Biometric access sensitivity
12 claims: 4 independent, 8 dependent
- 1[0052] While the foregoing invention has been described in some detail for purposes of clarity and understanding, it will be appreciated by one skilled in the art, from a reading of the disclosure, that various changes in form and detail can 5 be made without departing from the true scope of the invention as defined in the appended claims. Claims :1. A method of detecting a change of user of a gaming device comprising: receiving, at an input device associated with the gaming device, at least one item of identity verification data from a user of the gaming device;enabling at least one service on the gaming device based on a match between the at least one item of identity verification data received and at least one item of identity verification data obtained previously;sensing, with a biometric sensor associated with the gaming device, at least one item of behavioural biometric data from a user during game play, wherein the at least one item of behavioural biometric data relates to at least one of blood pressure, heart rate, body temperature, speech, handwriting and body movement of a user;comparing, in a processing means, the at least one item of behavioural biometric data with an item of behavioural biometric data obtained previously;determining whether or not a user change has occurred on the basis of the comparison;and outputting a request to the user to input identity verification data if it is determined that a user change has occurred. The method of claim 1, comprising repeatedly sensing items of behavioural biometric data.
- 45. The method of any of claims 1 to 4, wherein the 25 identity verification data comprises physical biometric data.
- 67. The method of any preceding claim, further 10 comprising the steps of:comparing at least one of the identity verification data and the behavioural biometric data with data obtained previously;establishing a level of confidence associated 15 with the comparison;and determining whether or not the user is to be ’·***· prompted for identity verification data based on the ······ level of confidence associated with the comparison. ··· · • · · · * i’“2o
- 89. The method of any preceding claim, further 25 comprising the steps of:establishing a plurality of different error classifications;comparing at least one of the identity verification data and the behavioural biometric data 5 with data obtained previously;determining an error classification associated with the comparison from the established plurality of error classif ications ,· and determining whether or not the user is to be 10 prompted for identity verification data based on the error classification associated with the comparison.
- 1113. Electronic gaming apparatus comprising:a gaming device having input means for inputting at least one item of identity verification data from a user of the gaming device;means for storing at least one item of identity 10 verification data relating to the user;means for enabling at least one service on the gaming device based on a match between the at least one item of identity verification data input and at least one stored item of identity verification data;fsensor means associated with the gaming device for sensing at least one item of behavioural biometric • · data from a user, wherein the at least one item of behavioural biometric data relates to at least one of ·· · · *····* blood pressure, heart rate, body temperature, speech, • 20 handwriting and body movement of a user;·*·**· storage means for storing at least one item of *1”*: behavioural biometric data of the user;processing means for comparing a sensed item of behavioural biometric data with a stored item of 25 behavioural biometric data;means for determining whether or not a user change has occurred on the basis of the comparison;and means for delivering a prompt to the user to 5 input identity verification data if it is determined that a user change has occurred.
Independent claims5
114 paragraphs in 7 sections, as filed
3/3
404
Activate Gaming Device
Display First Interface Screen
406 —_ ———
Determine Location of Gaming Device
418
<img file="GB2458049B_D0001.tif" />
408
Y
N ew User
Activated
Device?
Register User/Activate Device
410
412
Receive Identity Validation Data
<img file="GB2458049B_D0002.tif" />
.................. S —......................M .............
Determine Surveillance Level of Location
Receive User Preferences
414
Obtain Identity Validation Data Based on Location/Serveillance Level
420
Store Identity
416
Compare Identity Validation Data
422
Validation Data/ User__J Preferences
N
<img file="GB2458049B_D0003.tif" />
424
Authorized
User?
426
Determine Location Based Service Limits
428
Determine User Preferences
430
Display Service-Type Interface Screen F
FIG. 4
432
Obtain User Change Data
436
Prompt User for Identity Validation Data
<img file="GB2458049B_D0004.tif" />
434
N
User
438
<img file="GB2458049B_D0005.tif" />
Location
Change?
BIOMETRIC ACCESS SENSITIVITY
[0001] The present invention relates to apparatus and methods of detecting, after an identity verification has taken place, a change of user of an electronic gaming apparatus. One aspect of the invention provides an electronic gaming method as defined in claim 1. A second aspect provides an electronic gaming apparatus as defined in claim 12.
BRIEF DESCRIPTION OF THE FIGURES
[0002] FIG. 1 illustrates a gaming system according to at least one embodiment of the systems disclosed herein;
[0003] FIG. 2 illustrates a gaming system according to at least one embodiment of the systems disclosed herein;
[0004] FIG. 3 illustrates a gaming system according to at least one embodiment of the systems disclosed herein; and
[0005] FIG. 4 is a flow chart of a method according to at least one embodiment of the methods disclosed herein.
DETAILED DESCRIPTION OF THE INVENTION
[0006] Referring to FIG. 1, a gaming system 100 according to at least one embodiment of the systems disclosed herein includes at least one computing device, such as a remote computer 118, e.g., a server computer, a gaming device 113, or a combination thereof, which may reside in whole or in part within the domain of a gaming service provider 120. The gaming provider 120 may be the proprietor of a casino and the gaming system 100 may be physically within the geographic boundaries of the casino. Alternatively, the computing device, e.g., the remote computer 118 and/or the gaming device 113, may be remote from the casino. As such, the gaming system 100 may allow users to engage in gaming services and access the other services disclosed herein from remote and/or mobile locations relative to the gaming service provider 120 or relative to the casino.
[0007] The computing device generally includes at least one processor 102, and a memory 104, such as ROM, RAM, FLASH, etc., or any computer readable medium 106, such as a hard drive, a flash-drive, an optical or magnetic disk, etc. The memory 104 or computer readable medium 106 preferably includes software stored thereon that when executed performs one or more steps of the methods disclosed herein, including communicating data back and forth between devices, displaying interface screens, etc. The computing device may also be associated with or have access to one or more databases for retrieving and storing the various types of data discussed herein, including identity verification data, such as an ID and password, physical biometric data, etc., user continuity data, such as behavioural biometric data, proficiency data, player pattern data, etc., and user profile data, such as the user's names, identification number, address, credit or debit card data, account balances, user preferences, device preferences, etc.
