Biometric Template Transfer via Protected Environment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing biometric authentication systems face challenges in ensuring user control over biometric reference templates, leading to privacy concerns due to permanent storage on remote servers or devices that may be lost or shared.
Innovation Solution
A biometric authentication system where client devices conditionally transfer biometric reference templates to authentication devices only if the templates are stored in a protected environment and will be deleted upon a termination event, such as session expiration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If biometric reference templates are stored on remote authentication servers, then authentication can be performed centrally, but user privacy is compromised and users lose control over their biometric data
Solution Approach 1:
The patent extracts the biometric reference templates from the remote authentication server and places them on the client device instead. This extraction removes the sensitive data from the centralized server, allowing the server to perform authentication functions without storing the actual biometric templates, thereby resolving the contradiction between centralized authentication and user data control
Solution Approach 2:
The patent inverts the traditional storage architecture by storing biometric reference templates on the client device rather than on the remote server. This inversion flips the conventional model where servers hold user data, creating a model where users retain control over their biometric information while still enabling remote authentication
2Loss of information
If biometric reference templates are stored permanently on client devices, then users maintain control over their data, but privacy concerns arise when devices are lost or shared
Solution Approach 1:
The patent introduces dynamic control over biometric reference template storage by allowing users to configure whether templates are stored permanently or temporarily on client devices. This dynamic option enables users to adapt the storage behavior based on their privacy needs and device security circumstances, resolving the contradiction between maintaining user control and preventing privacy risks from device loss
Solution Approach 2:
The patent implements periodic deletion of biometric reference templates from client devices after a specified period or under certain conditions. This periodic action ensures that even if templates are stored on devices, they are automatically removed after serving their authentication purpose, thereby reducing the long-term privacy risks associated with device loss or sharing
3Ease of operation
If biometric reference templates are transferred to authentication devices, then authentication can be performed, but templates may be compromised by hackers targeting the authentication server
Solution Approach 1:
The patent extracts biometric reference templates from the authentication server environment and stores them on client devices instead. This extraction eliminates the vulnerability where hackers could access stored templates on servers, while still enabling authentication capability through the client device's local storage
Solution Approach 2:
The patent implements temporary storage of biometric reference templates on client devices with automatic deletion after use or after a specified period. This disposable approach ensures that templates do not persist on devices long-term, reducing the window of opportunity for hackers to compromise and reuse the data, thereby maintaining both authentication capability and security
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Generally, this disclosure describes technologies for securely storing and using biometric authentication information, such as biometric reference templates. In some embodiments, the technologies include a client device that stores one or more biometric reference templates in a memory thereof. The client device may transfer such templates to an authentication device. The transfer may be conditioned on verification that the authentication device includes a suitable protected environment for the templates and will execute an acceptable temporary storage policy. The technologies may also include an authentication device that is configured to temporarily store biometric reference templates received from a client device in a protected environment thereof. Upon completion of biometric authentication or the occurrence of a termination event, the authentication devices may delete the biometric reference templates from the protected environment.