Identity Management System Biometric Token Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security measures, such as user IDs and passwords, fail to provide adequate privacy protection and safeguard against online threats and data breaches for consumers and financial institutions in e-commerce and electronic communications.
Innovation Solution
A system that requests a biometric signature from a user device, generates an encrypted token based on this signature, and stores it securely, allowing biometric authentication for identity confirmation, which can be validated by third-party entities through an authoritative identity source.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If user IDs and passwords are used for security, then authentication functionality is provided, but privacy protection and security against data breaches are insufficient
Solution Approach 1:
The patent extracts the biometric authentication data from the user device and stores it securely in a remote location, separating the sensitive biometric information from the authentication process. This allows the system to provide strong security without exposing the user's actual biometric data, thereby protecting privacy while maintaining reliability.
Solution Approach 2:
The patent introduces an intermediary component that acts as a secure bridge between the user device and third-party systems. This intermediary handles the authentication process using stored biometric data without exposing the actual biometric information to third parties, thus providing both security and privacy protection.
2Reliability
If traditional username/password systems are used, then ease of operation is maintained, but protection against online threats and fraud is inadequate
Solution Approach 1:
The patent performs preliminary actions by capturing and storing the user's biometric signature during an initial enrollment phase. This pre-captured biometric data is then used for subsequent authentication without requiring the user to repeatedly provide their biometric information, thus enhancing security while maintaining ease of operation.
Solution Approach 2:
The patent creates a secure copy of the user's biometric signature and stores it in a protected remote location. This copy can be used for authentication purposes without compromising the original biometric data, providing strong fraud protection while keeping the authentication process simple for users.
3Reliability
If biometric signatures are stored locally on user devices, then authentication speed is improved, but security against device compromise is reduced
Solution Approach 1:
The patent segments the authentication system into multiple components: the user device that captures biometric data, a secure remote storage location that holds the biometric signature, and an intermediary that performs authentication. This segmentation allows the system to maintain security even if one component is compromised, while still providing fast authentication through efficient data retrieval.
Solution Approach 2:
The patent moves the biometric signature storage from the local device dimension to a remote cloud-based dimension, creating a new spatial dimension for data storage. This dimensional shift enhances security by protecting against device compromise while maintaining authentication speed through optimized remote access protocols.
Data Source
AI summary
Identity management is disclosed that allows authentication of a user for a third party by way of an encrypted token. A biometric signature can be requested for a user of a user device. In response, an encrypted token can be generated based at least in part on the biometric signature. The encrypted token can then be provided back to the user device, which can save the encrypted token to a secure location on the user device accessible by biometric authentication of the user on the user device. An authentication request can be provided from a third party which includes an encrypted token. A determination can be made regarding whether user identity can be confirmed based on the encrypted token. An indication of whether the user identity was confirmed or unconfirmed can then be communicated in response to the authentication request.


