Password-Biometric Key Binding with Fuzzy Extractor Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication methods face challenges with passwords being difficult to remember and biometric data being inflexible and vulnerable to theft, leading to security risks.

Innovation Solution

A method involving generating a second secret key based on a password and biometric input using device-enhanced password-authenticated key exchange (DE-PAKE) and fuzzy extractor helper data, allowing for secure authentication with biometric or textual inputs without exposing the biometric template.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If passwords are used for authentication, then security can be maintained through regular updates, but users find it difficult to remember multiple passwords with different criteria

Engineering Contradiction:
ImprovesecurityVSAvoidpassword memorability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces biometric data as an intermediary that mediates between security requirements and user convenience. Instead of directly using passwords, the system uses biometric templates (fingerprint, face, iris) as a mediator that automatically authenticates users without requiring them to remember passwords, while still enabling secure authentication through cryptographic protocols

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If biometric data is used for authentication, then usability is improved as users do not need to remember passwords, but biometric data cannot be updated readily increasing security risk

Engineering Contradiction:
Improveauthentication convenienceVSAvoidsecurity update capability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication system into two independent components: biometric templates for convenience and passwords for security. The biometric template is used for seamless authentication while the password serves as a separate, updatable security credential. This segmentation allows each component to fulfill its specific function without compromising the other

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter of updateability by introducing a password that can be modified independently of the biometric template. While the biometric template remains static and cannot be updated, the password parameter can be changed by the user, providing a mechanism to respond to security threats without affecting the biometric authentication functionality

Inventive Principle:
Principle #35Parameter changes

3Reliability

If biometric data is encrypted and masked, then security is improved, but attackers can still recover the data or use encrypted versions in re-usability attacks

Engineering Contradiction:
Improvedata protectionVSAvoidattack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the sensitive biometric template from the authentication decision-making process. Instead of using the biometric template directly for authentication, the system extracts only a cryptographic binding between the biometric template and the password. The actual biometric template is stored securely and never transmitted or processed during authentication, eliminating the attack surface while maintaining security

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If two-factor authentication is used, then security is improved, but users must carry separate devices and access separate accounts creating burden

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges the two-factor authentication requirements into a single unified authentication process. The biometric template and password are combined into one authentication flow where the user provides only their biometric data, and the system internally handles the password verification through cryptographic protocols. This eliminates the need for separate devices and accounts while maintaining the security benefits of two-factor authentication

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250247242A1Method, System, and Computer Program Product for Authentication
Publication Date: 2025.07.31 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US20250247242A1 patent drawing
  • US20250247242A1 patent drawing
  • US20250247242A1 patent drawing

AI summary

Provided is a method for authentication. The method may include receiving first password data, first biometric input data, and first secret key data. A second secret key may be generated based on the first secret key and the first password. Fuzzy extractor helper data may be generated based on the first biometric input and the second secret key. The fuzzy extractor helper data and the first secret key may be stored. The user may be authenticated based on an attempted password and/or a second biometric input. A system and computer program product are also disclosed.