Non-invertible Biometric Data Transformation for Secure Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed computer systems, biometric data is vulnerable to compromise as original data must be stored and transmitted in clear text, posing a security risk across all systems where it is used, and encryption alone does not suffice to address this issue.

Innovation Solution

A method and device that transform biometric data into non-invertible data using a feature transform scheme, which is then securely enrolled and stored with a trusted network node, allowing authentication over a secure communication channel without exposing clear-text biometric data outside the client device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If original biometric data is stored and transmitted in clear text for authentication purposes, then authentication functionality is enabled across distributed systems, but security is compromised as biometric data becomes vulnerable to compromise across all systems

Engineering Contradiction:
Improveauthentication functionalityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent transforms biometric data using a non-invertible transformation function that changes the parameter state of the data from original to transformed form. This transformation is applied consistently across different systems, enabling authentication functionality while maintaining security because the transformed data cannot be reversed to obtain original biometric information.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent creates a transformed copy of the biometric data that preserves authentication capability but eliminates security vulnerabilities. Instead of storing and transmitting original biometric data, the system stores and transmits transformed biometric data that serves as a secure copy for authentication purposes across distributed systems.

Inventive Principle:
Principle #26Copying

2Object-affected harmful factors

If biometric data is transformed into non-invertible data for security purposes, then security is enhanced by preventing data exposure, but authentication capability must be maintained through the transformation process

Engineering Contradiction:
Improvedata exposure preventionVSAvoidauthentication capability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The transformation function changes the parameters of biometric data in a way that prevents inversion while preserving authentication capability. The transformed data maintains the essential characteristics needed for authentication comparison without allowing recovery of original biometric information.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent converts the potential harm of storing biometric data (security risk) into a benefit (enhanced security) by applying non-invertible transformation. The transformation process turns vulnerable original data into secure transformed data that cannot be compromised to reveal original biometric information.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentEP3622429B1Methods and devices of enabling authentication of a user of a client device over a secure communication channel based on biometric data
Publication Date: 2022.10.12 FINGERPRINT CARDS ANACATUM IP AB
  • EP3622429B1 patent drawingFigure 1~2
  • EP3622429B1 patent drawingFigure 3
  • EP3622429B1 patent drawingFigure 4

AI summary

In an aspect of the invention, a network node (300) configured to enable authentication of a user (200) of a client device (100, 500) based on biometric data captured by the client device (100, 500) is provided, which network node (300) receives a request to authenticate a user of a client device (500), the authentication request comprising a user identifier, fetch at least one set of enrolled transformed biometric data corresponding to the user identifierand a secret feature transform key with which the biometric data was transformed at enrolment of the transformed biometric data at the network node (300), and submit the transformed biometric data and the secret feature transform key over a secure communication channel to the client device (500).