System, device and method for secure authentication and verification without requiring biometric device during authentication

A biometric identity system with double-encrypted QR codes and cloud-based storage addresses vulnerabilities in biometric authentication by ensuring secure, hardware-free identity verification with multiple validation layers.

WO2026154483A1PCT designated stage Publication Date: 2026-07-23CHUGH HARVI SINGH +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
CHUGH HARVI SINGH
Filing Date
2025-03-05
Publication Date
2026-07-23

AI Technical Summary

Technical Problem

Biometric authentication systems are vulnerable to data breaches and unauthorized access due to the storage and management of biometric data, necessitating a more robust and secure system for identity authentication.

Method used

A biometric identity system using double-encrypted QR codes and cloud-based storage, eliminating the need for hardware, ensures secure authentication through user-centric identity management and two-factor verification.

Benefits of technology

The system provides enhanced security by reducing exposure of raw biometric data, requiring multiple levels of validation, and ensuring user privacy, making it scalable for various industries.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IN2025050310_23072026_PF_FP_ABST
    Figure IN2025050310_23072026_PF_FP_ABST
Patent Text Reader

Abstract

A system, a method and a device for user authentication is provide that includes the steps of receiving (302), at an authentication server, a code transmitted from a first electronic device. This code contains doubly encrypted biometric data of the user, wherein the biometric data is encrypted once and further encrypted to be embedded within the code. Upon receiving the code, a notification is sent (304) to a second electronic device associated with the user. The notification includes a trigger to confirm or deny the user's authentication. After receiving a response to the notification, the authentication server retrieves and doubly decrypts the biometric data from the code. The decrypted biometric data is compared with pre-stored biometric data to verify (306) the user's identity. Upon successful matching, the user is authenticated (308).
Need to check novelty before this filing date? Find Prior Art

Description

TITLE OF INVENTION:SYSTEM, DEVICE AND METHOD FOR SECURE AUTHENTICATION AND VERIFICATION WITHOUT REQUIRING BIOMETRIC DEVICE WHILE AUTHENTICATIONFIELD OF THE INVENTION

[0001] The present invention relates generally to identity authentication systems and, in particular, to biometric identity system, device and method for secure authentication and verification of an identity of users and of identifying those users to third parties. Overall, the system eliminates the need for hardware (biometric device) on both the user's and provider's sides during authentication.BACKGROUND OF THE INVENTION

[0002] Identity theft remains a pervasive and growing concern, extending beyond financial fraud to include various other domains such as medical, insurance, perimeter, and network identity theft. For instance, medical and insurance identity theft involve unauthorized access to sensitive medical and insurance information, which can result in fraudulent use or exploitation. Perimeter identity theft involves the unauthorized use of someone’s personal identity to gain access to restricted areas, such as airports, nuclear power plants, or municipal water facilities, posing serious security risks. Similarly, network identity theft entails unauthorized access to user credentials to infiltrate secure systems like military or corporate computer networks.

[0003] To address these challenges, biometric -based identity authentication systems have been developed, offering improved security through the use of unique biological identifiers. However, even the most advanced biometric systems are not immune to compromise. A primary vulnerability lies in the storage and management of biometric data. When stored in centralized databases, biometric identifier files become high-value targets for hackers, risking massive data breaches. Alternatively, storing biometric data on tokens disperses the files, but these systems are still vulnerable. Token-based systems rely on token readers to access biometric data for authentication, making the readers a critical point of attack. Once a reader is compromised, it can provide access to individual tokens, enabling attackers to replace the legitimate biometric data with fraudulent identifiers and effectively steal the user's identity.

[0004] These security flaws expose users and organizations to significant risks, underscoring the urgent need for a more robust and secure system for managing user identities and facilitating authentication with third parties. A solution that minimizes vulnerabilities in biometric data storage and transmission, while ensuring secure authentication, is critical to addressing these pressing challenges.SUMMARY

[0005] The following embodiments present a simplified summary in order to provide a basic understanding of some aspects of the disclosed invention. This summary is not an extensive overview, and it is not intended to identify key / critical elements or to delineate the scope thereof. Its sole purpose is to present some concepts in a simplified form as a prelude to the more detailed description that is presented later.

[0006] The present invention revolves around a biometric identity system that delivers Identity as a Service for secure authentication and verification. It uses a combination of biometric data (such as fingerprints, iris scans, or facial recognition), robust encryption methods, and QR code technology to provide a portable and highly secure identity solution. The system eliminates the need for hardware (biometric) on both the user's and provider's sides during authentication.

[0007] The process involves capturing a user's biometric data, encrypting it using advanced AES-256-CBC encryption, and converting it into a double-encrypted QR code. This QR code is securely stored on a cloud-based platform and can be shared with providers for verification. When a provider requests authentication, the platform notifies the user, who grants permission for the verification process. The platform then decrypts and matches the biometric data in real time, sending the result to the provider for authentication.

[0008] Key features include:

[0009] User-Centric Identity Management: Users control their biometric identity through encrypted QR codes.

[0010] Secure Sharing and Verification: Two-factor verification using QR codes and unique codes ensures data confidentiality.[Oil] Hardware-Free Authentication: The system works remotely without requiring specialized hardware at either end.

[0012] Versatility: Applications range from personal identity verification to cybersecurity, with potential use as a unique biometric password.

[0013] This system is designed to enhance security, protect user privacy, and simplify identity management across various industries, making it a scalable and future -ready solution for biometric authentication.

[0014] The inventions focus on securing user identity through encryption, biometrics, and QR codes, offering robust solutions for identity management and verification. The inventions stand out for their emphasis on encryption, biometric uniqueness, and secure data handling, while eliminating the need for physical hardware during authentication. These systems prioritizeuser privacy and security, ensuring that sensitive information remains protected. The system eliminates the need for hardware on both the user's and provider's sides during authentication.

[0015] In an aspect, a method for user authentication is provide that includes the steps of receiving, at an authentication server, a code transmitted from a first electronic device. This code contains doubly encrypted biometric data of the user, wherein the biometric data is encrypted once and further encrypted to be embedded within the code. Upon receiving the code, a notification is sent to a second electronic device associated with the user. The notification includes a trigger to confirm or deny the user’s authentication. After receiving a response to the notification, the authentication server retrieves and doubly decrypts the biometric data from the code. The decrypted biometric data is compared with pre-stored biometric data to verify the user's identity. Upon successful matching, the user is authenticated. The system eliminates the need for hardware on both the user's and provider's sides during authentication.

[0016] As compared to the conventional solutions, the present invention provides a secure method for user authentication, leveraging a two-layer encryption mechanism to safeguard biometric data. By embedding doubly encrypted biometric data into a code (e.g., QR code), the method prevents unauthorized access during data transmission. The process involves verification through dual-device interaction, ensuring the user’s participation for enhanced security. This method addresses vulnerabilities in conventional systems by reducing exposure of raw biometric data and requiring multiple levels of validation for user authentication. The method eliminates the need for hardware on both the user's and provider's sides during authentication.

