Identity Cryptographic Chip Biometric Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity authentication technologies in decentralized systems, such as blockchain and IoT networks, face challenges in securely managing cryptographic keys, particularly in ensuring that keys are accessed only by authorized users and remain secure if lost.

Innovation Solution

An identity cryptographic chip (ICC) is used to receive biometric information, verify user identity, and encrypt and store user key pairs, ensuring that cryptographic operations can only be performed after successful identity authentication, thereby securing the storage and use of cryptographic keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cryptographic keys are stored in decentralized systems (blockchain, IoT), then user autonomy and system flexibility are improved, but security and control over key access deteriorate

Engineering Contradiction:
Improveuser autonomyVSAvoidkey access security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an identity cryptographic chip as an intermediary device between the user and the decentralized system. The chip securely stores biometric information and cryptographic keys, acting as a trusted mediator that enables user autonomy while maintaining security. The chip verifies user identity through biometric authentication before allowing key access, thus resolving the contradiction between user control and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If private keys are stored as data strings on computing devices, then ease of access and operation are improved, but vulnerability to copying and unauthorized access increases

Engineering Contradiction:
Improvekey accessibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements local quality by storing different types of information in different security zones within the identity cryptographic chip. Biometric information is stored in a secure element that is difficult to access, while cryptographic keys are stored in protected memory areas. This differentiated storage approach allows easy access for authorized operations while preventing copying and unauthorized access.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs preliminary biometric authentication before allowing any cryptographic key operations. The biometric template is pre-stored in the chip during initialization, and before each key access, the system verifies the user's biometric data against this template. This preliminary verification ensures that only authorized users can access the keys, preventing unauthorized access while maintaining ease of operation for legitimate users.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If cryptographic keys are made retrievable, then user convenience is improved, but security against loss and theft deteriorates

Engineering Contradiction:
Improvekey retrievabilityVSAvoidkey security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The identity cryptographic chip provides self-service recovery capabilities through secure backup mechanisms. The chip can generate backup copies of cryptographic keys and store them in protected locations or transmit them through secure channels. When a key is lost, the system can retrieve it through biometric verification without compromising the security of the primary key storage, thus balancing retrievability with security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11251941B2Managing cryptographic keys based on identity information
Publication Date: 2022.02.15 ADVANCED NEW TECHNOLOGIES CO LTD
  • US11251941B2 patent drawing
  • US11251941B2 patent drawing
  • US11251941B2 patent drawing

AI summary

Disclosed herein are methods, systems, and apparatus, including computer programs encoded on computer storage media, for managing cryptographic keys based on user identity information. One of the methods includes receiving biometric information associated with a user and a request to store a user key pair to a memory on an identity cryptographic chip (ICC); comparing the biometric information associated with the user with biometric information pre-stored in the memory as pre-stored biometric information; in response to determining that the biometric information associated with the user matches the pre-stored biometric information, encrypting the user key pair to provide an encrypted user key pair; and storing the encrypted user key pair to the memory.