Biometric identification verification with site feasibility determination
The system improves biometric security in mobile devices by monitoring travel feasibility between events and performing a second-stage verification, effectively reducing duplication forgery risks.
Patent Information
- Application Number
- DE102017116780
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2016-08-11
- Filing Date
- 2017-07-25
- Publication Date
- 2025-09-25
- Estimated Expiration
- 2037-07-25
AI Technical Summary
Biometric sensors in mobile devices are susceptible to duplication forgery, and existing location-based authentication methods are inadequate in verifying the authenticity of identity.
A system that monitors biometric identification events across multiple devices, utilizing location information to determine the feasibility of the user's travel path between events, and performs a second-stage verification if the path is not feasible, thereby enhancing security.
Enhances security by reducing the risk of unauthorized access through duplication forgery by implementing a second-stage verification based on travel feasibility analysis.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
BACKGROUNDField of the invention
[0001] This invention relates generally to mobile computer systems and, more particularly, to performing biometric identity verification with location feasibility determination. Description of the state of the art
[0002] Many mobile devices offer users a variety of ways to verify their identity. Biometric sensors generally offer a higher level of verification, but are still subject to the problem of forgery through duplication. Fingerprint verification allows a user to take a fingerprint. Latex duplication or a high-resolution image can be used to falsify the identification. Other types of biometric sensors are also vulnerable to forgery.
[0003] US 2015 / 0 067 890 A1 discloses an identification method in which identification entries are filtered from a database of identification entries depending on the current location of a user and the user's historical location history.
[0004] US 2009 / 0 158 404 A1 discloses an identification method in which a maximum permissible distance is determined between the current location of a user during an authentication attempt and the location of the user during the previous authentication attempt.
[0005] US 2010 / 0 245 042 A1 discloses an authentication method in which a threshold of a match in a facial recognition depends on the number of location entries in a database that show a user's location within a certain time of less than a predetermined distance from the current location.
[0006] JP 2004 - 118 456 A discloses an authentication method in which a user's location is compared with previous locations of the user.
[0007] US 2014 / 0 278 086 A1 discloses an app that calculates a route to a probable location of an event entered in a calendar based on timetable information from public transport.
[0008] The object of the present invention is to provide various methods and devices that can solve or at least reduce some of the problems mentioned. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] The invention with its numerous features and advantages is explained in more detail below with reference to the accompanying drawings. Fig. 1 shows a simplified block diagram of a communication system for performing biometric identity verification with feasibility determination according to some embodiments of the present invention; Fig. 2 is a flowchart of a method for performing biometric identity verification with feasibility determination according to one or more embodiments of the present invention; Fig. 3 is a flowchart of a method for determining feasibility based on application patterns, according to some embodiments of the present invention; and Fig. 4 is a flowchart of a method for determining feasibility based on a travel nexus, according to some embodiments of the present invention.
[0010] Where identical reference symbols are used in the various drawing figures, these indicate similar or identical elements. DETAILED DESCRIPTION OF ONE(S) EMBODIMENT(S)
[0011] In the Fig. 1 to 4 show example procedures for performing biometric identity verification with feasibility determination.
[0012] To improve security, biometric identification verification events related to a user are monitored across multiple devices. Location information associated with the events is used to determine or ascertain whether it was feasible for the user to travel between locations in the time elapsed between events. Second-level identity verification can be performed based on the location information.
[0013] Fig. 1 shows a simplified block diagram of a communication system 100 with a first device 105. The first device 105 implements a computer system 112, which includes, among other things, a processor 115, a memory 120, a microphone 125, a speaker 130, a display 135, a biometric sensor 137 (e.g., a fingerprint sensor, a retinal scanner, etc.), a motion sensor 138, and a location module 139 (e.g., Wi-Fi or other location detection device). The memory 120 can be volatile memory (e.g., DRAM, SRAM) or non-volatile memory (e.g., ROM, flash memory, or a hard disk, etc.). The first device 105 includes a transceiver 140 for transmitting and receiving signals via an antenna 145 and via a communication link 150. The transceiver 140 may include one or more radio devices for communicating according to various radio access technologies such as cellular technologies, Wi-Fi, Bluetooth®, etc.The communication link 150 can be provided in a variety of forms. In some embodiments, the communication link 150 can be a wireless or cellular radio link. The communication link 150 can also communicate over a packet-based communication network such as the Internet.
