Voronoi Cell Hash Authentication for Biometric Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Biometric recognition systems face security issues due to the potential misuse of unique user biometric data, such as facial or fingerprint images, which can be compromised or reused across different services, leading to unauthorized access.
Innovation Solution
A method involving the use of Voronoi cell identifiers and knowledge-based secondary information to generate a hash, which is transmitted for verification, ensuring secure authentication by preventing the reuse of biometric data across services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If biometric data is stored and used for authentication across multiple services, then authentication convenience is improved, but security risk increases due to potential data breach and unauthorized reuse
Solution Approach 1:
The patent segments the authentication process by separating biometric template processing from actual authentication. Biometric templates are processed locally on user devices to generate service-specific authentication data, while only hashed verification data is transmitted to servers. This segmentation prevents centralization of biometric data, reducing security risks while maintaining authentication convenience across multiple services.
Solution Approach 2:
The patent introduces hash functions and service-specific identifiers as intermediaries between biometric data and authentication verification. Instead of storing or transmitting raw biometric data, the system uses hashed representations combined with service identifiers. This intermediary layer ensures that even if authentication data is breached, the original biometric information cannot be reconstructed, thereby reducing security risks while preserving cross-service authentication functionality.
2Measurement precision
If raw biometric data is transmitted for verification, then authentication accuracy is improved, but security risk increases due to exposure of sensitive information
Solution Approach 1:
The patent extracts only the essential verification information needed for authentication while leaving the sensitive biometric data on the user device. Specifically, the system extracts service-specific authentication hashes from biometric templates locally, and only transmits these extracted hashes to servers for verification. This extraction approach maintains authentication accuracy by preserving the essential verification capability while eliminating the security risk of transmitting raw biometric data.
Solution Approach 2:
The patent uses disposable, service-specific authentication tokens (hashed data combined with service identifiers) instead of reusing permanent biometric data for each authentication attempt. Each service receives a unique hashed representation that is valid only for that specific service verification. This approach ensures authentication accuracy for each service while preventing the security risk of biometric data exposure, as the hashed tokens cannot be reverse-engineered to reveal original biometric information.
Data Source
AI summary
Methods, systems, and media for secure authentication of users using one or more biometric recognition systems are provided. In some embodiments, the method comprises: receiving an indication that a biometric identifier is to be used to authenticate a user to a service; receiving (i) the biometric identifier of the user from a capture device and (ii) knowledge-based secondary information associated with the user from an input device; determining a Voronoi cell identifier that corresponds to the biometric identifier; calculating a hash of the Voronoi cell identifier and the knowledge-based secondary information; transmitting the hash to a server device for verification; in response to transmitting the hash to the server device, receiving a response indicating whether the hash matches a previously stored hash that was stored in the server device; and determining whether to automatically authenticate the user to the service based on the response from the server device.


