Password-Biometric Key Binding with Fuzzy Extractor Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods face challenges with passwords being difficult to remember and biometric data being inflexible and vulnerable to theft, leading to security risks.
Innovation Solution
A method involving generating a second secret key based on a password and biometric input using device-enhanced password-authenticated key exchange (DE-PAKE) and fuzzy extractor helper data, allowing for secure authentication with biometric or textual inputs without exposing the biometric template.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If passwords are used for authentication, then security can be maintained through regular updates, but users find it difficult to remember multiple passwords with different criteria
Solution Approach 1:
The patent introduces biometric data as an intermediary that mediates between security requirements and user convenience. Instead of directly using passwords, the system uses biometric templates (fingerprint, face, iris) as a mediator that automatically authenticates users without requiring them to remember passwords, while still enabling secure authentication through cryptographic protocols
2Ease of operation
If biometric data is used for authentication, then usability is improved as users do not need to remember passwords, but biometric data cannot be updated readily increasing security risk
Solution Approach 1:
The patent segments the authentication system into two independent components: biometric templates for convenience and passwords for security. The biometric template is used for seamless authentication while the password serves as a separate, updatable security credential. This segmentation allows each component to fulfill its specific function without compromising the other
Solution Approach 2:
The patent changes the parameter of updateability by introducing a password that can be modified independently of the biometric template. While the biometric template remains static and cannot be updated, the password parameter can be changed by the user, providing a mechanism to respond to security threats without affecting the biometric authentication functionality
3Reliability
If biometric data is encrypted and masked, then security is improved, but attackers can still recover the data or use encrypted versions in re-usability attacks
Solution Approach 1:
The patent extracts the sensitive biometric template from the authentication decision-making process. Instead of using the biometric template directly for authentication, the system extracts only a cryptographic binding between the biometric template and the password. The actual biometric template is stored securely and never transmitted or processed during authentication, eliminating the attack surface while maintaining security
4Reliability
If two-factor authentication is used, then security is improved, but users must carry separate devices and access separate accounts creating burden
Solution Approach 1:
The patent merges the two-factor authentication requirements into a single unified authentication process. The biometric template and password are combined into one authentication flow where the user provides only their biometric data, and the system internally handles the password verification through cryptographic protocols. This eliminates the need for separate devices and accounts while maintaining the security benefits of two-factor authentication
Data Source
AI summary
Provided is a method for authentication. The method may include receiving first password data, first biometric input data, and first secret key data. A second secret key may be generated based on the first secret key and the first password. Fuzzy extractor helper data may be generated based on the first biometric input and the second secret key. The fuzzy extractor helper data and the first secret key may be stored. The user may be authenticated based on an attempted password and/or a second biometric input. A system and computer program product are also disclosed.


