Identity authentication method and system
Through the digital identity proof mechanism, the processor is used to receive and process user interaction requests and compare identity information, which solves the problem of difficult identity authentication in online network space, and achieves high confidence services and transactions.
Patent Information
- Application Number
- CN202380074076.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-11-04
- Filing Date
- 2023-10-05
- Publication Date
- 2025-05-30
AI Technical Summary
The existing technology is difficult to effectively solve the frequent fraud and fraud cases in online cyberspace, making it difficult for service providers and institutions to ensure the authenticity of customer identity before providing services and executing transactions.
By providing a digital identity proof mechanism, the processor receives user interaction requests, displays multiple options for proof of identity, receives user selection, access and compares corresponding information, thereby determining whether the identity authentication is passed or not.
The ability to provide services and execute transactions with high confidence levels is achieved, the accuracy and security of identity authentication is improved, and the risks of fraud and fraud are reduced.
Smart Images

Figure CN120077374A_ABST
Abstract
Description
[0001] Cross - Reference to Related Applications
[0002] This application claims priority to U.S. Patent Application No. 17 / 980,775, filed on November 4, 2022, the entire content of which is incorporated herein by reference. Background Art
[0003] 1. Field of the Disclosure
[0004] The present technology generally relates to methods and systems for identity authentication, and more particularly to methods and systems for providing a digital identity verification mechanism for personal identity authentication to facilitate the provision of services and the execution of transactions with a high level of confidence.
[0005] 1. Background Information
[0006] Currently, globally, especially in the online cyber - space, fraud and deception cases occur frequently. This has led to many service providers and institutions that execute transactions with individual customers being concerned about ensuring the identity of each customer before providing services and / or executing transactions.
[0007] Therefore, there is a need for a method and system for providing a digital identity verification mechanism for personal identity authentication to facilitate the provision of services and the execution of transactions with a high level of confidence. Summary of the Invention
[0008] Through one or more of the various aspects, embodiments, and / or specific features or sub - components of the present disclosure, the present disclosure particularly provides various systems, servers, devices, methods, media, programs, and platforms for providing a digital identity verification mechanism for personal identity authentication to facilitate the provision of services and the execution of transactions with a high level of confidence.
[0009] According to one aspect of the present disclosure, a method for authenticating an identity is provided. The method is implemented by at least one processor. The method includes: receiving, by at least one processor, an interaction request from a user; displaying, by at least one processor, a user interface including a plurality of options for proving the identity of the user; receiving, by at least one processor, via the user interface, a user's selection of one of the plurality of options; accessing, by at least one processor, from the user, first information corresponding to the selected option; retrieving, by at least one processor, from a database, second information corresponding to the selected option; comparing, by at least one processor, the accessed first information with the retrieved second information; and determining, by at least one processor, based on the result of the comparison, whether to authenticate the user's identity.
[0010] Accessing the first information may include extracting the first information from a card that stores the first information electronically.
[0011] The method may further include: receiving a password from a user. The card may be configured to control access to the first information based on whether the received password matches a predetermined personal identification number (PIN).
[0012] The first information may include at least one of the user's name, the user's home address, the user's date of birth, the user's email address, the user's phone number, an account associated with the user, and an answer to a predetermined security question associated with the user.
[0013] Access to the database may be controlled by a financial institution that manages the account associated with the user.
[0014] Accessing the first information may include extracting the first information from a smart phone that stores the first information electronically.
[0015] According to another aspect of the present disclosure, a computing device for authenticating an identity is provided. The computing device includes a processor; a memory; and a communication interface coupled to each of the processor and the memory. The processor is configured to: receive an interaction request from a user via the communication interface; display a user interface including a plurality of options for proving the user's identity; receive, via the user interface, a selection by the user of one of the plurality of options; access, from the user, first information corresponding to the selected option; retrieve second information corresponding to the selected option from an external database; compare the accessed first information with the retrieved second information; and determine whether to authenticate the user's identity based on the result of the comparison.
[0016] The processor may also be configured to access the first information by extracting the first information from a card that stores the first information electronically.
[0017] The processor may also be configured to receive a password from the user via the communication interface. The card may be configured to control access to the first information based on whether the received password matches a predetermined personal identification number (PIN).
[0018] The first information may include at least one of the user's name, the user's home address, the user's date of birth, the user's email address, the user's phone number, an account associated with the user, and an answer to a predetermined security question associated with the user.
[0019] Access to the external database may be controlled by a financial institution that manages the account associated with the user.
[0020] The processor may also be configured to access the first information by extracting the first information from a smart phone that stores the first information electronically.
[0021] In accordance with yet another aspect of the present disclosure, a card is provided. The card includes: a processor configured to facilitate communication with a point-of-sale device; and an electronic storage mechanism configured to store first information related to the identity of a user of the card. The processor is further configured to: send an interaction request to the point-of-sale device; receive a request for a subset of the first information from the point-of-sale device; and send the requested subset of the first information to the point-of-sale device.
[0022] The electronic storage mechanism may include a magnetic stripe. The processor may also be configured to facilitate communication with the point-of-sale device when the card is swiped through a reader connected to the point-of-sale device.
