Shared Device Biometric Access with Peer Profile Synchronization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The integration of biometric authentication in a shared-device paradigm presents challenges in maintaining user profile data synchronization across devices while ensuring security and integrity, especially in environments with high employee turnover and shift work, where user profiles need to be maintained and synchronized across a pool of shared devices.
Innovation Solution
A decentralized system for shared device access control is implemented, utilizing a secure peer-to-peer communication protocol with a trusted execution environment to manage and synchronize user profiles across devices, employing biometric authentication and a group key for secure data exchange, ensuring that user profiles are consistently updated and maintained without compromising security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If biometric authentication is implemented in shared devices, then user authentication security is improved, but user profile data synchronization complexity increases
Solution Approach 1:
The system segments user profile data into multiple components stored across different devices in the shared pool. Each device maintains a portion of the user profile, and the system uses decentralized synchronization to reassemble complete profiles when needed, reducing the synchronization burden on any single device while maintaining security.
Solution Approach 2:
The system introduces an intermediary synchronization mechanism that mediates between biometric authentication requirements and profile data distribution. This intermediary layer handles the complexity of coordinating profile updates across devices without requiring centralized control, thus improving security while managing synchronization complexity.
2Ease of operation
If user profiles are synchronized across shared devices, then user experience consistency is improved, but data security risks increase
Solution Approach 1:
The system applies local quality by allowing each shared device to maintain localized user profile data with specific access permissions. Different devices can have different levels of profile visibility and access rights, enabling consistent user experience through selective data availability while minimizing security risks through localized data retention.
Solution Approach 2:
The system dynamically changes data access parameters based on device context, user role, and security requirements. Profile data is encrypted with device-specific keys, and access permissions are adjusted according to the operational context, maintaining user experience consistency while adapting security parameters to mitigate risks.
3Reliability
If decentralized synchronization is used, then system reliability is improved, but communication overhead increases
Solution Approach 1:
The system implements periodic synchronization cycles where devices exchange profile data updates at scheduled intervals rather than continuously. This periodic action maintains system reliability by ensuring data consistency across devices while reducing communication overhead by limiting unnecessary data transmissions during stable periods.
Solution Approach 2:
The decentralized synchronization system uses feedback mechanisms where devices report their current profile data state to peers. Based on this feedback, devices determine whether synchronization is necessary, allowing the system to maintain reliability through selective updates while minimizing communication overhead by avoiding redundant data exchanges.
Data Source
AI summary
A method includes receiving, at an electronic device and from a second electronic device, a second root identifier, wherein the second root identifier is associated with a second profile tree maintained at the second electronic device and determining that a first root identifier does not match the second root identifier, wherein the first root identifier is based on a first profile tree maintained at the electronic device. The method further includes sending, to the second electronic device, the first profile tree, wherein the first profile tree comprises representation of currently maintained user profiles at the electronic device, receiving, from the second electronic device, user profile update information, and updating a subset of the currently maintained user profiles based on the user profile update information.


