Local Biometric Authentication Engine for Secure User Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for data authentication and identity verification in transactions are limited by reliance on external databases, lack of multi-dimensional verification, and vulnerability to tampering, leading to inefficiencies and security risks.

Innovation Solution

A system and method for biometric authentication that locally stores and authenticates user data using a biometric engine, local database, and authentication engine on the user's device, eliminating the need for third-party servers and enhancing security through real-time verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user data is stored in external databases on third-party servers, then data storage and access is simplified, but security and vulnerability to tampering increases

Engineering Contradiction:
Improvedata storage and accessVSAvoidsecurity against tampering
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the critical authentication function from external databases and implements it locally on the user's own device. The biometric engine and authentication engine are deployed on the user's device, allowing verification to be performed locally without relying on third-party servers for security-critical operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary verification process where the system verifies user data against source systems and cross-checks with biometric identifications stored locally on the user's device. This intermediary layer prevents direct access to external databases while maintaining verification integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If digital signatures and encryption are used to protect data, then data integrity is improved, but vulnerability to unauthorized access to private keys increases

Engineering Contradiction:
Improvedata integrityVSAvoidunauthorized access to private keys
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the private key and cryptographic verification functions from external storage and implements them locally on the user's device. The authentication engine performs verification locally, eliminating the need to store private keys on third-party servers where they could be compromised.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The user's device performs self-verification by storing biometric identifications locally and using the authentication engine to verify data integrity without external intervention. The system cross-checks user data against source systems and verifies against locally stored biometric data, making the device self-sufficient for security-critical operations.

Inventive Principle:
Principle #25Self-service

3Reliability

If biometric authentication is implemented, then security against unauthorized access is improved, but processing time and system complexity increases

Engineering Contradiction:
Improvesecurity against unauthorized accessVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary verification by cross-checking user data against source systems and verifying against biometric identifications stored locally on the user's device before completing the authentication process. This preliminary action prevents unnecessary processing of unauthorized access attempts.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent merges multiple verification functions (data verification against source systems, biometric authentication, and cryptographic verification) into a single integrated authentication engine that operates locally on the user's device, streamlining the process and reducing overall processing time.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If multiple verification modes are implemented, then authentication reliability is improved, but device complexity and integration difficulty increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsystem integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication engine that can perform multiple verification functions including data verification against source systems, biometric authentication, and cryptographic verification. This single multi-functional engine reduces the need for separate specialized components while maintaining comprehensive verification capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11615174B2Method and a system to locally store and authenticate a data of a user
Publication Date: 2023.03.28 BIOCUBE TECH INC
  • US11615174B2 patent drawing
  • US11615174B2 patent drawing
  • US11615174B2 patent drawing

AI summary

An authentication system is disclosed here to locally store and authenticate user data associated with a user. The authentication system comprises a biometric engine, a local database, a requesting module, and an authentication engine. The biometric engine stores biometric identification of the user for registration, which is retrieved using a user owned mobile device. The local database stores the user data associated with the user after the registration, and is in communication with the biometric engine via a client application. The requesting module is in communication with a processor to request an authentication of the user data, which is accepted if the request matches the identified user data. The authentication engine authenticates the user data by verifying the user data against one or more of the biometric identifications, and generate an authentication message that is sent to a proprietor that requests for the authentication of the user data.