In-Vehicle FIDO Fingerprint Authentication for Payment Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing vehicle control systems are inconvenient for user authentication, particularly when using password-based methods for in-vehicle payment services, which can be cumbersome and inefficient.
Innovation Solution
An apparatus and method utilizing Fast Identity Online (FIDO) authentication, integrating fingerprint recognition, encryption, and communication with financial and FIDO authentication servers to facilitate secure and convenient user payment processing, including driver verification and account management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If password-based authentication is used for in-vehicle payment, then user verification can be performed, but user convenience deteriorates due to cumbersome authentication process
Solution Approach 1:
The patent replaces the mechanical/password-based authentication system with a biometric authentication system using fingerprint recognition. The fingerprint recognition module captures the user's fingerprint, and the processor compares it with stored fingerprint data to authenticate the user, eliminating the need for manual password input and significantly improving authentication convenience while maintaining security.
2Ease of operation
If FIDO authentication with fingerprint recognition is implemented, then authentication convenience is improved, but device complexity increases due to additional modules and protocols
Solution Approach 1:
The patent integrates the fingerprint recognition module into the existing vehicle payment system, making it serve multiple functions: user authentication, payment verification, and account management. The processor handles both the fingerprint data processing and the payment transaction coordination, reducing the need for separate dedicated components and minimizing overall system complexity.
Solution Approach 2:
The patent introduces a FIDO authentication server as an intermediary that manages the complex cryptographic operations and protocol handling. The server receives authentication requests from the vehicle system, processes the fingerprint verification through standardized FIDO protocols, and returns authentication results, thereby offloading complexity from the vehicle's onboard system.
3Reliability
If encryption is applied to pin code before transmission, then security is improved, but processing time increases due to encryption operations
Solution Approach 1:
The patent performs encryption of the PIN code immediately after user input and before any transmission or further processing occurs. The processor encrypts the PIN using stored cryptographic keys, and only the encrypted form is transmitted to the authentication server or stored in the system, ensuring security from the earliest possible point while minimizing the window for potential security breaches.
Solution Approach 2:
The patent replaces traditional unencrypted or简单地 stored PIN codes with cryptographic encryption based on FIDO standards. The system uses public-key cryptography where the PIN is encrypted with a private key and can only be decrypted by the corresponding public key held by the authentication server, providing robust security without requiring complex additional verification steps that would increase processing time.
Data Source
AI summary
An apparatus for controlling a vehicle includes a memory, a network interface, and a processor, where the processor may check whether a fingerprint recognition module in the vehicle supports fast identity online (FIDO), may request for an encryption key to register the FIDO, may encrypt an input pin code to transmit the encrypted pin code to a financial information processing server, may transmit vehicle and account information for the FIDO registration to a FIDO authentication server when receiving an authentication token from the financial information processing server, may generate information on the FIDO registration when receiving policy information from the FIDO authentication server, and may transmit the information on the FIDO registration to the FIDO authentication server.


