Post quantum identity (PQID) method involving deterministic stable bit vectors

The method generates stable bit vectors from biometric data using post-quantum cryptography to create secure, quantum-resistant authentication, addressing vulnerabilities in traditional systems by ensuring consistent cryptographic key generation and privacy-centric data handling.

WO2026073566A1PCT designated stage Publication Date: 2026-04-09WHATSKEY INC LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-10-05
Publication Date
2026-04-09

AI Technical Summary

Technical Problem

Traditional authentication methods, including password-based systems and biometric systems, are vulnerable to security breaches due to weak password practices and the threat of quantum computing, with biometric data storage creating a single point of failure and potential for unauthorized access.

Method used

A method using biometric data to generate a stable bit vector, combined with post-quantum cryptographic algorithms, which eliminates sensitive biometric data storage and employs a privacy-centric Certificate Authority, incorporating salting, error-correcting codes, and multi-factor authentication for robust, quantum-resistant identity verification.

Benefits of technology

Ensures secure and consistent cryptographic key generation resistant to quantum computing threats, maintaining user privacy by eliminating biometric data storage and enhancing security with dual asymmetric and symmetric cryptography.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024078081_09042026_PF_FP_ABST
    Figure EP2024078081_09042026_PF_FP_ABST
Patent Text Reader

Abstract

A method for quantum-resistant cryptographic identity authentication is disclosed, comprising the collection of biometric data from a user and the application of a stable bit vector algorithm to generate a stable bit vector. The stable bit vector algorithm combines the user's biometric features with public parameters to deterministically compute the stable bit vector. Cryptographic information, including private, secret, and public information, are deterministically generated from the stable bit vector using a post-quantum cryptographic algorithm. The method includes deleting the biometric data after enrollment, storing public information in a privacy-centric Certificate Authority, and updating and revoking public information as needed. During authentication, a new stable bit vector is computed from newly collected biometric data, and a new set of cryptographic information is generated for identity verification against stored public information. The method provides a secure, scalable, and quantum-resistant authentication system compatible with various devices.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] DESCRIPTION

[0002] Field of invention

[0003] The present relates to digital security, more specifically to cryptographic identity authentication methods that are resistant to quantum computing threats using biometric-generated stable bit vectors and post-quantum cryptographic algorithms.

[0004] Background

[0005] In the realm of digital security, the verification of user identities remains an aspect of maintaining secure access to various services while safeguarding individual privacy. Security measures are increasingly facing challenges due to their vulnerabilities. For instance, methods relying on secret codes are susceptible to various forms of compromise, including weak selection practices and the potential for repeated use across different platforms, which can lead to widespread security breaches. Systems that utilize individual physical characteristics for identification purposes are not without their own set of risks. These risks are particularly pronounced in scenarios where sensitive data is stored within third party infrastructure vaults, often centrally, creating a single point of failure that, if exploited, could result in unauthorized access to multiple services. Additionally, the emergence of advanced computing technologies has introduced a new array of potential threats to cryptographic systems, underscoring the urgency for more robust security solutions. This context highlights the pressing need for innovative security measures that effectively balance the dual requirements of enhanced protection and user privacy.

[0006] Brief description of drawings

[0007] FIG. 1 illustrates the enrollment process flow for generating a stable bit vector and cryptographic elements in the pqlD system.

[0008] FIG. 2 illustrates a block diagram of the authentication process using the stable bit vector algorithm and post-quantum cryptographic (PQC) algorithm.

[0009] PROBLEM & SOLUTION STATEMENT In the field of digital security, the authentication of user identities is a juncture between access and privacy. Traditional authentication methods, such as password-based systems, are vulnerable to a variety of security threats. Users often employ easily guessable passwords or reuse them across multiple platforms, which can lead to widespread security breaches if one system is compromised. Furthermore, the increasing computational power of modern technology has rendered many conventional cryptographic systems vulnerable, highlighting the need for more secure authentication methods.