[0008] In one embodiment, the system 100 includes a plurality of computing devices, such as a remote computer 118 coupled to at least one gaming device 113 over a communication network 116, which are generally configured or otherwise capable of transmitting and/or receiving communications to and/or from each other. The term remote in this context merely means that the remote computer 118 and the gaming device are separate from each other. Thus, the devices may be remote even if the devices are located within the same room. As such, the gaming device 113 is preferably configured or otherwise capable of transmitting and/or receiving communications to and/or from the remote computer 118. This may be accomplished with a communication element 124, such as a modem, an Ethernet interface, a transmitter/receiver, etc., that enables communication with a similarly equipped remote computer 118, wirelessly, wired, or a combination thereof. It is understood that the relative functionality described herein may be provided by the remote computer 118, by the gaming device 113, or both, and is thus not limited to any one implementation discussed herein.
[0009] The gaming devices 113 may include, without limitation, a mobile phone,
PDA, pocket PC, personal computer, as well as any special or general purpose gaming device, such as a slot machine, a video poker machine, video or computer-based versions of table games, e.g., roulette, blackjack, etc. As such, the gaming device 113 preferably includes a processor 122, a memory 123, a 10 display 125, such as a CRT or an LCD monitor, for displaying information and/or graphics associated with the services provided by the gaming system 100, and at least one input device, such as a mouse, a touch-sensitive pad, a pointer, a stylus, a trackball, a button, e.g., alphanumeric, a scroll wheel, a touch-sensitive monitor, etc., or a combination thereof, for users to enter commands and/or information relevant to the gaming system services. With the general purpose type gaming devices 113, such as the PC or PDA, users may access the services provided by the gaming system 100, e.g., the remote computer 118, with a browser or any other generic application, or with special purpose software designed specifically for accessing and providing the services disclosed herein.
. [0010] In at least one embodiment, the gaming device 113 includes or is otherwise associated with at least one biometric sensor 121. The biometric sensor 121 is any device that is used to determine directly from the user at least one item ; of biometric data associated with a user, such as a fingerprint reader, an iris
5 scanner, a retinal scanner, a vascular pattern reader, a facial recognition camera, , etc. The biometric sensor 121 may be embodied in hardware, software, or a combination thereof. The biometric sensor 121 may further share resources with other components of the gaming device 113, such as the processor 122, memory 123, a camera, a microphone, a speaker, etc. A single biometric sensor 121 may be used for reading more than one type of biometric data. For example, a digital camera may be used to obtain an image of the user's eye for iris scanning and an image of the user s face for facial recognition. In this instance, a single image capture of the users face may provide the data for facial recognition as well as data for iris or retinal comparisons. The biometric data is generally obtained with the biometric sensor 121 and used at least to verify the identity of the user as a gateway for allowing the user to access the services provided with the gaming device 113 and/or the remote computer 118. In this regard, biometric data may be compared with previously obtained/stored physical biometric data that has preferably been authenticated as being associated with a particular authorized user, and access to the gaming system's services may be provided based on a positive match thereof.
[0011] In addition to the physical biometrics discussed above, the biometric sensor 121 may also obtain behavioural biometric data, such as blood pressure, heart or pulse rate, body temperature data, speech, handwriting, keystrokes, body movements, etc. The behavioural biometric data may be analyzed to determine whether there has been a user change or otherwise verify that there has not been a break in user continuity at any time following verification of a user's identify following initial validation with, e.g., the physical biometric data, or ID and password. For example, a user's identity may be verified with a fingerprint reader and access may be provided thereafter to the services provided by the gaming system 100, e.g., for a predetermined period of time or until some predetermined event, such as the gaming device 113 being turned off, the device 113 being moved outside an approved gaming area, etc. The gaming system 100 may thereafter monitor behavioural biometric data with the device and prompt the user for physical biometric data or other identity verification data if it is determined from the behavioural data collected following identity verification that there may have been a change in the users of the device. For example, the user's heart rate or body temperature may be monitored following initial verification to determine if there are any changes in the data stream, e.g., in consecutive data readings, that may be attributed to a change in users, such as a sudden change in heart rate or temperature (either lower or higher) in a relatively short amount of time, e.g., in 5 seconds or less, or a break in the data, e.g., a null reading for one or more consecutive data readings, or a combination thereof.
[0012] The behavioural biometric data collected may be analyzed for any recognizable pattern that may indicate a user change. The data collected may be analyzed without reference to data collected previously, e.g. prior to the initial or an immediately preceding identity verification, or based on historic biometric data, e.g., data collected prior to the initial or the immediately preceding identity verification, for particular individuals or for a group of individuals. For example, a heart rate reading either above or below an average heart rate computed based on historic data for an authorized user may trigger the system 100 to prompt the user for identity verification data, such as for a user ID and password, or physical biometric data. A heart rate reading following a null reading in the data stream that is either below or above a heart rate reading before the break in the data stream may also trigger the prompt for identity verification data. Similarly, different peak heart rates in general or keyed to specific gaming events, such as at the time the user places a bet, wins or loses a wager, etc., may also trigger the prompt for identity verification data in order for the user to continue using the services of the system 100. The biometric data for establishing the data stream may be obtained repeatedly, such as continuously, cyclically, periodically, e.g., every second, minute, etc.
[0013] Pattern recognition may be applied to user continuity data other than behavioural biometric data, including data indicative of a user's proficiency with the system and/or the services provided by the system. For example the system may track the keystroke rate of a user in general or for particular services, e.g., games, and determine if the keystroke rate of a user following identity verification differs from the keystroke data obtained within the betting session following verification or from data obtained prior to the verification. Other proficiency data may be tracked to determine if there may have been a change in the user of the system 100, such as the rate at which the user navigates through the menus, false selections of menus or menu items, etc. Keystroke data may be mapped or certain events, such as wins or losses, as a measure for reducing false positives as a result of different keystroke rates that may be attributed to user nervousness. In any event, a prompt for identity verification data may also be triggered based on a determination that there may have been a change in the user based on the proficiency data collected.
