Biometric authentication through vascular monitoring
By utilizing vascular dynamics for authentication through electromagnetic radiation, the system addresses impersonation concerns and inconvenience of direct hand scanning, offering secure and contactless verification.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- JVC KENWOOD CORP
- Filing Date
- 2021-11-18
- Publication Date
- 2026-04-28
AI Technical Summary
Vascular pattern authentication systems are susceptible to impersonation and require direct access to the back of the hand, which can be inconvenient or burdensome in certain situations.
Authentication is based on vascular dynamics, monitoring temporal changes in blood vessel properties using electromagnetic radiation emitted and sensed from a distance, allowing for contactless and minimally disruptive biometric verification.
Provides high accuracy and reliability while reducing susceptibility to impersonation, enabling secure authentication without direct contact or exposure of the hand.
Smart Images

Figure 0007852636000001 
Figure 0007852636000002 
Figure 0007852636000003
Abstract
Description
Technical Field
[0001] (Cross - reference to Related Applications) This application claims the priority of U.S. Provisional Application No. 63 / 115,941, filed on November 19, 2020, entitled "Arterial Pocket Authentication", which is hereby incorporated by reference in its entirety.
[0002] (Technical Field) This disclosure relates to biometric authentication in computer security, and more specifically, to technologies where physiological characteristics are examined to enable minimally disruptive authentication.
Background Art
[0003] Biometric authentication procedures confirm an individual's identity (personal identification) through biometrics. The term "biometric" refers to physical or behavioral characteristics that can be used as a means of personal identification. Biometrics are difficult to forge and are convenient because the corresponding individual does not need to remember a password or manage a token. Instead, the authentication mechanism is part of the individual.
[0004] Fingerprints are historically the most common biometric modality. However, with the evolution of technology, other biometric modalities have emerged. As an example, vascular pattern recognition (also called "venous pattern authentication") uses near - infrared light to create an image of subcutaneous blood vessels. These subcutaneous blood vessels are collectively referred to as "vascular patterns", which can be used for authentication. Venous pattern authentication is promising because the vascular pattern is not only unique to the corresponding individual but also changes little with the age of that individual.
[0005] Vein pattern authentication typically requires identifying and then analyzing the vascular pattern along the back of the hand. For example, near-infrared light emitted from a light-emitting diode (LED) is shone towards the back of the hand and penetrates the skin. Due to differences in absorbance between blood vessels and other tissues, the near-infrared light is reflected back towards the skin at different depths. Based on the analysis of the reflected near-infrared light, the vascular pattern can be inferred, and features such as branching locations and angles can be identified from the vascular pattern (and can even be used for authentication).
[0006] Because it is difficult to reproduce vascular patterns, vein pattern authentication is attracting attention as a relatively contactless biometric authentication method that is less susceptible to forgery. However, vein pattern authentication has several drawbacks. Although it does not require touching the sensing surface like fingerprint authentication, the back of the hand must be presented for analysis. This can be difficult in some situations (for example, when the individual is not near the payment system) and may simply be burdensome in other situations (for example, when the individual is wearing gloves). [Brief explanation of the drawing]
[0007] [Figure 1] Figure 1 includes a high-level diagram of a conventional authentication procedure in which an unknown person is prompted to present their hand to a vascular scanner.
[0008] [Figure 2A] Figure 2A includes a high-level representation of a system that can be used to authenticate the identity of an unknown person whose vascular system can be scanned.
[0009] [Figure 2B] Figure 2B includes a high-level representation of a system that can be used to authenticate the identity of an unknown person based on gesture recognition.
[0010] [Figure 2C] Figure 2C includes a high-level representation of a system that can be used to authenticate the identity of an unknown person based on location recognition.
[0011] [Figure 3] Figure 3 shows an example of an electronic device that can implement an authentication platform designed to authenticate an unknown person based on data generated by a signal sensor.
[0012] [Figure 4A] Figures 4A-B include a flowchart of the procedure for authenticating users of an authentication platform based on radar detection of vascular dynamics monitored using electronic devices positioned in close proximity to the body. [Figure 4B] Figures 4A-B include a flowchart of the procedure for authenticating a user of an authentication platform based on radar detection of vascular dynamics monitored using electronic devices positioned in close proximity to the body.
[0013] [Figure 5A] Figures 5A-B include flowcharts of the registration and usage phases in an embodiment in which the authentication platform determines whether or not to authenticate a user based on gesture recognition. [Figure 5B] Figures 5A-B include flowcharts of the registration and usage phases in an embodiment in which the authentication platform determines whether or not to authenticate a user based on gesture recognition.
[0014] [Figure 6A] Figures 6A-B include flowcharts of the registration and usage phases in an embodiment in which the authentication platform determines whether or not to authenticate a user based on location recognition. [Figure 6B] Figures 6A-B include flowcharts of the registration and usage phases in an embodiment in which the authentication platform determines whether or not to authenticate a user based on location recognition.
[0015] [Figure 7A] Figures 7A-B include a flowchart of the registration and usage phases of an example of a vascular dynamics-dependent authentication procedure. [Figure 7B] Figures 7A-B include flowcharts of the registration and usage stages of an example of an authentication procedure that depends on blood vessel dynamics.
[0016] [Figure 8] Figure 8 includes an explanatory diagram of a scenario where authentication of an unknown person occurs even though the unknown person leaves an electronic device in the front pocket of their pants.
[0017] [Figure 9] Figure 9 shows an example of a schematic implementation of an authentication platform that can authenticate an unknown person based on the blood vessel dynamics of the blood vessels.
[0018] [Figure 10] Figure 10 shows a flowchart of a process for biometrically authenticating that a person claiming to be a certain individual is indeed that person.
[0019] [Figure 11] Figure 11 shows a flowchart of a process for generating a biometric signature of an individual that can then be used for authentication.
[0020] [Figure 12] Figure 12 shows a flowchart of a process for determining whether to authenticate a person as a certain individual based on the blood vessel dynamics of the blood vessels over time.
[0021] [Figure 13] Figure 13 is a block diagram showing an example of a processing system in which at least some of the operations described herein can be implemented.
[0022] Various features of the technology described herein will become more apparent to those skilled in the art from the detailed description accompanied by the drawings. Embodiments are shown in the drawings as examples, without limitation. Although the drawings depict various embodiments for illustrative purposes, those skilled in the art will recognize that alternative embodiments can be adopted without departing from the principles of the art. Thus, although specific embodiments are shown in the drawings, the art is subject to various modifications. [Modes for carrying out the invention]
[0023] To register for an authentication program that relies on vein matching, an individual (also called a "user") may first be prompted to present their hand to a vascular scanner. The term "vascular scanner" may be used to refer to an imaging device that includes (i) an emitter capable of emitting electromagnetic radiation (e.g., in the near-infrared range) into the body, and (ii) a sensor capable of sensing electromagnetic radiation reflected by physiological structures within the body. Typically, an image is created based on the reflected electromagnetic radiation, which serves as a reference template. At a high level, the reference template represents a "grand truth" vascular pattern that can be used for authentication.
[0024] Figure 1 includes a high-level diagram of a conventional authentication procedure in which an unknown person is prompted to present their hand to a vascular scanner. As shown in Figure 1, the vascular scanner emits electromagnetic radiation to the hand and then creates an image (also called a “scan”) based on the electromagnetic radiation reflected by the blood vessels in the hand. This image represents the vascular pattern of the hand and can therefore be matched against a reference template created by a given individual during the enrollment phase (also called the “registration phase”). If the image matches the reference template, the unknown person is authenticated as the given individual. However, if the image does not match the reference template, the unknown person is not authenticated as the given individual.
[0025] Because vascular scanners do not require touching the body part being scanned, vein matching has become an attractive option for biometric authentication. However, vein matching has been shown to be susceptible to impersonation. For example, Jan Krissler and Julian Albrecht demonstrated at the 2018 Chaos Communication Congress that vascular scanners could be bypassed using a fake hand made of wax. While impersonation is unlikely to succeed under most real-world conditions, concerns related to vulnerabilities could hinder the adoption of trusted biometric authentication techniques.
[0026] Therefore, the approach described here is to authenticate an unknown person based on changes in the properties of blood vessels over time. At a high level, these approaches rely on monitoring vascular dynamics to recognize an unknown person. The term "vascular dynamics" refers to the temporal changes in the properties of blood vessels. Examples of properties include the location, size, volume, and pressure of the vessels, as well as the velocity and acceleration of the blood flowing through them.
[0027] To prevent impersonation, an authentication platform (also called an “authentication system”) may determine the degree to which the vascular dynamics of an unknown person whose identity should be authenticated are similar to those of a given individual. For example, suppose an unknown person wishes to authenticate themselves as a given individual. In such a scenario, the unknown person may be prompted to place a part of their body near a vascular scanner. The vascular scanner then emits a series of signals to the body part, which may then generate data representing the signals reflected by physiological structures, including blood vessels, located in that part of the body. By analyzing the data, the authentication platform may determine, derive, or obtain a metric that indicates the vascular dynamics of the unknown person. This metric may be called the unknown person’s “biometric signature” or “vascular signature.” The authentication platform may then compare the biometric signature to at least one registered biometric signature associated with a given individual in order to determine whether the unknown person should be authenticated as a given individual. Thus, based on the comparison of their vascular dynamics, the authentication platform can establish the likelihood that the unknown person is the given individual.
