Biometric Session Management for Secure Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure communication systems, such as VPNs, face challenges in ensuring that confidential information is accessed only by authorized individuals, particularly in remote working scenarios where security risks are heightened due to the presence of unauthorized persons.

Innovation Solution

The system implements personalized secure communication session management by authenticating users through a multi-factor authentication process that includes biometric verification, ensuring that only authorized users can access secured resources and that access is continuously monitored and secured.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multi-factor authentication with biometric verification is implemented, then security against unauthorized access is improved, but device complexity and authentication time increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs biometric verification and authentication checks in advance before granting access to secured resources. The continuous monitoring mechanism is pre-established, so that when access is requested, the verification has already been performed, reducing the perceived complexity for the user while maintaining high security standards.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The biometric authentication system uses the user's own biological characteristics (fingerprint, facial recognition, etc.) to verify identity, eliminating the need for external verification devices or complex manual authentication processes. The system serves itself by using inherently unique user traits for security verification.

Inventive Principle:
Principle #25Self-service

2Reliability

If continuous authentication monitoring is implemented, then protection against unauthorized access is improved, but processing overhead and system resource consumption increase

Engineering Contradiction:
Improvecontinuous security protectionVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

Instead of continuous real-time monitoring that would consume constant resources, the system implements periodic authentication checks at defined intervals during the secure communication session. This maintains security protection while allowing the system to enter low-power states between checks, significantly reducing overall resource consumption.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The authentication monitoring maintains continuous security protection through a series of periodic checks that together provide uninterrupted coverage. The useful action of security verification continues without gaps, but the system optimizes resource usage by allowing brief idle periods between authentication confirmations.

Inventive Principle:
Principle #20Continuity of useful action

3Reliability

If strict authentication requirements are enforced, then security against unauthorized access is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveaccess securityVSAvoidaccess convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system replaces traditional mechanical authentication methods (passwords, physical tokens, manual verification) with biometric verification using optical, acoustic, or other sensing fields. This substitution maintains strict security requirements while dramatically improving ease of operation, as users simply need to present their biological characteristics rather than remember complex credentials or carry physical devices.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12335239B2Personalized secure communication session management
Publication Date: 2025.06.17 JOURNEY AI
  • US12335239B2 patent drawing
  • US12335239B2 patent drawing
  • US12335239B2 patent drawing

AI summary

The techniques herein are directed generally to personalized secure communication session management, such as for virtual private networks (VPNs). In one embodiment, a user is authenticated at a client device to verify that the user is present at the client device and authorized to access one or more secured resources, and in response, a secure communication session is established for the client device to access the secured resources. At a later time during the secure communication session, it is determined whether the user is still authenticated at the client device, such that if so, access to the one or more secured resources is maintained on the secure communication session, or else access is restricted to the one or more secured resources (e.g., the session is terminated, or access is otherwise limited).