Biometric Enrollment System Using Encrypted Template Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current biometric authentication systems face challenges in providing secure and portable authentication solutions, particularly in protecting biometric data from unauthorized access and overcoming the limitations of existing cryptographic protocols like TLS.
Innovation Solution
The Biometric Authentication Biometric Enrollment (BABE) processing system addresses these challenges by using a biometric authentication protocol that generates and manages Enrollment Confirmation Messages (ECMs) containing unique biometric reference template identifiers and Uniform Resource Identifiers (URIs) of Biometric Service Providers (BSPs), enabling secure and portable biometric authentication across different platforms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional cryptographic protocols like TLS are used for biometric authentication, then security can be provided, but processing power is consumed and digital certificates/PKI are required
Solution Approach 1:
The patent extracts and removes the dependency on digital certificates and Public Key Infrastructure (PKI) from the authentication system. By using biometric-based cryptographic key generation instead of traditional certificate-based authentication, the system eliminates the need for complex certificate management and reduces processing overhead associated with PKI operations.
Solution Approach 2:
The patent replaces the mechanical/cryptographic system of digital certificates and PKI with a biometric-based cryptographic system. Instead of relying on certificate chains and key pairs, the system uses biometric templates to generate cryptographic keys, substituting the traditional cryptographic infrastructure with a more efficient biometric-driven approach.
2Ease of operation
If biometric data is stored and processed, then authentication can be performed, but biometric data may be vulnerable to unauthorized access and attacks
Solution Approach 1:
The patent segments the biometric authentication process into distinct components: biometric template generation, cryptographic key derivation, and authentication verification. The biometric template is processed to generate cryptographic keys without storing raw biometric data, and the authentication process uses these derived keys rather than directly accessing biometric data, creating security layers that protect against unauthorized access.
Solution Approach 2:
The patent introduces cryptographic keys as an intermediary between biometric data and authentication decisions. Instead of directly using biometric templates for authentication, the system derives cryptographic keys from biometric data, and these keys serve as the actual authentication credentials. This intermediary layer protects biometric data from direct exposure while enabling secure authentication.
3Reliability
If encryption is applied to biometric enrollment data, then data security is improved, but additional processing steps are required
Solution Approach 1:
The patent merges the encryption process with the biometric template generation process. Instead of separately encrypting biometric data and then processing it, the system directly generates cryptographic keys from biometric templates through a combined process. This integration reduces the number of separate processing steps while maintaining strong security through cryptographic key derivation.
Data Source
AI summary
An example method includes receiving an encrypted biometric enrollment data and user identifier data. The encrypted biometric enrollment data includes at least one biometric enrollment sample from a user encrypted using an encryption key. The encryption key is generated based on a user secret and the user identifier is associated with the user. The user identifier is matched with a stored user secret. A decryption key is generated based on the stored user secret. The encrypted biometric enrollment data is decrypted using the decryption key. The at least one biometric enrollment sample is retrieved from the decrypted biometric enrollment data. The at least one biometric enrollment sample is processed using a biometric processing algorithm to generate a biometric reference template. A biometric reference template identifier uniquely identifying the biometric reference template is generated. An encryption key is generated based on the stored user secret and encrypts an enrollment confirmation message.


