Biometric Authentication via Fuzzy Vault and Non-Invertible Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed computer systems, biometric data authentication over secure communication channels is vulnerable due to the need for original biometric data to be stored and distributed, making it susceptible to compromise, and simple encryption does not adequately address this issue.

Innovation Solution

A method using a fuzzy vault scheme where biometric data is transformed into non-invertible data, combined with client-generated secret keys and random numbers, allowing secure authentication without storing clear biometric data outside the user's trusted device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If original biometric data is stored and distributed at central nodes in distributed systems, then authentication functionality is enabled, but security is compromised due to vulnerability to data compromise

Engineering Contradiction:
Improveauthentication functionalityVSAvoidbiometric data compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the biometric data from the authentication process by using it only to lock the fuzzy vault during enrollment. The actual authentication relies on the secret key contained in the fuzzy vault, not the biometric data itself. This removes the harmful aspect of distributing biometric data while preserving authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The fuzzy vault acts as an intermediary mechanism that mediates between the biometric data and the secret key. The biometric data locks the vault which contains the secret key, but the biometric data itself is never distributed. This intermediary structure enables authentication while protecting the biometric data from compromise.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If biometric data is transformed into non-invertible data, then security is improved by preventing original data exposure, but authentication capability must be maintained through alternative mechanisms

Engineering Contradiction:
Improvebiometric data exposureVSAvoidauthentication capability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent performs preliminary action by enrolling the user's biometric data in advance to lock the fuzzy vault and generate the secret key. This preliminary enrollment phase stores the locked vault locally, enabling future authentication without needing to transmit or store the original biometric data, thus maintaining authentication capability while ensuring security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3586257B1Biometrics-based remote login
Publication Date: 2022.10.26 FINGERPRINT CARDS ANACATUM IP AB
  • EP3586257B1 patent drawingFigure 1~2
  • EP3586257B1 patent drawingFigure 3
  • EP3586257B1 patent drawingFigure 4

AI summary

The invention relates to methods and devices for enabling authentication of a user based on biometric data. In an aspect of the invention, a method performed by a client device (100) of enabling authentication of user (200) of the client device (100) with a network node over a secure communication channel based on biometric data is provided. Further, an enrollment set is provided by the client device, which is used for the authentication, where said enrollment set comprises a fuzzy vault, which contains registered biometric data and a first secret key. The enrollment set also comprises transformed non-invertible biometric data, a second secret key and a secret random number.