IP Library Granted Patent US 10,917,788
Granted Patent B2
US 10,917,788 · App. 16/395,779 · Granted Feb 9, 2021

Inference-based detection of proximity changes

Inventors: Alain Slak (Bedford, MA); Paul Bradford (Bedford, MA); Boris Boruchovich (Bedford, MA); Lou Bergandi (Fallbrook, CA); Jay Tucker (Arlington, MA); Joel Lemieux (Natick, MA); Jason Mafera (Francestown, NH)
Assignee: IMPRIVATA, INC.
H04W12/06G06N3/02H04W4/80H04W12/00503H04W12/0802H04W24/08H04W76/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,917,788
App. No.
16/395,779
Granted
Feb 9, 2021
Kind
B2
Abstract

Embodiments of the present invention analyze multiple factors—such as user input events, device motion data, other data from the endpoint, or data from an external system (such as a real-time location system)—to make a probabilistic determination whether a walkaway event has occurred.

Claims (68)

1. A method of detecting departure of a previously authenticated user from proximity to a secure resource, the method comprising the steps of:

establishing a wireless communication link between the secure resource and a device proximate thereto;

verifying, by the secure resource, an association between the authenticated user and the device;

monitoring over time, by the secure resource, a signal strength of the wireless communication link and periodically storing, in a computer memory, values indicative of the monitored signal strength;

periodically analyzing, by the secure resource, the stored values for patterns indicative of a walkaway event and, when a pattern indicative of a walkaway event is detected, assigning a probability thereto;

when the probability exceeds a first threshold specified by a security policy, registering a walkaway event and terminating the authenticated user's access to the secure resource; and

when the probability does not exceed the first threshold but does exceed a second threshold lower than the first threshold, obtaining, by the secure resource, corroborating data indicative of the probability of a walkaway event.

2. The method of claim 1 , wherein the secure resource verifies the association by communication with a location server having access to a user database.

3. The method of claim 1 , wherein the authenticated user's access to the secure resource is terminated by ending a session hosted by the secure resource.

4. The method of claim 1 , wherein the authenticated user's access to the secure resource is terminated by launching a privacy screen removable only by a new authentication.

5. The method of claim 1 , wherein the wireless communication link is a short-range wireless protocol.

6. The method of claim 5 , wherein the short-range wireless protocol is Bluetooth Low Energy.

7. The method of claim 1 , wherein the corroborating data is a GPS location obtained from the device.

8. The method of claim 1 , wherein the corroborating data is pedestrian dead reckoning.

9. The method of claim 1 , wherein the analyzing step is performed with a recurrent neural network.

10. The method of claim 1 , further comprising, by the secure resource following the user's authentication, subscribing to location events of the user with a location server configured to broadcast location events to subscribers thereto.

11. The method of claim 1 , further comprising:

when the corroborating data increases the probability such that the probability exceeds the first threshold, registering a walkaway event and terminating the authenticated user's access to the secure resource; and

when the corroborating data does not increase the probability such that the probability exceeds the first threshold, refraining from registering a walkaway event.

12. A system comprising a plurality of secure resources, each of the secure resources comprising:

a processor;

a computer memory including stored instructions executable by the processor for implementing (i) an authentication module and (ii) an event-monitoring module;

a wireless interface for establishing wireless communication links with user devices proximate to the secure resource;

RSSI circuitry configured to monitor a signal strength of a wireless communication link between the wireless interface and a user device, and periodically storing, in the computer memory, values indicative of the monitored signal strength,

wherein:

the authentication module is configured to authenticate a user and verify an association between the authenticated user and the linked user device; and

the event-monitoring module is configured to (i) periodically analyze the stored values for patterns indicative of a walkaway event and, when a pattern indicative of a walkaway event is detected, assign a probability thereto; (ii) when the probability exceeds a first threshold specified by a security policy, terminating the authenticated user's access to the secure resource, and (iii) when the probability does not exceed the first threshold but does exceed a second threshold lower than the first threshold, obtain corroborating data indicative of the probability of a walkaway event.

13. The system of claim 12 , further comprising a user database storing associations between users and the user devices.

14. The system of claim 12 , wherein the event-monitoring module is configured to terminate the authenticated user's access to the secure resource by ending a session hosted by the secure resource.

15. The system of claim 12 , wherein the event-monitoring module is configured to terminate the authenticated user's access to the secure resource by launching a privacy screen removable only by a new authentication by the authentication module.

16. The system of claim 12 , wherein the wireless communication link is a short-range wireless protocol.

17. The system of claim 16 , wherein the short-range wireless protocol is Bluetooth Low Energy.

18. The system of claim 12 , wherein the corroborating data is a GPS location obtained from the user device via the wireless interface.