[0017] In this aspect, a method for authenticating a user is disclosed. The method includes the steps of receiving, by a processor of an authentication server, a code from a first electronic device, wherein the code comprising an encrypted biometric data of the user, and the encrypted biometric data is further encrypted to be embedded in the code as a doubly encrypted biometric data; transmitting, by the processor, a notification to a second electronic device in response to receiving the code, wherein the second electronic device is associated with the user to be authenticated, and the notification comprises a trigger to allow authentication of the user to be authenticated; verifying, by the processor and upon receiving response to the trigger to allow authentication, an identify of the user to be authenticated based on the received code, wherein the identity of the user is verified by: retrieving the doubly encrypted biometric data from the received code; doubly decrypting the doubly encrypted biometric data to obtain the biometric data of the user; and matching the obtained biometric data with pre-stored biometric data associated with the user; and thereby authenticating, by the processor and upon successful matching, the user.

[0018] In another aspect, an authentication server is disclosed that includes a processor and memory storing instructions. The processor executes instructions to receive a code containing doubly encrypted biometric data from a first electronic device. It sends a notification to a second electronic device associated with the user, prompting a response to confirm or deny authentication. Upon receiving the response, the processor retrieves and decrypts the biometric data from the code in two stages to obtain the original biometric data. The decrypted data is then compared with pre-stored biometric data to verify the user’s identity. If the comparison is successful, the processor authenticates the user.

[0019] As compared to the conventional solutions, the present invention provides an authentication server that offers a secure infrastructure for biometric authentication. It incorporates encryption and decryption mechanisms to ensure data integrity during transmission and verification. The server facilitates interaction between two devices, adding a layer of security through dual confirmation. This server mitigates the risks of data theft by encrypting biometric information twice and embedding it into codes, which can only be decrypted at the server end. The system eliminates the need for hardware on both the user's and provider's sides during authentication.

[0020] In this aspect, the authentication server for authenticating a user is provided. The authentication server includes a processor and a memory for storing a set of executable instructions which when executed by the processor causes the authentication server to receive a code from a first electronic device, wherein the code comprising an encrypted biometric data of the user, and the encrypted biometric data is further encrypted to be embedded in the code as a doubly encrypted biometric data; transmit a notification to a second electronic device in response to receiving the code, wherein the second electronic device is associated with the user to be authenticated, and the notification comprises a trigger to allow authentication of the user to be authenticated; verify, upon receiving response to the trigger to allow authentication, an identify of the user to be authenticated based on the received code, wherein the processor further causes the authentication server to: retrieve the doubly encrypted biometric data from the received code; doubly decrypt the doubly encrypted biometric data to obtain the biometric data of the user; and match the obtained biometric data with pre-stored biometric data associated with the user to verify the identity of the user; and thereby authenticate the user. The server eliminates the need for hardware on both the user's and provider's sides during authentication.

[0021] In yet another embodiment, a system for user authentication is disclosed that includes a first electronic device configured to generate a code containing doubly encrypted biometric data and transmit it to an authentication server. The authentication server receives thecode and sends a notification to a second electronic device associated with the user. The notification prompts the user to confirm or deny authentication. Upon receiving the response, the authentication server retrieves the doubly encrypted biometric data from the code, decrypts it in two stages to extract the original biometric data, and compares it with pre-stored biometric data to verify the user’s identity. If the verification succeeds, the user is authenticated.

[0022] As compared to the conventional solutions, the described system integrates multiple components — devices and a server — to ensure robust biometric authentication. The first electronic device handles data encryption and code generation, while the server executes verification tasks. The second device ensures user consent, reinforcing security through a dualdevice framework. The system effectively addresses issues like identity theft by securely managing biometric data and requiring multi-layer validation during authentication.

[0023] In this aspect, a system for authenticating a user is disclosed. The system includes a first electronic device, an authentication server, and a second electronic device. The first electronic device configured to generate a code comprising an encrypted biometric data of the user, and the encrypted biometric data is further encrypted to be embedded in the code as a doubly encrypted biometric data; and transmit the generated code to an authentication server. The authentication server configured to receive the generated code from the first electronic device; transmit a notification to a second electronic device in response to receiving the code, wherein the second electronic device is associated with the user to be authenticated, and the notification comprises a trigger to allow authentication of the user to be authenticated; verify, upon receiving response to the trigger to allow authentication, an identify of the user to be authenticated based on the received code. The processor further causes the authentication server to retrieve the doubly encrypted biometric data from the received code; doubly decrypt the doubly encrypted biometric data to obtain the biometric data of the user; and match the obtained biometric data with pre-stored biometric data associated with the user to verify the identity of the user; and thereby authenticate the user.

[0024] The system eliminates the need for hardware on both the user's and provider's sides during authentication.

[0025] In the above aspects, the method further includes the step of transmitting, by the processor, a confirmation about the authentication to the first electronic device.

[0026] In this aspect, the code is a barcode or quick-response (QR) code.

[0027] In the above aspects, the biometric data and the pre-stored biometric data comprises fingerprints, facial scans, voice recognition, iris scans, palm prints, and hand geometry associated with the user.

[0028] In the above aspects, the biometric data of the user is encrypted, further encrypted and decrypted by an algorithm selected from any or a combination of Elliptic Curve Cryptography (ECC), Rivest-Shamir-Adleman (RSA), Symmetric encryption, Diffie-Hellman key exchange, Advanced Encryption Standard (AES), Triple Data Encryption Algorithm (TDEA or Triple DEA).

[0029] In the above aspects, the method further comprising: encoding, by using an encoding technique, the encrypted biometric data is further encrypted to be embedded in the code as a doubly encrypted biometric data, wherein the encoding technique is selected from any or a combination of Base64, Base-122, Base62x, and Base85.

[0030] In the above aspects, the notification is selected from any or a combination of a message, an email, a link, a missed call; and the trigger corresponds to an approval or a disapproval to the authentication.

[0031] The foregoing summary is illustrative only and is not intended to be in any way limiting. In addition to the illustrative aspects, embodiments, and features described above, further aspects, embodiments, and features will become apparent by reference to the drawings and the following detailed description.BRIEF DESCRIPTION OF DRAWINGS

[0032] The above and still further example embodiments of the present disclosure will become apparent upon consideration of the following detailed description of embodiments thereof, especially when taken in conjunction with the accompanying drawings, and wherein:

[0033] FIG. 1 illustrates a block diagram a system for authenticating a user, in accordance with an example embodiment;

[0034] FIG. 2 illustrate an exemplary block diagram illustrating various steps within an authentication server for authenticating a user, in accordance with an example embodiment;

[0035] FIG. 3 illustrates a flow diagram of a method for authenticating a user, in accordance with an example embodiment;

[0036] FIG. 4 illustrates a block diagram of an exemplary computer system for implementing embodiments consistent with the present disclosure;

[0037] FIG. 5 illustrates a sequence diagram of a method for authenticating a user from the overall systems perspective, in accordance with an example embodiment.

[0038] The figures illustrate embodiments of the invention for purposes of illustration only. One skilled in the art will readily recognize from the following description that alternative embodiments of the structures and methods illustrated herein may be employed without departing from the principles of the invention described herein.DETAILED DESCRIPTION

[0039] In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding of the present disclosure. It will be apparent, however, to one skilled in the art that the present disclosure can be practiced without these specific details. In other instances, systems, apparatuses, and methods are shown in block diagram form only in order to avoid obscuring the present disclosure.