[0010] Biometric authentication systems, which use physical characteristics for identification, offer an alternative to password-based systems. These systems typically store biometric data on a central server or on a local device, creating a single point of failure. In the event of a server and or device breach, sensitive biometric data could be exposed, potentially allowing unauthorized access across multiple platforms. Additionally, the advent of quantum computing presents a significant threat to the security of current cryptographic systems, including those based on biometrics, due to the potential for quantum computers to break traditional encryption algorithms.

[0011] The present method introduces a method for quantum-resistant cryptographic identity authentication that addresses the aforementioned security concerns. This method utilizes biometric data to generate a stable bit vector, which in turn is used to deterministically generate cryptographic data using post-quantum cryptographic algorithms. The method eliminates the need to store sensitive biometric data after the enrollment phase, thereby reducing the risk of data breaches. Furthermore, the method employs a privacy-centric Certificate Authority for storing public data, enhancing user privacy while maintaining security. The method is designed to be universally compatible with various biometric sensors and devices, ensuring flexibility and user convenience. By incorporating additional security measures such as salting, error-correcting codes, and multi-factor authentication, the method provides a robust, scalable, and quantum-resistant identity verification system. The salting method enhances security by not only combining multiple stable bit vectors derived from the user's biometric data, such as fingerprints, face recognition, and iris scans, but also by introducing variants of stable bit vectors and other types of deterministic values. Additionally, a stable bit vector can be derived from the same biometric algorithms applied to an object, and the salting process can involve mixing various stable bit vectors from different or similar sources. This approach ensures that the stable bit vector used as a deterministic seed input to generate the post-quantum cryptographic (PQC) keys is highly secure and resistant to potential attacks. Error-correcting codes further improve the stability and reliability of the stable bit vector, while multi-factor authentication adds an extra layer of security by requiring additional forms of verification beyond biometric data.

[0012] TECHNICAL EFFECTS

[0013] The method for quantum-resistant cryptographic identity authentication described in claim 1 introduces a novel approach by leveraging a stable bit vector algorithm combined with post-quantum cryptographic algorithms. This combination ensures that the authentication process remains secure even against the computational power of future quantum computers. The stable bit vector algorithm deterministically combines the user's biometric features and public parameters to generate a stable bit vector, which is then used to derive cryptographic keys. This deterministic approach ensures that the same biometric data will always produce the same bit vector, which in turn will consistently generate the same set of post-quantum cryptographic (PQC) keys. These PQC keys are the essence of the post quantum Identity (pqlD) system, enhancing the reliability and security of the authentication process.

[0014] By generating cryptographic keys, including private, secret, and public keys, from the stable bit vector using a post-quantum cryptographic algorithm, the method provides a robust defense against quantum computing threats. The generated private keys are asymmetric keys designed to pair with the generated public keys, which are later stored in Certificate Authorities (CAs). These private-public key pairs are essential for establishing secure and authenticated communication channels. On the other hand, the secret keys are used as symmetric keys, which can be employed to establish secure communication channels utilizing symmetric key algorithms, such as AES. This dual approach ensures that the system benefits from the strengths of both asymmetric and symmetric cryptography, providing a comprehensive and quantum-resistant security solution. The cryptographic keys are derived deterministically from the stable bit vector, ensuring consistency and security in the key generation process. This approach eliminates the need to store sensitive biometric data after the enrollment phase, significantly reducing the risk of data breaches and unauthorized access.

[0015] Furthermore, the method's reliance on public parameters and the stable bit vector algorithm ensures that no sensitive biometric data is stored or transmitted, enhancing user privacy and security. The public parameters also contribute to improving the robustness of the system by allowing for easier re-computation of the stable bit vector during the authentication process, thereby reducing errors due to biometric noise. The public parameters, which are stored in a publicly accessible database such as a Certificate Authority (CA), facilitate secure and scalable authentication without the need for device-specific enrollments. This universal compatibility with various biometric sensors and devices provides flexibility and convenience for users, making the system practical for widespread adoption.

[0016] Overall, the method described in claim 1 offers a secure, scalable, and quantum-resistant identity verification system that addresses the limitations of traditional password-based and biometric authentication methods. By combining biometric data with post-quantum cryptographic algorithms and ensuring the deletion of sensitive data post-enrollment, the method provides a robust solution for secure digital identity authentication in the face of emerging quantum computing threats.

