IP Library › Granted Patent US 12,639,412
Granted Patent B2
US 12,639,412 · App. 18/617,914 · Granted May 26, 2026

Application access management based on biometric behavior

Inventors: Pawan Raghunath Chowdhary (San Jose, CA); Dinesh C. Verma (New Castle, NY); Satishkumar Sadagopan (Overland Park, KS); Gerald Coon (Durham, NC); Mathews Thomas (Flower Mound, TX); Utpal Mangla (Toronto, CA)
Assignee: International Business Machines Corporation
G06F21/32
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,639,412
App. No.
18/617,914
Granted
May 26, 2026
Kind
B2
Abstract

According to one embodiment, a method, computer system, and computer program product for managing application access is provided. The embodiment may include receiving real-time biometric data of a user as the user interacts with a computing device and deriving a real-time biometric signature of the user based on the received real-time biometric data. Responsive to determining that the real-time biometric signature is known, the embodiment may include identifying the user, computing a confidence score of the real-time biometric signature, and configuring application access and application functionality available to the user via the computing device based on the identification of the user and the computed confidence score. The embodiment may include continuously performing the receiving and the deriving as the user interacts with the computing device. While a successive real-time biometric signature is known, the embodiment may include continuously performing the identifying, the computing, and the configuring.

Claims (67)

1 . A computer-implemented method, the method comprising:

receiving real-time biometric data of a user as the user interacts with a computing device;

deriving a real-time biometric signature of the user based on the received real-time biometric data;

responsive to determining that the real-time biometric signature is known, identifying the user, and computing a confidence score of the real-time biometric signature, wherein the computed confidence score is based on a computed root mean square error deviation between a biometric signature associated with an application access control profile, of one or more stored application access control profiles, and the real-time biometric signature;

based on identification of the user and the computed confidence score, configuring accessibility and corresponding application programming interface (API) call functionality of one or more applications available to the user via the computing device, wherein configuring the API call functionality is based on how the computed confidence score relates to confidence thresholds defined within the application access control profile;

continuously performing the receiving and the deriving as the user interacts with the computing device; and

while a successive real-time biometric signature is known, continuously performing the identifying, the computing, and the configuring as the user interacts with the computing device.

2 . The method of claim 1 , wherein deriving the real-time biometric signature of the user further comprises:

inputting the received real-time biometric data of the user into a machine learning model; wherein the received real-time biometric data comprises one or more types of biometric data, and wherein the real-time biometric data is received from one or more sensors;

combining, via the machine learning model, one or more behavioral patterns observed from each type of input biometric data;

evaluating, via the machine learning model, variabilities of the one or more sensors; and

outputting, via the machine learning model, a real-time biometric model of the user.

3 . The method of claim 1 , wherein determining that the real-time biometric signature is known further comprises:

referencing the one or more stored application access control profiles, wherein each application access control profile of the one or more stored application access control profiles is associated with a respective biometric signature of a known user of the computing device; and

determining that the real-time biometric signature matches, within a threshold degree, the biometric signature associated with the application access control profile of the one or more stored application access control profiles.

4 . The method of claim 1 , wherein identification of the user is based on a user identity specified within the application access control profile associated with the biometric signature, and wherein configuring the accessibility is based on a defined listing and/or defined categories of applications on the computing device which are specified in the application access control profile as accessible by the user.

5 . The method of claim 1 , wherein continuous performance of the configuring comprises dynamically increasing or decreasing application accessibility and/or application API call functionality available to the user via the computing device.

6 . The method of claim 1 , further comprising:

responsive to determining that the real-time biometric signature is unknown, determining whether an adverse situation exists; and

responsive to determining that an adverse situation does exist, performing one or more evasive actions via the computing device.

7 . The method of claim 6 , further comprising:

responsive to determining that an adverse situation does not exist, disabling access to the computing device by the user.

