Biometric Consent Authentication System for GDPR Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack efficient methods for obtaining and storing separate, authenticated, advance consent for each instance of personally identifiable information (PII) use, particularly in compliance with regulations like GDPR, which requires irrefutable biometric authentication to prevent fraud and ensure compliance.
Innovation Solution
A computer-implemented method and system that uses biometric authentication, including video recordings, fingerprint photographs, and identification credential photographs, to electronically request, receive, and store consent specimens, with matching determination and transaction information, facilitating quick and secure consent processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric authentication is implemented for each consent instance, then reliability of consent authentication is improved, but device complexity and processing time increase
Solution Approach 1:
The consent process is segmented into distinct phases: enrollment phase where biometric reference data is captured and stored, and consent phase where the same biometric modalities are used for authentication. This segmentation allows the system to maintain high reliability through consistent biometric verification while managing complexity by separating the data collection and verification operations.
Solution Approach 2:
The system employs multiple biometric modalities (facial recognition, fingerprint, voice recognition) that can be used across different consent instances. This multi-functionality approach ensures reliable authentication while allowing the system to select appropriate modalities based on context, reducing unnecessary processing complexity.
2Reliability
If separate authenticated consent is obtained for each PII use instance, then compliance with data protection regulations is improved, but time required for consent processing increases
Solution Approach 1:
The system performs preliminary action by capturing and storing biometric reference data during an enrollment phase before actual consent is needed. This pre-collection of reference data eliminates the need for time-consuming biometric verification during each consent instance, allowing rapid authentication while maintaining regulatory compliance.
Solution Approach 2:
The system creates and stores digital copies of biometric data (facial images, fingerprint scans, voice samples) as reference templates. These copies enable rapid comparison and verification during consent processes without requiring repeated physical biometric measurements, significantly reducing processing time while maintaining authentication reliability.
3Measurement precision
If biometric data is stored and compared for consent verification, then authentication accuracy is improved, but data security risks increase
Solution Approach 1:
The system uses an intermediary verification mechanism where stored biometric reference data is compared against new biometric inputs using standardized algorithms. This intermediary comparison process, handled by secure processing systems, maintains high matching accuracy while isolating sensitive data handling from direct user interaction, reducing security risks.
Solution Approach 2:
The system employs parameter changes in biometric verification by adjusting matching thresholds and sensitivity levels based on the specific consent context and risk level. This allows the system to maintain high accuracy for critical authentication while reducing data processing intensity for lower-risk scenarios, thereby managing security risks.
Data Source
AI summary
A computer implemented system and method for acquisition of advance consent for each instance of PII use includes the steps of receiving reference specimens for a user, electronically storing the reference specimens on a distributed block chain. When PII of the user is to be used, a consent session is electronically requested for the user. Consent-session specimens are electronically received from the user in response to the electronic request for the consent-session after completion of the consent session. The consent-session specimens include a video of the user making an affirmative consent statement, a photograph of fingerprints of the user, and a photograph of identification (ID) credentials of the user. A degree to which each of the consent-session specimens from the user match the reference specimens for the user is electronically determined and the transaction information is electronically stored on the distributed block chain.


