Biometric Private Key Generation for Decentralized Identity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional token devices for multi-factor authentication (MFA) are often not carried by users when needed, can be damaged or stolen, and provide an opportunity for malicious interception of generated passwords, reducing security.
Innovation Solution
A decentralized identity system using biometric coordinates, such as fingerprints or retinal scans, to generate a private key, integrated with a federated trust platform and blockchain network for secure and decentralized MFA across cloud providers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a token device is used for MFA, then possession factor authentication is provided, but the device may not always be carried by the user when needed
Solution Approach 1:
The patent replaces the mechanical token device with a biometric-based authentication system. Instead of relying on a physical device that generates passwords, the system uses biometric coordinates (fingerprint, facial, or retinal scan) to generate private keys and authenticate users. This substitution eliminates the need for users to carry physical tokens while maintaining authentication reliability.
2Reliability
If a token device is used for MFA, then possession factor authentication is provided, but the device may be damaged or stolen
Solution Approach 1:
The patent extracts the authentication capability from the physical token device and embeds it directly in the user's biometric data. The biometric coordinates serve as the secure element, eliminating the vulnerable physical device. Even if a device is compromised, the biometric data stored securely in the authenticator remains protected and cannot be easily extracted or replicated.
3Ease of operation
If password generation occurs before access attempt, then authentication is enabled, but security is reduced by providing an opportunity for malicious interception
Solution Approach 1:
The patent implements dynamic password generation where the private key is created on-demand at the moment of authentication request. The biometric coordinates are processed in real-time within the authenticator to generate the private key, which is then immediately used for signature verification. This dynamic approach eliminates the window of opportunity for interception that exists in static pre-generated password systems.
4Reliability
If a decentralized identity system with biometric coordinates is used, then security is enhanced by real-time key generation, but device complexity increases
Solution Approach 1:
The patent introduces a blockchain-based federated trust platform as an intermediary layer that manages the complexity of decentralized identity verification. The blockchain network stores and verifies biometric identity records, allowing the authenticator to focus on generating private keys from biometric coordinates without needing to implement complex verification logic. This intermediary handles the computational and storage complexity, making the overall system more manageable.
Data Source
AI summary
Systems, methods, and other embodiments for decentralized identity with user biometrics are presented herein. In one embodiment, a method includes, in response to a request to access resources of a cloud service provider by a computing device, transmitting a request for a biometric private key to a mobile device associated with a user; in response to receiving the biometric private key, submitting the biometric private key for validation against a blockchain associated with the user and the mobile device; adding a record of the results of the validation to the blockchain; and controlling access to the resources of the cloud service provider based on the record in the blockchain by (i) denying access where the record indicates that validation has failed (ii) granting access where the record indicates that validation has succeeded.


