Biometric Authentication System for Secure Web Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing password-based user authentication systems are vulnerable to attacks such as phishing, social engineering, and 'Man in the Browser' attacks, lacking physical authentication and providing inadequate security for transactions.

Innovation Solution

Implementing a biometric authentication system that uses fingerprint or other biometric information, combined with cryptographic algorithms, to verify user identity and secure transactions by integrating biometric sensors with web browser applications and servers, ensuring that only authorized users can initiate transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If password-based authentication is used, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of authenticationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent combines multiple authentication factors (biometric data, device identifiers, and cryptographic tokens) into a unified authentication system. The biometric sensor captures physiological data, which is then processed alongside device information and cryptographic verification to create a multi-layered security approach that maintains user convenience while significantly enhancing security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a server as an intermediary that coordinates between the client device, biometric sensor, and authentication database. This intermediary manages the complex authentication process, verifying biometric data against stored templates and coordinating with the device's cryptographic system, thereby simplifying the user experience while maintaining high security standards.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If longer passwords with combinations of letters and numbers are used, then security is improved, but ease of operation is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidease of authentication
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical system of manual password entry and memorization with an automated biometric recognition system. The biometric sensor captures physiological data (such as fingerprints or facial features), and the system automatically processes this data through cryptographic verification and template matching, eliminating the need for users to remember complex passwords while maintaining high security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If biometric authentication system is implemented, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the authentication system into distinct modular components: a biometric sensor module for capturing physiological data, a processing module for converting raw data into usable templates, a cryptographic module for generating and verifying tokens, and a server-based authentication database. This segmentation allows each component to be optimized independently and simplifies integration and maintenance while providing robust security.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8904495B2Secure transaction systems and methods
Publication Date: 2014.12.02 SYNAPTICS INC
  • US8904495B2 patent drawing
  • US8904495B2 patent drawing
  • US8904495B2 patent drawing

AI summary

A user transaction request is received at a client device. A web browser plug-in communicates the user transaction request to a server that determines whether the user transaction request is a secure transaction. Transaction data is received from the server via the web browser plug-in. If the received transaction data indicates a secure transaction, the user is prompted to provide biometric data, which is received from the user. The web browser plug-in then communicates a transaction confirmation to the server.