IP Library Granted Patent US 11,210,375
Granted Patent B2
US 11,210,375 · App. 16/218,139 · Granted Dec 28, 2021

Systems and methods for biometric processing with liveness

Inventor: Scott Edward Streit (Woodbine, MD)
Assignee: Private Identity LLC
G06F21/32G06K9/00906G06N3/08
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,210,375
App. No.
16/218,139
Filed
Dec 12, 2018
Granted
Dec 28, 2021
Kind
B2
Art Unit
2666
USPC
382/115
Abstract

In one embodiment, a set of feature vectors can be derived from any biometric data, and then using a deep neural network (“DNN”) on those one-way homomorphic encryptions (i.e., each biometrics' feature vector) an authentication system can determine matches or execute searches on encrypted data. Each biometrics' feature vector can then be stored and/or used in conjunction with respective classifications, for use in subsequent comparisons without fear of compromising the original biometric data. In various embodiments, the original biometric data is discarded responsive to generating the encrypted values. In another embodiment, the homomorphic encryption enables computations and comparisons on cypher text without decryption of the encrypted feature vectors. Security of such privacy enable biometrics can be increased by implementing an assurance factor (e.g., liveness) to establish a submitted biometric has not been spoofed or faked.

Claims (80)

1. An authentication system for evaluating privacy-enabled biometrics and validating contemporaneous input of biometrics, the system comprising:

at least one processor operatively connected to a memory;

an interface, executed by the at least one processor configured to:

receive a candidate set of instances of a first biometric data type input by a user requesting authentication;

a classification component executed by the at least one processor, configured to:

analyze a liveness threshold, wherein analyzing the liveness threshold includes processing the candidate set of instances to determine that the candidate set of instances matches a random set of instances;

the classification component further comprising at least a first deep neural network (“DNN”), the classification component configured to:

accept, as an input to the first DNN, one-way homomorphic encrypted feature vectors, output from at least one layer of a first neural network, the first neural network configured to process a plaintext input of the first biometric data type into the one-way homomorphic encrypted feature vectors;

classify, with the first DNN during training, the one-way homomorphic encrypted feature vectors of the first biometric data type, based on training the first DNN with the one-way homomorphic encrypted feature vectors and respective labels taken as inputs;

define at least a plurality of identification classes during training of the first DNN, wherein respective identification classes correspond to the respective labels, and the respective labels are associated with respective user identities;

return, during prediction, a matching label for person identification from the plurality of identification classes in response to a match and an unknown result responsive to failure to match to the plurality of identification classes based, at least in part, on analyzing one-way homomorphic encrypted feature vectors with the first DNN; and

confirm the matching label based at least on the liveness threshold.

2. The system of claim 1 , wherein the classification component is configured to:

determine for values above the liveness threshold that the contemporaneous input matches the random set of instances; and

determine for values below the liveness threshold that a current authentication request is invalid.

3. The system of claim 1 , further comprising a liveness component, executed by the at least one processor, configured to generate a random set of instances of a first biometric data type in response to an authentication request.

4. The system of claim 3 , wherein the system is configured to request a user provide the candidate set of instances of the first biometric data type based on the generated random set of instances.

5. The system of claim 4 , wherein the interface is configured to prompt user input of randomly selected instances of the first biometric data type, that are requested as input to establish a threshold volume of biometric information confirmed at validation.

6. The system of claim 1 , wherein the classification component further comprises at least a first pair of neural networks configured to process the first biometric data type, the pair including the first DNN and the first neural network, wherein the first neural network is configured to:

generate a first training encrypted feature vector output that is coupled with a respective label to train the first DNN, and

generate a first prediction encrypted feature vector output for prediction using the first DNN on input of a new biometric of the first biometric data type; and

wherein the classification component further comprises:

an application running on a user device configured to:

execute the first neural network on the user device to capture and process plaintext input of the first biometric data type;

communicate the first prediction encrypted feature vector output of the first neural network to a remote application executing the first DNN; and

delete from memory the plaintext input of the first biometric data type;

a remote application running on a server system configured to:

execute the first DNN to classify the first prediction encrypted feature vector output of the first biometric type to determine if there is a match to an existing label; and

at least a second pair of neural networks including a second deep neural network (“DNN”) and a second neural network to process a second biometric data type, wherein the second neural network is configured to:

generate a second training encrypted feature vector output, from a plaintext input of the second biometric data type, that is coupled with a respective label to train the second DNN, and

generate a second prediction encrypted feature vector output for prediction using the second DNN on input of a new biometric of the second biometric data type; and

wherein the application running on the user device is further configured to:

execute the second neural network on the user device to capture and process plaintext input of the second biometric data type;

communicate the second prediction encrypted feature vector output of the second neural network to the server system executing the second DNN; and

delete from memory the plaintext input of the second biometric data type; and

wherein the second deep neural network (“DNN”) is configured to:

accept the second prediction encrypted feature vector output generated from the second neural network and classify the second prediction encrypted feature vector output from the second neural network;

wherein the remote application running on the server system is further configured to:

execute the second DNN to determine if there is a match to an existing label; and

return a label for person identification or an unknown result during prediction responsive to analyzing the second prediction encrypted feature vector output of the second neural network; and

wherein the classification component is configured to confirm identification based on matching respective labels for person identification from the first and second DNNs.

7. The system of claim 1 , wherein the classification component further comprises:

at least a first pair of neural networks configured to process the first biometric data type, the pair including the first DNN and the first neural network;

at least a second pair of neural networks, including a second DNN and a second neural network, configured to process a second biometric data type;

an application running on a user device configured to:

execute the first neural network and the second neural network to generate respective first and second encrypted feature vectors responsive to plaintext biometric input;

communicate the respective first and second encrypted feature vectors to a remote application; and

delete plaintext biometric input from memory responsive to generation of the respective first and second encrypted feature vectors; and

a remote application running on a server system configured to:

execute the first and the second DNN to classify the respective first and second encrypted feature vectors; and

return a valid authentication signal to the application running on the user device responsive to matching the respective first and second encrypted feature vectors of the first and second biometric data type to a label.

