Biometric Security Device for Digital Key Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current biometric security devices for digital key storage, such as smartphones, lack flexibility in managing multiple users and are not cost-effective for secure key storage, especially in IoT devices, as they compromise security when accessed by third-party organizations.
Innovation Solution
A biometric security device utilizing TrustZone technology and biometric authentication, with a processing module configured into secure and normal execution environments, featuring a nonvolatile storage unit with biometric and application databases, and a communication interface for secure data transfer, allowing flexible access management without compromising data confidentiality and integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If smartphones are used to store digital keys, then portability and user accessibility are improved, but security is worsened due to inability to control third-party access and manage multiple users
Solution Approach 1:
The system is segmented into a secure environment (Trusted Execution Environment) and a normal environment, with the secure environment isolated to protect digital keys while the normal environment handles user applications. This segmentation allows controlled access where only authorized applications can interact with keys, solving both accessibility and security requirements
Solution Approach 2:
An intermediary access control mechanism is introduced between the digital keys and third-party applications. The system uses biometric authentication and application-specific access controls as intermediaries to mediate key access, preventing direct access by unauthorized applications while allowing legitimate access through the mediation layer
2Reliability
If TrustZone technology is used for secure key storage, then security is improved, but cost-effectiveness and flexibility are worsened due to inability to manage multiple users and applications
Solution Approach 1:
The system implements dynamic access control where permissions are not fixed but can be changed based on user identity, application requirements, and security policies. Multiple users can be registered with different biometric data, and each user can have different access permissions for different applications, making the system adaptable while maintaining security
Solution Approach 2:
The secure device is designed with universal functionality to support multiple users, multiple applications, and different types of digital keys simultaneously. The system can manage diverse cryptographic operations (encryption, decryption, signing, verification) for different applications while maintaining a single secure environment, achieving both security and versatility
3Reliability
If biometric authentication is implemented, then security is improved, but device complexity is worsened
Solution Approach 1:
The biometric authentication functionality is merged with the existing secure element and TrustZone infrastructure. The biometric data is stored and processed within the secure environment alongside the digital keys, combining multiple security functions into a unified system that reduces overall complexity compared to separate implementations
Data Source
AI summary
A biometric security device for digital key storing is disclosed. The biometric security device includes a biometric information fetching module and a processing module. The processing module has a nonvolatile storage unit and a processing unit. The nonvolatile storage unit includes a secure storage unit and a general storage unit. The biometric security device with a secure electronic key designed for storing secret data utilizes both TrustZone⢠technology (or similar technology) and biometric authentication. Thus, it can provide the flexibility for multiple users or applications to use the biometric security device or any equipment the biometric security device mounted in without compromising the safeguard of the data stored therein.


