Software Two-Factor Authentication for Digital Wallets
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing payment systems face challenges in providing secure and convenient two-factor authentication for digital wallet access and transactions without relying on hardware-based secure elements or trusted execution environments, and require cost-effective solutions that balance security with user experience and regulatory compliance.
Innovation Solution
A two-factor authentication mechanism using a secret PIN and a device-specific cryptographic key, implemented using software-only security techniques, including white box cryptography, to secure payment transactions without the need for hardware-based secure elements or trusted execution environments, and provisioning of single-use keys for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware-based secure elements or trusted execution environments are used for two-factor authentication, then security and reliability are improved, but device complexity and manufacturing costs increase
Solution Approach 1:
The patent replaces hardware-based secure elements and trusted execution environments with a software-based authentication mechanism. The two-factor authentication is implemented through cryptographic operations executed by the processor, using a secret stored in memory and a one-time password generated without hardware security modules. This substitution eliminates the need for complex hardware infrastructure while maintaining authentication security.
2Reliability
If hardware-based secure elements are deployed, then authentication security is improved, but manufacturing cost and device cost increase
Solution Approach 1:
The patent employs a disposable one-time password mechanism where each authentication credential is used once and then discarded. The system generates a new one-time password for each authentication attempt, eliminating the need for expensive, long-lived hardware secure elements. This approach reduces manufacturing costs while maintaining security through the ephemeral nature of the credentials.
3Reliability
If complex hardware infrastructure is used for authentication, then security is improved, but ease of operation and user convenience deteriorate
Solution Approach 1:
The authentication system operates autonomously without requiring user interaction with complex hardware devices. The one-time password is generated and verified automatically by the processor through cryptographic operations, eliminating the need for users to manually input codes or interact with hardware security tokens. This self-service mechanism maintains security while improving ease of operation.
Data Source
AI summary
A method of performing a payment transaction employing a two-factor authentication mechanism. In an embodiment, a user device operated by a user during a payment transaction engages in cryptographic processing with a cryptographic function having a secret key encoded therein. The cryptographic function is stored in a storage device of the user device, and the secret key serves as a first authentication factor. The method also includes the user device utilizing a second authentication factor, which was implemented using only software security techniques, in performing the payment transaction.