8. The system of claim 1 , further comprising the first neural network configured to process an unencrypted a plaintext input of the first biometric data type into the one-way homomorphic encrypted feature vectors of the first biometric data type.

9. The system of claim 8 , further comprising a pre-processing component configured to reduce a volume of plaintext input biometric information for input into the first neural network.

10. The system of claim 1 , wherein the classification component is configured to incrementally update the first DNN with new person labels and new person feature vectors, based on updating null or undefined elements defined in the first DNN at training, and maintaining a network architecture of the first DNN, and accommodating the unknown result for subsequent predictions without requiring full retraining of the first DNN.

11. The system of claim 1 , wherein the system is configured to analyze output values from the first DNN and based on positioning of the output values in an array and values in positions in the array, determine the label or unknown.

12. A computer implemented method of evaluating privacy-enabled biometrics and validating contemporaneous input of biometrics, the method comprising:

receiving, by at least one processor, a candidate set of instances of a first biometric data type input by a user requesting authentication;

analyzing, by the at least on processor, a liveness threshold, wherein analyzing the liveness threshold includes processing the candidate set of instances to determine that the candidate set of instances matches a random set of instances;

accepting, by a first deep neural network (“DNN”) executed by the at least one processor, one- way homomorphic encrypted feature vectors output from at least one layer of a first neural network, the first neural network configured to process a plaintext input of the first biometric data type into the one-way homomorphic encrypted feature vectors;

classifying, by the first DNN during training, the one-way homomorphic encrypted feature vectors of the first biometric data type, based on training the first DNN with the one-way homomorphic encrypted feature vectors and respective labels taken as inputs;

defining at least a plurality of identification classes during training of the first DNN, wherein respective identification classes correspond to the respective labels, and the respective labels are associated with respective user identities;

returning, by the first DNN during prediction, a matching label for person identification from the plurality of identification classes in response to a match and an unknown result responsive to failure to match to the plurality of identification classes based, at least in part, on analyzing one-way homomorphic encrypted feature vectors; and

confirming the matching label based at least on the liveness threshold.

13. The method of claim 12 , wherein the method further comprises:

determining for values above the liveness threshold that the contemporaneous input matches the random set of instances; and

determining for values below a threshold that a current authentication request is invalid.

14. The method of claim 12 , wherein the method further comprises generating a random set of instances of a first biometric data type in response to an authentication request.

15. The method of claim 14 , wherein the method further comprises requesting a user provide the candidate set of instances of the first biometric data type based on the generated random set of instances.

16. The method of claim 15 , wherein the method further comprises prompting user input of randomly selected instances of the first biometric data type, that are requested as input to establish a threshold volume of biometric information confirmed at validation.

17. The method of claim 12 , wherein the method further comprises:

accepting, by at least a second deep neural network, second encrypted feature vectors generated from a second neural network, the second neural network configured to process a plaintext input of a second biometric data type into the second encrypted feature vectors of the second biometric data type;

returning, by the second DNN a label for person identification or an unknown result during prediction responsive to analyzing the second encrypted feature vectors of the second biometric data type; and

confirming identification based on matching respective labels for person identification from the first and second DNNs;

executing an application on a user device, wherein executing includes managing operation of the first neural network and second neural network to generate respective first and second encrypted feature vectors of the first and the second biometric data types;

communicating, by the application, the first and second encrypted feature vectors of the first and the second biometric data types to a remote application;

deleting from memory plaintext input of the first and the second biometric data type, responsive to generating respective first and second encrypted feature vectors;

managing, by the remote application running on a server system, the first and second DNN to classify the respective first and second encrypted feature vectors; and

returning, by the remote application, a valid authentication signal to the application responsive to matching the respective first and second encrypted feature vectors of the first and second biometric data type to respective labels.

18. The method of claim 12 , wherein the method further comprises processing, by the first neural network, a plaintext input of the first biometric data type into the one-way homomorphic encrypted feature vectors of the first biometric data type.

19. The method of claim 12 , wherein the method further comprises incrementally updating the first DNN with new person labels and new persons feature vectors, based on updating null or undefined elements established in the first DNN at training, and maintaining an architecture of the first DNN and accommodating the unknown result for subsequent predictions without requiring full retraining of the first DNN.

Assignments (3)
SECURITY INTEREST Recorded Aug 14, 2023
From: PRIVATE IDENTITY LLC
To: POLLARD, MICHAEL
Reel/Frame 064581/0864 →
CHANGE OF NAME Recorded Dec 16, 2019
From: OPEN INFERENCE HOLDINGS LLC
To: PRIVATE IDENTITY LLC
Reel/Frame 051302/0284 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 15, 2019
From: STREIT, SCOTT EDWARD
To: OPEN INFERENCE HOLDINGS LLC
Reel/Frame 048881/0747 →
Continuity (4)
Continuation In Part 15914562 · Mar 7, 2018
Continuation In Part 15914942 · Mar 7, 2018
Continuation In Part 15914969 · Mar 7, 2018
Related Publication 20190278895A1 · Sep 12, 2019
Cited By (13)
US 12,206,783 US 12,238,218 US 12,248,549 US 12,254,072 US 12,299,101 US 12,301,698 US 12,306,961 US 12,335,400 US 12,411,924 US 12,430,099 US 12,443,392 US 12,457,111 US 12,670,249