Offline Authentication Using Limited-Use Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing secure element-based payment systems in portable communication devices are cumbersome and costly, and they pose security concerns when transactions are conducted without constant network connectivity or when relying on secure elements is impractical.
Innovation Solution
The implementation of cloud-based transactions using limited-use account parameters, which are replenished from the cloud, allowing transactions to be conducted securely without relying on secure elements, and enabling offline data authentication to reduce processing time in environments with limited connectivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a secure element is used to store account information, then transaction security is improved, but device complexity and manufacturing cost increase
Solution Approach 1:
The patent extracts the security-critical functions from the secure element hardware and implements them through software-based cryptographic operations using the mobile device's existing processor and memory resources. The system uses cryptographic protocols to achieve secure transaction processing without requiring dedicated secure element hardware, thereby reducing device complexity while maintaining security.
Solution Approach 2:
The patent creates a virtual representation of secure element functionality through software emulation. Instead of relying on physical secure element hardware, the system uses cryptographic keys and protocols to replicate the security functions, allowing the mobile device to perform secure transactions through software-based authentication and encryption mechanisms.
2Reliability
If a secure element is used to store account information, then transaction security is improved, but manufacturing cost increases
Solution Approach 1:
The patent removes the requirement for expensive secure element hardware by extracting security functions to software implementation. The mobile device uses its existing processor, memory, and communication interfaces to perform cryptographic operations, eliminating the need to manufacture and integrate additional secure element components, thereby reducing manufacturing costs.
Solution Approach 2:
The patent employs ephemeral cryptographic keys and single-use authentication tokens that are generated and discarded after each transaction. This approach replaces expensive, permanent secure element hardware with inexpensive, temporary cryptographic credentials that provide equivalent security for each transaction without requiring costly hardware infrastructure.
3Loss of time
If offline authentication is implemented, then processing time is reduced in environments with limited connectivity, but security verification complexity increases
Solution Approach 1:
The patent performs cryptographic authentication and verification operations locally on the mobile device before transaction completion, without requiring real-time network connectivity to the issuer. The system uses pre-configured cryptographic keys and protocols to verify transaction authenticity offline, eliminating network latency and enabling rapid transaction processing in environments with limited connectivity.
Solution Approach 2:
The patent implements self-contained cryptographic verification capabilities within the mobile device that do not require external issuer system involvement during the authentication process. The device independently performs cryptographic operations to verify transaction legitimacy, enabling offline authentication without complex real-time communication protocols with remote systems.
Data Source
AI summary
Techniques for enhancing the security of a communication device when conducting a transaction using the communication device may include using a limited-use key (LUK) to generate a transaction cryptogram, and using a signature key to generate a signature. The transaction can be an offline data authentication transaction, and access can be granted based on authentication of the signature prior to verifying the transaction cryptogram.


