Biometric Authentication Fast Boot via USB Initialization Bypass

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer startup methods using biometric authentication devices face challenges in reducing boot time while ensuring security, as excluding USB from the POST process hinders mutual authentication and requires password input, thereby increasing boot time.

Innovation Solution

A computer startup method that employs a biometric authentication device for fast boot, omitting USB initialization and using stored passwords for system access, with measures to ensure security through authentication data and power control circuits, allowing for normal or fast boot based on authentication type.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If USB initialization is excluded from the POST process to reduce boot time, then boot time is reduced, but mutual authentication between BIOS and fingerprint authentication device cannot be performed

Engineering Contradiction:
Improveboot timeVSAvoidauthentication security
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The authentication process is segmented into two distinct phases: (1) Fast Boot mode where USB initialization is skipped and authentication data is verified without USB, and (2) Normal Boot mode where USB initialization is performed and mutual authentication is executed. This segmentation allows the system to choose the appropriate authentication path based on whether the fingerprint authentication device is already trusted, thereby resolving the contradiction between fast boot and authentication security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary authentication actions during the first normal boot where USB initialization is completed and mutual authentication is established. The authentication results and trust relationships are stored as authentication data in the fingerprint authentication device. This preliminary action enables subsequent fast boots to skip USB initialization while maintaining security through pre-verified authentication data.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple passwords are required for system access to ensure security, then security is improved, but the time to make the computer usable increases

Engineering Contradiction:
Improvesystem securityVSAvoidtime to make computer usable
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system creates a copy of the authentication verification process by storing authentication data (including password verification results) in the fingerprint authentication device during normal boot. During fast boot, this stored authentication data is used instead of requiring real-time verification of multiple passwords, thereby maintaining security while significantly reducing the time to make the computer usable.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

Multiple password verifications are performed in advance during the normal boot process, and the results are stored as authentication data. This preliminary action eliminates the need to re-verify multiple passwords during fast boot, resolving the contradiction between security and usability time.

Inventive Principle:
Principle #10Preliminary action

3Loss of time

If USB interface is excluded from POST for fast boot, then boot time is reduced, but device complexity increases due to conditional boot modes

Engineering Contradiction:
Improveboot timeVSAvoidboot mode management
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system implements self-service boot mode selection where the fingerprint authentication device automatically determines whether to operate in Fast Boot or Normal Boot mode based on the presence and validity of authentication data. This self-determination mechanism reduces the need for complex external control logic, thereby managing device complexity while enabling fast boot functionality.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9230080B2Method of starting a computer using a biometric authentication device
Publication Date: 2016.01.05 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US9230080B2 patent drawing
  • US9230080B2 patent drawing
  • US9230080B2 patent drawing

AI summary

A computer is made usable in a short time using a fingerprint authentication device. When a fingerprint authentication device performs authentication successfully, the fingerprint authentication device sends a startup signal to a power controller via a line. The power controller controls a DC/DC converter to supply power to devices. The fingerprint authentication device sets whether normal boot or fast boot that is completed in a shorter time than the normal boot is successful, in a register via a line. In the fast boot, initialization of a USB interface of a line and password input by a user are skipped, and a BIOS accesses a system by single sign-on using a password stored in a secure area.