Cross-Channel Biometric Authentication Without Passwords or Apps
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for web applications often require passwords, which are cumbersome and prone to breaches, leading to high support costs and abandoned transactions, while workstations lacking biometrics face additional friction.
Innovation Solution
Utilizing biometric authentication on pre-registered smart/mobile devices to streamline app-free access, where a workstation browser interacts with an authorization server to redirect authentication via encoded combinations, such as QR codes, leveraging biometric capabilities of the device for seamless access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If password-based authentication is used, then security can be maintained, but user friction increases and support costs rise
Solution Approach 1:
The patent replaces the mechanical/password-based authentication system with a biometric authentication system. Instead of requiring users to manually enter passwords, the system uses biometric data (fingerprint, face recognition, iris scan) captured by the mobile device to automatically authenticate users. This substitution eliminates the friction of password entry while maintaining or enhancing security through more reliable biometric verification.
Solution Approach 2:
The mobile device itself serves as the authentication mechanism, leveraging its built-in biometric sensors and processing capabilities. The device autonomously captures biometric data, processes it through its secure enclave, and communicates authentication status to the workstation without requiring user intervention beyond presenting the device. This self-service approach reduces support costs by eliminating password reset requirements.
2Reliability
If multi-factor authentication is implemented, then security is enhanced, but authentication complexity increases
Solution Approach 1:
The patent merges multiple authentication factors into a single unified flow. The biometric authentication on the mobile device simultaneously provides both something the user has (the device itself) and something the user is (biometric data). The QR code exchange combines device-to-device communication with server verification, consolidating what would traditionally require separate steps into one integrated authentication sequence.
Solution Approach 2:
The patent introduces a QR code as an intermediary mechanism that simplifies the authentication flow. Instead of directly complex multi-factor verification, the system uses QR codes to encode authentication state and enable seamless handoff between mobile device and workstation. This intermediary abstracts the complexity of multi-factor authentication into a simple scan-and-verify process.
3Ease of operation
If biometric authentication on mobile devices is used, then user experience is improved, but compatibility with workstations without biometrics is challenged
Solution Approach 1:
The patent makes the mobile device universal by leveraging its existing biometric capabilities (which are standard in modern smartphones) to authenticate users across multiple platforms and devices. The same mobile device that users carry for personal use becomes the authentication key for workstation access, eliminating the need for workstation-specific biometric hardware. The system adapts to various workstation configurations through browser-based implementation.
Solution Approach 2:
Instead of requiring the workstation to have biometric capabilities, the patent inverts the approach by placing biometric authentication on the mobile device that the user already possesses. The authentication flow is reversed: rather than the workstation verifying the user's biometrics directly, the mobile device performs biometric verification and then proves authentication to the workstation through QR code exchange. This inversion allows any workstation with a camera and browser to support biometric authentication.
Data Source
AI summary
The technology disclosed teaches performing biometric app free authentication or authorization of a user to access a web-based application, with the user interacting with a workstation browser running on a workstation to access the web-based application using built-in resources of a smart/mobile device. A web application uses methods to authenticate and authorize users before the users are permitted to access the application. A demand exists for improving the security and ease of use of authentication and access management. Access management and authentication of users has evolved to more than just entering a username and password. Multi-factor authentication (MFA) is common. The numerous paths involved in authentication use numerous forms of identification of users during the authentication journey. An opportunity arises to combine paths used for non-standard circumstances with device codes and biometrics for users to log into web applications conveniently and securely without installing another app for authentication and authorization.


