Biometric Authentication for Secure Data Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic communication devices rely on encryption keys for data security, but these keys can be compromised, and device authentication does not guarantee the authorization of users, leading to potential fraudulent data access or transmission.
Innovation Solution
A method involving multiple levels of user-identity authentication using biometric information, where one user's biometric data is encrypted and verified through a central server before data exchange, ensuring both device and user authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If encryption keys are used for data security, then data confidentiality is improved, but security reliability deteriorates because keys can be compromised by unauthorized users
Solution Approach 1:
The patent introduces a central server as an intermediary that stores and manages biometric templates and identity profiles. Instead of relying solely on encryption keys stored in devices, the system uses the central server to verify user identities by comparing biometric data against stored templates. This mediator approach shifts the security burden from device-stored keys to a centralized authentication authority, reducing the risk of key compromise.
Solution Approach 2:
The patent replaces the mechanical/crypto-based encryption key system with a biometric-based authentication system. Instead of using encryption keys that can be stolen or compromised, the system uses unique physiological characteristics (fingerprints, facial recognition, iris patterns) that are difficult to replicate. The biometric data is converted into templates and stored securely on the central server, substituting the traditional key-based security mechanism with a more reliable biometric verification process.
2Reliability
If device authentication is implemented, then authorized devices can communicate, but user authorization cannot be guaranteed as unauthorized users may control authorized devices
Solution Approach 1:
The patent replaces device-based authentication with user-based biometric authentication. Instead of verifying only the device's identity through cryptographic credentials, the system captures biometric data from the user (such as fingerprint scans or facial recognition) and verifies it against the user's stored template on the central server. This ensures that the person using the authorized device is indeed the authorized user, preventing unauthorized users from exploiting legitimate devices.
Solution Approach 2:
The patent implements preliminary biometric verification before data exchange occurs. The system captures the user's biometric data, converts it to a template, and verifies it against the stored template in advance of the actual data transaction. This preliminary authentication step ensures user identity is confirmed before any sensitive operations take place, preventing fraudulent access attempts.
3Reliability
If biometric authentication is added to verify user identity, then user authorization reliability is improved, but system complexity increases due to multiple authentication levels
Solution Approach 1:
The patent implements a universal biometric authentication framework that can work across different devices and applications. The central server stores biometric templates and identity profiles that can be used for various types of data exchanges (messaging, file transfer, video calls). The same authentication mechanism serves multiple security purposes: verifying user identity, authorizing data access, and preventing fraudulent transactions. This multi-functional approach reduces overall system complexity compared to implementing separate authentication systems for different functions.
Data Source
AI summary
Systems and methods for authenticating authorized users of electronic communication devices, such mobile communication devices, for a secure data exchange between the devices. The authentication of authorized users include multiple levels of user authentication wherein identity profiles of the users are exchanged for user authentication based on identity information obtained or observed from the users.