[0023] The electronic storage mechanism may include an electronic chip embedded in the card. The processor may also be configured to facilitate communication with the point-of-sale device when a portion of the card including the embedded electronic chip is inserted into a reader connected to the point-of-sale device.
[0024] The processor may also be configured to: receive a password from the user via the point-of-sale device; compare the received password with a personal identification number (PIN) stored in the electronic storage mechanism; and control access to the requested subset of the first information based on the result of the comparison.
[0025] The first information may include at least one of the user's name, the user's home address, the user's date of birth, the user's email address, the user's phone number, an account number associated with the user, and an answer to a predetermined security question associated with the user.
[0026] The point-of-sale device may include at least one of the following: a conventional point-of-sale terminal, a dongle capable of attaching to an electronic device including at least one of a smart phone, a tablet, and a computer terminal, and a biometric identification device configured to identify a user via at least one of fingerprint, thumbprint, palm, iris recognition, and facial recognition. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] In the following detailed description, which refers to the accompanying drawings, the present disclosure is further described by way of non-limiting examples of preferred embodiments of the present disclosure, wherein like reference characters represent like elements in all views of the drawings.
[0028] Figure 1 An exemplary computer system is shown.
[0029] Figure 2 An exemplary illustration of a network environment is shown.
[0030] Figure 3An exemplary system for implementing a method for providing a digital identity authentication mechanism for personal identity authentication to facilitate the provision of services and the execution of transactions with a high level of confidence is shown.
[0031] Figure 4 A flowchart of an exemplary process for implementing a method for providing a digital identity authentication mechanism for personal identity authentication to facilitate the provision of services and the execution of transactions with a high level of confidence. Detailed Description
[0032] According to one or more aspects of the present disclosure, embodiments and / or specific features or sub-components of the present disclosure are intended to bring one or more of the advantages specifically described above and mentioned hereinafter.
[0033] The examples may also be embodied as one or more non-transitory computer-readable media having stored thereon instructions for one or more aspects of the present technology described and illustrated by the examples herein. The instructions in some examples include executable code that, when executed by one or more processors, cause the processors to perform the steps necessary to implement the example methods of the present technology described and illustrated herein.
[0034] Figure 1 An exemplary system for use according to the embodiments described herein. System 100 is generally shown and may include what is generally referred to as computer system 102.
[0035] Computer system 102 may include an instruction set that may be executed to cause computer system 102 to perform, either alone or in combination with other described devices, any one or more of the methods or computer-based functions disclosed herein. Computer system 102 may operate as a stand-alone device or may be connected to other systems or peripheral devices. For example, computer system 102 may include or be included in any one or more computers, servers, systems, communication networks, or cloud environments. Further, the instructions may operate in such cloud-based computing environments.
[0036] In a networked deployment, computer system 102 can operate in the capacity of a server or as a client user computer in a server-client user network environment, as a client user computer in a cloud computing environment, or as a peer computer system in a peer-to-peer (or distributed) network environment. Computer system 102 or portions thereof can be implemented as or incorporated into a variety of devices, such as a personal computer, a tablet computer, a set-top box, a personal digital assistant, a mobile device, a handheld computer, a laptop computer, a desktop computer, a communication device, a wireless smart phone, a personal trust device, a wearable device, a Global Positioning Satellite (GPS) device, a web device, or any other machine capable of (sequentially or otherwise) executing a set of instructions that specify actions to be taken by that machine. Additionally, although a single computer system 102 is shown, additional embodiments can include any collection of systems or subsystems that individually or jointly execute instructions or perform functions. In the present disclosure, the term "system" should be regarded as including any collection of systems or subsystems that individually or jointly execute one or more sets of instructions to perform one or more computer functions.
[0037] As Figure 1 shown, computer system 102 can include at least one processor 104. Processor 104 is tangible and non-transitory. As used herein, the term "non-transitory" is not construed as an eternal property of a state, but rather as a property of a state that will persist for a period of time. The term "non-transitory" specifically excludes transient properties, such as a particular carrier wave or signal or other forms of properties that only exist temporarily at any time and any place. Processor 104 is a manufactured product and / or a machine component. Processor 104 is configured to execute software instructions to perform the functions described in the various embodiments herein. Processor 104 can be a general-purpose processor or can be part of an Application Specific Integrated Circuit (ASIC). Processor 104 can also be a microprocessor, a microcomputer, a processor chip, a controller, a microcontroller, a Digital Signal Processor (DSP), a state machine, or a programmable logic device. Processor 104 can also be a logic circuit including a Programmable Gate Array (PGA) such as a Field Programmable Gate Array (FPGA), or can be another type of circuit including discrete gates and / or transistor logic. Processor 104 can be a Central Processing Unit (CPU), a Graphics Processing Unit (GPU), or both. Additionally, any processor described herein can include multiple processors, parallel processors, or both. Multiple processors can be included in or coupled to a single device or multiple devices.
