Authentication Terminal Mediator for Biometric Consent
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge is to provide an authentication system that allows users to control and manage their personal information related to service provision using biometric authentication, while ensuring privacy protection and compliance with user consent for data sharing with third parties.
Innovation Solution
The proposed authentication system includes an authentication server for biometric authentication, a management server for storing personal information, and a terminal possessed by the user. When biometric authentication is successful, the authentication server notifies the terminal, which then acquires the user's intention regarding the provision of personal information to a third party. Upon user consent, the terminal transmits a notification of acceptance to the management server, allowing the personal information to be shared.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If personal information is collected and accumulated for service provision, then the value of personal information increases, but user privacy protection deteriorates
Solution Approach 1:
The terminal device acts as an intermediary between the authentication server and the user. It receives authentication notifications, obtains user consent for personal information provision, and only then transmits acceptance notifications to the management server. This intermediary role ensures that personal information is shared with third parties only with explicit user consent, resolving the contradiction between information value and privacy protection.
2Loss of information
If personal information is provided to third parties, then service value increases, but user consent compliance deteriorates
Solution Approach 1:
The system performs preliminary action by notifying the user of authentication results before any personal information is shared with third parties. The terminal device obtains user consent in advance through the notification and acceptance mechanism, ensuring that personal information provision complies with user consent before the actual sharing occurs.
3Measurement precision
If biometric authentication is performed, then authentication accuracy improves, but personal information management complexity increases
Solution Approach 1:
The system segments personal information management into distinct functional modules: the authentication server handles biometric verification, the management server stores personal information, and the terminal device manages consent and coordination. This segmentation allows each component to focus on its specific function, reducing overall system complexity while maintaining authentication accuracy.
Data Source
AI summary
An authentication system includes an authentication server, a management server, and a terminal that the user possesses. The authentication server stores first biometric information of the user and performs biometric authentication of the user using the first biometric information. The management server stores the personal information of the user. When the biometric authentication of the user is successful, the authentication server transmits, to the terminal, a notification of authentication that indicates the biometric authentication of the user was successful. In response to the notification of authentication received, the terminal acquires the intent of the user regarding whether or not to accept the provision of stored personal information to a third person. When the user accepts the provision of stored personal information to the third person, the terminal transmits a notification of acceptance to the management server.