[0014] The gaming system 100 may also verify user continuity by tracking the playing pattern of a user and prompting the user for identity verification data based on gaming commands or requests that deviate or are inconsistent from the playing pattern associated with the user. For example, if the user has a pattern of never having wagered more than $100 on any particular game, the system 100 may prompt the user for verification data, such as physical biometric data, if the user makes a wager of $500 or any appreciable amount above the highest wager, such as 5% or greater than the highest wager. Similarly, the system 100 may track the user's response to wins or losses and prompt the user for identity verification data on any deviation therefrom. For example, a user may establish a pattern of placing a higher wager on every win and lowering the wager on a loss. The system 100 may, upon comparing playing pattern data obtained previously and current playing pattern data and determining therefrom that a wager deviates from the pattern of wagers for the particular authorized user, prompt the user for identity verification data before the user is allowed to continue accessing the services provided by the system 100. Continuity may also be tracked with an authentication device as discussed below.
[0015] The system 100 may track the user continuity data, i.e., behavioural biometric data obtained from users for a sufficient amount of time to collect a data set for the ·· • · comparisons discussed above. The amount of data in the data set for the comparison will generally vary based on the type of data and the desired sample set for the comparison. For example, in determining whether there may have been a user change based on a change in consecutive data readings, such as when there is a break in the data stream, the amount of data necessary for the comparison generally includes two consecutive readings: a first reading followed by a second reading having an appreciable value, e.g., 5% or greater, above or below the first reading. Similarly, when the comparison is based on historic data, the amount of data necessary for the comparison includes at least two nonconsecutive readings: a first reading at a time to classify the data as historic data, e.g., prior to the then current physical biometric identity verification, and a second more recent reading, e.g., after the then current physical biometric identity verification, having an appreciable value above or below the first reading. It can be appreciated that a larger data set, in certain instances, may yield greater accuracy or less false prompts for additional data (false positives). For example, comparison of a current reading with, e.g., the average of 5 prior readings, may result in less false positives in that the average value will tend to diminish the impact of noise in the data set for the comparison. Alternatively or additionally, the system 100 may filter noise from the data set for the comparison. The system 100 may, for example, filter improbable data, such as temperature readings less than 90 degrees F and greater than 110 degrees F, heart rates less than 40 bpm and greater than 180 bpm, etc.
[0016] In one embodiment, the system 100 triggers the prompt for identity verification data based at least on a configurable level of confidence associated with the comparison. The level of confidence may be set, e.g., by a system administrator or by the user. The level of confidence may be set in any manner including by adjusting variables that factor into the confidence or the probability of a false positive or negative, as the case may be, such as the difference between the data that will trigger the prompt for identity verification data, the amount of data in the data set used for the comparison, the filters used to filter noise from the data set for the comparison, etc.
[0017] In one embodiment, the system 100 tracks data indicative of a false positive, which may be used as a basis for adjusting variables associated with the data set, the data set filters, the difference between the data that triggers the prompt, etc., and/or algorithms used to trigger the prompt for identity verification data. False positive data generally includes a positive verification of the user's identity in response to a prompt for identity verification data following a trigger. The data indicative of the false positive may further include the amount of time between the prompt and the positive verification, or any other data which may indicate that the positive verification of the user's identity is attributed to a user change back to the authorized user, including the data believed to be suspect.
[0018] The data resulting in a false positive, prompting the user for identity verification data, may further be input into a neural network which adjusts the variables associated with the data set, the data set filter, algorithms, etc. accordingly. Similarly, data indicative of true positives may also be input into the neural network. The neural network may be trained using supervised, unsupervised learning, and reinforced learning techniques, or a combination thereof. With supervised techniques, the neural network is supplied sets of example pairs, e.g., data reading(s) and an indication of the data reading(s) is/are false or true positive, and the neural network infers a mapping implied by the data. With unsupervised techniques, the neural network is supplied with data and the neural network derives therefrom a mapping without the aid of the false or true positive indications, such as based on statistical modelling, filtering, blind source separation, clustering, etc. With reinforcement learning, the data is derived generally from interactions within the system and observations made therefrom. In addition to the data resulting in a false positive, any of the data discussed herein may be supplied to the neural network to adjust the size of the data set, vary the data set filter values, the difference between the readings that trigger the prompt, etc., as the case may be, to achieve a desired confidence, such as greater than 85% or greater accuracy. Alternatively or additionally, the data 5 resulting in a false positive maybe fed into a support vector machine, which classifies the data using a supervised machine learning technique. Image type data may further be preprocessed prior to being introduced into the neural network or the support vector machine to create an abstract representation of the image that is dimensionally smaller than the image data. Preprocessing may be performed using statistical techniques, such linear discriminant analysis techniques.
[0019] The system 100 may detect various types of errors and may further categorize the types of errors in one of a plurality of categories, such as a type I error, a type II error, etc. The categories may be derived based on the severity of the error or any other characterization scheme. For example, a false identity verification with physical biometric data may be classified as a type I error which has greater weight than a false identity verification with behavioural biometric data classified as a type II error. The manner in which the system 100 responds to
0 errors may be class dependent. In this respect, the system 100 may favour certain classes of errors and respond, e.g., aggressively or favourably, based on the class of the error. For example, the system may block all access with type I errors while providing continued access for type II errors until a configurable tolerance •J***; has been crossed. For instance, continued access may be provided until a certain . ..25 number of type II errors have been registered, e.g., 3 or more type II errors. In • · · this respect, type II errors favour permitting rather than excluding game play in comparison to type I errors. The classification and the threshold maybe be either • ;*’· administrator or user configurable. Additionally, users may be limited to only
.....ί configuring the classification of certain errors and thresholds more restrictively .
For example, users may be limited to only adding default type II errors into type I error class with a more aggressive response that type II errors. Similarly, the user configuration with regard to the threshold may be limited to only reducing the threshold, e.g., to 2 instead of 3 type II errors, before accesses is blocked. All user configurations may be stored in a user profile in one or more databases associated with the gaming system 100. The thresholds and/or classifications may be location specific. For example, the thresholds for certain types of errors while in a hotel restaurant may be relaxed to account for the user engaging in other activity, such as eating.
