Passkey Credential Selection for Phishing-Resistant Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current online interactions lack security due to the risk of data breaches and phishing attacks, especially when sensitive authentication data is exposed or provided to potentially untrusted resource providers, relying on insecure communication channels.

Innovation Solution

Implementing passkeys and WebAuthn to enable secure, frictionless authentication by leveraging discoverable credentials, eliminating the need for personal information and enhancing card-present security in online interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication data is stored in a database, then user authentication can be performed, but security is compromised in case of data breaches

Engineering Contradiction:
Improveauthentication securityVSAvoiddata breach risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication data from centralized databases and stores it locally in the user device's secure element. This eliminates the centralized database that is vulnerable to data breaches, while maintaining the ability to authenticate users through local credential storage and verification.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a credential verification system that acts as an intermediary between the user device and the resource provider. Instead of directly storing authentication data in databases, the system uses secure elements and verification protocols to mediate authentication, reducing exposure to data breaches.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication data is provided directly by user device to resource provider, then no database storage is needed, but users must input sensitive data into potentially unknown webpages

Engineering Contradiction:
Improveauthentication securityVSAvoidphishing attack risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements self-service authentication where the user device automatically provides authentication data to the resource provider without requiring manual input from the user. The system uses secure elements to store and transmit credentials automatically, eliminating the need for users to enter sensitive data into webpages and thus preventing phishing attacks.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary actions by pre-storing authentication data in secure elements on user devices before the authentication event. This allows the system to automatically provide credentials when needed without exposing users to phishing risks during data entry, as the credentials are already prepared and can be transmitted securely.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If authentication data is provided to resource provider computer, then authentication can be performed, but security relies on communication channel between user device and resource provider

Engineering Contradiction:
Improveauthentication convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts authentication data from the communication channel dependency and stores it locally in secure elements on user devices. This allows authentication to occur without relying solely on the security of the communication channel between user device and resource provider, while maintaining ease of operation through automatic credential provision.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20260046131A1Pass-key based credential processing
Publication Date: 2026.02.12 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US20260046131A1 patent drawing
  • US20260046131A1 patent drawing
  • US20260046131A1 patent drawing

AI summary

A computer receives an interaction request message. The computer transmits, to a user device, a relying party identifier associated with a relying party computer. The user device thereafter determines a list of credentials or identifiers thereof based on the relying party identifier. The computer receives the list of credentials or identifiers thereof from the user device. The computer conducts an interaction using a credential, identifier thereof, of the list of credentials or identifiers thereof.