Biometric Authentication System with Dynamic Profile Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In open network environments, biometric authentication systems face challenges with convenience and adaptability due to difficulties in determining the appropriate entity device for authentication, handling device mounting/demounting, selecting suitable devices, presenting compatible services, setting desired security levels, and managing varying service levels, leading to inefficient and inconvenient user experiences.

Innovation Solution

An authentication system comprising multiple entity devices capable of executing biometric authentication subprocesses, a client device, and an authentication device that manages service-compatible profiles, dynamically selects and verifies entity devices, and adapts to user environments, enabling flexible authentication and service provision.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If biometric authentication is implemented in open network environments, then user convenience is improved, but adaptability to varying execution environments deteriorates

Engineering Contradiction:
Improveuser convenienceVSAvoidadaptability to execution environment
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic profile verification where the authentication system adapts to different execution environments by verifying device profiles against service requirements in real-time. The system dynamically determines whether to proceed with authentication based on environmental compatibility, making the biometric authentication system both convenient and adaptable to varying network conditions and device capabilities.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If multiple entity devices are allowed for authentication, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improvedevice selection flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into distinct functional modules: profile verification module, device detection module, authentication module, and service provision module. This segmentation allows multiple entity devices to be supported while managing system complexity through modular architecture, where each module handles specific aspects of the authentication process independently.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a profile verification module as an intermediary between the authentication device and multiple entity devices. This intermediary verifies device profiles and determines compatibility with service requirements, simplifying the interaction between multiple devices and the authentication system while maintaining adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If profile verification is performed for each service, then service compatibility is improved, but processing time increases

Engineering Contradiction:
Improveservice compatibilityVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs profile verification as a preliminary action before authentication processing. By verifying device profiles against service requirements in advance and determining environmental compatibility beforehand, the system ensures service compatibility while streamlining the subsequent authentication process, reducing overall processing time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP1785907B1Authentication system, device, and program
Publication Date: 2019.06.05 KK TOSHIBA
  • EP1785907B1 patent drawingFigure 1
  • EP1785907B1 patent drawingFigure 2
  • EP1785907B1 patent drawingFigure 3

AI summary

A client device transmits service identification information to an authentication device (10) at the time of a service request, prompts selection of one or more authentication entity devices which execute one or more authentication subprocesses from among all the authentication entity devices adaptive to profile information received from the authentication device, based on "function list information defining an execution environment of each of the authentication entity devices (50, 60, 70)", transmits a request for executing an authentication subprocess to such selected each authentication entity device, and transmits to the authentication device "authentication context information including an execution environment and an execution result of an authentication subprocess" received from such each authentication entity device.