Delegated biometric authentication

CN114556339BActive Publication Date: 2026-08-21VISA INTERNATIONAL SERVICE ASSOCIATION
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202080067453.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-10-01
Filing Date
2020-09-28
Publication Date
2026-08-21
Estimated Expiration
2040-09-28

AI Technical Summary

Technical Problem

[0007]然而,存在与在并非由对应于生物特征的用户拥有的装置上使用例如那些生物特征的敏感认证信息相关联的固有安全风险

Benefits of technology

[0149]本发明的实施例的优点在于,在认证时创建生物特征模板并在认证时使用,紧接着弃用。在认证时创建的生物特征模板不绑定到特定身份,而是仅用于检查其是否可以解锁仓库。因此,公共装置从不了解用户的确切身份(保留隐私)。另一个优点是登记模板在登记或认证期间不从用户的私人通信装置发送到公共装置。这样做的好处是安全性更高。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114556339B_ABST
    Figure CN114556339B_ABST
Patent Text Reader

Abstract

A delegated biometric feature authentication system and related methods are disclosed. Using the system, a user can securely delegate biometric authentication from their communication device to a public device. This public device can be an Internet of Things device that is not owned by the user, such as a computer, smart television, tablet, etc. The public device can operate in a public space, such as a hotel or library. The communication device can be the user's own smartphone or tablet, etc. The user's biometric template can be stored in the system using a fuzzy vault process. Embodiments protect the user's privacy without compromising authentication security and user convenience.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-referencing related applications

[0002] This application is a PCT application that claims priority to U.S. Non-Provisional Application No. 16 / 589,609, filed October 1, 2019, which is incorporated herein by reference in its entirety for all purposes. Background Technology

[0003] "Biometrics" can refer to physical measurements that can be used to identify or authenticate an individual. Advances in sensor technology, including digital cameras, have made biometrics easier to use in authentication processes. For example, facial recognition can be used to lock or unlock certain brands of smartphones. Recent trends suggest that biometrics may be used more frequently for authentication in the future, contrary to more traditional authentication information such as passwords, personal identification numbers (PINs), etc. While fraudsters may remember and steal passwords, it is generally more difficult to obtain or forge biometric information such as iris, retinal, facial, or fingerprint scans.

[0004] In some situations, biometric authentication can offer users greater convenience. For example, in traditional systems, users authenticate by actively entering a password into the terminal, while in biometric authentication systems, users passively look at the camera. This requires no effort and may be faster and more convenient for users.

[0005] Relatedly, advancements in processing and networking technologies have led to a surge in smart connected devices, such as Internet of Things (IoT) devices. These devices offer users greater convenience in a variety of ways. For example, smart TVs allow users to easily purchase pay-per-view content, and smart thermostats allow users to control the temperature of their homes when they are away from home.

[0006] IoT devices and other public devices are becoming increasingly prevalent in public spaces such as hotels, libraries, airplanes, taxis, or the backs of shared cars. These devices can be used by users during their stay in these public spaces, such as while on vacation, traveling to a library, or getting to an airport. Many of these devices allow users to perform interactions, such as checking in at a library or purchasing pay-per-view content from a hotel's smart TV. These interactions may involve authentication, specifically biometric authentication.

[0007] However, there are inherent security risks associated with using sensitive authentication information, such as those biometrics, on devices not owned by the corresponding biometric user. For example, a user's smartphone will typically be owned by the user and accessible only to that user, while a hotel's smart TV could be accessed by hundreds or thousands of users, including potential hackers or fraudsters.

[0008] The embodiments individually and collectively address these and other problems. Summary of the Invention

[0009] The embodiments relate to a delegated biometric authentication system and related methods. The embodiments allow users to perform biometric authentication using public devices without compromising user security and privacy. In doing so, sensitive biometric information (e.g., biometric templates) and interaction tokens (e.g., payment tokens, including limited-use or limited-time tokens) are protected without sacrificing user convenience.

[0010] Some embodiments include devices associated with the delegated biometric system, including a communication device associated with a user (e.g., a smartphone, laptop, etc.), a public device (e.g., a public IoT device associated with a public space, such as a hotel smart TV, a terminal for registering to borrow books in a library, etc.), an authentication server computer, and a token server computer. In some embodiments, the authentication server computer can be used to verify that the user's communication device connects (e.g., using NFC) to the registered public IoT device during the setup phase. Subsequently, the authentication server can control the process (e.g., request a cleanup process on the IoT device). In some embodiments, the token server computer can issue access data, such as an interaction token (e.g., a payment token) and / or a master secret key.

[0011] By using a delegated authentication system, users can delegate biometric authentication to public devices, allowing them to authenticate themselves using biometrics (e.g., facial scans, iris scans, retinal scans, fingerprint scans, voice recordings, handwritten signatures, etc.). This allows users to securely and conveniently perform interactions that require some form of authentication (e.g., purchasing or borrowing library books, accessing email or bank accounts).

[0012] Implementations can utilize fuzzy extractor schemes, such as fuzzy repository schemes. These fuzzy repository schemes can be used to securely store sensitive information (e.g., interaction tokens) in the form of a data repository. Other information or data (e.g., biometric templates) can be used to lock the sensitive data, which can be considered as keys. Users can unlock the data repository by providing a key in the form of a biometric template to a public device (e.g., by performing a facial scan using a digital camera attached to the public device). Because the interaction token is locked in the data repository using the biometric template associated with the user, other users cannot access and misuse the interaction token (e.g., by using the interaction token for unauthorized purchases). Furthermore, since the data repository does not store the biometric template or interaction token in plaintext, hackers or other malicious users cannot access the public device's memory to steal the biometric template or interaction token. Therefore, the delegation authentication system provides greater security and convenience for users using public devices.

[0013] One embodiment relates to a method comprising: receiving a request from a user to interact with a resource provider by a public device; collecting a first biometric template corresponding to the user by the public device; unlocking a data warehouse by the public device using the first biometric template, wherein the data warehouse includes access data locked using a second biometric template corresponding to the user; sending the access data to the resource provider by the public device; and performing the interaction with the resource provider by the public device.

[0014] Another embodiment relates to a common device comprising: a processor; and a non-transient computer-readable medium coupled to the processor, the non-transient computer-readable medium including code executable by the processor to implement the methods described above.

[0015] Another embodiment relates to a method comprising: receiving access data from an authentication server computer or a token server computer by a communication device associated with a user; generating a fuzzy database by the communication device using a biometric template corresponding to the user to lock the access data; and sending the database to a public device by the communication device.

[0016] Another embodiment relates to a method comprising: receiving, by an authentication server computer, an authentication request message from a public device, the authentication request message including an identifier of a communication device associated with a user; sending a delegation confirmation message to the communication device by the authentication server computer; receiving a delegation confirmation response from the communication device by the authentication server computer; sending a request for access data to a token server computer by the authentication server computer; receiving the access data from the token server computer by the authentication server computer; and sending the access data to the communication device by the authentication server computer, wherein the communication device uses a biometric template associated with the user to lock the access data in a data warehouse.

[0017] the term

[0018] Before discussing specific embodiments of the present invention, some terms may be described in detail.

[0019] A "server computer" can include a powerful computer or cluster of computers. For example, a server computer can be a mainframe, a small cluster of computers, or a group of servers that work like cells. In one example, a server computer can be a database server coupled to a web server. A server computer can include one or more computing devices and can use any of a variety of computing architectures, arrangements, and compilations to serve requests from one or more client computers.

[0020] "Memory" can include one or more suitable means for storing electronic data. Suitable memory can include non-transient computer-readable media whose storage can be executed by a processor to implement a desired method. Examples of memory can include one or more memory chips, disk drives, etc. Such memory can be operated using any suitable electrical, optical, and / or magnetic modes of operation.

[0021] "Processor" can include any suitable one or more data computing devices. A processor can include one or more microprocessors working together to perform the desired function. A processor can include a CPU, which includes at least one high-speed data processor sufficient to execute program components for performing user and / or system-generated requests. The CPU can be a microprocessor such as AMD's Athlon, Duron, and / or Opteron; IBM and / or Motorola's PowerPC; IBM and Sony's Cell processors; Intel's Celeron, Itanium, Pentium, Xeon, and / or XScale; and / or similar processors.

[0022] A “communication device” can include any electronic device that can provide communication capabilities, including via mobile phone (wireless) networks, wireless data networks (e.g., 3G, 4G, or similar networks), Wi-Fi, Wi-Max, or any other communication medium that provides access to networks such as the Internet or a private network. Examples of communication devices include mobile phones (e.g., cellular phones), PDAs, tablets, netbooks, laptops, personal music players, handheld dedicated readers, wearable devices (e.g., watches), vehicles (e.g., automobiles), etc. A communication device can include any suitable hardware and software for performing such functions, and may also include multiple devices or components (e.g., two devices combined can be considered a single communication device when the device remotely accesses a network by being attached to another device (i.e., using another device as a repeater)). A communication device can store and capture biometric templates, for example, using a camera to capture facial scans or using a touchscreen to capture fingerprints. Mobile devices can store biometric templates on secure storage elements. A communication device can be a “dedicated device” for a user. A user’s dedicated device may be used only by a single user.

