Method, computer program, and computer system for performing access control based on fingerprints by key

The integration of fingerprint-based authentication with virtual key areas on a touch screen addresses security vulnerabilities and inefficiencies in access control systems by verifying both biometric data and key presses, enhancing security and reducing the number of steps required for access.

JP7702192B2Active Publication Date: 2025-07-03INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
JP2021173556
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2020-11-06
Filing Date
2021-10-24
Publication Date
2025-07-03
Estimated Expiration
2041-10-24

AI Technical Summary

Technical Problem

Existing access control systems face security vulnerabilities and inefficiencies due to reliance on single-factor authentication methods, such as passwords or biometrics, which can be easily compromised or time-consuming.

Method used

A method and system that integrates fingerprint-based authentication with virtual key areas on a touch screen, combining biometric data collection with touch input to verify both the user's identity and the sequence of key presses, enhancing security and reducing the number of steps required for access.

Benefits of technology

This approach provides enhanced security by ensuring that both biometric and input sequence match, thereby reducing the time and complexity of access control, making it more robust against unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007702192000001
    Figure 0007702192000001
  • Figure 0007702192000002
    Figure 0007702192000002
  • Figure 0007702192000003
    Figure 0007702192000003
Patent Text Reader

Abstract

To provide a method for key specific fingerprint based access control, a system, and a computer program.SOLUTION: A method uses a biometric sensor coupled to a touchscreen of a device to collect fingerprint data from within a plurality of virtual key areas of the touchscreen. A virtual key area in the plurality of virtual key areas comprises an area of the touchscreen configured to display an input prompt and collect touch data responsive to the input prompt. Responsive to determining that the fingerprint data has above a threshold level of similarity with stored fingerprint data associated with each of the virtual key areas and that a sequence of the virtual key areas matches a stored key sequence, access to a protected resource is allowed.SELECTED DRAWING: Figure 6
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention generally relates to a method, system, and computer program for fingerprint-based access control. More particularly, the present invention relates to a method, system, and computer program for access control based on fingerprints for each key.

Background Art

[0002] An access control system controls access to protected resources and restricts access to only authorized users. The protected resource can be software. For example, an access control system may permit access to some software function only when a user enters the correct password or username and matching password. The protected resource can also be a physical facility, such as a building or a part of a building, or a physical device, that can be entered or used only by those who have entered a code on a keypad or have an authorized fingerprint or other biometric data, or have used other access control methods.

[0003] Mobile devices typically include a processor, memory, voice and data communication capabilities, and a touch screen. A touch screen is a display device that also receives user input via touches or gestures at specified portions of the display. On some devices, the touch screen or a portion of the touch screen also simulates a physical keyboard and has a labeled portion of the display, also called a virtual key area, where each virtual key area is labeled with the character, number, or symbol that is input into the device when that portion is touched.

[0004] To prevent unauthorized use, mobile devices typically include a password function where the user touches a set of virtual key areas in a certain order to enter a password. If the user touches a sequence that matches the stored password, the user is granted access to additional device functions. For example, when a single physical key included in one mobile device is pressed, the device displays a screen including a virtual numeric keypad and prompts the user to enter their numeric personal identification number (PIN). Access to notifications and emergency functions beyond the basic set is permitted only if the user enters the PIN correctly. Other mobile devices have no physical keys, and when the device detects that it has been lifted, a PIN input prompt is triggered. Other mobile devices permit access via a password that includes letters, numbers, and symbols. Many mobile devices also have additional biometric access control features, such as those that use a dedicated fingerprint sensor or a camera-based face recognition function.

[0005] Devices that include a processor, memory, voice and data communication functions, and a touch screen are also used as access control devices to control access to protected physical resources. For example, the access control device can be configured as a virtual keypad that controls the locking of a door and unlocks the door only when a pre-set code is entered on the virtual keypad.

Summary of the Invention

Problems to be Solved by the Invention

[0006] The present invention provides a method, a system, and a computer program for access control based on fingerprints for each key.

Means for Solving the Problems

[0007] Exemplary embodiments provide a method, a system, and a computer program. One embodiment includes a method of collecting fingerprint data from within a plurality of virtual key areas of a touch screen using a biometric sensor coupled to the touch screen, wherein the virtual key areas within the plurality of virtual key areas comprise areas of the touch screen configured to display an input prompt and collect touch data in response to the input prompt. One embodiment permits access to a protected resource in response to determining that the fingerprint data has a level of similarity exceeding a threshold with stored fingerprint data associated with each of the virtual key areas and that a sequence of the virtual key areas matches a stored key sequence.

[0008] One embodiment includes a computer-usable program. The computer-usable program includes one or more computer-readable storage devices and program instructions stored in at least one of the one or more storage devices.

[0009] One embodiment includes a computer system. The computer system includes one or more processors, one or more computer-readable memories, one or more computer-readable storage devices, and program instructions, the program instructions being stored in at least one of the one or more storage devices and executed by at least one of the one or more processors using at least one of the one or more memories.

[0010] Certain novel features believed to be characteristics of the invention are set forth in the appended claims. However, the invention itself, as well as preferred modes of use, further objects and advantages thereof, will be best understood by reference to the following detailed description of exemplary embodiments read in conjunction with the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0011]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Best Mode for Carrying Out the Invention

[0012] In an exemplary embodiment, it has been recognized that an access control system typically relies on a permitted user having a particular item (e.g., a physical key for a lock, a key card having a magnetic strip to pass through for access or a chip to be read for access, or knowledge of a password), or being identified as a permitted user (e.g., using an ID card or biometric information). However, relying on the possession of a particular item still presents security vulnerabilities. For example, an unauthorized user can observe a permitted user entering the correct password and then use the same password to access again. Relying on identification as a permitted user also presents security vulnerabilities. For example, a child can place a sleeping parent's finger on the device's fingerprint sensor and gain unauthorized access to the parent's mobile device. Therefore, security can be improved by implementing access control based on both having a particular item and being identified as a permitted user.

[0013] However, in an exemplary embodiment, it has also been recognized that a two-step access control process can be inconveniently time-consuming. For example, asking a user to place a finger on a dedicated fingerprint sensor and then use the touch screen to enter a PIN takes twice as long as performing only one of these steps, degrading the user experience for a user who accesses a mobile device hundreds of times a day. Therefore, in an exemplary embodiment, it has been recognized that it is necessary to combine access control based on both having a particular item and being identified as a permitted user into a single process.

