Biometric Authentication System with Secondary Device Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems using biological information face security risks due to the possibility of incorrect user authentication results, particularly when relying solely on biological data from devices not registered with a secondary authentication system.

Innovation Solution

An authentication system comprising a first device that acquires biological information and a second device that communicates with the first, performing additional authentication if the first device is not registered, ensuring user authentication through a combination of biological data and optional secondary verification methods like question-answer pairs, to enhance security and convenience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user authentication is performed solely based on biological information from any device, then convenience is improved for multiple users, but security deteriorates due to risk of incorrect authentication results

Engineering Contradiction:
ImproveconvenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system is segmented into two independent authentication processes: first authentication based on biological information from the first device, and second authentication based on the authentication result from the first device. This segmentation allows the system to maintain both convenience (through biological authentication) and security (through additional verification layers) by dividing the authentication flow into distinct stages with different security requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary registration of the first device's identification information in the second device before authentication occurs. This preliminary action establishes a trusted relationship between devices, allowing the system to later determine whether to apply additional authentication measures based on whether the first device is registered, thereby balancing convenience and security proactively.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If additional authentication is performed when the first device is not registered, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication requirement dynamically adjusts based on the registration status of the first device. When the device is registered, only standard authentication is required. When not registered, additional authentication is automatically imposed. This dynamic approach allows the system to maintain security while avoiding unnecessary complexity for trusted devices, optimizing the balance between security and simplicity based on real-time conditions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The second device acts as an intermediary that receives and verifies authentication results from the first device. It mediates between the biological authentication performed by the first device and the final access control decision, adding a layer of verification without requiring complex changes to the first device itself. This intermediary role centralizes the security logic in one component.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3503608B1Authentication system and authentication device
Publication Date: 2023.09.13 TOYOTA JIDOSHA KK
  • EP3503608B1 patent drawingFigure 1
  • EP3503608B1 patent drawingFigure 2~3
  • EP3503608B1 patent drawingFigure 4

AI summary

An authentication system (100) that executes user authentication processing in accordance with an authentication request includes at least one first device (10). The first device (10) has a biological information acquiring unit (12) that is configured to acquire biological information of a user, and a first authentication unit (13) that outputs an authentication result of which the user is authenticated, based on the biological information. The authentication system includes a second device (20) that is configured to communicate with the first device (10). The second device (20) has an information acquiring-storing unit (21) that is able to store identification information of the first device (10) beforehand, a determination unit (22) that is configured to determine whether the first device (10) is registered, and a second authentication unit (23) that is configured to perform user authentication, in accordance with an authentication result output by the first authentication unit (13), when the determination unit (22) determines that the first device (10) is registered.