Offline Payment Authentication Emulation via Counterfeit FIDO Payloads
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge in payment systems is ensuring secure user authentication for payment-enabled mobile devices when they are offline, as existing solutions like FIDO may cause user confusion due to differences in the user experience between online and offline processes.
Innovation Solution
A payment-enabled mobile device is designed to execute a local CDCVM process that emulates the FIDO user authentication experience by pre-storing templates and generating a counterfeit FIDO registration response payload, allowing the FIDO software to participate in offline authentication without departing from its normal online functionality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a local CDCVM process is used for offline authentication, then user authentication can be performed offline, but the user experience differs from online FIDO authentication causing user confusion
Solution Approach 1:
The patent creates a counterfeit FIDO registration response payload that copies the structure and appearance of a genuine FIDO authentication response. This allows the offline CDCVM process to present itself as if it were the online FIDO process, making the user experience consistent across both modes while enabling offline functionality
Solution Approach 2:
The system pre-generates and stores template data including counterfeit FIDO registration response payloads during offline operation. This preliminary preparation allows the offline authentication process to proceed smoothly without requiring real-time server communication, while maintaining the appearance of the expected online FIDO flow
2Reliability
If FIDO protocol is used for online authentication, then security is enhanced through biometric verification, but offline authentication becomes problematic due to server unavailability
Solution Approach 1:
The system performs preliminary actions by pre-generating authentication templates and counterfeit response payloads during online operation or in advance. These pre-prepared materials are stored locally and can be deployed during offline operation, ensuring that secure authentication capability is maintained even when the server is unavailable
Solution Approach 2:
The counterfeit FIDO registration response payload acts as an intermediary that bridges the gap between the offline CDCVM process and the FIDO software expectations. It allows the offline process to communicate with the FIDO authentication flow without requiring actual server interaction, thus maintaining security protocols while enabling offline operation
Data Source
AI summary
A payment-enabled mobile device is operable in a first operating mode and a second operating mode. The first mode is an online operating mode. The second mode is an offline operating mode. The payment-enabled mobile device operates in the second operating mode to replicate a screen display sequence presented by the payment-enabled mobile device in the first operating mode.