[0017] DIFFERENT EMBODIMENTS

[0018] In one embodiment, the method for quantum-resistant cryptographic identity authentication incorporates a multi-modal biometric data collection approach during the enrollment phase. This approach may include the simultaneous or sequential collection of fingerprints, facial recognition data, and iris scans to generate a comprehensive stable bit vector that encapsulates a wider array of biometric features. The stable bit vector algorithm in this embodiment is designed to process and integrate these diverse biometric inputs, ensuring a high level of accuracy and security in the resulting cryptographic data. Another embodiment might focus on the adaptability of the stable bit vector algorithm to different environmental conditions and biometric data quality. For instance, the algorithm could be tailored to compensate for low-quality biometric samples by employing advanced image processing techniques or machine learning models that can accurately extract biometric features even from suboptimal data. This would ensure that the stable bit vector remains consistent and reliable across various conditions and biometric sensor technologies.

[0019] A further embodiment could involve the integration of the stable bit vector algorithm with wearable technology. In this scenario, biometric data could be collected via smartwatches, fitness trackers, or other wearable devices equipped with sensors capable of capturing biometric information like heart rate or gait patterns. The stable bit vector algorithm would be optimized for the types of biometric data these devices provide, expanding the versatility of the authentication method to include new forms of biometric data.

[0020] Additionally, an embodiment may be designed for environments with strict privacy regulations, where the stable bit vector algorithm is enhanced with additional layers of security. This could involve the use of homomorphic encryption techniques that allow the algorithm to operate on encrypted biometric data without ever decrypting the biometric data, thereby preserving the privacy of the user's biometric information throughout the authentication process.

[0021] An embodiment could be tailored for high-traffic public spaces, such as airports or stadiums, where the authentication process needs to be both rapid and highly secure. In this embodiment, the stable bit vector algorithm would be optimized for speed, employing parallel processing and high-performance computing techniques to quickly generate stable bit vectors and cryptographic elements, facilitating a seamless user experience without compromising security.

[0022] In one embodiment, the method for quantum-resistant cryptographic identity authentication is implemented within a secure mobile application environment. The application utilizes the device's integrated biometric sensors, such as a fingerprint scanner or facial recognition camera, to collect the user's biometric data which can be securely transmitted to a distant execution environment if not local. The stable bit vector algorithm processes this data in conjunction with the retrieved public parameters from a secure cloud-based database to compute a new stable bit vector each time the user attempts authentication. The application then uses a post-quantum cryptographic algorithm such as FrodoKEM, NewHope, or Crystals-KYBER, among others to generate the necessary cryptographic data, ensuring that the user's identity is verified securely and efficiently without storing sensitive biometric information on the device and remotely.

[0023] Another embodiment involves the integration of the authentication method within a smart home ecosystem. In this scenario, various biometric sensors are strategically placed throughout the home, such as on door locks or home security panels. These sensors collect biometric data from residents and visitors for authentication purposes. The system's central processing unit applies the stable bit vector algorithm and interacts with a home-based server or a distributed network to retrieve public parameters and generate cryptographic data. This embodiment allows for a seamless and secure method of identity verification that is both convenient for users and resilient to potential quantum computing threats.

[0024] A further embodiment includes the deployment of the authentication method within an enterprise security infrastructure. Here, the method is integrated with existing security protocols and hardware, such as employee ID scanners or secure access terminals. The stable bit vector algorithm is hosted on the enterprise's secure servers, which also store the public parameters and manage the generation of cryptographic data. This embodiment ensures that employee identity authentication is not only quantum-resistant but also aligns with the organization's broader security measures and compliance requirements.

[0025] Additionally, an embodiment may be designed for use in financial transactions, where the stable bit vector algorithm is incorporated into ATMs or payment terminals. In this context, the algorithm processes biometric data collected during transactions to authenticate users before allowing access to financial services. The system ensures that cryptographic information is generated in real-time and that no biometric data is stored after the transaction, providing a high level of security for sensitive financial operations.

