Method for enrolling biometric data in a data carrier with a biometric sensor
By combining smartphones and other read/write devices with remote computing devices, the problems of hardware cost and unstable connection in the biometric data registration process are solved, realizing secure and simplified biometric data registration, meeting the two-factor binding of the PSD2 criterion, and improving user experience and data security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- G&D ELECTRONIC PAYMENT CO LTD
- Filing Date
- 2024-12-19
- Publication Date
- 2026-07-21
AI Technical Summary
In existing technologies, the registration of biometric data on card-shaped data carriers requires additional hardware, which increases costs and generates electronic waste. At the same time, the instability of contactless connections causes the registration process to be interrupted, making it difficult to meet the two-factor binding requirements of the PSD2 criterion.
By using read/write devices such as smartphones, combined with two-factor authentication and contactless interfaces, biometric data can be securely registered on data carriers, separating the collection, transmission, and storage processes of biometric data. Remote computing devices are used for data processing and encryption to ensure connection stability.
It enables a secure and simplified biometric data registration process without the need for additional hardware, reduces the probability of connection interruption, meets the two-factor binding requirements of the PSD2 criterion, and improves user experience and data security.
Smart Images

Figure CN122439155A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the use of a read / write device, such as a mobile device (e.g., a smartphone), to register a user's biometric data in a data carrier with a biometric sensor. Background Technology
[0002] Today, card-based data carriers are used in many application areas. For example, they can be used for non-cash payments for goods or services, personal identification, or access to internet-based applications. Correspondingly, card-based data carriers exist in the form of chip cards, payment cards (such as credit or debit cards), and identity cards. In particular, payment cards in the form of credit or debit cards are often dual-interface chip cards (DI chip cards), which can communicate with other devices, such as point-of-sale terminals, not only through contact-based communication via the chip element but also through contactless communication via Near Field Communication (NFC). To authorize the payment process using this data carrier, a PIN is typically required.
[0003] However, there are also card-shaped data carriers with integrated biometric sensors (such as fingerprint sensors) used in the process of authorizing the use of the data carrier. Here, a crucial step is registering the fingerprint on the card-shaped data carrier. This should be done securely and must be done with the participation of the end user. However, due to logistical reasons, this process occurs outside of a banking or private environment after the card has been sent to the user. These data carriers are initially delivered to the customer without storing biometric features. Then, the cardholder's biometric features (such as fingerprints) are stored on the data carrier by the cardholder (i.e., the so-called "registration"). Furthermore, based on the EU's PSD2 (Payment Service Directive 2) guidelines, two separate factors are required to ensure that these card credentials are linked to the correct user.
[0004] For registration, specialized hardware (a sleeve) can be shipped along with the data carrier, into which the customer inserts the data carrier. The sleeve then activates the collection of the biometric features to be stored, such as a fingerprint. The customer can then register their fingerprint. However, these sleeves have the disadvantage of increasing the cost of providing the data carrier. These additional costs are added to the already necessary cost of the biometric card. Furthermore, these sleeves generate additional electronic waste.
[0005] Another possibility for initial biometric data collection by the customer is through a corresponding smartphone app. Users can use these apps to collect biometric data via NFC communication with the card-like data carrier and store it on the carrier. For this, the card-like data carrier must be kept close to the smartphone's NFC port. A stable NFC connection must be maintained throughout the registration process to collect biometric data. To allow users to see and follow instructions on the smartphone's display during registration and simultaneously interact with the fingerprint sensor, the card-like data carrier is placed on the back of the smartphone, allowing the user to continuously touch the fingerprint sensor. However, this is generally not the best placement for connection stability or power transfer (the "sweet spot"). Furthermore, smartphones typically have a read power of less than approximately 2A / m. Therefore, especially during command flows with increased power requirements (i.e., when controlling the fingerprint sensor), sudden connection interruptions can occur during interaction. Consequently, it is difficult for users to find the correct / ideal position for optimal power input to the card-like data carrier with the fingerprint sensor. Additionally, maintaining a stable contactless connection between the data carrier and the smartphone for a sufficiently long period is challenging. For example, if the card slides during registration, it may cause a connection interruption, thus interrupting the registration process itself. That is, the user must simultaneously hold the mobile phone, keep the card stably in one spot, and place their finger on the sensor multiple times in parallel and then remove it again. Summary of the Invention
[0006] Correspondingly, the technical problem to be solved by the present invention is to provide a method that enables sufficiently secure and simple fingerprint registration on biometric cards without the need to send additional hardware. Furthermore, in particular, the disclosed method can be performed over a longer period of time without requiring a contactless connection between the data carrier and the read / write device (e.g., a mobile phone / smartphone). Moreover, registration can be linked to user identity using two factors, according to the PSD2 guidelines.
[0007] The aforementioned technical problem is solved by the subject matter of the independent claims. Exemplary embodiments are derived from the dependent claims and the following description.