[0014] As in Fig. 1, the first device 105 may be one of a plurality of connected devices 105, 155, 160 associated with the same user. The other connected devices 155, 160 may also comprise a computer system, wherein the units are included in whole or in part within the computer system 112 of the first device 105, such as a processor, memory, and a transceiver. When using the method and apparatus described herein, any number of connected devices of various types may be present. In various embodiments, the devices 105, 155, 160 may be handheld devices or portable devices, such as laptop computers, handheld computers, tablet computers, mobile devices, telephones, personal data assistants, music players, gaming devices, portable computing devices, and the like.One or more of the connected devices 155, 160 could also be a non-portable device, such as a desktop computer. For example, device 155 may be a laptop computer and device 160 may be a tablet computer. While certain example aspects of devices 155, 155, 160 are not described herein, these aspects may or may not be present in the various embodiments without limiting the scope of the invention as understood by one of ordinary skill in the art.
[0015] The user may select biometric identity verification to access one or more of devices 105, 155, 160. In some embodiments, a cloud computing resource 165 may interface with devices 105, 155, 160 to facilitate the exchange of biometric identification history data with some or all of devices 105, 155, 160 and / or to process a biometric authentication request, as described herein. In one embodiment, the biometric identification history data may include a user identifier (e.g., based on the output of biometric sensor 137), a device identifier, location data, time data, and device modality data for each biometric identification request made by the user of one of devices 105, 155, 160, as explained in more detail below.
[0016] In the first device 105, the processor 115 may execute instructions stored in the memory 120 and may store instructions in the memory 120, such as the results of the executed instructions. Some embodiments of the processor 115, the memory 120, and the microphone 125 may be configured to implement a biometric security application 170 and to perform portions of the method 200 described in the Fig. 2 to 4 and described below. For example, the processor 115 may execute the biometric security application 170 to monitor biometric identification requests and to impose additional security measures based on the detection of suspicious usage patterns associated with one or more of the devices 105, 155, 160. In general, one or more of the devices 105, 155, 160 are adapted to perform various elements of the methods described in the Fig. 2 through 4. In one example, the various elements of the methods may be implemented on the first device 105. In some embodiments, the cloud computing resource 165 may also be used to perform one or more elements of the methods.
[0017] Fig. 2 is a flowchart of an exemplary method 200 for monitoring biometric identification requests, according to some of the embodiments described herein. In method block 205, an incoming biometric identification request is received. For illustrative purposes, assume the request is received at device 105. In one embodiment, the user communicates with biometric sensor 137 via an interface to gain access to device 105. Device 105 may determine or determine that the biometric data is suitable for unlocking device 105, but may apply additional verification to the incoming request. In some embodiments, all incoming requests are subject to a second level of verification. In other embodiments, however, the incoming requests may be sampled.For example, once a particular request has been reviewed and approved, a time window (e.g., 5 minutes) can be established during which subsequent requests are not subject to additional review. This approach can be chosen to reduce the wait time associated with unlocking device 105.
[0018] In process block 210, the biometric security application 170 first determines location data for the device 105, for example, by querying the location module 139. The biometric security application 170 may forward the initial location data, a user identifier, and a device identifier to the cloud computing resource 165 for evaluation. Time data for the incoming biometric identification request may be sent by the biometric security application 170 or may be derived based on the time at which the request data for authentication was sent to the cloud computing resource 165.
[0019] In process block 215, second location data associated with a previous biometric identification request associated with the user is retrieved. For example, a library of biometric identification requests may be maintained (e.g., by storage in cloud computing resource 165). The entries in the library may include the time of the request, the user identity, the device identity, the location, and the time.
[0020] In process block 220, a second-level identification request is optionally initiated at device 105 based on at least the first and second location data. Various methods may be employed, using the location data to determine whether one of devices 105, 155, 160 may have been acquired from a third party. In some embodiments, cloud computing resource 165 receives the first location data captured by biometric security application 170 in process block 210 and performs an analysis to determine whether the incoming biometric verification request matches the other requests with which the user has logged in to one or more of devices 105, 155, 160. Cloud computing resource 165 may send an indication (e.g., a Boolean flag) to biometric security application 170 that second-level identification is required.
