Biometric Device Cryptographic Circuitry State Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing biometric devices with cryptographic functionality face a tradeoff between high security and ease of implementation/debugging, making them vulnerable to attacks during testing and debugging processes.
Innovation Solution
A biometric device with controllable states (test and functional) that prevents cryptographic operations on biometric data in the test state, using a test key and device key, and allows secure cryptographic operations in the functional state, with routing circuitry for state transitions and separate key management to enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic functionality is integrated into biometric devices for enhanced security, then security level is improved, but implementation and debugging complexity increases
Solution Approach 1:
The patent segments the cryptographic key into two separate areas: a device key area storing a unique cryptographic device key, and a test key area storing a cryptographic test key. This segmentation allows independent management of security-critical operations and testing operations, reducing implementation complexity while maintaining security.
Solution Approach 2:
The patent introduces dynamic controllability that allows the biometric device to switch between different operational states (test state and functional state). This dynamic state management enables developers to toggle between testing modes and secure operational modes, facilitating debugging while ensuring security during actual use.
2Ease of operation
If test key area is connected to cryptographic circuitry for debugging purposes, then ease of debugging is improved, but vulnerability to attacks increases
Solution Approach 1:
The patent implements dynamic state control where the connection between the test key area and cryptographic circuitry is controlled by a state signal. In the functional state, the test key area is disconnected from the cryptographic circuitry, preventing attackers from accessing cryptographic operations using known test keys, while still allowing debugging in the test state.
Solution Approach 2:
The patent applies preliminary anti-action by preventing the test key from being used in cryptographic operations during functional state. This preemptive measure blocks potential attack vectors before they can be exploited, ensuring that even if test keys are known, they cannot compromise security during actual device operation.
3Ease of operation
If device is configured to allow cryptographic operations in test state for debugging, then debugging capability is improved, but security against hacker access deteriorates
Solution Approach 1:
The patent uses dynamic state management to control which key area is active for cryptographic operations. A state signal determines whether the device operates in test mode (allowing debugging with test keys) or functional mode (using secure device keys). This ensures that debugging capabilities are available when needed but cannot be exploited by hackers in deployed devices.
Solution Approach 2:
The patent applies local quality by giving different functional properties to different key areas based on the operational state. The test key area is enabled for cryptographic operations only in test state, while the device key area is used in functional state. This localized control ensures security is maintained in the critical functional operation context while allowing debugging flexibility.
Data Source
AI summary
A biometric device comprising: biometric sensing circuitry; cryptographic circuitry; a device key area in the biometric device for storing a cryptographic device key unique to the biometric device; and a test key area in the biometric device, for storing a cryptographic test key. The biometric device is controllable between: a test state in which the test key area is connected to the cryptographic circuitry to provide the test key to the cryptographic circuitry, and the cryptographic circuitry is prevented from performing cryptographic operations on data provided by the biometric sensing circuitry; and a functional state in which the device key area is connected to the cryptographic circuitry to provide the device key to the cryptographic circuitry, and the cryptographic circuitry is connected to the biometric sensing circuitry to receive and perform cryptographic operations on data from the biometric sensing circuitry using the device key.


