Biometric Template Encryption Key Derivation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional biometric systems face vulnerabilities in privacy protection and recognition accuracy, especially when scaling, as they require significant effort to apply biometric encryption methods to new modalities or representations, and encryption keys are not under individual control.

Innovation Solution

A method and system that encrypts a second biometric template using a first biometric template-derived key, allowing for private multi-template settings without storing the encryption key, ensuring high security and efficient verification by deriving temporary decryption keys for decrypting encrypted templates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional biometric encryption methods are applied to protect biometric templates, then privacy protection is improved, but the system requires significant effort to apply to new modalities or representations and encryption keys are not under individual control

Engineering Contradiction:
Improveprivacy protectionVSAvoidintegration effort
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary cryptographic key that mediates between the biometric template and the encryption process. This key is derived from the biometric template itself through a one-way function, allowing the template to control encryption without requiring external key management infrastructure. This resolves the contradiction by providing automated key control (improving reliability) while avoiding complex key distribution systems (reducing device complexity).

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The biometric template serves itself by generating the cryptographic key through a one-way derivation function. The template inherently controls its own encryption without requiring external key management, making the system self-sufficient. This eliminates the need for complex key distribution and management infrastructure while ensuring the template owner controls their own data (improving reliability without increasing device complexity).

Inventive Principle:
Principle #25Self-service

2Measurement precision

If multiple biometric templates are stored for different modalities, then recognition accuracy is improved, but security vulnerabilities increase due to key management issues

Engineering Contradiction:
Improverecognition accuracyVSAvoidsecurity
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent segments the security architecture by creating independent cryptographic key derivation paths for each biometric modality. Each template generates its own key through separate one-way functions, isolating security vulnerabilities to individual modalities. This allows multiple templates to be stored for improved recognition accuracy while maintaining security through modular, isolated key management (improving measurement precision without compromising reliability).

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the cryptographic parameter management approach by deriving keys from biometric templates themselves rather than using external key management. This parameter change enables secure storage of multiple templates with different modalities, as each template's unique characteristics generate unique cryptographic parameters. This resolves the contradiction by allowing multiple templates (improving measurement precision) while maintaining security through template-derived key isolation (maintaining reliability).

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2377064B1Method and system for verifying the identity of an individual by employing biometric data features associated with the individual
Publication Date: 2018.02.07 GENKEY NETHERLANDS
  • EP2377064B1 patent drawingFigure 1a
  • EP2377064B1 patent drawingFigure 1b
  • EP2377064B1 patent drawingFigure 1c

AI summary

The invention relates to a method for verifying the identity of an individual by employing biometric data features associated with the individual, which method provides privacy of said biometric data features, comprising at least the steps of: a) for enrolment purposes deriving a first biometric template from at least a first set of first biometric data features associated with said individual, and b) for identity verifying purposes deriving a further biometric template from at least a further set of said first biometric data features associated with said individual, and c) comparing said further biometric template with said first biometric template. The invention also relates to a system for verifying the identity of an individual by employing biometric data features associated with the individual, which system at least comprises: an enrolment means and a verifying means, wherein said enrolment means are arranged in deriving a first biometric template data, said first biometric template data being secret and associated with a first set of first biometric data features of said individual, and in receiving a further set of first biometric data features of said individual, and in deriving a further biometric template data associated with said further set of first biometric data, and wherein said verifying means are arranged in comparing the first biometric template data with the further biometric template data to check for correspondence, wherein the identity of the individual is verified if correspondence exists.