[0023] A "biometric template" can be a digital reference for unique features extracted from a biometric instance. Templates are used during the biometric authentication process.

[0024] A "fuzz extractor" can be a biometric tool that allows user authentication using a biometric template composed of the user's biometric data as a key. A fuzzy repository or fuzzy repository scheme can be an example of a fuzz extractor.

[0025] A "fuzzy vault" or "fuzzy vault scheme" can be a method for providing secure authentication based on fuzzy set matching. A fuzzy vault can be an encryption scheme that uses concepts from error-correcting codes to encode information in a way that makes it difficult to retrieve the information even if the encoding method is well-known, without the "key" used for encoding. The encoded information can be in the form of a data warehouse. Fuzzy vaults are described in the following document: A. Juels and M. Sudan, "A Fuzzy Vault Scheme," Proceedings of the IEEE International Symposium on Information Theory (…). Proc. IEEE Int.l. Symp. Inf. Theory)A. Lapidoth and E. Teletar (eds.), p. 408, 2002; K. Nandakumar et al., “Fingerprint-based fuzzy vault: Implementation and performance,” IEEE Transactions on Information Forensics and Security (December 2007); and U. Uludag et al., “Fuzzy Fingerprint Vault,” Proceedings of the Symposium: Biometrics: A Challenge from Theory to Practice. (Proc.) Workshop: Biometrics: Challenges Arising from Theory to Practice) Pages 13-16, 2004.

[0026] A "data warehouse" can be a secure encoding of data. Data in a data warehouse may be protected in some way so that it can only be accessed with the correct key. Data warehouses can contain encrypted data, and in some embodiments, they may be formed using a fuzzy warehouse scheme.

[0027] A "public device" can be a device that is not designated for use by a single user but is typically used by many users. Therefore, the data security that can be provided to a public device can be less than that of a device specifically associated with a particular user.

[0028] "User" can include an individual. In some embodiments, a user can be associated with one or more personal accounts and / or mobile devices. A user can also be referred to as a cardholder, account holder, or consumer.

[0029] A "biometric instance" may include information related to biological observation. A biometric instance may include biometric data corresponding to a biometric sample. A "biometric template" can be exported from a biometric instance. Biometric instances can be captured via a "biometric interface," hardware used to capture the biometric instance. For example, a biometric instance can be captured via a biometric interface such as an iris scanner, which includes an infrared light source and a camera. Examples of biometric instances include a digital representation of an iris scan (e.g., binary code representing the iris), fingerprints, voice recordings, facial scans, and so on.

[0030] "Resource provider" can include entities that can provide resources such as goods, services, information, and / or access. Examples of resource providers include businesses, government entities, entities that provide secure location access, data access providers, etc. "Business" can be an entity that participates in transactions and can sell goods or services or provide access to goods or services.

[0031] "Acquiring party" can include a business entity (e.g., a commercial bank) that has a business relationship with a particular merchant or other entity. Some entities can perform both issuing and acquiring functions. Some embodiments may cover such a single-entity issuing-acquiring party. The acquiring party can operate an acquiring party computer, which may also be generally referred to as a "transfer computer".

[0032] "Authorizing entity" can include any entity that requests authorization. Instances of authorizing entities can include issuers, government agencies, document repositories, access administrators, and so on. "Issuer" typically refers to a commercial entity that maintains user accounts (such as a bank). Issuers can also issue payment credentials to consumers stored on mobile devices such as cell phones, smart cart cards, tablets, or laptops. Authorizing entities can operate authorized computers.

[0033] "Authentication data" can include any data suitable for proving the authenticity and validity of something. Authentication data can be obtained from a user or a device operated by the user. Examples of authentication data obtained from a user may include a PIN (Personal Identification Number), password, etc. Examples of authentication data that can be obtained from a mobile device may include a device serial number, hardware security element identifier, device fingerprint, phone number, IMEI number, biometric template stored on the mobile device, etc.

[0034] A "payment device" can include any suitable device that can be used to conduct financial transactions, such as issuing payment credentials to merchants. A payment device can be a software object, a hardware object, or a physical object. As an example of a physical object, a payment device can include a substrate (e.g., a paper or plastic card) and information printed, embossed, encoded, or otherwise included on or near the surface of the object. Hardware objects may involve circuitry (e.g., permanent voltage values), while software objects may involve non-permanent data stored on the device. A payment device can be associated with, for example, monetary value, discount, or store credit, and can be associated with an entity such as a bank, merchant, payment processing network, or individual. A payment device can be used to conduct payment transactions. Suitable payment devices can be handheld and compact, allowing them to be placed in a user's wallet and / or pocket (e.g., pocket-sized). Exemplary payment devices can include smart cards, magnetic stripe cards, and keychain devices (e.g., Speed-passes available commercially from ExxonMobil). TMOther examples of mobile devices include pagers, payment cards, security cards, access cards, smart media, answering machines, etc. If the payment device is in the form of a debit card, credit card, or smart card, it may optionally also have features such as a magnetic stripe. Such devices can operate in contact or contactless modes. In some embodiments, the mobile device can be used as a payment device (e.g., the mobile device can store and be able to send payment credentials for a transaction).

[0035] "Access data" can include any suitable data that can be used to access resources. Access data can be in any suitable form. Examples of access data can include credentials (e.g., tokens, such as interaction tokens), a master secret key that can be used to decrypt the interaction token, etc. In embodiments, the use of a master secret key may be desirable. The advantage of doing so is that the master key can be in a predefined fixed format (e.g., a 256-bit key), while the interaction token can be generic; thus making the framework expandable / scalable.

[0036] A “credential” can include any suitable information that serves as reliable evidence of value, ownership, identity, or power. An “access credential” can be a document that can be used to obtain access to a specific resource (e.g., goods, services, location, etc.). A credential can be a string of numbers, letters, or any other suitable characters, or any object or document that can serve as authentication. Examples of credentials include identity cards, authentication documents, access cards, passwords and other login information, payment account numbers, access badge numbers, payment tokens, access tokens, etc.

[0037] A "payment credential" may include any suitable information associated with an account (e.g., a payment account and / or a payment device associated with that account). Such information may be directly related to the account or derived from account-related information. Examples of account information may include PAN (primary account number or "account number"), user name, expiry date, CVV (card verification value), dCVV (dynamic card verification value), CVV2 (card verification value 2), etc. A payment credential may be any information identifying or associated with a payment account. A payment credential can be provided to facilitate payment from a payment account. A payment credential may also include a username, expiry date, gift card number or code, and any suitable information.

[0038] An "interaction token" can include any alternative value to a real credential that can be used for interaction. A token can be a credential and can be a string of numbers, letters, or any other suitable characters. Examples of tokens include payment tokens, personal identification tokens, etc.

[0039] A "payment token" may include an identifier for a payment account, which is an alternative to an account identifier such as a Primary Account Number (PAN). For example, a token may include a string of alphanumeric characters that can be used as an alternative to the original account identifier. For example, the token 4900 0000 0000 0001 can be used in place of PAN 4147 0900 0000 1234. In some embodiments, the token may be "reserved format" and may have a numerical format consistent with account identifiers used in existing transaction processing networks (e.g., the ISO 8583 Financial Transaction Message Format). In some embodiments, the token may replace the PAN in initiating, authorizing, processing, or resolving payment transactions, or represent the original credentials in other systems where the original credentials would typically be provided. In some embodiments, a token value may be generated such that the original PAN or other account identifier can be recovered from the token value without computation. Additionally, in some embodiments, the token format may be configured to allow the entity receiving the token to identify it as a token and to recognize the entity issuing the token.

[0040] An "authorization request message" may include an electronic message sent to request authorization of a transaction. In some embodiments, an "authorization request message" may be an electronic message sent to a payment processing network and / or the issuer of a payment card to request authorization of a transaction. Authorization request messages according to some embodiments may conform to ISO 8583, a standard for systems for exchanging information about electronic transactions associated with payments made by a consumer using a payment device or payment account. An authorization request message may include an issuer account identifier that can be associated with a payment device or payment account. An authorization request message may also include additional data elements corresponding to "identification information," such as, for example, a service code, CVV (card verification value), dCVV (dynamic card verification value), expiration date, etc. An authorization request message may also include "transaction information," such as any information associated with the current transaction, such as the transaction amount, merchant identifier, merchant location, etc., and any other information that may be used to determine whether to identify and / or authorize the transaction.

[0041] An "authorization response message" may include an electronic message reply to an authorization request message. It may be generated by the issuing financial institution or a payment processing network. As an example only, an authorization response message may include one or more of the following status indicators: Approval—the transaction is approved; Rejection—the transaction is not approved; or Call Center—a response suspending further information, requiring the merchant to call the toll-free authorization number. The authorization response message may also include an authorization code, which may be a code returned by the credit card issuing bank to the merchant's access device (e.g., a POS device) in response to the authorization request message in an electronic message (directly or via a payment processing network), indicating that the transaction has been approved. This code can serve as evidence of authorization.

