Smart Card Transaction Verification via Dual Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile transaction processes using two-dimensional codes are inefficient due to the time required to generate and scan codes, leading to lengthy transaction times, which is unsuitable for processing efficiency.

Innovation Solution

A method utilizing a smart card that includes a decryption key and encrypted card data, where a client terminal acquires card identification information and data directly from the smart card, and a server performs verification processes to authenticate the smart card and process transactions, thereby streamlining the transaction process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If two-dimensional code generation and scanning is used for mobile transactions, then transaction security is maintained through code verification, but transaction time becomes excessively long

Engineering Contradiction:
Improvetransaction securityVSAvoidtransaction time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the essential authentication elements (card identification information and encrypted card data) from the smart card and transmits them directly to the server, eliminating the need for time-consuming two-dimensional code generation and scanning while maintaining security through direct encrypted data transmission

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary actions by pre-storing card identification information and encrypted card data in the smart card, allowing for rapid authentication without requiring real-time code generation. The server also performs preliminary verification of decryption keys and card data encoding before transaction processing

Inventive Principle:
Principle #10Preliminary action

2Productivity

If direct card data transmission is implemented, then transaction processing speed increases, but card authentication security may be compromised

Engineering Contradiction:
Improvetransaction processing speedVSAvoidcard authentication security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces the server as an intermediary that performs dual verification: checking whether the smart card possesses the correct decryption key corresponding to the card identification information, and verifying that the encrypted card data encodes stored card data corresponding to the user account, thus maintaining security while enabling fast processing

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the authentication parameters from visual code recognition to cryptographic verification of decryption keys and encrypted data encoding, allowing for faster automated processing while maintaining or enhancing security through cryptographic methods

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If traditional mobile transaction processes are used, then system compatibility is maintained across different devices, but processing efficiency decreases due to code generation requirements

Engineering Contradiction:
Improvesystem compatibilityVSAvoidprocessing efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent makes the smart card a universal authentication device that can be used across different transaction systems. The card contains standardized card identification information and encrypted card data that can be verified by any server implementing the verification protocol, eliminating the need for device-specific code generation while maintaining broad compatibility

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11640605B2Method, server, and storage medium for verifying transactions using a smart card
Publication Date: 2023.05.02 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US11640605B2 patent drawing
  • US11640605B2 patent drawing
  • US11640605B2 patent drawing

AI summary

A method, server and storage medium for verifying a transaction using a smart card are disclosed. A server receives a transaction request to perform a transaction with a user of the smart card. The transaction request includes identification information and encrypted data extracted from the smart card, and transaction information. The server determines a user account linked to the identification information. The server performs a first verification process to authenticate the smart card by verifying that the smart card possesses a correct decryption key corresponding to the identification information. The server performs a second verification process to authenticate the smart card by verifying that the encrypted data extracted from the smart card encodes stored data corresponding to the respective user account linked to the identification information. If the first and the second verification processes are successful, the server processes the transaction in accordance with the transaction information.