IP Library › Granted Patent US 12,368,582
Granted Patent B2
US 12,368,582 · App. 18/200,228 · Granted Jul 22, 2025

Systems and methods for generating and using biometric secret keys

Inventors: Salil Jain (Hartford, CT); Andrew L. Hinton (Hartford, CT)
Assignee: Aetna Inc.
H04L9/0866H04L9/085
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,368,582
App. No.
18/200,228
Granted
Jul 22, 2025
Kind
B2
Abstract

A system comprising a first user device is provided. The first user device is configured to: obtain biometric registration data associated with a user; generate a secret key for the biometric registration data, wherein the secret key indicates an index translate point array; determine enrollment data for the user based on an index translate function, the biometric registration data, and the secret key, wherein the index translate function modifies entries of the biometric registration data based on the index translate point array; generate one or more cryptographic keys for the user based on the index translate point array; and provide, to a computing platform, ancillary information associated with the one or more cryptographic keys and the enrollment data.

Claims (82)

1. A method, comprising:

obtaining, by a user device, biometric registration data associated with a user;

generating, by the user device, a secret key for the biometric registration data, wherein the secret key indicates an index translate point array;

determining, by the user device, enrollment data for the user based on an index translate function, the biometric registration data, and the secret key, wherein the index translate function modifies entries of the biometric registration data based on the index translate point array; and

generating, by the user device, one or more cryptographic keys for the user based on the index translate point array.

2. The method of claim 1 , wherein generating the one or more cryptographic keys comprises generating an encryption key based on the index translate point array, and wherein the method further comprises:

encrypting sensitive data associated with the user using the encryption key; and

storing the enrollment data and encrypted sensitive data associated with the user in memory of the user device.

3. The method of claim 2 , further comprising:

subsequent to storing the enrollment data and the encrypted sensitive data, deleting the encryption key;

retrieving, from the memory of the user device, the encrypted sensitive data and the enrollment data;

obtaining new biometric data associated with the user; and

recreating the secret key based on the retrieved enrollment data, the new biometric data, and the index translate function.

4. The method of claim 3 , further comprising:

re-generating the encryption key based on the recreated secret key;

decrypting the encrypted sensitive data using the re-generated encryption key; and

utilizing the decrypted sensitive data for one or more tasks.

5. A system, comprising:

a first user device configured to:

obtain biometric registration data associated with a user;

generate a secret key for the biometric registration data, wherein the secret key indicates an index translate point array;

determine enrollment data for the user based on an index translate function, the biometric registration data, and the secret key, wherein the index translate function modifies entries of the biometric registration data based on the index translate point array;

generate one or more cryptographic keys for the user based on the index translate point array; and

provide, to a computing platform, ancillary information associated with the one or more cryptographic keys and the enrollment data.

6. The system of claim 5 , wherein the biometric registration data comprises a biometric user array indicating a biometric representation of the user, wherein the biometric representation of the user is associated with a fingerprint of the user or a facial recognition image of the user.

7. The system of claim 5 , wherein the first user device is further configured to obtain second biometric data that is different from the biometric registration data associated with the user, and

wherein determining the enrollment data for the user comprises:

determining first index translate outputs based on the index translate point array, the biometric registration data, and the index translate function;

determining second index translate outputs based on the second biometric data and the index translate function; and

generating the enrollment data based on the first index translate outputs and the second index translate outputs.

8. The system of claim 7 , wherein generating the enrollment data comprises:

generating intermediate enrollment data using the first index translate outputs and the second index translate outputs; and

generating the enrollment data based on using a sparsify function and the intermediate enrollment data, wherein the sparsify function resets at least one entry from the intermediate enrollment data to zero.

9. The system of claim 8 , wherein generating the intermediate enrollment data is based on a noise vector.

10. The system of claim 5 , wherein generating the one or more cryptographic keys comprises generating a private and public key pair comprising a public key and a private key, and wherein providing the ancillary information comprises providing, to the computing platform, the public key and the enrollment data.

11. The system of claim 10 , wherein the first user device is further configured to:

subsequent to providing the public key and the enrollment data to the computing platform, delete the secret key and the private and public key pair;

receive, from the computing platform, the enrollment data;

obtain new biometric data associated with the user; and

recreate the secret key based on the received enrollment data, the new biometric data, and the index translate function.

12. The system of claim 11 , wherein recreating the secret key comprises:

determining one or more index translated vectors based on the index translate function and the new biometric data;

determining a plurality of enrollment-based index translated vectors based on the one or more index translated vectors and the enrollment data; and

obtaining the recreated secret key based on a mathematical operation and the plurality of enrollment-based index translated vectors.

13. The system of claim 11 , wherein the first user device is further configured to:

re-generate the private and public key pair based on the recreated secret key;

encrypt an element using the private key from the re-generated private and public key pair; and

provide the encrypted element to the computing platform.

14. The system of claim 13 , further comprising:

the computing platform, wherein the computing platform is configured to:

authenticate the user based on decrypting the encrypted element using the public key; and

provide an indication indicating the authentication of the user to the first user device.

15. The system of claim 10 , further comprising:

a second user device configured to:

receive, from the computing platform, the enrollment data;

obtain new biometric data associated with the user; and

recreate the secret key based on the received enrollment data, the new biometric data, and the index translate function.

16. The system of claim 15 , wherein the second user device is further configured to:

re-generate the private and public key pair based on the recreated secret key;

encrypt an element using the private key from the re-generated private and public key pair; and

provide the encrypted element to the computing platform, and

wherein the system further comprises the computing platform, wherein the computing platform is configured to:

authenticate the user based on decrypting the encrypted element using the public key; and

provide an indication indicating the authentication of the user to the second user device.

