Authentication Terminal Mediator for Biometric Consent

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge is to provide an authentication system that allows users to control and manage their personal information related to service provision using biometric authentication, while ensuring privacy protection and compliance with user consent for data sharing with third parties.

Innovation Solution

The proposed authentication system includes an authentication server for biometric authentication, a management server for storing personal information, and a terminal possessed by the user. When biometric authentication is successful, the authentication server notifies the terminal, which then acquires the user's intention regarding the provision of personal information to a third party. Upon user consent, the terminal transmits a notification of acceptance to the management server, allowing the personal information to be shared.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If personal information is collected and accumulated for service provision, then the value of personal information increases, but user privacy protection deteriorates

Engineering Contradiction:
Improvevalue of personal informationVSAvoiduser privacy protection
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The terminal device acts as an intermediary between the authentication server and the user. It receives authentication notifications, obtains user consent for personal information provision, and only then transmits acceptance notifications to the management server. This intermediary role ensures that personal information is shared with third parties only with explicit user consent, resolving the contradiction between information value and privacy protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If personal information is provided to third parties, then service value increases, but user consent compliance deteriorates

Engineering Contradiction:
Improveservice valueVSAvoiduser consent compliance
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The system performs preliminary action by notifying the user of authentication results before any personal information is shared with third parties. The terminal device obtains user consent in advance through the notification and acceptance mechanism, ensuring that personal information provision complies with user consent before the actual sharing occurs.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If biometric authentication is performed, then authentication accuracy improves, but personal information management complexity increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidpersonal information management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments personal information management into distinct functional modules: the authentication server handles biometric verification, the management server stores personal information, and the terminal device manages consent and coordination. This segmentation allows each component to focus on its specific function, reducing overall system complexity while maintaining authentication accuracy.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12212563B2Authentication system, terminal, control method for terminal, and storage medium
Publication Date: 2025.01.28 NEC CORP
  • US12212563B2 patent drawing
  • US12212563B2 patent drawing
  • US12212563B2 patent drawing

AI summary

An authentication system includes an authentication server, a management server, and a terminal that the user possesses. The authentication server stores first biometric information of the user and performs biometric authentication of the user using the first biometric information. The management server stores the personal information of the user. When the biometric authentication of the user is successful, the authentication server transmits, to the terminal, a notification of authentication that indicates the biometric authentication of the user was successful. In response to the notification of authentication received, the terminal acquires the intent of the user regarding whether or not to accept the provision of stored personal information to a third person. When the user accepts the provision of stored personal information to the third person, the terminal transmits a notification of acceptance to the management server.