IP Library Granted Patent US 9,984,221
Granted Patent B2
US 9,984,221 · App. 15/415,117 · Granted May 29, 2018

Apparatus and method for enabling fingerprint-based secure access to a user-authenticated operational state of an information handling system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,984,221
App. No.
15/415,117
Granted
May 29, 2018
Kind
B2
Abstract

A computer-implemented method provides power to a fingerprint reader while the remaining components of the information handling system are held in a low power, non-operating state. Placement of a finger across the fingerprint reader is detected with the information handling system in the non-operating state. A fingerprint is read and a corresponding fingerprint image is generated. The fingerprint image is buffered and an embedded controller is triggered to start an authentication device having a secure storage. The fingerprint image is compared to a fingerprint template contained in the secure storage. In response to the fingerprint image matching the fingerprint template, the authentication device signals the embedded controller to activate a user authenticated wake-up cycle to provide power to the other components of the information handling system such that the information handling system activates an operating system and enters a fully powered and user authenticated, operational state.

Claims (71)

1. A computer implemented method to activate an information handling system having a fingerprint reader, an embedded controller, and a secure storage for enabling fingerprint-based secure access to a user-authenticated operational state of the information handling system, the method comprising:

providing power to the fingerprint reader while remaining components of the information handling system are held in a low power, non-operating state in which the information handling system is not functional;

in response to detecting placement of a finger across a surface of the fingerprint reader while the information handling system is in the low power, non-operating state:

reading a fingerprint from the finger and generating a corresponding fingerprint image;

triggering an embedded controller to start operation of an authentication device having secure storage;

comparing the fingerprint image to a previously-established fingerprint template contained in the secure storage; and

in response to the fingerprint image matching the fingerprint template, the authentication device signaling the embedded controller to activate a user authenticated wake-up cycle to provide power to processing and other components of the information handling system such that the information handling system activates an operating system and enters a fully powered-on and user authenticated, operational state rather than a regular wake-up cycle that requires user authentication;

wherein triggering the embedded controller to activate the user authenticated wake-up cycle further comprises transmitting a payload stored in the secure storage from the authentication device to the operating system, wherein the payload is required for full operation of and accessibility to the operating system.

2. The method of claim 1 , wherein triggering the embedded controller to activate the user authenticated wake-up cycle further comprises:

triggering an operating system environment to be fully accessible on the information handling system in response to receipt of the payload.

3. The method of claim 1 , further comprising:

in response to the fingerprint image matching the fingerprint template, the authentication device establishing a universal serial bus communication channel to the fingerprint reader.

4. The method of claim 1 , further comprising:

in response to a successful match of the fingerprint image to the fingerprint template, illuminating a light emitting diode to indicate the successful match; and

in response to an unsuccessful match of the fingerprint image to the fingerprint template, illuminating the light emitting diode to indicate the unsuccessful match.

5. The method of claim 1 , further comprising:

in response to the fingerprint image not matching the fingerprint template, triggering the embedded controller to return the computer system to the low power, non-operating state that provides power only to the fingerprint reader; and

discontinuing communication between the fingerprint reader and the authentication device.

6. The method of claim 1 , further comprising:

while the system is in the operational state, enabling creation of a fingerprint template for use as an authentication mechanism by:

prompting for placement of a finger scan across the fingerprint reader;

scanning a fingerprint from the finger placed across the fingerprint reader;

generating a fingerprint image from the fingerprint;

generating a fingerprint template corresponding to the fingerprint image using the authentication device; and

storing the fingerprint template to the secure storage.

7. The method of claim 1 , wherein activating the user authenticated wake-up cycle further comprises:

in response to the fingerprint image matching the fingerprint template, the secure storage signaling the embedded controller to activate and to by-pass a power on authentication application.

8. The method of claim 1 , wherein activating the user authenticated wake-up cycle further comprises:

triggering a basic input output system to load;

detecting bypassing of a power on authentication application; and

transmitting a key stored in the secure storage from the authentication device to the basic input output system, wherein the key is required for continued booting of the information handling system without requiring further user authentication.

9. The method of claim 1 , wherein detecting placement of the finger across the surface of the fingerprint reader further comprises sensing a swipe of the finger across the fingerprint reader.

10. The method of claim 1 , wherein the low power, non-operating state is a hibernation state in which the embedded controller, the authentication device, the processors and the remaining components, other than the fingerprint reader, of the information handling system are not functional.