[0038] The computer system 102 may further include a computer memory 106. The computer memory 106 may include static memory, dynamic memory, or both in communication connection. The memory described herein is a tangible storage medium that can store data and executable instructions and is non-transitory during the time the instructions are stored therein. Again, the term "non-transitory" as used herein should not be construed as an eternal property of a state, but rather as a property of a state that will persist for a period of time. The term "non-transitory" specifically excludes transient properties such as a particular carrier wave or signal or other forms of properties that only exist temporarily at any given time and place. The memory is a manufactured product and / or a machine component. The memory described herein is a computer-readable medium from which a computer can read data and executable instructions. The memory as described herein may be random access memory (RAM), read-only memory (ROM), flash memory, electrically programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, caches, removable disks, magnetic tapes, compact disc read-only memory (CD-ROM), digital versatile disk (DVD), floppy disks, Blu-ray discs, or any other form of storage medium known in the art. The memory may be volatile or non-volatile, secure and / or encrypted, insecure and / or unencrypted. Of course, the computer memory 106 may include any combination of memories or individual storage devices.
[0039] The computer system 102 may further include a display 108, such as a liquid crystal display (LCD), an organic light-emitting diode (OLED), a flat panel display, a solid state display, a cathode ray tube (CRT), a plasma display, or any other type of display, examples of which are well known to those skilled in the art.
[0040] The computer system 102 may also include at least one input device 110, such as a keyboard, a touch-sensitive input screen or tablet, voice input, a mouse, a remote control device with a wireless keyboard, a microphone coupled to a voice recognition engine, a camera (such as a video camera or a still camera), a cursor control device, a global positioning system (GPS) device, an altimeter, a gyroscope, an accelerometer, a proximity sensor, or any combination thereof. Those skilled in the art will appreciate that various embodiments of the computer system 102 may include multiple input devices 110. In addition, those skilled in the art should also understand that the exemplary input devices 110 listed above are not meant to be exhaustive, and the computer system 102 may include any additional or alternative input devices 110.
[0041] The computer system 102 may also include a media reader 112 configured to read any one or more instruction sets, such as software, from any of the memories described herein. When executed by the processor, the instructions can be used to perform one or more of the methods and processes described herein. In a particular embodiment, the instructions may reside, in whole or in part, within the memory 106, the media reader 112, and / or the processor 110 during the execution of the computer system 102.
[0042] In addition, the computer system 102 may include any additional devices, components, parts, peripherals, hardware, software, or any combination thereof that are commonly known and understood to be included in or within a computer system, such as, but not limited to, a network interface 114 and an output device 116. The output device 116 may be, but is not limited to, a speaker, an audio output, a video output, a remote control output, a printer, or any combination thereof.
[0043] Each component of the computer system 102 may be interconnected and communicate via a bus 118 or other communication link. As Figure 1 shown, the components may be interconnected and communicate via an internal bus. However, those skilled in the art should understand that any component may also be connected via an expansion bus. In addition, the bus 118 may enable communication via any commonly known and understood standard or other specification, such as, but not limited to, Peripheral Component Interconnect, Peripheral Component Interconnect Express, Parallel Advanced Technology Attachment, Serial Advanced Technology Attachment, etc.
[0044] The computer system 102 may communicate with one or more additional computer devices 120 via a network 122. The network 122 may be, but is not limited to, a local area network, a wide area network, the Internet, a telephone network, a short-range network, or any other network commonly known and understood in the art. The short-range network may include, for example, Bluetooth, Zigbee, infrared, near field communication, Ultra Wideband, or any combination thereof. Those skilled in the art should understand that additional networks 122 that are known and understood may be additionally or alternatively used, and the exemplary network 122 is not restrictive or exhaustive. Moreover, although the network 122 is shown as a wireless network in Figure 1 this figure, those skilled in the art should understand that the network 122 may also be a wired network.
[0045] The additional computer devices 120 are in Figure 1is shown as a personal computer. However, those skilled in the art should understand that in alternative embodiments of the present application, the computer device 120 can be a laptop computer, a tablet PC, a personal digital assistant, a mobile device, a palm computer, a desktop computer, a communication device, a wireless phone, a personal messaging device, a Web device, a server, or any other device capable of executing a set of instructions specifying actions to be taken by the device in sequence or otherwise. Of course, those skilled in the art should understand that the devices listed above are merely exemplary devices, and the device 120 can be any additional device or apparatus commonly known and understood in the art, as long as it does not depart from the scope of the present application. For example, the computer device 120 can be the same as or similar to the computer system 102. In addition, those skilled in the art will similarly understand that the device can be any combination of devices and apparatuses.
[0046] Of course, those skilled in the art should understand that the components listed above for the computer system 102 are merely exemplary and are not intended to be exhaustive and / or comprehensive. In addition, the examples of the components listed above are also intended to be exemplary and are similarly not intended to be exhaustive and / or comprehensive.
[0047] According to various embodiments of the present disclosure, the methods described herein can be implemented using a hardware computer system that executes software programs. In addition, in an exemplary non-limiting embodiment, the implementation can include distributed processing, component / object distributed processing, and parallel processing. A virtual computer system processing can be constructed to implement one or more of the methods or functions described herein, and the processors described herein can be used to support a virtual processing environment.
