Server-based biometric authentication
By splitting and reconstructing the biometric template and user identification information on the server side, the fraud risk of the biometric authentication system is resolved, achieving higher security and protection effects.
Patent Information
- Application Number
- CN202210049706.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2015-11-11
- Filing Date
- 2016-09-22
- Publication Date
- 2025-09-23
- Estimated Expiration
- 2036-09-22
AI Technical Summary
In existing biometric authentication systems, forgers can copy user biometrics to conduct fraudulent transactions, and existing encryption methods cannot effectively distinguish between similar biometric data, making the authentication system vulnerable to attacks.
Split the biometric template into multiple fragments and reconstruct and match them on the server side. Improve security by splitting user identification information and generating random numbers to avoid direct matching on consumer devices.
The security of biometric authentication is improved, and fraudsters need to steal multiple pieces of information to successfully commit fraud, reducing the risk of system attacks.
Smart Images

Figure CN114358793B_ABST
Abstract
Description
[0001] This invention application is a divisional application of the invention patent application with international application number PCT / US2016 / 053187, international application date September 22, 2016, application number 201680065575.9 entering the Chinese national phase, and titled “Server-based biometric authentication”. Background Art
[0002] Fraud within the consumer transaction services industry has become a problem. For example, many consumer transactions can now be completed using consumer devices (e.g., mobile phones) without the need for physical payment cards. Users can initiate payment transactions from consumer devices at point-of-sale terminals or in remote payment environments. Some transactions initiated by consumer devices without the need for physical payment cards may require biometric authentication to verify the identity of the paying user. However, in some cases, counterfeiters are able to replicate user biometrics and use the paying user's payment card details to complete fraudulent transactions.
[0003] Some systems attempt to reduce fraud in transactions using biometric authentication by performing the matching of biometric data within an encrypted context. For example, a biometric template (e.g., based on a fingerprint) can be encrypted and matched to received biometric data without decrypting the template, making it more difficult for fraudsters to construct the biometric data. However, a major problem with this approach is that typical encryption methods map plain text into ciphertext that appears completely random. Even if the content of two plain texts is very similar, their corresponding ciphertexts may be arbitrary strings with very different content. As a result, these systems will interpret the biometric data as originating from two different users, when in fact they may have originated from the same user.
[0004] Embodiments of the present invention address these and other problems. Summary of the Invention
[0005] In some embodiments of the present invention, systems and methods for server-side biometric authentication are provided. The server-side biometric authentication system can split data knowledge and processing so that a fraudster would require a significant amount of collusion to compromise the system. The biometric data provided by the user during the authentication process can be matched to a biometric template on (one or more) servers, rather than to a biometric template on a consumer device as is typically done. More specifically, at enrollment, the biometric template can be split into two or more segments. Each of the segments can be encrypted and stored on a template storage server. At a later point in time, during the authentication process, the biometric data provided by the user (e.g., from a fingerprint) can be compared to a reconstructed version of the biometric template in which each segment of the template is retrieved from a matcher computer and combined together.
[0006] Some embodiments of the present invention relate to a method for biometric authentication, comprising receiving, by an identity (ID) manager computer, user identification information associated with a user from a resource-providing entity computer. The method may also include sending, by the ID manager computer, the user identification information to an ID splitting computer. The method may also include, in response to sending the user identification information to the ID splitting computer, receiving, by the ID manager computer, a first user identifier and a second user identifier from the ID splitting computer, wherein the first user identifier and the second user identifier are associated with the user identification information. The method may also include sending, by the ID manager computer, the first user identifier to a first template storage computer, wherein the first template storage computer matches the first user identifier with a first segment of a biometric template associated with the user and sends the first segment of the biometric template to a matcher computer. The method may also include sending, by the ID manager computer, the second user identifier to a second template storage computer, wherein the second template storage computer matches the second user identifier with a second segment of a biometric template associated with the user and sends the second segment of the biometric template to the matcher computer. In some embodiments, the matchmaker computer combines the first segment of the biometric template and the second segment of the biometric template to determine whether the user-provided biometric data received by the matchmaker computer from the resource providing entity computer matches the combined biometric template.
[0007] In some embodiments, the method further includes sending, by the ID manager computer, a transaction identifier to the resource providing entity computer, the first template storage computer, and the second template storage computer, wherein determining whether the biometric data provided by the user matches the combined biometric template is based at least in part on a match between the transaction identifier received by the resource providing entity computer and the transaction identifiers received by the first and second template storage computers.
[0008] In some embodiments, the first segment of the biometric template is stored on the first template storage computer and the second segment of the biometric template is stored on the second template storage computer.
[0009] In some embodiments, matching the first user identifier with the first fragment of the biometric template is based at least in part on a first random number associated with both the first user identifier and the first fragment of the biometric template, and wherein matching the second user identifier with the second fragment of the biometric template is based at least in part on a second random number associated with both the second user identifier and the second fragment of the biometric template.
[0010] In some embodiments, the user identification information includes at least one of a primary account number (PAN), a token, a name, an address, a telephone number, or an email address.
[0011] In some embodiments, the biometric data provided by the user includes at least one of a voice sample, a fingerprint, an iris scan, palm geometry, earlobe geometry, or a deoxyribonucleic acid (DNA) scan.
[0012] In some embodiments, the method may further include receiving, by the ID manager computer, a third user identifier associated with the user identification information from the first server computer. The method may further include sending, by the ID manager computer, the third user identifier to the matchmaker computer, wherein the matchmaker computer matches the third user identifier with a third segment of the biometric template associated with the user and sends the third segment of the biometric template to the matchmaker computer.
[0013] Some embodiments of the present invention relate to a method for biometric authentication, comprising receiving, by a matchmaker computer, biometric data provided by a user from a resource-providing entity computer. The method may also include receiving, by the matchmaker computer, a first segment of a biometric template from a first template storage computer. The method may further include receiving, by the matchmaker computer, a second segment of the biometric template from a second template storage computer. The method may additionally include combining, by the matchmaker computer, the first segment of the biometric template and the second segment of the biometric template. The method may also include determining whether the biometric data provided by the user matches the combined biometric template based, at least in part, on a match between a transaction identifier received from the resource-providing entity computer and a transaction identifier received from the first template storage computer and a transaction identifier received from the second template storage computer.