[0042] A “device code” or “device identifier” may include any code specifically associated with a device (e.g., only one device). The device code can be derived from any device-specific information, including but not limited to one or more of the following: Secure Element Identifier (SE ID), IMEI number, telephone number, geolocation, device serial number, device fingerprint, etc. Such a code can be derived from this information using any appropriate mathematical operations, including hashing and / or encryption. The device code may include any suitable number and / or type of characters. Attached Figure Description

[0043] Figure 1 A system block diagram of a delegated biometric authentication system according to some embodiments is shown.

[0044] Figure 2 A lane diagram illustrating delegated biometric authentication according to some embodiments is shown.

[0045] Figure 3A A flowchart is shown for a fuzzy warehouse revocation method according to some embodiments.

[0046] Figure 3B A flowchart illustrating a method for a fuzzy warehouse replacement scheme according to some embodiments is shown.

[0047] Figure 4 A hybrid diagram illustrating data warehouse generation methods according to some embodiments is shown.

[0048] Figure 5 A hybrid diagram illustrating a method for unlocking a data warehouse formed using a fuzzy warehouse scheme, according to some embodiments.

[0049] Figure 6 A system block diagram illustrating a first exemplary interaction is shown according to some embodiments.

[0050] Figure 7 A system block diagram illustrating a second exemplary interaction is shown according to some embodiments.

[0051] Figure 8 A system block diagram of an exemplary communication device according to some embodiments is shown.

[0052] Figure 9 A system block diagram of an exemplary public device according to some embodiments is shown.

[0053] Figure 10 Exemplary methods performed by an authentication server computer according to some embodiments are shown. Detailed Implementation

[0054] The embodiments relate to methods and systems that enable users to interact with resource providers via public facilities. Public facilities can include various computers or Internet of Things (IoT) devices used by users or located in public spaces. Smart TVs in hotel rooms, computers in libraries, and security terminals in apartment buildings are examples of public facilities.

[0055] The embodiments can be used for various types of interactions. For example, embodiments can be used for transactional interactions between users and resource providers. For instance, a hotel room guest could use a public smart TV to purchase pay-per-view boxing matches offered by a broadcaster resource provider. Embodiments can also be used for non-transactional interactions between users and resource providers. For example, a library user could use a public library computer as part of a book-borrowing registration interaction to borrow a book from the library. These interactions may involve the use of interaction tokens, i.e., credentials that a user can use to authorize the interaction.

[0056] These interactions may first require user authentication. Authentication has several benefits, including fraud prevention. Authentication can be performed using biometrics such as iris scanning and facial scanning. Biometrics can be more secure than conventional authentication information (e.g., username, password, answers to security questions, etc.) and are more convenient for users because biometrics can be collected passively (e.g., by a device that takes a photo of the user's face) rather than actively (e.g., by the user entering a password into the computer system via a keyboard).

[0057] The embodiments also include a method for performing a biometric authentication delegation process that enables public devices to be used for biometric authentication. Traditionally, public devices may be too insecure to perform biometric authentication because users and resource providers do not trust that the public device or a malicious user of the public device will not steal or misuse sensitive data (such as interaction tokens and biometric templates). However, the embodiments provide a method for performing delegated biometric authentication that involves additional security and privacy measures to enable public devices to be used for biometric authentication.

[0058] These additional security and privacy measures include the use of a data warehouse formed using a fuzzy warehousing scheme. The data warehouse formed using a fuzzy warehousing scheme can lock an interaction token or a master secret key used to encrypt the interaction token using a biometric template corresponding to the user. The data warehouse can be sent to a public device, which can use it to perform delegated biometric authentication. The public device can capture a sample of a biometric instance from the user and then determine a biometric template from the biometric instance. The public device can then use the biometric template to unlock the data warehouse. If the data warehouse is successfully unlocked, the user is biometrically authenticated, and an interaction token (or other access data) can be sent to the resource provider to authorize the interaction. Furthermore, the data warehouse cannot be compromised by hackers or malicious users of the public device. Therefore, user information, including the biometric template and interaction token, is secure, and users and resource providers can trust the public device to perform delegated biometric authentication during the interaction.

[0059] Figure 1 An exemplary delegated biometric authentication system 100 according to some embodiments is illustrated. System 100 may include a user 102, a public device 104, a communication device 106, a resource provider 108, an interactive network 110, a biometric server computer 112, and a token server computer 114. Entities of system 100 may operatively communicate with each other via one or more communication networks. Additionally, entities of system 100 may communicate with each other via other suitable means such as direct connection, Bluetooth, near field communication (NFC), etc.

[0060] The communication network may take any suitable form, which may include any one and / or a combination of the following: direct interconnection, the Internet, a local area network (LAN), a metropolitan area network (MAN), an Operational Mission as an Internet node (OMNI), a secure custom connection, a wide area network (WAN), a wireless network (e.g., using protocols such as, but not limited to, Wireless Application Protocol (WAP), I-mode, etc.), and so on. Messages between entities and computers may be sent using secure communication protocols such as, but not limited to, File Transfer Protocol (FTP); Hypertext Transfer Protocol (HTTP); Secure Hypertext Transfer Protocol (HTTPS); Secure Sockets Layer (SSL), ISO (e.g., ISO 8583), and so on.

[0061] Typically, the delegated biometric authentication system 100 enables user 102 to interact with one or more resource providers 108 using a public device 104. These interactions may include transactions. For example, resource provider 108 may include a broadcaster with broadcasting rights to sporting events (e.g., boxing matches), and public device 104 may include a smart TV. User 102 can use public device 104 to purchase sporting events on a pay-per-view basis, thereby allowing user 102 to watch sporting events on public device 104. As another example, resource provider 108 may include a library that lends books to user 102. Public device 104 may be a terminal that allows user 102 to register to borrow books from resource provider 108 during an interaction. As a third example of interaction, resource provider 108 may include a building security group that controls access to secure buildings, such as apartment buildings. User 102 can use public device 104 (e.g., a secure terminal) to gain access to the apartment building.

[0062] Furthermore, in order to perform these interactions using public device 104, public device 104 can authenticate user 102 using biometrics, that is, verify user 102's identity using one or more biometric features corresponding to user 102 (e.g., iris scan, retinal scan, facial scan, fingerprint, etc.). This provides additional security for user 102 by making it more difficult for malicious users or fraudsters to impersonate user 102. Additionally, biometric authentication can provide improved convenience for user 102, as they may be able to interact without devices typically associated with those interactions, such as making transactions without a credit card or borrowing library books without a library card.

[0063] Delegated biometric authentication can involve using a fuzzy repository scheme to create a data warehouse. A data warehouse can refer to information or data locked using other information or data. For example, an interaction token (tokenized data used for interaction) locked using a biometric template. To access data locked in the data warehouse (e.g., the interaction token), the data warehouse must first be unlocked, for example, using a biometric template corresponding to the biometric template used to form the data warehouse.

[0064] A data repository containing an interaction token corresponding to user 102 and locked using a biometric signature of user 102 can be provided to public device 104 by communication device 106. To perform an interaction with resource provider 108 using the interaction token, the data repository is first unlocked using a biometric template corresponding to user 102. Therefore, unlocking the data repository is a form of biometric authentication, as the data repository cannot be unlocked without a valid biometric template associated with user 102. Furthermore, without a biometric template, it is impossible to determine the interaction token (or master key) locked in the data repository or the biometric template used to lock the interaction token. Therefore, this sensitive information is secure even if stored on public device 104, which is beyond the control of user 102.

[0065] Public device 104 may include the Internet of Things (IoT) or other smart devices capable of communicating with other devices via a network such as the Internet. Public device 104 may also communicate with devices using other means. For example, public device 104 may communicate with communication device 106 via Bluetooth or NFC. Public device 104 may be present in public or shared spaces such as hotel rooms, libraries, restaurants, banks, and grocery stores. Examples of public devices include smart TVs, self-checkout terminals, terminals for library registration and borrowing, ATMs, video game consoles, laptops, tablets, desktop computers, etc. Public device 104 can be used by various users during its operation. For example, a first user can use a smart TV in a hotel room, and then subsequent users can use the smart TV after the first user checks out of the room. Public device 104 may store a data repository corresponding to various users. Furthermore, public device 104 may include one or more biometric interfaces for collecting biometric instances from users. Biometric instances may be formed into biometric templates, which can be used to unlock the corresponding data repository. (See reference below.) Figure 8 The public facility 104 is described in more detail.

