Biometric Binding Scheme Using Modulo-N Addition for Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing biometric binding schemes face challenges in providing secure and private identity authentication, particularly in untrusted computing environments, due to reversibility issues, insufficient security, and performance degradation, as well as the risk of biometric data leakage and privacy concerns.

Innovation Solution

A novel data binding scheme that securely binds biometric data with a personal secret using a modulo-N addition operation, generating a verifiable biometric template for identity authentication, which is irreversible, tunable, and cryptographically secure, employing a biometric feature-based counter data generation for standard encryption, allowing secure comparison and management of personal data without direct protection by biometric data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric data is bound with a secret using prior art binding schemes (XOR operation, value offsetting), then the binding process is simple and reversible, but security is compromised because leakage of one input reveals the other

Engineering Contradiction:
ImprovesecurityVSAvoidbinding scheme complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary binding function that transforms the direct relationship between biometric data and secret into an indirect relationship through a third element. The binding function processes both inputs through a cryptographic transformation that prevents reverse engineering, acting as a mediator that protects both inputs from direct exposure while maintaining their functional relationship for authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter space of the binding operation by moving from simple arithmetic operations (XOR, addition) to cryptographic hash functions or block cipher operations. This transformation changes the mathematical properties from reversible linear operations to irreversible non-linear operations, fundamentally improving security while accepting increased computational complexity.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If biometric templates are protected using prior art methods, then some privacy protection is achieved, but performance degradation occurs and security remains insufficient

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs preliminary binding of biometric data with a secret during the enrollment phase, creating a pre-processed protected template. This preliminary action ensures that when authentication occurs, the system only needs to perform the binding operation again with the same secret, rather than processing raw biometric data from scratch, thus maintaining performance while achieving security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a cryptographic copy or transformation of the biometric template that preserves the essential authentication properties while removing direct links to the original biometric data. This copied representation can be stored and compared without exposing the actual biometric features, maintaining both security and performance.

Inventive Principle:
Principle #26Copying

3Ease of operation

If biometric data is used for identity authentication, then convenience is provided, but privacy concerns arise as biometric data may disclose personal information

Engineering Contradiction:
Improveauthentication convenienceVSAvoidprivacy leakage
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent extracts and removes the personally identifiable biometric information from the authentication process by binding it with a secret that the user controls. The extracted protected representation can be used for authentication without the system needing to store or process the actual biometric data, thus maintaining convenience while preventing privacy leakage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The secret acts as an intermediary that mediates between the biometric data and the authentication system. The biometric data never directly interacts with the system in its raw form but is always transformed through the binding function with the secret, protecting privacy while enabling convenient authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If biometric templates are made irreversible and unlinkable, then security and privacy are improved, but the ability to verify identity accurately becomes more difficult

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent introduces dynamic elements to the binding process, such as using different salts or nonces for each binding operation, or using the secret in a dynamic manner (e.g., derived from multiple factors). This dynamic approach ensures that even if two bindings use the same biometric data, they produce different outputs, preventing linking while maintaining verification accuracy through the consistent use of the secret.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10594688B2Privacy-enhanced biometrics-secret binding scheme
Publication Date: 2020.03.17 HID GLOBAL CORP
  • US10594688B2 patent drawing
  • US10594688B2 patent drawing
  • US10594688B2 patent drawing

AI summary

Generating a distinguishing feature vector by means of a distinguishing feature extractor module from a raw biometric feature of the individual, the distinguishing feature vector being configured for differentiating individuals is carried out in a method. Further steps include generating a robust feature vector by means of a robust feature extractor module from the raw biometric feature of the individual; generating a cryptographic key from first auxiliary data based on the secret of the individual and optionally other data; using the robust feature vector together with second auxiliary data in a standard cryptographic module configured to perform a standard cryptographic function keyed by the cryptographic key; and binding the results produced by the standard cryptographic module and the distinguishing feature vector together as fused data by means of a modulo-N addition operation module, wherein N=2, 3, . . . , i.e. N is an integer greater than 1.