Biometric Authentication Data Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current biometric identification systems lack secure data handling and life/consciousness detection, with captured biometric data often transmitted insecurely and authentication sequences being fixed, failing to provide robust access control.
Innovation Solution
A biometric authentication system that stores initial biometric data on both the registered biometric device and a remote computer system, allowing local comparison of re-captured data without transmission, and incorporates dynamic authentication sequences including consciousness detection, using various biometric devices such as cameras, iris scanners, and microphones.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If captured biometric data is transmitted to remote authentication module for comparison, then authentication can be performed, but security is compromised due to insecure transmission and storage
Solution Approach 1:
The system segments biometric data storage across multiple locations: the captured biometric data is stored locally in the biometric device, while authentication templates are stored in the authentication module. This segmentation eliminates the need to transmit sensitive biometric data over the network, as only authentication results are communicated, thereby resolving the security contradiction.
Solution Approach 2:
The patent introduces an intermediary comparison process where the authentication module receives processed biometric data from the biometric device and performs template matching locally. This intermediary step allows authentication to occur without transmitting raw biometric data, using the authentication module as a secure intermediary that handles only authenticated templates rather than sensitive personal data.
2Adaptability or versatility
If fixed authentication sequence is used in biometric identification system, then system complexity is reduced, but adaptability to different access scenarios is limited
Solution Approach 1:
The system implements dynamic authentication sequences where the authentication module can select different authentication methods and sequences based on the access scenario, user profile, and security requirements. The authentication sequence is no longer fixed but adapts dynamically to different situations, such as using single-factor or multi-factor authentication depending on the context.
Solution Approach 2:
The patent allows changing authentication parameters such as the type of biometric data required, the number of authentication factors, and the sequence of authentication steps based on predefined policies and real-time conditions. This parameter flexibility enables the system to adapt to different access scenarios without requiring complete system redesign.
3Reliability
If biometric data is stored only in remote authentication module, then centralization is achieved, but system reliability is reduced due to single point of failure and transmission requirements
Solution Approach 1:
The system applies local quality by storing different types of authentication data in appropriate locations: captured biometric data is stored locally in the biometric device where it was captured, while authentication templates are stored in the authentication module. This localized storage strategy improves reliability by eliminating transmission requirements while maintaining centralized authentication capability.
Solution Approach 2:
The patent implements a nested data structure where the biometric device contains locally stored captured data, which in turn references authentication templates stored in the authentication module. This nested arrangement allows the system to maintain both local and centralized storage benefits, improving reliability by reducing transmission needs while preserving centralized authentication management.
Data Source
AI summary
A biometric authentication system implementing a registration phase comprising: assigning a registered biometric device's identification information to a registered user; and storing, on a remote computer system, initial biometric data captured by the registered device, wherein the initial biometric data is stored on the registered device and on the remote system; and an access granting phase comprising receiving biometric device identification information from the registered device; determining that the received biometric device identification information matches the registered device's identification information assigned to the registered user; in response to determining that the received device identification information matches the registered device's identification information assigned to the registered user, instructing the registered device to re-capture the registered user's biometric data; comparing the re-captured biometric data of the registered user to the initial biometric data stored on the registered device; and based on the comparing, granting the registered user access to a resource.