[0026] In one embodiment of the apparatus for quantum-resistant cryptographic identity authentication, the biometric sensor is integrated into a secure access control system for facilities such as data centers or research labs. The sensor is designed to quickly and accurately collect biometric data, such as retinal scans or hand geometry, to ensure that only authorized personnel can gain access. The processor, equipped with advanced algorithms, processes the biometric data in real-time and applies the stable bit vector algorithm to generate an identifier for each individual. The cryptographic module, utilizing state-of-the-art post-quantum cryptographic algorithms, ensures the generation of secure pqlD that are immune to quantum attacks. The storage module not only deletes the biometric data post-enrollment and post-authentication but also manages the lifecycle of the public identifiers in collaboration with the privacy-centric Certificate Authority, which operates with enhanced privacy protocols to prevent user tracking.

[0027] In another embodiment, the apparatus is deployed in a healthcare setting, where patient identification and privacy are of utmost importance. The biometric sensor is capable of non-intrusive biometric data collection, such as voice recognition or behavioral biometrics, to minimize patient discomfort. The processor and cryptographic module work in tandem to provide a secure and private authentication process that complies with healthcare regulations like HIPAA. The storage module ensures that all biometric data is handled according to strict data protection standards, and the privacy-centric Certificate Authority facilitates secure access to patient records and medical services.

[0028] A further embodiment involves the apparatus being incorporated into a financial services infrastructure, such as ATMs or online banking platforms. The biometric sensor is designed to thwart spoofing attempts and ensure that the biometric data collected is genuine. The processor's stable bit vector algorithm is optimized for high-speed processing to deliver a seamless user experience during transactions. The cryptographic module provides robust encryption for financial data, and the storage module works with the Certificate Authority to implement stringent security measures that protect against fraud and identity theft.

[0029] Additionally, an embodiment of the apparatus is tailored for consumer electronics, such as smartphones and laptops, where user convenience and security are crucial. The biometric sensor is miniaturized and embedded into the devices, allowing for discrete and continuous biometric data collection. The processor's stable bit vector algorithm is optimized for low power consumption to preserve battery life, while the cryptographic module offers a balance between strong security and computational efficiency. The storage module ensures that biometric data is securely erased after use, and the privacy-centric Certificate Authority enables secure device unlocking and authentication for various applications and services. Furthermore, the processor's stable bit vector algorithm and the post-quantum cryptographic (PQC) algorithm do not necessarily need to operate locally on the thin device. Instead, these algorithms can be executed in a secure, remote environment, such as a cloud-based server or a dedicated hardware security module, ensuring that the computationally intensive processes are offloaded from the device, thereby preserving its resources and enhancing overall security.

[0030] These embodiments demonstrate the versatility of the method for quantum-resistant cryptographic identity authentication, showcasing the method's adaptability to various environments and applications while maintaining the security features outlined in the patent claims.

[0031] DESCRIPTION OF FIGURES

[0032] FIG. 1 illustrates the enrollment process flow for generating a stable bit vector and cryptographic elements in the pqlD system. The process involves a user 10, biometrics features 15, a stable bit vector algorithm learning data 20, public parameters 25, a stable bit vector 30, a deterministic seed 40, a post-quantum cryptographic (PQC) algorithm 45, private cryptographic elements 50, a public cryptographic element (PKI) 55, and public storage including a Certificate Authority (CA) 35.

[0033] The user 10 initiates the enrollment process by providing biometrics features 15, which may include fingerprints, facial recognition data, or iris scans. These features are for creating an identifier for the user 10.

[0034] The stable bit vector algorithm learning data 20 receives the biometric features 15 and applies a learning algorithm to generate a stable representation of the user's biometric data. This process involves several key steps to ensure the stability and security of the generated bit vector 30. Initially, the biometric features 15, which may include fingerprints, facial recognition data, or iris scans, are collected from the user 10. These features are then processed by the learning algorithm to extract unique and stable characteristics that can be consistently reproduced across different samples of the same biometric data.

