Biometric Consent Authentication System for GDPR Compliance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack efficient methods for obtaining and storing separate, authenticated, advance consent for each instance of personally identifiable information (PII) use, particularly in compliance with regulations like GDPR, which requires irrefutable biometric authentication to prevent fraud and ensure compliance.

Innovation Solution

A computer-implemented method and system that uses biometric authentication, including video recordings, fingerprint photographs, and identification credential photographs, to electronically request, receive, and store consent specimens, with matching determination and transaction information, facilitating quick and secure consent processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric authentication is implemented for each consent instance, then reliability of consent authentication is improved, but device complexity and processing time increase

Engineering Contradiction:
Improveconsent authentication reliabilityVSAvoidconsent processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The consent process is segmented into distinct phases: enrollment phase where biometric reference data is captured and stored, and consent phase where the same biometric modalities are used for authentication. This segmentation allows the system to maintain high reliability through consistent biometric verification while managing complexity by separating the data collection and verification operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs multiple biometric modalities (facial recognition, fingerprint, voice recognition) that can be used across different consent instances. This multi-functionality approach ensures reliable authentication while allowing the system to select appropriate modalities based on context, reducing unnecessary processing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If separate authenticated consent is obtained for each PII use instance, then compliance with data protection regulations is improved, but time required for consent processing increases

Engineering Contradiction:
Improveregulatory complianceVSAvoidconsent processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by capturing and storing biometric reference data during an enrollment phase before actual consent is needed. This pre-collection of reference data eliminates the need for time-consuming biometric verification during each consent instance, allowing rapid authentication while maintaining regulatory compliance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates and stores digital copies of biometric data (facial images, fingerprint scans, voice samples) as reference templates. These copies enable rapid comparison and verification during consent processes without requiring repeated physical biometric measurements, significantly reducing processing time while maintaining authentication reliability.

Inventive Principle:
Principle #26Copying

3Measurement precision

If biometric data is stored and compared for consent verification, then authentication accuracy is improved, but data security risks increase

Engineering Contradiction:
Improvebiometric matching accuracyVSAvoiddata security risk
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system uses an intermediary verification mechanism where stored biometric reference data is compared against new biometric inputs using standardized algorithms. This intermediary comparison process, handled by secure processing systems, maintains high matching accuracy while isolating sensitive data handling from direct user interaction, reducing security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system employs parameter changes in biometric verification by adjusting matching thresholds and sensitivity levels based on the specific consent context and risk level. This allows the system to maintain high accuracy for critical authentication while reducing data processing intensity for lower-risk scenarios, thereby managing security risks.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11777929B2Field forensic method to acquire adaptable format biometric evidentiary proof of having complied with the special consent provisions of countries' data protection regulations
Publication Date: 2023.10.03 NATIONAL FINGERPRINT INC
  • US11777929B2 patent drawing
  • US11777929B2 patent drawing
  • US11777929B2 patent drawing

AI summary

A computer implemented system and method for acquisition of advance consent for each instance of PII use includes the steps of receiving reference specimens for a user, electronically storing the reference specimens on a distributed block chain. When PII of the user is to be used, a consent session is electronically requested for the user. Consent-session specimens are electronically received from the user in response to the electronic request for the consent-session after completion of the consent session. The consent-session specimens include a video of the user making an affirmative consent statement, a photograph of fingerprints of the user, and a photograph of identification (ID) credentials of the user. A degree to which each of the consent-session specimens from the user match the reference specimens for the user is electronically determined and the transaction information is electronically stored on the distributed block chain.