Biometric Template Segmentation for Secure Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing biometric authentication systems lack security and privacy protection, as they rely on centralized storage of biometric data, making them vulnerable to tampering and unauthorized access.
Innovation Solution
A user authentication method that splits a biometric template into two separable portions, encrypts, and stores them in different memories, ensuring that neither portion alone can recreate the original template, thus enhancing security and privacy by distributing the data across multiple systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric data is stored centrally in a single location, then the system is simpler to operate and manage, but security and privacy are compromised as the data becomes vulnerable to tampering and unauthorized access
Solution Approach 1:
The biometric template is divided into multiple separate portions (first template portion and second template portion) that are stored in different memories. This segmentation ensures that no single location holds the complete biometric data, thereby preventing unauthorized access even if one memory is compromised. The segmentation principle directly resolves the security vulnerability of centralized storage while maintaining system functionality.
Solution Approach 2:
Different portions of the biometric template are stored in different memories with potentially different access controls and security characteristics. Each memory location has specialized properties tailored to its specific role in the authentication process, allowing for differentiated security measures at different levels of the system architecture.
2Loss of information
If the complete biometric template is stored in one memory, then data access is faster and simpler, but privacy protection is reduced as the entire template is exposed to potential breaches
Solution Approach 1:
The biometric template is segmented into multiple portions distributed across different memories, ensuring that privacy is protected even if one memory is accessed or compromised. This segmentation limits the exposure of sensitive information to minimal data portions only, preventing complete template disclosure while maintaining authentication capability through the distributed architecture.
3Reliability
If biometric data is distributed across multiple memories, then security and privacy are enhanced, but the system becomes more complex and requires additional components
Solution Approach 1:
The biometric template is divided into separate portions stored in different memories, creating a distributed security architecture. This segmentation provides security benefits by ensuring that compromise of one memory does not expose the complete biometric data, while the system maintains functionality through the coordinated access of distributed portions.
Solution Approach 2:
An intermediary mechanism is required to coordinate access between the different memory locations holding template portions. This intermediary facilitates the authentication process by managing the retrieval and combination of distributed portions, abstracting the complexity from the user while enabling secure distributed storage.
4Ease of manufacture
If the complete biometric template is stored centrally, then the system is easier to implement, but vulnerability to tampering increases as the entire template is exposed
Solution Approach 1:
The biometric template is segmented into multiple portions distributed across different memories, reducing vulnerability to tampering. This segmentation ensures that even if one memory is tampered with or compromised, the complete biometric template cannot be accessed or modified, thereby protecting against tampering attacks while maintaining implementation feasibility.
Data Source
AI summary
A user authentication method based on the use of identification biometric techniques, including the steps of generating a reference biometric template from a first biometric image of a user to be authenticated; splitting the reference biometric template into a first and a second reference biometric template portion that can be physically separated; signing and enciphering the first and the second reference biometric template portion; storing the signed and enciphered first and second reference biometric template portion into different memories.


