Biometric Template Security via Hardware Binding and Public Key Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Biometric systems face vulnerabilities in large-scale deployment, leading to insider abuse and outside attacks, as encryption keys are not under individual control, and there is no means to prevent biometric information from being used across different applications without consent, making it difficult for law enforcement to trace illegal use.

Innovation Solution

Irreversibly linking unique hardware component-specific data features to biometric information and application identifiers, ensuring that biometric data can only be used with the correct hardware and application, and generating a signature that binds the application identifier to hardware components, allowing traceability of biometric information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric templates are stored in encrypted form with encryption keys controlled by the system owner, then biometric information is protected from external attacks, but the system becomes vulnerable to insider abuse and the system owner gains unauthorized access to personal biometric information

Engineering Contradiction:
Improveprotection from external attacksVSAvoidinsider abuse and unauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the encryption key control from the system owner and transfers it to the individual through public key infrastructure. The individual's public key is used to encrypt biometric templates, removing the system owner's ability to access encrypted biometric data while maintaining protection from external attacks.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces public key cryptography as an intermediary mechanism between the individual and the biometric system. The public key acts as a mediator that allows secure storage without requiring the system owner to possess decryption capabilities, thus preventing insider abuse while maintaining external security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If biometric systems allow flexible use of biometric information across multiple applications, then adaptability and convenience are improved, but the ability to prevent unauthorized use and trace illegal applications is reduced

Engineering Contradiction:
Improveuse across different applicationsVSAvoidtraceability and control of usage
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements feedback mechanisms through audit logs that record which applications access biometric information. This allows the system to monitor and trace usage patterns while still permitting flexible multi-application use, enabling law enforcement to identify illegal applications through the accumulated feedback data.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary binding of application identifiers to biometric templates during the enrolment process. This preliminary action establishes traceability from the outset, allowing the system to track which applications are authorized to use biometric information before any actual usage occurs.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If traditional encryption methods are used to protect biometric templates, then storage security is improved, but the encryption and decryption keys being controlled by the system owner creates access vulnerabilities

Engineering Contradiction:
Improvestorage securityVSAvoidindividual control over personal data
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables self-service by allowing individuals to generate their own key pairs and use their public keys to encrypt their biometric templates. This eliminates the need for system owners to control decryption keys, giving individuals direct control over their personal biometric data while maintaining strong storage security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2513834B1System and method for verifying the identity of an individual by employing biometric data features associated with the individual as well as a computer program product for performing said method
Publication Date: 2018.09.19 GENKEY NETHERLANDS
  • EP2513834B1 patent drawing
  • EP2513834B1 patent drawing
  • EP2513834B1 patent drawing

AI summary

The invention relates to a system for verifying the identity of an individual by employing biometric data features associated with the individual, which system comprises at least one or more hardware components, an enrolment means, and a verifying means, wherein said enrolment means are arranged in deriving a first biometric template data, said first biometric template data being secret and associated with a first set of first biometric data features of said individual, and in receiving a further set of first biometric data features of said individual, and in deriving a further biometric template data associated with said further set of first biometric data, and wherein said verifying means are arranged in comparing the first biometric template data with the further biometric template data to check for correspondence, wherein the identity of the individual is verified if correspondence exists. The invention aims to provide a solution to the above identified drawbacks and thereto at least one of said hardware components is provided with at least one component specific data feature associated therewith and wherein said enrolment means are arranged in associating at least one of said component specific data features with said biometric template data.