[0014] Also, in an exemplary embodiment, for example, in devices that currently permit access based on biometric access control such as using a dedicated fingerprint sensor or a camera-based face recognition function, it has been recognized that these devices still require the user to enter a PIN or password at regular intervals or for accessing particularly protected device functions such as an update of the device's operating system. Further, these devices are exposed to the same security vulnerabilities discussed herein. Thus, in an exemplary embodiment, it has been recognized that in these devices, it is necessary to improve security and simplify the access control process by combining biometric and password-based access control into a single process.

[0015] In an exemplary embodiment, it has been recognized that currently available tools or solutions do not address these needs and do not provide sufficient solutions for these needs. The exemplary embodiments used in the description of the present invention generally address and solve the above problems and other problems related to access control based on key-specific fingerprints.

[0016] One embodiment can be implemented as a software application. An application implementing one embodiment can be configured as a modified access control system, as a separate application operating in cooperation with an existing access control system, as a stand-alone application, or as some combination thereof.

[0017] Specifically, some exemplary embodiments provide a method of collecting biometric data from within a plurality of virtual key areas of a touch screen and determining whether the biometric data has a similarity greater than a threshold with stored biometric data associated with each of the virtual key areas and whether a sequence of virtual key areas matches a stored key sequence. If both are true, the method permits access to a protected resource; otherwise, the method blocks access to the protected resource.

[0018] One embodiment uses a biometric sensor coupled to the touch screen. The display component of the touch screen displays one or more virtual key areas, each virtual key area being labeled with a character, number, or symbol that is input into the device when the data collection surface of the touch screen is touched, and a second surface of the touch screen parallel to the data collection surface is coupled to a biometric sensor configured to collect fingerprint data. Optical fingerprint sensors that use light reflected from the user's finger to collect fingerprint data, those that use an optical-capacitive technique, and those that use ultrasonic technology are all currently known. Additional fingerprint data collection techniques are possible and contemplated within the scope of the present invention. Thus, when the user's finger touches the data collection surface of the touch screen, the biometric sensor collects fingerprint data of the user's finger. Also, the touch screen collects touch data, and a processor that executes software resolves the touch data to data of a single virtual key area touched by the user's finger during fingerprint collection. In one embodiment, fingerprint data collection is triggered by the user's finger touching the data collection surface. In other embodiments, fingerprint data collection is triggered by resolving touch data to data of a single virtual key area.

[0019] Other embodiments use a set of biometric sensors configured to collect fingerprint data, each biometric sensor being coupled to a plane parallel to the data collection surface of the touch screen. Other embodiments use a set of biometric sensors, each of which is coupled to a physical key of a keypad. Thus, when the user's finger touches the data collection surface of the touch screen or a physical key, the biometric sensor collects fingerprint data of the user's finger. Also, data is collected about which touch screen or physical key was touched by the user's finger during fingerprint collection.

[0020] Other embodiments use biometric sensors configured to collect biometric data other than fingerprint data. Some non-limiting examples of biometric data other than fingerprints include a portion of the surface of the user's hand or foot, a portion of a different area of the user's skin, and scan data of the iris or retina. Also, the biometric data need not be human.

[0021] In one embodiment, during a setup phase, the user is prompted to enter a desired password or PIN. The user enters the password by typing on each key using a desired finger on a physical key or on a virtual key area of a touch screen. During the entry of the desired password, if the user touches each key (physical or virtual) with a specific finger, this embodiment collects both fingerprint and key data for each touch. Since the fingerprint of each finger of the user is different, the resulting stored password includes data about which finger was used to type which key. For example, one exemplary desired PIN entered by the user into a set of virtual key areas labeled as a numeric keypad could be the sequence 1 (typed with the left ring finger), 2 (typed with the left middle finger), 3 (typed with the left index finger), and 0 (typed with the left thumb). Another exemplary desired PIN entered by the user into a set of virtual key areas labeled as a numeric keypad could be the sequence 2 (typed with the left middle finger), 3 (typed with the left index finger), 5 (typed with the left middle finger), and 6 (typed with the left index finger). Another exemplary desired password entered by the user into a set of virtual key areas labeled as a QWERTY alphanumeric keyboard could be the sequence a (typed with the left pinky), s (typed with the left ring finger), d (typed with the left middle finger), and f (typed with the left index finger).

[0022] One embodiment rejects a user's desired password if the password, fingering sequence, or combination of password and fingering sequence is included in a list of passwords that are considered too easy to use for access control. In other embodiments, if a password, fingering sequence, or combination of password and fingering sequence has been used by other users more than a predetermined threshold number of times, this indicates that the password is too easy to use for access control or too easily guessed by others, and the user's desired password is rejected. For example, PINs such as 1234 or 0000 are often default PINs and may be included in the list of rejected PINs. As another example, the sequence asdf typed with the four fingers of the left hand may be rejected because perhaps 50 other users are already using this sequence because it is probably easy to type.

[0023] Other embodiments prompt the user to enter a desired password or PIN during a setup phase. The user enters the password by typing on a physical key or a virtual key area on a touch screen. This embodiment does not require the use of a desired finger for each key during the setup phase; instead, it identifies the finger usage pattern for the password. Specifically, during normal use by the user, while the user enters the password multiple times to access a protected resource, this embodiment collects both fingerprint and key data for each touch. This embodiment stores the fingerprint data for each finger used to type the key while allowing the user to access the protected resource (if the entered password is correct). One embodiment determines that, as a usage pattern, the user has used the same finger to type a particular key (physical or virtual) more than a threshold number of times (i.e., the similarity between the collected fingerprint data exceeds a threshold). Other embodiments determine that, as a usage pattern, the user has used the same finger to type a particular key (i.e., the similarity between the collected fingerprint data exceeds a threshold) in more than a threshold percentage of all password entries. Once an embodiment identifies a usage pattern, this embodiment switches to require the use of a particular consistent finger for the corresponding virtual key. One embodiment switches to require a particular finger only if the user confirms. Other embodiments switch to require a particular finger without requiring user confirmation. For example, one exemplary user may set their PIN to 1230. Subsequently, when the user uses this PIN, the collected data indicates that the user has entered this PIN as 1 (typed with the left ring finger), 2 (typed with the left middle finger), 3 (typed with the left index finger), and 0 (typed with the left thumb) in more than 90% of the times the user entered this PIN. As a result, with the user's consent, this embodiment switches to require this user to enter this PIN using a particular finger for each digit in the sequence.

[0024] One embodiment stores specific fingerprint data for a specific finger. Non-limiting examples of specific fingerprints include the first fingerprint collected, the most recently collected fingerprint if this embodiment determines that a usage pattern exists, and a randomly selected fingerprint selected from the fingerprint data collected for that fingerprint and virtual key combination. Other embodiments store a composite of the fingerprint data collected for the combination of that fingerprint and virtual key as the fingerprint data for a specific finger.

