Biometric Authentication Flow With Token-Guided Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing biometric authentication systems face challenges with high false acceptance and rejection rates, especially in large databases, and require manual user input for one-to-one matching, leading to inefficiencies and user inconvenience.
Innovation Solution
A method and device for multi-factor authentication that includes receiving an identification token from a user device, obtaining a verification status from a biometric service, determining user authentication based on this status, and approving secure service access, utilizing one-to-one and one-to-few matching before one-to-many matching to enhance efficiency and reduce latency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If one-to-many biometric matching is used in large databases, then comprehensive user identification is achieved, but authentication time and latency increase significantly
Solution Approach 1:
The patent segments the biometric matching process into three distinct phases: one-to-one matching for quick verification, one-to-few matching for narrowed-down candidates, and one-to-many matching for comprehensive database search. This segmentation allows the system to perform most authentications quickly using restricted candidate sets while maintaining the ability to perform exhaustive searches when necessary, thereby reducing overall authentication latency while preserving accuracy.
Solution Approach 2:
The system performs preliminary filtering actions before the full one-to-many matching process. By using one-to-one and one-to-few matching as preliminary steps to identify potential candidates, the system prepares a narrowed-down candidate set that reduces the scope of subsequent comprehensive matching, thus reducing authentication time while maintaining reliability.
2Reliability
If centralized biometric authentication systems are used, then one-to-one matching capability is provided, but user convenience deteriorates due to manual credential input requirements
Solution Approach 1:
The patent implements self-service functionality where the user's mobile device automatically performs device fingerprinting and generates identification tokens without manual intervention. The system automatically extracts device characteristics, creates cryptographic identifiers, and initiates the authentication process, eliminating the need for users to manually input credentials while maintaining secure one-to-one matching capabilities.
Solution Approach 2:
The system replaces manual mechanical credential input with automated electronic processes. Instead of users physically entering usernames or passwords, the system uses automated device fingerprinting and cryptographic token generation to identify users, substituting manual operations with electronic self-service mechanisms that improve both convenience and security.
3Reliability
If traditional multi-factor authentication is implemented, then security is improved, but system complexity increases beyond single-point authentication
Solution Approach 1:
The patent merges multiple authentication factors into a unified biometric-based system. It combines device fingerprinting, biometric verification, and cryptographic token validation into a single integrated authentication flow, eliminating the need for separate multi-factor authentication steps while maintaining enhanced security against fraud.
Solution Approach 2:
The system creates a universal authentication mechanism that can handle various authentication scenarios (one-to-one, one-to-few, one-to-many matching) through a single biometric verification framework. This multi-functional approach provides MFA-level security without requiring separate authentication systems for different scenarios, thereby reducing overall system complexity.
Data Source
AI summary
Disclosed are techniques for authentication. In some aspects, an authentication device may receive, from a user device, an identification token of a user attempting to access a secure service. The authentication device may obtain, from a biometric service, a verification status of the user based at least in part on the identification token. The authentication device may determine whether the user is authenticated based at least in part on the verification status. The authentication device may approve access to the secure service based on a determination that the user is authenticated.


