Systems and methods for intertwined authentication of biosensors and biosensor outputs
Integrating a biometric sensor with a secure element through a dedicated interface ensures authentic biometric data acquisition, addressing spoofing attacks on mobile devices by cryptographically entangling the data, enhancing security and privacy.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-04-29
- Publication Date
- 2026-03-06
AI Technical Summary
Biometric sensors on mobile devices are vulnerable to spoofing attacks where malicious actors replace the fingerprint sensor with unauthorized circuitry to provide pre-recorded data for authentication, compromising privacy and security, especially in transactions and access control.
Integrate a biometric sensor with a secure element, such as a low-cost serial interface secure element, using a dedicated communication interface to ensure that the biometric data is cryptographically entangled with a cryptographic response, making it inseparable and verifiable as originating from the correct sensor.
Enhances security by ensuring that the biometric data is authentic and acquired from a living subject, preventing spoofing attacks while maintaining a low-cost and efficient solution without significant modifications to the host or sensor.
Smart Images

Figure 0007825639000004 
Figure 0007825639000005 
Figure 0007825639000006
Abstract
Description
[Technical Field]
[0001] Embodiments of the present disclosure relate generally to sensors, including biometric sensors (also referred to as biosensors), authentication, encryption, privacy, fraud prevention, privacy, and security, and more particularly to systems and methods for entangled authentication of biometric sensors and biometric sensor outputs. [Background technology]
[0002] In today's modern world, there are many situations where it is important for devices, systems of devices, networks, etc. to be able to confirm (i.e., verify, validate, etc.) that individuals, such as employees, customers, authorized users of a particular device, are who they claim to be. The process of confirming (or at least attempting to confirm) the identity of individuals (and devices) is commonly referred to as authentication. This is distinct from authorization, which enables control over the specific resources that properly authenticated individuals and / or devices can access.
[0003] Generally, as is well known in the art and as exemplified herein, authenticating an individual requires demonstrating what that individual "knows," "has," and / or "is." Examples of what an individual "knows" (or may know) include a password, a personal identification number (PIN), answers to one or more security questions, frequently changing authentication codes, etc. Examples of what an individual "has" (or may have) include an access card, a smart card, a particular mobile device, etc. Finally, examples of what an individual "is" (or may have) include a particular fingerprint, a particular voiceprint, a particular face (e.g., facial structure), a particular retina, a pair of retinas, etc. Of course, a fingerprint does not represent the entire person, but such terms are commonly used in the art.
[0004] In the field of biometric sensors, threats to systems equipped with such sensors are ever-present, involving repeated attempts by malicious actors to gain access to various resources that are at least partially protected by one or more sensors. These access attempts may include, for example, unauthorized physical entry into a building or other secured space (e.g., an office, laboratory, or storage room), unauthorized login to a protected system, making fraudulent purchases or transfers, or obtaining personal information. Perpetrators of such attacks often masquerade as legitimate users of the relevant systems. Whether human or computerized (e.g., so-called "bots"), these malicious actors are persistent and continually adjust their attack strategies to evade defenses. In response, defenses evolve in response to these attacks. [Brief explanation of the drawings]
[0005] Details can be seen from the following description taken in conjunction with the drawings, in which like elements are numbered like, and in which: [Figure 1] FIG. 1 illustrates a first example communication configuration according to at least one embodiment. [Figure 2] FIG. 10 illustrates a second example communication configuration according to at least one embodiment. [Figure 3] FIG. 10 illustrates a third example communication configuration according to at least one embodiment. [Figure 4] FIG. 1 illustrates a first example architecture of a secure biometric sensor system according to at least one embodiment. [Figure 5] FIG. 1 illustrates a second example architecture of a secure biometric sensor system according to at least one embodiment. [Figure 6] FIG. 1 illustrates a first example of an information flow diagram, showing an example configuration in which both an example host and an example biometric sensor use multiple corresponding hash functions, according to at least one embodiment. [Figure 7]FIG. 10 illustrates a second example information flow diagram, illustrating an example configuration in which both an example host and an example biometric sensor use a single corresponding hash function, according to at least one embodiment. [Figure 8] FIG. 10 illustrates a third example information flow diagram and a first example configuration in which an example host and an example biometric sensor use a common encryption and decryption method, according to at least one embodiment. [Figure 9] FIG. 10 illustrates a fourth example information flow diagram, and a second example configuration in which an example host and an example biometric sensor use a common encryption and decryption method, according to at least one embodiment. [Figure 10] FIG. 10 illustrates a fifth example information flow diagram and a third example configuration in which an exemplary host and an exemplary biometric sensor use a common encryption and decryption method, according to at least one embodiment. [Figure 11] FIG. 1 illustrates an exemplary method performed, for example, by a biometric sensor or secure biometric sensor system, according to at least one embodiment. [Figure 12] FIG. 1 illustrates an exemplary computer system configured to execute at least one embodiment and / or embody one or more devices, systems, etc., in accordance with at least one embodiment. [Figure 13] FIG. 13 illustrates an example software architecture that can be implemented in a computer system, such as the example computer system of FIG. 12, in accordance with at least one embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0006] Currently, various types of biometric sensors are commercially available, and many more are expected to be available in the future. Examples of types of biometric sensors include fingerprint scanners, retinal scanners, voiceprint identification devices, facial recognition scanners, etc. While this disclosure primarily describes fingerprint scanners (also referred to herein as fingerprint sensors), this is by way of example and not limitation. Embodiments of the present disclosure are equally applicable to other types of biometric sensors, and may also be applicable to a wide variety of other sensors (e.g., temperature sensors, motion detectors, glass break sensors, pressure sensors, proximity sensors, gas (e.g., carbon monoxide) detectors, location determination systems, etc.). Validating that data has been legitimately acquired by a particular sensor is beneficial in many fields. Furthermore, verifying the integrity of acquired data is closely related to and important for authentication.
[0007] In traditional configurations, fingerprint sensors are often integrated into large, fixed systems such as kiosks, ATMs (automated teller machines), point-of-sale devices, etc. In such installations, there is a relatively high degree of confidence that a given fingerprint image was acquired by the fingerprint sensor integrated into a particular device or system, because such physically secured, fixed systems are often directly controlled and / or monitored by interested parties (e.g., store employees, bank employees, government officials, etc.).
[0008] Among other ideas and objectives, embodiments of the present disclosure arise from the recognition and understanding that fingerprint sensors used to authenticate one or more individuals (e.g., for physical access, payment transactions, etc.) are increasingly being deployed on mobile devices such as smartphones, tablets, laptops, netbooks, ID tokens, and smart cards (e.g., smart credit cards). In a typical scenario, an individual owns or is the authorized user of a smartphone (an example of a mobile device). Such an individual may have purchased or rented a smartphone from a service provider, may have received a smartphone from an employer, or may be the account holder for a smartphone service plan subscription, for example. An individual uses the fingerprint sensor on the smartphone to approve purchases, app downloads, viewing of personal information (e.g., saved passwords), or for other purposes that require identity authentication to access information or perform (or authorize) certain functions or transactions.
[0009] Embodiments of the present disclosure also arise from the recognition and understanding that fingerprint sensors on mobile devices (and some other devices) are relatively simple devices that malicious actors can often successfully spoof using pre-recorded data (e.g., stored fingerprint images, etc.). An attacker may gain physical access to a device that includes a fingerprint sensor or to which the fingerprint sensor is at least temporarily connected (e.g., using a Universal Serial Bus (USB) port). Once an attacker has gained physical access, they can replace the fingerprint sensor with another sensor or other electronic circuitry that is configured and / or programmed, etc., to transmit pre-recorded data for authentication.
[0010] Attacks such as these are facilitated by the fact that the interface between a typical host (e.g., a smartphone) and a typical fingerprint sensor is often standard and relatively simple. Furthermore, digital samples of valid fingerprint images have proven easy to obtain by attackers. This problem is exacerbated when there is no tight coupling between the host and the fingerprint sensor that authenticates (or rejects) the presented fingerprint (or other biometric reading), such as over a network connection.
[0011] Furthermore, embodiments of the present disclosure arise from a recognition and appreciation of the importance of preventing fingerprint sensors used to authorize the downloading, transfer, viewing, etc. of sensitive information, or to authorize the execution of purchases, trades, and other financial transactions, etc., from being replaced with unauthorized circuitry configured to provide a pre-recorded image or other data to a host for authentication (rather than a proper biometric sensor that provides biometric data actually obtained from a living human being who is “biometric,” i.e., in the vicinity of and in physical contact with the sensor). This importance is particularly evident when the device is a mobile device or a device used by an individual user (e.g., a consumer). Replacing the fingerprint sensor in such a device with an effective emulator could create a variety of problems for individuals and organizations (e.g., businesses), including privacy and financial issues.
[0012] Many solutions have been attempted in conventional configurations. Some solutions involve physically placing a sealed protective case around both the sensor and the processing system (e.g., a host that determines whether a fingerprint image is authentic) or disabling the sensor and / or the entire device if physical tampering is detected. Another approach currently used in some configurations involves incorporating a technology called a physically unclonable function (PUF) into the sensor and using the embedded PUF to authenticate the sensor. This approach is costly, at least in terms of chip area (i.e., silicon area), and PUF-based authentication has been shown to be susceptible to being defeated by attackers. Furthermore, the security of PUF-based authentication is often problematic.
[0013] To overcome the problems of conventional configurations, embodiments of systems and methods for intertwined authentication of a biometric sensor and biometric sensor output are disclosed herein. In embodiments of the present disclosure, a biometric sensor (such as a fingerprint sensor) is physically coupled with a so-called secure element, e.g., molded into the same packaging substrate as the secure element. The following points are noted with respect to various different embodiments:
[0014] Exemplary communications and functions performed by a host to which a particular (e.g., solid-state) biometric sensor (or secure biometric sensor system) is communicatively connected Exemplary communications and functionality related to a biometric sensor (or secure biometric sensor system) Exemplary communications and functions related to the secure element In order to avoid repetition of expressions such as "biometric sensor (or system)", "biometric sensor (or secure biometric sensor system)", etc., in this disclosure the term "biometric sensor" will be understood to refer to "biometric sensor, secure biometric sensor system, biometric sensor as part of such system, etc." unless expressly specified otherwise or clear from the context.
[0015] The secure element will now be described. As is known in the art, the secure element has a relatively simple communication interface (e.g., two wires (or pins, pads, etc.)) in the IC field. Furthermore, in embodiments of the present disclosure, a biometric sensor is communicatively interposed between a host that verifies a biometric reading (e.g., a fingerprint image) and the secure element. The biometric sensor is communicatively connected to the host via a first communication interface and to the secure element via a separate, second communication interface. The second communication interface is dedicated to the biometric sensor (i.e., it is not directly available to the host, but only via the biometric sensor). Thus, one advantage of embodiments of the present disclosure is that to the host, the secure biometric sensor system (including the biometric sensor and secure element) of embodiments of the present disclosure appears, at least physically and with respect to communication protocols, as a conventional biometric sensor.
