IP Library Granted Patent US 12,242,582
Granted Patent B2
US 12,242,582 · App. 18/209,332 · Granted Mar 4, 2025

Biometric identification using homomorphic primary matching with failover non-encrypted exception handling

Inventor: Arun Vemury (North Bethesda, MD)
Assignee: The Government of the United States of America, as represented by the Secretary of Homeland Security
G06F21/32G06F21/602G06F21/6245G06V40/168G06V40/172G06V40/50H04L9/008H04L9/3231
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,242,582
App. No.
18/209,332
Granted
Mar 4, 2025
Kind
B2
Abstract

Systems and methods for providing exception failover augmented, homomorphic encrypted (HE) distributing, end-to-endpoint persistent encryption, and distributed HE domain non-decrypting, privacy-protective biometric processing are provided. Some configurations may include generating HE biometric feature data, based on homomorphic encrypting the biometric feature data. Some configurations determine an exception status of the HE biometric feature data between exception and non-exception. Systems and methods may include performing a HE domain, non-decrypting biometric classifying of the HE biometric feature data.

Claims (97)

1. A method for HE (homomorphic encrypted), privacy BGH(k)-protective, dynamically expandable, distributed resource biometrics identification and verification processing, with exception based local cleartext failover comprising:

an interface session logic of a biometric capture, EP HE ECDS (biometric capture, exception protective HE encryption and distribution) unit storing a correspondence (TID(k)↔BGH(k)), between captured biographic information BGH(k) and a temporary identifier TID(k);

the biometric capture, EP HE ECDS unit appending TID(k) to communications from the unit to a third-party computer resource of a k th user; k is a natural number;

the third-party computer resource appending TID(k) to processing results the third-party computer resource communicates back to the biometric capture, EP HE ECDS unit;

the biometric capture, EP HE ECDS unit including a biometric capture device; the biometric capture device capturing one or more types of biometric information BM(k) of the k th user;

the biometric capture, EP HE ECDS unit including biometric feature vector logic; the biometric feature vector (FV) logic computing from the biometric information BM(k), a biometric feature vector FV(BM(k));

the biometric capture, EP HE ECDS unit including HE encrypting logic; the HE encrypting logic HE encrypting FV(BM(k)) to generate HE{FV(BM(k))}; and

uploading the HE feature vector encrypted biometric information HE{FV(BM(k))} to a biometric reference gallery holding biometric information in memory;

generating HE encryption of a feature vector of a first user's biometric information (FV(BM(k 1 );

generating HE encryption of a feature vector of a second user's biometric information FV(BM(k 2 ));

wherein HE encryption of the feature vector of a first user's biometric information is identical to the HE encryption of the feature vector of a second user's biometric information, irrespective of the two feature vectors having different values; and

detecting a collision wherein the first user feature vector and the second user feature vector, k 1 not being equal to k 2 , and FV(BM(k 1 )) not being equal to FV(BM(k 2 )), there is an instance of HE{FV(BM(k 1 ))} being identical to HE{FV(BM(k 2 ))}.

2. The method of claim 1 comprising the step of the biometric capture device capturing a row-by-column pixel array of a facial image of the k th user.

3. The method of claim 1 wherein the biometric feature vector logic computes FV(BM(k)) using an orthogonal basis function transformation selected from the list consisting essentially of DWT, Walsh Transform, WHT, and combinations thereof.

4. The method of claim 1 wherein the step of providing failover biometric processing in response further comprises biometric classifying, relative to the biometric reference gallery, of:

a cleartext version of the feature vector FV(BM(k)) computed by the biometric feature vector logic; or

a cleartext version of the captured biometric information BM(k).

5. The method of claim 1 comprising:

receiving the third-party computer resource HE processing results including appended TID(k);

determining no match was found; and

performing system internal cleartext biometric processing, using a cleartext form of BM(k) or a cleartext form of FV(BM(k)).

6. The method of claim 1 comprising the steps of:

the exception detection and failover logic determining HE{FV(BM(k))} is not a collision with an earlier HE{FV(BM(k′))}; and

the HE encrypting logic uploading HE{FV(BM(k))} and TID(k) to FV similarity logic in the third-party computer resource; the third-party computer resource comprising a matching output logic;

the matching output logic sending a classification result and TID(k) to the biometric capture, EP HE ECDS unit or a third-party recipient; and

an HE domain classifier configuring logic configuring the third-party computer resource to perform non-decrypting HE domain classifying of the uploaded HE encrypted biometric information of the k th user.

