BESAKE Token Biometric Key Exchange Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication systems, particularly those using internet-centric services, face challenges in providing certainty of identity due to vulnerabilities in username and password login systems, which are susceptible to hacking and phishing attacks, and lack the efficiency and convenience of internet-based transactions.
Innovation Solution
The Biometric Electronic Signature Authenticated Key Exchange (BESAKE) token system uses a biometric sample and a secret knowledge factor to generate a token that includes an encrypted biometric sample and a signing party identifier, enabling multi-factor authentication through a hybrid cryptographic technique of authenticated encryption and key exchange, without requiring digital signatures or Public Key Infrastructure (PKI).
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional username and password authentication is used, then ease of operation is improved, but reliability deteriorates due to susceptibility to hacking and phishing attacks
Solution Approach 1:
The patent combines multiple authentication factors (biometric data, knowledge factors, and possession factors) into a unified authentication mechanism. The BESAKE token integrates encrypted biometric templates with cryptographic key exchange, creating a multi-factor authentication system that maintains ease of use while significantly improving security reliability.
Solution Approach 2:
The authentication system uses composite authentication credentials consisting of biometric data encrypted with cryptographic keys derived from knowledge factors. This composite structure combines the uniqueness of biometrics with the security of cryptographic protocols, creating an authentication mechanism that is both user-friendly and highly secure.
2Reliability
If heavy protection mechanisms are used to protect biometric data, then reliability is improved, but productivity deteriorates due to processor-intensive operations
Solution Approach 1:
The system performs preliminary encryption of biometric data during the authentication setup phase, creating encrypted templates that can be efficiently processed during actual authentication. The BESAKE token is pre-generated with embedded cryptographic keys, allowing for rapid verification without intensive real-time processing.
Solution Approach 2:
The patent extracts and separates the heavy cryptographic processing from the real-time authentication flow. Complex key exchange operations are performed in advance to generate the BESAKE token, while the actual authentication process uses the pre-computed token for rapid verification, thereby maintaining both security and speed.
3Reliability
If multi-factor authentication is implemented, then reliability is improved, but device complexity increases
Solution Approach 1:
The BESAKE token serves multiple functions simultaneously: it acts as an encrypted biometric template, a cryptographic key exchange mechanism, and an authentication credential. This multi-functionality consolidates what would otherwise require separate systems into a single unified token, reducing overall system complexity while maintaining multi-factor authentication benefits.
Data Source
AI summary
A method of generating a biometric electronic signature authenticated key exchange (“BESAKE”) token. The method begins when a biometric sample captured from a signing party is received. A secret knowledge factor is received. An encryption key is generated using the secret knowledge factor as an input to a password authenticated key exchange protocol. The biometric sample is encrypted with the encryption key. The BESAKE token is generated and includes the encrypted biometric sample and a signing party identifier associated with the secret knowledge factor. The BESAKE token can be verified using a decryption key generated using a stored knowledge factor as an input to the password authenticated key exchange protocol. The secret knowledge factor is retrieved based on the signing party identifier. The identity of the signing party can be authenticated by decrypting the biometric sample from the BESAKE token using the decryption key and matching the decrypted biometric sample.


