Biometric PKI Authentication on Mobile Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The use of alphanumeric log-in/password combinations for network service access is vulnerable to attacks due to password re-use, weak passwords, vulnerable password databases, and credentials being exchanged in the clear, compromising user accounts.
Innovation Solution
A mobile device generates and stores biometric-based passwords to protect user credentials, including a public/private key pair and digital certificate, using biometric data such as fingerprints, iris scans, or voice patterns, ensuring secure authentication and access to network services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If alphanumeric log-in/password combinations are used for network service access, then account creation and access are simple, but security is compromised due to password re-use, weak passwords, vulnerable password databases, and credentials being exchanged in the clear
Solution Approach 1:
The patent replaces the mechanical/password-based authentication system with a biometric authentication system. Instead of relying on users to create and remember complex passwords, the system uses biological characteristics (fingerprint, iris, voice, face) to automatically authenticate users. This substitution eliminates the security vulnerabilities of password-based systems while maintaining ease of operation, as biometric authentication is more convenient than remembering passwords and cannot be reused or phished.
2Productivity
If passwords are stored in databases, then user authentication can be processed, but the password databases become vulnerable to unauthorized access and retrieval
Solution Approach 1:
The patent extracts the authentication data from traditional password databases and stores it in secure enclaves or hardware security modules within the service provider's infrastructure. Biometric templates and authentication credentials are kept in isolated, protected storage areas that are inaccessible even to administrators. This extraction from vulnerable databases eliminates the risk of unauthorized database access while maintaining authentication processing capability.
Solution Approach 2:
The patent introduces secure enclaves and hardware security modules as intermediary layers between the authentication system and storage. These intermediaries provide protected environments where biometric data and credentials are stored and processed, acting as a buffer that prevents direct access to the underlying storage. This intermediary layer maintains authentication productivity while blocking unauthorized access paths.
3Speed
If credentials are exchanged in the clear during authentication, then the authentication process is simple and fast, but the credentials become vulnerable to eavesdropping and compromise
Solution Approach 1:
The patent replaces clear-text credential exchange with biometric-based authentication protocols that transmit only encrypted biometric features or authentication tokens. Instead of sending passwords or credentials in the clear, the system transmits processed biometric data that cannot be reverse-engineered or used for phishing attacks. This substitution maintains fast authentication speed while eliminating eavesdropping vulnerabilities.
Data Source
AI summary
A mobile device obtains an encryption key pair, including a public key and a private key, and engages in a process, that uses the private key, for requesting a digital certificate from a Public Key Infrastructure (PKI) Certificate Authority. The mobile device receives a digital certificate signed by the PKI Certificate Authority, and obtains, via a biometric input unit device, biometric data related to an identity of a user of the device. The mobile device derives a password using the biometric data, and stores, and password protects using the derived password, the public key, the private key, and the digital certificate in a secure key store.


