Passwordless Authentication via Optical Biometric Pattern Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional password-based authentication is insecure due to password vulnerabilities and biometric authentication methods that require transmission of sensitive information, increasing risk of attack and privacy concerns.

Innovation Solution

A passwordless authentication system using a mobile device for local biometric authentication, where biometric hashes are generated and stored securely, and a QR matrix code or flash pattern is used to verify user identity without transmitting biometric data, combining biometric authentication with a unique identifier and temporal code to authenticate users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric authentication is implemented by transmitting biometric information to a server for comparison, then user authentication capability is improved, but security deteriorates due to vulnerability of biometric data transmission and storage on multiple servers

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the essential verification element (temporal code) from the biometric authentication process, eliminating the need to transmit or store actual biometric data on servers. The mobile device performs local biometric verification and sends only a timestamped code to the server, removing the security vulnerability of biometric data transmission while preserving authentication capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a temporal code as an intermediary element between the biometric authentication process and server verification. Instead of directly transmitting biometric data, the system uses a timestamped code generated by the mobile device as a mediator that proves authentication occurred without exposing sensitive biometric information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If password-based authentication is used to access multiple accounts, then ease of operation is improved by reducing the number of passwords to remember, but security deteriorates due to password reuse and simplified passwords

Engineering Contradiction:
Improvepassword management convenienceVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements self-service authentication where the mobile device automatically performs biometric verification and generates authentication codes without requiring user input of passwords. The system serves itself by using the device's built-in biometric capabilities to authenticate the user to multiple accounts, eliminating password management entirely.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If biometric information is stored securely on a mobile device in a secure enclave, then security is improved by preventing external access to biometric data, but device complexity increases due to secure enclave implementation

Engineering Contradiction:
Improvebiometric data protectionVSAvoidsecure enclave architecture
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent merges the biometric authentication functionality directly into the mobile device's secure enclave, combining storage and verification capabilities in a single integrated security module. This consolidation protects biometric data while managing complexity through unified architecture rather than separate components.

Inventive Principle:
Principle #5Merging (Combining)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This method enhances security by eliminating the need for passwords and preventing biometric data transmission, providing a more secure and practical authentication process that is resistant to attacks and privacy breaches.

Implementation Method 1

a remitted pattern is recorded by the mobile device application. The flash pattern is remitted by the biometric source (e.g., the user's finger) at the time of biometric authentication and sensed by an optical sensor

Methodology Applied
Scientific EffectLight reflection: Reflection

Data Source

PatentUS20220004617A1Passwordless authentication systems and methods
Publication Date: 2022.01.06 ORCHID AUTHENTICATION SYSTEMS INC
  • US20220004617A1 patent drawing
  • US20220004617A1 patent drawing
  • US20220004617A1 patent drawing

AI summary

A passwordless authentication method authenticates a user to access a remote computer. A mobile device receives a flash pattern included on a webpage by an authenticator. A body part of a user of the mobile device is biometrically authenticating at the mobile device. Concurrently with the authenticating, a modulated optical signal based upon the flash pattern is emit toward the body part and detected remission of the modulated optical signal by the body part is recorded as a remitted pattern. An indication of authenticity of the user, as determined by the step of biometrically authenticating, and the remitted pattern are communicated to the authenticator, and the user is authenticated to the website based upon the indication of authenticity and a match of the remitted pattern to the flash pattern.