[0066] User 102 may own and / or operate communication device 106. Communication device 106 may be a personal device associated with user 102. For example, communication device 106 may be a smartphone, laptop, tablet, desktop, etc. owned by user 102. Communication device 106 may include a processor, memory, and code or instructions for performing various functions, including collecting biometric instances, forming biometric templates from biometric instances, generating a data warehouse, and delegating biometric authentication to public device 104. User 102 may use communication device 106 to perform additional functions, such as making and receiving calls, sending text messages, browsing the Internet, streaming video, etc. See below for reference. Figure 9 The communication device 106 is described in more detail.

[0067] Resource provider 108 may include one or more resource providers that offer resources to users as part of the interaction. For example, these resource providers may include businesses, governments, and non-profit organizations. Examples of resource providers include merchants that provide goods or services to customers, libraries that lend books to borrowers, building managers that allow access to buildings, and broadcasting companies that allow access to broadcast content.

[0068] Resource provider 108 may communicate with or be part of interactive network 110. Interactive network 110 may include entities linked or connected together to facilitate interaction. For example, a payment processing network may be an interactive network used to process payment interactions. See below for reference. Figure 6 and 7 A more detailed description of the interaction network and examples of the interaction are provided. In some embodiments, the interaction network 110 may additionally include... Figure 1 One or more computers or entities shown include resource provider 108, authentication server computer 112, token server computer 114, etc.

[0069] The authentication server computer 112 may include a server computer capable of verifying user 102 and communication device 106. It may also verify biometric delegation. The authentication server computer 112 may store or otherwise manage a list or registry of users or communication devices registered in the biometric authentication system. User 102 may have registered communication device 106 in the biometric authentication system at some point in the past. In some embodiments, registration with the authentication server computer 112 may be a prerequisite for performing delegated biometric authentication using system 100. The authentication server computer 112 may use the user list or registry to verify that user 102 is legitimate (e.g., not impersonated by a fraudster). The authentication server computer 112 may communicate with the token server computer 114 to provide interaction tokens (or other access data) to communication device 106. These interaction tokens (or other access data) may then be locked in a data repository by communication device 106.

[0070] Token server computer 114 may include a server computer associated with the tokenization service. Token server computer 114 can generate, manage, and distribute interaction tokens that can be used to interact with resource provider 108. Interaction tokens may include, for example, numeric or alphanumeric sequences, such as “4000 1234 5678 9000”. Interaction tokens may be subject to any number of limitations assigned and / or executed by token server computer 114. For example, token server computer 114 may generate tokens with limited use, which are valid for a limited number of interactions (e.g., three interactions). Additionally, token server computer 114 may generate tokens with limited time, which are valid only within a specific time period (e.g., within one week of generation). Furthermore, token server computer 114 may generate tokens with limited amount, which are valid only if the amount does not exceed a certain threshold (e.g., for a transaction, a limited amount of tokens may correspond to an amount, such as $100.00. A limited amount of tokens may be valid if less than $100.00 is spent in one or more transactions). In some embodiments, the interaction token generated by the token server computer 114 can substitute for other credentials, such as payment credentials, like a PAN. The token server computer 114 can maintain a security database that associates interaction tokens with the credentials they substitute.

[0071] In other embodiments, the token server computer 114 may be a computer that provides access data, which may provide other types of access data including the master secret key.

[0072] Figure 2 A sequence diagram of a delegated biometric authentication method according to some embodiments is shown. Typically, the method involves a communication device 204 using a fuzzy repository technique with a second biometric template of a user to generate a data repository to be sent to a public device 206. Later, when a user 202 wishes to perform an interaction (e.g., a transaction) using the public device 206, the user 202 can use their first biometric template on the public device 206 to unlock the data repository. Note that references to "first," "second," "third," etc., in this application do not imply any particular order or priority, but can specify different instances of the same type of item.

[0073] In step S214, user 202 may provide a biometric instance to communication device 204. For example, user 202 may use a camera on communication device 204 to collect facial scans, iris scans, or retinal scans. Alternatively, user 202 may use a microphone on communication device 204 to capture voice recordings, or use a touchscreen on communication device 204 to capture handwriting samples. Communication device 204 may generate a biometric instance, then generate a biometric template, and subsequently securely store the biometric template on a secure storage element.

[0074] In step S216, the public device 206 may receive a delegation request message from the communication device 204. The delegation request message may indicate that the user 202 wishes to delegate biometric authentication to the public device 206. The delegation request message may be generated by the communication device 204 by any suitable means. For example, the communication device 204 may store and execute an application (e.g., a smartphone application) that enables the user 202 to initiate the generation and transmission of the delegation request message. The delegation request message may include data or information, such as a communication device identifier or user identifier that enables the public device 206 to uniquely identify the communication device 204 or the user associated with the delegation request message. The communication device 204 may transmit the delegation request message to the public device 206 via any suitable means, such as via a network, for example, a local area network or the Internet. In some embodiments, the user 202 may connect the communication device 204 to the public device 206 via near-field communication, i.e., by bringing the communication device 204 close to a near-field communication element on the public device 206. Alternatively, communication device 204 may be connected to public device 206 via Bluetooth, Zigbee, Wi-Fi or any other suitable network or communication means.

[0075] In step S218, the public device 206 may send a verification request message to the authentication server computer 208. The verification request message may indicate to the authentication server computer 208 that the communication device 204 is attempting to delegate biometric authentication to the public device 206. The verification request message may further indicate that the public device 206 wants to verify the communication device 204 and the delegation request. The verification request message may include a communication device identifier and / or a user identifier used to identify the communication device 204.

[0076] The authentication server computer 208 can maintain a registry of users or communication devices (including user 202 and communication device 204) registered or registered in the biometric authentication program. User 202 may have previously registered communication device 204 in this program. The authentication server computer 208 can use a communication device identifier, a user identifier, or other appropriate identifier contained in the authentication request message to verify that communication device 204 is registered or registered.

[0077] In step S220, communication device 204 may receive a delegation confirmation message from the authentication server computer. The delegation confirmation message may instruct the authentication server computer 208 to confirm that biometric authentication should be delegated to public device 206, either to communication device 204 or user 202. The delegation confirmation message may be routed or sent to communication device 204 using a communication device identifier, such as a cellular phone number. The delegation confirmation message may be sent in any suitable form, such as as a text message, email, or push notification received via an application (e.g., a smartphone application) stored on communication device 204. The delegation confirmation message may be displayed on communication device 204 so that user 202 can read and respond to it. The delegation confirmation message may include information such as the name or identifier of public device 206, and prompts, such as text prompts. For example, the delegation confirmation message may include a message such as "Do you want to delegate biometric authentication to the hotel smart TV?" and user interface elements such as a confirm button or a reject button.

[0078] In step S222, user 202 may provide a response to the delegation confirmation message to communication device 204. For example, user 202 may choose a button that instructs user 202 to confirm that biometric authentication should be delegated to public device 206, or choose a different button that instructs biometric authentication not to be delegated to public device 206. As part of providing a response to the delegation confirmation message, user 202 may provide additional forms of authentication or verification, such as a password, native biometric authentication, or a response to a security question (e.g., “What is your mother’s maiden name?”).

[0079] In step S224, the communication device 204 may send a delegation confirmation response to the authentication server computer 208. The delegation confirmation response may indicate to the user 202 whether to confirm the biometric authentication delegation.

[0080] In step S226, the authentication server computer 208 may send a request for an interaction token to the token server computer 210. The communication device 204 may use the interaction token to perform an interaction. For example, the communication device 204 may use the interaction token to execute a transaction with a resource provider (e.g., a merchant). The interaction token may be used as a substitute for another payment credential. For example, the interaction token may be used as a substitute for a payment credential such as a PAN (e.g., a credit card number). If the interaction token is used as a substitute for a payment credential, the interaction token may be associated with its substitute credential in some way. For example, the token server computer 210 may maintain a database or other suitable data structure that associates interaction tokens with their corresponding payment credentials.

[0081] Interaction tokens may be subject to any number of limitations. For example, an interaction token can be a limited-use token, which can only be used for a limited number of interactions (e.g., three interactions). For instance, if an interaction token is used to register for book borrowing at a library, it can only be used to register a limited number of books for borrowing. As another example, if an interaction token is used as a payment token, it can only be used to perform a limited number of purchases.

[0082] Interaction tokens can also be limited to a time period, meaning they can only be used to perform interactions within that time period. Similarly, interaction tokens can be limited to an amount, such as a monetary sum, for example, $100.00. If an interaction token is used to execute a transaction, it can be used until the total cost of transactions executed using the interaction token reaches the stated amount.

[0083] Upon receiving a request for an interaction token, token server computer 210 can generate an interaction token and associate it with user 202 or communication device 204, for example, by associating the interaction token with a user identifier, communication device identifier, or a user account managed by authentication server computer 208 or token server computer 210. The interaction token may include any suitable data that can be used to perform or facilitate the interaction. The interaction token may conform to any suitable standard, including the ISO 8583 financial transaction message format. If the interaction token is a substitute for another credential, such as a payment credential, such as a PAN, the interaction token may take a form similar to its substitute credential. For example, a PAN (e.g., a credit card number) is typically in the form of a 16-bit numeric sequence. An interaction token acting as a substitute for a PAN may also take the form of a 16-bit numeric sequence. The interaction token can be derived from the credential that the interaction token substitutes for (e.g., by hashing the PAN), or it can be derived using any other suitable means, such as a random or pseudo-random number generator.

