Edge Data Packages Using Biometrics for Tamper-Resistant Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Obtaining authenticating information is an inherently insecure process, making it challenging to ensure secure data processing and access control.
Innovation Solution
Scanning biometric signatures and device identifiers to generate encrypted user data, using digital keys for access control, and verifying the data with security tokens to ensure integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional authenticating information gathering methods are used, then the process is simple and straightforward, but the security is inherently insecure and vulnerable to attacks
Solution Approach 1:
The patent segments the authentication process into multiple independent components: biometric data collection, device identifier extraction, cryptographic key generation, data encryption, and security token verification. Each component operates independently and contributes to the overall security, transforming a single vulnerable process into a multi-layered security architecture where compromise of one element does not jeopardize the entire system
Solution Approach 2:
The patent creates a composite authentication mechanism by combining multiple types of data (biometric signatures, device identifiers, cryptographic keys) and multiple security layers (encryption, digital signatures, security tokens). This composite approach integrates heterogeneous security mechanisms into a unified authentication system that leverages the strengths of each component while mitigating their individual weaknesses
2Reliability
If biometric scanning and encryption are implemented, then data security and integrity are enhanced, but the processing time and computational resources increase
Solution Approach 1:
The patent performs preliminary actions by pre-generating cryptographic key pairs, pre-encrypting data packages, and pre-verifying security tokens before actual data transmission or access requests. Biometric data is scanned and converted into cryptographic keys in advance, and data packages are encrypted and signed beforehand, so that when access is needed, the verification process is significantly faster since the heavy computational work has already been completed
Solution Approach 2:
The patent creates cryptographic copies and representations of data: digital signatures that copy the essence of data integrity, encrypted versions that copy data in protected form, and security tokens that copy authentication credentials. These copies enable efficient verification without requiring repeated access to original sensitive data, reducing processing time for authentication while maintaining security
3Reliability
If multiple digital keys and security tokens are used, then access control and data protection are strengthened, but the system complexity and key management overhead increase
Solution Approach 1:
The patent merges multiple security functions into unified structures: data packages that combine encrypted data with embedded security tokens, and authentication systems that integrate biometric verification with cryptographic key management. This consolidation reduces the number of separate components that need to be managed independently while maintaining comprehensive access control through integrated security mechanisms
Data Source
AI summary
Disclosed are example methods, systems, and devices that allow for secure data processing using data packages generated by edge devices. A computing device can generate a biometric signature from a scan of a physical feature of a user and encrypt user data based on the biometric signature and a device identifier to produce encrypted user data decryptable with a first digital key. The first digital key can be transmitted to a first computing system to receive a security token indicating validity of at least part of the user data. The encrypted user data and security token can be stored in a data package such that alterations invalidate the token. A second digital key corresponding to the data package can be generated and transmitted with the data package to a second computing system to provide a service.


