Mobile Device Transaction Security via Local Biometric Cryptography

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile device transaction methods require network connectivity and expose sensitive data to security risks, limiting their use in areas with limited connectivity and posing challenges for smaller merchants to adopt new payment systems.

Innovation Solution

A system that allows mobile devices to conduct transactions without internet connectivity by generating a limited-use key based on biometric inputs, enabling secure transactions directly with merchant systems without modifying existing hardware or software, and using a token stored on the device for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network connectivity is required for transaction authentication, then secure data exchange with remote servers is achieved, but transaction capability is lost in areas with limited connectivity

Engineering Contradiction:
Improvetransaction capabilityVSAvoidnetwork connectivity requirement
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by storing authentication data and generating cryptographic keys locally on the mobile device before network connectivity is needed. The device can authenticate transactions using pre-stored security credentials, eliminating the requirement for real-time network connection during transaction execution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a local cryptographic intermediary mechanism that mediates between the transaction data and remote servers. Instead of requiring direct network communication for authentication, the system uses locally-generated cryptographic proofs as intermediaries to verify transactions without exposing sensitive data or requiring continuous network connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If sensitive account data is transmitted over network connections, then transaction authentication is enabled, but security risks increase due to exposure on public networks

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system extracts sensitive account data from network transmission by implementing local authentication mechanisms. Instead of transmitting account information over networks, the patent extracts only necessary transaction identifiers and cryptographic proofs, keeping sensitive data localized on the user's device and eliminating exposure risks associated with network transmission.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent employs disposable cryptographic tokens and single-use authentication credentials that are generated locally and consumed immediately for transaction verification. These short-lived cryptographic objects replace persistent sensitive data transmission, ensuring that even if intercepted, the data cannot be reused for fraudulent transactions.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If merchant systems require specialized hardware and software modifications, then secure transaction processing is improved, but adoption barriers increase for smaller merchants

Engineering Contradiction:
Improvetransaction securityVSAvoidmerchant system requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service functionality by enabling mobile devices to perform local authentication and cryptographic verification independently. This shifts the computational burden from merchant systems to user devices, allowing merchants to process secure transactions using existing standard hardware without requiring specialized equipment or complex software modifications.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal authentication protocol that works across diverse merchant systems without requiring specialized hardware. The standardized cryptographic interface can be implemented on general-purpose computing devices, enabling widespread adoption across different merchant types from small businesses to large enterprises without infrastructure investment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3642761B1System, method, and computer program product for mobile device transactions
Publication Date: 2022.11.02 VISA INTERNATIONAL SERVICE ASSOCIATION
  • EP3642761B1 patent drawingFigure 1~2
  • EP3642761B1 patent drawingFigure 3
  • EP3642761B1 patent drawingFigure 4

AI summary

Provided is a system, method, and computer program product for conducting a transaction with a mobile device. The method includes generating, on the mobile device, a limited use key based at least partially on at least one biometric input from a user, receiving, on the mobile device, transaction data from a point-of-sale system via a direct wireless communication with the mobile device, the transaction data corresponding to a transaction between the user and a merchant, generating, on the mobile device, a cryptogram based at least partially on the limited use key and the transaction data, and communicating, from the mobile device, the cryptogram to the point-of-sale system via the direct wireless communication.