BESAKE Token Biometric Key Exchange Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems, particularly those using internet-centric services, face challenges in providing certainty of identity due to vulnerabilities in username and password login systems, which are susceptible to hacking and phishing attacks, and lack the efficiency and convenience of internet-based transactions.

Innovation Solution

The Biometric Electronic Signature Authenticated Key Exchange (BESAKE) token system uses a biometric sample and a secret knowledge factor to generate a token that includes an encrypted biometric sample and a signing party identifier, enabling multi-factor authentication through a hybrid cryptographic technique of authenticated encryption and key exchange, without requiring digital signatures or Public Key Infrastructure (PKI).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional username and password authentication is used, then ease of operation is improved, but reliability deteriorates due to susceptibility to hacking and phishing attacks

Engineering Contradiction:
Improveease of authenticationVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent combines multiple authentication factors (biometric data, knowledge factors, and possession factors) into a unified authentication mechanism. The BESAKE token integrates encrypted biometric templates with cryptographic key exchange, creating a multi-factor authentication system that maintains ease of use while significantly improving security reliability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication system uses composite authentication credentials consisting of biometric data encrypted with cryptographic keys derived from knowledge factors. This composite structure combines the uniqueness of biometrics with the security of cryptographic protocols, creating an authentication mechanism that is both user-friendly and highly secure.

Inventive Principle:
Principle #40Composite materials

2Reliability

If heavy protection mechanisms are used to protect biometric data, then reliability is improved, but productivity deteriorates due to processor-intensive operations

Engineering Contradiction:
Improvedata protectionVSAvoidinformation exchange speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary encryption of biometric data during the authentication setup phase, creating encrypted templates that can be efficiently processed during actual authentication. The BESAKE token is pre-generated with embedded cryptographic keys, allowing for rapid verification without intensive real-time processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent extracts and separates the heavy cryptographic processing from the real-time authentication flow. Complex key exchange operations are performed in advance to generate the BESAKE token, while the actual authentication process uses the pre-computed token for rapid verification, thereby maintaining both security and speed.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If multi-factor authentication is implemented, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication assuranceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The BESAKE token serves multiple functions simultaneously: it acts as an encrypted biometric template, a cryptographic key exchange mechanism, and an authentication credential. This multi-functionality consolidates what would otherwise require separate systems into a single unified token, reducing overall system complexity while maintaining multi-factor authentication benefits.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11405387B1Biometric electronic signature authenticated key exchange token
Publication Date: 2022.08.02 WELLS FARGO BANK NA
  • US11405387B1 patent drawing
  • US11405387B1 patent drawing
  • US11405387B1 patent drawing

AI summary

A method of generating a biometric electronic signature authenticated key exchange (“BESAKE”) token. The method begins when a biometric sample captured from a signing party is received. A secret knowledge factor is received. An encryption key is generated using the secret knowledge factor as an input to a password authenticated key exchange protocol. The biometric sample is encrypted with the encryption key. The BESAKE token is generated and includes the encrypted biometric sample and a signing party identifier associated with the secret knowledge factor. The BESAKE token can be verified using a decryption key generated using a stored knowledge factor as an input to the password authenticated key exchange protocol. The secret knowledge factor is retrieved based on the signing party identifier. The identity of the signing party can be authenticated by decrypting the biometric sample from the BESAKE token using the decryption key and matching the decrypted biometric sample.