Biometric Template Security via Hardware Binding and Public Key Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Biometric systems face vulnerabilities in large-scale deployment, leading to insider abuse and outside attacks, as encryption keys are not under individual control, and there is no means to prevent biometric information from being used across different applications without consent, making it difficult for law enforcement to trace illegal use.
Innovation Solution
Irreversibly linking unique hardware component-specific data features to biometric information and application identifiers, ensuring that biometric data can only be used with the correct hardware and application, and generating a signature that binds the application identifier to hardware components, allowing traceability of biometric information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric templates are stored in encrypted form with encryption keys controlled by the system owner, then biometric information is protected from external attacks, but the system becomes vulnerable to insider abuse and the system owner gains unauthorized access to personal biometric information
Solution Approach 1:
The patent extracts the encryption key control from the system owner and transfers it to the individual through public key infrastructure. The individual's public key is used to encrypt biometric templates, removing the system owner's ability to access encrypted biometric data while maintaining protection from external attacks.
Solution Approach 2:
The patent introduces public key cryptography as an intermediary mechanism between the individual and the biometric system. The public key acts as a mediator that allows secure storage without requiring the system owner to possess decryption capabilities, thus preventing insider abuse while maintaining external security.
2Adaptability or versatility
If biometric systems allow flexible use of biometric information across multiple applications, then adaptability and convenience are improved, but the ability to prevent unauthorized use and trace illegal applications is reduced
Solution Approach 1:
The patent implements feedback mechanisms through audit logs that record which applications access biometric information. This allows the system to monitor and trace usage patterns while still permitting flexible multi-application use, enabling law enforcement to identify illegal applications through the accumulated feedback data.
Solution Approach 2:
The patent performs preliminary binding of application identifiers to biometric templates during the enrolment process. This preliminary action establishes traceability from the outset, allowing the system to track which applications are authorized to use biometric information before any actual usage occurs.
3Reliability
If traditional encryption methods are used to protect biometric templates, then storage security is improved, but the encryption and decryption keys being controlled by the system owner creates access vulnerabilities
Solution Approach 1:
The patent enables self-service by allowing individuals to generate their own key pairs and use their public keys to encrypt their biometric templates. This eliminates the need for system owners to control decryption keys, giving individuals direct control over their personal biometric data while maintaining strong storage security.
Data Source
AI summary
The invention relates to a system for verifying the identity of an individual by employing biometric data features associated with the individual, which system comprises at least one or more hardware components, an enrolment means, and a verifying means, wherein said enrolment means are arranged in deriving a first biometric template data, said first biometric template data being secret and associated with a first set of first biometric data features of said individual, and in receiving a further set of first biometric data features of said individual, and in deriving a further biometric template data associated with said further set of first biometric data, and wherein said verifying means are arranged in comparing the first biometric template data with the further biometric template data to check for correspondence, wherein the identity of the individual is verified if correspondence exists. The invention aims to provide a solution to the above identified drawbacks and thereto at least one of said hardware components is provided with at least one component specific data feature associated therewith and wherein said enrolment means are arranged in associating at least one of said component specific data features with said biometric template data.