[0028] Because the "readable" information resides within the body, vasodynamic authentication offers many of the same advantages as vein matching: high accuracy, reliability, and consistency. However, because vasodynamic authentication can use both vascular patterns and changes in vascular characteristics as unique biometrics, it is less susceptible to impersonation.
[0029] For illustrative purposes, embodiments may be described in the context of monitoring the vascular dynamics of the femoral artery. However, the approach described herein may be equally applicable to any artery, arteriole, capillary, venule, or vein. Similarly, the approach described herein may be equally applicable to any set of blood vessels. Therefore, in situations where authentication is required for highly sensitive tasks, an authentication platform may monitor the vascular dynamics of multiple blood vessels.
[0030] While not mandatory, implementation is described below in the context of instructions that can be executed by electronic devices. The term “electronic device” is generally used interchangeably with the term “computing device” and can therefore be used to refer to computer servers, POS systems, tablet computers, wearable devices (e.g., fitness trackers and watches), mobile phones, etc.
[0031] While certain aspects of this technology, such as specific modules, may be described as being performed exclusively or independently by a single electronic device, some implementations run in a distributed environment where modules are shared among multiple electronic devices linked via a network. For example, an unknown person may be prompted by a POS system to initiate an authentication procedure, while the measurement of vascular dynamics may be performed by a mobile phone placed in close proximity to the unknown person. Similarly, a mobile phone may be responsible for measuring the vascular dynamics of an unknown person, but the decision of whether or not to authenticate the unknown person may be made by an authentication platform residing on a computer server to which the mobile phone is communicably connected. [term]
[0032] References to “one embodiment” or “several embodiments” in this disclosure mean that the features, functions, structures, or characteristics described are included in at least one embodiment. The appearance of such phrases does not necessarily refer to the same embodiment, nor does it necessarily refer to alternative embodiments that are mutually exclusive.
[0033] Unless otherwise clearly indicated by the context, the terms “equipped,” “equipped,” and “consisting of” shall be interpreted in a comprehensive, not exclusive, sense (i.e., “including but not limited to”). Similarly, the term “based on” shall be interpreted in a comprehensive, not exclusive, sense. Therefore, unless otherwise specified, the term “based on” is intended to mean “based on at least partially.”
[0034] The terms “connected,” “joined,” and their variations are intended to include any connection or joining, directly or indirectly, between two or more elements. The connection / joining can be physical, logical, or a combination thereof. For example, elements may be electrically or communicatively joined to one another even if they do not share a physical connection.
[0035] The term "module" can broadly refer to software, firmware, and / or hardware. A module is typically a functional component that produces one or more outputs based on one or more inputs. A computer program may contain or utilize one or more modules. Thus, a computer program may utilize multiple modules responsible for completing different tasks, or a single module responsible for completing all tasks.
[0036] When used in relation to a list of multiple items, the term "or" is intended to cover all interpretations: any of the items in the list, all items in the list, and any combination of items in the list. The term "and / or" is interpreted similarly. For example, suppose an embodiment is described as including "a first item, a second item, and / or a third item." In such a context, the phrase is intended to cover the first item individually, the second item individually, the third item individually, a combination of the first and second items, a combination of the first and third items, and a combination of the second and third items.
[0037] The order of steps performed in any of the processes described herein is illustrative. However, steps can be performed in various orders and combinations, as long as it does not conflict with physical feasibility. For example, steps can be added to or removed from the processes described herein. Similarly, steps can be replaced or their order can be changed. Thus, any description of a process is intended to be open-ended. [Authentication through vascular information analysis]
[0038] The authentication platform described here utilizes vascular dynamics as biometric proof that an unknown person is a designated individual. As will be described later, the vascular dynamics of an unknown person can be measured using probing signals emitted from the body. The reflection of these probing signals can be detected by sensors placed in close proximity to the body. These reflections can represent "return signals" that can determine variations in vascular characteristics.
[0039] Authentication platforms can be used to protect biometric-driven transactions, such as payments authorized via a hands-free interface. For example, suppose an unknown person wants to authenticate themselves to complete a transaction. Instead of prompting the unknown person to place a part of their body (e.g., their hand) near a vascular scanner, biometric authentication can instead be performed using an electronic device already positioned close to their body. For example, the electronic device could be placed in a pocket of clothing worn on the body. As an example, a cell phone in the pocket of a trouser worn by an unknown person might include an emitter capable of emitting a probing signal and a sensor capable of detecting the probing signal reflected by physiological structures within the body. This authentication approach relies on the analysis of blood vessels beneath the skin, but the cell phone does not need to touch the skin, nor does the cell phone need to "see" the skin. In this way, authentication platforms can enable individuals to authenticate themselves in a minimally destructive manner by relying on information about vascular dynamics.
[0040] Several different approaches to authentication are described in more detail below. These approaches are: • Vascular pattern authentication: Authentication is based on the pattern of blood vessels determined from the return signal; • Vascular dynamics authentication: Authentication is based on the characteristics of the measured blood vessels; and • Vascular deformation authentication: Authentication is based on the characteristics of blood vessels measured when an unknown person interacts with the environment, for example by making gestures that cause deformation of blood vessels. Includes.
[0041] In one embodiment, the authentication platform operates independently to authenticate the identity of an unknown person, while in other embodiments, the authentication platform operates in conjunction with other systems. For example, a payment system may interface with the authentication platform to ensure that transactions are completed in a secure and hassle-free manner. As an example, the authentication platform may facilitate contactless payment procedures in which an unknown person is permitted to initiate or complete a transaction by enabling scanning of a part of their body. As described above, an unknown person may make a part of their body available for scanning simply by placing a vascular scanner near their body (for example, in the pocket of trousers worn by the unknown person).
[0042] While in some embodiments, authentication may be discussed in the context of initiating or completing a transaction, it should be noted that authentication is useful in a variety of contexts. For example, suppose a group of individuals are invited to a network-accessible meeting where confidential information is shared. Each person attempting to join the network-accessible meeting may need to be authenticated by an authentication platform before access is granted. [Overview of the Authentication Platform]
[0043] Figure 2A includes a high-level representation of system 200A, which can be used to authenticate the identity of an unknown person whose vascular system can be scanned. As shown in Figure 2A, system 200A includes an authentication platform 202A that has access to a user interface (UI) 204, a signal emitter 206, a signal sensor 208, and a processor 210. As will be further described below, these elements of system 200A can be embedded in the same electronic device or distributed across multiple electronic devices. For example, the authentication platform 202A may reside, partially or entirely, on a network-accessible server system, while the UI 204, signal emitter 208, signal sensor 208, and processor 210 may reside on separate electronic devices positioned in close proximity to the unknown person.
[0044] UI204 represents an interface through which an unknown person can interact with system 200. UI204 may be a voice-driven graphical user interface (GUI) displayed on the display of an electronic device. Alternatively, UI204 may be a non-voice-driven GUI displayed on the display of an electronic device. In such embodiments, UI204 may visually indicate body parts to be presented for authentication. For example, UI204 may visually prompt an unknown person to present their hand to signal emitter 206 and signal sensor 208 for scanning by presenting an illustration of the same.
[0045] The signal emitter 206 (also called the “signal generator”) may be configured to emit electromagnetic radiation in the form of pulses to a body part presented by an unknown person. For example, suppose UI 204 indicates that the unknown person presents their hand for authentication. In such a scenario, the signal emitter 206 may emit a signal to the hand over a period of time. Typically, this period is between 0.1 and 1.0 second, but in some embodiments it may be longer or shorter. Meanwhile, the signal sensor 208 may be any sensing device capable of generating data representing signals reflected by physiological structures located within the body. At a high level, the signal emitter 206 may be responsible for emitting a signal into the body over a period of time, and the signal sensor 208 may be responsible for collecting the reflection of the signal. For convenience, the signal emitted into the body may be called a “probing signal” or “measurement signal,” and the reflection of that signal may be called a “return signal.”
[0046] Those skilled in the art will recognize that reflection occurs at the surface to which a signal is incident. Reflective surfaces are typically the boundaries between two structures with different electromagnetic properties (e.g., blood vessels and tissue). Ideally, the sensing device should be able to detect the return signal with sufficient resolution to distinguish small differences (e.g., on a micrometer scale) in order to detect changes in the properties of blood vessels, as will be further discussed below. For example, in large arterial vessels with wall diameters of 0.5 to 1.0 millimeters, a resolution on a scale of several tens of micrometers is usually sufficient to detect changes due to changes in blood flow. Smaller vessels tend to require higher resolution, e.g., a resolution on a scale of less than a micrometer.
[0047] In some embodiments, the signal emitter 206 and signal sensor 208 are part of an active sensing system. The active sensing system may be an integrated circuit (IC) designed to emit and sense electromagnetic radiation within a given frequency range (e.g., 6–8 gigahertz (GHz), 6–8.5 GHz, 6–9 GHz). ICs that emit and sense electromagnetic radiation over a wider frequency range (e.g., wider than 2 GHz) may be called "ultra-wideband (UWB) ICs".
[0048] In particular, the signal emitter 206 and signal sensor 208 can work together to acquire information about the vascular system (and more specifically, the characteristics of a particular blood vessel) at a distance, even through obstacles. Therefore, an unknown person to be authenticated may not need to actually touch the signal emitter 206 or signal sensor 208, as will be discussed further below.