[0084] In step S228, the communication device 204 can receive an interaction token from the authentication server computer 208 or the token server computer 210. The communication device 204 can securely store the interaction token, for example, using a mobile wallet application or a secure storage element.

[0085] In step S230, communication device 204 can generate a data warehouse using a fuzzy warehouse method / technique by locking an interaction token using a biometric template corresponding to user 202. In other embodiments, communication device 204 can generate a data warehouse using a fuzzy warehouse method / technique by locking a master secret key generated to encrypt the interaction token. The biometric template can be based on biometric instances or samples collected from user 202 in step S214. The data warehouse can be transmitted to public device 206 and used by user 202 to perform biometric authentication and interactions (e.g., transactions) using public device 206.

[0086] refer to Figure 4 To better understand step S230, the diagram illustrates a hybrid graph corresponding to the creation or locking of the data warehouse. Typically, a data warehouse (e.g., data warehouse 416) comprises a set of unsorted points. Each point may include two values, in... Figure 4 The points are labeled "x" and "y". Some points are "random points" or "hash points". These points may include two random values. Other points correspond to data and functions of said data. In an embodiment, these other points may be referred to as "biometric points" and may correspond to biometric template 406 (e.g., a biometric template corresponding to a user of a communication device) and function P(x) 404. Function P(x) 404 may be derived from an interaction token, for example, from interaction token 402. Therefore, the data warehouse may include a set of unsorted points, comprising multiple random points and multiple biometric points corresponding to the biometric template and interaction token.

[0087] Because data warehouse 416 includes random points, it is impossible to distinguish points corresponding to biometric templates by observation alone. Therefore, biometric templates cannot be extracted from the data warehouse. Similarly, because the data warehouse includes random points, it is impossible to uniquely determine function P(x) 404 and interaction token 402 by observation alone.

[0088] The method for generating a data warehouse using a fuzzy warehouse scheme according to some embodiments is as follows. First, the communication device can generate an encoding function P(x) 404 corresponding to the interaction token 402. In other embodiments, the interaction token can also be a master secret key that can be used to decrypt encrypted interaction tokens. Figure 4 In this representation, the interaction token is shown as a 16-bit sequence of numbers. Several different techniques can be used to generate the encoding function P(x) 404. One technique involves generating a polynomial function of X using numbers corresponding to the interaction token 402. Figure 4An exemplary application of this technique is illustrated. The encoding function P(x) 404 can be generated by using each block of four consecutive interactive token 402 numbers as polynomial coefficients. A polynomial function may be convenient because efficient techniques exist for generating and interpolating polynomials, which can be used for locking and unlocking the repository, respectively. However, embodiments can be implemented using a function P(x) 404 other than a polynomial function.

[0089] The communication device can then generate multiple biometric points by using biometric template 406 as input to encoding function P(x) 404. Biometric template 406 may include a sequence or array of data values ​​corresponding to biometric features. Each data value can be represented numerically and can be applied as input to encoding function P(x) 404. The result is multiple P(x) or "y" values. These values ​​can be paired with their respective biometric template 406 ("x") values ​​to generate multiple biometric points. Similarly, the communication device can generate multiple random points, for example, using a random or pseudo-random number generator.

[0090] Figure 408 shows a graphical representation of the data warehouse. Point 410 is an example of a random point that does not correspond to the encoding function P(x) 404 or the biometric template 406. Point 412 is an example of a biometric point that corresponds to the biometric template 406 and lies on line 414, which corresponds to the encoding function P(x) 404.

[0091] Data warehouse 416 is represented as a two-dimensional array, including multiple biometric points and multiple random points. Data warehouse 416 may be unsorted or obfuscated, therefore it is impossible to determine which points are random points and which points are biometric points based on the order of the points in data warehouse 416.

[0092] Back Figure 2 In step S232, the communication device 204 can send the data warehouse to the public device 206. The data warehouse can be sent via any suitable means, such as Bluetooth, Wi-Fi, Zigbee, LAN, Internet, etc.

[0093] At the end of step S232, biometric authentication has been successfully delegated to the public device 206. At this point, user 202 can use the public device 206 to perform biometric authentication and interaction. Steps S234-S242 correspond to the biometric authentication and interaction process according to some embodiments.

[0094] In step S234, the public device 206 may receive a request from the user 202 to interact with the resource provider 212. This request may include a request to execute a transaction with the merchant resource provider 212. For example, the public device 206 may be a smart TV in a hotel room, and the resource provider 212 may be a pay-per-view broadcaster. The request to perform the interaction may include a request to purchase pay-per-view content (e.g., a boxing match) from the resource provider 212.

[0095] In step S236, the public device 206 can collect a first biometric instance corresponding to user 202. This biometric instance can be transformed into another biometric instance, and then that biometric instance can be transformed into a first biometric template. The first biometric template may include data based on fingerprint scanning, facial scanning, iris scanning, retinal scanning, DNA samples, handwritten signatures and / or voice recordings, or any other biometric data. The public device 206 can collect the first biometric instance using any suitable biometric interface. For example, the public device 206 can use a camera attached to the public device 206 to capture an iris scan of the user. The public device 206 can store the first biometric template in temporary memory.

[0096] In step S238, the public device 206 can unlock the data warehouse using a first biometric template, wherein the data warehouse includes an interaction token or master secret key locked using a second biometric template corresponding to user 202. That is, the data warehouse may include an interaction token locked using the biometric template collected in step S214, provided to the communication device 204 in step S228. If both the first and second biometric templates correspond to user 202, the public device should be able to successfully unlock the data warehouse. In doing so, the public device 206 authenticates user 202 biometrically. By unlocking the data warehouse, the public device 206 accesses the interaction token, which can then be used to perform the requested interaction with resource provider 214. After unlocking the data warehouse, the public device 206 may store the interaction token in a temporary storage device.

[0097] refer to Figure 5 To better understand step S238, this diagram illustrates a hybrid diagram of methods for unlocking a data warehouse according to some embodiments.

[0098] The public device can connect the data warehouse 502 with the captured biometric template 504 (i.e., Figure 2 The "first biometric template" referenced in step S236 is compared so that a subset of the plurality of biometric points 506 corresponding to the first biometric template can be determined by the public device.

[0099] A subset of multiple biometric points 506 includes points that share common values ​​between the determined biometric template 504 and the data warehouse 502. For various reasons, the biometric template 504 determined by the public device (also referred to as the "first biometric template") and the biometric template determined by the communication device for locking the data warehouse (also referred to as the "second biometric template") are not expected to be identical, even if they originate from the same user. For example, if the biometric template corresponds to a facial scan, the lighting conditions may differ during the collection of biometric instances corresponding to the first and second biometric templates. As another example, if the biometric template corresponds to a voice recording, the background noise (e.g., caused by traffic or other background noise) may be greater during the capture of one biometric instance associated with a biometric template and softer during the capture of another biometric instance associated with a different biometric template.

[0100] Therefore, a perfect match of biometric templates is not expected; that is, biometric points corresponding to every biometric value may not exist in the captured biometric template 504. However, it is expected that at least some (i.e., subsets) of the biometric points will correspond to the captured biometric template 504. These subsets of biometric points 506 may include points from the fuzzy repository 502 that share values ​​(e.g., "x" values) with the biometric template 504.

[0101] Figure 508 shows a graphical representation of a subset of biometric points 506. Point 510 is an example of a point belonging to this subset. Line 512 corresponds to the encoding function P(x) 514. Because the subset of biometric points 506 includes biometric points, the subset of biometric points 506 lies on line 512 corresponding to the encoding function P(x) 514.

[0102] Then, the public device can determine the encoding function P(x) 514 based on a subset of multiple biometric points. Various techniques can be used to determine the encoding function P(x) 514. For example, if the encoding function P(x) 514 is a polynomial function (such as... Figure 5 As shown), polynomial interpolation can be used, for example, by using a Lagrange polynomial, to determine the function.

[0103] Typically, it is necessary k A unique point to define k -1 degree polynomial. Due to this property, as long as a subset of multiple biometric points 506 includes at least k With a single point, the encoding function P(x) 514 can be accurately reconstructed. For example, for a four-term polynomial encoding function P(x) 514 (such as... Figure 5As shown, a subset of multiple biometric points 506 must include at least five points. For example, for a sixteen-term polynomial coding function P(x) 514, a subset of multiple biometric points 506 must include at least 17 points. This characteristic allows the data warehouse to be unlocked even under imperfect biometric matching conditions.

