Sensor Reader Security Objects for Trusted Data Registration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in securely handling and managing data, particularly biometric data, across multiple client devices and sensor readers, ensuring data integrity and authorization during transfer and storage, while preventing unauthorized access and misuse.
Innovation Solution
A method involving client devices, sensor readers, and trusted servers, where secure protected objects are created and exchanged to enforce security policies, ensuring only authorized devices can access and operate on the data, with trusted servers verifying the integrity and compliance of these operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If data is allowed to leave the secure execution environment of the sensor reader for matching purposes, then data usability is improved, but security is worsened due to risk of illegal access or use
Solution Approach 1:
The patent extracts only the necessary data elements from the secure execution environment for matching purposes, while keeping the core biometric data protected. The sensor reader creates matching data from the biometric data without exposing the original biometric data, thus enabling data usability while maintaining security.
Solution Approach 2:
The patent introduces an intermediary matching data structure that acts as a mediator between the secure biometric data and the matching process. This matching data can be exported and used for comparison without compromising the security of the original biometric data stored in the secure execution environment.
2Reliability
If data is stored on the sensor reader in a secure execution environment, then security is improved, but data integrity verification becomes more difficult
Solution Approach 1:
The patent applies preliminary action by creating cryptographic hashes and security protected objects before data leaves the secure execution environment. The sensor reader generates matching data with integrity protection in advance, allowing verification without compromising security.
Solution Approach 2:
The patent implements feedback mechanisms where the sensor reader verifies data integrity through cryptographic checks and returns verification results to the client device. This allows continuous monitoring of data integrity while maintaining security constraints.
3Adaptability or versatility
If multiple client devices need to access data on different sensor readers, then adaptability is improved, but security control becomes more complex
Solution Approach 1:
The patent implements universality by creating a standardized security protected object structure that can be used across multiple client devices and sensor readers. The matching data format and security mechanisms are designed to be universally applicable, simplifying multi-device access while maintaining security control.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
There is provided mechanisms for requesting, by a client device, registration of identified data at a sensor reader. The client device and the sensor reader have a security trusted relationship with a trusted server. A method comprises sending a request command, from the client device and to the sensor reader, the request command pertaining to a registration operation to be performed on identified data at the sensor reader. The method comprises assigning, by the sensor reader, a security policy to the identified data. The method comprises creating, by the sensor reader and based on the request command and the security policy, a first security protected object and a second security protected object of the identified data. The method comprises sending, by the sensor reader, the second security protected object to the client device. The method comprises sending, by the sensor reader, the first security protected object towards the trusted server. The method comprises verifying, by the trusted server and upon reception of the first security protected object, that the sensor reader that created the first security protected object has a security trusted relationship with the trusted server.