Trusted User Database Provisioning for Secure Multi-User Wake Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional UPD-capable information handling systems face issues in multi-user environments, including spurious system wake events and unauthorized access due to lack of customization in wake and lock methods, leading to power loss and security vulnerabilities.
Innovation Solution
Implement a database of trusted users (TMU database) that stores biometric data and policy settings, enabling customized wake and lock actions based on user identity and presence, preventing unauthorized access and reducing power consumption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional UPD-capable information handling systems use generic wake and lock methods, then system operation is simple, but security vulnerabilities and unauthorized access occur in multi-user environments
Solution Approach 1:
The patent segments the user database into trusted users and untrusted users, creating distinct groups with different access permissions. This segmentation allows the system to apply different wake and lock policies based on user identity, thereby improving security without requiring complete system redesign.
Solution Approach 2:
The system performs preliminary actions by pre-configuring wake and lock policies for different user groups before authentication occurs. When a user is identified, the corresponding pre-established policy is automatically applied, enabling secure multi-user operation without real-time policy creation complexity.
2Loss of energy
If the system implements customized wake and lock policies for different users, then security and power management improve, but device complexity increases
Solution Approach 1:
Wake and lock policies are pre-configured for different user groups during system setup or administration phases. This preliminary action eliminates the need for complex real-time policy creation and management, reducing operational complexity while enabling fine-grained power control based on user identity.
Solution Approach 2:
The system changes operational parameters (wake sensitivity, lock timing) based on user identity parameters. By linking power management parameters to user authentication results, the system achieves dynamic power optimization without requiring separate control mechanisms for each user scenario.
3Ease of operation
If the system wakes upon detecting any user presence, then system accessibility is improved, but spurious wake events and power loss occur
Solution Approach 1:
The patent applies different wake detection qualities to different user scenarios. Trusted users trigger immediate system wake with full accessibility, while untrusted users result in restricted wake behavior or no wake at all. This local differentiation maintains ease of operation for authorized users while preventing spurious wakes from unauthorized presence.
Solution Approach 2:
The system dynamically adjusts wake behavior based on real-time user authentication results. Rather than a static wake-on-detection policy, the system modifies its wake response characteristics according to the authenticated user's trust level, optimizing both accessibility and power consumption adaptively.
Data Source
AI summary
Embodiments of systems and methods are provided for provisioning a database of trusted users stored locally on one or more information handling systems. The systems and methods disclosed herein may utilize a database of trusted users (otherwise referred to as a trusted multi-user database, or TMU database), a database template and/or policy stored within a remote system (e.g., a cloud or backend server) to remotely manage and provision a TMU database stored locally within one or more information handling systems. In doing so, the systems and methods disclosed herein may be used to securely back-up and restore a TMU database stored locally with an IHS, remotely manage enrollment and provisioning of a TMU database stored locally within one or more information handling systems based on policy, and apply TMU configuration settings globally to the TMU databases stored locally within a plurality of information handling systems.