[0025] Then, when a specific finger is associated with a specific physical key or virtual key area, along with the corresponding fingerprint data, through settings or via a usage pattern, one embodiment prompts the user to enter their password or PIN by typing the password using the finger set for each key. During the entry of the desired password, if the user touches each key with a specific finger, this embodiment collects both the fingerprint and key data for each touch. If the collected fingerprint data has a similarity exceeding a threshold with the user's stored fingerprint data associated with each key, and this embodiment determines that the key sequence matches the user's stored key sequence, this embodiment permits access to the protected resource. On the other hand, if this embodiment determines that the collected fingerprint data does not have a similarity exceeding the threshold with the user's stored fingerprint data associated with each key within the stored sequence, this embodiment blocks access to the protected resource.

[0026] The method of the access control system described in this specification is not obtainable by currently available methods in the technological field of endeavor related to biometric-based access control systems. The method of one embodiment described in this specification, when implemented to run on a device or data processing system, includes a significant advancement in the functionality of that device or data processing system with respect to collecting biometric data from within multiple virtual key areas of a touch screen and determining whether the biometric data has a similarity exceeding a threshold with stored biometric data associated with each of the virtual key areas and whether the sequence of virtual key areas matches a stored key sequence. If both are true, the method permits access to protected resources; otherwise, the method blocks access to protected resources.

[0027] Exemplary embodiments are described by way of example only with respect to particular types of biometric data, touch data, passwords, sequences, virtual key areas, thresholds, sensors, measurements, devices, data processing systems, environments, components, and applications. No particular manifestation of these and other similar artifacts is intended to limit the present invention. Any suitable manifestation of these and other similar artifacts can be selected within the scope of the exemplary embodiments.

[0028] Furthermore, the exemplary embodiments can be implemented with respect to any type of data, data source, or access to a data source via a data network. Any type of data storage device can provide data to an embodiment of the present invention locally in a data processing system or via a data network within the scope of the present invention. When describing an embodiment using a mobile device, any type of data storage device suitable for use in a mobile device can provide data to such an embodiment locally in the mobile device or via a data network within the scope of the exemplary embodiment.

[0029] The exemplary embodiments are described by using specific codes, designs, architectures, protocols, layouts, circuit diagrams, and tools as mere examples and are not limited to the exemplary embodiments. Furthermore, the exemplary embodiments are described by using some examples of specific software, tools, and data processing environments as mere examples for clarity of the description. The exemplary embodiments can be used with other equivalent or similar purpose structures, systems, applications, or architectures. For example, other equivalent mobile devices, structures, systems, applications, or their architectures can be used with such embodiments of the present invention within the scope of the present invention. The exemplary embodiments can be implemented in hardware, software, or a combination thereof.

[0030] The examples of the present disclosure are used only for clarity of the description and are not limited to the exemplary embodiments. Additional data, operations, actions, tasks, activities, and operations can be contemplated from the present disclosure and the same is intended within the scope of the exemplary embodiments.

[0031] All of the advantages enumerated in this specification are merely examples and are not intended to be limited to exemplary embodiments. Additional or different advantages may be realized by specific exemplary embodiments. Further, specific exemplary embodiments may or may not have some or all of the advantages enumerated above.

[0032] Although this disclosure includes a detailed description of cloud computing, it should be understood that the implementation forms of the teachings enumerated in this specification are not limited to cloud computing environments. Rather, embodiments of the present invention can be implemented with any other type of computing environment known currently or developed in the future.

[0033] Cloud computing is a service delivery model that enables convenient on-demand network access to a shared pool of configurable computing resources (such as networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal management effort or interaction with a service provider. This cloud model can include at least five characteristics, at least three service models, and at least four deployment models.

[0034] The characteristics are as follows.

[0035] On-demand self-service: Cloud consumers can automatically and unilaterally provision computing capabilities such as server time and network storage as needed, without the need for human interaction with a service provider.

[0036] Broad network access: The capabilities are available over a network and accessed via a standard mechanism that promotes use by heterogeneous thin or thick client platforms (such as mobile phones, laptops, and PDAs).

[0037] Resource pooling: The provider's computing resources are pooled to serve multiple consumers using a multi-tenant model in which various physical and virtual resources are dynamically assigned and reassigned according to demand. In general, the consumer has no control over, nor knowledge of, the exact location of the provided resources, but there is a sense of location independence in that the location can be specified at a higher level of abstraction (such as country, state, or data center).

[0038] Rapid elasticity: Capabilities can be provisioned quickly and elastically, in some cases automatically, to quickly scale out and rapidly released to quickly scale in. To the consumer, the available capabilities often appear to be unlimited and can be purchased in any quantity at any time.

[0039] Measured service: Cloud systems leverage a metering capability at some appropriate level of abstraction for the type of service (such as storage, processing, bandwidth, and active user accounts) to control and optimize resource use automatically. Resource usage can be monitored, controlled, and reported, providing transparency for both the provider and consumer of the utilized services.

[0040] The service model is as follows.

[0041] Software as a Service (SaaS): The ability provided to the consumer is to use the provider's application operating on cloud infrastructure. The application is accessible from various client devices via a thin client interface such as a web browser (e.g., web-based email). The consumer does not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, storage, or even individual application features, with the possible exception of limited user-specific application configuration settings.

[0042] Platform as a Service (PaaS): The ability provided to the consumer is to deploy the consumer-created or acquired application, created using programming languages and tools supported by the provider, on cloud infrastructure. The consumer does not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, or storage, but controls the deployed application and, in some cases, the application hosting environment configuration.

[0043] Infrastructure as a Service (IaaS): The ability provided to the consumer is to supply processing, storage, networks, and other fundamental computing resources on which the consumer can deploy and run any software, which can include an operating system and applications. The consumer does not manage or control the underlying cloud infrastructure, but controls the operating system, storage, deployed applications, and, in some cases, selectively controls the networking components (e.g., host firewall) they have chosen.

[0044] The deployment models are as follows.

[0045] Private Cloud: The cloud infrastructure is operated solely for an organization. It may be managed by the organization or a third party and may exist on or off premises.

[0046] Community Cloud: The cloud infrastructure is shared by several organizations and supports a specific community with common concerns (e.g., mission, security requirements, policy, and compliance considerations, etc.). It may be managed by the organization or a third party and may exist on or off premises.

[0047] Public Cloud: The cloud infrastructure is made available to the general public or a large industry group and is owned by an organization that sells cloud services.

[0048] Hybrid Cloud: The cloud infrastructure is a composition of two or more clouds (private, community, or public) that remain distinct entities but are bound together by standardized or proprietary technology (e.g., cloud bursting for load balancing between clouds) that enables data and application portability.