[0104] The public device can then determine the interaction token 516 based on the encoding function P(x) 514. The public device can utilize or revoke the process used to generate the encoding function P(x) 514 to determine the interaction token 516. For example, if the communication device uses the interaction token 516 to generate polynomial coefficients, the public device can use the polynomial coefficients to generate the interaction token 516. Figure 5 This shows the case where the polynomial coefficients of the encoding function P(x) 514 (i.e., 4000, 1234, 5678, and 9000) correspond to the numbers of the interactive token 516.

[0105] Return to Figure 2 In step S240, the public device 206 may send an interaction token to the resource provider 212 to initiate the interaction requested by the user in step S234. The interaction token may be sent to the resource provider 212 via any suitable means, such as using a network like the Internet. The interaction token may be sent in encrypted or unencrypted form.

[0106] In step S242, the public device 206 can perform an interaction with the resource provider 212. Depending on the nature of the public device 206 and the resource provider 212, the interaction can take many forms. For example, if the public device 206 is a smart TV, the interaction could include the user 202 purchasing pay-per-view content from the resource provider 212 (i.e., the broadcaster associated with the sports league). Alternatively, if the public device 206 is a security system for controlling access to a building (resource) managed by a building manager (resource provider 212), the interaction could include the resource provider 212 automatically unlocking an electronically controlled door after receiving an interaction token in step S240. See below for reference. Figure 6 and 7 Two examples of the interaction are described in more detail.

[0107] After sending the interaction token to the resource provider in step S240, the public device 206 can delete the first biometric template and interaction token from the temporary storage device to protect the privacy of user 202 and prevent the first biometric template and interaction token from being obtained by hackers, fraudsters, or malicious users of the public device 206. This cleanup step can be performed by the authentication server computer described earlier.

[0108] Delegated biometric authentication systems can support additional features that can provide users with greater convenience and security. These additional features may include delegation revocation features, including user-initiated revocation and other forms of revocation. These additional features may also include repeated biometric authentication delegation. Figure 3A and 3B The flowcharts show the methods for revoking and repeatedly assigning biometric authentication, respectively.

[0109] Figure 3A Flow 302, corresponding to a biometric authentication revocation method according to some embodiments, is shown. For example, a user, an authentication server computer, a token server computer, or another entity (e.g., an issuer) can revoke the ability of a public device to perform biometric authentication. This can be useful when a user no longer wishes to use the public device to perform interactions. For example, a user may have stayed at a hotel with a smart TV in their room. During their stay, the user may have used the smart TV to purchase pay-per-view content, such as broadcasts of boxing matches. However, when the user checks out of the hotel, they may no longer need to use the smart TV to purchase content and may wish to revoke the data repository.

[0110] In step S306, the communication device may generate a revocation message. The revocation message may indicate that the user wishes to revoke the data repository stored on the public device. The revocation message may include a user identifier or a communication device identifier used to identify the data repository associated with the user or the communication device.

[0111] In step S308, the communication device may send the revocation message to a public device, for example, via Bluetooth, Wi-Fi, Zigbee, NFC, LAN, the Internet, etc.

[0112] In step S310, the public device can receive the revocation message from the communication device. In other embodiments, the revocation message can be received from the authentication server computer.

[0113] In step S312, in response to receiving the revocation message, the public device can delete the data repository from memory. Alternatively, the public device or communication device can send a request to the authentication server computer or token server computer to request the expiration of the interaction token.

[0114] Alternatively, the revocation message may not be generated by the user, but by another entity, such as an authentication server computer, a token server computer, or the issuer. For example, if the interaction token is a time-limited or limited-use token and expires, the token server computer may send a revocation message to a public device to revoke the data repository corresponding to the interaction token. Alternatively, if a user unsubscribes from a biometric authentication service, the authentication server computer may send a revocation message to a public device. As another example, if an issuer (e.g., an issuer managing payment accounts for users) suspects misuse of the interaction token (e.g., fraudulent spending using the interaction token), the issuer may send a revocation message to a public device.

[0115] The revocation process may additionally involve the user verifying their identity in some way to determine that it is a user, not a malicious entity, attempting to revoke the data repository. The user can verify their identity by providing a biometric template to a public device (e.g., by performing an iris scan using a camera on the public device). The public device can then use the biometric template to open the data repository to verify the user's identity and subsequently delete the data repository as part of the revocation process.

[0116] Figure 3B A process 304 for performing recurring biometric delegation is illustrated according to some embodiments. This is convenient for users who regularly interact with public devices. For example, if a user goes to a grocery store every few weeks to buy groceries, or registers to borrow books from a library every few weeks. Using recurring biometric delegation, users can take advantage of the security benefits of using limited interaction tokens (e.g., tokens with limited time) while still maintaining the convenience associated with delegated biometrics. For example, using recurring biometric delegation, a user's communication device could generate a new data warehouse weekly and send it to a public device, replacing the previous week's data warehouse.

[0117] In step S314, the communication device can generate a subsequent data warehouse. The subsequent data warehouse may include data generated using a second biometric template (i.e., a template used to generate...). Figure 2 The biometric template of the original data warehouse in step S230 or the subsequent interaction token corresponding to the user's subsequent biometric template lock.

[0118] In step S316, the public device can receive the subsequent data repository from the communication device. The public device can receive the subsequent data repository via any suitable communication means, such as Bluetooth or NFC as described above.

[0119] In step S318, the public device can replace the data warehouse with a subsequent data warehouse. This may include, for example, deleting the data warehouse from memory and storing the subsequent data warehouse in memory.

[0120] You can refer to this. Figure 6-7 The following description will help you better understand interaction and interaction networks. Figure 6 An example of a transaction processing system used to perform transaction interactions is shown. Figure 7 An example of a building access network used to perform access interactions (i.e., granting a user building access rights) is shown.

[0121] Figure 6 This diagram illustrates a transaction processing system that can be used to execute interactions between users and resource providers. (Source: [Original Source Name]) Figure 1 The interactive network 110 may include Figure 6 One or more computers or entities that are part of a transaction processing system. Figure 6 A user 602 is shown who can operate the public device 604. User 602 can use the public device 604 to perform transaction interactions with the resource provider. The resource provider can operate the resource provider computer 608. Access network 606 (e.g., a network such as the Internet) can be used to enable communication between the public device 604 and the resource provider computer 608. The resource provider computer 608 can communicate with the issuer computer 614 via the acquiring computer 610 and the payment processing network 612.

[0122] Payment processing network 612 may include a data processing subsystem, a network, and operations for supporting and transmitting authorization services, exception handling services, and clearing and settlement services. An exemplary payment processing network 612 may include VisaNet. TM For example, VisaNet TM VisaNet's payment processing network can handle credit card transactions, debit card transactions, and other types of commercial transactions. TM This includes, in particular, the VIP system (Visa Integrated Payment System) for processing authorization requests and the Base II system for performing clearing and settlement services. The payment processing network can use any suitable wired or wireless network, including the Internet.

[0123] A typical payment transaction flow involving public device 604 can be described as follows. User 602 has a first biometric template captured by public device 604 (e.g., public device 604 scans user 602's face using a camera). As described above, public device 604 uses the first biometric template to unlock the data repository corresponding to user 602. In doing so, public device 604 accesses an interaction token (e.g., a payment token) that can be used to authorize interaction between user 602 and the resource provider. The interaction token can be securely sent from public device 604 (e.g., in encrypted form) to resource provider computer 608. Resource provider computer 608 can then generate an authorization request message including the interaction token and additional transaction information (e.g., the amount or cost associated with the transaction, merchant identifier or category code, timestamp, etc.) and send this information electronically to acquiring computer 610. Acquiring computer 610 can then receive, process, and forward the authorization request message via payment processing network 612 to issuing computer 614 for authorization. Issuing computer 614 can reply with an authorization response message. An authorization response message can be sent from the issuer computer 614 to the resource provider computer 608 via the payment processing network 612 and the acquirer computer 608. The authorization response message can then be forwarded to the public device 604 via the resource provider 608 and the access network 606. Upon receiving the authorization response message, the resource provider associated with the resource provider computer 608 can provide goods or services to the user 602 via the public device 604. For example, the resource provider computer 608 can send a digital video file to the public device 604, and the user 602 can then view the digital video file.

[0124] At the end of the day or at some other suitable time interval, the clearing and settlement process between the acquiring computer 610, the payment processing network 612, and the issuing computer 614 can be executed.

[0125] Figure 7 A block diagram of a building access system that can be implemented using some embodiments is shown. Figure 7 A public device 702 operated by user 704 is shown. The public device 702 can communicate with a resource provider computer 708 via access network 706. The resource provider computer 708 can be used to control access to building 710; for example, the resource provider computer 708 can engage or disengage electronic locks to lock or unlock doors of building 710.

[0126] For example, building 710 could be an apartment building located on a busy street. To ensure resident safety, biometric authentication might be required to enter building 710. User 704 could be a resident of building 710 and could approach public device 702 for biometric authentication. Public device 702 could collect a first biometric template from user 704 and use it to unlock a data repository locked with a second biometric template corresponding to the user and containing an interaction token. Public device 702 could send the interaction token to resource provider computer 708 via access network 706. Resource provider computer 708 could verify the interaction token and unlock the door of building 710, thereby allowing user 704 to enter.

