Biometric Authentication Linking for Shared Device Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern user devices face performance issues when shared among multiple users due to conventional authentication methods that rely on biometric data for security, leading to security challenges and performance problems.

Innovation Solution

A method that links individual biometric data to specific applications and protected resources on user devices, allowing only authorized biometric data to access these resources, thereby enhancing security and performance by managing multiple user profiles effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple user profiles are created on a single device to enable biometric authentication for multiple users, then security is improved, but device performance deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiddevice performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments biometric authentication by creating separate biometric databases and authentication contexts for different users. Each user profile has its own isolated biometric data storage and authentication logic, allowing multiple users to authenticate securely without loading the entire device with multiple complete user profiles. This segmentation maintains security while reducing the performance overhead of managing multiple full user profiles.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts biometric authentication functionality from the broader user profile context. Instead of creating complete user profiles with all associated data and permissions, the system extracts only the essential biometric authentication components needed for security. This extraction allows multiple users to authenticate biometrically without the performance penalty of maintaining multiple full user profiles on the device.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If biometric data is stored for multiple users on a shared device, then authentication capability is improved, but security risks increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements segmentation by creating separate, isolated biometric databases for each user. Each user's biometric data is stored in its own protected namespace with dedicated access controls. This segmentation allows the system to support multiple users' authentication needs while preventing unauthorized access between user contexts, thereby maintaining both authentication capability and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by implementing user-specific security policies and access controls for each biometric database. Each user profile has customized security parameters, permission levels, and authentication requirements tailored to that user's needs. This localized approach allows the system to accommodate diverse authentication requirements while maintaining appropriate security boundaries for each user's biometric data.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If conventional biometric authentication is implemented on shared devices, then ease of use is improved, but device performance deteriorates

Engineering Contradiction:
Improveease of useVSAvoiddevice performance
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent extracts biometric authentication as a standalone, lightweight functionality that operates independently of complete user profile management. By separating the biometric authentication engine from the full user profile infrastructure, the system maintains ease of biometric authentication while reducing the performance burden. Users can authenticate biometrically without the system needing to load and manage entire user profiles, thus preserving ease of use while improving performance.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent changes system parameters by implementing lazy loading and on-demand authentication contexts. Instead of pre-loading all user profile data into memory, the system dynamically loads only the specific biometric authentication parameters needed for the current user. This parameter change reduces memory usage and processing overhead, maintaining ease of biometric authentication while significantly improving device performance on shared devices.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11514145B2Linking individual biometric data to protected resources accessed via user devices
Publication Date: 2022.11.29 EMC IP HLDG CO LLC
  • US11514145B2 patent drawing
  • US11514145B2 patent drawing
  • US11514145B2 patent drawing

AI summary

Methods, apparatus, and processor-readable storage media for linking individual biometric data to protected resources accessed via user devices are provided herein. An example computer-implemented method includes obtaining biometric data associated with users of a user device and identifying information pertaining to the biometric data; outputting the identifying information pertaining to the of biometric data and identifying information pertaining to protected resources; linking at least a portion of the multiple sets of biometric data to one of the protected resources based on input from at least a first of the users in response to the outputting step; processing, in response to an authentication request in connection with an attempt to access the protected resource by the at least first user, biometric data input to the user device; and resolving the authentication request in response to a determination that the input biometric data match the biometric data linked to the protected resource.