US2004123113A1PendingUtilityA1

Portable or embedded access and input devices and methods for giving access to access limited devices, apparatuses, appliances, systems or networks

Priority: Dec 18, 2002Filed: Dec 18, 2002Published: Jun 24, 2004
Est. expiryDec 18, 2022(expired)· nominal 20-yr term from priority
G07C 9/26G07C 9/257G07F 7/1008G06F 21/32G06F 21/34G06Q 20/40145H04L 63/0428G07C 9/00563G06Q 20/4014H04L 63/0861H04L 63/10G06F 21/35G06Q 20/341B60R 25/252G06Q 20/346
45
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A portable or embedded access device is provided for being coupled to, and for allowing only authorized users access to, an access-limited apparatus, device, network or system, e.g. a computer terminal, an internet bank or a corporate or government intranet. The access device comprises an integrated circuit (IC) ( 1 ) providing increased security by bridging the functionality of biometrics input from a user and, upon positive authentication of the user's fingerprint locally to provide secure communication with the said access-limited apparatus, device, network or system, whether local or remote. A corresponding method of using the portable device or the embedded device is disclosed for providing a bridge from biometrics input to a computer locally, into secure communication protocol responses to a non-biometrics network. An embedded access control and user input device or apparatus for being a built-in part of stand alone appliances with some form of access control, e.g. hotel safes, medicine cabinet or the like, and for providing increased security, is also provided. Further, a method of providing secured access control and user input in stand-alone appliances having an embedded access control or user input device according to the invention is also explained.

Claims

exact text as granted — not AI-modified
1 . Portable access device for being coupled to, and for allowing only authorized users access to, an access-limited apparatus, device, network or system, e.g. a computer terminal, an internet bank or a corporate or government intranet comprising 
 a device interface, being electronic or mechanical or both, for coupling the device to the access-limited unit, e.g. a computer terminal port,    characterized by    an integrated circuit (IC) ( 1 ) providing increased security by bridging the functionality of fingerprint input from a user and, upon positive authentication of the user's fingerprint to provide secure communication with the said access-limited apparatus, device, network or system, said IC comprising:    a processor unit ( 2 ) communicating with the other on-chip components via a high speed bus ( 3 ),    a first memory interface block ( 6 B or  6 D) being connected to the high speed bus ( 3 ) for interfacing with volatile memory ( 6 A or  6 C) as thus providing working memory available to other modules on the IC ( 1 ),    a second memory interface block ( 7 B or  7 D) being connected to the high speed bus ( 3 ) for interfacing with non-volatile memory ( 7 A or  7  or  7 E), for storing of program code, e.g. administrative software, tailored security output responses and fingerprint representations in the form of so-called fingerprint minutiae,    a first interface block ( 5 A) for being coupled to a fingerprint sensor ( 5 )    said first interface block ( 5 A) is connected to an image capture and pre-processing block ( 5 C),    said image capture and pre-processing block ( 5 C) is adapted to perform the initial heavy-duty processing of the raw fingerprint images captured from the sensor ( 5 ) into a dataset of reduced size, denoted intermediate fingerprint data, the intermediate fingerprint data being submitted as output to the central processor block ( 2 ) via the high speed bus ( 3 ) for final processing to compact fingerprint representations by so-called minutiae, on the central processor ( 2 ),    encryption modules ( 8  or  8 A,  8 B and  8 C) connected to the high-speed bus ( 3 ) for providing encryption information, or alternatively scrambling information,    the processor unit ( 2 ) is adapted to apply the encryption information to the fingerprint data for producing secured data as an output to the high speed bus ( 3 ) and    one or more second interface blocks ( 9 A,  9 B,  9 C or  9 D) for supplying the secured data to the external access-limited apparatus, device or system via the device interface.    
     
