IP Library Granted Patent US 12,250,542
Granted Patent B2
US 12,250,542 · App. 17/738,274 · Granted Mar 11, 2025

Inference-based detection of proximity changes

Inventors: Alain Slak (Bedford, MA); Paul Bradford (Bedford, MA); Boris Boruchovich (Bedford, MA); Lou Bergandi (Fallbrook, CA); Jay Tucker (Arlington, MA); Joel Lemieux (Natick, MA); Jason Mafera (Francestown, NH)
Assignee: IMPRIVATA, INC.
H04W12/06G06N3/02H04W4/80H04W12/082H04W12/63H04W24/08H04W76/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,250,542
App. No.
17/738,274
Granted
Mar 11, 2025
Kind
B2
Abstract

Embodiments of the present invention analyze multiple factors—such as user input events, device motion data, other data from the endpoint, or data from an external system (such as a real-time location system)—to make a probabilistic determination whether a walkaway event has occurred.

Claims (34)

1. A method of controlling access to a secure resource accessible by a user via a node, the node being in operative communication, via a network, with (i) a location server configured to receive and broadcast location events to subscribers thereto, and (ii) an authentication server, the location events comprising notifications of walk-away events that involve geospatial zones, the method comprising:

authenticating the user at the node in accordance with a security policy applicable both to the user and the secure resource;

with the authentication server, subscribing to the location events, receivable from the location server, pertaining to at least one of the user, the node, or the secure resource;

when a location event indicative of a walk-away event of the user from the node is broadcast to the authentication server, terminating the user's access of the secure resource via the node by launching a privacy screen on the node, the walk-away event resulting from the user exiting a monitored geospatial zone or entering another one or leaving a predetermined vicinity of the secure resource;

thereafter, when a location event indicative of a walk-up event of the user to the node is broadcast to the authentication server, and only when an elapsed time between the walk-away event and the walk-up event does not exceed a threshold, removing the privacy screen and affording the user access to the secure resource via the node without requiring additional authentication from the user.

2. The method of claim 1 , further comprising detecting the walk-away event at least in part by:

monitoring over time a signal strength of a wireless communication link established between the node and a user device and periodically storing, in a computer memory, values indicative of the monitored signal strength;

periodically analyzing the stored values for patterns indicative of a walk-away event from the node and, when a pattern indicative of a walk-away event is detected, assigning a probability thereto; and

when the probability exceeds a threshold specified by the security policy, registering the walk-away event.

3. The method of claim 2 , wherein the stored values are analyzed using a recurrent neural network.

4. The method of claim 2 , wherein the wireless communication link comprises a short-range wireless protocol.

5. The method of claim 4 , wherein the short-range wireless protocol is Bluetooth Low Energy.

6. The method of claim 1 , wherein, when the elapsed time between the walk-away event and the walk-up event exceeds the threshold, requiring additional authentication from the user prior to affording the user access to the secure resource via the node.

7. The method of claim 1 , wherein the node is a workstation.

8. The method of claim 1 , wherein the node is a network-connected medical device.

9. The method of claim 1 , wherein the secure resource comprises one or more electronic medical records.

10. The method of claim 1 , wherein the node is disposed within an institutional space, and further comprising monitoring a location of the user within the institutional space.

11. The method of claim 10 , wherein the location of the user is monitored using a real-time location services (RTLS) system.

12. The method of claim 10 , wherein the node is movable within the institutional space, and/or a location of the node is unknown.

13. A system comprising a plurality of secure resources, the system comprising:

a processor;

a computer memory including stored instructions comprising (i) an authentication module and (ii) an event-monitoring module that are executable by the processor;

a wireless interface for establishing wireless communication links with user devices proximate to a secure resource; and

received signal strength index (RSSI) circuitry configured to monitor a signal strength of a wireless communication link between the wireless interface and a user device, and periodically storing, in the computer memory, values indicative of the monitored signal strength,

wherein:

the authentication module is configured to authenticate a user and verify an association between the authenticated user and a linked user device, wherein the linked user device is not utilized to access the secure resource or to enable access to the secure resource; and

the event-monitoring module is configured to (i) periodically analyze the stored values for patterns indicative of a walkaway event resulting from the user exiting a monitored geospatial zone or entering another one or leaving a predetermined vicinity of the secure resource and, when a pattern indicative of a walkaway event is detected, assign a probability thereto; and (ii) when the probability exceeds a threshold specified by a security policy, register the walkaway event for the secure resource with a server and terminate the authenticated user's access to the secure resource after the walkaway event is registered.

14. The system of claim 13 , wherein the wireless interface is configured to establish wireless communication links with user devices only after the user has been authenticated by the authentication module.

15. The system of claim 13 , wherein the event-monitoring module is configured to terminate the authenticated user's access to the secure resource by ending a session hosted by the secure resource.

16. The system of claim 13 , wherein the event-monitoring module is configured to terminate the authenticated user's access to the secure resource by launching a privacy screen removable only by a new authentication by the authentication module.

17. The system of claim 13 , wherein the wireless communication link comprises a short-range wireless protocol.

18. The system of claim 17 , wherein the short-range wireless protocol is Bluetooth Low Energy.

19. The system of claim 13 , wherein the event-monitoring module implements a recurrent neural network.

20. The system of claim 13 , wherein a notification of the walkaway event is provided to applications subscribing to receive walkaway events for the secure resource.

