Anonymous Biometric Matching via Cancelable Transforms

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current biometric systems face challenges in identifying individuals while preserving anonymity, particularly in security screening contexts, where widespread collection is met with privacy concerns and risks of data misuse, such as infiltration by moles or restrictions on international information sharing.

Innovation Solution

The use of cancelable non-invertible biometric transforms allows for the comparison of biometric data in a transformed manner that preserves anonymity, enabling secure matching without revealing original biometric information, thus addressing privacy concerns and facilitating secure screening without creating permanent collections.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric data is collected and stored for security screening purposes, then security identification capability is improved, but privacy protection deteriorates and risk of data misuse increases

Engineering Contradiction:
Improvesecurity identification capabilityVSAvoidprivacy invasion and data misuse risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trusted third party (TTP) as an intermediary that holds the master key and facilitates secure biometric matching between entities without allowing them to access raw biometric data. The TTP transforms biometric templates using secure multi-party computation protocols, enabling security screening while preserving privacy by ensuring no single entity possesses both the raw biometric data and the transformation key.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent transforms biometric templates by changing their mathematical representation through cryptographic transformations. Original biometric templates are converted into transformed templates using secure transformation functions, allowing matching operations to be performed on transformed data rather than raw biometric data, thereby maintaining security identification capability while protecting privacy.

Inventive Principle:
Principle #35Parameter changes

2Productivity

If biometric collections are shared between security agencies, then intelligence gathering capability is improved, but security risk deteriorates due to potential infiltration and unauthorized disclosure

Engineering Contradiction:
Improveintelligence gathering capabilityVSAvoidsecurity risk from infiltration and unauthorized disclosure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The trusted third party acts as a secure intermediary that enables intelligence sharing between security agencies without requiring direct access to sensitive biometric collections. Agencies can query for matches against transformed templates through the TTP, which performs the matching operation securely and returns only match results, preventing mole infiltration from compromising the entire network.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates transformed copies of biometric templates that can be shared and queried without exposing the original sensitive data. These transformed templates serve as secure surrogates that enable intelligence gathering through matching operations while the original biometric collections remain protected and inaccessible to potential infiltrators.

Inventive Principle:
Principle #26Copying

3Measurement precision

If raw biometric data is stored permanently for future reference, then identification accuracy is improved, but vulnerability to data breaches and unauthorized access increases

Engineering Contradiction:
Improveidentification accuracyVSAvoidvulnerability to data breaches
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent permanently stores transformed biometric templates rather than raw biometric data. The transformation changes the parameter representation of biometric features into a cryptographic form that maintains identification accuracy for matching purposes while being computationally infeasible to reverse or misuse for unauthorized identification, thereby reducing vulnerability to data breaches.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8908929B2Method, apparatus and computer program product implementing anonymous biometric matching
Publication Date: 2014.12.09 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8908929B2 patent drawing
  • US8908929B2 patent drawing
  • US8908929B2 patent drawing

AI summary

Method, apparatus and computer program product compare biometrics in an anonymous manner. A first collection of biometrics is transformed using a first cancelable non-invertible biometric transform to create a first collection of transformed biometrics. A second collection of biometrics is transformed using the first cancelable non-invertible biometric transform to create a second collection of transformed biometrics. The first and second collection of transformed biometrics are then compared in the transformed domain to determine if any of the transformed biometrics from the first collection match any of the transformed biometrics from the second collection. If a match is found, the parties respectively maintaining the first and second collections of biometrics exchange information confidential nature of the biometrics are maintained by the entities responsible for the collections, since the biometrics are not compared in an untransformed state.