System and Method for Authentication Across Multiple Platforms Using Biometric Data
A system and method for authenticating a system user across multiple digital systems using a single biometric key employs a scanning device to preclude the use of passwords and login identifiers when signing into secured digital environments. The scanning device performs a primary biometric scanning operation to obtain a primary multipoint digital image for an anatomical feature of the system user. The primary multipoint digital image is then associated with a system password and username for each of a plurality of secured digital systems. By connecting the scanning device to an external computing device and performing a subsequent biometric scanning operation, the scanning device is able to authenticate the system user and retrieve the system password and username for a specific secured digital system from the plurality of secured digital systems. A data vault is provided to back-up data and restore the scanning device when the system user is authenticated.
The current application is a 371 of international PCT application serial number PCT/IB2016/052871 filed on May 17, 2016 which claims benefit of U.S. provisional patent application Ser. No. 62/244,571 filed on Oct. 21, 2015.
FIELD OF THE INVENTIONThe present invention relates generally to a biometric scanner based user authentication platform. More specifically the present invention is a system and method which enables an individual to use a single biometric data key in place of a plurality of passwords.
BACKGROUND OF THE INVENTIONCreating secured digital environments is essential in the modern age. One needs to only turn on the news to hear of data breach scandal after data breach scandal. Everyone, from the average citizen to Fortune 500 companies, has become a target for malevolent individuals seeking to access secure information. To combat the ever increasing frequency of brazen virtual attacks, users are forced to implement authentication protocols of greater and greater complexity. To compound the problem of the increasingly complex data security protocols, users must memorize multiple passwords for multiple digital services.
The problem of passwords can be likened to a curse of dimensionality. That is, as users are required to create multiple passwords to access an ever increasing number of digital systems, the difficulty in maintaining these passwords increases for the user. A common response to this problem is to use a single password for multiple services. This practice, however, is quite flawed and decreases the overall security of a user's personal information. If a malicious individual is able to acquire this password, he will be able to access many of the user's accounts. Therefore, users seem to be in a double bind situation. Biometric authentication has been proposed as a possible means of mitigating this issue. Because biometric data is intrinsically unique, it negates the need to memorize passwords for user authentication. One noticeable failing is the depth of penetration of digital services which accept biometric user authentication. Because of this, the effectiveness of robust biometric authentication systems is significantly reduced. At times users must memorize some passwords, in other instances they are able to biometrically authenticate.
Therefore, it is an object of the present invention to provide a biometric scanner that can be used for authentication across multiple platforms. The present invention addresses the issue of memorizing multiple passwords by providing a biometric authentication platform which generates, or inserts, valid passwords into various digital systems. This is accomplished by creating a digital user profile for a system user; the digital user profile containing the username and password data required to access a plurality of secured digital systems. Once the digital user profile is created, a scanning software correlates biometric data obtained from an anatomical feature of the system user with the username and password data required to access the plurality of secured digital systems. Using the platform provided by the present invention enables the system user to forego the arduous process of creating and memorizing passwords.
It is another object of the present invention to provide a data vault that can be used to back-up the scanning device and restore data on the scanning device. The scanning device can be docked in the data vault, wherein the data vault is able to determine whether to perform a back-up function or a restore function. The scanning software on the scanning device is used to authenticate the system user before performing either the back-up function or the restore function. In this way, data can be securely maintained on the data vault.
All illustrations of the drawings are for the purpose of describing selected versions of the present invention and are not intended to limit the scope of the present invention.
The present invention is a system and method for authenticating a system user across multiple digital systems using a single biometric key. It is an aim of the present invention to provide a handheld device and an associated software platform which work in concert to function as a physical key enabling user authentication on digital systems. In reference to
The scanning device 1 acquires and stores biometric data, while the scanning software analyzes the biometric data. The biometric data acquired by the scanning device 1 is used to access a plurality of secured digital systems in place of using traditional passwords. In the preferred embodiment of the present invention, the scanning software performs the translation and handshaking operations required to use the biometric data of the system user as an access code for the plurality of secured digital systems. The data vault 10 is used to store a back-up copy of the biometric data and system passwords, wherein the data vault 10 can be used to restore the scanning device 1 if the scanning device 1 is compromised. Furthermore, the latest settings of the scanning device can be copied from the scanning device 1 to the data vault 10 in order to synchronize both devices.
