Biometric Identity Registration via Device and Server Reliability Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current biometric identification technologies face challenges in ensuring secure identity registration and authentication, particularly in mobile payment applications, where the reliability of user equipment and service servers needs to be verified to prevent unauthorized access and ensure data security.
Innovation Solution
A method and device that utilize a service client, biometric authentication middleware, identity authentication detector, and token and key manager on user equipment to securely register and authenticate biometric identities by using pre-stored device and server keys for verification, ensuring the reliability of user equipment and service servers through multi-level security mechanisms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If biometric identification is used for mobile payment authentication, then convenience of operation is improved, but security reliability needs to be enhanced to prevent unauthorized access
Solution Approach 1:
The patent introduces multiple intermediary components including a biometric authentication client, biometric authentication middleware, and identity authentication detector. These intermediaries act as security layers between the user equipment and service servers, verifying device reliability and biometric authenticity to prevent unauthorized access while maintaining convenient biometric authentication
Solution Approach 2:
The system performs preliminary device reliability verification and biometric feature extraction before actual authentication. The identity authentication detector pre-verifies device information and the biometric authentication client pre-processes biometric data, ensuring security measures are in place before the authentication transaction occurs
2Reliability
If multi-level security verification is implemented, then security reliability is improved, but device complexity increases
Solution Approach 1:
The authentication system is segmented into distinct functional modules: device information verification module, biometric feature extraction module, local verification module, and server authentication module. Each module handles a specific aspect of security verification, making the complex security process manageable and maintainable while ensuring comprehensive security coverage
3Reliability
If device and server reliability verification is performed, then security against unauthorized access is improved, but authentication time increases
Solution Approach 1:
Device reliability information and server verification data are obtained in advance before the actual authentication transaction. The identity authentication detector pre-verified device information and the system caches reliability data, so that during authentication, only biometric verification is needed, significantly reducing authentication time while maintaining security
Solution Approach 2:
The system performs local biometric feature verification on the user equipment before sending data to servers. This local verification quickly filters authentic users, reducing the need for time-consuming server-side verification and thereby reducing overall authentication time while maintaining security
Data Source
AI summary
An authentication information request packet of user equipment is received at an authentication server. The authentication information request packet includes a device identity of the user equipment. A virtual account identity corresponding to the device identity is obtained. The authentication information response packet is signed using a server private key. An authentication request packet of the user equipment is received. The authentication request packet includes the device identifier, the virtual account identity, and a biometric feature token. A registered service public key and a registered biometric feature token corresponding to the device identifier, the virtual account identity, and a biometric authentication type are obtained. A signature verification is performed by the authentication server on the authentication request packet using the registered service public key. An identity authentication is performed based on the biometric feature token in the authentication request packet and the registered biometric feature token.


