Integrated Biometric and Entity Authentication Handshake
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The TLS protocol and TLS Inner Application technologies require unnecessary paths and processes when performing biometric authentication after establishing a secure session through entity authentication, leading to inefficiencies and increased resource utilization.
Innovation Solution
A client and server apparatus configuration that integrates biometric authentication during the agreement process, including mutual certificate authentication, to establish a secure session without generating unnecessary paths, by using a biometric negotiation message, encrypted random numbers, and authentication contexts, thereby reducing wasted processes and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric authentication is performed after establishing a secure session through entity authentication, then authentication security is improved, but unnecessary paths and processes are generated leading to increased complexity and resource consumption
Solution Approach 1:
The patent merges entity authentication and biometric authentication into a single integrated process. The biometric authentication is performed as part of the TLS handshake procedure rather than as a separate subsequent process. The server performs both certificate verification and biometric verification within the same authentication flow, eliminating unnecessary paths and reducing process complexity while maintaining enhanced security.
Solution Approach 2:
The patent applies preliminary action by performing biometric authentication before the secure session is fully established. The server verifies the user's biometric characteristics during the handshake process, and only after successful biometric verification does the server proceed to establish the secure session and grant access. This prevents unnecessary path generation by avoiding the need for separate post-session authentication steps.
2Reliability
If two separate handshakes are used for entity authentication and biometric authentication, then authentication completeness is improved, but time consumption and resource waste increase
Solution Approach 1:
The patent combines two separate authentication handshakes into a single integrated handshake process. The TLS handshake and biometric authentication are performed concurrently rather than sequentially. The server includes biometric verification steps within the standard TLS handshake messages, allowing both entity and biometric authentication to be completed in one unified process, thereby reducing time loss and resource consumption.
3Reliability
If biometric authentication is performed separately after secure session establishment, then authentication robustness is improved, but energy consumption and processing overhead increase
Solution Approach 1:
The patent performs biometric authentication as a preliminary action during the handshake process rather than as a subsequent operation. The server verifies biometric characteristics before establishing the secure session, which means the authentication robustness is achieved without requiring additional separate processing steps that would consume extra energy and computational resources.
Data Source
AI summary
A client apparatus receives a message including a random number from a server apparatus during the handshake of agreement process, creates a biometric negotiation message including the biometric authentication method information and sends the biometric negotiation message to the server apparatus. Then, the client apparatus executes a biometric authentication based on biometric authentication method information notified from the server apparatus and encrypts the random number based on the private key. In addition, the client apparatus generates an authenticator from a result of the biometric authentication, the biometric authentication method information, the encrypted random number, and the client certificate, and sends to the server apparatus an authentication context including these. The server apparatus verifies the authentication context and establishes a secure session in one handshake.