[0016] Recently, low-cost serial interface secure elements have emerged as effective technology components for assigning a cryptographic identity to a specific device or other system. This cryptographic identity can be proven and verified using one or more cryptographic protocols, as described in more detail below. As previously mentioned, secure elements are often low-pin-count integrated circuits, typically bare silicon die or chip-scale packages (CSPs). CSPs are a type of integrated circuit package and are specified in J-STD-012, entitled "Flip-Chip and Chip-Scale Technology Implementations." J-STD-012 is published by a trade association known as IPC.
[0017] In various embodiments, the communication interface used between the biometric sensor and the secure element is an Inter-Integrated Circuit ("IIC"). 2 The biometric sensor operates according to a protocol (or format) such as "Inter-C" or "I2C" (Inter-Interface). In contrast, a separate and independent interface between the biometric sensor and a given host operates according to a protocol such as USB, Serial Peripheral Interface (SPI), Ethernet, Wi-Fi, Bluetooth, infrared, RF, etc. In general, the two interfaces can use the same or different protocols, and one or both can be any protocol deemed optimal by those skilled in the art depending on the configuration or situation.
[0018] In some embodiments, the sensor die (i.e., the die on which the fingerprint sensor component is located) may be configured with a simple one-wire or two-wire interface (I 2The secure element is connected by a dedicated connection via a private key (such as via a private key) to the secure element. In some embodiments, it can perform several cryptographic calculations to generate a so-called message authentication code (MAC). The MAC can be any of a variety of MACs used in the art. For example, the MAC can be a hash-based MAC (HMAC), also known in the art as a "keyed-hash MAC." An HMAC is typically generated by processing a message or other data using a cryptographic hash function in conjunction with a secret key.
[0019] In another example, the MAC is a type of MAC based on a block cipher. For example, the MAC is a cipher-block-chaining MAC (CBC-MAC). CBC-MAC uses an encryptor that uses a block cipher to create a "chain" of blocks. To encrypt a given block, the encryptor must have properly encrypted the previous block, thus forming the chain. This property—that each block (except the first) depends on the block immediately preceding it—means that any changes to the plaintext bits of the message (or fingerprint image, etc.) will unpredictably and irreversibly change the final block. This ensures security, as the decryptor must have the encryption key to properly decrypt the message.
[0020] It should be noted that for the purposes of this disclosure, regardless of whether a particular key is used at a given time to encrypt or decrypt a message, the key will be referred to as an "encryption key" in both contexts (we do not use "encryption key" or "decryption key" for the same value at different times, as this could be confusing and would obscure that they are, in fact, the same value). Encryption keys are also sometimes referred to herein as "session keys," "temporary session keys," etc.
[0021] As noted above, in some embodiments, the biometric sensor communicates with the host via a first communication interface (such as using USB or SPI). In addition to using this interface to read fingerprint images and set the biometric sensor's operational registers, the host can use the first interface of the present disclosure to perform one or more of the many authentication processes supported by the biometric sensor that utilize the biometric sensor itself or the functionality of the secure element. Of the exemplary authentication processes described herein, the biometric sensor of the presently disclosed embodiments supports one or more of the following:
[0022] 1. Authenticating the biometric sensor itself (i.e., as a device) to the host. 2. Authenticating the fingerprint image captured by the biometric sensor, and at the same time inherently authenticating the biometric sensor itself.
[0023] 3. An authentication process as in 2 above, where at least the relevant communications between the sensor and the host are encrypted (e.g., encrypted using a temporary session key). Relevant communications are, for example, communications containing the fingerprint actually sent for authentication purposes (as opposed to communications for administrative purposes such as calibrating the pixel array).
[0024] In particular, with regard to the first of the three authentication processes above, i.e., the process by which the biometric sensor authenticates itself as a device to the host, the host may perform such a process periodically, for example, after a predetermined number of images, at the user's request, when a specific trigger event is detected, etc. However, in at least one embodiment, the first process above is unnecessary if each image is itself authenticated as it is captured (i.e., the second or third authentication process above is performed), and this (whether to keep authentication on for all images) can be determined by the host.
[0025] It should be noted that even in embodiments in which the host authenticates "all" images from the biometric sensor, there will be intervening images that are not authenticated. For example, even if the host configures the biometric sensor to authenticate "all" images, images that are captured but not used for authentication, such as images used to calibrate (e.g., focus) the pixel array that captures the fingerprint image, will not be authenticated. Such "calibration images" may simply be discarded by the host and / or the biometric sensor. Such calibration images may also be used in a kind of forward feedback loop that iteratively adjusts the settings of one or more registers in the biometric sensor to achieve focus for the image that will ultimately be the subject of an authentication attempt. Other approaches may also be employed.
[0026] In this manner, embodiments of the present disclosure can significantly enhance the security of sensors, such as fingerprint sensors, in an efficient, low-cost manner that does not require significant modifications to either the host or the sensor. Embodiments of the present disclosure significantly improve the protection of biometric readings, such as by combining image source data and cryptographic response source data at the sensor, in the example of a fingerprint image, such that the combination cannot be intelligibly separated until a host equipped with a coding sequence corresponding to the sensor-side coding sequence receives and processes the cryptographically entangled image and cryptographic data at the sensor.
[0027] The image data and the encrypted ID proof data are combined and entangled at the sensor side. The entangled data is then used as input to at least one cryptographic process or function (e.g., hashing, encryption, etc.) at the sensor side. Verification of this cryptographically entangled data (e.g., successful comparison of hash results, successful decryption, etc.) at the host side provides confirmation by the host that the corresponding image was indeed captured from a living body by that particular biometric sensor. In this way, authenticating a particular image essentially simultaneously authenticates that the image was captured by that sensor. Various embodiments are described in more detail later in this disclosure. One advantage of embodiments of the present disclosure is that data transfer and authentication are combined into a single process (e.g., a series of operations). In various embodiments, this and other advantages are achieved by utilizing low-cost secure elements that are readily available on the market.
[0028] In some embodiments, the sensor-acquired data acquired by a fingerprint sensor may include, in addition to a fingerprint image, data referred to in the art as “liveness sensing data.” The purpose of acquiring this data is to verify that the fingerprint image was acquired from a real finger of a living person present near the sensor. Such data may include, for example, measurements of skin temperature, pulse (i.e., heart rate), blood pressure, pulse oximetry, sweat, electrical conductance, and the like. In some examples, one or more machine learning models are trained to classify fingerprints as “live” or “non-live,” and the classification results (and / or associated confidence levels, etc.) are used as part of authentication. Thus, as used herein, terms and phrases such as “image data,” “fingerprint image data,” “fingerprint image,” and “sensor data” should be understood to encompass liveness sensing data in at least one embodiment. Accordingly, in at least one embodiment, the data combined and intertwined at the sensor side for host-side verification includes fingerprint and liveness sensing data.
[0029] Furthermore, in embodiments of the present disclosure, in addition to the image data being inseparable from the authentication data, enhanced security is also achieved by the biometric sensor and secure element being physically coupled together as part of a secure biometric sensor system. Not only can a host trust that a successful authentication based on the information ensures that the associated image was acquired from a living subject by the correct sensor, but in at least some embodiments, the host's trustworthiness is enhanced by the biometric sensor and secure element being integral parts of a single physical assembly. The very fact that the biometric sensor and secure element are provided together (e.g., by molding) in a single physical package enhances security. In at least some embodiments, it is impossible or extremely difficult to separate a biometric sensor from its corresponding secure element without disabling the functionality of the secure biometric sensor system itself.
[0030] Embodiments of the present disclosure also have the advantage of using less board area in situations where area is at a premium. In this regard, cost is often measured in dollars per square millimeter (mm). Additionally, there are physical size constraints (e.g., the surface area of a typical fingerprint). Furthermore, no high-power elements, such as additional memory modules, are required. These features make embodiments of the present disclosure not only more streamlined but also reduce manufacturing costs and overhead compared to other approaches.
[0031] Additionally, the convenience and security provided by embodiments of the present disclosure are further enhanced by the above-described configuration in which a biometric sensor is communicatively interposed between the host and the secure element. Thus, in some embodiments, the communication interface between the host and the biometric sensor can remain structurally identical (as in conventional configurations), but in addition, at least some embodiments are configured such that only the biometric sensor can communicate directly with the secure element. In such embodiments, communications that demonstrate successful engagement of the correct secure element can be trusted by the host to have been sent via the correct biometric sensor. Because the cryptographically altered image data and the cryptographic authentication data are inseparable, it is possible to verify that the correct secure element was engaged via the correct biometric sensor. Aspects of various embodiments are described in further detail throughout this disclosure.
[0032] One embodiment is configured as a secure biometric sensor system including a secure element and a biometric sensor physically coupled to one another. The biometric sensor is configured to communicatively interpose between a host and the secure element. The biometric sensor has logic that, when executed by at least one hardware processor of the biometric sensor, causes the biometric sensor to perform a process including receiving a cryptographic challenge from the host, transferring the cryptographic challenge to the secure element, obtaining a biometric reading using the biometric sensing element, and transmitting the obtained biometric reading to the host. The process includes receiving from the secure element a cryptographic response calculated by the secure element based on the cryptographic challenge. The cryptographic response includes a shared secret between the host and the secure element. The process further includes generating a cryptographically entangled token from a predetermined combination of read-related data and the shared secret. The read-related data includes one or both of the biometric reading and data derived from the biometric reading. The process further includes transmitting the cryptographically entangled token to the host for use by the host in attempting to authenticate that the captured biometric reading was captured by the biometric sensor.
[0033] Another embodiment is embodied as a biometric sensor having a first communication interface and a second communication interface. The biometric sensor is configured to communicatively interpose between a host and a secure element via the first communication interface and the second communication interface. The biometric sensor and the secure element are physically coupled to each other. The biometric sensor also has logic that, when executed by at least one hardware processor of the biometric sensor, causes the biometric sensor to perform a process including receiving a cryptographic challenge from the host, forwarding the cryptographic challenge to the secure element, obtaining a biometric reading using the biometric sensing element, and transmitting the obtained biometric reading to the host. The process includes receiving from the secure element a cryptographic response calculated by the secure element based on the cryptographic challenge. The cryptographic response includes a shared secret between the host and the secure element. The process further includes generating a cryptographically entangled token from a predetermined combination of the read-related data and the shared secret. The read-related data includes one or both of the biometric reading and data derived from the biometric reading. The process further includes transmitting the cryptographically entangled token to the host for use by the host in attempting to authenticate that the captured biometric reading was captured by the biometric sensor.
[0034] Yet another embodiment is embodied as a method performed by a biometric sensor executing stored instructions. The method includes receiving a cryptographic challenge from a host, the biometric sensor communicatively interposed between the host and a secure element. The biometric sensor and the secure element are physically coupled to one another. The biometric sensor forwards the cryptographic challenge to the secure element, acquires a biometric reading using the biometric sensing element, and transmits the acquired biometric reading to the host. The biometric sensor also receives a cryptographic response from the secure element calculated by the secure element based on the cryptographic challenge. The cryptographic response includes a shared secret between the host and the secure element. The biometric sensor generates a cryptographically entangled token from a predetermined combination of read-related data and the shared secret. The read-related data includes one or both of the biometric reading and data derived from the biometric reading. The biometric sensor transmits the cryptographically entangled token to the host for use by the host in attempting to authenticate that the acquired biometric reading was acquired by the biometric sensor.
