Biometric Sensor Encryption for Roaming Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Biometric authentication systems are susceptible to spoofing and replay attacks, particularly in roaming authentication scenarios where biometric credentials can be misused across networks of Information Handling Systems (IHSs), compromising security.

Innovation Solution

Implementing a biometric authentication method that uses a biometric sensor to collect and encrypt user prints with a group-specific key, transmitting them to an authentication system for matching against stored templates, with secure storage and out-of-band communication pathways to prevent unauthorized access and misuse.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If biometric authentication is implemented in roaming scenarios across networks of IHSs, then user convenience and access flexibility are improved, but security vulnerability to spoofing and replay attacks increases

Engineering Contradiction:
Improveaccess flexibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by capturing and encrypting biometric data at the point of collection before transmission. The biometric sensor encrypts the captured biometric print using a key stored in secure storage, preventing the data from being usable for replay attacks if intercepted during transmission across the network.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary secure storage component that holds encryption keys separate from both the biometric sensor and the authentication system. This intermediary secure element acts as a trusted mediator that enables roaming authentication while preventing direct access to raw biometric data, thereby mitigating replay attack risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If biometric prints are transmitted across networks for roaming authentication, then authentication capability is improved, but risk of credential capture and misuse increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidcredential capture risk
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The system changes the parameter of biometric data from plaintext to encrypted form before transmission. The biometric sensor applies encryption using a key retrieved from secure storage, transforming the biometric print into ciphertext that cannot be used for authentication if captured during network transmission.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent extracts the encryption key from the biometric sensor and stores it separately in a secure storage element. This separation ensures that even if the biometric sensor is compromised, the extracted biometric data cannot be decrypted without the separately stored key, preventing credential misuse.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If encryption is applied to biometric data during transmission, then security is improved, but processing complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The biometric sensor performs self-service by encrypting the captured biometric data using a key it retrieves from its own secure storage. This eliminates the need for external encryption infrastructure, reducing system-wide complexity while maintaining security. The sensor autonomously handles the encryption process before transmission.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11316680B2Protected credentials for roaming biometric login profiles
Publication Date: 2022.04.26 DELL PROD LP
  • US11316680B2 patent drawing
  • US11316680B2 patent drawing
  • US11316680B2 patent drawing

AI summary

In a system of networked IHSs (Information Handling Systems) supporting the use of roaming biometric profiles, an individual may utilize biometric authentication for gaining access to various IHSs within the system. An IHS configured to support roaming biometric authentication includes biometric sensors that support secure transmission and management of biometric prints collected by such sensors. Such biometric sensors may interoperate with a secure processing component of the IHS in order to prevent transmission and storage of unprotected biometric prints, while still supporting roaming biometric authentication. The biometric sensor utilizes an encryption key for encoding biometric prints where the key is selected based on a group affiliation of the individual, thus protecting biometric prints from other groups that use roaming biometric authentication while sharing the same network of IHSs.