Biometric verification with improved privacy and network performance in client-server networks
First Claim
1. A method of biometric authentication of a client-side authorized smart device user at least occasionally connected to a remote server via a communication network, comprising:
- comparison, by the smart device, of an encrypted input biometric template corresponding to a biometric representation operably received by the smart device with an encrypted reference biometric template previously stored on the smart device and corresponding to a biometric representation of the user; and
reporting by the smart device to the remote server of user authentication success/failure based on the comparison of the encrypted input biometric template and the previously stored encrypted reference biometric template,wherein previously storing the reference biometric template corresponding to a biometric representation of the user comprises;
recording a biometric representation of the user on the client-side smart device;
converting the biometric representation of the user into an unencrypted reference biometric template;
encrypting the unencrypted reference biometric template, using a revocable hardwired encryption key, to obtain the encrypted reference biometric template; and
substantially simultaneously storing the encrypted reference biometric template in a memory of the smart device and permanently deleting the recorded biometric representation of the user and the unencrypted reference biometric template.
0 Assignments
0 Petitions
Accused Products
Abstract
The present invention relates to improving the privacy of biometric information used in biometric authentication of identity by retaining all biometric information corresponding to a given user, and conducting all transactions related thereto (i.e., the actual authentication process) on a client (i.e., user) side of the system, thereby maximizing the user'"'"'s control over biometric information corresponding to himself and preventing the storage of biometric templates on third-party servers outside of the control of the concerned individual. In a particular example of the present invention, security for the biometric information is further enhanced by encrypting the biometric template (used as a comparison reference during authentication, as is known) stored on the client side and completely destroying an original unencrypted version of the template. Also specified is secure storage of encryption keys for encrypting biometric data at the client. In yet a further example of the present invention, authentication is preferably conducted using the encrypted biometric templates.
11 Citations
11 Claims
-
1. A method of biometric authentication of a client-side authorized smart device user at least occasionally connected to a remote server via a communication network, comprising:
-
comparison, by the smart device, of an encrypted input biometric template corresponding to a biometric representation operably received by the smart device with an encrypted reference biometric template previously stored on the smart device and corresponding to a biometric representation of the user; and reporting by the smart device to the remote server of user authentication success/failure based on the comparison of the encrypted input biometric template and the previously stored encrypted reference biometric template, wherein previously storing the reference biometric template corresponding to a biometric representation of the user comprises;
recording a biometric representation of the user on the client-side smart device;
converting the biometric representation of the user into an unencrypted reference biometric template;
encrypting the unencrypted reference biometric template, using a revocable hardwired encryption key, to obtain the encrypted reference biometric template; and
substantially simultaneously storing the encrypted reference biometric template in a memory of the smart device and permanently deleting the recorded biometric representation of the user and the unencrypted reference biometric template. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A system for authenticating the identity of a smart device client user, comprising:
-
a client-side smart device constructed and arranged to selectively receive a biometric representation of an authorized user of the smart device, convert the biometric representation into a reference biometric template, and encrypt the reference biometric template using a revocable hardwired encryption key in the smart device, wherein the smart device comprises or is operably associated with a biometric representation reader for detecting and inputting the biometric representation of the authorized user; and at least one remote server in at least occasional electronic communication with the smart device, and constructed and arranged to selectively send a request to a given smart device user to authenticate himself, and to act in response to the authentication result transmitted back from the smart device, wherein the smart device is further constructed and arranged to selectively receive an input biometric representation of the smart device user who is to be authenticated, convert the input biometric representation into an encrypted input biometric template, and perform an authentication comparison of the encrypted reference biometric template and the encrypted input biometric template. - View Dependent Claims (9, 10, 11)
-
Specification