Biometric User Identification via Trusted Platform Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing online identity verification methods, such as usernames and passwords, are insecure and can be easily compromised, allowing impersonation and cybercrime, while two-factor authentication is not foolproof, especially with stolen devices.

Innovation Solution

A system that uses an electronic personal computing device, an electronic access controller, and a trusted platform server for user identification, where user data is validated by the device and confirmed by a trusted third party, ensuring multiple communication channels are used to prevent interception, and biometric data is used for secure authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional username and password authentication is used, then the system is easy to operate, but security is compromised and impersonation is possible

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a trusted platform server as an intermediary between the user and the access control system. This server validates user credentials and provides authentication confirmation, thereby enhancing security without requiring the user to directly manage complex security protocols. The intermediary handles the security-critical operations while maintaining ease of use for the end user.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is divided into separate functional components: the electronic personal computing device that collects user data, the trusted platform server that validates credentials, and the access controller that grants access. This segmentation allows each component to specialize in specific security functions, improving overall system security while maintaining operational simplicity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If two-factor authentication is implemented, then security is improved to some extent, but it remains vulnerable to stolen devices and SMS code interception

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional SMS-based two-factor authentication with a biometric-based verification system. Instead of relying on mechanical processes like SMS transmission and manual code entry, the system uses biological characteristics (fingerprint, facial recognition, iris scan) that are inherently more secure and difficult to compromise. This substitution eliminates the vulnerability to SMS interception while maintaining user-friendly operation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The authentication method changes from using knowledge-based credentials (passwords, SMS codes) to biometric parameters. The system verifies the user's identity by comparing biometric data against stored templates, fundamentally changing the authentication parameter from something the user knows to something the user is, thereby improving security against device theft and interception.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If identity matching databases are used, then identification can be performed, but the system becomes vulnerable to hacking and identity theft

Engineering Contradiction:
Improveidentification accuracyVSAvoididentity fraud risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary validation of user credentials through the trusted platform server before granting access. The server pre-verifies the authenticity of biometric data and other identifying information against secure databases, ensuring that only genuinely authorized users can proceed. This preliminary action prevents unauthorized access attempts before they can compromise the system.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The trusted platform server acts as an intermediary that mediates between the user's biometric data and the identification databases. Rather than directly querying databases that could be targeted by hackers, the system routes verification through a secure intermediary that validates credentials and provides authentication confirmation, thereby reducing the risk of database exploitation and identity theft.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If multiple communication channels are used for verification, then security against interception is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted platform server provides multi-functional capabilities by handling multiple verification tasks through a single communication interface. It validates biometric data, verifies user credentials, checks against identification databases, and provides authentication confirmation all through one secure channel. This universal approach achieves the security benefits of multiple verification steps without the complexity of managing multiple separate communication systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250240294A1User identification system
Publication Date: 2025.07.24 HANSCAN HLDG LTD
  • US20250240294A1 patent drawing
  • US20250240294A1 patent drawing
  • US20250240294A1 patent drawing

AI summary

A system is provided comprising an access controller that can grant—or deny to a person or device an access to a location or premises, a service provided via an electronic access point like a web shop. The access is denied or granted based on an identification of a user by means of an electronic computing device. The device is arranged to collect data identifying the user, like biometric data and to verify whether the data received matches data related to a user, which data has been received before. The system further comprises a trusted platform server. Upon successful identification of the user, the personal computing device confirms the identification to the trusted platform. The trusted platform notifies the access controller that identification was successful and the access controller may thereupon grant the requested access.