Biometric Key Generation for Secure Data Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data management systems face challenges in securely managing biometric data without relying on portable devices for private key management, leading to concerns about privacy invasion and fraudulent use of lost or stolen usage permits.

Innovation Solution

A data management system comprising three computers that encrypt and decrypt data using public and private keys generated from biometric information, eliminating the need for portable devices in private key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If biometric information is stored in existing data management systems, then authentication functionality is improved, but privacy security and risk of unauthorized use deteriorate

Engineering Contradiction:
Improveauthentication functionalityVSAvoidprivacy security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the private key management function from portable devices and relocates it to a server system. The biometric information is stored and processed on the server rather than on user devices, removing the security vulnerability of storing sensitive data on potentially lost or stolen portable devices while maintaining authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a server as an intermediary between the user and the authentication system. The server acts as a trusted mediator that securely stores biometric information and manages key pairs, eliminating the need for users to directly handle or store sensitive cryptographic materials on their own devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If usage permits are issued to individuals on portable devices, then user control and convenience are improved, but vulnerability to loss and theft increases

Engineering Contradiction:
Improveuser controlVSAvoidloss and theft risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the critical authentication data (private keys and biometric information) from portable devices and stores them centrally on a server. This removes the harmful factor of data exposure from lost or stolen devices while maintaining user control through secure remote access and management capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent merges the functions of key management, biometric storage, and authentication control into a single centralized server system. This consolidation eliminates the need for distributed key management across multiple portable devices, reducing the attack surface and vulnerability to physical loss or theft.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12321470B2Data management system, data management method, and non-transitory computer readable medium
Publication Date: 2025.06.03 HITACHI LTD
  • US12321470B2 patent drawing
  • US12321470B2 patent drawing
  • US12321470B2 patent drawing

AI summary

A first computer, in data registration processing: determines a type of biometric information for encryption with which the data is to be encrypted; acquires the determined type of biometric information for encryption from a user of the first computer; generates, from each piece of the acquired biometric information for encryption, a public key based on a predetermined algorithm; transmits the public key to a second computer; and transmits the data encrypted with the public key to the third computer, the first computer, in data presentation processing: acquires the encrypted data from a third computer; acquires the determined type of biometric information for decryption from the user of the first computer; generates, from each piece of the acquired biometric information for decryption, a private key based on the predetermined algorithm; decrypts the encrypted data with use of the private key; and presents each piece of the decrypted registered data.