Dynamic User Identification With Biometric Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication systems, particularly those relying on static user identifiers and passwords, are susceptible to credential theft and compromise, leading to unauthorized access, and often burden users with cumbersome multi-factor authentication processes, compromising user experience and security.

Innovation Solution

Implement a dynamic user identifier (DID) system combined with biometric authentication, where a time-based token (e.g., TOTP) serves as the UID and facial recognition or other biometrics verify the user, eliminating the need for static credentials and enhancing security through a transparent, user-friendly process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static user identifiers and passwords are used for authentication, then the authentication process is simple and familiar to users, but the system is susceptible to credential theft and compromise

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent transforms static user identifiers into dynamic identifiers that change over time or with each authentication attempt. This is achieved by using time-based tokens (TOTP) or counter-based tokens (HOTP) that generate different identifiers for each authentication session, making stolen credentials useless after a single use or after expiration, thereby resolving the security vulnerability while maintaining user-friendly operation

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the temporal parameter of user identifiers from static to dynamic by introducing time-based or usage-based validity periods. Credentials expire after a predetermined time or number of uses, fundamentally altering the security parameter without requiring complex multi-factor authentication processes, thus improving security while preserving ease of operation

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multi-factor authentication is implemented to enhance security, then unauthorized access is reduced, but user experience is compromised with cumbersome processes

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the identifier and credential verification into a single dynamic token that encompasses both functions. The time-based or counter-based token serves as both the user identifier and the authentication credential, eliminating the need for separate multi-factor authentication steps while maintaining strong security through the dynamic nature of the token

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system enables self-service authentication where the user's device automatically generates and manages dynamic credentials without requiring additional authentication factors or complex user actions. The token is automatically updated and validated by the server, reducing device complexity and improving user experience while maintaining security

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12430415B1Authentication with dynamic user identification
Publication Date: 2025.09.30 US BANK NATIONAL ASSOCIATION
  • US12430415B1 patent drawing
  • US12430415B1 patent drawing
  • US12430415B1 patent drawing

AI summary

An embodiment includes receiving, from a device, at an authentication service, a dynamic user identifier having a one-time password in an authentication message constructed to carry the dynamic user identifier in place of a pre-determined user identifier of a user. The embodiment locates in a profiles database, using a customized search query with a code based on the dynamic user identifier, a user profile. The embodiment receives at the authentication service, a secondary identification data of the user including a biometric information of the user. The embodiment validates the biometric information using the user profile and enables, when the validating is successful, the device to perform an operation. The enabling is not based on the authentication service validating an entirely static user identifier and is not based on the authentication service validating a manually typed password.