Decentralized Biometric Authentication System with Local Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing biometric authentication systems face security risks due to central management of biometric information, making them vulnerable to information leakage.

Innovation Solution

A system comprising an authentication terminal, a server apparatus, and a terminal that stores biometric information and qualification information, where the terminal transmits user information notifications to the authentication terminal, which acquires second biometric information, matches it with stored information, and requests qualification validity from the server, providing service only when the qualification is valid.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If biometric information is centrally managed in an authentication system, then the system can provide authentication services efficiently, but the security risk increases due to potential information leakage

Engineering Contradiction:
Improveauthentication service efficiencyVSAvoidsystem security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the authentication system into multiple independent components: terminal devices that collect and store biometric information locally, authentication servers that verify credentials, and distributed verification nodes. This segmentation prevents centralization of biometric data, reducing security risks while maintaining authentication efficiency through distributed processing

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts biometric information from the central authentication server and stores it locally in terminal devices. This extraction removes the vulnerable central storage of sensitive data while preserving the server's role in verification logic, thus improving security without sacrificing authentication service capability

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If biometric information is stored in terminal devices rather than centrally managed, then security is improved, but system complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service functionality in terminal devices, where each device independently performs biometric data collection, local storage, and initial processing. This self-service approach distributes computational tasks to edge devices, reducing the complexity burden on central servers while maintaining enhanced security through decentralized data management

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary actions by pre-storing biometric information in terminal devices before authentication events occur. This preliminary storage and processing at the edge reduces the complexity of real-time centralized processing while enhancing security, as the heavy lifting of data management occurs locally rather than requiring complex centralized infrastructure

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250047664A1System, authentication terminal, control method of authentication terminal, and storage medium
Publication Date: 2025.02.06 NEC CORP
  • US20250047664A1 patent drawing
  • US20250047664A1 patent drawing
  • US20250047664A1 patent drawing

AI summary

System includes authentication terminal, server apparatus, and terminal. The terminal stores first biometric information of user and qualification information on qualification required to receive service from the authentication terminal. When the terminal is ready to communicate with the authentication terminal, the terminal transmits user information notification including first biometric information and qualification information to the authentication terminal. When the authentication terminal provides the service to the user, the authentication terminal acquires second biometric information of the user and identifies the user to be provided the service by matching processing using acquired second biometric information and first biometric information included in user information notification. The authentication terminal transmits qualification information of the identified user to the server apparatus. The server apparatus determines validity of qualification information and transmits result of the determination to the authentication terminal. The authentication terminal provides the service to the user when qualification information is valid.