Biometric Feature Descriptor Authentication via Local Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing user authentication methods are prone to errors due to changes in user appearance over time and require significant processing power, and may involve carrying identification documents, with concerns about data privacy and vulnerability to replay attacks.

Innovation Solution

A method using a digital camera on a mobile user terminal to capture biometric data, generate a biometric feature descriptor, and transmit it to an inspection server for authentication, along with a document identifier and user profile, ensuring secure and privacy-compliant authentication without storing human-recognizable visual representations, and incorporating a one-time stamp to prevent replay attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric data is captured and stored in a centralized server for authentication, then authentication reliability is improved, but data privacy and security risks increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiddata privacy risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the essential biometric feature descriptor from the complete biometric data, storing only this compressed representation on the server while keeping the original biometric data local to the user device. This extraction approach maintains authentication reliability through centralized verification while minimizing privacy risks by reducing the amount of sensitive data stored centrally.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication system is segmented into two parts: local processing on the user device that generates the biometric feature descriptor, and centralized verification on the server that stores and compares only these descriptors. This segmentation allows the system to benefit from both local data protection and centralized authentication reliability.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If complete biometric data is transmitted to the inspection server for authentication, then authentication accuracy is improved, but data transmission volume and processing time increase

Engineering Contradiction:
Improveauthentication accuracyVSAvoiddata transmission time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system extracts only the essential biometric feature descriptor from the complete biometric data before transmission. This descriptor contains sufficient information for accurate authentication while being significantly smaller in size, thereby reducing transmission time and processing overhead while maintaining authentication accuracy.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If identification documents are carried and read using RFID or NFC technology, then authentication convenience is improved, but security vulnerabilities and replay attack risks increase

Engineering Contradiction:
Improveauthentication convenienceVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary processing of biometric data locally on the user device to generate a unique feature descriptor before transmission. This preliminary action ensures that even if communication channels are compromised, the transmitted data cannot be easily replayed or forged, as each authentication attempt requires fresh local processing of the user's biometric features.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The biometric feature descriptor acts as an intermediary representation between the user's biometric data and the authentication decision. This intermediary form preserves the convenience of contactless authentication while enhancing security, as the descriptor cannot be directly reversed to obtain the original biometric data and cannot be easily replayed without detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If user profile information is shared with inspection terminals, then authentication functionality is improved, but data privacy protection deteriorates

Engineering Contradiction:
Improveauthentication functionalityVSAvoidprivacy exposure
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system applies local quality by allowing different levels of personalization data to be shared with different inspection terminals based on specific authentication requirements. Users can control which attributes of their profile are disclosed to each terminal, enabling tailored information sharing that matches the specific needs of each authentication context while minimizing overall privacy exposure.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11675884B2Authentication of a person using a virtual identity card
Publication Date: 2023.06.13 IDEMIA THE NETHERLANDS BV
  • US11675884B2 patent drawing
  • US11675884B2 patent drawing
  • US11675884B2 patent drawing

AI summary

A method and system for authenticating a user based on a human-recognizable visual representation of biometric data of the user is captured using the digital camera, wherein a biometric feature descriptor is generated from the captured biometric data of the user, and the feature descriptor, together with a user selected user profile, is transmitted to an inspection server adapted for validating whether the transmitted biometric feature descriptor corresponds to a centrally stored biometric feature descriptor of biometric data of the user. If this is the case, the inspection server transmits an “authentication approved” signal together with user personalization data specified in the selected user profile to the inspection terminal.