Offline Authentication Using Limited-Use Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing secure element-based payment systems in portable communication devices are cumbersome and costly, and they pose security concerns when transactions are conducted without constant network connectivity or when relying on secure elements is impractical.

Innovation Solution

The implementation of cloud-based transactions using limited-use account parameters, which are replenished from the cloud, allowing transactions to be conducted securely without relying on secure elements, and enabling offline data authentication to reduce processing time in environments with limited connectivity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure element is used to store account information, then transaction security is improved, but device complexity and manufacturing cost increase

Engineering Contradiction:
Improvetransaction securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security-critical functions from the secure element hardware and implements them through software-based cryptographic operations using the mobile device's existing processor and memory resources. The system uses cryptographic protocols to achieve secure transaction processing without requiring dedicated secure element hardware, thereby reducing device complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a virtual representation of secure element functionality through software emulation. Instead of relying on physical secure element hardware, the system uses cryptographic keys and protocols to replicate the security functions, allowing the mobile device to perform secure transactions through software-based authentication and encryption mechanisms.

Inventive Principle:
Principle #26Copying

2Reliability

If a secure element is used to store account information, then transaction security is improved, but manufacturing cost increases

Engineering Contradiction:
Improvetransaction securityVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent removes the requirement for expensive secure element hardware by extracting security functions to software implementation. The mobile device uses its existing processor, memory, and communication interfaces to perform cryptographic operations, eliminating the need to manufacture and integrate additional secure element components, thereby reducing manufacturing costs.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent employs ephemeral cryptographic keys and single-use authentication tokens that are generated and discarded after each transaction. This approach replaces expensive, permanent secure element hardware with inexpensive, temporary cryptographic credentials that provide equivalent security for each transaction without requiring costly hardware infrastructure.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Loss of time

If offline authentication is implemented, then processing time is reduced in environments with limited connectivity, but security verification complexity increases

Engineering Contradiction:
Improveprocessing timeVSAvoidsecurity verification complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent performs cryptographic authentication and verification operations locally on the mobile device before transaction completion, without requiring real-time network connectivity to the issuer. The system uses pre-configured cryptographic keys and protocols to verify transaction authenticity offline, eliminating network latency and enabling rapid transaction processing in environments with limited connectivity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-contained cryptographic verification capabilities within the mobile device that do not require external issuer system involvement during the authentication process. The device independently performs cryptographic operations to verify transaction legitimacy, enabling offline authentication without complex real-time communication protocols with remote systems.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11842350B2Offline authentication
Publication Date: 2023.12.12 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11842350B2 patent drawing
  • US11842350B2 patent drawing
  • US11842350B2 patent drawing

AI summary

Techniques for enhancing the security of a communication device when conducting a transaction using the communication device may include using a limited-use key (LUK) to generate a transaction cryptogram, and using a signature key to generate a signature. The transaction can be an offline data authentication transaction, and access can be granted based on authentication of the signature prior to verifying the transaction cryptogram.