Biometric Authentication for Secure Remote Token Release

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods, such as usernames and passwords, are inadequate for securing multiple online accounts, prone to compromise, and do not allow authorization entities to authenticate users effectively, while transmitting sensitive credentials is vulnerable to attacks.

Innovation Solution

A system using biometric authentication on a communication device linked to a public/private key pair, where the public key is stored on a secure remote server, verifies user identity by signing an authentication indicator with the private key and releasing a token upon successful verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If usernames and passwords are used for authentication, then ease of operation is improved, but security is worsened due to susceptibility to compromise and phishing

Engineering Contradiction:
Improveease of authenticationVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical/password-based authentication system with a biometric authentication system. Biometric data (fingerprint, facial recognition, iris scan) is used to authenticate users, eliminating the need for usernames and passwords. This substitution maintains ease of operation while dramatically improving security against compromise and phishing attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the authentication parameter from discrete credentials (usernames/passwords) to continuous biometric characteristics. By using biometric data that is unique to each user and difficult to replicate, the system maintains ease of use while enhancing security reliability.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If the same password is used for multiple accounts, then ease of operation is improved, but security is worsened as all accounts become vulnerable when one is compromised

Engineering Contradiction:
Improveease of account accessVSAvoidaccount security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the practice of using identical passwords across multiple accounts with individual biometric authentication for each account. Each account can be accessed through the user's unique biometric data, eliminating the security risk associated with password reuse while maintaining convenient access.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Ease of operation

If passwords are stored in a password manager, then ease of operation is improved, but security is worsened due to centralized storage risks

Engineering Contradiction:
Improveease of password managementVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the authentication function from centralized password managers and implements it directly on the user's device through biometric authentication. This eliminates the need for centralized password storage while maintaining ease of access to multiple accounts through the user's biometric data stored securely on their device.

Inventive Principle:
Principle #2Taking out (Extraction)

4Device complexity

If authorization entities rely on resource providers for user authentication, then device complexity is reduced, but security is worsened due to inconsistent authentication quality

Engineering Contradiction:
Improveauthentication system complexityVSAvoidauthentication quality
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements self-service authentication where the user's device performs authentication using stored biometric data and cryptographic keys. The device independently verifies user identity without requiring complex authentication infrastructure from resource providers, thereby reducing system complexity while maintaining high authentication quality through consistent biometric verification.

Inventive Principle:
Principle #25Self-service

5Ease of operation

If sensitive credentials are transmitted over data networks, then ease of operation is improved, but security is worsened due to vulnerability to man-in-the-middle attacks

Engineering Contradiction:
Improveease of remote accessVSAvoiddata transmission security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the transmission of sensitive credentials over networks with a key-based authentication mechanism. The user's device stores cryptographic keys locally and uses them to authenticate actions, eliminating the need to transmit passwords or other sensitive credentials over data networks, thereby maintaining ease of remote access while preventing man-in-the-middle attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250274281A1Secure remote token release with online authentication
Publication Date: 2025.08.28 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US20250274281A1 patent drawing
  • US20250274281A1 patent drawing
  • US20250274281A1 patent drawing

AI summary

A system and techniques are described herein for providing authentication. The technique includes registering user authentication data such as biometrics data with a communication device. The authentication data is linked to an account or service provider, and is used to verify the identity of the user when accessing the account. The communication device may obtain a public/private key pair, for which the pubic key may be stored on a secure remote server. When the user attempts to access the account or service provider, the user may provide the authentication data to authenticate the user to the communication device. Thereafter, the communication device may sign an authentication indicator using the private key and send the authentication indicator to the secure remote server. Upon verification of the signature using the public key, the secure remote server may grant access to the user, for example, by releasing a token.