Fingerprint Authentication Security Against Device Replacement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing fingerprint authentication systems for personal computers face challenges in securely verifying user identity, particularly when a fingerprint authentication device is replaced with a counterfeit one, leading to potential unauthorized access.
Innovation Solution
An information processing apparatus that integrates a password input module, a biological authentication device with storage for biological and identification information, and an authentication control module that sets and holds identification information, allowing password entry to be substituted by fingerprint authentication when both sets of information match, and includes a mechanism to detect and prevent unauthorized access by requiring fingerprint verification after valid password entry.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If fingerprint authentication is implemented to replace password entry, then convenience and security are improved, but vulnerability to device replacement attacks increases
Solution Approach 1:
The patent introduces an intermediary verification mechanism where the BIOS checks identification information from the fingerprint authentication device against stored reference information. This intermediary security check prevents direct authentication bypass even when the device is replaced, as the identification information verification acts as a mediator between the authentication request and system access.
Solution Approach 2:
The system performs preliminary registration of identification information in the BIOS during initial setup or before device replacement. This preliminary action stores reference identification information that will be used for future verification, enabling the system to detect and prevent device replacement attacks before they can compromise security.
2Reliability
If identification information correspondence is established between BIOS and fingerprint authentication device, then security is improved, but system complexity increases
Solution Approach 1:
The patent merges the identification information storage and verification functions into the existing BIOS system. By combining the fingerprint authentication device's identification information with the BIOS's existing security framework, the system achieves enhanced security without adding separate complex verification systems, thus reducing overall system complexity.
Solution Approach 2:
The BIOS automatically performs the verification of identification information without requiring manual intervention or complex user configuration. The system self-services the security verification process by automatically comparing the authentication device's identification information against stored reference information, simplifying the user experience while maintaining security.
3Reliability
If password entry is required when identification information does not match, then security is improved, but user convenience deteriorates
Solution Approach 1:
The patent implements a dynamic authentication process that adapts based on verification results. When identification information matches, the system provides convenient fingerprint-only authentication. When there's a mismatch indicating potential device replacement, the system dynamically requires password entry. This dynamic approach balances security and convenience by adjusting authentication requirements based on real-time verification outcomes.
Data Source
AI summary
According to one embodiment, an information processing apparatus includes an input to input a password, a biological authentication device including a storage unit for storing biological information and identification information, and an authentication controller. The authentication controller sets and holds identification information to be stored in the storage unit of the biological authentication device, and permits a password input using the input to be substituted by authentication using the biological authentication device when the identification information held by itself and the identification information stored in the storage unit of the biological authentication device match. The authentication controller includes a setter to perform a setting for the identification information stored in the storage unit of the biological identification device and held by itself, on both conditions of authentication establishment with a registered password entry using the input and authentication establishment using the biological authentication device.


