Biometric Self-Enrollment via Portable Device and Enrollment Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional biometric authentication systems require cumbersome and inconvenient enrollment processes that often necessitate users to visit a specific location, making them impractical and costly for widespread distribution.
Innovation Solution
A method and system for biometric self-enrollment using a portable device and an enrollment device, where users receive these devices and an enrollment identifier through separate communications, allowing them to enroll securely and efficiently without specialized software or cryptographic keys, enabling biometric data capture and storage on the portable device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional biometric enrollment is performed at a special location with sophisticated devices, then security and authentication reliability are improved, but user convenience and ease of operation deteriorate
Solution Approach 1:
The system enables users to perform biometric enrollment independently at any location using their own portable devices. The enrollment device communicates with the portable device to capture and store biometric data without requiring user presence at a specialized enrollment location, thus maintaining security while dramatically improving convenience.
Solution Approach 2:
The patent introduces an enrollment device as an intermediary between the user's portable device and the authentication system. This intermediary facilitates secure biometric enrollment by communicating with the portable device's biometric sensor and securely transmitting enrollment data, enabling remote enrollment while maintaining system security standards.
2Reliability
If sophisticated enrollment devices with specialized software and cryptographic keys are distributed to users, then security is improved, but device complexity and cost increase
Solution Approach 1:
The patent extracts the cryptographic keys and specialized software from the enrollment device and relocates them to the portable device. The enrollment device becomes a simpler communication interface that facilitates enrollment without storing sensitive cryptographic materials, thereby reducing its complexity while maintaining security through the portable device's secure elements.
Solution Approach 2:
The system uses the portable device as a copy of the authentication functionality, enabling it to store biometric templates and cryptographic keys locally. This allows the portable device to serve as a standalone authentication credential, eliminating the need for users to carry or rely on complex enrollment devices with embedded security infrastructure.
3Productivity
If enrollment devices are made simple and distributed widely, then ease of operation and productivity are improved, but security features and cryptographic capabilities deteriorate
Solution Approach 1:
The system segments security functions across multiple components: the enrollment device handles user interface and communication, the portable device stores cryptographic keys and biometric templates in its secure element, and the authentication system performs verification. This segmentation allows the enrollment device to remain simple while security is maintained through the distributed architecture.
Solution Approach 2:
The enrollment device acts as a mediator that facilitates secure enrollment communication between the user and the authentication system without needing to implement complex security features itself. It transmits enrollment data securely to the portable device, which then stores it in its secure element, thereby maintaining security while keeping the enrollment device simple.
Data Source
AI summary
A method and system for biometric self-enrollment is provided. A user can receive a portable device and an enrollment device, as well as an enrollment identifier in a separate communication. The user can couple the portable device and the enrollment device, enter the enrollment identifier into the enrollment device. Using the coupled portable device, the user can capture a biometric that can be stored on the portable device. At another time, a user can provide an additional biometric to the portable device. The portable device can compare the biometric received during the biometric self-enrollment and compare it to the additional biometric as part of a biometric authentication procedure. An enrolled portable device can be utilized for a variety of subsequent transactions.