[0049] The cloud computing environment is service-oriented, placing emphasis on statelessness, low coupling, modularity, and semantic interoperability. At the core of cloud computing is an infrastructure that includes a network of interconnected nodes.

[0050] Referring to the figures, and particularly to FIGS. 1 and 2, these figures are exemplary diagrams of a data processing environment in which exemplary embodiments may be implemented. FIGS. 1 and 2 are merely examples and are not intended to suggest any limitation or claim regarding the environments in which different embodiments may be implemented. In a particular implementation, based on the following description, many changes may be made to the illustrated environments.

[0051] FIG. 1 shows a block diagram of a network of a data processing system in which an exemplary embodiment can be implemented. The data processing environment 100 is a network of computers in which an exemplary embodiment can be implemented. The data processing environment 100 includes a network 102. The network 102 is a medium used to provide communication links between various devices and computers interconnected within the data processing environment 100. The network 102 can include connections such as wired, wireless communication links, or fiber optic cables.

[0052] A client or server is only an exemplary role of a particular data processing system connected to the network 102 and is not intended to exclude other configurations or roles of these data processing systems. Servers 104 and 106 are coupled to the network 102 along with a storage unit 108. Software applications can be executed on any computer within the data processing environment 100. Clients 110, 112, and 114 are also coupled to the network 102. Data processing systems such as servers 104 or 106, or clients 110, 112, or 114 can contain data and software applications or software tools can be executed thereon.

[0053] As just one example, without suggesting any limitation to such an architecture, FIG. 1 shows certain components that can be used in an exemplary implementation of one embodiment. For example, servers 104 and 106, and clients 110, 112, 114 are shown as servers and clients, not to suggest a limitation to a client-server architecture, but as just one example. As another example, one embodiment can be distributed across several data processing systems and data networks as shown, while other embodiments can be implemented on a single data processing system within the scope of the exemplary embodiment. Data processing systems 104, 106, 110, 112, and 114 also represent exemplary nodes, partitions, and other configurations suitable for implementing one embodiment within a cluster.

[0054] Device 132 is an example of a device described herein. For example, device 132 can take the form of a smartphone, tablet computer, laptop computer, stationary or portable client 110, wearable computing device, or any other suitable device. Any software application described as being executed on other data processing systems in FIG. 1 can be configured to be executed in a similar manner on device 132. Any data or information stored or generated in other data processing systems in FIG. 1 can be configured to be stored or generated in a similar manner on device 132. Device 132 includes a touch screen 134 configured to collect touch data and a biometric sensor 136 configured to collect biometric data. Client 112 further includes a biometric sensor 138 coupled to the physical keyboard portion of client 112. Clients 110 and 114 and servers 104 and 106 can also be configured to include biometric sensors (not shown).

[0055] Application 105 implements one embodiment described herein. Application 105 may be executed on any of servers 104 and 106, clients 110, 112, and 114, and device 132.

[0056] Servers 104 and 106, storage unit 108, clients 110, 112, and 114, and device 132 may be coupled to network 102 using a wired connection, a wireless communication protocol, or other suitable data connection. Clients 110, 112, and 114 may be, for example, personal computers or network computers.

[0057] In the illustrated example, server 104 may provide data such as, for example, boot files, operating system images, and applications to clients 110, 112, and 114. Clients 110, 112, and 114 may be clients with respect to server 104 in this example. Clients 110, 112, 114, or some combination thereof may include their own data, boot files, operating system images, and applications. Data processing environment 100 may include additional servers, clients, and other devices not shown.

[0058] In the illustrated example, the data processing environment 100 can be the Internet. The network 102 can represent a collection of networks and gateways that communicate with each other using Transmission Control Protocol / Internet Protocol (TCP / IP) and other protocols. At the center of the Internet is a backbone of data communication links between major nodes or host computers, including thousands of commercial, government, educational, and other computer systems that route data and messages. Of course, the data processing environment 100 can also be implemented as several different types of networks, such as an intranet, a local area network (LAN), or a wide area network (WAN), etc. FIG. 1 is intended as an example and is not intended as an architectural limitation to different exemplary embodiments.

[0059] Among other uses, the data processing environment 100 can be used to implement a client-server environment in which exemplary embodiments can be implemented. A client-server environment allows software applications and data to be distributed across a network so that applications can function using the bi-directionality between client data processing systems and server data processing systems. The data processing environment 100 can also adopt a service-oriented architecture in which interoperable software components distributed across the network can be packaged together as a coherent business application. The data processing environment 100 can also take the form of a cloud and adopt a cloud computing model for service delivery that enables convenient on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing, memory, storage, applications, virtual machines, and services) that can be quickly provisioned and released with minimal administrative effort or interaction with a service provider.

[0060] Referring to FIG. 2, this figure shows a block diagram of a data processing system in which an exemplary embodiment may be implemented. The data processing system 200 is an example of a computer such as the servers 104 and 106 of FIG. 1, or the clients 110, 112, and 114, or another type of device in which computer-usable program code or instructions implementing the processing of the exemplary embodiment may be disposed.

[0061] The data processing system 200 also represents a data processing system or a configuration therein, such as the data processing system 132 of FIG. 1, in which computer-usable program code or instructions implementing the processing of the exemplary embodiment may be disposed. The data processing system 200 is described as a computer by way of example only and is not limited thereto. Implementations in other forms of devices, such as the device 132 of FIG. 1, may modify the data processing system 200 by adding a touch interface, for example, without departing from the general description of the operation and functions of the data processing system 200 described herein, and may even exclude certain illustrated components from the data processing system 200.

[0062] In the example shown, the data processing system 200 employs a hub architecture that includes a North Bridge and Memory Controller Hub (NB / MCH) 202, and a South Bridge and Input / Output (I / O) Controller Hub (SB / ICH) 204. The processing unit 206, main memory 208, and graphics processor 210 are coupled to the North Bridge and Memory Controller Hub (NB / MCH) 202. The processing unit 206 may include one or more processors and may be implemented using one or more heterogeneous processor systems. The processing unit 206 may be a multi-core processor. In certain implementations, the graphics processor 210 may be coupled to the NB / MCH 202 via an Accelerated Graphics Port (AGP).

