Biometric Authentication System Using Multi-Server Encrypted Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for providing services using biometric information face challenges in protecting user biometric data, particularly due to its uniqueness and vulnerability to external attacks, which limits service access for users without cash or credit cards and poses risks of information exposure.
Innovation Solution
A system involving an electronic device, a first server, and a second server that encrypts biometric information using encryption keys, transmits encrypted data, and authenticates user identification, allowing secure service provision without exposing raw biometric data, utilizing multiple servers for registration and validation processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If biometric information is stored and transmitted in plaintext for service authentication, then service accessibility is improved, but user data security deteriorates
Solution Approach 1:
The patent introduces encrypted biometric information as an intermediary between the user and the service system. Instead of transmitting plaintext biometric data, the system uses encrypted representations that cannot be directly interpreted, thus protecting user privacy while enabling authentication services.
Solution Approach 2:
The patent creates encrypted copies of biometric information that functionally replace the original plaintext data. These encrypted copies contain the necessary authentication information while being useless for identity reconstruction, effectively decoupling service functionality from data exposure risk.
2Object-affected harmful factors
If biometric information is encrypted to protect user privacy, then data security is improved, but service authentication capability deteriorates
Solution Approach 1:
The patent transforms biometric information from its original plaintext parameter state to an encrypted parameter state. This parameter change maintains the essential authentication properties while eliminating the privacy risks, allowing the system to work with transformed data that preserves functionality but removes vulnerability.
3Object-affected harmful factors
If multiple encryption layers are applied to biometric information, then data protection is improved, but system complexity deteriorates
Solution Approach 1:
The patent segments the encryption process into distinct stages: initial encryption of biometric information, and subsequent encryption of the already-encrypted data. This segmentation allows each encryption layer to serve a specific protective function while maintaining clear system architecture and manageable complexity.
Data Source
Figure 1
Figure 2
Figure 3A
AI summary
A system for performing a service by using biometric information is disclosed. A system according to the present disclosure comprises an electronic device, a first server and a second server, and a control method of the system comprises the steps of: allowing the electronic device to acquire first biometric information; allowing the electronic device to acquire first encrypted data, in which the first biometric information is encrypted, by using the acquired first biometric information and a first encryption key, and to transmit same to the first server, allowing the first server to acquire second encrypted data, in which the first encrypted data is encrypted, by using the first encrypted data received from the electronic device and a second encrypted key, and first user identification information corresponding to the first biometric information, and to transmit same to the second server; allowing the second server to match the second encrypted data and the first user identification information corresponding to the biometric information, which are received from the first server, and to store same; allowing the second server to acquire authentication information on the basis of the matched second encrypted data and first user identification information, and to transmit same to the first server, and allowing the first server to register the authentication information on the biometric information.