Biometric Authentication Linking for Shared Device Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern user devices face performance issues when shared among multiple users due to conventional authentication methods that rely on biometric data for security, leading to security challenges and performance problems.
Innovation Solution
A method that links individual biometric data to specific applications and protected resources on user devices, allowing only authorized biometric data to access these resources, thereby enhancing security and performance by managing multiple user profiles effectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple user profiles are created on a single device to enable biometric authentication for multiple users, then security is improved, but device performance deteriorates
Solution Approach 1:
The patent segments biometric authentication by creating separate biometric databases and authentication contexts for different users. Each user profile has its own isolated biometric data storage and authentication logic, allowing multiple users to authenticate securely without loading the entire device with multiple complete user profiles. This segmentation maintains security while reducing the performance overhead of managing multiple full user profiles.
Solution Approach 2:
The patent extracts biometric authentication functionality from the broader user profile context. Instead of creating complete user profiles with all associated data and permissions, the system extracts only the essential biometric authentication components needed for security. This extraction allows multiple users to authenticate biometrically without the performance penalty of maintaining multiple full user profiles on the device.
2Adaptability or versatility
If biometric data is stored for multiple users on a shared device, then authentication capability is improved, but security risks increase
Solution Approach 1:
The patent implements segmentation by creating separate, isolated biometric databases for each user. Each user's biometric data is stored in its own protected namespace with dedicated access controls. This segmentation allows the system to support multiple users' authentication needs while preventing unauthorized access between user contexts, thereby maintaining both authentication capability and security.
Solution Approach 2:
The patent applies local quality by implementing user-specific security policies and access controls for each biometric database. Each user profile has customized security parameters, permission levels, and authentication requirements tailored to that user's needs. This localized approach allows the system to accommodate diverse authentication requirements while maintaining appropriate security boundaries for each user's biometric data.
3Ease of operation
If conventional biometric authentication is implemented on shared devices, then ease of use is improved, but device performance deteriorates
Solution Approach 1:
The patent extracts biometric authentication as a standalone, lightweight functionality that operates independently of complete user profile management. By separating the biometric authentication engine from the full user profile infrastructure, the system maintains ease of biometric authentication while reducing the performance burden. Users can authenticate biometrically without the system needing to load and manage entire user profiles, thus preserving ease of use while improving performance.
Solution Approach 2:
The patent changes system parameters by implementing lazy loading and on-demand authentication contexts. Instead of pre-loading all user profile data into memory, the system dynamically loads only the specific biometric authentication parameters needed for the current user. This parameter change reduces memory usage and processing overhead, maintaining ease of biometric authentication while significantly improving device performance on shared devices.
Data Source
AI summary
Methods, apparatus, and processor-readable storage media for linking individual biometric data to protected resources accessed via user devices are provided herein. An example computer-implemented method includes obtaining biometric data associated with users of a user device and identifying information pertaining to the biometric data; outputting the identifying information pertaining to the of biometric data and identifying information pertaining to protected resources; linking at least a portion of the multiple sets of biometric data to one of the protected resources based on input from at least a first of the users in response to the outputting step; processing, in response to an authentication request in connection with an attempt to access the protected resource by the at least first user, biometric data input to the user device; and resolving the authentication request in response to a determination that the input biometric data match the biometric data linked to the protected resource.


