Biometric Cryptographic Processing Unit Local Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional biometric systems face security and privacy risks due to the storage of biometric information in central databases, and existing personal device methods lack assurance that only authorized users can access and use the information, especially in remote network transactions.
Innovation Solution
A biometric/cryptographic processing unit (BCU) that integrates biometric and cryptographic functions within a personal information device, enabling secure biometric identification and authentication by generating unique asymmetric key pairs locally, with private keys remaining disabled until authorized user biometric authentication occurs, ensuring secure and confidential information exchange over a network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric information is stored in a central database, then identification can be performed, but security and privacy risks increase significantly if the database is compromised
Solution Approach 1:
The patent extracts biometric information from centralized storage and places it exclusively in personal devices. The biometric data never leaves the user's personal device, eliminating the central database vulnerability while maintaining identification capability through local storage and processing.
Solution Approach 2:
The system segments the biometric identification function into distributed personal devices rather than centralized storage. Each user's biometric information is segmented and stored in their own personal device, creating multiple independent security zones instead of a single vulnerable central database.
2Object-affected harmful factors
If personal device stores biometric information locally, then privacy is protected, but there is no ongoing assurance that only authorized users can access and use the information
Solution Approach 1:
The system performs preliminary biometric authentication before enabling access to stored information. The personal device requires successful biometric verification as a preliminary step before allowing any access to or use of the stored data, ensuring that only the authorized user can utilize the information.
Solution Approach 2:
The system implements continuous feedback through cryptographic verification. Each access attempt triggers cryptographic verification that provides feedback on whether the user is authorized, ensuring ongoing assurance rather than one-time authentication.
3Ease of operation
If cryptographic keys are released after biometric authentication, then information exchange can occur, but the private keys remain vulnerable to unauthorized use
Solution Approach 1:
The cryptographic keys transition from a static released state to a dynamic controlled state. The private keys are dynamically enabled or disabled based on continuous biometric verification, allowing the system to adapt key availability to current security requirements rather than maintaining constant access.
Solution Approach 2:
The system performs preliminary verification of user authorization before enabling cryptographic key usage. Each cryptographic operation requires preliminary biometric verification to confirm the user is still authorized, preventing unauthorized use even if keys are temporarily released.
Data Source
AI summary
A biometric and cryptographic processing unit includes a biometric receiver receiving biometric information of a BCU user. A biometric unit of the BCU has a store of biometric information of an authorized BCU user and compares received biometric information with the stored biometric information to determine if the user is an authorized BCU user. A cryptographic unit generates/stores an asymmetric cryptographic public/private key pair associated with each authorized BCU user. An input/output port allows encrypted/unencrypted data to be input to/output from the BCU. The cryptographic unit operates in response to a specific authorized user giving permission to undertake a specific cryptographic operation on data input to the BCU only upon the specific authorized user being determined as an authorized BCU user, whereby a specific private key corresponding to the specific authorized user is enabled for use in the specific cryptographic operation after which the specific private key is disabled.


