Biometric Template Handling via Segmented Key Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current biometric authentication systems face challenges in balancing security and user friendliness, particularly in the enrollment process and the handling of biometric templates, which often require secure but not cumbersome methods for multiple device compatibility.
Innovation Solution
A method involving an authenticating device that acquires a decryption key from a key carrying device to decrypt an encrypted biometric template for authentication, allowing secure and flexible use of biometric templates across multiple devices, with the decryption key being temporarily present and associated with the enrolled user.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric templates are encrypted and stored locally in the authenticating device, then security is improved, but device compatibility and user friendliness deteriorate
Solution Approach 1:
The patent divides the biometric template into two separate components: an encrypted template stored locally in the authenticating device and a decryption key stored in a separate cloud-based database. This segmentation allows the template to remain secure on the device while enabling compatibility across multiple devices through centralized key management, resolving the contradiction between security and device compatibility.
Solution Approach 2:
The patent introduces a cloud-based database as an intermediary that stores both the encrypted biometric templates and their corresponding decryption keys. This intermediary enables secure template transfer and decryption across different devices without compromising the security of the biometric data, thus improving both security and adaptability simultaneously.
2Ease of operation
If biometric templates are shared between different devices, then user friendliness is improved, but security deteriorates
Solution Approach 1:
The patent segments the template and key into separate locations: the encrypted template remains on the device while the decryption key is stored in the cloud. This allows the template to be accessible across multiple devices for user friendliness, while the separate key storage maintains security by preventing unauthorized access to the biometric data.
Solution Approach 2:
The cloud-based database acts as a secure intermediary that provides decryption keys to authorized devices. This intermediary enables template sharing across devices for improved user experience while maintaining security through controlled key distribution and centralized management.
3Ease of operation
If encryption keys are stored on the same device as biometric templates, then ease of authentication is improved, but security deteriorates
Solution Approach 1:
The patent segments the storage location of the encrypted template and decryption key: the template is stored locally on the authenticating device for fast access, while the decryption key is stored in a separate cloud-based database. This segmentation maintains authentication speed by keeping the template locally available while improving security by preventing the key from being compromised if the device is breached.
Data Source
AI summary
A method for handling biometric templates is disclosed for an authenticating device applying biometric authentication. The method comprises acquiring a set of biometric data associated with a prospect user, and acquiring a decryption key (associated with an encrypted biometric template associated with an enrolled user of the authenticating device) from a key carrying device external to the authenticating device responsive to the key carrying device being in a vicinity of the authenticating device. The method also comprises retrieving, from a storage medium, at least a part of the encrypted biometric template associated with the enrolled user, decrypting the retrieved part of the biometric template using the acquired decryption key and performing an attempt to authenticate the prospect user as the enrolled user based on a comparison between the acquired set of biometric data and the decrypted part of the biometric template.


