Mobile Device Transaction Security via Local Biometric Cryptography
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile device transaction methods require network connectivity and expose sensitive data to security risks, limiting their use in areas with limited connectivity and posing challenges for smaller merchants to adopt new payment systems.
Innovation Solution
A system that allows mobile devices to conduct transactions without internet connectivity by generating a limited-use key based on biometric inputs, enabling secure transactions directly with merchant systems without modifying existing hardware or software, and using a token stored on the device for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network connectivity is required for transaction authentication, then secure data exchange with remote servers is achieved, but transaction capability is lost in areas with limited connectivity
Solution Approach 1:
The system performs preliminary actions by storing authentication data and generating cryptographic keys locally on the mobile device before network connectivity is needed. The device can authenticate transactions using pre-stored security credentials, eliminating the requirement for real-time network connection during transaction execution.
Solution Approach 2:
The patent introduces a local cryptographic intermediary mechanism that mediates between the transaction data and remote servers. Instead of requiring direct network communication for authentication, the system uses locally-generated cryptographic proofs as intermediaries to verify transactions without exposing sensitive data or requiring continuous network connectivity.
2Reliability
If sensitive account data is transmitted over network connections, then transaction authentication is enabled, but security risks increase due to exposure on public networks
Solution Approach 1:
The system extracts sensitive account data from network transmission by implementing local authentication mechanisms. Instead of transmitting account information over networks, the patent extracts only necessary transaction identifiers and cryptographic proofs, keeping sensitive data localized on the user's device and eliminating exposure risks associated with network transmission.
Solution Approach 2:
The patent employs disposable cryptographic tokens and single-use authentication credentials that are generated locally and consumed immediately for transaction verification. These short-lived cryptographic objects replace persistent sensitive data transmission, ensuring that even if intercepted, the data cannot be reused for fraudulent transactions.
3Reliability
If merchant systems require specialized hardware and software modifications, then secure transaction processing is improved, but adoption barriers increase for smaller merchants
Solution Approach 1:
The system implements self-service functionality by enabling mobile devices to perform local authentication and cryptographic verification independently. This shifts the computational burden from merchant systems to user devices, allowing merchants to process secure transactions using existing standard hardware without requiring specialized equipment or complex software modifications.
Solution Approach 2:
The patent creates a universal authentication protocol that works across diverse merchant systems without requiring specialized hardware. The standardized cryptographic interface can be implemented on general-purpose computing devices, enabling widespread adoption across different merchant types from small businesses to large enterprises without infrastructure investment.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
Provided is a system, method, and computer program product for conducting a transaction with a mobile device. The method includes generating, on the mobile device, a limited use key based at least partially on at least one biometric input from a user, receiving, on the mobile device, transaction data from a point-of-sale system via a direct wireless communication with the mobile device, the transaction data corresponding to a transaction between the user and a merchant, generating, on the mobile device, a cryptogram based at least partially on the limited use key and the transaction data, and communicating, from the mobile device, the cryptogram to the point-of-sale system via the direct wireless communication.