Biometric Sensor Encryption for Roaming Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Biometric authentication systems are susceptible to spoofing and replay attacks, particularly in roaming authentication scenarios where biometric credentials can be misused across networks of Information Handling Systems (IHSs), compromising security.
Innovation Solution
Implementing a biometric authentication method that uses a biometric sensor to collect and encrypt user prints with a group-specific key, transmitting them to an authentication system for matching against stored templates, with secure storage and out-of-band communication pathways to prevent unauthorized access and misuse.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If biometric authentication is implemented in roaming scenarios across networks of IHSs, then user convenience and access flexibility are improved, but security vulnerability to spoofing and replay attacks increases
Solution Approach 1:
The system performs preliminary actions by capturing and encrypting biometric data at the point of collection before transmission. The biometric sensor encrypts the captured biometric print using a key stored in secure storage, preventing the data from being usable for replay attacks if intercepted during transmission across the network.
Solution Approach 2:
The patent introduces an intermediary secure storage component that holds encryption keys separate from both the biometric sensor and the authentication system. This intermediary secure element acts as a trusted mediator that enables roaming authentication while preventing direct access to raw biometric data, thereby mitigating replay attack risks.
2Adaptability or versatility
If biometric prints are transmitted across networks for roaming authentication, then authentication capability is improved, but risk of credential capture and misuse increases
Solution Approach 1:
The system changes the parameter of biometric data from plaintext to encrypted form before transmission. The biometric sensor applies encryption using a key retrieved from secure storage, transforming the biometric print into ciphertext that cannot be used for authentication if captured during network transmission.
Solution Approach 2:
The patent extracts the encryption key from the biometric sensor and stores it separately in a secure storage element. This separation ensures that even if the biometric sensor is compromised, the extracted biometric data cannot be decrypted without the separately stored key, preventing credential misuse.
3Reliability
If encryption is applied to biometric data during transmission, then security is improved, but processing complexity increases
Solution Approach 1:
The biometric sensor performs self-service by encrypting the captured biometric data using a key it retrieves from its own secure storage. This eliminates the need for external encryption infrastructure, reducing system-wide complexity while maintaining security. The sensor autonomously handles the encryption process before transmission.
Data Source
AI summary
In a system of networked IHSs (Information Handling Systems) supporting the use of roaming biometric profiles, an individual may utilize biometric authentication for gaining access to various IHSs within the system. An IHS configured to support roaming biometric authentication includes biometric sensors that support secure transmission and management of biometric prints collected by such sensors. Such biometric sensors may interoperate with a secure processing component of the IHS in order to prevent transmission and storage of unprotected biometric prints, while still supporting roaming biometric authentication. The biometric sensor utilizes an encryption key for encoding biometric prints where the key is selected based on a group affiliation of the individual, thus protecting biometric prints from other groups that use roaming biometric authentication while sharing the same network of IHSs.


