Biometric Authentication for Multi-User Mobile Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile device authentication methods for multi-user interactions are insecure, as they rely on user identifiers or PIN codes, which can be easily compromised, lacking robust verification of user identities, especially in shared or proximity-based interactions.
Innovation Solution
Implementing biometric authentication using devices capable of obtaining and processing physiological characteristics, such as fingerprints, iris, or voice, integrated into mobile devices, which verify user identities before allowing multi-user interactions, including electronic payments, social networking, and gaming applications, by comparing biometric data with stored profiles on the device or a server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If user identifiers or PIN codes are used for authentication, then ease of operation is improved, but security is worsened
Solution Approach 1:
The patent replaces mechanical authentication methods (typing PIN codes, entering user identifiers) with biometric authentication using fingerprint sensors, iris scanners, or voice recognition systems. This substitution maintains ease of operation while dramatically improving security, as biometric traits are unique to each user and cannot be easily compromised or shared like PIN codes.
Solution Approach 2:
The patent changes the authentication parameter from easily replicable data (PIN codes, user identifiers) to unique physiological parameters (fingerprint patterns, iris structures, voice characteristics). This parameter change ensures that authentication credentials cannot be easily stolen or guessed, resolving the security weakness while maintaining user convenience.
2Reliability
If biometric authentication is implemented, then security is improved, but device complexity is worsened
Solution Approach 1:
The patent implements a universal biometric authentication system that can handle multiple authentication types (fingerprint, iris, voice) through a single integrated framework. This multi-functional approach allows the system to provide robust security without requiring separate complex systems for each authentication method, as the same underlying architecture supports all biometric modalities.
Solution Approach 2:
The patent introduces a biometric authentication intermediary layer that sits between the user and the application layer. This intermediary handles all biometric verification operations, comparing biometric data with stored profiles and granting or denying access. By centralizing this functionality, the system manages complexity efficiently while providing enhanced security across all applications.
3Loss of time
If biometric data is stored on the device, then authentication speed is improved, but security risk is worsened
Solution Approach 1:
The patent implements a nested security architecture where biometric templates are stored in a secure enclave or trusted execution environment within the device. This nested structure allows the device to perform fast local authentication by comparing biometric data against stored templates, while the sensitive biometric information remains protected within the secure nested layer, reducing the risk of external breaches.
Data Source
AI summary
There is provided a method for use by a mobile device. The method includes launching a software application requiring an identity verification of each of a plurality of users for performing a requested action, the plurality of users including a first user and a second user, receiving a first biometric information of the first user and a second biometric information of the second user, sending the first biometric information of the first user and the second biometric information of the second user to a server, receiving notifications from the server as to whether the first and second biometric information corresponding to biometric information in first user and second user profiles, respectively, and performing the requested action, if the notifications indicate a match.


