External Biometric Reader with Secure Microcontroller Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identity verification systems using biometric data face security vulnerabilities due to the permanence and sensitivity of biometric information, particularly when stored on devices that may not be optimized for secure storage, and the risk of spoofed authentication messages from malicious devices.
Innovation Solution
An external biometric reader and verification device that stores biometric data locally and uses a secure microcontroller to authenticate users, ensuring that biometric data is not sent over networks and employing cryptographic methods like private signing keys and message authentication codes to secure communication between the device and the computing system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric data is stored on a computing device, then identity verification can be performed, but security is compromised due to potential vulnerabilities in the computing device
Solution Approach 1:
The system is divided into two separate devices: an external biometric reader that captures and processes biometric data, and a computing device that receives verification results. This segmentation isolates sensitive biometric data processing from the main computing system, reducing security vulnerabilities while maintaining verification functionality.
Solution Approach 2:
An external biometric reader acts as an intermediary device between the user and the computing device. It performs biometric verification locally and transmits only the verification result to the computing device, preventing direct exposure of biometric data to the computing system and reducing security risks.
2Ease of operation
If biometric data is transmitted over a network or connection, then verification can be performed remotely, but the data becomes vulnerable to interception and spoofing
Solution Approach 1:
The biometric verification process is extracted from the computing device and performed locally on the external biometric reader. Only the verification result (not the raw biometric data) is transmitted to the computing device, eliminating the vulnerability of transmitting sensitive biometric information over connections.
Solution Approach 2:
The external biometric reader performs preliminary verification of biometric data before transmission, and establishes authenticated communication channels in advance. This preliminary authentication prevents spoofed authentication messages from malicious devices, as the reader verifies the identity of connected devices before accepting or transmitting verification data.
3Reliability
If an external biometric device is used, then security is improved by isolating biometric data, but authentication vulnerabilities exist from spoofed messages
Solution Approach 1:
The system implements authenticated communication with feedback mechanisms where the external biometric reader and computing device verify each other's identities through cryptographic authentication. This feedback loop ensures that only authorized devices can exchange verification data, preventing spoofed authentication messages while maintaining secure isolated biometric processing.
Data Source
AI summary
An external biometric reader and verification device for providing access control to a computing device, and associated methods, are disclosed. The external reader can store and verify biometrics under the control of the computing device and send identity verification messages to the computing device. One disclosed device includes a biometric reader communicatively connected to an external secure microcontroller. The external secure microcontroller stores a set of biometric data and a signing key. The signing key can be injected by a device manufacturer in a controlled key injection room in a manufacturing facility and can be used to sign a certificate. An operating system of the computing device can be programmed to send a request for the certificate, receive the certificate, and predicate control of access to the operating system using the verification messages on verification of the certificate.