[0035] As described herein, one or more embodiments of the present disclosure are embodied as a method including a plurality of processes. One or more other embodiments include at least one hardware processor and one or more non-transitory computer-readable storage media storing instructions that, when executed by the at least one hardware processor, cause the at least one hardware processor to perform a plurality of processes (which in some embodiments correspond to processes performed in embodiments of the disclosed method, but in other embodiments do not correspond). Yet one or more other embodiments are embodied as one or more non-transitory computer-readable storage media storing instructions that, when executed by the at least one hardware processor, cause the at least one hardware processor to perform a plurality of processes (which in some embodiments correspond to processes performed in embodiments of the disclosed method and / or processes performed in embodiments of the disclosed system).
[0036] Furthermore, many variations and permutations of the above-described embodiments are described herein, and any variation or permutation described in this disclosure may be implemented in any type of embodiment. For example, variations and permutations described in this disclosure primarily in connection with method embodiments may also be embodied in connection with system embodiments and / or non-transitory computer-readable storage medium embodiments. This flexibility and interoperability of such embodiments is not dependent on slight differences in the language (e.g., process, process flow, method, technique, step, operation, function, etc.) used to describe and / or define the embodiments and / or their elements.
[0037] FIG. 1 illustrates an exemplary communication configuration 100 according to at least one embodiment. As shown in FIG. 1, the communication configuration 100 includes a secure biometric sensor system 102 and a host 104, where the host 104 controls access to a resource 106. The resource 106 is intended to be a generic term, such as a physical space, a computer system, an online resource, or personal information (e.g., medical information, financial information, etc.) of one or more users. In the described example, the host 104 grants or denies access to the resource 106 based on its communication with the secure biometric sensor system 102 and its processing of information received from the secure biometric sensor system 102. In some configurations, the host 104 grants access if it authenticates the currently presented fingerprint and denies access otherwise. In other configurations, the host 104 grants access as soon as the presented fingerprint is authenticated, but provides another opportunity, such as a request for additional information, if authentication is not immediately successful.
[0038] The host 104 may comprise, for example, a microcontroller or microprocessor (e.g., ARM CM4, ARM CM7, ARM Cortex A9, etc.). Generally, the host 104 may be any computing and communication device appropriately equipped and configured (e.g., programmed) to perform the host processes described herein, or a combination of multiple devices that collectively perform the host processes. The secure biometric sensor system 102 and the host 104 may be located at a common geographic location, such as, but not limited to, a single computing device (e.g., a smartphone) or other enclosure. Generally, the secure biometric sensor system 102 and the host 104 may be separated by any distance and communicate with each other via one or more networks.
[0039] Communication between the secure biometric sensor system 102 and the host 104 may be wired and / or wireless. In the example primarily described herein, the host 104 and the secure biometric sensor system 102 are connected via a wired serial interface such as USB, SPI, etc. Furthermore, in the example primarily described herein, the biometric sensor 108 is one component of the secure biometric sensor system 102 that communicates directly with the host 104. In addition to the biometric sensor 108, the secure biometric sensor system 102 includes a secure element 110, and the biometric sensor 108 and the secure element 110 are physically coupled by a physical coupling 112.
[0040] As with resource 106, physical coupling 112 is intended to be generic, and in embodiments, any physical coupling between biometric sensor 108 and secure element 110 is used where appropriate. For example, in some embodiments, physical coupling 112 is configured as or at least includes a common package substrate on which both biometric sensor 108 and secure element 110 are molded. In some embodiments, biometric sensor 108 and secure element 110 are provided on separate dies and then bonded together by known methods (such as by die-to-die bonding). In at least one embodiment, physical coupling 112 is configured to prevent tampering, such that physical separation of biometric sensor 108 from secure element 110 renders secure biometric sensor system 102 inoperable.
[0041] The host 104 and the biometric sensor 108 communicate via a host / sensor interface 116 using a host-sensor communication path 114. This communication may occur via a serial interface, a parallel interface (such as a camera interface), a network connection, or a wireless interface such as Bluetooth or Wi-Fi. Additionally, the biometric sensor 108 and the secure element 110 communicate via a sensor / secure element interface 120 using a sensor-secure element communication path 118. Communication between the biometric sensor 108 and the secure element 110 is performed via an I / O interface. 2 C or other suitable protocols.
[0042] The secure element 110 may be an IC (e.g., a commercially available IC such as the NXP A1006) that contains one or more secrets and one or more private keys. These secrets and private keys provide a unique cryptographic identity for the secure element 110 and, therefore, for devices such as the biometric sensor 108 that are tightly coupled to the secure element 110. This unique cryptographic identity may be verified using a challenge-response authentication scheme or other well-known methods. Additionally, the secure element 110 may store a digital certificate cryptographically signed by an appropriate entity, such as the manufacturer of the secure biometric sensor system 102. In at least one embodiment, the host 104 also stores a copy of the secure element 110's digital certificate and uses this copy to verify one or more data blocks that the secure element 110 digitally signed with its own digital signature. In some embodiments, the host 104 itself contains a secure element (not shown).
[0043] In at least one embodiment, with respect to communications conducted over the sensor / secure element interface 120, the biometric sensor 108 functions as the controlling component and the secure element 110 functions as the corresponding controlled component. While this relationship is sometimes referred to in the art as a “master-slave” relationship, the terms “controlling component” and “controlled component” are used instead in this disclosure. The biometric sensor 108 may also function as a serial clock to synchronize communications between the biometric sensor 108 and the secure element 110. Similarly, in at least one embodiment, with respect to communications conducted over the host / sensor interface 116, the host 104 functions as the controlling component and the biometric sensor 108 functions as the controlled component.
[0044] In various embodiments and in various cases, the host 104 selects or is instructed to operate in a mode in which it simply reads unauthenticated fingerprints at least for some time. It may also have a mode in which it authenticates all fingerprints. Alternatively or additionally, the host 104 may have a mode in which it authenticates some but not all fingerprints, and may operate to authenticate one or more fingerprints at regular intervals, at regular intervals after each fingerprint scanner scan, randomly, depending on required resources, and / or in other ways. In one embodiment, the host 104 instructs the biometric sensor 108 regarding its current operating mode, at least in part, by writing specific values and / or commands to one or more registers or other storage elements within the biometric sensor 108. These registers are referred to herein as “authentication registers” because they are dedicated to authentication-related tasks.
[0045] In some embodiments, the host 104 instructs the biometric sensor 108 to authenticate itself to the host 104 on a case-by-case basis (e.g., periodically, by one of the examples above, or another method). Before describing such examples, it should be noted that in many of the examples described below with reference to various figures and / or combinations of figures, the host 104 authenticates that a fingerprint image was acquired by the biometric sensor 108. However, in the examples described next, the host 104 requests that the biometric sensor 108 authenticate itself as a device. This process may additionally or alternatively be initiated by the biometric sensor 108.
[0046] To authenticate the biometric sensor 108 (or the secure biometric sensor system 102) as a device, the host 104 may store a copy of a digital certificate unique to the secure element 110. This certificate may be used for other purposes, such as verifying the digital signature of image data sent from the biometric sensor 108 to the host 104, as described below. Continuing with the example of authenticating the biometric sensor 108 as a device, the host 104 first sends a read command to the biometric sensor 108 via the host / sensor interface 116, and this read is forwarded from the biometric sensor 108 to the secure element 110. The host 104 then sends a cryptographic challenge (a random number with a multiplier, a point on a particular elliptic curve, etc., depending on the technical capabilities of the secure element) to the biometric sensor 108, which in turn forwards it to the secure element 110.
[0047] The biometric sensor 108 includes logic referred to herein as "sensor authentication logic." The biometric sensor 108 executes this logic to perform the above and various other operations. The secure element 110 calculates a response to the generated challenge and communicates the response to the biometric sensor 108. The biometric sensor 108 transmits the response to the host 104. The host 104 then authenticates the biometric sensor 108 as a device by verifying the authenticity of the response. The biometric sensor 108 then forwards the reading (taken by the host 104) to itself, i.e., the biometric sensor 108. The secure element 110 may digitally sign the response using its digital certificate, which the host 104 can verify using its copy of the certificate. The above process of authenticating the biometric sensor 108 as a device to the host 104 takes approximately 60 milliseconds (ms), with the majority of this time (~50 ms) being spent by the secure element 110 calculating the response to the challenge.
[0048] Other examples of image authentication (i.e., essentially sensor authentication) are described below. While the host 104's device authentication of the biometric sensor 108 is somewhat useful, it leaves the host 104 vulnerable to attacks. For example, a malicious actor could intervene between the host 104 and the biometric sensor 108 and transmit a pre-recorded fingerprint image as if it came from the biometric sensor 108, thereby spoofing the biometric sensor 108. This is one example of a problem addressed by embodiments of the present disclosure. In embodiments, the fingerprint image itself is authenticated by the host 104; specifically, the host 104 authenticates that the confirmed image was acquired by the biometric sensor 108. This essentially authenticates the biometric sensor 108 to the host 104 as a device.
[0049] FIG. 2 illustrates an exemplary communications configuration 200 according to at least one embodiment. Similar to communications configuration 100 of FIG. 1, communications configuration 200 of FIG. 2 also includes a host 104 and a resource 106, as well as a host / sensor interface 116 and a sensor / secure element interface 120 (shown in communications configuration 200). Host 104 includes a host component 204 and a protocol A control component 206. Host component 204 is a generic term that collectively represents each component of host 104, including memory, other data storage devices, one or more processors, one or more other communications interfaces, and any user interfaces. Details of the host's internal architecture may vary depending on the configuration.
[0050] Communication configuration 200 further includes secure biometric sensor system 202. Secure biometric sensor system 202 includes (i) a biometric sensor 208 including a sensor die 214 and (ii) a secure element die 216, which are physically coupled to one another via a physical coupling 212, which may be, for example, die-to-die bonding, as is well known to those skilled in the art. Sensor die 214 includes a protocol A controlled component 218, sensor registers 220, a fingerprint sensor array 222, sensor authentication logic 230, authentication registers 232, and a protocol B control component 234. If SPI is used as an exemplary protocol for communication between host 104 and secure biometric sensor system 202 via host / sensor interface 116, protocol A control component 206 is an SPI control component, and protocol A controlled component 218 is an SPI controlled component.
[0051] The sensor register 220 and the fingerprint sensor array 222 communicate control and status messages 224. Once a fingerprint is scanned, the fingerprint sensor array 222 sends a fingerprint image 226 (collectively shown as "sensor data" in FIG. 2) to the protocol A controlled component 218. A copy of the fingerprint image 226 is also sent to the sensor authentication logic 230 via junction 228. The protocol A controlled component 218 communicates with the sensor register 220, the sensor authentication logic 230, and the authentication register 232 for various purposes described herein.
