Secure Element Biometric Authentication with Localized Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing biometric authentication systems face challenges in securely storing and managing biometric data, as well as preventing unauthorized access to encrypted biometric features and cryptographic keys, which can lead to identity theft and database cross-matching attacks.
Innovation Solution
A method and system that store an encrypted identifier based on an individual's secret, allowing the individual to prove knowledge of the identifier without revealing the secret, using encryption and decryption keys derived from biometric data, and employing a zero-knowledge protocol to authenticate without exposing sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric data is stored in encrypted form in a database, then privacy is protected and database cross-matching attacks are avoided, but if cryptographic keys are broken, hackers can obtain the biometric features and steal identities
Solution Approach 1:
The patent extracts the biometric template from the centralized database and stores it locally in a secure element within the authentication device. This eliminates the single point of failure in centralized databases and prevents database cross-matching attacks, as each device has its own isolated copy of the biometric template that cannot be used to compromise other devices.
Solution Approach 2:
The patent introduces a secure element as an intermediary between the biometric sensor and the authentication logic. This secure element acts as a trusted mediator that protects the biometric template and cryptographic keys, allowing authentication to proceed without exposing sensitive data to potential hackers while maintaining system security.
2Ease of operation
If biometric features are used for authentication, then users do not need to memorize or write down passwords, but biometric data cannot be replaced if compromised and secrets must be renewed
Solution Approach 1:
The patent implements dynamic secret renewal by allowing the biometric template to be updated periodically or when security compromises are detected. The secure element can generate new cryptographic keys and update the biometric template without requiring physical replacement of the authentication device, thus maintaining both convenience and security over time.
Solution Approach 2:
The patent enables parameter changes in the cryptographic system by allowing the secure element to generate new keys and update encryption parameters. This permits the system to renew secrets and improve security protocols without changing the fundamental biometric authentication mechanism, maintaining user convenience while enhancing security.
3Productivity
If encrypted biometric features are stored centrally, then authentication can be performed efficiently, but the system becomes vulnerable to database breaches and cross-matching attacks
Solution Approach 1:
The patent segments the authentication system into distributed components, with each authentication device containing its own secure element with localized biometric templates. This segmentation eliminates the centralized database vulnerability while maintaining authentication efficiency, as each device independently verifies biometric data without needing to query a central database.
Solution Approach 2:
The patent transitions from a centralized two-dimensional database model to a distributed three-dimensional architecture where biometric templates exist in multiple locations (different devices) with different access permissions. This dimensional change prevents cross-matching attacks while maintaining efficient local authentication capabilities.
Data Source
AI summary
The present invention relates to a method of authenticating an individual (321) at an authenticating device (311) and an authenticating system for authenticating an individual. A basic idea of the present invention is to store, at a device or a system with which an individual wishes to authenticate herself, one or more data structures each comprising a value based on an identifier pertaining to the individual and an encrypted copy of the identifier. When the individual wants to authenticate herself, she contacts the authenticating device whereby a request is made to attain the encrypted identifier included in a specific data structure stored at the authenticating device. The individual subsequently provides proof to the authenticating device that she actually knows the identifier.


