Presence-Aware Biometric Authentication for Impersonation Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication technologies, such as those described in Patent Literature 1 and Patent Literature 2, are susceptible to impersonation when multiple users with similar biometric features are present in the same facility, leading to security vulnerabilities.

Innovation Solution

An authentication system that includes first authentication means for users checking in at a place, prediction means to identify potential impersonation risks based on user presence or arrival patterns, and processing execution means to enforce additional authentication measures during predicted vulnerable periods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If biometric authentication is used for user identification, then authentication speed and convenience are improved, but security deteriorates when multiple users with similar biometric features are present

Engineering Contradiction:
Improveauthentication convenienceVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary registration of multiple users with similar biometric features in advance. During authentication, the system proactively identifies potential impersonation risks by comparing the authenticated user's biometric data against registered similar users, and preemptively notifies facility managers before granting access, thereby preventing security incidents before they occur

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system establishes a feedback loop where authentication results are continuously monitored and compared against registered similar users. When potential impersonation is detected, the system provides feedback notifications to facility managers, who can then verify the user's identity through alternative means, creating a closed-loop security mechanism that continuously improves authentication reliability

Inventive Principle:
Principle #23Feedback

2Reliability

If additional authentication measures are implemented during vulnerable periods, then security is improved, but processing time and system complexity increase

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary registration of multiple users with similar biometric features in advance. During authentication, the system proactively identifies potential impersonation risks by comparing the authenticated user's biometric data against registered similar users, and preemptively notifies facility managers before granting access, thereby preventing security incidents before they occur

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies additional verification measures selectively rather than universally. When biometric authentication succeeds, the system checks whether the authenticated user has similar registered users present in the facility. Additional verification steps (such as manager notification or alternative authentication) are applied only in these specific high-risk cases, not for all users, thereby balancing security enhancement with system simplicity

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12407683B2Authentication system, authentication method and program
Publication Date: 2025.09.02 RAKUTEN GROUP INC
  • US12407683B2 patent drawing
  • US12407683B2 patent drawing
  • US12407683B2 patent drawing

AI summary

An authentication system, comprising at least one processor configured to: execute first authentication for a first user when the first user is present at a first place or arrives at a first place; predict a predicted period in which a second user who has a possibility of being authenticated as the first user by the first authentication is not expected to be present at the first place or arrive at the first place, based on at least one type of information out of second-time information about a second time at which the second user has been present at a second place or has arrived at a second place and second-place information about the second place; and execute first processing for the first user based on the first authentication executed in the predicted period.