In the preferred method of use, the present invention provides a secured authentication platform which maintains a locally encrypted record of user data. To accomplish this task, the scanning device 1 comprises a biometric scanner 2, a microcontroller 3, an onboard memory bank 4, and an external device interconnect 7 [100]. The scanning software runs on the microcontroller 3 to perform all required password selection, encryption, and generation operations. To begin using the scanning device 1 as a password manager for the plurality of secured digital systems, the system user creates a digital user profile with the scanning software. The digital user profile contains a list of each of the plurality of secured digital systems with which the system user is affiliated. Additionally, the digital user profile contains a system password for each of the plurality of secured digital systems in order to access each of the plurality of secured digital systems.
In reference to
After the digital user profile is created, the system user places a finger onto the scanning device 1; more specifically, onto the biometric scanner 2. In reference to
In reference to
In reference to
When the system user desires to access a specific secured digital system from the plurality of secured digital systems, the system user first connects the scanning device 1 to an external computing device. The term ‘external computing device’ is used herein to refer to any electronic system capable of accessing—or requesting access to—secured digital environments. Examples of external computing devices include, but are not limited to, computers, smartphones, tablets, security systems, and the like. In reference to
After the scanning device 1 is connected to the external computing device and the handshaking operation is performed with the specific secured digital system, a subsequent biometric scanning operation can be carried out to authenticate the system user. In reference to
To perform the subsequent biometric scanning operation, the biometric scanner 2 first scans the anatomical feature of the system user in order to obtain the necessary biometric data. The microcontroller 3 then utilizes the biometric data to generate the subsequent multipoint digital image of the anatomical feature, wherein the subsequent multipoint digital image includes unique attributes of the anatomical feature. In reference to
When the system user is successfully authenticated by matching the subsequent multipoint digital image to the primary multipoint digital image, the microcontroller 3 searches through the list of the plurality of secured digital systems for the specific secured digital system. In reference to
In the preferred embodiment of the present invention, the primary biometric scanning operation performed by the biometric scanner 2 acquires fingerprint data. The system user places a finger on the biometric scanner 2, wherein the biometric scanner 2 scans the finger and the microcontroller 3 generates the primary multipoint digital image of the finger. To access the plurality of secured digital systems each subsequent time, the system user places the finger on the biometric scanner 2, wherein the subsequent multipoint digital image is generated to authenticate the system user. In other embodiments of the present invention, various other types of biometric data may be acquired. For example, the primary biometric scanning operation may be a retinal scan, vocal scan to obtain vocal fingerprints, or a vein map.
In reference to
In reference to
In reference to
The first indicator 13 corresponds to one of the ports, while the second indicator 14 correspond to the other port. More specifically, the first indicator 13 corresponds to the first port 17, while the second indicator 14 corresponds to the second port 18, as depicted in
In reference to
While performing the back-up function, the digital user profile and the system password for each of the plurality of secured digital systems are transferred from the onboard memory bank 4 to the vault memory bank 16. The digital user profile and the system password for each of the plurality of secured digital systems are stored on the vault memory bank 16 as the recent copy. The next time that the restore function is performed, the recent copy will be loaded onto the scanning device 1. In summary, the scanning software authenticates the system user identity via the anatomical feature and then transfers data from the onboard memory bank 4 to the vault memory bank 16 if the system user is authenticated. In this way, data can only be transferred to the data vault 10 in a secured manner and as designated by the system user.
In reference to
While performing the restore function, the recent copy of the digital user profile and the system password for each of the plurality of secured digital systems is transferred from the vault memory bank 16 to the onboard memory bank 4. The digital user profile and the system password for each of the plurality of secured digital systems from the recent copy are stored on the onboard memory bank 4 for future use with the other external computing devices. In summary, the scanning software authenticates the system user identity via the anatomical feature and then transfers data from the vault memory bank 16 to the onboard memory bank 4 if the system user is authenticated. In this way, only the scanning device 1 is able to access the recent copy of the digital user profile and the system password for each of the plurality of secured digital systems stored on the vault memory bank 16.
