Frictionless Biometric Identification via Split-Token Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identification methods using biometrics often require complex and insecure mechanisms to ensure data confidentiality and controlled use, which can infringe on individual privacy and create friction in the identification process.
Innovation Solution
A method and system that utilize a token containing an encrypted biometric template, split into two parts, where one part is stored on a mobile terminal and the other on a server database, allowing for frictionless identification by merging and decrypting the token during access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric data is stored centrally in a database to enable identification, then identification functionality is achieved, but data security and privacy protection deteriorate due to centralized storage vulnerabilities
Solution Approach 1:
The patent divides the biometric data storage system into multiple distributed nodes across a blockchain network. Each node holds a copy of the biometric template, eliminating centralized storage vulnerabilities. The biometric data is encrypted and distributed across multiple blocks in the blockchain, so no single point of failure exists. This segmentation resolves the contradiction by maintaining identification functionality through distributed access while improving data security through elimination of centralized storage risks.
2Reliability
If complex security mechanisms are implemented to protect biometric data, then data confidentiality is improved, but system complexity and operational friction increase
Solution Approach 1:
The patent introduces a blockchain network as an intermediary layer between biometric data storage and access control. The blockchain's inherent cryptographic security mechanisms (hash functions, digital signatures, consensus protocols) automatically enforce data confidentiality without requiring additional complex security layers. Smart contracts act as automated intermediaries that manage access rights and verification processes, reducing the need for manual security management and lowering operational complexity while maintaining strong confidentiality guarantees.
3Measurement precision
If traditional biometric verification processes are used, then identification accuracy is achieved, but user convenience deteriorates due to required user actions and friction
Solution Approach 1:
The patent implements a self-service identification system where the blockchain network automatically performs biometric verification without requiring active user participation. The system autonomously retrieves stored biometric templates from the blockchain, compares them with presented biometric data, and executes access control decisions through smart contracts. This eliminates the need for users to manually authenticate or interact with complex verification processes, maintaining high identification accuracy while dramatically improving ease of operation through automated, frictionless verification.
Data Source
Figure 1~2
Figure 3~4
AI summary
A method for identifying an individual based on biometric data within a system comprising an access control device (5), an open-access terminal (2) and a server (3) containing an application for signing and encrypting a biometric model, such that it comprises at least the following steps: - Enrolling an individual on an enrolment device (2) and acquiring the biometric data of the individual, - Transmitting said biometric data to said server (3), which generates a biometric model M, - The server (3), via the application for signing and encrypting a biometric model, signs and encrypts the biometric model and generates a token containing at least said biometric model M and identification data, - Dividing the encrypted token into at least two parts Τ1, T2, - Transmitting a first part of the token Τ1 (107) for storage (13) on a mobile terminal (1) of the individual and a second part of the token T2 (105) to a database (33) of a server (3) that is separate from the storage (13), - Checking the identity data of the individual, - Detecting (201) the mobile terminal of the individual using the access control device (5), - Pairing the detected mobile terminal with the access control means, - Recovering the first part of the token Τ1 (202) through frictionless communication and the second part of the token T2 (205), and then fusing (206) the two parts of the token for the purpose of recovering the initial token T, decrypting the token and verifying its signature, and returning the corresponding biometric model (206), - Acquiring biometric data of the individual, comparing the biometric data with the biometric model and triggering the opening of the access control means if the data correspond (207).