[0020] The gaming system 100 may provide users with access to various types of services including one or more of a plurality of different types of games, e.g., card games; slot-machine style games; craps; other casino-style games; table games, such as poker, craps, roulette, blackjack, baccarat, etc.; the wheel of fortune game; keno; sports betting; horse, dog, or auto racing; jai alai; lottery-type games, including video versions of scratch off lotteries. The system 100 may provide game play based on the outcome of any type of event, such as sporting events and athletic competitions, including football, basketball, baseball, golf, etc., and nonsporting events, such as on the movement in particular financial markets, indexes, or securities, political elections, entertainment industry awards, box office performance of movies, weather events, etc. The games may be provided both with and without wagering, or with simulated wagering using points that may be traded in for prizes. The gaming system 100 may also provide non-gaming services, e.g., on the gaming device 113, such as audio and video entertainment, news, messaging, telephone, IP telephony, etc.
[0021] The gaming system 100 may be implemented over any type of communications network 116, such as a local area network (LAN), a wide area network (WAN), the Internet, a telephone network (POTS), a wireless network, including cellular, WiFi (RTM), and WiMax (RTM) networks, or a combination of wired and/or wireless networks. The communications network 116 may be entirely independent of the Internet. The system 100 may alternatively limit the information transmitted over the Internet to that with little or no security risk, or that which has been encrypted.
[0022] As noted above, the gaming system 100 may, in certain embodiments, allow users to access services provided by the system from one or more of a plurality of remote locations. The system 100 may also allow users to access the services of the system 100 with the device 113 while mobile or transient. For example, the gaming system 100 may allow users to access services in any location within a service area 148, such as within the vicinity of a hotel. Service area 148 may further be broken down into a plurality of sub-areas 140, 146, such as the casino of a hotel vs. general occupancy areas, e.g., the lobby, the pool, the gym, etc. The service area 148, in the broadest sense, includes any location within the communication capability of the system 100. Thus, service area 148 for services provided over the Internet includes any location with access to the Internet. Similarly, service area 148 for services provided by wireless communication includes any locations within the transmission range of the transmitter and/or reception range of the receiver. The service area 148 may be limited artificially by the system provider and/or the user within certain geographic boundaries. For example, the system provider may limit the service area to within one or more states, cities, municipalities, hotels in a city or municipality, areas within the hotel, such as the casino area, etc., or a combination thereof. Thus, the system 100 may provide services to users in a disjointed area 140, as shown in FIG. 1, where the service provider provides services in one state, such as Nevada, and one or more cities in another state, such as in Atlantic City, NJ, or in any one or more hotels within a city. User defined location access limits may be stored in a user profile in a database associated with the system 100.
[0023] Accordingly, in one embodiment, the system 100 has a location verification feature, which is discussed below in greater detail. The location verification feature may be used to permit or block users from accessing the services provided by the system 100 based on the particular location of, e.g., the gaming device 113. For example, services may be enabled when it is determined that the location of the gaming device 113 is within a pre-defined area 140, such as within the area of a hotel that provides the services disclosed herein, or disabled when the device 113 is moved to a location outside of the area 140. The location verification feature may also be used to disable fewer than all of the services of the gaming system 100 based on the location of the device 113. For example, the system 100 may limit wager-type gaming to areas where such gaming is permitted by law, such as to the casino area of a hotel, whereas nonwagering services, such as messaging, may be enabled irrespective of the location of the device 113. Particular services may also be enabled or disabled by the provider and/or the user based on the location of the device. For example, the user may be allowed to disable non- wagering services, such as messaging, when the user is within the wagering area, such as the casino, and/or during certain events, such as when the user is engaged in game play. As with the classification and threshold limitations discussed above, the user may only be allowed to specify more restrictive service limitations and thus may not be able to override certain limitations imposed by the service provider. For example, the user may not be allowed to enable wager-type gaming in areas where that type of gaming is has been disabled by the service provider. The user defined service limitations may be stored in a user profile in a database associated with the system 100.
[0024] In one embodiment, the gaming system 100 provides services in at least two areas 140, 146 each of the areas having a different level of surveillance than the other. The level of surveillance may be quantified based on any scheme indicative of the effectiveness with regard to determining whether an authorized user is in fact using the gaming system 100 or that the gaming system 100 is being used properly. The level may be established based on the number of measures implemented in this regard. For example, the level of surveillance for an area using face recognition and human surveillance may be deemed greater than an area with only fingerprint scanning. Alternatively or additionally, certain measures may be given greater weight, e.g., based on the reliability of the measure. For example, a fingerprint scan may have a greater reliability or accuracy in verifying the identity of a user than an iris scan. The weight of a particular measure may be independent of its reliability and may simply be based on a subjective confidence in the measure, e.g. of the user or the service provider, relative to other measures. The surveillance level may have nominal designations indicative of overall effectiveness and/or confidence. For example, the level of an area may be classified as being A, B, C,..., Z; low, medium, high, or as a Type I, II, III, ... The surveillance level may also be distinguished using finer nominal designations, such as 0 % to 100 % in increments of 1, 0.1, 0.01,...
[0025] In one embodiment, the system 100 provides access based on the surveillance level of the area the gaming system 100 is being accessed from, e.g., the location of the gaming device 113. That is, surveillance based access may allow access to one or more services if there is a sufficient level of surveillance, defined by either the system provider and/or the user. In this respect, surveillance based access may be implemented in any one of a number of ways. The system may, for instance, provide wager-type gaming services only if the level of security associated with the access area satisfies a minimum level. For example, a user may limit wager-type gaming with system 100 to areas having no less that a type I surveillance level, such as a casino. Thus, wager-type gaming will be disabled in type II surveillance level or less areas, such as hotel common areas, e.g., the pool, the hotel lobby, and non-common areas, such as hotel rooms.
[0026] In one embodiment, the system 100 supplements the surveillance of the area with surveillance measures available with the system 100 to achieve the desired surveillance level. Further to the previous example, the system 100 may increase the surveillance level of type II areas to type I for wager-type gaming by prompting the user for identity verification data and/or collect user continuity data thereby adding to the surveillance level of type II areas sufficient to classify the area with the combined area and device surveillance measures as a type I or better. Thus, the system 100 may allow the user to access services in higher surveillance areas, such as casinos, without biometric data while requiring biometric data with the device in areas with lesser surveillance, such as the hotel courtyard. Surveillance based access limitations may be stored in a user profile in a database associated with the system 100.
