Offline Biometric Validation via Smartphone Secure Element

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing biometric ID validation systems require internet access and central databases, making them unreliable and vulnerable to forged documents, and they often infringe on citizens' privacy and civil rights by handling sensitive data insecurely.

Innovation Solution

A standalone biometric ID validation system that uses a smartphone to store encrypted biometric data, allowing offline validation through a client-server application pair, where the smartphone's biometric data is used for secure, challenge-based authentication without internet access, ensuring data privacy and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a central database system is used for biometric validation, then validation can be performed online with external server access, but the system becomes vulnerable to security breaches, requires internet access, and infringes on citizen privacy

Engineering Contradiction:
Improvevalidation reliabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the biometric template from the central database and places it locally in the smartphone's secure element. This extraction eliminates the need for continuous connection to external databases, removing the security vulnerability associated with centralized storage while maintaining validation capability offline.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an encrypted biometric template as an intermediary between the citizen's biometric data and the validation system. This intermediary allows verification without exposing the actual biometric data, solving the contradiction between validation capability and privacy/security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If a central database system is used for biometric validation, then centralized control and management is achieved, but the system requires internet access and becomes unreliable without external connectivity

Engineering Contradiction:
Improvesystem centralizationVSAvoidoffline operation capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the validation system into two parts: a lightweight client application in the smartphone that stores encrypted biometric templates, and a minimal server component that only needs to verify proofs. This segmentation enables offline operation while maintaining system control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the essential validation functionality from the central database and embeds it in the smartphone's secure element. This extraction allows the system to operate independently of external servers, achieving reliability without internet access while maintaining centralized security management through the secure element.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If traditional ID documents are used for identification, then the process is simple and accessible, but the system is vulnerable to forged documents and look-alike phot IDs

Engineering Contradiction:
Improveidentification accessibilityVSAvoiddocument authenticity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical/document-based identification system with a biometric-based system. Instead of verifying physical documents, the system uses unique biometric templates stored in secure elements, eliminating forgery vulnerability while maintaining ease of use through automated biometric capture.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the fundamental parameter of identification from document-based visual verification to biometric template matching. This parameter change transforms the system from being vulnerable to document forgery to being secured by the uniqueness and non-replicability of biometric data.

Inventive Principle:
Principle #35Parameter changes

4Device complexity

If biometric data is stored in a central database, then centralized management is achieved, but citizen privacy and civil rights are infringed upon

Engineering Contradiction:
Improvedata management centralizationVSAvoidprivacy infringement
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts biometric templates from centralized databases and stores them locally in citizens' smartphones within secure elements. This extraction gives citizens control over their own biometric data, eliminating privacy infringement while maintaining centralized management capabilities through the secure element's cryptographic controls.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent inverts the traditional model where the system stores citizen data, and instead implements a model where citizens store their own encrypted biometric templates in secure elements. This inversion transfers control and ownership of biometric data to citizens, fundamentally addressing privacy concerns.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentEP4283499A1Data base terminator
Publication Date: 2023.11.29 ADELAIDE VIDAL
  • EP4283499A1 patent drawingFigure 1~2
  • EP4283499A1 patent drawingFigure 3~4
  • EP4283499A1 patent drawingFigure 5~7

AI summary

DBT - Data base terminator is an invention to avoid the need for internet and biometric central databases to validate biometric Identity. ABSTRACT; DBT is an invention for automatic biometric Identity Identification, hands free, offline, to facilitating access control to sensitive locations, Premises and computer systems without the need to access databases public or Private. The innovation and uniqueness of this solution is that the biometric information of the user is custodied by the user all the time. A DBT client application installed in a wireless device held by the user, stores all the biometric data necessary for a biometric identification. Thus the validation process is done hands free automatically without need of : • Internet access. • Access to external databases. • Biometric Identity validation done totally hands free, off line. The DBT uses three components: ● A client application, DBT Client, that the user can download from any Appstore google Play to his/her computer or wireless Watch/Phone device . ● A server application, DBT Server, that detects the presence of the user, establish a secure VPN communication and checks user stored biometric data with biometrics captured. ● A Digital Token ID containing user's encrypted biometric Data that is used to match captured user's biometric data. When User Cell Phone with a client DBT application, enters in the DBT Server field of Action the following sequence of events happen: 1. User Cell DBT client is controlled if it is as an authorized member. 2. If it's an authorized DBT member a challenge ID Protocol (VPN) is established between Cell phone DBT client app and Access control DBT Server app. 3. User Cell DBT Client app is validated, and a VPN secure communication is established. 4. DBT Server asks DBT Client to identify user holder. 5. DBT Client app in the Citizen Cell Phone sends the ID HashTag template of user's biometrics data (Face, Finger, others) to the DBT server Totem. 6. DBT Server totem Activates camera or other biometric scanner to capture User biometrics. 7. Biometric match is processed with user biometric ID HashTag. 8. If Match is Ok User ID is validated and access is granted.