[0048] As described herein, various embodiments provide digital identity authentication mechanisms for providing digital identity proofs for personal identity authentication, as well as optimized methods and systems for facilitating the provision of services and the execution of transactions with a high level of confidence.
[0049] Reference Figure 2 , a schematic diagram of an exemplary network environment 200 is shown, in which a method for providing a digital identity authentication mechanism for personal identity authentication to facilitate the provision of services and the execution of transactions with a high level of confidence is implemented. In an exemplary embodiment, the method can be executed on any networked computer platform, such as a personal computer (PC).
[0050] The method for providing a digital identity authentication mechanism for personal identity authentication to facilitate the provision of services and the execution of transactions with a high level of confidence can be implemented by a digital identity authentication (DIA) device 202. The DIA device 202 can be associated with, as described for Figure 1is the same as or similar to the described computer system 102. The DIA device 202 can store one or more applications, and the one or more applications can include executable instructions that, when executed by the DIA device 202, cause the DIA device 202 to perform actions, such as, for example, actions of sending, receiving, or otherwise processing network messages, such as performing other actions described and illustrated below with reference to the accompanying drawings. The one or more applications can be implemented as modules or components of other applications. In addition, the one or more applications can be implemented as operating system extensions, modules, plug-ins, etc.
[0051] Furthermore, the one or more applications can operate in a cloud-based computing environment. The one or more applications can be within or executed as one or more virtual machines or one or more virtual servers that can be managed in a cloud-based computing environment. Moreover, the one or more applications, and even the DIA device 202 itself, can be located in one or more virtual servers running in a cloud-based computing environment rather than being tied to one or more specific physical network computing devices. In addition, the one or more applications can run in one or more virtual machines (VMs) executed on the DIA device 202. Additionally, in one or more embodiments of the present technology, one or more virtual machines running on the DIA device 202 can be managed or supervised by a hypervisor.
[0052] In Figure 2 the network environment 200, the DIA device 202 is coupled to a plurality of server devices 204(1)-204(n) that host a plurality of databases 206(1)-206(n), and is also coupled to a plurality of client devices 208(1)-208(n) via one or more communication networks 210. A communication interface of the DIA device 202 (such as Figure 1 the network interface 114 of the computer system 102) is operably coupled and communicates between the DIA device 202, the server devices 204(1)-204(n), and / or the client devices 208(1)-208(n), and the above devices are all coupled together via one or more communication networks 210, although other types and / or quantities of communication networks or systems with other types and / or quantities of connections and / or configurations to other devices and / or elements can also be used.
[0053] One or more communication networks 210 can be the same as those for Figure 1is the same as or similar to the described network 122, although the IA device 202, the server devices 204(1)-204(n), and / or the client devices 208(1)-208(n) may be coupled together via other topologies. Additionally, the network environment 200 may include other network devices, such as one or more routers and / or switches, which are well known in the art and thus will not be described herein. The present technology provides numerous advantages, including a method, a non-transitory computer-readable medium, and a DIA device that efficiently implement a digital identity authentication mechanism for providing digital identity for personal authentication, in order to facilitate a method for providing services and performing transactions with a high confidence level.
[0054] By way of example only, one or more communication networks 210 may include one or more local area networks (LANs) or one or more wide area networks (WANs), and may use TCP / IP over Ethernet and industry standard protocols, although other types and / or quantities of protocols and / or communication networks may be used. The one or more communication networks 210 in this example may employ any suitable interface mechanisms and network communication technologies, including, for example, telecommunications services in any suitable form (e.g., voice, modem, etc.), the public switched telephone network (PSTN), Ethernet-based packet data networks (PDNs), and combinations thereof, etc.
[0055] The DIA device 202 may be a stand-alone device or integrated with one or more other devices or apparatuses, e.g., integrated with one or more of the server devices 204(1)-204(n). In a particular example, the DIA device 202 may include or be hosted by one of the server devices 204(1)-204(n), and other arrangements are also feasible. Additionally, for example, one or more devices of the DIA device 202 may be in the same or different communication networks, which include one or more public networks, private networks, or cloud networks.
[0056] The multiple server devices 204(1)-204(n) may be the same as or similar to the computer system 102 or computer device 120 as described for Figure 1 including any of the features or combinations of features described therefor. For example, among other features, any one of the server devices 204(1)-204(n) may include one or more processors, a memory, and a communication interface coupled together via a bus or other communication link, although other quantities and / or types of network devices may also be used. In this example, the server devices 204(1)-204(n) may process requests received from the DIA device 202 via one or more communication networks 210, for example, according to protocols based on HTTP and / or JavaScript Object Notation (JSON), although other protocols may also be used.
[0057] The server devices 204(1)-204(n) can be hardware or software, or can represent a system with multiple servers in a pool, which can include an internal or external network. The server devices 204(1)-204(n) host databases 206(1)-206(n), which are configured to store data related to customer-specific personal identification information and customer account data.
[0058] Although the server devices 204(1)-204(n) are shown as a single device, one or more actions of each of the server devices 204(1)-204(n) can be distributed across one or more different network computing devices, which together include one or more of the server devices 204(1)-204(n). Additionally, the server devices 204(1)-204(n) are not limited to a particular configuration. Thus, the server devices 204(1)-204(n) can include multiple network computing devices operating using a master / slave method, whereby one of the network computing devices of the server devices 204(1)-204(n) operates to manage and / or otherwise coordinate the operation of the other network computing devices.
