Out-of-band Biometric Enrollment via Interactive Messaging
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current single sign-on (SSO) technologies pose security risks due to the potential compromise of login credentials, and users face difficulties managing multiple login identities across various online services, while biometric authentication is not fully integrated for enhanced security.
Innovation Solution
An integrated system combining interactive messaging with a biometric engine for out-of-band biometric enrollment and verification, allowing users to enroll and authenticate using biometric modalities like face, finger, iris, and voice, and providing secure transactions through a biometric authentication service.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If single sign-on (SSO) technology is implemented to simplify access to multiple online services, then ease of operation is improved, but security is worsened due to the risk of credential compromise
Solution Approach 1:
The patent segments the authentication process into multiple independent components: traditional username/password authentication, biometric authentication, and out-of-band verification. This segmentation allows the system to maintain SSO convenience while distributing security risks across multiple authentication factors, so that compromise of one factor does not lead to complete system compromise.
Solution Approach 2:
The patent creates a composite authentication mechanism that combines multiple authentication methods (username/password, biometrics, out-of-band verification) into a unified authentication framework. This composite approach integrates different authentication strengths to achieve both ease of operation through SSO and enhanced security through multi-factor authentication.
2Reliability
If multiple login credentials are used for different online services to improve security, then security is improved, but device complexity is worsened due to managing multiple identities
Solution Approach 1:
The patent implements a universal biometric authentication system that can be used across multiple online services and platforms. The biometric engine and out-of-band verification system provide a multi-functional authentication solution that works for different service providers, reducing the need for users to manage separate credentials for each service while maintaining security.
3Reliability
If biometric authentication is integrated into the messaging system for out-of-band verification, then security is improved, but device complexity is worsened
Solution Approach 1:
The patent introduces an intermediary biometric engine that handles the complex biometric processing and verification tasks. This intermediary component mediates between the messaging system and the biometric authentication process, absorbing the complexity of biometric operations while presenting a simple interface to the messaging system and users.
Solution Approach 2:
The system implements self-service capabilities where the biometric engine automatically performs enrollment, verification, and token generation without requiring manual configuration. The out-of-band verification process automatically triggers and completes authentication steps, reducing the operational complexity users would otherwise need to manage.
Data Source
AI summary
A system and method for enabling out of band biometric verification is disclosed. The system includes a biometric engine coupled with an interactive messaging system and configured as an identity provider. The biometric identity provider includes a biometric enrollment process using open standard authentication protocols. The identity provider may answer calls generated by a service provider for biometric verification request for a user by sending an interactive message to a wireless mobile device associated to the user. The user captures and sends a biometric input to the identity provider. Biometrics provided by a user are compared by the biometric engine against biometric templates stored for that user in order to verify the user. The identity provider then sends a response back to the service provider. The service provider may grant or deny services to a user depending on the response.


