Biometric Key Authentication via Tamper-Resistant Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional user authentication methods require users to memorize multiple credentials or rely on access objects that do not verify the legitimate user, leading to difficulties in secure access management.
Innovation Solution
A biometric key system that persistently stores a user's device identifier and biometric data in a tamper-resistant format, allowing for wireless verification using fingerprint or retinal scans, and transmitting a verification code to a trusted key authority for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional authentication requires users to memorize credentials, then access security is improved, but user convenience deteriorates
Solution Approach 1:
The patent extracts the credential storage function from human memory and relocates it to an electronic key device. The key stores encrypted credential data and biometric templates, allowing the user to carry authentication credentials externally without memorization, thus resolving the contradiction between security and convenience.
Solution Approach 2:
The patent introduces a biometric template as an intermediary between the user and the authentication system. The biometric template serves as a mediator that enables automatic verification of the user's identity without requiring manual credential entry, thereby improving both security and ease of operation.
2Ease of operation
If access objects are used for authentication, then user convenience is improved, but authentication reliability deteriorates
Solution Approach 1:
The patent merges two separate authentication mechanisms into a single integrated system: (1) possession verification through the electronic key device, and (2) identity verification through biometric authentication. This combination ensures that both the device and the legitimate user must be present for successful authentication, resolving the reliability issue while maintaining convenience.
Solution Approach 2:
The patent creates a composite authentication system that combines cryptographic credentials stored in the electronic key with biometric characteristics of the user. This composite approach ensures that stolen or copied access objects alone cannot compromise security, as the biometric component provides an additional layer of verification that is difficult to replicate.
3Reliability
If hybrid authentication requiring both access object and credentials is used, then authentication reliability is improved, but device complexity increases
Solution Approach 1:
The patent implements self-service functionality within the electronic key device, where the biometric sensor and processing capabilities are integrated directly into the key. This allows the device to autonomously perform biometric verification and credential verification without requiring external authentication systems, thereby improving reliability while managing complexity through integration.
Data Source
AI summary
Systems and methods are provided for an integrated device that persistently (or permanently) stores biometric data for a user in a tamper-resistant format. Subsequently, scan data collected from a user (e.g., a finger-print) can be compared against the biometric data. Once the user has been verified by the integrated device, a code can be wirelessly transmitted for authentication. The authentication module sends the code to a trusted key authority. The trusted key authority checks a list of enrolled integrated devices for a match. If there is a match, the authentication module sends a message to an application to allow access by the user. The trusted key authority also stores a profile associated with the code. The profile can contain user information such as name, age, account numbers, preferences, etc. and can also describe the status of the integrated device.


