Asynchronous Biometric Authentication for Information Processing Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Biometric authentication systems that perform authentication on the client side are vulnerable to security risks and increase the time required for authentication, particularly when using external authenticators, which can lead to decreased usability.

Innovation Solution

An information processing device that communicates with external authenticators to perform biometric authentication by transmitting verification data and signature data without waiting for the user's log-in instruction, allowing for asynchronous preparation of the authentication process, including requesting verification data and connecting to the authenticator before the user initiates the log-in.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If verification data is acquired and authenticator communication is performed after user log-in instruction, then security is maintained, but authentication time increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by acquiring verification data from the service provider system and establishing communication with the external authenticator before the user submits the log-in instruction. This allows the authentication process to be partially completed in advance, so that when the user logs in, only the final authentication steps are needed, significantly reducing the perceived authentication time while maintaining security through the server-side verification process

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication processes are performed synchronously after user instruction, then security verification is ensured, but user experience deteriorates due to waiting time

Engineering Contradiction:
Improveverification accuracyVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication preparations including acquiring verification data and communicating with the authenticator before the user's log-in instruction is processed. This asynchronous preparation ensures that when the user submits their log-in request, the system is already ready to complete the authentication quickly, improving user experience without compromising verification accuracy

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The service provider system acts as an intermediary that provides verification data to the terminal device. This intermediary role allows the terminal to perform local authentication operations using pre-acquired verification data, reducing the need for synchronous server communication during the actual authentication moment, thus improving responsiveness while maintaining security through the intermediary's verification data

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12021862B2Information processing device, control method for information processing device, and recording medium
Publication Date: 2024.06.25 CANON KK
  • US12021862B2 patent drawing
  • US12021862B2 patent drawing
  • US12021862B2 patent drawing

AI summary

An information processing device includes a display control means that displays a log-in screen for a service which is provided by a collaboration service after accessing the collaboration service, a first transmission means that transmits a request for verification data to the collaboration service, a communication control means that communicates with an authenticator before authenticating a user, a second transmission means that transmits a request including verification data to the authenticator when an instruction for log-in is received, and a third transmission means that transmits signature data received from the authenticator to the collaboration service. At least one of transmission of the request to the collaboration service from the first transmission means and communication of the communication control means with the authenticator is performed without waiting until the instruction for log-in is received from the user after accessing the collaboration service.