Voiceprint Authentication for Hardware Encryption Key Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for managing and protecting encryption keys in computing environments often rely on passwords and digital certificates, which can be cumbersome and insecure, particularly in scenarios where users may forget passwords or require additional equipment for management.

Innovation Solution

A system and method that utilizes a user's voiceprint to authenticate and retrieve encryption keys stored within a hardware module, such as a Trusted Platform Module (TPM), eliminating the need for passwords and additional management equipment by comparing extracted voice features with stored voice features to grant access to encryption keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If passwords and digital certificates are used for key management, then security protection is provided, but user convenience deteriorates and system complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical system of password entry and digital certificate management with a voiceprint recognition system. The voice-based authentication mechanism eliminates the need for users to remember complex passwords or manage digital certificates, while the voiceprint template stored in secure element provides cryptographic security equivalent to traditional methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a voiceprint template as an intermediary between the user and the encryption key. Instead of directly using passwords or certificates to access keys, the system uses the voiceprint template stored in the secure element as a mediator that authenticates the user and triggers key release, simplifying the authentication flow while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If passwords are used for key access, then security is maintained, but user accessibility deteriorates when users forget passwords

Engineering Contradiction:
ImprovesecurityVSAvoiduser accessibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent substitutes the password-based access mechanism with voiceprint recognition. Since voiceprints are biometric characteristics that users naturally possess and cannot forget, this eliminates the accessibility problem associated with forgotten passwords while maintaining security through cryptographic protection of the voiceprint template and encryption key.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If additional equipment is used for key management, then security protection is enhanced, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidmanagement equipment
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the key management functionality directly into the mobile device by utilizing the device's existing secure element and microphone. Instead of requiring external key management equipment, the system combines voice capture, voiceprint template storage, and encryption key protection within the device's native hardware components, eliminating the need for additional management equipment.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent enables the mobile device to perform self-service key management by using its own secure element to store and protect both the voiceprint template and encryption key. The device autonomously handles voice authentication and key release without requiring external key management infrastructure, reducing system complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10985913B2Method and system for protecting data keys in trusted computing
Publication Date: 2021.04.20 CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
  • US10985913B2 patent drawing
  • US10985913B2 patent drawing
  • US10985913B2 patent drawing

AI summary

One embodiment described herein provides a system and method for facilitating user access to encryption keys stored within a hardware module. During operation, a server coupled to the hardware module receives a key request from the user, the key request comprising a user identifier and a key identifier. The server receives a voice message from the user, extracts voice features from a voiceprint associated with the received voice message, looks up voice features stored within the hardware module based on the user identifier, and compares the extracted voice features with the voice features stored within the hardware module. In response to the extracted voice features matching the stored voice features, the server retrieves from the hardware module an encryption key based on the user identifier and the key identifier.