Trusted Mobile Payment via QR Code and Biometric Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Fraudulent transactions on mobile devices pose a significant challenge, limiting the adoption of automatic payment systems due to concerns about protecting customers' proprietary payment information and ensuring merchant payments, especially with growing identity fraud cases.

Innovation Solution

A third-party transaction service is established that uses a unique data object, such as a QR code, displayed on a mobile device, which is verified by both the customer and merchant, ensuring secure transactions without storing or transmitting sensitive information directly, and utilizing biometric data for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a third-party transaction service is introduced to verify transactions and protect payment information, then security and fraud prevention are improved, but system complexity increases

Engineering Contradiction:
Improvetransaction securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a third-party transaction service as an intermediary between the customer and merchant. This service receives transaction requests from the customer's mobile device, verifies the data object (QR code), and coordinates with the merchant to complete the transaction. The intermediary handles sensitive payment information verification without requiring direct sharing between customer and merchant, thereby improving security while maintaining a manageable system architecture through clear role separation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If biometric authentication is implemented to verify customer identity, then fraud detection is improved, but ease of operation decreases

Engineering Contradiction:
Improveidentity verificationVSAvoidoperation convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements biometric authentication by capturing the customer's image at the point of sale and comparing it with a pre-stored reference image. The reference image is obtained in advance during account setup, and the verification process simply requires capturing a new image and comparing it against the stored template. This preliminary action approach enables rapid identity verification without requiring complex real-time biometric analysis, thus improving security while maintaining operational ease.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If payment information is not stored or transmitted directly between customer and merchant, then security is improved, but loss of information occurs

Engineering Contradiction:
Improvedata protectionVSAvoidpayment verification
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent extracts sensitive payment information from the direct customer-merchant communication channel and routes it through the third-party transaction service. The customer's mobile device generates a data object (QR code) that contains encoded payment information, which is then verified by the transaction service rather than being directly transmitted to the merchant. This extraction of sensitive data from the direct transmission path protects customer information while the transaction service maintains verification capability through secure encoding and decoding processes.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10089606B2System and method for trusted mobile device payment
Publication Date: 2018.10.02 SIEMENS MOBILITY INC
  • US10089606B2 patent drawing
  • US10089606B2 patent drawing
  • US10089606B2 patent drawing

AI summary

This invention is related to secure payments using data codes displayed on a mobile device, for example a QR code displayed on a cell-phone. The invention establishes a third party transaction service that protects the customer's proprietary payment information, for example, credit card numbers, while ensuring for a merchant that a payment token, for example, the QR code, will represent a valid payment.