Biometric Template Encryption for Secure Server Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Server-based biometric comparison systems face risks of data breaches and are not scalable, as biometric data is stored on servers and cannot be easily substituted or changed like passwords, and not all service providers can ensure secure storage of biometric data.

Innovation Solution

A system that performs biometric match analysis without maintaining records of biometric data by encrypting biometric templates using a public key, allowing secure comparison between encrypted templates without decryption, ensuring that only encrypted match results are shared, thus protecting sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If biometric data is stored on a server for remote comparison, then ease of operation and device compatibility are improved, but security and reliability deteriorate due to data breach risks

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the sensitive biometric data from the server environment and keeps it only on the user's device. Only encrypted templates and match results are stored on the server, while the actual biometric data remains local, eliminating the security risk of centralized storage while maintaining server-based comparison capabilities

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces encrypted biometric templates as an intermediary between the raw biometric data and the server storage system. These encrypted templates serve as a secure representation that allows server-based comparison without exposing the actual biometric information, thus enabling ease of operation while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If biometric data is stored centrally on a server, then device compatibility and user flexibility are improved, but the system becomes vulnerable to data breaches and lacks scalability

Engineering Contradiction:
Improvedevice compatibilityVSAvoiddata breach risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the biometric authentication system into multiple components: raw biometric data stored locally on the device, encrypted templates stored on the server, and match results generated through secure comparison. This segmentation allows device compatibility while distributing security risks across multiple entities rather than centralizing them

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the state of biometric data from plaintext to encrypted format before server storage. By transforming the data parameter from readable to encrypted, the system maintains adaptability for server-based comparison while eliminating the harmful effect of data breach vulnerability

Inventive Principle:
Principle #35Parameter changes

3Reliability

If biometric comparisons are made locally on the user's device, then security is improved by keeping data on-device, but device complexity and software size increase

Engineering Contradiction:
ImprovesecurityVSAvoidsoftware size
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates encrypted copies of biometric templates that can be stored on the server without increasing device complexity. These encrypted templates serve as lightweight representations that enable server-based comparison functionality while the actual biometric data remains on the device, avoiding the need for complex local authentication software

Inventive Principle:
Principle #26Copying

4Adaptability or versatility

If multiple service providers store biometric data on their servers, then service versatility is improved, but overall system security deteriorates as not all providers can ensure secure storage

Engineering Contradiction:
Improveservice versatilityVSAvoidoverall security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts the sensitive biometric data from the service provider's server environment and keeps it only on the user's device. Service providers only handle encrypted templates and match results, not the actual biometric data. This extraction allows service versatility while eliminating the security risk that arises from multiple providers storing sensitive data

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces encrypted biometric templates as an intermediary that enables multiple service providers to participate in the authentication process without having access to or storage of actual biometric data. This intermediary mechanism maintains service versatility while ensuring that no single provider becomes a security vulnerability point

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11943363B2Server-assisted privacy protecting biometric comparison
Publication Date: 2024.03.26 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US11943363B2 patent drawing
  • US11943363B2 patent drawing
  • US11943363B2 patent drawing

AI summary

Described herein are a system and techniques for enabling biometric authentication without exposing the authorizing entity to sensitive information. In some embodiments, the system receives a biometric template from a user device which is encrypted using a public key associated with the system. The encrypted biometric template is then provided to a second entity along with a biometric identifier. Upon receiving a request to complete a transaction that includes the biometric identifier and a second biometric template, the second entity may encrypt the second biometric template using the same public key associated with the system and perform a comparison between the two encrypted biometric templates. The resulting match result data file is already encrypted and can be provided to the system to determine an extent to which the two biometric templates match.