Biometric Access via Trusted Platform Module
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face inconvenience and security risks due to the need to manage multiple sets of credentials for accessing different network services, which can lead to compromised private information and inefficient resource utilization.
Innovation Solution
A method and device configuration that utilizes biometric authentication and a Trusted Platform Module (TPM) to enable optimized access to network services without requiring users to communicate credentials, using a signature key for validation and encryption, thereby minimizing exposure of private information and optimizing resource usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If users manage multiple sets of credentials for accessing different network services, then access to multiple services is enabled, but security risks increase and private information exposure increases
Solution Approach 1:
The patent merges multiple credential management functions into a single TPM-based authentication system. Instead of managing separate credentials for each service, the system uses a unified biometric authentication mechanism that leverages the TPM's cryptographic capabilities to provide secure access across multiple network services, thereby reducing security risks while maintaining versatility
Solution Approach 2:
The TPM acts as an intermediary between the user's biometric data and the network services. Rather than directly exposing credentials to multiple services, the TPM serves as a secure mediator that handles authentication requests, protecting private information while enabling access to multiple services through a standardized authentication interface
2Adaptability or versatility
If users manage multiple sets of credentials for accessing different network services, then access to multiple services is enabled, but resource utilization efficiency decreases
Solution Approach 1:
The patent implements a universal authentication mechanism using biometric data and TPM that can be applied across multiple network services. This multi-functional approach eliminates the need to manage separate credentials for each service, optimizing resource utilization by using a single authentication system that serves multiple purposes and reducing the computational overhead of managing multiple credential sets
3Reliability
If biometric authentication and TPM are used for optimized access, then security is improved and credential exposure is minimized, but system complexity increases
Solution Approach 1:
The patent extracts the complex cryptographic operations and credential management functions into the TPM hardware module. By moving these complex security functions out of the main system software and into a dedicated security coprocessor, the overall system complexity is managed more effectively while maintaining high security standards. The TPM handles the computationally intensive cryptographic operations independently
4Ease of operation
If multiple credentials are stored and managed, then access flexibility is improved, but the risk of unauthorized access increases
Solution Approach 1:
The patent implements a disposable credential approach where ephemeral cryptographic credentials are generated on-demand by the TPM for each authentication session. These temporary credentials are used once and then discarded, eliminating the need to store multiple long-term credentials. This approach maintains access flexibility while minimizing the risk of unauthorized access, as compromised credentials cannot be reused
Data Source
AI summary
A method including configuring, by an infrastructure device, a user device to receive validation data based at least in part on transmitting a first service request to receive a first network service; configuring, by the infrastructure device, the user device to receive the first network service based at least in part on signing the validation data using a signature key and on authenticating first biometric information; configuring, by the infrastructure device, the user device to transmit, while receiving the first service, a second service request to receive encrypted content; and configuring, by the infrastructure device, the user device to decrypt the encrypted content based at least in part on utilizing a master key and on authenticating second biometric information is disclosed. Various other aspects are contemplated.