In reference to
In the preferred embodiment of the present invention, the scanning device 1 is a physical scanner capable of storing user data, connecting to external computing devices, and executing password insertion operations. In reference to
In the preferred embodiment of the present invention, the housing 5 is an ergonomically designed rigid enclosure containing the electronic components of the scanning device 1. In reference to
In the preferred embodiment of the present invention, the internal compartment 50 is the main enclosure within the housing 5 that secures the biometric scanner 2, the microcontroller 3, the onboard memory bank 4, the control circuit 6, the adjustable scanner mount 56, and the external device interconnect 7. It is an aim of the internal compartment 50, in conjunction with the adjustable scanner mount 56, to provide a structure that enables the system user to transition the biometric scanner 2 and the external device interconnect 7 between a retracted position and an extended position, as shown in
The adjustment slot 51 is an opening about one face of the housing 5. The adjustment slot 51 is positioned adjacent to the internal compartment 50, wherein the adjustment slot traverses into the internal compartment 50. The adjustment slot 51 allows the biometric scanner 2 to be accessed by the system user to perform scanning operations, when the present invention is configured in the extended position. In some embodiments, the biometric scanner 2 protrudes through the adjustment slot 51 while in the extended position, thus increasing the ease of interfacing with the biometric scanner 2 to obtain a multipoint digital image. In reference to
The biometric scanner 2 and the external device interconnect 7 are mounted onto the adjustable scanner mount 56, such that the biometric scanner 2, the external device interconnect 7, and the adjustable scanner mount 56 move in tandem. As such, the adjustment rail 52 defines the path along which the biometric scanner 2 and the external device interconnect 7 travel while transitioning between the extended position and the retracted position. In the extended position, the biometric scanner 2 is positioned adjacent to the adjustment slot 51, while the external device interconnect 7 traverses out of the housing 5 through the interconnect channel 55. Meanwhile, in the retracted position, the biometric scanner is offset from the adjustment slot 51, while the external device interconnect 7 is positioned within the housing 5.
In reference to
In a first embodiment, the adjustment locking mechanism 53 is positioned along the adjustment rail 52, wherein the adjustment locking mechanism 53 is a ridge of material protruding from the adjustment rail 52. As the system user slides the biometric scanner 2 into the extended position, the adjustable scanner mount 56 passes over the ridge. Once the adjustable scanner mount 56 passes over the adjustment locking mechanism 53, the adjustable scanner mount 56 becomes wedged between the adjustment locking mechanism 53 and an interior wall of the housing 5. In this position, the external device interconnect 7 is protruding from the interconnect channel 55 and able to establish a physical connection with an external computing device. To disengage the adjustment locking mechanism 53 in the first embodiment, the system user must apply force in one direction to dislodge the adjustable scanner mount 56.
In a second embodiment the adjustment locking mechanism 53 is a button slider, which retains the biometric scanner 2 in the extended position when engaged. To disengage the adjustment locking mechanism 53 in the second embodiment, the system user moves the button slider into the unlocked position. In other embodiments, the adjustable locking mechanism 53 may include other components such as a spring mechanism or other moveable locking parts that are used to re-position the adjustable scanner mount 56 within the housing 5 when the adjustable locking mechanism 53 is actuated by the system user.
In reference to
The interconnect channel 55 is a hole extending from the internal compartment 50 out of the exterior of the housing 5. That is, the interconnect channel 55 is positioned adjacent to the internal compartment 50 and forms an opening into the internal compartment 50, similar to the adjustment slot 51. The interconnect channel 55 forms the pathway through which the external device interconnect 7 travels while being transitioned between the retracted position and the extended position. In the retracted position, the external device interconnect 7 is at least partially stored within the interconnect channel 55. While transitioning from the retracted position to the extended position, the external device interconnect 7 passes through the interconnect channel 55, wherein the external device interconnect 7 protrudes from the housing 5 while in the extended position. In this way, the external device interconnect 7 may interface with an external computing device while in the extended position.
In the preferred embodiment of the present invention, the microcontroller 3 is adjacently connected to the adjustable scanner mount 56, while the biometric scanner 2 is mounted onto the microcontroller 3, such that the microcontroller 3 is positioned in between the adjustable scanner mount 56 and the biometric scanner 2. As such, the adjustable scanner mount 56 forms the intermediary connector between the housing 5 and both the microcontroller 3 and the biometric scanner 2. The biometric scanner 2 is oriented towards the adjustment slot, such that the biometric scanner 2 can be accessed by the system user when the adjustable scanner mount 56 is slid along the adjustment rail 52 into the extended position. Furthermore, the external device interconnect 7 is connected to the microcontroller 3, such that the external device interconnect 7 is oriented towards the interconnect channel 55. In this way, the external device interconnect 7 may traverse through the interconnect channel 55 when the adjustable scanner mount 56 is displaced within the housing 5.
