Trusted User Enrollment Timing for Secure System Wake Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional UPD-capable information handling systems face issues in multi-user environments, including spurious system wake events and unauthorized access due to lack of customization in wake and lock methods, leading to power loss and security vulnerabilities.
Innovation Solution
Implement a database of trusted users (TMU database) that stores biometric data and policies, enabling personalized wake and lock actions based on user identity and presence, reducing spurious events and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional User Presence Detection systems are used to detect any user presence, then the system can wake and provide access to users, but spurious wake events occur and unauthorized access is enabled due to inability to differentiate between trusted and untrusted users
Solution Approach 1:
The patent segments users into distinct categories (trusted users versus untrusted users) and applies different access rules to each segment. The system maintains separate enrollment processes and access control policies for trusted users, allowing them to wake the system and access content without restrictions, while untrusted users trigger secure wake events requiring authentication. This segmentation resolves the contradiction by enabling reliable security differentiation without requiring complex overall system restructuring.
Solution Approach 2:
The system performs preliminary enrollment actions during initial system use, where the authenticated user can pre-enroll trusted users in the trusted user database before leaving the system. This preliminary enrollment creates a foundation of trusted identities that enables automatic trusted wake events later, eliminating the need for complex real-time verification and reducing spurious wake events while maintaining simple operational procedures.
2Ease of operation
If the system wakes for any detected user presence, then user access is enabled, but power consumption increases due to spurious wake events from untrusted users
Solution Approach 1:
The patent segments wake events into two distinct types: trusted wake events for enrolled trusted users that enable direct access without authentication, and secure wake events for untrusted users that require authentication. This segmentation allows the system to consume minimal power for trusted user access while maintaining security for untrusted users, resolving the contradiction between operational convenience and power consumption.
Solution Approach 2:
Trusted users enroll themselves and other trusted users in the system during authenticated sessions, creating a self-maintaining database of trusted identities. This self-service enrollment process eliminates the need for continuous administrative intervention or complex verification procedures, enabling convenient automatic wake events for trusted users while minimizing power consumption by avoiding spurious wake events from untrusted users.
3Productivity
If trusted user enrollment is permanent, then trusted users can consistently access the system, but security risks increase if untrusted users are incorrectly enrolled
Solution Approach 1:
The patent implements dynamic enrollment status that automatically expires after a predetermined period of inactivity. Trusted user enrollment is not permanent but temporarily valid, requiring re-enrollment after the time threshold is exceeded. This dynamic approach maintains high productivity for actively used systems while improving security by automatically removing potentially incorrect enrollments, resolving the contradiction between access efficiency and enrollment accuracy.
Solution Approach 2:
The system performs periodic verification of trusted user enrollment status by monitoring usage patterns and automatically expiring enrollments after predetermined time intervals. This periodic action ensures that the trusted user database remains accurate and current, maintaining efficient access for legitimate users while preventing security risks from stale or incorrect enrollments, thus resolving the contradiction between productivity and reliability.
Data Source
AI summary
Embodiments of systems and methods are provided for controlling the enrollment status of trusted users included within a TMU database. More specifically, embodiments of systems and methods are disclosed to control the enrollment status of a trusted user enrolled within a TMU database based on time. In doing so, the disclosed systems and methods improve system security in an information handling system operated within a multi-user environment by: controlling how long a trusted user is given access to an active system session when the authenticated user walks away, and providing a way to continue or revoke the enrollment status of a trusted user for a subsequent system session based on time.


