Biometric Authentication for Shared Mobile Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In enterprise systems, shared mobile devices pose security and management challenges due to the lack of mechanisms for managing distinct user passcodes and facial features, leading to compromised security and accountability issues when multiple users share the same passcode or facial data.
Innovation Solution
Implementing an enrollment process that creates a temporary one-to-one mapping of each user to a shared device using a physical medium external to the device, which includes challenge data, user identifiers, and biometric data, allowing each user to authenticate independently without sharing passcodes or biometric features.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a shared mobile device uses a single passcode for multiple users, then ease of operation is improved, but security and accountability deteriorate
Solution Approach 1:
The patent segments the authentication system by creating separate passcodes and biometric data profiles for each user. Instead of one shared passcode, the system divides authentication credentials into individual user-specific segments stored in a database, allowing multiple users to access the shared device with their own unique credentials.
Solution Approach 2:
The patent introduces an intermediary authentication system that mediates between users and the shared device. This system includes a database storing multiple user profiles with distinct passcodes and biometric data, and an authentication mechanism that verifies user identity before granting device access, thereby resolving the conflict between ease of access and security.
2Ease of operation
If biometric data is shared among multiple users, then ease of operation is improved, but security deteriorates
Solution Approach 1:
The patent segments biometric authentication by creating separate biometric data profiles for each user in the database. Instead of sharing a single biometric profile, the system divides biometric credentials into individual user-specific segments, allowing each user to authenticate with their own unique biometric data.
Solution Approach 2:
The patent introduces an intermediary authentication system with a database that mediates biometric authentication. The database stores multiple user profiles with distinct biometric data, and the authentication mechanism verifies user identity against the correct profile before granting device access, resolving the security concerns of shared biometric data.
3Reliability
If the device locks after inactivity, then security is improved, but productivity deteriorates
Solution Approach 1:
The patent introduces an intermediary authentication system that mediates between the locked device and users. When the device locks after inactivity, users can quickly authenticate through the intermediary system using their stored passcodes or biometric data, thereby maintaining security while minimizing access delays and preserving productivity.
Data Source
AI summary
An authentication screen that prevents access to at least one application via the computing device can be rendered on a display of a computing device. The computing device can scan a physical medium that is external to, and independent of, the computing device to acquire challenge data for a user from the physical medium and the computing device can acquire response data from the user. In response to a successful match between the challenge data and the response data, the authentication screen can be removed from the display and access to the at least one application can be granted. Once access to the computing device is granted to the user, the computing device can identify the user and manage the challenge data, response data, SSO sessions, and/or personalized device configurations.