[0049] As described above, the signal emitter 206 and signal sensor 208 may be incorporated into a single electronic device. In some embodiments, the electronic device is associated with an unknown person. For example, the signal emitter 206 and signal sensor 208 may be incorporated into a mobile phone associated with an unknown person. In other embodiments, the electronic device is not associated with an unknown person. For example, the signal emitter 206 and signal sensor 208 may be incorporated into a POS system through which an unknown person is attempting to complete a transaction.
[0050] As shown in Figure 2A, the authentication platform 202A may include a vascular dynamics (VD) signal characterization algorithm 212, a return signal evaluation algorithm 214, a VD signature processing algorithm 216, an authentication algorithm 218, and a biometric database 220. The biometric database 220 may store biometric data representing collected information related to vascular characteristics that can be used to identify a known person. As will be further described below, the biometric data in the biometric database 220 may vary depending on the authentication approach employed by the system 200A. The biometric data in the biometric database 220 may be encrypted, hashed, or obfuscated to prevent unauthorized access.
[0051] For example, in an embodiment in which the authentication platform 200A determines whether authentication is appropriate based on vascular dynamics, the biometric database 220 may include reference values for different vascular characteristics. Thus, the biometric database 220 may include data showing the temporal changes in vascular characteristics for a given blood vessel. As will be further explained below, this data can be used for authentication because the temporal changes are not only uniquely associated with an individual but can also vary across different blood vessels of that individual.
[0052] As another example, the biometric database 220 may include models showing the deformation of a given blood vessel when a gesture is performed by a given individual or by different individuals. Each model may represent a set of discrete locations showing how the shape of the given blood vessel changed over time when the gesture was performed. These models may be stored in profiles associated with different individuals. A profile may include a single model associated with a single gesture, multiple models associated with a single gesture, or multiple models associated with different gestures.
[0053] Therefore, the biometric database 220 may contain one or more biometric signatures. Each biometric signature may represent one or more values indicating the temporal changes in the vascular characteristics of a given blood vessel of a given individual. For example, a biometric signature may have a vector of length N, where each element is an intensity value based on the magnitude of the frequency shift between a probing signal and a corresponding return signal, thereby indicating the amplitude of vibration of the blood vessel wall. N may represent the number of samples acquired over time. In other words, N may represent the number of probing signals emitted within the body during the authentication procedure.
[0054] A biometric signature in the biometric database 220 may be associated with a single individual, in which case the authentication platform 202A may be limited to authenticating an unknown person as that individual. Alternatively, these biometric signatures may be associated with multiple individuals, in which case the authentication platform 202A may be able to authenticate an unknown person as any of those individuals. Thus, a single individual may have multiple biometric signatures in the biometric database 220. These biometric signatures may correspond to different blood vessels and / or different electronic devices used for retrieval. For example, a single electronic device (e.g., a mobile phone) may be positioned in proximity to multiple anatomical regions (e.g., in different pockets), and a different biometric signature may exist for each anatomical region. As another example, an individual may be associated with multiple electronic devices (e.g., a mobile phone and a wearable device), and a different biometric signature may exist for each electronic device.
[0055] In some embodiments, each biometric signature is assigned a quality rating indicating how reliable that biometric signature is for authentication. The quality rating may be based on factors such as the signal-to-noise ratio (SNR) of the original return signal and the reproducibility of the original measurement. In embodiments where multiple biometric signatures are used for authentication, corresponding quality ratings may be used to establish appropriate weights for these biometric signatures. At a high level, these biometric signatures with higher quality ratings may be assigned more weights.
[0056] When executed by processor 210, the algorithm implemented in authentication platform 202A enables individuals to generate biometric signatures during the registration phase. Subsequently, the algorithm implemented in authentication platform 202A enables verification during the usage phase. The registration and usage phases are further described below with reference to Figures 4A-4B.
[0057] The VD signal characterization algorithm 212 can be used to define the characteristics of a probing signal emitted within the body of an unknown person to be authenticated. For example, the VD signal characterization algorithm 212 may define characteristics of the probing signal such as frequency (e.g., to control penetration depth), amplitude (e.g., to return a stronger signal with a higher risk of noise), samples / second, emission timing, emission duration, or any combination thereof. The VD signal characterization algorithm 212 can take any of the following as input: Characteristics of electronic devices, such as known location or power availability; Characteristics of the signal emitter 206, such as power requirements, maximum radiation magnitude, or maximum radiation frequency; • Characteristics of the signal sensor 208, such as power requirements, sensitivity, and frequency range; or For example, an output generated by the return signal evaluation algorithm 214 that indicates a problem with data acquisition.
[0058] The return signal evaluation algorithm 214 may also be responsible for evaluating the return signals by examining the data generated by the signal sensor 208. For example, the return signal evaluation algorithm 214 may evaluate each return signal to generate and then assign a quality evaluation. If one or more return signals are deemed unacceptable (for example, based on the corresponding quality evaluation), the return signal evaluation algorithm 214 may prompt the VD signal characteristic algorithm 212 to modify one or more characteristics of the probing signal. For example, the return signal evaluation algorithm 214 may trigger the VD signal characteristic algorithm 212 to modify the probing signal in response to discovering that a certain number or percentage of the return signals are unacceptable. The data acquisition process can then be restarted. Thus, the return signal evaluation algorithm 214 may initiate a feedback loop to optimize the characteristics of the probing signal.
[0059] The VD signature processing algorithm 216 may be responsible for examining the data generated by the signal sensor 208 and generating a biometric signature that can be used for authentication. As further described below, a biometric signature can be created during (i) the registration phase in which an individual registers with an authentication program supported by the authentication platform 202A, and (ii) the usage phase in which an unknown person is authenticated by the authentication platform 202A. At a high level, a biometric signature may represent metrics related to vascular dynamics. An example of a biometric signature is a set of values that show changes over time in the location, size, volume, or pressure of a blood vessel. Another example of a biometric signature is a set of values that show changes over time in the velocity or acceleration of blood flowing through a blood vessel. The term “biometric signature” can be used to refer to multiple values corresponding to different points in time, but a single value can also be used as a biometric signature. For example, the depth of a given blood vessel relative to the surface of the skin can be used as a biometric signature.
[0060] During the usage phase, the authentication algorithm 218 may be invoked to perform authentication by comparing a new biometric signature generated for an unknown person with one or more reference biometric signatures associated with a given individual. As described above, the reference biometric signatures may be stored in the biometric database 220. The output generated by the authentication algorithm 218 may represent a final decision on whether the unknown person should be authenticated as a given individual. The authentication algorithm 218 may output discrete or continuous outputs such as a probabilistic metric (e.g., specifying the likelihood that the unknown person is a given individual), a binary output (e.g., authenticated or not authenticated), or a classification (e.g., specifying whether the unknown person was authenticated with a low, medium, or high degree of confidence).
[0061] Figure 2B includes a high-level representation of system 200B, which can be used to authenticate an unknown person based on gesture recognition. At a high level, system 200B in Figure 2B operates in a similar manner to system 200A in Figure 2A. However, here, the authentication platform 200B decides whether or not to authenticate the unknown person based on the analysis of data generated by signal sensor 208 when the unknown person performs a physical action (referred to as a "gesture"). Alternatively, the data may be based on or represent the output generated by signal sensor 208 when the unknown person performs a gesture.
[0062] Therefore, the biometric database 220 may include data related to the performance of a given gesture and other data related to the characteristics of a blood vessel. For example, the biometric database 220 may include a “gesture signature” representing data related to the performance of a gesture by a given individual. The data may include one or more values of a blood vessel characteristic during the performance. The gesture signature may be associated with an anatomical location (and thus one or more blood vessels) and / or an electronic device. As an example, the data may specify a change in the size of the radial artery, determined by an electronic device attached to the wrist, as a given individual bends their wrist downward and then upward. In such a scenario, the gesture signature is associated with a specific gesture (i.e., bending the wrist downward and then upward), a specific blood vessel (i.e., the radial artery), and a specific electronic device (i.e., an electronic device attached to the wrist).
[0063] A gesture may be any movement that requires stiffening or activating one or more muscles and results in a fluctuation in blood supply to those muscles. This fluctuation in blood supply will affect the vasodynamics of blood vessels in the same anatomical region. Each gesture signature may comprise a vector of length N, where each element is an intensity value based on the magnitude of the frequency shift between a probing signal and a corresponding return signal. The frequency shift may correlate with the dilation or constriction of the corresponding blood vessels, and consequently, with the activation of a particular muscle(s) during the performance of the gesture.
[0064] As shown in Figure 2B, the authentication platform 202B may include a gesture recognition module 222 that can operate to facilitate vascular dynamics-based authentication while a gesture is being performed. The gesture recognition module 222 may include a gesture processing algorithm 224 and a gesture recognition algorithm 226. At a high level, these algorithms may be able to determine whether the data generated by the signal sensor 208 while an unknown person is performing the gesture is sufficiently similar to the data generated by the signal sensor 208 (or another signal sensor) during one or more previous performances. With such an approach, the gesture recognition module 222 can determine whether the unknown person performed the gesture as requested, and therefore whether the unknown person should be authenticated as a given individual.