[0063] In the illustrated example, the local area network (LAN) adapter 212 is coupled to the south bridge and I / O controller hub (SB / ICH) 204. The audio adapter 216, keyboard and mouse adapter 220, modem 222, read-only memory (ROM) 224, universal serial bus (USB) and other ports 232, and PCI / PCIe devices 234 are coupled to the south bridge and I / O controller hub 204 via bus 238. The hard disk drive (HDD) or solid state drive (SSD) 226 and CD-ROM 230 are coupled to the south bridge and I / O controller hub 204 via bus 240. The PCI / PCIe devices 234 can include, for example, an Ethernet (R) adapter, an add-in card, and a PC card for a notebook computer. PCI uses a card bus controller, while PCIe does not. The ROM 224 can be, for example, a flash binary input / output system (BIOS). The hard disk drive 226 and CD-ROM 230 can use, for example, an integrated drive electronics (IDE), serial advanced technology attachment (SATA) interface, or variations such as external SATA (eSATA) and micro SATA (mSATA). The super I / O (SIO) device 236 can be coupled to the south bridge and I / O controller hub (SB / ICH) 204 via bus 238.

[0064] Memory, such as main memory 208, ROM 224, or flash memory (not shown), is an example of some of the computer-usable storage devices. Hard disk drives or solid state drives 226, CD-ROMs 230, and other similarly usable devices are examples of some of the computer-usable storage devices that include computer-usable storage media.

[0065] The operating system operates on the processing unit 206. The operating system coordinates and controls various components within the data processing system 200 of FIG. 2. The operating system can be a commercially available operating system for any type of computing platform including, but not limited to, server systems, personal computers, and mobile devices. An object-oriented or other type of programming system operates in conjunction with the operating system and can provide calls to the operating system from programs or applications executed on the data processing system 200.

[0066] Instructions of the operating system, object-oriented programming system, and applications or programs such as application 105 of FIG. 1 are arranged on a storage device in the form of code 226A on the hard disk drive 226 and can be loaded into at least one of one or more memories such as the main memory 208 for execution by the processing unit 206. The processing of the exemplary embodiment can be executed by the processing unit 206 using, for example, computer-implemented instructions arranged in a memory such as the main memory 208, read-only memory 224, or one or more peripheral devices.

[0067] Furthermore, in some cases, the code 226A can be downloaded via the network 201A from a remote system 201B where similar code 201C is stored in the storage device 201D. In other cases, the code 226A can be downloaded via the network 201A to the remote system 201B where the downloaded code 201C is stored in the storage device 201D.

[0068] The hardware in FIGS. 1 and 2 may vary depending on the implementation form. Other internal hardware or peripheral devices such as flash memory, equivalent non-volatile memory, or optical disk drives may be used in addition to or instead of the hardware shown in FIGS. 1 and 2. Further, the processing of the exemplary embodiments may be applied to a multiprocessor data processing system.

[0069] In some exemplary examples, the data processing system 200 may generally be configured as a personal digital assistant (PDA) equipped with flash memory that provides non-volatile memory for storing operating system files or user-generated data or both. The bus system may include one or more buses such as a system bus, an I / O bus, and a PCI bus. Of course, the bus system may be implemented using any type of communication fabric or architecture, which realizes the transfer of data between various components or devices connected to that fabric or architecture.

[0070] The communication unit may include one or more devices used for transmitting and receiving data, such as a modem or a network adapter. The memory may be, for example, main memory 208 or a cache, such as the cache in the north bridge and memory controller hub 202. The processing unit may include one or more processors or CPUs.

[0071] The examples shown in FIGS. 1 and 2 and the above examples do not imply architectural limitations. For example, in addition to taking the form of a mobile device or a wearable device, the data processing system 200 may also be a tablet computer, a laptop computer, or a telephone device.

[0072] When describing a computer or data processing system as a virtual machine, virtual device, or virtual component, the virtual machine, virtual device, or virtual component operates like the data processing system 200 using a virtualized representation of some or all of the components illustrated within the data processing system 200. For example, in a virtual machine, virtual device, or virtual component, the processing unit 206 is represented as a virtualized instance of all or a portion of the hardware processing unit 206 available in the host data processing system, the main memory 208 is represented as a virtualized instance of all or a portion of the main memory 208 that may be available in the host data processing system, and the disk 226 is represented as a virtualized instance of all or a portion of the disk 226 that may be available in the host data processing system. The host data processing system in such a case is represented by the data processing system 200.

[0073] Referring to FIG. 3, this figure shows a block diagram of an exemplary configuration for access control based on key-specific fingerprints according to an exemplary embodiment. The application 300 is an example of the application 105 of FIG. 1 and is executed on any of the servers 104 and 106, clients 110, 112, and 114, and device 132 of FIG. 1.

[0074] The data collection module 310 collects biometric data and key data. One implementation of module 310 uses a biometric sensor coupled to a touch screen. The display component of the touch screen displays one or more virtual key areas, and each virtual key area is labeled with a character, number, or symbol that is input into the device when the data collection surface of the touch screen is touched. The second surface of the touch screen parallel to the data collection surface is coupled to a biometric sensor configured to collect fingerprint data. Thus, when the user's finger touches the data collection surface of the touch screen, the biometric sensor collects the fingerprint data of the user's finger. Also, the touch screen collects touch data, and a processor that executes software resolves the touch data into data of a single virtual key area touched by the user's finger during fingerprint collection. In one implementation of module 310, fingerprint data collection is triggered when the user's finger touches the data collection surface. In other implementations of module 310, fingerprint data collection is triggered by resolving touch data into data of a single virtual key area.

[0075] Other implementations of module 310 use a set of biometric sensors configured to collect fingerprint data, and each biometric sensor is coupled to a surface parallel to the data collection surface of the touch screen. Other implementations of module 310 use a set of biometric sensors, each of which is coupled to a physical key of a keypad. Thus, when the user's finger touches the data collection surface of the touch screen or a physical key, the biometric sensor collects the fingerprint data of the user's finger. Also, data is collected about which touch screen or physical key was touched by the user's finger during fingerprint collection.

[0076] Other implementations of module 310 use a biometric sensor configured to collect biometric data that is not fingerprint data. Some non-limiting examples of biometric data that is not a fingerprint include a portion of the surface of a user's hand or foot, a portion of a different area of the user's skin, and scan data of the iris or retina. Also, the biometric data need not be human.

[0077] The setting module 320 prompts the user to enter a desired password or PIN. The user enters the password by typing on each key using the desired finger on a physical key or in a virtual key area of a touch screen. During the entry of the desired password, if the user touches each key (physical or virtual) with a specific finger, module 310 collects both fingerprint and key data for each touch. Since the fingerprint of each finger of the user is different, the resulting stored password includes data about which finger was used to type which key. One implementation of module 320 rejects the user's desired password if the password, fingering sequence, or a combination of the password or fingering sequence is included in a list of passwords that are considered to be too easy to understand for use in access control. In other implementations of module 320, if the password, fingering sequence, or a combination of the password or fingering sequence has been used by other users more than a predetermined threshold number of times, this indicates that this password is too easy to understand or too easily guessed by others for use in access control, and the user's desired password is rejected.