7. The method of claim 6 wherein the step of configuring the third-party computer resource comprising the step of configuring for non-decrypting HE domain 1:N classifying of the user's HE encrypted biometric information against N verified reference identifies for which the biometric reference gallery stores reference biometric information.

8. The method of claim 7 wherein the biometric reference gallery stores a gallery of biometric reference images (RG(i), i=1 to N).

9. The method of claim 1 comprising the steps of

HE domain classifier configuring logic configuring the third-party computer resource to perform non-decrypting HE domain classifying of the uploaded HE encrypted biometric information of the k th user;

the third-party computer resource configuring non-decrypting HE domain 1:N classifying of the user's HE encrypted biometric information against N verified reference identifies for which the biometric reference gallery stores reference biometric information;

the biometric reference gallery storing a gallery of biometric reference images RG(i), (i=1 to N); the biographic reference images RG captured from a population of N different, verified individuals; and

the biometric reference gallery storing, for each of N identities, one or more biometric reference images RG, of one or more biometric types; wherein the biometric types are selected from the list consisting essentially of biometric reference images RG, eye scan images, facial images, fingerprint images, and combinations thereof, for each of N identities; and the biometric reference images (RG) are selected from the list consisting essentially of images at different capture angles, different lightings, different facial expressions and different fingers.

10. The method of claim 9 wherein the HE domain classifier configuring logic includes:

HE encrypted reference gallery generating logic; the HE encrypted reference gallery generating logic generating a HE encrypted biometric reference gallery (HE{FV(RG(i))), i=1 to N); and

uploading logic uploading the HE encrypted biometric reference gallery to the third-party computer resource; the HE encrypted biometric reference gallery including HE encryptions of feature vectors (FV(RG(i))) of the reference gallery images RG(i).

11. The method of claim 10 wherein the HE encrypted reference gallery generating logic comprises:

feature vector generating logic generating logic generating FV(RG(i) for i=1 to N by applying an orthogonal basis transformation;

HE encryption logic generating HE{FV(RG(i))), for i=1 to N; and

uploading logic uploading the HE encrypted biometric reference gallery (HE{FV(RG(i))}, i=1 to N) to the third-party computer resource.

12. The method of claim 10 comprising the steps of:

the third-party computer resource receiving HE encrypted biometric reference gallery (HE{FV(RG(i))), i=1 to N); and

feature vector similarity logic (FV similarity logic, HE{FV(BM(k))} against reference HE{FV(RG(i))}, i=1, N) determining a level of similarity between a current HE encrypted feature vector of biometric information k against a reference list of HE encrypted feature vectors reference gallery information i through N.

13. A method for HE (homomorphic encrypted), privacy BGH(k)-protective, dynamically expandable, distributed resource biometrics identification and verification processing, with exception based local cleartext failover comprising:

an interface session logic of a biometric capture, EP HE ECDS (biometric capture, exception protective HE encryption and distribution) unit storing a correspondence (TID(k)↔BGH(k)), between captured biographic information BGH(k) and a temporary identifier TID(k);

the biometric capture, EP HE ECDS unit appending TID(k) to communications from the unit to a third-party computer resource of a k th user; k is a natural number;

the third-party computer resource appending TID(k) to processing results the third-party computer resource communicates back to the biometric capture, EP HE ECDS unit;

the biometric capture, EP HE ECDS unit including a biometric capture device; the biometric capture device capturing one or more types of biometric information BM(k) of the k th user;

the biometric capture, EP HE ECDS unit including biometric feature vector logic; the biometric feature vector (FV) logic computing from the biometric information BM(k), a biometric feature vector FV(BM(k));

the biometric capture, EP HE ECDS unit including HE encrypting logic; the HE encrypting logic HE encrypting FV(BM(k)) to generate HE{FV(BM(k))}; and

uploading the HE feature vector encrypted biometric information HE{FV(BM(k))} to a biometric reference gallery holding biometric information in memory;

the exception detection and failover logic comprises:

a holding memory storing temporarily a copy of the captured biometric information BM(k) and a copy of the biometric feature vector FV(BM(k));

an accumulated homomorphic encrypted feature vector memory (Accumulated HE{FV}MRY);

an exception detection and memory update logic; the exception detection and memory update logic connected to the HE encrypting logic of the biometric capture, EP HE ECDS unit; the HE encrypting logic is configured such that uploading of HE{FV(BM(k))} is conditioned on verification by the exception detection and memory update logic that the HE{FV(BM(k))} value is not a collision with an earlier HE{FV(BM(k′))}, FV(BM(k′)) being an earlier computed biometric feature vector FV(BM(k′)), for a biometric image BM(k′) captured from a k′ user; and

a local failover verification and identification logic (LCL FO VF-ID Logic); the local failover verification and identification controlling biometric classification relative to the biometric reference gallery of cleartext feature vector FV(BM(k)) or cleartext captured biometric image BM(k) held in the holding memory.