[0065] The gesture processing algorithm 224 may also be responsible for examining the data generated by the signal sensor 208 and generating a gesture signature that can be used for authentication. For example, the gesture processing algorithm 224 may analyze the data to identify a set of values corresponding to the execution of a gesture, and then define a gesture signature based on that set of values. As will be discussed further below, the gesture processing algorithm 224 may be tasked with generating a gesture signature during the registration and usage phases.
[0066] Conversely, the gesture recognition algorithm 226 may be executed only during the usage phase. During the usage phase, the gesture recognition algorithm 226 may be responsible for identifying the gesture being performed based on the analysis of data generated by the signal sensor 208. For example, the gesture recognition algorithm 226 may identify a gesture by comparing a new gesture signature generated for an unknown person with one or more reference gesture signatures stored in the biometric database 220. The gesture recognition algorithm 226 can then generate an output, for example, as a request via the UI 202, indicating whether the unknown person performed the gesture. In some embodiments, the authentication platform 202B decides whether to authenticate the unknown person as a given individual based solely on whether the output indicates that the gesture was performed by the unknown person. In other embodiments, the authentication platform 202B takes a slightly different approach. For example, the authentication platform 202B may attempt to determine the degree of similarity between the gesture performance by the unknown person and past gesture performances by a given individual.
[0067] Figure 2C includes a high-level representation of system 200C, which can be used to authenticate an unknown person based on location recognition. At a high level, system 200C in Figure 2C operates in a similar manner to system 200A in Figure 2A. However, here, the authentication platform 200C determines whether to authenticate the unknown person based on whether the signal scanner 208 is in the expected position relative to the unknown person's body.
[0068] In this embodiment, at least a portion of the biometric signatures in the biometric database 220 may be associated with location-indicating values. These values may be referred to as “location tags” or “location labels.” Location labels may include alphanumeric identifiers or location descriptions. Preferred descriptions include “front right trouser pocket,” “rear left trouser pocket,” “left chest,” and “right wrist.” Thus, each location label may indicate an anatomical region near where the signal sensor 208 was located when the corresponding biometric signature was generated.
[0069] As shown in Figure 2C, the authentication platform 202C may include a location recognition module 228 that can operate to facilitate authentication based on whether vascular dynamics indicate that the signal sensor 208 is in the expected location. The location recognition module 228 may include a registration system 230, a location algorithm 232, and a location rule database 234.
[0070] The location rule database 234 may contain rules associated with each available location label. These rules may be defined by users of the authentication platform 200C, administrators responsible for managing the authentication platform 200C, or the authentication platform 200C itself. For example, a rule may specify purchase permission, purchase conditions (e.g., maximum purchase price), or authentication conditions. Thus, the location recognition module 228 (and therefore the authentication platform 200C) may prevent, restrict, or limit authentication based on the rules in the location rule database 234. Rules may also be general instructions related to a specific computer program. For example, a rule may define criteria that must be met in order to play a song through a music-focused computer program, or a rule may define criteria that must be met in order to start step counting for a fitness-focused computer program. Rules may be configurable (e.g., createable or editable) through the UI 202.
[0071] The registration system 230 may allow a person (e.g., a user or administrator) to assign rules to specific location labels and update these rules once they have been stored in the location rule database 234. For example, a user might want to specify that transactions requiring authentication should be limited to a certain amount (e.g., $50 or less) unless a certain electronic device (e.g., a mobile phone) is in a certain location (e.g., the front left pocket of a pair of trousers). As described above, the authentication platform 200C may be able to estimate whether a certain electronic device is in a certain location by examining the data generated by the signal sensor 208 during the usage phase. More specifically, the authentication platform 200C may analyze the data to determine whether the value indicates a blood vessel (e.g., the femoral artery) that is known to be close to the location in question.
[0072] On the other hand, the location algorithm 232 may be responsible for retrieving location labels associated with biometric signatures from the biometric database 214 as needed. Furthermore, the location algorithm 232 may use those location labels to retrieve appropriate rules from the location rule database 234.
[0073] Figure 3 shows an example of an electronic device 300 that can implement an authentication platform 314 designed to authenticate an unknown person based on data generated by a signal sensor 310. As described above, the signal emitter 308 can emit a probing signal to the body of an unknown person, while the signal sensor 310 can generate data based on the reflection of the probing signal by physiological structures within the body. In some embodiments, the probing signal represents a radio wave, so the return signal detected by the signal sensor 310 may also be a radio wave. Note that the signal emitter 308 can also be configured to emit a discrete series of probing signals called a "pulse" over a period of time.
[0074] In some embodiments, the authentication platform 314 is embodied as a computer program executed by an electronic device 300. For example, the authentication platform 314 may reside on a mobile phone that can acquire data on which a determination is made as to whether or not authentication is appropriate. In another example, the authentication platform 314 may reside on a wearable device that can acquire data on which a determination is made. Examples of wearable devices include watches, fitness trackers, and head-mounted displays. In other embodiments, the authentication platform 314 is embodied as a computer program executed by another electronic device to which the electronic device 300 is communicably connected. In such embodiments, the electronic device 314 may transmit data to the other electronic device for processing. For example, authentication of an unknown person may be required by a POS system used to initiate a transaction, while the data may be generated by a mobile phone located in close proximity to the unknown person. The data may be provided to the POS system or other electronic device (e.g., a computer server) for processing, or the data may be processed by the mobile phone before being provided to the POS system or other electronic device. Those skilled in the art will recognize that embodiments of the authentication platform 314 may also be distributed among multiple electronic devices.
[0075] The electronic device 300 may include a processor 302, a memory 304, a user interface (UI) output device 306, a signal emitter 308, a signal sensor 310, and a communication module 312. The communication module 312 may be, for example, a wireless communication circuit designed to establish a communication channel with other electronic devices. Examples of wireless communication circuits include integrated circuits (also called "chips") configured for Bluetooth®, Wi-Fi®, NFC, etc. The processor 302 may have general-purpose characteristics similar to a general-purpose processor, or it may be an application-specific integrated circuit (ASIC) that provides control functions to the electronic device 300. As shown in Figure 3, the processor 302 may be coupled directly or indirectly to all components of the electronic device 300 for communication purposes.
[0076] Memory 304 may consist of any suitable type of storage medium, such as static random access memory (SRAM), dynamic random access memory (DRAM), electrically erasable programmable read-only memory (EEPROM), flash memory, or registers. In addition to storing instructions executable by processor 302, memory 304 may also store data generated by signal sensor 310 and (for example, when executing modules of authentication platform 314) data generated by processor 302. It should be noted that memory 304 is merely an abstract representation of the storage environment. Memory 304 may consist of actual memory chips or modules.
[0077] As described above, the signal emitter 308 may be configured to emit electromagnetic radiation into the body of an unknown person to be authenticated, for example, in the form of radio waves. Typically, the signal emitter 308 emits electromagnetic radiation only when instructed to do so. For example, the authentication platform 314 may be configured to determine whether authentication is required. In such a scenario, the authentication platform 314 may generate an output prompting the processor 302 to instruct the signal emitter 308 to emit a probing signal having certain characteristics. As described above, those characteristics may be determined by the authentication platform 314.
[0078] The signal sensor 310 may be any sensing device capable of collecting reflections of probing signals reflected by physiological structures within the body. Data from which vascular dynamics can be determined may be based on or represent these reflections.
[0079] The communication module 312 can manage communication between components of the electronic device 300. The communication module 312 can also manage communication with other electronic devices. Examples of electronic devices include mobile phones, tablet computers, personal computers, wearable devices, POS systems, and network-accessible server systems consisting of one or more computer servers. For example, in an embodiment where the electronic device 300 is a mobile phone, the communication module 312 may be commutably connected to a network-accessible server system that is responsible for examining data generated by the signal sensor 310.
[0080] For convenience, the authentication platform 314 may be referred to as a computer program residing in memory 304. However, the authentication platform 314 may consist of software, firmware, or hardware components implemented in or accessible from the electronic device 300. According to the embodiments described herein, the authentication platform 314 may include various algorithms and modules (collectively referred to as “elements”), as described above with reference to Figures 2A-C. These elements may be an integral part of the authentication platform 314. Alternatively, these elements may be logically separate from the authentication platform 314 but may operate “in parallel” with it. Together, these elements may enable the authentication platform 314 to authenticate an unknown person based on an analysis of vascular dynamics determined from data generated by the signal sensor 310. As an example, upon acquiring data generated by the signal sensor 310, the authentication platform 314 may generate a biometric signature of the unknown individual from whom the signal emitter 308 emitted a pulse signal. Next, the authentication platform 314 can compare the biometric signature with at least one reference biometric signature associated with a given individual stored in the biometric database 316. Based on the degree of similarity between the biometric signature and the reference biometric signature, the authentication platform 314 may decide whether or not to authenticate the unknown person as the given individual. In Figure 3, the biometric database 318 is located in the memory 304 of the electronic device 300. However, the biometric database 318 may, alternatively or additionally, be located in remote memory accessible to the electronic device 300 via a network.
