Biometric-Based Cryptographic Key Generation for Secure Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional cryptographic keys are vulnerable to unauthorized access and duplication, leading to security breaches in authentication systems, as they can be recreated and spoofed, compromising system security.

Innovation Solution

Generating a unique signature key based on user biometric data, such as fingerprints, heartbeat waveforms, and other physiological characteristics, which is then used to create a verification key for identity verification, ensuring the key is specific to the user and not stored persistently, thus reducing the risk of unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cryptographic keys are used for authentication, then the authentication system is simple to implement, but the security is vulnerable to unauthorized access and key duplication

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms static cryptographic keys into dynamic biometric-based authentication. Biometric parameters (fingerprint patterns, facial features, iris structures) replace traditional key parameters, creating unique, non-duplicable authentication credentials that are inherently secure and difficult to compromise

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces mechanical cryptographic key storage and verification systems with biometric sensing and pattern recognition systems. Instead of storing and managing cryptographic keys, the system captures and analyzes physiological characteristics, eliminating key management complexity while enhancing security

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Speed

If cryptographic keys are stored persistently for authentication, then authentication speed is improved, but the risk of unauthorized access increases

Engineering Contradiction:
Improveauthentication speedVSAvoidunauthorized access risk
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic authentication where biometric data is captured and processed in real-time during each authentication attempt. Instead of relying on statically stored keys, the system continuously verifies current biometric characteristics, ensuring authentication speed while eliminating persistent security vulnerabilities

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent treats biometric authentication credentials as ephemeral rather than persistent. Each authentication uses temporary biometric data capture and processing without long-term storage of sensitive credentials, reducing the attack surface while maintaining fast verification through efficient pattern matching

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If biometric data is used to generate signature keys, then security against duplication is improved, but the complexity of key generation increases

Engineering Contradiction:
Improvekey securityVSAvoidkey generation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables the biometric data itself to serve as the foundation for key generation. The unique physiological patterns automatically generate cryptographic credentials through mathematical transformations, eliminating the need for complex external key management infrastructure while ensuring each user possesses inherently secure, unique keys

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10396985B1Federated identity management based on biometric data
Publication Date: 2019.08.27 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US10396985B1 patent drawing
  • US10396985B1 patent drawing
  • US10396985B1 patent drawing

AI summary

Techniques are described for cryptographic key generation based on biometric data associated with a user. Biometric data, such as fingerprint(s) and/or heartbeat data, may be collected using one or more sensors in proximity to the user. The biometric data may be analyzed to generate a cryptographic key. In some implementations, the key may be employed by the user to access data, access certain (e.g., secure) feature(s) of an application, authenticate the user, digitally sign document(s), and/or for other purpose(s). In some implementations, the key may be re-generated for each access request or authentication instance, based on the user's fingerprint or other biometric data.