[0008] According to one aspect, a method is provided for registering biometric data in a data carrier having a biometric sensor using a read / write device. The method includes: providing a data carrier and a read / write device; authenticating an authorized user of the data carrier at the issuer of the data carrier; obtaining the biometric data to be registered on the data carrier at the read / write device; transmitting the obtained biometric data to the data carrier via a contactless interface of the read / write device; and storing and registering the biometric data received from the read / write device in the data carrier.
[0009] Registering biometric data can be understood not only as the initial registration / storage of biometric data in a data carrier, but also as the re-registration of biometric data within the data carrier. The data carrier can then use the biometric data stored and registered within it during a later authentication process, comparing it with biometric features collected by the biometric sensors on the data carrier to authorize the corresponding process (e.g., payment process for payment cards; authentication process for identity documents; etc.). In other words, registering biometric data refers to collecting biometric reference data within a data carrier.
[0010] While this description primarily focuses on card-shaped data carriers with fingerprint sensors, it should be noted that, in principle, any suitable data carrier and any suitable biometric sensor can be used with the described method. Examples of other data carriers include USB dongles with fingerprint sensors or access hardware for specific services. Although there is no issue of power supply via NFC for data carriers with their own power supply, registration using the disclosed method is, in principle, possible for such data carriers. This makes it possible to achieve biometric binding with user identity, particularly for such data carriers with their own power supply, and therefore the method may also be advantageous there. However, the method is preferred for passive data carriers (e.g., card-shaped data carriers without their own power supply) because, as described herein, the greatest advantages are realized in this application scenario.
[0011] The read / write device can be, for example, a smartphone with an NFC (Near Field Communication) interface. However, it should be noted that while this description primarily refers to such mobile phones / smartphones, in principle, any suitable hardware with a contactless interface can be used as the read / write device. Furthermore, it should be noted that contactless communication technologies different from NFC, enabling contactless communication with the read / write device, can also be used.
[0012] In the first step of the method, a data carrier on which biometric data is to be registered, and a read / write device for registration, are provided. For example, the data carrier can be provided to the customer by the issuing bank, such as by the bank sending the customer a card-shaped data carrier (also referred to herein as a "card" or "biometric card") equipped with a biometric sensor (e.g., a fingerprint sensor). The customer can then use, for example, their smartphone as the read / write device.
[0013] Then, in the second step, the customer (or user in general) is authenticated as an authorized user of the data carrier by the issuer of the data carrier. For example, when the issuer is a bank that issues biometric cards to customers, the customer can authenticate themselves as the legitimate holder / user of the biometric card by the bank before allowing the customer to register their fingerprint (or other biometric features). For example, the customer or authorized user can authenticate with the issuer of the data carrier via a software application (e.g., a corresponding application), for example, by logging into the issuer's corresponding account using the user's known access data, or, for example, by (after correspondingly verifying the user's identity) providing the user with a corresponding authorization code by telephone at the issuer (or, for example, by sending it via SMS or an authentication application), which can then be entered into the software application to activate registration. However, all other possible authentication methods are also conceivable. For example, the user can also use the software application used for registering biometric data to read electronic certificates (e.g., electronic ID cards) and use them for authentication in a known manner.
[0014] It is preferable to use two-factor authentication methods known to those skilled in the art to authenticate authorized users, thereby improving security and also meeting any applicable legal requirements (such as EU Payment Services Guideline 2). However, at least from a technical point of view, such two-factor authentication methods are not mandatory.
[0015] Furthermore, to ensure that users collect their biometric data only on their own (trusted) data carriers, users may optionally be required to verify the data carrier in an appropriate manner during authentication. This can be done, for example, by entering or collecting a number or other suitable identifier affixed to or otherwise sent with the data carrier (e.g., by scanning a QR code affixed to the data carrier using a camera), by briefly reading the data carrier using a contactless interface of a reader / writer (e.g., by the user briefly bringing the data carrier close to the NFC interface of their smartphone, allowing the reader / writer to read the relevant data), by verifying using the issuer's product (as an example, the applicant's product "Convego Tap" is mentioned here, where card verification is performed, for example, via NFC to ensure possession of a genuine card, not just a dummy card. This also ensures the integrity of the card data), or by any other suitable method. However, as will be described below, verification of the data carrier can also be performed alternatively before the transmission of the biometric data carrier, since a contactless connection is already established between the data carrier and the reader / writer at this step.
[0016] After the authorized user of the data carrier has been authenticated, and optionally the data carrier has been verified as the correct data carrier, the biometric data to be registered on the data carrier is obtained at the read / write device. This can be done in several ways. For example, the biometric data can be collected by the read / write device itself and optionally evaluated; or the read / write device can collect the biometric data and transmit the collected raw biometric data to a remote computing device (e.g., the issuer's server) for evaluation, and then receive the evaluated biometric data again from the remote computing device; or the biometric data can exist in a manner that has been pre-stored (e.g., by earlier registration) in the remote computing device and can be received from the corresponding data set associated with the customer. These possibilities will be described below with reference to specific embodiments.
