IP Library › Granted Patent US 11,316,680
Granted Patent B2
US 11,316,680 · App. 16/282,070 · Granted Apr 26, 2022

Protected credentials for roaming biometric login profiles

Inventors: Charles D. Robison (Buford, GA); Daniel L. Hamlin (Round Rock, TX)
Assignee: Dell Products, L.P.
H04L9/0866H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,316,680
App. No.
16/282,070
Filed
Feb 21, 2019
Granted
Apr 26, 2022
Kind
B2
Art Unit
2491
USPC
713/168
Abstract

In a system of networked IHSs (Information Handling Systems) supporting the use of roaming biometric profiles, an individual may utilize biometric authentication for gaining access to various IHSs within the system. An IHS configured to support roaming biometric authentication includes biometric sensors that support secure transmission and management of biometric prints collected by such sensors. Such biometric sensors may interoperate with a secure processing component of the IHS in order to prevent transmission and storage of unprotected biometric prints, while still supporting roaming biometric authentication. The biometric sensor utilizes an encryption key for encoding biometric prints where the key is selected based on a group affiliation of the individual, thus protecting biometric prints from other groups that use roaming biometric authentication while sharing the same network of IHSs.

Claims (39)

1. A method for roaming biometric authentication of users requesting access to an Information Handling System (IHS) or a resource available via the IHS, the method comprising:

receiving a request to collect a biometric print for authentication of a user of the IHS;

retrieving, by a logic unit of a biometric sensor of the IHS, a biometric key associated with a group affiliation of the user, wherein the biometric key associated with the group affiliation of the user is retrieved from a secure storage of a secure processor of the IHS;

upon retrieving the biometric key, collecting, by the biometric sensor of the IHS, the biometric print from the user;

encrypting, by instructions executed by the logic unit of the biometric sensor, the collected biometric print using the biometric key associated with the group affiliation of the user, wherein the collected biometric print is encrypted by the biometric sensor without transmitting the collected biometric print to any other component of the IHS; and

transmitting the biometric print encrypted by the logic unit of the biometric sensor to an authentication system for matching the biometric print against a library of stored biometric templates, wherein the authentication system operates within a secure execution environment of the secure processor, and wherein the authentication system attempts to match the biometric print against a library of locally stored biometric templates and wherein the authentication system transmits the encrypted biometric print to a remote authentication service when the biometric print cannot be matched locally.

2. The method of claim 1 , further comprising signaling, based on the instructions executed by the logic unit of the biometric sensor, an indication that the biometric sensor is ready to collect the biometric print of the user.

3. The method of claim 2 , wherein the indication signaled by the biometric sensor comprises illumination of an indicator light.

4. The method of claim 1 , wherein the biometric sensor is coupled to the secure processor via an out-of-band signal pathway that is not accessible via the operating system of the IHS, and wherein the logic unit of the biometric sensor transmits the encrypted biometric print to the secure processor via the out-of-band signal pathway.

5. The method of claim 1 , wherein instructions utilized by the logic unit of the biometric sensor comprise firmware instructions that are authenticated upon initialization of the biometric sensor.

6. The method of claim 5 , wherein the firmware instructions of the biometric sensor are authenticated based on a reference signature for the firmware instructions generated during assembly of the IHS.

7. An Information Handling System (IHS) supporting roaming biometric authentication of users of the IHS resource available via the IHS, the IHS comprising:

a biometric sensor comprising a logic unit and a secured memory, wherein the biometric sensor is operable for collecting biometric prints, and wherein the logic unit of the biometric sensor is configured to:

receive a request for the biometric sensor to collect a biometric print for authentication of a user of the IHS;

retrieve a biometric key associated with a group affiliation of the user, wherein the biometric key associated with the group affiliation of the user is retrieved from a secure storage of a secure processor of the IHS;

upon the biometric sensor retrieving the biometric key, collect the biometric print from the user;

encrypt the collected biometric print using the biometric key associated with the group affiliation of the user, wherein the collected biometric print is encrypted by the biometric sensor without transmitting the collected biometric print to any other component of the IHS; and

transmit the encrypted biometric print to an authentication system; and

the authentication system configured to:

decrypt the biometric print received from the biometric sensor; and

match the biometric print against a library of stored biometric templates, wherein the authentication system operates within a secure execution environment of the secure processor, and wherein the authentication system attempts to match the biometric print against a library of locally stored biometric templates and wherein the authentication system transmits the encrypted biometric print to a remote authentication service when the biometric print cannot be matched locally.

8. The IHS of claim 7 , wherein the logic unit of the biometric sensor is further configured to signal an indication that the biometric sensor is ready to collect the biometric print of the user.

9. The IHS of claim 8 , wherein the indication signaled by the biometric sensor comprises illumination of an indicator light.

10. The IHS of claim 8 , wherein the biometric sensor is coupled to the secure processor via an out-of-band signal pathway that is not accessible via the operating system of the IHS, and wherein the logic unit of the biometric sensor transmits the encrypted biometric print to the secure processor via the out-of-band signal pathway.

11. The IHS of claim 7 , wherein instructions utilized by the logic unit of biometric sensor comprise firmware instructions that are authenticated upon initialization of the biometric sensor based on a reference signature for the firmware instructions generated during assembly of IHS.

12. A system for roaming biometric authentication, the system comprising:

a plurality of Information Handling Systems (IHSs) operable for providing biometric authentication of a plurality of users of the system, wherein each IHS comprises:

a biometric sensor comprising a logic unit and a secured memory, wherein the biometric sensor is operable for collecting biometric prints, and wherein the logic unit of the biometric sensor is configured to:

receive a request for the biometric sensor to collect a biometric print for authentication of a user;

retrieve a biometric key associated with a group affiliation of the user, wherein the biometric key associated with the group affiliation of the user is retrieved from a secure storage of a secure processor of a respective IHS;

upon the biometric sensor retrieving the biometric key, collect the biometric print from the user;

encrypt the collected biometric print using the biometric key associated with the group affiliation of the user, wherein the collected biometric print is encrypted by the biometric sensor without transmitting the collected biometric print to any other component of the IHS; and

transmit the encrypted biometric print to an authentication system; and

a secure processor, wherein the authentication system operates within a secure execution environment of the secure processor and wherein the authentication system is configured to:

decrypt the biometric print received from the biometric sensor; and

match the biometric print against a library of stored biometric templates, wherein the authentication system attempts to match the biometric print against a library of locally stored biometric templates and wherein the authentication system transmits the encrypted biometric print to a remote authentication service when the biometric print cannot be matched locally.

13. The system of claim 12 , wherein the logic unit of the biometric sensor is further configured to signal an indication that the biometric sensor is ready to collect the biometric print of the user.

14. The system of claim 13 , wherein the indication signaled by the biometric sensor comprises illumination of an indicator light.

15. The system of claim 12 , wherein the biometric key associated with the group affiliation of the user is retrieved from a secure storage of a secure processor of the IHS, and wherein the biometric sensor is coupled to the secure processor via an out-of-band signal pathway that is not accessible via the operating system of an IHS.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (050724/0466) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO WYSE TECHNOLOGY L.L.C.)
Reel/Frame 060753/0486 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST AT REEL 050405 FRAME 0534 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058001/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 15, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 050724/0466 →
SECURITY AGREEMENT Recorded Sep 17, 2019
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 050405/0534 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 21, 2019
From: ROBISON, CHARLES D.; HAMLIN, DANIEL L.
To: DELL PRODUCTS, L.P.
Reel/Frame 048410/0216 →
Continuity (1)
Related Publication 20200274705A1 · Aug 27, 2020