[0021] Fig. 3 is a flowchart of a method 300 for determining feasibility based on usage patterns, in accordance with one or more embodiments described herein. At method block 305, a usage pattern for the user may be created based on the library of biometric identification requests and previous locations. In some embodiments, cloud computing resource 165 may generate and store the usage pattern. At method block 310, the location of the biometric identification request is compared to the usage pattern to determine a match. For example, based on the usage patterns, a location nexus may be determined that indicates the locations frequented by the user.If the location for the incoming request lies outside the location nexus determined based on the usage pattern, this may be an indication that the device 105 has been stolen and that third parties are attempting to gain access to the device 105. The location nexus may also be time-based, so that the location associated with the incoming request is a frequented location, but the time does not match the usage pattern. If the location of the incoming biometric identification request matches the usage pattern in process block 310, the device 105 is unlocked in process block 315. If the location of the incoming biometric identification request does not match the usage pattern in process block 310, a second-level identity verification is required in process block 320.
[0022] Fig. 4 is a flowchart of a method for determining feasibility based on a travel nexus, according to some embodiments described herein. The first location data may be compared to the second location data for the immediately preceding biometric identification request or requests. By comparing the locations, it may be determined that it would not have been feasible for the user to travel between the two locations in the time elapsed between the requests. In process block 405, a travel time for the travel between the first location and the second location is estimated. In determining the estimate, travel schedules (e.g., flight schedules, train schedules, estimated time of arrival, walking distance, cycling distance, etc.) may be used to estimate the possible travel time or times.For example, a minimum travel time or minimum drive time may be determined based on the distance between the locations and available transportation. In some embodiments, the device modality may also be provided with the biometric authentication requests and stored in the library. The output of the motion sensor 138 may be used to determine whether the user is walking, running, driving, biking, etc. Generally, motion patterns obtained from the motion sensor 138 are compared by the processor 115 with previously established patterns to determine the device modality. The modality at the time of the incoming request or for the period preceding the incoming request may be communicated to the cloud computing resource 165 or utilized by the biometric security application 170.In some embodiments, cloud computing resource 165 may access travel schedules and may optionally consider the device modality to determine the estimated travel time. In process block 410, it is determined whether it was possible to travel the distance between the first and second locations (e.g., based on a probability metric). If it was possible to travel the distance, device 105 is unlocked in process block 415. If it was not possible to travel the distance in process block 410, a second-level identity verification is required in process block 420.
[0023] In some embodiments, the incoming biometric identity verification request and the preceding request or requests may be associated with the same user, but not the same device 105, 155, 160. The feasibility may be determined for multiple entries in the library (e.g., in the context of Fig. 4 an estimated travel time). For example, the feasibility for the incoming biometric identity request can be determined compared to the most recent previous requests for each device 105, 155, 160.
[0024] Various methods may be used to implement second-level identity verification. In some embodiments, the user may be prompted to enter a password or a verification code. In some embodiments, a verification code may not be sent to device 105, but instead may be sent to one of devices 155, 160, or to the user's alternate work phone or home phone. For example, cloud computing resource 165 may communicate with the other device 155, 160. If biometric security application 170 requires second-level verification, the user may be prompted to indicate how they would like to receive the verification code.
[0025] In some embodiments, if no connection is present, biometric identification requests may be cached and uploaded to cloud computing resource 165 once the connection is restored. If no connection is present, biometric security application 170 may temporarily accept the authentication requests and unlock device 105 based on the output of biometric sensor 137. Upon later processing the requests, cloud computing resource 165 may send a signal to biometric security application 170 to immediately lock device 105 and may request a second-level identity verification if the feasibility check fails.
[0026] In some embodiments, certain aspects of the methods described above may be implemented by one or more processors of a processor system executing software. The methods 200, 300, 400 described above may be implemented by executing software on a computing device, such as the processor 115 of Fig. 1, such approaches being non-abstract in that they improve the operation of the devices 105, 155, 160 and the user experience in operating the devices 105, 155, 160. Before execution, the software instructions may be written from a non-transitory computer-readable storage medium to a memory such as the memory 120 of Fig. 1 be transferred.
[0027] The software may include one or more sets of executable instructions stored in or otherwise tangibly provided on a non-transitory computer-readable storage medium. The software may include the instructions and certain data that, when executed by one or more processors, direct the processor(s) to perform one or more aspects of the methods described above. The non-transitory storage medium may include, for example, a magnetic or optical storage disk, solid-state storage devices such as flash memory, cache memory, random access memory (RAM), or other non-volatile storage device(s), and the like.The executable instructions stored on the non-transitory computer-readable storage medium may be provided as source code, assembly language code, object code, or other instruction format that can be interpreted or otherwise executed by the processor(s).
