Smart Card Authentication System Using Biometric Delegation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication systems face challenges in determining whether transactions made by non-account holders using an authorized user's credit card are fraudulent or authorized, leading to risks of fraudulent transactions or inconvenience to the account holder when trying to delegate account usage.
Innovation Solution
The system provides a secondary card linked to the account holder's biometric information and limitations, allowing for secure delegation of account usage by storing a mapping between the secondary card, biometric data, and usage limitations, enabling authentication of transactions based on matching biometric information and compliance with set limitations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the authentication system requires the account holder to be present for all transactions, then fraudulent transactions are prevented, but the account holder loses flexibility to authorize other users
Solution Approach 1:
The patent segments the authentication process by separating the account holder's biometric data (stored in the database) from the transaction verification process. The system divides authentication into two parts: storing reference biometric information during account setup and comparing it during transactions, allowing delegation while maintaining security.
Solution Approach 2:
The patent introduces biometric information as an intermediary element that mediates between the account holder and the authentication system. The biometric data serves as a verifiable intermediary that proves the user's identity without requiring the account holder's physical presence, enabling authorized delegation.
2Ease of operation
If the authentication system allows non-account holders to use the credit card, then convenience is improved, but the risk of fraudulent transactions increases
Solution Approach 1:
The patent applies preliminary action by collecting and storing the authorized user's biometric information before any transactions occur. This pre-captured biometric data is stored in the database and used for subsequent verification, allowing the system to authenticate users who are not account holders while maintaining fraud prevention.
Solution Approach 2:
The patent replaces the traditional mechanical authentication system (physical presence of account holder, signature verification) with a biometric-based system. This substitution allows remote and delegated authentication while maintaining security, as biometric verification provides a reliable alternative to physical presence requirements.
3Measurement precision
If the system stores biometric information for authentication, then transaction verification accuracy is improved, but system complexity increases
Solution Approach 1:
The patent applies universality by using biometric information as a multi-functional element that serves both as identification and authentication. The same biometric data stored in the database can verify the identity of any authorized user making transactions, eliminating the need for separate identification and authentication mechanisms.
Solution Approach 2:
The patent uses copying by creating a digital copy of the account holder's biometric information and storing it in the database. This biometric copy serves as a reference for verification during transactions, allowing the system to authenticate users without requiring the original account holder's physical presence while maintaining high verification accuracy.
Data Source
AI summary
Aspects described herein may allow for authentication of smart card usage. A server may receive, from a first computing device associated with a first user, a delegation request to delegate an authority, to a second user, to use a secondary card associated with an account belonging to the first user. The first user may hold a primary card associated with the account and the delegation request comprises one or more limitations on the authority. The server may also receive, via a sensor on the secondary card, first biometric information associated with the second user. The server may authenticate subsequent transaction requests based on the first biometric information and one or more limitations. In this way, the system may provide account holders with the flexibility to authorize other users to use the account while minimizing the risk of being exposed to fraudulent requests.