     
         2 . Portable device according to  claim 1 , wherein the integrated circuit ( 1 ) comprises hardware and software required to supply output signals to one or more of the second interface blocks ( 9 A,  9 B,  9 C or  9 D), implemented in the form of a USB-port, a PCMCIA-port or a UART-port.  
     
     
         3 . Portable device according to  claim 1 , wherein 
 the said IC ( 1 ) being mounted on a small printed circuit board PCB ( 12 B)    the said PCB ( 12 B) is connected to at least one of a USB interface ( 12 C) or a PCMCIA mechanical interface ( 13 B)    electronic surface components to support at least one of the USB mechanical interface ( 12 C) and the PCMCIA mechanical interface ( 13 B) being mounted on the same PCB ( 12 B)    an SDRAM chip ( 6 ), typically at least with 4 MB capacity, being mounted on the same PCB ( 12 B)    a non-volatile serial Flash chip ( 7 ), typically with at least 256 Kbytes capacity, being mounted on the same PCB ( 12 B)    a fingerprint sensor ( 5 ) being mounted on the same PCB ( 12 B)    all preceding components and chips being protected inside a housing ( 12 A or  13 C).    
     
     
         4 . Portable device according to  claim 3 , wherein said housing is designed with a recess enabling a finger (A) to be placed on, or swiped over the sensor ( 5 ) being protected down in said recess, but still conveniently accessible by the finger (A)  
     
     
         5 . Portable device according to  claim 3 , wherein 
 said housing is equipped with a sliding lid ( 13 D) enabling a finger (A) to be placed on, or swiped over the sensor ( 5 ) being protected under said sliding lid, but still conveniently accessible by the finger (A)    said sliding lid ( 13 D) being forced into closed position fully covering the sensor ( 5 ) when the sliding lid is not pushed aside by a finger (A) when a fingerprint image is to be captured    a finger guide structure ( 13 E) is placed adjacent to the sliding lid ( 13 D) when the sliding lid ( 13 E) is in closed position, fully covering the sensor ( 5 ). The purpose of the finger guide ( 13 E) is to intuitively guide the finger (A) in correct position to open the sliding lid ( 13 D) and thereby swipe the finger (A) correctly over the sensor ( 5 ) if the sensor ( 5 ) is of the swipe type    for this application the UART interface ( 9 D) on the IC ( 1 ) will support the PCMCIA port ( 13 B).    
     
     
         6 . Portable device according to  claim 3 , wherein 
 the said non-volatile memory ( 7 ) is expanded with extra capacity beyond the 256 Kbytes minimum capacity, to provide extra storage capacity for data to enable the device to operate as a general portable data storage, and    the said IC chip ( 1 ) is equipped with a USB mass storage class controller with at least one control endpoint and  2  bulk endpoints (in/out), to provide access to data onboard the portable device upon positive match of the captured fingerprint image with one of the fingerprint representations of authorized users stored onboard the portable device.    
     
