Decentralized Biometric Authentication via Identity Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Biometric authentication systems lack assurance that the authenticating individual has undergone identity proofing and is the same person who enrolled the biometrics, leading to potential fraud and security breaches, especially in sensitive applications like financial services, immigration, and healthcare.

Innovation Solution

The proposed solution involves using a combination of biometrics and cryptographic hashes, where a user's biometric image is enrolled on a mobile device, and a hash is generated and stored on an identity server, allowing for secure verification by comparing the captured biometric with the enrolled one, ensuring that only a hash is shared, protecting identity and preventing recreation or identification from the hash, and using SHA-256 or higher cryptographic hashing algorithms for collision resistance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If biometric authentication is implemented without identity proofing assurance, then user convenience and authentication speed are improved, but security and reliability deteriorate due to potential fraud and impersonation

Engineering Contradiction:
Improveauthentication convenienceVSAvoididentity verification reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an identity provider as an intermediary that performs identity proofing and issues verifiable credentials. This intermediary binds biometric templates to verified identities before authentication, ensuring that the biometric data is linked to a proven identity without requiring the authenticating system to perform the proofing itself. The intermediary acts as a trusted third party that bridges the gap between convenience and reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements identity proofing as a preliminary action that occurs before authentication. The identity provider verifies the user's identity and binds the biometric template to the verified identity in advance, creating a verifiable credential. This preliminary identity binding ensures that subsequent authentication operations can proceed quickly while maintaining reliability, as the identity verification has already been performed.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If centralized authentication systems are used, then identity verification can be performed, but security deteriorates due to centralized vulnerability to hacks and breaches

Engineering Contradiction:
Improveidentity verification capabilityVSAvoidcentralized security vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authentication system into multiple independent components: identity providers that perform proofing, authentication services that verify credentials, and users who hold verifiable credentials. This segmentation distributes trust and functionality across multiple entities rather than centralizing it in a single vulnerable system. Each segment operates independently, reducing the impact of security breaches in any single component.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces verifiable credentials as an intermediary mechanism that enables decentralized authentication. Instead of users directly connecting to centralized authentication servers, the verifiable credentials serve as a trusted intermediary that proves identity without requiring continuous connection to a central authority. This intermediary layer reduces dependency on centralized systems and their associated security vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If biometric data is stored centrally for verification, then authentication can be performed, but security and privacy deteriorate due to risk of data breaches and identity theft

Engineering Contradiction:
Improveauthentication functionalityVSAvoidbiometric data security risk
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent extracts the biometric template from the authentication flow and replaces it with a verifiable credential that contains a cryptographic proof of identity binding. Instead of storing and transmitting raw biometric data, the system extracts only the necessary verification capability through cryptographic hashing and digital signatures. This extraction removes the sensitive biometric data from the authentication process while maintaining functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a cryptographic copy of the identity-biometric binding in the form of a verifiable credential. Instead of using the actual biometric template for verification, the system uses a cryptographic hash and digital signature that serves as a secure copy. This copy contains all the necessary verification information without exposing the original biometric data, enabling authentication while protecting the source material.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11080380B2Decentralized biometric identity authentication
Publication Date: 2021.08.03 AWARE INC
  • US11080380B2 patent drawing
  • US11080380B2 patent drawing
  • US11080380B2 patent drawing

AI summary

A decentralized biometric identity authentication method utilizes biometrics captured on a mobile device to perform identity authentication against data that was registered as part of an identity proofing process and is thus trusted. The user registers his or her biometric using the user's mobile device and associates it with the user's electronic identity as part of a supervised identity proofing process, thus forming a proofed identity, and registers the proofed identity with a federated identity system. To later access the resources of the federated identity system, the user logs in with his or her biometrics. The methods described herein are useful, for example, in the travel, healthcare, and financial services fields.