Cloud Biometric Authentication Using Unique Identifier Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Biometric identifier information is vulnerable to interception, modification, or forgery when transmitted over the Internet for cloud-based authentication, lacking secure methods for user authentication in cloud computing environments.

Innovation Solution

Implementing a system where the cloud services application receives a request for biometric authentication, prompts the user to input a biometric identifier, and uses a unique identifier associated with the biometric data, searching a list of user profiles to verify the identity without transmitting the actual biometric data over the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If biometric identifier information is transmitted over the Internet for cloud-based authentication, then user authentication functionality is enabled, but the biometric data becomes vulnerable to interception, modification, or forgery

Engineering Contradiction:
Improveauthentication functionalityVSAvoiddata security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the biometric data from the transmission process entirely. Instead of transmitting the actual biometric identifier over the network, the system generates a unique identifier that is derived from the biometric data locally on the user device. This unique identifier is then transmitted to the cloud service for authentication, while the sensitive biometric data remains securely stored only on the user's local device. This extraction principle eliminates the security vulnerability while preserving authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a unique identifier as an intermediary element between the biometric data and the cloud authentication system. This unique identifier serves as a safe mediator that carries the necessary authentication information without exposing the actual biometric data. The cloud service authenticates users based on this intermediary identifier rather than handling sensitive biometric information directly, thus resolving the contradiction between authentication capability and data security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If biometric data is not transmitted over the network, then security is enhanced, but the cloud service must verify identity using alternative methods

Engineering Contradiction:
Improvedata securityVSAvoidauthentication process complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by generating and storing the unique identifier locally on the user device before any cloud interaction occurs. The biometric data is processed locally to create this unique identifier, which is then stored in the device's secure storage. This preliminary processing eliminates the need for complex cloud-based biometric verification, as the unique identifier can be directly compared against stored profiles in the cloud, thereby reducing overall system complexity while maintaining high security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a copy or representation of the biometric data in the form of a unique identifier. This unique identifier is a simplified representation that contains the essential authentication information without being the actual biometric data. The cloud service stores and compares these unique identifier copies rather than handling complex biometric templates, which simplifies the verification process while maintaining security.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10979424B2Systems, methods, and apparatuses for secure biometric identifier authentication within a cloud based computing environment
Publication Date: 2021.04.13 SALESFORCE INC
  • US10979424B2 patent drawing
  • US10979424B2 patent drawing
  • US10979424B2 patent drawing

AI summary

A cloud services application executing on a cloud computing platform receives from a browser application executing on a customer computer system a request of a user to login to the cloud services application. The cloud services application further receives an indication via the browser application that biometric identifier authentication of the user is supported by the customer computer system, and transmits an indication to the browser application that biometric identifier authentication of the user is enabled for a session that is to be established. The cloud services application transmits a response to the login request, responsive to receipt of the login request, the response prompting the user to input a biometric identifier, and receives a unique identifier (UID) associated with the biometric identifier. The cloud services application searches a list of user profiles, each with an associated one or more UIDs, for a UID that matches the received UID associated with the biometric identifier and transmits an indication to the browser application allowing access to the web service application responsive to finding a UID that matches the received UID associated with the biometric identifier.