Biometric Electronic Signature Authentication System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional electronic signature authentication methods fail to effectively validate electronic documents when the document provider is different from the signer, and lack robust verification for integrity and non-repudiation, especially in scenarios involving third-party verification.
Innovation Solution
An electronic signature authentication system and method utilizing biometric information such as handwritten signatures, iris patterns, fingerprints, and voice, which generates and manages public and private keys based on unique biometric data to ensure user identification, document integrity, and non-repudiation, enabling verification of the document provider and signer, and preventing tampering.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional electronic signature authentication method is used, then simple signature verification is achieved, but reliability and security are insufficient for third-party verification and document integrity validation
Solution Approach 1:
The authentication process is segmented into distinct phases: biometric authentication phase (where the user provides biometric data and receives a challenge), document signing phase (where the challenge is incorporated into the signature), and verification phase (where the signature is validated against the biometric template). This segmentation allows each phase to be optimized independently while working together to provide reliable authentication.
Solution Approach 2:
A challenge value acts as an intermediary element that is transmitted between the authentication server and the signing device. The challenge value is generated by the authentication server, incorporated into the signature by the signing device, and used for verification by the verification device. This intermediary enables secure communication and authentication without direct exposure of sensitive biometric data or private keys.
2Measurement precision
If biometric information is used for key generation, then user identification accuracy is improved, but security vulnerabilities arise from biometric data storage and processing
Solution Approach 1:
Instead of storing raw biometric data (fingerprints, facial images, etc.), the system creates a mathematical template or hash representation of the biometric data. This template is what is actually stored and processed throughout the authentication system. The template serves as a copy that retains the essential identification characteristics while eliminating the sensitive original biometric data from the system.
Solution Approach 2:
The system extracts only the essential authentication information from the biometric data and discards or destroys the original biometric templates after authentication. By taking out only the necessary challenge-response verification capability and eliminating the stored biometric templates, the system maintains identification accuracy while removing the security vulnerability associated with storing sensitive biometric data.
3Adaptability or versatility
If multiple encryption keys are managed for different users and documents, then authentication versatility is improved, but key management complexity increases
Solution Approach 1:
The authentication server and verification system serve multiple functions: they authenticate users through biometric verification, manage encryption keys for different users, validate document integrity, and provide non-repudiation. This multi-functional design eliminates the need for separate key management systems for each user or document type, reducing overall system complexity while maintaining high versatility.
Solution Approach 2:
The system implements feedback mechanisms where the authentication server verifies the challenge-response pair and provides confirmation of successful authentication. The verification device receives feedback about the validity of the signature and the identity of the signer. This feedback loop simplifies key management by providing clear validation results without requiring complex manual verification procedures.
Data Source
AI summary
The present disclosure provides an electronic signature authentication system and method capable of enhancing stability and reliability of an electronic signature by generating electronic signature information for authentication of an electronic document based on biometric information of a user. The electronic signature authentication system includes an authentication server, a user device, and an electronic document device, and is capable of providing identification of an electronic document provider among the electronic document provider, a signer of the electronic document, and a third party person using a signed electronic document, and providing verifications of integrity of the electronic document, prevention of repudiation of the signer, verification of whether the electronic document signed by the signer is identical to the electronic document provided by the electronic document provider, and a scheme for preventing falsification or tampering of the electronic document committed by the electronic document provider.


