Biometric Authentication Server Architecture for Secure Portable Objects

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Biometric authentication systems that store and compare signatures on chip cards are vulnerable to hacking and have high complexity and cost, making them unsuitable for low-cost mass production and secure authentication.

Innovation Solution

Transferring the creation, storage, and comparison of signatures to an authentication server, where biometric samples are encrypted and compared securely, eliminating the need for non-encrypted data transfer and reducing the complexity and cost of portable objects.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If verification is implemented in the chip card reader with signatures stored in the reader, then authentication can be performed locally, but the signatures are vulnerable to hacking, alteration and fraudulent reuse

Engineering Contradiction:
Improveauthentication securityVSAvoidhacking and fraudulent reuse
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the signature creation and storage functions from the terminal device and relocates them to a remote authentication server. The terminal only captures biometric samples and transmits encrypted data, while the server generates and stores signatures securely, preventing local hacking and fraudulent reuse at the terminal.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an authentication server as an intermediary between the terminal and the biometric data. The server acts as a secure mediator that receives encrypted biometric samples, creates signatures, and verifies authentication requests, eliminating the need for the terminal to store or handle plain biometric data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the chip card itself carries out verification with substantial calculating power and means of memorization, then signatures do not leave the card, but the complexity and cost increase making it incompatible with low-cost mass production

Engineering Contradiction:
Improveauthentication securityVSAvoidcalculating power and memorization means
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into three distinct components: the portable object with minimal biometric capture capability, the terminal with encryption functions, and the remote authentication server with signature creation and storage. This segmentation allows each component to have appropriate complexity levels, with the portable object remaining simple and low-cost while security-critical functions reside on the server.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses encryption to create a secure copy of the biometric sample that can be transmitted without exposing the original data. The encrypted biometric sample serves as a safe intermediary that preserves authentication capability while eliminating security risks associated with transmitting or storing plain biometric data.

Inventive Principle:
Principle #26Copying

3Reliability

If the portable object transmits biometric samples to the authentication server, then security is enhanced by preventing local storage, but data transmission requires secure encryption to prevent interception

Engineering Contradiction:
ImprovesecurityVSAvoidencryption capability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary encryption to the biometric sample before transmission. The terminal encrypts the biometric data captured from the portable object before sending it to the authentication server, ensuring that even if the transmission is intercepted, the data remains secure. This preliminary security measure simplifies the overall system architecture compared to requiring the portable object to perform complex verification operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8799670B2Biometric authentication method, computer program, authentication server, corresponding terminal and portable object
Publication Date: 2014.08.05 BANKS & ACQUIRERS INT HLDG SAS
  • US8799670B2 patent drawing
  • US8799670B2 patent drawing
  • US8799670B2 patent drawing

AI summary

A biometric authentication method and apparatus are provided. A user to be authenticated uses a portable object including at least one biometric sensor. The portable object is adapted to cooperate with a terminal. The method includes: capturing, by the portable object, a biometric sample to be compared coming from the user to be authenticated; transmitting, by the portable object, the biometric sample, in a secure form to an authentication server; and determining, by the authentication server, a signature to be authenticated using said biometric sample, then comparing the signature with a reference signature.