Methods and system for controlling access to enterprise resources based on tracking

US12418536B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12418536-B2
Application numberUS-201816757129-A
CountryUS
Kind codeB2
Filing dateNov 2, 2018
Priority dateNov 3, 2017
Publication dateSep 16, 2025
Grant dateSep 16, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Methods and systems for controlling access to enterprise resources based on tracking are disclosed. In one implementation, an enterprise security system includes one or more tracking systems, an information technology (IT) system, and a security integration system (SIS). The one or more tracking systems track movement of individuals throughout the enterprise. The SIS blocks access to the computer resources based on the tracked movement of the individuals within the enterprise.

First claim

Opening claim text (preview).

What is claimed is: 1. An enterprise security system, comprising: one or more tracking systems for tracking, using facial recognition to identify individuals based on images captured using one or more surveillance cameras installed in multiple rooms of an enterprise building, movement of the individuals throughout the multiple rooms, wherein the one or more tracking systems include an access control system for controlling physical access of the individuals through access points within the enterprise building, a first access point of the access points permitting physical access to a room of the enterprise building and having a reader device that is included in the access control system; an information technology (IT) system for providing access to computer resources within the enterprise building; and a security integration system for one of: receiving, from the IT system, a list of authorized computers for each of the individuals, and providing, to the IT system based on the list of authorized computers, a white list identifying one or more of the individuals that are determined, based on a metadata stream of the tracked movement of the individuals, to be in a same room as the authorized computers; or receiving, from the IT system, a list of unauthorized computers for each of the individuals, and providing, to the IT system based on the list of unauthorized computers, a black list identifying one or more the individuals that are determined, based on the metadata stream of the tracked movement of the individuals, to be in a same room as the unauthorized computers; wherein the metadata stream includes location within the enterprise building and time stamp for each identified individual, wherein the IT system allows or blocks access, requested by the one or more of the individuals, to at least a portion of the computer resources based on the white list or the black list. 2. The system as claimed in claim 1 , wherein the security integration system determines at least the portion of the computer resources as authorized computer systems for the one or more of the individuals identified in the white list, and wherein the IT system blocks access to the authorized computer systems, for one of the individuals that is not identified in the white list. 3. The system as claimed in claim 1 , wherein the security integration system accesses an asset management database to determine locations of computer systems within the enterprise building. 4. An enterprise security system, comprising: one or more tracking systems for tracking, using facial recognition to identify an individual based on images captured using one or more surveillance cameras installed in multiple rooms of an enterprise building, movement of the individual throughout the multiple rooms, wherein the one or more tracking systems include an access control system for controlling physical access of individuals through access points within the enterprise building, a first access point of the access points permitting physical access to a room of the enterprise building and having a reader device that is included in the access control system; an employee resource management system including an employee database indicating location of a desk of the individual; a security integration system for determining, based on receiving a metadata stream of the tracked movement of the individual, whether the individual is moving to and/or from the desk of the individual, wherein the metadata stream includes location within the enterprise building and time stamp for the individual; providing, based on a list of authorized computer resources, a white list identifying the individual determined, based on the metadata stream, to be moving to the desk of the individual associated with the authorized computer resources; and providing, based on the white list, access for the individual to the authorized computer resources. 5. A method, comprising: tracking, using facial recognition to identify an individual based on images captured using one or more surveillance cameras installed in multiple rooms of an enterprise building, movement of the individual throughout the multiple rooms, wherein tracking movement includes controlling and reporting, via an access control system and to a metadata stream, physical access of individuals through access points within the enterprise building, a first access point of the access points permitting physical access to a room of the enterprise building and having a reader device that is included in the access control system, wherein the metadata stream includes location within the enterprise building and time stamp for the individual; providing, based on a list of authorized computer resources, a white list identifying the individual determined, based on the metadata stream, to be in a same room as the authorized computer resources; providing, based on a list of unauthorized computer resources, a black list identifying the individual determined, based on the metadata stream, to be in a same room as the unauthorized computer resources; providing, based on the white list, access for the individual to the authorized computer resources within the enterprise building using an authentication server; and blocking, based on the black list, access for the individual to the unauthorized computer resources determined, based on the tracked movement of the individual within the enterprise building, to be in a same room as the individual. 6. The method as claimed in claim 5 , further comprising instructing an IT system to block access to the authorized computer resources, based on the tracked movement of the individual, when individual is not present. 7. The method as claimed in claim 6 , further comprising accessing an asset management database to determine locations of computer systems within the enterprise building. 8. A method, comprising: tracking, using facial recognition to identify an individual based on images captured using one or more surveillance cameras installed in multiple rooms of an enterprise building, movement of the individual throughout the multiple rooms, wherein the tracking movement includes controlling and reporting, via an access control system, physical access of individuals through access points within the enterprise building, a first access point of the access points that permits physical access to an area of the enterprise building and having a reader device that is included in the access control system; receiving a metadata stream of the tracked movement of the individual, wherein the metadata stream includes location within the enterprise building and time stamp for the individual; determining, based on the metadata stream of the tracked movement of the individual, whether the individual is moving to and/or from a desk of the individual based on information from an employee resource management system including an employee database indicating location of the desk of the individual; providing, based on a list of authorized computer resources, a white list identifying the individual determined, based on the metadata stream, to be moving to the desk of the individual associated with the authorized computer resources; and providing, based on the white list, access for the individual to the authorized computer resources. 9. The method as claimed in claim 8 , further comprising determining an assigned desk location of the desk of the individual and comparing the tracked movement to the assigned desk location. 10. The method of claim 8 , wherein the controlling the physical access of the individuals through the access points within the enterprise building comprises: receiving, from a reader device installed at the first access point, one

Assignees

Inventors

Classifications

  • using mutual or relative location information between multiple location based services [LBS] targets or of distance thresholds · CPC title

  • Tracking movement of a target, e.g. by detecting an object predefined as a target, using target direction and or velocity to predict its new position · CPC title

  • Government or public services (business processes related to the transportation industry G06Q50/40) · CPC title

  • Calendar-based scheduling for persons or groups · CPC title

  • Human resources · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12418536B2 cover?
Methods and systems for controlling access to enterprise resources based on tracking are disclosed. In one implementation, an enterprise security system includes one or more tracking systems, an information technology (IT) system, and a security integration system (SIS). The one or more tracking systems track movement of individuals throughout the enterprise. The SIS blocks access to the comput…
Who is the assignee on this patent?
Tyco Fire & Security Gmbh
What technology area does this patent fall under?
Primary CPC classification H04L63/102. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Sep 16 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).