System and method of determiing persistent presence of an authorized user while performing an allowed operation on an allowed resource of the system under a certain context-sensitive restriction
Abstract
A system and a method of determining persistent presence of an authorized user while performing allowed operations on an allowed resource of the system while satisfying certain context-sensitive restrictions are disclosed. The system receives a request from a user to authenticate him/her. The system authenticates the user using biometric information of the user or any other authentication mechanism in a given context-sensitive restriction. If the user is authenticated, then the system allows the user to perform the allowed operation using the allowed resources in the context-sensitive restriction. If the authentication fails indicating that the user is an unauthorized user, then the system initiates a resolution process to halt or terminate the allowed operation to restrict or obfuscate the allowed operation from being accessed by the unauthorized user. In one embodiment, the system comprises an External Companion Device (ECD) paired with the system to perform the authentication and manage the allowed.
Claims
exact text as granted — not AI-modifiedWhat we claim:
1 . A computing device or server for authorizing a set of authorized operations on allowable associated circuits in associated electronic devices, comprising:
circuitry, computer processors, and computer processor instructions, executable computer operation instructions and data, and password and/or biometric persistent user authentication algorithms; wherein said server system provides a set of authorized operations further comprising a set of operating system level functions on an associated electronic device and on an identified application on said associated electronic device, wherein said set of authorization operations occur on circuitry, said circuitry comprising—
circuitry and executable instructions for authorizing a specified user input through one or more potentially heterogeneous electronic devices having potentially different computational capabilities;
a plurality of sensors distributed among said electronic devices;
an accessibility/authorization protocol for providing rules for authentication and validation of said plurality of electronic devices, user interfaces, executable instructions and data, resources and contacts;
firmware for executing instructions and processing data for authenticating a plurality of user inputs having a plurality of authentication elements;
wherein said set of authorization operations comprise instructions and data for use of a hierarchy of layers, said hierarchy of layers comprising
a user authentication layer operating on said associated electronic device;
a validation layer for validating an intended operation from a set of authorized operations;
a contextual layer or allowing said set of authorized operations only under a set of specified contexts, including geo-location, date and time contexts;
an allowable resource layer for allowing said set of authorized operations according to allowable resources from a set comprising data, information, messages, audio data, image data, files and media;
a resolution layer for executing a plurality of resolution operations when an authentication operation fails according to a predetermined hierarchy of actions, said hierarchy actions depending upon the state of said server and said associated electronic device.
2 . The server of claim 1 , further comprising authentication elements grouped for multi-factor (primary, secondary, tertiary or more) simultaneous or near simultaneous authentication and/or authorization, said authentication elements comprising multi-step (initiation and persistent) authentication and/or authorization process for creating a sequence of methods according to a group of predefined settings that may depend on availability and status of devices, sensors and environmental conditions.
3 . The server of claim 1 , further comprising authentication elements for performing said authentication operation in a remote device with authentication relayed via secure encrypted means, and further whereby said authentication operation is performed in an external device is passive, comprising a beacon or RFID tag, for interacting with one or more of the devices for authentication and/or context validation.
4 . The server of claim 1 , further comprising authentication elements including, but are not limited to one or a combination of passcodes, facial or hand gestures, device gesture, signature, biometrics, from the group comprising voice, fingerprint, facial recognition, and retinal scan.
5 . The server of claim 1 , further comprising authentication elements according to a set of predefined user preferences for providing user or user group authorizations.
6 . The server of claim 5 , further comprising authentication elements for granting access to or deny access to using the computing device(s) (e.g., a phone, a tablet, a desktop computer, a router, a control panel, a Programmable Logic Controller, etc.).
7 . The server of claim 5 , further comprising authentication elements for granting access to or deny access to perform an operation (e.g., launch an application, delete a file, print an image, edit a document, take a photograph, change volume, use microphone, access GPS, etc.).
8 . The server of claim 5 , further comprising authentication elements for granting the ability or deny ability for executing specific action within an application (e.g., read a message).
9 . The server of claim 5 , further comprising authentication elements for granting the ability or deny ability for performing a specific action within an application on allowed resources (e.g., read Mary Jones messages).
10 . The server of claim 5 , further comprising authentication elements for granting the ability or deny ability for performing a specific action within an application on allowed resources based on certain allowed context (e.g., write emails @office, @work_days+@work_hours)
11 . The server of claim 5 , further comprising authentication elements for predefining whether one or multiple of the multitude of authentication(s) is to be a one-time authentication or a persistent authentication, said one-time or persistent authentication(s) combinable by having one or a multitude of one-time or persistent authentications, and useable in a multitude of operations and resources where authentication is required (e.g. launching an app, reading a message, and other examples of authorizations herein disclosed.).