[0052] In addition to receiving fingerprint images 226 from fingerprint sensor array 222 and communicating with protocol A controlled component 218 as described above, sensor authentication logic 230 also communicates with sensor register 220, authentication register 232, and protocol B control component 234. Furthermore, authentication register 232 communicates with protocol B control component 234 in addition to communicating with protocol A controlled component 218 and sensor authentication logic 230 as described above.
[0053] Additionally, the protocol B control component 234 communicates with the sensor authentication logic 230 and the authentication register 232, as well as with the protocol B controlled component 236. The protocol B controlled component 236 is provided on the secure element die 216 along with the secure element 210. An exemplary protocol for communication between the biometric sensor 208 and the secure element 210 is I / O. 2 If C is used, the protocol B control component 234 2 C controlling component, and Protocol B controlled component 236 is I 2 Additionally, although the secure element 210 and the protocol B controlled component 236 are shown as separate components in FIG. 2 for purposes of illustration, the secure element 210 itself may be a 2It may also be a component that is (partly) controlled according to C and / or one or more other protocols.
[0054] Fingerprint sensor array 222 may be a pixel array or other sensing array and / or element as is well known. Sensor registers 220 may be set to various values by host 104 to configure fingerprint sensor array 222 to operate in various ways and modes. Authentication registers 232 are used as resources by sensor authentication logic 230 and secure element 210, via protocol B control component 234 and protocol B controlled component 236, to perform various authentication-related tasks and functions described in this disclosure. In other embodiments, authentication registers 232 are used for various other purposes, such as control registers, status registers, data registers, etc.
[0055] In operation, the secure biometric sensor system 202 performs one or more of the processes described herein by executing the sensor authentication logic 230. For example, the secure biometric sensor system 202 is configured (e.g., programmed) to perform the method 1100 and many of the alternatives described herein. These functions are described elsewhere in this disclosure with reference to the figures. As shown in FIG. 2, a secure and cost-effective secure biometric sensor system is achieved by integrating two dies in a single, integrated module. Secure Module. The fingerprint sensor array 222 and the sensor authentication logic 230 can be implemented on a field-programmable gate array (FPGA), and the secure element 210 is, for example, a product such as the NXP A1006. Many implementations exist, including those in which dedicated hardware is used to implement some or all of the sensor authentication logic 230, and those in which the biometric sensor 208 and the secure element 210 are located on a single die or in a die-to-die bonded configuration.
[0056] In various embodiments, the sensor authentication logic 230 can perform both authentication and image reading over the same physical line (e.g., SPI), can send non-authentication related commands and data to components of the biometric sensor 208, such as the sensor register 220 and fingerprint sensor array 222, and can send authentication related commands and data between the authentication register 232 and the secure element 210 via the protocol B control component 234 and the protocol B controlled component 236, with the advantage of providing computational resources to support image authentication, encryption, etc. In the latter regard, the sensor authentication logic 230 in some embodiments supports image authentication using one or more cryptographic hash functions, and in some embodiments supports image authentication and encryption (e.g., using a block cipher).
[0057] Figure 3 illustrates an exemplary communications configuration 300 according to at least one embodiment. The communications configuration 300 of Figure 3 is similar in many respects to the communications configuration 200 of Figure 2 and will not be described in detail again. The primary difference between Figures 2 and 3 is that, for a secure biometric sensor system 302, the components shown on a separate sensor die 214 in Figure 2 are provided on a common package substrate 304 along with the secure element 310. While most other aspects are essentially the same (in at least one embodiment), communication between (i) the sensor authentication logic 330 and authentication registers 332 and (ii) the secure element 310 via the sensor / secure element interface 120 is achieved by a wired connection (e.g., wire bonding) on the package substrate 304.
[0058] In many of the figures in this disclosure, corresponding elements are numbered similarly in different figures. Thus, in Figures 2 and 3, the secure biometric sensor system 202 (302), Protocol A controlled component 218 (318), sensor register 220 (320), fingerprint sensor array 222 (322), control and status message 224 (324), fingerprint image 226 (326), junction 228 (328), sensor authentication logic 230 (330), and authentication register 232 (332) share the same element numbers, except for the leading digit. Wherever possible, elements are numbered in this manner throughout the figures.
[0059] FIG. 4 illustrates an exemplary architecture 400 for an exemplary secure biometric sensor system 402 according to at least one embodiment. The architecture 400 of FIG. 4 includes a secure biometric sensor system 402 similar in scope to the secure biometric sensor system 102 of FIG. 1, the secure biometric sensor system 202 of FIG. 2, and the secure biometric sensor system 302 of FIG. 3. For simplicity of illustration, the host and resources are omitted from FIG. 4, although they would not be absent in an actual configuration. Elements of FIG. 4, including a protocol A controlled component 418, a sensor register 420, a fingerprint sensor array 422, control and status messages 424, a fingerprint image 426, a junction 428, a sensor authentication logic 430, and an authentication register 432, correspond, in at least one embodiment, to elements shown in FIG. 3 (and FIG. 2), and therefore will not be described in detail.
[0060] As shown, the secure element 410 shares a package substrate 404 with the sensor die 406 on which the other components reside. In FIG. 4, the host / sensor interface 116 is shown as a group of four pads. These pads are part of a larger group, shown in FIG. 4 as additional pads 444. These pads are labeled "additional" in FIG. 4 because they are in addition to the four named pads: power pad 440, ground pad 442, data pad 436, and data pad 438. In FIG. 4, the sensor / secure element interface 120 is shown as the wire bond connections connecting (i) data pad 436 of the sensor die 406 to data pad 446 of the secure element 410 and (ii) data pad 438 of the sensor die 406 to data pad 448 of the secure element 410. The secure element 410 also has a power pad 450 and a ground pad 452.
[0061] To indicate the corresponding interconnections, data pads 436 and 446 are both labeled "A," and data pads 438 and 448 are both labeled "B." In FIG. 4 , protocol B control component 434 is shown connected to sensor authentication logic 430 and authentication register 432 and also having terminals "A" and "B." Through these connections, sensor authentication logic 430 and authentication register 432 use the "A" and "B" terminals in protocol B control component 434 to communicate (i) with the "A" data pad 446 of secure element 410 via the "A" data pad 436 of sensor die 406, and (ii) with the "B" data pad 438 of secure element 410 via the "B" data pad 438 of sensor die 406.
[0062] In at least one embodiment, the sensor die 406 and the secure element 410, along with a communication channel (e.g., I2C), are mounted and molded as bare dies on a common package substrate, i.e., package substrate 404. In various embodiments, the sensor die (e.g., sensor die 406) and the secure element (e.g., secure element 410) are connected by wire bonding or other equivalent multi-die module or system-in-package interconnection techniques. The substrate with the two interconnected dies can be molded using an epoxy compound or the like, which is common practice in the field of solid-state fingerprint sensor technology.
[0063] Figure 5 illustrates a slightly different architecture 500 of an exemplary secure biometric sensor system 502 according to at least one embodiment. Because architecture 500 of Figure 5 is similar to architecture 400 of Figure 4, 400 numbers are also used in Figure 5. The 500 numbers in Figure 5 refer to secure biometric sensor system 502, package substrate 504, secure element 510, and four components of secure element 510: power solder bumps 550, ground solder bumps 552, data solder bumps 546, and data solder bumps 548. The solder bumps are stacked on chip pads.
[0064] Thus, the secure element 510 is connected to the package substrate 504 not by pads but by four solder balls 546, 548, 550, and 552. This is an example of what is known in the art as chip-scale packaging (CSP), a type of packaging for ICs. In one embodiment, the height of the solder CSP (with collapsed balls) is less than the height of the biometric sensor so as not to compromise the shape of the corresponding biometric sensor.
[0065] FIG. 6 illustrates a first example information flow diagram 600. This diagram illustrates an example configuration in which both an example host 604 and an example secure biometric sensor system 602 use multiple corresponding hash functions, according to at least one embodiment. FIG. 6 illustrates a secure biometric sensor system 602 and a host 604. The host 604 includes an image store 618, a response calculator 610, an internal hash function 624, an external hash function 640, and a comparison function 646. The secure biometric sensor system 602 includes a fingerprint sensor array 622, a junction 614, a secure element 608 including a response calculator 612, and sensor authentication logic 630 including an internal hash function 624 and an external hash function 640. Of course, the internal hash function 624 and the external hash function 640 are sensor-side instances of hash functions, but are substantially the same. In FIG. 6 and the following four figures, items of information (e.g., cryptographic challenge 606, cryptographic response 636, etc.) are indicated with dashed lines.
[0066] The information flow in information flow diagram 600 begins with host 604 generating (e.g., calculating) a cryptographic challenge 606 and providing it to both a response calculator 610 in host 604 and a response calculator 612 in secure element 608. One or both of these response calculators 610 and 612, as well as the other response calculators described with reference to the following figures, may be configured with any combination of hardware, firmware, and / or software that one of ordinary skill in the art would deem appropriate. In some embodiments, the host's response calculator is configured with firmware and / or software, while the secure element's response calculator is configured with hardware. Response calculator 610 calculates a secret 628 based on the cryptographic challenge 606 and uses the secret 628 as one of two inputs to what is referred to herein as an internal hash function 624.
[0067] On the sensor side, a fingerprint image 626 is read by a fingerprint sensor array 622 and transmitted via junction 614 to both an internal hash function 624 on the sensor side and to an image storage device 618 on the host side. In at least one embodiment, the fingerprint image 626 is transmitted as clear text between the secure biometric sensor system 602 and the host 604. As shown, the fingerprint image 626 is one of two inputs, the other being a secret 638 calculated by a response calculator 612 of the secure element 608 based on a cryptographic challenge 606. This secret 638 is the secret 638 in the cryptographic response 636 that is transmitted from the secure element 608 to the internal hash function 624.
[0068] In many cases, the secure element 608 will have a latency of approximately 50 milliseconds to calculate the cryptographic response 636. If the sensor-side internal hash function 624 waits until this calculation is complete before proceeding, this 50 millisecond delay would stall the entire process. However, in at least one embodiment, the sensor-side internal hash function 624 begins calculating a hash result of the data blocks from the fingerprint image 626 to generate a digest. This digest is shown in FIG. 6 as the sensor-side intermediate hash result 634. In one embodiment, once the secret 638 is available, the sensor-side internal hash function 624 calculates a result based on the secret 638.
[0069] At this point in the process, the secure biometric sensor system 602 has generated a data set using the sensor authentication logic 630 that includes hash function results based on both the fingerprint image 626 and the secret 638. However, these hash function results are still two separate data sets that can be separated based on the data (fingerprint image 626 or secret 638) from which they were generated using the sensor-side internal hash function 624. To further enhance security, embodiments of the present disclosure then process the combined data set (sensor-side intermediate hash result 634) using an external hash function 640 to generate the sensor hash result 644 in FIG.
[0070] Importantly, the sensor hash result 644 is a value that is inseparably generated from both (i) the image source data (in this example, the hash result of processing the fingerprint image 626 using the internal hash function 624) and (ii) the cryptographic authentication data (in this example, the secret 638). From the value of the sensor hash result 644 itself, it is impossible to know which of these two sets of data contributed (solely) to any portion of the sensor hash result 644. As such, it is an example of what is referred to herein as a "cryptographically entangled token."
