Cloud Biometric Step-Up Authentication for Cross-Device Identity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing biometric authentication methods are device-centric, lacking the ability to verify user identity based on who they are, introducing security risks such as phishing, device vulnerability, and requiring re-enrollment across devices.

Innovation Solution

A cloud-centric biometric step-up and authentication process that involves capturing a user's photograph on their device, encrypting it, and processing it against pre-recorded templates in the cloud for identity confirmation, ensuring liveness and device integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If device-centric biometric authentication is used, then authentication speed is improved, but security reliability deteriorates because the system trusts the device rather than verifying the user's actual identity

Engineering Contradiction:
Improveauthentication speedVSAvoidsecurity reliability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent introduces a cloud-based intermediary service that acts as a mediator between the user's device and the authentication system. The cloud service receives biometric data from the device, performs verification against stored templates, and returns authentication results. This intermediary approach maintains the speed of device-based authentication while adding a layer of security that actually verifies user identity rather than just trusting device assertions.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into distinct components: the user's local device that captures biometric data, the cloud service that stores templates and performs verification, and the application that requests authentication. This segmentation allows the device to operate quickly for data collection while the cloud handles the security-critical verification process, resolving the contradiction between speed and reliability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If cloud-based biometric verification is implemented, then security reliability is improved, but device complexity increases due to additional cloud communication and processing requirements

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The user's device performs self-service by locally capturing biometric data and preparing it for transmission. The device autonomously manages the authentication initiation, data formatting, and cloud communication without requiring complex local verification algorithms. This self-service approach simplifies the device while the cloud handles the complex verification logic.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The complex biometric verification logic and template storage are extracted from the user device and placed in the cloud service. The device only needs to perform simple data capture and transmission functions, while the cloud handles the computationally intensive tasks of template matching and security verification. This extraction reduces device complexity while maintaining high security reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If biometric templates are stored in the cloud, then adaptability across devices is improved, but information security risks increase due to centralized storage of sensitive biometric data

Engineering Contradiction:
Improvecross-device adaptabilityVSAvoiddata security risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system implements local quality by encrypting biometric templates with device-specific or user-specific keys before storing them in the cloud. Each user's biometric data is protected with unique cryptographic parameters, ensuring that even though data is centralized in the cloud, each individual's biometric information maintains its own security characteristics and cannot be easily compromised or transferred to other devices.

Inventive Principle:
Principle #3Local quality

4Ease of operation

If traditional password-based authentication is used, then ease of operation is maintained, but security reliability deteriorates due to vulnerabilities like phishing and device theft

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical/password-based authentication system with a biometric authentication system. Instead of relying on users to remember and enter passwords (mechanical interaction), the system uses automated biometric capture and verification. This substitution maintains ease of operation since biometric authentication is more intuitive and requires less user effort, while simultaneously improving security reliability by using unique physiological characteristics that cannot be easily compromised like passwords.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12598179B2Systems and methods for cloud-centric biometric step-up and authentication
Publication Date: 2026.04.07 ZSCALER INC
  • US12598179B2 patent drawing
  • US12598179B2 patent drawing
  • US12598179B2 patent drawing

AI summary

Systems and methods for cloud-centric biometric step-up and authentication include monitoring traffic from one or more endpoints via a cloud service; determining a requirement for authentication of a user associated with the traffic based on the monitoring; causing a computing device associated with the user and the traffic to capture a photograph of the user; and processing the photograph to confirm an identity of the user. In various embodiments, the capturing of the photograph is performed by a computing device associated with the user, wherein the processing of the photograph is performed by the cloud service for identification of the user.