Context-aware biometric access control policies

US10958644B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10958644-B2
Application numberUS-201916426034-A
CountryUS
Kind codeB2
Filing dateMay 30, 2019
Priority dateNov 20, 2017
Publication dateMar 23, 2021
Grant dateMar 23, 2021

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A context-aware biometric access control policy is provided. A request to access a protected resource received from a client device is identified. A resource hierarchy associates each of a plurality of protected resources with one or more respective confidence levels of authentication. A confidence level that is associated with the protected resource is identified based on the resource hierarchy. Instructions to capture a biometric token via the client device are generated based on a set of one or more confidence level parameters that is associated with the identified confidence level. The generated instructions are sent to the client device. A biometric token received from the client device is determined to authenticate the user of the client device and, in response, the request to access the protected resource is approved.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for executing a context-aware biometric access control policy, the method comprising: identifying a request to access a protected resource of a plurality of protected resources, wherein the request is received from a client device; identifying a confidence level that is associated with the protected resource based, at least in part, on a resource hierarchy, wherein the resource hierarchy associates each of the plurality of protected resources with one or more respective confidence levels for authentication; generating instructions to capture a biometric token via the client device based, at least in part, on a set of one or more confidence level parameters that is associated with the identified confidence level, wherein one or more confidence level parameters in the generated instructions require a new configuration of device settings of the client device to capture the biometric token according to the identified confidence level; sending the generated instructions to the client device; determining when a biometric token received from the client device meets the identified confidence level; providing a human-comprehensible suggestion to the client device of a user, in response to the biometric token not meeting the identified confidence level; receiving a first biometric token from the client device; determining that the first biometric token does not authenticate the user of the client device to the identified confidence level; identifying one or more unsatisfied confidence level parameters with respect to the first biometric token, and in response, generating updated instructions that identify the one or more unsatisfied confidence level parameters; sending the updated instructions to the client device; and determining that a second biometric token received from the client device authenticates the user of the client device to the identified confidence level; wherein the determining that the first biometric token does not authenticate the user of the client device to the identified confidence level comprises determining that a facial-recognition algorithm cannot authenticate an image of a face of the user of the client device to the identified confidence level; wherein the generating updated instructions that identify the one or more unsatisfied confidence level parameters comprise generating an instruction that a user interface of the client device present one or more suggestions that identify the one or more unsatisfied confidence level parameters; wherein the generating instructions to capture the biometric token via the client device based, at least in part, on the set of one or more confidence level parameters that is associated with the identified confidence level comprises, generating an instruction to an application program interface of the client device that one or more settings of a camera used to capture the image of the face of the user of the client device be configured in accordance with camera settings specified by the one or more confidence level parameters; wherein the resource hierarchy associates a first confidence level and a second confidence level with the protected resource and the identified confidence level is identified based on a magnitude of a parameter of the request to access the protected resource; wherein a first set of one or more confidence level parameters is associated with the first confidence level and a second set of one or more confidence level parameters is associated with the second confidence level; wherein the first set of one or more confidence level parameters specifies a first set of camera settings and the second set of one or more confidence level parameters specifies a second set of camera settings, wherein the first set of camera settings and the second set of camera settings specify respective magnitudes at which to set corresponding camera setting types; and wherein the identified confidence level is associated with the first set of one or more confidence level parameters and the first set of camera settings. 2. The method of claim 1 , further comprising: identifying a threshold magnitude for the parameter of the request that is associated with the first confidence level and the second confidence level, wherein the first confidence level is identified when the magnitude of the parameter is greater than or equal to the threshold magnitude and the second confidence level is identified when the magnitude of the parameter is less than the threshold magnitude; and determining that the magnitude of the parameter is greater than or equal to the threshold magnitude, and in response, identifying the first confidence level. 3. The method of claim 1 , wherein generating instructions to capture a biometric token via the client device based, at least in part, on a set of one or more confidence level parameters that is associated with the identified confidence level further comprises: generating an instruction to an application program interface of the client device that one or more setting of a sensor used to capture the biometric token be configured in accordance with the one or more confidence level parameters. 4. The method of claim 1 , further comprising: authenticating the user of the client device using the received biometric token based, at least in part, on user credentials stored in a credential database, in response to the biometric token received from the client device meeting the identified confidence level. 5. The method of claim 1 , further comprising: approving the request to access the protected resource, in response to the biometric token authenticating the user.

Assignees

Inventors

Classifications

  • applying multi-factor authentication · CPC title

  • using biometrical features, e.g. fingerprint, retina-scan (cryptographic mechanisms or cryptographic arrangements for entity authentication using biological data H04L9/3231) · CPC title

  • Multiple levels of security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10958644B2 cover?
A context-aware biometric access control policy is provided. A request to access a protected resource received from a client device is identified. A resource hierarchy associates each of a plurality of protected resources with one or more respective confidence levels of authentication. A confidence level that is associated with the protected resource is identified based on the resource hierarch…
Who is the assignee on this patent?
IBM
What technology area does this patent fall under?
Primary CPC classification H04L63/0861. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Mar 23 2021 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).