Biometric Authentication via Segmented Cryptographic Key Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for authenticating or identifying individuals in digital environments face challenges in generalizing biometric use while protecting digital identity and rights, particularly in everyday applications, where conventional methods are difficult to implement securely and ergonomically.

Innovation Solution

A method involving an initialization phase that captures biometric data, generates encryption keys, and creates a public identity stored on a server, allowing secure authentication without revealing personal data, using a security component in identification objects like mobile phones or smart cards, ensuring the object's secure use only by its legitimate holder.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric data are used in association with an identification object to ensure uniqueness, then authentication reliability is improved, but the complexity of the authentication system increases

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into multiple independent components: biometric data captured by the identification object, cryptographic keys generated by the security component, and authentication verification performed by the server. This segmentation allows each component to be optimized independently while maintaining overall system reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Cryptographic keys act as intermediaries between biometric data and authentication verification. The biometric data is transformed into cryptographic keys through a one-way function, and these keys serve as the actual authentication credential exchanged with the server, simplifying the overall authentication process while maintaining reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If personal data are used for registering individuals with the server, then identification accuracy is improved, but the risk to individual anonymity increases

Engineering Contradiction:
Improveidentification accuracyVSAvoidanonymity risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The invention extracts and uses only the necessary identifying features (biometric data) while excluding unnecessary personal information. The biometric data is processed through a one-way cryptographic function to generate keys that can verify identity without revealing the actual biometric characteristics or personal data to the server.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of storing or transmitting actual biometric data or personal information, the system creates cryptographic copies (keys) that represent the identity information. These cryptographic keys can be used for authentication purposes without containing or revealing the original sensitive data, thus protecting anonymity while maintaining identification accuracy.

Inventive Principle:
Principle #26Copying

3Reliability

If complex data such as passwords are used for authentication, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of use
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The identification object autonomously performs the complex cryptographic operations required for secure authentication. The security component within the object automatically generates cryptographic keys from biometric data and handles the authentication protocol with the server, eliminating the need for the user to manually manage complex passwords or cryptographic credentials while maintaining high security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10007773B2Method for generating public identity for authenticating an individual carrying an identification object
Publication Date: 2018.06.26 IDEMIA IDENTITY & SECURITY FRANCE SAS
  • US10007773B2 patent drawing
  • US10007773B2 patent drawing
  • US10007773B2 patent drawing

AI summary

A method for generating a public identity for authenticating an individual carrying an identification object, the method including: entering an initial biometric datum of the individual; generating a first key from the biometric datum; generating a second key derived from a datum generated by a security component of the object; generating an initial encryption key combining the first key and the second key; communicating with a server a first identity of the individual in connection with the initial encryption key; generating by the server a public identity by encrypting the first identity using the initial encryption key, the public identity being stored by the server in connection with the initial encryption key. The public identity is not significant, but is secured by a strong connection between the object and biometry of the individual.