Biometric Data Encryption With User-Held Keys for Private Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for storing biometric data face challenges in complying with privacy laws and regulations, as they often require direct access to the data, making it vulnerable to theft and coerced production, and users are hesitant to provide sensitive biometric data due to the risk of identity fraud and theft.

Innovation Solution

A system and method for encrypting biometric data using multiple encryption keys, where the user possesses one key, ensuring only the user can decrypt the data, and storing it in a manner that complies with privacy laws, using a biometric data management system with a blockchain architecture for secure storage and retrieval.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric data is stored in a database for verification purposes, then identity verification capability is improved, but privacy protection and security against coercion deteriorate because the system has direct access to the data

Engineering Contradiction:
Improveidentity verification capabilityVSAvoidprivacy violation risk and coercion vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the decryption key from the system and gives it exclusively to the user. The encrypted biometric data remains in the database, but without the user's private key, the system cannot access or coerce the data. This separates the storage function from the decryption capability, allowing verification while protecting privacy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces encrypted biometric data as an intermediary between the original biometric data and the database. Instead of storing raw biometric data, the system stores encrypted versions that cannot be accessed without the user's key. This intermediary form enables verification while preventing direct access and coercion.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If hashed biometric data is stored to protect privacy, then direct access control is improved, but the system still retains access to decrypted data somewhere in the verification system

Engineering Contradiction:
Improvedata access controlVSAvoidsecurity against coercion
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent extracts the decryption capability from the system entirely and places it solely in the user's possession. Unlike hashing where the system retains the ability to decrypt or access the original data, this approach removes all system access to decrypted biometric data, making coercion impossible.

Inventive Principle:
Principle #2Taking out (Extraction)

3Object-affected harmful factors

If multiple encryption keys are used with user possession of one key, then security and user control are improved, but system complexity increases

Engineering Contradiction:
Improvedata theft riskVSAvoidencryption key management
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent segments the encryption into two distinct parts: public encryption keys stored in the database and a private decryption key held by the user. This segmentation allows the system to store encrypted data without having the capability to decrypt it, thereby reducing security risks while maintaining manageable complexity through clear separation of duties.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20260005862A1Secure biometric data storage and retrieval system
Publication Date: 2026.01.01 VERAI SYSTEMS INC
  • US20260005862A1 patent drawing
  • US20260005862A1 patent drawing
  • US20260005862A1 patent drawing

AI summary

A computer system and method for storage and retrieval of encrypted biometric data which includes a biometric data intake device that selectively intakes original biometric data from a user and communicates with a biometric data management system. The biometric data management system has a resident data storage or a remote storage in communication therewith for the selective storage and retrieval of the encrypted biometric data. The system and method allow a user to originally encrypt biometric data such that the user solely possesses one of the necessary keys for later decryption of the stored and encrypted biometric data. The system and method will then doubly encrypt and store the user's biometric data in such a secure manner that the data can be stored on a public blockchain architecture, if desired. Full decryption of the original user biometric data for identity verification can only be performed with access to the user key.