Biometric Smart Card Authentication with Dynamic Spoofing Risk

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing biometric smart cards are vulnerable to spoofing attacks, with fake fingers often passing anti-spoofing tests with scores slightly above the acceptance threshold, compromising user authentication security.

Innovation Solution

A biometric smart card system that updates a security indicator based on the spoofing score during anti-spoofing tests, applies a security policy based on this indicator, and adapts authentication methods such as offline, online, PIN code-based, or two-factor authentication to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a fixed acceptance threshold is used for anti-spoofing tests, then genuine users can be authenticated, but fake fingers with scores slightly above the threshold can bypass security

Engineering Contradiction:
Improveauthentication securityVSAvoidadaptive security response
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms the static security threshold into a dynamic security indicator that evolves with each transaction. Instead of using a fixed acceptance threshold, the system updates the security indicator based on the spoofing score, allowing the security level to adapt dynamically. When spoofing scores are consistently high, the security indicator increases, triggering more stringent authentication policies, thus resolving the contradiction between maintaining reliability and improving adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter from a fixed threshold to a variable security indicator that is updated based on spoofing scores. This parameter change allows the system to adjust its security response based on the actual risk level indicated by the spoofing scores, enabling differentiated security policies for different risk scenarios while maintaining authentication reliability.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple authentication methods are implemented, then security is enhanced, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a dynamic security policy selection mechanism that adapts the authentication method based on the security indicator value. Instead of always using the most complex multi-factor authentication, the system dynamically selects the appropriate authentication level: simple biometric authentication when security risk is low, or more stringent methods (PIN, online verification, two-factor authentication) when the security indicator indicates higher risk. This dynamic approach enhances security when needed while minimizing unnecessary complexity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies different authentication requirements to different security contexts based on the security indicator. Rather than uniformly applying complex authentication to all transactions, the system applies enhanced authentication measures only when the security indicator triggers them, leaving simple authentication for low-risk scenarios. This local differentiation optimizes security while reducing overall system complexity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP4505330B1Method for executing an authentication of a user for a transaction
Publication Date: 2025.12.17 THALES DIS FRANCE SA
  • EP4505330B1 patent drawingFigure 1
  • EP4505330B1 patent drawingFigure 2
  • EP4505330B1 patent drawing

AI summary

The invention is a method for executing an authentication of a user (50) for a transaction. A card captures (S20) a biometric data from the user and checks said biometric data passes an anti-spoofing test. The card retrieves (S30) a security indicator (28) updated during a previous transaction, and if said biometric data passed the anti-spoofing test, the card updates (S40) the security indicator by using a measured spoofing score computed during the anti-spoofing test. The card generates a result (12) by checking (S50) whether the security indicator complies with a pre-established safety rule (27) and selects (S60) a security policy (23) depending on the result. The card contributes (S70) to the authentication of the user according to the security policy or reject (S80) the authentication.