[0040] Reference in this specification to “one embodiment” or “an embodiment” or “example embodiment” means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present disclosure. The appearance of the phrase “in one embodiment” in various places in the specification are not necessarily all referring to the same embodiment, nor are separate or alternative embodiments mutually exclusive of other embodiments. Further, the terms “a” and “an” herein do not denote a limitation of quantity, but rather denote the presence of at least one of the referenced items. Moreover, various features are described which may be exhibited by some embodiments and not by others. Similarly, various requirements are described which may be requirements for some embodiments but not for other embodiments.

[0041] Some embodiments of the present disclosure will now be described more fully hereinafter with reference to the accompanying drawings, in which some, but not all, embodiments of the invention are shown. Indeed, various embodiments of the invention may be embodied in many different forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this disclosure will satisfy applicable legal requirements. Like reference numerals refer to like elements throughout.

[0042] The terms “comprise”, “comprising”, “includes”, or any other variations thereof, are intended to cover a non-exclusive inclusion, such that a setup, device, or method that comprises a list of components or steps does not include only those components or steps but may include other components or steps not expressly listed or inherent to such setup, device, or method. In other words, one or more elements in a system or apparatus proceeded by “comprises... a” does not, without more constraints, preclude the existence of other elements or additional elements in the system or method.

[0043] The embodiments are described herein for illustrative purposes and are subject to many variations. It is understood that various omissions and substitutions of equivalents are contemplated as circumstances may suggest or render expedient but are intended to cover the application or implementation without departing from the spirit or the scope of the present disclosure. Further, it is to be understood that the phraseology and terminology employed hereinare for the purpose of the description and should not be regarded as limiting. Any heading utilized within this description is for convenience only and has no legal or limiting effect.

[0044] The present invention revolves around a biometric identity system that delivers identity as a service for secure authentication and verification. It uses a combination of biometric data (such as fingerprints, iris scans, or facial recognition), robust encryption methods, and QR code technology to provide a portable and highly secure identity solution. The system eliminates the need for hardware on both the user's and provider's sides during authentication.

[0045] The process involves capturing a user's biometric data, encrypting it using advanced AES-256-CBC encryption, and converting it into a double-encrypted QR code. This QR code is securely stored on a cloud-based platform and can be shared with providers for verification. When a provider requests authentication, the platform notifies the user, who grants permission for the verification process. The platform then decrypts and matches the biometric data in real time, sending the result to the provider for authentication.

[0046] In an embodiment, a method for user authentication is provide that includes the steps of receiving, at an authentication server, a code transmitted from a first electronic device. This code contains doubly encrypted biometric data of the user, wherein the biometric data is encrypted once and further encrypted to be embedded within the code. Upon receiving the code, a notification is sent to a second electronic device associated with the user. The notification includes a trigger to confirm or deny the user’s authentication. After receiving a response to the notification, the authentication server retrieves and doubly decrypts the biometric data from the code. The decrypted biometric data is compared with pre-stored biometric data to verify the user's identity. Upon successful matching, the user is authenticated. The system eliminates the need for hardware on both the user's and provider's sides during authentication.

[0047] As compared to the conventional solutions, the present invention provides a secure method for user authentication, leveraging a two-layer encryption mechanism to safeguard biometric data. By embedding doubly encrypted biometric data into a code (e.g., QR code), the method prevents unauthorized access during data transmission. The process involves verification through dual-device interaction, ensuring the user’s participation for enhanced security. This method addresses vulnerabilities in conventional systems by reducing exposure of raw biometric data and requiring multiple levels of validation for user authentication.

[0048] In an embodiment, an authentication server is disclosed that includes a processor and memory storing instructions. The processor executes instructions to receive a code containing doubly encrypted biometric data from a first electronic device. It sends a notification to a second electronic device associated with the user, prompting a response to confirm or denyauthentication. Upon receiving the response, the processor retrieves and decrypts the biometric data from the code in two stages to obtain the original biometric data. The decrypted data is then compared with pre-stored biometric data to verify the user’s identity. If the comparison is successful, the processor authenticates the user. The system eliminates the need for hardware on both the user's and provider's sides during authentication.

[0049] As compared to the conventional solutions, the present invention provides an authentication server that offers a secure infrastructure for biometric authentication. It incorporates encryption and decryption mechanisms to ensure data integrity during transmission and verification. The server facilitates interaction between two devices, adding a layer of security through dual confirmation. This server mitigates the risks of data theft by encrypting biometric information twice and embedding it into codes, which can only be decrypted at the server end.

[0050] In an embodiment, a system for user authentication is disclosed that includes a first electronic device configured to generate a code containing doubly encrypted biometric data and transmit it to an authentication server. The authentication server receives the code and sends a notification to a second electronic device associated with the user. The notification prompts the user to confirm or deny authentication. Upon receiving the response, the authentication server retrieves the doubly encrypted biometric data from the code, decrypts it in two stages to extract the original biometric data, and compares it with pre-stored biometric data to verify the user’s identity. If the verification succeeds, the user is authenticated. The system eliminates the need for hardware on both the user's and provider's sides during authentication.

[0051] As compared to the conventional solutions, the described system integrates multiple components — devices and a server — to ensure robust biometric authentication. The first electronic device handles data encryption and code generation, while the server executes verification tasks. The second device ensures user consent, reinforcing security through a dualdevice framework. The system effectively addresses issues like identity theft by securely managing biometric data and requiring multi-layer validation during authentication.

[0052] Embodiments of the present disclosure may provide a method and a system for managing data structures in a Java Card environment. The method and the system for such management are described with reference to FIG. 1A to FIG. 6 as detailed below.

[0053] FIG. 1 illustrates a block diagram of an environment of a system (100) for for authenticating a user, in accordance with an example embodiment. The system (100) for authenticating a user is designed with a multi-step, secure approach that leverages encryption and communication between multiple devices to ensure robust identity verification. The system(100) includes a first electronic device (102), an authentication server (104), and a second electronic device (106) communicably coupled with each other.

[0054] Below, each step of the system is elaborated in detail with examples to provide a comprehensive understanding of its functioning.

[0055] Step 1: Generating and Transmitting the Code: The process begins with a first electronic device (102), such as the user's smartphone, tablet, or biometric capture device. This device is configured to capture the user's biometric data, which could include fingerprints, facial scans, voice recognition, or iris scans. Once the biometric data is captured, it undergoes a two-stage encryption process. First, the biometric data is encrypted using a secure encryption algorithm, such as Advanced Encryption Standard (AES). In the second stage, the already encrypted biometric data is further encrypted and embedded within a code, such as a QR code or barcode, creating what is known as "doubly encrypted biometric data."

[0056] In another implementation, the biometric data of an individual is first captured and encrypted using a secret code at the time of collection. This encrypted biometric data is then further encoded into a QR code for secure storage. The QR code is stored securely within the user's account on the platform. The user can share this QR code, in a secure manner, with a service provider who needs to authenticate or verify their identity. Additionally, the service provider must register with the platform to facilitate the verification process. Overall, the system eliminates the need for hardware on both the user's and provider's sides during authentication.

[0057] Step 2: Receiving the Code and Sending Notification: Once the authentication server (104) receives the transmitted code, it initiates the next step by sending a notification to a second electronic device (106) associated with the user. This second device could be another smartphone, a smartwatch, or any electronic device linked to the user's identity. The notification contains a trigger, which prompts the user to either approve or disapprove the authentication request.

[0058] For instance, upon receiving the QR code from the first device, the authentication server sends a push notification to the user’s smartwatch. The notification might state, “Approve authentication request for secure building access?” The user can then respond by selecting an approval or disapproval option on their smartwatch.

