Mobile App Biometric Data Encryption for Secure Identity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for identity verification at airports lack secure integration of mobile applications with identity verification processes, compromising the protection of passengers' personally identifiable information (PII) during transit.

Innovation Solution

A secure mobile application that encrypts biographic data and processes biometric data on the mobile device before communicating it to a security server for validation and biometric enrolment, ensuring the protection of PII throughout the process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If mobile applications are integrated into identity verification systems to enable self-service verification, then ease of operation and productivity are improved, but security and reliability of personally identifiable information (PII) in transit deteriorate

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The application performs preliminary actions by encrypting biographic data and hashing biometric data on the mobile device before transmission to the security server. This preliminary encryption and processing ensures that sensitive information is protected before it leaves the mobile device, resolving the contradiction by maintaining security while enabling self-service verification

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces encryption algorithms and hashing functions as intermediary mechanisms between the mobile application and the security server. These intermediaries transform sensitive data into protected forms (encrypted biographic data, hashed biometric data) during transmission, allowing seamless mobile integration while maintaining information security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If biometric data is transmitted to security servers for validation and enrolment, then verification accuracy is improved, but security and protection of PII during transit deteriorate

Engineering Contradiction:
Improvemeasurement precisionVSAvoidobject-affected harmful factors
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The patent extracts only the necessary processed forms of biometric data (hashed biometric data) for transmission to the security server, rather than transmitting raw biometric information. This extraction approach enables verification accuracy while minimizing security risks by removing sensitive personal identifiers from the transmission process

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The application transforms biometric data through hashing and encryption, changing its parameter state from raw, identifiable form to processed, protected form. This parameter transformation maintains the utility of biometric verification while eliminating the harmful factor of exposing sensitive personal information during transit

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP4510020A1Methods and systems for communicating with security servers
Publication Date: 2025.02.19 AMADEUS SAS
  • EP4510020A1 patent drawingFigure 1
  • EP4510020A1 patent drawingFigure 2
  • EP4510020A1 patent drawingFigure 3

AI summary

A method is provided for communicating with a security server performed by an application executing on a mobile device, including: receiving biographic and biometric data captured from a passport; encrypting the biographic data to generate encrypted biographic data; processing the biometric data to generate processed biometric data; communicating the encrypted biographic data and processed biometric data to the security server for submission to a validation operation; receiving a validation result message; in the event that the validation result message indicates success of the validation operation, receiving confirmation biometric data captured by the mobile device; communicating the confirmation biometric data to the security server for submission to a biometric enrolment operation; and receiving an enrolment result message indicating a result of the biometric enrolment operation.