Offline Biometric Authentication for Mobile Transaction Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for mobile transactions struggle with providing offline access to transactional data, as they rely on network connectivity for authentication and data access, which is not always available.

Innovation Solution

A system and method that utilize a mobile device with biometric sensors to authenticate users offline, allowing access to encrypted transactional data using a cryptographic authentication key generated from biometric and password inputs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network connectivity is required for authentication, then security is maintained, but offline access to transactional data becomes impossible

Engineering Contradiction:
ImprovesecurityVSAvoidoffline access capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary authentication actions by storing encrypted transactional data and authentication credentials on the mobile device before offline access is needed. This allows the device to authenticate users and provide access to transactional data without requiring network connectivity at the time of access, while maintaining security through pre-established encryption.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If encrypted data is stored on the device, then offline access is enabled, but security risks increase

Engineering Contradiction:
Improveoffline access capabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system applies different security qualities to different parts of the data storage system. Transactional data is encrypted using device-specific keys stored securely on the mobile device, while authentication credentials are protected through biometric authentication. This localized application of security measures enables offline access while maintaining appropriate security protections for each type of data.

Inventive Principle:
Principle #3Local quality

3Reliability

If biometric authentication is implemented, then security is enhanced, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses the user's own biometric characteristics (fingerprint, facial recognition, or iris scan) as the authentication mechanism. The mobile device's built-in biometric sensor captures and verifies the user's biometric data locally, eliminating the need for external authentication servers or complex manual authentication processes. This self-service approach enhances security while keeping the device architecture relatively simple.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12307446B2Secure multi-factor user authentication on disconnected mobile devices
Publication Date: 2025.05.20 PAYPAL INC
  • US12307446B2 patent drawing
  • US12307446B2 patent drawing
  • US12307446B2 patent drawing

AI summary

Embodiments described herein disclose a mobile device system for providing access to a subset of data within an application executed by the mobile device. During a first time period, when the mobile device is connected to a network, authentication information corresponding to a user account with a payment services provider is received. A biometric authentication signature and password are received in response to a request to enable access to a subset of data associated with the account. The subset of data is encrypted with a key generated from the biometric signature and password and stored. At a second time period, when the mobile device is disconnected from a network, the subset of data is decrypted using a key generated from an entered biometric signature and password.