Location-Based Trusted User Database for Secure System Wake
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional UPD-capable information handling systems face issues in multi-user environments, including spurious system wake events and unauthorized access due to lack of customization in wake and lock methods, leading to power loss and security vulnerabilities.
Innovation Solution
Implementing a database of trusted users (TMU database) that stores biometric data and policies, allowing systems to differentiate between trusted and untrusted users, and manage wake and lock events based on user identity and presence.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional UPD-capable systems use generic wake and lock methods, then system operation is simple, but security is compromised and power is wasted due to spurious wake events and unauthorized access
Solution Approach 1:
The patent segments the user database into trusted users and untrusted users, creating distinct access categories. The wake and lock methods are also segmented into different types (first type for trusted users, second type for untrusted users), allowing customized security policies for different user groups without requiring complex individual configurations for each user.
Solution Approach 2:
The patent applies different security policies and wake/lock methods to different user categories based on their trust status. Trusted users receive customized methods that allow more flexible access, while untrusted users receive restricted methods that prevent unauthorized access and spurious wake events, creating local quality variations in security response.
2Ease of operation
If the system wakes for any detected user, then ease of operation is improved, but power loss increases due to spurious wake events
Solution Approach 1:
The patent divides wake events into different categories based on user trust status. First type wake methods are triggered by trusted users and allow system wake, while second type wake methods are triggered by untrusted users and prevent system wake, eliminating spurious wake events caused by unauthorized users.
Solution Approach 2:
The patent introduces a user identity verification mechanism as an intermediary between user presence detection and system wake activation. The system verifies whether the detected user is trusted before allowing wake, acting as a mediator that filters out spurious wake events while maintaining ease of operation for legitimate users.
3Reliability
If the system uses a single lock method, then device complexity is reduced, but security vulnerabilities increase due to unauthorized access
Solution Approach 1:
The patent segments lock methods into first type lock methods for trusted users and second type lock methods for untrusted users. First type methods allow more flexible access control, while second type methods enforce stricter security measures, preventing unauthorized access without requiring complex individual policies for each user.
Solution Approach 2:
The patent applies different lock security levels to different user categories based on their trust status. Trusted users experience customized lock behavior that maintains accessibility, while untrusted users encounter restricted lock methods that prevent unauthorized access, creating local quality variations in security response.
Data Source
AI summary
Embodiments of systems and methods are provided for provisioning a database of trusted users stored locally within an information handling system (IHS) based on location. The systems and methods disclosed herein may be used to identify a location of the IHS, and provision a database of trusted users (e.g., a TMU database) stored locally with the IHS based on the identified location. The TMU database is initially provisioned with a set of trusted users (and associated TMU information) expected for the identified location. If the IHS moves to a different location, the systems and methods disclosed herein may automatically reprovision the TMU database with a set of trusted users (and associated TMU information) expected for the new location. This reduces re-enrollment and enables the systems and methods disclosed herein to intelligently manage the TMU database stored locally with the IHS.