In the preferred embodiment of the present invention the biometric scanner 2 is a device used to create digital representations of unique body characteristics of the system user. The biometric scanner 2 is slidably attached to the housing 5 via the connection formed between the adjustable scanner mount 56 and the adjustment rail 52. It is an aim of the biometric scanner 2 to provide a sensory unit which is manipulated by the system user to move from a hidden position (i.e. the retracted position) into an exposed position (i.e. the extended position). In reference to
In the preferred embodiment of the present invention, the microcontroller 3 functions as the central processing unit which coordinates communication between the scanning device 1 and the external computing devices, correlates acquired biometric data to the system password of each of the plurality of secured digital systems, and encrypts all data stored on the onboard memory bank 4. The external device interconnect 7, the biometric scanner 2, and the onboard memory bank 4 are electronically connected to the microcontroller 3. The microcontroller 3 is maintained in electrical communication with the biometric scanner 2, the external device interconnect 7, and the onboard memory bank 4 via the control circuit 6, as depicted in
In reference to
In an alternative embodiment of the present invention, the scanning device 1 is integrated into a credit card. In this embodiment, the anatomical feature (e.g. a finger) of the system user functions as an electrical contact switch in conjunction with the biometric scanner 2. When the credit card is inserted into a merchant terminal, the system user places the finger on the biometric scanner 2, wherein the finger completes an electrical circuit formed by the credit card and the merchant terminal. With the finger completing the circuit between the credit card and the merchant terminal, current is passed through the credit card in order to power the scanning device 1.
The alternative embodiment, the external device interconnect 7 comprises a first terminal and a second terminal, and the control circuit 6 is a digital circuitry. The first terminal and the second terminal are positioned opposite the biometric scanner 2, along the credit card body (i.e. the housing 5), wherein the first terminal and the second terminal provide electrical contacts that engage the merchant terminal. Meanwhile, the digital circuitry is integrated throughout the credit card and electrically connects the first terminal and the second terminal to the biometric scanner 2. When the credit card is inserted into the merchant terminal and the system user places the finger on the biometric scanner 2, current is drawn from the merchant terminal to power the scanning device 1. Once current is supplied to the scanning device 1, the biometric scanner 2 reads twenty-four points of biometric information to generate the subsequent multipoint digital image and validate the identity of the system user using the primary multipoint digital image. The present invention then allows and authorizes the transaction to go through.
In the preferred embodiment of the present invention, the scanning software is a program tasked with acquiring biometric data and communicating the biometric data between the scanning device 1 and the external computing devices. The scanning software comprises a profile engine, a scanning engine, an application programming interface (API) engine, a password engine, and an encryption engine. It is an aim of the scanning software to provide a program which works in concert with the scanning device 1 to create a system that uses a single device to access multiple digital systems. The term engine is used herein to refer to collections of programs which are grouped based upon function.
The profile engine is tasked with storing personal user data of the system user, the list of the plurality of secured digital systems, and the system password associated with each of the plurality of secured digital systems. Meanwhile, the API engine is tasked with performing all of the handshaking operations required to communicate with the external digital system and send the system password for the specific secured digital system to the specific secured digital system. That is, the API engine communicates with the specific secured digital system, and is used to insert the appropriate password into the specific secured digital system.
In the preferred embodiment of the present invention, the scanning engine controls the operation of the biometric scanner 2. The scanning engine is tasked with forming the primary multipoint digital image of the anatomical feature of the system user. The primary multipoint digital image uses multiple points of data which correspond to the unique physical features of the anatomical feature. In the preferred embodiment of the present invention, the primary multipoint digital image generated by the scanning engine contains at least twenty-four unique data points of a fingerprint.
In the preferred embodiment of the present invention, the password engine is used to create unique passwords for the plurality of secured digital systems which do not currently exist within, and need be added to, the digital user profile. The profile engine enables the system user to create unique passwords for any secured digital system by connecting the scanning device 1 to an external computing device and performing a scanning operation. More specifically, the primary multipoint digital image is used as each of the unique passwords. In the preferred embodiment of the present invention, the encryption engine secures any data created by the scanning software. More particularly, the encryption engine encrypts the system password for each of the plurality of secured digital systems, the personal user data, and biometric data used by the present invention.
Although the invention has been explained in relation to its preferred embodiment, it is to be understood that many other possible modifications and variations can be made without departing from the spirit and scope of the invention as hereinafter claimed.
