Secure Element Biometric Authentication with Localized Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing biometric authentication systems face challenges in securely storing and managing biometric data, as well as preventing unauthorized access to encrypted biometric features and cryptographic keys, which can lead to identity theft and database cross-matching attacks.

Innovation Solution

A method and system that store an encrypted identifier based on an individual's secret, allowing the individual to prove knowledge of the identifier without revealing the secret, using encryption and decryption keys derived from biometric data, and employing a zero-knowledge protocol to authenticate without exposing sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric data is stored in encrypted form in a database, then privacy is protected and database cross-matching attacks are avoided, but if cryptographic keys are broken, hackers can obtain the biometric features and steal identities

Engineering Contradiction:
Improveprivacy protectionVSAvoididentity theft risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the biometric template from the centralized database and stores it locally in a secure element within the authentication device. This eliminates the single point of failure in centralized databases and prevents database cross-matching attacks, as each device has its own isolated copy of the biometric template that cannot be used to compromise other devices.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a secure element as an intermediary between the biometric sensor and the authentication logic. This secure element acts as a trusted mediator that protects the biometric template and cryptographic keys, allowing authentication to proceed without exposing sensitive data to potential hackers while maintaining system security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If biometric features are used for authentication, then users do not need to memorize or write down passwords, but biometric data cannot be replaced if compromised and secrets must be renewed

Engineering Contradiction:
Improveauthentication convenienceVSAvoidsecret renewability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic secret renewal by allowing the biometric template to be updated periodically or when security compromises are detected. The secure element can generate new cryptographic keys and update the biometric template without requiring physical replacement of the authentication device, thus maintaining both convenience and security over time.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent enables parameter changes in the cryptographic system by allowing the secure element to generate new keys and update encryption parameters. This permits the system to renew secrets and improve security protocols without changing the fundamental biometric authentication mechanism, maintaining user convenience while enhancing security.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If encrypted biometric features are stored centrally, then authentication can be performed efficiently, but the system becomes vulnerable to database breaches and cross-matching attacks

Engineering Contradiction:
Improveauthentication efficiencyVSAvoiddatabase breach vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authentication system into distributed components, with each authentication device containing its own secure element with localized biometric templates. This segmentation eliminates the centralized database vulnerability while maintaining authentication efficiency, as each device independently verifies biometric data without needing to query a central database.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a centralized two-dimensional database model to a distributed three-dimensional architecture where biometric templates exist in multiple locations (different devices) with different access permissions. This dimensional change prevents cross-matching attacks while maintaining efficient local authentication capabilities.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS8046589B2Renewable and private biometrics
Publication Date: 2011.10.25 KONINKLIJKE PHILIPS NV
  • US8046589B2 patent drawing
  • US8046589B2 patent drawing
  • US8046589B2 patent drawing

AI summary

The present invention relates to a method of authenticating an individual (321) at an authenticating device (311) and an authenticating system for authenticating an individual. A basic idea of the present invention is to store, at a device or a system with which an individual wishes to authenticate herself, one or more data structures each comprising a value based on an identifier pertaining to the individual and an encrypted copy of the identifier. When the individual wants to authenticate herself, she contacts the authenticating device whereby a request is made to attain the encrypted identifier included in a specific data structure stored at the authenticating device. The individual subsequently provides proof to the authenticating device that she actually knows the identifier.