Speaker Recognition Processor Security Module for Biometric Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Biometric authentication systems, such as voice recognition, are vulnerable to malware attacks that can hijack audio data and spoof authentication processes, compromising security, especially when the processor is in a low-power state and takes time to boot up, and malware can inject false audio signals to bypass security.
Innovation Solution
A biometric authentication system with a Speaker Recognition Processor (SRP) that integrates a security module to monitor signal routing configurations, ensuring only secure inputs are used for authentication, and keeps the biometric data processing entirely within the SRP to prevent unauthorized access and data copying, thereby enhancing security and reducing power consumption during authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Use of energy by moving object
If the processor is put in a low-power state to reduce energy consumption, then energy efficiency is improved, but the processor takes time to boot up and can be vulnerable to malware attacks during this period
Solution Approach 1:
The system is divided into two distinct processing units: a low-power speaker recognition processor (SRP) dedicated to biometric authentication and a main application processor (AP) for general operations. The SRP operates independently in low-power mode, handling voice authentication without requiring the main AP to be active, thus maintaining security while conserving energy.
Solution Approach 2:
The SRP acts as an intermediary security layer between the microphone input and the main system. It processes and validates voice biometrics before allowing access to the main processor, serving as a secure gateway that operates independently and prevents malware from compromising the entire system during low-power states.
2Productivity
If biometric data is processed externally or through shared processors, then processing capability is improved, but the risk of data theft and spoofing attacks increases
Solution Approach 1:
The voice biometric processing functionality is extracted from the main application processor and implemented as a separate, dedicated SRP. This extraction isolates the sensitive biometric data processing from potential malware on the main system, ensuring that even if the AP is compromised, the biometric authentication remains secure and isolated.
Solution Approach 2:
The SRP implements specialized, localized processing optimized specifically for voice biometrics rather than general-purpose computing. This dedicated local processing unit provides enhanced security through hardware-level isolation while maintaining efficient biometric authentication performance independent of the main processor's capabilities.
3Adaptability or versatility
If malware is allowed to run on the device, then device functionality is improved, but malware can hijack audio data and bypass security authentication
Solution Approach 1:
The system architecture segments critical security functions from general-purpose applications. The SRP handles only voice biometric authentication in an isolated environment, while the AP runs the operating system and applications including potentially malicious software. This segmentation ensures that malware on the AP cannot compromise the authentication process.
Solution Approach 2:
The SRP serves as an intermediary security layer that sits between the physical microphone input and the main system. It validates voice biometrics before granting access to the main processor, acting as a trusted mediator that prevents malware on the AP from intercepting or spoofing authentication data.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Embodiments of the invention provide methods and apparatus for monitoring the routing configuration within an electronic device such that a biometric authentication process can be carried out without interference from other components of the device, such as may occur when the device has become infected with malware for example. The invention may provide a codec or speaker recognition processor, coupled to receive biometric input data, comprising a security module that determines whether a routing configuration complies with one or more rules. The security module may be implemented to prevent genuine biometric data from being output from the speaker recognition processor, and/or to prevent spoof biometric data from being inserted into the authentication module.