Biometric Query Conversion for Spoof-Resistant Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Biometric authentication systems face issues with spoofing attacks due to the leakage of authentication query data, which can be exploited to bypass security measures.

Innovation Solution

An authentication system that includes an authentication client apparatus with a temporary conversion part and an authentication server apparatus with a registration feature data storage part and matching part, using temporary conversion parameters to encrypt and convert biometric features, ensuring that even if data is leaked, it cannot be used for spoofing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication query data is stored and transmitted in plaintext or standard encrypted form, then authentication functionality is maintained, but the system becomes vulnerable to spoofing attacks when data is leaked

Engineering Contradiction:
Improveauthentication securityVSAvoidspoofing vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by making the conversion parameter temporary and changeable. Instead of using a fixed encryption key, the system generates a new conversion parameter for each authentication session, transforming the static security model into a dynamic one where security parameters evolve over time, thereby preventing replay attacks and spoofing.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter from a permanent encryption key to a temporary conversion parameter that varies for each authentication session. This parameter change ensures that even if one session's authentication data is leaked, it cannot be used for spoofing because the conversion parameter for that session is different from all other sessions.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If temporary conversion parameters are used to convert authentication data, then spoofing resistance is improved, but the system complexity increases due to additional conversion operations

Engineering Contradiction:
Improvespoofing preventionVSAvoidconversion processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a conversion parameter as an intermediary element between the raw biometric feature and the authentication data. This intermediary transforms the original data into a protected form without requiring complex cryptographic protocols, simplifying the overall system architecture while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The conversion parameter functions as a disposable, single-use element that is generated for one authentication session and then discarded. This approach avoids the need for complex key management systems required by traditional encryption, reducing device complexity while providing strong spoofing prevention.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Loss of information

If standard encryption is applied to authentication data, then data confidentiality is maintained, but the data can still be used for spoofing if the encryption is compromised or keys are leaked

Engineering Contradiction:
Improvedata confidentialityVSAvoidauthentication integrity
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent applies preliminary action by converting the authentication data using a temporary conversion parameter before the data leaves the authentication client apparatus. This pre-conversion ensures that the data is already protected against spoofing before transmission or storage, preventing potential security breaches without requiring complex verification processes later.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250358270A1Authentication system, authentication server apparatus, authentication method, and program
Publication Date: 2025.11.20 NEC CORP
  • US20250358270A1 patent drawing
  • US20250358270A1 patent drawing
  • US20250358270A1 patent drawing

AI summary

The authentication system includes: an authentication client apparatus including a temporary conversion part that receives a feature to be authenticated and converts the feature into authentication query data using a temporary conversion parameter; and an authentication server apparatus including a registration feature data storage part and a matching part, the registration feature data storage part receiving a feature(s) to be registered in a system and storing registration feature data generated, the matching part executing matching on a basis of the registration feature data and the authentication query data.