[0059] Step 3: Verification of the User’s Identity: Upon receiving the user's response to the notification, the authentication server begins the verification process. First, it retrieves the doubly encrypted biometric data embedded within the received code. Next, the server performs a two-stage decryption process to extract the original biometric data. Using decryptionalgorithms such as RS A or ECC, the server sequentially decrypts the data to restore the user’s biometric information.

[0060] For example, the server extracts the fingerprint data from the QR code and decrypts it in two stages. The first stage reverses the outer encryption layer, and the second stage reverses the inner encryption layer, resulting in the original fingerprint data.

[0061] Step 4: Matching the Decrypted Biometric Data: After decrypting the biometric data, the authentication server compares it with pre-stored biometric data associated with the user. This pre-stored data resides in a secure database and has been previously registered by the user during an onboarding process. The comparison ensures that the decrypted biometric data matches the pre-stored data, verifying the user’s identity.

[0062] For instance, the decrypted fingerprint data is compared with a fingerprint stored in the authentication server's secure database. If the two sets of data match, the server confirms that the user attempting access is indeed the registered individual.

[0063] Step 5: Authentication of the User: Finally, upon successful matching of the biometric data, the server authenticates the user and grants access to the requested resource or system. Additionally, a confirmation message is transmitted to the first electronic device (102), notifying the user of the successful authentication. If the biometric data does not match, the server denies authentication and may alert the user and administrator about the failed attempt. Overall, the system eliminates the need for hardware on both the user's and provider's sides during authentication.

[0064] For example, after confirming the fingerprint match, the authentication server unlocks the secure building's entrance and sends a confirmation message to the user's smartphone, stating, “Authentication successful. Access granted.”

[0065] This system provides a highly secure method for biometric authentication by utilizing double encryption, dual-device interaction, and multi-step verification. It addresses vulnerabilities in traditional biometric systems, such as susceptibility to hacking and unauthorized access to stored data. The system finds applications in secure building access, online banking, e-commerce platforms, and other scenarios requiring robust identity authentication.

[0066] By encrypting biometric data twice, embedding it in a code, and involving the user in the authentication process via notifications, the system ensures unparalleled security and user control, mitigating risks of identity theft and data breaches.

[0067] The first electronic device (102) may be communicatively coupled with the authentication server (104) and the second electronic device (106) via a communication network (not shown). Examples of the first electronic device (102), the authentication server (104) andthe second electronic device (106) may comprise, but are not limited to, a desktop, a laptop, a notebook, a tablet, a smartphone, a mobile phone, an application server, or the like. The first electronic device (102), the authentication server (104) and the second electronic device (106) is associated with at least one user. The server (106) acts as s a central point for for authenticating a user.

[0068] The communication network may be wired, wireless, or any combination of wired and wireless communication networks, such as cellular, Wi-Fi, internet, local area networks, or the like. In one embodiment, the communication network 104may comprise one or more networks such as a data network, a wireless network, a telephony network, or any combination thereof. It is contemplated that the data network may be any local area network (LAN), metropolitan area network (MAN), wide area network (WAN), a public data network (e.g., the Internet), short range wireless network, or any other suitable packet- switched network, such as a commercially owned, proprietary packet-switched network, e.g., a proprietary cable or fibreoptic network, and the like, or any combination thereof. In addition, the wireless network may be, for example, a cellular network and may employ various technologies comprising enhanced data rates for global evolution (EDGE), general packet radio service (GPRS), global system for mobile communications (GSM), Internet protocol multimedia subsystem (IMS), universal mobile telecommunications system (UMTS), etc., as well as any other suitable wireless medium, e.g., worldwide interoperability for microwave access (WiMAX), Long Term Evolution (LTE) networks, code division multiple access (CDMA), wideband code division multiple access (WCDMA), wireless fidelity (Wi-Fi), wireless LAN (WLAN), Bluetooth®, Internet Protocol (IP) data casting, satellite, mobile ad-hoc network (MANET), and the like, or any combination thereof.

[0069] FIG. 2 illustrate an exemplary block diagram illustrating various steps within the authentication server (104) for authenticating a user, in accordance with an example embodiment. The authentication server (104) may comprise a storage unit (memory) (204), and a processing unit (processor) (202) as shown in FIG. 2. The term “storage” used herein may refer to any computer-readable storage medium, for example, volatile memory, random access memory (RAM), non-volatile memory, read only memory (ROM), or flash memory. The storage unit 204 may comprise a Random-Access Memory (RAM), a Read-Only Memory (ROM), a Complementary Metal Oxide Semiconductor Memory (CMOS), a magnetic surface memory, a Hard Disk Drive (HDD), a floppy disk, a magnetic tape, a disc (CD-ROM, DVD-ROM, etc.), a USB Flash Drive (UFD), or the like, or any combination thereof.

[0070] The term “processing unit” used herein may refer to a hardware processor comprising a Central Processing Unit (CPU), an Application-Specific Integrated Circuit(ASIC), an Application-Specific Instruction-Set Processor (ASIP), a Graphics Processing Unit (GPU), a Physics Processing Unit (PPU), a Digital Signal Processor (DSP), a Field Programmable Gate Array (FPGA), a Programmable Logic Device (PLD), a Controller, a Microcontroller unit, a Processor, a Microprocessor, an ARM, or the like, or any combination thereof.

[0071] The processing unit (202) may retrieve computer program code instructions that may be stored in the storage unit (204) for execution of the computer program code instructions. The processing unit (202) may be embodied in a number of different ways. For example, the processing unit (202) may be embodied as one or more of various hardware processing means such as a coprocessor, a microprocessor, a controller, a digital signal processor (DSP), a processing element with or without an accompanying DSP, or various other processing circuitry including integrated circuits such as, for example, an ASIC (application specific integrated circuit), an FPGA (field programmable gate array), a microcontroller unit (MCU), a hardware accelerator, a special-purpose computer chip, or the like. As such, in some embodiments, the processing unit (202) may comprise one or more processing cores configured to perform independently. A multi-core processor may enable multiprocessing within a single physical package. Additionally, or alternatively, the processing unit (202) may comprise one or more processors configured in tandem via the bus to enable independent execution of instructions, pipelining, and / or multithreading.

[0072] Additionally, or alternatively, the processing unit (202) may comprise one or more processors capable of processing large volumes of workloads and operations to provide support for big data analysis. In an example embodiment, the processing unit (202) may be in communication with a storage unit (204) via a bus for passing information among components of the server (104).

[0073] The storage unit (204) may be non-transitory and may comprise, for example, one or more volatile and / or non-volatile memories. In other words, for example, the storage unit (204) may be an electronic storage device (for example, a computer readable storage medium) comprising gates configured to store data (for example, bits) that may be retrievable by a machine (for example, a computing device like the processor 202). The storage unit (204) may be configured to store information, data, contents, applications, instructions, or the like, for enabling the apparatus to carry out various functions in accordance with an example embodiment of the present disclosure. For example, the storage unit (204) may be configured to buffer input data for processing by the processing unit (202).

[0074] The storage unit (204) may store instructions that, when executed by the processing unit (202), cause the server (104) to perform one or more operations of the present disclosure which will be described in greater detail in conjunction with FIG. 2.

