Biometrically Encrypted Secret Storage in Security Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security tokens face challenges in securely assigning and protecting secrets, particularly in ensuring the secrecy of private keys used for cryptographic operations, as they often rely on hardware measures that may not be sufficient against advanced threats.

Innovation Solution

A method involving biometric encryption, where biometric data is used to encrypt a secret, and only the encrypted secret is stored in the security token, with the unencrypted secret and biometric data being erased, ensuring that decryption can only occur with matching biometric data, providing a high level of security through error correction encoding and XOR operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware measures are used to protect the secrecy of private keys, then the security level is improved, but the protection may not be sufficient against advanced threats

Engineering Contradiction:
Improvesecurity levelVSAvoidvulnerability to advanced threats
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces biometric data as an intermediary element that mediates between the user and the secret. The biometrically encrypted secret acts as a mediator that combines hardware protection with biometric verification, creating an additional layer of security that is not vulnerable to traditional hardware attacks alone.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the security parameter from relying solely on hardware protection to using biometrically encrypted secrets. This parameter change transforms the security model by incorporating biometric data encryption, making the system resistant to advanced threats that could bypass traditional hardware measures.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If the unencrypted secret is stored in the security token for cryptographic operations, then the operational functionality is improved, but the security risk increases

Engineering Contradiction:
Improvecryptographic operation functionalityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs preliminary encryption of the secret using biometric data before storage. This preliminary action ensures that the secret is never stored in unencrypted form, eliminating the security risk while maintaining operational functionality. The biometrically encrypted secret is prepared in advance for cryptographic operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses volatile memory to store the biometrically encrypted secret temporarily during operations. This approach is analogous to using disposable objects - the data is held only as long as needed for the cryptographic operation and then erased, minimizing the window of vulnerability while maintaining functionality.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Ease of operation

If biometric data is stored in the security token for decryption, then the decryption capability is improved, but the storage of sensitive data increases security risks

Engineering Contradiction:
Improvedecryption capabilityVSAvoidsecurity risk from stored sensitive data
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the biometric data from permanent storage and uses it only temporarily for the encryption/decryption process. The biometric data is taken out of the storage system, used for the cryptographic operation, and then discarded, eliminating the security risk of storing sensitive biometric data while maintaining decryption capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements a process where biometric data is discarded after use and cannot be recovered. The biometrically encrypted secret is stored, but the original biometric data is erased from volatile memory after the enrollment or authentication process, ensuring that sensitive data is not permanently stored while maintaining the ability to decrypt when needed.

Inventive Principle:
Principle #34Discarding and recovering

4Reliability

If the secret is erased from volatile memory after storage, then the security is improved, but the ability to perform cryptographic operations is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidcryptographic operation capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent enables the security token to perform self-service cryptographic operations using the biometrically encrypted secret stored in volatile memory. The token can independently execute cryptographic functions without needing external assistance, and the secret is erased automatically when power is removed, maintaining both security and operational capability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2323308B1A method of assigning a secret to a security token, a method of operating a security token, storage medium and security token
Publication Date: 2016.03.23 MORPHO CARDS GMBH
  • EP2323308B1 patent drawingFigure 1~2
  • EP2323308B1 patent drawingFigure 3~4
  • EP2323308B1 patent drawingFigure 5~6

AI summary

A method of assigning a secret to a security token (100) comprising: - receiving first biometrical data (108) of a biometrical feature of a person by the security token, - storing the first biometrical data in the security token, - storing the unencrypted secret in the security token, - biometrically encrypting the secret using the first biometrical data by the security token, - storing the encrypted secret in the security token, - erasing the unencrypted secret and the first biometrical data from the security token.