Biometric Template Encryption via PIN and Hardware ID
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Stand-alone computing devices face security risks due to reliance on insecure password-based authentication, which can lead to unauthorized access and data breaches, especially when lost or stolen, and existing biometric systems struggle to protect biometric templates and generate secure encryption keys.
Innovation Solution
A method that combines a numeric PIN, device hardware components, and an obfuscated, user-chosen password with biometric samples to provide secure and user-friendly access to devices, eliminating the need for complex password entry, using a one-way hashed PIN and device ID to generate encryption keys for biometric template encryption and decryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complex passwords are used to provide sufficient security, then security is improved, but user-friendliness deteriorates
Solution Approach 1:
The patent introduces biometric data (fingerprint, facial recognition, iris patterns) and PIN codes as intermediary authentication factors that replace complex passwords. These intermediaries provide strong security through multiple authentication factors while maintaining user-friendliness by using intuitive biometric scanning and simple numeric PINs instead of memorizing complex password strings.
Solution Approach 2:
The patent replaces the mechanical system of manual password entry and memorization with automated biometric recognition systems. Fingerprint sensors, facial recognition cameras, and iris scanners automatically capture and verify user identity without requiring manual input, eliminating the need for users to remember complex passwords while maintaining high security standards.
2Ease of operation
If simple PIN authentication is used, then user-friendliness is improved, but security deteriorates
Solution Approach 1:
The patent merges multiple authentication factors including biometric data (fingerprint, facial recognition, iris patterns), PIN codes, and device hardware identifiers into a unified authentication system. This combination maintains user-friendliness by allowing simple PIN or biometric input while dramatically improving security through multi-factor authentication that makes brute force and social engineering attacks ineffective.
Solution Approach 2:
The authentication system uses a composite approach combining different types of authentication data (biometric templates, hashed PINs, device IDs) similar to composite materials. Each component alone may have limitations, but their integration creates a robust authentication mechanism that provides both ease of use and strong security, with each layer compensating for the weaknesses of others.
3Adaptability or versatility
If biometric templates are stored on devices, then authentication capability is improved, but security risk deteriorates
Solution Approach 1:
The patent extracts the biometric template data from the authentication decision-making process. Instead of storing and processing raw biometric templates on the device, the system extracts only the necessary authentication verification capability. The actual biometric templates are stored securely in encrypted form, separate from the authentication logic, reducing the security risk of template exposure while maintaining full authentication capability.
Solution Approach 2:
The patent segments the authentication system into separate secure components: biometric template storage (encrypted and isolated), PIN hashing (stored separately), and authentication verification logic. This segmentation ensures that even if one component is compromised, the others remain protected, reducing overall security risk while maintaining comprehensive authentication capability across multiple factors.
Data Source
AI summary
Biometric data, suitably transformed are obtained from a biometric input device contained within a stand-alone computing device and used in conjunction with a PIN to authenticate the user to the device. The biometric template and other data residing on the device are encrypted using hardware elements of the device, the PIN and Password hash. A stored obfuscated password is de-obfuscated and released to the device authentication mechanism in response to a successfully decrypted template and matching biometric sample and PIN. The de-obfuscated password is used to authenticate the user to device, the user to a remote computer, and to encrypt device data at rest on the device and in transit to and from the remote computer. This creates a trusted relationship between the stand-alone device and the remote computer. The system also eliminates the need for the user to remember and enter complex passwords on the device.


