Biometric Authentication Data Migration via Public Key Copying
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for data migration in user authentication systems, particularly those using biometric information, face challenges in seamlessly transferring authentication data between devices due to the secure storage of unique information in tamper-resistant regions, making it difficult to continuously use services after device changes without re-registration.
Innovation Solution
A method involving a user authentication system with a first information processing apparatus having a tamper-resistant storage region and a second apparatus with communication capabilities, where authentication requests are processed using signature data generated with secret keys, allowing for secure data migration and registration of new authentication information on the second device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication information is stored in a tamper-resistant storage region, then security against information leakage is improved, but data migration between devices becomes difficult
Solution Approach 1:
The patent creates a copy of the authentication function by generating a public key that can be stored outside the tamper-resistant region. This public key copy enables authentication on new devices without compromising the security of the original secret key stored in the secure region, thus allowing data migration while maintaining security.
Solution Approach 2:
The patent introduces a public key as an intermediary element that mediates between the secure secret key stored in the tamper-resistant region and the need for authentication on new devices. The public key acts as a bridge that enables migration without exposing the secret key.
2Reliability
If biometric information is used for authentication, then information leakage risk is reduced, but re-registration is required when changing devices
Solution Approach 1:
The patent performs preliminary action by generating and distributing the public key before device migration occurs. This allows the authentication system to be pre-configured on new devices, eliminating the need for time-consuming re-registration processes while maintaining biometric security.
Solution Approach 2:
The patent copies the authentication capability to new devices through public key distribution. Instead of requiring complete re-registration, the system copies the necessary public key information to enable immediate authentication on new devices while the original biometric data remains securely stored.
3Reliability
If authentication data is securely managed in tamper-resistant storage, then authentication security is improved, but service continuity after device replacement becomes difficult
Solution Approach 1:
The patent makes the authentication system universal by creating a public key that can function across multiple devices. The public key serves multiple functions: it enables authentication on new devices, maintains security through cryptographic pairing with the secret key, and ensures service continuity without requiring device-specific configurations.
Solution Approach 2:
The patent copies the authentication functionality to new devices through public key distribution. This allows the same authentication service to continue working on different devices while the original secret key remains securely stored in the tamper-resistant region of the original device.
Data Source
AI summary
The present disclosure provides a system in which a migration operation which is different from a normal registration operation performed on a system is started in one of a terminal before replacement and a terminal after the replacement so that a registration operation performed on the terminal after the replacement is easily completed only by causing a user to consecutively perform an authentication operation on both of the terminals.