     
         7 . Embedded access device for integration into peripherals of networked computers or communication terminals, to allow only authorized users access to all types of proprietary networks (LAN, WAN, etc.) typically represented by internet banking applications, corporate and government intranets, and similar, including 
 a device interface, being electronic or mechanical or both, for integration by embedment in peripherals of a computer terminal like in a PC mouse, keyboard or on the computer itself whether it is a laptop PC, a PDA or in cell phone with wired or wireless access to a network, or networked devices containing a computer permanently or occasionally serving as a terminal in a network,    characterized by    an integrated circuit (IC) ( 1 ) providing increased security by bridging the functionality of fingerprint input from a user and fingerprint authentication to provide secure communication with the said terminal and the network it is permanently or occasionally networked to, by wire or wireless connection, said IC comprising:    a processor unit ( 2 ) communicating with the other on-chip components via a high speed bus ( 3 ),    a first memory interface block ( 6 B or  6 D) being connected to the high speed bus ( 3 ) for interfacing with volatile memory ( 6 A or  6 C) thus providing working memory available to other modules on the integrated circuit,    a second memory interface block ( 7 B or  7 D) being connected to the high speed bus ( 3 ) for interfacing with non-volatile memory ( 7 A or  7  or  7 E), for storing of program code, e.g. administrative software, tailored security output responses, and fingerprint representations in the form of so-called fingerprint minutiae,    a first interface block ( 5 A) for being coupled to a fingerprint sensor ( 5 )    said first interface block ( 5 A) is connected to an image capture and pre-processing block ( 5 C),    said sensor signal capturing and pre-processing block ( 5 C) is adapted to perform the initial heavy-duty processing of the raw fingerprint images captured from the sensor ( 5 ) into a dataset of reduced size, denoted intermediate fingerprint data, the intermediate fingerprint data being submitted as output to the central processor block ( 2 ) via the high speed bus ( 3 ) for final processing to compact fingerprint representations by so-called minutiae, on the central processor ( 2 ),    encryption modules ( 8  or  8 A,  8 B and  8 C) connected to the high-speed bus ( 3 ) for providing encryption information, or alternatively scrambling information,    the processor unit ( 2 ) is adapted to apply the encryption information to the fingerprint data for producing secured data as an output to the high speed bus ( 3 )    one or more second interface blocks ( 9 A,  9 B,  9 C or  9 D) for supplying the secured data to the external access-limited apparatus, device or system via the device interface.    
     
     
         8 . Embedded/integrated device according to  claim 7 , wherein the integrated circuit comprises hardware and software required to supply output signals to one or more of the second interface blocks ( 9 A,  9 B,  9 C or  9 D), implemented in the form of a USB-port, a PCMCIA-port or a UART-port.  
     
     
         9 . Embedded/integrated device according to  claim 7 , 
 wherein said IC ( 1 ) is mounted on a small printed circuit board PCB ( 12 B),    the said IC ( 1 ) is connected to the PCB ( 12 B) by one or more of a USB ( 9 A), an Ethernet ( 9 B), a GPIO ( 9 C), a UART ( 9 D) or a SmartCard ( 7 C) interface on the IC ( 1 ),    the said PCB ( 12 B) is equipped with a mechanical/electronic interface suitable for the host device,    an SDRAM chip ( 6 ), typically with at least 4 MB capacity, being mounted on the same PCB ( 12 B)    a non-volatile serial Flash chip ( 7 ), typically with at least 256 Kbytes capacity, being mounted on the same PCB ( 12 B)    a fingerprint sensor ( 5 ) being mounted on the same PCB ( 12 B), or mounted separately in the host device, and connected to the IC ( 1 ) on the PCB ( 12 B) by cable    
     
     
         10 . Method of using a portable device-according to  claim 1  or an embedded device according to  claim 7  for providing a bridge from biometrics input to a computer, into secure communication protocol responses to a non-biometrics network, comprising in a single integrated circuit (IC) ( 1 ) executing the following steps: 
 capturing (SC) an image from a fingerprint sensor ( 5 ) via a first interface block ( 5 A),  
 pre-processing (SC) the captured fingerprint signal in the image capture and pre-processing block (SC) containing hardware-embedded algorithms optimized for high-speed processing of the most laborious initial processing of the raw fingerprint image data,  
 transferring the pre-processed data to the processor unit ( 2 ) for extracting compact minutiae features of the fingerprint via a high-speed bus ( 3 )  
 retrieval by the processor unit ( 2 ) of compact fingerprint minutiae information from a non-volatile storage module ( 7 ,  7 A or  7 E) holding pre-stored master fingerprint representations of authorized persons  
 comparing in the processor unit ( 2 ) the extracted features representing the captured fingerprint with features of the pre-stored master fingerprint representations  
 producing in dependence of the result from the said comparison, a secure output in a pre-defined format to an external unit, network or system through one of the communication interfaces ( 9 A,  9 B,  9 C,  9 D and  7 C).  
 
