Biometric Authentication with Attribute Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems in information security often lack seamless integration of privilege and identity authentication, leading to potential inaccuracies and unreliabilities in managing user access and privileges.

Innovation Solution

A method and system that combines biometric authentication with attribute-based privilege management by using attribute certificates and biometric certificates, where biometric feature data is matched against biometric identification parameters to determine security levels and authenticate user access, ensuring a corresponding relation between privilege and identity authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If only privilege authentication or identity authentication is performed separately, then the authentication process is simpler, but the accuracy and reliability of authentication are reduced

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines privilege authentication (PMI) and identity authentication (PKI) into a unified authentication system. The attribute certificate and biometric certificate are integrated to perform both types of authentication simultaneously, ensuring that both privilege authorization and identity verification are conducted together to improve authentication reliability without significantly increasing system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The authentication system is designed to perform multiple functions: it can conduct privilege authentication, identity authentication, or both together depending on the configuration. The service providing unit can flexibly select which authentication type to perform based on the certificate types available, making the system universally applicable to different authentication scenarios.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If high security levels are applied to all attributes, then information security is improved, but the ease of operation and user convenience are reduced

Engineering Contradiction:
Improveinformation securityVSAvoiduser access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies different security levels to different attributes based on their sensitivity and importance. The service providing unit determines the security level for each attribute individually, allowing high security measures for critical attributes while using lower security measures for less sensitive attributes, thereby balancing information security with user convenience.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The security level application is dynamic rather than static. The service providing unit can adjust the security level and authentication strictness based on the specific attribute being accessed, the user's privileges, and the current authentication context. This allows the system to adapt security measures to the actual risk level of each access request.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2214342B1Method and system for implementing authentication on information security
Publication Date: 2014.06.18 HUAWEI TECH CO LTD
  • EP2214342B1 patent drawingFigure 1~2
  • EP2214342B1 patent drawingFigure 3~4
  • EP2214342B1 patent drawingFigure 5

AI summary

Methods and systems for implementing authentication on information security are disclosed, and the process includes: receiving, from a user, an access request which carries an attribute certificate, wherein different security levels are set for attributes with different privileges in the attribute certificate; acquiring a biometric algorithm certificate which records corresponding relations between security levels and one or more biometric identification parameters; determining, based on the privilege of an attribute in the attribute certificate, the security level of the attribute, and acquiring the one or more biometric identification parameters corresponding to the security level; acquiring a biometric certificate and biometric feature data of the user to perform identity authentication, and determining whether a match degree between the biometric feature data and the biometric certificate meets a requirement set forth by the one or more biometric identification parameters (606) ; performing privilege authentication based on the attribute certificate; and controlling user access based on results of the identity authentication and privilege authentication. A corresponding relation is established between the privilege authentication and the identity authentication so that the privilege management can be performed accurately and reliably.