[0035] The learning data 20 utilizes public parameters 25 to ensure the stability and security of the bit vector 30 generated. The public parameters 25 are predefined values that play a crucial role in the generation process. These parameters 25 are combined with the biometric features 15 in a deterministic manner, meaning that the same biometric input will always produce the same stable bit vector 30. This deterministic approach is essential for maintaining the reliability and consistency of the system, as it ensures that the stable bit vector 30 remains unchanged for the same biometric data, even when collected at different times or under varying conditions.

[0036] The public parameters 25 also contribute to the security of the stable bit vector 30. By incorporating these parameters 25 into the generation process, the system can prevent unauthorized access and ensure that the bit vector 30 cannot be easily guessed or replicated by malicious actors. The parameters 25 act as an additional layer of security, making it more difficult for attackers to compromise the system. Once the stable bit vector 30 is generated, it serves as a deterministic output from the stable bit vector algorithm learning data 20. This bit vector 30 is then used in conjunction with a deterministic seed 40 to generate cryptographic values. The deterministic seed 40 is a predefined value that, when combined with the stable bit vector 30, provides an additional layer of security and ensures the cryptographic values generated by the PQC algorithm 45 are robust and secure.

[0037] The PQC algorithm 45 is responsible for generating the cryptographic data necessary for secure communication. The algorithm 45 uses the stable bit vector 30 and the deterministic seed 40 to produce private keys and secret keys 50, which remain confidential to the user 10. These cryptographic keys are generated in a manner that is resistant to quantum computing attacks, ensuring the long-term security of the authentication process.

[0038] The private keys and secret keys 50 are used by the user 10 to authenticate and establish secure connections. The PQC algorithm 45 also generates a public key 55, which is a non-confidential piece of data that can be shared publicly to facilitate secure communication with the user 10. The public key 55 is stored in public storage including CA 35, which is a repository accessible by entities that need to verify the user's identity. The inclusion of CA 35 ensures that the public key 55 can be trusted and is managed in a secure manner.

[0039] This comprehensive process ensures that the stable bit vector 30 is not only consistent and reliable but also secure against potential threats, providing a robust foundation for quantum-resistant cryptographic identity authentication.

[0040] FIG. 2 illustrates a block diagram of the authentication process using the stable bit vector algorithm and post-quantum cryptographic (PQC) algorithm. The process involves several components, each playing a role in the authentication method:

[0041] The user 10 represents an individual seeking to authenticate their identity through the system. User 10 initiates the authentication process by providing a biometric sample 60.

[0042] The biometric sample 60 is a collection of biometric data provided by user 10. This data may include, but is not limited to, fingerprints, facial recognition data, or iris scans. Biometric sample 60 serves as the basis for generating a stable bit vector 30.

[0043] The stable bit algorithm 65 receives the biometric sample 60 and processes it using public parameters 25. The stable bit algorithm 65 applies a deterministic process to generate the stable bit vector 30, which is used for the subsequent cryptographic operations. The public parameters 25 are predefined values that ensure the stability and security of the bit vector 30. These parameters 25 are combined with the biometric sample 60 in a deterministic manner, meaning that the same biometric input will always produce the same stable bit vector 30. This deterministic approach is essential for maintaining the reliability and consistency of the system, as it ensures that the stable bit vector 30 remains unchanged for the same biometric data, even when collected at different times or under varying conditions.

[0044] The stable bit vector 30 is the output of the stable bit algorithm 65. The stable bit vector 30 is a representation of the user's biometric data, computed deterministically to ensure consistency and security in the authentication process. The deterministic seed 40 is an input to the post-quantum cryptographic (PQC) algorithm 45. The deterministic seed 40 is a predefined value that, when combined with the stable bit vector 30, contributes to the generation of cryptographic key material.

[0045] The post-quantum cryptographic (PQC) algorithm 45 utilizes the stable bit vector 30 and the deterministic seed 40 to generate a set of cryptographic elements. These elements include private keys and secret keys 50, which are used for establishing a secure and authenticated session for user 10. The PQC algorithm 45 is responsible for generating the cryptographic data necessary for secure communication. The algorithm 45 uses the stable bit vector 30 and the deterministic seed 40 to produce private keys and secret keys 50, which remain confidential to the user 10. These cryptographic keys are generated in a manner that is resistant to quantum computing attacks, ensuring the long-term security of the authentication process.

