Biometric Template Enrollment in Authentication Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication token systems require users to enroll biometric data in a secure environment, which is inconvenient and may expose users to interception risks, as the enablement of a biometric template as a reference template needs to be protected against unauthorized access.
Innovation Solution
A method that splits the biometric enrollment process into a security-irrelevant part for capturing and storing biometric samples offline and a security-relevant part for verifying the template and user identity at a terminal device, allowing remote enrollment without the need for a secure environment, using a biometric sensor and processing unit in the authentication token and a terminal device for verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric enrollment is performed in a secure environment, then security against interception is improved, but user convenience and accessibility deteriorate
Solution Approach 1:
The patent segments the biometric enrollment process into two distinct phases: a secure offline phase where the biometric template is initially created and stored in the authentication token, and a subsequent verification phase where the template is enabled at a terminal device. This segmentation allows the sensitive template creation to occur in a secure environment while the enabling process can happen conveniently at any terminal, resolving the contradiction between security and user convenience.
Solution Approach 2:
The patent performs the security-critical action of creating and storing the biometric template in advance, before the user needs to enroll. The template is created offline in a secure environment and stored in the authentication token, so that when the user later visits a terminal device, only a simple verification and enabling process is needed, rather than performing the entire enrollment process at the terminal.
2Ease of operation
If biometric template enablement is performed remotely, then user convenience is improved, but security against unauthorized access deteriorates
Solution Approach 1:
The patent introduces the authentication token as an intermediary device that holds the biometric template in a secure offline environment. The token acts as a mediator between the user's biometric data and the terminal device, allowing remote enrollment while maintaining security. The template is created offline in the token, and only enabled at the terminal after verification, with the token itself serving as the secure intermediary that protects the template throughout the process.
3Reliability
If multiple verification steps are implemented, then security is improved, but process complexity increases
Solution Approach 1:
The patent segments the multi-step verification process into distinct phases with clear responsibilities: offline template creation, secure storage in the authentication token, and subsequent verification at the terminal device. Each phase has simplified requirements, and the segmentation allows the system to implement multiple verification steps without overwhelming complexity at any single point in the process.
Data Source
Figure 1
Figure 2~3
Figure 4
AI summary
In accordance with a first aspect of the present disclosure, a method is conceived for enabling a biometric template in an authentication token, the method comprising: capturing, by a biometric sensor comprised in the authentication token, at least one biometric sample; creating, by a processing unit comprised in the authentication token, a biometric template from the at least one biometric sample and storing said biometric template in the authentication token; verifying, at a terminal device, said biometric template; verifying, by the terminal device, an identity of a user; enabling, by the terminal device, said biometric template if the biometric template and the identity of the user have been verified. In addition, a corresponding computer program, authentication token and terminal device are provided.