Biometric Password Association in Legacy BIOS

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing biometric security systems are not compatible with legacy security systems like BIOS, which require special application programs to operate, limiting their use in conjunction with password security schemes and posing issues when biometric data is unavailable due to injury or system compatibility.

Innovation Solution

A method that associates biometric information with passwords, allowing users to access computer systems by either using biometric data or manually entering passwords, and a system comprising a biometric mechanism and two security mechanisms to manage password and biometric authentication within the BIOS, enabling compatibility with legacy systems without requiring a special application program.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If biometric security systems are implemented to replace password security schemes, then user convenience is improved (no need to remember passwords), but compatibility with legacy security systems deteriorates (cannot work with BIOS password schemes)

Engineering Contradiction:
Improveuser convenienceVSAvoidcompatibility with legacy security systems
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent merges biometric authentication and password authentication into a single unified security mechanism within the BIOS. The biometric scanner and password input mechanisms are combined to authenticate users for the same set of passwords, allowing the system to accept either biometric data or passwords interchangeably for accessing HDP, POP, and SVP security levels.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security mechanism is designed to perform multiple functions: it can authenticate users using biometric information (fingerprint, retinal scan, face geometry), using passwords, or using either method interchangeably. This multi-functional approach allows the same security mechanism to replace traditional password schemes while maintaining compatibility with legacy BIOS password requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If biometric information is used exclusively for authentication, then security is improved, but reliability deteriorates (user cannot access system if biometric data is unavailable due to injury)

Engineering Contradiction:
Improveaccess availabilityVSAvoidbiometric data unavailability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system prepares backup authentication methods in advance by allowing users to set passwords that are stored and associated with their biometric profiles. If biometric authentication fails or is unavailable due to injury, the system has pre-prepared alternative passwords ready for immediate use, cushioning against the harmful effect of biometric unavailability.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Solution Approach 2:

The patent introduces passwords as an intermediary authentication method between the user and the system when biometric data is unavailable. The password serves as a mediator that can substitute for biometric authentication, allowing users to access the system through an alternative pathway when their primary biometric method is compromised.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If existing biometric security schemes are implemented, then biometric authentication capability is improved, but device complexity increases (require special application programs to be loaded)

Engineering Contradiction:
Improvebiometric authentication capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The biometric scanner and authentication logic are integrated into the BIOS itself, performing preliminary authentication actions before the operating system loads. This eliminates the need to load special application programs after system startup, as the biometric authentication capability is already present and operational at the firmware level during the boot process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces the mechanical/software-based approach of loading special application programs with a firmware-based implementation directly in the BIOS. This substitution eliminates the need for separate application programs by integrating the biometric authentication functionality into the existing BIOS structure, reducing overall system complexity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8539248B2Associating biometric information with passwords
Publication Date: 2013.09.17 LENOVO GLOBAL TECHNOLOGIES SWITZERLAND INTERNATIONAL GMBH
  • US8539248B2 patent drawing
  • US8539248B2 patent drawing
  • US8539248B2 patent drawing

AI summary

Associating biometric information with passwords is disclosed. If biometric information received from a user matches stored biometric information, stored passwords associated therewith are retrieved. If these stored passwords are identical to access-enabling passwords, then the user is permitted to gain access associated with the access-enabling passwords. If the biometric information matches the stored biometric information but the stored passwords do not match the access-enabling passwords or are not present, then the user is requested to manually enter passwords, which are stored. If these stored passwords are identical to the access-enabling passwords, the user is permitted to gain access. However, if the biometric information does not match the stored biometric information, or if the biometric information has not been received from the user or is not present, then the user is requested to manually enter passwords. If these passwords match the access-enabling passwords, then the user is permitted to gain access.