Biometric Smart Card Authentication with PKI and VPN Tunneling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional information protection systems fail to prevent unauthorized access to administration systems and credit/debit card misuse, even when illegitimate users possess personal or card information of legitimate users, leading to security breaches and illegal transactions.

Innovation Solution

A user authentication system utilizing a biometric smart card or USB token that combines biometric signatures with PKI certificates for enhanced authorization, establishing a virtual private network (VPN) for secure service access, and storing log data for verification purposes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional information protection systems use log information or network information for access control, then the system can monitor terminal access, but the system fails to prevent unauthorized access when illegitimate users possess personal information of legitimate users

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidunauthorized access vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication system is segmented into multiple independent verification layers: terminal identification, user credential verification, and biometric authentication. Each layer operates independently and contributes to the overall security, so that compromise of one layer does not lead to complete system failure

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary biometric authentication before granting access to the administration system. By verifying the user's biological characteristics in advance, the system prevents unauthorized access even if personal information is compromised, as biometric data cannot be easily replicated or stolen

Inventive Principle:
Principle #10Preliminary action

2Reliability

If remote users install virtual private network modules or information protection modules in terminals, then secure remote access is enabled, but the authentication process becomes complex and requires additional software installation

Engineering Contradiction:
Improveremote access securityVSAvoidauthentication convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The smart card contains embedded biometric authentication capability and automatically performs verification when presented to the terminal. The card itself provides the authentication service without requiring external software modules or manual configuration, simplifying the user experience while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system merges the smart card, biometric sensor, and authentication logic into a single integrated device. This combination eliminates the need for separate VPN modules or information protection software, as all authentication functions are consolidated in the smart card

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If credit cards or transportation cards use simple personal information or card information for authentication, then card usage is convenient, but illegal use becomes easy when card information is obtained by illegitimate users

Engineering Contradiction:
Improvecard usage convenienceVSAvoidcard duplication and misuse
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system replaces mechanical/card-based authentication with biometric authentication. Instead of relying on physical cards that can be duplicated or lost, the system uses the user's unique biological characteristics, which cannot be replicated, thereby preventing card misuse while maintaining convenience

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If PKI certificates or security cards are used for internet banking or electronic bidding, then transaction security is improved, but the system remains vulnerable to illegal withdrawals or bidding when certificate information is obtained

Engineering Contradiction:
Improvetransaction securityVSAvoidcertificate information compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary biometric verification before authorizing any transaction involving PKI certificates. Even if certificate information is compromised, the biometric layer provides an additional security barrier that prevents unauthorized transactions, as the biological characteristics must match for authentication to succeed

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9037851B2User authentication system, user authentication apparatus, smart card, and user authentication method for ubiquitous authentication management
Publication Date: 2015.05.19 CHOI OK
  • US9037851B2 patent drawing
  • US9037851B2 patent drawing
  • US9037851B2 patent drawing

AI summary

A user authorization system for authorization management is disclosed. The user authorization system includes a public key infrastructure (PKI) certificate issuing server that issues a PKI certificate including a subscriber's biometric signature. The system also includes a sensing means that recognizes biometric patterns. The system also includes a smart card that stores the subscriber's biometric signature and the PKI certificate and verifies the user. The user authorization system also includes a terminal configured to establish a virtual private network (VPN) between the smart card and the service server in response to a tunneling start signal received from the smart card. The smart card transmits the tunneling start signal to the terminal if the user's biometric pattern matches with the subscriber's biometric signature and transmits authorization information derived from the PKI certificate to the service server through the VPN.