Biometric Authentication Device with Mutual Authentication and Counter-Based Stoppage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Biometric authentication methods using IC cards are vulnerable to security breaches as the authentication program can be easily altered, allowing unauthorized access and data falsification.
Innovation Solution
A biometric authentication device with a biometric information storage module, an authenticating module, a mutual authentication module, a registration counter, an authentication counter, and a stoppage flag that automatically stops the authentication process if validity is not authenticated, preventing unauthorized access and data leakage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If biometric information is stored in the IC card for individual authentication, then individual authentication capability is improved, but security is worsened because the authentication program can be easily altered and data can be falsified or stolen
Solution Approach 1:
The patent segments the authentication system into multiple independent modules: mutual authentication module (for verifying terminal and card validity), biometric information authenticating module (for verifying biometric data), authentication control module (for managing authentication flow), and data management module. Each module operates independently with specific security functions, preventing a single point of failure or compromise that could affect the entire system.
Solution Approach 2:
The patent implements preliminary mutual authentication between the terminal and IC card before allowing any biometric information registration or verification. The system pre-establishes validity confirmation through counter checks (authentication counter, registration counter) and stoppage flag verification, ensuring that only authenticated terminals can access biometric functions, thereby preventing unauthorized access before it occurs.
2Ease of operation
If authentication program is made accessible for biometric verification, then authentication functionality is improved, but vulnerability to program alteration and data theft is increased
Solution Approach 1:
The patent applies preliminary anti-action by implementing the mutual authentication module that proactively verifies terminal validity and checks authentication counters before allowing any authentication operations. The stoppage flag mechanism preemptively blocks further operations when unauthorized access attempts are detected, counteracting potential attacks before they can compromise the program or steal data.
Solution Approach 2:
The authentication control module serves as an intermediary between the terminal and the biometric authentication functions. It mediates all authentication requests by verifying the stoppage flag status and coordinating between mutual authentication results and biometric verification, preventing direct access to vulnerable program components and adding a protective layer that filters out unauthorized operations.
3Ease of operation
If multiple authentication attempts are allowed, then user convenience is improved, but security risk from repeated unauthorized access is worsened
Solution Approach 1:
The patent implements feedback mechanisms through authentication counters and registration counters that track the number of authentication attempts and operations. The authentication control module continuously monitors these counters and the stoppage flag status, providing feedback control that automatically stops further authentication attempts when thresholds are exceeded, thereby balancing user convenience with security by allowing reasonable attempts while blocking brute-force attacks.
Data Source
AI summary
A biometric authentication device has high security by preventing intra-device information from being falsified and stolen by a third party. A biometric authentication device includes a biometric information storage module, a biometric information authenticating module for individual authentication, a mutual authentication module with the terminal, a registration counter corresponding to the mutual authentication, an authentication counter corresponding to the biometric authentication, a stoppage flag set when the value of the counter is larger than a predetermined value, and authentication control module for preventing the module from operating depending on the stoppage flag.


