Fuzzy Extractor for Biometric Authentication Privacy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Biometric authentication systems face challenges due to the inability to change biometric characteristics and variability in biometric data, requiring strong privacy guarantees and error-correcting codes specific to each parameter set, limiting their universality and effectiveness.
Innovation Solution
A cryptographic primitive using a fuzzy extractor with a Hamming Distance-based error threshold, enabling universal application across any biometric type or length with any error threshold, and providing privacy guarantees through a single algorithm for biometric authentication and key exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If biometric characteristics are used for authentication, then user authentication can be performed without passwords, but the inability to change biometric characteristics creates security risks if compromised
Solution Approach 1:
The patent extracts the biometric data from direct authentication use and instead uses it to generate cryptographic keys through a fuzzy extractor. The biometric data itself never leaves the user device, only the generated keys are used for authentication, separating the immutable biometric trait from the authentication process.
Solution Approach 2:
The fuzzy extractor acts as an intermediary between the biometric data and the authentication system. It transforms the biometric input into cryptographic keys through a controlled process that includes error correction and privacy protection, mediating the interaction between the immutable biometric trait and the authentication requirement.
2Measurement precision
If traditional error-correcting codes are used for biometric variability, then authentication accuracy improves, but different parameter sets require different codes limiting universality
Solution Approach 1:
The patent implements a universal fuzzy extractor that works with any biometric type (fingerprints, iris, voice, genomic data) and any error threshold. The same algorithmic framework handles all biometric modalities by adjusting parameters like the error threshold δ, eliminating the need for different error-correcting codes for different biometric types.
Solution Approach 2:
The patent changes the approach from using different error-correcting codes to using a single fuzzy extractor algorithm with adjustable parameters. The error threshold δ and polynomial degree k can be modified to accommodate different biometric variabilities, providing adaptability without requiring fundamentally different algorithms for each case.
3Productivity
If biometric data is stored for authentication, then authentication can be performed, but privacy is compromised as biometric characteristics cannot be changed if leaked
Solution Approach 1:
The patent extracts only the essential authentication capability from the biometric data while leaving the actual biometric template secure. The fuzzy extractor generates cryptographic keys from the biometric input without storing the raw biometric data on the server, extracting authentication functionality while preserving privacy.
Solution Approach 2:
The patent creates a cryptographic copy (the authentication key) from the biometric data that can be used for authentication without exposing the original biometric information. This copy serves the authentication function while the original biometric data remains private and unchanged on the user device.
Data Source
AI summary
A method of biometric authentication includes receiving a biometric input from a user for authentication of the user to access a system. The method includes receiving a set of elements of a field and a random number from an authentication server via a network. The method further includes decoding the biometric input based on the set of elements to generate a polynomial. The method also includes generating a signature key based on the polynomial. The method includes signing the random number with the signature key. The method includes sending the signed random number to the authentication server. The method further includes restricting access to the system until the user is authenticated by the authentication server. The method also includes permitting access to the system in response to receiving an authentication message from the authentication server.


