Dual Key Authentication for Mobile Operations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user authentication systems for mobile operations require multiple authentications to access different keys, which is inefficient and insecure, as keys are not adequately protected from unauthorized access by new users on communication devices.
Innovation Solution
A dual key scheme is implemented, where a primary operation-based key authenticates the user and protects a secondary time-based key, allowing single authentication to access both keys for distinct operations, with the primary key stored securely in a trusted execution environment and only accessible by the payment application.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple separate authentication mechanisms are used to protect different keys, then security is improved, but system complexity and user operation burden increase
Solution Approach 1:
The patent combines multiple authentication mechanisms into a unified authentication flow. A single user authentication triggers the generation and release of multiple operation-based keys (first key for payment operations, second key for other operations) that were previously protected by separate authentication requirements. This merging maintains security while reducing operational complexity.
Solution Approach 2:
The patent creates a universal authentication system where a single user authentication event serves multiple purposes: it authenticates the user and simultaneously enables multiple different operations (payment transactions and other operations) through the generation of multiple operation-based keys. This multi-functionality eliminates the need for separate authentication flows for different operations.
2Reliability
If multiple separate authentication mechanisms are used to protect different keys, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The patent merges multiple authentication requirements into a single user authentication event. When the user authenticates once, the system generates multiple operation-based keys that collectively protect both payment and non-payment operations, eliminating the need for multiple separate authentication steps and improving user convenience.
Solution Approach 2:
The system performs preliminary key generation and association during the single authentication event. Operation-based keys are generated in advance and linked to the authenticated user session, allowing multiple operations to proceed without requiring additional authentication steps, thus improving ease of operation.
3Device complexity
If traditional authentication systems are used without operation-based keys, then device complexity is reduced, but security deteriorates as keys are not adequately protected from unauthorized access
Solution Approach 1:
The patent segments the authentication system into distinct operation-based keys (first operation-based key for payment operations, second operation-based key for other operations), each with specific access controls and lifecycles. This segmentation allows the system to maintain relatively simple overall structure while providing granular security protection for different types of operations, preventing unauthorized access even when new users are added to the device.
Data Source
AI summary
Systems and methods provide multi-function authentication. One exemplary method includes receiving a request to opt into multi-function authentication. A primary operation-based key is generated by the communication device, the operation-based key accessible based on authentication of the user and available for use after the authentication. The primary key is imported, by an application, into a secure key data structure, such that it is only accessible by the application. When the biometric authentication of the user is successful, the communication device transmits to an account server an indication that the user is eligible for multi-function authentication. The communication device receives a time-based secondary key from the account server, wherein the time-based key is useable only during a defined interval. The application links the secondary key to the primary key and imports the secondary key into the data structure such that it is only accessible via the primary key.


