Biometric Identity Verification via Electronic Private Key Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional access control systems face security and management challenges due to the vulnerability of IC cards and password-based systems, which can be lost, duplicated, or compromised, and fingerprint identification systems require dedicated devices that store user data, posing security risks.

Innovation Solution

An identity validity verification method and apparatus that uses biometric feature data to generate an electronic private key on an electronic terminal, which is then sent to an access control system for verification, eliminating the need for a dedicated fingerprint device and enhancing security by preventing data leakage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a dedicated fingerprint identification device is deployed at a fixed position, then fingerprint identification can be performed, but fingerprint information remains stored on the device creating security risks

Engineering Contradiction:
ImprovesecurityVSAvoiddedicated device deployment
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the biometric data processing function from a dedicated fingerprint device and relocates it to a mobile electronic terminal. The electronic terminal captures biometric data, generates cryptographic keys locally, and transmits only verification results to the access control system, eliminating the need for a dedicated fingerprint device at the access point while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an electronic terminal as an intermediary between the user and the access control system. This intermediary performs biometric data processing and cryptographic operations, preventing raw biometric information from being stored on the access control system or dedicated devices, thus reducing security risks while enabling convenient access verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If IC cards are used for access control, then zero-distance operation is enabled, but cards can be lost, duplicated, or compromised increasing management complexity and cost

Engineering Contradiction:
Improvezero-distance operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the fundamental parameter of identification from magnetic/card-based data storage to biometric-based cryptographic key generation. By using biometric features to generate electronic private keys, the system maintains zero-distance operation capability while eliminating the security vulnerabilities of IC cards, as biometric data cannot be lost, stolen, or duplicated in the traditional sense.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If passwords are used for access control, then zero-distance operation is enabled, but passwords can be easily subjected to leakage compromising security

Engineering Contradiction:
Improvezero-distance operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical/password-based authentication system with a biometric-cryptographic system. Instead of relying on user-memory-based passwords that can be leaked or guessed, the system uses biometric data to generate cryptographic private keys, providing both ease of operation (automatic biometric capture) and enhanced security (cryptographic protection).

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP3525181B1Identity validity verification method and electronic terminal
Publication Date: 2021.04.21 SHENZHEN GOODIX TECH CO LTD
  • EP3525181B1 patent drawingFigure 1~2
  • EP3525181B1 patent drawingFigure 3~5
  • EP3525181B1 patent drawingFigure 6

AI summary

Embodiments of the present application provide identity validity verification method, pertaining to the technical field of information security. The identity validity verification method is applied to an electronic terminal and includes: acquiring biometric feature data; generating an electronic private key based on the biometric feature data; and sending the electronic private key to the access control system, such that the access control system carries out identity validity verification based on the electronic private key. According to the present application, a dedicated fingerprint identification device does not need to be arranged at a specific position, and thus fingerprint data of a user does not remain on the fingerprint identification device. In this way, convenient is brought to the user and security is enhanced.