Passkey Authentication in 3-D Secure for Cross-Origin Payments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Electronic transactions lack robust security features for verifying the identity of the purchaser, as they rely on user-provided information that can be fraudulent, and existing authentication protocols like 3-D SECURE do not integrate well with more secure methods such as WebAuthN, especially in cross-origin contexts.
Innovation Solution
Integrate the 3-D SECURE protocol with WebAuthN by enabling the use of biometrics and passkeys for authentication, allowing cross-origin iFrame support in different versions of the WebAuthN protocol to enhance security in online transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional password-based authentication is used in 3-D SECURE protocol, then implementation compatibility is maintained, but security against fraudulent transactions is insufficient
Solution Approach 1:
The patent merges the 3-D SECURE protocol with WebAuthN to create a hybrid authentication system that combines the security benefits of both approaches. The 3-D SECURE protocol provides transaction-specific security while WebAuthN provides robust user authentication using biometrics and passkeys, resolving the contradiction by integrating two complementary security frameworks rather than replacing one with the other.
Solution Approach 2:
The patent introduces WebAuthN as an intermediary authentication layer between the merchant and the payment network. This intermediary uses biometric verification and passkeys to establish user identity before the 3-D SECURE protocol processes the transaction, thereby enhancing security without requiring changes to the core 3-D SECURE architecture.
2Adaptability or versatility
If cross-origin iFrame support is enabled for WebAuthN, then authentication versatility is improved, but protocol compatibility issues arise
Solution Approach 1:
The patent implements dynamic protocol selection that adapts to the browser and context capabilities. The system dynamically determines whether to use cross-origin iFrame support or traditional authentication flows based on the specific browser version, security context, and transaction requirements, allowing versatile cross-origin authentication while managing protocol complexity through intelligent adaptation.
Solution Approach 2:
The patent changes the authentication parameters and configuration options based on the operational context. By adjusting protocol parameters such as origin validation rules, iFrame embedding settings, and authentication flow selection, the system achieves cross-origin versatility while maintaining compatibility through parameter-based adaptation rather than structural complexity.
3Reliability
If biometrics and passkeys are integrated into 3-D SECURE, then user authentication security is enhanced, but implementation complexity increases
Solution Approach 1:
The patent implements self-service authentication where the user's device automatically handles biometric verification and passkey authentication without requiring server-side processing. The WebAuthN library on the client side performs cryptographic operations locally, eliminating the need for complex server infrastructure while maintaining high security standards, thus enhancing authentication security without proportionally increasing implementation complexity.
Data Source
AI summary
Disclosed are various embodiments for integrating the use of passkeys in the 3-D SECURE authentication protocol for transactions. A user of a client device can be prompted to enter a secondary factor of authentication for a second transaction, wherein the prompt includes transaction information and merchant information. In response to a selection to enter the secondary factor of authentication, biometric authentication of the user of the client device can be performed. In response to successful biometric authentication of the second transaction, a challenge comprising the transaction information and the merchant information can be cryptographically signed with a private passkey. The cryptographic signature of the challenge can then be sent to the transaction authorization service.