8 . A computer system, the computer system comprising:

one or more processors, one or more computer-readable memories, one or more computer-readable tangible storage medium, and program instructions stored on at least one of the one or more tangible storage medium for execution by at least one of the one or more processors via at least one of the one or more memories, wherein the computer system is capable of performing a method comprising:

receiving real-time biometric data of a user as the user interacts with a computing device;

deriving a real-time biometric signature of the user based on the received real-time biometric data;

responsive to determining that the real-time biometric signature is known, identifying the user, and computing a confidence score of the real-time biometric signature, wherein the computed confidence score is based on a computed root mean square error deviation between a biometric signature associated with an application access control profile, of one or more stored application access control profiles, and the real-time biometric signature;

based on identification of the user and the computed confidence score, configuring accessibility and corresponding application programming interface (API) call functionality of one or more applications available to the user via the computing device, wherein configuring the API call functionality is based on how the computed confidence score relates to confidence thresholds defined within the application access control profile;

continuously performing the receiving and the deriving as the user interacts with the computing device;

while a successive real-time biometric signature is known, continuously performing the identifying, the computing, and the configuring as the user interacts with the computing device.

9 . The computer system of claim 8 , wherein deriving the real-time biometric signature of the user further comprises:

inputting the received real-time biometric data of the user into a machine learning model; wherein the received real-time biometric data comprises one or more types of biometric data, and wherein the real-time biometric data is received from one or more sensors;

combining, via the machine learning model, one or more behavioral patterns observed from each type of input biometric data;

evaluating, via the machine learning model, variabilities of the one or more sensors; and

outputting, via the machine learning model, a real-time biometric model of the user.

10 . The computer system of claim 8 , wherein determining that the real-time biometric signature is known further comprises:

referencing the one or more stored application access control profiles, wherein each application access control profile of the one or more stored application access control profiles is associated with a respective biometric signature of a known user of the computing device; and

determining that the real-time biometric signature matches, within a threshold degree, the biometric signature associated with the application access control profile of the one or more stored application access control profiles.

11 . The computer system of claim 8 , wherein identification of the user is based on a user identity specified within the application access control profile associated with the biometric signature, and wherein configuring the accessibility is based on a defined listing and/or defined categories of applications on the computing device which are specified in the application access control profile as accessible by the user.

12 . The computer system of claim 8 , wherein continuous performance of the configuring comprises dynamically increasing or decreasing application accessibility and/or application API call functionality available to the user via the computing device.

13 . The computer system of claim 8 , further comprising:

responsive to determining that the real-time biometric signature is unknown, determining whether an adverse situation exists; and

responsive to determining that an adverse situation does exist, performing one or more evasive actions via the computing device.

14 . The computer system of claim 13 , further comprising:

responsive to determining that an adverse situation does not exist, disabling access to the computing device by the user.

15 . A computer program product, the computer program product comprising:

one or more computer-readable tangible storage medium and program instructions stored on at least one of the one or more tangible storage medium, the program instructions executable by a processor capable of performing a method, the method comprising:

receiving real-time biometric data of a user as the user interacts with a computing device;

deriving a real-time biometric signature of the user based on the received real-time biometric data;

responsive to determining that the real-time biometric signature is known, identifying the user, and computing a confidence score of the real-time biometric signature, wherein the computed confidence score is based on a computed root mean square error deviation between a biometric signature associated with an application access control profile, of one or more stored application access control profiles, and the real-time biometric signature;

based on identification of the user and the computed confidence score, configuring accessibility and corresponding application programming interface (API) call functionality of one or more applications available to the user via the computing device, wherein configuring the API call functionality is based on how the computed confidence score relates to confidence thresholds defined within the application access control profile;

continuously performing the receiving and the deriving as the user interacts with the computing device; and

while a successive real-time biometric signature is known, continuously performing the identifying, the computing, and the configuring as the user interacts with the computing device.

16 . The computer program product of claim 15 , wherein deriving the real-time biometric signature of the user further comprises:

inputting the received real-time biometric data of the user into a machine learning model;

wherein the received real-time biometric data comprises one or more types of biometric data, and wherein the real-time biometric data is received from one or more sensors;

combining, via the machine learning model, one or more behavioral patterns observed from each type of input biometric data;

evaluating, via the machine learning model, variabilities of the one or more sensors; and

outputting, via the machine learning model, a real-time biometric model of the user.

