US2018005232A1PendingUtilityA1

Systems and methods for prevention of unauthorized access to resources of an information system

Individually held — no corporate assignee on recordPriority: May 14, 2004Filed: Aug 31, 2017Published: Jan 4, 2018
Est. expiryMay 14, 2024(expired)· nominal 20-yr term from priority
Inventors:Peter N. Ching
G06Q 2220/00G06Q 20/382G06Q 20/20G06Q 40/04G06Q 20/401G06Q 20/40H04L 9/50
63
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An information security system prevents unauthorized access to resources of an information system. The information security system includes a fingerprint scanner that provides fingerprint data, a radio transceiver that stores encrypted data including fingerprint data from authorized users in a first portion and second data in a second portion, and a hub device that receives the encrypted data and the fingerprint data associated with the scanned fingerprint of a user, decrypts the first portion of the encrypted data to provide decrypted fingerprint data, compares the decrypted fingerprint data with the fingerprint data associated with the scanned fingerprint of the user, identifies the user as an authorized user when the decrypted fingerprint data matches the fingerprint data associated with the scanned fingerprint of the user, and provides the second data to the third party device via the second data interface when the user is identified as the authorized user.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . An information security system to restrict use of encrypted data, the information security system comprising:
 a fingerprint scanner configured to scan a fingerprint and provide fingerprint data associated with the scanned fingerprint;   a radio transceiver comprising memory and associated with the fingerprint scanner, the radio transceiver configured to store in the memory encrypted data that includes fingerprint data from one or more authorized users in a first portion and second data in a second portion; and   a hub device comprising a first data interface configured to communicate with the radio transceiver and the fingerprint scanner, and a second data interface configured to communicate with a third party device, the hub device configured to:
 receive, via the first interface, the encrypted data from the memory and the fingerprint data associated with the scanned fingerprint of a user from the fingerprint scanner; 
 decrypt the first portion of the encrypted data to provide decrypted fingerprint data; 
 compare the decrypted fingerprint data with the fingerprint data associated with the scanned fingerprint of the user; 
 determine that the decrypted fingerprint data matches the fingerprint data associated with the scanned fingerprint of the user; 
 after said determine, identify the user as an authorized user of the one or more authorized users; and 
 after said identify, provide the second data to the third party device via the second data interface. 
   
     
     
         2 . A method to restrict use of encrypted data, the method comprising:
 storing on a cell phone data indicative of fingerprints of one or more authorized users of the cell phone;   storing on the cell phone encrypted information;   reading a fingerprint of a user with a fingerprint scanner included on the cell phone;   generating user fingerprint data indicative of the read fingerprint of the user;   comparing the user fingerprint data indicative of the read fingerprint of the user with the stored data indicative of the fingerprints of the one or more authorized users of the cell phone;   determining that the comparison of the user fingerprint data with the stored data indicative of the fingerprints of the one or more authorized users of the cell phone indicates that the user fingerprint data matches at least one fingerprint in the stored data indicative of fingerprints of the one or more authorized users of the cell phone;   after said determining that the comparison indicates that the user fingerprint data matches the at least one fingerprint in the stored data, determining that the user is an authorized user of the one or more authorized users of the cell phone;   transmitting wirelessly with the cell phone encrypted information stored on the cell phone directly to a first device using one of infrared-based communication and radio frequency-based communication;   after said determining that the user is the authorized user, authorizing use of the encrypted information; and   receiving wirelessly a confirmation with the cell phone directly from the first device using one of the infrared-based communication and the radio frequency-based communication, the confirmation indicating that the use of the encrypted information has been completed, the confirmation including at least one data structure comprising data associated with the use of the encrypted information.   
     
     
         3 . The method of  claim 2  further comprising adding a one-way hash algorithm identifier to the confirmation. 
     
     
         4 . The method of  claim 3  further comprising applying the one-way hash algorithm to the confirmation. 
     
     
         5 . The method of  claim 4  further comprising encrypting the hashed confirmation with a key to provide an encrypted record. 
     
     
         6 . The method of  claim 5  attaching the encrypted record to the confirmation to create a consolidated information file. 
     
     
         7 . The method of  claim 6  further comprising storing in the cell phone the consolidated information file. 
     
     
         8 . A method to restrict use of encrypted data, the method comprising:
 storing information on a data transfer device, the information comprising authentication data identifying one or more users authorized to use the data transfer device;   providing the information from the data transfer device associated with a current one of the one or more users to a first device associated with a first party;   collecting, via the data transfer device, identity data associated with the current one of the one or more users;   providing the identity data to the first device associated with the first party;   after a determination that the authentication data matches the identity data, authenticating a right of the current one of the one or more users to permit access to a restricted portion of the information;   subsequent to said authenticating the right, permitting access to the restricted portion of the information; and   storing, on the data transfer device, a record comprising at least one data structure comprising data associated with the access to the restricted portion of the information.   
     
     
         9 . The method of  claim 8  wherein the authentication data comprises data representative of a fingerprint of the one or more users authorized to use the data transfer device, and wherein the authentication data stored on the data transfer device is not in a human readable format. 
     
     
         10 . The method of  claim 9  wherein the authentication data further comprises a personal identification number. 
     
     
         11 . The method of  claim 8  wherein said authenticating utilizes at least dual key encryption. 
     
     
         12 . The method of  claim 11  further comprising validating at least a portion of the information using at least a one-way hash algorithm. 
     
     
         13 . The method of  claim 8  wherein the at least one data structure further comprises data associated with completion of the access to the restricted portion of the information and wherein the restricted portion of the information is not in a human readable format. 
     
     
         14 . The method of  claim 13  wherein the data associated with completion of the access to the restricted portion of the information comprises an encrypted indicator. 
     
     
         15 . The method of  claim 14  wherein the encrypted indicator comprises a hashed electronic document. 
     
     
         16 . An information security system to restrict use of encrypted data, the information security system comprising:
 a biometric data reader configured to read biometrics and provide biometric data associated with the read biometric;   a data transfer device configured to store information that comprises authentication data identifying one or more users authorized to use the data transfer device and restricted data; and   a first device in communication with the biometric data reader and the data transfer device, the first device configured to receive biometric data associated with a user of the data transfer device and the information, compare the biometric data associated with the user of the data transfer device with the authentication data, determine that the biometric data associated with the user of the data transfer device matches the authentication data, and subsequent to the determination that the biometric data matches the authentication data, permit use of the restricted data.   
     
     
         17 . The information security system of  claim 16  wherein the data transfer device is further configured to store data associated with completion of the use of the restricted data. 
     
     
         18 . The information security system of  claim 16  wherein the restricted data is encrypted, and wherein the authentication data stored on the data transfer device is not in a human readable format. 
     
     
         19 . The information security system of  claim 16  wherein the data transfer device comprises the biometric data reader. 
     
     
         20 . The information security system of  claim 19  wherein the biometric data reader comprises a fingerprint acquisition device and the biometric data associated with the user comprises data representative of the user's fingerprint entered on the fingerprint acquisition device.

Join the waitlist — get patent alerts

Track US2018005232A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.