14. A method for HE (homomorphic encrypted), privacy BGH(k)-protective, dynamically expandable, distributed resource biometrics identification and verification processing, with exception based local cleartext failover comprising:

an interface session logic of a biometric capture, EP HE ECDS (biometric capture, exception protective HE encryption and distribution) unit storing a correspondence (TID(k)↔BGH(k)), between captured biographic information BGH(k) and a temporary identifier TID(k);

the biometric capture, EP HE ECDS unit appending TID(k) to communications from the unit to a third-party computer resource of a k th user; k is a natural number;

the third-party computer resource appending TID(k) to processing results the third-party computer resource communicates back to the biometric capture, EP HE ECDS unit;

the biometric capture, EP HE ECDS unit including a biometric capture device; the biometric capture device capturing one or more types of biometric information BM(k) of the k th user;

the biometric capture, EP HE ECDS unit including biometric feature vector logic; the biometric feature vector (FV) logic computing from the biometric information BM(k), a biometric feature vector FV(BM(k));

the biometric capture, EP HE ECDS unit including HE encrypting logic; the HE encrypting logic HE encrypting FV(BM(k)) to generate HE{FV(BM(k))}; and

uploading the HE feature vector encrypted biometric information HE{FV(BM(k))} to a biometric reference gallery holding biometric information in memory;

for exception failover augmented, homomorphic encrypted (HE) distributing, and end-to-endpoint persistent encryption, and distributed HE domain non-decrypting, privacy-protective biometric processing, comprising:

capturing a biometric information of an individual as a biometric record;

computing a biometric feature data based at least in part on the biometric record;

generating HE biometric feature data based at least in part on homomorphic encrypting the biometric feature data;

determining an exception status of the HE biometric feature data, between exception and non-exception;

responsive to the non-exception status:

HE distributing the HE biometric feature data to an external computer processing resource;

performing, by the external computer processing resource, a HE domain, non-decrypting biometric classifying of the HE biometric feature data, and sending from the external computer processing resource to a designated destination a result of the HE domain, non-decrypting biometric classifying; and

responsive to the exception status: performing a non-distributed classifying of the biometric feature data, or the biometric record.

15. The method of claim 14 for exception failover augmented, HE encryption and persistent HE, privacy-protective distributed non-decrypting HE domain biometric processing, further comprising:

receiving a biographical information of a user;

generating a temporary identifier;

storing a correspondence between the temporary identifier and at least a portion of the biographical information;

communicating, in association with communicating the biometric information to the external computer processing resource, the temporary identifier to the external computer processing resource; and

communicating, by the external computer processing resource, the temporary identifier in association with the result of the HE domain, non-decrypting biometric classifying.

16. The method of claim 14 for exception failover augmented, HE encryption and persistent HE, privacy-protective distributed non-decrypting HE domain biometric processing, further comprising configuring the external computer processing resource to perform the HE domain, non-decrypting biometric classifying of the homomorphic encrypted biometric feature data.

17. The method of claim 16 for exception failover augmented, HE encryption and persistent HE, privacy-protective distributed non-decrypting HE domain biometric processing, further comprising:

generating a HE biometric reference gallery, including a HE biometric reference data for each of N identities; and

the configuring the external computer processing resource to perform the HE domain, non-decrypting biometric classifying of the HE biometric feature data to include:

communicating the HE biometric reference gallery to the external computer processing resource; and

configuring the external computer processing resource to perform the classifying the HE biometric feature data based at least in part on computing a respective similarity between the HE biometric feature data and the HE biometric reference data for each of the N identities.

