IP Library Granted Patent US 11,947,701
Granted Patent B2
US 11,947,701 · App. 17/100,718 · Granted Apr 2, 2024

Techniques for preventing malicious use of biometric data

Inventor: Ahmad Arash Obaidi (Sammamish, WA)
Assignee: T-Mobile USA Inc.
G06F21/6245G06F21/604G06N5/04G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,947,701
App. No.
17/100,718
Granted
Apr 2, 2024
Kind
B2
Abstract

Described herein are techniques for preventing software applications from gaining access to unauthorized biometric data in accordance with user preferences. In some embodiments, a software application requests access to sensor data collected by a sensor installed on a user device via a gateway application installed on the user device. Upon receipt of the request, the gateway application determines what types of biometric data the software application is authorized to obtain within the sensor data. The gateway application then identifies biometric data that is present within the sensor data. The sensor data is then altered such that biometric data that the software application is not authorized to obtain is obfuscated. Once the sensor data has been altered, the software application is provided access to that altered sensor data.

Claims (57)

1. A method comprising:

receiving, by a gateway application installed in a computing device, a request to access data collected by a sensor device on the computing device, the request originating from a software application installed in the computing device;

determining, by the gateway application, whether the software application has authorization to access one or more biometric features in the collected data;

upon determining that the software application does have authorization to access the one or more biometric features, providing, by the gateway application, the software application with access to the collected data; and

upon determining that the software application does not have authorization to access the one or more biometric features:

altering, by the gateway application, the collected data by obfuscating the one or more biometric features within the collected data; and

providing, by the gateway application, the software application with access to the collected data having the obfuscated one or more biometric features,

wherein:

the collected data collected by the sensor device comprises image data; and

obfuscating the one or more biometric features within the collected data comprises:

identifying a region within the image data associated with the one or more biometric features; and

applying an obfuscation technique to the region within the image data.

2. The method of claim 1 , wherein the one or more biometric features comprises facial features associated with a person.

3. The method of claim 2 , wherein the one or more facial features comprises an eye area of a face associated with the person.

4. The method of claim 1 , wherein the one or more biometric features are identified within the collected data using one or more machine learning techniques.

5. The method of claim 1 , wherein the sensor device comprises a camera.

6. The method of claim 1 , wherein the obfuscation technique comprises one or more of blurring, pixilating, or adding noise to the region of the image data.

7. The method of claim 1 , wherein the region within the image data associated with the one or more biometric features is identified using one or more object recognition techniques.

8. A computing device comprising:

a processor;

at least one sensor device; and

a memory including instructions that, when executed with the processor, cause the computing device to, at least:

receive a request to access data collected by the at least one sensor device, the request originating from a software application installed in the memory;

determine whether the software application has authorization to access one or more biometric features in the collected data;

upon determining that the software application does have authorization to access the one or more biometric features, provide the software application with access to the collected data; and

upon determining that the software application does not have authorization to access the one or more biometric features:

alter the collected data by obfuscating the one or more biometric features within the collected data; and

provide the software application with access to the collected data having the obfuscated one or more biometric features,

wherein:

the collected data collected by the at least one sensor device comprises image data; and

obfuscating the one or more biometric features within the collected data comprises:

identifying a region within the image data associated with the one or more biometric features; and

applying an obfuscation technique to the region within the image data.

9. The computing device of claim 8 , wherein the instructions comprise a gateway application different from the software application, and wherein the request to access data is received by the gateway application from an operating system of the computing device.

10. The computing device of claim 9 , wherein the request to access data is received via an application programming interface associated with the operating system.

11. The computing device of claim 8 , wherein determining whether the software application has authorization to access one or more biometric features in the collected data comprises determining whether the software application is included within a list of software applications stored in the memory.

12. The computing device of claim 11 , wherein the list of software applications is a whitelist comprising a set of authorized software applications.

13. The computing device of claim 11 , wherein the list of software applications is a blacklist comprising a set of unauthorized software applications.

14. The computing device of claim 8 , wherein determining whether the software application has authorization to access one or more biometric features in the collected data comprises communicating with a support platform.

15. A non-transitory computer-readable media collectively storing computer-executable instructions that upon execution cause a computing device to perform acts comprising:

receiving, by a gateway application installed in the non-transitory computer-readable media on the computing device, a request to access data collected by at least one sensor device on the computing device, the request originating from a software application installed in the non-transitory computer-readable media on the computing device;

determining whether the software application has authorization to access one or more biometric features in the collected data;

upon determining that the software application does have authorization to access the one or more biometric features, providing, by the gateway application, the software application with access to the collected data; and

upon determining that the software application does not have authorization to access the one or more biometric features:

altering, by the gateway application, the collected data by obfuscating the one or more biometric features within the collected data; and

providing, by the gateway application, the software application with access to the collected data having the obfuscated one or more biometric features,

wherein:

the collected data collected by the at least one sensor device comprises image data; and

obfuscating the one or more biometric features within the collected data comprises:

identifying a region within the image data associated with the one or more biometric features; and

applying an obfuscation technique to the region within the image data.

16. The non-transitory computer-readable media of claim 15 , wherein the collected data is streaming video data.

17. The non-transitory computer-readable media of claim 16 , wherein the instructions further cause the one or more computing devices to:

monitor the one or more biometric features within the streaming video data; and

continue to obfuscate the one or more biometric features within the streaming video data.

18. The non-transitory computer-readable media of claim 15 , wherein the determination as to whether the software application has authorization to access one or more biometric features in the collected data is made based on user preferences.

19. The non-transitory computer-readable media of claim 15 , wherein the altered collected data is consumed by the software application during the course of its execution.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2020
From: OBAIDI, AHMAD ARASH
To: T-MOBILE USA, INC.
Reel/Frame 054437/0439 →
Continuity (1)
Related Publication 20220164470A1 · May 26, 2022