[0078] Other implementations of module 320 prompt the user to enter a desired password or PIN. The user enters the password by typing on a physical key or a virtual key area on a touch screen. This implementation of module 320 does not require using a desired finger for each key during the setup phase; instead, it identifies the finger usage pattern of the password. Specifically, as part of the user's normal usage, while the user enters the password multiple times to access a protected resource, module 310 collects both fingerprint and key data for each touch. Module 320 stores the fingerprint data of each finger used to type the key while permitting the user to access the protected resource (if the entered password is correct). One implementation of module 320 determines that, as a usage pattern, the user has used the same finger to type a specific key (physical or virtual) more than a threshold number of times (i.e., the similarity between the collected fingerprint data exceeds a threshold). Other implementations of module 320 determine that, as a usage pattern, the user has used the same finger to type a specific key (i.e., the similarity between the collected fingerprint data exceeds a threshold) in more than a threshold percentage of all password entries. When module 320 identifies a usage pattern, application 300 switches to require using a specific consistent finger for the corresponding virtual key.

[0079] Module 320 stores, as fingerprint data for a specific finger, a randomly selected fingerprint such as a specific fingerprint, e.g., the first collected fingerprint, the most recently collected fingerprint when the usage pattern is identified, and the fingerprint data collected for the combination of that fingerprint and the virtual key, etc. Other implementations of module 320 store, as fingerprint data for a specific finger, a composite of the fingerprint data collected for the combination of that fingerprint and the virtual key.

[0080] Then, when a particular finger is associated with a particular physical or virtual key area, along with the corresponding fingerprint data, through settings or via usage patterns, the authentication module 330 prompts the user to enter their password or PIN by typing the password using the finger set for each key. During the input of the desired password, if the user touches each key with a particular finger, the module 310 collects both the fingerprint and key data for each touch. If the collected fingerprint data has a similarity exceeding a threshold with the user's stored fingerprint data associated with each key, and the module 330 determines that the key sequence matches the user's stored key sequence, the module 330 permits access to the protected resource. On the other hand, if the module 330 determines that the collected fingerprint data does not have a similarity exceeding the threshold with the user's stored fingerprint data associated with each key within the stored sequence, the module 330 blocks access to the protected resource.

[0081] Referring to FIG. 4, this figure shows a block diagram of an exemplary configuration for access control based on key - specific fingerprints according to an exemplary embodiment. Specifically, FIG. 4 shows further details of the module 310 of FIG. 3.

[0082] In one implementation of module 310, when using a biometric sensor coupled to a touch screen, the display component of the touch screen displays one or more virtual key areas, and each virtual key area is labeled with a character, number, or symbol that is input into the device when the data collection surface of the touch screen is touched. A second surface of the touch screen parallel to the data collection surface is coupled to a biometric sensor configured to collect fingerprint data. Thus, when the user's finger touches the data collection surface of the touch screen, the fingerprint collection module 410 collects the fingerprint data of the user's finger. Also, the virtual key area module 420 collects touch data and resolves the touch data into data of a single virtual key area touched by the user's finger during fingerprint collection. In one implementation of module 420, fingerprint data collection is triggered when the user's finger touches the data collection surface. In other implementations of module 420, fingerprint data collection is triggered by resolving the touch data into data of a single virtual key area.

[0083] Referring to FIG. 5, this figure shows a block diagram of an exemplary configuration for key-specific fingerprint-based access control according to an exemplary embodiment. Specifically, FIG. 5 shows further details of module 320 of FIG. 3.

[0084] The setup module 520 prompts the user to enter a desired password or PIN. The user enters the password by typing on each key using a desired finger on a physical key or a virtual key area of a touch screen. Since the fingerprint of each finger of the user is different, the resulting stored password includes data on which finger was used to type which key. One implementation of module 520 rejects the user's desired password if the password, finger sequence, or combination of password and finger sequence is included in a list of passwords that are considered too easy to use for access control. In other implementations of module 520, if the password, finger sequence, or combination of password and finger sequence has been used by other users more than a predetermined threshold number of times, this indicates that this password is too easy to use for access control or too easily guessed by others, and the user's desired password is rejected.

[0085] The learning module 510 identifies the fingerprint usage pattern of the password. Specifically, as part of the user's normal usage, while the user enters the password multiple times to access the protected resource, the module 310 collects both the fingerprint and key data for each touch. The module 510 stores the fingerprint data of each finger used to type the key while permitting the user to access the protected resource (if the entered password is correct). One implementation of the module 510 determines, as the usage pattern, that the user has used the same finger to type a specific key (physical or virtual) more than a threshold number of times (i.e., the similarity between the collected fingerprint data exceeds the threshold). Another implementation of the module 510 determines, as the usage pattern, that the user has used the same finger to type a specific key in more than a threshold percentage of all password entries (i.e., the similarity between the collected fingerprint data exceeds the threshold). When the module 510 identifies the usage pattern, the application 300 switches to request that a specific consistent finger be used for the corresponding virtual key.

[0086] Referring to FIG. 6, this figure shows an example of access control based on per-key fingerprints according to an exemplary embodiment. This example can be executed using the application 300 of FIG. 3. The device 132 and the touch screen 134 are the same as the device 132 and the touch screen 134 of FIG. 1.

[0087] Device 132 uses a biometric sensor (not shown) coupled to touch screen 134. The display component of touch screen 134 displays one or more virtual key areas, and each virtual key area is labeled with a character, number, or symbol that is input into device 132 when the data collection surface of the touch screen is touched. A second surface of touch screen 134 parallel to the data collection surface is coupled to a biometric sensor configured to collect fingerprint data. Thus, when the user's finger touches the data collection surface of touch screen 134, the biometric sensor collects fingerprint data of the user's finger. Also, touch screen 134 collects touch data, and a processor that executes software resolves the touch data into data of a single virtual key area touched by the user's finger during fingerprint collection. For example, as shown in the figure, the user touches virtual key area 611 with finger 602 to type "1", touches virtual key area 612 with finger 604 to type "2", touches virtual key area 613 with finger 606 to type "3", and touches virtual key area 610 with finger 608 to type "0" to enter his PIN. If the collected fingerprint data has a similarity exceeding a threshold with the user's memorized fingerprint data associated with each key, and application 300 determines that the key sequence "1230" matches the user's memorized key sequence, application 300 permits access to the protected resource. On the other hand, if application 300 determines that the collected fingerprint data does not have a similarity exceeding a threshold with the user's memorized fingerprint data associated with each key within the memorized sequence, this embodiment blocks access to the protected resource.

