Remote Authentication Using Dynamic Biometrics and Challenge Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current electronic authentication methods in e-commerce are vulnerable to fraud due to reliance on static biometrics and two-factor authentication systems that can be easily compromised, leading to significant financial losses and security breaches, with no effective solution that meets NIST's multi-factor authentication standards.

Innovation Solution

A multi-factor authentication system using a user's possession of a device, a secret password, and a dynamic biometric identity, combined with a random challenge-response method, providing high-assurance authentication through cryptographic binding and behavioral biometrics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If biometric authentication systems are implemented, then authentication convenience is improved, but susceptibility to spoofing attacks increases

Engineering Contradiction:
Improveauthentication convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a liveness detection module as an intermediary between the biometric sensor and authentication decision system. This intermediary analyzes physiological signals (pupil response, skin conductivity changes, blood flow patterns) to verify that the biometric sample comes from a living person rather than a spoof, thereby maintaining authentication convenience while eliminating spoofing vulnerabilities

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically changes authentication parameters by switching between different biometric modalities (fingerprint, facial recognition, iris scanning) and adjusting verification stringency based on risk assessment. When spoofing is detected or suspected, the system changes the authentication challenge parameters to require additional verification steps, thus maintaining security without permanently impacting user convenience

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple authentication factors are required, then authentication security is improved, but authentication time increases

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a dynamic authentication system that adjusts the number and type of authentication factors required based on real-time risk assessment. For low-risk scenarios (recognized devices, consistent user behavior patterns), only one factor is required. For high-risk scenarios (new devices, unusual locations, behavior anomalies), additional factors are dynamically added, optimizing both security and speed for each authentication event

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary authentication actions in advance by continuously monitoring device usage patterns, location data, and behavioral biometrics during normal device operation. This preliminary data collection and analysis enables the system to pre-assess risk levels, so that when actual authentication is needed, the system already has context information ready, reducing the time required for multi-factor authentication

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4433923B1Systems and methods for trustworthy electronic authentication using a computing device
Publication Date: 2026.05.20 BENNISON JAMES E
  • EP4433923B1 patent drawingFigure 1
  • EP4433923B1 patent drawingFigure 2a
  • EP4433923B1 patent drawingFigure 2b

AI summary

A method, system, and digital recording medium provides for convenient and trustworthy user authentication with a computing device combining four authentication factors through use of a remote authentication system (RAS). An identity token (Device-ID) cryptographically bound to the user's computing device is generated as a first authentication factor. A password known only to the user is a second factor. Cryptographic signatures generated from the user's biometric minutiae is a third factor. A random challenge received from the RAS is a fourth factor. An encryption key-generation key is created cryptographically using the Device-ID and stored locally, which together with the user's cryptographic signatures are encrypted with a one-time-pad encryption key obtained from the RAS on a communication channel different from that used for other communication between the device and the RAS to provide perfect secrecy, then transmitted from the device to the RAS on a connection therebetween to register said shared-secrets.