External Biometric Reader with Secure Microcontroller Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity verification systems using biometric data face security vulnerabilities due to the permanence and sensitivity of biometric information, particularly when stored on devices that may not be optimized for secure storage, and the risk of spoofed authentication messages from malicious devices.

Innovation Solution

An external biometric reader and verification device that stores biometric data locally and uses a secure microcontroller to authenticate users, ensuring that biometric data is not sent over networks and employing cryptographic methods like private signing keys and message authentication codes to secure communication between the device and the computing system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If biometric data is stored on a computing device, then identity verification can be performed, but security is compromised due to potential vulnerabilities in the computing device

Engineering Contradiction:
ImprovesecurityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is divided into two separate devices: an external biometric reader that captures and processes biometric data, and a computing device that receives verification results. This segmentation isolates sensitive biometric data processing from the main computing system, reducing security vulnerabilities while maintaining verification functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An external biometric reader acts as an intermediary device between the user and the computing device. It performs biometric verification locally and transmits only the verification result to the computing device, preventing direct exposure of biometric data to the computing system and reducing security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If biometric data is transmitted over a network or connection, then verification can be performed remotely, but the data becomes vulnerable to interception and spoofing

Engineering Contradiction:
Improveverification capabilityVSAvoiddata interception and spoofing
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The biometric verification process is extracted from the computing device and performed locally on the external biometric reader. Only the verification result (not the raw biometric data) is transmitted to the computing device, eliminating the vulnerability of transmitting sensitive biometric information over connections.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The external biometric reader performs preliminary verification of biometric data before transmission, and establishes authenticated communication channels in advance. This preliminary authentication prevents spoofed authentication messages from malicious devices, as the reader verifies the identity of connected devices before accepting or transmitting verification data.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If an external biometric device is used, then security is improved by isolating biometric data, but authentication vulnerabilities exist from spoofed messages

Engineering Contradiction:
Improvebiometric data protectionVSAvoidspoofed authentication messages
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system implements authenticated communication with feedback mechanisms where the external biometric reader and computing device verify each other's identities through cryptographic authentication. This feedback loop ensures that only authorized devices can exchange verification data, preventing spoofed authentication messages while maintaining secure isolated biometric processing.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10965468B2Authenticated external biometric reader and verification device
Publication Date: 2021.03.30 CLOVER NETWORK INC
  • US10965468B2 patent drawing
  • US10965468B2 patent drawing
  • US10965468B2 patent drawing

AI summary

An external biometric reader and verification device for providing access control to a computing device, and associated methods, are disclosed. The external reader can store and verify biometrics under the control of the computing device and send identity verification messages to the computing device. One disclosed device includes a biometric reader communicatively connected to an external secure microcontroller. The external secure microcontroller stores a set of biometric data and a signing key. The signing key can be injected by a device manufacturer in a controlled key injection room in a manufacturing facility and can be used to sign a certificate. An operating system of the computing device can be programmed to send a request for the certificate, receive the certificate, and predicate control of access to the operating system using the verification messages on verification of the certificate.