[0088] Referring to FIG. 7, this figure shows a flowchart of an exemplary process for access control based on key-by-key fingerprints according to an exemplary embodiment. Process 700 can be implemented in application 300 of FIG. 3.

[0089] In block 702, the application uses a biometric sensor coupled to the touch screen to collect fingerprint data from within a plurality of key areas of the touch screen. In block 704, the application determines whether the collected biometric data has a similarity exceeding a threshold with stored biometric data associated with the same key area. If yes (the "YES" path of block 704), in block 706, the application determines whether the sequence of key areas matches the stored key sequence. If yes (the "YES" path of block 706), in block 708, the application permits access to the protected resource. Otherwise (the "NO" paths of blocks 704 and 706), in block 710, the application blocks access to the protected resource. And the application terminates.

[0090] Referring now to FIG. 8, an exemplary cloud computing environment 50 is shown. As illustrated, cloud computing environment 50 includes one or more cloud computing nodes 10 with which local computing devices used by cloud consumers, such as, for example, a personal digital assistant (PDA) or cellular telephone 54A, desktop computer 54B, laptop computer 54C, or automotive computer system 54N, or a combination thereof, may communicate. Nodes 10 may communicate with one another. These may be physically or virtually grouped (not shown) in one or more networks, such as, for example, the private, community, public, or hybrid clouds described above, or a combination thereof. This allows cloud computing environment 50 to provide infrastructure as a service, platform as a service, or software as a service, or a combination thereof, such that a cloud consumer need not maintain resources on a local computing device. It is intended that the types of computing devices 54A-N shown are exemplary only, and that cloud computing nodes 10 and cloud computing environment 50 can communicate with any type of computerized device via any type of network or network addressable connection (e.g., using a web browser) or both.

[0091] Referring now to FIG. 9, a set of functional abstractions provided by cloud computing environment 50 (FIG. 8) is shown. It is intended that the components, layers, and functions shown are exemplary only and that embodiments of the invention are not limited thereto. As illustrated, the following layers and corresponding functions are provided.

[0092] The hardware and software layer 60 includes hardware components and software components. Examples of hardware components include mainframe 61, RISC (Reduced Instruction Set Computer) architecture-based server 62, server 63, blade server 64, storage device 65, and network and networking components 66. In some embodiments, the software components include network application server software 67 and database software 68.

[0093] The virtualization layer 70 provides an abstraction layer from which the following examples of virtual entities can be provided: virtual server 71, virtual storage 72, virtual network 73 including a virtual private network, virtual applications and operating systems 74, and virtual clients 75.

[0094] In one example, the management layer 80 can provide the following functions. Resource provisioning 81 provides for the dynamic procurement of computing resources and other resources utilized to execute tasks within a cloud computing environment. Metering and pricing 82 provides for expense tracking when resources are utilized within a cloud computing environment and accounting or billing for the consumption of these resources. In one example, these resources can include application software licenses. Security provides not only ID verification of cloud consumers and tasks but also protection for data and other resources. The user portal 83 provides access to the cloud computing environment for consumers and system administrators. Service level management 84 provides for the allocation and management of cloud computing resources such that the required service level is met. Planning and fulfillment of service level agreements (SLAs) 85 provides for the advance arrangement and procurement of cloud computing resources expected to be required in the future according to the SLA.

[0095] The workload layer 90 provides examples of functionality that can be utilized in a cloud computing environment. Examples of workloads and functions that can be provided from this layer include mapping and navigation 91, software development and lifecycle management 92, virtual classroom education delivery 93, data analysis processing 94, transaction processing 95, and application selection based on cumulative vulnerability risk assessment 96.

[0096] Thus, in an exemplary embodiment, a computer-implemented method, system or apparatus, and a computer program for access control based on key-by-key fingerprints, and other related features, functions, or operations are provided. When describing an embodiment or a part thereof with respect to a certain type of device, the computer-implemented method, system or apparatus, computer program, or a part thereof is adapted or configured to be used with an appropriate and equivalent representation of that type of device.

[0097] When describing an embodiment as implemented in an application, delivery of the application in a software-as-a-service (SaaS) model is contemplated within the scope of the exemplary embodiments. In the SaaS model, the functionality of the application implementing an embodiment is provided to users by running the application on cloud infrastructure. Users can access the application using various client devices via a thin-client interface such as a web browser (e.g., web-based email) or other lightweight client applications. The user does not manage or control the underlying cloud infrastructure, including the cloud infrastructure's network, servers, operating systems, or storage. In some cases, the user may not even manage or control the functionality of the SaaS application. In some other cases, the SaaS implementation of the application may permit limited exceptions for user-specific application configuration settings.

[0098] The present invention can be a system, a method, or a computer program, or combinations thereof, at any possible technical detail level of integration. A computer program product can include a computer-readable storage medium (or media) having thereon computer-readable program instructions for causing a processor to execute aspects of the present invention.

[0099] A computer-readable storage medium can be a tangible device that can hold and store instructions for use by an instruction execution device. A computer-readable storage medium can be, for example, but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination thereof. A non-exhaustive list of more specific examples of computer-readable storage media includes portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital versatile disk (DVD), memory stick (R), floppy disk (R), mechanically encoded devices such as punch cards or raised structures in grooves in which instructions are recorded, and any suitable combination thereof. A computer-readable storage medium, as used herein, should not be construed to be a transient signal per se, such as, for example, radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission medium (e.g., optical pulses passing through an optical fiber cable), or electrical signals transmitted through a wire.

[0100] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to respective computing / processing devices, or to an external computer or external storage device via a network such as, for example, the Internet, a local area network, a wide area network, or a wireless network, or a combination thereof. The network can include copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers, or edge servers, or a combination thereof. The network adapter card or network interface of each computing / processing device receives the computer-readable program instructions from the network and transfers the computer-readable program instructions to be stored in a computer-readable storage medium within each respective computing / processing device.

[0101] The computer-readable program instructions for carrying out the operations of the present invention may be source code or object code written in any combination of one or more programming languages, including assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, configuration data for integrated circuits, or object-oriented programming languages such as Smalltalk(R), C++, and procedural programming languages such as the "C" programming language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (for example, via the Internet using an Internet service provider). In some embodiments, an electronic circuit, including, for example, a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA), may utilize the state information of the computer-readable program instructions to execute the computer-readable program instructions in order to personalize the electronic circuit for an individual, in order to carry out aspects of the present invention.

[0102] Aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer programs according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0103] These computer-readable program instructions, when executed via the processor of a computer or other programmable data processing apparatus, may create means for causing the functions / operations specified in one or more blocks of a flowchart, a block diagram, or both to be implemented, and thus may provide a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus with the means to create a machine. Also, these computer-readable program instructions may be stored in a computer-readable storage medium that includes a product containing instructions for implementing the functions / operations as specified in one or more blocks of a flowchart, a block diagram, or both, so as to direct a computer, a programmable data processing apparatus, or other device, or a combination thereof, to function in a particular manner.

