Remote Biometric Template Transmission for Secure Pre-Boot Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional fingerprint authentication systems require users to provide their fingerprint or biometric input every time they access a new system, making it cumbersome for groups to manage and distribute fingerprint templates across multiple devices for secure logon.

Innovation Solution

A method and apparatus that allow for the remote transmission and storage of biometric templates on a physical computing device, enabling secure logon using fingerprint authentication data in conjunction with pre-boot passwords, eliminating the need for manual input at each device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If fingerprint templates are distributed to every system for user authentication, then system access convenience is improved, but device complexity and security management burden increase

Engineering Contradiction:
Improvesystem access convenienceVSAvoiddevice complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces a centralized server as an intermediary that stores and manages fingerprint templates. Instead of distributing templates to every device, the server acts as a central repository that authenticates users and provides access tokens, simplifying the architecture while maintaining security and convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a digital copy of the fingerprint template in encrypted form stored on the server. This encrypted copy can be transmitted to authorized systems without compromising security, allowing multiple systems to authenticate the same user without each system needing to store the original biometric data.

Inventive Principle:
Principle #26Copying

2Reliability

If biometric authentication is required at every system logon, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent performs biometric authentication in advance during system logon, before the user needs to access specific applications or data. The authentication result is cached or tokenized, allowing subsequent access without repeated biometric verification, thus maintaining security while improving operational ease.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a universal authentication mechanism where a single biometric verification at logon provides access across multiple systems and applications. The authentication token or cached credential serves multiple functions, eliminating the need for repeated biometric scans at each system while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If fingerprint templates are pre-installed on all user computers, then productivity is improved, but security risk increases

Engineering Contradiction:
ImproveproductivityVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent transforms the fingerprint template from its original form into an encrypted digital representation with modified parameters. The encrypted template can be safely transmitted and stored on user computers without exposing the actual biometric data, maintaining security while enabling fast local authentication that improves productivity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent segments the authentication process into multiple components: the encrypted template is stored locally on the user computer for fast authentication, while the decryption keys and verification algorithms remain on the centralized server. This segmentation allows local processing for productivity while maintaining centralized security control.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8667577B2Remote registration of biometric data into a computer
Publication Date: 2014.03.04 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US8667577B2 patent drawing
  • US8667577B2 patent drawing
  • US8667577B2 patent drawing

AI summary

Systems and arrangements for permitting the transmission of fingerprint authentication data to a system remotely, while also permitting the system to employ such data as well as passwords in order to operate a computer system, while ensuring a reliable level of security for any group or organization using such systems and arrangements.