Biometric Authentication System with One-Time Pass-Phrase
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods for network-based transactions are inadequate in preventing fraudulent activities due to password misuse and sophisticated techniques like phishing, leading to increased risks for users and entities.
Innovation Solution
A biometric authentication system that stores user data and generates a one-time pass-phrase, using a communications device to verify identity through biometric data capture and comparison, thereby enhancing security and reducing transaction risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional password-based authentication is used, then ease of operation is improved, but security and reliability deteriorate due to password misuse and phishing attacks
Solution Approach 1:
The patent introduces a biometric authentication intermediary system that mediates between the user and the network resource. The biometric data (fingerprint, iris, facial recognition) serves as an intermediary verification layer that is neither easily hackable like passwords nor requiring complex token hardware. This intermediary biometric verification process significantly enhances authentication security while maintaining ease of operation, as users simply provide biometric data without needing to remember passwords or carry additional devices.
2Reliability
If biometric authentication system is implemented, then security and reliability are improved, but device complexity increases due to multiple systems and communications channels
Solution Approach 1:
The patent segments the authentication system into distinct functional components: a biometric data capture module, a biometric template storage system, a verification engine, and a communications interface. Each component performs a specific function and can be independently managed. The system separates the biometric authentication process into enrollment (capturing and storing biometric templates) and verification (comparing live biometric data against stored templates) phases. This segmentation reduces overall system complexity by making each component manageable and interchangeable.
Solution Approach 2:
The biometric authentication system is designed with universal applicability across multiple platforms and devices. The same biometric template stored in the authentication system can verify identity across different workstations, mobile devices, and network resources. The system accepts multiple biometric modalities (fingerprint, iris, facial recognition) that can serve the same authentication purpose, providing multi-functionality that reduces the need for device-specific authentication solutions and thereby reduces overall system complexity.
3Reliability
If one-time pass-phrase generation is used, then security is improved against fraudulent transactions, but loss of time increases due to additional authentication steps
Solution Approach 1:
The system performs preliminary biometric authentication before generating or requiring a one-time pass-phrase. By verifying the user's biometric identity first, the system establishes a trusted context that accelerates subsequent authentication steps. The biometric verification creates a pre-authenticated state where the one-time pass-phrase generation or verification becomes a rapid confirmation process rather than a full authentication sequence. This preliminary biometric action significantly reduces the time penalty associated with enhanced security measures.
Data Source
AI summary
A method of authenticating users to reduce transaction risks includes indicating a desire to conduct a transaction and determining whether the transaction requires access to protected resources. Moreover, the method determines whether inputted information is known, determines a state of a communications device when the inputted information is known, and transmits a biometric authentication request from a server to an authentication system when the state of the communications device is enrolled. Additionally, the method includes validating the communications device, capturing biometric authentication data in accordance with a biometric authentication data capture request with the communications device, biometrically authenticating the user, generating a one-time pass-phrase and storing the one-time pass-phrase on the authentication system when the user is authenticated, comparing the transmitted one-time pass-phrase against the stored one-time pass-phrase, and granting access to the protected resources when the transmitted and stored one-time pass-phrases match.


