Biometric Challenge-Response Authentication Without Central Data Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing biometric authentication systems face challenges in ensuring privacy and security, particularly due to the storage of sensitive biometric data in centralized databases, which are vulnerable to identity theft and privacy breaches, and are prone to errors from equipment differences and biological changes.
Innovation Solution
A method using pseudo-homomorphic authentication based on challenge-response pairs (CRPs) generated from unclonable biological features, where biometric data is never stored, and authentication is performed using pre-enrollment data to standardize measurements, allowing secure communication without storing biometric images.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric data is stored in centralized databases for authentication, then authentication functionality is enabled, but security and privacy are compromised due to vulnerability to identity theft and privacy breaches
Solution Approach 1:
The patent extracts and eliminates the centralized biometric database from the authentication system. Instead of storing biometric templates centrally, the system uses distributed authentication where each user device independently verifies authentication credentials locally, removing the vulnerable centralized storage component while maintaining authentication functionality
Solution Approach 2:
The patent introduces cryptographic credentials and challenge-response protocols as intermediaries between the user and the authentication system. These cryptographic mechanisms mediate the authentication process without requiring direct access to or storage of raw biometric data, thereby protecting privacy while enabling reliable authentication
2Ease of operation
If biometric data is stored centrally, then authentication is simplified, but the system becomes prone to errors from equipment differences and biological changes
Solution Approach 1:
The patent performs preliminary processing of biometric data during enrollment to create stable cryptographic credentials. Challenge-response pairs are pre-computed and stored, allowing rapid authentication without re-measuring or re-comparing raw biometric data, thus eliminating errors from equipment variations and biological changes while maintaining operational simplicity
Solution Approach 2:
The patent transforms biometric measurements into cryptographic parameters through hashing and challenge-response mechanisms. This parameter transformation converts variable biometric readings into stable cryptographic credentials that are insensitive to measurement variations, preserving authentication accuracy while simplifying the authentication process
Data Source
AI summary
Methods for the generation and use of session keys for authentication of a user of a server device are disclosed. The methods use a biological objects of the user to generate responses to challenges. During enrollment, the server device receives a password, hashes it a first number of times, and sends the hash to the user. The user interprets the hash as a set of challenges for the biological object, applies the challenges, and stores the responses. During authentication, the server hashes the password a second number of times, less than the first number, and sends the hash to the user. The user iteratively applies second hash to the biological object, compares the responses to the stored responses, and if there is not a match, hashes the challenges again until there is a match. The number of hashes needed for a match is a session key or subkey.