[0081] Other elements may also be included as part of the authentication platform 314. For example, a UI module may be responsible for generating content to be output by the UI output device 306 for presentation to an unknown person. The form of the content may depend on the nature of the UI output device 306. For example, if the UI output device 306 is a speaker, the content may include audio instructions for positioning the electronic device 300 near an anatomical area or indicating that the authentication process should proceed. As another example, if the UI output device 306 is a display, the content may include visual instructions for positioning the electronic device 300 near an anatomical area or indicating that the authentication process should proceed. [Methods for Authentication]
[0082] Figures 4A-B include a flowchart of the procedure for authenticating a user of an authentication platform based on radar detection of vascular dynamics monitored using an electronic device positioned close to the body. Figures 5A-B include a flowchart of these processes in a gesture recognition scenario, and Figures 6A-B include a flowchart of these processes in a location recognition scenario. Note that unless otherwise specified, these processing steps may be combined with other processing steps. Thus, the authentication platform may utilize vascular dynamics recognition, gesture recognition, or location recognition when tasked with authenticating an unknown person.
[0083] As shown in Figures 4A-B, the authentication procedure has two stages: a registration stage 400 and a usage stage 450. These stages may be designed to enable hands-free authentication, without requiring the user to interact with any electronic devices.
[0084] To initiate registration stage 400, the user may place the electronic device, including (i) a signal emitter and (ii) a signal sensor, into its initial position. Note that in some situations, the user may need to place the electronic device into its initial position. For example, the user may need to hold the electronic device in its initial position. In other situations, the user may simply need to ensure the electronic device remains in its current position. For example, the user may be instructed to place the electronic device in a trouser pocket where the electronic device is already located.
[0085] The user may be prompted by one or another electronic device to position the electronic device in an initial location. For example, the user may indicate their interest in registering with the authentication platform via an interface presented on the electronic device's display. Generally, the initial position is positioned close to the anatomical region of interest (and therefore, a blood vessel). For example, the authentication platform may require the user to position the electronic device in the front pocket of their trousers so as to be close to the femoral artery, or the authentication platform may require the user to position the electronic device near their wrist so as to be close to the radial artery.
[0086] In some embodiments, the user may authenticate themselves before the registration step 400 proceeds. For example, the user may be prompted to provide sensitive information (e.g., name, address, or payment card number) that can serve as a means of proving their identity.
[0087] Next, the VD signal characteristics algorithm of the authentication platform can generate an initial set of signal characteristics. In some embodiments, the initial set of signal characteristics represents default signal characteristics, and in other embodiments, the initial set of signal characteristics represents default signal characteristics modified based on the conditions of registration stage 400. For example, the VD signal characteristics algorithm may modify the default frequency range used for scanning based on the initial position (and therefore the required penetration depth). As another example, the VD signal characteristics algorithm may modify the default peak amplitude based on the minimum power requirements of the signal sensor contained in the electronic device.
[0088] The signal characteristics of an initial set can be provided to a signal emitter included in an electronic device so that a probing signal can be emitted according to the signal characteristics of the initial set. Thus, the signal emitter can emit a probing signal within the intensity, duration, timing conditions, and frequency range defined by the VD signal characteristics algorithm. As shown in Figure 4A, the signal sensor can then detect a return signal generated through the reflection of the probing signal within the body. The return signal can be provided as input to a return signal evaluation algorithm or a VD signature processing algorithm.
[0089] A return signal evaluation algorithm can be responsible for evaluating the quality of a return signal. For example, to evaluate quality, a return signal evaluation algorithm may compare one or more characteristics of the return signal to a predefined benchmark. Such characteristics may include amplitude, SNR, and repeatability. For each benchmark, the return signal evaluation algorithm may assign a value (e.g., between 0 and 1, between 1 and 100) based on the difference between the corresponding characteristic and the benchmark. These values may then be summed and divided by the total number of characteristics to establish an overall quality evaluation of the return signal. In some embodiments, weights may be assigned to the characteristics. In such embodiments, some characteristics may have a greater impact on the quality evaluation than others. If any value falls below a threshold defining a minimum acceptable standard, the return signal evaluation algorithm may output a report showing each characteristic that does not meet the corresponding benchmark. This report may be used by a VD signal characteristics algorithm to update the signal characteristics of the probing signal and then initiate another scan.
[0090] After an acceptable return signal is obtained, the VD signature processing algorithm can process the return signal to generate a biometric signature. For example, the VD signature processing algorithm may obtain the frequency difference (called the "frequency shift") between the probing signal and the return signal for each of the N timestamped samples taken over a period of time (also called the "measurement interval" or "scan interval"). The frequency shifts can then be normalized and stored in a vector of length N. In some embodiments, the vector may further include information such as temporal "steps" between each frequency shift. The vector may represent the biometric signature generated for the return signal.
[0091] As shown in Figure 4A, the quality evaluation generated by the return signal evaluation algorithm and the biometric signature generated by the VD signature processing algorithm can be stored in a biometric database accessible to the authentication platform. For example, the quality evaluation and the biometric signature can be entered into entries in a data structure representing the biometric database. In some embodiments, the biometric database is maintained on the same electronic device as the authentication platform, and in other embodiments, the biometric database is maintained on a different electronic device from the authentication platform. For example, the authentication platform may reside on an electronic device located in close proximity to the user's body, and the biometric database may reside on a network-accessible server system to which the electronic device is communicably connected.
[0092] This process can be completed multiple times during registration stage 400. For example, the user may place electronic devices in different locations to generate multiple biometric signatures, or the user may place different electronic devices in the same or different locations to generate multiple biometric signatures. Regardless of the number of biometric signatures generated during registration stage 400, those biometric signatures can be stored in a biometric database for future use in authentication.
[0093] In the usage phase 450, the user may be prompted to place an electronic device at one of the predetermined locations where a biometric signature was defined in the registration phase 400. For example, suppose a user is attempting to complete a transaction using a POS system. In such a scenario, the POS system may send a request to authenticate the user directly or indirectly to an authentication platform. For example, the POS system may send a request to perform authentication directly to the electronic device via a wireless channel established according to a short-range communication protocol such as Bluetooth, near-field communication (NFC), or Wi-Fi. As another example, the POS system may send an instruction to a server system over a network that authentication is required, and the server system may send a request to perform authentication to the electronic device.
[0094] After receiving the request, the authentication platform may perform the steps described above with respect to registration stage 400 in order to generate a biometric signature. As described above, these steps may need to be performed one or more times in order to generate a biometric signature of acceptable quality.
[0095] Information about an electronic device or the user being authenticated can be used to retrieve one or more reference biometric signatures from a biometric database. For example, criteria such as the geographical location of the electronic device, the identifier of the electronic device, and the identity of the claimed user can be used to identify the reference biometric signature(s). The VD authentication algorithm can then compare the biometric signature(s) to the reference biometric signature(s). For example, the VD authentication algorithm may identify equivalent features in the biometric signature and the reference biometric signature. An example of such feature is a set of elements in both vectors where the frequency shift is increasing, indicating the start of a pulse. From the start of the equivalent feature, the value of each element of the biometric signature can be compared to the corresponding element in the reference biometric signature. This may be done to identify the difference in values and / or the rate of change in values. This process may be repeated for one or more features that the VD authentication algorithm has determined to be approximately or substantially equivalent between the biometric signature and the reference biometric signature. The VD authentication algorithm can then check these differences against an acceptable range. For example, a VD authentication algorithm may consider a biometric signature to be sufficiently similar to a baseline biometric signature if these differences fall within 0.25, 0.5, or 0.75 standard deviations.
[0096] Authentication decisions can be made by a VD authentication algorithm, for example, based on the number of differences within an acceptable range and / or the average size of the deviations. While authentication platforms may have varying levels of confidence in their authentication decisions, as described above, authentication decisions are typically binary. In other words, an authentication decision will usually indicate either authenticated or not authenticated. The authentication decision can be communicated to the destination by the authentication platform. For example, if a request for authentication is presented by a POS system as described above, the authentication decision can be communicated to the POS system.
[0097] Figures 5A-B include flowcharts of registration stage 500 and usage stage 550 in an embodiment in which the authentication platform determines whether or not to authenticate a user based on gesture recognition. These flowcharts illustrate how the authentication platform may detect the execution of a gesture based on how those gestures alter the user's vascular dynamics.
[0098] At a high level, registration stage 500 and use stage 550 in Figure 5A-B are equivalent to registration stage 400 and use stage 450 in Figure 4A-B. However, here, the user may be prompted to perform a gesture while the electronic device is positioned in close proximity to an anatomical area of the body. The gesture may be selected (e.g., from several possible gestures) so that the performance of the gesture can cause an observable change in the vasodynamics of the blood vessels located in the anatomical area. For example, the gesture may require the user to tense the thigh muscles once per second for several seconds, or the gesture may require the user to bend their wrist downward and then upward for several seconds.
[0099] As described above, the signal emitter may emit a probing signal having characteristics defined by the VD signal characteristics algorithm into an anatomical region, and the signal sensor may sense a return signal representing the probing signal reflected by physiological structures within the anatomical region. After the return signal evaluation algorithm determines that an acceptable return signal has been obtained, the gesture signature processing algorithm may process the return signal to generate a gesture signature. For example, the gesture signature processing algorithm may determine the frequency shift between the probe signal and the return signal for each of the N timestamped samples acquired over the measurement interval. The frequency shift can then be normalized and stored in a vector of length N. As described above, the vector may also contain information such as the temporal "steps" between each frequency shift. If the user is asked to perform a known gesture, the frequency shifts may also be associated with or "tagged" with each action. The vector may represent the gesture signature generated for the return signal.
