Biometric data, which may be suitably transformed are obtained from a biometric
input device contained within a stand-alone computer or a
mobile device, which may contain an ASIC
chip connected to or incorporated within the stand-alone computer or
mobile device and which includes the capability for capturing one or more biometric samples and for biometric
feature extraction, matching and
encryption. For extra security, the biometric matching is used in conjunction with a PIN to authenticate the user to the stand-alone computer or
mobile device. The biometric template and other sensitive data residing on the mobile device are encrypted using hardware elements of the mobile device (or the ASIC) together with the PIN hash and / or the
Password hash. An obfuscated version of the
Password, stored on the ASIC or the mobile device is de-obfuscated and released to the mobile device
authentication mechanism, including a
Trusted Platform Module if present, in response to a successfully decrypted template and matching biometric sample and PIN. A de-obfuscated
password is used to authenticate the user to the mobile device and the same or a different de-obfuscated
password may be used to authenticate the user to a
remote computer using the SSL / TLS or a process based upon a symmetric
encryption algorithm. The locally generated
password may be used to encrypt
data at rest on the mobile device or ASIC and the remote
authentication password may be used to encrypt
data in transit to and from a
remote computer. This creates a trusted relationship between the stand-alone computer or mobile device and the
remote computer. The
system also eliminates the need for the user to remember and enter complex passwords on the mobile device or for
secure transmission of data. A similar method may be used, with the signature / sign biometric modality to determine whether the holder of an IC
chip card is, in fact the card owner.