Biometric Liveness Processing for Replay-Resistant Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional biometric systems are vulnerable to faked or replayed biometric signals, lacking effective liveness detection and privacy-enabled authentication methods.
Innovation Solution
Implementing a biometric authentication system that incorporates liveness detection through randomized biometric requests, using encrypted feature vectors and deep neural networks to validate biometric inputs, ensuring contemporaneous and authentic identity verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional biometric systems are used for identity validation, then authentication can be performed, but the system is vulnerable to faked or replayed biometric signals
Solution Approach 1:
The system performs liveness detection before completing authentication by analyzing whether the biometric signal is from a live source. This preliminary check prevents faked or replayed signals from proceeding to full authentication, thereby resolving the vulnerability to spoofing while maintaining authentication reliability.
Solution Approach 2:
The patent introduces an intermediary liveness detection mechanism that acts as a mediator between biometric signal capture and authentication validation. This intermediary layer analyzes characteristics of the biometric signal to determine if it originates from a live source, blocking fraudulent signals before they can compromise authentication reliability.
2Reliability
If active biometric collection with gesture-based authentication is implemented, then liveness detection is improved, but the gesture set itself becomes a vulnerability that can be tricked with pre-recorded gestures
Solution Approach 1:
The system dynamically adjusts the authentication process by introducing random challenges that require real-time biometric responses. This dynamic approach ensures that even if gesture patterns are known, the timing and context of each challenge-response pair cannot be pre-recorded, eliminating the vulnerability to replay attacks while maintaining liveness detection capability.
Solution Approach 2:
The patent changes the parameters of the authentication challenge by varying the timing, content, and type of biometric requests. This parameter variation ensures that each authentication attempt is unique and cannot be replicated from pre-recorded gestures, resolving the vulnerability while preserving the ability to detect live biometric sources.
3Measurement precision
If biometric data is processed for authentication, then identity verification is achieved, but privacy protection is compromised
Solution Approach 1:
The system extracts only the necessary authentication features from biometric data without retaining the full biometric information. By extracting and processing only the minimal required characteristics for verification, the system achieves accurate identity validation while minimizing privacy loss through selective data extraction and non-retention of sensitive biometric information.
Data Source
AI summary
In one embodiment, a set of feature vectors can be derived from any biometric data, and then using a deep neural network (“DNN”) on those one-way homomorphic encryptions (i.e., each biometrics' feature vector) an authentication system can determine matches or execute searches on encrypted data. Each biometrics' feature vector can then be stored and/or used in conjunction with respective classifications, for use in subsequent comparisons without fear of compromising the original biometric data. In various embodiments, the original biometric data is discarded responsive to generating the encrypted values. In another embodiment, the homomorphic encryption enables computations and comparisons on cypher text without decryption of the encrypted feature vectors. Security of such privacy enable biometrics can be increased by implementing an assurance factor (e.g., liveness) to establish a submitted biometric has not been spoofed or faked.