[0104] Furthermore, these computer-readable program instructions may be loaded onto a computer, other programmable apparatus, or other device to create a process executed by the computer for causing the instructions executed thereon to implement the functions / operations specified in one or more blocks of a flowchart, a block diagram, or both, and thus may cause a series of operational steps to be executed on the computer, other programmable apparatus, or other device.

[0105] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer programs according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, segment, or portion of one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the blocks may be performed out of the order noted in the figures. For example, depending on the functionality involved, two blocks shown in succession may in fact be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order. It will also be noted that each block of the block diagrams or flowchart diagrams, or combinations of blocks in the block diagrams or flowchart diagrams or both, can be implemented by a dedicated hardware-based system that performs the specified function or operation, or combinations of dedicated hardware and computer instructions.

Explanation of Signs

[0106] 102 Network 104 Server 105 Application 106 Server 108 Storage 110 Client 112 Client 114 Client 132 Device 134 Touch Screen 136 Biometric Sensor 138 Biometric Sensor 201A Network 201B Remote System 201C Code 201D Storage 202 NB / MCH 204 SB / ICH 206 Processing Unit 208 Main Memory 210 Graphic Processor 212 Network Adapter 216 Audio Adapter 220 Keyboard and Mouse Adapter 222 Modem 224 ROM 226 Disk 226A Code 230 CD-ROM 232 USB and Other Ports 234 PCI / PCIe Device 236 SIO 238 Bus 240 Bus 310 Data Collection Module 320 Setup Module 330 Authentication Module 410 Fingerprint Collection Module 420 Virtual Key Area Module 510 Learning Module 520 Setup Module 602 Finger 604 Finger 606 Finger 608 Finger 610 Virtual Key Area 611 Virtual Key Area 612 Virtual Key Area 613 Virtual Key Area

Claims

1. A method implemented by a computer, comprising: in a setting phase for causing the computer to store a password for permitting access to a protected resource, collecting first fingerprint data from a plurality of virtual key areas of the touch screen when a user inputs the password a plurality of times, using a biometric sensor coupled to the touch screen, wherein each virtual key area within the plurality of virtual key areas comprises an area of the touch screen configured to display an input prompt and collect touch data in response to the input prompt; further comprising identifying a fingering sequence used when the password is input a plurality of times by analyzing the first fingerprint data, wherein the fingering sequence is a sequence of specific fingers used in specific ones of the virtual key areas; further comprising requiring use of the fingering sequence when inputting the password in response to determining that the fingering sequence has not been used by another user more than a predetermined threshold number of times; the method further comprising, after the setting phase, collecting second fingerprint data from the plurality of virtual key areas of the touch screen using the biometric sensor coupled to the touch screen; and permitting access to the protected resource in response to determining that the fingering sequence used for inputting the second fingerprint data has a similarity exceeding the threshold with the required fingering sequence and that the sequence of the virtual key areas matches the password.

2. Blocking access to the protected resource in response to determining that the fingering sequence used for inputting the second fingerprint data does not have a similarity exceeding the threshold with the required fingering sequence further comprising the method according to claim 1.

3. Collecting a set of training fingerprint data from a set of the virtual key areas of the touch screen using the biometric sensor, wherein each member of the set of training fingerprint data is associated with a virtual key area within the set of virtual key areas Further, in response to determining that the mutual similarity of members of a subset of the set of training fingerprint data associated with a particular virtual key area exceeds a threshold, storing the subset as stored fingerprint data, wherein the stored fingerprint data is associated with the particular virtual key area, the method according to claim 1.

4. The method according to claim 3, wherein the subset includes members of the set of training fingerprint data.

5. The method according to claim 3, wherein the subset includes a composite of a plurality of members of the set of training fingerprint data.

6. The method according to claim 1, wherein the collecting is triggered by detecting the touch data within the virtual key area.

7. The method according to claim 1, wherein the biometric sensor is coupled to a first surface of the touch screen, and the virtual key area includes a portion of a second surface of the touch screen configured to display the input prompt and collect the touch data.

8. A computer program comprising program instructions for causing a computer to execute the method according to any one of claims 1 to 7.

9. The computer program according to claim 8, wherein the program instructions are stored in at least one of one or more storage media of a local data processing system, and the program instructions are transferred from a remote data processing system via a network.

10. The computer program according to claim 8, wherein the program instructions are stored in at least one of one or more storage media of a server data processing system, and the program instructions are downloaded via a network to a remote data processing system and used in a computer-readable storage device associated with the remote data processing system.

11. The computer program according to claim 8, wherein the computer program is provided as a service within a cloud environment.

12. A computer system comprising one or more processors, one or more computer-readable memories, one or more computer-readable storage devices, and program instructions, wherein the program instructions are stored in at least one of the one or more storage devices and are executed by at least one of the one or more processors using at least one of the one or more memories to cause the computer system to perform the method according to any one of claims 1 to 7.

13. A storage medium storing the computer program according to claim 8 on a computer-readable storage medium.

14. A method implemented by a computer, comprising: Collecting fingerprint data from within a plurality of virtual key areas of the touch screen using a biometric sensor coupled to the touch screen, wherein the virtual key areas within the plurality of virtual key areas comprise areas of the touch screen configured to display an input prompt and collect touch data in response to the input prompt. The method further comprises: In response to determining that the fingerprint data has a similarity exceeding a threshold with stored fingerprint data associated with each of the virtual key areas and that the sequence of the virtual key areas matches a stored key sequence, permitting access to a protected resource. Further, collecting a set of training fingerprint data from the set of virtual key areas of the touch screen using the biometric sensor, wherein each member of the set of training fingerprint data is associated with a virtual key area within the set of virtual key areas. Further, in response to determining that the mutual similarity of the members of a subset of the set of training fingerprint data associated with a particular virtual key area exceeds a threshold, storing the subset as the stored fingerprint data, wherein the stored fingerprint data is associated with the particular virtual key area.

15. The method according to claim 14, wherein the subset comprises a member of the set of training fingerprint data or a composite of a plurality of members.

Citation Information

Patent Citations

  • Personal identification system by fingerprint

    JP2004110839A

  • Personal identification system, personal authentication method and storage medium

    JP2006085559A

  • Electric equipment and control method of electric equipment

    JP2008197995A

  • Personal digital assistant, personal digital assistant authentication method and personal digital assistant authentication program

    JP2009048418A

  • Biometric device and biometric system

    JP2010250475A