18. The method of claim 14 for exception failover augmented, HE encryption and persistent HE, privacy-protective distributed non-decrypting HE domain biometric processing, wherein the determining the exception status of the HE biometric feature data, between exception and non-exception comprises:

determining whether the HE biometric feature data differs from all stored generated HE biometric feature data in an accumulated HE biometric feature data database;

responsive to determining the HE biometric feature data differs from all stored generated HE biometric feature data in the accumulated HE biometric feature data database; determining the exception status as non-exception and storing the HE biometric feature data in the accumulated database of generated HE biometric feature data; and

based at least in part on determining the HE biometric feature data is not different from all stored generated HE biometric data in the accumulated database of generated HE biometric feature data, determining the exception status as exception.

19. The method of claim 18 for exception failover augmented, HE encryption and persistent HE, privacy-protective distributed non-decrypting HE domain biometric processing, further comprising:

receiving a biographical information of a user; and

storing the HE biometric feature data in the accumulated database of generated HE biometric feature data to include storing, in association with the generated HE biometric feature data, at least a portion of the biographic information of the user as a stored biographic information.

20. The method of claim 19 for exception failover augmented, HE encryption and persistent HE, privacy-protective distributed non-decrypting HE domain biometric processing, further comprising:

responsive to determining the HE biometric feature data is stored in the accumulated database, comparing the biographic information of the user to the stored biographic information associated with the stored HE biometric feature data;

storing the HE biometric feature data in the accumulated database of generated HE biometric feature data to include storing, in association with the generated HE biometric feature data, at least a portion of the biographic information in the accumulated database of generated HE biometric feature data;

generating a temporary identifier; and

storing a correspondence between the temporary identifier and at least a portion of the biographical information.