[0027] As can be appreciated from the present disclosure, the system 100 may maintain a plurality of different types of data, such as physical biometric data, behavioural biometric data, proficiency data, playing pattern data, etc., for identity verification purposes for each authorized user. The system 100 preferably verifies the identity of a user before allowing the user to access at least one of the services provided therewith. In this respect, the system may require that the user submit at least one item of identity verification data, such as an ID and password combination, or any one of the physical biometric data items discussed herein, etc. The system may further require from the user at least one additional item of identity verification data for system access. In this respect, the system maintains at least one item of redundant verification data. The requirement for additional verification data may be implemented in certain but not all instances. For example, additional verification data may be required in certain areas of a hotel, such as those with lesser surveillance or reliability as discussed above. In these areas, the system 100 may prompt the user for a first and a second item of verification data, such as at least two of: a facial image, an iris scan, a retinal scan, a fingerprint scan, a vascular pattern scan, etc., before allowing the user to access the system services. The surveillance level or reliability associated with each of the measures may be added to achieve a desired surveillance level or reliability as indicated above.
[0028] The user may generally customize any of the aspects of the services provided by the system 100 or any other customizable aspect of the system 100, including classification and threshold configurations, and service, location, and surveillance based access limits. In certain instances, customization generally allows users to vary the level of security, e.g., above a minimum set by a service provider, to a level based on the user's comfort level and/or the location where services are being accessed. For example, if the user only intends to access the system 100, e.g., the gaming device 113, at a particular casino, the user may configure the system 100 to require biometric data at any time the gaming device is used at a off the premises of the particular casino, e.g., at another casino. This feature may be used to prevent a situation where a thief steals the gaming device 113 and attempts to access services at another casino. The services may be customized for each device 113 individually or for groups of devices.
[0029] The system 100 may further be configured to encrypt data, such as the physical biometric data, before it is communicated from the gaming device 113 to the remote computer 118 over network 116 for authentication. In one embodiment, this is accomplished with a one-way encryption algorithm that encrypts, e.g., the identity verification data, to produce a string of alphanumeric characters having a length, such as 100 or greater, from, in certain instances, image data. The string may then be communicated to the remote computer 118 for verification, which is compared with data in the user's profile. The remote computer 118 preferably does not store any identity verification data in the raw form, i.e., unencrypted. Rather, the remote computer stores the post encryption string of characters for the validation. Thus, a match between the string of characters communicated from the device for identity verification and the stored string, within a configurable tolerance, will result in enabling the user to access one or more of the services provided by the system 100. The gaming device 113 may also be configured so that the raw and/or the encrypted identity verification data is not stored permanently and/or to purged periodically, following validation, when the data is transmitted successfully to the remote computer 113, or at any other time the data is no longer needed for the immediate validation. Therefore, in this instance, the gaming device 113 will be required to obtain and/or encrypt identity verification data anew each time there is a prompt for such data.
[0030] The system 100 may also disable access thereto with a hard check mechanism. That is, device 113 may include a reader 150 that obtains information from a corresponding authentication device 155. The authentication device 155 may be any item for storing information thereon, such as a card which bears a magnetic strip, such as a credit card, a key that includes an RFID transponder, a limited-distance signal emitter or other transponder, a smart card, a bracelet or wristband which includes a signal transmitter, such as an RFID signal transmitter, or which includes a magnetically encoded signal, a substrate that bears a bar code or other optically readable identifier, or any combination thereof. The reader 150 may be a magnetic strip reader, an RF or infrared receiver, an optical scanner, etc.
[0031] The gaming device 113 may therefore be capable of detecting a signal from the authentication device 155 and the system 100 may enable system access based on the signal from the authentication device 155. Continued access may also be conditioned on the gaming device 113 receiving continuing to detect the signal from the authentication device 155. The signal produced by authentication device 155 may additionally or alternatively include information stored on the device 155, such as identity verification data, or any other data that may be used as a key for system access. In one embodiment, the authentication device 155 includes a token that is derived from the authorized user's biometric data, such as the string of alphanumeric characters derived from the user's biometrics. The system 100 may then provide access based on a comparison of the string of characters derived from the biometric sensor reading and the string stored on the authentication device. Alternatively or additionally, the data stored on the authentication device 155 may be used to authenticate the user without other identity verification data. That is, the authentication device data may be given greater weight and may thus be used as the primary data for identity verification.
[0032] It is understood that all or some of the data discussed herein may be stored on the authentication device 155 and used as a basis for the comparison with data obtained for identity verification. For example, the device 155 may include physical biometric data, such as fingerprint data, that is compared with fingerprint data received for immediate identity verification. The data used for the comparison may also be limited to being stored to areas only within the user's control, such as areas other than the authentication device 155 and/or the gaming device 113. Validation may therefore be accomplished locally between the gaming device 113 and the authentication device 155; without the transfer of identity verification data to the remote computer 118 for this purpose. Alternatively or additionally, the validation may be accomplished between the remote computer 118 and the authentication device 155.
[0033] The functionality disclosed herein may be provided with software that resides on both the gaming communication device 113 and the remote computer 118. Software resident on gaming communication device 113 is preferably operable to present information corresponding to the system services, including wagering and non- wagering type gaming to the user. The information includes, without limitation, graphical and/or textual representations of objects associated with the services, e.g., in one or more interface screens, windows, and/or message boxes, with the presentation of selectable options related to the services, such as menus, icons, buttons, selectable areas, hyperlinks, etc. The gaming device software is also preferably operable to receive data from the remote computer 118 and data input by the user. Software resident on the remote computer 118 is preferably able to exchange data with the gaming device 118, access additional computers, and data storage devices, and perform all of the functions described herein, including providing the backend functionality for the services discussed herein as well those common to gaming systems.