[0071] This is similar to taking two text documents and counting the total number of words in both documents that start with "a", "b", through "z". You enter a cryptographic code known to both parties, such as "horse", and calculate the product of the total number of words that start with "h", the total number of words that start with "o", the total number of words that start with "r", the total number of words that start with "s", and the total number of words that start with "e". Both sides of the encrypted channel will (hopefully) get the same answer, but no details about either document can be inferred from the number alone. This is therefore an example of "cryptographically entangled tokens".
[0072] Returning to the two hash functions in this example, the sequential operation of the two hash functions 624 and 640 can be expressed as follows:
[0073]
number
[0074] where "H1" represents the inner hash function 624, "H2" represents the outer hash function 640, "K" represents the calculated secret 628 or 638, "image data" represents the fingerprint image 626, "K XOR ipad" represents the ipad slice of the calculated secret, and "K XOR opad" represents the opad slice of the calculated secret. As known in the art, "ipad" and "opad" are known constants that essentially function as knives used to slice your secret. Specifically, "ipad" is the block-sized inner padding and consists of repeated 0x36 bytes, while opad is the block-sized outer padding and consists of repeated 0x5c bytes.
[0075] The host-side processing is represented by similar formulas, with the obvious differences being that host-side instances of inner hash function 624 and outer hash function 640 are used, host-side intermediate hash result 632 is used instead of sensor-side intermediate hash result 634 (however, in the case of a valid authentication attempt, i.e., an attempt in which a biometric fingerprint scan is properly taken from the body of the person in secure biometric sensor system 602, whether or not the authentication attempt is successful, these results are substantially equivalent), and secret 628 is used instead of secret 638 (however, again, in a valid authentication attempt, these secrets are substantially equivalent).
[0076] The output of host-side external hash function 640 is shown in Figure 6 as host hash result 642. Using comparison function 646, host 604 compares host hash result 642 with sensor hash result 644 received from secure biometric sensor system 602. If there is a match, it can be concluded that fingerprint image 626 was legitimately scanned from a living body at secure biometric sensor system 602. Thus, authentication result 648 is set to true if there is a match, and false otherwise. Of course, whether or not the fingerprint image 626 is that of an authorized user of a particular system is another matter.
[0077] In some embodiments, inner hash function 624 and outer hash function 640 are secure hash algorithms such as the Secure Hash Algorithm 256 (SHA-256) algorithm, the SHA-512 algorithm, etc. Inner hash function 624 and outer hash function 640 may be the same hash function run twice with different inputs, or they may be two different hash functions. In some embodiments, the order of the inputs to inner hash function 624 is reversed, as follows:
[0078]
number
[0079] Note that these two "separate inputs" are actually a single-valued concatenation of the "two" inputs. This method also has higher latency than the above method because subsequent calculations are performed after the calculation of "K" (i.e., secret 638) is completed. Similarly, on the host side, once the host 604 begins receiving the fingerprint image 626 from the secure biometric sensor system 602 (e.g., as image data frames at a frame readout rate typically exceeding 60 ms), it begins hashing the fingerprint image 626. Because secure elements typically have lower processing power, the host is likely to have the secret 628 much faster than the secure element 608 can have the secret 638.
[0080] The secure biometric sensor system 602 checks (e.g., after each frame transmission) for the generation of a cryptographic response 636 (including a secret 638) from the secure element 608. Once the secret 638 is ready, the secure biometric sensor system 602 hashes the secret 638 using an internal hash function 624 and accumulates it in a digest, and then hashes the sensor-side intermediate hash result 634 using an external hash function 640. Once this is complete, the secure biometric sensor system 602 transmits a sensor hash result 644 to the host 604. This transmission can be on an interrupt basis or in response to periodic polling by the host 604. In some embodiments, the sensor hash result 644 is sent by the secure biometric sensor system 602 to the secure element 608 and is cryptographically signed using the secure element's 608 digital certificate. In this case, the digital signature is also verified by the host 604 as an added security measure. Additionally, in at least one embodiment, the entire image is processed with the associated encryption function, whether a hash function, encryption (discussed in more detail below), or another encryption technique is used, allowing the host to determine that an exact match of the entire image has been obtained at the host.
[0081] A second example information flow diagram 700 is shown in Figure 7, which illustrates an example configuration in which both the example host and the example biometric sensor use a single corresponding hash function, according to at least one embodiment. Figure 7 is similar to, and simpler than, Figure 6, and will not be described in detail. The primary difference between information flow diagram 600 of Figure 6 and information flow diagram 700 of Figure 7 is that in Figure 7, only a single hash function is used on each side (secure biometric sensor system 702 and host 704), whereas in information flow diagram 600 of Figure 6, two (or more) hash functions are used.
[0082] Of the elements shown in FIG. 7, cryptographic challenge 706, response calculator 710, secret 724, secure element 708, response calculator 712, cryptographic response 734, secret 736, image store 718, comparison function 744, and authentication result 746 are substantially the same (in at least one embodiment) as the correspondingly numbered elements in FIG. 6.
[0083] In a single hash function 732 on each side, the fingerprint image 726 and the secret 724 or 736 are combined in a predetermined manner before being processed with the hash function 732, resulting in the generation of a cryptographically entangled token using only a single hash function. In one example, both the host 704 and the secure biometric sensor system 702 can place the calculated secret in a specific position within the block sequence consisting of the fingerprint image 726 and the secret 724 or 736. For example, each will place the secret fifth from the end before generating the host hash result 740 and the sensor hash result 742, respectively, knowing that the other will do the same. In another example, the choice of the secret's position within the block sequence depends on the calculated secret itself. For example, on both sides, the values are calculated as follows:
[0084]
number
[0085] In this case, both parties know that the modulus to be used is 11. In other embodiments, the last digit (or other predetermined digit) of the calculated secret is used as the modulus. Also, various other techniques can be used to combine fingerprint image 726 and secret 724 or 736 in a predetermined format in generating the cryptographically entangled token. As in Figure 6, comparison function 744 sets authentication result 746 to true or false depending on whether a match is determined between host hash result 740 and sensor hash result 742.
[0086] FIG. 8 illustrates a third example information flow diagram 800, showing a first example configuration in which an example host 804 and an example secure biometric sensor system 802 use a common encryption and decryption method, according to at least one embodiment. The encryption embodiments described with reference to FIGS. 8, 9, and 10 may have higher latency than the hash function-based embodiments described above. This is because the secure element in the embodiments of FIGS. 8, 9, and 10 must complete the calculation of the secret before using the image data and the secret together to generate the encrypted cryptographically entangled token (which in these embodiments includes the entire image and additional data).
[0087] Of the elements shown in FIG. 8, cryptographic challenge 806, response calculator 810, secure element 808, response calculator 812, secret 814, cryptographic response 832 including secret 834, image store 818, fingerprint sensor array 822, and fingerprint image 826 are substantially the same (at least in one embodiment) as correspondingly numbered elements in the previous figures (and therefore will not be described in detail).
[0088] In this embodiment, the sensor authentication logic 830 includes a hardware encryption device 836 that uses a block cipher-based encryption standard, such as the Advanced Encryption Standard (AES), to encrypt blocks of data using an encryption key. In the embodiment shown in FIG. 8, the hardware encryption device 836 encrypts the fingerprint image 826 using a secret 834 as the encryption key. In response, the host 804 decrypts the fingerprint image 826 using the calculated secret 814. The authentication result 844 is set to true if the decryption is successful and false otherwise. In at least some embodiments, such as the embodiments shown in FIGS. 8, 9, and 10, the fingerprint image is not transmitted until encryption is performed. However, in some descriptions of the embodiments, this operation is mentioned earlier in the process (e.g., operation 1108 of the communication arrangement 100 of FIG. 11).
[0089] FIG. 9 illustrates a fourth example information flow diagram 900, illustrating a second example configuration in which an example host and an example biometric sensor share a common encryption and decryption method, in accordance with at least one embodiment. Information flow diagram 900 of FIG. 9 is similar to information flow diagram 800 of FIG. 8 and will not be described in detail again. The only difference is that hardware encryption device 936 encrypts fingerprint image 926 using an encryption key equal to a random number 944 that it requests from secure element 908. In other embodiments, sensor authentication logic 930 itself generates random number 944.
[0090] Furthermore, as shown in sensor encryption result 938, hardware encryption device 936 not only encrypts fingerprint image 926 using random number 944 as a (temporary) encryption key, but also encrypts the random number using secret 934 as the encryption key. In one embodiment, host 904 requests encrypted random number 944 after initially receiving encrypted fingerprint image 926. Host 904 then decrypts random number 944 using secret 914 that it calculated, and then decrypts fingerprint image 926 using random number 944 as a temporary session key. The result of comparison function 946 is stored as authentication result 948.
[0091] 10 illustrates a fifth example information flow diagram 1000, depicting a third example configuration in which an example host 1004 and an example secure biometric sensor system 1002 use a common encryption and decryption method, according to at least one embodiment. The elements illustrated in FIG. 10, including cryptographic challenge 1006, secure element 1008, response calculator 1010, response calculator 1012, secret 1014, image storage 1018, fingerprint sensor array 1022, fingerprint image 1026, and comparison function 1044, are substantially the same as corresponding similarly numbered elements in the previous figures.
[0092] The main difference between the previous two figures and Figure 10 is that the sensor authentication logic 1030 uses a hardware encryption device 1036 to encrypt both the fingerprint image 1026 and the secret 1034 together as a package, as can be seen from the sensor encryption result 1038, using a symmetric encryption key 1048. Similarly, on the host side, the information transmitted from the secure biometric sensor system 802 is decrypted using the key 1048, and then the host 1004 compares the host-computed secret 1014 with the secure element-computed secret 1034 using a comparison function 1044. Depending on the output of the comparison function 1044, a true or false result is stored as the authentication result 1046. Additionally, the fingerprint image 1026 is stored in the image storage device 1018.
[0093] 11 illustrates method 1100, an example of a method performed by a secure biometric sensor system, such as secure biometric sensor system 102, secure biometric sensor system 202, secure biometric sensor system 302, secure biometric sensor system 402, or another secure biometric sensor system. In general, method 1100 is performed by any suitable computing and communication device equipped, programmed, and configured to perform the described functions. While method 1100 will be described relatively briefly here, it should be understood that all permutations and combinations of the embodiments disclosed herein are applicable as permutations, embodiments, etc. of method 1100.
[0094] In operation 1102, the secure biometric sensor system receives a cryptographic challenge from the host. The biometric sensor is communicatively interposed between the host and the secure element, and the biometric sensor and secure element are physically coupled to one another. In operation 1104, the secure biometric sensor system forwards the cryptographic challenge to the secure element. In operation 1106, the secure biometric sensor system acquires a biometric reading using the biometric sensing element. In operation 1108, the secure biometric sensor system transmits the acquired biometric reading to the host. As previously mentioned, this operation does not occur until encryption is performed on the sensor side. In general, except as dictated by logical dependencies, the order of the operations recited in method 1100 is not intended to be limiting, and operations may be performed in a different order.
