Biometric Identity Verification with Secure Local Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional identity verification methods are vulnerable to attacks and data leakage during the calculation and transmission of intermediate results, compromising security.
Innovation Solution
The method involves obtaining biometric feature images via an encrypted connection, extracting biometric feature information in a local secure area, encrypting it, and transmitting the encrypted information to a verification server through a network connection, ensuring security by performing encryption before transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric feature information is transmitted in plaintext for identity verification, then verification efficiency is improved, but security is compromised due to vulnerability to attacks by malicious intermediaries
Solution Approach 1:
The patent applies preliminary action by performing encryption on biometric feature information before transmission to the verification server. The encryption operation is executed in advance during the data preparation phase, ensuring that sensitive information is protected before entering the transmission channel, thus preventing attacks by malicious intermediaries without affecting verification efficiency
Solution Approach 2:
The patent introduces encryption as an intermediary mechanism between the biometric feature information and the transmission channel. This encryption layer acts as a mediator that protects the original data from being accessed or tampered with during transmission, allowing secure communication without requiring changes to the verification server or protocol
2Reliability
If biometric feature information is encrypted before transmission, then security is improved, but processing complexity increases
Solution Approach 1:
The patent applies segmentation by dividing the system into distinct functional modules: a client device for encryption and data preparation, a transmission channel for secure data transfer, and a verification server for decryption and verification. This modular segmentation isolates the encryption complexity to the client side, preventing it from propagating through the entire system
Solution Approach 2:
The patent implements self-service by enabling the client device to autonomously perform encryption operations on biometric feature information before transmission. The client device independently manages the encryption process without requiring complex coordination with the verification server, thereby containing system complexity within a manageable scope
3Measurement precision
If intermediate calculation results are transmitted for verification, then verification accuracy is improved, but vulnerability to attacks increases
Solution Approach 1:
The patent applies preliminary anti-action by preemptively encrypting intermediate calculation results before they leave the client device. This pre-encryption measure counteracts potential attacks by malicious intermediaries who might otherwise intercept or tamper with the data during transmission, allowing accurate verification without exposing sensitive intermediate results
Data Source
AI summary
This application relates to an identity verification method performed at a computer device. The method includes: obtaining a biometric feature image of an object; performing living body detection on the biometric feature image in a secure running environment of the computer device; in accordance with a determination that the object is a living body, extracting biometric feature information from the biometric feature image and encrypting the biometric feature information in the secure running environment of the computer device; transmitting the encrypted feature information to an application in a normal running environment of the computer device for performing identity verification of the object; and receiving, from the application, an identity verification result of the object, the identity verification result being obtained after the encrypted feature information is decrypted and verified.


