IP Library Granted Patent US 12,726,370
Granted Patent B2
US 12,726,370 · App. 18/397,975 · Granted Sep 1, 2026

Pseudo-homomorphic authentication of users with biometry

Inventors: Bertrand F. Cambou (Flagstaff, AZ); Michael L. Garrett (Flagstaff, AZ)
Assignee: Arizona Board of Regents on Behalf of Northern Arizona University
H04L9/3278H04L9/3231H04L9/3239
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,726,370
App. No.
18/397,975
Granted
Sep 1, 2026
Kind
B2
Abstract

Methods for the generation and use of session keys for authentication of a user of a server device are disclosed. The methods use a biological objects of the user to generate responses to challenges. During enrollment, the server device receives a password, hashes it a first number of times, and sends the hash to the user. The user interprets the hash as a set of challenges for the biological object, applies the challenges, and stores the responses. During authentication, the server hashes the password a second number of times, less than the first number, and sends the hash to the user. The user iteratively applies second hash to the biological object, compares the responses to the stored responses, and if there is not a match, hashes the challenges again until there is a match. The number of hashes needed for a match is a session key or subkey.

Claims (27)

1 . A method of generating and using a session key at a client device, comprising:

receiving a first challenge bitstream, the first challenge bitstream comprising a password that has been iteratively hashed a first number of times according to a hashing method;

generating, from the first challenge bitstream, a first series of challenges, the first series of challenges specifying measurement conditions for measuring physical properties of a biological object;

measuring the biological object according to the first series of challenges;

receiving a first response bitstream from the measurement of the biological object;

storing the first response bitstream;

receiving a second challenge bitstream, the second challenge bitstream comprising the password that has been iteratively hashed a second number of times by the hashing method, the second number of times being less than the first predetermined number of times;

iteratively performing the following steps n times until a stop condition is reached:

hashing the second challenge bitstream using the hashing method;

generating from the hashed second challenge bitstream a second series of challenges;

measuring the biological object according to the second series of challenges;

receiving a second response bitstream from the measurement of the biological object; and

comparing the first response bitstream to the second response bitstream, wherein the stop condition is reached when the first response bitstream matches the second response bitstream, and using n as a session key.

2 . The method of claim 1 , wherein the biological object is one of a human face, fingerprint, iris or retina.

3 . The method of claim 1 , wherein measuring the biological object according to the first and second series of challenges comprises taking electronic image data from the biological object and extracting data about the biological object from the image data on the basis of the challenges.

4 . The method of claim 3 , wherein extracting data about the biological object from the image data on the basis of the challenges comprises taking a Fourier transform of the image data and extracting one or more frequencies of features in the image data from the Fourier transform.

5 . The method of claim 3 , wherein extracting data about the biological object from the image data on the basis of the challenges comprises determining the density or level of grayness of one or more portions of the image data identified by the challenges.

6 . The method of claim 3 , wherein extracting data about the biological object from the image data on the basis of the challenges comprises determining an orientation of a gradient of shading or grayness of one or more portions of the image data identified by the challenges.

7 . The method of claim 1 , further comprising pre-enrolling the client device by taking repeated calibration measurements of the biological object, determining calibration data on the basis of the repeated measurements, storing the calibration data, and applying the calibration data during future measurements.

8 . The method of claim 7 , wherein determining calibration data comprises defining the orientation and origin of a reference coordinate system with respect to identifiable features of the biological object, and wherein applying the calibration data during future measurements comprises aligning image data of the biological object to the reference coordinate system.

9 . The method of claim 8 , wherein aligning image data of the biological object to the reference coordinate system comprises rotating and translating the image data with respect to the reference coordinate system.

10 . The method of claim 7 , wherein determining calibration data on the basis of repeated measurements comprises determining a size value of the biological object, and wherein applying the calibration data during measurements comprises scaling image data of the biological object according to the size value.

11 . The method of claim 1 , wherein the hashing method is one of SHA-1, SHA-2, SHA-3, Shake, or a lighter custom hash function.

12 . The method of claim 1 , wherein using n as a session key comprises combining n with a plurality of additional subkeys.

13 . The method of claim 1 , wherein using n as a session key comprises using n to generate an encryption key according to a symmetrical keying algorithm.

14 . The method of claim 1 , wherein measuring the biological object according to the first and second series of challenges comprises taking an electronic image of the biological object with an image capture device and extracting data from the electronic image in accordance with the first and second challenges.

