System for provisioning authenticated access to resources linked with individual characteristic data
A system is provided for provisioning authenticated access to resources linked with individual characteristic data. In particular, the system may comprise an endpoint device associated with a primary user, where the endpoint device stores a resource that is secured using the authentication credentials of the primary user. The endpoint device may have an authentication agent installed thereon that may manage authenticated access to the endpoint device and/or the resources stored thereon. In the event of the primary user's unavailability, a secondary user may attempt to pass the authentication check of the primary user's endpoint device. If a match is found, the authentication agent may grant authorization for the secondary user to access the endpoint device and/or the resources stored thereon.
1 . A system for provisioning authenticated access to resources linked with individual characteristic data, the system comprising:
at least one non-transitory storage device; and
at least one processor coupled to the at least one non-transitory storage device, wherein the at least one processor is configured to:
receive, at an endpoint device associated with a primary user, a request from a secondary user to access a resource stored on the endpoint device, wherein the request comprises individual characteristic data associated with the secondary user;
convert the individual characteristic data associated with the secondary user to a cryptographic hash value;
determine that the primary user is unavailable based on one or more predefined circumstances, wherein determining that the primary user is unavailable comprises:
retrieving user status data associated with the primary user by communicating with one or more third party entity systems; and
verifying the user status data matches the one or more predefined circumstances to determine unavailability of the primary user;
based on determining that the primary user is unavailable, retrieve reference authentication data from an authentication credential repository, wherein the reference authentication data is stored within the authentication credential repository in a raw data format that is not directly readable as authentication data by an endpoint device;
use a machine learning model to convert the reference authentication data from the raw data format into a format that is recognizable to the endpoint device and compatible to be accessed by the endpoint device as authentication data, wherein the format that is recognizable to the endpoint device is associated with a reference hash value based on the reference authentication data;
determine a match between the individual characteristic data associated with the secondary user and an entry within the reference authentication data by comparing the cryptographic hash value with the reference hash value:
grant authorized access to the secondary user to the resource stored on the endpoint device;
following granting the authorized access for the secondary user, determine that the primary user is no longer unavailable; and
revoke access to the secondary user to the resource stored on the endpoint device in response to the determination that the primary user is no longer unavailable.
2 . The system of claim 1 , wherein the at least one processor is further configured to present a graphical user interface on a display of the endpoint device, wherein the graphical user interface comprises one or more interface elements configured to receive, from the primary user, a selection of the secondary user as an authorized user.
3 . The system of claim 2 , wherein the one or more interface elements are further configured to receive, from the primary user, a revocation of authorization with respect to the secondary user.
4 . The system of claim 1 , wherein the individual characteristic data associated with the secondary user comprises a fingerprint sample.
5 . A computer program product for provisioning authenticated access to resources linked with individual characteristic data, the computer program product comprising a non-transitory computer-readable medium comprising code causing an apparatus to:
receive, at an endpoint device associated with a primary user, a request from a secondary user to access a resource stored on the endpoint device, wherein the request comprises individual characteristic data associated with the secondary user;
convert the individual characteristic data associated with the secondary user to a cryptographic hash value;
determine that the primary user is unavailable based on one or more predefined circumstances, wherein determining that the primary user is unavailable comprises:
retrieving user status data associated with the primary user by communicating with one or more third party entity systems; and
verifying the user status data matches the one or more predefined circumstances to determine unavailability of the primary user;
based on determining that the primary user is unavailable, retrieve reference authentication data from an authentication credential repository, wherein the reference authentication data is stored within the authentication credential repository in a raw data format that is not directly readable as authentication data by an endpoint device;
use a machine learning model to convert the reference authentication data from the raw data format into a format that is recognizable to the endpoint device and compatible to be accessed by the endpoint device as authentication data, wherein the format that is recognizable to the endpoint device is associated with a reference hash value based on the reference authentication data;
determine a match between the individual characteristic data associated with the secondary user and an entry within the reference authentication data by comparing the cryptographic hash value with the reference hash value:
grant authorized access to the secondary user to the resource stored on the endpoint device;
following granting the authorized access for the secondary user, determine that the primary user is no longer unavailable; and
revoke access to the secondary user to the resource stored on the endpoint device in response to the determination that the primary user is no longer unavailable.
6 . The computer program product of claim 5 , wherein the code further causes the apparatus to present a graphical user interface on a display of the endpoint device, wherein the graphical user interface comprises one or more interface elements configured to receive, from the primary user, a selection of the secondary user as an authorized user.
7 . The computer program product of claim 6 , wherein the one or more interface elements are further configured to receive, from the primary user, a revocation of authorization with respect to the secondary user.
8 . A computer-implemented method for provisioning authenticated access to resources linked with individual characteristic data, the computer-implemented method comprising:
receiving, at an endpoint device associated with a primary user, a request from a secondary user to access a resource stored on the endpoint device, wherein the request comprises individual characteristic data associated with the secondary user;
converting the individual characteristic data associated with the secondary user to a cryptographic hash value;
determining that the primary user is unavailable based on one or more predefined circumstances, wherein determining that the primary user is unavailable comprises:
retrieving user status data associated with the primary user by communicating with one or more third party entity systems; and
verifying the user status data matches the one or more predefined circumstances to determine unavailability of the primary user;
based on determining that the primary user is unavailable, retrieving reference authentication data from an authentication credential repository, wherein the reference authentication data is stored within the authentication credential repository in a raw data format that is not directly readable as authentication data by an endpoint device;
use a machine learning model to convert the reference authentication data from the raw data format into a format that is recognizable to the endpoint device and compatible to be accessed by the endpoint device as authentication data, wherein the format that is recognizable to the endpoint device is associated with a reference hash value based on the reference authentication data;
determining a match between the individual characteristic data associated with the secondary user and an entry within the reference authentication data by comparing the cryptographic hash value with the reference hash value;
granting authorized access to the secondary user to the resource stored on the endpoint device;
following granting the authorized access for the secondary user, determining that the primary user is no longer unavailable; and
revoking access to the secondary user to the resource stored on the endpoint device in response to the determination that the primary user is no longer unavailable.
9 . The computer-implemented method of claim 8 , wherein the computer-implemented method further comprises presenting a graphical user interface on a display of the endpoint device, wherein the graphical user interface comprises one or more interface elements configured to receive, from the primary user, a selection of the secondary user as an authorized user.
10 . The computer-implemented method of claim 9 , wherein the one or more interface elements are further configured to receive, from the primary user, a revocation of authorization with respect to the secondary user.
11 . The computer-implemented method of claim 8 , wherein the individual characteristic data associated with the secondary user comprises a fingerprint sample.
12 . The system of claim 1 , wherein the individual characteristic data associated with the secondary user comprises a retinal scan.
13 . The system of claim 1 , wherein the individual characteristic data associated with the secondary user comprises a facial scan.
14 . The computer program product of claim 5 , wherein the individual characteristic data associated with the secondary user comprises a fingerprint sample.
15 . The computer program product of claim 5 , wherein the individual characteristic data associated with the secondary user comprises a retinal scan or facial scan.
16 . The computer-implemented method of claim 8 , wherein the individual characteristic data associated with the secondary user comprises a retinal scan.
17 . The computer-implemented method of claim 8 , wherein the individual characteristic data associated with the secondary user comprises a facial scan.