Biometric Pass Phrase Encryption for Confidential Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for IC authentication, such as those using portable media and biometric information, face challenges in ensuring secure and convenient access to confidential information, particularly when users forget passwords or experience dispersion in biometric data inputs, leading to inconvenience and security threats.
Innovation Solution
A method that acquires multiple sets of biometric information, generates a pass phrase using this information and a management number, and uses this pass phrase to encrypt and decrypt confidential information, such as passwords, for secure storage and access without relying on user memory.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a password is used for IC authentication, then security is improved, but user convenience deteriorates when the user forgets the password
Solution Approach 1:
The patent introduces biometric information as an intermediary between the user and the password system. Instead of directly using the password, the system uses biometric data to generate a pass phrase that then accesses the encrypted password. This mediator (biometric system) resolves the contradiction by providing automatic authentication without requiring the user to remember or manually input the password, thus maintaining security while improving convenience.
Solution Approach 2:
The patent replaces the mechanical system of manual password input and memory reliance with a biometric recognition system. The biometric reader automatically captures and processes biological data (fingerprint, face, iris, etc.) to generate authentication credentials, eliminating the need for users to manually handle or remember passwords, thereby solving the contradiction between security and ease of operation.
2Ease of operation
If biometric information is used for authentication, then user convenience is improved, but security deteriorates due to dispersion in biometric data inputs
Solution Approach 1:
The patent segments the authentication process into distinct functional components: biometric data acquisition, pass phrase generation, password encryption, and authentication verification. By dividing the biometric information processing into multiple discrete steps and using it only to generate a pass phrase rather than directly for authentication, the system reduces the impact of biometric data dispersion while maintaining convenience.
Solution Approach 2:
The patent transforms biometric information (which varies due to dispersion) into a standardized pass phrase through a deterministic generation process. By changing the parameter from raw biometric data to a derived pass phrase, and then using this pass phrase to encrypt a stable password, the system converts the variable biometric input into a reliable authentication mechanism, resolving the security concern while preserving convenience.
3Ease of operation
If biometric information is stored for authentication, then ease of operation is improved, but security risk increases due to potential biometric data leakage
Solution Approach 1:
The patent extracts only the necessary functional element from biometric information - using it solely to generate a pass phrase - while not storing the actual biometric data in the authentication system. The biometric information is processed transiently to create the pass phrase, and the original biometric data remains stored only in dedicated biometric databases with appropriate security measures, separating the sensitive biometric storage from the authentication credential storage.
Solution Approach 2:
The patent performs preliminary encryption of the password using the pass phrase generated from biometric information before storing the password in the authentication system. This preliminary action ensures that even if the stored authentication data is compromised, the actual password remains protected by the encryption key derived from biometric data, which is not stored in the same system, thereby reducing the security risk of biometric data leakage.
4Reliability
If multiple sets of biometric information are acquired and stored, then reliability of authentication is improved, but device complexity increases
Solution Approach 1:
The patent merges multiple sets of biometric information into a single pass phrase through a unified generation process. Instead of managing multiple separate biometric templates and their corresponding authentication logic, the system combines all biometric data sets to produce one deterministic pass phrase, which then encrypts the password. This merging approach maintains high authentication reliability while simplifying the overall system architecture and reducing management complexity.
Data Source
AI summary
A confidential information storing method performed by a computer is disclosed. Multiple sets of biometric information are acquired from a biometric information reader. The multiple sets of the acquired biometric information and specific information for specifying the biometric information to be used to generate a pass phrase are stored in a biometric information storage part. The pass phrase generated based on the biometric information and the specific information are acquired. Confidential information is encrypted by using the acquired pass phrase. The encrypted confidential information is stored.


