Biometric Authentication System for Secure Personal Identifier Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for authenticating users through personal identification numbers (PINs) are burdensome and vulnerable to fraudulent access, as PINs are often transmitted over networks, making them susceptible to hacking and keylogging, leading to significant financial losses despite regulatory efforts.
Innovation Solution
A system where a partner computing device receives a representation of the PIN, such as a hashed or encrypted personal identifier string, rather than the actual PIN, to authenticate users for accessing secured websites or facilities, thereby reducing the risk of data exposure and unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a PIN is transmitted over a network for authentication, then user authentication can be performed, but the system becomes vulnerable to hacking and keylogging attacks
Solution Approach 1:
The patent extracts the PIN from the transmission path by implementing biometric authentication (fingerprint, iris, facial recognition) that eliminates the need for PIN input and transmission entirely. The biometric data is processed locally on the user's device, and only authentication results are transmitted, not the sensitive PIN or biometric data itself.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism where biometric data serves as a mediator between the user and the system. Instead of transmitting the PIN directly, the biometric authentication system acts as an intermediary that verifies identity through physiological characteristics, thereby preventing direct exposure of authentication credentials to potential attackers.
2Reliability
If a PIN is required for access control, then security is improved, but user convenience and ease of operation deteriorate
Solution Approach 1:
The patent implements self-service authentication where the user's own biometric characteristics (fingerprint, iris, face) serve as the authentication credential. The system automatically captures and processes biometric data without requiring the user to manually input a PIN, making the authentication process as convenient as presenting a physical trait while maintaining strong security.
Solution Approach 2:
The patent replaces the mechanical system of manual PIN entry (typing, keylogging vulnerability) with automated biometric sensing systems. Fingerprint scanners, iris cameras, and facial recognition systems automatically capture and verify biometric data, eliminating the need for manual input devices and reducing user burden while enhancing security through harder-to-copy biological traits.
3Adaptability or versatility
If PINs are stored in databases for verification, then authentication functionality is enabled, but the system becomes susceptible to database hacking and intrusions
Solution Approach 1:
The patent extracts the authentication verification process from centralized database storage. Instead of storing PINs in vulnerable databases, the system uses distributed biometric templates stored securely in encrypted form. Authentication verification is performed by comparing live biometric scans against these encrypted templates, eliminating the need for plaintext credential storage and reducing database hacking risks.
Solution Approach 2:
The patent changes the fundamental parameter of what is stored and transmitted. Instead of storing and comparing plaintext PINs or hashed credentials, the system stores encrypted biometric templates and compares them using cryptographic protocols. This parameter change from credential storage to biometric template storage fundamentally reduces the value of database breaches, as stolen templates cannot be easily reverse-engineered into usable credentials.
Data Source
AI summary
A system for transferring secured data has an authentication facilitator that transmits data indicative of a graphical key pad to a remote display device of a user computing device and, in response, receives from the user computing device icon location data indicative of locations of icons selected by a user. Additionally, the authentication facilitator recovers a personal identifier (PI) from the icon location data, translates the recovered PI to obtain a translated PI, and transmits the translated PI. The system further has a partner computing apparatus that receives the translated PI and allows the user access to a secured area based upon the translated PI.


