Biometric Authentication System for Secure Personal Identifier Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for authenticating users through personal identification numbers (PINs) are burdensome and vulnerable to fraudulent access, as PINs are often transmitted over networks, making them susceptible to hacking and keylogging, leading to significant financial losses despite regulatory efforts.

Innovation Solution

A system where a partner computing device receives a representation of the PIN, such as a hashed or encrypted personal identifier string, rather than the actual PIN, to authenticate users for accessing secured websites or facilities, thereby reducing the risk of data exposure and unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a PIN is transmitted over a network for authentication, then user authentication can be performed, but the system becomes vulnerable to hacking and keylogging attacks

Engineering Contradiction:
Improveauthentication securityVSAvoidhacking and keylogging vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the PIN from the transmission path by implementing biometric authentication (fingerprint, iris, facial recognition) that eliminates the need for PIN input and transmission entirely. The biometric data is processed locally on the user's device, and only authentication results are transmitted, not the sensitive PIN or biometric data itself.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where biometric data serves as a mediator between the user and the system. Instead of transmitting the PIN directly, the biometric authentication system acts as an intermediary that verifies identity through physiological characteristics, thereby preventing direct exposure of authentication credentials to potential attackers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a PIN is required for access control, then security is improved, but user convenience and ease of operation deteriorate

Engineering Contradiction:
Improveaccess securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service authentication where the user's own biometric characteristics (fingerprint, iris, face) serve as the authentication credential. The system automatically captures and processes biometric data without requiring the user to manually input a PIN, making the authentication process as convenient as presenting a physical trait while maintaining strong security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical system of manual PIN entry (typing, keylogging vulnerability) with automated biometric sensing systems. Fingerprint scanners, iris cameras, and facial recognition systems automatically capture and verify biometric data, eliminating the need for manual input devices and reducing user burden while enhancing security through harder-to-copy biological traits.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If PINs are stored in databases for verification, then authentication functionality is enabled, but the system becomes susceptible to database hacking and intrusions

Engineering Contradiction:
Improveauthentication functionalityVSAvoiddatabase hacking vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication verification process from centralized database storage. Instead of storing PINs in vulnerable databases, the system uses distributed biometric templates stored securely in encrypted form. Authentication verification is performed by comparing live biometric scans against these encrypted templates, eliminating the need for plaintext credential storage and reducing database hacking risks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes the fundamental parameter of what is stored and transmitted. Instead of storing and comparing plaintext PINs or hashed credentials, the system stores encrypted biometric templates and compares them using cryptographic protocols. This parameter change from credential storage to biometric template storage fundamentally reduces the value of database breaches, as stolen templates cannot be easily reverse-engineered into usable credentials.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8874912B2Systems and methods for securely transferring personal identifiers
Publication Date: 2014.10.28 FIRST DATA MERCHANT SERVICES LLC
  • US8874912B2 patent drawing
  • US8874912B2 patent drawing
  • US8874912B2 patent drawing

AI summary

A system for transferring secured data has an authentication facilitator that transmits data indicative of a graphical key pad to a remote display device of a user computing device and, in response, receives from the user computing device icon location data indicative of locations of icons selected by a user. Additionally, the authentication facilitator recovers a personal identifier (PI) from the icon location data, translates the recovered PI to obtain a translated PI, and transmits the translated PI. The system further has a partner computing apparatus that receives the translated PI and allows the user access to a secured area based upon the translated PI.