Encrypted Biometric Data Storage with User-Controlled Decryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing biometric data storage systems face challenges in complying with privacy laws and regulations, as they often require direct access to the data, making them vulnerable to theft and compelled production to third parties, and users are hesitant to store sensitive biometric data due to privacy concerns.
Innovation Solution
A system and method for encrypting biometric data with multiple encryption keys, where the user possesses one key, ensuring only the user can decrypt the data, and storing it on a public blockchain architecture to maintain privacy and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric data is stored in a database for verification purposes, then identity verification capability is improved, but privacy security and protection from compelled production deteriorate
Solution Approach 1:
The system segments biometric data into multiple encrypted components stored separately in the database. Each component alone is insufficient for identity verification, but together they enable verification while maintaining privacy. This segmentation prevents compelled production of usable biometric data while preserving verification capability.
Solution Approach 2:
The system introduces encrypted biometric data as an intermediary between the original biometric data and storage. This intermediary form allows database storage and verification operations while acting as a barrier that prevents direct access to usable biometric data, thereby protecting against compelled production and privacy breaches.
2Object-affected harmful factors
If hashed biometric data is stored to comply with privacy regulations, then direct access security is improved, but the system still retains access to decryption keys creating vulnerability
Solution Approach 1:
The system extracts and removes decryption keys from the database environment entirely. Keys are stored separately in secure key management systems outside the database's control sphere. This extraction ensures that even if the database is compromised or subjected to compelled production, the stored encrypted biometric data remains inaccessible without the external keys.
3Ease of operation
If encryption keys are stored within the verification system for data access, then data retrieval capability is improved, but vulnerability to theft and compelled production increases
Solution Approach 1:
The system moves key storage from the traditional single-dimension database environment to a separate dimensional space in secure key management systems. This spatial and organizational separation maintains retrieval capability through defined access protocols while adding a dimensional barrier that protects against theft and compelled production of keys along with encrypted data.
Data Source
AI summary
A computer system and method for storage and retrieval of encrypted biometric data which includes a biometric data intake device that selectively intakes original biometric data from a user and communicates with a biometric data management system. The biometric data management system has a resident data storage or a remote storage in communication therewith for the selective storage and retrieval of the encrypted biometric data. The system and method allow a user to originally encrypt biometric data such that the user solely possesses one of the necessary keys for later decryption of the stored and encrypted biometric data. The system and method will then doubly encrypt and store the user's biometric data in such a secure manner that the data can be stored on a public blockchain architecture, if desired. Full decryption of the original user biometric data for identity verification can only be performed with access to the user key.


