-time operational data. This composite authentication credential provides superior security compared to a single-factor password while maintaining systematic simplicity through automated generation and verification.
3Reliability
If location-based authentication is implemented, then prevention of unauthorized transactions is improved, but adaptability deteriorates for users with multiple frequent locations
Solution Approach 1:
The patent segments the authentication factors into multiple independent components that are combined to form the digital fingerprint: device information, user behavior patterns, transaction characteristics, and temporal data. This segmentation allows the system to verify identity without being constrained to specific geographical locations, improving adaptability while maintaining security.
Data Source
AI summary
An identity authentication method is provided, including: obtaining a virtual-resource data processing request sent by a mobile terminal, the virtual-resource data processing request carrying a prestored digital fingerprint, and the digital fingerprint being generated by using device information and user information; performing virtual-resource data processing authentication on the virtual-resource data processing request according to a pre-established user value transfer behavior model; after virtual-resource data processing authentication succeeds, generating a value transfer token according to the digital fingerprint, and returning the value transfer token to the mobile terminal; receiving a value transfer request sent by the mobile terminal, the value transfer request carrying the value transfer token; and checking whether the value transfer token is valid, if the value transfer token is valid, identity authentication succeeding; otherwise, identity authentication failing.