[0059] For example, the server devices 204(1)-204(n) can operate as multiple network computing devices within a cluster architecture, a peer-to-peer architecture, a virtual machine, or a cloud architecture. Thus, the techniques disclosed herein should not be construed as limited to a single environment, and other configurations and architectures are also contemplated.
[0060] The multiple client devices 208(1)-208(n) can also be the same as or similar to the computer system 102 or computer device 120 as described for Figure 1 including any of the features or combinations of features described therefor. For example, in the present example, the client devices 208(1)-208(n) can include any type of computing device capable of interacting with the DIA device 202 via one or more communication networks 210. Thus, the client devices 208(1)-208(n) can be mobile computing devices, desktop computing devices, virtual computing devices, laptop computing devices, tablet computing devices, virtual machines (including cloud-based computers), etc. that host, for example, chat, email, or voice-to-text applications. In an exemplary embodiment, at least one client device 208 is a wireless mobile communication device, i.e., a smart phone.
[0061] Client devices 208(1)-208(n) can run an interface application, such as a standard web browser or a stand-alone client application, which can provide an interface to communicate with the DIA device 202 via one or more communication networks 210 for communicating user requests and information. In addition to other features, client devices 208(1)-208(n) may also include a display device (such as a display screen or a touch screen) and / or an input device (such as a keyboard).
[0062] Although an exemplary network environment 200 having a DIA device 202, server devices 204(1)-204(n), client devices 208(1)-208(n), and one or more communication networks 210 is described and illustrated herein, other types and / or quantities of systems, devices, components, and / or elements in other topologies may be used. It should be understood that, as understood by those skilled in the relevant art, the exemplary systems described herein are for exemplary purposes, as many variations of the specific hardware and software used to implement the examples are feasible.
[0063] For example, one or more devices depicted in network environment 200 (such as DIA device 202, server devices 204(1)-204(n), or client devices 208(1)-208(n)) may be configured to operate as virtual instances on the same physical machine. In other words, one or more of the DIA device 202, server devices 204(1)-204(n), or client devices 208(1)-208(n) may operate on the same physical device rather than communicate as separate devices via one or more communication networks 210. Additionally, there may be more or fewer DIA devices 202, server devices 204(1)-204(n), or client devices 208(1)-208(n) than shown. Figure 2 shown
[0064] Furthermore, for any one of the computing systems or devices in any of the examples, it may be replaced by two or more computing systems or devices. Thus, the principles and advantages of distributed processing (such as redundancy and replication) may also be implemented as needed to improve the robustness and performance of the example devices and systems. The examples may also be implemented on one or more computer systems that are extended over any suitable network using any suitable interface mechanism and business technology, including, for example, telecommunications services in any appropriate form (such as voice and modem), wireless service networks, cellular service networks, packet data networks (PDNs), the Internet, intranets, and combinations thereof, etc.
[0065] The DIA device 202 is in Figure 3is described and shown as including a digital identity authentication module 302, although it may include, for example, other rules, policies, modules, databases, or applications. As will be described below, the digital identity authentication module 302 is configured to implement a digital identity proofing mechanism for providing personal identity authentication, in order to facilitate methods for providing services and performing transactions with a high level of confidence.
[0066] In Figure 3 is shown an exemplary process 300 for implementing a digital identity proofing mechanism for providing personal identity authentication, in order to facilitate a mechanism for providing services and performing transactions with a high level of confidence, by leveraging a Figure 2 network environment. Specifically, a first client device 208(1) and a second client device 208(2) are shown communicating with a DIA device 202. In this regard, the first client device 208(1) and the second client device 208(2) may be “clients” of the DIA device 202 and are described as such herein. However, it should be known and understood that the first client device 208(1) and / or the second client device 208(2) are not necessarily “clients” of the DIA device 202, or any entity described in association herewith. Any additional or alternative relationship may exist between either or both of the first client device 208(1) and the second client device 208(2) and the DIA device 202, or no relationship may exist between them.
[0067] Further, the DIA device 202 is shown as being able to access a customer-specific personal identity profile data repository 206(1) and a customer account database 206(2). The digital identity authentication module 302 may be configured to access these databases to implement a digital identity proofing mechanism for providing personal identity authentication, in order to facilitate methods for providing services and performing transactions with a high level of confidence.
[0068] The first client device 208(1) may be, for example, a smart phone. Of course, the first client device 208(1) may be any additional device described herein. The second client device 208(2) may be, for example, a personal computer (PC). Of course, the second client device 208(2) may also be any additional device described herein.
[0069] This process may be performed via one or more communication networks 210, which may include multiple networks as described above. For example, in an exemplary embodiment, either or both of the first client device 208(1) and the second client device 208(2) may communicate with the DIA device 202 via broadband or cellular communication. Of course, these embodiments are merely exemplary and not restrictive or exhaustive.