15 . The method of claim 1 , wherein when the first response bitstream matches the second response bitstream occurs when the first response bitstream is within a predetermined Hamming distance from the second response bitstream.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 8, 2024
From: CAMBOU, BERTRAND F.; GARRETT, MICHAEL L.
To: ARIZONA BOARD OF REGENTS ON BEHALF OF NORTHERN ARIZONA UNIVERSITY
Reel/Frame 066054/0898 →
Continuity (2)
Provisional Application 63435470 · Dec 27, 2022
Related Publication 20240214224A1 · Jun 27, 2024
References Cited (49)
US 7949880B2 · Champine et al. · 2011 [cited by applicant]
US 8745405B2 · Pizano et al. · 2014 [cited by applicant]
US 9646306B1 · Quigley et al. · 2017 [cited by applicant]
US 9967249B2 · Roth et al. · 2018 [cited by applicant]
US 10044514B1 · Peterson et al. · 2018 [cited by applicant]
US 10129028B2 · Kamakari et al. · 2018 [cited by applicant]
US 10140220B2 · Cambou · 2018 [cited by applicant]
US 10177922B1 · Hamlet et al. · 2019 [cited by applicant]
US 10719858B2 · Mimassi · 2020 [cited by applicant]
US 10742421B1 · Wentz et al. · 2020 [cited by applicant]
US 10887100B2 · Wentz · 2021 [cited by applicant]
US 11010465B2 · Cambou · 2021 [cited by applicant]
US 11477039B2 · Cambou et al. · 2022 [cited by applicant]
US 12184797B2 · Cambou · 2024 [cited by examiner]
US 20070083918A1 · Pearce · 2007 [cited by examiner]
US 20070291106A1 · Kenrick · 2007 [cited by examiner]
US 20070291776A1 · Kenrick · 2007 [cited by examiner]
US 20080112596A1 · Rhoads · 2008 [cited by examiner]
US 20110055585A1 · Lee · 2011 [cited by examiner]
US 20110138192A1 · Kocher · 2011 [cited by examiner]
US 20110215829A1 · Guajardo Merchan et al. · 2011 [cited by applicant]
US 20130191899A1 · Eldefrawy et al. · 2013 [cited by applicant]
US 20150242620A1 · Guajardo Merchan et al. · 2015 [cited by applicant]
US 20180034793A1 · Kibalo et al. · 2018 [cited by applicant]
US 20180262331A1 · Noguchi et al. · 2018 [cited by applicant]
US 20190036713A1 · Silk · 2019 [cited by applicant]
US 20190273612A1 · Sinha · 2019 [cited by examiner]
US 20200167504A1 · Oh et al. · 2020 [cited by applicant]
US 20200342112A1 · Plusquellic et al. · 2020 [cited by applicant]
US 20200412521A1 · Shi · 2020 [cited by applicant]
US 20240127614A1 · Kim et al. · 2024 [cited by applicant]
WO 2022122130A1 · 2022 [cited by applicant]
Cambou, B. et al., “Statistical Analysis to Optimize the Generation of Cryptographic Keys from Physical Unclonable Functions,” SAI Computing Conference, IEEE 2020. [cited by applicant]
Cambou, B., “Unequally Powered Cryptography with PUFs for networks of Internet of Things Terminals,” IEEE Spring Simulation Conference, 2019. [cited by applicant]
Cambou, B. et al., “Response-Based Cryptographic Methods with Ternary Physical Unclonable Functions,” SAI FICC, IEEE 2019. [cited by applicant]
Cambou, B. et al., “Password Manager Combining Hashing Functions and Ternary PUFs”; 2019 SAIcomputing conference, IEEE; Jul. 2019. [cited by applicant]
Cambou B. et al., Ternary Computing to Strengthen Cybersecurity, Development of Ternary State based Public Key Exchange, SAI Computing Conference, IEEE 2018. [cited by applicant]
Cambou, B. et al., “Ternary Computing to Strengthen Information Assurance, Development of Ternary State Based Public Key Exchange,” SAI Computing Conference, IEEE 2018. [cited by applicant]
Cambou, B. et al. “Design of Physical Unclonable Functions with ReRAM and Ternary States,” Cyber and Information Security Research Conference, CISR 2016. [cited by applicant]
Delvaux, J. et al., “Helper Data Algorithms for PUF-Based Key Generation: Overview and Analysis,” IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems, vol. 34, No. 6, pp. 889-902, 2015. [cited by applicant]
Kang, H. et al., “Cryptographic Key Generation from PUF Data Using Efficient Fuzzy Extractors,” In 16th International Conference on Advanced Communication Technology, 2014. [cited by applicant]
Taniguchi, M. et al., “A Stable Key Generation from PUF Responses with a Fuzzy Extractor for Cryptographic Authentications,” In IEEE 2nd Global Conference on Consumer Electronics, 2013. [cited by applicant]
Regev, O. “New Lattice-Based Cryptographic Constructions,” Journal of the ACM, 51(6): 899-942, 2004, https://doi.org/10.1145/1039488.1039490. [cited by applicant]
Assiri, S. et al., Homomorphic Password Manager Using Multiple-Hash With PUF, Springer, AISC 1363, pp. 772-792, 2021, https://doi.org/10.1007/978-3-030-73100-7_55. [cited by applicant]
Herder, C. et al., “Physical Unclonable Functions and Applications: A Tutorial,” in Proceedings of the IEEE, vol. 102, No. 8, pp. 1126-1141, Aug. 2014, doi: 10.1109/JPROC.2014.2320516. [cited by applicant]
Suh, G. E. et al., “Physical Unclonable Functions for Device Authentication and Secret Key Generation”, Proc. Design Automation Conference, 2007, pp. 9-14. [cited by applicant]
Guajardo, J. et al., “PUFs and Public Key Crypto for FPGA IP Protection,” Conference on Field Programmable Logic and Applications, 2007, 189-195. [cited by applicant]
Lofstrom, K. et al., “IC Identification Circuits using Device Mismatch,” Proc. of ISSCC, 2000, pp. 372-373, http://kl-ic.com/isscc2K.pdf. [cited by applicant]
Alkabani, Y. et al., “Trusted Integrated Circuits: A Nondestructive Hidden Characteristics Extraction Approach,” Information Hiding, 2008. [cited by applicant]