Biometric Encryption Key Generation for Secure User Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face inconvenience in managing multiple passwords for securing sensitive data across devices, and existing solutions do not effectively balance privacy protection with convenience in a cloud-based service environment.

Innovation Solution

Using biometric data, such as fingerprints, to generate an encryption key that decrypts user-specific data on devices, eliminating the need for password management by associating biometric metrics with clusters and cryptographic keys, allowing secure access to personalized data across devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a password is used to secure user data, then data security is improved, but user convenience deteriorates due to the need to remember multiple passwords

Engineering Contradiction:
Improvedata securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical/password-based authentication system with a biometric authentication system. Instead of requiring users to manually enter and remember passwords, the system uses fingerprint sensors to capture and verify biometric data, automatically generating encryption keys without user intervention. This substitution eliminates the burden of password management while maintaining strong security through cryptographic key generation from biometric metrics.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If biometric data is used to generate encryption keys, then user convenience is improved by eliminating password management, but system complexity increases due to biometric processing requirements

Engineering Contradiction:
Improveuser convenienceVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts only the essential biometric metric from the complete biometric data set. Instead of processing and storing entire fingerprint images or complex biometric patterns, the system extracts a condensed metric representation that can be used to generate encryption keys. This extraction reduces the processing and storage requirements while maintaining the security and convenience benefits of biometric authentication.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary processing of biometric data during enrollment, generating and storing encryption keys in advance based on captured biometric metrics. When authentication is needed, the system simply verifies the biometric metric against the pre-generated key rather than performing complex real-time key generation. This preliminary action reduces the computational complexity during actual authentication operations.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If biometric clustering is implemented to manage encryption keys, then key management efficiency is improved, but data processing complexity increases

Engineering Contradiction:
Improvekey management efficiencyVSAvoiddata processing complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the biometric data space into distinct clusters, each associated with a specific encryption key. During enrollment, biometric metrics are analyzed and assigned to appropriate clusters based on similarity metrics. This segmentation allows the system to efficiently manage multiple encryption keys by organizing them into discrete groups, reducing the complexity of key retrieval and management operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the parameter space from raw biometric data to clustered metric categories. By transforming continuous biometric measurements into discrete cluster assignments, the system simplifies key management while maintaining security. The clustering process groups similar biometric patterns together, allowing efficient key retrieval based on cluster identification rather than complex pattern matching.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3161708B1Managing user data for software services
Publication Date: 2020.10.21 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3161708B1 patent drawingFigure 1
  • EP3161708B1 patent drawingFigure 2
  • EP3161708B1 patent drawingFigure 3~5

AI summary

User-specific data for use with a software service may be stored in an encrypted form, where the encryption and/or decryption keys used are associated with a user's biometric data (that the user voluntarily provides after appropriate disclosure, to protect the user's interest in privacy). When the user uses the software service on a device, the device may receive the user-specific data in an encrypted form, and then may use the biometric data to retrieve or generate the cryptographic key that is used to decrypt the user-specific data. The user-specific data is then decrypted and used on the device with the software service.