[0075] The server (104) may comprise various hardware and software tools that may be integrated with the server (104) to enhance its functionality. The complete process followed by the server (104) is explained in detail in conjunction with FIG. 2 to FIG. 5.

[0076] FIG. 2 illustrates a block diagram illustrating various modules within the authentication server (104) for authenticating a user, in accordance with an example embodiment. The authentication server (104) comprises one or more processing unit (202). The one or more processing unit (202) are implemented as one or more microprocessors, microcomputers, microcontrollers, digital signal processors, central processing units, logic circuitries, and / or any devices that manipulate data based on operational instructions. Among other capabilities, processing unit (202) are configured to fetch and execute computer-readable instructions stored in a memory of the sink device. The storage unit (204) stores one or more computer-readable instructions or routines, which are fetched and executed to create or share the data units over a network service. Storage unit (204) comprises any non-transitory storage device comprising, for example, volatile memory such as RAM, or non-volatile memory such as EPROM, flash memory, and the like.

[0077] In an embodiment, the authentication server (104) also comprises an interface(s) (206). The interface(s) (206) comprises a variety of interfaces, for example, interfaces for data input and output devices referred to as VO devices, storage devices, and the like. The interface(s) (206) facilitates communication of the authentication server (104) with various devices or servers coupled to the electronic devices. The interface(s) (206) also provides a communication pathway for one or more components of the authentication server (104). Examples of such components comprise, but are not limited to, processing engine(s) and database. Interface (206) comprises a platform for communication with the devices / servers to read real-time data / write data in the authentication server (104) and to communicate with the other devices. Interfaces (206) comprise a Graphical interface that allows user to feed inputs, to type / write / upload the data and certificates, and other software and hardware interfaces, for example, interfaces for peripheral device(s), such as a keyboard, a mouse, an external memory, and a printer.

[0078] In an embodiment, the processing engine(s) (208) are implemented as a combination of hardware and programming (for example, programmable instructions) to implement one or more functionalities of the processing engine(s) (208). In the examples described herein, such combinations of hardware and programming may be implemented in several different ways. Forexample, the programming for the processing engine(s) (208) are processor-executable instructions stored on a non-transitory machine -readable storage medium, and the hardware for the processing engine(s) (208) comprises a processing resource (for example, one or more processors), to execute such instructions. In the present examples, the machine -readable storage medium stores instructions that, when executed by the processing resource, implement the processing engine(s). In such examples, the authentication server (104) comprises the machine-readable storage medium storing the instructions and the processing resource to execute the instructions, or the machine-readable storage medium may be separate but accessible to the user device and the processing resource. In other examples, the processing engine(s) (208) is implemented by electronic circuitry. Database comprises data that is either stored or generated as a result of functionalities implemented by any of the components of the processing engine(s) (208).

[0079] In an exemplary embodiment, the authentication server (104) plays a crucial role in verifying a user's identity through secure and systematic steps. The server comprises a processor (202) and a memory (204), which stores a set of executable instructions. These instructions guide the server's operations, ensuring seamless interaction between devices, secure data handling, and precise user authentication. The detailed processes involve receiving encrypted data, sending notifications, verifying identity, and confirming authentication. Below, each step is explained in detail.

[0080] Receiving a Code Containing Doubly Encrypted Biometric Data: The authentication server receives (210) a code from a first electronic device. This code comprises encrypted biometric data of the user, which is further encrypted and embedded as doubly encrypted biometric data. For instance, a user attempting authentication sends a QR code from their smartphone. This QR code contains their biometric data, such as a facial scan, encrypted using an advanced algorithm like AES and further encrypted with another technique like RSA. This doubly encrypted data ensures that sensitive biometric information is securely transferred.

[0081] Transmitting a Notification to a Second Device: Upon receiving the code, the server transmits (212) a notification to a second electronic device associated with the user. This notification acts as a trigger, prompting the user to approve or disapprove the authentication request. For example, if the user’s biometric code is sent from their smartphone, the server might send a notification to their smartwatch or secondary phone. The notification could be a message or link asking the user to confirm their intent to authenticate. Overall, the system eliminates the need for hardware on both the user's and provider's sides during authentication.

[0082] Verifying the User’s Identity: After receiving the response to the trigger, the server verifies (214) the user’s identity. This step involves retrieving the doubly encrypted biometricdata from the received code, decrypting it twice, and matching it with pre-stored biometric data. For example: the server extracts the doubly encrypted biometric data from the QR code. Using algorithms like Diffie-Hellman key exchange and Triple DEA, the data is decrypted in two stages to reveal the original biometric data. The obtained biometric data, such as a fingerprint, is compared with the fingerprint data stored in the server’s database. If a match is found, the user’s identity is verified.

[0083] Authenticating the User: Once the identity is verified, the server completes the authentication (216). It ensures that the user is legitimate and grants access to the requested system or resource. For instance, if a financial app uses this authentication server, the user is granted access to their account after successful authentication.

[0084] Confirmation of Authentication: The server transmits a confirmation to the first electronic device after successful authentication. For example, a message like "Authentication Successful" is sent to the user’s smartphone, notifying them that their identity verification process has been completed.

[0085] Code Formats for Biometric Data: The code containing biometric data can be a barcode or QR code. These formats ensure easy scanning and transferability of the encoded data between devices.

[0086] Biometric Data Types: The biometric data used for authentication can include fingerprints, facial scans, voice recognition, iris scans, palm prints, and hand geometry. For instance, a high-security facility may use iris scans, while an e-commerce platform might rely on fingerprints for user authentication.

[0087] Encryption and Decryption Algorithms: The advanced encryption and decryption algorithms are used to secure the biometric data. Examples include: Elliptic Curve Cryptography (ECC) for compact encryption. RSA for asymmetric encryption. Advanced Encryption Standard (AES) for secure symmetric encryption. The use of these algorithms ensures that the biometric data remains protected from unauthorized access during transmission and storage.

[0088] Encoding Techniques for Embedding Data: The encoding techniques used to embed encrypted biometric data into the code. Techniques like Base64, Base- 122, and Base85 are employed to efficiently encode the data, ensuring compatibility with the code format.

[0089] Notification and Trigger Mechanisms: Notifications can be in the form of messages, emails, or missed calls, while triggers correspond to user approvals or disapprovals. For instance, a user might receive an email with an approval link to confirm their authentication request.

[0090] The authentication server (104) is a sophisticated system that ensures secure, efficient, and reliable user authentication. By leveraging advanced encryption methods, encoding techniques, and multiple devices for validation, the server minimizes the risk of unauthorized access and ensures that only verified users are granted access to sensitive systems. This multi-step process, from receiving encrypted biometric data to final confirmation, demonstrates a robust approach to modem authentication challenges.

[0091] In an embodiment, the processing engine(s) (208) are implemented as a combination of hardware and programming (for example, programmable instructions) to implement one or more functionalities of the processing engine(s) 308. In the examples described herein, such combinations of hardware and programming may be implemented in several different ways. For example, the programming for the processing engine(s) (208) are processor-executable instructions stored on a non-transitory machine -readable storage medium, and the hardware for the processing engine(s) comprises a processing resource (for example, one or more processors), to execute such instructions. In the present examples, the machine -readable storage medium stores instructions that, when executed by the processing resource, implement the processing engine(s). In such examples, the electronic devices and server comprises the machine-readable storage medium storing the instructions and the processing resource to execute the instructions, or the machine -readable storage medium may be separate but accessible to the electronic devices and server and the processing resource. In other examples, the processing engine(s) (208) is implemented by electronic circuitry. Database comprises data that is either stored or generated as a result of functionalities implemented by any of the components of the processing engine(s) (208).