[0014] In some embodiments, the method may further include sending, by the matchmaker computer, a result of the determining step to the resource providing entity computer.
[0015] Other embodiments of the present invention also relate to servers and systems configured to perform the above methods.
[0016] These and other embodiments of the invention are described in more detail below. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 A diagram illustrating a registration process employing a server-side biometric authentication system according to some embodiments of the present invention is shown.
[0018] Figure 2 A diagram illustrating an authentication process employing a server-side biometric authentication system according to some embodiments of the present invention is shown.
[0019] Figure 3 A block diagram of an identity (ID) manager computer according to some embodiments of the present invention is shown.
[0020] Figure 4 A block diagram of a matchmaker computer according to some embodiments of the present invention is shown.
[0021] Figure 5 A block diagram of an exemplary payment system according to some embodiments of the present invention is shown.
[0022] Figure 6 An exemplary computer device according to some embodiments of the present invention is shown. DETAILED DESCRIPTION
[0023] Before discussing embodiments of the present invention, describing some terms may be helpful in understanding embodiments of the present invention.
[0024] A "payment device" may include any suitable device capable of effecting a payment. For example, a payment device may include a card, including a credit card, debit card, charge card, gift card, or any combination thereof. A payment device may be used in conjunction with a consumer device, as further defined below.
[0025] "Payment processing network" (e.g. VisaNet TM ) may include data processing subsystems, networks, and operations used to support and provide authorization services, exception file services, and clearing and settlement services. Exemplary payment processing networks may include VisaNet TM Such as VisaNet TM VisaNet is a payment processing network that processes credit card transactions, debit card transactions, and other types of commercial transactions. TM Specifically, it includes the VIP system (Visa Integrated Payment System) that processes authorization requests and the Base II system that performs clearing and settlement services.
[0026] An "authorization request message" may be an electronic message sent to an authorization system and / or an issuer computer, such as a payment processing network, requesting authorization for a transaction. An authorization request message is an example of a transaction message. According to some embodiments, the authorization request message may conform to ISO 8583, a standard for systems for exchanging electronic transaction information associated with payments made by consumers using payment devices or payment accounts. The authorization request message may include a primary account number (PAN), expiration date, service code, CVV, and other data from the payment device. In some embodiments of the present invention, the authorization request message may include a payment token (e.g., an alternative account number or a pseudo-account number), expiration date, token presentation mode, token requester identifier, application cryptogram, and assurance level data. The payment token may include a payment token issuer identifier, which may be an alternative to the issuer's actual issuer identifier. For example, the actual issuer identifier may be part of a BIN range associated with the issuer. The authorization request message may also include additional data elements corresponding to "identification information," including, by way of example only: a service code, CVV (card verification value), dCVV (dynamic card verification value), expiration date, etc.
[0027] An "authorization response message" may be an electronic message reply to an authorization request message generated by an authorization system. The authorization response message may include an authorization code, which may be a code returned by the authorization system in response to receiving the authorization request message (directly or through a payment processing network). The authorization response message is received at a merchant's access device (e.g., a POS terminal) and can indicate the authorization system's approval or rejection of the transaction.
[0028] A "server computer" can be a single powerful computer or a cluster of computers. For example, a server computer can be a mainframe, a cluster of small computers, or a group of servers working together as a unit. A server computer can be associated with an entity such as a payment processing network, a wallet provider, a merchant, an authentication cloud, an acquirer, or an issuer. An identity (ID) manager computer, an ID splitting computer, a matchmaker computer, and a template storage computer can all be examples of server computers.
[0029] An "access device" may include a device that allows communication with a remote computer and may include a device that allows a consumer to make a payment to a merchant in exchange for goods or services. An access device may include hardware, software, or a combination thereof. Examples of access devices include a point-of-sale (POS) terminal, a mobile phone, a tablet computer, a laptop or desktop computer, and the like.
[0030] “Biometric data” includes data that can be used to uniquely identify an individual based on one or more inherent physiological or behavioral characteristics. For example, biometric data may include fingerprint data and retinal scan data. Other examples of biometric data include digital photograph data (e.g., facial recognition data), deoxyribonucleic acid (DNA) data, palm print data, palm geometry data, and iris recognition data.
[0031] A "biometric template" can be a digital reference to unique features extracted from a biometric sample provided by a user. The biometric template is used during the biometric authentication process. Data from the biometric sample provided by the user during authentication can be compared to the biometric template to determine whether the provided biometric template closely matches the biometric template.
[0032] A "resource providing entity" may be an entity that provides resources during a transaction. For example, the resource providing entity may be a merchant.
[0033] "User identification information" can be any information associated with a user and capable of identifying the user. User identification information may include, but is not limited to, primary account number (PAN), phone number, email address, zip code, mailing address, photo identification, personal identification number (PIN), etc.
[0034] A "user identifier" may be a piece of data that can identify a user. A user identifier may be derived from user identification information. A user identifier may also be split into multiple parts, where a single part alone is insufficient to identify the user without the remaining parts.
[0035] Figure 1 A diagram illustrating a registration process using a server-side biometric authentication system according to some embodiments of the present invention is shown. As described above, the server-side biometric authentication system can achieve secure biometric authentication by splitting a biometric template into two or more fragments, then recombining the fragments, and then comparing the recombined biometric template to the biometric data provided by the user. Because the matching is performed on the server side (as opposed to the client side, which is typically the case), a fraudster would require a significant amount of collusion on their part to compromise the system and perform a fraudulent authentication. The following description will illustrate the process of registering biometric data using the server-side biometric authentication system before biometric authentication occurs. The steps outlined below may be performed in an order other than that described.
[0036] In step s1, user 110 may register with the biometric authentication system by providing a biometric sample at a registration station 190. The registration station may be located in a variety of institutions, including but not limited to a merchant store, a bank, a government office, an automated teller machine (ATM), or any other suitable location. User 110 may provide their biometric sample by interacting with a biometric reader 140 at the registration station 190. In this example, the biometric sample 140 is shown as a fingerprint scanner, but it may be other devices capable of obtaining a biometric sample from the user 110. For example, the biometric reader 140 may be an iris scanner, a palm scanner, an ear scanner, a voice scanner, a DNA scanner, etc.
