Biometric Template Encryption Key Derivation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional biometric systems face vulnerabilities in privacy protection and recognition accuracy, especially when scaling, as they require significant effort to apply biometric encryption methods to new modalities or representations, and encryption keys are not under individual control.
Innovation Solution
A method and system that encrypts a second biometric template using a first biometric template-derived key, allowing for private multi-template settings without storing the encryption key, ensuring high security and efficient verification by deriving temporary decryption keys for decrypting encrypted templates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional biometric encryption methods are applied to protect biometric templates, then privacy protection is improved, but the system requires significant effort to apply to new modalities or representations and encryption keys are not under individual control
Solution Approach 1:
The patent introduces an intermediary cryptographic key that mediates between the biometric template and the encryption process. This key is derived from the biometric template itself through a one-way function, allowing the template to control encryption without requiring external key management infrastructure. This resolves the contradiction by providing automated key control (improving reliability) while avoiding complex key distribution systems (reducing device complexity).
Solution Approach 2:
The biometric template serves itself by generating the cryptographic key through a one-way derivation function. The template inherently controls its own encryption without requiring external key management, making the system self-sufficient. This eliminates the need for complex key distribution and management infrastructure while ensuring the template owner controls their own data (improving reliability without increasing device complexity).
2Measurement precision
If multiple biometric templates are stored for different modalities, then recognition accuracy is improved, but security vulnerabilities increase due to key management issues
Solution Approach 1:
The patent segments the security architecture by creating independent cryptographic key derivation paths for each biometric modality. Each template generates its own key through separate one-way functions, isolating security vulnerabilities to individual modalities. This allows multiple templates to be stored for improved recognition accuracy while maintaining security through modular, isolated key management (improving measurement precision without compromising reliability).
Solution Approach 2:
The patent changes the cryptographic parameter management approach by deriving keys from biometric templates themselves rather than using external key management. This parameter change enables secure storage of multiple templates with different modalities, as each template's unique characteristics generate unique cryptographic parameters. This resolves the contradiction by allowing multiple templates (improving measurement precision) while maintaining security through template-derived key isolation (maintaining reliability).
Data Source
Figure 1a
Figure 1b
Figure 1c
AI summary
The invention relates to a method for verifying the identity of an individual by employing biometric data features associated with the individual, which method provides privacy of said biometric data features, comprising at least the steps of: a) for enrolment purposes deriving a first biometric template from at least a first set of first biometric data features associated with said individual, and b) for identity verifying purposes deriving a further biometric template from at least a further set of said first biometric data features associated with said individual, and c) comparing said further biometric template with said first biometric template. The invention also relates to a system for verifying the identity of an individual by employing biometric data features associated with the individual, which system at least comprises: an enrolment means and a verifying means, wherein said enrolment means are arranged in deriving a first biometric template data, said first biometric template data being secret and associated with a first set of first biometric data features of said individual, and in receiving a further set of first biometric data features of said individual, and in deriving a further biometric template data associated with said further set of first biometric data, and wherein said verifying means are arranged in comparing the first biometric template data with the further biometric template data to check for correspondence, wherein the identity of the individual is verified if correspondence exists.