Biometric Data Extraction System for Secure Cloud Password Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud-based password manager services face security risks due to the need for users to manage and store encryption decoding keys, and may compromise user convenience by requiring management of additional secret information, while also raising concerns about personal biological information being shared with cloud servers.

Innovation Solution

A data extraction system that encrypts secret information using a secret key, which is further encrypted with biological information, allowing users to securely access and manage their data by extracting the secret key using their biological information, thereby keeping sensitive information secure and reducing the burden on users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cloud-based password manager service is used to access password manager from various terminals, then user convenience is improved, but security is worsened because user authentication is required and users need to hold and manage a single password for authentication

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the authentication key from the cloud server and places it in the user's terminal device. The key is encrypted and stored locally in the terminal, allowing the user to access their password manager without requiring the key to be transmitted to or stored on the cloud server. This eliminates the security risk of cloud servers holding authentication keys while maintaining the convenience of multi-terminal access.

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If cloud-based password manager service is used, then user convenience is improved, but the burden on users is worsened because users need to hold and manage a single password for authentication

Engineering Contradiction:
Improveuser convenienceVSAvoidburden on users
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service by having the terminal device automatically retrieve and use the encrypted authentication key from the user's local storage when accessing the password manager. The system automatically decrypts and processes the key without requiring user intervention to manage authentication credentials. This eliminates the burden of managing multiple passwords while maintaining security.

Inventive Principle:
Principle #25Self-service

3Reliability

If biological information is used for user authentication, then security is improved, but the harm is worsened because personal biological information is shared with cloud servers

Engineering Contradiction:
ImprovesecurityVSAvoidpersonal biological information sharing
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the biological information processing from the cloud server and performs it locally in the user's terminal device. The terminal device contains the encrypted authentication key and processes biological information locally to verify authentication without transmitting personal biological data to the cloud server. This maintains high security through biometric authentication while eliminating the harmful sharing of personal biological information with cloud services.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11968300B2Data extraction system, data extraction method, registration apparatus, and program
Publication Date: 2024.04.23 NEC CORP
  • US11968300B2 patent drawing
  • US11968300B2 patent drawing
  • US11968300B2 patent drawing

AI summary

A data extraction system includes a registration apparatus, a data storage apparatus, and a query apparatus. The registration apparatus generates registration data including first information obtained by encrypting secret information, which is information that a user wishes to keep secret, by using a secret key and second information obtained by encrypting the secret key by using at least biological information of the user. The data storage apparatus holds the registration data. The query apparatus acquires the registration data by generating a query for acquiring the registration data from the data storage apparatus, extracts the secret key from the registration data by using biological information of the user, and extracts the secret information from the registration data by using the extracted secret key.