[0046] The private keys and secret keys 50 are the cryptographic data generated by the PQC algorithm 45. They are used by user 10 to authenticate and establish secure connections. Private keys and secret keys 50 are designed to be resistant to quantum computing attacks, ensuring the long-term security of the authentication process.

[0047] The public storage including Certificate Authority (CA) 35 serves as a repository for the public cryptographic element (public key) 55. The Certificate Authority (CA) 35 is a trusted entity that manages the storage and accessibility of public cryptographic elements necessary for the authentication of user 10. The public key 55 is a non-confidential piece of data that can be shared publicly to facilitate secure communication with the user 10. The public key 55 is stored in public storage including CA 35, which is a repository accessible by entities that need to verify the user's identity. The inclusion of CA 35 ensures that the public key 55 can be trusted and is managed in a secure manner.

[0048] The digital signature 70 is a cryptographic proof of the user's identity, generated by the PQC algorithm 45. The digital signature 70 is used in conjunction with the public storage including CA 35 for ID check 75.

[0049] The ID check 75 is the final step in the authentication process, where the digital signature 70 and the public cryptographic element (public key) 55 are used to verify the identity of user 10 against the stored public information in the public storage including CA 35.

[0050] This authentication process depicted in FIG. 2 provides a secure and efficient method for verifying the identity of user 10 by leveraging biometric data, public parameters, and post-quantum cryptography to generate and manage cryptographic data.

Claims

CLAIMS1. A method for quantum-resistant cryptographic identity authentication, comprising:- collecting a set of biometric data from a user during an enrollment phase;- applying the stable bit vector algorithm learning data to the new set of biometric data to compute the paired public parameters and stable bit vector;- generating cryptographic keys using a post-quantum cryptographic algorithm, wherein the cryptographic keys are derived deterministically from the stable bit vector, and wherein the cryptographic keys include private keys, secret keys, and public keys;- deleting the collected biometric data after the enrollment phase is completed;- storing the public keys in a privacy-centric Certificate Authority (CA) that anonymizes user activities;- collecting a new set of biometric data from the user during an authentication phase;- retrieving the public parameters associated with the user from a publicly accessible database during the authentication phase;- applying the stable bit vector algorithm to the new set of biometric data and the retrieved public parameters to compute a new stable bit vector;- generating a new set of cryptographic keys using the post-quantum cryptographic algorithm, wherein the new set of cryptographic keys is derived deterministically from the new stable bit vector;- verifying the user's identity by comparing the new set of cryptographic keys with the public keys stored in the publicly accessible database.

2. The method according to claim 1 , wherein the set of biometric data collected from the user includes at least one of fingerprints, face images, and iris images.

3. The method according to claim 1 , wherein the post-quantum cryptographic algorithm used for generating cryptographic keys is FrodoKEM or a similar algorithm.

4. The method according to claim 1, further enhancing the stable bit vector algorithm with a salting method to enhance security.

5. The method according to claim 4, further comprising applying error-correcting codes or locality-sensitive hashing to improve the stability of the stable bit vector.

6. The method according to claim 1 , wherein the public keys are stored in a privacy-centric Certificate Authority (CA) that anonymizes user activities.

7. The method according to claim 1 , further comprising regularly updating and revoking public keys in the public key infrastructure.

8. The method according to claim 1 , wherein the biometric data is collected using standard biometric sensors.

9. The method according to claim 1 , further comprises associating the public keys with the user's public identifier and storing the public keys in a publicly accessible database.

10. The method according to claim 1 , further comprises a multi-factor authentication process that combines the biometric-based authentication with another form of authentication, such as a password or a hardware token.

11. The method according to claim 1 , wherein the stable bit vector algorithm includes a machine learning model trained to enhance the accuracy and stability of the bit vector generation.

12. The method, according to claim 1, further involves encrypting the public parameters before storing them in the publicly accessible database to enhance security.

13. The method according to claim 1, wherein the biometric data collected during the authentication phase is processed in real-time to generate the stable bit vector.

14. The method according to claim 1 , further comprising using a distributed ledger technology, such as blockchain, to store and manage the public keys and public parameters to enhance transparency and security.

