Biometric Electronic Signature Token Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional electronic signature methods lack robust authentication and data integrity, particularly in electronic transactions and communications, as they rely solely on digital signatures without incorporating biometric authentication, making them susceptible to unauthorized access and data tampering.
Innovation Solution
The implementation of a Biometric Electronic Signature Token (BEST) system, which generates a tokenized biometric sample, digitally signs it with a private key, and binds it to a record using a public/private key pair, providing a secure and authenticable electronic signature that includes both 'something-you-have' and 'something-you-are' factors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional digital signature methods are used, then electronic transactions can be performed, but authentication robustness and data integrity are insufficient
Solution Approach 1:
The patent combines multiple authentication factors (biometric data, private key, device identifier) into a single integrated digital signature process. The biometric data is encrypted with the private key and combined with device identifiers to create a composite authentication mechanism that resolves the contradiction by merging security elements rather than adding separate systems.
Solution Approach 2:
The digital signature is constructed as a composite structure containing encrypted biometric data, device identifiers, and cryptographic signatures. This composite approach integrates multiple security layers (biometric authentication, cryptographic protection, device binding) into a unified signature that enhances reliability without proportionally increasing complexity.
2Reliability
If biometric authentication is added to electronic signatures, then authentication security is improved, but processing complexity increases
Solution Approach 1:
Biometric data is encrypted with the private key during the initial signature creation process rather than being processed separately later. This preliminary encryption of biometric data integrates the authentication step into the core signing operation, improving data integrity while avoiding the need for separate complex processing stages.
Solution Approach 2:
The patent replaces traditional mechanical authentication methods (physical signatures, manual verification) with cryptographic operations on biometric data. By substituting biometric encryption and digital signature verification for manual processes, the system achieves higher data integrity while reducing the complexity of human-operated verification steps.
3Reliability
If traditional electronic signature methods are used, then transaction speed is maintained, but susceptibility to unauthorized access increases
Solution Approach 1:
The system uses the user's own biometric data and private key to automatically generate the authentication signature without requiring external verification. This self-service approach where the user's biometric characteristics serve as the authentication mechanism maintains transaction speed while dramatically improving authorization security through cryptographic protection of the biometric data.
Solution Approach 2:
The patent changes the authentication parameter from traditional credentials (passwords, tokens) to biometric characteristics encrypted with private keys. This parameter change enables automated biometric verification that occurs rapidly during the signing process, maintaining transaction efficiency while enhancing authorization security through the uniqueness and cryptographic protection of biometric data.
Data Source
AI summary
Systems and methods for verifying an identity of a user. A method includes generating a tokenized biometric sample by tokenizing a biometric sample associated with the user by a computing system. The method further includes generating a digitally-signed tokenized biometric sample by digitally signing the tokenized biometric sample with a private key associated with the user by the computing system. The method further includes, responsive to a biometric reference template matching a signing party biometric sample associated with a signing party and a record, determining that the user matches the signing party by the computing system. The biometric reference template is based on biometric data extracted from the biometric sample. Authenticity and data integrity of the record is determined based on each of the record, the tokenized biometric sample, and a public key of a public/private key pair comprising the private key.


