System and method for transmission of biometric data
The system uses ECG-derived encryption keys to securely transmit and control access to biometric data, addressing vulnerabilities in facial recognition systems by ensuring unique and un duplicable encryption for enhanced privacy and security.
Patent Information
- Application Number
- PCT/IN2024/051136
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-02-01
- Filing Date
- 2024-07-10
- Publication Date
- 2025-08-07
AI Technical Summary
Existing access control systems using facial recognition technology lack adequate safeguards to prevent unauthorized access and misuse of personal biometric data, particularly facial information, during transmission over insecure channels, posing risks to user privacy and data integrity.
A system and method that generates an encryption key using serial numbers or an array of data points from voltage values in the R-R interval of electrocardiogram (ECG) signals to encrypt biometric data, such as facial recognition data, ensuring secure transmission and access control.
Ensures the integrity and privacy of biometric data by making it impossible to recreate or duplicate, thus safeguarding against unauthorized access and misuse, while maintaining data confidentiality during transmission.
Smart Images

Figure IN2024051136_07082025_PF_FP_ABST
Abstract
Description
SYSTEM AND METHOD FOR TRANSMISSION OF BIOMETRIC DATAREFERENCE TO PARENT PATENT APPLICATION
[0001] The present invention comprises an improvement in or modification of the invention claimed in Indian patent application number 202321008953 titled “System and Method for the secure transmission of biomedical data” applied on 11th February, 2023.TECHNICAL FIELD
[0002] The present invention is directed, in general, towards a system and method for the secure transmission of biometric data.
[0003] The present invention particularly relates to a system and method for facilitating enhanced access control in ecosystems that use facial recognition technology. The facial data of a user, captured and processed for facial recognition, is safeguarded from unauthorised access by generating an encryption key using associated serial numbers / array of data points from voltage values corresponding to peak values in the R-R interval of electrocardiogram (ECG) signals.BACKGROUND
[0004] Security and privacy are two key challenges that electronic health systems are presently facing. With the development of medical sciences and the improvement of living standards, there is an increasing demand for remote medical services and remote health management services. In such scenarios, the medical industry has experienced an onset of medical consultations over calls and video calls. Such consultations require the patients to share their personal medical data such as body temperature, blood pressure, X-ray scans, CT scan results, diagnostic images, ECG scan results, blood sample reports etc. with the medical practitioner. This widespread use of computer-based patient records and the increased implementation of telecommunications has brought to the forefront the concern of patient data confidentiality, while balancing convenience and ease of sharing of personal medical data between the patient and the medical practitioner. Without adequate securitymeasures, a patient's medical information may be intercepted, accessed, modified, or deleted by an unauthorised individual or entity - causing a serious breach of privacy and doctor-patient confidentiality.
[0005] The personal and private patient data can be collected through several means. This includes conventional apparatus such as specific machines used for collecting this data. However, with the heavy adaptation of technology in this field, the personal medical data can also be collected by the patient within the proximity of their home. For example, smart watches that are available for purchase in the market allow their users to do ECG scans with the click of a button. These smart wearable devices also allow their users to measure their blood oxygen levels as well as several other health parameters that could prove to be useful for consultation with a medical practitioner. Therefore, such sensitive medical data is readily available, often in an electronic / digital format, with the patients and is often transmitted over less secure channels which makes such data vulnerable to interception, modification or unauthorised use.
[0006] In addition to biomedical data, biometric data is another form of data that is at risk of unauthorised access due to transmission over less secure channels. From mobile phones to physical spaces, biometric data is increasingly being used to authorise and authenticate user access. Among all the subsets of the biometric systems that are used for access control and verification, facial recognition technology is one of the most versatile and commonly used techniques. Facial recognition technology has continuously evolved over the years and there have been significant advances in facial recognition, detection of mouth movement or blinking of eyes, as well as critical liveness detection - all of which have been designed to enhance both speed and accuracy in access control. However, as is widely known, facial recognition systems are very susceptible to spoofing using printed photographs, electronic images or computer-generated images. Several developments in facial recognition systems have been made over the years to address and mitigate the spoofing attempts which involve critical stages like face detection, alignment, liveness detection and feature extraction by comparing feature vectors with a database for identification and incorporating liveness detection.
[0007] Over the years, several systems have been developed which combine multiple biometric parameters / features to improve the overall accuracy and efficacy of thesystem. These systems tend to combine facial recognition, fingerprint scans, iris / retinal scans, voice data, DNA data, and ECG data to provide an additional layer of security due to which these systems have been more resilient to spoofing and identity theft. However, these systems have major drawbacks of high costs as well as the need for high-power computing resources.
[0008] In recent times, upholding the privacy of the users and their data has also become important for systems that manage and process such data. It has been identified that continuous monitoring of a user, wherein the user is continuously monitored by use of multiple cameras and sensors, is also not desirable. In this regard, safeguarding facial recognition data is paramount, either in transit or at rest, as any breach of data could not only compromise the system's security but also expose sensitive personal information to bad-actors. Several legislations across the world have identified this issue and proposed and / or enacted legislations with the aim to protect users’ personal data (such as biomedical data and biometric data) from being unauthorisedly accessed.
[0009] KR20180026018 A discloses a “Method for encrypting and decrypting of personal information using ECG signal”. It measures a personalised electrocardiogram signal, encrypts personal information for personal recognition by analysing feature points and extracting a key, and decrypts the encrypted personal information based on the key. Here, the key information using the electrocardiogram feature points converted into a number or a character form and a symmetric key encryption scheme or an asymmetric key generation scheme used as an encryption and decryption scheme. However, such a method for encrypting and decrypting personal information is not safe for data transmission as it could be hacked.
[0010] US8849718B2 discloses a “Medical data encryption for communication over a vulnerable system” in which the system separates a patient's medical file into a demographics layer and a data layer, and separately encrypts the demographic layer and data layer using different encryption keys, and provides servers in a communication and processing system with a decryption key for the layer processed by such a server. Here, medical files are separated into separate parts with one part encrypted and can be decoded by the intended recipient while the second part isencrypted and can be decoded at an intermediary processor such as a server. This method also is not a safe and secure way of transmission of biomedical data.