[0092] As will be appreciated, any such computer program instructions may be loaded onto a computer or other programmable apparatus (for example, hardware) to produce a machine, such that the resulting computer or other programmable apparatus implements the functions specified in the flow diagram blocks. These computer program instructions may also be stored in a computer-readable memory that may direct a computer or other programmable apparatus to function in a particular manner, such that the instructions stored in the computer -readable memory produce an article of manufacture the execution of which implements the function specified in the flowchart blocks. The computer program instructions may also be loaded onto a computer or other programmable apparatus to cause a series of operations to be performed on the computer or other programmable apparatus to produce a computer-implemented process such that the instructions which execute on the computer or other programmable apparatus provide operations for implementing the functions specified in the flow diagram blocks. Accordingly, blocks of the flow diagram support combinations of means for performing thespecified functions and combinations of operations for performing the specified functions for performing the specified functions. It will also be understood that one or more blocks of the flow diagram, and combinations of blocks in the flow diagram, may be implemented by special purpose hardware-based computer systems which perform the specified functions, or combinations of special purpose hardware and computer instructions.

[0093] FIG. 3 illustrates a flow diagram of method (300) for authenticating a user, in accordance with an example embodiment. The method (300) is implemented by the system architecture and / or by a server (104).

[0094] Receiving the Code Containing Doubly Encrypted Biometric Data: The first step involves receiving (302), by the authentication server's processor, a code from a first electronic device. This code contains encrypted biometric data of the user, which is further encrypted to create a doubly encrypted biometric data. For example, the biometric data (such as a fingerprint scan) can be initially encrypted using the Advanced Encryption Standard (AES). Then, it is further encrypted using an asymmetric encryption algorithm like Rivest-Shamir-Adleman (RSA) to enhance security. The doubly encrypted data is then embedded into a QR code or barcode using encoding techniques like Base64 or Base85. This ensures secure transmission of sensitive data while maintaining compatibility with electronic devices.

[0095] Transmitting a Notification to a Second Device: After receiving the code, the authentication server transmits (304) a notification to a second electronic device associated with the user. This notification acts as a trigger for the user to approve or disapprove the authentication request. For instance, upon receiving a QR code from a smartphone, the server sends a message or email to the user's smartwatch or secondary phone. The notification could include a link prompting the user to confirm their identity or a one-time passcode (OTP) for added security. Techniques like Secure Sockets Layer (SSL) or Transport Layer Security (TLS) are used to encrypt the notification during transmission.

[0096] Verifying the User’s Identity: Verification (306) involves multiple sub-steps:

[0097] Retrieving the Doubly Encrypted Biometric Data: The server extracts the encrypted data from the received code using decoding techniques, such as Base62x or Basel22.

[0098] Doubly Decrypting the Biometric Data: The server first decrypts the outer encryption layer using RSA, then decrypts the inner layer using AES or another symmetric encryption algorithm. For enhanced security, algorithms like Elliptic Curve Cryptography (ECC) or the Diffie-Hellman key exchange can be employed during this process.

[0099] Matching Biometric Data: The decrypted biometric data (e.g., a facial scan or iris pattern) is matched against pre-stored data in the server's secure database. Biometric matchingalgorithms like Local Binary Patterns (LBP) for facial recognition or minutiae extraction for fingerprint analysis ensure accuracy in verifying the user’s identity.

[0100] Authenticating the User:

[0101] Upon successful matching, the server authenticates (308) the user. This authentication grants the user access to the requested service or system. For instance, if the user is attempting to log into a banking application, the authentication grants them secure access. Secure token generation methods like JSON Web Tokens (JWT) or OAuth-based ttokens can be utilized to maintain session security after authentication. Overall, the system eliminates the need for hardware on both the user's and provider's sides during authentication.

[0102] Transmitting Confirmation to the First Device: The method involves transmitting a confirmation of successful authentication back to the first electronic device. For example, after verifying the user’s identity, the server sends a message to the user's smartphone, such as "Authentication Successful." This step ensures transparency and provides feedback to the user.

[0103] Code Formats for Biometric Data: The code containing biometric data can be in the form of a QR code or barcode. QR codes are widely used due to their ability to store large amounts of data compactly and securely. Encoding techniques like Base85 ensure that the biometric data is optimally compressed and encoded into the QR code.

[0104] Types of Biometric Data Supported: Biometric data includes fingerprints, facial scans, voice recognition, iris scans, palm prints, and hand geometry. For example, a high-security application might use iris scans due to their high accuracy, while voice recognition might be used for remote authentication scenarios. Advanced image and pattern recognition algorithms ensure robust handling of these data types.

[0105] Encryption and Decryption Algorithms: The encryption and decryption are performed using algorithms such as ECC, RS A, AES, Triple DEA, or the Diffie -Hellman key exchange. AES provides fast and secure symmetric encryption, while RSA ensures secure asymmetric encryption for key exchange. Combining these algorithms adds multiple layers of protection to the biometric data.

[0106] Encoding Techniques for Embedding Data: The method specifies encoding techniques like Base64, Basel22, Base62x, and Base85. These techniques ensure that the encrypted biometric data is efficiently embedded in the code while maintaining readability and compatibility across devices. For instance, Base64 encoding is commonly used for embedding binary data into text-based formats like QR codes.

[0107] Notification and Trigger Mechanisms: The types of notifications (e.g., message, email, or missed call) and triggers (e.g., approval or disapproval) used in the process. For instance, a user might receive an email with a link to approve their authentication request.Secure and user-friendly notification systems ensure timely responses while maintaining the integrity of the authentication process.

[0108] To summarize, the described method (300) is a comprehensive framework for user authentication. By leveraging advanced encryption techniques, secure transmission methods, and robust biometric matching algorithms, the method ensures high levels of security and reliability. Encoding techniques and multi-device notification systems further enhance the user experience while maintaining stringent security standards.

[0109] The disclosed methods and systems may be executed on a conventional or general-purpose computing system, such as a personal computer (PC) or server. Referring to FIG. 4, an exemplary computing system 400 is illustrated, which may implement processing functionality for various embodiments (e.g., as a SIMD device, client device, server device, or one or more processors). Those skilled in the art will recognize that other computing systems or architectures may also be used to implement the invention. The computing system 400 may represent a user device, such as a desktop, laptop, mobile phone, personal entertainment device, DVR, or any other special or general-purpose computing device appropriate for a given application or environment. The computing system 400 may comprise one or more processors, such as processor 570, implemented using a general-purpose or specialized processing engine, such as a microprocessor, microcontroller, or other control logic. In some embodiments, processor 570 may be an Al processor, implemented as a Tensor Processing Unit (TPU), graphical processing unit (GPU), or custom-programmable solution, such as a Field-Programmable Gate Array (FPGA).

[0110] The computing system 400 may further comprise memory 530 (e.g., Random Access Memory (RAM) or other dynamic memory) for storing instructions and information to be executed by processor 570. Memory 530 may also store temporary variables or intermediate information during execution. Additionally, the computing system 400 may comprise a readonly memory (ROM) or other static storage device connected to bus 520 for storing static information and instructions for processor 570.

