Biometric Smart Card Authentication with PKI and VPN Tunneling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional information protection systems fail to prevent unauthorized access to administration systems and credit/debit card misuse, even when illegitimate users possess personal or card information of legitimate users, leading to security breaches and illegal transactions.
Innovation Solution
A user authentication system utilizing a biometric smart card or USB token that combines biometric signatures with PKI certificates for enhanced authorization, establishing a virtual private network (VPN) for secure service access, and storing log data for verification purposes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional information protection systems use log information or network information for access control, then the system can monitor terminal access, but the system fails to prevent unauthorized access when illegitimate users possess personal information of legitimate users
Solution Approach 1:
The authentication system is segmented into multiple independent verification layers: terminal identification, user credential verification, and biometric authentication. Each layer operates independently and contributes to the overall security, so that compromise of one layer does not lead to complete system failure
Solution Approach 2:
The system performs preliminary biometric authentication before granting access to the administration system. By verifying the user's biological characteristics in advance, the system prevents unauthorized access even if personal information is compromised, as biometric data cannot be easily replicated or stolen
2Reliability
If remote users install virtual private network modules or information protection modules in terminals, then secure remote access is enabled, but the authentication process becomes complex and requires additional software installation
Solution Approach 1:
The smart card contains embedded biometric authentication capability and automatically performs verification when presented to the terminal. The card itself provides the authentication service without requiring external software modules or manual configuration, simplifying the user experience while maintaining security
Solution Approach 2:
The system merges the smart card, biometric sensor, and authentication logic into a single integrated device. This combination eliminates the need for separate VPN modules or information protection software, as all authentication functions are consolidated in the smart card
3Ease of operation
If credit cards or transportation cards use simple personal information or card information for authentication, then card usage is convenient, but illegal use becomes easy when card information is obtained by illegitimate users
Solution Approach 1:
The system replaces mechanical/card-based authentication with biometric authentication. Instead of relying on physical cards that can be duplicated or lost, the system uses the user's unique biological characteristics, which cannot be replicated, thereby preventing card misuse while maintaining convenience
4Reliability
If PKI certificates or security cards are used for internet banking or electronic bidding, then transaction security is improved, but the system remains vulnerable to illegal withdrawals or bidding when certificate information is obtained
Solution Approach 1:
The system performs preliminary biometric verification before authorizing any transaction involving PKI certificates. Even if certificate information is compromised, the biometric layer provides an additional security barrier that prevents unauthorized transactions, as the biological characteristics must match for authentication to succeed
Data Source
AI summary
A user authorization system for authorization management is disclosed. The user authorization system includes a public key infrastructure (PKI) certificate issuing server that issues a PKI certificate including a subscriber's biometric signature. The system also includes a sensing means that recognizes biometric patterns. The system also includes a smart card that stores the subscriber's biometric signature and the PKI certificate and verifies the user. The user authorization system also includes a terminal configured to establish a virtual private network (VPN) between the smart card and the service server in response to a tunneling start signal received from the smart card. The smart card transmits the tunneling start signal to the terminal if the user's biometric pattern matches with the subscriber's biometric signature and transmits authorization information derived from the PKI certificate to the service server through the VPN.