[0011] US7519591B2 discloses a “Systems and methods for encryption-based deidentification of protected health information”. It protects individual privacy (e.g., patient privacy) when individual data records (e.g., patient data records) are shared between various entities (e.g., healthcare entities) by implementing secured key encryption for de-identifying patient data to ensure patient privacy, while allowing only the owners of the patient data and / or legally empowered entities to re-identify subject patients associated with de-identified patient data records, when needed. Here, a secured encryption protocol for de-identifying and re-identifying patient data may be implemented using an asymmetric or symmetric key encryption method. An encryption key used for de-identification / re-identification in this system is also not safe and secure.
[0012] The existing access control systems which use facial recognition technology for user verification do not have adequate safeguards to prevent unauthorised access and misuse of the private and personal data of users which is generally stored or transmitted over the internet or any other communication network.
[0013] Accordingly, enhancing data encryption practices within databases which store and process sensitive personal information like biomedical data and biometric data (such as facial information or data), is required for protecting user’s personal data.
[0014] As ECG signals, at any given time, are unique to each and every person, it is desirable to incorporate them appropriately into an access control system which uses facial recognition technology. As is known, ECG signals of a user are unique and are challenging to replicate when compared to other biometric systems. Therefore, ECG signals offer a unique and effective means to ensure data integrity and effectively uphold user privacy. Accordingly, the ECG signals or the data therefrom can be appropriately used for encrypting data, either biomedical data or biometric data such as facial recognition data, in various implementations - specifically in access control systems which use facial recognition technology.DISCLOSURE OF THE INVENTION
[0015] The principal obj ect of the invention is to provide a system and method for the secure transmission of biometric data using electrocardiogram signals.
[0016] Another object of the invention is to analyse the ECG chart and provide peak points in the R-R interval.
[0017] Another obj ect of the present invention is to provide a system and method for secure transmission of biometric data, such as facial recognition data, for facilitating enhanced access control in ecosystems that use facial recognition technology.
[0018] Another object of the invention is to analyse ECG charts / data and provide peak points in the R-R interval.
[0019] Another object of the invention is to generate an encryption key using associated serial numbers or an array of data points from voltage values corresponding to peak values in the R-R interval of electrocardiogram signals.
[0020] Another object of the invention is to provide a system and method for secure and safe transmission of the biometric data (such as facial data / information) by generating an encryption key by using the peak values in an electrocardiogram chart.
[0021] Another obj ect of the present invention is to encrypt the biometric data (such as facial recognition data) and transmit it to the designated recipient(s) along with a decryption key to decrypt the facial recognition data.
[0022] Another object of the present invention is to deliver a single-use decryption key to the designated recipient(s) for accessing the facial recognition data.
[0023] The other objects and advantages of the present invention will be apparent from the following description when read in conjunction with the accompanying drawings, which are incorporated for illustration of preferred embodiments of the present invention and are not intended to limit the scope thereof.SUMMARY OF THE INVENTION
[0024] The following information presents a simplified summary of the disclosure in order to provide a basic understanding for the reader. This summary is not an extensive overview of the disclosure and it does not identify the key / critical elements of theinvention. This summary does not limit the scope of the invention and should not be construed to limit the scope of the invention. The sole purpose of this summary is to summarise some of the concepts disclosed herein as a prelude to the more detailed description presented later.
[0025] In order to overcome the problem of data leakage and data privacy when transmitting biometric data, the present invention discloses a system and method of secure transmission of biometric data. Additionally, it discloses a method of generating an encryption key using associated serial numbers / array of data points from voltage values corresponding to peak values in the R-R interval of ECG signals. It is well known that ECG signals are highly variable in as much as they vary from person to person as well as showing high degrees of randomness and variation when different time-samples of the ECG signals from the same ECG scan are compared with each other. Therefore, ECG signals can form the basis for the development of a technique / method for secure transmission of sensitive biometric data (such as facial information / data) over communication channels.
[0026] An ECG waveform typically comprises a P wave, a Q wave, an R wave, an S wave and a T wave. The Q wave, the R wave and the S wave of an ECG chart are collectively referred to as a QRS complex. As is well known in the art, the R wave is considered to be the most prominent wave in the waveform of the ECG chart. The voltage values at any given point in time (measured in seconds) vary from person to person and from one ECG chart to the other, even if the ECG chart is of the same person. Thus, the generation of a matrix including an array of serial numbers / data points corresponding to R-R peaks of ECG signals and generating an encryption key using the said data points / array of associated serial numbers corresponding to peak values in the R-R interval can be used to encrypt biometric data (such as facial recognition data) for their secure transmission as it will be unique, hence impossible to recreate, re-engineer or duplicate. This would also ensure the integrity of the biometric data that is encrypted and sent across the communication channel using the generated encryption key.
[0027] The present invention discloses a system and method for secure transmission of biometric data (such as facial recognition data), for facilitating enhanced access control in ecosystems that use facial recognition technology. The present invention,in its preferred embodiment, includes creating an encrypted package, to be transmitted to designated recipient(s), which includes the biometric data (such as facial recognition data) that is captured and processed for implementing facial recognition of a user and wherein an encryption key is generated using associated serial numbers / array of data points from voltage values corresponding to peak values in the R-R interval of electrocardiogram signals which are collected from the user.
[0028] In the system of the present invention, an access control computer system with an attached biometric data capturing apparatus and a biometric data processing apparatus is disclosed. The biometric data capturing apparatus collects biometric data (such as facial recognition information) to facilitate the facial recognition technology enabled access control system. The computer system receives the biometric data from the biometric data capturing apparatus while receiving the ECG data of the user through other means (such as an ECG scanner or a wearable device). In the preferred embodiment of the present invention, the biometric data is facial recognition data which is captured using the biometric data capturing apparatus, such as a camera or any other image capturing means. The biometric data processing apparatus generates facial key-points from the facial recognition data. The facial key-points, as generated by the biometric data processing apparatus of the system, are encrypted using the encryption unit. The encryption key is generated using the ECG data of the user, which is provided separately. The encryption unit generates the encryption key using associated serial numbers / array of data points from voltage values corresponding to peak values in the R-R interval of electrocardiogram (ECG) signals collected from the user.
