Secure Enclave Biometric Authentication for Wireless Payments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for secure financial transactions via wireless communication are cumbersome and insecure, requiring repeated authentication processes that degrade the user experience and restrict the use of electronic devices for commercial activities.

Innovation Solution

An electronic device with a secure enclave processor and secure element that uses local biometric authentication information to validate transactions, enabling secure communication and single-proximity financial transactions through near-field communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (signature or PIN) are used for wireless financial transactions, then security is improved, but ease of operation deteriorates due to repeated authentication requirements and cumbersome processes

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs authentication in advance by comparing local authentication information (biometric data) with stored authentication information before the financial transaction occurs. The secure enclave processor validates the user's identity beforehand and provides local validation information to the secure element, enabling the payment applet to conduct transactions exceeding a financial value without requiring further validation during the transaction itself.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional authentication methods are used for wireless financial transactions, then security is improved, but device complexity increases due to the need for secure end-to-end communication systems

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is divided into distinct functional components: a secure enclave processor that handles biometric authentication and comparison, a secure element that stores authentication information and conducts transactions, and a payment applet that executes payment operations. This segmentation allows each component to perform its specific function securely without requiring the entire system to be complex.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure enclave processor acts as an intermediary between the biometric sensor and the secure element. It receives biometric data, compares it with stored information, and provides validation information to the secure element without exposing sensitive authentication data. This intermediary approach simplifies the overall system architecture while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If repeated authentication operations are required for each transaction, then security is improved, but productivity deteriorates due to degraded user experience and reduced commercial activity

Engineering Contradiction:
ImprovesecurityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Authentication is performed in advance and the validation information is stored in the secure element. When a transaction exceeds a financial value, the pre-authenticated payment applet can conduct the transaction without requiring the user to perform authentication operations again, thereby improving transaction speed and user experience while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12026705B2System and method for payments using biometric authentication
Publication Date: 2024.07.02 APPLE INC
  • US12026705B2 patent drawing
  • US12026705B2 patent drawing
  • US12026705B2 patent drawing

AI summary

In order to validate a user to facilitate conducting a high-valued financial transaction via wireless communication between an electronic device (such as a smartphone) and another electronic device (such as a point-of-sale terminal), the electronic device may authenticate the user prior to the onset of the high-valued financial transaction. In particular, a secure enclave processor in a processor may provide local validation information that is specific to the electronic device to a secure element in the electronic device when received local authentication information that is specific to the electronic device (such as a biometric identifier of the user) matches stored authentication information. Moreover, an authentication applet in the secure element may provide the local validation information to an activated payment applet in the secure element. This may enable the payment applet to conduct the high-valued financial transaction via wireless communication, such as near-field communication.