Biometric Identity Verification with Local Keys and Zero-Knowledge Proofs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In Card-Not-Present (CNP) transactions, the identity of the consumer cannot be verified, leading to increased liability for fraudulent transactions, and existing solutions compromise consumer privacy.
Innovation Solution
A biometric-based identity verification system using zero-knowledge proofs, where a biometric security device generates a private key from user data, which remains local, and a public key is used to verify membership in an identity verification program without disclosing personal information, allowing secure identity confirmation at the transaction terminal.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional payment verification methods are used in CNP transactions, then transaction processing is simple, but consumer identity cannot be verified and privacy is compromised
Solution Approach 1:
The verification system segments identity information into two parts: a public key that can be shared for verification purposes, and private biometric data that remains localized and protected. This segmentation allows verification without exposing sensitive personal information, resolving the contradiction between verification reliability and privacy protection.
Solution Approach 2:
The patent introduces cryptographic keys as intermediaries between the consumer and the verification system. The public key acts as a mediator that enables identity verification without directly exposing private biometric data, allowing reliable verification while preserving consumer privacy.
2Reliability
If biometric data is stored locally for security, then consumer privacy is protected, but identity verification becomes more complex
Solution Approach 1:
The patent replaces traditional mechanical biometric verification systems with a cryptographic-based system. Instead of directly transmitting or storing biometric templates, the system uses biometric data to generate cryptographic keys, substituting complex biometric matching mechanisms with simpler cryptographic verification operations.
3Reliability
If personal information is disclosed for verification, then identity can be confirmed, but consumer privacy is compromised
Solution Approach 1:
The patent extracts only the necessary verification element (public key) from the complete set of personal information. This extraction allows identity verification to proceed without exposing other sensitive personal data, eliminating the harmful effect of privacy exposure while maintaining verification reliability.
Solution Approach 2:
Instead of the traditional approach where personal information is disclosed to prove identity, the patent inverts the process: identity is proven by demonstrating possession of the private key without disclosing the actual biometric data. This inversion eliminates privacy exposure risk while maintaining verification reliability.
Data Source
AI summary
Disclosed are various embodiments for verifying a consumer's identity during card-not-present (CNP) transactions using biometric data (e.g., fingerprint, retina scan, iris scan, handprint, voice sample, face scan, etc.) of the consumer obtained using a biometric security device. A zero-knowledge proof algorithm is used to verify the identity of a user initiating a transaction without disclosing personal information (e.g., biometric data) of the user to the issuer, merchant, recipient and/or other party, thereby preserving the privacy of the user.


