Biometric Credential Hashing for Offline Privacy-Preserving Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic authentication methods are vulnerable to attacks that capture network traffic, exposing sensitive biometric data and risking catastrophic breaches due to the transmission of credentials across networks, and lack offline authentication capabilities.
Innovation Solution
A privacy-enhanced, biometrics-based authentication system that generates a cryptographically-trusted credential with a QR code containing a hashed biometric signature, allowing local verification without network transmission, using a private certificate for secure authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric data is transmitted across a network for authentication, then authentication functionality is enabled, but vulnerability to network attacks and data breaches increases
Solution Approach 1:
The patent extracts the biometric verification process from the network environment and performs it locally on the user's device. The biometric data never leaves the device - instead, the authentication model is downloaded and executed locally to verify biometric features, eliminating network transmission vulnerabilities while maintaining authentication functionality.
Solution Approach 2:
The patent introduces an authentication model as an intermediary between the biometric data and the verification process. This model acts as a local verifier that processes biometric features without requiring direct network communication, thereby mediating the authentication process in a way that preserves security while enabling remote authentication capabilities.
2Ease of operation
If biometric credentials are stored and transmitted electronically, then authentication capability is provided, but risk of unauthorized access and identity fraud increases
Solution Approach 1:
The patent performs preliminary actions by downloading and storing the authentication model locally on the user's device before authentication is needed. This pre-positioning of verification capabilities allows immediate local biometric verification without requiring real-time network connection or transmission of sensitive credentials, thereby enabling ease of operation while reducing fraud risk.
Solution Approach 2:
The system enables self-service authentication by empowering the user's device to independently verify biometric data locally without external assistance. The device uses its own stored authentication model to perform verification, eliminating the need to transmit credentials to external servers and thereby reducing vulnerability to unauthorized access and identity fraud.
3Reliability
If network transmission of authentication data is used, then centralized verification is achieved, but offline authentication capability is lost
Solution Approach 1:
The patent segments the authentication system into two parts: the authentication model (verification logic) and the biometric data (input). By separating these and placing the model locally on the user's device while keeping biometric data local as well, the system enables offline verification while maintaining the integrity and reliability originally provided by centralized verification architectures.
Solution Approach 2:
The patent transitions the authentication paradigm from a single-dimension network-dependent model to a two-dimension hybrid model that operates both online (for model updates) and offline (for verification). This dimensional change allows the system to maintain centralized verification reliability when connected while gaining offline authentication capability when disconnected, thereby resolving the contradiction between centralized control and offline adaptability.
Data Source
AI summary
According to one embodiment, a method, computer system, and computer program product for privacy-enhanced, biometrics-based authentication is provided. The embodiment may include capturing credential information on a credential medium and biometric information for a user, each provided by the user, by one or more information capture devices. The embodiment may also include identifying a hash stored on the credential medium based on the captured credential information. The embodiment may further include calculating, locally, a hash of the biometric information using a preconfigured hashing algorithm. The embodiment may also include, in response to the identified hash matching the calculated hash, authenticating the user.


