Biometric Authentication System with Secondary Device Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication systems using biological information face security risks due to the possibility of incorrect user authentication results, particularly when relying solely on biological data from devices not registered with a secondary authentication system.
Innovation Solution
An authentication system comprising a first device that acquires biological information and a second device that communicates with the first, performing additional authentication if the first device is not registered, ensuring user authentication through a combination of biological data and optional secondary verification methods like question-answer pairs, to enhance security and convenience.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If user authentication is performed solely based on biological information from any device, then convenience is improved for multiple users, but security deteriorates due to risk of incorrect authentication results
Solution Approach 1:
The authentication system is segmented into two independent authentication processes: first authentication based on biological information from the first device, and second authentication based on the authentication result from the first device. This segmentation allows the system to maintain both convenience (through biological authentication) and security (through additional verification layers) by dividing the authentication flow into distinct stages with different security requirements.
Solution Approach 2:
The system performs preliminary registration of the first device's identification information in the second device before authentication occurs. This preliminary action establishes a trusted relationship between devices, allowing the system to later determine whether to apply additional authentication measures based on whether the first device is registered, thereby balancing convenience and security proactively.
2Reliability
If additional authentication is performed when the first device is not registered, then security is improved, but device complexity increases
Solution Approach 1:
The authentication requirement dynamically adjusts based on the registration status of the first device. When the device is registered, only standard authentication is required. When not registered, additional authentication is automatically imposed. This dynamic approach allows the system to maintain security while avoiding unnecessary complexity for trusted devices, optimizing the balance between security and simplicity based on real-time conditions.
Solution Approach 2:
The second device acts as an intermediary that receives and verifies authentication results from the first device. It mediates between the biological authentication performed by the first device and the final access control decision, adding a layer of verification without requiring complex changes to the first device itself. This intermediary role centralizes the security logic in one component.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
An authentication system (100) that executes user authentication processing in accordance with an authentication request includes at least one first device (10). The first device (10) has a biological information acquiring unit (12) that is configured to acquire biological information of a user, and a first authentication unit (13) that outputs an authentication result of which the user is authenticated, based on the biological information. The authentication system includes a second device (20) that is configured to communicate with the first device (10). The second device (20) has an information acquiring-storing unit (21) that is able to store identification information of the first device (10) beforehand, a determination unit (22) that is configured to determine whether the first device (10) is registered, and a second authentication unit (23) that is configured to perform user authentication, in accordance with an authentication result output by the first authentication unit (13), when the determination unit (22) determines that the first device (10) is registered.