Biometric Authentication for Secure Email Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current electronic mail (e-mail) security systems are inadequate in preventing fraudulent access by imposters, as users cannot effectively control who accesses their e-mail messages after transmission, and existing authentication methods can be compromised, leading to inadequate protection against unauthorized access and inadvertent distribution.
Innovation Solution
A system that includes a Biometric Authentication Computer (BAC) and a Control Computer (CC) to authenticate users, manage e-mail message security levels, and allow senders to control access and attributes of e-mail messages, using biometric data and configurable authentication policies to ensure secure access and prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional username and password authentication is used, then ease of operation is improved, but security against imposter access deteriorates
Solution Approach 1:
The patent introduces an intermediary authentication system that mediates between the user and the email system. This intermediary verifies the user's identity through multiple factors (username, password, and additional verification steps) before granting access, thereby maintaining ease of operation for legitimate users while significantly improving security against imposters.
Solution Approach 2:
The system performs preliminary authentication actions before allowing email access. Users must complete verification steps (such as entering security codes, answering security questions, or providing biometric data) before they can access their email accounts. This preliminary action prevents imposters from gaining access even if they obtain credentials.
2Reliability
If secret PINs are used for decryption, then security is improved, but vulnerability to imposter acquisition deteriorates
Solution Approach 1:
The patent changes the parameter of authentication from a single static secret (PIN) to multiple dynamic factors. Instead of relying solely on a secret PIN that can be acquired by imposters, the system incorporates additional verification parameters such as security codes, answers to security questions, or biometric data, making it significantly harder for imposters to gain access.
Solution Approach 2:
The authentication process is segmented into multiple independent verification steps. Rather than using a single PIN, the system divides authentication into separate factors (something the user knows, something the user has, or something the user is), where each segment must be successfully verified. This segmentation prevents imposters from compromising the entire system by obtaining just one secret.
3Adaptability or versatility
If message forwarding is restricted, then sender control is improved, but ability to share messages deteriorates
Solution Approach 1:
The patent implements dynamic control over message forwarding and sharing. Instead of static restrictions, the system allows senders to dynamically adjust sharing permissions based on various conditions (such as recipient identity, time limits, or specific purposes). This dynamic approach maintains strong sender control while still enabling legitimate message sharing when appropriate.
Solution Approach 2:
The system incorporates feedback mechanisms that allow senders to monitor and control message distribution after sending. Senders receive feedback about who has accessed or forwarded their messages and can intervene to revoke permissions or take corrective actions, thereby maintaining control while allowing flexible sharing.
Data Source
AI summary
A method for accessing e-mail messages from a control system includes requesting access to e-mail message contents of a user stored in the control system, determining whether the user is enrolled in and activated by the control system, and authenticating the user when the user is enrolled in and activated by the control system. Moreover, the method includes permitting the user to view a list of e-mail messages when the user is successfully authenticated. The e-mail messages included in the list are associated with the user. Furthermore, the method includes permitting the user to access the contents of e-mail messages in the list having a security level equal to or less than a security level associated with the successful authentication.


