Zero-Knowledge Biometric Authentication Without Template Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Contemporary authentication systems face challenges in ensuring robust and trustworthy remote verification of user presence, leading to privacy risks, data breaches, and scalability issues due to the storage of sensitive biometric data, which can result in false negatives or positives.
Innovation Solution
A Zero Knowledge Proof (ZKP) protocol that authenticates users without storing their biometric templates, using a private key derived from biometric data and a stable key algorithm, ensuring secure and indisputable remote verification by relying on a public-key infrastructure (PKI) without storing biometric data on remote servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric templates are stored and managed by entities for authentication, then user verification capability is improved, but privacy risks and data breach vulnerabilities increase
Solution Approach 1:
The patent extracts and removes the biometric template storage function from the authentication system. Instead of storing biometric templates, the system uses biometric data only to generate cryptographic keys locally on the user's device. The biometric data itself is never stored or transmitted, eliminating the vulnerability source while maintaining verification capability through cryptographic proof.
Solution Approach 2:
The patent introduces cryptographic keys as an intermediary between biometric data and authentication verification. The biometric data generates cryptographic keys locally, which then serve as the medium for authentication proofs. This intermediary eliminates the need to store sensitive biometric templates while maintaining reliable user verification through cryptographic mechanisms.
2Reliability
If biometric data is stored for authentication purposes, then authentication reliability is improved, but the attack surface for malicious actors increases
Solution Approach 1:
The patent removes biometric data storage from the system architecture entirely. Biometric data is used only transiently to generate cryptographic keys on the user's device, then discarded. This extraction of the storage function eliminates the attack surface associated with stored biometric databases while maintaining authentication reliability through cryptographic key pairs.
3Reliability
If remote authentication systems store user biometric data, then verification trustworthiness is improved, but false positives and false negatives increase
Solution Approach 1:
The patent replaces the mechanical/biological comparison system (comparing stored biometric templates with new biometric inputs) with a cryptographic system. The verification process uses cryptographic key validation and zero-knowledge proofs instead of direct biometric template matching, eliminating errors associated with biometric template storage and comparison while maintaining high verification trustworthiness.
4Reliability
If entities manage and store biometric templates, then user identity verification is improved, but overhead costs and compliance burdens increase
Solution Approach 1:
The patent implements self-service authentication where the user's device independently generates and manages cryptographic keys using local biometric data. No external entity needs to store, manage, or protect biometric templates. The system performs identity verification through cryptographic proofs without requiring centralized biometric database management, eliminating compliance burdens and data management overhead.
Data Source
AI summary
Systems and methods for performing zero knowledge proofs to prove a user's possession of secret data and/or biometric data without exposing such data. The methods can include receiving a certificate signing request and biometric data associated with a user; creating a stable key based at least in part on the biometric data; creating a private key based at least in part on the stable key; transmitting the private key to the user device for local storage thereon; creating a public key based at least in part on the private key; and forwarding the certificate signing request to an issuer.