[0029] In one embodiment of the present invention, a user provides the facial recognition data, along with the ECG data of the user 102 as .csv voltage data against the time interval. The ECG data may be captured using smart watches, home ECG monitors or through other means already known in the art. The encryption key is generated using the ECG data collected from the said .csv data file or through other means known in the art. The said encryption key is used to encrypt the facial recognition data and then transmitted over a transmission channel. The encrypted facial recognition data is received by a receiver. The received encrypted facial recognitiondata is decrypted using a unique, single-use validated key that is provided by the user to the receiver.
[0030] In another embodiment of the present invention, a method of securely transmitting biometric data of a user comprising generating an encryption key from an ECG signal is disclosed. The generation of the encryption key includes the steps of preprocessing the generated ECG charts, selecting and extracting the R-R segments from the pre-processed ECG charts, identifying peak points in QRS complex (feature extraction) of the segmented ECG charts, generating an array of serial numbers / data points from voltage values corresponding to R-R peaks, generating an encryption key using the said array, creating a zipped package including the biometric data (such as facial recognition data) that has to be sent across the communication channel, using the encryption key to encrypt the zipped package, transmitting the encrypted biometric data (such as facial recognition data) through a transmission channel and decrypting the encrypted biometric data (such as facial recognition data) using the validated key that is provided by the user to the receiver. It is understood by a person skilled in the art that the ECG data can be raw voltage data of an electrocardiogram scan measured against time or a waveform plot of an electrocardiogram scan voltage plotted against time.
[0031] Alternative embodiments of the present invention may involve the use of one or more types of biometric data, that is encrypted using the ECG data of the user. This biometric data may contain information relating to the facial recognition data of the user, fingerprint(s) of the user, iris / retinal scans of the user’s eye(s), voice recognition data, DNA data of the user or any combination thereof which is capable of uniquely identifying the user.BRIEF DESCRIPTION OF DRAWINGS
[0032] Fig. 1 shows a system of secure transmission of biometric data (such as facial recognition data).
[0033] Fig. 2 illustrates a method to generate an encryption key for the secure transmission of biometric data.
[0034] Fig. 3 shows a flow chart outlining the general steps for the method of generation of an encryption key from an electrocardiogram (ECG) chart.
[0035] Fig. 4(a) shows an electrocardiogram (ECG) chart depicting electrical activity of the heart of an individual.
[0036] Fig. 4(b) shows R-R peaks in the QRS complex of an electrocardiogram (ECG) chart.
[0037] Fig. 4(c) shows a zoomed in view of R-R peaks in the QRS complex against the corresponding voltage values of an electrocardiogram (ECG) chart.
[0038] Fig. 5 shows a secure transmission of biometric data (such as facial recognition data) to multiple receivers.
[0039] Fig. 6 shows facial key points extracted from a facial image taken by a biometric data capturing apparatus.DETAILED DESCRIPTION OF THE INVENTION
[0040] In the following description, numerous specific details are set forth in order to provide a thorough understanding of embodiments of the present invention. It will be apparent to one skilled in the art that embodiments of the present invention may be practised without some of these specific details.
[0041] As used in the description herein and throughout the claims that follow, the meaning of “a”, “an”, and “the” includes plural reference unless the context clearly dictates otherwise. Also, as used in the description herein, the meaning of “in” includes “in” and “on” unless the context clearly dictates otherwise.
[0042] Numerous modifications, changes, variations, substitutions, and equivalents of the embodiments described herein will be apparent to those skilled in the art, without departing from the spirit and scope of the invention.
[0043] In this specification, an ECG data means an ECG scan or chart obtained from smart watches, home ECG monitors or an ECG signal obtained using a conventional method or a .csv file containing particulars of an ECG scan, specifically the voltage values corresponding to time values in the ECG scan process. It would be apparent to a person skilled in the art that the ECG data may be procured using other existing techniques as well.
[0044] In the present invention, biometric data may be obtained from smart phones, or any other devices which capture the unique measurable characteristics of a human body. Biometric data includes, but is not limited to, facial recognition data of the user, fingerprint(s) of the user, iris / retinal scans of the user’s eye(s), voice recognition data, DNA data of the user or any combination thereof which is capable of uniquely identifying the user. It is understood by a person skilled in the art that the most relevant biometric data may vary as per the application and its requirements.
[0045] Fig. 1 shows a system 100 for the secure transmission of biometric data from a user 102 to a receiver 106 through an intermediate system 104. The user 102 collects the input data which, as per the preferred embodiment, includes the .csv data of the ECG scan that includes the voltage values corresponding to the time intervals in an ECG scan. In an alternative embodiment of the present invention, ECG charts are generated using the input data. The ECG charts generated from the input data are filtered and segmented to identify and localise the R-R peak of QRS complex of the said ECG chart. The voltage values corresponding to the R-R peaks are arranged in the form of a matrix of data points and an encryption key is generated. The data points are selected from a random time-sample of the ECG chart. As per the preferred embodiment of the present invention, the selected time sample may be as long as 2 seconds however, it would be apparent to a person skilled in the art that the time sample could be either longer or shorter than 2 seconds depending on the processing capabilities of the system as well as the desired complexity of the encryption key. The length of the time sample may be altered depending on the limitations or capabilities of the equipment available to the user; however, the random time-sample should be at least 0.5 seconds long. Furthermore, the matrix of data points is generated from an array of the serial numbers corresponding to the localised R-R peak values in the ECG chart. The encryption key, generated from the serial numbers associated with peak values in the R-R interval in the ECG data, is used for encrypting the biometric data. The encrypted biometric data is stored in the memory unit and is transmitted through a transmission channel which is part of the transmission unit. After the transmission of the encrypted biometric data, this encrypted biometric data is received by the receiving unit and decrypted in the decryption unit using a validated decryption key provided by the user 102 to thereceiver 106. Upon decryption, the receiver 106 can access the biometric data sent by the user 102.
