IP Library Granted Patent US 11,514,146
Granted Patent B2
US 11,514,146 · App. 16/938,877 · Granted Nov 29, 2022

Risk-based biometric identification and authentication with trusted source for security access

Inventors: Joseph Militello (Miamisburg, OH); Keith Lennard (Charlotte, NC); James D. Barton (Miamisburg, OH)
Assignee: Nautilus Hyosung America, Inc.
G06F21/32G06F21/34G06F21/604G06K7/0013G06Q20/1085G06Q20/206G06Q20/4016G06Q20/40145G06F2221/2113G06F2221/2153G06Q50/265
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,514,146
App. No.
16/938,877
Granted
Nov 29, 2022
Kind
B2
Abstract

A method including receiving, in a security device, a user object storing stored biometric data describing a biometric parameter of the user. Sensed biometric data is generating by sensing directly, using a sensor, the biometric parameter of the user. The stored biometric data is compared to the sensed biometric data. A confidence factor is determined using a first degree of trust, assigned to the object, combined with a second degree of match between the stored biometric data and the sensed biometric data. A user input is received indicating a desired activity. A risk factor is determined based on a combination of the confidence factor and the user input. The risk factor is compared to a selected pre-determined threshold. The user is granted a selected level of access to the security device from among different levels of access to the security device when the risk factor satisfies the selected pre-determined threshold.

Claims (102)

1. A method comprising:

receiving, in a receptacle of a security device and from a user, an object storing stored biometric data describing a biometric parameter of the user;

reading the stored biometric data from the object;

generating sensed biometric data by sensing directly, using a biometric sensor of the security device, the biometric parameter of the user;

comparing the stored biometric data to the sensed biometric data;

determining a confidence factor using a first degree of trust, assigned to the object, combined with a second degree of match between the stored biometric data and the sensed biometric data;

receiving, from an input device of the security device, a user input indicating a desired activity to be taken with respect to the security device;

determining a risk factor based on a combination of the confidence factor and the user input;

comparing the risk factor to a selected pre-determined threshold; and

granting, to the user, a selected level of access to the security device from among a plurality of levels of access to the security device when the risk factor satisfies the selected pre-determined threshold.

2. The method of claim 1 , further comprising:

selecting the selected pre-determined threshold from among a plurality of pre-determined thresholds, wherein selecting is performed by using the confidence factor and the user input to select a security rule, and then applying the security rule to the risk factor to select the selected pre-determined threshold.

3. The method of claim 2 , further comprising:

taking, by the security device, a security action when the risk factor fails to satisfy a second selected threshold of the plurality of pre-determined thresholds.

4. The method of claim 3 , wherein the security action is selected from the group consisting of:

requesting the user to provide a secondary form of identification;

connecting the security device to a live security agent to further verify the user; and

preventing the user from accessing a higher access level that is higher than the selected level of access.

5. The method of claim 1 , further comprising, prior to generating the sensed biometric data:

prompting the user to input a passcode;

receiving, from the user, an entered passcode;

comparing the entered passcode to a known passcode; and

responsive to the entered passcode being different than the known passcode, taking a security action.

6. The method of claim 1 , wherein the selected level of access is selected from the group consisting of:

allowing the user to designate user preferences;

allowing the user to enter additional security information in order to access a higher level of access relative to the selected level of access;

opening the security device;

allowing the user to withdraw a pre-determined number of objects from the security device; and

allowing the user to perform a first selected transaction within a software program with which the security device is in communication, but also preventing the user from performing a second selected transaction within the software program, wherein performing the second selected transaction requires a higher level of access than the selected level of access.

7. A method of operating an automated kiosk, comprising:

receiving, in proximity to a receptacle of the automated kiosk and from a user, an identity device storing stored biometric data describing a biometric parameter of the user;

generating sensed biometric data by sensing directly, using a biometric sensor of the automated kiosk, the biometric parameter of the user;

comparing the stored biometric data to the sensed biometric data;

determining a confidence factor using a first degree of trust, assigned to the identity device, combined with a second degree of match between the stored biometric data and the sensed biometric data;

receiving, from an input device of the automated kiosk, a user input indicating a type of transaction desired by the user;

determining a risk factor based on a combination of the confidence factor and the user input;

comparing the risk factor to a selected pre-determined threshold; and

preventing the user from performing the type of transaction when the risk factor fails to satisfy the selected pre-determined threshold.

8. The method of claim 7 , further comprising:

responsive to preventing the user from performing the type of transaction, prompting the user to provide additional authentication; and

responsive to providing the additional authentication, allowing the user to perform the type of transaction.

9. The method of claim 7 , further comprising:

responsive to preventing the user from performing the type of transaction, contacting a remote device operable by a remote user;

communicating, via the remote device and the automated kiosk, an authentication requested by the remote user to the user; and

allowing, responsive to a command transmitted from the remote device to the automated kiosk, the user to perform the type of transaction.

10. The method of claim 7 , further comprising:

allowing the user to perform a second transaction, different than the type of transaction, wherein the second transaction is associated with second risk factor that satisfies a second selected pre-determined threshold.

