Biometric Credential Hashing for Offline Privacy-Preserving Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic authentication methods are vulnerable to attacks that capture network traffic, exposing sensitive biometric data and risking catastrophic breaches due to the transmission of credentials across networks, and lack offline authentication capabilities.

Innovation Solution

A privacy-enhanced, biometrics-based authentication system that generates a cryptographically-trusted credential with a QR code containing a hashed biometric signature, allowing local verification without network transmission, using a private certificate for secure authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric data is transmitted across a network for authentication, then authentication functionality is enabled, but vulnerability to network attacks and data breaches increases

Engineering Contradiction:
Improveauthentication securityVSAvoidnetwork attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the biometric verification process from the network environment and performs it locally on the user's device. The biometric data never leaves the device - instead, the authentication model is downloaded and executed locally to verify biometric features, eliminating network transmission vulnerabilities while maintaining authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an authentication model as an intermediary between the biometric data and the verification process. This model acts as a local verifier that processes biometric features without requiring direct network communication, thereby mediating the authentication process in a way that preserves security while enabling remote authentication capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If biometric credentials are stored and transmitted electronically, then authentication capability is provided, but risk of unauthorized access and identity fraud increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoididentity fraud risk
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent performs preliminary actions by downloading and storing the authentication model locally on the user's device before authentication is needed. This pre-positioning of verification capabilities allows immediate local biometric verification without requiring real-time network connection or transmission of sensitive credentials, thereby enabling ease of operation while reducing fraud risk.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service authentication by empowering the user's device to independently verify biometric data locally without external assistance. The device uses its own stored authentication model to perform verification, eliminating the need to transmit credentials to external servers and thereby reducing vulnerability to unauthorized access and identity fraud.

Inventive Principle:
Principle #25Self-service

3Reliability

If network transmission of authentication data is used, then centralized verification is achieved, but offline authentication capability is lost

Engineering Contradiction:
Improvecentralized verificationVSAvoidoffline authentication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the authentication system into two parts: the authentication model (verification logic) and the biometric data (input). By separating these and placing the model locally on the user's device while keeping biometric data local as well, the system enables offline verification while maintaining the integrity and reliability originally provided by centralized verification architectures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions the authentication paradigm from a single-dimension network-dependent model to a two-dimension hybrid model that operates both online (for model updates) and offline (for verification). This dimensional change allows the system to maintain centralized verification reliability when connected while gaining offline authentication capability when disconnected, thereby resolving the contradiction between centralized control and offline adaptability.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS12567945B2Enhancing privacy in biometrics-based authentication systems
Publication Date: 2026.03.03 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12567945B2 patent drawing
  • US12567945B2 patent drawing
  • US12567945B2 patent drawing

AI summary

According to one embodiment, a method, computer system, and computer program product for privacy-enhanced, biometrics-based authentication is provided. The embodiment may include capturing credential information on a credential medium and biometric information for a user, each provided by the user, by one or more information capture devices. The embodiment may also include identifying a hash stored on the credential medium based on the captured credential information. The embodiment may further include calculating, locally, a hash of the biometric information using a preconfigured hashing algorithm. The embodiment may also include, in response to the identified hash matching the calculated hash, authenticating the user.