Claims
1. A system for utilizing biometric data to authenticate an individual across multiple digital systems comprises:
- a scanning device comprising a housing, a slot panel, an adjustable scanner mount, an external device interconnect, a biometric scanner, a microcontroller, and an onboard memory bank;
- the housing comprising an internal compartment, an interconnect channel, and an adjustment slot;
- the external device interconnect, the biometric scanner, and the onboard memory bank being electronically connected to the microcontroller;
- the interconnect channel being positioned adjacent to the internal compartment;
- the adjustment slot traversing into the internal compartment;
- the adjustable scanner mount being slidably mounted within the housing;
- the biometric scanner and the external device interconnect being mounted onto the adjustable scanner mount;
- the biometric scanner being oriented towards the adjustment slot;
- the external device interconnect being oriented towards the interconnect channel; and
- the slot panel being slidably mounted to the housing about the adjustment slot.
2. The system for utilizing biometric data to authenticate an individual across multiple digital systems as claimed in claim 1 comprises:
- the internal compartment comprising an adjustment rail; and
- the adjustable scanner mount being slidably engaged with the adjustment rail.
3. The system for utilizing biometric data to authenticate an individual across multiple digital systems as claimed in claim 2 comprises:
- the internal compartment further comprising an adjustment locking mechanism; and
- the adjustment locking mechanism being positioned along the adjustment rail.
4. The system for utilizing biometric data to authenticate an individual across multiple digital systems as claimed in claim 1 comprises:
- the internal compartment comprising an adjustment locking mechanism; and
- the adjustable scanner mount being selectively engaged with the adjustment locking mechanism.
5. The system for utilizing biometric data to authenticate an individual across multiple digital systems as claimed in claim 1 comprises:
- the scanning device further comprising a transceiver; and
- the transceiver being electronically connected to the microcontroller.
6. The system for utilizing biometric data to authenticate an individual across multiple digital systems as claimed in claim 1 comprises:
- the scanning device further comprising a power supply; and
- the power supply being electrically connected to the biometric scanner, the onboard memory bank, and the microcontroller.
7. The system for utilizing biometric data to authenticate an individual across multiple digital systems as claimed in claim 6 comprises:
- the scanning device further comprising a transceiver; and
- the transceiver being electrically connected to the power supply.
8. The system for utilizing biometric data to authenticate an individual across multiple digital systems as claimed in claim 1 comprises:
- the slot panel being offset from the adjustment slot;
- the biometric scanner being positioned adjacent to the adjustment slot; and
- the external device interconnect traversing out of the housing through the interconnect channel.
9. The system for utilizing biometric data to authenticate an individual across multiple digital systems as claimed in claim 1 comprises:
- the slot panel being positioned adjacent to the adjustment slot;
- the biometric scanner being offset from the adjustment slot; and
- the external device interconnect being positioned within the housing.
10. The system for utilizing biometric data to authenticate an individual across multiple digital systems as claimed in claim 1 comprises:
- a data vault comprising a logic board, a vault memory bank, a first port, and a second port;
- the vault memory bank, the first port, and the second port being electronically connected to the logic board; and
- the first port and the second port being configured to receive the external device interconnect.
11. The system for utilizing biometric data to authenticate an individual across multiple digital systems as claimed in claim 10 comprises:
- the logic board being configured to transfer data from the scanning device to the vault memory bank when the scanning device is docked within the first port.
12. The system for utilizing biometric data to authenticate an individual across multiple digital systems as claimed in claim 10 comprises:
- the logic board being configured to transfer data from the vault memory bank to the scanning device when the scanning device is docked within the second port.
13. The system for utilizing biometric data to authenticate an individual across multiple digital systems as claimed in claim 10 comprises:
- the logic board comprising a first indicator and a second indicator;
- the first indicator corresponding to the first port; and
- the second indicator corresponding to the second port.
14. The system for utilizing biometric data to authenticate an individual across multiple digital systems as claimed in claim 10 comprises:
- the data vault further comprising a vault power supply; and
- the vault power supply being electrically connected to the logic board, the vault memory bank, the first port, and the second port.
15. The system for utilizing biometric data to authenticate an individual across multiple digital systems as claimed in claim 1 comprises:
- the biometric scanner being a finger print scanner.
Type: Application
Filed: Apr 23, 2018
Publication Date: Aug 30, 2018
Inventors: Bob A. Schuster (Aiea, HI), David Delaune (Honolulu, HI)
Application Number: 15/960,299