Biometric Authentication Workflow for Controlled Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing biometric authentication methods, such as fingerprint scanning, are vulnerable to exploitation and insufficient as a sole security measure, and sharing sensitive user data can be cumbersome and insecure, especially when interacting with terminals of varying capabilities.

Innovation Solution

A system that utilizes biometric credentials and an authentication system to authenticate user requests, differentiating between specific and general requests, and requiring user approval, while storing data centrally to provide secure and efficient data sharing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If biometric authentication is used alone, then authentication speed is improved, but security reliability deteriorates due to vulnerability to exploitation

Engineering Contradiction:
Improveauthentication speedVSAvoidsecurity reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The authentication process is divided into multiple independent stages: biometric verification (fingerprint scanning), credential validation (comparing biometric data with stored data), and authorization approval (user confirmation on terminal). Each stage acts as a separate security layer, allowing the system to maintain fast biometric authentication while adding security through segmented verification steps that prevent single-point failures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system prepares stored biometric credentials and authentication frameworks in advance before actual authentication events. By pre-storing fingerprint data and authentication parameters, the system can rapidly verify identities without requiring real-time data processing, thus maintaining speed while the pre-prepared security frameworks ensure reliability against exploitation attempts.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

2Ease of operation

If data sharing is enabled without central management, then ease of operation is improved, but security reliability deteriorates due to unauthorized access risk

Engineering Contradiction:
Improvedata sharing convenienceVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The terminal device serves as an intermediary between the user and third-party data requests. It receives authentication credentials from the user, validates them against stored data, and only permits data sharing after successful verification and user authorization. This intermediary role maintains ease of operation by automating the authentication flow while ensuring security through controlled, verified data transmission.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the terminal receives authentication results and user authorization responses, then adjusts data transmission accordingly. The feedback loop ensures that data is only shared when authentication succeeds and the user explicitly approves, maintaining both operational convenience and security reliability through continuous verification.

Inventive Principle:
Principle #23Feedback

3Reliability

If multiple authentication layers are added, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The terminal device performs multiple functions within the authentication system: it stores biometric credentials, receives authentication requests, validates credentials against stored data, obtains user authorization, and controls data transmission. By making the terminal a multi-functional universal component, the system improves security through multiple authentication layers without proportionally increasing overall system complexity, as one device handles all authentication tasks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12413628B2Authentication of data sharing
Publication Date: 2025.09.09 CAPITAL ONE SERVICES LLC
  • US12413628B2 patent drawing
  • US12413628B2 patent drawing
  • US12413628B2 patent drawing

AI summary

In some implementations, a system may receive, from a terminal, an account identifier, an authentication credential, and a request for data associated with a user, wherein the request may identify requested data items associated with the account identifier. The system may authenticate the request using the account identifier and the authentication credential. The system may determine whether the request satisfies a pre-approval condition after authenticating the request. The system may transmit a first message to a user device associated with the user or transmit a second message to a third party device associated with the terminal based on whether the requested data items satisfy the pre-approval condition. The first message to the user device may request approval to transmit the requested data items to the third party device via the second message, and the second message may enable access to the requested data items.