Asymmetric Key Generation from Biometric Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication systems, such as RSA SecurID, are vulnerable to cyber attacks due to the use of symmetric keys, which can be stolen or compromised, leading to unauthorized access to corporate networks, and lack a secure integration of user identity with data protection, resulting in insecure transactions and compromised biometric authentication.
Innovation Solution
A decentralized and non-deterministic system using asymmetric keys generated from biometric data and physical processes, where each user's asymmetric secrets are unique and mathematically intractable to derive, stored on both a physical token and a backend server, ensuring that compromising one device does not reveal the other's secret, and using one-time passcodes that are unpredictable and difficult to predict.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If symmetric keys are used for authentication, then authentication can be performed, but the system becomes vulnerable to cyber attacks and key theft
Solution Approach 1:
The patent applies asymmetry by transitioning from symmetric key authentication to asymmetric key authentication. Each user has a unique key pair (private key and public key) where the private key remains secret on the user's device and the public key is stored on the blockchain. This asymmetric structure eliminates the vulnerability of shared secret keys while maintaining authentication capability through cryptographic verification of digital signatures.
2Ease of operation
If passwords are used for access control, then users can authenticate, but users must remember many complex passwords and passwords can be stolen
Solution Approach 1:
The patent replaces the mechanical password system (where users manually create, remember, and type passwords) with a cryptographic system based on asymmetric keys and digital signatures. Users generate key pairs once, and the private key is securely stored in their digital wallet. Authentication is performed automatically through digital signature verification on the blockchain, eliminating the need for users to remember complex passwords while maintaining strong security.
3Reliability
If biometric authentication is used, then user identity can be verified, but the integration with data protection remains insecure
Solution Approach 1:
The patent segments the authentication system into distinct functional components: biometric data collection, biometric template generation and storage, and cryptographic key generation. The biometric data is processed to create unique templates that are stored securely, while asymmetric key pairs are generated separately. This segmentation allows biometric verification to be integrated with blockchain-based cryptographic authentication, ensuring that biometric information itself is not exposed during transactions while still providing strong identity verification.
Data Source
AI summary
Methods and systems are provided for performing a secure transaction. In an embodiment, users register biometric and/or other identifying user information. A private encryption key is generated from the biometric information and/or other user information and/or information obtained from a unpredictable physical process and are stored in a secure area of a device and a public key is transmitted to the blockchain network which acts as a service provider. In some embodiments, the execution and integrity of transactions by using transaction signatures, based on visual images is disclosed. In an embodiment, a blockchain network verifies and executes the transaction.


