IP Library Granted Patent US 12,567,945
Granted Patent B2
US 12,567,945 · App. 18/180,891 · Granted Mar 3, 2026

Enhancing privacy in biometrics-based authentication systems

Inventors: Mohamed Zouhaier Ramadhane (Azcapotzalco, MX); Ricardo Ramos (Lima, PE); Syed Ali (Irvine, CA); Mauro Marzorati (Lutz, FL); Fernando R Zuliani (Newport Beach, CA)
Assignee: International Business Machines Corporation
H04L9/06G06K19/06018H04L9/0866H04L9/3268
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,567,945
App. No.
18/180,891
Granted
Mar 3, 2026
Kind
B2
Abstract

According to one embodiment, a method, computer system, and computer program product for privacy-enhanced, biometrics-based authentication is provided. The embodiment may include capturing credential information on a credential medium and biometric information for a user, each provided by the user, by one or more information capture devices. The embodiment may also include identifying a hash stored on the credential medium based on the captured credential information. The embodiment may further include calculating, locally, a hash of the biometric information using a preconfigured hashing algorithm. The embodiment may also include, in response to the identified hash matching the calculated hash, authenticating the user.

Claims (41)

1 . A processor-implemented method, the method comprising:

capturing user credential information on a credential medium, through a quick reference (QR) code, and biometrics from a user by one or more information capture devices, wherein the credential information comprises encrypted, hashed biometric information specific to the user, and wherein the one or more information capture devices are disconnected from a wide area network (WAN;

identifying a hash stored on the credential medium based on the captured credential information, wherein the hash is a private key in public-private encryption, and wherein the hash comprises a time-variable seed that produces different hashes at different times for a same input;

determining whether the identified hash is signed by an organization based on a read and/or decryption of the identified hash using a public certificate returns an expected result;

calculating, locally, a hash of the biometric information using a preconfigured hashing algorithm;

in response to the identified hash matching the calculated hash, authenticating the user;

determining one or more access restrictions within the captured credential information; and

in response to the user being permitted to a location based on the one or more determined access restrictions, granting the user access to the location.

2 . The method of claim 1 , further comprising:

in response to the identified hash not matching the calculated hash:

denying an authentication of the user; and

notifying the user of the denied authentication.

3 . The method of claim 1 , wherein the one or more information capture devices are selected from a group consisting of a QR code scanner, a barcode scanner, a NFC reader, an RFID scanner, an image capture device, an optical sensor, a capacitive scanner, an ultrasonic sensor, and a thermal line sensor.

4 . A computer system, the computer system comprising:

one or more processors, one or more computer-readable memories, one or more computer-readable tangible storage medium, and program instructions stored on at least one of the one or more tangible storage medium for execution by at least one of the one or more processors via at least one of the one or more memories, wherein the computer system performs a method comprising:

capturing user credential information on a credential medium, through a quick reference (QR) code, and biometrics from a user by one or more information capture devices, wherein the credential information comprises encrypted, hashed biometric information specific to the user, and wherein the one or more information capture devices are disconnected from a wide area network (WAN);

identifying a hash stored on the credential medium based on the captured credential information, wherein the hash is a private key in public-private encryption, and wherein the hash comprises a time-variable seed that produces different hashes at different times for a same input;

determining whether the identified hash is signed by an organization based on a read and/or decryption of the identified hash using a public certificate returns an expected result;

calculating, locally, a hash of the biometric information using a preconfigured hashing algorithm;

in response to the identified hash matching the calculated hash, authenticating the user;

determining one or more access restrictions within the captured credential information; and

in response to the user being permitted to a location based on the one or more determined access restrictions, granting the user access to the location.

5 . The computer system of claim 4 , wherein the method further comprises:

in response to the identified hash not matching the calculated hash:

denying an authentication of the user; and

notifying the user of the denied authentication.

6 . The computer system of claim 4 , wherein the one or more information capture devices are selected from a group consisting of a QR code scanner, a barcode scanner, a NFC reader, an RFID scanner, an image capture device, an optical sensor, a capacitive scanner, an ultrasonic sensor, and a thermal line sensor.

7 . A computer program product, the computer program product comprising:

one or more computer-readable tangible storage medium and program instructions stored on at least one of the one or more tangible storage medium, the program instructions executable by a processor performing a method, the method comprising:

capturing user credential information on a credential medium, through a quick reference (QR) code, and biometrics from a user by one or more information capture devices, wherein the credential information comprises encrypted, hashed biometric information specific to the user, and wherein the one or more information capture devices are disconnected from a wide area network (WAN);

identifying a hash stored on the credential medium based on the captured credential information, wherein the hash is a private key in public-private encryption, and wherein the hash comprises a time-variable seed that produces different hashes at different times for a same input;

determining whether the identified hash is signed by an organization based on a read and/or decryption of the identified hash using a public certificate returns an expected result;

calculating, locally, a hash of the biometric information using a preconfigured hashing algorithm;

in response to the identified hash matching the calculated hash, authenticating the user;

determining one or more access restrictions within the captured credential information; and

in response to the user being permitted to a location based on the one or more determined access restrictions, granting the user access to the location.

8 . The computer program product of claim 7 , wherein the method further comprises:

in response to the identified hash not matching the calculated hash:

denying an authentication of the user; and

notifying the user of the denied authentication.

9 . The computer program product of claim 7 , wherein the one or more information capture devices are selected from a group consisting of a QR code scanner, a barcode scanner, a NFC reader, an RFID scanner, an image capture device, an optical sensor, a capacitive scanner, an ultrasonic sensor, and a thermal line sensor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 9, 2023
From: RAMADHANE, MOHAMED ZOUHAIER; RAMOS, RICARDO; ALI, SYED; MARZORATI, MAURO; ZULIANI, FERNANDO R
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 062927/0732 →
Continuity (1)
Related Publication 20240305441A1 · Sep 12, 2024
References Cited (22)
US 9619639B2 · Donenfeld · 2017 [cited by applicant]
US 9715686B2 · Sadacharam · 2017 [cited by applicant]
US 10931461B2 · Dilles · 2021 [cited by applicant]
US 10990776B2 · Azanza Ladrón · 2021 [cited by applicant]
US 11165581B2 · Hunt · 2021 [cited by applicant]
US 20040243806A1 · McKinley · 2004 [cited by examiner]
US 20120138679A1 · Doyle · 2012 [cited by applicant]
US 20130214043A1 · Kong · 2013 [cited by applicant]
US 20160071101A1 · Winarski · 2016 [cited by applicant]
US 20160248759A1 · Tsurumi · 2016 [cited by examiner]
US 20170053252A1 · Votaw · 2017 [cited by applicant]
US 20170085562A1 · Schultz · 2017 [cited by examiner]
US 20170243041A1 · Arce · 2017 [cited by examiner]
US 20170264608A1 · Moore · 2017 [cited by applicant]
US 20180075229A1 · Jan · 2018 [cited by examiner]
US 20200042685A1 · Tussy · 2020 [cited by applicant]
US 20210011986A1 · Tussy · 2021 [cited by applicant]
US 20220103362A1 · Chafni · 2022 [cited by applicant]
GB 2600924A · 2022 [cited by applicant]
JP 2006503374A · 2006 [cited by applicant]
KR 101561170B1 · 2015 [cited by applicant]
Choudhury et al., “Biometric Passport Security by Applying Encrypted Biometric Data Embedded in the QR Code”, Part of the Advances in Intelligent Systems and Computing book series, AISC, vol. 1079, Springer, Jan. 2020, … [cited by applicant]