     
     
         11 . Method according to  claim 10 , comprising pre-loading into the non-volatile memory ( 7 A,  7 E or  7 ) a subset of the administrative software which tailors the output secure communication response to the target network (N) or Intranet (E) to a pre-defined format and sequence, including e.g. handshake sequences.  
     
     
         12 . Method according to  claim 11 , wherein the output from the chip ( 1 ) is blocked (non-authorized access state) if the matching by IC ( 1 ) of the captured fingerprint is negative relative to any of the authorized fingerprint representations stored in the non-volatile memory ( 7 A,  7 E or  7 ).  
     
     
         13 . Method according to  claim 11 , wherein the output from the chip ( 1 ) is opened (authorized access state) if the matching by the IC ( 1 ) of the captured fingerprint is positive relative to any of the authorized fingerprint representations stored in the non-volatile memory ( 7 A,  7 E or  7 ).  
     
     
         14 . Method according to  claim 11 , wherein the pre-loaded subset of the administrative software can combine the steps of 
 generating the pseudo-random secure key or password ( 8  or  8 A),    applying any of the encryption methods at hand and embedded in the hardware blocks, such as DES, ECB, CBC, TDES ( 8  or  8 B), or any proprietary encryption algorithm also embedded in hardware ( 8 C)    tailoring handshake sequences according to the rules of secure communication of the device, network or system.    
     
     
         15 . Method according to  claim 11 , wherein the pre-loaded subset of the administrative software is adapted to perform 
 sequencing the operation of the respective functionality blocks of the chip ( 1 ) in order to produce secured output data which is suitable for transmission in the targeted network (N) and for processing by receiving units connected to the network (N).    
     
     
         16 . Method according to  claim 10 , wherein 
 the secure communication parameters of a network or a device, such as e.g. encryption seed, electronic certificates, PKI keys, IP address, etc. of the targeted server or resident computer in a device are pre-stored during personalization of the chip ( 1 ) into either embedded SmartCard block ( 7 C) or external SmartCard chip ( 7 E), or in scrambled format on external non-volatile memory ( 7 )    
     
     
         17 . Method according to clam  16 , wherein 
 the said secure communication parameters can only be retrieved from the embedded SmartCard block ( 7 C) or from the external SmartCard chip ( 7 E) upon a positive match of the captured fingerprint relative to a fingerprint representation of an authorized person, and    an output signal from the chip ( 1 ) including secure communication responses are initiated in dependence upon the result of a comparison of the captured fingerprint relative with a fingerprint representation of an authorized person.    
     
     
         18 . Embedded access control and user input device or apparatus for being a built-in part of stand alone appliances with some form of access control, e.g. hotel safes, medicine cabinet or the like, and for providing increased security,  
       characterized by 
 an integrated circuit (IC) ( 1 ) for bridging the functionality of fingerprint input from a user to secure communication with other parts of the said stand-alone appliance, said IC comprising  
 a processor unit ( 2 ) communicating with the other on-chip components via a high speed bus ( 3 ),  
 a first memory interface block ( 6 B or  6 D) being connected to the high speed bus ( 3 ) for interfacing with volatile memory ( 6 A or  6 C), thus providing working memory available to other modules on the integrated circuit,  
 a second memory interface block ( 7 B or  7 D) being connected to the high speed bus ( 3 ) for interfacing with non-volatile memory ( 7 A or  7  or  7 E), for storing of program code, e.g. administrative software, tailored security output responses, and fingerprint representations in the form of so-called fingerprint minutiae,  
 a first interface block ( 5 A) for being coupled to a fingerprint sensor ( 5 )  
 said first interface block ( 5 A) is connected to an image capture and pre-processing block ( 5 C),  
 said image capture and pre-processing block ( 5 C) is adapted to perform the initial heavy-duty processing of the raw fingerprint images captured from the sensor ( 5 ) into a dataset of reduced size, denoted intermediate fingerprint data, the intermediate fingerprint data being submitted as output to the central processor block ( 2 ) via the high speed bus ( 3 ) for final processing to compact fingerprint representations by so-called minutiae, on the central processor ( 2 ),  
 encryption modules ( 8  or  8 A,  8 B and  8 C) connected to the high-speed bus ( 3 ) for providing encryption information, or alternatively scrambling information or for performing encryption or scrambling,  
 the processor unit ( 2 ) is adapted to apply the encryption or scrambling information to the fingerprint data for producing secured data as an output to the high speed bus ( 3 )  
 one or more second interface blocks ( 9 A,  9 B or  9 C) for supplying the secured data to other modules of the stand-alone appliance.  
 
