Anonymous Biometric Matching via Cancelable Transforms
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current biometric systems face challenges in identifying individuals while preserving anonymity, particularly in security screening contexts, where widespread collection is met with privacy concerns and risks of data misuse, such as infiltration by moles or restrictions on international information sharing.
Innovation Solution
The use of cancelable non-invertible biometric transforms allows for the comparison of biometric data in a transformed manner that preserves anonymity, enabling secure matching without revealing original biometric information, thus addressing privacy concerns and facilitating secure screening without creating permanent collections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric data is collected and stored for security screening purposes, then security identification capability is improved, but privacy protection deteriorates and risk of data misuse increases
Solution Approach 1:
The patent introduces a trusted third party (TTP) as an intermediary that holds the master key and facilitates secure biometric matching between entities without allowing them to access raw biometric data. The TTP transforms biometric templates using secure multi-party computation protocols, enabling security screening while preserving privacy by ensuring no single entity possesses both the raw biometric data and the transformation key.
Solution Approach 2:
The patent transforms biometric templates by changing their mathematical representation through cryptographic transformations. Original biometric templates are converted into transformed templates using secure transformation functions, allowing matching operations to be performed on transformed data rather than raw biometric data, thereby maintaining security identification capability while protecting privacy.
2Productivity
If biometric collections are shared between security agencies, then intelligence gathering capability is improved, but security risk deteriorates due to potential infiltration and unauthorized disclosure
Solution Approach 1:
The trusted third party acts as a secure intermediary that enables intelligence sharing between security agencies without requiring direct access to sensitive biometric collections. Agencies can query for matches against transformed templates through the TTP, which performs the matching operation securely and returns only match results, preventing mole infiltration from compromising the entire network.
Solution Approach 2:
The patent creates transformed copies of biometric templates that can be shared and queried without exposing the original sensitive data. These transformed templates serve as secure surrogates that enable intelligence gathering through matching operations while the original biometric collections remain protected and inaccessible to potential infiltrators.
3Measurement precision
If raw biometric data is stored permanently for future reference, then identification accuracy is improved, but vulnerability to data breaches and unauthorized access increases
Solution Approach 1:
The patent permanently stores transformed biometric templates rather than raw biometric data. The transformation changes the parameter representation of biometric features into a cryptographic form that maintains identification accuracy for matching purposes while being computationally infeasible to reverse or misuse for unauthorized identification, thereby reducing vulnerability to data breaches.
Data Source
AI summary
Method, apparatus and computer program product compare biometrics in an anonymous manner. A first collection of biometrics is transformed using a first cancelable non-invertible biometric transform to create a first collection of transformed biometrics. A second collection of biometrics is transformed using the first cancelable non-invertible biometric transform to create a second collection of transformed biometrics. The first and second collection of transformed biometrics are then compared in the transformed domain to determine if any of the transformed biometrics from the first collection match any of the transformed biometrics from the second collection. If a match is found, the parties respectively maintaining the first and second collections of biometrics exchange information confidential nature of the biometrics are maintained by the entities responsible for the collections, since the biometrics are not compared in an untransformed state.