15. The method according to claim 1 , wherein the stable bit vector algorithm is designed to be resilient to variations in biometric data due to aging, injuries, or environmental factors.

16. The method according to claim 1, further comprising providing a user interface that allows users to manage their public keys and view their authentication history.

17. The method according to claim 1, wherein the system includes a mechanism for detecting and mitigating potential spoofing attacks during the biometric data collection phase.

18. The method according to claim 1 , further comprising periodically re-enrolling users to update their biometric data and public parameters to maintain the accuracy and security of the authentication process.

19. The method according to claim 1 , wherein the system is designed to operate in a decentralized manner, allowing multiple independent entities to perform the authentication process.

20. An apparatus for quantum-resistant cryptographic identity authentication, comprising:- a biometric sensor configured to collect a set of biometric data from a user during an enrollment phase;- a processor configured to apply a stable bit vector algorithm learning data to the new set of biometric data to compute the paired public parameters and stable bit vector;- a cryptographic module configured to generate cryptographic keys using a post-quantum cryptographic algorithm, wherein the cryptographic keys are derived deterministically from the stable bit vector, and wherein the cryptographic keys include private keys, secret keys, and public keys;- a storage module configured to delete the collected biometric data after the enrollment phase is completed and to store the public keys in a privacy-centric Certificate Authority (CA) that anonymizes user activities;- wherein the processor is further configured to collect a new set of biometric data from the user during an authentication phase, retrieve the public parameters associated with the user from a publicly accessible database during the authentication phase, apply the stable bit vector algorithm to the new set of biometric data and the retrieved public parameters to compute a new stable bit vector, generate a new set of cryptographic keys using the post-quantum cryptographic algorithm, wherein the new set of cryptographic keys is derived deterministically from the new stable bit vector, and verify the user's identity by comparing the new set of cryptographic keys with the public keys stored in the publicly accessible database.

21. A system for quantum-resistant cryptographic identity authentication, comprising:- a plurality of biometric sensors configured to collect biometric data from users during an enrollment phase;- a central processing unit (CPU) configured to apply a stable bit vector algorithm learning data to the new set of biometric data to compute the paired public parameters and stable bit vector;- a cryptographic engine configured to generate cryptographic keys using a post-quantum cryptographic algorithm, wherein the cryptographic keys are derived deterministically from the stable bit vectors, and wherein the cryptographic keys include private keys, secret keys, and public keys;- a privacy-centric Certificate Authority (CA) configured to store the public keys and anonymize user activities;- a database accessible by the CA for storing public parameters and public keys;- wherein the CPU is further configured to collect new sets of biometric data from users during an authentication phase, retrieve the public parameters associated with the users from the database during the authentication phase, apply the stable bit vector algorithm to the new sets of biometric data and the retrieved public parameters to compute new stable bit vectors, generate new sets of cryptographic keys using the post-quantum cryptographic algorithm, wherein the new sets of cryptographic keys are derived deterministically from the new stable bit vectors, and verify the users' identities by comparing the new sets of cryptographic keys with the public keys stored in the database.

22. A non-transitory computer-readable medium storing instructions that, when executed by a processor, cause the processor to perform a method for quantum-resistant cryptographic identity authentication, the method comprising:- collecting a set of biometric data from a user during an enrollment phase;- applying a stable bit vector algorithm learning data to the new set of biometric data to compute the paired public parameters and stable bit vector;- generating cryptographic keys using a post-quantum cryptographic algorithm, wherein the cryptographic keys are derived deterministically from the stable bit vector, and wherein the cryptographic keys include private keys, secret keys, and public keys;- deleting the collected biometric data after the enrollment phase is completed;- storing the public keys in a privacy-centric Certificate Authority (CA) that anonymizes user activities;- collecting a new set of biometric data from the user during an authentication phase;- retrieving the public parameters associated with the user from a publicly accessible database during the authentication phase;- applying the stable bit vector algorithm to the new set of biometric data and the retrieved public parameters to compute a new stable bit vector;- generating a new set of cryptographic keys using the post-quantum cryptographic algorithm, wherein the new set of cryptographic keys is derived deterministically from the new stable bit vector;- verifying the user's identity by comparing the new set of cryptographic keys with the public keys stored in the publicly accessible database.