[0070] At startup, the digital identity authentication module 302 executes a digital identity proof mechanism for providing personal identity authentication to facilitate the processing of providing services and executing transactions with a high confidence level. Figure 4 The flowchart 400 in
[0071] In Figure 4 processing 400, at step S402, the digital identity authentication module 302 receives an interaction request from a user. In an exemplary embodiment, the interaction request may include a service request or a request to execute a transaction (such as a commercial transaction between a merchant and a customer). In this regard, the digital identity authentication module 302 may communicate with or be installed in a point-of-sale (PoS) machine controlled by a merchant.
[0072] At step S404, the digital identity authentication module 302 displays a user interface including a plurality of options for proving the user's identity. In an exemplary embodiment, the options may include providing various types of personally identifiable information, such as the user's name, the user's home address, the user's date of birth, the user's email address, the user's phone number, an account number associated with the user, an answer to a predefined security question associated with the user, and / or any other specific type of information that can be used to prove the user's identity.
[0073] At step S406, the digital identity authentication module 302 receives the user's selection of one of the plurality of options. Then, at step S408, the digital identity authentication module 302 accesses the information provided by the user corresponding to the selected option. In an exemplary embodiment, the information may be extracted from a card owned by the user, which stores the information electronically on a magnetic stripe or an electronic chip embedded in the card. In such a scenario, the point-of-sale machine may be configured to enable the card to be swiped or inserted through a reader to facilitate the extraction of the information. In an alternative embodiment, the information may be accessed from the user's smart phone. In the latter scenario, the point-of-sale machine may be configured to facilitate communication with the smart phone via a near field communication (NFC) mechanism or any other mechanism suitable for facilitating such communication. In another alternative embodiment, the information may be accessed from the user's wearable device or Internet of Things (IoT) device.
[0074] In an exemplary embodiment, the ability to access information from a user's card can be controlled by a Personal Identification Number (PIN) to ensure that the card is not being used by someone unauthorized to use the card. In this scenario, when the digital identity authentication module 302 receives a user selection in step S406 and before attempting to access the information stored on the card, the user can be prompted to provide a password, and then the digital identity authentication module 302 compares the password entered by the user with the PIN stored on the card. If there is a match, then in step S408, the card allows the digital identity authentication module 302 to extract the personally identifiable information stored on the card.
[0075] In step S410, the digital identity authentication module 302 retrieves information corresponding to the option selected by the user in step S406 from an external database that independently stores the user's personally identifiable information. In an exemplary embodiment, the external database can be controlled by a financial institution (such as a bank) that manages the account associated with the user.
[0076] In step S412, the digital identity authentication module 302 compares the information retrieved in step S410 with the information extracted in step S408, and then determines whether the user's identity is authenticated based on the result of the comparison. If there is no match, then the digital identity authentication module 302 indicates that there is a difference and the user's identity has not been proven. If there is a match, then the digital identity authentication module 302 authenticates the user's identity and enables the requested interaction to continue.
[0077] In an exemplary embodiment, each card is assigned a unique identifier, such as an alphanumeric 64-string, an alphanumeric 128-string, or a similar type of identifier. This identifier is mapped to a payment instrument / device (e.g., a credit card, a debit card, a physical device, etc.), which in turn is mapped to the customer's personally identifiable information (PII) on the backend system. If the same customer has more than one credit card or debit card, then each card has a unique identifier representing the customer, and this unique identifier is embedded in the magnetic stripe of the card. This is generally not perceptible to the customer, and the customer does not need to remember or be aware of this unique identifier. Additionally, when the payment instrument / device is lost, stolen, misplaced, replaced, upgraded, transacted, or otherwise swapped out, a different unique identifier will be assigned for replacement. In this regard, the uniqueness of the identifier is invariant and is intended to be associated with only one payment instrument and not used with any other payment instrument.
[0078] In an exemplary embodiment, when manufacturing a physical card, the unique identifier is embedded in the magnetic stripe.
[0079] Table 1 shows an example of the relationship between the unique identifier, the customer identifier, and the card number:
[0080] Table 1
[0081] Customer ID Card Number Unique Identifier Customer ID 1 Credit Card 1#…1234 228542ce-9aea-4f43-8021-ac540354b9d7 Customer ID 1 Credit Card 2#…2345 c601274c-fdf8-462a-9c48-3c722912b67a Customer ID 1 Debit Card 1#…3456 782f21da-2a81-4f34-bb52-1423154cb56c
[0082] In an exemplary embodiment, a unique identifier is mapped to a PIN and the information accessible when the PIN is provided. Table 2 provides an example where the same unique identifier is associated with two separate PINs, and the associated information accessible depends on which PIN the customer uses:
[0083] Table 2
[0084]
[0085] In an exemplary embodiment, a single PIN can be assigned to all items of PII. In another exemplary embodiment, separate PINs can be assigned to individual items of PII, or separate PINs can be assigned to specific groups of parameters. In this regard, depending on the use case, context, or specific implementation, as needed, the user is provided with the ability to set multiple PINs.
