Biometric Authentication Secure Element PIN Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multi-factor authentication methods are vulnerable to interception of Personal Identification Numbers (PINs) during transmission between devices, as they are often sent in clear text or encrypted forms, providing opportunities for attackers to intercept the PIN.

Innovation Solution

A method and apparatus that uses a biometric input device to encrypt and decrypt a PIN associated with an identity verification element, reducing the need for manual PIN entry and minimizing transmission vulnerabilities by employing a cryptographic key generated from biometric data for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a PIN is transmitted between multiple software and hardware components during authentication, then the authentication process can be completed, but the number of opportunities for attackers to intercept the PIN increases

Engineering Contradiction:
Improveauthentication processVSAvoidPIN interception risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the PIN transmission from the traditional multi-component software/hardware chain and relocates it to a dedicated secure element (smart card or token). This isolation removes the PIN from the vulnerable transmission paths between UI components, kernel, and secure device, thereby eliminating interception opportunities while preserving authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a secure element (smart card or token) as an intermediary between the user and the authentication system. This intermediary stores the PIN securely and handles authentication locally, preventing the PIN from being transmitted through vulnerable software components. The secure element mediates the authentication process, eliminating the need for PIN transmission through the operating system's component chain.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the PIN is transmitted in encrypted form, then security is improved, but the complexity of the transmission system increases

Engineering Contradiction:
ImprovesecurityVSAvoidtransmission system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the encryption/decryption functionality from the transmission system and relocates it to a dedicated secure element. The secure element contains the cryptographic keys and performs all security operations locally, eliminating the need for complex encryption mechanisms in the software transmission layer. This simplifies the overall system while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If multiple components are involved in PIN transmission, then the authentication functionality is achieved, but the vulnerability surface for attacks increases

Engineering Contradiction:
Improveauthentication functionalityVSAvoidattack surface
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication functionality from the distributed software component model and consolidates it within a secure element. This extraction removes the vulnerability surface associated with multiple software components (UI, kernel, application layers) while preserving the essential authentication functionality. The secure element provides a single, isolated point of authentication that cannot be attacked through the software transmission paths.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9262616B2Simplified multi-factor authentication
Publication Date: 2016.02.16 MALIKIE INNOVATIONS LTD
  • US9262616B2 patent drawing
  • US9262616B2 patent drawing
  • US9262616B2 patent drawing

AI summary

A reader element is associated with an identity verification element. The reader element has a biometric input device and is configured, through enrollment of a biometric element is used to encrypt a character sequence associated with the identity verification element. In a verification phase subsequent to the enrollment, a user may be spared a step of providing the character sequence by, instead, providing the biometric element. Responsive to receiving the biometric element, the reader element may decrypt the character sequence and provide the character sequence to the identity verification element.