Biometric Template Encryption for Secure Server Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Server-based biometric comparison systems face risks of data breaches and are not scalable, as biometric data is stored on servers and cannot be easily substituted or changed like passwords, and not all service providers can ensure secure storage of biometric data.
Innovation Solution
A system that performs biometric match analysis without maintaining records of biometric data by encrypting biometric templates using a public key, allowing secure comparison between encrypted templates without decryption, ensuring that only encrypted match results are shared, thus protecting sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If biometric data is stored on a server for remote comparison, then ease of operation and device compatibility are improved, but security and reliability deteriorate due to data breach risks
Solution Approach 1:
The patent extracts the sensitive biometric data from the server environment and keeps it only on the user's device. Only encrypted templates and match results are stored on the server, while the actual biometric data remains local, eliminating the security risk of centralized storage while maintaining server-based comparison capabilities
Solution Approach 2:
The patent introduces encrypted biometric templates as an intermediary between the raw biometric data and the server storage system. These encrypted templates serve as a secure representation that allows server-based comparison without exposing the actual biometric information, thus enabling ease of operation while maintaining security
2Adaptability or versatility
If biometric data is stored centrally on a server, then device compatibility and user flexibility are improved, but the system becomes vulnerable to data breaches and lacks scalability
Solution Approach 1:
The patent segments the biometric authentication system into multiple components: raw biometric data stored locally on the device, encrypted templates stored on the server, and match results generated through secure comparison. This segmentation allows device compatibility while distributing security risks across multiple entities rather than centralizing them
Solution Approach 2:
The patent changes the state of biometric data from plaintext to encrypted format before server storage. By transforming the data parameter from readable to encrypted, the system maintains adaptability for server-based comparison while eliminating the harmful effect of data breach vulnerability
3Reliability
If biometric comparisons are made locally on the user's device, then security is improved by keeping data on-device, but device complexity and software size increase
Solution Approach 1:
The patent creates encrypted copies of biometric templates that can be stored on the server without increasing device complexity. These encrypted templates serve as lightweight representations that enable server-based comparison functionality while the actual biometric data remains on the device, avoiding the need for complex local authentication software
4Adaptability or versatility
If multiple service providers store biometric data on their servers, then service versatility is improved, but overall system security deteriorates as not all providers can ensure secure storage
Solution Approach 1:
The patent extracts the sensitive biometric data from the service provider's server environment and keeps it only on the user's device. Service providers only handle encrypted templates and match results, not the actual biometric data. This extraction allows service versatility while eliminating the security risk that arises from multiple providers storing sensitive data
Solution Approach 2:
The patent introduces encrypted biometric templates as an intermediary that enables multiple service providers to participate in the authentication process without having access to or storage of actual biometric data. This intermediary mechanism maintains service versatility while ensuring that no single provider becomes a security vulnerability point
Data Source
AI summary
Described herein are a system and techniques for enabling biometric authentication without exposing the authorizing entity to sensitive information. In some embodiments, the system receives a biometric template from a user device which is encrypted using a public key associated with the system. The encrypted biometric template is then provided to a second entity along with a biometric identifier. Upon receiving a request to complete a transaction that includes the biometric identifier and a second biometric template, the second entity may encrypt the second biometric template using the same public key associated with the system and perform a comparison between the two encrypted biometric templates. The resulting match result data file is already encrypted and can be provided to the system to determine an extent to which the two biometric templates match.