[0034] The data discussed herein as being transmitted or used by the various devices of the gaming system 100 may be in any format, which is necessary or desirable for the services provided for the user. The information may be transmitted in whole or in fractional portions thereof, in any format including digital or analog, text or voice, and according to any transport technology, which may include wired or wireless technologies. Wireless technologies may include licensed or license-exempt technologies. Some specific technologies which may be used include, without limitation, Code Division Multiple Access (CDMA), Global System for Mobile Communication (GSM), General Packet Radio Service (GPRS), WiFi (RTM) (802.1 lx), WiMax (RTM) (802.16x), Public Switched Telephone Network (PSTN), Digital Subscriber Line (DSL), Integrated Services Digital Network (ISDN), or cable modem technologies. These are examples only and one of ordinary skill will understand that other types of communication techniques are within the scope of the present invention. Further, it will be understood that additional components may be used in the communication of information between the users and the gaming server. Such additional components may include, without limitation, physical communication lines, trunks, antennas, switches, cables, transmitters, receivers, computers, routers, servers, fibre optical transmission equipment, repeaters, amplifiers, etc.
[0035] In at least one embodiment, some or all of the data communication may take place through the Internet or without involvement of the Internet. In certain embodiments, a portion of the information may be transmitted over the Internet while another portion of the information is communicated over a more secure network. For instance, graphic files depicting a roulette table, such as files in .gif or .jpg formats, may be communicated over the Internet while gaming information, such as the results from roulette wheel spin, may be communicated in a parallel network and assembled at the gaming device 113 for display together in a single interface screen. In addition to security considerations, the choice of which of the plurality of networks handle the split data may be based on the bandwidth of the network. Thus, larger graphics files may be transmitted to device 113 over a WiMax (RTM) network while smaller data files are transmitted over a cellular network.
[0036] Referring to FIG. 2, the communication network 116 may be a cellular network 222. Cellular network 222 comprises a plurality of base stations 223, each of which has a corresponding coverage area 225. Base stations may have coverage areas that overlap. Further, the coverage areas may be sectorized or non-sectorized. In the cellular network, the gaming device 113 is generally a mobile station 224, such as a cell phone, that may be transient within the network. The mobile stations 224 communicate with the base stations 223 wirelessly via radio signals. The base stations 223 generally communicate with, e.g., the remote computer 118, over landlines, such as POTS, T1-T3, ISDN, etc. Each base station is preferably programmed to send and receive voice and/or data transmissions to and from mobile station. The gaming device 113 may be coupled to the remote computer 118 with a private label cellular carrier. The mobile stations 224 are preferably preprogrammed with the carrier's authentication software to establish a connection to the cellular network.
[0037] In one embodiment, the location verification feature for determining the location of the gaming device 113 does so in relation to the location of at least one of the base stations of the cellular network. That is, the system 100 determines the location of the gaming device 113 based on the location of one or more base stations and the distance and/or the direction (azimuth) of the device 113 from at least one base station. The distance may be determined based on the strength of ^0 the transmit signal received from gaming device 113. That is, the gaming system device's transmitter communicates at a fixed transmit power output. The attenuation of the transmit signal is generally a function of the distance between the transmitter and the receiver. Thus, the power of the signal received from the device 113 may be measured at the base station and the distance determined there from, e.g., calculated, or looked up in a database or table that maps distance to signal strength. The direction may be determined based on the azimuth of the antenna receiving the signal from the device 113. Alternatively or additionally, the direction may be determined based on the distance of the device 113 from a plurality of the base stations 223, such as two or three, using techniques, such as triangulation, multilateration, etc., as shown in FIG. 3. Determining the location of the gaming device 113 based on the power level of the signal received form the gaming device is not limited to cellular network. Rather, the process is generally applicable to all types of wireless networks, including satellite, WiFi (RTM), GPS, LORAN, RFID, etc., where the location of the base stations are known and the location of the device 113 may be derived based on the distance from the base station.
[0038] Referring to FIG. 3, in one embodiment, the location verification feature is implemented using geo-fencing. That is, the location based access features disclosed herein are enforced based on the communication range of base stations in the wireless communication network. For example, the gaming system 100 may communicate with a plurality of gaming devices 354, 355, and 356. Device 354 is shown located outside the gaming jurisdiction or area 358. Devices 355 and 356 are both located inside gaming area 58. However, only device 356 is located within sub-area or geo-fence 357, which is defined by the perimeter of the coverage areas of the plurality of base stations 353. Thus, geo-fencing may be used to enable access for device 356 but disable services for devices 354 and 355. Even though some gaming devices may be within the area 358, such as device 355, those devices may not be allowed to access the gaming system 100 based on its location in relation to geo-fence 357. The base stations may be cellular base stations as discussed above or base stations having a relatively short range, such
<td></td><td> as WiFi (RTM) or RFID transmitters/receivers, located within the premises of a hotel. The short-range base stations may, for example, be set up within the service area in a grid pattern, e.g., in the ceiling of a facility, with sufficient</td>
<td> 5</td><td> separation to determine the location of the device. [0039] Location verification may be implemented with multiple overlapping as well as non-overlapping geo-fences. For example, geo-fence 361 may be defined by the range of fewer than all of the base stations in the network, such as base station 360, which includes all of the base stations in a casino. Geo- fence 360</td>
<td> 10</td><td> may be a subset of the area of geo-fence 357 or excluded from area 357, which may include all of the base stations in a hotel. In either event, location based access features, such as classifications, thresholds, services, surveillance, etc., may be geo-fence specific. Geo-fencing may further be combined with triangulation and/or other location verification techniques to determine the</td>
<td> 15</td><td> specific location of the device within the geo-fence. For example, the location of device 356 may be determined based on triangulation between three of the base stations 353. [0040] Alternatively or additionally, the device 113 may include a global</td>
<td> 20</td><td> positioning satellite (GPS) chip that determines the location of the device based on signals received from GPS satellites. The GPS chip may stand alone, in which instance the GPS chip sends the GPS location data to other components of the device, such as the processor 122 and/or communication element 124, or part of a single computer chip that combines the function of the GPS chip with the other</td>
<td> 25</td><td> element. [0041] The location verification feature may generally be implemented with an element, i.e., a location verification element, which is a component of the gaming device 113, the remote computer 118, any intermediary component there between,</td>
<td> 30</td><td> such as the base station or stations, or a combination thereof. The location</td>
<td></td><td> verification element may be implemented in hardware, software, or a combination thereof, and generally determines the location of the gaming device 113. [0042] In connection with any of the location determination methods, the gaming</td>
