Entangled Biosensor Authentication Against Rogue Sensor Spoofing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Biometric sensors in mobile devices are vulnerable to spoofing attacks where attackers replace the fingerprint sensor with a rogue circuit configured to provide prerecorded data, compromising identity and financial security.
Innovation Solution
A biometric sensor is physically bound to a secure element, using separate communication interfaces to ensure cryptographically entangled authentication, combining image and cryptographic data for secure verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric sensors are used for authentication, then user convenience and security are improved, but the system becomes vulnerable to spoofing attacks where attackers replace the sensor with rogue circuits
Solution Approach 1:
The patent combines the biometric sensor with a secure element into a single integrated unit. The sensor die and secure element die are bonded together to form an integrated circuit that cannot be separated without destroying functionality. This merging ensures that the biometric data capture and cryptographic verification occur together in a single authenticated component, preventing rogue circuit substitution attacks.
Solution Approach 2:
The patent introduces a secure element as an intermediary between the biometric sensor and the host system. The secure element acts as a trusted mediator that performs cryptographic operations and validates the sensor's authenticity before allowing authentication. This intermediary layer prevents direct access to biometric data and blocks spoofing attempts by verifying the sensor's identity through cryptographic challenges.
2Reliability
If the biometric sensor is integrated with a secure element, then authentication integrity is improved, but device complexity increases
Solution Approach 1:
By merging the sensor and secure element into a single integrated circuit package, the patent reduces overall system complexity. Although the internal structure becomes more complex, the external interface remains simple and unified. The host system interacts with a single authenticated component rather than managing separate sensor and security modules, simplifying integration and reducing points of failure.
Solution Approach 2:
The patent implements a nested structure where the secure element is embedded within the sensor package, or the sensor is integrated onto the same substrate as the secure element. This nesting allows the complex cryptographic functionality to be contained within the authentication component without adding external complexity to the overall system architecture.
Data Source
AI summary
Disclosed herein are systems and methods for entangled authentication of biometric sensors and biometric-sensor outputs. In an embodiment, a secure-biometric-sensor system includes a biometric sensor and a secure element physically bound to one another. The sensor is communicatively interposed between a host and the secure element. The sensor receives a cryptographic challenge from the host and forwards it to the secure element. The sensor captures a biometric reading and transmits it to the host. The sensor receives, from the secure element, a challenge response that includes a shared secret between the host and the secure element. The sensor generates a cryptographically entangled token from a predetermined combination of the shared secret and data specific to the captured biometric reading, and transmits the cryptographically entangled token to the host for use by the host in attempting to authenticate the biometric reading as having been captured by the sensor.