[0037] In step s2, biometric reader 140 obtains a biometric sample from user 110 (e.g., by scanning the user's fingerprint). Upon obtaining the biometric sample from user 110, biometric reader 140 may create a biometric template associated with user 110. A biometric template may be a digital reference of unique features extracted from the biometric sample. For example, if the biometric sample is a fingerprint, the biometric template may contain minutiae (or major features) of the fingerprint. The biometric template may serve as a reference to be compared with data received from the biometric sample provided by the user during authentication to determine whether the user is authentic.
[0038] In step S3, after the biometric reader 140 creates a biometric template, the biometric template can be split into two or more segments. The biometric template can be split into two or more segments by the biometric reader 140 or other computer systems (not shown) present within the registration station 190. For example, as shown in the figure, the biometric template can be split into two segments: templ_F1 and templ_F2. By splitting the biometric template into two segments, knowing or accessing one of the segments (but not both) can prevent the original biometric template from being known. Thus, if a fraudster only gains access to one of the segments, they may not be able to replicate the original biometric template. In some embodiments, the biometric template can be split into two or more segments using the Shamir secret sharing algorithm, which can be generalized to an M-out-of-N scheme (1 < N ≤ M), where the biometric template can be split into M parts, and N of these parts must be present to recreate the original biometric template.
[0039] In addition to splitting the biometric template into two or more segments, the biometric reader 140 or other computer systems (not shown) within the registration station 190 can generate two or more large random numbers, where the number of large random numbers generated can be equal to the number of segments into which the biometric template is split. In some embodiments, the large random numbers generated can be large enough such that the likelihood of generating a random number equivalent to a random number generated during a previous registration process during a subsequent registration process can be very low. In some embodiments, the large random numbers generated can be 20 bytes each.
[0040] After the biometric template is split into two or more segments and the random numbers are generated, the pairs consisting of the segments and the numbers can be sent to two or more template storage computers. For example, in step S4, the first segment (templ_F1) of the biometric template and the first generated random number (ran1) can be sent by the biometric reader 140 or other computer systems (not shown) to the first template storage computer 150. For example, in step S5, the second segment (temp l_F2) of the biometric template and the second generated random number (ran2) can be sent by the biometric reader 140 or other computer systems (not shown) to the second template storage computer 160. In some embodiments, the first template storage computer 150 and the second template storage computer 160 can be run by different entities. In some embodiments, if the biometric template is split into N segments, there can be N template storage computers within the server-side biometric authentication system, each template storage computer storing one of the N segments and one of the N generated random numbers.
[0041] In step s6, user 110 may provide certain user identification information to access device 130. User identification information may include, but is not limited to, some form of identification, payment credentials, a primary account number (PAN), a token, a phone number, or an email address. For example, user 110 may use their mobile device to present payment credentials to access device 130. In some embodiments, step s6 may be performed simultaneously with step s1. Access device 130 may then capture the user identification information provided by user 110.
[0042] In step s7, after capturing the user identification information provided by user 110, access device 130 may send the captured user identification information to identity (ID) manager computer 170. In addition, access device 130 may send the generated random number along with the user identification information to ID manager computer 170. For example, access device 130 may send ran1 and ran2 to ID manager computer 170. The access device may obtain the generated random number from biometric reader 140 or other computer system (not shown) via a communication link. ID manager computer 170 may not receive any of the biometric data provided by user 110 in step s1. In some embodiments, ID manager computer 170 may reside on payment processing network 540 ( Figure 5 ). In some embodiments, the ID manager computer 170 can be run by a trusted third party. In some embodiments, the biometric reader 140 and the access device 130 can be interconnected as part of a harmonious system, such that the biometric reader 140 and the access device 130 have access to each other's data.
[0043] In step s8, after receiving the user identification information, the ID manager computer 170 can send the user identification information to the ID splitting computer 180. The ID splitting computer 180 can be responsible for splitting the user identification information into multiple parts. In some embodiments, the ID splitting computer 180 can be run by a trusted third party.
[0044] In step s9, after receiving the user identification information, the ID splitting computer 180 may split the user identification information into multiple parts. In some embodiments, the ID splitting computer 180 may split the user identification information into a number of parts equal to the number of biometric template fragments created. The purpose of splitting the user identification information into multiple parts is that the multiple parts cannot individually identify the user 110, but the combination of the multiple parts can identify the user. In some embodiments, splitting the user identification information may include generating two or more random numbers and associating the random numbers with the user identification information. For example, if the ID splitting computer 180 receives user identification information that has not been received before, the ID splitting computer 180 may generate two random numbers (e.g., useridentifier_1 and useridentifier_2). If the ID splitting computer 180 receives user identification information that has been received before, the ID splitting computer 180 may simply return the random number associated with the user identification information instead of generating a new random number. The generated random numbers may be stored in a database within the ID splitting computer 180. Furthermore, it can be seen from the figure that the ID splitting computer 180 never receives the random numbers (e.g., ran1 and ran2) generated from the registration station 190. Thus, the ID splitting computer 180 cannot associate the received user identification information with any particular transaction, thereby further improving security.
[0045] After splitting the user identification information into multiple parts (eg, by generating multiple random numbers and associating them with the received user identification information), ID split computer 180 may send the multiple parts of the user identification information back to ID manager computer 170 .
[0046] In step s10, after receiving the multiple parts of the user identification information from the ID splitting computer 180, the ID manager computer 170 may send one of the parts of the user identification information (e.g., useridentifier_1) and one of the random numbers generated in step s3 to one of the template storage computers. For example, the ID manager computer 170 may send useridentifier_1 and ran1 to the first template storage computer 150. After receiving useridentifier_1 and ran1 from the ID manager computer 170, the first template storage computer 150 can correlate useridentifier_1 with templ_F1 (the first segment of the biometric template) because both pieces of information are associated with ran1. No other entity within the server-side biometric authentication system can deduce this correlation because the enrollment station 190 has not seen any of the parts of the user identification information (e.g., useridentifier_1), and the ID manager computer 170 has not seen any of the segments of the biometric template (e.g., templ_F1).