19. The system of claim 12 , wherein the event-monitoring module implements a recurrent neural network.

20. The system of claim 12 , wherein the event-monitoring module is configured to:

when the corroborating data increases the probability such that the probability exceeds the first threshold, terminating the authenticated user's access to the secure resource; and

when the corroborating data does not increase the probability such that the probability exceeds the first threshold, refraining from registering a walkaway event.

21. The system of claim 12 , further comprising:

a plurality of tracking sensors at different locations in an institutional space, each of the tracking sensors being configured to detect a proximate presence of an individual or a device and to produce signals indicative thereof; and

a location server in operative communication with the tracking sensors and the secure resources via a network, the location server further including computer storage defining:

(i) a user location database that stores records for a plurality of users, each of the records including a current location of the user based on signals from the tracking sensors;

(ii) a device location database that stores records for a plurality of devices, each of the records including a current location of the device; and

(iii) a subscription database that stores records for a plurality of applications each running on a different device, each of the records specifying an application and one or more location events to which the application has subscribed,

wherein (i) the secure resources are configured to subscribe to location events of the user with the location server, and (ii) the location server is configured to receive signals from the tracking sensors, interpret the received signals as events, and notify secure resources upon occurrence of events to which they subscribe.

22. A system comprising:

a plurality of secure resources, each of the secure resources comprising:

a processor;

a computer memory including stored instructions executable by the processor for implementing (i) an authentication module and (ii) an event-monitoring module;

a wireless interface for establishing wireless communication links with user devices proximate to the secure resource;

RSSI circuitry configured to monitor a signal strength of a wireless communication link between the wireless interface and a user device, and periodically storing, in the computer memory, values indicative of the monitored signal strength,

wherein:

the authentication module is configured to authenticate a user and verify an association between the authenticated user and the linked user device; and

the event-monitoring module is configured to (i) periodically analyze the stored values for patterns indicative of a walkaway event and, when a pattern indicative of a walkaway event is detected, assign a probability thereto; and (ii) if the probability exceeds a threshold specified by a security policy, terminating the authenticated user's access to the secure resource;

a plurality of tracking sensors at different locations in an institutional space, each of the tracking sensors being configured to detect a proximate presence of an individual or a device and to produce signals indicative thereof; and

a location server in operative communication with the tracking sensors and the secure resources via a network, the location server further including computer storage defining:

(i) a user location database that stores records for a plurality of users, each of the records including a current location of the user based on signals from the tracking sensors;

(ii) a device location database that stores records for a plurality of devices, each of the records including a current location of the device; and

(iii) a subscription database that stores records for a plurality of applications each running on a different device, each of the records specifying an application and one or more location events to which the application has subscribed,

wherein (i) the secure resources are configured to subscribe to location events of the user with the location server, and (ii) the location server is configured to receive signals from the tracking sensors, interpret the received signals as events, and notify secure resources upon occurrence of events to which they subscribe.

23. The system of claim 22 , wherein the event-monitoring module implements a recurrent neural network.

24. The system of claim 22 , further comprising a user database storing associations between users and the user devices.

25. The system of claim 22 , wherein the event-monitoring module is configured to terminate the authenticated user's access to the secure resource by ending a session hosted by the secure resource.

26. The system of claim 22 , wherein the event-monitoring module is configured to terminate the authenticated user's access to the secure resource by launching a privacy screen removable only by a new authentication by the authentication module.

27. The system of claim 22 , wherein the wireless communication link is a short-range wireless protocol.

28. The system of claim 27 , wherein the short-range wireless protocol is Bluetooth Low Energy.

29. The system of claim 22 , wherein the event-monitoring module is configured to:

when the corroborating data increases the probability such that the probability exceeds the first threshold, terminating the authenticated user's access to the secure resource; and

when the corroborating data does not increase the probability such that the probability exceeds the first threshold, refraining from registering a walkaway event.

Assignments (4)
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY COLLATERAL AT REEL/FRAME NO. 59644/0097 Recorded Sep 18, 2024
From: BLUE OWL CAPITAL CORPORATION (FORMERLY KNOWN AS OWL ROCK CAPITAL CORPORATION), AS COLLATERAL AGENT
To: IMPRIVATA, INC.
Reel/Frame 068981/0732 →
INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT (1L) Recorded Aug 12, 2024
From: IMPRIVATA, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 068551/0623 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 8, 2022
From: IMPRIVATA, INC.
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 059644/0097 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 30, 2020
From: SLAK, ALAIN; BRADFORD, PAUL; BORUCHOVICH, BORIS; BERGANDI, LOU; TUCKER, JAY; LEMIEUX, JOEL; MAFERA, JASON
To: IMPRIVATA, INC.
Reel/Frame 054224/0512 →
Cited By (2)
US 12,250,542 US 12,283,355