IP Library › Granted Patent US 12,248,544
Granted Patent B2
US 12,248,544 · App. 17/796,443 · Granted Mar 11, 2025

User authentication based on biometric data

Inventors: Sailesh Kumar Tammannagari (Palo Alto, CA); Rafael Dal Zotto (Porto Alegre, BR)
Assignee: Hewlett-Packard Development Company, L.P.
G06F21/32G06F21/316G06F2221/2115
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,248,544
App. No.
17/796,443
Granted
Mar 11, 2025
Kind
B2
Abstract

In an example implementation according to aspects of the present disclosure, a system receives behavioral biometric data associated with a user of a computing device. The system determines whether an identity of the user is authenticated based on a comparison of the received behavior biometric data and historical behavioral biometric data associated with the user of the computing device. In response to determining that the identity of the user is not authenticated based on the comparison of the received behavioral biometric data and the historical behavioral biometric data, the system receives physiological biometric data associated with the user. The system determines whether the identity of the user is authenticated based on a comparison of the received physiological biometric data and historical physiological biometric data associated with the user of the computing device.

Claims (32)

1. A system comprising a processor operatively coupled with a computer readable storage media and program instructions stored on the computer readable storage media that, when read and executed by the processor, direct the processor to:

receive, from a biometric sensor, behavioral biometric data associated with a user of a computing device, wherein the received behavioral biometric data comprises at least one of keystroke dynamic data, mouse movement data, frequency of mouse usage data, or file launch data;

determine whether an identity of the user is authenticated based on a comparison of the received behavior biometric data and historical behavioral biometric data associated with the user of the computing device;

in response to determining that the identity of the user is not authenticated based on the comparison of the received behavioral biometric data and the historical behavioral biometric data, receive, from the biometric sensor, physiological biometric data associated with the user;

determine whether the identity of the user is authenticated based on a comparison of the received physiological biometric data and historical physiological biometric data associated with the user of the computing device; and

in response to determining that the identity of the user is not authenticated based on the comparison of the received physiological biometric data and the historical physiological biometric data associated with the user of the computing device, performing a mitigating action on the computing device, wherein the mitigating action comprises a lock down of the computing device.

2. The system of claim 1 wherein, in response to determining that the identity of the user is authenticated based on the comparison of the received physiological biometric data and the historical physiological biometric data associated with the user of the computing device, the program instructions further direct the processor to update the historical behavioral biometric data with the received behavioral biometric data.

3. The system of claim 1 wherein the mitigating action comprises a notifying a third party of determination that the identity of the user is not authenticated.

4. The system of claim 1 wherein multiple user profiles are associated with the computing device and wherein the multiple user profiles each comprise historical behavioral biometric data and historical physiological biometric data associated with an individual user.

5. The system of claim 1 wherein the program instructions further direct the processor to maintain the historical behavioral biometric data and the historical physiological biometric data in a cloud-based data repository to be ingested by a machine learning system.

6. The system of claim 1 wherein the received physiological biometric data comprises at least one of facial recognition data, voice recognition data, or fingerprint recognition data.

7. A method comprising:

collecting behavioral biometric data associated with a user of a computing device, wherein the collected behavioral biometric data comprises at least one of keystroke dynamic data, mouse movement data, frequency of mouse usage data, or file launch data;

determining whether an identity of the user is verified based on a comparison of the collected behavior biometric data and historical behavioral biometric data associated with the user of the computing device;

in response to determining that the identity of the user is not verified based on the comparison of the collected behavioral biometric data and the historical behavioral biometric data, collecting physiological biometric data associated with the user;

determining whether the identity of the user is verified based on a comparison of the collected physiological biometric data and historical physiological biometric data associated with the user of the computing device;

in response to determining that the identity of the user is verified based on the comparison of the collected physiological biometric data and the historical physiological biometric data associated with the user of the computing device, updating the historical behavioral biometric data with the collected behavioral biometric data; and

in response to determining that the identity of the user is not authenticated based on the comparison of the received physiological biometric data and the historical physiological biometric data associated with the user of the computing device, performing a mitigating action on the computing device, wherein the mitigating action comprises a lock down of the computing device.

8. The method of claim 7 wherein multiple user profiles are associated with the computing device and wherein the multiple user profiles each comprise historical behavioral biometric data and historical physiological biometric data associated with an individual user.

9. The method of claim 7 further comprising maintaining the historical behavioral biometric data and the historical physiological biometric data in a cloud-based data repository to be ingested by a machine learning system.

10. The method of claim 7 wherein the collected physiological biometric data comprises at least one of facial recognition data, voice recognition data, or fingerprint recognition data.

11. A non-transitory machine-readable storage medium comprising executable instructions, that when executed cause a processor to:

maintain historical behavioral biometric data and historical physiological biometric data in a cloud-based data repository to be ingested by a machine learning system;

receive behavioral biometric data associated with a user of a computing device wherein the received behavioral biometric data comprises at least one of keystroke dynamic data, mouse movement data, frequency of mouse usage data, or file launch data;

determine whether an identity of the user is confirmed based on a comparison of the received behavior biometric data and the historical behavioral biometric data associated with the user of the computing device;

receive physiological biometric data associated with the user;

determine whether the identity of the user is confirmed based on a comparison of the received physiological biometric data and the historical physiological biometric data associated with the user of the computing device; and

in response to determining that the identity of the user is not authenticated based on the comparison of the received physiological biometric data and the historical physiological biometric data associated with the user of the computing device, performing a mitigating action on the computing device, wherein the mitigating action comprises a lock down of the computing device.

12. The method of claim 7 wherein the behavioral biometric data is collected from a biometric sensor associated with the computing device.

13. The machine-readable storage medium of claim 11 wherein the behavioral biometric data is received from a biometric sensor associated with the computing device.

14. The machine-readable storage medium of claim 11 wherein the mitigating action comprises a notifying a third party of determination that the identity of the user is not confirmed.

15. The machine-readable storage medium of claim 11 wherein the received physiological biometric data comprises at least one of facial recognition data, voice recognition data, or fingerprint recognition data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2022
From: TAMMANNAGARI, SAILESH KUMAR; DAL ZOTTO, RAFAEL
To: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
Reel/Frame 061581/0804 →
Continuity (1)
Related Publication 20230051980A1 · Feb 16, 2023
References Cited (12)
US 10111093B2 · Harthattu et al. · 2018 [cited by applicant]
US 10303864B2 · Blake et al. · 2019 [cited by applicant]
US 10339288B2 · Rebelo et al. · 2019 [cited by applicant]
US 20090240949A9 · Kitchens et al. · 2009 [cited by applicant]
US 20100162386A1 · Li · 2010 [cited by examiner]
US 20170034183A1 · Enqvist · 2017 [cited by examiner]
US 20170279800A1 · Castinado · 2017 [cited by examiner]
US 20190133474A1 · Longinotti-Buitoni · 2019 [cited by examiner]
CN 106339610A · 2017 [cited by applicant]
CN 107018121A · 2017 [cited by examiner]
CN 109376725A · 2019 [cited by applicant]
WO 2014205148A1 · 2014 [cited by applicant]