Smart Card Transaction Verification via Dual Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile transaction processes using two-dimensional codes are inefficient due to the time required to generate and scan codes, leading to lengthy transaction times, which is unsuitable for processing efficiency.
Innovation Solution
A method utilizing a smart card that includes a decryption key and encrypted card data, where a client terminal acquires card identification information and data directly from the smart card, and a server performs verification processes to authenticate the smart card and process transactions, thereby streamlining the transaction process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If two-dimensional code generation and scanning is used for mobile transactions, then transaction security is maintained through code verification, but transaction time becomes excessively long
Solution Approach 1:
The patent extracts the essential authentication elements (card identification information and encrypted card data) from the smart card and transmits them directly to the server, eliminating the need for time-consuming two-dimensional code generation and scanning while maintaining security through direct encrypted data transmission
Solution Approach 2:
The patent performs preliminary actions by pre-storing card identification information and encrypted card data in the smart card, allowing for rapid authentication without requiring real-time code generation. The server also performs preliminary verification of decryption keys and card data encoding before transaction processing
2Productivity
If direct card data transmission is implemented, then transaction processing speed increases, but card authentication security may be compromised
Solution Approach 1:
The patent introduces the server as an intermediary that performs dual verification: checking whether the smart card possesses the correct decryption key corresponding to the card identification information, and verifying that the encrypted card data encodes stored card data corresponding to the user account, thus maintaining security while enabling fast processing
Solution Approach 2:
The patent changes the authentication parameters from visual code recognition to cryptographic verification of decryption keys and encrypted data encoding, allowing for faster automated processing while maintaining or enhancing security through cryptographic methods
3Adaptability or versatility
If traditional mobile transaction processes are used, then system compatibility is maintained across different devices, but processing efficiency decreases due to code generation requirements
Solution Approach 1:
The patent makes the smart card a universal authentication device that can be used across different transaction systems. The card contains standardized card identification information and encrypted card data that can be verified by any server implementing the verification protocol, eliminating the need for device-specific code generation while maintaining broad compatibility
Data Source
AI summary
A method, server and storage medium for verifying a transaction using a smart card are disclosed. A server receives a transaction request to perform a transaction with a user of the smart card. The transaction request includes identification information and encrypted data extracted from the smart card, and transaction information. The server determines a user account linked to the identification information. The server performs a first verification process to authenticate the smart card by verifying that the smart card possesses a correct decryption key corresponding to the identification information. The server performs a second verification process to authenticate the smart card by verifying that the encrypted data extracted from the smart card encodes stored data corresponding to the respective user account linked to the identification information. If the first and the second verification processes are successful, the server processes the transaction in accordance with the transaction information.


