Cloud Biometric Authentication Using Unique Identifier Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Biometric identifier information is vulnerable to interception, modification, or forgery when transmitted over the Internet for cloud-based authentication, lacking secure methods for user authentication in cloud computing environments.
Innovation Solution
Implementing a system where the cloud services application receives a request for biometric authentication, prompts the user to input a biometric identifier, and uses a unique identifier associated with the biometric data, searching a list of user profiles to verify the identity without transmitting the actual biometric data over the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If biometric identifier information is transmitted over the Internet for cloud-based authentication, then user authentication functionality is enabled, but the biometric data becomes vulnerable to interception, modification, or forgery
Solution Approach 1:
The patent extracts the biometric data from the transmission process entirely. Instead of transmitting the actual biometric identifier over the network, the system generates a unique identifier that is derived from the biometric data locally on the user device. This unique identifier is then transmitted to the cloud service for authentication, while the sensitive biometric data remains securely stored only on the user's local device. This extraction principle eliminates the security vulnerability while preserving authentication functionality.
Solution Approach 2:
The patent introduces a unique identifier as an intermediary element between the biometric data and the cloud authentication system. This unique identifier serves as a safe mediator that carries the necessary authentication information without exposing the actual biometric data. The cloud service authenticates users based on this intermediary identifier rather than handling sensitive biometric information directly, thus resolving the contradiction between authentication capability and data security.
2Object-affected harmful factors
If biometric data is not transmitted over the network, then security is enhanced, but the cloud service must verify identity using alternative methods
Solution Approach 1:
The patent applies preliminary action by generating and storing the unique identifier locally on the user device before any cloud interaction occurs. The biometric data is processed locally to create this unique identifier, which is then stored in the device's secure storage. This preliminary processing eliminates the need for complex cloud-based biometric verification, as the unique identifier can be directly compared against stored profiles in the cloud, thereby reducing overall system complexity while maintaining high security.
Solution Approach 2:
The patent creates a copy or representation of the biometric data in the form of a unique identifier. This unique identifier is a simplified representation that contains the essential authentication information without being the actual biometric data. The cloud service stores and compares these unique identifier copies rather than handling complex biometric templates, which simplifies the verification process while maintaining security.
Data Source
AI summary
A cloud services application executing on a cloud computing platform receives from a browser application executing on a customer computer system a request of a user to login to the cloud services application. The cloud services application further receives an indication via the browser application that biometric identifier authentication of the user is supported by the customer computer system, and transmits an indication to the browser application that biometric identifier authentication of the user is enabled for a session that is to be established. The cloud services application transmits a response to the login request, responsive to receipt of the login request, the response prompting the user to input a biometric identifier, and receives a unique identifier (UID) associated with the biometric identifier. The cloud services application searches a list of user profiles, each with an associated one or more UIDs, for a UID that matches the received UID associated with the biometric identifier and transmits an indication to the browser application allowing access to the web service application responsive to finding a UID that matches the received UID associated with the biometric identifier.


