Biometric Challenge-Response Authentication Without Central Data Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing biometric authentication systems face challenges in ensuring privacy and security, particularly due to the storage of sensitive biometric data in centralized databases, which are vulnerable to identity theft and privacy breaches, and are prone to errors from equipment differences and biological changes.

Innovation Solution

A method using pseudo-homomorphic authentication based on challenge-response pairs (CRPs) generated from unclonable biological features, where biometric data is never stored, and authentication is performed using pre-enrollment data to standardize measurements, allowing secure communication without storing biometric images.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric data is stored in centralized databases for authentication, then authentication functionality is enabled, but security and privacy are compromised due to vulnerability to identity theft and privacy breaches

Engineering Contradiction:
Improveauthentication securityVSAvoidprivacy breach vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts and eliminates the centralized biometric database from the authentication system. Instead of storing biometric templates centrally, the system uses distributed authentication where each user device independently verifies authentication credentials locally, removing the vulnerable centralized storage component while maintaining authentication functionality

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces cryptographic credentials and challenge-response protocols as intermediaries between the user and the authentication system. These cryptographic mechanisms mediate the authentication process without requiring direct access to or storage of raw biometric data, thereby protecting privacy while enabling reliable authentication

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If biometric data is stored centrally, then authentication is simplified, but the system becomes prone to errors from equipment differences and biological changes

Engineering Contradiction:
Improveauthentication simplicityVSAvoidbiometric matching accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent performs preliminary processing of biometric data during enrollment to create stable cryptographic credentials. Challenge-response pairs are pre-computed and stored, allowing rapid authentication without re-measuring or re-comparing raw biometric data, thus eliminating errors from equipment variations and biological changes while maintaining operational simplicity

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent transforms biometric measurements into cryptographic parameters through hashing and challenge-response mechanisms. This parameter transformation converts variable biometric readings into stable cryptographic credentials that are insensitive to measurement variations, preserving authentication accuracy while simplifying the authentication process

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20260005876A1Pseudo-homomorphic authentication of users with biometry
Publication Date: 2026.01.01 ARIZONA BOARD OF REGENTS ACTING FOR & ON BEHALF OF NORTHERN ARIZONA UNIV
  • US20260005876A1 patent drawing
  • US20260005876A1 patent drawing
  • US20260005876A1 patent drawing

AI summary

Methods for the generation and use of session keys for authentication of a user of a server device are disclosed. The methods use a biological objects of the user to generate responses to challenges. During enrollment, the server device receives a password, hashes it a first number of times, and sends the hash to the user. The user interprets the hash as a set of challenges for the biological object, applies the challenges, and stores the responses. During authentication, the server hashes the password a second number of times, less than the first number, and sends the hash to the user. The user iteratively applies second hash to the biological object, compares the responses to the stored responses, and if there is not a match, hashes the challenges again until there is a match. The number of hashes needed for a match is a session key or subkey.