[0111] Storage devices 550 / 510 may also be included in computing system 400, consisting of, for example, a media drive and a removable storage interface. Media drive may support fixed or removable storage media, such as hard disk drives, floppy drives, magnetic tape drives, SD card ports, USB ports, optical disk drives (e.g., CD or DVD drives), or other media. Storage media may comprise hard disks, magnetic tapes, flash drives, or other media that can be read and written to by media drive. Storage media may store computer-readable software or data.

[0112] Alternatively, storage devices 550 / 510 may comprise other means for loading computer programs or data into computing system 400, such as removable storage unit 510 and interface, program cartridges, removable memory (e.g., flash memory), memory slots, and similar storage units and interfaces.

[0113] Computing system 400 may also comprise a communications interface 560 to transfer software and data between external devices and system 400. Examples comprise network interfaces (e.g., Ethernet), communication ports (e.g., USB, micro-USB), Near Field Communication (NFC), and other protocols. The signals transferred via communications interface 560 may comprise electronic, electromagnetic, optical, or other forms of transmission through channel, which may utilize wireless mediums, fibre optics, wires, or cables.

[0114] Computing system 400 may also comprise Input / Output (I / O) devices, such as a display, keypad, microphone, speakers, vibration motors, LED indicators, etc., allowing user interaction and feedback. The term "computer-readable medium" may refer to any storage medium used, such as memory 530 / 540, storage devices 510 / 550, removable storage unit 510, or signal(s) on channel. Such media may store sequences of instructions, or "computer program code," which, when executed, enable computing system 400 to perform the methods and functions described in embodiments of the invention.

[0115] In embodiments where elements are implemented in software, the software may be stored on a computer-readable medium and loaded into computing system 400 via removable storage unit 510, media drive, or communications interface 560. When executed by processor 570, this control logic (e.g., software instructions or computer program code) causes processor 570 to perform the invention's functions as described.

[0116] As will be appreciated by those skilled in the art, the techniques described in the various embodiments discussed above are not routine, or conventional, or well understood in the art. The techniques discussed above provide for innovative solutions to address the challenges associated with generating holistic responses based on structural and semantic queries. The disclosed techniques offer several advantages over the existing methods as listed in below paragraphs.

[0117] FIG. 5 illustrates a sequence diagram of a method for authenticating a user from the overall systems perspective, in accordance with an example embodiment.

[0118] In an exemplary implementation, the sequence diagram that explains the flow of user data through various entities: User, MobileApp, Server, and GoogleCloud. Below is an explanation of each step in the process depicted in the diagram:

[0119] Actors in the System:

[0120] User: The end user who provides input and interacts with the mobile application.

[0121] MobileApp: A client application on the user's device that encrypts and communicates data.

[0122] Server: A backend system that processes and stores user data securely.

[0123] GoogleCloud: A cloud storage service for QR codes and encrypted user data.

[0124] Flow of Events1. User Input and Initial ProcessingUser Inputs: The user provides their details (e.g., name, phone, email) into the mobile application.QR Code Scan: The mobile app scans a QR code that may represent some pre-embedded data or unique information.2. Data Encryption in MobileAppThe mobile app encrypts the user data using AES-256 in CBC mode to ensure confidentiality. Additionally, it encrypts any update information (e.g., metadata or session info) with AES-256-CBC.3. Transmission to ServerThe encrypted data (both user data and update info) is sent securely to the Server using HTTPS.4. Decryption and Storage on ServerThe server decrypts the user data and the update information using AES-256-CBC.Decrypted data is stored securely in the following formats:Encrypted User Data: Stored as user_data.json.Encrypted Update Information: Stored as user_updatingData.json.The server then generates QR codes and stores them along with user data on GoogleCloud. 5. Retrieving and Verifying QR CodeThe user scans a QR code that is retrieved from GoogleCloud.The mobile app extracts encrypted data from the QR code.6. Data Transmission for VerificationThe mobile app sends the encrypted QR code data along with a unique number (likely a session ID or user ID) to the Server via HTTPS.7. Decryption on ServerThe server decrypts the QR code data using AES-256-CBC.It retrieves the corresponding user data from GoogleCloud and decrypts it.8. Data Comparison and ValidationThe server compares the decrypted QR code data with the decrypted user data retrieved from the cloud.Outcome:If the data matches: Verification is successful, and the process proceeds with a success response.If the data does not match: Verification fails, and an error is returned.

[0125] Working Example: Secure Access to Healthcare Records: The invention can be applied to securely authenticate users accessing their healthcare records via a cloud-based system, eliminating the need for specialized biometric devices during authentication.

[0126] For example, A patient wants to access their electronic medical records (EMR) on a healthcare provider's platform. The authentication system uses the described method to ensure secure access without requiring a biometric device at the time of authentication.

[0127] Biometric Data Capture and Encryption:

[0128] The patient uses their smartphone to scan their fingerprint via the phone’s built-in biometric sensor. The fingerprint data is encrypted using AES-256-CBC encryption for initial security. The encrypted data is further encrypted using RSA encryption, creating a doubly encrypted dataset. The doubly encrypted biometric data is encoded into a QR code using Base64 encoding for compatibility across platforms. The QR code is securely stored on a cloudbased healthcare platform, under the patient’s unique account.

[0129] Authentication Request: The patient logs into the healthcare platform using their smartphone. The system prompts them to scan the previously stored QR code for authentication. The smartphone transmits the QR code to the authentication server over a secure channel (e.g., TLS encryption).

[0130] Notification to a Second Device: To enhance security, the server sends a push notification to the patient’s smartwatch or another registered second device. The notification states: “Login attempt detected for your healthcare account. Do you approve? Click ‘Yes’ to proceed or ‘No’ to deny.” This notification includes a trigger for the patient to explicitly approve or reject the authentication request.

[0131] Verification of Biometric Data: Upon approval from the second device, the server decodes the received QR code to retrieve the doubly encrypted biometric data. The server decrypts the outer encryption layer using its private RSA key and the inner layer using the AES decryption algorithm, extracting the patient’s original fingerprint data. The decrypted fingerprint data is compared with the patient’s pre-stored biometric data in the cloud using Minutiae-based matching or similar algorithms.

[0132] Authentication and Access Grant: If the biometric data matches, the patient is authenticated, and access to their medical records is granted. A JSON Web Token (JWT) is generated to secure the session while interacting with the EMR system. The server sends aconfirmation message to the patient’s smartphone, such as: “Authentication successful. You now have access to your medical records.”

[0133] Key Features Demonstrated in the Example:

[0134] No Physical Biometric Device Required: The system leverages existing devices (smartphone and smartwatch) to perform secure authentication without dedicated biometric readers.

[0135] Double Encryption for Security: Biometric data undergoes AES and RSA encryption, ensuring robust protection during transmission and storage.

[0136] Multi-Device Verification: The system employs a second device for user approval, enhancing security against unauthorized access.

[0137] QR Code-Based Storage: The use of QR codes simplifies data portability and compatibility across platforms.

[0138] Advanced Encoding Techniques: Base64 encoding ensures data integrity within the QR code during transmission.

[0139] Versatility of Biometric Data: The system supports various biometric data types, such as fingerprints, facial scans, and iris recognition, making it adaptable for different users.

