Digital Wallet Biometric Authentication Identifier Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
User credentials are at high risk of being stolen due to the multiple enrollment systems used for biometric authentication, which increases the exposure of personal and private information.
Innovation Solution
A method and system where a user device provides identifiers of enrollment systems for user authentication, allowing users to enroll once into multiple authentication systems and store these identifiers in a digital wallet, thereby reducing the need for multiple enrollments and minimizing exposure of personal information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple enrollment systems are used for biometric authentication across different services, then user authentication capability and service accessibility are improved, but the risk of credential theft and exposure of personal information increases
Solution Approach 1:
The patent introduces a digital wallet as an intermediary component that stores biometric credentials locally on the user's device. Instead of directly enrolling with multiple service providers, the user enrolls once with the digital wallet, which then acts as a mediator to authenticate the user with various relying party systems. This reduces the number of direct enrollment relationships and minimizes credential exposure.
Solution Approach 2:
The patent segments the authentication system into distinct components: the digital wallet that stores credentials, the enrollment system that creates credentials, and relying party systems that verify credentials. This segmentation allows the biometric data to be stored in a dedicated secure environment rather than being distributed across multiple service providers, reducing overall exposure risk.
2Adaptability or versatility
If users enroll into multiple enrollment systems for different services, then service accessibility is improved, but the complexity of managing personal information across multiple systems increases
Solution Approach 1:
The digital wallet is designed as a universal authentication mechanism that can store and manage multiple types of biometric credentials (voice, facial, fingerprint) for multiple services in a single location. This multi-functional system eliminates the need for users to separately manage credentials for each service, simplifying information management while maintaining broad service accessibility.
Solution Approach 2:
The patent combines multiple enrollment systems and credential management functions into a single digital wallet interface. Users interact with one unified system rather than multiple separate enrollment systems, which consolidates the management complexity into a single manageable location while maintaining access to diverse services.
3Adaptability or versatility
If biometric data is provided to multiple enrollment systems, then authentication coverage across services is improved, but the exposure of personal and private information increases
Solution Approach 1:
The digital wallet serves as an intermediary that minimizes information exposure by locally storing biometric templates and only sharing necessary authentication results with service providers. Rather than distributing raw biometric data to multiple enrollment systems, the wallet processes authentication locally and communicates only verification outcomes, reducing the exposure of sensitive personal information.
Solution Approach 2:
The patent uses cryptographic copying where biometric templates are transformed into secure, non-reversible representations stored in the digital wallet. These copied representations can be used for authentication without exposing the original biometric data, allowing authentication coverage across multiple services while protecting the underlying personal information.
Data Source
AI summary
A method for authenticating a user is provided. The method comprises: providing first biometric enrollment data of the user to a first enrollment system of a plurality of enrollment systems; receiving a first enrollment identifier identifying the first enrollment system; storing the first enrollment identifier identifying the first enrollment system into a digital wallet of the user; in response to a request to access content on a relying party system, providing a biometric marker of the user and the first enrollment identifier from the digital wallet of the user to the relying party system; based on the relying party system identifying the first enrollment system using the first enrollment identifier and verifying the biometric marker of the user with the first enrollment system, accessing the requested content associated with the relying party system.


