Biometric Token Authentication via Encrypted Credential Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Biometric security systems face issues with data security and interoperability, as user biometric information must be stored either in a database or on a device, making it vulnerable to theft or alteration and limiting its use across multiple systems.

Innovation Solution

A method generates a unique user identification code by combining and encrypting a biometric value with a public key, eliminating the need for storing biometric data and allowing multi-system authentication using a smart card token with a microprocessor, RAM, and biometric input unit.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric information is stored in a database or on a device, then user identification and authentication can be performed, but the stored information becomes vulnerable to theft or alteration

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiddata security risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the biometric data from centralized storage and moves it to the user's mobile device, where it is processed locally to generate a credential identifier. This eliminates the need to store sensitive biometric information in databases while maintaining authentication capability through the generated identifier.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a credential identifier as an intermediary element between the biometric data and the authentication system. This credential identifier is generated from the biometric data but is not the biometric data itself, thereby protecting the original biometric information while enabling authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If biometric information is stored in a specific system, then authentication can be performed in that system, but the information cannot be shared among various systems

Engineering Contradiction:
Improveauthentication capabilityVSAvoidmulti-system accessibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal credential identifier that can be used across multiple different authentication systems. The mobile device generates this identifier from the user's biometric data, and the same identifier can be presented to various systems for authentication, enabling multi-system accessibility without requiring system-specific biometric storage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If biometric information is stored on a mobile device, then the user can authenticate without system database access, but the device must carry and process the information

Engineering Contradiction:
Improveauthentication convenienceVSAvoidmobile device requirements
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent stores only the necessary biometric data on the mobile device rather than complete authentication systems. The device performs local processing to generate credential identifiers, which is a partial action that enables authentication without requiring the device to store or process entire system databases, thus balancing convenience with acceptable complexity.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9237018B2Multisystem biometric token
Publication Date: 2016.01.12 HONEYWELL INTERNATIONAL INC
  • US9237018B2 patent drawing
  • US9237018B2 patent drawing
  • US9237018B2 patent drawing

AI summary

An apparatus and a method for generating a unique user identification code for a user of a biometric security system are presented. No biometric information is stored either within the security system or on a device, and the method enables a unique user identification code to be generated to allow multi-system identification of the same user.The method includes receiving a public key from the system, obtaining a characteristic from the user, generating a biometric value from the characteristic, creating the identification code by combining and encrypting the generated biometric value and the system supplied public key, and transmitting the identification code to the system for authentication.