Biometric Token Generation via Obscured Algorithm

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Biometric authentication systems face limitations due to inadequate protection of biometric data during registration and challenge stages, making compromised biometric information difficult to revoke and reuse.

Innovation Solution

A method and system for securely managing biometric data by generating a token using a biometric signature and a seed value through an obscured algorithm, allowing for secure storage and transmission, and enabling secure authentication without exposing the original biometric data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric data is stored for authentication purposes, then authentication functionality is enabled, but security is compromised because biometric information cannot be changed once leaked

Engineering Contradiction:
Improveauthentication securityVSAvoidbiometric data revocability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments biometric authentication into multiple components: original biometric data, seed value, and token. The biometric data is processed to generate a biometric signature, which is then combined with a seed value to create a token. This segmentation allows the token to be revoked and regenerated if compromised, while the original biometric data remains secure and unchanged.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a token as an intermediary between the biometric data and the authentication system. The token is generated by combining the biometric signature with a seed value through an obscured algorithm. This intermediary layer allows the system to authenticate users without directly exposing or storing the original biometric data, enabling revocability while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If biometric data is protected through secure storage, then security is improved, but the system complexity increases due to additional protection mechanisms

Engineering Contradiction:
Improvebiometric data protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts the essential authentication information from the original biometric data by generating a biometric signature. This signature is then combined with a seed value to create a token. By extracting only the necessary authentication elements and storing the token rather than the original biometric data, the system reduces complexity while maintaining protection.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If biometric information is reused across multiple authentication instances, then ease of use is improved, but security is worsened because compromised biometric data cannot be changed

Engineering Contradiction:
Improveauthentication convenienceVSAvoidbiometric data security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements dynamic authentication tokens that can be regenerated when compromised. Instead of static biometric data, the token combines the biometric signature with a seed value and can be updated by changing the seed value or re-generating the token. This dynamic approach maintains ease of use while improving security through revocability.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10681025B2Systems and methods for securely managing biometric data
Publication Date: 2020.06.09 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US10681025B2 patent drawing
  • US10681025B2 patent drawing
  • US10681025B2 patent drawing

AI summary

Systems and methods for securely managing biometric data are provided. In a method conducted at a secure element which is directly connected to a biometric input, biometric data is received directly from the biometric input. A biometric signature based on the biometric data is obtained. A seed value specific to the biometric data is accessed by obtaining the seed value from the biometric data or biometric signature. The biometric signature is encoded using an obscured algorithm and the seed value to generate a token which is output for secure storage within the secure element or secure transmission to a secure server for registration or authentication of the biometric data. Obtaining the seed value from the biometric data or biometric signature can be repeated reliably to obtain the same the seed value.