xR Headset Multi-Factor Authentication via Biometric OTPs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtual, augmented, and mixed reality (xR) applications lack secure multi-factor authentication methods for user authorization and key management, especially when xR headsets are used to access external computing devices, leading to potential unauthorized access.
Innovation Solution
Implementing multi-factor authentication systems in xR headsets that utilize biometric samples, such as iris or retina scans, to authenticate users and generate One-Time Passwords (OTPs) encrypted with private keys, allowing secure logging into Information Handling Systems (IHS) and enabling secure key generation and transfer between devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If xR headset uses biometric authentication to log into external computing devices, then security is improved, but device complexity increases
Solution Approach 1:
The authentication system is segmented into multiple independent factors: biometric authentication (iris/retina/fingerprint), device ownership verification, and One-Time Password (OTP) generation. Each factor operates independently but contributes to the overall authentication process, allowing the system to maintain high security while managing complexity through modular design
Solution Approach 2:
The xR headset acts as an intermediary device between the user and external computing devices. It hosts a secure enclave that manages cryptographic keys and biometric data, mediating the authentication process between the user's biometric traits and the external device's security requirements, thereby simplifying the overall system architecture
2Reliability
If xR headset implements multi-factor authentication with encrypted OTPs, then unauthorized access is prevented, but authentication process time increases
Solution Approach 1:
Biometric traits are captured and stored in the secure enclave during an initial enrollment phase, before actual authentication is needed. During login, the system only needs to verify the biometric match and generate an OTP, significantly reducing authentication time while maintaining multi-factor security
Solution Approach 2:
The system changes the complexity parameter from real-time multi-factor verification to a two-stage process: rapid biometric matching followed by quick OTP generation. This parameter change optimizes the balance between security and speed by avoiding computationally intensive operations during the actual authentication moment
3Reliability
If xR headset stores biometric information and cryptographic keys locally, then authentication reliability is improved, but security risk from local storage increases
Solution Approach 1:
A secure enclave is established beforehand to protect biometric and cryptographic data. This enclave implements cryptographic safeguards and access controls that cushion against potential security threats, allowing local storage of sensitive information while mitigating the associated risks through pre-configured security measures
Solution Approach 2:
One-Time Passwords (OTPs) are generated as temporary, single-use authentication credentials that expire immediately after use. This approach replaces the need for long-term storage of highly sensitive authentication data with transient credentials, reducing the security risk associated with local storage while maintaining authentication reliability
Data Source
AI summary
Systems and methods for multi-factor authentication in virtual, augmented, and mixed reality (xR) applications are described. In some embodiments, an xR headset may include a processor and a memory coupled to the processor, the memory comprising program instructions stored thereon that, upon execution, cause the xR headset to: authenticate a user wearing the xR headset, and, in response to the authentication, log the user into an Information Handling System (IHS) distinct from the xR headset.