[0046] The user 102 who wants to share biometric data, to a receiver or multiple receivers, can send the encrypted biometric data through the transmission channel. The user 102 may be any person whose identity may need to be verified for the purposes of providing access to certain systems, information or physical space. Furthermore, the system 100 would not limit the functionality or the transmission of the biometric data by the user 102 depending on the type of device that the user 102 is using. The user 102 may use either a mobile device with a compatible operating system or a computer system with a compatible operating system. The present invention and the system provided herein is compatible with all major operating systems including Windows, Android, iOS, MacOS etc. These compatible operating systems provide the user 102 with a user interface to access the system on either the mobile device or the computer system.
[0047] The biometric data is encrypted using an encryption key generated from the serial numbers associated with the peak points, i.e. R-R peaks of a QRS complex in an electrocardiogram chart. The transmission channel facilitates the communication between the user 102 and the receiver 106. In accordance with a preferred embodiment of the present invention, the user 102 may be any person whose identity may need to be verified for the purposes of providing access to certain systems, information or physical space and the receiver 106 may be an automated authenticator or a security personnel responsible for verifying the identity of the user 102. The transmission channel is used for transmitting the encrypted biometric data from the user 102 to the receiver 106. As per an embodiment of the present invention, the transmission channel can be an access control system through which the encrypted biometric data of the user 102 is transmitted to the receiver 106.
[0048] Upon receipt of the encrypted biometric data, the receiver 106 will require a decryption key, which is the validated key, for decrypting the biometric data in the receiving unit 224. In accordance with a preferred embodiment of the present invention, the validated decryption key may be communicated to the receiver 106 either along with the transmission of the biometric data or separately, in a different communication transaction. Alternatively, the decryption key could also be providedby the user 102 to a receiver 106 through a data sharing platform. It is well known in the art that data sharing platforms are the platforms through which encrypted data can be communicated and security and privacy of such data is maintained. Cloud based data sharing platforms are the commonly used platform for this purpose. The receiver 106 receives the encrypted biometric data and decrypts the received biometric data by using a validated key that is provided by the user 102. In accordance with the principles of the present invention, the validated decryption key used by a receiver 106 to decrypt the encrypted biometric data can be the same as the encryption key that was generated or it can be a unique decryption key which is further paired with the encryption key which enables the receiver 106 to unlock the biometric data. In either case, the decryption key will be provided to the receiver 106 by the user 102. It would be apparent to a person skilled in the art that the decryption key can be communicated through a separate means of communication to the receiver 106 or through a standalone key management system where the receiver 106 can login and get access for the key to unlock the biometric data. It is well known in the art that a key management system is a system which deals with generating, exchanging, storing, using and replacing keys as per the requirement and ensures the safety of confidential data.
[0049] Fig. 2 illustrates the method 200 used to generate an encryption key for the secure transmission of biometric data. As per the preferred embodiment of the present invention, the biometric data includes facial recognition data. The user 102 provides an electrocardiogram input to the system through the electrocardiogram input apparatus 202 in the input unit 221 using a user interface. The user interface may vary depending on the operating system compatible with the device of the user 102. The electrocardiogram input is the ECG data of the user 102, the electrocardiogram data (ECG data) being .csv data comprising raw voltage data corresponding to the time intervals in the ECG scan or a waveform plot of an electrocardiogram scan voltage against time. The biometric data (such as facial recognition data) is captured using the biometric data capturing apparatus 203a and processed using the biometric data processing apparatus 203b. The biometric data may contain information relating to the facial recognition data of the user 102, fingerprint(s) of the user 102, iris / retinal scans of the user’s 102’s eye(s), voice recognition data, DNA data of the user 102 or any combination thereof which is capable of uniquely identifying the user102. As per the preferred embodiment of the present invention, pre-processing 204 of the biometric data and / or the electrocardiogram data may be carried out inside the input unit 221 to make the data available for segmentation and transmission in an appropriate format or to remove noise and other undesirable features from the electrocardiogram data using different filters. Noise is termed as an unreasonable QRS complex with no peaks / not right valleys and the charts containing noise are mostly flat charts. There could be several factors that introduce noise into the ECG data / charts. Some of these factors, that introduce noise into the ECG data / charts, include wrong posture of the patient while capturing ECG, a calibration error in the machine / handheld device used to capture the ECG waveform or a symptomatic health reason of the patient (such as fluctuations in blood pressure). If, upon an initial analysis, the charts are determined to include high levels of noise, the same can be removed using pre-processing and filtering techniques. The electrocardiogram data is stored on a memory unit, the memory unit may be located either inside the input unit 221 or as a standalone unit in the system.
[0050] As per a preferred embodiment of the present invention, pre-processing filters may be used to remove the noise from an ECG chart. There could be some distortion in the ECG signal which may have been introduced due to low frequency data points. These low frequency data points can be removed by applying frequency filters. This method of removing low frequency data points by applying a frequency filter is known as notch filter method. After the notch filters have been applied, the complete chart is zoomed out for visual inspection and the zoom out process is carried out in accordance with sample size reduction or increase, in order to arrive at a visually linear chart.
[0051] Once the noise and other undesirable characteristics are removed from the electrocardiogram input, a random time sample interval is segmented 206 from the ECG waveform. The segmented regions of the pre-processed ECG chart 204 contain data points, which are selected as a random range of time-samples. The selected range of time samples can be longer or shorter than 2 seconds depending on the processing capabilities of the system. Thereafter, the segmented ECG data is supplied to the encryption unit 222.
[0052] In the encryption unit 222, the desirable features, which are most applicable for the generation of the encryption key 212, i.e. the R-R peak values in the QRS complex, are localised and extracted 208 from the segmented data points 206 of the ECG data / charts. Thereafter, a matrix of data points is generated 210 as an array of the serial numbers corresponding to the localised R-R peak values in the ECG chart using which the encryption key 212 is generated. A zipped package 214 is developed which contains biometric data (such as facial recognition data) that the user 102 wishes to send to the receiver 106. The generated encryption key 212 is used to encrypt 216 the zipped packages which are to be transmitted across the transmission channel 218.
