IP Library Granted Patent US 11,783,018
Granted Patent B2
US 11,783,018 · App. 17/521,400 · Granted Oct 10, 2023

Biometric authentication

Inventor: Scott Edward Streit (Woodbine, MD)
Assignee: Private Identity LLC
G06F21/32G06F2221/2133
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,783,018
App. No.
17/521,400
Granted
Oct 10, 2023
Kind
B2
Abstract

Systems and methods of authorizing access to access-controlled environments are provided. In one example, a method includes receiving, passively by a computing device, user behavior authentication information indicative of a behavior of a user of the computing device, comparing, by the computing device, the user behavior authentication information to a stored user identifier associated with the user, calculating, by the computing device, a user identity probability based on the comparison of the user behavior authentication information to the stored user identifier, receiving, by the computing device, a request from the user to execute an access-controlled function, and granting, by the computing device, the request from the user responsive to determining that the user identity probability satisfies a first identity probability threshold associated with the access-controlled function.

Claims (67)

1. A method of authorizing access to access-controlled environments, the method comprising:

receiving, by a computing device, passive user authentication information indicative of an identity of a user of the computing device;

comparing, by the computing device, the passive user authentication information to a stored user identifier associated with the user;

receiving, by the computing device, active user authentication information indicative of the identity of the user of the computing device;

comparing, by the computing device, the active user authentication information to the stored user identifier associated with the user;

generating a liveness evaluation of the user and validating of submission of the passive and active authentication information, wherein the liveness evaluation includes authentication information that validates capture of the passive and active sources of authentication information by a live user, wherein generating the liveness evaluation includes an act of processing the authentication information that validates the capture of the passive and active user authentication information using a plurality of neural networks including at least a first neural network configured to process passive authentication information and a second neural network configured to process active authentication information, wherein the first and second neural networks are configured to process authentication information and generate a respective output probability that the passive authentication information and the active authentication information are actually obtained from the user;

receiving, by the computing device, a request from the user to execute an access-controlled function; and

granting, by the computing device, the request from the user responsive to determining that a user identity probability satisfies a first identity probability threshold associated with the access-controlled function based on, at least in part, the active and passive user authentication information and the liveness evaluation.

2. The method of claim 1 , wherein the passive authentication information includes user behavior authentication information.

3. The method of claim 2 , wherein receiving the passive user behavior authentication information is performed without prompting the user to provide the user behavior authentication information.

4. The method of claim 1 , wherein the first neural network configured to process passive authentication information and the second neural network configured to process active authentication information are configured as a consolidated neural network.

5. The method of claim 1 , further comprising:

receiving, by the computing device, a second request from the user to execute a second access-controlled function;

prompting, by the computing device, the user to provide at least one biometric input responsive to determining that the user identity probability does not satisfy a second identity probability threshold associated with the second access-controlled function;

receiving, by the computing device, the at least one biometric input from the user;

comparing, by the computing device, the at least one biometric input to a user profile;

calculating, by the computing device, a second user identity probability based on the comparison of the at least one biometric input to the user profile;

adjusting, by the computing device, the user identity probability based on the second user identity probability; and

granting, by the computing device, the second request from the user responsive to determining that the user identity probability satisfies the second identity probability threshold.

6. The method of claim 5 , wherein the user profile includes an encrypted biometric value corresponding to the user, the encrypted biometric value being encrypted by a first encryption algorithm.

7. The method of claim 6 , wherein comparing the at least one biometric input to the user profile includes:

encrypting the at least one biometric input using the first encryption algorithm to generate at least one encrypted biometric input; and

comparing the at least one encrypted biometric input to the encrypted biometric value.

8. The method of claim 5 , further comprising:

receiving, by the computing device, a third request from the user to execute a third access-controlled function;

determining, by the computing device, that the user identity probability does not satisfy a third identity probability threshold associated with the third access-controlled function;

receiving, by the computing device, a liveness indicator from the user;

calculating, by the computing device, a third user identity probability based on the liveness indicator;

adjusting, by the computing device, the user identity probability based on the third user identity probability; and

granting, by the computing device, the third request from the user responsive to determining that the user identity probability satisfies the third identity probability threshold.

9. The method of claim 8 , wherein generating the liveness evaluation indicator includes an act of determining a probability that the user is a live human user.

10. The method of claim 9 , wherein generating the liveness evaluation includes at least evaluation of one of an audio recording of the user speaking a phrase generated by the computing device or a video of the user performing a gesture generated by the computing device.

