Proximity-based system for automatic application initialization

Patent No. US9450956 (titled "Proximity-based system for automatic application initialization") on Nov 5, 2014. The application was issued on Sep 20, 2016.

What is this patent about?

’956 is related to the field of radio frequency identification (RFID) and electronic authentication, specifically within high-traffic environments like healthcare facilities. In these settings, the constant manual entry of usernames and passwords for secure terminals creates significant workflow bottlenecks. The background context involves the need for a system that can distinguish between multiple authorized users in close proximity while maintaining strict security protocols for sensitive data access.

The underlying idea behind ’956 is the use of a Personal Digital Key (PDK)—a portable wireless token—that carries not just identity data, but also a user priority hierarchy. The inventive insight lies in managing shared computing resources by resolving conflicts between multiple detected keys. Instead of a simple first-come-first-served approach, the system evaluates the relative priority levels stored on the keys to determine which user should be granted control or if a higher-ranking user should be allowed to override an active session.

The claims of ’956 focus on a system and method for managing access to a shared computing device based on the detection of multiple PDKs within a proximity zone. The independent claims specifically cover the mechanism of detecting a first user, granting them access, and then detecting a second, previously non-present user. The system then decides whether to grant the second user access to the device or the first user's active session by comparing the first user priority against the second user priority retrieved directly from the respective keys.

In practice, the invention functions as an automated gatekeeper for workstations. When a healthcare provider enters the wireless range of a reader, the system identifies their PDK and logs them in. If a second provider enters the same zone, the reader captures their priority data. If the second provider has a higher priority—such as a doctor needing to override a nurse's session in an emergency—the system facilitates this transition automatically based on the priority-based determination logic.

This approach differs from prior solutions by moving away from static, manual login procedures and simple proximity-based triggers. By embedding priority information within the portable keys themselves, the system can dynamically manage multi-user environments without requiring a central server to constantly arbitrate every interaction. This allows for seamless user switching and session takeovers that are essential in fast-paced clinical environments where immediate access to data can impact patient outcomes.

How does this patent fit in bigger picture?

Technical Landscape

In the early 2010s when ’956 was filed, secure access to sensitive electronic records was typically implemented using manual credential entry, such as unique usernames and passwords, at fixed workstations. At a time when systems commonly relied on active user intervention for both login and logout procedures to maintain security, the management of session persistence was often a trade-off between administrative overhead and data protection. Hardware and software constraints made the seamless transition between different terminal locations non-trivial, as authentication state was generally bound to specific local sessions rather than the physical proximity of the user. Furthermore, the tracking of mobile physical assets within a facility was often limited to periodic manual inventories or static logging, as real-time integration between identity management and asset location was not a standard architectural feature of enterprise software environments.

Prosecution Position

The disclosed invention represents a meaningful technical advancement through the integration of a portable physical token, referred to as a Personal Digital Key (PDK), with a proximity-based biometric verification architecture. This solution shifts the authentication paradigm from manual input to an automated, multi-factor process where a local reader validates a live biometric sample against a profile stored directly on the user's portable hardware. This architectural shift enables the technical capability of automatic application launching and data retrieval tailored to specific user roles or group memberships immediately upon detection. By decoupling the authentication credentials from the central server and placing them on a localized, secure hardware device that interacts with an auto-login server, the system overcomes the technical constraint of time-intensive manual logins while maintaining high security standards. Additionally, the architecture enables the simultaneous tracking of assets and users by associating PDK identifiers with group-based priority rules, allowing for context-aware access control based on the physical location and professional role of the individual.

Claims

The patent contains a total of 20 claims, with claims 1 and 7 serving as the independent claims. These independent claims focus on a system and method for managing access to a shared computing device by utilizing personal digital keys that store user priority information, allowing a second user to access the device or an active session based on their priority relative to an initial user. The dependent claims generally serve to add specific technical layers to this process, such as incorporating biometric authentication, automating login and application launching procedures, managing session security when a user leaves a proximity zone, and applying user-specific or group-based preferences to the computing environment.

Key Claim Terms New

Definitions of key terms used in the patent claims.

Term (Source)Support for SpecificationInterpretation
Personal digital key
(Claim 1, Claim 7)
A portable physical device, referred to herein as a Personal Digital Key or “PDK”, stores one or more profiles uniquely associated with a user in a memory. In one embodiment, one of the profiles is a biometric profile that is acquired in a secure trusted process and is uniquely associated with a user authorized to use the PDK and associated with the PDK. A reader wirelessly communicates with the PDK and receives a profile from the PDK.A portable physical device that stores one or more profiles uniquely associated with a user in a memory, including priority information, and communicates wirelessly with a reader to facilitate automatic authentication.
Proximity zone
(Claim 1, Claim 7)
A reader wirelessly communicates with the PDK and receives a profile from the PDK. A computing device is coupled to the reader and displays data on a display device responsive to receiving data associated with the profile from the reader.A defined physical area surrounding a reader within which the reader is capable of detecting and wirelessly communicating with a Personal Digital Key (PDK).
Session
(Claim 1, Claim 7)
The auto login server receives the profile from the reader and automatically launches, on the computing device, one or more applications associated with a user name identified by the profile. In one embodiment, a user's group membership determines a default scenario or one or more applications that auto launch.An active state of authenticated access or an instance of running applications on a computing device associated with a specific user's identity and profile.
Shared computing device
(Claim 1, Claim 7)
A computing device is coupled to the reader and displays data on a display device responsive to receiving data associated with the profile from the reader. Additionally, an auto login sever is coupled to the computing device and to the reader and the auto login server receives the profile from the reader and automatically launches, on the computing device, one or more applications associated with a user name identified by the profile.A workstation or computer terminal configured to be used by multiple users, where access and application launching are managed based on the detection of PDKs and their relative priorities.
User priority
(Claim 1, Claim 7)
In one embodiment, the groups are part of established priority rules and user hierarchies, which can permit or exclude member access to particular workstations or applications. For example, not allowing a billing clerk to login at computing device 120 in an exam room. In one embodiment, a user's group membership determines a default scenario or one or more applications that auto launch.A hierarchical ranking or status associated with a user, often derived from group membership or roles, used to determine access rights or the ability to override/interact with an active session on a shared device.

Litigation Cases New

US Latest litigation cases involving this patent.

Case NumberFiling DateTitle
6:25-cv-00016Jan 14, 2025Proxense, Llc V. Hyundai Motor Company

Patent Family

Patent Family

File Wrapper

The dossier documents provide a comprehensive record of the patent's prosecution history - including filings, correspondence, and decisions made by patent offices - and are crucial for understanding the patent's legal journey and any challenges it may have faced during examination.

  • Get instant alerts for new documents

US9450956

Application Number
US14534045A
Filing Date
Nov 5, 2014
Publication Date
Sep 20, 2016
External Links
Slate, USPTO , Google Patents