Biometric Network Traffic Authentication via Verification Codes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network security systems are inadequate in addressing sophisticated attacks and malicious activities, particularly in managing and authenticating network traffic in expanded enterprise networks and IoT environments, where traditional methods fail to validate user identity effectively.
Innovation Solution
The implementation of biometric-based systems and methods that authenticate and manage network traffic by using biometric markers, which are stored as verification codes generated from a user's biometric template, ensuring only human-originated and authenticated traffic is allowed, and utilizing blockchain auditing for non-repudiation and identity verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric-based authentication systems are implemented, then network security and user identity validation are improved, but system complexity increases
Solution Approach 1:
The patent introduces verification codes as intermediary elements that bridge biometric authentication and network traffic management. These verification codes are generated from biometric templates and attached to network traffic, allowing the system to authenticate users without requiring direct biometric verification at every access point, thus reducing overall system complexity while maintaining security
Solution Approach 2:
The authentication process is segmented into distinct phases: biometric enrollment, verification code generation, and traffic authentication. By dividing the complex authentication workflow into manageable segments, the system reduces the complexity burden at any single point while maintaining comprehensive security across the network
2Reliability
If biometric verification is performed for each network connection, then user identity validation is improved, but authentication time increases
Solution Approach 1:
Biometric templates are enrolled and verification codes are generated in advance during user registration. These pre-computed verification codes are then attached to network traffic, eliminating the need for real-time biometric verification at each connection point and significantly reducing authentication time while maintaining identity validation reliability
Solution Approach 2:
Instead of requiring original biometric data to be processed at every authentication event, the system creates and transmits copies of authentication information (verification codes) that can be quickly validated without re-processing the original biometric templates, thus reducing authentication time
3Reliability
If network traffic is continuously monitored and authenticated, then network security is improved, but processing requirements increase
Solution Approach 1:
The patent employs lightweight verification codes that can be easily generated and attached to network traffic packets. These verification codes serve as disposable authentication tokens that provide security without requiring heavy processing, as they can be quickly validated and discarded after use, reducing overall processing requirements
Data Source
AI summary
The present disclosure describes systems and methods for managing network traffic using biometrics. A server may store a first value N, a primitive root modulo N, and a plurality of verification codes generated using the primitive root modulo N to the power of a hash function result of a respective portion of a first biometric template acquired from the user during enrollment. The sever may receive a request to connect to the server, from a client operated by the user. The client may use a first offset identifier from the server to identify a first portion of a second biometric template acquired from the user, and generate a first value corresponding to a common exponentiation function. The server may generate a second value corresponding to the common exponentiation function. The server may determine that the user is authenticated if the first value from the client matches the second value.


