Remote Token Release Using Biometric Key Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods, such as usernames and passwords, are inadequate for securing multiple online accounts, prone to compromise, and lack robust user authentication, while authorization entities struggle to verify user identity, leading to data security issues and vulnerabilities in transmitting sensitive credentials.
Innovation Solution
A system utilizing biometric authentication on a communication device linked to a public/private key pair, where the device signs an authentication indicator with a private key, which is verified by a secure remote server to grant access, ensuring legitimate device authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional username and password authentication is used, then users can access multiple online accounts, but account security is compromised due to password reuse, phishing, and data breaches
Solution Approach 1:
The patent replaces the mechanical password-based authentication system with a biometric authentication system. Biometric data (fingerprint, facial recognition, iris scan) is captured and processed to verify user identity, eliminating the need for users to remember and manage multiple passwords. This substitution provides stronger security through unique biological characteristics while maintaining ease of use through automatic biometric capture.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism that acts as a mediator between the user and the online accounts. The biometric authentication system serves as this intermediary, verifying user identity through cryptographic protocols and token generation. This intermediary layer prevents direct exposure of sensitive credentials while enabling secure access to multiple accounts.
2Reliability
If authorization entities rely on resource providers for user authentication, then authentication can be performed, but data security problems arise due to varying authentication quality across providers
Solution Approach 1:
The patent creates a universal biometric authentication system that can be applied across multiple resource providers and authorization entities. The same biometric authentication mechanism and cryptographic protocol work consistently regardless of which resource provider is involved. This multi-functionality ensures uniform authentication quality across different providers while maintaining a relatively simple system architecture through standardized protocols.
3Ease of operation
If sensitive credentials are transmitted over data networks, then account access is enabled, but security risks increase due to man-in-the-middle attacks
Solution Approach 1:
The patent extracts sensitive credentials from the authentication process entirely. Instead of transmitting passwords or other sensitive data over the network, the system uses biometric verification locally on the user's device and only transmits cryptographic tokens and authentication indicators. This extraction of sensitive data from the transmission path eliminates the vulnerability to man-in-the-middle attacks while maintaining account access functionality.
Solution Approach 2:
The patent uses cryptographic copying mechanisms where the user's biometric identity is verified and represented by cryptographic tokens and digital signatures. These cryptographic copies serve as secure representations of user identity that can be transmitted safely over networks. The actual sensitive biometric data never leaves the user's device, but its cryptographic representation can be verified remotely, enabling secure account access without exposing sensitive information to network attacks.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system and techniques are described herein for providing authentication. The technique includes registering user authentication data such as biometrics data with a communication device. The authentication data is linked to an account or service provider, and is used to verify the identity of the user when accessing the account. The communication device may obtain a public/private key pair, for which the pubic key may be stored on a secure remote server. When the user attempts to access the account or service provider, the user may provide the authentication data to authenticate the user to the communication device. Thereafter, the communication device may sign an authentication indicator using the private key and send the authentication indicator to the secure remote server. Upon verification of the signature using the public key, the secure remote server may grant access to the user, for example, by releasing a token.