Virtual Electronic Card Issuance via Biometric Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems for financial transactions using physical payment cards are vulnerable to identity theft and fraud, with existing security measures being slow to detect and address such issues, often taking days or weeks to issue new cards.
Innovation Solution
A method and system for authenticating and issuing electronic cards using encryption information passed via plug-ins, where an authentication application on a user's device receives a unique identifier for a plugin, securely communicates with a secure gateway, and authenticates the user using biometric information and a unique device identifier, allowing for the issuance of electronic cards through a mobile payment application.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical payment cards are used for financial transactions, then transaction capability is provided, but security vulnerability to identity theft and fraud increases
Solution Approach 1:
The patent replaces physical payment cards with virtual card copies stored in mobile devices. The virtual card contains encrypted account information that replicates the functionality of physical cards while eliminating the security vulnerabilities of physical media. This copying approach allows users to have multiple virtual card instances and enables rapid issuance and revocation without physical constraints.
Solution Approach 2:
The patent substitutes mechanical physical card systems with electronic/digital systems. Instead of relying on physical plastic cards with magnetic strips or EMV chips, the system uses encrypted digital representations of card accounts stored in mobile device memory, accessed through software applications and authenticated via biometric or PIN-based verification.
2Reliability
If new physical payment cards are issued after fraud detection, then security is restored, but time loss of days or weeks occurs
Solution Approach 1:
The system performs preliminary actions by pre-generating and storing virtual card data in encrypted form within mobile devices before fraud occurs. When fraud is detected, the system can immediately revoke access to compromised virtual card instances and activate alternative virtual card instances without requiring physical card production, shipping, or activation processes.
Solution Approach 2:
The patent implements dynamic virtual card systems where card data can be rapidly issued, revoked, or modified through software updates. Virtual cards can be generated instantly through electronic communication between the card issuer's system and the user's mobile device, allowing real-time response to fraud detection without the static constraints of physical card production cycles.
3Productivity
If encrypted card information is stored in device memory, then quick access for transactions is enabled, but security risk from memory exposure increases
Solution Approach 1:
The patent applies different security qualities to different parts of the system. Encrypted card information is stored in device memory with restricted access controls, while the actual decryption and authentication processes occur only during verified user sessions. The encryption keys and sensitive data are protected through device-level security mechanisms, creating localized security zones that balance accessibility with protection.
Solution Approach 2:
The system implements beforehand cushioning through multiple layers of encryption and authentication protocols. Card information is stored in encrypted form with additional security layers that prevent unauthorized access even if memory is compromised. The system prepares security measures in advance, including biometric authentication, PIN verification, and encrypted storage protocols, to cushion against potential memory exposure risks before they can be exploited.
Data Source
AI summary
An authentication application may securely communicate with a secure gateway using encryption based on an identifier of the plugin. The authentication application may authorize the plugin based on the identifier. The plug-in may receive biometric information and a unique device identifier. The authentication application may authenticate the user for use of the authorized plugin based the biometric information and the unique device identifier. The plug-in may receive a request to issue a new electronic card via the secure gateway. The plug-in may receive, responsive to sending the request via a secure communication channel with the secure gateway, the electronic card information issued to the device via the secure gateway. The plug-in may automatically add, responsive to receiving the electronic card information, the electronic card information into a mobile payment application of the device using the electronic card information.