     
     
         19 . Embedded access control device or apparatus according to  claim 18  comprising 
 fingerprint information non-volatile storage means ( 7 ,  7 A or  7 E), such as e.g. a SmartCard unit, for storing information related to the fingerprint characteristics of authorized users,  
 fingerprint input means ( 5 ) for entering the fingerprint characteristics of authorized users into non-volatile memory ( 7 ,  7 A or  7 E) of the IC ( 1 ) and  
 fingerprint verification means in the form of processing capability ( 2 ) including biometrics software for checking the authenticity of the user trying to access the device.  
 
     
     
         20 . Embedded access control or input device according to  claim 18  which in addition allows the input of code or commands by also comprising 
 a fingerprint storage module ( 7 ,  7 A or  7 E) where the device may store a series of consecutive fingerprint representations generated by the fingerprint sensor signal capturing and pre-processing block ( 5 C),  
 movement analyzing means, in the form of a hardware or a software movement analyzing program module for analyzing the obtained series of fingerprint representations to obtain a measure of the omni-directional finger movements across the sensor in two dimensions,  
 translation means in the form of a hardware or a software translation program module for analyzing and categorizing the omni-directional finger movements across the fingerprint sensor according to predefined sets of finger movement sequences including directional and touch/no-touch finger movement sequences  
 a command table for translating the categorized finger movements into control signals whereby the translating means generates control signal for controlling the stand-alone appliance in response to the finger movements on the sensor.  
 
     
     
         21 . Embedded access control and user input device or apparatus according to  claim 18 , wherein 
 the operating and control software of the stand-alone appliance is loaded into the non-volatile memory block ( 7  or  7 A or  7 E) of the integrated circuit IC ( 1 ),    said operating and control software of the stand-alone appliance is executed by the central processor block ( 2 ) of the IC ( 1 )    
     
     
         22 . Method of secured access control and user input in stand-alone appliances having an embedded access control or user input device according to  claim 18 , the method comprising performing the following steps in the integrated circuit: 
 capturing ( 5 C) an image in a fingerprint sensor ( 5 ) via a first interface block ( 5 A),    pre-processing ( 5 C) the captured signal in the image capture and pre-processing block ( 5 C) containing hardware-embedded algorithms optimized for high-speed processing of the most laborious initial processing of the raw fingerprint image data,    transferring the pre-processed data to the processor unit ( 2 ) for extracting compact minutiae features of the fingerprint via a high-speed bus ( 3 )    retrieval by the processor unit ( 2 ) of compact fingerprint minutiae information from a non-volatile storage module ( 7 ,  7 A or  7 E) holding pre-stored master fingerprint representations of authorized persons,    comparing in the processor unit ( 2 ) the extracted features representing the captured fingerprint with features of the pre-stored master fingerprint representations,    producing in dependence of the said comparison, a pre-defined secure output to other parts of the stand-alone appliance.    
     
     
         23 . Use of embedded access control device or apparatus according to  claim 18  for implementing secure access to various functions in an automobile, such as door locks, engine ignition, or the like.

Join the waitlist — get patent alerts

Track US2004123113A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.