Offline Payment Authentication Emulation via Counterfeit FIDO Payloads

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge in payment systems is ensuring secure user authentication for payment-enabled mobile devices when they are offline, as existing solutions like FIDO may cause user confusion due to differences in the user experience between online and offline processes.

Innovation Solution

A payment-enabled mobile device is designed to execute a local CDCVM process that emulates the FIDO user authentication experience by pre-storing templates and generating a counterfeit FIDO registration response payload, allowing the FIDO software to participate in offline authentication without departing from its normal online functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a local CDCVM process is used for offline authentication, then user authentication can be performed offline, but the user experience differs from online FIDO authentication causing user confusion

Engineering Contradiction:
Improveoffline authentication capabilityVSAvoiduser experience consistency
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent creates a counterfeit FIDO registration response payload that copies the structure and appearance of a genuine FIDO authentication response. This allows the offline CDCVM process to present itself as if it were the online FIDO process, making the user experience consistent across both modes while enabling offline functionality

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system pre-generates and stores template data including counterfeit FIDO registration response payloads during offline operation. This preliminary preparation allows the offline authentication process to proceed smoothly without requiring real-time server communication, while maintaining the appearance of the expected online FIDO flow

Inventive Principle:
Principle #10Preliminary action

2Reliability

If FIDO protocol is used for online authentication, then security is enhanced through biometric verification, but offline authentication becomes problematic due to server unavailability

Engineering Contradiction:
Improveauthentication securityVSAvoidoffline operation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by pre-generating authentication templates and counterfeit response payloads during online operation or in advance. These pre-prepared materials are stored locally and can be deployed during offline operation, ensuring that secure authentication capability is maintained even when the server is unavailable

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The counterfeit FIDO registration response payload acts as an intermediary that bridges the gap between the offline CDCVM process and the FIDO software expectations. It allows the offline process to communicate with the FIDO authentication flow without requiring actual server interaction, thus maintaining security protocols while enabling offline operation

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10657533B2Apparatus and method for emulating online user authentication process in offline operations
Publication Date: 2020.05.19 MASTERCARD INT INC
  • US10657533B2 patent drawing
  • US10657533B2 patent drawing
  • US10657533B2 patent drawing

AI summary

A payment-enabled mobile device is operable in a first operating mode and a second operating mode. The first mode is an online operating mode. The second mode is an offline operating mode. The payment-enabled mobile device operates in the second operating mode to replicate a screen display sequence presented by the payment-enabled mobile device in the first operating mode.