Gateway Application for Biometric Data Obfuscation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As online commerce grows, sophisticated identity fraud techniques using biometric data become more prevalent, and consumers face challenges in protecting their biometric data from unauthorized collection, often without even realizing it, especially by seemingly innocuous software applications on their devices.

Innovation Solution

A gateway application on user devices determines the authorization of software applications to access biometric data from sensors, obfuscating unauthorized biometric data to prevent unauthorized access while allowing access to necessary sensor data for functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software applications are granted access to sensor data, then application functionality is enabled, but biometric data may be accessed without user authorization

Engineering Contradiction:
Improveapplication functionalityVSAvoidunauthorized biometric data access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a gateway application as an intermediary layer between sensor applications and the operating system. This gateway intercepts sensor data requests, analyzes them for biometric content, and selectively blocks or permits access based on user-defined policies. The gateway acts as a mediator that enables legitimate application functionality while preventing unauthorized biometric data access, thus resolving the contradiction between ease of operation and harmful factors.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If biometric data is protected through strict access control, then unauthorized access is prevented, but legitimate application functionality may be restricted

Engineering Contradiction:
Improveunauthorized biometric data accessVSAvoidapplication functionality
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access control where the gateway application continuously monitors sensor data requests and adjusts access permissions in real-time based on the specific application, data type, and user policies. Rather than static blocking, the system dynamically evaluates each request, allowing legitimate applications to access necessary biometric data while blocking unauthorized access. This dynamic approach maintains adaptability for legitimate uses while providing strong protection against unauthorized access.

Inventive Principle:
Principle #15Dynamics

3Object-affected harmful factors

If all sensor data is blocked to prevent biometric data collection, then biometric data protection is maximized, but application functionality is compromised

Engineering Contradiction:
Improvebiometric data protectionVSAvoidapplication functionality
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent applies local quality by treating different types of sensor data differently. The gateway application analyzes sensor data requests and applies selective filtering based on the specific data type and application context. Non-biometric sensor data is permitted to pass through freely, maintaining full application functionality for legitimate purposes. Only data identified as containing biometric information is subject to access control, thus providing targeted protection without compromising overall application productivity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11947701B2Techniques for preventing malicious use of biometric data
Publication Date: 2024.04.02 T MOBILE US INC
  • US11947701B2 patent drawing
  • US11947701B2 patent drawing
  • US11947701B2 patent drawing

AI summary

Described herein are techniques for preventing software applications from gaining access to unauthorized biometric data in accordance with user preferences. In some embodiments, a software application requests access to sensor data collected by a sensor installed on a user device via a gateway application installed on the user device. Upon receipt of the request, the gateway application determines what types of biometric data the software application is authorized to obtain within the sensor data. The gateway application then identifies biometric data that is present within the sensor data. The sensor data is then altered such that biometric data that the software application is not authorized to obtain is obfuscated. Once the sensor data has been altered, the software application is provided access to that altered sensor data.