Biometric Authentication Server Architecture for Secure Portable Objects
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Biometric authentication systems that store and compare signatures on chip cards are vulnerable to hacking and have high complexity and cost, making them unsuitable for low-cost mass production and secure authentication.
Innovation Solution
Transferring the creation, storage, and comparison of signatures to an authentication server, where biometric samples are encrypted and compared securely, eliminating the need for non-encrypted data transfer and reducing the complexity and cost of portable objects.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If verification is implemented in the chip card reader with signatures stored in the reader, then authentication can be performed locally, but the signatures are vulnerable to hacking, alteration and fraudulent reuse
Solution Approach 1:
The patent extracts the signature creation and storage functions from the terminal device and relocates them to a remote authentication server. The terminal only captures biometric samples and transmits encrypted data, while the server generates and stores signatures securely, preventing local hacking and fraudulent reuse at the terminal.
Solution Approach 2:
The patent introduces an authentication server as an intermediary between the terminal and the biometric data. The server acts as a secure mediator that receives encrypted biometric samples, creates signatures, and verifies authentication requests, eliminating the need for the terminal to store or handle plain biometric data.
2Reliability
If the chip card itself carries out verification with substantial calculating power and means of memorization, then signatures do not leave the card, but the complexity and cost increase making it incompatible with low-cost mass production
Solution Approach 1:
The patent segments the authentication system into three distinct components: the portable object with minimal biometric capture capability, the terminal with encryption functions, and the remote authentication server with signature creation and storage. This segmentation allows each component to have appropriate complexity levels, with the portable object remaining simple and low-cost while security-critical functions reside on the server.
Solution Approach 2:
The patent uses encryption to create a secure copy of the biometric sample that can be transmitted without exposing the original data. The encrypted biometric sample serves as a safe intermediary that preserves authentication capability while eliminating security risks associated with transmitting or storing plain biometric data.
3Reliability
If the portable object transmits biometric samples to the authentication server, then security is enhanced by preventing local storage, but data transmission requires secure encryption to prevent interception
Solution Approach 1:
The patent applies preliminary encryption to the biometric sample before transmission. The terminal encrypts the biometric data captured from the portable object before sending it to the authentication server, ensuring that even if the transmission is intercepted, the data remains secure. This preliminary security measure simplifies the overall system architecture compared to requiring the portable object to perform complex verification operations.
Data Source
AI summary
A biometric authentication method and apparatus are provided. A user to be authenticated uses a portable object including at least one biometric sensor. The portable object is adapted to cooperate with a terminal. The method includes: capturing, by the portable object, a biometric sample to be compared coming from the user to be authenticated; transmitting, by the portable object, the biometric sample, in a secure form to an authentication server; and determining, by the authentication server, a signature to be authenticated using said biometric sample, then comparing the signature with a reference signature.