11. The method of claim 9 , wherein receiving the liveness indicator includes receiving, passively by the computing device, one or more signals indicative of one or more vital signs of the user.

12. A system of authorizing access to access-controlled environments, the system comprising:

at least one processor operatively connected to a memory, the at least one processor configured to:

receive passive user authentication information indicative of an identity of a user of the computing device;

compare the passive user authentication information to a stored user identifier associated with the user;

receive active user authentication information indicative of the identity of the user of the computing device;

compare the active user authentication information to the stored user identifier associated with the user;

generate a liveness evaluation of the user and validate submission of the passive and active user authentication information, wherein the liveness evaluation is based on authentication information that validates capture of the passive and active sources of authentication information by a live user, wherein generation of the liveness evaluation includes operations executed by the at least one processor configured to validate the capture of the passive and active user authentication information using a plurality of neural networks including at least a first neural network configured to process passive authentication information and a second neural network configured to process active authentication information, wherein the first and second neural networks are configured to process the authentication information and generate a respective output probability that the passive user authentication information and the active user authentication information inputs are actually obtained from the user;

receive a request from the user to execute an access-controlled function; and

grant the request from the user responsive to a determination that a user identity probability satisfies a first identity probability threshold associated with the access-controlled function based on, at least in part, the active and passive authentication information and the liveness evaluation.

13. The system of claim 12 , wherein the passive authentication information includes user behavior authentication information.

14. The system of claim 12 , wherein passively receiving the user behavior authentication information is performed without prompting the user to provide the user behavior authentication information.

15. The system of claim 12 , wherein the first neural network configured to process passive authentication information and the second neural network configured to process active authentication information are configured as a consolidated neural network.

16. The system of claim 12 , wherein the at least one processor is further configured to:

receive a second request from the user to execute a second access-controlled function;

prompt the user to provide at least one biometric input responsive to determining that the user identity probability does not satisfy a second identity probability threshold associated with the second access-controlled function;

receive the at least one biometric input from the user;

compare the at least one biometric input to a user profile;

calculate a second user identity probability based on the comparison of the at least one biometric input to the user profile;

adjust the user identity probability based on the second user identity probability; and

grant the second request from the user responsive to a determination that the user identity probability satisfies the second identity probability threshold.

17. The system of claim 16 , wherein the user profile includes an encrypted biometric value corresponding to the user, the encrypted biometric value being encrypted by a first encryption algorithm.

18. The system of claim 17 , wherein the at least one processor is further configured to:

encrypt the at least one biometric input using the first encryption algorithm to generate at least one encrypted biometric input; and

compare the at least one encrypted biometric input to the encrypted biometric value.

19. The system of claim 16 , wherein the at least one processor is further configured to:

receive a third request from the user to execute a third access-controlled function;

determine that the user identity probability does not satisfy a third identity probability threshold associated with the third access-controlled function;

receive a liveness indicator from the user;

calculate a third user identity probability based on the liveness indicator;

adjust the user identity probability based on the third user identity probability; and

grant the third request from the user responsive to determining that the user identity probability satisfies the third identity probability threshold.

20. The system of claim 19 wherein the at least one processor is further configured to: determine a probability that the user is a live human user based on, at least in part, generation of the liveness evaluation.

21. The system of claim 20 , wherein generation of the liveness evaluation includes at least evaluation of one of an audio recording of the user speaking a phrase generated by the computing device or a video of the user performing a gesture generated by the computing device.

22. The system of claim 20 , wherein the at least one processor is further configured to: receive passively one or more signals indicative of one or more vital signs of the user.

Assignments (4)
SECURITY INTEREST Recorded Aug 14, 2023
From: PRIVATE IDENTITY LLC
To: POLLARD, MICHAEL
Reel/Frame 064581/0864 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2022
From: STREIT, SCOTT EDWARD
To: STEPUP AUTHENTICATION LLC
Reel/Frame 059516/0307 →
CHANGE OF NAME Recorded Apr 6, 2022
From: OPEN INFERENCE HOLDINGS LLC
To: PRIVATE IDENTITY LLC
Reel/Frame 059652/0526 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 6, 2022
From: STEPUP AUTHENTICATION LLC
To: OPEN INFERENCE HOLDINGS LLC
Reel/Frame 059664/0826 →
Continuity (2)
Continuation 16022101 · Jun 28, 2018
Related Publication 20220058255A1 · Feb 24, 2022
Cited By (10)
US 12,206,783 US 12,238,218 US 12,248,549 US 12,254,072 US 12,299,101 US 12,301,698 US 12,335,400 US 12,430,099 US 12,443,392 US 12,457,111