12 . The server of claim 1 , further comprising persistent authentication further comprising one or a combination of passcodes, facial or hand gestures, device gesture, signature, biometrics from the group consisting of voice, fingerprint, facial recognition, and retinal scan), wherein said authentication is performed in the device and a plurality of persistent authentications formed to be continuous with any user predefined protocol rules to how often the authentication is verified, and further comprising user instructions for providing authority and ability to temporarily suspend persistent authentication or override the frequency (time period) of authentication verification if they have all of the required authentication (user, operation, resource and context).
13 . A method for authorizing a set of authorized operations on allowable associated circuits in associated electronic devices, comprising:
providing circuitry, computer processors, and computer processor instructions, executable computer operation instructions and data, and password and/or biometric persistent user authentication algorithms; providing using said server system a set of authorized operations further comprising a set of operating system level functions on an associated electronic device and on an identified application on said associated electronic device, operating said set of authorization operations to occur on circuitry, said circuitry comprising—
circuitry and executable instructions for authorizing a specified user input through one or more potentially heterogeneous electronic devices having potentially different computational capabilities;
a plurality of sensors distributed among said electronic devices;
an accessibility/authorization protocol for providing rules for authentication and validation of said plurality of electronic devices, user interfaces, executable instructions and data, resources and contacts;
firmware for executing instructions and processing data for authenticating a plurality of user inputs having a plurality of authentication elements;
performing said set of authorization operations comprise instructions and data for use of a hierarchy of layers, said hierarchy of layers comprising
a user authentication layer operating on said associated electronic device;
a validation layer for validating an intended operation from a set of authorized operations;
a contextual layer or allowing said set of authorized operations only under a set of specified contexts, including geo-location, date and time contexts;
allowing, said an allowable resource layer, said set of authorized operations according to allowable resources from a set comprising data, information, messages, audio data, image data, files and media; and
using a resolution layer for executing a plurality of resolution operations when an authentication operation fails according to a predetermined hierarchy of actions, said hierarchy actions depending upon the state of said server and said associated electronic device.
14 . The method of claim 13 , further comprising grouping said authentication elements for multi-factor (primary, secondary, tertiary or more) simultaneous or near simultaneous authentication and/or authorization, said authentication elements comprising multi-step (initiation and persistent) authentication and/or authorization process for creating a sequence of methods according to a group of predefined settings that may depend on availability and status of devices, sensors and environmental conditions.
15 . The method of claim 13 , further performing said authentication operation in a remote device with authentication relayed via secure encrypted means, and further whereby said authentication operation is performed in an external device is passive, comprising a beacon or RFID tag, for interacting with one or more of the devices for authentication and/or context validation.
16 . The method of claim 13 , further providing said set of authentication elements to include, but not be limited to one or a combination of passcodes, facial or hand gestures, device gesture, signature, biometrics, from the group comprising voice, fingerprint, facial recognition, and retinal scan.
17 . The method of claim 13 , further providing said authentication elements according to a set of predefined user preferences for providing user or user group authorizations.
18 . The method of claim 17 , further providing said authentication elements for granting access to or deny access to using the computing device(s) (e.g., a phone, a tablet, a desktop computer, a router, a control panel, a Programmable Logic Controller, etc.).
19 . The method of claim 17 , further comprising the steps of granting access to or deny access to perform an operation (e.g., launch an application, delete a file, print an image, edit a document, take a photograph, change volume, use microphone, access GPS, etc.).
20 . The method of claim 17 , further comprising the step of granting the ability or deny ability for executing specific action within an application (e.g., read a message).
21 . The method of claim 17 , further comprising the step of granting the ability or deny ability for performing a specific action within an application on allowed resources (e.g., read Mary Jones messages).
22 . The method of claim 17 , further comprising the step of granting the ability or deny ability for performing a specific action within an application on allowed resources based on certain allowed context (e.g., write emails @office, @work_days+@work_hours)
23 . The method of claim 17 , further comprising the step of predefining whether one or multiple of the multitude of authentication(s) is to be a one-time authentication or a persistent authentication, said one-time or persistent authentication(s) combinable by having one or a multitude of one-time or persistent authentications, and useable in a multitude of operations and resources where authentication is required (e.g. launching an app, reading a message, and other examples of authorizations herein disclosed.).
24 . The method of claim 13 , further comprising the step of providing persistent authentication further comprising one or a combination of passcodes, facial or hand gestures, device gesture, signature, biometrics from the group consisting of voice, fingerprint, facial recognition, and retinal scan, wherein said authentication is performed in the device and a plurality of persistent authentications formed to be continuous with any user predefined protocol rules to how often the authentication is verified, and further comprising user instructions for providing authority and ability to temporarily suspend persistent authentication or override the frequency (time period) of authentication verification if they have all of the required authentication (user, operation, resource and context).Join the waitlist — get patent alerts
Track US2023023664A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.