<td> 5</td><td> system 100 may periodically update the location determination information. This may be done, for example, during a gaming session, at predefined time intervals to ensure that movement of the gaming device 113 to an unauthorized area is detected during play, and not just upon login or initial access.</td>
<td> 10</td><td> [0043] Referring to FIG. 4, a method according to at least one embodiment of the methods disclosed herein begins at 402 with initiating the gaming device 113. Initiation is dependent on the type of the gaming device 113. For example, initiation may simply be turning the device 113 or running an application, such as a browser application or special purpose software. In one embodiment, initiation</td>
<td> 15</td><td> includes communicating an initiation message from the device 113 to the system 100, e.g., the remote computer 118. The initiation message is generally interpreted by the system 100 as a first request for access. The initiation message may include information therein identifying the device and/or the user, such as a unique device identification number, e.g., for an initial access determination. The</td>
<td> 20</td><td> unique device identification number may be serial number, a cell-phone number, an IP address, etc. [0044] In one embodiment, the system 100 displays at 404 a first interface screen in response to initiation, such as in response to the initiation message. The first</td>
<td> 25</td><td> interface screen may be stored locally on the device 113 or communicated over the network 116 to the device 113 for display. The nature of the first interface screen will vary depending on the circumstances. For instance, if the device 113 cannot establish a link to the remote computer 113, the first interface screen may contain a message indicating as such. Alternatively, upon successfully</td>
<td> 30</td><td> establishing the necessary connection, the first interface screen may include at</td>
least one form element therein, such as a text box, for the user to enter an ID, a password, or a combination thereof to log into the system 100. The ID and/or password may generally be used as a first level of identity verification and for providing users with user specific customized services. Alternatively or additionally, the customized services may be device specific in which instance the device identification number may be used distinguish the particular device 113 from all other devices in the system.
[0045] If at 408 it is determined that the user is new and/or the device has not been activated, the user and the device may at 140 be registered and activated for service, respectively. In one embodiment, the user is registered by receiving at 412 identity verification data, such as a user ID and password, name(s), identification number, address, credit card number(s), physical biometric data, e.g., a fingerprint scan, an iris scan, a retinal scan, a vascular pattern scan, a facial image, etc. The identity verification data may be authenticated with a third party provider, such as the relevant department of motor vehicles, a credit rating agency, etc. User preference information may also be received at 414, such as preference information relating to error classifications and thresholds, location access limits, service limits, surveillance limits, etc. The identity verification data may be encrypted and stored at 416 either with the remote computer 118 or the authentication device 155, as discussed above, and the device 113 may at 417 be activated for service. Once all the requisite and/or desired information is obtained, an appropriate service-type interface screen is displayed at 430.
[0046] If at 408 it is determined that the user and/or the device 113 are not new and activated, respectively, the system 100, in one embodiment, determines at 406 the location of the device 113. The location of the device 113 may be determined in a variety of ways, as discussed above. In one embodiment, the location of the device 113 is determined based on the location of at least one base station with which the device 113 is in communication with wirelessly. The base station may be a base station in a cellular network, a local WiFi (RTM) router, an RFID transponder, etc. The location of the device 113 may simply be an acknowledgement that the device 113 is communicating with at least one base station having a known location. Thus, it can be determined therefrom that the device is within an area defined by the communication range of the at least one base station. Additionally or alternatively, the location of the device 113 may be determined based further on the distance and direction of the device 113 from one or more base stations, e.g., based on the received signal power from the device transmitter. The determination of the device location may also be accomplished with GPS technology. In either instance, the location of the device 113 may be communicated and/or received by the system 10 for use in providing services as discussed herein. The location may be specified in terms of the coordinates, e.g., latitude and longitude, the base station communicating with the device, the class of base station the device is communicating with, e.g., base stations in the casino vs. those in the hotel, base stations in a wagering vs. non-wagering geo-fence areas, etc.
[0047] In one embodiment, the system 100 determines at 418 the surveillance level associated with the location of the device 113. This may be accomplished, for instance by looking up the surveillance level in a table that includes surveillance level data mapped to the locations within the service area of the system 100. Alternatively or additionally, the surveillance level may be computed in real-time based on surveillance measures in place at that time.
[0048] In one embodiment, the system 100 prompts the user for identity verification data, e.g. physical biometric data, based on the location and/or the surveillance level associated with the location of the device 113. In this instance, the system 100 implements a verification scheme based thereon. That is, the particular type and quantity of identity verification data required to access the services of the system 100 is based on the location and/or surveillance level associated with the location. For example, in a casino area the system 100 may not require any physical biometric verification for access whereas non-casino areas may require physical biometric verification with at least one item of physical biometric data. Similarly, certain common areas outside of the casino, identity verification may require further a second, redundant item of physical biometric data. In the context of the surveillance levels, areas with a type I surveillance may not require physical biometric verification whereas areas with type II surveillance may require at least one item of physical biometric data and areas with type III surveillance may further require at least one redundant item of physical biometric data. As noted above, the system 100 may implement a verification scheme to achieve a target surveillance level. That is, the system 100 may determine the surveillance level of the device location and require identity verification to the extent necessary to meet or exceed the target level. For example, at least one item of redundant verification data may be required to raise type II areas to a target type I. Similarly, at least two items of redundant verification data may be required to raise type III areas to target type I.
[0049] Identity verification data may then be compared at 422 with the data stored previously, such as with the remote computer 118 and/or the authentication device 155. If identity verification fails at 424, the system 100 may prompt the user for reentry or additional data. If verification passes, the system 100 may at 426 determine if there are any location based service limits and at 428 determine any applicable user preferences related thereto. That is, the system 100 may determine which of the plurality of available services the user will be provided access to based on the location of the device and/or the surveillance level associated with the location. For example, the system 100 may provide access to all services, such as wagering, entertainment, news, messaging, telephone, IP telephony etc., in the casino, when the device 113 is located within the casino. Similarly, access to all services other than wagering may be provided in all areas. In this respect, the system 100 blocks access to wagering services in certain areas, such as areas outside of the casino.