[0047] Similarly, in step s11, the ID manager computer 170 may send useridentifier_2 and ran2 to the second template storage computer 160. After receiving useridentifier_2 and ran2 from the ID manager computer 170, the second template storage computer 150 may correlate useridentifier_2 with templ_F2 (the second fragment of the biometric template) because both pieces of information are associated with ran2.
[0048] Upon receiving the respective portions of the user identification information and one of the random numbers, first template storage computer 150 and second template storage computer 160 may each store a record associating one of the segments of the biometric template with one of the portions of the user identification information. For example, first template storage computer 150 may store a record associating useridentifier_1 with temp1_F1, and second template storage computer 160 may store a record associating useridentifier_2 with temp1_F2. Thus, each template storage computer has an association of portions (e.g., segments) of the user's identity with segments of the biometric template.
[0049] Any compromise of the first template storage computer 150 or the second template storage computer 160 by a fraudster may only generate random numbers that are associated with the other random number. Even if both the first template storage computer 150 and the second template storage computer 160 are compromised by the fraudster, there is no association between the user identification information portion stored in the first template storage computer 150 (e.g., useridentifier_1) and the user identification information portion stored in the second template storage computer 160 (e.g., useridentifier_2). Therefore, the fraudster will not be able to know which portion of the user identification information stored in the first template storage computer 150 (e.g., useridentifier_1) needs to be combined with the portion of the user identification information stored in the second template storage computer 160 (e.g., useridentifier_2) to create a template.
[0050] After completing Figure 1 Following the illustrated registration process, user 110 may be able to authenticate transactions at a later point in time using the server-side biometric authentication system.
[0051] Figure 2 A diagram illustrating an authentication process employing a server-side biometric authentication system according to some embodiments of the present invention is shown. Figure 2 The steps shown can occur after executing Figure 1 At a point in time after the steps shown. For example, Figure 2 The steps shown may occur when a user wishes to authenticate a transaction using the server-side biometric authentication system.The steps outlined below may be performed in an order other than that described.
[0052] In step s1, user 110 may be at a merchant location and may wish to begin the process of being authenticated to complete a transaction. User 110 may submit their biometric sample by interacting with biometric reader 140. For example, user 110 may provide their fingerprint to biometric reader 140.
[0053] In step s2, user 110 may provide certain user identification information to access device 130. User identification information may include, but is not limited to, a primary account number (PAN), a payment token, a phone number, or an email address. For example, user 110 may present payment device 120 storing the PAN to access device 130. Step s2 may be performed simultaneously with step s1.
[0054] In step s3, after the user provides certain user identification information to the access device 130, the access device 130 may generate a point-of-sale (PoS) transaction ID (PoS_tx_ID) and send the PoS transaction ID, the user identification information, and an identifier (ID_Matcher) of a matchmaker computer 220 associated with the access device 130 or the merchant to the ID manager computer 170. The identifier of the matchmaker computer 220 may be a uniform resource locator (URL) pointing to the matchmaker computer 220. The transmission of information from the access device 130 to the ID manager computer 170 may be encrypted using the public key of the ID manager computer 170. Alternatively, Transport Layer Security (TLS) may be used if the ID manager computer 170 has been authenticated to ensure that personally identifiable information (PII) data is only sent to legitimate parties.
[0055] In step s4, the ID manager computer 170 may generate a transaction ID (e.g., tx_ID) that is unique to the transaction being processed. The ID manager computer 170 may send the generated transaction ID along with the PoS transaction ID (PoS_tx_ID) to the access device 130, thereby enabling the access device 130 to know which transaction ID will be associated with the current transaction. The generated transaction ID may be a large random number that is large enough to significantly reduce the likelihood of reusing the same transaction ID. In some embodiments, the generated transaction ID may be 20 bytes in length.
[0056] In step s5 , the biometric reader 140 and / or access device 130 may send the transaction ID received from the ID manager computer 170 to the matchmaker computer 220 together with data pertaining to the currently provided biometric sample received by the biometric reader 140 .
[0057] In step s6, the ID manager computer 170 may send the user identification information received in step s3 to the ID splitting computer 180. Figure 1 As described above, the ID splitting computer 180 may split the user identification information into two or more parts (e.g., useridentifier_1 and useridentifier_2). As mentioned above, useridentifier_1 and useridentifier_2 may simply be random numbers generated and associated with the user identification information. In step s7, after the ID splitting computer 180 splits the user identification information into two or more parts, the ID splitting computer 180 may send the split parts of the user identification information to the ID manager computer 170.
[0058] In step s8, after receiving the split parts of the user identification information sent to the ID manager computer 170, the ID manager computer 170 may send the first part of the user identification information (e.g., useridentifier_1), the identifier of the matchmaker computer 220, and the transaction ID to the first template storage computer 150. Similarly, in step s9, the ID manager computer 170 may send the second part of the user identification information (e.g., useridentifier_2), the identifier of the matchmaker computer 220, and the transaction ID to the first template storage computer 150. The various parts of the user identification information, the identifier of the matchmaker computer 220, and the transaction ID may be encrypted through the mutually authenticated TLS session.
[0059] In step s10, after the first template storage computer 150 receives the first part of the user identification information (e.g., useridentifier_1), the identifier of the matchmaker computer 220, and the transaction ID, the first template storage computer 150 may compare the received user identification information part (e.g., useridentifier_1) with the transaction ID in the contact. Figure 1 After matching the received user identification information portion with the first segment of the biometric template stored in the first template storage computer 150, the first template storage computer 150 may send the received transaction ID (e.g., tx_ID) and the first segment of the biometric template (e.g., templ_F1) to the matchmaker computer 220. The first template storage computer 150 may learn the identity of the matchmaker computer 220 based on the identity of the matchmaker computer (e.g., ID_Matcher) received from the ID manager computer 170.
