Software Two-Factor Authentication for Digital Wallets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing payment systems face challenges in providing secure and convenient two-factor authentication for digital wallet access and transactions without relying on hardware-based secure elements or trusted execution environments, and require cost-effective solutions that balance security with user experience and regulatory compliance.

Innovation Solution

A two-factor authentication mechanism using a secret PIN and a device-specific cryptographic key, implemented using software-only security techniques, including white box cryptography, to secure payment transactions without the need for hardware-based secure elements or trusted execution environments, and provisioning of single-use keys for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-based secure elements or trusted execution environments are used for two-factor authentication, then security and reliability are improved, but device complexity and manufacturing costs increase

Engineering Contradiction:
Improveauthentication securityVSAvoidhardware infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces hardware-based secure elements and trusted execution environments with a software-based authentication mechanism. The two-factor authentication is implemented through cryptographic operations executed by the processor, using a secret stored in memory and a one-time password generated without hardware security modules. This substitution eliminates the need for complex hardware infrastructure while maintaining authentication security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If hardware-based secure elements are deployed, then authentication security is improved, but manufacturing cost and device cost increase

Engineering Contradiction:
Improveauthentication securityVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent employs a disposable one-time password mechanism where each authentication credential is used once and then discarded. The system generates a new one-time password for each authentication attempt, eliminating the need for expensive, long-lived hardware secure elements. This approach reduces manufacturing costs while maintaining security through the ephemeral nature of the credentials.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If complex hardware infrastructure is used for authentication, then security is improved, but ease of operation and user convenience deteriorate

Engineering Contradiction:
Improveauthentication securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication system operates autonomously without requiring user interaction with complex hardware devices. The one-time password is generated and verified automatically by the processor through cryptographic operations, eliminating the need for users to manually input codes or interact with hardware security tokens. This self-service mechanism maintains security while improving ease of operation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20210365938A1Authentication system and method for server-based payments
Publication Date: 2021.11.25 MASTERCARD INT INC
  • US20210365938A1 patent drawing
  • US20210365938A1 patent drawing
  • US20210365938A1 patent drawing

AI summary

A method of performing a payment transaction employing a two-factor authentication mechanism. In an embodiment, a user device operated by a user during a payment transaction engages in cryptographic processing with a cryptographic function having a secret key encoded therein. The cryptographic function is stored in a storage device of the user device, and the secret key serves as a first authentication factor. The method also includes the user device utilizing a second authentication factor, which was implemented using only software security techniques, in performing the payment transaction.