Biometric Device Attestation via Cryptographic Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current biometric authentication systems lack standardized techniques to verify the integrity of biometric devices in remote, unsupervised environments, such as cloud services, making them vulnerable to malware and physical tampering, and there are no effective methods for cloud services to distinguish between genuine and malicious requests.

Innovation Solution

Implementing a cryptographic attestation system with a secure attestation key storage and protection logic within biometric devices to ensure the integrity of the authentication process, using a cryptographic engine to generate and verify signatures, and employing Direct Anonymous Attestation (DAA) to maintain user privacy while ensuring device authenticity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If biometric devices are deployed in remote, unsupervised environments (e.g., cloud services), then accessibility and convenience are improved, but security and integrity protection deteriorate due to vulnerability to malware and physical tampering

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system separates the biometric authentication function from the host system by implementing a standalone attestation mechanism. The attestation key storage is segmented as a separate secure component within the biometric device, isolated from the main processing units and external interfaces, thereby providing security even when deployed in unsupervised remote environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary attestation process that acts as a mediator between the biometric device and the cloud service. The attestation key and its cryptographic verification mechanism serve as an intermediary layer that proves device integrity without requiring direct supervision or trust in the host system, enabling secure remote operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If standardized verification techniques are implemented to ensure device integrity, then security is improved, but system complexity increases due to additional cryptographic mechanisms

Engineering Contradiction:
Improvedevice integrity verificationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the critical security function (attestation key storage and verification) from the complex biometric processing system. By isolating the attestation key in a dedicated secure storage component with separate protection logic, the system provides standardized integrity verification without requiring the entire biometric system to be overly complex.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The attestation key is pre-loaded into the secure storage during device manufacturing or initialization, before the device is deployed. This preliminary action ensures that the verification mechanism is already in place and does not require complex runtime setup or configuration, reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If protection logic is integrated within the attestation key storage to prevent tampering, then security is improved, but manufacturing complexity increases

Engineering Contradiction:
Improvetamper resistanceVSAvoidmanufacturing complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent merges the protection logic directly with the attestation key storage component, creating an integrated secure element. This combination ensures that the key storage and its protection mechanisms are implemented as a single unified component, which can be manufactured as a standardized module, thereby limiting the increase in manufacturing complexity while achieving strong tamper resistance.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3005202B1System and method for biometric authentication with device attestation
Publication Date: 2022.02.16 NOK NOK LABS INC
  • EP3005202B1 patent drawingFigure 1
  • EP3005202B1 patent drawingFigure 2
  • EP3005202B1 patent drawingFigure 3a

AI summary

A system, apparatus, method, and machine readable medium are described for biometric device attestation. For example, one embodiment of an apparatus comprises: a biometric device to read biometric authentication data from a user and determine whether to successfully authenticate the user based on a comparison with biometric reference data; and a cryptographic engine to establish communication with a relying party and to attest to the model and/or integrity of the biometric device to the relying party.