[0060] Similarly, in step s11, after the second template storage computer 160 receives the second portion of the user identification information (e.g., useridentifier_2), the identifier of the matchmaker computer 220, and the transaction ID, the second template storage computer 160 can compare the received portion of the user identification information (e.g., useridentifier_2) with the transaction ID in the contact. Figure 1After matching the received user identification information portion with the second segment of the biometric template stored in template storage computer 150, second template storage computer 160 may send the received transaction ID (e.g., tx_ID) and the second segment of the biometric template (e.g., temp1_F2) to matchmaker computer 220. Second template storage computer 150 may learn the identity of matchmaker computer 220 based on the identity of the matchmaker computer (e.g., ID_Matcher) received from ID manager computer 170.
[0061] In step s12, the matchmaker computer 220 can now correlate the different transmissions received from the various entities using the transaction id (e.g., tx_ID) received from the access device 130. The matchmaker computer 220 can combine the two received biometric template fragments (e.g., templ_F1 and templ_F2) to create a combined biometric template that is used in conjunction with the access device 130. Figure 1 A copy of the biometric template generated during the registration process described above is generated. The matchmaker computer 220 can then compare the combined biometric template with the biometric data obtained during the current authentication process. The matchmaker computer 220 can determine whether the biometric data obtained during the current authentication process matches the biometric template obtained during the registration process, and ultimately determine whether the current user 110 is the authentic user. If the matchmaker computer 220 determines that the biometric data obtained during the current authentication process matches the biometric template obtained during the registration process, the matchmaker computer 220 can publish the match result along with a transaction ID (e.g., tx_ID) on its website or blockchain. The access device 130 can then use the transaction ID (e.g., tx_ID) to search for the match result on the website or blockchain and perform authentication based on the result. In some embodiments, the biometric data obtained during the current authentication process may not exactly match the biometric template obtained during the registration process. Rather, the biometric data obtained during the current authentication process may successfully match the biometric template obtained during the registration process because it "closely" matches the biometric template obtained during the registration process.
[0062] As shown, the matchmaker computer 220 does not receive any user-identifying information, and the first and second template storage computers 150 and 160 simply receive random numbers that cannot be associated with a biometric template or user-identifying information. If a fraudster were able to eavesdrop on incoming transmissions to the first and second template storage computers 150, they would be able to recover fragments of the biometric template, but would not be able to associate them with any user-identifying information. Consequently, the fraudster would not be able to obtain valuable information and would be unable to compromise the server-side biometric authentication system.
[0063] The ID manager computer 170, the ID splitting computer 180, the first template storage computer 1500, the second template storage computer 160, and the matchmaker computer 220 may be known entities that can use trusted TLS sessions with each other. In some embodiments, there may be more than one matchmaker computer 220 and more than one ID manager computer 170. A public key infrastructure (PKI) may be employed to enable mutually authenticated TLS sessions. Alternatively or in addition, encryption using public keys may also be implemented.
[0064] Figure 3 is a simplified block diagram of an ID manager computer 170 according to an embodiment of the present invention. The ID manager computer 170 includes an input / output interface 310, a memory 320, a processor 330, and a computer readable medium 340. In some embodiments, the ID manager computer 170 may reside on a computer readable medium. Figure 1 and Figure 2 Described within a server-side biometric authentication system.
[0065] The input / output (I / O) interface 310 is configured to receive and send data. For example, the I / O interface 310 may receive user identification information ( Figure 1 In another example, the I / O interface 310 may send the transaction ID to the access device 130 ( Figure 2 ), the first template storage computer 150 ( Figure 2 ) and the second template storage computer 160 ( Figure 2 ). I / O interface 310 can also be used for direct interaction with ID manager computer 170. I / O interface 310 can accept input from an input device (such as, but not limited to, a keyboard, keypad, or mouse). In addition, the I / O interface can display output on a display device.
[0066] Memory 320 may be any magnetic, electronic, or optical memory. It is understood that memory 320 may include any number of memory modules. An example of memory 320 may be dynamic random access memory (DRAM).
[0067] Processor 330 may be any general purpose processor operable to execute instructions on ID manager computer 170. Processor 330 is coupled to other elements of ID manager computer 170, including input / output interface 310, memory 320, and computer readable media 340.
[0068] The computer readable medium 340 may be any magnetic, electronic, optical or other computer readable storage medium. The computer readable storage medium 340 includes a user identifier retrieval module 342 and a user identifier transmission module 344 .
[0069] The user identifier retrieval module 342 may be configured to interface with the ID splitting computer 180 when executed by the processor 330 ( Figure 1 ) to facilitate retrieval of portions of the user identification information. The user identifier retrieval module 342 may facilitate receipt of user identification information from the access device 130 ( Figure 1 After receiving the user identification information from the access device 130 ( Figure 1 ), the user identifier retrieval module 342 may send the received user identification information to the ID splitting computer 180 ( Figure 1 Thereafter, the user identifier retrieval module 342 may facilitate receipt of two or more parts of user identification information (eg, useridentifier_1 and useridentifier_2) from the ID splitting computer 180. Figure 1 The user identifier retrieval module 342 can facilitate various data transmission and reception by interfacing with the I / O interface 310 .
[0070] The user identifier transmission module 344 may be configured to interface with the first and second template storage computers 150, 160 when executed by the processor 330. Figure 1 ) to transmit the parts of the user identification information. Once the ID manager computer 170 receives two or more parts of the user identification information from the ID splitting computer 180 ( Figure 1 ), the user identifier retrieval module 342 may facilitate transmission of one of the portions of the user identification information to each of the template storage computers. For example, the user identifier retrieval module 342 may facilitate transmission of the first portion of the user identification information (e.g., useride ntifier_1) to the first template storage computer 150 ( Figure 1 ), the second part of the user identification information (eg, useridentifier_2) is transmitted to the second template storage computer 160 ( Figure 2 The user identifier transmission module 344 can facilitate various data transmission and reception by interfacing with the I / O interface 310 .
[0071] Figure 4 is a simplified block diagram of a matchmaker computer 220 according to an embodiment of the present invention. The matchmaker computer 220 includes an input / output interface 410, a memory 420, a processor 430, and a computer readable medium 440. In some embodiments, the matchmaker computer 220 may reside on a computer connected to the Figure 2 Described within a server-side biometric authentication system.
