Biometric Authentication System for Secure Web Service Execution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for using web services, such as print services, require inefficient repetitive operations for authentication and function execution, as they do not leverage biometric authentication to streamline user interactions.
Innovation Solution
A system that includes an information processing apparatus with biometric authentication capabilities, storing biometric information and secret keys, and a server managing public keys, allowing for biometric authentication and signature creation for secure and efficient execution of web service functions without network exposure of sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric authentication is implemented for web services, then security is improved, but operability deteriorates due to required repetitive settings and operations
Solution Approach 1:
The system performs preliminary registration of biometric information and associated operations during an initial setup phase. The server stores multiple pieces of biometric information along with their corresponding operation settings in advance. During subsequent authentication, the system automatically selects and executes the appropriate pre-registered operation based on the authenticated biometric information, eliminating the need for users to repeatedly perform setup operations.
2Adaptability or versatility
If multiple biometric information pieces are registered for different functions, then functionality is improved, but device complexity increases
Solution Approach 1:
The server acts as an intermediary that manages the complexity of storing and managing multiple biometric information pieces and their associated operations. Instead of requiring the information processing apparatus to handle complex registration and management logic, the server receives authentication results from the apparatus and autonomously selects and executes the appropriate operation based on the authenticated biometric information. This distributes complexity from the client device to the server.
Data Source
AI summary
An MFP stores a plurality of different pieces of biometric information of a user and a plurality of secret keys respectively corresponding to the pieces of biometric information in the TPM and registers public keys corresponding to the private keys in a server. When an authentication request is received from the server, the MFP executes a biometric authentication process using the biometric information input from the user and the biometric information registered in the TPM. If authentication is successful in the biometric authentication process, the MFP creates signature data and transmits it to the server. If verification of the signature data using the public key in the server is successful, the MFP performs display related to a shortcut process associates with the biometric information corresponding to the secret key used when the signature data that is a target of the verification is created by an input and output device.


