Biometric Identification System with Pre-Transmission Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Fingerprint-based identification systems are limited in untrusted environments due to the risk of tampering and data compromise, as they rely on trusted scanners and are vulnerable to impersonation attacks, making them unsuitable for deployment in uncontrolled settings.

Innovation Solution

A method and system for biometric identification that encrypts user biometric properties before encoding, provides them as a challenge, decrypts for verification, and includes a protecting terminal with metadata for enhanced security, allowing secure operation even with untrusted scanners and preventing impersonation attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If fingerprint scanners are deployed in uncontrolled environments, then accessibility and convenience are improved, but security and reliability deteriorate due to tampering risks and data compromise

Engineering Contradiction:
ImproveAccessibilityVSAvoidSecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system divides the biometric identification process into separate functional components: a protecting terminal that encrypts biometric data before transmission, and a checking entity that verifies the encrypted data. This segmentation ensures that even if one component is compromised, the other remains secure, allowing deployment in untrusted environments while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The protecting terminal performs encryption of biometric properties before they are transmitted to the checking entity. This preliminary security action ensures that sensitive data is protected during transmission and storage, enabling the system to operate securely in uncontrolled environments without requiring modifications to existing scanners.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If biometric data is transmitted and stored in untrusted environments, then identification functionality is improved, but vulnerability to impersonation attacks and data theft increases

Engineering Contradiction:
ImproveIdentification functionalityVSAvoidVulnerability to attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system transforms biometric properties from their original form into encrypted representations using cryptographic parameters. The protecting terminal encrypts biometric data with cryptographic keys, and the checking entity verifies the encrypted data without accessing the original biometric information. This parameter transformation maintains identification functionality while preventing impersonation attacks and data theft.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If encryption and additional security protocols are implemented, then security and privacy are improved, but system complexity increases

Engineering Contradiction:
ImproveSecurityVSAvoidSystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The protecting terminal acts as an intermediary component that handles encryption and decryption operations. By introducing this dedicated intermediary device, the system achieves enhanced security without requiring complex modifications to existing fingerprint scanners or database systems. The intermediary manages all cryptographic operations, keeping the overall system architecture simple and modular.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9613250B2Method and system for biometrical identification of a user
Publication Date: 2017.04.04 NEC CORP
  • US9613250B2 patent drawing
  • US9613250B2 patent drawing
  • US9613250B2 patent drawing

AI summary

A method for biometrical identification of a user includes receiving, as an input, biometrical properties of a user, and encoding the biometrical properties. The encoded biometrical properties are checked with corresponding provided biometrical user information, Based on a result of the check, the user is identified and a response of the identification is outputted. Prior to encoding, the biometrical properties are encrypted, The encoded biometrical properties are provided as a biometrical challenge. The biometrical challenge is decrypted for performing the check. A verification of the response is provided for.