23. The method according to claim 1 , further comprising periodically re-enrolling users to update their biometric data and public parameters to maintain the accuracy and security of the authentication process.

24. The method according to claim 1 , wherein the system is designed to operate in a decentralized manner, allowing multiple independent entities to perform the authentication process.

25. An apparatus for quantum-resistant cryptographic identity authentication, comprising:- a biometric sensor configured to collect a set of biometric data from a user during an enrollment phase;- a processor configured to apply a stable bit vector algorithm learning data to the new set of biometric data to compute the paired public parameters and stable bit vector;- a cryptographic module configured to generate cryptographic keys using a post-quantum cryptographic algorithm, wherein the cryptographic keys are derived deterministically from the stable bit vector, and wherein the cryptographic keys include private keys, secret keys, and public keys;- a storage module configured to delete the collected biometric data after the enrollment phase is completed and to store the public keys in a privacy-centric Certificate Authority (CA) that anonymizes user activities;- wherein the processor is further configured to collect a new set of biometric data from the user during an authentication phase, retrieve the public parameters associated with the user from a publicly accessible database during the authentication phase, apply the stable bit vector algorithm to the new set of biometric data and the retrieved public parameters to compute a new stable bit vector, generate a new set of cryptographic keys using the post-quantum cryptographic algorithm, wherein the new set of cryptographic keys is derived deterministically from the new stable bit vector, and verify the user's identity by comparing the new set of cryptographic keys with the public keys stored in the publicly accessible database.

26. A system for quantum-resistant cryptographic identity authentication, comprising:- a plurality of biometric sensors configured to collect biometric data from users during an enrollment phase;- a central processing unit (CPU) configured to apply a stable bit vector algorithm learning data to the new set of biometric data to compute the paired public parameters and stable bit vector;- a cryptographic engine configured to generate cryptographic keys using a post-quantum cryptographic algorithm, wherein the cryptographic keys are derived deterministically from the stable bit vectors, and wherein the cryptographic keys include private keys, secret keys, and public keys;- a privacy-centric Certificate Authority (CA) configured to store the public keys and anonymize user activities;- a database accessible by the CA for storing public parameters and public keys;- wherein the CPU is further configured to collect new sets of biometric data from users during an authentication phase, retrieve the public parameters associated with the users from the database during the authentication phase, apply the stable bit vector algorithm to the new sets of biometric data and the retrieved public parameters to compute new stable bit vectors, generate new sets of cryptographic keys using the post-quantum cryptographic algorithm, wherein the new sets of cryptographic keys are derived deterministically from the new stable bit vectors, and verify the users' identities by comparing the new sets of cryptographic keys with the public keys stored in the database.

27. A non-transitory computer-readable medium storing instructions that, when executed by a processor, cause the processor to perform a method for quantum-resistant cryptographic identity authentication, the method comprising:- collecting a set of biometric data from a user during an enrollment phase;- applying a stable bit vector algorithm learning data to the new set of biometric data to compute the paired public parameters and stable bit vector;- generating cryptographic keys using a post-quantum cryptographic algorithm, wherein the cryptographic keys are derived deterministically from the stable bit vector, and wherein the cryptographic keys include private keys, secret keys, and public keys;- deleting the collected biometric data after the enrollment phase is completed;- storing the public keys in a privacy-centric Certificate Authority (CA) that anonymizes user activities;- collecting a new set of biometric data from the user during an authentication phase;- retrieving the public parameters associated with the user from a publicly accessible database during the authentication phase;- applying the stable bit vector algorithm to the new set of biometric data and the retrieved public parameters to compute a new stable bit vector;- generating a new set of cryptographic keys using the post-quantum cryptographic algorithm, wherein the new set of cryptographic keys is derived deterministically from the new stable bit vector;- verifying the user's identity by comparing the new set of cryptographic keys with the public keys stored in the publicly accessible database.

Citation Information

Patent Citations

  • Biometric Public Key System Providing Revocable Credentials

    US20230031928A1