Biometric Authentication for Secure Remote Token Release
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods, such as usernames and passwords, are inadequate for securing multiple online accounts, prone to compromise, and do not allow authorization entities to authenticate users effectively, while transmitting sensitive credentials is vulnerable to attacks.
Innovation Solution
A system using biometric authentication on a communication device linked to a public/private key pair, where the public key is stored on a secure remote server, verifies user identity by signing an authentication indicator with the private key and releasing a token upon successful verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If usernames and passwords are used for authentication, then ease of operation is improved, but security is worsened due to susceptibility to compromise and phishing
Solution Approach 1:
The patent replaces the mechanical/password-based authentication system with a biometric authentication system. Biometric data (fingerprint, facial recognition, iris scan) is used to authenticate users, eliminating the need for usernames and passwords. This substitution maintains ease of operation while dramatically improving security against compromise and phishing attacks.
Solution Approach 2:
The patent changes the authentication parameter from discrete credentials (usernames/passwords) to continuous biometric characteristics. By using biometric data that is unique to each user and difficult to replicate, the system maintains ease of use while enhancing security reliability.
2Ease of operation
If the same password is used for multiple accounts, then ease of operation is improved, but security is worsened as all accounts become vulnerable when one is compromised
Solution Approach 1:
The patent replaces the practice of using identical passwords across multiple accounts with individual biometric authentication for each account. Each account can be accessed through the user's unique biometric data, eliminating the security risk associated with password reuse while maintaining convenient access.
3Ease of operation
If passwords are stored in a password manager, then ease of operation is improved, but security is worsened due to centralized storage risks
Solution Approach 1:
The patent extracts the authentication function from centralized password managers and implements it directly on the user's device through biometric authentication. This eliminates the need for centralized password storage while maintaining ease of access to multiple accounts through the user's biometric data stored securely on their device.
4Device complexity
If authorization entities rely on resource providers for user authentication, then device complexity is reduced, but security is worsened due to inconsistent authentication quality
Solution Approach 1:
The patent implements self-service authentication where the user's device performs authentication using stored biometric data and cryptographic keys. The device independently verifies user identity without requiring complex authentication infrastructure from resource providers, thereby reducing system complexity while maintaining high authentication quality through consistent biometric verification.
5Ease of operation
If sensitive credentials are transmitted over data networks, then ease of operation is improved, but security is worsened due to vulnerability to man-in-the-middle attacks
Solution Approach 1:
The patent replaces the transmission of sensitive credentials over networks with a key-based authentication mechanism. The user's device stores cryptographic keys locally and uses them to authenticate actions, eliminating the need to transmit passwords or other sensitive credentials over data networks, thereby maintaining ease of remote access while preventing man-in-the-middle attacks.
Data Source
AI summary
A system and techniques are described herein for providing authentication. The technique includes registering user authentication data such as biometrics data with a communication device. The authentication data is linked to an account or service provider, and is used to verify the identity of the user when accessing the account. The communication device may obtain a public/private key pair, for which the pubic key may be stored on a secure remote server. When the user attempts to access the account or service provider, the user may provide the authentication data to authenticate the user to the communication device. Thereafter, the communication device may sign an authentication indicator using the private key and send the authentication indicator to the secure remote server. Upon verification of the signature using the public key, the secure remote server may grant access to the user, for example, by releasing a token.