[0028] A computer-readable storage medium may include any storage medium or combination of storage media that can be accessed by a computer system during operation for providing instructions and / or data to the computer system. Such storage media include, but are not limited to, optical media (e.g., a compact disk (CD), a digital versatile disk (DVD), a Blu-ray disk), magnetic media (e.g., a floppy disk, magnetic tape, or a magnetic hard disk), volatile memory (e.g., random access memory (RAM) or cache memory), non-volatile memory (e.g., read-only memory (ROM) or flash memory), or microelectromechanical system (MEMS)-based storage media. The computer-readable storage medium may be contained within the computer system (e.g., system RAM or system ROM), may be permanently attached to the computer system (e.g.,a magnetic hard disk), may be detachably attached to the computer system (e.g., an optical disk storage device or a Universal Serial Bus (USB)-based flash memory device), or may be connected to the computer system via a wired or wireless network (e.g., a network-accessible storage device (NAS)).
[0029] A method comprises receiving an incoming biometric identification request from a user at a first device. First location data is determined for the first device. Second location data associated with at least one previous biometric identification request associated with the user is retrieved. Based on at least the first and second location data, a second-level identification request is optionally initiated at the first device.
[0030] A device comprises a location module for determining first location data for the device, a biometric sensor for generating an incoming biometric identification request from a user, and a processor for retrieving second location data associated with the at least one previous biometric identification request associated with the user and for selectively initiating a second level identification request at the device based on at least the first and second location data.
Claims
[1] Method comprising: receiving an incoming biometric identification request from a user at a first device (105); determining first location data for the first device (105); and implementing, by one or more processors (115), the following steps: access to a library of identification verification entries associated with the user, each identification verification entry comprising at least time data, location data, and device identity data; retrieving second location data associated with a selected subset of multiple biometric identification verification entries associated with the user; determining a time interval between the incoming biometric identification request and each biometric identification verification entry in the selected subgroup, wherein each biometric identification verification entry in the subgroup has different device identity data; estimating a travel time for each of the biometric identification verification entries in the subgroup based on the first location data and the location data for each of the biometric identification verification entries in the subgroup; selectively initiating a second stage identification request at the first device (105) depending on one of the estimated travel times exceeding the time interval. [2] The method of claim 1, further comprising: determining a user usage pattern based on the library; and the requirement for second-level identity verification depends on the incoming biometric identification request, which deviates from the usage pattern. [3] The method of claim 2, further comprising requesting second-level identity verification contingent upon determining that the time data associated with the incoming biometric identification request deviates from the usage pattern. [4] The method of claim 2 or claim 3, further comprising requesting second level identity verification contingent upon determining that the first location data associated with the incoming biometric identification request deviates from the usage pattern. [5] The method of any one of claims 1 to 4, wherein estimating the travel time further comprises: determining a device motion modality using a motion sensor (138) in the device (105); and estimating travel time based on device movement modality and schedule data. [6] Device (105) comprising: a location module (139) for determining first location data for the device (105); a biometric sensor (137) for generating an incoming biometric identification request from a user; and a processor (115): to access a library of biometric identification verification entries associated with the user, wherein each biometric identification verification entry comprises at least time data, location data and device identity data, to retrieve second location data associated with a selected subset of multiple biometric identification verification entries associated with the user, to determine a time interval between the incoming biometric identification request and each biometric identification verification entry in the selected subgroup, to estimate a travel time for each of the biometric identification verification entries in the subgroup based on the first location data and the location data for each of the biometric identification verification entries in the subgroup and for selectively initiating a second stage identification request at the device (105) depending on one of the estimated travel times exceeding the time interval. [7] The device (105) of claim 6, wherein the processor (115) determines a usage pattern of the user based on the library and requests second-level identity verification in response to the incoming biometric identification request deviating from the usage pattern. [8] The device (105) of claim 7, wherein the processor (115) requests second-level identity verification in response to determining that the time data associated with the incoming biometric identification request deviates from the usage pattern. [9] The device (105) of claim 7 or claim 8, wherein the processor (115) requests second-level identity verification in response to determining that the first location data associated with the incoming biometric identification request deviates from the usage pattern. [10] The device (105) of claim 9, wherein the processor (115) determines a time interval by determining a device movement modality using a motion sensor (138) in the device (105) and estimates travel time based on the device movement modality and schedule data.
Citation Information
Patent Citations
JP002004118456A
Apparatus, system, and method for user authentication based on authentication credentials and location information
US20090158404A1
Authenticator and authentication method
US20100245042A1
Using historical location data to improve estimates of location
US20140278086A1
Identification system
US20150067890A1