Assignments (4)
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY COLLATERAL AT REEL/FRAME NO. 68553/0806 Recorded Sep 18, 2024
From: BLUE OWL CAPITAL CORPORATION (FORMERLY KNOWN AS OWL ROCK CAPITAL CORPORATION), AS COLLATERAL AGENT
To: IMPRIVATA, INC.
Reel/Frame 068981/0790 →
INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT (1L) Recorded Aug 12, 2024
From: IMPRIVATA, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 068551/0623 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT SUPPLEMENT (2L) Recorded Aug 12, 2024
From: IMPRIVATA, INC.
To: BLUE OWL CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 068553/0806 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 26, 2022
From: SLAK, ALAIN; BRADFORD, PAUL; BORUCHOVICH, BORIS; BERGANDI, LOU; TUCKER, JAY; LEMIEUX, JOEL; MAFERA, JASON
To: IMPRIVATA, INC.
Reel/Frame 061545/0575 →
Continuity (7)
Continuation 17089982 · Nov 5, 2020
Continuation 16395779 · Apr 26, 2019
Continuation In Part 15843460 · Dec 15, 2017
Continuation In Part 14945658 · Nov 19, 2015
Provisional Application 62183793 · Jun 24, 2015
Provisional Application 62081820 · Nov 19, 2014
Related Publication 20220264298A1 · Aug 18, 2022
References Cited (48)
US 8607067B1 · Janse van Rensburg et al. · 2013 [cited by applicant]
US 8943580B2 · Fadell et al. · 2015 [cited by applicant]
US 9201885B1 · Nasserbakht · 2015 [cited by examiner]
US 9405602B1 · Verne et al. · 2016 [cited by applicant]
US 10216366B2 · Ullrich · 2019 [cited by applicant]
US 10656796B2 · Ullrich · 2020 [cited by applicant]
US 10917788B2 · Slak et al. · 2021 [cited by applicant]
US 20050076078A1 · Salton · 2005 [cited by applicant]
US 20060230140A1 · Aoyama et al. · 2006 [cited by applicant]
US 20080010229A1 · Lee Shu Tak · 2008 [cited by examiner]
US 20080184355A1 · Walrath · 2008 [cited by applicant]
US 20080260119A1 · Marathe et al. · 2008 [cited by applicant]
US 20090063852A1 · Messerges et al. · 2009 [cited by applicant]
US 20090301200A1 · Wakefield · 2009 [cited by applicant]
US 20090303329A1 · Morisaki · 2009 [cited by applicant]
US 20100093380A1 · Gustafsson · 2010 [cited by applicant]
US 20100205667A1 · Anderson · 2010 [cited by examiner]
US 20110106681A1 · Cockerell · 2011 [cited by examiner]
US 20110159884A1 · Chawla · 2011 [cited by applicant]
US 20120072521A1 · Goodman et al. · 2012 [cited by applicant]
US 20120144452A1 · Dyor et al. · 2012 [cited by applicant]
US 20120233314A1 · Jakobsson · 2012 [cited by applicant]
US 20120323592A1 · Bechtel et al. · 2012 [cited by applicant]
US 20130110537A1 · Smith · 2013 [cited by applicant]
US 20130152047A1 · Moorthi et al. · 2013 [cited by applicant]
US 20130157685A1 · King · 2013 [cited by applicant]
US 20140123249A1 · Davis et al. · 2014 [cited by applicant]
US 20140156833A1 · Robinson · 2014 [cited by applicant]
US 20140200036A1 · Egner et al. · 2014 [cited by applicant]
US 20140282877A1 · Mahaffey et al. · 2014 [cited by applicant]
US 20140355592A1 · Camps · 2014 [cited by examiner]
US 20150070134A1 · Nagisetty et al. · 2015 [cited by applicant]
US 20150088978A1 · Motukuru et al. · 2015 [cited by applicant]
US 20150172920A1 · Ben Ayed · 2015 [cited by applicant]
US 20150188956A1 · Chauhan et al. · 2015 [cited by applicant]
US 20150245165A1 · Chen · 2015 [cited by examiner]
US 20150289820A1 · Miller · 2015 [cited by examiner]
US 20150334439A1 · Zhang · 2015 [cited by applicant]
US 20160043968A1 · Jacob et al. · 2016 [cited by applicant]
US 20160078750A1 · King et al. · 2016 [cited by applicant]
US 20160092875A1 · Howe · 2016 [cited by applicant]
US 20160112871A1 · White · 2016 [cited by applicant]
US 20170109770A1 · Kusens et al. · 2017 [cited by applicant]
US 20180109936A1 · Ting et al. · 2018 [cited by applicant]
US 20190313252A1 · Slak et al. · 2019 [cited by applicant]
US 20200310606A1 · Ullrich · 2020 [cited by applicant]
US 20210127264A1 · Slak et al. · 2021 [cited by applicant]
Rahimi, et al., “Indoor geo-fencing and access control for wireless networks,” 2013 IEEE Symposium on Computational Intelligence in Cyber Security (CICS), 2013, pp. 1-8, doi: 10.1109/CICYBS.2013.6597198. [cited by applicant]