Universal Authentication App Biometric Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional secure remote platform systems rely on browser cookies for authentication, which can be stolen or deleted, and WebAuthn with biometric authentication requires separate verifications for each account credential, leading to burdensome processes for users and devices.

Innovation Solution

Implementing a universal authentication application that receives user credential verification requests, transmits them to a web browser to invoke an authenticator for biometric verification, and provides a trusted attestation to a resource provider computer, allowing multiple SRT systems to retrieve account information without separate biometric requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate biometric verification is required for each account credential, then security is improved, but user burden and device complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoiduser burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent combines multiple separate biometric verification requests into a single unified biometric authentication process. The system performs one biometric verification that generates a credential usable across multiple SRT systems, eliminating the need for users to repeatedly provide biometric data for each individual credential retrieval operation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal biometric credential that can be used across multiple different SRT systems. A single biometric authentication result serves multiple functions by enabling the user to access account information from various SRT systems without requiring separate authentication for each system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate biometric verification is required for each account credential, then security is improved, but communication overhead and processing time increase

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges multiple communication requests for biometric verification into a single request-response cycle. Instead of establishing separate communication channels with each SRT system for individual biometric verifications, the system performs one authentication that satisfies multiple credential retrieval operations, significantly reducing network traffic and processing time.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If browser cookies are used for authentication, then ease of operation is improved, but security is worsened due to theft and deletion risks

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the browser cookie-based authentication mechanism with a biometric authentication system. Instead of relying on stored cookies that can be stolen or deleted, the system uses cryptographic credentials backed by biometric verification, providing both security and ease of operation without the vulnerabilities of cookie-based systems.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP4058913B1Use of web authentication to enhance security of secure remote platform systems
Publication Date: 2025.02.12 VISA INTERNATIONAL SERVICE ASSOCIATION
  • EP4058913B1 patent drawingFigure 1
  • EP4058913B1 patent drawingFigure 2
  • EP4058913B1 patent drawingFigure 3

AI summary

A method includes receiving, by a universal authentication application from a resource provider computer, a user credential verification request message comprising a user identifier, server computer data, and interaction data for an interaction. The universal authentication application transmits the user credential verification request message to a browser that invokes the authenticator to verify biometric information of a user. The universal authentication application receives a user credential verification response message from the authenticator. The user credential verification response message includes signed interaction data. The universal authentication application sends the user credential verification response message to the resource provider computer. The resource provider computer provides at least the signed interaction data to a plurality of server computers to retrieve a plurality of portable device credentials respectively associated with the plurality of server computers.