Biometric Sensor Authentication via Host Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current fingerprint match systems are vulnerable to software attacks that can bypass security, and implementing full verification processes on the sensor increases costs significantly.
Innovation Solution
A biometric sensor authenticates itself to a host system by verifying image processing steps without performing the entire set of authentication processes itself, using a method that involves transmitting fingerprint data to a host for validation and comparing results to ensure secure authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If full verification processes are implemented on the sensor, then security is improved, but device cost and complexity increase significantly
Solution Approach 1:
The authentication process is divided into two segments: the sensor performs image capture and basic processing, while the host computer performs the computationally intensive verification algorithms. This segmentation allows the sensor to remain simple and cost-effective while the host, which has greater processing power, handles the complex security verification.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism where the sensor captures biometric data and transmits it to the host for verification. The host acts as an intermediary that performs the complex cryptographic operations and template matching, then returns authentication results to the sensor. This intermediary approach distributes the computational burden appropriately.
2Reliability
If the sensor performs all authentication steps itself, then security is improved, but memory and processor requirements increase
Solution Approach 1:
The authentication workload is segmented between the sensor and host based on their respective capabilities. The sensor handles data acquisition and preliminary processing, while the host handles template extraction, encryption, and matching operations that require significant processor power and memory resources.
Solution Approach 2:
The sensor performs partial authentication processing (image capture and basic processing) rather than attempting to perform the entire authentication sequence. This partial action approach allows the sensor to contribute to security verification without requiring the full computational resources needed for complete authentication processing.
3Ease of operation
If host software is vulnerable to attacks, then ease of operation is maintained, but security is compromised
Solution Approach 1:
The system implements preliminary anti-action by having the host computer perform secure template extraction and encryption before transmitting data to the sensor. The host verifies the sensor's authenticity and establishes secure communication channels in advance, preventing attackers from intercepting or manipulating biometric data during transmission or processing.
Solution Approach 2:
The authentication system implements feedback mechanisms where the host verifies sensor responses and authenticates the sensor before allowing biometric data processing. This feedback loop ensures that only authenticated sensors can access the authentication pipeline, and the system can detect and respond to potential attacks by monitoring the authentication process.
Data Source
AI summary
A novel system, device and method of validation is provided for sensing a biometric such as a fingerprint, where biometric data corresponding to the biometric entity such as a fingerprint is then transmitted to a host configured to perform a plurality of authentication processes to authenticate the biometric data. At least one of the plurality of authentication steps is then validated. Alternatively, a portion of the biometric data may be retained, where biometric data corresponding to the biometric is then transmitted to a host configured to perform a plurality of authentication steps to authenticate the biometric data. At least one of the plurality of authentication steps is then validated.


