Biometric Login Authentication Using Secure Enclave Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current user and device authentication methods for transactions, such as those used by payment providers, are insecure and require repeated login credentials across different browsers, leading to inefficiencies and potential fraud.
Innovation Solution
Implementing biometric authentication using IntelĀ® SGX technology to store tokens or public/private key pairs in a secure enclave on the user's device, allowing device-specific identification and secure transactions without the need for repeated login credentials.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cookie-based authentication is used, then user identification across sessions is enabled, but security is compromised as cookies can be copied and used by unauthorized individuals
Solution Approach 1:
The patent introduces an intermediary authentication mechanism that uses device-specific identifiers and biometric data as a mediator between the user and the authentication system. Instead of relying on vulnerable cookies, the system uses an intermediate layer of device identification and biometric verification that cannot be easily copied or stolen, thus improving security while maintaining convenience.
Solution Approach 2:
The patent replaces the mechanical cookie-based authentication system with a biometric authentication system. Instead of using transferable digital cookies that can be copied, the system uses unique biological characteristics (fingerprint, facial recognition, iris scan) that cannot be replicated, thereby substituting a vulnerable mechanical system with a more secure biometric system.
2Productivity
If repeated login credentials are required across different browsers, then security is maintained, but user experience and transaction efficiency deteriorate
Solution Approach 1:
The patent implements a universal authentication system that works across multiple browsers and devices using device-specific identifiers and biometric data. The authentication mechanism is designed to be platform-agnostic, allowing users to complete transactions efficiently on any device while maintaining strong security through unique biometric verification rather than browser-specific cookies.
Solution Approach 2:
The system performs preliminary authentication by storing device-specific identifiers and biometric data during an initial setup or first login. This preliminary action enables subsequent transactions to be authenticated quickly without requiring repeated credential entry, as the system has already established the user's identity and device association in advance.
3Speed
If secure cookie-based instant checkout is implemented, then transaction speed is improved, but device identification reliability deteriorates as stolen cookies cannot be distinguished from legitimate ones
Solution Approach 1:
The patent changes the identification parameters from mutable cookies that can be stolen to immutable device-specific identifiers and biometric characteristics. By using parameters such as device hardware IDs, fingerprint patterns, or facial geometry, the system achieves both fast checkout speeds and high identification accuracy, as these parameters cannot be replicated or stolen like cookies.
Data Source
AI summary
As disclosed herein, a token and/or a public/private key can be stored in a secure enclave that can be later used when a user logs into the payment provider's website. At that time, the user can simply swipe a fingerprint to complete a transaction. Thus, biometric authentication may be applied to complete the transaction. Moreover, the transaction can be completed across different browsers. In an implementation, a long-term token is not utilized. Instead, when a user opts into the disclosed implementation, a private and public key pair is generated on the client side device. The private key may be stored in the secure enclave and the public key may be sent to the payment provider. Thus, there may be no token involved to complete the transaction.


