Biometric Authentication Secure Channel for Protocol Compatibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional biometric systems based on match on host (MOH) technology are not compatible with existing security protocols, such as the Secure Device Connection Protocol (SDCP) developed by Microsoft, which are designed for match on chip (MOC) technology, limiting their use in secure login processes.

Innovation Solution

A method and system for authentication data transmission that establishes a secure channel between a computer system and a MOH-based biometric device, allowing encryption and decryption of biometric feature data within a secure environment, enabling MOH technology to comply with security protocols like SDCP by offloading computation-intensive tasks to the computer system's processor.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If match on host (MOH) based biometric technology is used, then hardware costs are reduced and flexibility is improved, but compatibility with existing security protocols like SDCP is lost

Engineering Contradiction:
Improvehardware costVSAvoidprotocol compatibility
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent introduces a secure channel as an intermediary layer between the MOH biometric device and the host system. This secure channel implements the security protocol requirements (originally designed for MOC devices) without requiring the biometric device itself to be MOC-based. The secure channel acts as a mediator that translates and protects the authentication data transmission, enabling MOH devices to comply with protocols like SDCP while maintaining their hardware simplicity and cost advantages.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If match on chip (MOC) technology is used, then security protocol compatibility is improved, but hardware costs increase and system complexity is increased

Engineering Contradiction:
Improveprotocol compatibilityVSAvoidhardware cost
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent extracts the security protocol implementation from the biometric device hardware and relocates it to the host system's secure channel. Instead of requiring the biometric device to incorporate complex MOC security features, the security functionality is taken out and implemented separately in the host's secure channel. This separation allows the biometric device to remain simple and inexpensive while still achieving protocol compatibility through the host's secure channel implementation.

Inventive Principle:
Principle #2Taking out (Extraction)

3Device complexity

If MOH technology is used without secure channel, then device complexity is reduced, but security against malicious programs is compromised

Engineering Contradiction:
Improvedevice complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The secure channel serves as a security intermediary that protects the authentication process between the MOH biometric device and the host system. It encrypts and secures the transmission of authentication data, preventing malicious programs from intercepting or tampering with the data. This intermediary layer provides the necessary security protections without requiring the biometric device itself to be complex, maintaining device simplicity while enhancing overall system security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11870774B2Method and system for authentication data transmission
Publication Date: 2024.01.09 REALTEK SEMICON CORP
  • US11870774B2 patent drawing
  • US11870774B2 patent drawing
  • US11870774B2 patent drawing

AI summary

A method for authentication data transmission and a system thereof are provided. The method is operated in a computer system that is connected to a biometric device, and a secure channel is established there-between according to a security protocol. The computer system can receive encrypted biometric feature data from the biometric device based on a request. In a secure environment built in the computer system, the biometric feature data is decrypted and biometric features can be extracted. A comparison result is generated after comparing the biometric features with feature data in a database. The comparison result can be transmitted to the biometric device. The comparison result is then encrypted in the biometric device according to the security protocol. The biometric device can therefore transmit the encrypted comparison result to the computer system via the secure channel.