[0100] In registration stage 500, the gesture signature can simply be stored in a biometric database. However, in usage stage 550, the gesture signature can be compared to at least one reference gesture signature by a gesture recognition algorithm. Criteria such as the geographical location of the electronic device, the identifier of the electronic device, the identity of the claimed user, and the gesture can be used to identify the reference gesture signature(s). For example, the gesture recognition algorithm may identify equivalent features of the gesture signature and the reference gesture signature. One example of such features is a set of elements in both vectors where the frequency shift is increasing, indicating the start of the gesture execution.
[0101] Starting from the equivalent features, the values of each element of the gesture signature can be compared to the corresponding elements of the reference gesture signature. This may be done to identify similarities and differences in characteristics such as the timing, rate of change, or magnitude of frequency shifts. Across the vector, differences in such characteristics may be checked to determine whether the differences fall within a certain tolerance (e.g., within 0.5 standard deviations). Based on the differences, the gesture recognition algorithm can generate a gesture confirmation indicating whether the gesture signature matches the reference gesture signature. In situations where the gesture confirmation indicates a mismatch, the authentication platform may not authenticate the user, or it may require the user to perform the gesture again (and repeat the usage stage 550).
[0102] Figures 6A-B include flowcharts of registration stage 600 and usage stage 650 in an embodiment in which the authentication platform determines whether to authenticate a user based on location recognition. These flowcharts illustrate how the authentication platform assigns rules, settings, or functions to locate an electronic device in a given anatomical region by first recognizing its location from vascular dynamics and then retrieving relevant rules from a biometric database.
[0103] As shown in Figure 6A, registration stage 600 may be substantially the same as registration stage 400 in Figure 4A. However, after the biometric signature is generated, the user may assign a location label to the biometric signature. Subsequently, the user, the authentication platform, or another computer program run on the electronic device may use the registration system to input one or more location rules for the newly assigned location label. For example, the location algorithm may generate a table of functions in the biometric database for each location tag. These functions may be invoked via an application programming interface (API) to apply settings to computer programs running on the electronic device, or to call functions within those computer programs.
[0104] In usage phase 650, the authentication platform may generate a biometric signature that can be compared to a reference biometric signature, as described above with reference to Figure 4B. After the biometric signature is generated, the location algorithm can retrieve a location label associated with the reference biometric signature from the biometric database. The location algorithm can then use the location label to retrieve a corresponding location rule, if any, from the location rule database. These location rules can then be used by the authentication platform (for example, to determine whether authentication is appropriate) or by another computer program running on the electronic device. For example, in the context of a transaction completed through a computer program, location rules may be used to determine whether the transaction meets certain criteria before authentication is permitted. In addition or alternatively, location rules may be useful to or facilitate the UI. For example, step counting monitored by an electronic device may be enabled by calling relevant functions via an API corresponding to a fitness-related computer program.
[0105] Figures 7A-B include a flow chart of registration and usage stages 700 and 750 for an example of a vascular dynamics-dependent authentication procedure.
[0106] In registration stage 700, the UI may prompt the individual to first place the electronic device in its initial position (step 701). Generally, the UI is presented by the electronic device. For example, the electronic device may instruct the individual verbally or visually to place the electronic device in its initial position. However, the UI may be presented by another electronic device. For example, the UI may instruct the individual to place a wearable device (e.g., a watch or fitness tracker) in a predetermined anatomical area (e.g., the wrist), but may be presented by a mobile phone in which the individual is interested in completing registration stage 700.
[0107] Subsequently, the authentication platform can determine the initial characteristics of the probing signal to be emitted into the body (step 702). As described above, the initial characteristics may be based on the individual, the electronic device, or the initial position. Next, the authentication platform can (i) cause a signal emitter to emit a probing signal into the body, and (ii) cause a signal sensor to sense a return signal generated by the reflection of the probing signal (step 703). For example, the authentication platform may generate an instruction specifying the initial characteristics of the probing signal and transmit that instruction to the operating system of the electronic device. Upon receiving the instruction, the operating system may operate the signal emitter contained in the electronic device so that a probing signal with the initial characteristics is emitted. The data generated by the signal sensor representing the return signal can be acquired by the authentication platform (e.g., via the operating system).
[0108] The authentication platform can evaluate the data (and therefore the return signal) to generate a quality assessment (step 703). If the quality assessment falls below a threshold, the authentication platform may adjust the probing signal settings as described above. However, if the quality assessment exceeds the threshold, the authentication platform can use the return signal to generate a biometric signal (step 705). Furthermore, the authentication platform can store the quality assessment and biometric signature in a biometric database (step 706).
[0109] In the usage stage 750, the authentication platform first receives an input from a source indicating an authentication request (step 751). In some embodiments, the source is a computer program running on the same electronic device as the authentication platform. For example, if the authentication platform resides on a mobile phone, the authentication request may originate from a mobile application in which the user is attempting to perform an activity that requires authentication. In other embodiments, the source may originate from another electronic device. For example, suppose a user attempts to complete a transaction using a POS system associated with a merchant. In such a scenario, the POS system may request authentication, but the scan may be performed by an electronic device associated with the user.
[0110] Subsequently, the authentication platform can perform steps equivalent to steps 701-705 of the registration phase (step 752). Thus, the authentication platform can generate a biometric signature related to the vascular dynamics of blood vessels within an anatomical region based on data generated by signal sensors contained in an electronic device located in close proximity to the user's anatomical region. Next, the authentication platform can retrieve at least one reference biometric signature from the biometric database (step 753). The reference biometric signature(s) can be associated with the individual to whom the user should be authenticated. Thus, in order to determine whether or not to authenticate the user as an individual, the authentication platform can evaluate the similarity between the biometric signature and the reference biometric signature(s) (step 754). Subsequently, the authentication platform can communicate the authentication decision to the source (step 755). As described above, the authentication decision may be based on the degree of similarity between the biometric signature and the reference biometric signature(s).
[0111] Figure 8 includes an illustrative diagram of a scenario in which an unknown person is authenticated despite the unknown person having an electronic device in their front trouser pocket. In this embodiment, the vascular dynamics of the femoral artery are used as a means to uniquely identify the unknown person. Those skilled in the art will recognize that in other embodiments, authentication may be based on the vascular dynamics of another conveniently accessible blood vessel. For example, if the electronic device used for scanning is positioned close to the wrist or forearm, authentication may be based on the vascular dynamics of the radial or ulnar artery. Authentication may also be based on the vascular dynamics of multiple blood vessels as described above. For example, if the electronic device used for scanning is positioned close to the buttocks (e.g., in a back trouser pocket), authentication may be based on the common iliac artery, internal iliac artery, and external iliac artery.
[0112] At a high level, this approach enables hands-free authentication because the authentication platform can define the characteristics of the probing signals emitted into the body of an unknown person by an electronic device. These characteristics can be algorithmically generated so that information about vascular dynamics can be obtained through the analysis of return signals representing the probing signals reflected by physiological structures within the body. As mentioned above, the authentication platform can reside in an electronic device or another electronic device. For example, the authentication platform may reside in a network-accessible server system or POS system to which the electronic device is communicably connected.
[0113] Typically, a probing signal represents electromagnetic radiation emitted within the 3.1–10.6 GHz band, although in some embodiments, the electromagnetic radiation may be outside this range. Therefore, the probing signal can not only pass through clothing before entering the body, as shown in Figure 8, but can also penetrate the skin, fat, and muscle to a certain depth. Similarly, the return signal generated by the reflection of the probing signal can also pass through muscle, fat, skin, and clothing to reach the electronic device. For these reasons, an unknown person may simply leave the electronic device in its usual place (e.g., a front trouser pocket) while authentication is being performed.
[0114] This approach to authentication offers several advantages. Firstly, electronic devices, including signal emitters and sensors, can be used without requiring conscious action to initiate or complete authentication. In fact, the approach described herein would not require the user to wear or place the electronic device in a location that would interfere with normal daily use. Secondly, this approach presents a novel means of locating the electronic device along the surface of the body by examining the vascular dynamics of scanned blood vessels. Thirdly, while gestures can be used as a means of authentication in this approach, the gestures do not need to be flashy or attention-grabbing. Instead, the gestures can be subtle (e.g., tensing muscles or moving limbs) and therefore barely detectable by others.
[0115] Figure 9 shows a schematic implementation example of an authentication platform 900 that can authenticate an unknown person 902 based on the vascular dynamics of the blood vessels. First, the authentication platform 900 would receive an input indicating a request to authenticate the unknown person (also called the “user” of the authentication platform 900). In Figure 9, the request originates from the POS system 904 that the unknown person 902 is using to complete a transaction. In other embodiments, the request may originate from other locations as described above.
[0116] Next, the authentication platform 900 can instruct an unknown person 902 to position an electronic device 906 in a predetermined location corresponding to the anatomical region of interest. The instruction may be presented by the POS system 904, or it may be presented by the electronic device 906. The manner in which the instruction is presented may depend on how the authentication platform 900 is deployed. In other words, whether the instruction is presented by the POS system 904 or the electronic device 906 (or other electronic device) may depend on where the authentication platform 900 is located.
[0117] After the electronic device 906 is positioned in place, it can emit a probing signal to the target anatomical region. Typically, the probing signal is generated according to instructions generated by the authentication platform 900. The instructions may specify the characteristics of the probing signal, such as frequency, amplitude, samples / second, emission timing, emission time, or any combination thereof. Furthermore, the electronic device 906 can generate a return signal representing the probing signal reflected by physiological structures within the target anatomical region.