[0086] In an exemplary embodiment, a customer can initiate an interaction by swiping a card at a point-of-sale terminal and entering a PIN. Then, the customer can manually enter PII information, such as a social security number, at the point-of-sale terminal, and the point-of-sale terminal retrieves the unique identifier from the card and sends the PIN, PII, and unique identifier to a backend server to verify whether the unique identifier matches the social security number entered by the user and to check whether the information is accurate. If all the information matches, the backend server returns a boolean response "yes"; if not, the backend server returns a "no" response. In this example, the PII is not shared with the requester; instead, only a boolean (yes / no) type of response is provided. In other scenarios, the backend server can send the actual PII merchant information back to the requester. In this regard, the customer is able to control which PII data elements are going to be shared with merchants and / or partners via a user interface provided by the customer's bank or financial institution or via a third-party provider working with the customer's bank or financial institution. The customer is also able to decide to start, stop, pause, and / or resume sharing any such PII data with merchants and / or partners at any time.
[0087] In an exemplary embodiment, the term "point-of-sale device" generally refers to any type of device designed to interact with a user's card. Specifically, as mentioned herein, the point-of-sale device can include any one or more of the following devices: a conventional point-of-sale terminal, an electronic dongle attachable to an electronic device (such as a smart phone, tablet, or computer), and / or a biometric device designed to identify a user via any one or more of fingerprint, thumbprint, palm, iris recognition, face recognition, and / or any other suitable mechanism for identifying a person via biometric information.
[0088] Accordingly, with the present technology, a digital identity authentication mechanism for providing digital identity for personal identity authentication is provided to facilitate optimized processing of providing services and executing transactions with a high confidence level.
[0089] Although the present invention has been described with reference to several exemplary embodiments, it should be understood that the terms used are descriptive and illustrative and not restrictive. Changes may be made within the scope of the appended claims as presently stated and modified without departing from the scope and spirit of various aspects of the present disclosure. Although the present invention has been described with reference to specific means, materials, and embodiments, the present invention is not intended to be limited to the disclosed details; rather, the present invention extends to all functionally equivalent structures, methods, and uses within the scope of the appended claims.
[0090] For example, although a computer-readable medium may be described as a single medium, the term "computer-readable medium" includes a single medium or multiple media, such as a centralized or distributed database, and / or associated caches and servers that store one or more instruction sets. The term "computer-readable medium" should also include any medium that can store, encode, or carry an instruction set for execution by a processor or cause a computer system to execute any one or more of the embodiments disclosed herein.
[0091] A computer-readable medium may include one or more non-transitory computer-readable media, and / or may include one or more transitory computer-readable media. In a particular non-limiting exemplary embodiment, a computer-readable medium may include solid-state memory, such as a memory card or other encapsulation that stores one or more non-volatile read-only memories. Additionally, a computer-readable medium may be random access memory or other volatile rewritable memory. Further, a computer-readable medium may include magneto-optical or optical media (such as a disk or tape) or other storage devices for capturing carrier signals (such as signals communicated through a transmission medium). Accordingly, the present disclosure is considered to include any computer-readable medium or other equivalent and successor media in which data or instructions may be stored.
[0092] Although the present application describes specific embodiments that may be implemented as computer programs or code segments in a computer-readable medium, it should be understood that dedicated hardware implementations, such as application-specific integrated circuits, programmable logic arrays, and other hardware devices, may be constructed to implement one or more of the embodiments described herein. Applications that may include the various embodiments set forth herein may generally include a variety of electronic and computer systems. Accordingly, the present application may cover software, firmware, and hardware implementations or combinations thereof. Nothing in the present application should be construed as implementing or being implementable only in software rather than hardware.
[0093] Although this specification describes components and functions that can be implemented in particular embodiments with reference to particular standards and protocols, the present disclosure is not limited to such standards and protocols. Such standards are periodically superseded by faster or more efficient equivalents that perform substantially the same functions. Accordingly, alternative standards and protocols that perform the same or similar functions are considered equivalents thereof.
[0094] The illustrations of the embodiments described herein are intended to provide a general understanding of the various embodiments. The illustrations are not intended to be a complete description of all elements and features of the apparatus and systems that utilize the structures or methods described herein. Many other embodiments will be apparent to those of ordinary skill in the art upon reading the present disclosure. Other embodiments can be derived from and utilized in the present disclosure, such that structural and logical substitutions and changes can be made without departing from the scope of the present disclosure. Additionally, the illustrations are merely representative and may not be drawn to scale. Some scales in the illustrations may be exaggerated while others may be minimized. Accordingly, the present disclosure and the drawings are to be regarded as illustrative rather than restrictive.
[0095] In this document, one or more embodiments of the present disclosure may, for convenience only, be referred to individually and / or collectively by the term "invention" without intending to actively limit the scope of this application to any particular invention or inventive concept. Furthermore, although particular embodiments have been shown and described herein, it should be understood that any subsequent arrangement designed to achieve the same or similar purpose may replace the particular embodiments shown. The present disclosure is intended to cover any and all subsequent modifications or variations of the various embodiments. Combinations of the above embodiments and other embodiments not specifically described herein will be apparent to those of ordinary skill in the art upon reading the specification.
