Biometric authentication system
View Patent ↗A biometric authentication system is disclosed. In one embodiment, a method includes detecting an interaction between a biometric authentication device and an external system, generating biometric information of a device wearer using a biometric sensor of the biometric authentication device, comparing the biometric information of the device wearer to stored biometric information, and transmitting to the external system an authentication result based on the comparison of the biometric information of the device wearer to the stored biometric information.
1 . A method comprising:
detecting, by a client interface device, an interaction between a personal identification device worn by a device wearer and the client interface device;
verifying, by the client interface device, an identity of the personal identification device using a cryptographic challenge-response protocol;
determining, by the client interface device, a position of the personal identification device relative to the client interface device by measuring at least one of: time difference of arrival or phase difference of arrival of wireless signals exchanged between the personal identification device and the client interface device;
determining whether the personal identification device is within a configurable predetermined area relative to the client interface device based on the determined position;
transmitting, by the client interface device, an authentication request to the personal identification device in response to the personal identification device being within the configurable predetermined area;
generating, by the personal identification device, biometric information of the device wearer using a set of one or more biometric sensors of the personal identification device in response to receiving the authentication request;
comparing, by the personal identification device, the biometric information of the device wearer to biometric information stored in a secure region of the personal identification device;
transmitting, from the personal identification device to the client interface device, an authentication result based on the comparison of the biometric information of the device wearer to the stored biometric information;
transmitting, by the client interface device to an external system, an access grant based on the authentication result;
continuously monitoring, by the client interface device after transmitting the access grant, the position of the personal identification device relative to the client interface device by measuring at least one of time difference of arrival or phase difference of arrival of wireless signals exchanged between the personal identification device and the client interface device;
detecting, by the client interface device, when the personal identification device is not within the configurable predetermined area relative to the client interface device; and
transmitting, by the client interface device, a de-authentication instruction to the external system in response to detecting that the personal identification device is not within the configurable predetermined area.
2 . The method of claim 1 , wherein the biometric information comprises vein signature information of the device wearer.
3 . The method of claim 1 , wherein the biometric information is generated using one or more of magnetic, thermal, acoustic, or optical sensing.
4 . The method of claim 1 , wherein the biometric information is generated in response to the client interface device transmitting the authentication request to the personal identification device.
5 . The method of claim 1 , wherein the stored biometric information is associated with the device wearer, and wherein the personal identification device obtains the stored biometric information before the personal identification device is used to authenticate the device wearer.
6 . The method of claim 1 , wherein the personal identification device has the secure region and a non-secure region, wherein the stored biometric information is stored in the secure region and is never communicated out of the personal identification device.
7 . The method of claim 1 , wherein the personal identification device is a ring wearable by the device wearer.
8 . The method of claim 1 , wherein the comparison of the biometric information of the device wearer to the stored biometric information involves extracting identifying features from sensor data obtained from one or more of the biometric sensors and comparing the identifying features to the stored biometric information.
9 . An apparatus comprising:
a personal identification device comprising:
a set of one or more biometric sensors; and
a processing system coupled to the set of biometric sensors, wherein the processing system stores a biometric identifier, and wherein in response to receiving an authentication request, the processing system obtains biometric information using the set of biometric sensors, compares the biometric information to the biometric identifier, and transmits an authentication result; and
a client interface device comprising:
a positioning sensor configured to determine a position of the personal identification device relative to the client interface device by measuring at least one of time difference of arrival or phase difference of arrival of wireless signals exchanged with the personal identification device;
a communication module configured to communicate with the personal identification device and an external system; and
a controller configured to:
verify an identity of the personal identification device using a cryptographic challenge-response protocol;
determine whether the personal identification device is within a configurable predetermined area based on the determined position;
transmit the authentication request to the personal identification device in response to determining that the personal identification device is within the configurable predetermined area;
receive the authentication result from the personal identification device;
transmit an access grant to the external system based on the authentication result;
continuously monitor the position of the personal identification device after transmitting the access grant; and
transmit a de-authentication instruction to the external system in response to detecting that the personal identification device is not within the configurable predetermined area.
10 . The apparatus of claim 9 , further comprising: an enclosure, wherein the set of biometric sensors and the processing system are disposed within the enclosure of the personal identification device.
11 . The apparatus of claim 9 , wherein the processing system comprises a non-secure region and a secure region, and wherein the biometric identifier is stored in the secure region and is never transmitted out of the secure region.
12 . The apparatus of claim 9 , further comprising: a wireless charging circuit; and a battery, wherein the battery is charged using the wireless charging circuit, and wherein the battery supplies power to all components of the personal identification device.
13 . The apparatus of claim 9 , wherein the biometric identifier comprises vein signature information of a user, and wherein the biometric identifier is generated and stored in a secure region before the apparatus operates to authenticate the user.
14 . The apparatus of claim 9 , wherein the personal identification device is a ring-shaped wearable device worn on a finger of a user.
15 . The apparatus of claim 9 , wherein the set of biometric sensors is configured to perform one or more of magnetic, thermal, acoustic, or optical sensing.
16 . The apparatus of claim 9 , wherein the positioning sensor of the client interface device uses Ultra-Wideband (UWB) signals.
17 . The method of claim 1 , wherein the client interface device checks the personal identification device against a whitelist of authorized devices before transmitting the authentication request.
18 . The method of claim 1 , wherein the personal identification device only responds to the authentication request from client interface devices with which the personal identification device is enrolled.
19 . The method of claim 1 , wherein the external system comprises at least one of: a door access system, a vehicle access system, a firearm control system, or a financial transaction system.
20 . The apparatus of claim 9 , wherein the controller of the client interface device is further configured to check the personal identification device against a whitelist of authorized devices before transmitting the authentication request.