Authentication Context Function Unit Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In biometric authentication systems, especially those operating over the internet, it is challenging to verify the legitimacy of authentication subprocesses when multiple function modules within an entity device can execute the same authentication subprocess, making it difficult for the verifier to determine which module executed the process and thus affecting the accuracy of authentication legitimacy.

Innovation Solution

Incorporating execution device identification information and function unit certification into the authentication context, allowing specification of the function unit that executed the authentication subprocess, even when multiple units are capable of performing the same task, thereby enabling verification of the legitimacy of the authentication process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple function modules are deployed in the entity device to execute authentication subprocess, then the system functionality and reliability are improved, but the verifier cannot determine which function module executed the authentication subprocess, making it difficult to verify the legitimacy of the authentication process

Engineering Contradiction:
Improveauthentication legitimacy verificationVSAvoidfunction module identification information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the authentication context information into distinct components, including a specific field for identifying which function module executed the authentication subprocess. This segmentation allows the verifier to extract and validate the function module identification information separately, resolving the ambiguity caused by multiple function modules while maintaining system reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism (the authentication context with embedded function module identification) that bridges the gap between multiple function modules and the verifier. This intermediary carries the necessary identification information from the entity device to the verifier, enabling legitimate verification without compromising the multi-function module architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If a single function module is used to execute authentication subprocess, then the verification of authentication legitimacy is simplified, but the system lacks flexibility and redundancy when multiple modules are needed for different authentication scenarios

Engineering Contradiction:
Improveauthentication subprocess execution flexibilityVSAvoidauthentication context structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal authentication context structure that can accommodate multiple function modules while maintaining a consistent verification process. The authentication context is designed to be multi-functional, carrying both the authentication result and the function module identification information in a unified format that works across different authentication scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent modifies the authentication context parameters to include function module identification information. By changing the parameter structure of the authentication context to incorporate this additional information field, the system achieves both adaptability for multiple function modules and maintainable verification complexity through standardized parameter changes.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP1942434B1Authentication system, apparatus and program
Publication Date: 2020.11.25 KK TOSHIBA
  • EP1942434B1 patent drawingFigure 1
  • EP1942434B1 patent drawingFigure 2
  • EP1942434B1 patent drawingFigure 3

AI summary

A configuration including, in authentication contexts (AP1, AP2), function unit identification information unique to the function unit that has executed an authentication subprocess in entity devices (30, 50) permits an authentication apparatus (10) to specify the function unit that has executed the authentication subprocess in the entity devices (30, 50). The verifier, therefore, can verify the legitimacy of the authentication subprocess from the authentication context even in the presence of a plurality of function units capable of executing the same authentication subprocess in the entity devices (30, 50).