Decentralized Biometric Authentication via Identity Binding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Biometric authentication systems lack assurance that the authenticating individual has undergone identity proofing and is the same person who enrolled the biometrics, leading to potential fraud and security breaches, especially in sensitive applications like financial services, immigration, and healthcare.
Innovation Solution
The proposed solution involves using a combination of biometrics and cryptographic hashes, where a user's biometric image is enrolled on a mobile device, and a hash is generated and stored on an identity server, allowing for secure verification by comparing the captured biometric with the enrolled one, ensuring that only a hash is shared, protecting identity and preventing recreation or identification from the hash, and using SHA-256 or higher cryptographic hashing algorithms for collision resistance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If biometric authentication is implemented without identity proofing assurance, then user convenience and authentication speed are improved, but security and reliability deteriorate due to potential fraud and impersonation
Solution Approach 1:
The patent introduces an identity provider as an intermediary that performs identity proofing and issues verifiable credentials. This intermediary binds biometric templates to verified identities before authentication, ensuring that the biometric data is linked to a proven identity without requiring the authenticating system to perform the proofing itself. The intermediary acts as a trusted third party that bridges the gap between convenience and reliability.
Solution Approach 2:
The patent implements identity proofing as a preliminary action that occurs before authentication. The identity provider verifies the user's identity and binds the biometric template to the verified identity in advance, creating a verifiable credential. This preliminary identity binding ensures that subsequent authentication operations can proceed quickly while maintaining reliability, as the identity verification has already been performed.
2Reliability
If centralized authentication systems are used, then identity verification can be performed, but security deteriorates due to centralized vulnerability to hacks and breaches
Solution Approach 1:
The patent segments the authentication system into multiple independent components: identity providers that perform proofing, authentication services that verify credentials, and users who hold verifiable credentials. This segmentation distributes trust and functionality across multiple entities rather than centralizing it in a single vulnerable system. Each segment operates independently, reducing the impact of security breaches in any single component.
Solution Approach 2:
The patent introduces verifiable credentials as an intermediary mechanism that enables decentralized authentication. Instead of users directly connecting to centralized authentication servers, the verifiable credentials serve as a trusted intermediary that proves identity without requiring continuous connection to a central authority. This intermediary layer reduces dependency on centralized systems and their associated security vulnerabilities.
3Ease of operation
If biometric data is stored centrally for verification, then authentication can be performed, but security and privacy deteriorate due to risk of data breaches and identity theft
Solution Approach 1:
The patent extracts the biometric template from the authentication flow and replaces it with a verifiable credential that contains a cryptographic proof of identity binding. Instead of storing and transmitting raw biometric data, the system extracts only the necessary verification capability through cryptographic hashing and digital signatures. This extraction removes the sensitive biometric data from the authentication process while maintaining functionality.
Solution Approach 2:
The patent creates a cryptographic copy of the identity-biometric binding in the form of a verifiable credential. Instead of using the actual biometric template for verification, the system uses a cryptographic hash and digital signature that serves as a secure copy. This copy contains all the necessary verification information without exposing the original biometric data, enabling authentication while protecting the source material.
Data Source
AI summary
A decentralized biometric identity authentication method utilizes biometrics captured on a mobile device to perform identity authentication against data that was registered as part of an identity proofing process and is thus trusted. The user registers his or her biometric using the user's mobile device and associates it with the user's electronic identity as part of a supervised identity proofing process, thus forming a proofed identity, and registers the proofed identity with a federated identity system. To later access the resources of the federated identity system, the user logs in with his or her biometrics. The methods described herein are useful, for example, in the travel, healthcare, and financial services fields.


