Personal Security Device Biometric Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Biometric authentication systems using Personal Security Devices (PSDs) face challenges in achieving the required 1:1,000,000 false acceptance rate for high-security environments, leading to increased administrative costs due to inadequate security and inability to deploy high-accuracy fingerprint biometric authentication.

Innovation Solution

A method that involves a Personal Security Device transferring identification information retrieval data in response to a match between biometric data from another device and a predetermined biometric reference, with the PSD authorizing access only upon a successful match between the retrieved identification information and its stored information, incorporating cryptographic security enhancements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric authentication is implemented using a Personal Security Device, then authentication capability is provided, but the false acceptance rate cannot meet the 1:1,000,000 requirement for high-security environments

Engineering Contradiction:
Improvefalse acceptance rateVSAvoidability to deploy high-accuracy fingerprint biometric authentication
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authentication process is segmented into two distinct stages: first, biometric data is compared against a stored biometric reference to generate identification information retrieval data; second, this retrieval data is used to obtain identification information which is then verified against stored identification information. This segmentation allows the system to achieve high reliability by combining probabilistic biometric matching with deterministic cryptographic verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Identification information retrieval data acts as an intermediary between the biometric authentication process and the final access authorization. The PSD generates this retrieval data based on biometric matching, which then serves as a key or token to retrieve the actual identification information from another device. This intermediary mechanism bridges the gap between biometric probability and cryptographic certainty.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic security enhancements are incorporated into biometric authentication, then security level is improved to meet FIPS 140 requirements, but device complexity increases

Engineering Contradiction:
Improvesecurity levelVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The Personal Security Device autonomously performs cryptographic operations including generating identification information retrieval data from biometric matches and verifying retrieved identification information against stored references. The system self-manages the cryptographic verification process without requiring external cryptographic processing, thereby enhancing security while keeping the overall system architecture relatively simple.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7787661B2Method, system, personal security device and computer program product for cryptographically secured biometric authentication
Publication Date: 2010.08.31 ASSA ABLOY AB
  • US7787661B2 patent drawing
  • US7787661B2 patent drawing
  • US7787661B2 patent drawing

AI summary

A system is used for authorizing access to a Personal Security Device. This system comprises a Personal Security Device 75 and another device 105 which is in functional communication with said Personal Security Device. Said Personal Security Device comprises identification information retrieval data and a biometric authentication application 200 which transfers said identification information retrieval data to said other device 105 in response to an identified match between biometric data sent by said other device and a predetermined biometric reference. Said other device 105 comprises a security executive application 230 for retrieving an Identification Information with at least said identification information retrieval data, thus generating a retrieved Identification Information, and transferring said retrieved Identification Information to said Personal Security Device 75. Said Personal Security Device comprises a security executive application 215 for authorizing access in response to an identified match between said transferred retrieved Identification Information and a predetermined Identification Information stored in said Personal Security Device.