11. The method of claim 7 , further comprising, prior to generating the sensed biometric data:

prompting a user to input a passcode;

receiving, from the user, an entered passcode;

comparing the entered passcode to a known passcode; and

responsive to the entered passcode being different than the known passcode, taking a security action.

12. The method of claim 7 further comprising:

after preventing, prompting the user to provide to the automated kiosk a different type of identification storing a second stored biometric parameter, different than the biometric parameter;

generating second sensed biometric data by sensing directly, using a second biometric sensor of the automated kiosk, the second biometric parameter of the user;

comparing the second stored biometric parameter to the second sensed biometric data;

determining a second confidence factor using a third degree of trust, assigned to the different type of identification, combined with a fourth degree of match between the second stored biometric data and the second sensed biometric data;

determining a second risk factor based on a combination of the second confidence factor and the user input;

comparing the second risk factor to a second selected pre-determined threshold; and

allowing the user to perform the type of transaction when the second risk factor satisfies the second selected pre-determined threshold.

13. A kiosk comprising:

a receptacle disposed in a frame;

a reader disposed to read an identity device placed in proximity to the receptacle;

a display device connected to the frame;

an input device connected to the frame and in electronic communication with the display device;

a processor connected to the frame and in electronic communication with the display device and the input device;

a biometric sensor connected to the frame and in electronic communication with the processor;

a non-transitory computer readable storage medium connected to the frame and in electronic communication with the processor, wherein the non-transitory computer readable storage medium stores computer readable program code which, when executed by the processor, performs a computer-implemented method of controlling one or both of the kiosk and software to which the kiosk has access, the computer-implemented method comprising:

responsive to detecting insertion of the identity device in the receptacle, reading, from the identity device, stored biometric data describing a biometric parameter of a user;

generating sensed biometric data by sensing directly, using the biometric sensor, the biometric parameter of the user;

comparing the stored biometric data to the sensed biometric data;

determining a confidence factor using a first degree of trust, assigned to the identity device, combined with a second degree of match between the stored biometric data and the sensed biometric data;

receiving, from the input device, a user input indicating a transaction desired by the user;

determining a risk factor based on a combination of the confidence factor and the user input;

comparing the risk factor to a selected pre-determined threshold; and

allowing, responsive to the risk factor satisfying the selected pre-determined threshold, the user to perform a transaction via the input device.

14. The kiosk of claim 13 , wherein the computer readable program code is further configured such that, when executed by the processor, the computer-implemented method further comprises:

selecting the selected pre-determined threshold from among a plurality of pre-determined thresholds, wherein selecting is performed by using the confidence factor and the user input to select a security rule, and then applying the security rule to the risk factor to select the selected pre-determined threshold.

15. The kiosk of claim 14 , wherein the computer readable program code is further configured such that, when executed by the processor, the computer-implemented method further comprises:

taking, by processor, a security action when the risk factor fails to satisfy a second selected threshold of the plurality of pre-determined thresholds.

16. The kiosk of claim 15 , wherein the security action is selected from the group consisting of:

requesting the user to provide a secondary form of identification;

connecting the kiosk to a live security agent to further verify the user; and

preventing the user from performing a second transaction different than the transaction.

17. The kiosk of claim 13 , wherein the computer readable program code is further configured such that, when executed by the processor, the computer-implemented method further comprises, prior to generating the sensed biometric data:

prompting a user to input a passcode;

receiving, from the user, an entered passcode;

comparing the entered passcode to a known passcode; and

responsive to the entered passcode being different than the known passcode, taking a security action.

18. The kiosk of claim 13 , wherein the transaction is selected from the group consisting of:

allowing the user to designate user preferences;

allowing the user to enter additional security information in order to access a second transaction; and

allowing the user to withdraw a pre-determined number of objects from the kiosk.

19. The kiosk of claim 13 , wherein the computer readable program code is further configured such that, when executed by the processor, the computer-implemented method further comprises:

concurrently with allowing the user to perform the transaction, preventing the user from performing a second transaction within the software, wherein grant of access to the second transaction is associated with a second risk factor determined from the first degree of trust and the second degree of match, the second risk factor failing to satisfy a second threshold selected for the second transaction.

20. The kiosk of claim 13 , wherein the computer readable program code is further configured such that, when executed by the processor, the computer-implemented method further comprises:

responsive to the risk factor failing to satisfy the pre-determined threshold, performing a security action selected from the group consisting of:

preventing the user from performing the transaction;

prompting the user to provide additional authentication;

establishing communication, via a communication device disposed in the frame and in communication with the processor, with a remote device through which a remote user communicates with the user;

displaying, to the user, one or more different transactions to which the user has been granted access based on the risk factor; and

a combination thereof.

Assignments (2)
SECURITY INTEREST Recorded Oct 6, 2025
From: NAUTILUS HYOSUNG AMERICA, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 072480/0142 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2020
From: MILITELLO, JOSEPH; LENNARD, KEITH; BARTON, JAMES D.
To: NAUTILUS HYOSUNG AMERICA, INC.
Reel/Frame 053464/0909 →
Continuity (1)
Related Publication 20220027442A1 · Jan 27, 2022