Biometric Authentication Infrastructure for Secure Online Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current online authentication methods for accessing financial information and e-commerce transactions lack sufficient security, as single-factor authentication is inadequate for high-risk transactions, and existing systems are vulnerable to fraud, necessitating a more robust and reliable multi-factor authentication solution.

Innovation Solution

A third-party maintained authentication infrastructure utilizing a biometric device for multifactor authentication, where users log in securely through a biometric sensor connected to their personal computer, providing an additional layer of security beyond traditional username and password methods, and enabling secure payment transactions via electronic wallets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If single-factor authentication (username and password) is used, then ease of operation is improved, but security reliability deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system is segmented into multiple independent factors: something the user knows (password), something the user has (biometric device), and something the user is (biometric characteristics). This segmentation allows the system to maintain ease of operation through familiar interfaces while dramatically improving security reliability by requiring multiple factors to be satisfied simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A third-party maintained authentication infrastructure acts as an intermediary between the user and the online service provider. This intermediary handles the complex biometric verification process, allowing users to authenticate securely without directly managing the complexity of multi-factor authentication, thus maintaining ease of operation while improving security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multi-factor authentication is implemented, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The third-party authentication infrastructure serves as an intermediary that manages the complexity of multi-factor authentication. The biometric device communicates with this intermediary, which handles template matching, template generation, and verification logic. This allows the authentication system to achieve high security reliability while keeping the user-facing interface and device complexity manageable.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system employs self-service mechanisms where the biometric device automatically performs template generation and matching against stored templates in the third-party infrastructure. This automation reduces the operational complexity for users and administrators, allowing multi-factor authentication to be implemented with minimal manual intervention while maintaining high security reliability.

Inventive Principle:
Principle #25Self-service

3Reliability

If biometric templates are stored centrally, then security reliability is improved through non-repudiation, but loss of information risk increases if centralized storage is compromised

Engineering Contradiction:
Improvenon-repudiationVSAvoidbiometric template security
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system creates a secure, controlled environment for storing biometric templates by using a third-party maintained authentication infrastructure with specialized security measures. This 'inert environment' protects the templates from unauthorized access and manipulation, enabling non-repudiation while minimizing the risk of information loss even if the centralized storage is compromised, as the templates are protected by multiple security layers including encryption and access controls.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

Data Source

PatentUS9911146B2Method and system for providing online authentication utilizing biometric data
Publication Date: 2018.03.06 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9911146B2 patent drawing
  • US9911146B2 patent drawing
  • US9911146B2 patent drawing

AI summary

A system and method for securely authenticating a user for the purpose of accessing information, such as private financial or personal information, in an online environment are disclosed. In addition, a system and method for allowing consumers to make secure payments from an electronic wallet with biometric authentication are disclosed.