Biometric Authentication Server Architecture for Secure Key Separation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing biometric authentication systems face security risks due to the concentration of decryption keys and encrypted biometric information in a single server, making them vulnerable to hacking and potential data leaks.
Innovation Solution
Implementing a control method that separates the storage of biometric information and decryption keys across different servers, where biometric information is encrypted and decrypted using unique keys, and only the decryption key corresponding to the target client is used for authentication, preventing unauthorized access and data exposure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If decryption keys and encrypted biometric information are stored in a single server, then the system structure is simple and easy to manage, but the security against hacking and data leaks deteriorates
Solution Approach 1:
The patent divides the storage system into separate components: a biometric information storage server that stores encrypted biometric data and a decryption key storage server that stores decryption keys. This segmentation ensures that even if one server is hacked, the other server contains the necessary information to prevent complete data breach, thus resolving the contradiction between system simplicity and security reliability.
2Reliability
If decryption keys are stored separately from biometric information, then the security against data leaks is improved, but the device complexity and management difficulty increase
Solution Approach 1:
The patent introduces a matching server as an intermediary component that coordinates between the biometric information storage server and the decryption key storage server. The matching server manages the authentication process by requesting encrypted biometric information from one server and decryption keys from another, then performing the matching operation. This intermediary approach simplifies the overall system management while maintaining the security benefits of separate storage.
3Reliability
If multiple servers are used for storing biometric information and decryption keys, then the security and data protection are enhanced, but the system complexity and communication overhead increase
Solution Approach 1:
The matching server performs multiple functions: it receives authentication requests, obtains encrypted biometric information from the biometric information storage server, retrieves decryption keys from the decryption key storage server, performs the matching operation, and returns results. This multi-functionality consolidates complex operations into a single server, reducing system complexity while maintaining the security advantages of distributed storage.
Data Source
AI summary
Provided are control methods of a decryption key storage server, a biometric information storage server, and a matching server in an authentication system. The control method of a decryption key storage server in an authentication system includes: acquiring an identifier of a target client and a encrypted biometric information for authentication; acquiring biometric information for registration corresponding to the identifier to be matched among pieces of the biometric information for registration having been encrypted by the at least one client transmitting the biometric information for registration; extracting a decryption key corresponding to the identifier from the at least one decryption key; decrypting the encrypted biometric information for authentication and the biometric information for registration corresponding to the identifier using the decryption key corresponding to the identifier; and determining whether or not the decrypted biometric information for authentication and the decrypted biometric information for registration corresponding to the identifier match.


