Biometric Authentication Using Pseudonymous Identifiers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for an apparatus and method that effectively provides user authentication using biometric information, addressing the requirement for secure and efficient authentication services.
Innovation Solution
The solution involves a biometric information authentication system where a terminal transmits registration requests and biometric capability information to a server, acquires user biometric information, generates pseudonymous identifiers and auxiliary data, and uses these to register and authenticate users, employing security techniques to protect against external attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric information is transmitted and stored on a server for authentication, then authentication service is provided, but security risk and potential leakage of sensitive biometric information increases
Solution Approach 1:
The patent extracts only the essential authentication attributes from biometric information and transmits them to the server, while keeping the complete biometric data localized on the user's terminal device. This extraction approach enables authentication services to be provided remotely while preventing exposure of sensitive biometric information.
Solution Approach 2:
The patent introduces pseudonymous identifiers as an intermediary between the user's biometric information and the server's authentication database. These identifiers mask the actual biometric data, allowing the server to perform authentication without directly accessing or storing sensitive biometric information, thereby reducing security risks.
2Measurement precision
If complete biometric information is transmitted to server, then authentication accuracy is improved, but data privacy and security protection deteriorates
Solution Approach 1:
The system extracts only the necessary authentication features from complete biometric information and transmits them to the server. This extraction maintains sufficient authentication accuracy while minimizing the amount of sensitive data transmitted and stored, thereby protecting data privacy.
Solution Approach 2:
Instead of transmitting biometric information to the server for comparison, the patent inverts the approach by having the server send reference authentication data to the user's terminal, where local biometric information is compared against it. This inversion keeps sensitive data localized while achieving accurate authentication.
3Reliability
If biometric authentication system is implemented, then user security is improved, but system complexity increases
Solution Approach 1:
The patent enables the user's terminal device to perform self-service authentication by locally comparing biometric information against reference data provided by the server. This self-service approach simplifies the overall system architecture by reducing the need for complex centralized biometric processing while maintaining strong security.
Solution Approach 2:
The authentication system is segmented into distinct functional components: the user terminal handles biometric capture and local comparison, while the server provides reference data and manages pseudonymous identifiers. This segmentation distributes complexity across multiple components, making the overall system more manageable and scalable.
Data Source
Figure 1~2
Figure 3A~3B
Figure 4
AI summary
A terminal, a server, and a system for authenticating biometric information and a biometric information authentication method are provided. A method, performed by a terminal, of registering biometric information includes: transmitting a registration request and biometric capability information of the terminal to a server; receiving biometric capability information of the server from the server; acquiring a user's biometric information based on the biometric capability information of the server; acquiring a pseudonymous identifier (PI) and auxiliary data (AD) based on the user's biometric information; and transmitting the PI and the AD to the server.