Continuity (3)
Division 18080554 · Dec 13, 2022
Provisional Application 63350733 · Jun 9, 2022
Related Publication 20240020368A1 · Jan 18, 2024
References Cited (65)
US 8281148B2 · Tuyls · 2012 [cited by examiner]
US 9325707B2 · Ketchantang · 2016 [cited by applicant]
US 9900147B2 · Laine et al. · 2018 [cited by applicant]
US 9904840B2 · Zhang et al. · 2018 [cited by applicant]
US 11277258B1 · Zhang et al. · 2022 [cited by applicant]
US 11451394B2 · Arora et al. · 2022 [cited by applicant]
US 11496288B1 · Soltani et al. · 2022 [cited by applicant]
US 20060112278A1 · Cohen et al. · 2006 [cited by applicant]
US 20070055889A1 · Henneberry · 2007 [cited by examiner]
US 20080097851A1 · Bemmel et al. · 2008 [cited by applicant]
US 20130035979A1 · Tenbrock · 2013 [cited by applicant]
US 20130148868A1 · Troncoso Pastoriza et al. · 2013 [cited by applicant]
US 20150046990A1 · Oberheide et al. · 2015 [cited by applicant]
US 20150186634A1 · Crandell et al. · 2015 [cited by applicant]
US 20160103984A1 · Warrier · 2016 [cited by applicant]
US 20160204936A1 · Sakemi et al. · 2016 [cited by applicant]
US 20180053005A1 · Kamal · 2018 [cited by applicant]
US 20190044697A1 · Paz de Araujo et al. · 2019 [cited by applicant]
US 20190121951A1 · Nassi · 2019 [cited by examiner]
US 20190278937A1 · Streit · 2019 [cited by applicant]
US 20190280869A1 · Streit · 2019 [cited by examiner]
US 20190370688A1 · Patel · 2019 [cited by applicant]
US 20200044852A1 · Streit · 2020 [cited by applicant]
US 20200136818A1 · Jiang et al. · 2020 [cited by applicant]
US 20200228339A1 · Barham et al. · 2020 [cited by applicant]
US 20200228341A1 · Mohassel et al. · 2020 [cited by applicant]
US 20200259638A1 · Carmignani · 2020 [cited by examiner]
US 20200259896A1 · Sachs et al. · 2020 [cited by applicant]
US 20200358611A1 · Hoang · 2020 [cited by applicant]
US 20210124815A1 · Rindal · 2021 [cited by applicant]
US 20210211290A1 · Jindal et al. · 2021 [cited by applicant]
US 20210211291A1 · Jindal et al. · 2021 [cited by applicant]
US 20210344477A1 · Aharoni et al. · 2021 [cited by applicant]
US 20210377031A1 · Aharoni et al. · 2021 [cited by applicant]
US 20220085971A1 · Zhang et al. · 2022 [cited by applicant]
US 20220103362A1 · Chafni et al. · 2022 [cited by applicant]
US 20220109574A1 · Narumanchi et al. · 2022 [cited by applicant]
US 20220131698A1 · Badrinarayanan et al. · 2022 [cited by applicant]
US 20220277064A1 · Streit · 2022 [cited by applicant]
US 20220300593A1 · Brownlee · 2022 [cited by applicant]
US 20220321348A1 · Isshiki · 2022 [cited by applicant]
US 20220322083A1 · Kreishan et al. · 2022 [cited by applicant]
US 20230011633A1 · Waldron et al. · 2023 [cited by applicant]
US 20230033479A1 · Despiegel et al. · 2023 [cited by applicant]
WO 2019112650A1 · 2019 [cited by applicant]
WO 2022201411A1 · 2022 [cited by applicant]
Otto, Nate et al., Verifiable Credentials Use Cases, W3C Working Group Note Sep. 24, 2019, https://www.w3.org/TR/2019/NOTE-vc-use-cases-20190924. [cited by applicant]
Buolamwini, Joy et al., Gender Shades: Intersectional Accuracy Disparities in Commercial Gender Classification, Proceedings of Machine Learning Research, 81, pp. 1-15, 2018. [cited by applicant]
Gentry, Craig et al., “Homomorphic Encryption from Learning with Errors: Conceptually-Simpler, Asymptotically-Faster, Attribute-Based”, Jun. 8, 2013. [cited by applicant]
Rivest, Ronald et al., On Data Banks and Privacy Homomorphisms, Massachusetts Institute of Technology, Cambridge, Massachusetts, 1978. [cited by applicant]
Paillier, Pascal, “Public-Key Cryptosystems Based on Composite Degree Residuosity Classes”, Springer-Verlag Berlin Heidelberg, EUROCRYPT'99, LNCS 1592, pp. 223-238, 1999. [cited by applicant]
Sing, Harmeet, Public-Key Cryptosystem Based on Composite Degree Residuosity Classes aka Paillier Cryptosystem, Winter 2018. [cited by applicant]
Chillotti, Ilaria et al., “TFHE: Fast Fully Homomorphic Encryption over the Torus”, Journal of Cryptology 33, published Apr. 25, 2019. [cited by applicant]
Boddeti, Vishnu Naresh, “Secure Face Matching Using Fully Homomorphic Encryption” Michigan State University, East Lansing, MI, Jul. 2018. [cited by applicant]
Liu, Qingshan, et al. “Occlusion Robust Face Recognition with Dynamic Similarity Features”, 18th International Conference on Pattern Recognition (ICPR' 2006) 0-7695-2521-0/06, IEEE. [cited by applicant]
Nguyen, Hieu V. and Li Bai, “Cosine Similarity Metric Learning for Face Verification”, DOI: 10.1007/978-3-642-19309-5_55, source: DBLP Nov. 2010, https://www.researchgate.net/publication/220745463. [cited by applicant]
Remani, Naga et al., “Similarity of Inference Face Matching On Angle Oriented Face Recognition”, Journal of Information Engineering and Applications, ISSN 2224-5758 (print), ISSN 2224-896X (online). vol 1, No. 1, 2011. [cited by applicant]
Ahdid, Rachid et al., “Euclidean & Geodesic Distance between a Facial Feature Points in Two-Dimensional Face Recognition System”, International Journal of Neural Networks and Advanced Applications, vol. 4, 2017. [cited by applicant]
Boneh, Dan et al., “Evaluating 2-DNF Formulas on Ciphertexts” Apr. 2, 2006. [cited by applicant]
Vytautas Perlibakas, “Distance measures for PCA-based face recognition”, Pattern Recognition Letters vol. 25 (2004), pp. 711-724. [cited by applicant]
Eugenio A. Silva, “Practical use of Partially Homomorphic Cryptography”, 2016. [cited by applicant]
P. Jonathon Phillips, “Support Vector Machines Applied to Face Recognition”, Advances in Neural Information Processing Systems 11, technical report NISTIR 6241, 1999. [cited by applicant]
Sadeghi, Ahmad-Reza, et al., “Efficient Privacy-Preserving Face Recognition”, ICISC, 2009. [cited by applicant]
TSA Biometrics Roadmap For Aviation Security & the Passenger Experience, Sep. 2018. [cited by applicant]
Chibba, Michelle, et al., “On Uniqueness of Facial Recognition Templates”, NTIA US Department of Commerce, Privacy Multi-stakeholder Process: Facial Recognition Technology, Mar. 2014. [cited by applicant]