17. The system of claim 5 , wherein generating the one or more cryptographic keys comprises generating an encryption key based on the index translate point array, and wherein providing the ancillary information comprises:

generating encrypted sensitive data associated with the user based on the encryption key; and

providing the encrypted sensitive data and the enrollment data to the computing platform, and

wherein the computing platform is configured to store the encrypted sensitive data and the enrollment data.

18. The system of claim 17 , wherein the first user device is further configured to:

subsequent to providing the encrypted sensitive data and the enrollment data to the computing platform, delete the secret key and the encryption key;

receive, from the computing platform, the encrypted sensitive data and the enrollment data;

obtain new biometric data associated with the user; and

recreate the secret key based on the received enrollment data, the new biometric data, and the index translate function.

19. The system of claim 18 , wherein the first user device is further configured to:

re-generate the encryption key based on the recreated secret key;

decrypt the encrypted sensitive data using the re-generated encryption key; and

utilize the decrypted sensitive data for one or more tasks.

20. A non-transitory computer-readable medium having processor-executable instructions stored thereon, wherein the processor-executable instructions, when executed, facilitate:

obtaining biometric registration data associated with a user;

generating a secret key for the biometric registration data, wherein the secret key indicates an index translate point array;

determining enrollment data for the user based on an index translate function, the biometric registration data, and the secret key, wherein the index translate function modifies entries of the biometric registration data based on the index translate point array; and

generating one or more cryptographic keys for the user based on the index translate point array.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 22, 2023
From: JAIN, SALIL; HINTON, ANDREW L.
To: AETNA INC.
Reel/Frame 063721/0196 →
Continuity (1)
Related Publication 20240396723A1 · Nov 28, 2024
References Cited (41)
US 2017A · Cherry · 1841 [cited by examiner]
US 7167565B2 · Rajasekaran · 2007 [cited by examiner]
US 7257844B2 · Woodward · 2007 [cited by examiner]
US 9129536B2 · Tkacik · 2015 [cited by examiner]
US 10305690B1 · Gehrmann · 2019 [cited by examiner]
US 11362822B2 · Jain · 2022 [cited by examiner]
US 20060083372A1 · Chang · 2006 [cited by examiner]
US 20090177894A1 · Orsini · 2009 [cited by examiner]
US 20090310779A1 · Lam · 2009 [cited by examiner]
US 20100106964A1 · Hirata · 2010 [cited by examiner]
US 20110246766A1 · Orsini · 2011 [cited by examiner]
US 20140325309A1 · Resch · 2014 [cited by examiner]
US 20160105285A1 · Jakobsson · 2016 [cited by examiner]
US 20160253521A1 · Esmailzadeh · 2016 [cited by examiner]
US 20170109512A1 · Bower · 2017 [cited by examiner]
US 20170250816A1 · Popa · 2017 [cited by examiner]
US 20170373861A1 · Jain · 2017 [cited by applicant]
US 20180013557A1 · Jain · 2018 [cited by examiner]
US 20200036707A1 · Callahan · 2020 [cited by examiner]
US 20200042684A1 · Gehrmann · 2020 [cited by examiner]
US 20200235932A1 · Gehrmann · 2020 [cited by examiner]
US 20200244451A1 · Herder, III · 2020 [cited by examiner]
US 20200267144A1 · Wagner · 2020 [cited by examiner]
US 20210152360A1 · Gehrmann · 2021 [cited by examiner]
US 20210367786A1 · Sheets · 2021 [cited by examiner]
US 20240039718A1 · Nara · 2024 [cited by examiner]
US 20250111367A1 · Kopf · 2025 [cited by examiner]
Herder et al. “Trapdoor Computational Fuzzy Extractors and Stateless Cryptographically-Secure Physical Unclonable Functions” (2014). [cited by applicant]
Herder et al. “Public Key Cryptosystems with Noisy Secret Keys” (2017). [cited by applicant]
“How can one securely generate an asymmetric key pair from a short passphrase?” https://crypto.stackexchange.com/questions/1662/how-can-one-securely-generate-an-asymmetric-key-pair-from-a-short-passphrase/1665#1665 (201… [cited by applicant]
Johnson, Robert A. “The Unisys Stealth Solution and SecureParser: A New Method for Securing and Segregating Network Data,” Unisys Corporation (2008). [cited by applicant]
Lewin, Michael “All About XOR-accu.org” [cited by applicant]
Monrose et al., “Cryptographic Key Generation From Voice,” [cited by applicant]
O'Hare et al. “The New Paradigm for Cyber Security,” [cited by applicant]
Parmar et al., “A novel Approach for Verifiable Secret Sharing by Using a One Way Hash Function” 10 [cited by applicant]
“Pseudorandom number generator” Wikipedia (Feb. 14, 2023). [cited by applicant]
Reza Key Encoding & Decoding, EyeVerify Inc. (2015). [cited by applicant]
“Secret Sharing,” [cited by applicant]
Teoh et al. “Personalised Cryptographic Key Generation Based on FaceHashing” [cited by applicant]
“Threshold Cryptosystem with a Required Share” https://crypto.stackexchange.com/questions/11529/threschold-cryptosystem-wtih-a-required-share (2013). [cited by applicant]
You et al., “A Cryptographic Key Binding Method Based on Fingerprint Features and the Threshold Scheme,” [cited by applicant]