[0050] Following identity verification, a service appropriate interface screen may be displayed for the user at the device 113. That is, the interface screen displayed for the user includes therein selectable options for accessing the enabled services. Non-enabled services will preferably be blacked out. For example, the interface screen may include menu items, icons, hyperlinks, selectable text and graphics, etc., for each of the enabled services that when selected causes a related interface screen to be displayed. As noted above, the system 100 may provide users with access to, e.g., video versions of table games, such as poker. In this instance, a related interface screen may include graphics for video poker, including playing card graphics, betting selections, etc. The interface screens preferably include selectable elements for navigating through the service environment, e.g., for access to other services, and/or selectable elements for submitting gaming and wagering commands, such as hit, stay, hold, draw, bet, bet up, bet down, double down, etc.
[0051 ] In one embodiment, the system 100 obtains data for determining whether or not there has been a user change following the prior identity verification. As discussed above, a user change may be determined based on various types of data, such as behavioural biometric data, e.g., blood pressure, heart or pulse rate, body temperature data, speech, handwriting, keystrokes, body movements, etc., proficiency data, such as keystroke rate, menu item or icon selection rate, player pattern data, e.g., the magnitude and rate of gaming commands, wagering commands, etc. If it is determined at 434 that there may have been a user change since the previous identity verification, the system 100 may prompt the user for identity verification data at 436 or respond based on error classification and thresholds, and repeat identity verification. The system 100 preferably determines if there is a change in the location of the device 113 at 438 and adjusts/enables the services accordingly.
Contents7
9 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2002132663A1 | Cites | United States of America | Search report |
| US2003064798A1 | Cites | United States of America | Search report |
| US2004192442A1 | Cites | United States of America | Search report |
| WO2005022453A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| WO2005098650A1 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| US2005108365A1 | Cites | United States of America | Search report |
| US2006058102A1 | Cites | United States of America | Search report |
| US2006199649A1 | Cites | United States of America | Search report |
| US2006236395A1 | Cites | United States of America | Search report |
| WO2008005264A2 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| WO2008016610A2 | Cites | World Intellectual Property Organization (WIPO) | Search report |
| US5977957A | Cites | United States of America | Search report |
52 members in 8 offices
Priority claims16
| Document | Office | Kind | Date |
|---|---|---|---|
| 55948406 | United States of America | A | |
| 55948406 | United States of America | A | |
| 55982906 | United States of America | A | |
| 55982906 | United States of America | A | |
| 55993306 | United States of America | A | |
| 55993306 | United States of America | A | |
| 2007084669 | United States of America | W | |
| 2007084669 | United States of America | W | |
| 11559484 | – | – | – |
| 11559829 | – | – | – |
| 11559933 | – | – | – |
| 2007084669 | – | – | – |
| US20060559484 | – | – | – |
| US20060559829 | – | – | – |
| US20060559933 | – | – | – |
| WO2007US84669 | – | – | – |
Members52
| Document | Office | Kind | |
|---|---|---|---|
| US2008113785A1 | United States of America | A1 | |
| US2008113786A1 | United States of America | A1 | |
| US2008113787A1 | United States of America | A1 | |
| AU2007319235A1 | Australia | A1 | |
| CA2669836A1 | Canada | A1 | |
| CA2928614A1 | Canada | A1 | |
| CA3234218A1 | Canada | A1 | |
| WO2008061138A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO2008061138A3 | World Intellectual Property Organization (WIPO) | A3 | |
| GB0910202D0 | United Kingdom | D0 | |
| EP2092462A2 | European Patent Office (EPO) | A2 | |
| GB2458049A | United Kingdom | A | |
| JP2010509031A | Japan | A | |
| GB2458049BThis record | United Kingdom | B | |
| EP2092462A4 | European Patent Office (EPO) | A4 | |
| NZ577177A | New Zealand | A | |
| US2013072295A1 | United States of America | A1 | |
| US2013165213A1 | United States of America | A1 | |
| US2013165221A1 | United States of America | A1 | |
| US8510567B2 | United States of America | B2 | |
| US8645709B2 | United States of America | B2 | |
| US8784197B2 | United States of America | B2 | |
| JP2015042246A | Japan | A | |
| JP5681844B2 | Japan | B2 | |
| NZ618654A | New Zealand | A | |
| NZ706217A | New Zealand | A | |
| US9280648B2 | United States of America | B2 | |
| CA2669836C | Canada | C | |
| US9411944B2 | United States of America | B2 | |
| US2017039806A1 | United States of America | A1 | |
| US2017091435A1 | United States of America | A1 | |
| JP6126044B2 | Japan | B2 | |
| JP2017148537A | Japan | A | |
| US10546107B2 | United States of America | B2 | |
| JP6678126B2 | Japan | B2 | |
| US2020134155A1 | United States of America | A1 | |
| US10706673B2 | United States of America | B2 | |
| JP2020138029A | Japan | A | |
| US2020342711A1 | United States of America | A1 | |
| US11182462B2 | United States of America | B2 | |
| US2022083637A1 | United States of America | A1 | |
| JP2022106750A | Japan | A | |
| US11430293B2 | United States of America | B2 | |
| JP7139370B2 | Japan | B2 | |
| JP2022179489A | Japan | A | |
| US2022406128A1 | United States of America | A1 | |
| US11947646B2 | United States of America | B2 | |
| CA2928614C | Canada | C | |
| US2024193244A1 | United States of America | A1 | |
| US2024282168A1 | United States of America | A1 | |
| US2024362971A1 | United States of America | A1 | |
| JP2025061174A | Japan | A |
Numbers
- Publication
- 2458049
- Publication, DOCDB
- 2458049
- Publication, EPODOC
- GB2458049
- Application
- 910202
- Application, DOCDB
- 0910202
- Application, EPODOC
- GB20090010202
Titles
- English
- Biometric access sensitivity
Classification
- CPC, 3
- G07F17/3206
- G07F17/32
- G07F17/3237
- IPC, 1
- G07F17 32
