Biometric Authentication for Shared Mobile Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In enterprise systems, shared mobile devices pose security and management challenges due to the lack of mechanisms for managing distinct user passcodes and facial features, leading to compromised security and accountability issues when multiple users share the same passcode or facial data.

Innovation Solution

Implementing an enrollment process that creates a temporary one-to-one mapping of each user to a shared device using a physical medium external to the device, which includes challenge data, user identifiers, and biometric data, allowing each user to authenticate independently without sharing passcodes or biometric features.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a shared mobile device uses a single passcode for multiple users, then ease of operation is improved, but security and accountability deteriorate

Engineering Contradiction:
Improveease of device accessVSAvoidsecurity and user accountability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication system by creating separate passcodes and biometric data profiles for each user. Instead of one shared passcode, the system divides authentication credentials into individual user-specific segments stored in a database, allowing multiple users to access the shared device with their own unique credentials.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication system that mediates between users and the shared device. This system includes a database storing multiple user profiles with distinct passcodes and biometric data, and an authentication mechanism that verifies user identity before granting device access, thereby resolving the conflict between ease of access and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If biometric data is shared among multiple users, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improvebiometric authentication convenienceVSAvoidbiometric security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments biometric authentication by creating separate biometric data profiles for each user in the database. Instead of sharing a single biometric profile, the system divides biometric credentials into individual user-specific segments, allowing each user to authenticate with their own unique biometric data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authentication system with a database that mediates biometric authentication. The database stores multiple user profiles with distinct biometric data, and the authentication mechanism verifies user identity against the correct profile before granting device access, resolving the security concerns of shared biometric data.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the device locks after inactivity, then security is improved, but productivity deteriorates

Engineering Contradiction:
Improvedevice securityVSAvoiddevice accessibility
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an intermediary authentication system that mediates between the locked device and users. When the device locks after inactivity, users can quickly authenticate through the intermediary system using their stored passcodes or biometric data, thereby maintaining security while minimizing access delays and preserving productivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240362309A1Systems and Methods for Biometric Authentication
Publication Date: 2024.10.31 ZEBRA TECHNOLOGIES CORP
  • US20240362309A1 patent drawing
  • US20240362309A1 patent drawing
  • US20240362309A1 patent drawing

AI summary

An authentication screen that prevents access to at least one application via the computing device can be rendered on a display of a computing device. The computing device can scan a physical medium that is external to, and independent of, the computing device to acquire challenge data for a user from the physical medium and the computing device can acquire response data from the user. In response to a successful match between the challenge data and the response data, the authentication screen can be removed from the display and access to the at least one application can be granted. Once access to the computing device is granted to the user, the computing device can identify the user and manage the challenge data, response data, SSO sessions, and/or personalized device configurations.