Biometric Authentication with Attribute Certificates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication systems in information security often lack seamless integration of privilege and identity authentication, leading to potential inaccuracies and unreliabilities in managing user access and privileges.
Innovation Solution
A method and system that combines biometric authentication with attribute-based privilege management by using attribute certificates and biometric certificates, where biometric feature data is matched against biometric identification parameters to determine security levels and authenticate user access, ensuring a corresponding relation between privilege and identity authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If only privilege authentication or identity authentication is performed separately, then the authentication process is simpler, but the accuracy and reliability of authentication are reduced
Solution Approach 1:
The patent combines privilege authentication (PMI) and identity authentication (PKI) into a unified authentication system. The attribute certificate and biometric certificate are integrated to perform both types of authentication simultaneously, ensuring that both privilege authorization and identity verification are conducted together to improve authentication reliability without significantly increasing system complexity.
Solution Approach 2:
The authentication system is designed to perform multiple functions: it can conduct privilege authentication, identity authentication, or both together depending on the configuration. The service providing unit can flexibly select which authentication type to perform based on the certificate types available, making the system universally applicable to different authentication scenarios.
2Reliability
If high security levels are applied to all attributes, then information security is improved, but the ease of operation and user convenience are reduced
Solution Approach 1:
The patent applies different security levels to different attributes based on their sensitivity and importance. The service providing unit determines the security level for each attribute individually, allowing high security measures for critical attributes while using lower security measures for less sensitive attributes, thereby balancing information security with user convenience.
Solution Approach 2:
The security level application is dynamic rather than static. The service providing unit can adjust the security level and authentication strictness based on the specific attribute being accessed, the user's privileges, and the current authentication context. This allows the system to adapt security measures to the actual risk level of each access request.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
Methods and systems for implementing authentication on information security are disclosed, and the process includes: receiving, from a user, an access request which carries an attribute certificate, wherein different security levels are set for attributes with different privileges in the attribute certificate; acquiring a biometric algorithm certificate which records corresponding relations between security levels and one or more biometric identification parameters; determining, based on the privilege of an attribute in the attribute certificate, the security level of the attribute, and acquiring the one or more biometric identification parameters corresponding to the security level; acquiring a biometric certificate and biometric feature data of the user to perform identity authentication, and determining whether a match degree between the biometric feature data and the biometric certificate meets a requirement set forth by the one or more biometric identification parameters (606) ; performing privilege authentication based on the attribute certificate; and controlling user access based on results of the identity authentication and privilege authentication. A corresponding relation is established between the privilege authentication and the identity authentication so that the privilege management can be performed accurately and reliably.