Biometric Authentication System with One-Time Pass-Phrase Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing user authentication methods over networks are inadequate in preventing fraudulent transactions due to password misuse and sophisticated techniques like phishing, leading to increased risks for sensitive information and resources.
Innovation Solution
A biometric authentication system that stores user data and generates one-time pass-phrases, using a communications device to capture and verify biometric data, ensuring secure access to protected resources by separating the authentication system from the server and using a distinct communications channel for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional username and password authentication is used, then users can access websites easily, but security against fraudulent transactions is insufficient
Solution Approach 1:
The authentication system is divided into separate components: a server system for managing protected resources and an authentication system for verifying user identities. This segmentation allows each system to specialize in its function, improving both ease of access (server handles resource management) and security (authentication system handles verification).
Solution Approach 2:
The patent introduces an authentication system as an intermediary between users and protected resources. This intermediary verifies user identities through a challenge-response mechanism using cryptographic protocols, preventing fraudulent access while maintaining legitimate user access. The intermediary validates transactions without requiring users to directly trust the resource server.
2Reliability
If biometric authentication system is implemented, then security against fraud is improved, but system complexity increases
Solution Approach 1:
The patent replaces complex mechanical biometric authentication hardware with a software-based cryptographic authentication system. Instead of using fingerprint scanners, facial recognition cameras, or other biometric devices, the system uses cryptographic challenge-response protocols that can be implemented through standard communication channels, significantly reducing system complexity while maintaining high security.
Solution Approach 2:
The authentication system creates cryptographic copies of user credentials that can be verified without exposing the original credentials. The server stores cryptographic representations of user identities and uses these to verify authentication challenges, avoiding the need for complex biometric storage and comparison systems.
3Reliability
If authentication system is separated from server, then security is enhanced, but communication requirements increase
Solution Approach 1:
The authentication system is designed to work with multiple types of protected resources across different servers and applications. The challenge-response protocol and cryptographic verification methods are universally applicable to various resource types (financial accounts, medical records, military systems), allowing a single authentication infrastructure to serve multiple functions and reducing overall communication requirements.
Data Source
AI summary
A method of authenticating users to reduce transaction risks includes indicating a desire to conduct a transaction and determining whether the transaction requires access to protected resources. Moreover, the method determines whether inputted information is known, determines a state of a communications device when the inputted information is known, and transmits a biometric authentication request from a server to an authentication system when the state of the communications device is enrolled. Additionally, the method includes validating the communications device, capturing biometric authentication data in accordance with a biometric authentication data capture request with the communications device, biometrically authenticating the user, generating a one-time pass-phrase and storing the one-time pass-phrase on the authentication system when the user is authenticated, comparing the transmitted one-time pass-phrase against the stored one-time pass-phrase, and granting access to the protected resources when the transmitted and stored one-time pass-phrases match.


