Biometric Authentication via Transfer Characteristic Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In biometric authentication systems, there is a risk of leakage of user biometric information when a third party can simultaneously sniff both the one-time parameter generated in the parameter server and the feature value converted by the one-time parameter in the client device, potentially allowing restoration of the original biometric information.

Innovation Solution

A biometric authentication system that includes a response signal reception unit, a probe signal generation unit, a transfer characteristic calculation unit, and an authentication unit, where the client device generates and transmits an echo signal through the user's body, and the authentication server calculates and compares transfer characteristics to authenticate the user, making it difficult for a third party to restore the biometric information from the echo signal.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the client device transmits the converted feature value to the authentication server using a one-time parameter, then the biometric information security is improved, but there is a risk that a third party can sniff both the one-time parameter and the converted feature value to restore the original biometric information

Engineering Contradiction:
Improvebiometric information securityVSAvoidthird party sniffing risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the probe signal generation function from the client device and relocates it to the authentication server. This separation ensures that the client device only handles the response signal measurement and transmission, while the authentication server independently generates the probe signal and performs the conversion calculation, preventing third parties from obtaining both the probe signal and converted feature value simultaneously

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces the transfer characteristic as an intermediary element that decouples the relationship between the probe signal and the converted feature value. The conversion formula uses the transfer characteristic (which remains confidential on the server) as a mediator, so that even if the converted feature value is transmitted over the network, the original biometric information cannot be restored without the transfer characteristic

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the authentication server stores the template acquired by converting the feature value, then the authentication efficiency is improved, but there is a risk that a third party can intrude the authentication server and steal the biometric information

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidserver intrusion risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the parameter being stored from the original biometric feature value to the converted feature value (converted_feature_value = convert_feature_value(probe_signal, transfer_characteristic)). This parameter transformation ensures that the stored data cannot be directly reverse-engineered to obtain the original biometric information, even if the server is compromised

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent converts the potential harm of server storage into a benefit by storing the converted feature value instead of the original biometric information. The conversion process using the transfer characteristic transforms the stored data into a form that is useless to attackers without the transfer characteristic, while still maintaining authentication functionality

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Ease of operation

If the client device uses a sensor to acquire biometric information and convert it using a one-time parameter, then the convenience of biometric authentication is improved, but the complexity of the authentication system increases due to the parameter server

Engineering Contradiction:
Improvebiometric authentication convenienceVSAvoidauthentication system structure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent makes the authentication server perform multiple functions: it generates the probe signal (previously done by the client device), stores the transfer characteristic, performs the conversion calculation, and stores the converted feature value. This consolidation eliminates the need for a separate parameter server while maintaining the security benefits of the one-time parameter approach

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12255890B2Biometric authentication device, biometric authentication system, biometric authentication method and recording medium
Publication Date: 2025.03.18 NEC CORP
  • US12255890B2 patent drawing
  • US12255890B2 patent drawing
  • US12255890B2 patent drawing

AI summary

The present invention reduces the risk of user biometric information being leaked to a third party. A biometric authentication device (820) receives an echo signal (response signal) from a client device. The echo signal is formed as a result of an inspection signal being applied to an authentication subject by a client device, and the inspection signal being transmitted into the body or to the surface of the body of the authentication subject and changing into the echo signal. The biometric authentication device (820) comprises: an inspection signal generation unit (821) that generates the same inspection signal as the client device; a transmission characteristic calculation unit (823) that calculates, from the inspection signal and the echo signal, a transmission characteristic of the authentication subject; and an authentication unit (824) that authenticates the authentication subject by comparing a preregistered first transmission characteristic and a calculated second transmission characteristic.