Biometric Secret Keys Using Index Translation Without Stored Templates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing biometric authentication methods are vulnerable to spoofing and template matching failures due to environmental noise and storage of biometric identifiers, leading to security issues.

Innovation Solution

A system generates a biometric secret key using an index translate function to rearrange biometric data, creating enrollment data that is used to generate cryptographic keys, ensuring secure authentication without storing the biometric template.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric identifiers are stored in memory or on a server for template matching, then authentication can be performed, but security is compromised as malicious entities can gain unauthorized access or spoof the biometric data

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the necessary authentication verification capability from the biometric template, storing only encrypted biometric data and authentication rules on the server while keeping the decryption key and template processing capability on the user device. This removes the vulnerable stored template while preserving authentication functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces encrypted biometric data as an intermediary between the original biometric template and the authentication process. The encrypted data is stored on the server and cannot be directly used for spoofing, while still enabling verification through the authentication rules and decryption process on the user device.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If biometric identifiers are stored for authentication, then user identification can be performed, but privacy is compromised due to potential unauthorized access

Engineering Contradiction:
Improveauthentication capabilityVSAvoidprivacy loss
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent extracts only the essential authentication verification function from the complete biometric template, storing only encrypted biometric data and authentication rules on the server. The full template remains on the user device, minimizing stored information while preserving authentication capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements local processing of biometric data on the user device, where the template is decrypted and processed locally rather than being transmitted or stored in plaintext on the server. This localizes the sensitive operations to the user's device, protecting privacy while enabling authentication.

Inventive Principle:
Principle #3Local quality

3Productivity

If template matching is used for biometric authentication, then authentication can be performed, but the system becomes vulnerable to spoofing attacks

Engineering Contradiction:
Improveauthentication speedVSAvoidspoofing vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent converts the potential harm of storing biometric data into a benefit by encrypting the data before storage. The encrypted state prevents spoofing attacks while the decryption process on the user device enables rapid authentication, turning the storage vulnerability into a security feature.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The patent changes the state of biometric data from plaintext to encrypted form for storage, and back to decrypted form for processing. This parameter change in data representation prevents spoofing attacks on stored data while maintaining authentication speed through efficient local decryption and processing.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12368582B2Systems and methods for generating and using biometric secret keys
Publication Date: 2025.07.22 AETNA INC
  • US12368582B2 patent drawing
  • US12368582B2 patent drawing
  • US12368582B2 patent drawing

AI summary

A system comprising a first user device is provided. The first user device is configured to: obtain biometric registration data associated with a user; generate a secret key for the biometric registration data, wherein the secret key indicates an index translate point array; determine enrollment data for the user based on an index translate function, the biometric registration data, and the secret key, wherein the index translate function modifies entries of the biometric registration data based on the index translate point array; generate one or more cryptographic keys for the user based on the index translate point array; and provide, to a computing platform, ancillary information associated with the one or more cryptographic keys and the enrollment data.