Biometric Identity Verification with Local Keys and Zero-Knowledge Proofs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In Card-Not-Present (CNP) transactions, the identity of the consumer cannot be verified, leading to increased liability for fraudulent transactions, and existing solutions compromise consumer privacy.

Innovation Solution

A biometric-based identity verification system using zero-knowledge proofs, where a biometric security device generates a private key from user data, which remains local, and a public key is used to verify membership in an identity verification program without disclosing personal information, allowing secure identity confirmation at the transaction terminal.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional payment verification methods are used in CNP transactions, then transaction processing is simple, but consumer identity cannot be verified and privacy is compromised

Engineering Contradiction:
Improveidentity verification reliabilityVSAvoidconsumer privacy loss
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The verification system segments identity information into two parts: a public key that can be shared for verification purposes, and private biometric data that remains localized and protected. This segmentation allows verification without exposing sensitive personal information, resolving the contradiction between verification reliability and privacy protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cryptographic keys as intermediaries between the consumer and the verification system. The public key acts as a mediator that enables identity verification without directly exposing private biometric data, allowing reliable verification while preserving consumer privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If biometric data is stored locally for security, then consumer privacy is protected, but identity verification becomes more complex

Engineering Contradiction:
Improveidentity verification reliabilityVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical biometric verification systems with a cryptographic-based system. Instead of directly transmitting or storing biometric templates, the system uses biometric data to generate cryptographic keys, substituting complex biometric matching mechanisms with simpler cryptographic verification operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If personal information is disclosed for verification, then identity can be confirmed, but consumer privacy is compromised

Engineering Contradiction:
Improveidentity verification reliabilityVSAvoidprivacy exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the necessary verification element (public key) from the complete set of personal information. This extraction allows identity verification to proceed without exposing other sensitive personal data, eliminating the harmful effect of privacy exposure while maintaining verification reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of the traditional approach where personal information is disclosed to prove identity, the patent inverts the process: identity is proven by demonstrating possession of the private key without disclosing the actual biometric data. This inversion eliminates privacy exposure risk while maintaining verification reliability.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS12361422B2Biometric-based identity verification using zero-knowledge proofs
Publication Date: 2025.07.15 AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC
  • US12361422B2 patent drawing
  • US12361422B2 patent drawing
  • US12361422B2 patent drawing

AI summary

Disclosed are various embodiments for verifying a consumer's identity during card-not-present (CNP) transactions using biometric data (e.g., fingerprint, retina scan, iris scan, handprint, voice sample, face scan, etc.) of the consumer obtained using a biometric security device. A zero-knowledge proof algorithm is used to verify the identity of a user initiating a transaction without disclosing personal information (e.g., biometric data) of the user to the issuer, merchant, recipient and/or other party, thereby preserving the privacy of the user.