Biometric Pass Phrase Encryption for Confidential Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for IC authentication, such as those using portable media and biometric information, face challenges in ensuring secure and convenient access to confidential information, particularly when users forget passwords or experience dispersion in biometric data inputs, leading to inconvenience and security threats.

Innovation Solution

A method that acquires multiple sets of biometric information, generates a pass phrase using this information and a management number, and uses this pass phrase to encrypt and decrypt confidential information, such as passwords, for secure storage and access without relying on user memory.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a password is used for IC authentication, then security is improved, but user convenience deteriorates when the user forgets the password

Engineering Contradiction:
Improveauthentication securityVSAvoidaccess convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces biometric information as an intermediary between the user and the password system. Instead of directly using the password, the system uses biometric data to generate a pass phrase that then accesses the encrypted password. This mediator (biometric system) resolves the contradiction by providing automatic authentication without requiring the user to remember or manually input the password, thus maintaining security while improving convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical system of manual password input and memory reliance with a biometric recognition system. The biometric reader automatically captures and processes biological data (fingerprint, face, iris, etc.) to generate authentication credentials, eliminating the need for users to manually handle or remember passwords, thereby solving the contradiction between security and ease of operation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If biometric information is used for authentication, then user convenience is improved, but security deteriorates due to dispersion in biometric data inputs

Engineering Contradiction:
Improveauthentication convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication process into distinct functional components: biometric data acquisition, pass phrase generation, password encryption, and authentication verification. By dividing the biometric information processing into multiple discrete steps and using it only to generate a pass phrase rather than directly for authentication, the system reduces the impact of biometric data dispersion while maintaining convenience.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms biometric information (which varies due to dispersion) into a standardized pass phrase through a deterministic generation process. By changing the parameter from raw biometric data to a derived pass phrase, and then using this pass phrase to encrypt a stable password, the system converts the variable biometric input into a reliable authentication mechanism, resolving the security concern while preserving convenience.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If biometric information is stored for authentication, then ease of operation is improved, but security risk increases due to potential biometric data leakage

Engineering Contradiction:
Improvepassword-free authenticationVSAvoidbiometric data leakage risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the necessary functional element from biometric information - using it solely to generate a pass phrase - while not storing the actual biometric data in the authentication system. The biometric information is processed transiently to create the pass phrase, and the original biometric data remains stored only in dedicated biometric databases with appropriate security measures, separating the sensitive biometric storage from the authentication credential storage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary encryption of the password using the pass phrase generated from biometric information before storing the password in the authentication system. This preliminary action ensures that even if the stored authentication data is compromised, the actual password remains protected by the encryption key derived from biometric data, which is not stored in the same system, thereby reducing the security risk of biometric data leakage.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If multiple sets of biometric information are acquired and stored, then reliability of authentication is improved, but device complexity increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidbiometric data management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple sets of biometric information into a single pass phrase through a unified generation process. Instead of managing multiple separate biometric templates and their corresponding authentication logic, the system combines all biometric data sets to produce one deterministic pass phrase, which then encrypts the password. This merging approach maintains high authentication reliability while simplifying the overall system architecture and reducing management complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10291611B2Confidential information storing method, information processing terminal, and computer-readable recording medium
Publication Date: 2019.05.14 FUJITSU LTD
  • US10291611B2 patent drawing
  • US10291611B2 patent drawing
  • US10291611B2 patent drawing

AI summary

A confidential information storing method performed by a computer is disclosed. Multiple sets of biometric information are acquired from a biometric information reader. The multiple sets of the acquired biometric information and specific information for specifying the biometric information to be used to generate a pass phrase are stored in a biometric information storage part. The pass phrase generated based on the biometric information and the specific information are acquired. Confidential information is encrypted by using the acquired pass phrase. The encrypted confidential information is stored.