Multi-Verification Biometric Authorization Token System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In distributed computing environments, the sharing of authentication credentials introduces network security issues due to vulnerabilities in authentication mechanisms, allowing cyber attackers to fraudulently obtain and utilize credentials, leading to potential impersonation and data breaches.
Innovation Solution
Implementing secure multi-verification of biometric data by generating and verifying authorization tokens based on biometric data from multiple modalities, including facial scans, fingerprint scans, and voice samples, along with provenance data to ensure the authenticity and integrity of the authorization process, thereby enhancing network security and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If authentication credentials are shared in a distributed computing environment, then users can access resources from multiple devices, but network security is compromised and attackers can fraudulently obtain and utilize credentials
Solution Approach 1:
The patent segments the authentication process into multiple independent verification stages: device verification, biometric verification, and authorization token verification. Each stage operates independently and contributes to the overall security decision, preventing single-point failures and reducing the risk of fraudulent access.
Solution Approach 2:
The patent introduces an intermediary verification system that acts as a mediator between the user's devices and the network resources. This intermediary performs provenance verification and multi-factor authentication, preventing direct credential sharing while enabling controlled access through multiple verification layers.
2Ease of operation
If traditional authentication mechanisms are used, then the system is simple to operate, but the system is vulnerable to credential theft and impersonation
Solution Approach 1:
The patent changes the authentication parameters from simple credential verification to multi-factor verification including device provenance, biometric data, and authorization tokens. This parameter expansion maintains ease of operation for legitimate users while significantly increasing resistance to fraudulent attacks.
Solution Approach 2:
The patent creates a composite authentication mechanism that combines multiple verification methods (device verification, biometric verification, token verification) into a unified security framework. This composite approach maintains user convenience while providing robust protection against various attack vectors.
3Reliability
If multi-verification of biometric data is implemented, then network security is significantly improved, but the authentication process becomes more complex
Solution Approach 1:
The patent performs preliminary verification of device provenance and authorization tokens before initiating biometric verification. This preliminary action reduces the overall complexity by pre-filtering legitimate requests and only subjecting them to full multi-verification, rather than applying complex verification to all requests equally.
Solution Approach 2:
The patent implements self-service mechanisms where devices automatically verify their own provenance and generate authorization tokens without user intervention. The biometric verification process is streamlined to work automatically, reducing the perceived complexity for users while maintaining high security standards.
Data Source
AI summary
Disclosed are example methods, systems, and devices that allow for secure multi-verification of biometric data in a distributed computing environment. The techniques include receiving a request to grant authorization to a second user. The request can include biometric data of the first user and second user. An authorization token can be generated based on the request, which can be transmitted to a second computing device of the second user. A second request can be received from a third computing device that includes the authorization token and third biometric data. The second request can be verified based on the authorization token, the third biometric data, and provenance data, and an indication that the grant of authorization to the second user is verified can be transmitted to the first, second, or third computing devices.