[0072] The input / output (I / O) interface 310 is configured to receive and send data. For example, the I / O interface 310 may receive data from Figure 2 In another example, the I / O interface 310 can receive data from the biometric reader 140 ( Figure 2 ) and / or access device 130 ( Figure 2 ) and the current biometric data. The I / O interface 310 can also be used for direct interaction with the matchmaker computer 220. The I / O interface 310 can accept input from an input device (such as, but not limited to, a keyboard, keypad, or mouse). In addition, the I / O interface can display output on a display device.
[0073] Memory 320 may be any magnetic, electronic, or optical memory. It is understood that memory 320 may include any number of memory modules. An example of memory 320 may be dynamic random access memory (DRAM).
[0074] Processor 330 may be any general purpose processor that can be used to execute instructions on matching computer 220. Processor 330 is coupled to other elements of matchmaker computer 220, including input / output interface 310, memory 320, and computer readable media 340.
[0075] The computer-readable medium 340 can be any magnetic, electronic, optical or other computer-readable storage medium. The computer-readable storage medium 340 includes a template combination module 442 , a matching determination module 444 and a result transmission module 446 .
[0076] The template combination module 442, when executed by the processor 430, can be configured to facilitate combining multiple segments of a biometric template to create a combined biometric template. The template combination module 422 can facilitate receiving multiple segments of a biometric template from various template storage computers via the I / O interface 410. For example, the template combination module 442 can facilitate receiving a first segment of a biometric template ( Figure 2 ) and receiving a second segment of the biometric template from the second template storage computer 160 ( Figure 2 After receiving the various segments of the biometric template, the template combination module 442 can facilitate combining the various segments of the biometric template to create a biometric template that reflects the combination of the original biometric template generated during enrollment. The manner in which the segments of the biometric template are combined can be based on a specific algorithm.
[0077] When executed by the processor 430, the match determination module 444 may be configured to determine whether there is a match between the combined biometric template combined by the template combination module 442 and the biometric data provided by the user during the current authentication session. Determining whether there is a match between the combined biometric template combined by the template combination module 442 and the biometric data provided by the user during the current authentication session may be based on a specific algorithm.
[0078] The result transmission module 446, when executed by the processor 430, may be configured to publish the matching result determined by the matching determination module 444 to a website or blockchain. Alternatively, in some embodiments, the result transmission module 446 may transmit the result to the access device 130 ( Figure 1 ).
[0079] Figure 5 1 shows a block diagram of a typical transaction processing system 500. The system 500 may include a payment device 120, an access device 130, a merchant computer 535, an acquirer computer 530, a payment processing network computer 540, and an issuer computer 550. In some embodiments, Figure 5 The different entities in the system 500 may communicate with each other using one or more communication networks such as the Internet, a cellular network, a TCP / IP network, or any other suitable communication network. Figure 6 Some of the components described are associated with computer devices that implement them.
[0080] The payment device 120 may be associated with a user's payment account. In some embodiments, the payment device 120 may be a mobile device, such as a mobile phone, tablet computer, PDA, laptop computer, key card, or any suitable mobile device. In some embodiments, the payment device 120 may be a wearable device, such as, but not limited to, a smartwatch, a fitness tracker, an anklet, a ring, earrings, etc. For example, the payment device 120 may include a virtual wallet or payment application that may be associated with one or more payment accounts of the user. In some embodiments, the payment device 120 may be able to use, for example, Wi-Fi TM or Bluetooth TMThe payment device 120 may communicate with the access device 130 using a wireless data protocol. For example, the payment device 120 may interact with the access device 130 by establishing a connection with the access device 130 using the wireless data protocol. In some embodiments, the payment device 120 may be a plastic card associated with a user account.
[0081] The access device 130 can be an access point to a transaction processing system that can include an acquirer computer 530, a payment processing system computer 540, and an issuer computer 550. In some embodiments, the access device 130 can be associated with or operated by a merchant computer 535. For example, the access device 130 can be a point-of-sale device that can include a contactless reader, an electronic cash register, a display device, etc. In some embodiments, the access device 130 can be configured to transmit information related to one or more items purchased at the merchant 535 to the acquirer 530 or the payment processing network 540. In some embodiments, the access device 130 can be a personal computer that a user can use to initiate a transaction (e.g., an online transaction) with the merchant computer 525. In some embodiments, the access device can be configured to interface with a biometric reader to obtain biometric data pertaining to a biometric sample provided by the user.
[0082] Acquirer computer 530 may be operated by an acquirer. An acquirer is typically a system of an entity (e.g., a bank) that has a business relationship with a particular merchant, wallet provider, or another entity. Acquirer computer 530 may be communicatively coupled to merchant computer 535 and payment processing network 540 and may open and manage financial accounts for merchants. Acquirer computer 530 may be configured to route authorization requests for transactions to issuer computer 550 via payment processing network computer 540, and to route authorization responses received via payment processing network computer 540 to merchant computer 535.
[0083] The payment processing network computer 540 may be configured to provide authorization services and clearing and settlement services for payment transactions. The payment processing network computer 540 may include a data processing subsystem, a wired or wireless network, including the Internet. Examples of payment processing network computers 540 include computers powered by V VisaNet TM Payment processing networks such as VisaNet TM Able to process credit card transactions, debit card transactions and other types of commercial transactions. VisaNet TMSpecifically, it includes a Visa Integrated Payment (VIP) system that processes authorization requests and a Base II system that performs clearing and settlement services. The payment processing network computer 540 may include a server computer. In some embodiments, the payment processing network computer 540 may forward the authorization request received from the acquirer computer 530 to the issuer computer 550 via a communication channel. The payment processing network computer 540 may also forward the authorization response message received from the issuer computer 550 to the acquirer computer 530. In some embodiments, the payment processing network 540 may operate the ID manager computer 170 ( Figure 1 ).
[0084] Issuer computer 550 may represent an account issuer and / or an issuer processor. Typically, issuer computer 550 may be associated with a business entity (e.g., a bank) that issues an account and / or payment card (e.g., a credit account, a debit account, etc.) for a user's payment transaction. In some embodiments, the business entity (e.g., a bank) associated with issuer computer 550 may also act as an acquirer (e.g., acquirer computer 530).
