Biometric Authentication with Dynamic Private Key Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication methods, particularly those relying on biometric information, are vulnerable to hacking and misuse, necessitating a more secure approach that combines private key authentication with biometric verification for enhanced security.

Innovation Solution

A method and apparatus that utilize an information processing device to authenticate users through a combination of private key authentication and biometric information, where a matching ratio is calculated and compared to predetermined threshold values to update the private key and biometric authentication information, ensuring secure user verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric information is used for user authentication, then user-friendliness and security are improved, but the system becomes vulnerable to hacking and biometric information theft

Engineering Contradiction:
Improveauthentication securityVSAvoidbiometric information theft
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication system is segmented into multiple independent components: private key verification module and biometric verification module. The private key is stored separately in an information processing device while biometric data is stored in the authentication apparatus. This segmentation ensures that even if one component is compromised, the other remains secure, resolving the vulnerability to biometric information theft while maintaining authentication security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A code image serves as an intermediary carrier that transmits the private key from the information processing device to the authentication apparatus without exposing sensitive data. The code image acts as a secure mediator that enables key transmission while preventing direct access to the private key during the authentication process, thereby mitigating hacking risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If private key authentication is implemented, then security is enhanced, but the system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The information processing device performs multiple functions: it stores the private key, generates code images for key transmission, and communicates with the authentication apparatus. The authentication apparatus also serves dual purposes by verifying both the private key through code images and biometric information. This multi-functionality reduces the need for additional dedicated components, thereby limiting the increase in system complexity while maintaining enhanced security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Instead of transmitting the actual private key directly, the system creates and transmits a code image that represents or encodes the private key information. This copying approach allows the authentication apparatus to verify the private key without ever receiving or storing the actual sensitive data, simplifying the security architecture while maintaining strong authentication capabilities.

Inventive Principle:
Principle #26Copying

3Speed

If biometric information is stored digitally for authentication, then authentication speed is improved, but the risk of hacking and misuse increases

Engineering Contradiction:
Improveauthentication speedVSAvoidhacking risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The authentication system segments sensitive data storage across two separate locations: the private key is stored in the information processing device (mobile device) while biometric information is stored in the authentication apparatus. This physical and logical segmentation ensures that even if the authentication apparatus is hacked, the private key remains secure in the mobile device, thereby reducing hacking risk while maintaining fast digital authentication speed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system adds a new dimension to authentication by combining two different authentication factors (private key and biometric data) that exist in separate dimensions or locations. This multi-dimensional approach ensures that hackers would need to compromise both dimensions simultaneously, significantly increasing security while the system maintains the speed benefits of digital authentication through efficient verification processes.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS10091196B2Method and apparatus for authenticating user by using information processing device
Publication Date: 2018.10.02 SUPREMA HQ INC
  • US10091196B2 patent drawing
  • US10091196B2 patent drawing
  • US10091196B2 patent drawing

AI summary

A method and apparatus for authenticating a user is disclosed that includes measuring biometric information of the user to create biometric measurement information, determining whether a private key included in a user authentication request signal matches a private key issued in advance to the user, comparing pre-set biometric authentication information for the user with the biometric measurement information, calculating a matching ratio when a match is detected, authenticating the user having provided the biometric information as an authorized user based on a result of comparison of the calculated matching ratio with a pre-determined biometric authentication threshold value, and providing an updated private key to the information processing device based on a result of comparison of the calculated matching ratio with a pre-determined updated threshold value.