System and method for biometric protocol standards

Inventors

Mather, Jonathan FrancisOthman, AsemStreit, ScottDumitran, IonutWood, Thomas

Assignees

Hoyos Labs Ip LtdVeridium IP Ltd

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-10536454-B2

Patent

Publication Date

2020-01-14

Expiration Date


Abstract

Secure communications are provided between a user computing device and a server computing device. An enrollment request is received from a user computing device that is configured via a distributed client software application, and is processed. The enrollment request is usable to enroll the user computing device in a network and includes an encrypted partial initial biometric vector associated with a user. An authentication request is processed that is subsequently received that includes an encrypted partial second biometric vector and that is associated with a user of the user computing device. A comparison of the encrypted partial initial biometric vector and the encrypted partial second biometric vector is performed, and a value representing the comparison is generated and transmitted to the user computing device. The user computing device is authenticated where the value is above a minimum threshold.

Core Innovation

The invention provides secure communication between a user computing device and a server computing device using biometric vector shares. A server processes an enrollment request received from a user computing device configured with a distributed client software application, where the request includes an encrypted first portion of a biometric vector associated with a user, and the encrypted first portion is stored on non-transitory processor readable media accessible by or part of the server computing device.

Subsequently, the server processes an authentication request received from the user computing device, where the request includes an encrypted second portion of the biometric vector. The encrypted second portion is less than the biometric vector, the first portion and the second portion are different, and the server performs a comparison as a function of an algorithm, including at least one matching operation in encrypted space as a function of one-way encryption, and generates a value representing the comparison.

The server transmits the comparison value to the user computing device, and authentication is determined based on whether the value is above a minimum threshold or below the minimum threshold. If the value is above the minimum threshold, the user computing device is authenticated; if the value is below the minimum threshold, the user computing device is not authenticated, thereby performing encrypted-space matching without transmitting the compared biometric portions themselves.

The disclosed framework further supports certificate-based enrollment and authentication handling, including determining that a certificate is current and not revoked, intrusion detection and replay prevention using cryptographic one-time tokens, access control based on role gathering rules, discretionary access control, and mandatory access control, along with auditing and assurance modules and certificate revocation and Time-to-Live (TTL) handling.

Claims Coverage

The document includes two independent claims: clm-00001 (method) and clm-00009 (system). Across these independent claims, there are four core inventive features involving encrypted portions of a biometric vector, encrypted-space matching using one-way encryption, and an authentication decision based on a minimum threshold, with dependent refinements for certificate handling, intrusion detection, and access control.

Encrypted biometric vector portions for enrollment and storage

The server processes an enrollment request including an encrypted first portion of a biometric vector associated with a user, where the first portion is less than the biometric vector, and stores the encrypted first portion on non-transitory processor readable media accessible by or part of the server computing device.

Encrypted-space comparison of different biometric portions for authentication

The server processes an authentication request including an encrypted second portion of the biometric vector, where the second portion is less than the biometric vector and the first portion and second portion are different, and performs a comparison of the encrypted first portion and encrypted second portion, including at least one matching operation in encrypted space as a function of one-way encryption.

Minimum-threshold authentication decision based on comparison value

The server generates a value representing the comparison and transmits the value to the user computing device, where the user computing device is authenticated where the value is above a minimum threshold and is not authenticated where the value is below a minimum threshold.

System instructions implementing encrypted biometric enrollment, encrypted-space matching, and threshold authentication

A system comprises at least one processor operatively coupled to one or more non-transitory processor readable media that includes instructions enabling the processor to process enrollment and authentication requests with encrypted first and second portions of a biometric vector, perform encrypted-space matching using one-way encryption, generate a comparison value, and transmit the value such that authentication is determined by a minimum threshold.

Across both independent claims, the inventive coverage centers on server-side enrollment and authentication using encrypted, different portions of a biometric vector, encrypted-space matching using one-way encryption to generate a comparison value, and authenticating or not authenticating the user computing device based on whether the comparison value is above or below a minimum threshold. Dependent claim refinements further narrow encryption approaches and add certificate current/not revoked checks, intrusion detection, replay prevention, and role-based access control.

Stated Advantages

Provides secure communication between a user computing device and a server computing device using encrypted biometric vector portions.

Authenticates the user computing device based on encrypted-space matching and a minimum-threshold comparison value.

Generates and transmits only a value representing the comparison for authentication decision rather than transmitting the biometric portions used in the comparison.

Documented Applications

Enables secure communication and authentication in a network between user computing devices and a server, using a distributed client software application and server processing of enrollment requests and authentication requests.

Supports certificate-based client/server identity in an enrollment and authentication context, including certificate current/not-revoked determination.

Supports role-based access control for accessing a digital asset, using role gathering rules to grant or deny a user computing device access.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.