Biometric Authentication via Non-Invertible Feature Transformation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Biometric data security in distributed systems is compromised as original biometric data must be stored centrally, making it vulnerable to breaches, and simply encrypting the data does not solve the issue of remote authentication.

Innovation Solution

Transforming biometric data into non-invertible sets using feature transformation keys, which are securely registered and stored on a trusted network node, allowing secure authentication over a communication channel without exposing clear-text data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If original biometric data is stored centrally at a trusted network node, then authentication can be performed remotely, but the security of biometric data is compromised due to vulnerability to breaches

Engineering Contradiction:
Improveremote authentication capabilityVSAvoidbiometric data security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments biometric data into multiple components: original biometric data, transformed biometric data, and transformation keys. The original biometric data remains securely stored only at the client device, while transformed data is stored at the trusted network node. This segmentation allows remote authentication without centralizing the original sensitive data, thus maintaining security while enabling remote access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces transformed biometric data as an intermediary between the original biometric data and the authentication process. The transformed data, which cannot be reversed to obtain original data, serves as a mediator that enables remote verification without exposing the original biometric information. This intermediary mechanism resolves the contradiction by allowing remote authentication while protecting original data security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If biometric data is encrypted, then data protection is improved, but the original biometric data must still be available at remote locations for authentication

Engineering Contradiction:
Improvebiometric data protectionVSAvoiddata availability requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by transforming biometric data through irreversible transformation functions that change the data parameters fundamentally. Instead of simple encryption that preserves reversibility, the transformation modifies the data into a form that cannot be reverted to original biometric data. This allows the transformed data to be stored remotely without requiring original data availability, thus reducing device complexity while maintaining protection.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If transformed biometric data is stored at a trusted network node, then remote authentication is enabled, but the system complexity increases due to transformation key management

Engineering Contradiction:
Improveremote authenticationVSAvoidtransformation key management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-distributing transformation keys to client devices before authentication occurs. The trusted network node stores only the transformed biometric data without needing to manage transformation keys. This preliminary distribution of keys simplifies the overall system architecture, as the key management burden is shifted to individual client devices during the enrollment phase, reducing ongoing system complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3682357B1Methods and devices of enabling authentication of a user of a client device over a secure communication channel based on biometric data
Publication Date: 2022.03.09 FINGERPRINT CARDS ANACATUM IP AB
  • EP3682357B1 patent drawingFigure 1~2
  • EP3682357B1 patent drawingFigure 3
  • EP3682357B1 patent drawingFigure 4

AI summary

The invention relates to methods and devices of enabling authentication of a user (200) of a client device (100, 500) over a secure communication channel based on biometric data. In an aspect of the invention, a network node (300) configured to enable authentication of a user (200) of a client device (100, 500) based on biometric data captured by the client device (100, 500) is provided, which trusted network node (300) comprises a processing unit (301) being configured to receive, from the client device (500), a request to authenticate a user of the client device (500), the authentication request comprising a first set of transformed biometric data transformed with a first secret feature transform key shared with the client device, fetch, from the secure end-user repository (400), a second set of enrolled transformed biometric data associated with the first set of transformed biometric data received from the client device (500) and a second secret feature transform key with which the second set of biometric data was transformed at enrolment of the transformed biometric data at the network node (300), and submit the second set of transformed biometric data and the second secret feature transform key over a secure communication channel to the client device (500).