[0085] In some embodiments of the present invention, the issuer computer 550 and / or the payment processing network computer 540 can function as an authorization system. For example, after a user successfully biometrically authenticates with a server-side biometric authentication system disclosed herein, the issuer computer 550 and / or the payment processing network computer 540 can authorize a transaction.
[0086] The various entities in system 500 may communicate with each other via an interconnected network 560 (eg, the Internet).
[0087] References in this article Figure 1-5 The various parties and elements described may operate on one or more computer devices to facilitate the functions described herein. Figure 1-5 Any element in the , including any server or database, may use any suitable number of subsystems to facilitate the functionality described herein.
[0088] Figure 6 Examples of such subsystems or components are shown in . Figure 6The subsystems shown in FIG6 are interconnected via a system bus 675. Additional subsystems are also shown, such as a printer 603, a keyboard 606, a fixed disk 607 (or other memory including computer-readable media), a monitor 609 coupled to a display adapter 604, and other devices. Peripherals and I / O devices coupled to an input / output (I / O) controller 600 (which can be a processor or any suitable controller) can be connected to the computer system by any means known in the art, such as a serial port 605. For example, a serial port 605 or an external interface 608 can be used to connect the computer device to a wide area network (e.g., the Internet), a mouse input device, or a scanner. The interconnection via the system bus allows the central processor 602 to communicate with each subsystem and control the execution of instructions from the system memory 601 or the fixed disk 607 and the exchange of information between the subsystems. The system memory 601 and / or the fixed disk 607 can be embodied as computer-readable media.
[0089] Any software component or functionality described in this application can be implemented as software code executed by a processor using, for example, conventional or object-oriented techniques and using any suitable computer language (such as, for example, Java, C++, or Perl). The software code can be stored as a series of instructions or commands on a computer-readable medium (such as, random access memory (RAM), read-only memory (ROM), magnetic media (such as a hard disk or floppy disk), or optical media (such as a CD-ROM). Any such computer-readable medium can reside on or within a single computing device and can exist on or within different computing devices within a system or network.
[0090] The above description is illustrative and non-restrictive. After reading this disclosure, many variations of the present invention will become apparent to those skilled in the art. Therefore, the scope of the present invention should not be determined with reference to the above description, but should be determined with reference to the pending claims and their full scope or equivalents.
[0091] One or more features of any embodiment may be combined with one or more features of any other embodiment without departing from the scope of the present invention.
[0092] Unless expressly indicated to the contrary, the use of "a," "an," or "the" is intended to mean "one or more."
[0093] All patents, patent applications, publications, and descriptions mentioned above are incorporated herein by reference in their entirety for all purposes. No admission is made that they are prior art.
Claims
1. A method comprising: receiving, at an enrollment computer, from a user a biometric sample and user identification information associated with the user; generating, by the enrollment computer, a biometric template based on the biometric sample; Splitting the biometric template into a first segment of the biometric template and a second segment of the biometric template by the enrollment computer; generating, by the enrollment computer, a first random number associated with the first segment of the biometric template and a second random number associated with the second segment of the biometric template, wherein the first random number is different from the second random number; sending, by the enrollment computer, the first random number and the first segment of the biometric template to a first template storage computer; sending, by the enrollment computer, the second random number and the second segment of the biometric template to a second template storage computer; as well as The enrollment computer provides the user identification information, the first random number, and the second random number to an identity ID manager computer, the identity ID manager computer transmits the user identification information to an ID splitting computer, wherein the ID splitting computer generates a first user identifier and a second user identifier based on the user identification information, wherein the first user identifier is different from the second user identifier, and sends the first user identifier and the second user identifier to the identity ID manager computer, wherein the identity ID manager computer sends the first user identifier and the first random number to a first template storage computer, and sends the second user identifier and the second random number to a second template storage computer, and wherein the first template storage computer associates the first user identifier with the first segment of the biometric template based on the first random number, and the second template storage computer associates the second user identifier with the second segment of the biometric template based on the second random number.
2. The method of claim 1, wherein the biometric sample comprises at least one of a voice sample, a fingerprint, an iris scan, palm geometry, earlobe geometry, or a deoxyribonucleic acid (DNA) scan.
3. The method according to claim 1, wherein: Associating the first user identifier with the first segment of the biometric template includes storing a first record in a database associating the first user identifier with the first segment of the biometric template; and Associating the second user identifier with the second segment of the biometric template includes storing a second record in the database associating the second user identifier with the second segment of the biometric template.
4. The method of claim 1, wherein the user identification information comprises at least one of a primary account number (PAN), a token, a name, an address, a telephone number, or an email address.
5. The method according to claim 1, further comprising: splitting, by the enrollment computer, the biometric template into a third segment of the biometric template; generating, by the enrollment computer, a third random number associated with the third segment of the biometric template; as well as The third random number and the third segment of the biometric template are sent by the enrollment computer to a third template storage computer. The method of claim 1 , wherein the registration computer is an access device.
7. The method according to claim 1, wherein: During a user authentication step, the first segment of the biometric template is retrieved by a matcher computer from the first template storage computer, and the second segment of the biometric template is retrieved by the matcher computer from the second template storage computer; and Wherein the first segment of the biometric template and the second segment of the biometric template are combined by the matcher computer to determine whether the combined biometric template matches the biometric data provided by the user.
8. A computer device comprising: processor; as well as A non-transitory computer-readable medium comprising computer-executable code for performing a method comprising: receiving a biometric sample from a user and user identification information associated with the user; generating a bioassay template based on the bioassay sample; splitting the biometric template into a first fragment of the biometric template and a second fragment of the biometric template; generating a first random number associated with the first segment of the biometric template and a second random number associated with the second segment of the biometric template, wherein the first random number is different from the second random number; sending the first random number and the first segment of the biometric template to a first template storage computer; sending the second random number and the second segment of the biometric template to a second template storage computer; and The computer device provides the user identification information, the first random number, and the second random number to an identity (ID) manager computer, the identity (ID) manager computer transmits the user identification information to an ID splitting computer, wherein the ID splitting computer generates a first user identifier and a second user identifier based on the user identification information, wherein the first user identifier is different from the second user identifier, and sends the first user identifier and the second user identifier to the identity (ID) manager computer, wherein the identity (ID) manager computer sends the first user identifier and the first random number to a first template storage computer, and sends the second user identifier and the second random number to a second template storage computer, and wherein the first template storage computer associates the first user identifier with the first segment of the biometric template based on the first random number, and the second template storage computer associates the second user identifier with the second segment of the biometric template based on the second random number.
