| CPC G06F 21/32 (2013.01) | 21 Claims |

|
1. A secure-biometric-sensor system comprising:
a secure element; and
a biometric sensor that is configured to be communicatively interposed between a host and the secure element, the biometric sensor and the secure element being physically bound to one another, the biometric sensor comprising sensor authentication logic that, when executed by at least one hardware processor of the biometric sensor, causes the biometric sensor to perform operations comprising:
receiving a cryptographic challenge from the host;
forwarding the cryptographic challenge to the secure element;
capturing a biometric reading using a biometric-sensing element;
transmitting the captured biometric reading to the host;
receiving a cryptographic response from the secure element, the cryptographic response having been calculated by the secure element based on the cryptographic challenge, the cryptographic response comprising a shared secret between the host and the secure element;
generating a cryptographically entangled token from a predetermined combination of reading-specific data and the shared secret, the reading-specific data comprising one or both of the biometric reading and data derived from the biometric reading; and
transmitting the cryptographically entangled token to the host for use by the host in attempting to authenticate the captured biometric reading as having been captured by the biometric sensor.
|