Digital Rights Management Platform for Biometric Data Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Individuals have limited control over how their biometric data is used, stored, and shared when provided for identity verification, as entities may access and utilize this data without consent or restrictions.

Innovation Solution

A digital rights management (DRM) platform generates biometric templates from user data, allowing users to set access control data specifying permitted time periods for authentication, thereby limiting entity access and managing the use of their biometric information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If biometric data is provided for identity verification, then identity verification efficiency is improved, but user control over data usage is worsened

Engineering Contradiction:
Improveidentity verification efficiencyVSAvoiduser control over data usage
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent segments biometric data into two distinct components: biometric templates (stored locally on user devices) and authentication data (held by verification entities). This segmentation allows efficient verification while maintaining user control, as the template remains with the user and cannot be accessed or misused by third parties.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where the user's device acts as a mediator between the biometric data and verification entities. The device generates authentication data locally using the stored template and transmits only this derived data for verification, preventing direct access to the original biometric template while enabling efficient authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If biometric data is stored and accessed by entities, then authentication capability is improved, but data security and privacy are worsened

Engineering Contradiction:
Improveauthentication capabilityVSAvoiddata security and privacy risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the essential authentication capability from the original biometric data by generating a derived authentication data set that contains only the necessary verification information. This extracted data can be stored and accessed by entities for authentication purposes without exposing the original biometric template, thereby maintaining security and privacy.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a functional copy of the biometric template in the form of authentication data that can be used for verification purposes. This copy contains the necessary information for authentication but lacks the sensitivity and identifiability of the original biometric data, reducing security and privacy risks while maintaining authentication capability.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11977611B2Digital rights management platform
Publication Date: 2024.05.07 MASTERCARD INT INC
  • US11977611B2 patent drawing
  • US11977611B2 patent drawing
  • US11977611B2 patent drawing

AI summary

Various implementations described herein may refer to a digital rights management (DRM) platform. In one implementation, a method may include receiving first biometric data associated with a user. The method may also include generating first biometric templates based on the first biometric data using a DRM platform. The method may further include receiving access control data from the user, where the access control data includes data indicating time periods during which requestors are permitted to authenticate the user using the first biometric templates. The method may additionally include transmitting the first biometric templates and the access control data to the requestors using the DRM platform, where the first biometric templates are configured to be compared to second biometric templates based on the access control data, and where the second biometric templates are configured to be generated using the DRM platform based on second biometric data associated with the user.