Biometric Network Privacy via Asymmetric Key Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multiuser device environments, the use of biometric information for identity verification raises privacy concerns and inefficiencies due to the need for remote storage and lengthy training procedures, especially when users are hesitant to share their biometric data with third-party servers or have to register separately on multiple devices.
Innovation Solution
Biometric information is encrypted and stored on a server without the server possessing the decryption key, allowing seamless integration across multiple devices within a network without requiring users to undergo lengthy training procedures on each device, with asymmetric key pairs generated on secure execution environments for secure data transmission and verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If biometric information is stored on a centralized server for network-wide access, then device compatibility and user convenience are improved, but privacy security and user trust deteriorate due to external storage concerns
Solution Approach 1:
The patent introduces an intermediary cryptographic system where biometric data is encrypted using asymmetric cryptography. The server stores only encrypted biometric templates and cannot decrypt them, acting as a mediator that enables network-wide access without compromising privacy. The user's private key protects their biometric data while the server's public key enables secure storage and verification across multiple devices.
Solution Approach 2:
The patent implements local quality by keeping the decryption capability (private key) localized to the user's device while allowing the encrypted biometric data to be stored centrally on the server. This creates a distributed security model where the sensitive operation of decryption occurs locally on the user's device, not on the centralized server, thus maintaining privacy while enabling network-wide access.
2Reliability
If biometric training is conducted separately on each device, then device-specific security is improved, but time efficiency and user convenience deteriorate due to repeated lengthy training procedures
Solution Approach 1:
The patent applies preliminary action by conducting the time-consuming biometric training procedure only once on the user's home device. The resulting encrypted biometric template is then stored on the centralized server and can be used for verification on any network device without requiring repeated training. This preliminary training action eliminates the need for time-consuming re-training on each new device.
Solution Approach 2:
The patent achieves universality by creating a single encrypted biometric template that serves multiple functions across different devices. The same encrypted template stored on the server can be used for verification on any device within the network, making the biometric authentication system universally applicable across the entire device ecosystem rather than device-specific.
3Object-affected harmful factors
If asymmetric cryptography is implemented for secure biometric storage, then privacy protection is improved, but system complexity increases due to key management requirements
Solution Approach 1:
The patent extracts the complex key management burden from the user and places it on the system architecture. The asymmetric cryptographic key pair is generated and managed automatically by the system - the user's private key is securely stored on their device while the public key is distributed to the server. This extraction of complexity allows users to benefit from strong cryptography without manually managing keys.
Solution Approach 2:
The system implements self-service by automatically generating and managing the asymmetric cryptographic key pairs. When a user enrolls, the system automatically creates their public-private key pair, stores the private key securely on their device, and distributes the public key to the server. This self-service automation eliminates the need for users to manually manage cryptographic keys while still providing strong privacy protection.
Data Source
AI summary
Various methods and devices that involve biometrically secured networked devices with enhanced privacy protection are disclosed. For example, a computer-implemented method for onboarding a first biometrically secured device to a network is disclosed. The method comprises generating an asymmetric key pair, transmitting the public key to a second device, and receiving an encrypted master encryption key from the second device. The master key is encrypted with the public key. The method also comprises decrypting the encrypted master encryption key using the private key and receiving an encrypted set of biometric data. The encrypted set of biometric data is a set of biometric data that is encrypted with the master encryption key. The method also comprises storing the set of biometric data on a memory of the first device. The set of biometric data uniquely identifies at least two users that are registered to use both the first and second devices.


