Biometric Private Key Recovery Using Error-Correcting Encoding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The risk of private key leakage during backup is high when private keys are directly stored.
Innovation Solution
A private key recovery device and method that utilize a parameter generated by combining first biometric information and an encoded key, where the encoded key is obtained using an encoding scheme with error correction capability, to recover the private key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the private key is directly stored for backup, then the ease of operation is improved, but the security against private key leakage deteriorates
Solution Approach 1:
The private key is segmented into multiple shares using secret sharing schemes, where each share alone is insufficient to reconstruct the private key. This segmentation reduces the risk of leakage while maintaining backup functionality, as multiple authorized components are required for recovery.
Solution Approach 2:
An intermediary recovery system is introduced that acts as a mediator between the stored backup data and the private key reconstruction. The system uses biometric authentication and multi-factor verification as intermediaries to control access, ensuring that even if backup data is compromised, the private key cannot be recovered without proper authorization.
2Object-affected harmful factors
If the private key is encrypted and stored, then the security is improved, but the device complexity increases
Solution Approach 1:
The system changes parameters such as using different encryption algorithms, key lengths, and error correction codes based on security requirements. By adjusting these parameters, the system achieves adequate protection without unnecessarily increasing complexity, allowing flexible optimization between security and simplicity.
Solution Approach 2:
The backup system uses composite cryptographic approaches combining multiple encryption methods, error correction codes, and authentication mechanisms. This composite structure provides robust security while distributing complexity across standardized components, making the overall system manageable despite its sophisticated nature.
3Reliability
If biometric information is used for authentication, then the reliability of private key recovery is improved, but the measurement precision requirements increase
Solution Approach 1:
The system applies error correction codes and tolerance thresholds in advance to accommodate natural variations in biometric data. This cushioning approach ensures that minor differences in biometric measurements do not prevent successful authentication, maintaining reliability while reducing the stringency of precision requirements.
Solution Approach 2:
The system adjusts biometric matching parameters such as similarity thresholds and comparison algorithms based on the specific biometric modality and security requirements. By optimizing these parameters, the system achieves reliable authentication without demanding excessively high measurement precision that would be impractical to implement.
Data Source
AI summary
A private key recovery device uses a parameter, being data obtained by taking a sum of first biometric information and an encoded key obtained by encoding a private key using an encoding scheme having an error correction capability, and second biometric information, to generate data in which data based on the encoded key and a difference obtained by subtracting the second biometric information from the first biometric information is decoded using the encoding scheme.


