Risk-Based Biometric Authentication Using Trusted Source Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Kiosks face security challenges due to inadequate data storage design parameters, requiring secure access management without storing user information, and varying access levels based on user risk levels that change with authentication.

Innovation Solution

A method involving a security device that receives and compares biometric data from stored and sensed sources, determining a confidence factor and risk factor to grant appropriate access levels without storing user information, using a biometric sensor, input device, and processor to manage access dynamically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric data is stored centrally for authentication, then authentication reliability is improved, but security risk increases due to potential data breaches and unauthorized access

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the biometric template from centralized storage and places it on a trusted source device (e.g., smartphone, HSM). The kiosk only receives and processes the template locally without storing it, thereby removing the security vulnerability of centralized biometric storage while maintaining authentication capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a trusted source as an intermediary between the user and the kiosk. The trusted source holds the biometric template and provides it to the kiosk during authentication, acting as a secure mediator that eliminates the need for the kiosk to store sensitive biometric data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple levels of access are granted to different users, then system versatility is improved, but device complexity increases due to varying authentication requirements

Engineering Contradiction:
Improveaccess level versatilityVSAvoidauthentication system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic access control where the level of access granted is determined at runtime based on the calculated risk factor. The system adjusts authentication requirements dynamically rather than having fixed, pre-configured access levels, simplifying the system architecture while maintaining versatility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of access control from static user roles to dynamic risk-based thresholds. By adjusting the risk threshold parameter, the system can accommodate multiple access levels without requiring complex user role management, simplifying the authentication system while maintaining adaptability.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If biometric data is collected and stored for future reference, then authentication accuracy is improved, but loss of information privacy increases

Engineering Contradiction:
Improveauthentication accuracyVSAvoidinformation privacy
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent extracts only the necessary biometric template data from the user's device and processes it locally at the kiosk without storing it. This extraction approach maintains authentication accuracy by using the full template for comparison while preventing privacy loss by not retaining the data after the authentication transaction completes.

Inventive Principle:
Principle #2Taking out (Extraction)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enhances security by allowing non-customers to access cash transactions using biometric validation without registration, increasing participation and reducing the burden on financial institutions, while maintaining secure access control.

Implementation Method 1

generating sensed biometric data by sensing directly, using a biometric sensor of the security device, the biometric parameter of the user

Methodology Applied
Scientific EffectBiometric sensing:

Data Source

PatentUS11514146B2Risk-based biometric identification and authentication with trusted source for security access
Publication Date: 2022.11.29 NAUTILUS HYOSUNG AMERICA INC
  • US11514146B2 patent drawing
  • US11514146B2 patent drawing
  • US11514146B2 patent drawing

AI summary

A method including receiving, in a security device, a user object storing stored biometric data describing a biometric parameter of the user. Sensed biometric data is generating by sensing directly, using a sensor, the biometric parameter of the user. The stored biometric data is compared to the sensed biometric data. A confidence factor is determined using a first degree of trust, assigned to the object, combined with a second degree of match between the stored biometric data and the sensed biometric data. A user input is received indicating a desired activity. A risk factor is determined based on a combination of the confidence factor and the user input. The risk factor is compared to a selected pre-determined threshold. The user is granted a selected level of access to the security device from among different levels of access to the security device when the risk factor satisfies the selected pre-determined threshold.