[0095] In operation 1110, the secure biometric sensor system receives a cryptographic response from the secure element. The cryptographic response was calculated by the secure element based on the cryptographic challenge and includes a shared secret between the host and the secure element. In operation 1112, the secure biometric sensor system generates a cryptographically entangled token (e.g., the result of one or more hash functions, a cryptographic result, etc.) from a predetermined combination of the reading-related data and the shared secret. The reading-related data includes one or both of the biometric reading (e.g., a fingerprint image) and data derived from the biometric reading (e.g., a hash of the fingerprint image with one or more other values, such as a calculated cryptographic response secret). In operation 1114, the secure biometric sensor system transmits the cryptographically entangled token to the host. The host uses the cryptographically entangled token to attempt to authenticate the obtained biometric reading as having been obtained by the biometric sensor.
[0096] FIG. 12 illustrates a computer system 1200 that can be used to implement and / or perform at least one embodiment. Instructions 1212 (e.g., software, programs, applications, applets, apps, and / or other executable code) executed on the computer system 1200 cause the computer system 1200 to perform any one or more of the methods described herein. For example, the instructions 1212 cause the computer system 1200 to perform any one or more of the methods described herein. The instructions 1212 transform the unprogrammed, general computer system 1200 into a specific computer system 1200 that is programmed to perform the described and illustrated functions in the described manner. The computer system 1200 may operate as a standalone device or may be connected (e.g., networked) to other machines. In a networked configuration, the computer system 1200 may function as a server or client device in a server-client network environment, or as a peer device in a peer-to-peer (or distributed) network environment.
[0097] For purposes of this disclosure, on the sensor side, the sensor authentication logic in any embodiment may be implemented in hardware (e.g., dedicated hardware), via a processor executing instructions, or otherwise. Similarly, on the host side, it may be implemented in the above or another manner.
[0098] Computer system 1200 may be and include, but is not limited to, a server computer, client computer, personal computer (PC), tablet computer, laptop computer, netbook, set-top box (STB), personal digital assistant (PDA), entertainment media system, mobile phone, smartphone, mobile device, wearable device (such as a smart watch), smart home device (such as a smart appliance), other smart device, web appliance, network router, network switch, network bridge, and / or any other machine capable of sequentially or otherwise executing instructions 1212 that specify operations performed by computer system 1200. Furthermore, while only a single computer system 1200 is shown, the term "machine" should be taken to include a collection of machines that individually or jointly execute instructions 1212 to perform any one or more of the methods described herein.
[0099] Computer system 1200 includes processor 1202, memory 1204, and I / O components 1206, which are configured to communicate with each other via bus 1244. In an exemplary embodiment, processor 1202 (e.g., a central processing unit (CPU), a reduced instruction set computing (RISC) processor, a complex instruction set computing (CISC) processor, a graphics processing unit (GPU), a digital signal processor (DSP), an application specific integrated circuit (ASIC), a radio frequency integrated circuit (RFIC), other processors, and / or any suitable combination thereof) includes processor 1208 and processor 1210 that execute instructions 1212. The term "processor" is intended to include multi-core processors that include two or more independent processors (sometimes referred to as "cores") that can execute instructions simultaneously. While multiple processors 1202 are shown in FIG. 12, computer system 1200 may be a single processor with a single core, a single processor with multiple cores (e.g., a multi-core processor), multiple processors with a single core, multiple processors with multiple cores, or any combination thereof.
[0100] Memory 1204 includes main memory 1214, static memory 1216, and storage unit 1218, each accessible to processor 1202 via bus 1244. Memory 1204, static memory 1216, and / or storage unit 1218 store executable instructions 1212 to perform any one or more of the methods or functions described herein. Additionally or alternatively, instructions 1212, when executed by computer system 1200, may be located, completely or partially, in main memory 1214, in static memory 1216, in machine-readable medium 1220 in storage unit 1218, in at least one processor 1202 (e.g., in a cache memory of one of processors 1202), and / or a combination thereof. Machine-readable medium 1220 is one or more non-transitory computer-readable storage media.
[0101] I / O components 1206 include a wide variety of components for receiving input, generating and / or providing output, transmitting information, exchanging information, obtaining measurements, etc. The particular I / O components 1206 included in a particular instance of computer system 1200 depend on the type of machine. For example, a portable machine such as a cell phone may include a touch input device or other similar input mechanism, while a headless server machine may not include such a touch input device. Note that I / O components 1206 may include many other components not shown in FIG. 12 .
[0102] In various exemplary embodiments, I / O components 1206 include output components 1232 and input components 1230. Output components 1232 may be, for example, visual components (e.g., a plasma display panel (PDP), a light-emitting diode (LED) display, a liquid crystal display (LCD), a projector, a cathode ray tube (CRT)), acoustic components (e.g., speakers), haptic components (e.g., vibration motors, resistive mechanisms), and other signal generators. Input components 1230 may be, for example, alphanumeric input components (e.g., a keyboard, a touchscreen configured to receive alphanumeric input, a photo-optical keyboard, or other alphanumeric input component), point-based input components (e.g., a mouse, touchpad, trackball, joystick, motion sensor, or other pointing device), tactile input components (e.g., physical buttons, a touchscreen that responds to the location and force of a touch or touch gestures, one or more other tactile input components), or audio input components (e.g., a microphone).
[0103] In another exemplary embodiment, I / O component 1206 includes various components such as a biometric component 1234, a motion component 1236, an environmental component 1238, and a position component 1240. The biometric component 1234 is a component that detects facial expressions (e.g., hand expressions, facial expressions, vocal expressions, body gestures, eye tracking, etc.), measures biometric signals (e.g., blood pressure, heart rate, body temperature, sweat, brain waves, etc.), identifies individuals (e.g., via voice identification, retinal identification, facial identification, fingerprint identification, brain wave-based identification, etc.), etc. The motion component 1236 is an acceleration sensing component (e.g., an accelerometer), a gravity sensing component, a rotation sensing component (e.g., a gyroscope, etc.), etc.
[0104] Environmental components 1238 may include, for example, a light sensing component (such as a photometer), a temperature sensing component (such as one or more thermometers), a humidity sensing component, a pressure sensing component (such as a barometer), an acoustic sensing component (such as one or more microphones), a proximity sensing component (such as an infrared sensor that detects nearby objects), a gas sensing component (such as a gas detection sensor that detects concentrations of harmful gases for security purposes or to measure airborne pollutants), or other components that provide indicators, measurements, signals, etc. corresponding to the surrounding physical environment. Position components 1240 may include, for example, a location sensing component (such as a global positioning system (GPS) receiver), an altitude sensing component (such as an altimeter and / or barometer that detects air pressure to determine altitude), an orientation sensing component (such as a magnetometer), etc.
[0105] A variety of technologies can be employed for communication. I / O component 1206 also includes a communications component 1242. Communications component 1242 operates to communicatively couple computer system 1200 to network 1222 and / or devices 1224 via connection 1226 and / or connection 1228. For example, communications component 1242 may comprise a network interface component or another suitable device for connecting with network 1222. In other examples, communications component 1242 may be a wired communications component, a wireless communications component, a cellular communications component, a near field communications (NFC) component, a Bluetooth (such as Bluetooth Low Energy), a Wi-Fi component, other communications component that communicates via one or more modalities, etc. Device 1224 may be, for example, one or more other devices, various peripheral devices (e.g., peripheral devices connected via a universal serial bus (USB) connection), etc.
[0106] Additionally, the communications component 1242 may be capable of detecting an identifier or may comprise a component operable to detect an identifier. For example, the communications component 1242 may be a radio frequency identification (RFID) tag reader component, an NFC smart tag detection component, an optical reader component (e.g., an optical sensor for detecting one-dimensional barcodes such as Universal Product Code (UPC) barcodes, multi-dimensional barcodes such as Quick Response (QR) code, Aztec code, Data Matrix, Dataglyph, MaxiCode, PDF417, Ultra Code, UCC RSS-2D barcodes, or other optical codes), or an acoustic detection component (e.g., a microphone for identifying tagged audio signals). Additionally, various information, such as location via Internet Protocol (IP) geolocation, location via Wi-Fi signal triangulation, or location via detection of NFC beacon signals indicating a particular location, may be determined via the communications component 1242.
[0107] One or more instructions (e.g., software) and data structures embodying or used in the methods and functions described herein may be stored in various memories (e.g., memory 1204, main memory 1214, static memory 1216, (e.g., cache) memory of one or more processors 1202, etc.) and / or storage units 1218. These instructions (e.g., instructions 1212), when executed by one or more processors 1202, cause various operations to be performed to implement various embodiments of the present disclosure.
[0108] The instructions 1212 are sent and received over the network 1222 using a transmission medium via a network interface device (e.g., a network interface component included in the communications component 1242) using any of a variety of well-known transfer protocols (e.g., Session Initiation Protocol (SIP), Hypertext Transfer Protocol (HTTP), etc.). Similarly, the instructions 1212 are sent or received to the device 1224 via a connection 1228 (e.g., a peer-to-peer connection) using a transmission medium.
[0109] FIG. 13 illustrates an exemplary software architecture 1302 executable on a computer system, such as the exemplary computer system 1200 of FIG. 12 , according to at least one embodiment. The illustrated exemplary software architecture 1302 can be installed on one or more devices described herein. For example, the software architecture 1302 may be installed on any device or system configured similarly to the computer system 1200 of FIG. 12 . The software architecture 1302 is supported by hardware, such as a machine 1304 having a processor 1306, memory 1308, and I / O components 1310. In this example, the software architecture 1302 is conceptualized as a layered structure, with each layer providing specific functionality. The software architecture 1302 has layers such as an operating system 1312, libraries 1314, frameworks 1316, and applications 1318. Operationally, the applications 1318 use one or more application programming interfaces (APIs) to invoke API calls 1320 through the software hierarchy and receive messages 1322 in response to the API calls 1320.
[0110] The operating system 1312 manages hardware resources and provides common services. The operating system 1312 includes, for example, a kernel 1324, services 1326, and drivers 1328. The kernel 1324 serves as an abstraction layer between the hardware layer and other software layers. For example, the kernel 1324 provides functions such as memory management, processor management (such as scheduling), component management, networking and / or security configuration. The services 1326 provide other common services to the other software layers. The drivers 1328 control or connect to the underlying hardware. For example, the drivers 1328 may be a display driver, a camera driver, a Bluetooth or Bluetooth Low Energy driver, a flash memory driver, a serial communication driver (such as a USB driver), a Wi-Fi driver, an audio driver, a power management driver, etc.