9. The computer device of claim 8, wherein the biometric sample comprises at least one of a voice sample, a fingerprint, an iris scan, palm geometry, earlobe geometry, or a deoxyribonucleic acid (DNA) scan.
10. The computer device of claim 8, wherein: Associating the first user identifier with the first segment of the biometric template includes storing a first record in a database associating the first user identifier with the first segment of the biometric template; and Associating the second user identifier with the second segment of the biometric template includes storing a second record in the database associating the second user identifier with the second segment of the biometric template.
11. The computer device of claim 8, wherein the user identification information comprises at least one of a primary account number (PAN), a token, a name, an address, a telephone number, or an email address.
12. The computer device of claim 8, wherein the method further comprises: splitting the bioassay template into third fragments of the bioassay template; generating a third random number associated with the third segment of the biometric template; The third random number and the third segment of the biometric template are sent to a third template storage computer.
13. The computer device of claim 8, wherein the computer is an access device.
14. The computer device of claim 8, wherein: During a user authentication step, the first segment of the biometric template is retrieved by a matcher computer from the first template storage computer, and the second segment of the biometric template is retrieved by the matcher computer from the second template storage computer; and Wherein the first segment of the biometric template and the second segment of the biometric template are combined by the matcher computer to determine whether the combined biometric template matches the biometric data provided by the user.
15. A method comprising: generating, at the access device, a message including user identification information associated with the user; sending, by the access device, the message including the user identification information associated with the user to an ID manager computer; receiving, by the access device from the ID manager computer, a message including a transaction identifier; receiving a biometric sample from the user by a biometric reader in communication with the access device, wherein the biometric reader converts the biometric sample into biometric sample data; and The transaction identifier and the biometric sample data are sent to a matcher computer, wherein the matcher computer receives the transaction identifier and a first segment of a biometric template from a first template storage computer, receives the transaction identifier and a second segment of the biometric template from a second template storage computer, combines at least the first segment of the biometric template and the second segment of the biometric template, and compares at least the combined first segment of the biometric template and the second segment of the biometric template with the biometric sample data to determine whether at least the combined first segment of the biometric template and the second segment of the biometric template match the biometric sample data, wherein the first template storage computer stores the first segment of the biometric template and a first user identifier derived from the user identification information, and the second template storage computer stores the second segment of the biometric template and a second user identifier derived from the user identification information, and the first user identifier and the second user identifier are random numbers.
16. The method according to claim 15, further comprising: After determining whether the at least combined first segment of the biometric template and the second segment of the biometric template match the biometric sample data, a matching result is published on a website or a blockchain.
17. The method of claim 15, wherein the first template storage computer receives the first user identifier and the transaction identifier from the ID manager computer, and wherein the second template storage computer receives the second user identifier and the transaction identifier from the ID manager computer.
18. The method of claim 15, wherein the biometric sample is a fingerprint, a voiceprint, or a retinal scan.
19. The method of claim 15, wherein the user identification information comprises a primary account number, a telephone number, or an email address.
20. The method of claim 15, wherein the user identification information is provided to the access device by a portable device.
21. The method of claim 15, wherein the access device is a point-of-sale terminal.
22. The method of claim 15, wherein the message sent to the ID manager computer includes an identifier of the matchmaker computer.
23. The method of claim 15, further comprising: A transaction is conducted after determining that the at least combined first segment of the biometric template and the second segment of the biometric template match the biometric sample data.
24. A system comprising: processor; as well as A computer-readable medium comprising code executable by the processor to implement a method comprising: generating a message including user identification information associated with the user; sending said message including said user identification information associated with said user to an ID manager computer; receiving a message including a transaction identifier from the ID manager computer; receiving a biometric sample from the user, wherein a biometric reader in the system converts the biometric sample into biometric sample data; and sending the transaction identifier and the biometric sample data to a matcher computer, wherein the matcher computer receives the transaction identifier and a first segment of a biometric template from a first template storage computer, receives the transaction identifier and a second segment of the biometric template from a second template storage computer, combines at least the first segment of the biometric template and the second segment of the biometric template, and compares at least the combined first segment of the biometric template and the second segment of the biometric template with the biometric sample data to determine whether the at least combined first segment of the biometric template and the second segment of the biometric template match the biometric sample data, wherein the first template storage computer stores the first segment of the biometric template and a first user identifier derived from the user identification information, and the second template storage computer stores the second segment of the biometric template and a second user identifier derived from the user identification information, and wherein the first user identifier is different from the second user identifier, and the first user identifier and the second user identifier are random numbers.
25. The system of claim 24, wherein the method further comprises: After determining whether the at least combined first segment of the biometric template and the second segment of the biometric template match the biometric sample data, a matching result is published on a website or a blockchain.
26. The system of claim 24, wherein the first template storage computer receives the first user identifier and the transaction identifier from the ID manager computer, and wherein the second template storage computer receives the second user identifier and the transaction identifier from the ID manager computer.
27. The system of claim 24, wherein the biometric sample is a fingerprint, a voiceprint, or a retinal scan.
28. The system of claim 24, wherein the user identification information comprises a primary account number, a telephone number, or an email address.
29. The system of claim 24, wherein the user identification information is provided to the system by a portable device.
30. The system of claim 24, wherein the system comprises an access device and the biometric reader.
31. The system of claim 24, wherein the message sent to the ID manager computer includes an identifier of the matchmaker computer.
32. The system of claim 24, wherein the method comprises: A transaction is conducted after determining that the at least combined first segment of the biometric template and the second segment of the biometric template match the biometric sample data.
Citation Information
Patent Citations
System and method for protecting the privacy and security of stored biometric data
US20060239511A1
Apparatus and method for authenticating biometric information
US20120169463A1