Multi-factor Fingerprint Authenticator Using Encrypted Biometric Merging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Fingerprint-based authentication systems face challenges in achieving robust security and user convenience, particularly in maintaining secure biometric data and managing passwords, as short passwords are easily compromised, while long passwords are difficult to remember and biometric data is sensitive and irreplaceable.

Innovation Solution

A multi-factor fingerprint authenticator method that generates a long password by merging a biometric scanned image with a user-provided code using encryption, ensuring the password is reversible with the code, allowing for easy recall of a short user password and periodic updates to maintain security without storing biometric data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a short password is used for authentication, then user convenience is improved, but security is worsened due to ease of compromise

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent combines multiple authentication factors (biometric data and user code) into a single authentication mechanism. The system merges the fingerprint template with the user-provided code through encryption to create a composite authentication credential, thereby achieving both security of long passwords and convenience of biometric authentication

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If a long password is used for authentication, then security is improved, but user convenience is worsened due to difficulty in remembering

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the authentication process into two parts: a biometric component (fingerprint) that the user provides passively, and a code component that the user actively enters. This segmentation allows the system to achieve long password security through the combined credential while maintaining user convenience through the simple biometric scan and short code input

Inventive Principle:
Principle #1Segmentation

3Reliability

If biometric data is stored for authentication, then authentication capability is improved, but security is worsened due to sensitivity and irreplaceability of biometric data

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity risk of biometric data
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts and removes the raw biometric data (fingerprint template) from storage. Instead of storing the sensitive biometric template, the system only stores the encrypted composite credential that combines the template with a user code. This extraction eliminates the security risk of storing raw biometric data while preserving authentication capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary element (user code) between the biometric data and the stored credential. The user code acts as a mediator that encrypts the biometric template, creating a layered security structure where the biometric data is never stored in plain form. This intermediary mechanism protects the sensitivity of biometric data while maintaining authentication functionality

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11651060B2Multi-factor fingerprint authenticator
Publication Date: 2023.05.16 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11651060B2 patent drawing
  • US11651060B2 patent drawing
  • US11651060B2 patent drawing

AI summary

Techniques for client side multi-factor password generation include randomly removing one or more features of a record of a fingerprint image of a user and creating a distorted record of the fingerprint image by merging the record with a user input code using an encryption technique, the distorted record being reversible using the user input code. The distorted record for authentication of the user is registered.