Function Execution Authentication Using Biometrics Without Account Input
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for user authentication in printing services require input of account information, which can be inconvenient and may compromise security when passwords are used.
Innovation Solution
A function executing device operates using a FIDO authentication scheme with biometric authentication and a pair of keys, allowing execution of specific functions based on successful biometric authentication and decryption of signature information, enabling operation with or without input of account information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If account information input is required for authentication, then security can be maintained through traditional methods, but user convenience deteriorates due to additional input steps
Solution Approach 1:
The patent extracts the account information input step from the authentication process by implementing biometric authentication. The biometric data (fingerprint, face, iris) is stored in the authentication device and used directly for verification without requiring users to input passwords or account information, thereby improving ease of operation while maintaining security through cryptographic verification
Solution Approach 2:
The authentication device performs self-service by automatically capturing biometric data, comparing it with stored templates, and generating authentication results without requiring user intervention for data input. The system autonomously completes the authentication process based on physiological characteristics, eliminating the need for manual account information entry
2Reliability
If passwords are used for authentication, then ease of operation is maintained through simple input, but security deteriorates due to password leakage and theft risks
Solution Approach 1:
The patent replaces the mechanical/password-based authentication system with a biometric authentication system. Instead of relying on users to memorize and input passwords (mechanical interaction), the system uses biological characteristics (fingerprint, face, iris) captured by sensors and processed through cryptographic algorithms, thereby improving security while maintaining ease of operation through automatic capture
Solution Approach 2:
The authentication parameter is changed from account information (passwords, usernames) to biometric parameters (fingerprint patterns, facial features, iris structures). This parameter change fundamentally improves security because biometric data cannot be easily stolen or guessed like passwords, while the authentication process remains convenient through automatic biometric capture and comparison
3Reliability
If traditional authentication schemes are used, then compatibility with existing systems is maintained, but security deteriorates due to vulnerability to attacks
Solution Approach 1:
The patent implements preliminary action by pre-storing biometric templates and cryptographic key pairs in the authentication device before actual authentication occurs. The system prepares authentication credentials in advance and uses them during verification, enabling secure authentication without requiring complex real-time processing during the actual login process
Solution Approach 2:
The patent introduces cryptographic intermediaries (public key infrastructure, digital signatures, hash functions) between the biometric verification process and the final authentication result. These cryptographic intermediaries ensure security by preventing reverse engineering of biometric data and providing tamper-evident authentication, while the complexity is managed through standardized cryptographic protocols
Data Source
AI summary
A function executing device may, in a case where an input of specific account information is accepted, send a first authentication request to a server. The function executing device may receive first verification information from the server, acquire first signature information, send the first signature information to the sever, receive a first function executing instruction from the server, and cause a function executing engine to execute a specific function. The function executing device may send, to the server, a second authentication request including predetermined information without accepting the input of account information. The function executing device may receive second verification information from the server, acquire second signature information, send the second signature information to the sever, receive a second function executing instruction from the server, and cause the function executing engine to execute the specific function.


