Adaptive Identity Authentication for Mobile Terminals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity authentication methods using biometric features in mobile terminals are inefficient and insecure, as they provide uniform authentication accuracy for all services, failing to differentiate between various service security levels and resulting in unsatisfactory efficiency and security.

Innovation Solution

Implementing a dual authentication method where the first identity authentication uses high-accuracy biometric data, and subsequent authentication uses lower-accuracy data based on service security levels, with varying validity durations and matching accuracy settings for different applications, ensuring higher efficiency and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If uniform high-accuracy biometric authentication is used for all services, then authentication security is improved, but authentication efficiency deteriorates due to unnecessary high accuracy requirements for low-security services

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by differentiating authentication accuracy requirements according to service security levels. High-security services (e.g., payment) use high-accuracy authentication (first authentication with strict matching), while low-security services (e.g., messaging) use lower-accuracy authentication (second authentication with relaxed matching). This resolves the contradiction by matching authentication rigor to actual service needs, improving efficiency without compromising security where required.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the parameter of authentication accuracy based on service security levels. It introduces multiple authentication modes with different accuracy thresholds and validity durations. The terminal adjusts authentication parameters dynamically: for high-security services, it uses stricter matching criteria and shorter validity periods; for low-security services, it uses more lenient criteria and longer validity periods, thereby resolving the efficiency-security trade-off.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If frequent high-accuracy authentication is performed, then authentication security is improved, but user experience deteriorates due to increased authentication burden

Engineering Contradiction:
Improveauthentication securityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces dynamic authentication where the required authentication accuracy and frequency adapt based on service security levels and risk assessments. For low-security services, the system dynamically reduces authentication burden by using pre-validated credentials with extended validity. For high-security services, it dynamically increases scrutiny. This dynamic adjustment resolves the contradiction by making authentication adaptive rather than static.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies partial action by performing only the necessary level of authentication for each service. Instead of always executing full high-accuracy authentication, it performs partial verification for low-security services using previously validated biometric data, reserving full authentication for high-security operations. This reduces user burden while maintaining adequate security.

Inventive Principle:
Principle #16Partial or excessive action

3Device complexity

If single-level authentication is used for all applications, then system complexity is reduced, but adaptability deteriorates due to inability to meet different service security requirements

Engineering Contradiction:
Improvesystem complexityVSAvoidservice adaptability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the authentication system into multiple levels: first authentication for high-security services and second authentication for low-security services. Each segment has its own accuracy requirements, validity durations, and verification processes. This segmentation resolves the contradiction by organizing complexity into manageable, service-specific modules rather than a monolithic system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal authentication framework that handles multiple service types through a common architecture. The terminal maintains a unified credential storage and authentication management system that can serve both high-security and low-security services, adapting its behavior based on service requirements. This multi-functionality resolves the contradiction by providing service-specific authentication within a single integrated system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11096048B2Identity authentication method and communications terminal
Publication Date: 2021.08.17 HUAWEI TECH CO LTD
  • US11096048B2 patent drawing
  • US11096048B2 patent drawing
  • US11096048B2 patent drawing

AI summary

The present disclosure relates to an identity authentication method and a communications terminal. One example method includes: performing, by a terminal, first identity authentication on first user identity feature data; if the first identity authentication succeeds, and the wearable device is in a valid worn state, when receiving an access request for a preset application, obtaining, by the terminal, a service security level of the preset application, and obtaining an authentication time point for second identity authentication and matching accuracy of the second identity authentication; determining whether a difference between a current time point and the authentication time point is less than authentication validity duration corresponding to the service security level and whether the matching accuracy is higher than lowest matching accuracy corresponding to the service security level; and if yes, accepting the access request.