[0111] Libraries 1314 provide low-level common infrastructure used by applications 1318. Libraries 1314 may be, for example, system libraries 1330 (such as the C standard library) that provide functions such as memory allocation functions, string manipulation functions, mathematical functions, etc. Additionally, libraries 1314 may be API libraries 1332 such as media libraries (e.g., libraries that support the depiction and / or manipulation of various media formats such as Moving Picture Experts Group-4 (MPEG4), Advanced Video Coding (H.264 or AVC), Moving Picture Experts Group Layer-3 (MP3), Advanced Audio coding (AAC), Adaptive Multi-Rate (AMR) audio codec, Joint Photographic Experts Group (JPEG or JPG), Portable Network Graphics (PNG), etc.), graphics libraries (such as the OpenGL framework used to render graphical content on a display in two dimensions (2D) and three dimensions (3D)), database libraries (such as SQLite that provides various relational database functions), web libraries (such as WebKit that provides web browsing functions), etc. The library 1314 may include a wide variety of other libraries 1334 to provide many other APIs to the application 1318 .
[0112] Framework 1316 provides a high-level common infrastructure used by applications 1318. For example, framework 1316 may provide various graphical user interface (GUI) functionality, high-level resource management, high-level location services, etc. Framework 1316 may provide a wide range of other APIs that can be used by applications 1318, some of which may be proprietary to particular operating systems or platforms.
[0113] Representative examples of applications 1318 include a home application 1336, a contacts application 1338, a browser application 1340, a book reader application 1342, a location application 1344, a media application 1346, a messaging application 1348, a game application 1350, and various other applications shown in FIG. 13 as third-party applications 1352. An application 1318 is a program that performs a function defined in the program. Various programming languages, such as object-oriented programming languages (e.g., Objective-C, Java, C++) and procedural programming languages (e.g., C, assembly language), may be used to create one or more applications 1318 that are structured in various ways. In certain examples, third-party applications 1352 (e.g., applications developed using the ANDROID® or IOS® Software Development Kit (SDK) by an entity other than the manufacturer of a particular platform) are mobile software that runs on a mobile operating system, such as IOS, ANDROID, or a WINDOWS® phone. In this example, a third-party application 1352 can invoke API calls 1320 provided by the operating system 1312 to facilitate performing the functions described herein.
[0114] In view of the above disclosure, various examples are described below, in which one or more features, either alone or in combination, are within the scope of the disclosure of this application. Example 1 is a secure biometric sensor system comprising a secure element and a biometric sensor configured to be communicatively interposed between a host and the secure element, the biometric sensor and the secure element being physically coupled to one another, the biometric sensor having sensor authentication logic that, when executed by at least one hardware processor of the biometric sensor, causes the biometric sensor to perform a plurality of operations. The processes include receiving a cryptographic challenge from the host, forwarding the cryptographic challenge to the secure element, acquiring a biometric reading using the biometric sensing element, transmitting the acquired biometric reading to the host, receiving from the secure element a cryptographic response calculated by the secure element based on the cryptographic challenge, the cryptographic response including a shared secret between the host and the secure element, generating a cryptographically entangled token from a predetermined combination of read-related data and the shared secret, the read-related data including one or both of the biometric reading and data derived from the biometric reading, and transmitting the cryptographically entangled token to the host for use by the host in attempting to authenticate that the acquired biometric reading was obtained by the biometric sensor.
[0115] Example 2 is the secure biometric sensor system of Example 1, wherein the biometric sensor and the secure element are physically coupled to one another, including the biometric sensor and the secure element affixed to a common package substrate.
[0116] Example 3 is a secure biometric sensor system according to Example 1 or 2, including a biometric sensor configured to be communicatively interposed between a host and a secure element, the biometric sensor having a first communication interface, where the biometric sensor is configured to communicate with the host via the first communication interface, and a second communication interface, different from the first communication interface, where the biometric sensor is configured to separately communicate with the secure element via the second communication interface.
[0117] Example 4 is the secure biometric sensor system according to any of Examples 1 to 3, wherein transmitting the acquired biometric readings to the host is initiated before receiving the cryptographic response from the secure element.
[0118] Example 5 is the secure biometric sensor system of any of Examples 1 to 3, wherein transmitting the captured biometric readings to the host is initiated after receiving a cryptographic response from the secure element, and the processes further include encrypting the captured biometric readings using a shared secret before transmitting the captured biometric readings to the host.
[0119] Example 6 is a secure biometric sensor system according to any of Examples 1 to 5, wherein the plurality of processes further includes digitally signing the cryptographically entangled token using the secure element for verification of the digital certificate of the secure element by the host before transmitting the cryptographically entangled token to the host.
[0120] Example 7 is a secure biometric sensor system according to any of Examples 1 to 6, wherein the cryptographically entangled token includes a sensor-side hash result of a hash function, and wherein the processes further include using the hash function to generate the sensor-side hash result from a predetermined combination of the read-related data and the shared secret.
[0121] Example 8 is the secure biometric sensor system of Example 7, wherein the host attempting to authenticate that the captured biometric reading was captured by the biometric sensor includes the host computing a host-side copy of the shared secret from the cryptographic challenge, using a hash function to generate a host-side hash result from a corresponding predetermined combination of host-side reading-related data and the host-side copy of the shared secret, and determining whether the sensor-side hash result matches the host-side hash result.
[0122] Example 9 is a secure biometric sensor system described in any of Examples 1 to 6, wherein the cryptographically entangled token includes a sensor-side hash result of an external hash function, and wherein the plurality of processes further includes: generating an intermediate sensor-side hash result from the biometric reading and the shared secret using the internal hash function; and generating a sensor-side hash result from the intermediate sensor-side hash result using the external hash function.
[0123] Example 10 is the secure biometric sensor system of Example 9, wherein generating an intermediate sensor-side hash result from the biometric reading and the shared secret using an internal hash function includes using an internal hash function to generate a first part of the two parts of the intermediate sensor-side hash result from the biometric reading and the shared secret, and then using the internal hash function to generate a second part of the two parts of the intermediate sensor-side hash result.
[0124] Example 11 is a secure biometric sensor system as described in Example 10, wherein at least a portion of using an internal hash function to generate a first of two parts of the intermediate sensor-side hash result occurs before receiving a cryptographic response from the secure element.
[0125] Example 12 is the secure biometric sensor system of Example 10, wherein the use of the internal hash function to generate the first of the two parts of the intermediate sensor-side hash result is all performed before receiving the cryptographic response from the secure element.
[0126] Example 13 is a secure biometric sensor system according to any of Examples 9 to 12, wherein the host attempting to authenticate that the acquired biometric reading was acquired by the biometric sensor includes the host calculating a host-side copy of the shared secret from the cryptographic challenge, using an internal hash function to generate an intermediate host-side hash result from the biometric reading and the host-side copy of the shared secret, using an external hash function to generate a host-side hash result from the intermediate host-side hash result, and determining whether the sensor-side hash result matches the host-side hash result.
[0127] Example 14 is the secure biometric sensor system of any of Examples 1-6, further including encrypting the biometric readings with a first encryption key using a block cipher before transmitting the captured biometric readings to the host, wherein the cryptographically entangled token includes the encrypted biometric readings, and transmitting the cryptographically entangled token to the host includes transmitting the captured biometric readings to the host.
[0128] Example 15 is the secure biometric sensor system of example 14, wherein the shared secret is a first cryptographic key. Example 16 is the secure biometric sensor system of Example 15, wherein the host attempting to authenticate that the captured biometric reading was captured by the biometric sensor includes the host calculating a host-side copy of the shared secret from the cryptographic challenge and decrypting the encrypted biometric reading using the host-side copy of the shared secret as a decryption key.
[0129] Example 17 is the secure biometric sensor system described in Example 14, further including: obtaining a random number, where the obtained random number is a first encryption key; encrypting the random number using the shared secret as a second encryption key to generate an encrypted random number; and transmitting the encrypted random number to the host.
[0130] Example 18 is the secure biometric sensor system of Example 17, wherein the host attempting to authenticate that the captured biometric reading was captured by the biometric sensor includes the host calculating a host-side copy of the shared secret from the cryptographic challenge, obtaining a random number by decrypting the encrypted random number using the host-side copy of the shared secret as a second decryption key, and decrypting the encrypted biometric reading using the obtained random number as a first decryption key.
[0131] Example 19 is the secure biometric sensor system according to any of Examples 1 to 18, wherein the acquired biometric readings include biometric sensing data. Example 20 is a biometric sensor comprising: a first communication interface and a second communication interface, the biometric sensor configured to be communicatively interposed between a host and a secure element via the first communication interface and the second communication interface, the biometric sensor and the secure element being physically coupled to one another; and sensor authentication logic, the sensor authentication logic, when executed by at least one hardware processor of the biometric sensor, causing the biometric sensor to perform a plurality of operations, the plurality of operations including receiving a cryptographic challenge from the host; forwarding the cryptographic challenge to the secure element; and generating a cryptographic challenge using the biometric sensing element. acquiring a biometric reading, transmitting the acquired biometric reading to a host, receiving from the secure element a cryptographic response calculated by the secure element based on a cryptographic challenge, the cryptographic response including a shared secret between the host and the secure element, generating a cryptographically entangled token from a predetermined combination of read-related data and the shared secret, the read-related data including one or both of the biometric reading and data derived from the biometric reading, and transmitting the cryptographically entangled token to the host for use by the host in attempting to authenticate that the acquired biometric reading was obtained by the biometric sensor.
[0132] Example 21 is a method performed by a biometric sensor executing stored instructions, the method comprising: receiving a cryptographic challenge from a host, the biometric sensor being communicatively interposed between the host and a secure element, the biometric sensor and the secure element being physically coupled to one another; transferring the cryptographic challenge to the secure element; acquiring a biometric reading using the biometric sensing element; transmitting the acquired biometric reading to the host; receiving from the secure element a cryptographic response calculated by the secure element based on the cryptographic challenge, the cryptographic response including a shared secret between the host and the secure element; generating a cryptographically entangled token from a predetermined combination of read-related data and the shared secret, the read-related data including one or both of the biometric reading and data derived from the biometric reading; and transmitting the cryptographically entangled token to the host for use by the host in attempting to authenticate the acquired biometric reading as being obtained by the biometric sensor.
[0133] Example 22 is one or more non-transitory computer-readable storage media storing instructions that, when executed by at least one hardware processor, cause the at least one hardware processor to perform a plurality of processes, including a plurality of processes described above in connection with Example 1.
[0134] Example 23 is one or more non-transitory computer-readable storage media storing instructions that, when executed by at least one hardware processor, cause the at least one hardware processor to perform a plurality of processes, including a plurality of processes described above in connection with Example 20.
[0135] Example 24 is one or more non-transitory computer-readable storage media storing instructions that, when executed by at least one hardware processor, cause the at least one hardware processor to perform a plurality of processes, including the plurality of processes described above in connection with Example 21.
[0136] Example 25 is a system that includes at least one hardware processor and one or more non-transitory computer-readable storage media that store instructions that, when executed by the at least one hardware processor, cause the at least one hardware processor to perform a plurality of processes, including a plurality of processes described above in connection with Example 20.
[0137] Example 26 is a system that includes at least one hardware processor and one or more non-transitory computer-readable storage media that store instructions that, when executed by the at least one hardware processor, cause the at least one hardware processor to perform a plurality of processes, including a plurality of processes described above in connection with Example 21.
[0138] Further examples include the secure biometric sensor system embodiments, biometric sensor embodiments, method embodiments, non-transitory computer-readable storage medium embodiments, and system embodiments of Examples 2-19 above.