[0053] The transmission channel 218 is part of the transmission unit 223, in accordance with the preferred embodiment, is one that uses Transport Layer Security (TLS) protocol for the transmission of the encrypted zipped package 216 containing the biometric data (such as facial recognition data). The encrypted zipped package 216 containing the biometric data (such as facial recognition data) can be communicated on the same means of communication which requires a decryption key for the receiver 106 or data can be communicated through a data sharing platform. It is well known in the art that data sharing platforms are platforms through which encrypted data can be communicated while security and privacy of the data is maintained. Cloud based data sharing platforms are a commonly used platform for this purpose. The receiver 106 receives the encrypted zipped package 216 containing the biometric data (such as facial recognition data) at the receiving unit 224 and decrypts 220 the received encrypted zipped package 216 containing the biometric data (such as facial recognition data) by using a unique, single-use validated decryption key that is provided by the user 102. In accordance with the principles of the present invention, the unique, single-use validated decryption key used by the receiver 106 to decrypt the encrypted zipped package 216 containing the biometric data (such as facial recognition data) can be the same as the encryption key that is generated, or it can be a unique decryption key which is further paired with the encryption key which enables the receiver 106 to unlock and access the zipped package 216 containing the biometric data (such as facial recognition data). In either case, the decryption key will be provided to the receiver 106 by the user 102 or by the intermediate system 502. It would be apparent to a person skilled in the art that the decryption key can becommunicated through a separate means of communication to the receiver 106 or through a key management system where the receiver 106 can login and get access for the decryption key to unlock the encrypted zipped package 216 containing the biometric data (such as facial recognition data). It is well known in the art that a key management system is a system which deals with generating, exchanging, storing, using and replacing keys as per the requirement and ensures the safety of confidential data.
[0054] In one embodiment of the present invention, the input unit 221 is located on a mobile device such as a computer or a laptop. The user 102 uploads the biometric data (such as facial recognition data) along with the electrocardiogram data to a cloud-based server which acts as the memory unit for system 100. In the present embodiment, the memory unit and the encryption unit 222 along with the transmission unit 223 are located in the cloud-based server. The biometric data (such as facial recognition data) is encrypted in the cloud-based server and then transmitted to the receiving unit 224 where the receiver 106 can access the encrypted zipped package 216 containing biometric data (such as facial recognition data) using the validated decryption key.
[0055] In another embodiment of the present invention, the input unit 221, the encryption unit 222 and the transmission unit 223 are located on a single device. Such a device could be a mobile phone, tablet, computer or a laptop.
[0056] Fig. 3 shows a flow chart 300 outlining the general steps for the method of generating an encryption key from an electrocardiogram (ECG) chart which is used for encrypting the biometric data (such as facial recognition data) that is shared by the user 102 or by the intermediate system 502 with the receiver 106 over a transmission channel 218. The user 102 provides the electrocardiogram input through the input unit 221. A system 100 for the secure transmission of biometric data (such as facial recognition data), as per the preferred embodiment, can function with two kinds of input ECG data: raw voltage data against time interval, preferably in a .csv format or an ECG waveform plot / chart (voltage vs time). An ECG chart is generated 302 from the .csv voltage data. It is understood by a person skilled in the art that generating the ECG chart 302 is only required when the electrocardiogram input is raw voltage data in .csv format. The electrocardiogram input data may be procured from smart watches, home ECG monitors, or from any other apparatus while thebiometric data (such as facial recognition data) is provided by the biometric data capturing apparatus 203 a and biometric data processing apparatus 203b which, in an exemplary embodiment relating to facial recognition data, could be used to extract facial key points 604 from the captured image 602 of the user 102.
[0057] The present invention is also compatible with the conventional ECG waveforms and apparatus used to obtain the ECG waveform. An ECG waveform comprises a P wave, a Q wave, an R wave, an S wave and a T wave. The Q wave, the R wave and the S wave of an ECG chart are collectively referred to as a QRS complex. As is well known in the art, the R wave is considered to be the most prominent wave in the waveform of the ECG chart. Once the input is received, it is pertinent to remove any noise from the data. Noise is termed as an unreasonable QRS complex with no peaks / not right valleys and the charts containing noises are mostly flat charts. There could be several factors that introduce noise into the ECG data / charts. Some of these factors include wrong posture of the patient while capturing ECG, a calibration error in the machine / handheld device used to capture the ECG waveform or a symptomatic health reason of the patient (such as fluctuations in blood pressure). If, upon an initial analysis, the charts are determined to include high levels of noise, the same can be removed using filtering techniques. As per an embodiment of the present invention, the pre-processing of the received input data 304 is carried out to remove the noise associated with the ECG charts. It would be apparent to a person skilled in the art that these filters are commonly used in the field of the invention. In this step, in addition to removing the noise from the ECG chart, the R-R peaks in the QRS complex are also enhanced and emphasised to facilitate the method for generating the encryption key.
[0058] Segmentation methods are applied to the pre-processed ECG signals 304. Segmentation is the process of extracting the R-R peak segments 306 from the pre- processed ECG charts 304. It facilitates a thorough analysis for the localisation of the R-R peaks in the QRS complex. The segmented region of the pre-processed ECG chart 304 contains data points, which are selected as a random range of timesamples. Upon identification of the R-R peak segments, the features are extracted 308 from the segmented ECG charts 306. Extraction of features 308 includes the localisation and identification of R-R peak points in the QRS complex from thesegmented ECG charts 306. Once the R-R peak points in the QRS complex have been localised and identified, their corresponding serial numbers are extracted from the .csv file and stored as a matrix / array of data points.
