Biometric Access via Trusted Platform Module

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face inconvenience and security risks due to the need to manage multiple sets of credentials for accessing different network services, which can lead to compromised private information and inefficient resource utilization.

Innovation Solution

A method and device configuration that utilizes biometric authentication and a Trusted Platform Module (TPM) to enable optimized access to network services without requiring users to communicate credentials, using a signature key for validation and encryption, thereby minimizing exposure of private information and optimizing resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If users manage multiple sets of credentials for accessing different network services, then access to multiple services is enabled, but security risks increase and private information exposure increases

Engineering Contradiction:
Improveaccess to multiple network servicesVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent merges multiple credential management functions into a single TPM-based authentication system. Instead of managing separate credentials for each service, the system uses a unified biometric authentication mechanism that leverages the TPM's cryptographic capabilities to provide secure access across multiple network services, thereby reducing security risks while maintaining versatility

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The TPM acts as an intermediary between the user's biometric data and the network services. Rather than directly exposing credentials to multiple services, the TPM serves as a secure mediator that handles authentication requests, protecting private information while enabling access to multiple services through a standardized authentication interface

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If users manage multiple sets of credentials for accessing different network services, then access to multiple services is enabled, but resource utilization efficiency decreases

Engineering Contradiction:
Improveaccess to multiple network servicesVSAvoidresource utilization efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent implements a universal authentication mechanism using biometric data and TPM that can be applied across multiple network services. This multi-functional approach eliminates the need to manage separate credentials for each service, optimizing resource utilization by using a single authentication system that serves multiple purposes and reducing the computational overhead of managing multiple credential sets

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If biometric authentication and TPM are used for optimized access, then security is improved and credential exposure is minimized, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex cryptographic operations and credential management functions into the TPM hardware module. By moving these complex security functions out of the main system software and into a dedicated security coprocessor, the overall system complexity is managed more effectively while maintaining high security standards. The TPM handles the computationally intensive cryptographic operations independently

Inventive Principle:
Principle #2Taking out (Extraction)

4Ease of operation

If multiple credentials are stored and managed, then access flexibility is improved, but the risk of unauthorized access increases

Engineering Contradiction:
Improveaccess flexibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements a disposable credential approach where ephemeral cryptographic credentials are generated on-demand by the TPM for each authentication session. These temporary credentials are used once and then discarded, eliminating the need to store multiple long-term credentials. This approach maintains access flexibility while minimizing the risk of unauthorized access, as compromised credentials cannot be reused

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS20240340182A1Optimized access in a service environment
Publication Date: 2024.10.10 UAB 360 IT
  • US20240340182A1 patent drawing
  • US20240340182A1 patent drawing
  • US20240340182A1 patent drawing

AI summary

A method including configuring, by an infrastructure device, a user device to receive validation data based at least in part on transmitting a first service request to receive a first network service; configuring, by the infrastructure device, the user device to receive the first network service based at least in part on signing the validation data using a signature key and on authenticating first biometric information; configuring, by the infrastructure device, the user device to transmit, while receiving the first service, a second service request to receive encrypted content; and configuring, by the infrastructure device, the user device to decrypt the encrypted content based at least in part on utilizing a master key and on authenticating second biometric information is disclosed. Various other aspects are contemplated.