Biometric Registration Security via Segmented Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Biometric registration systems are vulnerable to data theft during the initial registration process, allowing unauthorized access when biometric devices and PIN codes are compromised.

Innovation Solution

A method and system that securely registers users by using a biometric device identifier and user information to initiate registration, including authentication through device verification, location matching, photograph recognition, and secret questions to ensure the user's identity before completing the registration with encrypted biometric data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric data is collected during initial registration, then user identification capability is improved, but security vulnerability increases due to potential data theft

Engineering Contradiction:
Improveuser identification capabilityVSAvoiddata theft risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the biometric system into multiple independent components: biometric device, authentication server, and user device. Each component performs a specific function and communicates through secure protocols. The biometric data collection, verification, and storage are separated into distinct operational phases, reducing the attack surface for potential data theft while maintaining reliable user identification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary authentication actions before completing biometric registration. The authentication server verifies device legitimacy and user identity through multiple checks (device authentication, user verification) before allowing biometric data to be transmitted and stored. This preliminary validation prevents unauthorized data collection and ensures only authenticated users can complete registration.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple authentication steps are implemented, then security is improved, but registration time increases

Engineering Contradiction:
ImprovesecurityVSAvoidregistration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authentication process is structured as a series of periodic, sequential steps rather than a single prolonged verification. The system cycles through distinct authentication phases (device authentication, user verification, biometric capture) with clear transitions between each. This periodic structure allows the system to efficiently manage multiple security checks while providing users with clear progress feedback, reducing perceived wait time despite enhanced security.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system enables users to perform self-service authentication actions during registration. Users independently complete device setup, provide personal verification information, and authorize biometric capture without requiring manual intervention from administrators. This self-service approach streamlines the multi-step authentication process, allowing users to quickly complete each security verification step at their own pace, reducing overall registration time while maintaining security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11373453B2Method and system to securely register a user in a biometric system
Publication Date: 2022.06.28 KONICA MINOLTA BUSINESS SOLUTIONS USA INC
  • US11373453B2 patent drawing
  • US11373453B2 patent drawing
  • US11373453B2 patent drawing

AI summary

A method and system for securely registering a user in a biometric system. The method includes: receiving, on a computer processor of the biometric system, an identifier of a biometric device and user information; sending, with the computer processor, a request that the biometric device be sent to the user of the biometric device upon the receipt of the identifier of the biometric device and user information; receiving, on the computer processor, the identifier of the biometric device and one or more authenticators from the user; initiating, with the computer processor, a registration of the user based on the receipt of the identifier of the biometric device and the one or more authenticators from the user; and receiving, on the computer processor, biometric data of the user from the biometric device to complete a registration of the user in the biometric system.