[0118] Subsequently, the authentication platform 900 can examine the return signal and decide whether or not to authenticate the unknown person 902 as the designated individual. In particular, the authentication platform 900 can generate a biometric signature that shows the vascular dynamics of blood vessels in the anatomical region of interest, and then compare the biometric signature with at least one reference biometric signature known to be associated with the designated individual. The authentication decision may be based on the degree of similarity between the biometric signature and the reference biometric signature(s).
[0119] Additionally or alternatively, the authentication platform 900 may determine, based on the return signal, whether the unknown person 902 has performed the expected gesture or whether the electronic device 906 is in the expected position. Thus, the authentication platform 900 may determine whether or not to authenticate the unknown person 902 based on (i) vascular dynamics determined from the return signal, (ii) gestures determined from vascular dynamics, or (iii) position determined from vascular dynamics.
[0120] After determining whether the unknown person 902 should be authenticated as the designated individual he claims to be, the authentication platform 900 may generate a notification indicating the authentication decision. The notification may also be sent to the POS system 904, which can then decide whether to authorize the transaction based on the notification.
[0121] Figure 10 shows a flowchart of process 1000 for biometric authentication of a person claiming to be a given individual. First, the authentication platform can receive an input indicating a request to authenticate a person possessing an electronic device including (i) a signal emitter and (ii) a signal sensor (step 1001). The signal emitter and signal sensor may be part of a UWB IC capable of generating and detecting signals in a frequency range spanning multiple GHz (e.g., 6-8 GHz, 6-8.5 GHz, 6-9 GHz). In some embodiments, the input is received from a computer program running on the electronic device. In other embodiments, the input is received from another electronic device. For example, the input may be received from a POS system or a network-accessible server system to which the electronic device is communicably connected.
[0122] The authentication platform can then cause an electronic device to emit a probing signal into a person's body for a period of time (step 1002). For example, the authentication platform may determine appropriate characteristics of the probing signal based on the electronic device or the person, and then cause a signal emitter to emit a probing signal with appropriate characteristics. This can be achieved by sending a command to the electronic device's operating system to operate a signal emitter that specifies the appropriate characteristics. The authentication platform can then obtain data representing the probing signal reflected by blood vessels located within the body (step 1003). The data may be generated by a signal sensor included in the electronic device from which the probing signal was emitted, or the data may be based on an output generated by a signal sensor included in the electronic device from which the probing signal was emitted.
[0123] The authentication platform can determine, based on the data, the changes in the characteristics of the blood vessels over the aforementioned time period (step 1004). Thus, the authentication platform can determine how the blood vessels have changed over time, rather than simply observing them in a "snapshot" corresponding to a single point in time. The characteristics may be (i) the size of the blood vessel, (ii) the location of the blood vessel, (iii) the flow rate of blood through the blood vessel, or (iv) the pressure exerted on the blood vessel.
[0124] The authentication platform can then determine the likelihood that a person is a predetermined individual based on an analysis of changes in characteristics (step 1005). Thus, the authentication platform can determine whether or not to authenticate a person as a predetermined individual based on the user's vascular dynamics determined from the data. For example, the authentication platform may compare changes in characteristics with baseline values included in the profile associated with the predetermined individual, and then generate a score indicating the likelihood that the person is a predetermined individual based on the similarity between the changes in characteristics and the baseline values.
[0125] In some embodiments, the authentication platform is programmed to generate biometric signatures that represent changes in characteristics as described above. In such embodiments, the authentication platform may examine a biometric database containing biometric signatures associated with different individuals and then identify a reference biometric signature from among the biometric signatures that is relevant to a given individual. Each biometric signature in the biometric database may represent a reference value for a characteristic established for the corresponding individual. The biometric database may be maintained in a datastore on an electronic device used to scan the body, or it may be maintained in a datastore accessible to the electronic device via a network. To establish the likelihood that a person is a given individual (and therefore whether or not to authenticate that person), the authentication platform can compare the biometric signature to the reference biometric signature.
[0126] Other steps may also be included. For example, the authentication platform may estimate, based on the data, that an electronic device is located in close proximity to an anatomical region of the body. More specifically, the authentication platform may analyze the data to identify a pattern of values indicating a given blood vessel known to be located in an anatomical region. For example, if the authentication platform finds a value representing the vascular dynamics of the femoral artery, the authentication platform may estimate that the electronic device is located near the waist. In another example, the authentication platform may receive a second input indicating confirmation that a person was prompted to perform a gesture. In such an embodiment, the authentication platform can determine, based on the analysis of the data, whether or not the person performed the gesture. The authentication platform may determine that the person performed the gesture in response to finding a pattern of values in the data indicating a gesture.
[0127] Figure 11 shows a flowchart of process 1100 for generating a biometric signature of an individual that can then be used for authentication. First, the authentication platform can receive a first input indicating a request to create a biometric signature of an individual to be used for authentication (step 1101). The first input may not itself request the creation of a biometric signature, but simply represent a request to register an individual with an authentication service provided, facilitated, or supported by the authentication platform.
[0128] The authentication platform may then provide instructions for positioning an electronic device near an anatomical region of the person's body (step 1102). In some embodiments, the individual may be required to actively position the electronic device near the anatomical region, while in other embodiments, the individual may be able to leave the electronic device in its current position. For example, if (i) the anatomical region is the anterior or lateral region of the thigh, and (ii) the electronic device is already in the front or back pocket of the trousers, the electronic device may not need to be repositioned. Another example is if (i) the anatomical region is the anterior or posterior region of the wrist, and (ii) the electronic device is already secured to the wrist, the electronic device may not need to be repositioned. Another example is if (i) the anatomical region is the chest region, and (ii) the electronic device is already in the chest pocket, the electronic device may not need to be repositioned. Other examples of anatomical regions include the cervical region (also called the “neck region”) and the temporal region, and these anatomical regions may be monitored using electronic devices such as networked neckwear (e.g., smart necklaces), earphones, and hearing aids. Subsequently, the authentication platform can cause an electronic device to emit a probing signal into the individual's body (step 1103), and obtain data representing the probing signal reflected by blood vessels located within the body (step 1104). Steps 1103-1104 in Figure 11 may be the same as steps 1002-1003 in Figure 10.
[0129] The authentication platform can then provide data as input to an algorithm that generates an individual's biometric signature as output (step 1105). The biometric signature may represent one or more values indicating the temporal variation of the vascular characteristics of a blood vessel. For example, the biometric signature may comprise a vector of length N, where each element is an intensity value based on the magnitude of the frequency shift between a probing signal and a corresponding return signal. In some embodiments, the biometric signature conveys information about the size of a blood vessel. In other embodiments, the biometric signature conveys information about the depth of a blood vessel beneath the skin of the body, the flow rate of blood through the vessel, and the pressure exerted on the vessel by the blood. In other embodiments, the biometric signature represents the vibrational profile of a blood vessel over time as the probing signal is emitted within the body.
[0130] Next, the authentication platform can store the biometric signature in a profile associated with the individual (step 1106). The profile may represent a single or multiple entries in a biometric database corresponding to the individual. The biometric database may be maintained on an electronic device used to scan the body and / or another electronic device to which the electronic device is communicatively connected.
[0131] These steps can be performed in various orders and combinations. For example, if the authentication platform requires the relocation of an electronic device to a different location, or the relocation of another electronic device to a different location, these steps may be performed again. This may be done to ensure that the authentication is robust to variations in the location of the electronic devices. Thus, the authentication platform may generate biometric signatures for different anatomical regions (and therefore different blood vessels), and these biometric signatures may be used in the future for authentication—individually or collectively.
[0132] Figure 12 shows a flowchart of process 1200 for determining whether to authenticate a person as a predetermined individual based on the vascular dynamics of blood vessels over time. First, the authentication platform can be prompted to provide instructions to position an electronic device near the anatomical region of the person to be authenticated (step 1201). The instructions may be audible or visual in nature. For example, the instructions may audibly request the positioning of the electronic device near the anatomical region, or the instructions may visually (e.g., through text instructions or visual representations) request the positioning of the electronic device near the anatomical region. In some embodiments, the instructions are provided by the electronic device, and in other embodiments, the instructions are provided by another electronic device (e.g., a POS system). The authentication platform can then acquire data generated by a signal sensor housed in the electronic device (step 1202). The data may represent a return signal based on (e.g., generated by) the reflection of a probing signal emitted to the person by the electronic device over a period of time.
[0133] The authentication platform can estimate, based on the data, the variation in the properties of blood vessels located in the anatomical region over the above time period (step 1203). The estimated variation may represent changes in the shape, location, flow rate, or pressure of the blood vessels over the above time period. Next, the authentication platform may determine whether to authenticate the person as the person in question based on a comparison of the estimated variation with a profile associated with the person in question (step 1204). The profile may represent one or more entries in a biometric database. Each entry may include a baseline value indicating how much the properties have changed when the person in question completed the registration stage. Thus, the authentication platform can determine the likelihood that the person is the person in question by comparing the estimated variation with at least one baseline value. [Processing System]
[0134] Figure 13 is a block diagram showing an example of a processing system 1300 in which at least some of the operations described herein may be implemented. For example, the components of the processing system 1300 may be hosted on an electronic device including a signal emitter and a signal sensor. In another example, the components of the processing system 1300 may be hosted on an electronic device including an authentication platform.
