IP Library Granted Patent US 11,831,766
Granted Patent B2
US 11,831,766 · App. 17/334,129 · Granted Nov 28, 2023

Generation of encryption keys using biometrics

Inventor: David Kye Liang Lee (Wantirna, AU)
H04L9/0866H04L9/0869H04L9/0894H04L9/3271H04L9/3247
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,831,766
App. No.
17/334,129
Granted
Nov 28, 2023
Kind
B2
Abstract

Methods and systems for improved generation of biometrics using biometrics and secure storage of biometrics are provided. In one embodiment, a method is provided that includes scanning and digitizing a plurality of biometrics to form a plurality of digitized biometrics. An encryption key for use in cryptographic applications may be generated based on the plurality of digitized biometrics. A biometrics encryption seed may be received and may be used to encrypt the plurality of digitized biometrics to generate a plurality of encrypted biometrics. The plurality of encrypted biometrics may then be stored.

Claims (38)

1. A method for generating an encryption key for use in cryptographic applications, the method comprising:

(a) scanning a plurality of biometrics;

(b) digitizing at least a subset of the plurality of biometrics to form a plurality of digitized biometrics;

(c) generating the encryption key based on the plurality of digitized biometrics;

(d) encrypting data for storage using the encryption key;

(e) receiving a biometrics encryption seed;

(f) encrypting the plurality of digitized biometrics at least in part based on the biometrics encryption seed to generate a first plurality of encrypted biometrics;

(g) storing the first plurality of encrypted biometrics;

(h) receiving, at a later time, the biometrics encryption seed;

(i) retrieving the first plurality of encrypted biometrics;

(j) decrypting, based on the biometrics encryption seed, the first plurality of encrypted biometrics to generate the plurality of digitized biometrics;

(k) generating the encryption key based on the plurality of digitized biometrics; and

(l) decrypting the data using the encryption key.

2. The method of claim 1 , wherein the encryption key is generated based on an ordered sequence of the plurality of digitized biometrics.

3. The method of claim 2 , wherein generating the encryption key based on the plurality of digitized biometrics further comprises:

generating, based on the ordered sequence of the plurality of digitized biometrics, an intermediate value; and

generating the encryption key based on the intermediate value.

4. The method of claim 1 , further comprising, prior to retrieving the first plurality of encrypted biometrics:

presenting a multi-factor authentication challenge; and

receiving a response that passes the multi-factor authentication challenge.

5. The method of claim 1 , further comprising repeating (a)-(c) to receive an updated plurality of biometrics and to generate an updated encryption key based on at least a subset of the updated plurality of biometrics.

6. The method of claim 1 , wherein the at least the subset of the plurality of biometrics includes at least two types of biometrics.

7. The method of claim 6 , wherein the at least two types of biometrics are selected from the group consisting of fingerprint scans, two-dimensional facial scans, three-dimensional facial scans, vocal feedback matching, capillary scans, and iris scans.

8. The method of claim 1 , wherein (a)-(c) are performed by a first processor and (d)-(f) are performed by a second processor.

9. The method of claim 1 , further comprising:

encrypting the plurality of digitized biometrics with a device key to generate a second plurality of encrypted biometrics,

wherein the encryption key is generated based on the second plurality of encrypted biometrics, and

wherein the second plurality of encrypted biometrics is encrypted at least in part based on the biometrics encryption seed to generate the first plurality of encrypted biometrics.

10. The method of claim 9 , wherein the device key is uniquely and immutably associated with a computing device implementing the method.

11. The method of claim 1 , wherein the plurality of digitized biometrics are digitized to a volatile memory and are deleted after completion of the method.

12. The method of claim 1 , wherein the first plurality of encrypted biometrics are stored in a non-volatile memory.

13. The method of claim 12 , wherein the non-volatile memory is at least a part of a secure enclave of a computing device implementing the method.

14. The method of claim 1 , wherein the at least the subset of the plurality of biometrics are encrypted and stored separately.

15. The method of claim 1 , wherein the at least the subset of the plurality of biometrics are encrypted and stored together.

16. The method of claim 1 , wherein the encryption key is generated for use in a particular cryptographic application and is deleted upon completion of the cryptographic application.

17. The method of claim 1 , wherein the cryptographic applications include generating digital signatures, encrypting data, and accessing previously-encrypted data.

18. The method of claim 1 , wherein encrypting the plurality of digitized biometrics comprises transforming the plurality of digitized biometrics prior to encrypting the plurality of digitized biometrics with the biometrics encryption seed.

19. The method of claim 1 , wherein transforming the plurality of digitized biometrics includes at least one of hashing the plurality of digitized biometrics and salting the plurality of digitized biometrics.

Continuity (2)
Provisional Application 63031309 · May 28, 2020
Related Publication 20210377013A1 · Dec 2, 2021