Web Bluetooth Token Transfer via Biometric Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The secure transfer of payment tokens between computing devices poses security risks due to incompatibility of security mechanisms across different devices and operating systems, making it challenging to manage authorization and authentication effectively.

Innovation Solution

The implementation of a system that uses web Bluetooth APIs to establish a secure connection between devices, allowing users to transfer payment tokens while ensuring authentication and authorization through biometric interfaces and cryptographic encryption, ensuring that only authorized users can access and use the payment tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If payment tokens are transferred to multiple devices, then user accessibility and convenience are improved, but security risks and vulnerability to unauthorized access increase

Engineering Contradiction:
Improveuser accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the token transfer process into distinct phases: authentication phase (verifying user identity via biometrics), authorization phase (checking device compatibility and user permissions), and transfer phase (actual token movement). This segmentation allows each phase to be secured independently, maintaining security while enabling multi-device access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary authentication mechanism that acts as a mediator between the user, the source device, and the target device. This intermediary verifies biometric credentials and device compatibility before allowing token transfer, ensuring that security is maintained even as tokens are distributed across multiple devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If security mechanisms are made compatible across all devices, then transferability and versatility are improved, but system complexity and implementation difficulty increase

Engineering Contradiction:
ImprovetransferabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system implements a universal authentication framework that works across different device types and operating systems. By using standardized biometric authentication methods and common cryptographic protocols, the system achieves broad compatibility without requiring device-specific security implementations, thus maintaining versatility while controlling complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system adapts security parameters dynamically based on the target device's capabilities. Instead of implementing all possible security mechanisms on every device, the system adjusts authentication and encryption parameters to match the device's security features, achieving compatibility across diverse devices without unnecessary complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11301862B2Secure transfer of tokens between devices
Publication Date: 2022.04.12 CAPITAL ONE SERVICES LLC
  • US11301862B2 patent drawing
  • US11301862B2 patent drawing
  • US11301862B2 patent drawing

AI summary

Various embodiments are generally directed to the secure transfer of account tokens between devices. For example, a first device may receive an account token stored on a second device using web Bluetooth application programming interfaces (APIs). As another example, the second device may push the account token to the first device.