[0059] The matrix / array of data points or serial numbers 310 corresponding to the R-R peaks in the QRS complex of the ECG charts identified in step 308 is generated. The number of data points corresponding to R-R peaks of ECG charts is dependent on the length and duration of the random time-sample that has been segmented from the ECG chart. An encryption key is generated 312 from the said matrix / array of data points. A package is developed which contains the sensitive biometric data of the user 102. The biometric data may contain information relating to the facial recognition data of the user 102, fingerprint(s) of the user 102, iris / retinal scans of the user’s 102’s eye(s), voice recognition data, DNA data of the user 102 or any combination thereof which is capable of uniquely identifying the user 102 that the user 102 wants to send to the receiver 106, i.e. an automated authenticator or a security personnel or to multiple receivers 106a, 106b or 106c at multiple checkpoints and the zipped package 314 is created. The facial recognition data, as per the preferred embodiment of the present invention, includes the facial key points 604 extracted from the captured image 602 of the user 102 by the biometric data processing apparatus 203b. Said zipped package 314 containing the biometric data is encrypted 316 using the encryption key generated in step 312. The encrypted zipped package 316 containing biometric data is transmitted 318 through the transmission channel 218. The transmission channel 218, in accordance with the present application, is one that uses Transport Layer Security (TLS) protocol for the transmission of the encrypted biometric data. These security protocols are widely used to secure the data that travels between web browsers and websites via HTTPS and also used to secure e-mail and host of other protocols. The received encrypted zipped package 316 containing the biometric data can only be decrypted 320 using the validated decryption key that is sent by the receiver 106. The said validated key is provided to the receiver 106 by the user 102.
[0060] As per an embodiment of the present invention, the encryption key generated in step312 is a unique key that is generated separately and individually each time the user 102 needs to send across his biometric data to the receiver 106. It is well known thatECG signals vary from person to person and are unique for each individual. For the transmission of biometric data of one person, the encryption key generated by using the serial numbers associated with the peak points of the said person’s ECG charts will be completely different from the encryption key generated from another person’s ECG charts and encryption key generated from one person's ECG chart cannot be used for another person. Hence, the encryption key generated by using the method disclosed herein would always relate uniquely to the user 102. Due to the inherent randomness and variations in the ECG signals, the encryption key generated using the ECG signals will be unique.
[0061] As per another embodiment of the present invention, the encryption key is generated at the time of initiation of the transmission process between the user 102 and the receiver 106. Each new transmission entails the creation of a new encryption key. Relying on the highly variable nature of the ECG signals, the keys generated for each transmission of the biometric data from the user 102 to the receiver 106 will be unique and different. The user 102 is mandatorily required to generate a new key each time he needs to send the biometric data to the receiver 106.
[0062] Fig. 4(a) shows an electrocardiogram (ECG) chart 401. The ECG chart 401 is indicative of the electrical activity of the heart of an individual which may be picked up by an ECG recording device. In Fig. 4(a), ECG signals are depicted on a graph, with voltage measured in milli-volts (mV) plotted on Y axis and time measured in milliseconds (ms) plotted on X axis.
[0063] Fig. 4(b) highlights R-R peaks 402 in the QRS complex of a filtered electrocardiogram (ECG) chart which is generated from the input data. In Fig. 4(b), ECG signals are depicted on a graph with voltage measured in milli-volts (mV) plotted on Y axis and time in milliseconds (ms) plotted on X axis with highlighted R-R peaks.
[0064] Fig. 4(c) shows a focussed view of R-R peaks 403 in the QRS complex against the corresponding voltage values of an electrocardiogram (ECG) chart. Any part of the ECG signals depicted on the graph with highlighted R-R peaks shown in Fig. 4(b) can be randomly taken. A matrix or array of data points from voltage values corresponding to peak values in the R-R interval of electrocardiogram scans isgenerated. The number of voltage values corresponding to R-R peaks in a matrix or array of data points is not fixed.
[0065] Fig. 5 shows the system 500 for securely encrypting and transmitting the biometric data (such as facial recognition data), in accordance with the preferred embodiment of the present invention. The biometric data is encrypted using the ECG data of the user 102. The system 500 is used for the transmission of the biometric data by the user 102 to at least one receiver 106 via an intermediate system 502. Each receiver 106 is provided with a unique, single-use decryption key for decrypting the encrypted biometric data. In an embodiment of the present invention, the biometric data of the user 102 is transmitted to multiple receivers 106a, 106b and 106c at multiple checkpoints in an authentication-based access control system. The intermediate system 502 is provided with two types of data by the user 102: an image 602 of the face of the user 102, as per the preferred embodiment of the present invention, and .csv data of ECG scan of the user 102 that includes the voltage values corresponding to the time intervals in an ECG scan. The image 602 of the user 102 is captured using a biometric data capturing apparatus 203a. As per the embodiments of the present invention, the biometric data capturing apparatus 203 a can be a camera that is communicatively coupled to either a mobile phone or to the intermediate system 502. It is understood by a person skilled in the art that the biometric data capturing apparatus 203a may be incorporated in the intermediate system 502 in other forms as well, which are commonly used in the industry.
[0066] In the preferred embodiment of the present invention, the image 602 captured by the biometric data capturing apparatus 203a is converted into facial recognition data using the biometric data processing apparatus 203b. The biometric data processing apparatus 203b is primarily responsible for converting the image 602 into facial recognition data that is encrypted and transmitted to the designated recipient(s) 106a, 106b and 106c along with a unique, single-use decryption key to decrypt the facial recognition data. The facial recognition data, for the purposes of the present invention, includes the facial key-points 604 which are extracted from the image 602 provided by the user 102 captured using the biometric data capturing apparatus 203a. The facial key -points 604 may be extracted using a constrained local model (CLM) which would estimate the key-point positions in sample images of faces which areused to train the constrained local model (CLM). Use of other methods to extract the facial key-points 604 are also within the scope of the present invention.
[0067] As would be evident to a person skilled in the art, the constrained local model (CLM) helps in addressing well-known limitations of conventional facial recognition systems by implementing robust features such as liveness testing. The training of the local model may be carried out using techniques that are already known in the prior art. The methods for identification of the key-points in images which contain facial features are well known in the art. For example, Kaggle's dataset for facial key-point detection - which comprises 15 key-points, may be used. Or the more intricate Milborrow / University of Cape Town (MUCT) dataset for facial key-point detection - which comprises 76 key-points can be used for identifying the facial key-points in the model.
