Offline Biometric Validation via Smartphone Secure Element
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing biometric ID validation systems require internet access and central databases, making them unreliable and vulnerable to forged documents, and they often infringe on citizens' privacy and civil rights by handling sensitive data insecurely.
Innovation Solution
A standalone biometric ID validation system that uses a smartphone to store encrypted biometric data, allowing offline validation through a client-server application pair, where the smartphone's biometric data is used for secure, challenge-based authentication without internet access, ensuring data privacy and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a central database system is used for biometric validation, then validation can be performed online with external server access, but the system becomes vulnerable to security breaches, requires internet access, and infringes on citizen privacy
Solution Approach 1:
The patent extracts the biometric template from the central database and places it locally in the smartphone's secure element. This extraction eliminates the need for continuous connection to external databases, removing the security vulnerability associated with centralized storage while maintaining validation capability offline.
Solution Approach 2:
The patent introduces an encrypted biometric template as an intermediary between the citizen's biometric data and the validation system. This intermediary allows verification without exposing the actual biometric data, solving the contradiction between validation capability and privacy/security protection.
2Device complexity
If a central database system is used for biometric validation, then centralized control and management is achieved, but the system requires internet access and becomes unreliable without external connectivity
Solution Approach 1:
The patent segments the validation system into two parts: a lightweight client application in the smartphone that stores encrypted biometric templates, and a minimal server component that only needs to verify proofs. This segmentation enables offline operation while maintaining system control.
Solution Approach 2:
The patent extracts the essential validation functionality from the central database and embeds it in the smartphone's secure element. This extraction allows the system to operate independently of external servers, achieving reliability without internet access while maintaining centralized security management through the secure element.
3Ease of operation
If traditional ID documents are used for identification, then the process is simple and accessible, but the system is vulnerable to forged documents and look-alike phot IDs
Solution Approach 1:
The patent replaces the mechanical/document-based identification system with a biometric-based system. Instead of verifying physical documents, the system uses unique biometric templates stored in secure elements, eliminating forgery vulnerability while maintaining ease of use through automated biometric capture.
Solution Approach 2:
The patent changes the fundamental parameter of identification from document-based visual verification to biometric template matching. This parameter change transforms the system from being vulnerable to document forgery to being secured by the uniqueness and non-replicability of biometric data.
4Device complexity
If biometric data is stored in a central database, then centralized management is achieved, but citizen privacy and civil rights are infringed upon
Solution Approach 1:
The patent extracts biometric templates from centralized databases and stores them locally in citizens' smartphones within secure elements. This extraction gives citizens control over their own biometric data, eliminating privacy infringement while maintaining centralized management capabilities through the secure element's cryptographic controls.
Solution Approach 2:
The patent inverts the traditional model where the system stores citizen data, and instead implements a model where citizens store their own encrypted biometric templates in secure elements. This inversion transfers control and ownership of biometric data to citizens, fundamentally addressing privacy concerns.
Data Source
Figure 1~2
Figure 3~4
Figure 5~7
AI summary
DBT - Data base terminator is an invention to avoid the need for internet and biometric central databases to validate biometric Identity. ABSTRACT; DBT is an invention for automatic biometric Identity Identification, hands free, offline, to facilitating access control to sensitive locations, Premises and computer systems without the need to access databases public or Private. The innovation and uniqueness of this solution is that the biometric information of the user is custodied by the user all the time. A DBT client application installed in a wireless device held by the user, stores all the biometric data necessary for a biometric identification. Thus the validation process is done hands free automatically without need of : • Internet access. • Access to external databases. • Biometric Identity validation done totally hands free, off line. The DBT uses three components: ● A client application, DBT Client, that the user can download from any Appstore google Play to his/her computer or wireless Watch/Phone device . ● A server application, DBT Server, that detects the presence of the user, establish a secure VPN communication and checks user stored biometric data with biometrics captured. ● A Digital Token ID containing user's encrypted biometric Data that is used to match captured user's biometric data. When User Cell Phone with a client DBT application, enters in the DBT Server field of Action the following sequence of events happen: 1. User Cell DBT client is controlled if it is as an authorized member. 2. If it's an authorized DBT member a challenge ID Protocol (VPN) is established between Cell phone DBT client app and Access control DBT Server app. 3. User Cell DBT Client app is validated, and a VPN secure communication is established. 4. DBT Server asks DBT Client to identify user holder. 5. DBT Client app in the Citizen Cell Phone sends the ID HashTag template of user's biometrics data (Face, Finger, others) to the DBT server Totem. 6. DBT Server totem Activates camera or other biometric scanner to capture User biometrics. 7. Biometric match is processed with user biometric ID HashTag. 8. If Match is Ok User ID is validated and access is granted.