Secure Logon Client for Shared Devices Using Biometric Sensors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information handling systems face challenges in securely managing logons for multiple users, particularly in shared systems where efficient and secure access is needed without compromising security or user convenience.

Innovation Solution

The implementation of a shared information handling system that utilizes biometric sensors, proximity sensors, and camera devices in conjunction with a secure logon client and session managed operating system to enable multi-user support, allowing for both full and expedited credential logons, with features like session management and facial recognition for user authentication and session resumption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional logon methods are used for shared devices, then security can be maintained through credential verification, but user convenience deteriorates due to repeated full credential entry requirements

Engineering Contradiction:
Improvelogon convenienceVSAvoidtime for credential entry
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system performs preliminary actions by capturing biometric data and establishing user sessions in advance. When a user returns to the shared device, the system has already prepared the authentication context, allowing for expedited logon resumption without requiring full credential re-entry, thus resolving the time loss issue while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces biometric sensors and proximity sensors as intermediary mechanisms between the user and the credential verification system. These sensors enable automatic user identification and session resumption, eliminating the need for manual credential entry while maintaining secure authentication through the session manager's verification processes

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If biometric sensors and proximity sensors are added to enable expedited logon, then user convenience improves through automatic recognition, but device complexity increases due to additional hardware components

Engineering Contradiction:
Improveautomatic user recognitionVSAvoidnumber of sensors and components
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent makes the shared device universal by enabling it to support multiple authentication methods (full credential logon, biometric logon, and expedited logon resumption). The session manager and authentication database work together to handle various user types and authentication scenarios, allowing the same device to serve diverse needs without requiring separate systems for each function

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements self-service through automatic user identification using biometric and proximity sensors. When a user approaches or uses the device, the system automatically captures biometric data, identifies the user through the authentication database, and resumes their session without manual intervention, allowing the device to serve itself in the authentication process

Inventive Principle:
Principle #25Self-service

3Productivity

If session management features are implemented for multiple users, then system resource management improves through efficient session control, but ease of operation deteriorates due to more complex logon processes

Engineering Contradiction:
Improvesystem resource management efficiencyVSAvoidlogon process simplicity
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent segments the logon process into distinct types: full credential logon for initial authentication, biometric logon for enhanced security scenarios, and expedited logon resumption for returning users. The session manager handles different session states (active, suspended, expired) separately, allowing efficient resource management while presenting simplified interfaces for each specific user scenario

Inventive Principle:
Principle #1Segmentation

4Reliability

If facial recognition and biometric authentication are used, then security improves through reliable user identification, but device complexity increases due to additional authentication mechanisms

Engineering Contradiction:
Improveuser identification accuracyVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses biometric sensors and camera devices as intermediary components that capture physiological data and pass it to the session manager for verification against the authentication database. This intermediary approach enables reliable user identification through facial recognition and biometric matching while keeping the core authentication logic centralized and manageable in the session manager, rather than distributing complex authentication mechanisms across the entire system

Inventive Principle:
Principle #24Intermediary (Mediator)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution provides secure, efficient, and convenient access for multiple users by enabling secure logon processes, managing user sessions effectively, and allowing for expedited logon resumption, enhancing user experience and system resource management.

Implementation Method 1

a biometric sensor, a proximity sensor, and a camera device

Methodology Applied
Scientific EffectBiometric detection:

Implementation Method 2

a biometric sensor, a proximity sensor, and a camera device

Methodology Applied
Scientific EffectProximity detection:

Data Source

PatentUS9813904B2System and method of secure logon for shared devices
Publication Date: 2017.11.07 DELL PROD LP
  • US9813904B2 patent drawing
  • US9813904B2 patent drawing
  • US9813904B2 patent drawing

AI summary

A system includes a sensor to determine a user is proximate to the system and a logon module to receive information from the sensor that a user is proximate to the system, receive logon information from the user and identification information associated with the user, authenticate the user to use the system based on the logon information, store the identification information, receive second information from the sensor that the user is not proximate to the system, suspend an operating system session, receive information from the sensor that the user is again proximate to the system, receive second identification information associated with the user, determine that the first and second identification information matches, and resume the OS session in response to determining that the first and second identification information matches.