Biometric Authentication via Non-Invertible Feature Transformation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Biometric data security in distributed systems is compromised as original biometric data must be stored centrally, making it vulnerable to breaches, and simply encrypting the data does not solve the issue of remote authentication.
Innovation Solution
Transforming biometric data into non-invertible sets using feature transformation keys, which are securely registered and stored on a trusted network node, allowing secure authentication over a communication channel without exposing clear-text data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If original biometric data is stored centrally at a trusted network node, then authentication can be performed remotely, but the security of biometric data is compromised due to vulnerability to breaches
Solution Approach 1:
The patent segments biometric data into multiple components: original biometric data, transformed biometric data, and transformation keys. The original biometric data remains securely stored only at the client device, while transformed data is stored at the trusted network node. This segmentation allows remote authentication without centralizing the original sensitive data, thus maintaining security while enabling remote access.
Solution Approach 2:
The patent introduces transformed biometric data as an intermediary between the original biometric data and the authentication process. The transformed data, which cannot be reversed to obtain original data, serves as a mediator that enables remote verification without exposing the original biometric information. This intermediary mechanism resolves the contradiction by allowing remote authentication while protecting original data security.
2Reliability
If biometric data is encrypted, then data protection is improved, but the original biometric data must still be available at remote locations for authentication
Solution Approach 1:
The patent applies parameter changes by transforming biometric data through irreversible transformation functions that change the data parameters fundamentally. Instead of simple encryption that preserves reversibility, the transformation modifies the data into a form that cannot be reverted to original biometric data. This allows the transformed data to be stored remotely without requiring original data availability, thus reducing device complexity while maintaining protection.
3Ease of operation
If transformed biometric data is stored at a trusted network node, then remote authentication is enabled, but the system complexity increases due to transformation key management
Solution Approach 1:
The patent implements preliminary action by pre-distributing transformation keys to client devices before authentication occurs. The trusted network node stores only the transformed biometric data without needing to manage transformation keys. This preliminary distribution of keys simplifies the overall system architecture, as the key management burden is shifted to individual client devices during the enrollment phase, reducing ongoing system complexity.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The invention relates to methods and devices of enabling authentication of a user (200) of a client device (100, 500) over a secure communication channel based on biometric data. In an aspect of the invention, a network node (300) configured to enable authentication of a user (200) of a client device (100, 500) based on biometric data captured by the client device (100, 500) is provided, which trusted network node (300) comprises a processing unit (301) being configured to receive, from the client device (500), a request to authenticate a user of the client device (500), the authentication request comprising a first set of transformed biometric data transformed with a first secret feature transform key shared with the client device, fetch, from the secure end-user repository (400), a second set of enrolled transformed biometric data associated with the first set of transformed biometric data received from the client device (500) and a second secret feature transform key with which the second set of biometric data was transformed at enrolment of the transformed biometric data at the network node (300), and submit the second set of transformed biometric data and the second secret feature transform key over a secure communication channel to the client device (500).