Biometric Device Enrollment via Trusted Smart Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Biometric devices, often limited by computing resources and lack of user interfaces, face challenges in enrolling with network services securely, especially when capturing and storing user biometric information, which can be vulnerable to attackers.

Innovation Solution

A system where a trusted coordinating smart device acts as an intermediary to enroll a biometric device with a network service using challenge-response authentication protocols like Zero-Knowledge Proof Authentication, ensuring secure communication and preventing the server from learning authentication credentials, thereby isolating biometric information capture and storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a biometric device directly enrolls with a network service, then the enrollment process is simpler, but the device is vulnerable to attacks and biometric information may be compromised

Engineering Contradiction:
Improvesecurity of biometric informationVSAvoidenrollment process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A coordinating smart device is introduced as an intermediary between the biometric device and the network service. The smart device manages the enrollment process, including generating challenges, receiving responses, and communicating with the network service, thereby protecting the biometric device from direct exposure to security threats while maintaining a secure enrollment process

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a biometric device has full computing resources and user interface, then it can independently manage authentication, but the device cost and complexity increase

Engineering Contradiction:
Improveindependent authentication capabilityVSAvoiddevice resources and interface
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The authentication system is segmented into two parts: a minimal biometric device that only captures biometric data and a coordinating smart device that handles complex authentication logic, challenge-response protocols, and communication with the network service. This allows the biometric device to remain simple and low-cost while still providing secure authentication capabilities

Inventive Principle:
Principle #1Segmentation

3Speed

If biometric information is stored on the biometric device, then authentication speed is improved, but the device becomes a target for attackers

Engineering Contradiction:
Improveauthentication speedVSAvoidvulnerability to attacks
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The sensitive biometric information and authentication credentials are extracted from the biometric device and managed by the coordinating smart device. The biometric device only retains minimal processing capability to capture biometric data and generate responses, while the smart device stores and manages the security credentials, reducing the attack surface of the biometric device

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10586032B2Systems and methods for authenticating a biometric device using a trusted coordinating smart device
Publication Date: 2020.03.10 TOBII TECHNOLOGIES LTD
  • US10586032B2 patent drawing
  • US10586032B2 patent drawing
  • US10586032B2 patent drawing

AI summary

Systems and methods for authenticating a biometric device using a trusted coordinating smart device in accordance with embodiments of the invention are disclosed. In one embodiment, a process for enrolling a configurable biometric device with a network service includes obtaining a device identifier (ID) of the configurable biometric device using a coordinating smart device, communicating the device ID from the coordinating smart device to a network service, communicating a first challenge based on a challenge-response authentication protocol from the network service to the coordinating smart device, communicating the first challenge and a response uniform resource locator (URL) from the coordinating smart device to the configurable biometric device, generating a first response to the first challenge and communicating the first response to the network service utilizing the response URL, receiving a secure channel key by the coordinating smart device from the network service, communicating the secure channel key from the coordinating smart device to the configurable biometric device, performing a biometric enrollment process using the configurable biometric device including capturing biometric information from a user, and creating a secure communication link between the configurable biometric device and the network service using the secure channel key when the first response satisfies the challenge-response authentication protocol.