[0127] Figure 8 An exemplary communication device 800 according to some embodiments is illustrated. The communication device 800 may include a circuitry for enabling certain device functions, such as wireless communication or telephone. Functional elements responsible for implementing those functions may include a processor 802, which executes instructions to implement the functions and operations of the device. The processor 802 may access a data storage device 810 (or another suitable memory area or element) to retrieve instructions or data for executing those instructions. A data input / output element 806, such as a keyboard or touchscreen, may be used to enable a user to operate the communication device 800 (e.g., allowing a user to navigate to a mobile wallet application 814). The data input / output 806 may also be configured to output data (e.g., via a speaker). A display 804 may also be used to output data to a user. A communication element 808 may be used to enable data transmission between the communication device 800 and a wired or wireless network (e.g., via an antenna 824), enabling data transmission functionality, and may be used to assist in connecting to the Internet or another network. The communication device 800 may also include a contactless element interface 820 to enable data transmission between a contactless element 822 and other elements of the device. The contactless element 820 may include secure storage and near-field communication data transmission elements (or another form of short-range communication technology). As noted, according to embodiments, cellular phones, smartphones, wearable devices, laptops, or other similar devices are examples of communication devices.

[0128] The data storage device 810 may include a computer-readable medium, which may include a number of software modules, such as a communication module 812, a mobile wallet application 814, a delegation application 816, and a fuzz extractor application 818.

[0129] Communication module 812 may include code that enables processor 802 to implement or enable communication between communication device 800 and other devices, such as other mobile devices or access terminals. Communication module 812 may allow communication according to any suitable protocol, such as TCP, UDP, IS-IS, OSPF, IGRP, EIGRP, RIP, BGP, etc. Communication module 812 may enable secure communication by enabling processor 802 to establish secure or encrypted communication channels between communication device 800 and other devices. For example, communication module 812 may include code executable by processor 802 for performing key exchange (e.g., Diffie-Hellman key exchange) between communication device 800 and another device, such as a public device. Communication module 812 may allow data warehouses to be sent to other devices, such as public devices.

[0130] The mobile wallet application 814 may include code enabling the communication device 800 to manage tokens, including interaction tokens and other payment credentials. For example, the mobile wallet application 814 may include code enabling the processor 802 to retrieve an access token stored in secure memory 822 via a contactless component interface 820. The mobile wallet application 814 may also include code enabling the communication device 800 to display any suitable token information, such as providing the time and date of the interaction token, an alias or identifier corresponding to the interaction token, the time and date of the most recent interaction or transaction involving the interaction token, etc. Furthermore, the mobile wallet application 814 may include code enabling the processor 802 to display a graphical user interface (GUI) that allows the user to activate token-related functionality.

[0131] The delegation application 816 may include code that enables the communication device 800 to perform any and all methods involved in the delegation of biometric authentication processes. (Refer to the above description and...) Figure 2-4 These methods can be better understood. The delegation application 816 may have already been used during the registration process, for example, from... Figure 1 The authentication server computer 112 is configured for the communication device 800.

[0132] The delegation application 816 may include the ability to capture biometric instances via data input / output 806. A user may use communication device 800 to capture an initial biometric template (e.g., a facial scan), which is used to lock an interaction token in a data warehouse using a fuzzy warehousing method, as referenced above. Figure 2 As described. The delegation application 816 can be used to capture biometric templates and store the templates in encrypted or unencrypted form on secure storage 822.

[0133] The fuzz extractor application 818 may include code that enables the communication device 800 to perform any functions associated with generating a data warehouse. These functions may include generating an encoding function based on an interactive token, generating biometric points by using a biometric template as input to the encoding function, generating random points or hash points, and packaging or grouping biometric points and random points into a data warehouse, as referenced above. Figure 4 As described, the fuzz extractor application 818 can utilize any suitable mathematical library to perform these functions, such as libraries associated with random or pseudo-random number generation, encoding function generation, and function analysis.

[0134] Figure 9 An exemplary common device 900 according to some embodiments is shown. The common device 900 may include a processor 902, a communication interface 904, a biometric interface 906, and a computer-readable medium 908. The computer-readable medium 908 may include multiple software modules, including a communication module 910, a biometric module 912, a fuzz extractor module 914, a temporary storage device 916, an interaction module 918, and an undo module 920.

[0135] Processor 902 can be any suitable processing device or apparatus as described above. Communication interface 904 may include a network interface that enables common device 900 to communicate with other computers or systems via a network such as the Internet. Communication interface 904 may include additional interfaces on the interface that enables common device 900 to communicate with other computers or systems. For example, communication interface 904 may include a near-field communication interface, etc.

[0136] Biometric interface 906 may include hardware for capturing instances of a user's biometrics. For example, biometric interface 906 may include an iris scanner comprising a low-energy infrared light emitter and an infrared light detector. The retinal scanner can shine infrared light onto the user's eye and then record the reflected infrared light picked up by the detector. The recorded light can be compiled into a biometric template, which can be stored on a computer-readable medium 908, such as in temporary storage device 916. Biometric interface 906 may be supported by biometric software module 912, which may include code executable by processor 902 for controlling the operation of biometric interface 906. For example, biometric module 912 may include signal processing algorithms or optical processing algorithms for converting captured biometrics into biometric templates.

[0137] The communication module 910 may include code that enables the processor 902 to generate messages, reformat messages, and / or otherwise communicate with other entities or computers. This may include communicating with a communication device, receiving data from a communication device, and sending interaction tokens to or otherwise communicating with a resource provider computer. The communication module 910 enables public devices to communicate over a network according to any suitable communication protocol, such as TCP or UDP.

[0138] The fuzz extractor module 914 may include code or instructions executable by the processor 902 for storing and unlocking the data warehouse, as referenced above. Figure 2 and 5 As described. These codes or instructions may include, for example, using captured biometrics to determine a subset of biometric points corresponding to a data warehouse, an interpolation encoding function, and determining an interaction token based on the encoding function. The fuzz extractor module 914 can be used to store and manage data warehouses corresponding to various users (i.e., more than one user). The fuzz extractor module 914 may additionally store the data warehouse or associate the data warehouse with user identifiers or communication device identifiers.

[0139] Temporary storage device 916 may include code or instructions executable by processor 902 for temporarily storing digital materials. These may include interaction tokens and biometrics collected via biometric interface 906. These temporary materials may be stored by public device 900 when needed and subsequently deleted.

[0140] The interaction module 918 may include code or instructions executable by the processor 902 for interacting with a resource provider, such as those referenced above. Figure 6-7 As described above. These instructions may include instructions for generating interactive messages, including interactive tokens, and sending these interactive messages to the resource provider. The instructions may also include instructions for receiving and interpreting authorization response messages received by the resource provider.

[0141] The undo module 920 may include code or instructions executable by the processor 902 for undoing the data warehouse, as referenced above. Figure 3A and Figure 3B As described. These instructions may include instructions for receiving, interpreting, and verifying revocation messages, as well as for deleting data warehouses from computer-readable media 908.

[0142] Figure 10 A flowchart illustrating an exemplary method performed by an authentication server computer according to some embodiments is shown.

[0143] In step S1002, the authentication server computer can receive a verification request message from the public device. This verification request message includes an identifier of the communication device associated with the user. The verification request message may indicate that the public device wishes to verify whether the user is registered in the biometric authentication system and is a legitimate user of the system, as referenced above. Figure 2 As described. The authentication server computer can use the identifier of the communication device to route messages to the communication device.

[0144] In step S1004, the authentication server computer can send a delegation confirmation message to the communication device. The authentication server computer can use the identifier of the communication device to send the delegation confirmation message. The delegation confirmation message can request the user or communication device to confirm that the biometric authentication delegation is a legitimate delegation request, as referenced above. Figure 2 As described.

[0145] In step S1006, the authentication server computer can receive a delegation confirmation response from the communication device. The delegation confirmation response can indicate whether the biometric delegation is legitimate or fraudulent. The delegation confirmation response may include a positive confirmation, indicating that the user is actually attempting to delegate biometric authentication to a public device, as referenced above. Figure 2 As described.

[0146] In step S1008, the authentication server computer may send a request for an interaction token to the token server computer, as referenced above. Figure 2 The steps described in step S226.

[0147] In step S1010, the authentication server computer may receive an interaction token from the token server computer in response to a request for an interaction token, as referenced above. Figure 2 The steps described in step S228.

[0148] In step S1012, the authentication server computer can send an interaction token to the communication device, wherein the communication device uses a biometric template associated with the user to lock the interaction token in the data warehouse, as referenced above. Figure 4 and Figure 2 As described in S230.

[0149] The advantage of embodiments of the present invention is that a biometric template is created and used during authentication, and then discarded. The biometric template created during authentication is not bound to a specific identity, but is only used to check if it can unlock the vault. Therefore, the public device never knows the user's exact identity (preserving privacy). Another advantage is that the registration template is not sent from the user's private communication device to the public device during registration or authentication. This results in enhanced security.

