Passwordless Login via Biometric Signed Response

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional password-based login systems are insecure, inconvenient, and not scalable, as they rely on easily shareable and rememberable passwords, which are susceptible to phishing and stealing attacks, and require frequent changes, leading to user inconvenience and privacy concerns.

Innovation Solution

A passwordless login system that uses a mobile computing device with biometric sensors and security chips to authenticate users through a signed response to a challenge, eliminating the need for passwords by logging users into applications via a public key verification process, utilizing QR codes or wave modulation to communicate identifiers between devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If password-based login systems are used, then ease of operation is improved (users can easily remember and input passwords), but security and reliability deteriorate (passwords are susceptible to phishing and stealing attacks)

Engineering Contradiction:
Improveease of login operationVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical/password-based authentication system with a biometric authentication system. Instead of using passwords that can be remembered and typed, the system uses biometric sensors (fingerprint, facial recognition, etc.) to verify user identity. This substitution eliminates the security vulnerabilities of password-based systems while maintaining ease of use, as biometric authentication is more difficult to compromise and does not require users to remember complex passwords.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces biometric sensors as an intermediary between the user and the authentication system. The biometric sensor captures physical or behavioral characteristics (fingerprint, facial features, voice patterns) and converts them into authentication data. This intermediary layer provides a more secure authentication mechanism that is difficult to steal or replicate, while still being convenient for users to provide.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If passwords are used for authentication, then device complexity is reduced (standard input devices suffice), but adaptability and scalability deteriorate (system cannot easily integrate with diverse devices and services)

Engineering Contradiction:
Improveauthentication system complexityVSAvoidsystem integration capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal authentication system that can work across multiple device types and service platforms. By using biometric sensors and cryptographic key pairs, the system provides a standardized authentication mechanism that can be integrated with various devices (mobile phones, tablets, computers) and services (cloud applications, mobile applications, web services). This multi-functional approach allows the same authentication system to serve diverse technical environments without requiring device-specific authentication mechanisms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the fundamental parameters of authentication from password-based to biometric-based. Instead of relying on text-based passwords that can be easily transmitted and stored, the system uses biometric data and cryptographic keys as authentication parameters. This parameter change enables better adaptability to different devices and services, as biometric authentication can be implemented across various platforms using standard sensors and cryptographic protocols, while maintaining high security standards.

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If passwords are used for user authentication, then ease of manufacture is improved (no specialized hardware needed), but loss of information increases (passwords can be stolen and shared)

Engineering Contradiction:
Improveauthentication system implementationVSAvoidpassword security
Core Design Contradiction:
Ease of manufactureVSLoss of information

Solution Approach 1:

The patent replaces the password-based information storage and transmission system with a biometric system that uses physical or behavioral characteristics. Instead of storing and transmitting passwords that can be stolen, the system uses biometric data captured by sensors and processed locally on devices. This substitution fundamentally changes how authentication information is handled, making it much more difficult to steal or share, while still being relatively easy to implement using standard sensor technologies.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent implements a self-service authentication mechanism where the biometric sensor automatically captures and verifies user identity without requiring manual password entry. The system performs authentication autonomously by comparing biometric data against stored templates, eliminating the need for users to manually provide passwords. This self-service approach reduces the risk of password leakage while maintaining ease of use.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20220303268A1Passwordless login
Publication Date: 2022.09.22 CITRIX SYSTEMS INC
  • US20220303268A1 patent drawing
  • US20220303268A1 patent drawing
  • US20220303268A1 patent drawing

AI summary

A computer system is provided. The computer system includes a memory, a network interface, and at least one processor coupled to the memory and the network interface. The at least one processor is configured to receive, via the network interface, a signed response to a challenge, verify the signed response using a public key associated with a mobile computing device, and log a user account associated with the public key into an application in response to verification of the signed response, thereby allowing access to the application.