One-Time Biometric Authentication via Time-Limited Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Biometric authentication systems face security risks due to the permanent nature of biometric data, which cannot be changed if leaked, and the difficulty in applying advanced encryption algorithms, leading to potential misuse of stolen data.
Innovation Solution
An apparatus and method that create and authenticate biometric information using a one-time password, encrypting biometric image information to generate one-time biometric information, which can only be decrypted within a predetermined time, ensuring that only freshly acquired biometric data is used for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If biometric information is converted into digital data and stored permanently, then authentication convenience is improved, but security risk increases due to irreversible leakage
Solution Approach 1:
The patent applies the disposable object principle by creating temporary biometric information that expires after a predetermined time period. The biometric information is generated as a one-time use credential that automatically becomes invalid, preventing long-term storage and reducing the impact of potential leaks. This resolves the contradiction by maintaining authentication convenience through digital data while eliminating permanent security risks through time-limited validity.
Solution Approach 2:
The patent implements dynamics by making biometric information time-dependent and dynamically changing. The system generates biometric information with embedded time parameters that cause automatic expiration, transforming static permanent credentials into dynamic temporary ones. This allows the system to maintain ease of operation while adapting security characteristics to change over time, resolving the contradiction between convenience and security risk.
2Reliability
If advanced encryption algorithms are applied to biometric data, then security is improved, but authentication accuracy deteriorates due to data transformation
Solution Approach 1:
The patent extracts only the necessary identifying features from biometric data to create authentication credentials, rather than encrypting and transforming the entire biometric dataset. By taking out only the essential identification elements and combining them with time parameters, the system maintains authentication accuracy while achieving security through temporary validity and controlled access to the extracted features.
Solution Approach 2:
The patent segments biometric information into multiple components including identifying features, time parameters, and validity periods. This segmentation allows the system to protect sensitive biometric data by distributing it across multiple elements that must be combined correctly for authentication, improving security without compromising the accuracy of the core identification features.
3Ease of operation
If biometric information is made available indefinitely, then user convenience is improved, but vulnerability to misuse increases
Solution Approach 1:
The patent implements periodic action by making biometric information valid only for specific time periods. The system automatically generates time-stamped credentials that expire after predetermined intervals, creating a periodic renewal cycle. This maintains user convenience through automatic time-based validation while reducing vulnerability to misuse by limiting the window of opportunity for unauthorized use.
Solution Approach 2:
The patent creates disposable biometric credentials that are intentionally designed with limited lifespans. Each authentication credential is generated as a temporary object that automatically becomes obsolete, preventing long-term misuse while maintaining ease of operation through automatic expiration and renewal mechanisms.
Data Source
AI summary
In accordance with the embodiments of the present invention, the biometric information created for biometric authentication is available for a predetermined time after it was acquired. In addition, the authentication processing is performed on the biometric information useful for a predetermined time after the biometric information was acquired when authenticating it. Therefore, the authentication processing can be normally performed on only the biometric information that is acquired immediately when it is necessary for the user to do the financial transaction or individual authentication.


