Biometric Private Key Generation for Decentralized Identity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional token devices for multi-factor authentication (MFA) are often not carried by users when needed, can be damaged or stolen, and provide an opportunity for malicious interception of generated passwords, reducing security.

Innovation Solution

A decentralized identity system using biometric coordinates, such as fingerprints or retinal scans, to generate a private key, integrated with a federated trust platform and blockchain network for secure and decentralized MFA across cloud providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a token device is used for MFA, then possession factor authentication is provided, but the device may not always be carried by the user when needed

Engineering Contradiction:
Improveauthentication availabilityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical token device with a biometric-based authentication system. Instead of relying on a physical device that generates passwords, the system uses biometric coordinates (fingerprint, facial, or retinal scan) to generate private keys and authenticate users. This substitution eliminates the need for users to carry physical tokens while maintaining authentication reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If a token device is used for MFA, then possession factor authentication is provided, but the device may be damaged or stolen

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication capability from the physical token device and embeds it directly in the user's biometric data. The biometric coordinates serve as the secure element, eliminating the vulnerable physical device. Even if a device is compromised, the biometric data stored securely in the authenticator remains protected and cannot be easily extracted or replicated.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If password generation occurs before access attempt, then authentication is enabled, but security is reduced by providing an opportunity for malicious interception

Engineering Contradiction:
Improveauthentication functionalityVSAvoidpassword security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic password generation where the private key is created on-demand at the moment of authentication request. The biometric coordinates are processed in real-time within the authenticator to generate the private key, which is then immediately used for signature verification. This dynamic approach eliminates the window of opportunity for interception that exists in static pre-generated password systems.

Inventive Principle:
Principle #15Dynamics

4Reliability

If a decentralized identity system with biometric coordinates is used, then security is enhanced by real-time key generation, but device complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a blockchain-based federated trust platform as an intermediary layer that manages the complexity of decentralized identity verification. The blockchain network stores and verifies biometric identity records, allowing the authenticator to focus on generating private keys from biometric coordinates without needing to implement complex verification logic. This intermediary handles the computational and storage complexity, making the overall system more manageable.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12021978B2Blockchain record of user biometrics for access control
Publication Date: 2024.06.25 ORACLE INT CORP
  • US12021978B2 patent drawing
  • US12021978B2 patent drawing
  • US12021978B2 patent drawing

AI summary

Systems, methods, and other embodiments for decentralized identity with user biometrics are presented herein. In one embodiment, a method includes, in response to a request to access resources of a cloud service provider by a computing device, transmitting a request for a biometric private key to a mobile device associated with a user; in response to receiving the biometric private key, submitting the biometric private key for validation against a blockchain associated with the user and the mobile device; adding a record of the results of the validation to the blockchain; and controlling access to the resources of the cloud service provider based on the record in the blockchain by (i) denying access where the record indicates that validation has failed (ii) granting access where the record indicates that validation has succeeded.