Biometric Key Pair Generation for Passwordless Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face the burden of remembering and managing multiple passwords across various networks and systems, leading to tedious sign-on processes and security concerns due to the need for complex and frequently changed passwords.
Innovation Solution
A computer-implemented method for single sign-on using biometric data to form a key pair on a client device, which includes a public and private key, allowing secure authentication without the need for password input, with the option to use biometric data as a backup or in combination with a password for additional security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users manage multiple passwords across different networks and systems, then security is improved through complex and frequently changed passwords, but user burden increases due to the need to remember and maintain this information
Solution Approach 1:
The patent introduces an authentication server as an intermediary that manages cryptographic key pairs and authentication tokens. The server stores public keys and verifies signatures, acting as a mediator between users and multiple systems. This eliminates the need for users to remember multiple passwords while maintaining security through cryptographic verification.
Solution Approach 2:
The patent replaces the mechanical system of password memorization and manual authentication with an automated cryptographic system. Biometric data is converted into cryptographic key pairs through mathematical functions, and authentication is performed automatically through digital signature verification, eliminating the need for users to manually manage passwords.
2Ease of operation
If a single sign-on system is implemented to enable one initial sign-on to access multiple networks and systems, then user convenience is improved, but password handling complexity increases
Solution Approach 1:
The patent replaces complex password handling with cryptographic key pair management. Instead of managing multiple passwords, the system uses biometric data to generate key pairs where the private key remains on the user's device and the public key is stored on the authentication server. Authentication is achieved through digital signatures rather than password verification.
Solution Approach 2:
The patent changes the fundamental parameter of authentication from password-based verification to cryptographic signature verification. The authentication mechanism transitions from comparing plaintext or hashed passwords to verifying digital signatures using public key cryptography, fundamentally altering how authentication credentials are handled.
3Reliability
If biometric data is used to form a key pair for authentication, then security is enhanced through biometric authentication, but the risk of biometric data extraction increases in unsafe environments
Solution Approach 1:
The patent extracts only the essential authentication capability from biometric data without exposing the biometric data itself. The biometric template is processed to generate a key pair, where the private key is derived from the biometric data but the biometric data never leaves the secure environment. Only the cryptographic keys and signatures are transmitted, not the biometric data.
Solution Approach 2:
The patent introduces a secure biometric processing environment as an intermediary that handles the conversion of biometric data to cryptographic keys. This intermediary ensures that biometric data never leaves the secure environment, acting as a protective barrier between the biometric data and external systems.
4Reliability
If multiple authentication factors are implemented including biometric data and password, then security is further enhanced, but the authentication process complexity increases
Solution Approach 1:
The patent merges multiple authentication factors into a unified cryptographic framework. Biometric data, passwords, or other credentials can all serve as sources for generating private keys through the same biometric-to-key conversion process. This unification simplifies the overall architecture while maintaining multi-factor authentication capabilities.
Data Source
AI summary
The present disclosure relates to a method for user authentication. In particular, the present disclosure relates to a computer implemented method for session based one-time authentication of a client operating an electronic device, typically using one of a biometric data relating to the user and/or information provided at a remote electronic device. The disclosure device server also relates to a corresponding authentication system and to a computer program product.