[0096] It should be understood that the abstract of the present disclosure submitted here is not used to interpret or limit the scope or meaning of the claims. Additionally, in the foregoing detailed description, for the purpose of simplifying the present disclosure, various features may be grouped together or described in a single embodiment. The present disclosure should not be, and is not intended to be, construed as: the claimed embodiments require more features than those expressly recited in each of the claims. On the contrary, as reflected in the appended claims, the inventive subject matter may be directed to only some of the features of any of the disclosed embodiments, rather than all of the features. Accordingly, the appended claims are incorporated into the detailed description, with each claim independently defining the separately claimed subject matter.
[0097] The subject matter disclosed above is considered illustrative and not restrictive, and the appended claims are intended to cover all such modifications, improvements, and other embodiments that fall within the true spirit and scope of this disclosure. Accordingly, to the maximum extent permitted by law, the scope of this disclosure will be determined by the broadest permissible interpretation of the appended claims and their equivalents, and shall not be limited or restricted by the foregoing detailed description.
Claims
1. A method for authenticating an identity, the method being implemented by at least one processor, the method comprising: receiving, by the at least one processor, an interaction request from a user; displaying, by the at least one processor, a user interface including a plurality of options for proving the identity of the user; receiving, by the at least one processor via the user interface, a selection by the user of one of the plurality of options; accessing, by the at least one processor from the user, first information corresponding to the selected option; retrieving, by the at least one processor from a database, second information corresponding to the selected option; comparing, by the at least one processor, the accessed first information with the retrieved second information; and determining, by the at least one processor based on the result of the comparison, whether to authenticate the identity of the user.
2. The method according to claim 1, wherein, accessing the first information includes extracting the first information from a card that electronically stores the first information.
3. The method according to claim 2, further comprising: receiving a password from the user, wherein the card is configured to control access to the first information based on whether the received password matches a predetermined personal identification number (PIN).
4. The method according to claim 1, wherein, the first information includes at least one of the user's name, the user's home address, the user's date of birth, the user's email address, the user's phone number, an account associated with the user, and an answer to a predetermined security question associated with the user.
5. The method according to claim 1, wherein, access to the database is controlled by a financial institution that manages an account associated with the user.
6. The method according to claim 1, wherein, accessing the first information includes extracting the first information from a smart phone that electronically stores the first information.
7. A computing device for authenticating an identity, the computing device comprising: a processor; a memory; and a communication interface coupled to each of the processor and the memory; wherein the processor is configured to: receive, via the communication interface, an interaction request from a user; display a user interface including a plurality of options for proving the identity of the user; receive, via the user interface, a selection by the user of one of the plurality of options; access from the user first information corresponding to the selected option; retrieve from an external database second information corresponding to the selected option; compare the accessed first information with the retrieved second information; and determine based on the result of the comparison whether to authenticate the identity of the user.
8. The computing device according to claim 7, wherein, the processor is further configured to access the first information by extracting the first information from a card that electronically stores the first information.
9. The computing device according to claim 8, wherein, The processor is further configured to: receive a password from a user via the communication interface, wherein the card is configured to control access to the first information based on whether the received password matches a predetermined personal identification number (PIN).
10. The computing device according to claim 7, wherein, the first information includes at least one of the user's name, the user's home address, the user's date of birth, the user's email address, the user's phone number, an account associated with the user, and an answer to a predetermined security question associated with the user.
11. The computing device according to claim 7, wherein, access to the external database is controlled by a financial institution that manages the account associated with the user.
12. The computing device according to claim 7, wherein, the processor is further configured to access the first information by extracting the first information from a smart phone that stores the first information electronically.
13. A card, comprising: a processor configured to facilitate communication with a point-of-sale device; and an electronic storage mechanism configured to store first information related to the identity of a user of the card; wherein the processor is further configured to: send an interaction request to the point-of-sale device; receive a request for a subset of the first information from the point-of-sale device; and send the requested subset of the first information to the point-of-sale device.
14. The card according to claim 13, wherein, the electronic storage mechanism includes a magnetic stripe, and wherein the processor is further configured to facilitate communication with the point-of-sale device when the card is swiped through a reader connected to the point-of-sale device.
15. The card according to claim 13, wherein, the electronic storage mechanism includes an electronic chip embedded in the card, and wherein the processor is further configured to facilitate communication with the point-of-sale device when a portion of the card including the embedded electronic chip is inserted into a reader connected to the point-of-sale device.
16. The card according to claim 13, wherein, the processor is further configured to: receive a password from the user via the point-of-sale device; compare the received password with a personal identification number (PIN) stored in the electronic storage mechanism; and control access to the requested subset of the first information based on the result of the comparison.
17. The card according to claim 13, wherein, the first information includes at least one of the user's name, the user's home address, the user's date of birth, the user's email address, the user's phone number, an account associated with the user, and an answer to a predetermined security question associated with the user.
18. The card according to claim 13, wherein, The point-of-sale device includes at least one of the following: a conventional point-of-sale terminal, an electronic dog capable of being attached to an electronic device including at least one of a smart phone, a tablet computer, and a computer terminal, and a biometric recognition device configured to recognize a user via at least one of fingerprint, thumbprint, palm, iris recognition, and face recognition.