[0068] There may be instances where the user 102 uploads an image wherein the facial image has to be extracted before the facial key-points can be detected and extracted by the biometric data processing apparatus 203b of the present invention. In such cases, the first step is to detect the face and its various components such as eyes, lips, and nose. In an embodiment of the present invention, the system 502 may use the Viola-Jones detector based on Haar-cascades to identify the silhouette / outline of the face in the image. The biometric data processing apparatus 203b extracts the facial key-points 604 from the image 602 to generate the facial recognition data. The facial recognition data, as generated, is then encrypted using the encryption key generated from the ECG signal data and transmitted to the designated recipient(s) 106. The biometric data capturing apparatus 203a and the biometric data processing apparatus 203b form part of the input unit 221.
[0069] In an alternative embodiment of the present invention, electrocardiogram data is procured from smart watches, home ECG monitors, or from any other conventional apparatus that are already known in the art. ECG charts generated from the collected ECG data are filtered and segmented to identify and localise the R-R peak of QRS complex of the said ECG chart. The voltage values corresponding to the R-R peaks are arranged in the form of a matrix of data points and an encryption key is generated. The data points are selected from a random time-sample of the ECG chart. As per the preferred embodiment of the present invention, the selected time sample may beas long as 2 seconds however, it would be apparent to a person skilled in the art that the time sample could be either longer or shorter than 2 seconds depending on the processing capabilities of the system as well as the desired complexity of the encryption key. The length of the time sample may be altered depending on the limitations or capabilities of the equipment available to the user; however, the random time-sample should be at least 0.5 seconds long. Furthermore, the matrix of data points is generated from an array of the serial numbers corresponding to the localised R-R peak values in the ECG chart. The encryption key, generated from the serial numbers associated with peak values in the R-R interval in the ECG data, is used for encrypting the facial recognition data generated, as per the preferred embodiment of the present invention. The encrypted facial recognition data is transmitted through a transmission channel which is part of the transmission unit. After the transmission of the encrypted facial recognition data, this encrypted facial recognition data received by the designated receiver(s) and decrypted in the decryption unit using a unique, single-use validated decryption key provided by the intermediate system 502 to the designated receiver(s) 106.
[0070] In an alternative embodiment of the present invention, the order of access of the encrypted data by multiple receivers 106 at their respective checkpoints is defined to ensure the integrity of the encrypted facial recognition data in an access control system. The intermediate system 502 generates the said unique, single-use decryption key for decrypting the encrypted facial recognition data and is sent to multiple receivers 106a, 106b and 106c. Each receiver receives a unique, single-use decryption key for decrypting the encrypted data. In another embodiment of the present invention, the order of the use of the decryption keys by multiple receivers 106a, 106b and 106c at respective checkpoints is pre-defined to ensure integrity of the data of the user 102. For example, in an access control system in accordance with the present invention, the identity of the user 102 is verified at multiple check-points by the receivers 106a, 106b and 106c. Each receiver uses a unique, single-use decryption key generated by the intermediate system 502 to access the encrypted facial data of the user 102 to ascertain and verify its identity. The order of accessing each check-point may be pre-defined and communicated to the user 102 by the intermediate system 502.
[0071] Fig. 6 shows the image 600 captured by the biometric data capturing apparatus 203a as per the preferred embodiment of the present invention. Facial key points 604 are extracted from the facial image 602 of the user 102 captured using the biometric data capturing apparatus 203a. The facial key -points 604 may be extracted using a constrained local model (CLM) which would estimate the key-point positions in sample images of faces which are used to train the constrained local model (CLM). As would be evident to a person skilled in the art, the constrained local model helps in addressing well-known limitations of conventional facial recognition systems by implementing robust features such as liveness testing. The training of the local model may be carried out using techniques that are already known in the prior art. The methods for identification of the key-points in images which contain facial features are well known in the art. For example, Kaggle's dataset for facial key-point detection - which comprises 15 key-points, or the more intricate Milborrow / University of Cape Town (MUCT) dataset for facial key-point detection - which comprises 76 key-points can be used for identifying the facial key-points in the model. There may be instances where the user 102 uploads an image wherein the facial image has to be extracted before the facial key-points can be detected and extracted by the biometric data processing apparatus 203b of the present invention. In such cases, the first step is to detect the face and its various components such as eyes, lips, and nose. In an exemplary embodiment of the present invention, the system 502 uses the Viola-Jones detector based on Haar-cascades to identify the silhouette / outline of the face in the image. Once the image of the face is extracted, the biometric data processing apparatus 203b extracts the facial key-points 604 to generate the facial recognition data. The facial recognition data, as generated, is then encrypted using the encryption key generated from the ECG signal data and transmitted to the designated recipient(s) 106.
[0072] It is understood by a person skilled in the art that the system and method of the present invention may be used for the secure transmission of other types of biometric data such as fingerprint(s) of the user 102, iris / retinal scans of the user’s 102’s eyes, voice recognition data, DNA data of the user 102 as well as a combination thereof which would be capable of uniquely identifying the user 102. It is further understood by a person skilled in the art that the means for capturing and processing the biometric data, even though all of them may not have been disclosed in the detaileddescription, may vary as per the application at hand and would also be covered within the scope of the present invention.
[0073] For example, in an additional embodiment of the present invention, the fingerprint(s) of the user 102 may be captured using a fingerprint scanner that is incorporated in the system 500 as a biometric data capturing apparatus. Additionally, in another embodiment of the present invention, a different scanner may be incorporated in the system 500 for procuring or capturing the iris / retinal scans of the user 102, voice data of the user 102, or the DNA data of the user 102. It is also understood by a person skilled in the art that the means for processing the biometric data, as captured by the biometric data capturing means in accordance with the embodiments of the present invention, may be adjusted to effectively process the biometric data of the user 102 which is to be transmitted to the receiver 106.
