Biometric Identity Verification via Electronic Private Key Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional access control systems face security and management challenges due to the vulnerability of IC cards and password-based systems, which can be lost, duplicated, or compromised, and fingerprint identification systems require dedicated devices that store user data, posing security risks.
Innovation Solution
An identity validity verification method and apparatus that uses biometric feature data to generate an electronic private key on an electronic terminal, which is then sent to an access control system for verification, eliminating the need for a dedicated fingerprint device and enhancing security by preventing data leakage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a dedicated fingerprint identification device is deployed at a fixed position, then fingerprint identification can be performed, but fingerprint information remains stored on the device creating security risks
Solution Approach 1:
The patent extracts the biometric data processing function from a dedicated fingerprint device and relocates it to a mobile electronic terminal. The electronic terminal captures biometric data, generates cryptographic keys locally, and transmits only verification results to the access control system, eliminating the need for a dedicated fingerprint device at the access point while maintaining security.
Solution Approach 2:
The patent introduces an electronic terminal as an intermediary between the user and the access control system. This intermediary performs biometric data processing and cryptographic operations, preventing raw biometric information from being stored on the access control system or dedicated devices, thus reducing security risks while enabling convenient access verification.
2Ease of operation
If IC cards are used for access control, then zero-distance operation is enabled, but cards can be lost, duplicated, or compromised increasing management complexity and cost
Solution Approach 1:
The patent changes the fundamental parameter of identification from magnetic/card-based data storage to biometric-based cryptographic key generation. By using biometric features to generate electronic private keys, the system maintains zero-distance operation capability while eliminating the security vulnerabilities of IC cards, as biometric data cannot be lost, stolen, or duplicated in the traditional sense.
3Ease of operation
If passwords are used for access control, then zero-distance operation is enabled, but passwords can be easily subjected to leakage compromising security
Solution Approach 1:
The patent replaces the mechanical/password-based authentication system with a biometric-cryptographic system. Instead of relying on user-memory-based passwords that can be leaked or guessed, the system uses biometric data to generate cryptographic private keys, providing both ease of operation (automatic biometric capture) and enhanced security (cryptographic protection).
Data Source
Figure 1~2
Figure 3~5
Figure 6
AI summary
Embodiments of the present application provide identity validity verification method, pertaining to the technical field of information security. The identity validity verification method is applied to an electronic terminal and includes: acquiring biometric feature data; generating an electronic private key based on the biometric feature data; and sending the electronic private key to the access control system, such that the access control system carries out identity validity verification based on the electronic private key. According to the present application, a dedicated fingerprint identification device does not need to be arranged at a specific position, and thus fingerprint data of a user does not remain on the fingerprint identification device. In this way, convenient is brought to the user and security is enhanced.