Identity Proxy for Access Control Systems
Abstract
A hardware security token in contact with a user's body can send a signal via interbody communication to one or more electronic devices associated with a system of electronic devices having unified access controls such that a user can access each of the electronic devices using the same credentials. The signal sent by the hardware security token can be deputized by a user in possession of credentials to the system as a temporary proxy for that user's identity. In other examples, the signal sent by the portable security token can be deputized by a user in possession of credentials to the system as a temporary proxy for another user's identity. In some embodiments, the proxy can expire after a period of time or after a particular event occurs.
Claims
exact text as granted — not AI-modifiedWe claim:
1 . A method of authenticating a user of an electronic device, comprising:
receiving a modulated signal through a body of the user of the electronic device; determining whether the modulated signal is deputized as an identity proxy of an authorized user of the electronic device; and denying the user access to a feature of the electronic device unless the modulated signal is deputized as an identity proxy of an authorized user of the electronic device.
2 . The method of claim 1 , further comprising:
identifying a set of valid permissions associated with the identity proxy; and limiting access to the electronic device, by the user, to the set of valid permissions.
3 . The method of claim 2 , wherein identifying the set of valid permissions comprises:
identifying a period of time for which a permission associated with the identity proxy is valid; and identifying the permission as a valid permission when a current time is within the period of time.
4 . The method of claim 2 , wherein identifying the set of valid permissions comprises:
identifying a first geographic region in which a permission associated with the identity proxy is valid; determining a second geographic region in which the modulated signal is received by the electronic device; and identifying the permission as a valid permission when the second geographic region is within the first geographic region.
5 . The method of claim 1 , further comprising:
requiring an identifier from the user of the electronic device; receiving the identifier from the user of the electronic device; determining whether the identifier identifies an authorized user of the electronic device; and denying the user access to the feature of the electronic device unless the identifier identifies an authorized user of the electronic device.
6 . The method of claim 1 , wherein the electronic device is a home appliance.
7 . The method of claim 1 , wherein the identity proxy comprises a proxy for a credential of the authorized user.
8 . An electronic device, comprising:
a capacitive interface configured to capacitively couple to a body of a user and receive a modulated signal through the body of the user; a processor configured to: determine whether the modulated signal is deputized as an identity proxy of an authorized user of the electronic device; and deny the user access to a feature of the electronic device unless the modulated signal is deputized as an identity proxy of an authorized user of the electronic device.
9 . The electronic device of claim 8 , wherein the processor is further configured to:
identify a set of valid permissions associated with the identity proxy; and limit access to the electronic device, by the user, to the set of valid permissions.
10 . The electronic device of claim 9 , wherein the processor is configured to identify the set of valid permissions by:
identifying a period of time for which a permission associated with the identity proxy is valid; and identifying the permission as a valid permission when a current time is within the period of time.
11 . The electronic device of claim 9 , wherein the processor is configured to identify the set of valid permissions by:
identifying a first geographic region in which a permission associated with the identity proxy is valid; determining a second geographic region in which the modulated signal is received by the electronic device; and identifying the permission as a valid permission when the second geographic region is within the first geographic region.
12 . The electronic device of claim 8 , wherein the processor is further configured to:
require an identifier from the user of the electronic device; receive the identifier from the user of the electronic device; determine whether the identifier identifies an authorized user of the electronic device; and deny the user access to the feature of the electronic device unless the identifier identifies an authorized user of the electronic device.
13 . The electronic device of claim 8 , wherein the electronic device is a home appliance.
14 . The electronic device of claim 8 , wherein the identity proxy comprises a proxy for a credential of the authorized user.
15 . A method of authorizing a user to access an electronic device, the method comprising:
receiving a modulated signal at the electronic device, the modulated signal received from an authentication token and via a capacitive interface defined between the authentication token in contact with a body of the user and through a portion of the body of the user that is in contact with the electronic device; requesting from the user, by the electronic device, a credential associated with authorized access to the electronic device; and deputizing the modulated signal as a proxy for the credential.
16 . The method of claim 15 , further comprising:
permitting access to the electronic device upon receiving the modulated signal at the electronic device via the capacitive interface.
17 . The method of claim 15 , wherein the credential comprises biometric information associated with the user.
18 . The method of claim 15 , wherein the modulated signal is deputized for a timeout period.
19 . The method of claim 18 , wherein a selection of the timeout period is received from the user.
20 . The method of claim 15 , wherein the modulated signal comprises a rolling code.Join the waitlist — get patent alerts
Track US2019236257A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.