Biometric Public Key Generation for Revocable Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security technologies struggle to authenticate users using biometric data without the need for non-transient storage of the biometric data, while also ensuring the security and revocability of the authentication process.
Innovation Solution
A device that generates a biometric public key for an individual based on their biometric data, without storing the data, using a computing facility with a processor and storage medium to process biometric values, encode them, and compute the public key, which can be used for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric data is stored for authentication purposes, then authentication reliability is improved, but security vulnerability increases due to data breach risks
Solution Approach 1:
The patent extracts only the necessary biometric features (landmarks and descriptors) from the complete biometric data, processes them to generate cryptographic keys, and discards the original biometric data. This extraction approach maintains authentication reliability through feature-based verification while eliminating security vulnerabilities by removing stored biometric templates.
Solution Approach 2:
The patent creates a cryptographic copy (public key) from the biometric data that can be stored and used for authentication without storing the original biometric data. The public key serves as a derivative copy that enables authentication while the original biometric remains unstored, thus maintaining security while preserving functionality.
2Ease of operation
If biometric data is stored to enable authentication, then authentication capability is improved, but loss of information increases due to data breach exposure
Solution Approach 1:
The system extracts only the minimal necessary information (biometric features) from the complete biometric data, processes this extracted information to generate authentication keys, and discards the original data. This ensures authentication capability is maintained while biometric data exposure is prevented since the original data is never stored.
Solution Approach 2:
The patent employs temporary, disposable cryptographic keys that can be generated and discarded without storing the biometric data. These keys serve their authentication purpose and then become obsolete, eliminating the permanent storage requirement and associated information exposure risks.
3Adaptability or versatility
If public keys are made revocable for security, then security flexibility is improved, but system complexity increases due to key management processes
Solution Approach 1:
The patent implements a dynamic key generation system where public keys can be regenerated whenever needed without requiring complex revocation procedures. The biometric data serves as a living template that can produce new keys on demand, providing flexibility while avoiding static key management complexity.
Solution Approach 2:
The system enables users to regenerate their own authentication keys using their biometric data without requiring administrator intervention or complex revocation workflows. This self-service capability provides security flexibility while minimizing system management complexity.
Data Source
AI summary
A device generates a biometric public key for a set of individuals based on biometric data of the set of individuals, where biometric features of each individual of the set constitute a subset of the set of biometric values. in a manner that verifiably characterizes both while tending to prevent recovery of either. The biometric public key may be later used to authenticate a candidate set of subjects purporting to be a subset of an enrolled set of individuals, using a computing facility that need not rely on a hardware root of trust.


