Biometric Tokenless Authentication Using Hashed Identity Linking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing payment and identity verification systems are vulnerable to fraud and identity theft due to the reliance on physical cards and stored user data, which can be hacked or intercepted, necessitating a secure, tokenless authentication method.
Innovation Solution
A biometric authorization system that uses multi-modal security and encryption to authenticate transactions and identity verification without physical tokens, utilizing biometric sampling and generating unique digital identifiers through one-way hash functions, stored in separate secure repositories to ensure secure and conclusive identity verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If physical cards and stored user data are used for authentication, then ease of operation is improved, but security and reliability deteriorate due to vulnerability to hacking and identity theft
Solution Approach 1:
The patent replaces physical cards with digital biometric templates stored in secure repositories. Instead of storing actual biometric data, the system creates and stores hashed templates that can be verified without exposing the original biometric data, thereby maintaining ease of use while improving security against hacking and data breaches
Solution Approach 2:
The patent substitutes the mechanical physical card system with a biometric authentication system using fingerprints, facial recognition, or other biometric characteristics. This replacement eliminates the need for physical tokens that can be lost or stolen, while providing more reliable authentication through unique biological identifiers
2Ease of operation
If physical tokens and stored data are used for authentication, then ease of operation is improved, but loss of information increases due to hacking and interception
Solution Approach 1:
The system stores hashed templates of biometric data rather than the actual biometric data itself. This copying approach ensures that even if the stored data is compromised during hacking, the original biometric information remains secure, preventing information loss and enabling continued authentication operations
Solution Approach 2:
The patent introduces secure repositories and intermediary verification systems between the user's biometric data and the authentication process. These intermediaries handle only the hashed templates, not the actual biometric data, creating a layer of protection that prevents direct exposure and loss of sensitive information during transmission and storage
3Reliability
If biometric sampling and one-way hash functions are used, then security is improved, but device complexity increases
Solution Approach 1:
The patent divides the authentication system into separate functional modules: biometric sampling components, one-way hash function processing, template storage repositories, and verification systems. This segmentation allows each component to be optimized independently and simplifies the overall system architecture by distributing complexity across specialized modules rather than requiring a single complex integrated system
Data Source
AI summary
Systems and methods for tokenless authorization are provided. Obtaining an electronic representation of an initial biometric sampling of a registrant. Applying the initial electronic representation to a template data construct producing a unique digital identifier (UDI). Obtaining account information constructs corresponding to an account by the registrant with a third party. Generating a unique secure identification number (SIN) using the UDI and the account information constructs. Storing a unique link from the UDI to the account information constructs. Receiving a request for service and an electronic representation of a second biometric sampling. Forming the UDI by applying the second electronic representation to the template data construct. Verifying the UDI corresponds to the stored UDI to reconstruct the unique SIN from the UDI and using this unique SIN to retrieve the account information constructs using the indexed data structure. Transmitting the request and the unique SIN to the third party.