11. An information handling system (IHS) comprising:

a processor;

a memory coupled to the processor via a system interconnect;

an authentication sub-system communicatively coupled to the system interconnect, the authentication sub-system including a fingerprint reader, an embedded controller, and a secure storage, the authentication sub-system having firmware executing thereon to enable fingerprint-based secure access to a user-authenticated operational state of the information handling system, wherein the firmware configures the authentication sub-system to:

provide power to the fingerprint reader while remaining components of the information handling system are held in a low power, non-operating state in which the information handling system is not functional;

in response to detecting placement of a finger across a surface of the fingerprint reader while the information handling system is in the low power, non-operating state:

read a fingerprint from the finger and generating a corresponding fingerprint image;

buffer the fingerprint image;

trigger an embedded controller to start operation of an authentication device having a secure storage;

compare the fingerprint image to a previously-established fingerprint template contained in the secure storage; and

in response to the fingerprint image matching the fingerprint template, illuminate a light emitting diode to indicate the successful match, and trigger the authentication device to signal the embedded controller to activate a user authenticated wake-up cycle to provide power to processing and other components of the information handling system such that the information handling system activates an operating system and enters a fully powered-on and user authenticated, operational state rather than a regular wake-up cycle that requires user authentication;

wherein to trigger the embedded controller to activate the user authenticated wake-up cycle, the firmware further configures the authentication sub-system to transmit a payload stored in the secure storage from the authentication device to the operating system, wherein the payload is required for full operation of and accessibility to the operating system.

12. The information handling system of claim 11 , wherein triggering the embedded controller to activate the user authenticated wake-up cycle comprises the firmware further configuring the authentication sub-system to:

trigger an operating system environment to be fully accessible on the information handling system in response to receipt of the payload.

13. The information handling system of claim 11 , wherein the firmware further configures the authentication sub-system to:

in response to the fingerprint image matching the fingerprint template, the authentication device establishing a universal serial bus communication channel to the fingerprint reader.

14. The information handling system of claim 11 , wherein the firmware further configures the authentication sub-system to:

in response to an unsuccessful match of the fingerprint image to the fingerprint template, illuminate a light emitting diode to indicate the unsuccessful match.

15. The information handling system of claim 11 , wherein the firmware further configures the authentication sub-system to:

in response to the fingerprint image not matching the fingerprint template, trigger the embedded controller to return the computer system to the low power, non-operating state that provides power to only the fingerprint reader; and

discontinue communication between the fingerprint reader and the authentication device.

16. The information handling system of claim 11 , wherein the firmware further configures the authentication sub-system to:

while the system is in the operational state, enable creation of a fingerprint template for use as an authentication mechanism by:

prompting for placement of a finger scan across the fingerprint reader;

scanning a fingerprint from the finger placed across the fingerprint reader;

generating a fingerprint image from the fingerprint;

generating a fingerprint template corresponding to the fingerprint image using the authentication device; and

storing the fingerprint template to the secure storage.

17. The information handling system of claim 11 , wherein activating the user authenticated wake-up cycle comprises the firmware further configuring the authentication sub-system to:

in response to the fingerprint image matching the fingerprint template, the secure storage signals the embedded controller to activate and to by-pass a power on authentication application.

18. The information handling system of claim 11 , wherein activating the user authenticated wake-up cycle comprises the firmware further configuring the authentication sub-system to:

trigger a basic input output system to load;

detect bypassing of the power on authentication application; and

transmit a key stored in the secure storage from the authentication device to the basic input output system, wherein the key is required for continued booting of the information handling system without requiring further user authentication.

19. The information handling system of claim 11 , wherein:

the fingerprint reader is positioned on an external surface of the information handling system; and

detecting placement of the finger across the surface of the fingerprint reader further comprises sensing a swipe of the finger across the fingerprint reader.

20. The information handling system of claim 11 , wherein the low power, non-operating state is a hibernation state in which the embedded controller, the authentication device, the processors and the remaining components, other than the fingerprint reader, of the information handling system are not functional.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (041829/0873) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 059803/0724 →
RELEASE OF SECURITY INTEREST AT REEL 041808 FRAME 0516 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL INTERNATIONAL, L.L.C.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; MOZY, INC.; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058297/0573 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY INTEREST (NOTES) Recorded Feb 28, 2017
From: DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; MOZY, INC.; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 041829/0873 →
PATENT SECURITY INTEREST (CREDIT) Recorded Feb 24, 2017
From: DELL INTERNATIONAL, L.L.C.; DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; MOZY, INC.; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 041808/0516 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2017
From: HAMLIN, DANIEL L.; GILLON, JAMES T.; CRITZ, CHRISTIAN L.
To: DELL PRODUCTS, L.P.
Reel/Frame 041080/0367 →