Biometric Authentication Fast Boot via USB Initialization Bypass
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer startup methods using biometric authentication devices face challenges in reducing boot time while ensuring security, as excluding USB from the POST process hinders mutual authentication and requires password input, thereby increasing boot time.
Innovation Solution
A computer startup method that employs a biometric authentication device for fast boot, omitting USB initialization and using stored passwords for system access, with measures to ensure security through authentication data and power control circuits, allowing for normal or fast boot based on authentication type.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If USB initialization is excluded from the POST process to reduce boot time, then boot time is reduced, but mutual authentication between BIOS and fingerprint authentication device cannot be performed
Solution Approach 1:
The authentication process is segmented into two distinct phases: (1) Fast Boot mode where USB initialization is skipped and authentication data is verified without USB, and (2) Normal Boot mode where USB initialization is performed and mutual authentication is executed. This segmentation allows the system to choose the appropriate authentication path based on whether the fingerprint authentication device is already trusted, thereby resolving the contradiction between fast boot and authentication security.
Solution Approach 2:
The system performs preliminary authentication actions during the first normal boot where USB initialization is completed and mutual authentication is established. The authentication results and trust relationships are stored as authentication data in the fingerprint authentication device. This preliminary action enables subsequent fast boots to skip USB initialization while maintaining security through pre-verified authentication data.
2Reliability
If multiple passwords are required for system access to ensure security, then security is improved, but the time to make the computer usable increases
Solution Approach 1:
The system creates a copy of the authentication verification process by storing authentication data (including password verification results) in the fingerprint authentication device during normal boot. During fast boot, this stored authentication data is used instead of requiring real-time verification of multiple passwords, thereby maintaining security while significantly reducing the time to make the computer usable.
Solution Approach 2:
Multiple password verifications are performed in advance during the normal boot process, and the results are stored as authentication data. This preliminary action eliminates the need to re-verify multiple passwords during fast boot, resolving the contradiction between security and usability time.
3Loss of time
If USB interface is excluded from POST for fast boot, then boot time is reduced, but device complexity increases due to conditional boot modes
Solution Approach 1:
The system implements self-service boot mode selection where the fingerprint authentication device automatically determines whether to operate in Fast Boot or Normal Boot mode based on the presence and validity of authentication data. This self-determination mechanism reduces the need for complex external control logic, thereby managing device complexity while enabling fast boot functionality.
Data Source
AI summary
A computer is made usable in a short time using a fingerprint authentication device. When a fingerprint authentication device performs authentication successfully, the fingerprint authentication device sends a startup signal to a power controller via a line. The power controller controls a DC/DC converter to supply power to devices. The fingerprint authentication device sets whether normal boot or fast boot that is completed in a shorter time than the normal boot is successful, in a register via a line. In the fast boot, initialization of a USB interface of a line and password input by a user are skipped, and a BIOS accesses a system by single sign-on using a password stored in a secure area.


