Biometric Authentication System Using Multi-Server Encrypted Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for providing services using biometric information face challenges in protecting user biometric data, particularly due to its uniqueness and vulnerability to external attacks, which limits service access for users without cash or credit cards and poses risks of information exposure.

Innovation Solution

A system involving an electronic device, a first server, and a second server that encrypts biometric information using encryption keys, transmits encrypted data, and authenticates user identification, allowing secure service provision without exposing raw biometric data, utilizing multiple servers for registration and validation processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If biometric information is stored and transmitted in plaintext for service authentication, then service accessibility is improved, but user data security deteriorates

Engineering Contradiction:
Improveservice accessibilityVSAvoiddata exposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces encrypted biometric information as an intermediary between the user and the service system. Instead of transmitting plaintext biometric data, the system uses encrypted representations that cannot be directly interpreted, thus protecting user privacy while enabling authentication services.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates encrypted copies of biometric information that functionally replace the original plaintext data. These encrypted copies contain the necessary authentication information while being useless for identity reconstruction, effectively decoupling service functionality from data exposure risk.

Inventive Principle:
Principle #26Copying

2Object-affected harmful factors

If biometric information is encrypted to protect user privacy, then data security is improved, but service authentication capability deteriorates

Engineering Contradiction:
Improvedata exposure riskVSAvoidauthentication capability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent transforms biometric information from its original plaintext parameter state to an encrypted parameter state. This parameter change maintains the essential authentication properties while eliminating the privacy risks, allowing the system to work with transformed data that preserves functionality but removes vulnerability.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If multiple encryption layers are applied to biometric information, then data protection is improved, but system complexity deteriorates

Engineering Contradiction:
Improvedata exposure riskVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the encryption process into distinct stages: initial encryption of biometric information, and subsequent encryption of the already-encrypted data. This segmentation allows each encryption layer to serve a specific protective function while maintaining clear system architecture and manageable complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3757830B1System for performing service by using biometric information, and control method therefor
Publication Date: 2022.03.23 SAMSUNG ELECTRONICS CO LTD
  • EP3757830B1 patent drawingFigure 1
  • EP3757830B1 patent drawingFigure 2
  • EP3757830B1 patent drawingFigure 3A

AI summary

A system for performing a service by using biometric information is disclosed. A system according to the present disclosure comprises an electronic device, a first server and a second server, and a control method of the system comprises the steps of: allowing the electronic device to acquire first biometric information; allowing the electronic device to acquire first encrypted data, in which the first biometric information is encrypted, by using the acquired first biometric information and a first encryption key, and to transmit same to the first server, allowing the first server to acquire second encrypted data, in which the first encrypted data is encrypted, by using the first encrypted data received from the electronic device and a second encrypted key, and first user identification information corresponding to the first biometric information, and to transmit same to the second server; allowing the second server to match the second encrypted data and the first user identification information corresponding to the biometric information, which are received from the first server, and to store same; allowing the second server to acquire authentication information on the basis of the matched second encrypted data and first user identification information, and to transmit same to the first server, and allowing the first server to register the authentication information on the biometric information.