[0150] Any computer system mentioned herein may use any suitable number of subsystems. In some embodiments, the computer system includes a single computer device, wherein the subsystem may be a component of the computer device. In other embodiments, the computer system may include multiple computer devices, each of which is a subsystem having internal components.

[0151] A computer system may include multiple components or subsystems connected together, for example, by external interfaces or internal interfaces. In some embodiments, the computer system, subsystem, or device may communicate via a network. In such cases, one computer may be considered a client, and another computer may be considered a server, where each computer may be part of the same computer system. The client and server may each include multiple systems, subsystems, or components.

[0152] It should be understood that any embodiment of the present invention can be implemented using hardware (e.g., application-specific integrated circuits or field-programmable gate arrays) and / or computer software in the form of control logic, wherein the general-purpose programmable processor is modular or integrated. As used herein, the processor includes a single-core processor, a multi-core processor on the same integrated chip, or multiple processing units on a single circuit board or networked thereon. Based on this disclosure and the teachings provided herein, those skilled in the art will know and understand other ways and / or methods of implementing embodiments of the present invention using hardware and combinations of hardware and software.

[0153] Any software component or function described in this application may be implemented as software code executed by a processor using any suitable computer language such as Java, C, C++, C#, Objective-C, Swift, or a scripting language such as Perl or Python, employing techniques such as conventional or object-oriented methods. This software code may be stored as a series of instructions or commands on a computer-readable medium for storage and / or transmission. Suitable media include random access memory (RAM), read-only memory (ROM), magnetic media (e.g., hard disk drives or floppy disks), or optical media (e.g., optical discs (CDs) or digital versatile optical discs (DVDs)), flash memory, and so on. The computer-readable medium may be any combination of such storage or transmission devices.

[0154] Such programs can also be encoded and transmitted using carrier signals suitable for transmission over wired, optical, and / or wireless networks conforming to various protocols, including the Internet. Therefore, a computer-readable medium according to an embodiment of the invention can be created using data signals encoded with such a program. Computer-readable media encoded with program code can be packaged with a compatible device or provided separately from other devices (e.g., downloaded via the Internet). Any such computer-readable medium can reside on or within a single computer product (e.g., a hard disk drive, CD, or an entire computer system) and can exist on or within different computer products within a system or network. A computer system may include a monitor, printer, or other suitable display for providing any results mentioned herein to a user.

[0155] Any method described herein can be performed, wholly or partially, by a computer system including one or more processors configured to perform these steps. Therefore, embodiments may relate to computer systems configured to perform steps of any method described herein, and may have different components performing corresponding steps or groups of corresponding steps. Although steps are presented with numbered labels, method steps herein may also be performed simultaneously or in different orders. Furthermore, portions of these steps may be used in conjunction with portions of other steps from other methods. Similarly, all or part of a step may be optional. Additionally, any step of any method may be performed using modules, circuitry, or other means for performing these steps.

[0156] Specific details of particular embodiments may be combined in any suitable manner without departing from the spirit and scope of the embodiments of the invention. However, other embodiments of the invention may relate to specific embodiments associated with each individual aspect, or specific combinations of these individual aspects. The foregoing description of exemplary embodiments of the invention has been presented for purposes of illustration and description. It is not intended to be exhaustive, or to limit the invention to the precise forms described; many modifications and variations are possible in accordance with the teachings above. These embodiments were chosen and described in order to best explain the principles of the invention and its practical application, thereby enabling those skilled in the art to best utilize the invention in various embodiments and to make various modifications suitable for the particular intended use.

[0157] The above description is illustrative and not restrictive. Many variations of the invention will become apparent to those skilled in the art after reading this disclosure. Therefore, the scope of the invention should not be determined by reference to the foregoing description, but rather by reference to the pending claims together with their full scope or equivalents.

[0158] Without departing from the scope of the invention, one or more features of any embodiment may be combined with one or more features of any other embodiment.

[0159] Unless explicitly indicated otherwise, the use of “one” or “the” is intended to mean “one or more”. Unless explicitly indicated otherwise, the use of “or” is intended to indicate “inclusive or” rather than “exclusive or”.

[0160] All patents, patent applications, publications, and descriptions mentioned herein are incorporated herein by reference in their entirety for all purposes. They are not acknowledged as prior art.

Claims

1. A method for performing an interaction, the method comprising: A public device that can be used by multiple users receives a delegation request message from a communication device designated for use by a single user, the delegation request message indicating that the single user wishes to delegate biometric authentication to the public device; The public device sends a verification request message to the authentication server computer. The individual user has registered the communication device with the authentication server computer using a communication device identifier. The verification request message indicates that the communication device is attempting to delegate biometric authentication to the public device. After the authentication server computer verifies the registration of the individual user with the communication device, the public device receives a data warehouse containing access data associated with the individual user from the communication device. The data warehouse has been locked by the communication device using a registration biometric template corresponding to the individual user. The public device receives a request from the individual user to perform an interaction with the resource provider; The public device collects the authentication biometric template corresponding to the individual user from the individual user; The data warehouse is unlocked by the public device using the authenticated biometric template; The access data is sent by the public device to the resource provider, thereby authorizing the interaction between the individual user and the resource provider; as well as The interaction with the resource provider is performed by the public device.

2. The method according to claim 1, further comprising: The public device receives a subsequent data warehouse from the communication device, the subsequent data warehouse including subsequent access data locked using the registered biometric template or a subsequent biometric template corresponding to the individual user; and The public device replaces the data warehouse with the subsequent data warehouse.

3. The method of claim 1, wherein the access data includes an interaction token or a master secret key, wherein the data warehouse includes a plurality of random points and a plurality of biometric points, the plurality of biometric points corresponding to the registered biometric template and the encoding function, wherein the encoding function is derived from the access data, and wherein unlocking the data warehouse includes: The public device determines a subset of the plurality of biometric points that corresponds to the authentication biometric template; The encoding function is determined by the public device based on the subset of the plurality of biometric points; as well as The access data is determined by the public device based on the encoding function.

4. The method according to claim 3, wherein: The encoding function includes a polynomial, which includes one or more polynomial coefficients derived from the accessed data; Determining the encoding function by the public device based on the subset of the plurality of biometric points includes: interpolating the polynomial by the public device based on the subset of the plurality of biometric points; and Determining the access data by the public device based on the encoding function includes: determining the access data by the public device based on the one or more polynomial coefficients.

5. The method according to claim 1, wherein the data warehouse is formed using a fuzzy warehouse scheme, and wherein the method further comprises: The authentication biometric template is stored in the public device; The access data is stored by the public device; as well as After the access data is sent to the resource provider by the public device, the public device deletes the authentication biometric template and the access data.

6. The method according to claim 1, wherein the method further comprises: The data warehouse is stored by the public device; The cancellation message is received by the public device; as well as In response to receiving the revocation message, the public device deletes the data warehouse.

7. The method of claim 1, wherein the authentication biometric template and the registration biometric template comprise data based on one or more of the following: fingerprint scan, facial scan, iris scan, retinal scan, DNA sample, handwritten signature, and / or voice recording.

8. A public facility, comprising: processor; as well as A non-transient computer-readable medium coupled to the processor, the non-transient computer-readable medium comprising code executable by the processor to implement the method according to any one of claims 1-7.

9. A method for performing an interaction, the method comprising: A registration biometric template is generated by a communication device designated for use by a single user based on biometric data collected for that single user; The communication device sends a delegation request message to the public device, the delegation request message indicating that the individual user wishes to delegate biometric authentication to the public device; The communication device receives a delegation confirmation message from an authentication server computer that has been registered by the individual user using the communication device identifier. The delegation confirmation message requests confirmation as to whether biometric authentication should be delegated to the public device. The communication device sends a delegation confirmation response to the authentication server computer; The communication device receives access data associated with the individual user from the authentication server computer or token server computer. The communication device generates a data warehouse by locking the access data using the registered biometric template corresponding to the individual user; as well as The communication device sends the data warehouse to a public device, enabling the public device to unlock the data warehouse using an authentication biometric template corresponding to the individual user, which has been collected by the public device from the individual user.

10. The method of claim 9, further comprising: A revocation message is generated by the communication device associated with the individual user; as well as The revocation message is sent by the communication device to the public device, whereby the public device subsequently deletes the data warehouse.

11. The method of claim 9, wherein the data warehouse comprises a plurality of biometric points and a plurality of random points, and wherein generating the data warehouse by the communication device using the access data locked by the registered biometric template corresponding to the individual user comprises: The communication device generates an encoding function corresponding to the accessed data; The communication device generates the plurality of biometric points by applying the registered biometric template as input to the encoding function; as well as The communication device generates the plurality of random points.

Citation Information

Patent Citations

  • Limited use tokens granting permission for biometric identity verification

    US20140136419A1