Biometric Authenticated Key Exchange Protocol for Mutual Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional authentication systems rely heavily on passwords and TLS protocols, which are vulnerable to phishing attacks and require personal digital certificates, limiting their ability to achieve mutual and multi-factor authentication efficiently.
Innovation Solution
The Biometrics-based Authenticated Key Exchange (B-AKE) protocol extracts knowledge data from biometric samples to establish a shared secret key for secure communication, using a combination of biometric and password data to provide mutual and multi-factor authentication without revealing credentials to imposters, leveraging symmetric encryption for faster and more secure key exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authentication systems use passwords and TLS protocols, then authentication can be achieved, but the systems are vulnerable to phishing attacks and require personal digital certificates, limiting their ability to achieve mutual and multi-factor authentication efficiently
Solution Approach 1:
The patent combines multiple authentication factors (biometric data, password data, and possession data) into a unified authentication mechanism. The system merges these different factor types into a single multi-factor authentication process that achieves mutual authentication between user and service provider without requiring complex separate protocols for each factor type.
Solution Approach 2:
The authentication system is designed to handle multiple authentication factors (something you are, something you know, something you have) through a universal protocol. This multi-functional system can process biometric samples, password verification, and device possession verification within a single authentication framework, eliminating the need for separate authentication mechanisms for each factor type.
2Reliability
If TLS protocols with personal digital certificates are used, then secure communication can be established, but processing power requirements increase and PKI support is required
Solution Approach 1:
The patent extracts the essential security functionality from complex TLS protocols and digital certificate systems. Instead of relying on full PKI infrastructure and heavy cryptographic protocols, the system extracts and implements only the necessary mutual authentication and key exchange mechanisms through a simplified protocol that maintains security while reducing computational overhead.
Solution Approach 2:
The system uses lightweight cryptographic operations and temporary session keys instead of heavy digital certificates and long-term PKI infrastructure. The authentication mechanism employs computationally efficient algorithms that provide adequate security without the high processing power requirements of traditional TLS with digital certificates.
3Reliability
If traditional authentication methods are used, then credentials must be protected from imposter access, but the ability to provide forward secrecy and prevent data breaches is limited
Solution Approach 1:
The system performs preliminary authentication and key exchange before any sensitive data transmission. Mutual authentication is established in advance, and session keys are generated and verified before credentials are exposed or data is transmitted, ensuring forward secrecy is built into the foundation of the communication rather than added as a later layer.
Data Source
AI summary
Various embodiments relate to a method performed by a processor of a computing system. An example method includes matching a possession object identifier with a stored user secret, generating a decryption key using the stored user secret as an input to a password authenticated key exchange protocol, decrypting an encrypted authentication data message using the decryption key, extracting a user secret from the biometric sample, authenticating the user by matching the extracted user secret with the stored user secret, and authenticating an identity of the user by matching the biometric sample with a biometric reference template associated with the possession object identifier.