[0139] Various embodiments are shown in the drawings to aid in understanding the gist of the present disclosure. The embodiments disclosed herein are not intended to be exhaustive or to limit the disclosure to the form disclosed in the above detailed description. The described embodiments were selected so that those skilled in the art could utilize the teachings. Therefore, they are not intended to limit the scope of the present disclosure.
[0140] Components of devices, systems, etc. referred to as modules in this disclosure include both hardware and executable instructions, and may be configured within a single component, configured as a single component, or distributed across multiple components. When executed by the hardware, the instructions cause the hardware to perform (e.g., execute) one or more processes (e.g., functions) described herein as being performed by the modules. Hardware may include one or more processors, one or more microprocessors, one or more microcontrollers, one or more microchips, one or more application-specific integrated circuits (ASICs), one or more field-programmable gate arrays (FPGAs), one or more graphical processing units (GPUs), one or more tensor processing units (TPUs), one or more other types of hardware devices and / or components deemed appropriate by one skilled in the art for the given configuration, etc. Instructions may include hardware (e.g., hardwired) instructions, firmware instructions, software instructions, etc. stored on one or more non-transitory computer-readable storage media deemed appropriate by one skilled in the art for the given configuration. Such a non-transitory computer-readable storage medium may be or comprise memory (e.g., random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM or E2PROM), flash memory, one or more other types of memory, etc.) and / or one or more other types of non-transitory computer-readable storage media.
[0141] Throughout this disclosure, including the claims, numerical modifiers such as first, second, and third are used to refer to components, data (values, identifiers, parameters, etc.) and / or other elements, but the use of such modifiers is not intended to imply a particular or required order of the referenced elements. Such modifiers are used to help distinguish between elements and are not intended to limit the elements to a particular order or importance unless a particular order or importance is expressly stated.
[0142] Furthermore, expressions such as "at least one of A and B," "at least one of A, B, and C," etc. used in this disclosure are to be interpreted as if expressions such as "A and / or B," "A, B, and / or C," etc. were used in place of the complete expression. Unless expressly stated otherwise in connection with a specific case, in this disclosure, such expressions do not mean "at least one of A and at least one of B," "at least one of A, at least one of B, and at least one of C," etc. In this disclosure, when there are two elements, it means one or more of "one or more As are present and no B is present," "one or more Bs are present and no A is present," and "one or more As and one or more Bs are present," and similarly when there are three or more elements. A similar interpretation applies when "one or more" is used in place of "at least one," unless expressly stated otherwise in connection with a specific case.
[0143] Additionally, the entities and arrangements described, including those depicted in the figures and those described in connection with the figures, are exemplary and not intended to be limiting. References or descriptions of "what" a particular element or entity in the figures or disclosure "is" or "has," and similar references not expressly qualified by a clause such as "in at least one embodiment," are properly construed as being limited by the clause stated above, even though they may be construed independently of the context as being absolute and limiting to all embodiments. This implied limiting clause has not been repeated in this disclosure for brevity and clarity of description.
Claims
1. 1. A secure biometric sensor system, comprising: A secure element; a biometric sensor configured to be communicatively interposed between a host and the secure element, the biometric sensor and the secure element being physically coupled to one another, the secure element and the biometric sensor being on the same substrate, the biometric sensor having sensor authentication logic; the sensor authentication logic, when executed by at least one hardware processor of the biometric sensor, causes the biometric sensor to perform a plurality of operations; The plurality of processes are receiving a cryptographic challenge from the host; forwarding the cryptographic challenge to the secure element; obtaining a biometric reading using a biometric sensing element; transmitting the obtained biometric readings to the host; receiving from the secure element a cryptographic response computed by the secure element based on the cryptographic challenge, wherein the cryptographic response includes a shared secret between the host and the secure element; generating a cryptographically entangled token from a predetermined combination of read-related data and the shared secret, wherein the read-related data includes one or both of the biometric read and data derived from the biometric read; transmitting the cryptographically entangled token to a host for use by the host in attempting to authenticate that the captured biometric reading was captured by the biometric sensor; A secure biometric sensor system comprising:
2. The secure biometric sensor system of claim 1 , wherein the biometric sensor and the secure element being physically coupled to one another comprise the biometric sensor and the secure element fixed to a common package substrate.
3. the biometric sensor configured to be communicatively interposed between the host and the secure element, a first communication interface; a second communication interface different from the first communication interface; the biometric sensor having the biometric sensor is configured to communicate with the host via the first communication interface; 3. The secure biometric sensor system of claim 1, wherein the biometric sensor is configured to communicate separately with the secure element via the second communication interface.
4. The secure biometric sensor system of claim 1 or 2, wherein transmitting the acquired biometric reading to the host is initiated before receiving the cryptographic response from the secure element.
5. transmitting the obtained biometric reading to the host is initiated after receiving the cryptographic response from the secure element; 3. The secure biometric sensor system of claim 1, wherein the plurality of processes further comprises encrypting the acquired biometric readings using the shared secret before transmitting the acquired biometric readings to the host.
6. 3. The secure biometric sensor system of claim 1, wherein the processes further comprise digitally signing the cryptographically entangled token with the secure element for verification of the digital certificate of the secure element by the host prior to transmitting the cryptographically entangled token to the host.
7. the cryptographically entangled token includes a sensor-side hash result of a hash function; 3. The secure biometric sensor system of claim 1, wherein the plurality of processes further comprises using the hash function to generate the sensor-side hash result from the predetermined combination of the reading-related data and the shared secret.
8. the host attempting to authenticate that the captured biometric reading was captured by the biometric sensor; computing a host-side copy of the shared secret from the cryptographic challenge; using the hash function to generate a host-side hash result from a corresponding predetermined combination of host-side read-related data and the host-side copy of the shared secret; determining whether the sensor-side hash result matches the host-side hash result; The secure biometric sensor system of claim 7 , wherein the host performs the following:
9. the cryptographically entangled token includes a sensor-side hash result of an external hash function; The plurality of processes are generating an intermediate sensor-side hash result from the biometric reading and the shared secret using an internal hash function; generating the sensor-side hash result from the intermediate sensor-side hash result using the external hash function; The secure biometric sensor system of claim 1 or 2, further comprising:
10. generating the intermediate sensor-side hash result from the biometric reading and the shared secret using the internal hash function; generating a first of two parts of the intermediate sensor-side hash result from the biometric reading and the shared secret using the internal hash function; then generating a second of the two portions of the intermediate sensor-side hash result using the internal hash function; 10. The secure biometric sensor system of claim 9, comprising:
11. 11. The secure biometric sensor system of claim 10, wherein at least part of using the internal hash function to generate the first of the two parts of the intermediate sensor-side hash result occurs before receiving the cryptographic response from the secure element.
12. 11. The secure biometric sensor system of claim 10, wherein using the internal hash function to generate the first of the two parts of the intermediate sensor-side hash result occurs all before receiving the cryptographic response from the secure element.
13. the host attempting to authenticate that the captured biometric reading was captured by the biometric sensor; computing a host-side copy of the shared secret from the cryptographic challenge; generating an intermediate host-side hash result from the biometric reading and the host-side copy of the shared secret using the internal hash function; generating a host-side hash result from the intermediate host-side hash result using the external hash function; determining whether the sensor-side hash result matches the host-side hash result; The secure biometric sensor system of claim 9 , wherein the host performs the following:
14. encrypting the obtained biometric readings with a first encryption key using a block cipher before transmitting the biometric readings to the host; the cryptographically entangled token includes the encrypted biometric reading; The secure biometric sensor system of claim 1 or 2, wherein transmitting the cryptographically entangled token to the host comprises transmitting the obtained biometric reading to the host.
15. The secure biometric sensor system of claim 14 , wherein the shared secret is the first cryptographic key.
16. the host attempting to authenticate that the captured biometric reading was captured by the biometric sensor; computing a host-side copy of the shared secret from the cryptographic challenge; decrypting the encrypted biometric reading using the host-side copy of the shared secret as a decryption key; The secure biometric sensor system of claim 15 , wherein the host:
17. obtaining a random number, wherein the obtained random number is the first encryption key; generating an encrypted random number by encrypting the random number using the shared secret as a second encryption key; The secure biometric sensor system of claim 14 , further comprising: transmitting the encrypted random number to the host.
18. the host attempting to authenticate that the captured biometric reading was captured by the biometric sensor; computing a host-side copy of the shared secret from the cryptographic challenge; obtaining the random number by decrypting the encrypted random number using the host-side copy of the shared secret as a second decryption key; decrypting the encrypted biometric reading using the obtained random number as a first decryption key; The secure biometric sensor system of claim 17 , further comprising the host performing:
19. The secure biometric sensor system of claim 1 or 2, wherein the acquired biometric readings include biometric sensing data.
20. 1. A biometric sensor comprising: a first communication interface and a second communication interface, wherein the biometric sensor is configured to be communicatively interposed between a host and a secure element via the first communication interface and the second communication interface, the biometric sensor and the secure element being physically coupled to each other, and the secure element and the biometric sensor being provided on the same substrate; sensor authentication logic; the sensor authentication logic, when executed by at least one hardware processor of the biometric sensor, causes the biometric sensor to perform a plurality of operations; The plurality of processes are receiving a cryptographic challenge from the host; forwarding the cryptographic challenge to the secure element; obtaining a biometric reading using a biometric sensing element; transmitting the obtained biometric readings to a host; receiving from the secure element a cryptographic response computed by the secure element based on the cryptographic challenge, wherein the cryptographic response includes a shared secret between the host and the secure element; generating a cryptographically entangled token from a predetermined combination of read-related data and the shared secret, wherein the read-related data includes one or both of the biometric read and data derived from the biometric read; transmitting the cryptographically entangled token to a host for use by the host in attempting to authenticate that the captured biometric reading was captured by the biometric sensor; a biometric sensor comprising:
21. 1. A method performed by a biometric sensor executing a plurality of stored instructions, comprising: receiving a cryptographic challenge from a host, wherein the biometric sensor is communicatively interposed between the host and a secure element, the biometric sensor and the secure element are physically coupled to one another, and the secure element and the biometric sensor are provided on the same substrate; forwarding the cryptographic challenge to the secure element; obtaining a biometric reading using a biometric sensing element; transmitting the obtained biometric readings to a host; receiving from the secure element a cryptographic response computed by the secure element based on the cryptographic challenge, wherein the cryptographic response includes a shared secret between the host and the secure element; generating a cryptographically entangled token from a predetermined combination of read-related data and the shared secret, wherein the read-related data includes one or both of the biometric read and data derived from the biometric read; transmitting the cryptographically entangled token to a host for use by the host in attempting to authenticate that the captured biometric reading was captured by the biometric sensor.
Citation Information
Patent Citations
Challenge / response biometrics authentication method
JP2008048263A
Biometric authentication system, biometric authentication method, and computer program
JP2015095877A
Substrate set and secure element
JP2021033697A
Method and apparatus to provide continuous authentication based on dynamic personal information
US20130133055A1
Fingerprint sensor for incorporation into smartcard
US20190251322A1