Biometric Authentication Device Using Local Key Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current user authentication and digital signature methods face challenges in ensuring confidentiality, safety, and ease of use, particularly in IoT and cryptocurrency applications, where passwords are easily compromised and biometric data is vulnerable to theft and misuse.
Innovation Solution
A user authentication and signature device that utilizes touch data and biometrics to generate and manage encryption keys, allowing users to register and authenticate using a combination of image data, touch pixel coordinates, and biometric information, eliminating the need for third-party certification and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a user provides biometric information to a third party for authentication, then user authentication and signature functions can be realized, but the biometric information may be stolen or leaked without modification, causing permanent misuse
Solution Approach 1:
The patent extracts the biometric information processing from the third-party server and keeps it entirely within the user's own device. The server only receives and verifies authentication results, not the raw biometric data itself. This extraction principle resolves the contradiction by allowing authentication functionality while removing the risk of biometric data leakage to third parties.
Solution Approach 2:
The patent introduces an intermediary mechanism where biometric information is transformed into authentication results through local processing. The user device acts as an intermediary that converts raw biometric data into verified authentication outcomes before transmitting only these results to the server, preventing direct exposure of biometric information.
2Reliability
If a complex and long combination of letters, numerals, and signs is generated as a password to prevent illegal use, then security is improved, but it is difficult for the user to remember the password
Solution Approach 1:
The patent replaces the mechanical system of manual password creation and memorization with an automated biometric authentication system. The device automatically generates secure authentication credentials based on biometric characteristics, eliminating the need for users to manually create and remember complex passwords while maintaining high security standards.
Solution Approach 2:
The patent changes the fundamental parameter of authentication from user-defined passwords to biometric characteristics. Instead of relying on memorizable but weak passwords, the system uses unique physiological parameters (fingerprint patterns, iris structures, etc.) that provide both high security and ease of use through automatic recognition.
3Adaptability or versatility
If biometric information is provided to a third party, then user authentication can be realized, but legal restrictions on leakage of personal information make it undesirable to let others manage biometric information
Solution Approach 1:
The patent segments the authentication system into two distinct parts: biometric data collection and processing occurs locally on the user device, while authentication verification occurs on the server. This segmentation ensures that biometric information never leaves the user device, complying with legal restrictions while maintaining authentication functionality through separate localized and remote operations.
Data Source
AI summary
The present invention relates to a device and method for authenticating users and obtaining user signatures, which can be provided in business services using networks and various user information devices including information devices equipped with touch displays such as smartphones, or desktop PCs, laptops, tablet PCs, CCTVs, IoT, self-driving cars, drones, etc. and, more specifically, to a device and method for authenticating users and obtaining user digital signatures which, as an encryption key/password generation and verification system for user authentication to be provided in various web-based businesses in which various information devices are serviced in a client-server or peer-to-peer model network environment and in app-based businesses running on a specific platform, is simpler and ensures confidentiality and security.


