Biometric Network Privacy via Device-Side Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multiuser device environments, biometric identity verification systems face challenges with user resistance to storing and transmitting sensitive biometric data, particularly when data is stored remotely or on centralized servers, due to privacy concerns and inefficiencies in registration and provisioning processes.
Innovation Solution
A network of biometrically secured devices where biometric data is encrypted and stored on devices within the network, with secure execution environments ensuring that biometric data is never exposed in unencrypted form on servers, allowing seamless integration across multiple devices without the need for repeated training procedures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If biometric data is stored and transmitted on centralized servers, then identity verification functionality is improved, but user privacy protection deteriorates
Solution Approach 1:
The patent extracts the biometric data from centralized server storage and places it exclusively on the user's mobile device. The server only stores encrypted authentication results, not the actual biometric templates. This extraction eliminates the privacy risk of centralized biometric storage while maintaining verification functionality.
Solution Approach 2:
The patent introduces an intermediary encryption mechanism where biometric data is transformed into encrypted authentication results before any server interaction. The encryption acts as a mediator that allows server-based verification processing without exposing raw biometric data, thus resolving the contradiction between functionality and privacy.
2Object-affected harmful factors
If biometric data is stored locally on each device, then user privacy protection is improved, but device complexity increases
Solution Approach 1:
The patent makes the mobile device universal by enabling it to store and process biometric data for authentication across multiple different devices (laptop, tablet, smart home devices). Instead of each device needing its own biometric storage, the mobile device serves as a universal secure credential holder for all connected devices.
Solution Approach 2:
The patent creates encrypted copies of authentication credentials on the mobile device that can be used across multiple target devices. Rather than storing raw biometric data everywhere, encrypted authentication results are copied to the mobile device, which then serves as the source for verifying access to other devices.
3Adaptability or versatility
If biometric information is collected from multiple users, then system functionality is improved, but registration time increases
Solution Approach 1:
The patent performs preliminary biometric data collection and encryption during an initial setup phase. Once the biometric template is captured and encrypted on the mobile device, the same encrypted credentials can be used immediately for multiple devices without requiring repeated collection processes, thus reducing overall registration time for multiuser scenarios.
Solution Approach 2:
The patent merges the biometric authentication process into a single centralized location (the mobile device) rather than requiring separate registration at each target device. This consolidation allows multiple users and devices to share a common authentication mechanism, reducing total registration time while maintaining multiuser functionality.
Data Source
AI summary
This disclosure includes biometrically secured networked devices with enhanced privacy protection. One system includes a first biometrically secured device having a first sensor, and a second biometrically secured device having a second sensor. The first device is programmed to: (i) obtain a first sample of a first biometric using the first sensor; (ii) generate a secret biometrically derived key using the first sample of the first biometric; (iii) encrypt a set of biometric data using the secret biometrically derived key; and (iv) transmit the set of encrypted biometric data to the second biometrically secured device. The second device is programmed to: (i) obtain a second sample of the first biometric using the second sensor; (ii) generate the secret biometrically derived key using the second sample of the first biometric; and (iii) decrypt the set of biometric data using the secret biometrically derived key.


