Multi-factor Authentication with Biometric Responses
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for electronic transactions are vulnerable to exploitation and burdensome for users, lacking a balance between security and convenience.
Innovation Solution
A multi-factor authentication system that employs biometric responses to prompts, where only a fraction of authentication information is used in each attempt, with prompts changed between successive authentications, and incorporates CAPTCHA and personalized prompts to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authentication methods (passwords, biometrics) are used, then authentication can be performed, but security vulnerabilities exist and users face burdens
Solution Approach 1:
The authentication process is segmented into multiple independent factors (something you know, something you have, something you are) that are combined. Each factor is evaluated separately and then integrated to make the final authentication decision, making the system more secure without significantly increasing user burden
Solution Approach 2:
Multiple authentication factors are merged into a unified authentication process. The system combines knowledge-based authentication (passwords, PINs), possession-based authentication (tokens, mobile devices), and biometric authentication (fingerprint, facial recognition) into a single coherent system that leverages the strengths of each factor
2Reliability
If authentication systems become more complex to defeat sophisticated attacks, then security improves, but user burden increases
Solution Approach 1:
The authentication system dynamically adjusts the factors required based on risk assessment. The system can require only knowledge-based authentication for low-risk transactions, while automatically incorporating possession and biometric factors for high-risk transactions, making the system adaptive rather than statically complex
Solution Approach 2:
The system changes authentication parameters (which factors are required, what thresholds to apply) based on the transaction context, user behavior patterns, and risk indicators. This allows the system to maintain security while adapting complexity to actual needs rather than applying uniform complexity
3Object-affected harmful factors
If biometric data is used for authentication, then copying protection improves, but biometric data can still be intercepted or duplicated
Solution Approach 1:
Biometric authentication is merged with other authentication factors (knowledge and possession factors) to create a multi-factor system. The biometric data is never used alone but combined with additional verification mechanisms, so even if biometric data is intercepted or duplicated, the attacker cannot complete authentication without the other factors
Solution Approach 2:
The system uses secure intermediaries (encrypted communication channels, secure enclaves in mobile devices, token-based verification) to protect biometric data during transmission and storage. The biometric template is transformed into an encrypted representation that cannot be reverse-engineered, acting as an intermediary that protects the original biometric data
4Ease of operation
If passwords are used for authentication, then ease of use is maintained, but passwords can be determined through trial and error or copying
Solution Approach 1:
Password-based authentication is merged with possession-based factors (one-time codes sent to mobile devices, security tokens) and biometric factors. The password remains the convenient entry point, but it must be combined with additional factors that are difficult to obtain through trial and error or copying
Solution Approach 2:
The system incorporates disposable one-time passwords or codes that are valid for only a single authentication attempt or a very limited time window. These short-living authentication credentials cannot be reused or copied effectively, providing protection against determination attacks while maintaining ease of use through automated delivery to the user's device
Data Source
Figure 1~3
Figure 4
Figure 5
AI summary
Systems and methods for authenticating electronic transactions are provided. The authentication methods employ a combination of security features. These security features can be based, for example, on unique knowledge of the person being authenticated, unique personal features and attributes of the person, the ability of the person to respond, and to do so in a fashion that a machine cannot, and so forth. Methods for enrolling the person prior to authentication are also provided, as well as systems for enrollment and authentication.