17 . The computer program product of claim 15 , wherein determining that the real-time biometric signature is known further comprises:

referencing the one or more stored application access control profiles, wherein each application access control profile of the one or more stored application access control profiles is associated with a respective biometric signature of a known user of the computing device; and

determining that the real-time biometric signature matches, within a threshold degree, the biometric signature associated with the application access control profile of the one or more stored application access control profiles.

18 . The computer program product of claim 15 , wherein identification of the user is based on a user identity specified within the application access control profile associated with the biometric signature, and wherein configuring the accessibility is based on a defined listing and/or defined categories of applications on the computing device which are specified in the application access control profile as accessible by the user.

19 . The computer program product of claim 15 , wherein continuous performance of the configuring comprises dynamically increasing or decreasing application accessibility and/or application API call functionality available to the user via the computing device.

20 . The computer program product of claim 15 , further comprising:

responsive to determining that the real-time biometric signature is unknown, determining whether an adverse situation exists; and

responsive to determining that an adverse situation does exist, performing one or more evasive actions via the computing device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 27, 2024
From: CHOWDHARY, PAWAN RAGHUNATH; VERMA, DINESH C.; SADAGOPAN, SATISHKUMAR; COON, GERALD; THOMAS, MATHEWS; MANGLA, UTPAL
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 066916/0028 →
Continuity (1)
Related Publication 20250307362A1 · Oct 2, 2025
References Cited (23)
US 7130452B2 · Bolle · 2006 [cited by applicant]
US 9762588B2 · Hudack · 2017 [cited by applicant]
US 10230723B2 · Korus · 2019 [cited by examiner]
US 10810510B2 · Baracaldo Angel · 2020 [cited by applicant]
US 11244757B1 · Gabay · 2022 [cited by examiner]
US 11451532B2 · Arif Khan · 2022 [cited by applicant]
US 11620370B2 · Douglas · 2023 [cited by examiner]
US 20160182503A1 · Cheng · 2016 [cited by examiner]
US 20170109514A1 · Cheng · 2017 [cited by examiner]
US 20190220583A1 · Douglas · 2019 [cited by examiner]
US 20210383410A1 · Talib · 2021 [cited by applicant]
US 20220029981A1 · Mavani · 2022 [cited by examiner]
CN 106415570B · 2019 [cited by applicant]
EP 1873999A1 · 2008 [cited by applicant]
EP 3019991B1 · 2019 [cited by applicant]
Biger-Levin, Ayelet, “What Is Behavioral Biometrics?”, BioCatch Blog, Accessed on Jan. 5, 2024, 3 Pages. [cited by applicant]
Callsign, “Behavioral Biometric Authentication”, Callsign Inc., Accessed on Jan. 5, 2024, 4 Pages. [cited by applicant]
Kover, Amy, “What are behavioral biometrics?”, Mastercard Newsroom, Nov. 15, 2021, 2 Pages. [cited by applicant]
Nerini et al., “Augmented PIN Authentication through Behavioral Biometrics”, MDPI, Journals, Sensors, vol. 22, Issue 13, Jun. 27, 2022, 15 Pages. [cited by applicant]
Plurilock, “Behavioural Biometric Authentication”, Plurilock Security Inc., Accessed on Jan. 5, 2024, 45 Pages. [cited by applicant]
Rees, Megan, “The Future of User Authentication: A Guide to Behavioral Biometrics”, Expert Insights, Mar. 28, 2023, 6 Pages. [cited by applicant]
Shah, Javed, “What Is Behavioral Biometric Authentication?”, Security Boulevard, Sep. 30, 2022, 4 Pages. [cited by applicant]
Stern et al., “A Basic iPhone Feature Helps Criminals Steal Your Entire Digital Life”, The Wall Street Journal, Feb. 24, 2023, 1 Page. [cited by applicant]