[0074] The above-described embodiments of the present are exemplary and non-limiting. They describe specific implementations of the present invention which are not to be construed as limiting the scope of the invention. The present invention can be implemented in different manners and with modifications, which would be obvious to a person skilled in the art, without departing from the spirit and scope of the invention.
Claims
STATEMENT OF CLAIMS im:
1. A system 104 for securely transmitting biometric data of a user 102 comprising: a user interface; an input unit 221 to receive the biometric data and electrocardiogram data of the user 102, wherein the input unit 221 comprises: a biometric data capturing apparatus 203 a to capture the biometric data; a biometric data processing apparatus 203b to process the biometric data; and an electrocardiogram input apparatus 202 to receive the electrocardiogram data; a memory unit for storing the biometric data and the electrocardiogram data; an encryption unit 222 for generating an encryption key 212 for encrypting the biometric data; a transmission unit 223 comprising a transmission channel 218 for wirelessly transmitting the encrypted biometric data; and at least one receiving unit 224 comprising a decryption unit for receiving and decrypting the encrypted biometric data using a decryption key; wherein the encryption key 212 is generated by using an array of serial numbers 210 associated with R-R peak values 208 in a random time-sample 206 of the electrocardiogram data, the random time-sample 206 of the electrocardiogram data being at least 0.5 seconds long.
2. The system as claimed in claim 1, wherein the biometric data capturing apparatus 203a, used to capture the biometric data of the user 102, comprises a camera or an image sensor to capture at least one image 602 of the user 102.
3. The system as claimed in claim 2, wherein the biometric data processing apparatus 203b extracts facial key points 604 from the at least one image 602 of the user 102.
4. The system as claimed in claim 1, wherein the input unit 221, the encryption unit 222 and the transmission unit 223 are all located on a single device, and wherein the input unit 221 comprises the biometric data capturing apparatus 203a, the biometric data processing apparatus 203b and the electrocardiogram input apparatus 202.
5. The system as claimed in claim 1, wherein the electrocardiogram data is raw voltage data of an electrocardiogram scan measured against time or a waveform plot of an electrocardiogram scan voltage plotted against time.
6. The system as claimed in claim 1, wherein the array of serial numbers 210 associated with the R-R peak values 208 in the random time-sample 206 of the electrocardiogram data is arranged in a matrix to generate the encryption key 212.
7. The system as claimed in claim 3, wherein the facial key points 604 from the at least one image of the user 102 are extracted using Kaggle’s dataset or Milborrow / University of Cape Town (MUCT) dataset.
8. The system as claimed in claim 1, wherein the biometric data comprises any combination of one or more of an iris or retinal scan of the user’ s 102’ s eyes, fingerprint data of the user 102, and facial recognition data of the user 102.
9. A method for securely transmitting biometric data of a user 102 comprising: receiving the biometric data of the user 102 and electrocardiogram data of the user 102 through an input unit 221; selecting a random time-sample 206 from the electrocardiogram data, the random time-sample 206 from the electrocardiogram data being at least 0.5 seconds long; identifying R-R peak values 208 in the selected random time-sample 206 of the electrocardiogram data; generating an array of serial numbers 210 associated with the identified R-R peak values 208;generating an encryption key 212 for encrypting the biometric data using the array of serial numbers 210 associated with the R-R peak values 208; encrypting the biometric data with the encryption key 212; and wirelessly transmitting the encrypted biometric data 216 to at least one other user 106; wherein the array of serial numbers 210 associated with the R-R peak values 208 in the random time-sample 206 of the electrocardiogram data is stored in a matrix to generate the encryption key 212.
10. The method as claimed in claim 9, wherein the input unit 221 comprises a biometric data capturing apparatus 203a used to capture the biometric data of the user 102, the biometric data capturing apparatus 203a comprises a camera or an image sensor to capture at least one image of the user 102.
11. The method as claimed in claim 10, wherein the input unit 221 further comprises a biometric data processing apparatus 203b that extracts facial key points 604 from the at least one image of the user 102.
12. The method as claimed in claim 11, wherein the facial key points 604 from the at least one image of the user 102 are extracted using Kaggle’s dataset or Milborrow / University of Cape Town (MUCT) dataset.
13. The method as claimed in claim 9, wherein the biometric data comprises any combination of one or more of an iris or retinal scan of the user’ s 102’ s eyes, fingerprint data of the user 102, and facial recognition data of the user 102.
14. An apparatus for securely transmitting biometric data of a user 102 comprising: a device 221 for receiving the biometric data and electrocardiogram data as input and generating an encryption key 212 to encrypt the biometric data for wirelessly transmitting it to at least one other user 106; wherein the encryption key 212 is generated by using an array of serial numbers 210 associated with R-R peak values 208 in a random time-sample 206 of the electrocardiogram data of the user 102, the random time-sample of the electrocardiogram data being at least 0.5 seconds long.
15. The apparatus as claimed in claim 14, wherein the electrocardiogram data of the user 102 is raw voltage data of an electrocardiogram scan measured against time or a waveform plot of an electrocardiogram scan voltage plotted against time.
16. The apparatus as claimed in claim 14, wherein the array of serial numbers 210 associated with the R-R peak values 208 in the random time-sample 206 of the electrocardiogram data is stored in a matrix to generate the encryption key 212.
17. The apparatus as claimed in claim 14, wherein the biometric data is facial recognition data of the user 102.
18. The apparatus as claimed in claim 14, wherein facial key points 604 are extracted from at least one image of the user 102.
19. The apparatus as claimed in claim 18, wherein the facial key points 604 from the at least one image of the user 102 are extracted using Kaggle’s dataset or Milborrow / University of Cape Town (MUCT) dataset.
20. The apparatus as claimed in claim 14, wherein the biometric data comprises any combination of one or more of an iris or retinal scan of the user’ s 102’ s eyes, fingerprint data of the user 102, and facial recognition data of the user 102.
Citation Information
Patent Citations
Method for Encrypting and Decrypting of Personal Information using ECG Signal
KR1020180026018A
Defecation Apparatus for Fet Dog with Seat Function
KR1020220001626A