[0140] By eliminating the need for dedicated biometric hardware, this invention provides a cost-effective, secure, and user-friendly solution for authentication across various domains.

[0141] Many modifications and other embodiments of the inventions set forth herein will come to mind to one skilled in the art to which these inventions pertain having the benefit of the teachings presented in the foregoing descriptions and the associated drawings. Therefore, it is to be understood that the inventions are not to be limited to the specific embodiments disclosed and that modifications and other embodiments are intended to be included within the scope of the appended claims. Moreover, although the foregoing descriptions and the associated drawings describe example embodiments in the context of certain example combinations of elements and / or functions, it should be appreciated that different combinations of elements and / or functions may be provided by alternative embodiments without departing from the scope of the appended claims. In this regard, for example, different combinations of elements and / or functions than those explicitly described above are also contemplated as may be set forth in some of the appended claims. Although specific terms are employed herein, they are used in a generic and descriptive sense only and not for purposes of limitation.

[0142] It is to be understood that the above description is intended to be illustrative, and not restrictive. For example, the above-discussed embodiments may be used in combination with each other. Many other embodiments will be apparent to those of skill in the art upon reviewing the above description.

[0143] With respect to the use of substantially any plural and / or singular terms herein, those having skill in the art can translate from the plural to the singular and / or from the singular to the plural as is appropriate to the context and / or application. The various singular / plural permutations may be expressly set forth herein for sake of clarity.

[0144] The benefits and advantages which may be provided by the present disclosure have been described above with regard to specific embodiments. These benefits and advantages, and any elements or limitations that may cause them to occur or to become more pronounced are not to be construed as critical, required, or essential features of any or all of the embodiments.

[0145] While the present disclosure has been described with reference to particular embodiments, it should be understood that the embodiments are illustrative and that the scope of the invention is not limited to these embodiments. Many variations, modifications, additions, and improvements to the embodiments described above are possible. It is contemplated that these variations, modifications, additions, and improvements fall within the scope of the invention.

Claims

1. WE CLAIM:

1. A method (300) for authenticating a user without requiring a biometric device while authentication, the method comprising:receiving (302), by a processor of an authentication server, a code from a first electronic device, wherein the code comprising an encrypted biometric data of the user, and the encrypted biometric data is further encrypted to be embedded in the code as a doubly encrypted biometric data;transmitting (304), by the processor, a notification to a second electronic device in response to receiving the code, wherein the second electronic device is associated with the user to be authenticated, and the notification comprises a trigger to allow authentication of the user to be authenticated;verifying (306), by the processor and upon receiving response to the trigger to allow authentication, an identify of the user to be authenticated based on the received code, wherein the identity of the user is verified by:retrieving the doubly encrypted biometric data from the received code; doubly decrypting the doubly encrypted biometric data to obtain the biometric data of the user; andmatching the obtained biometric data with pre-stored biometric data associated with the user; and therebyauthenticating (308), by the processor and upon successful matching, the user without requiring a biometric device while authentication.

2. The method according to claim 1, wherein the method further comprising: transmitting, by the processor, a confirmation about the authentication to the first electronic device.

3. The method according to claim 1, wherein the code is a barcode or quick-response (QR) code.

4. The method according to claim 1, wherein the biometric data and the pre- stored biometric data comprises fingerprints, facial scans, voice recognition, iris scans, palm prints, and hand geometry associated with the user.

5. The method according to claim 1, wherein the biometric data of the user is encrypted, further encrypted and decrypted by an algorithm selected from any or a combination of EllipticCurve Cryptography (ECC), Rivest-Shamir-Adleman (RSA), Symmetric encryption, Diffie-Hellman key exchange, Advanced Encryption Standard (AES), Triple Data Encryption Algorithm (TDEA or Triple DEA).

6. The method according to claim 1, wherein the method further comprising: encoding, by using an encoding technique, the encrypted biometric data is further encrypted to be embedded in the code as a doubly encrypted biometric data, wherein the encoding technique is selected from any or a combination of Base64, Base-122, Base62x, and Base85.

7. The method according to claim 1, wherein:the notification is selected from any or a combination of a message, an email, a link, a missed call; andthe trigger corresponds to an approval or a disapproval to the authentication.

8. An authentication server (104) for authenticating a user without requiring a biometric device while authentication, the authentication server comprising:a processor (202); anda memory (204) storing a set of executable instructions which when executed by the processor causes the authentication server to:receive (210) a code from a first electronic device, wherein the code comprising an encrypted biometric data of the user, and the encrypted biometric data is further encrypted to be embedded in the code as a doubly encrypted biometric data;transmit (212) a notification to a second electronic device in response to receiving the code, wherein the second electronic device is associated with the user to be authenticated, and the notification comprises a trigger to allow authentication of the user to be authenticated;verify (214), upon receiving response to the trigger to allow authentication, an identify of the user to be authenticated based on the received code, wherein the processor further causes the authentication server to:retrieve the doubly encrypted biometric data from the received code;doubly decrypt the doubly encrypted biometric data to obtain the biometric data of the user; andmatch the obtained biometric data with pre-stored biometric data associated with the user to verify the identity of the user; and therebyauthenticate (216) the user without requiring a biometric device while authentication.

9. The authentication server according to claim 8, wherein the processor causes the authentication server to: transmit a confirmation about the authentication to the first electronic device.

10. The authentication server according to claim 8, wherein the code is a barcode or quick -response (QR) code.

11. The authentication server according to claim 8, wherein the biometric data and the pre-stored biometric data comprises fingerprints, facial scans, voice recognition, iris scans, palm prints, and hand geometry associated with the user.

12. The authentication server according to claim 8, wherein the biometric data of the user is encrypted, further encrypted and decrypted by an algorithm selected from any or a combination of Elliptic Curve Cryptography (ECC), Rivest-Shamir-Adleman (RSA), Symmetric encryption, Diffie-Hellman key exchange, Advanced Encryption Standard (AES), Triple Data Encryption Algorithm (TDEA or Triple DEA).

13. The authentication server according to claim 8, wherein the processor causes the authentication server to: encode, by using an encoding technique, the encrypted biometric data is further encrypted to be embedded in the code as a doubly encrypted biometric data, wherein the encoding technique is selected from any or a combination of Base64, Base- 122, Base62x, and Base85.

14. The authentication server according to claim 8, wherein:the notification is selected from any or a combination of a message, an email, a link, a missed call; andthe trigger corresponds to an approval or a disapproval to the authentication.

15. A system (100) for authenticating a user, the system comprising:a first electronic device (102) configured to:generate a code comprising an encrypted biometric data of the user, and the encrypted biometric data is further encrypted to be embedded in the code as a doubly encrypted biometric data; andtransmit the generated code to an authentication server (104);the authentication server configured to:receive the generated code from the first electronic device;transmit a notification to a second electronic device (106) in response to receiving the code, wherein the second electronic device is associated with the user to be authenticated, and the notification comprises a trigger to allow authentication of the user to be authenticated;verify, upon receiving response to the trigger to allow authentication, an identify of the user to be authenticated based on the received code, wherein the processor further causes the authentication server to:retrieve the doubly encrypted biometric data from the received code;doubly decrypt the doubly encrypted biometric data to obtain the biometric data of the user; andmatch the obtained biometric data with pre-stored biometric data associated with the user to verify the identity of the user; and thereby authenticate the user without requiring a biometric device while authentication.