[0135] The processing system 1300 may include a processor 1302, main memory 1306, non-volatile memory 1310, a network adapter 1312 (e.g., a network interface), a video display 1318, an input / output device 1320, a control device 1322 (e.g., mechanical input such as a keyboard, pointing device, or buttons), a drive unit 1324 including a recording medium 1326, or a signal generator 1330, all of which are communicatively connected to the bus 1316. The bus 1316 is illustrated as an abstraction representing one or more physical buses and / or point-to-point connections connected by appropriate bridges, adapters, or controllers. Thus, the bus 1316 may include a system bus, a PCI (Peripheral Component Interconnect) bus, a PCI-Express bus, a HyperTransport bus, an ISA (Industry Standard Architecture) bus, a SCSI (Small Computer System Interface) bus, a USB (Universal Serial Bus), and an I 2 This may include a C (Inter Integrated Circuit) bus or a bus conforming to IEEE (Institute of Electrical and Electronics Engineers) standard 1394.
[0136] The processing system 1300 may share a computer processor architecture similar to that of a computer server, router, desktop computer, tablet computer, mobile phone, video game console, wearable electronic device (e.g., watch or fitness tracker), network-connected ("smart") device (e.g., television or home assistant device), augmented or virtual reality system (e.g., head-mounted display), or another electronic device capable of executing (sequentially or otherwise) a set of instructions that specifies the actions(s) to be performed by the processing system 1300.
[0137] Although the main memory 1306, non-volatile memory 1310, and recording medium 1324 are shown as a single medium, the terms “recording medium” and “machine-readable medium” should be interpreted to include a single or more mediums that store one or more sets of instructions 1326. Furthermore, the terms “recording medium” and “machine-readable medium” should be interpreted to include any medium that can store, encode, or carry a set of instructions for execution by the processing system 1300.
[0138] Generally, routines performed to implement embodiments of the present disclosure may be implemented as part of an operating system or a particular application, component, program, object, module, or sequence of instructions (collectively referred to as a "computer program"). A computer program typically comprises one or more instructions (e.g., instructions 1304, 1308, 1328) set at various times in various memories and storage devices within a computing device. When read and executed by processor 1302, the instructions cause processing system 1300 to perform actions to implement various embodiments of the present disclosure.
[0139] While embodiments have been described in the context of fully functional computing devices, those skilled in the art will understand that various embodiments can be distributed as various forms of program products. This disclosure applies regardless of the specific type of machine- or computer-readable medium used to actually achieve distribution. Further examples of machine- and computer-readable media include recordable type media such as volatile and non-volatile memory devices 1310, removable disks, hard disk drives, optical discs (e.g., Compact Disk Read-Only Memory (CD-ROM) and Digital Versatile Disc (DVD)), cloud-based storage, and transmission type media such as digital and analog communication links.
[0140] The network adapter 1312 enables the processing system 1300 to mediate data between entities outside the processing system 1300 and the network 1314 through any communication protocol supported by the processing system 1300 and the external entity. The network adapter 1312 may include a network adapter card, a wireless network interface card, a switch, a protocol converter, a gateway, a bridge, a hub, a receiver, a repeater, or a transceiver including an integrated circuit (for example, enabling communication via Bluetooth or Wi-Fi). [remarks]
[0141] The foregoing description of various embodiments of the claimed subject matter is provided for illustrative and explanatory purposes only. It is not intended to be exhaustive or to limit the claimed subject matter to the exact form disclosed. Many modifications and variations will be apparent to those skilled in the art. The embodiments have been selected and described to best illustrate the principles of the invention and its practical applications, thereby enabling those skilled in the art to understand the claimed subject matter, various embodiments, and various modifications suitable for the particular intended use.
[0142] While the detailed description illustrates specific embodiments and the intended best mode, the Art can be implemented in many ways, no matter how detailed the description may seem. Embodiments, while encompassed herein, may differ considerably in their implementation details. Any specific term used to describe particular features or aspects of various embodiments should not be construed as meaning that the term is redefined herein to limit the Art to any particular characteristic, feature, or aspect of the Art to which it relates. In general, the terms used in the following claims should not be construed as limiting the Art to any specific embodiment disclosed herein unless those terms are expressly defined herein. Therefore, the actual scope of the Art encompasses not only the disclosed embodiments but also all equivalent methods of carrying out or implementing those embodiments.
[0143] The terminology used herein has been selected primarily for readability and explanatory purposes. It has not been selected to define or enclose the subject matter. Accordingly, the scope of this art is intended to be limited not by this detailed description, but rather by any claims issued in an application relating thereto. Accordingly, the disclosure of various embodiments is intended to illustrate, but not to limit, the scope of the art set forth in the following claims. [Industrial applicability]
[0144] This disclosure is applicable to biometric authentication in computer security.
Claims
1. A method for authenticating a person as a designated individual, wherein the method is The electronic device receives input indicating a request to authenticate the person possessing the electronic device. The aforementioned electronic device emits a signal to the person's body over a certain period of time. The aforementioned electronic device acquires data representing signals reflected by blood vessels within the body. The electronic device establishes the changes in the characteristics of the blood vessel over time based on the data. The aforementioned electronic device determines, based on the analysis of the changes in the aforementioned characteristics, the likelihood that the person is a predetermined individual, and Based on the data, the electronic device estimates that it is located in a pocket of clothing that is close to an anatomical area of the body. A method for providing this.
2. Based on the data, the electronic device estimates that it is located in close proximity to the anatomical region of the body. The method according to claim 1, further comprising
3. The electronic device receives a second input indicating confirmation that the person has been prompted to perform a gesture, and The electronic device determines, based on the analysis of the data, whether or not the person performed the gesture. The method according to claim 1, further comprising:
4. The method according to claim 3, wherein it is determined that the person performed the gesture by discovering a pattern of values in the data indicating the gesture.
5. The above decision is, The change in the aforementioned characteristics is compared with a baseline value included in the profile associated with the predetermined individual, and Based on the similarity between the change in the aforementioned characteristics and the aforementioned reference value, a score is generated indicating the likelihood that the person is the predetermined individual. The method according to claim 1, comprising:
6. The method according to claim 5, wherein the characteristics include (i) the size of the blood vessel, (ii) the location of the blood vessel, (iii) the flow rate of blood through the blood vessel, and / or (iv) the pressure exerted on the blood vessel.
7. The method according to claim 5, wherein the profile is maintained on a network-accessible server system to which the electronic device is communicably connected.
8. The method according to claim 1, wherein the data is generated by an ultra-wideband (UWB) integrated circuit of the electronic device capable of detecting signals in a frequency range from 6 gigahertz to 9 gigahertz.
9. The above decision is, Consulting a biometric database that stores biometric signatures associated with different individuals, wherein each biometric signature represents a baseline value of the said characteristic established for the corresponding individual. From among the biometric signatures included in the biometric database, identify a reference biometric signature associated with the predetermined individual, and To establish the possibility by comparing the changes in the aforementioned characteristics with the aforementioned reference biometric signature, The method according to claim 1, comprising:
10. The method according to claim 9, wherein the biometric database is maintained in a data store accessible to the electronic device via a network.
11. The method according to claim 1, wherein the input is received from a payment system used by the person to initiate a transaction requiring authentication.
12. When executed by the processor of an electronic device, the electronic device: Receiving a first input indicating a request to create an individual's biometric signature to be used for authentication, To provide instructions for positioning the electronic device near an anatomical region of the individual's body. To emit a probing signal to the body of the aforementioned individual, The acquisition of data generated by a sensor housed in the electronic device, wherein the data represents a return signal generated by the reflection of the probing signal by blood vessels located in the anatomical region of the body. To provide the data as input to an algorithm that generates the biometric signature of the individual as output, The biometric signature is stored in the profile associated with the individual, and Based on the aforementioned data, it is estimated that the electronic device is located in a clothing pocket close to an anatomical area of the body. A computer program that performs an action that includes the following features.
13. The authentication platform provides instructions for positioning electronic devices in close proximity to the anatomical regions of the person being authenticated. The authentication platform acquires data generated by a sensor housed in the electronic device, wherein the data represents a return signal generated by the reflection of a probing signal emitted by the electronic device to the person over a certain period of time. The authentication platform estimates the temporal variation of the characteristics of blood vessels located in the anatomical region based on the data. The authentication platform determines whether or not to authenticate the person as the specified individual based on a comparison of the estimated fluctuations with the profile associated with the specified individual, and The authentication platform estimates, based on the data, that the electronic device is located in a clothing pocket close to an anatomical area of the person's body. A method for providing this.
14. The method according to claim 1 or 13, wherein the estimation is based on a pattern of values contained in the data indicating a predetermined blood vessel known to be located in the anatomical region.
15. The computer program according to claim 12, wherein the estimation is based on a pattern of values contained in the data that indicates a predetermined blood vessel known to be located in the anatomical region.
Citation Information
Patent Citations
Pulse wave detector and pulse wave detecting apparatus using the same
JP2005102959A
Personal authentication method and personal authentication system using vein pattern during bending and stretching motion of finger
JP2011100317A
Authentication device, authentication system, authentication program, and authentication method for personal authentication using cellular phone
JP2011215940A
Biological sensor and signal acquisition method of biological sensor
JP2019010436A
Method and apparatus for authenticating user using vein pattern
US20160117563A1