Biometric Authentication System Using Local Secure Element
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing biometric authentication systems fail to ensure user privacy as they often require external storage or transmission of biometric data, making users vulnerable to data theft and lacking control over their own data.
Innovation Solution
A biometric authentication system and method where biometric data are stored and processed on a user-owned medium with an embedded electronic device, allowing for secure comparison without external storage or transmission, ensuring absolute user privacy and eliminating the need for a biometric sensor on the medium.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric data are stored in external servers or devices for authentication, then authentication functionality is achieved, but user privacy is compromised and data security risks increase
Solution Approach 1:
The patent extracts the biometric data storage function from external servers and places it directly on the user's mobile device. The biometric template is stored locally in the device's secure storage, eliminating the need for external biometric databases and giving users control over their own biometric information.
Solution Approach 2:
The patent introduces an intermediary component - a trusted execution environment or secure element within the mobile device - that acts as a mediator between the biometric sensor and the authentication system. This intermediary processes and protects biometric data locally without exposing it to external servers, thus maintaining privacy while enabling authentication.
2Ease of operation
If biometric data are transmitted to external devices for verification, then authentication is performed, but data privacy cannot be ensured as data could be collected undesirably
Solution Approach 1:
Instead of the traditional approach where biometric data flows from the user to the authentication server, the patent inverts the data flow direction. The authentication request travels from the server to the user's device, and only a verification result (not the biometric data itself) is transmitted back. This inversion ensures biometric data remains on the user's device.
Solution Approach 2:
The patent uses a copy of the biometric template stored securely on the user's device for verification purposes, rather than transmitting the original biometric data. The local copy is used to generate a verification result that can be safely transmitted without compromising the privacy of the actual biometric information.
3Object-affected harmful factors
If media contain both biometric datum and biometric reader, then user privacy is guaranteed, but medium complexity and cost increase significantly
Solution Approach 1:
The patent makes the user's mobile device serve multiple functions: it acts as both the biometric sensor (using the device's camera or sensor for facial recognition) and the biometric database (storing the biometric template locally). This multi-functionality eliminates the need for separate dedicated biometric hardware, reducing complexity and cost while maintaining privacy.
Solution Approach 2:
The mobile device performs self-service by using its own existing sensors and processing capabilities to capture and verify biometric data locally. The device's processor compares the captured biometric data against the stored template without requiring external authentication hardware, thereby simplifying the overall system architecture.
Data Source
Figure 1~2
AI summary
The invention refers to a biometric authentication system and a biometric authentication method using biometric data that guarantee an absolute privacy of the user who needs to be authenticated.