Method and system for securing user access, data at rest and sensitive transactions using biometrics for mobile devices with protected, local templates
First Claim
1. A stand-alone computing device, which may also be a mobile device comprising:
- at least one processor;
at least one storage area;
at least one biometric sensor and;
ASIC logic, and software contained within the said storage areas, wherein, upon enablement of the said stand-alone computing device, and prior to executing at least some of the said software and ASIC logic, the said software and ASIC logic cause the said processors, either individually or in combination to;
biometrically enroll the identity of the user by capturing a plurality of biometric samples, including multi-modal samples, from one or more of the said biometric sensors and calculating one or more biometric templates;
encrypt the said biometric templates using a first private encryption key, whose derivation must include a device ID calculated from hardware characteristics of the said stand-alone computing device;
store the encrypted biometric templates in one of the said storage areas, and;
upon subsequent device enablement, commence normal processing, responsive to a successful match of one or more subsequent biometric samples to one or more of the said biometric templates.
1 Assignment
0 Petitions
Accused Products
Abstract
Biometric data are obtained from biometric sensors on a stand-alone computing device, which may contain an ASIC, connected to or incorporated within it. The computing device and ASIC, in combination or individually, capture biometric samples, extract biometric features and match them to one or more locally stored, encrypted templates. The biometric matching may be enhanced by the use of an entered PIN. The biometric templates and other sensitive data at rest are encrypted using hardware elements of the computing device and ASIC, and/or a PIN hash. A stored obfuscated PassWord is de-obfuscated and may be released to the authentication mechanism in response to successfully decrypted templates and matching biometric samples. A different de-obfuscated password may be released to authenticate the user to a remote or local computer and to encrypt data in transit. This eliminates the need for the user to remember and enter complex passwords on the device.
34 Citations
20 Claims
-
1. A stand-alone computing device, which may also be a mobile device comprising:
-
at least one processor; at least one storage area; at least one biometric sensor and; ASIC logic, and software contained within the said storage areas, wherein, upon enablement of the said stand-alone computing device, and prior to executing at least some of the said software and ASIC logic, the said software and ASIC logic cause the said processors, either individually or in combination to; biometrically enroll the identity of the user by capturing a plurality of biometric samples, including multi-modal samples, from one or more of the said biometric sensors and calculating one or more biometric templates; encrypt the said biometric templates using a first private encryption key, whose derivation must include a device ID calculated from hardware characteristics of the said stand-alone computing device; store the encrypted biometric templates in one of the said storage areas, and; upon subsequent device enablement, commence normal processing, responsive to a successful match of one or more subsequent biometric samples to one or more of the said biometric templates. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16)
-
-
17. A stand-alone computing device, which may also be a mobile device comprising:
-
at least one processor; at least one storage area; at least one biometric sensor, and; ASIC logic, and software contained within the said storage areas, which, when executed, causes the said stand-alone computing device processors, either in combination or individually to; capture biometric samples from the device user, using one or more of the said biometric sensors, and; responsive to a good match between the said biometric samples and one or more decrypted biometric templates stored in encrypted form in the said storage areas, the said ASIC logic and the said software further cause the said stand-alone computing device to communicate with a local or remote computer, using PKI communications without said user re-entering a password. - View Dependent Claims (18)
-
-
19. A stand-alone computing device, which may also be a mobile device comprising:
-
at least one processor; at least one storage area; at least one biometric sensor, integrated into the stand-alone computing device, and; ASIC logic, and software, contained within the said storage areas, which, when executed, causes the said stand-alone computing device processors, either in combination or individually to; capture a PIN from the device user and generate a hash of said PIN; capture one or more biometric samples from a device user using one or more of said biometric sensors and; responsive to a successful PIN entry and a good match between the said biometric samples and one or more decrypted biometric templates, stored in encrypted form in the said storage areas, the said ASIC logic and the said software further cause the said stand-alone computing device to communicate with a remote computer, using PKI communications without said user re-entering a password. - View Dependent Claims (20)
-
Specification