Biometric Authentication via Local Mobile Template Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for user authorization on servers lack a secure and efficient process for remote authentication using mobile electronic devices, particularly in accessing electronic services, often relying on bandwidth-intensive validation services and lacking robust biometric verification.

Innovation Solution

A method involving a mobile electronic device with a memory unit and sensor, coupled with an Identity Document Server, where biometric data is captured and transformed into a template for secure authentication, enabling access to servers through matching biometric data and templates, providing a 2-factor authentication mechanism.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If remote validation service is used for user authentication, then authentication can be performed remotely, but bandwidth usage increases and response time decreases

Engineering Contradiction:
Improveremote authentication capabilityVSAvoidbandwidth usage
Core Design Contradiction:
Ease of operationVSLoss of energy

Solution Approach 1:

The system performs preliminary actions by storing biometric templates locally on the user's mobile device during an initial enrollment phase. This allows the device to autonomously perform authentication by comparing new biometric data against stored templates without needing to contact remote validation services, thereby reducing bandwidth usage while maintaining remote authentication capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mobile device acts as an intermediary between the user and remote validation services. It captures biometric data, compares it locally against stored templates, and only communicates with remote servers when necessary (e.g., for initial template creation or verification of local authentication). This intermediary role reduces the frequency and volume of network communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If remote validation service is used for user authentication, then authentication can be performed remotely, but response time increases

Engineering Contradiction:
Improveremote authentication capabilityVSAvoidresponse time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-storing biometric templates on the user's mobile device during enrollment. This enables instant local comparison of new biometric data against stored templates, eliminating network latency and providing rapid authentication response times while still allowing remote authentication capability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication process is segmented into local and remote components. The time-critical biometric comparison operation is performed locally on the device using stored templates, while less time-sensitive functions (template creation, verification) are handled remotely. This segmentation isolates the performance-critical path from network dependencies.

Inventive Principle:
Principle #1Segmentation

3Reliability

If traditional authentication methods are used, then system complexity is reduced, but security is weakened

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system replaces traditional mechanical authentication methods (physical keys, cards, or simple passwords) with biometric authentication using fingerprint, facial recognition, or other physiological characteristics. This substitution enhances security by leveraging unique biological traits that are difficult to replicate, while the mobile device's built-in sensors and processors handle the complexity of biometric processing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the authentication parameter from something users can easily replicate (passwords, physical tokens) to something inherently unique and difficult to duplicate (biometric characteristics). The mobile device manages the complexity of capturing, processing, and comparing biometric data against stored templates, providing enhanced security without requiring users to understand or manage the underlying complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11228587B2Method, system, device and software programme product for the remote authorization of a user of digital services
Publication Date: 2022.01.18 IDEMIA CIVIL IDENTITY NA LLC
  • US11228587B2 patent drawing
  • US11228587B2 patent drawing
  • US11228587B2 patent drawing

AI summary

Disclosed is a method of authorizing a user for accessing a server and/or for receiving of an on-line service and the steps of: capturing biometric data of the user using the sensor on a ME; forming from the biometric data a biometric template on the IDS and storing the biometric template on the MED; and via the IDS allowing access to a server by the user providing to the IDS, via the MED, matching biometric data and a biometric template. On the MED, a local check can be made for a match between biometric data of the user that are captured using the sensor on the MED and biometric data read out of the memory.