Asymmetric Key Generation from Biometric Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication systems, such as RSA SecurID, are vulnerable to cyber attacks due to the use of symmetric keys, which can be stolen or compromised, leading to unauthorized access to corporate networks, and lack a secure integration of user identity with data protection, resulting in insecure transactions and compromised biometric authentication.

Innovation Solution

A decentralized and non-deterministic system using asymmetric keys generated from biometric data and physical processes, where each user's asymmetric secrets are unique and mathematically intractable to derive, stored on both a physical token and a backend server, ensuring that compromising one device does not reveal the other's secret, and using one-time passcodes that are unpredictable and difficult to predict.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If symmetric keys are used for authentication, then authentication can be performed, but the system becomes vulnerable to cyber attacks and key theft

Engineering Contradiction:
Improveauthentication securityVSAvoidcyber attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies asymmetry by transitioning from symmetric key authentication to asymmetric key authentication. Each user has a unique key pair (private key and public key) where the private key remains secret on the user's device and the public key is stored on the blockchain. This asymmetric structure eliminates the vulnerability of shared secret keys while maintaining authentication capability through cryptographic verification of digital signatures.

Inventive Principle:
Principle #4Asymmetry

2Ease of operation

If passwords are used for access control, then users can authenticate, but users must remember many complex passwords and passwords can be stolen

Engineering Contradiction:
Improvepassword managementVSAvoidpassword security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical password system (where users manually create, remember, and type passwords) with a cryptographic system based on asymmetric keys and digital signatures. Users generate key pairs once, and the private key is securely stored in their digital wallet. Authentication is performed automatically through digital signature verification on the blockchain, eliminating the need for users to remember complex passwords while maintaining strong security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If biometric authentication is used, then user identity can be verified, but the integration with data protection remains insecure

Engineering Contradiction:
Improveidentity verificationVSAvoidbiometric data security
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the authentication system into distinct functional components: biometric data collection, biometric template generation and storage, and cryptographic key generation. The biometric data is processed to create unique templates that are stored securely, while asymmetric key pairs are generated separately. This segmentation allows biometric verification to be integrated with blockchain-based cryptographic authentication, ensuring that biometric information itself is not exposed during transactions while still providing strong identity verification.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240169350A1Securing transactions with a blockchain network
Publication Date: 2024.05.23 BIOGY INC
  • US20240169350A1 patent drawing
  • US20240169350A1 patent drawing
  • US20240169350A1 patent drawing

AI summary

Methods and systems are provided for performing a secure transaction. In an embodiment, users register biometric and/or other identifying user information. A private encryption key is generated from the biometric information and/or other user information and/or information obtained from a unpredictable physical process and are stored in a secure area of a device and a public key is transmitted to the blockchain network which acts as a service provider. In some embodiments, the execution and integrity of transactions by using transaction signatures, based on visual images is disclosed. In an embodiment, a blockchain network verifies and executes the transaction.