[0017] Once biometric data is acquired at the read / write device, it is transferred to a data carrier, where it is stored and registered. For this purpose, the data carrier is kept (relatively briefly) close to the read / write device or its contactless interface (e.g., the NFC transmitter of a smartphone), allowing the biometric data, present in the read / write device in an evaluated form (i.e., with correspondingly evaluated / extracted biometric features), to be transferred to and stored on the data carrier.
[0018] The disclosed method has the advantage that the active data connection between the data carrier and the contactless interface of the read / write device only needs to exist for a relatively short period of time, namely, only during the transmission and storage of biometric data. In particular, active communication between the data carrier and the read / write device is not required during the acquisition and evaluation of the acquired raw biometric data. Furthermore, the user does not need to laboriously attempt to maintain a strong active data connection for an extended period while simultaneously operating the data carrier to acquire biometric data. Therefore, by reducing the required connection time and simplifying operation, the probability of premature connection interruption is reduced, thus lowering the probability of registration interruption. This is particularly achieved by separating the acquisition of biometric data from the transmission and storage of biometric data to the data carrier. This separation is not possible when the biometric sensor of the data carrier itself is used to acquire biometric data, because power must then be supplied to the data carrier throughout the entire process (from the contactless interface of the read / write device).
[0019] Alternatively, it is conceivable that before ordering a biometric data carrier (e.g., a biometric payment card), the user collects their own biometric data (e.g., fingerprints) and transmits it to the issuer, as described. The data carrier can then be delivered directly along with the stored / registered biometric data. In this case, the step of transmitting the biometric data to the data carrier is eliminated. The step of storing and registering the biometric data in the data carrier would then be performed on the manufacturer's side.
[0020] According to one implementation, obtaining biometric data includes receiving biometric data from a remote computing device via a data connection.
[0021] Biometric data may have been collected and processed at an earlier registration stage (e.g., via a read / write device, the corresponding service provider, a branch of the issuer, or any other suitable means) to extract the corresponding biometric features. For example, it is conceivable that the data carrier is a subsequent data carrier (e.g., a replacement for an expired payment card), and that biometric data has already been collected, evaluated, and stored when the initial data carrier is delivered. The corresponding biometric data can then be stored in a data set associated with the authorized user on a remote computing device and retained for use in future data carrier registration processes.
[0022] Generally speaking, when biometric data is mentioned here, it refers to evaluated biometric data that can therefore be used for authentication. In this professional field, such biometric data is also called a biometric "template," that is, a prototype of a biometric feature, which can later be used to compare with scanned biometric data for authentication. When raw biometric data is mentioned again, it refers to collected but unprocessed data.
[0023] The remote computing device could be, for example, the issuer's server or other computing equipment. However, it is also conceivable that the remote computing device be operated by a third-party vendor, such as an authentication service provider. Furthermore, the remote computing device could also store raw biometric data and process it upon retrieval to generate biometric data. Alternatively, it is also conceivable to transmit the raw biometric data directly to a read / write device, which then processes it.
[0024] Furthermore, it is conceivable that the remote computing device neither stores the original biometric data nor the biometric data itself. Instead, it receives and processes the original biometric data as raw data during the registration process on the data carrier—that is, when the user begins registration (in any suitable manner, such as via a read / write device) to obtain the evaluated biometric data. This data is then directly transmitted to the read / write device and subsequently deleted. This method enables the fulfillment of more stringent data protection requirements, and will be described below with reference to the implementation method.
[0025] According to another embodiment, obtaining biometric data includes: acquiring raw biometric data using a sensor of a read / write device.
[0026] When the biometric data is fingerprint data, the raw biometric data can be captured, for example, using the camera of a reader / writer device, such as a smartphone camera, by recording an image of the user's finger. Since cameras with the appropriate resolution exist, this type of fingerprint data capture is possible. Furthermore, the recorded camera data can be simply transmitted. However, in principle, this fingerprint data can also be captured as raw biometric data using the fingerprint sensor of the reader / writer device itself, provided the reader / writer device is configured accordingly. However, modern smartphones often do not allow the transmission of data recorded using a corresponding biometric sensor (e.g., a fingerprint sensor) because all biometric data capture and use are managed through a dedicated security element in the smartphone. Nevertheless, it is conceivable to use the biometric sensor of the reader / writer device to capture raw biometric data by appropriate configuration.
[0027] It is also conceivable that in the future, miniature cameras or other biometric sensors could be incorporated into data carriers, such as biometric cards, to enable processes utilizing the data carrier, for example, through facial comparison. Correspondingly, biometric data does not necessarily have to be fingerprint data, but could also be, for example, images of the face, images of the eyes, or other user-associated biometric data. This disclosure covers all such biometric data.
[0028] According to another embodiment, the sensor of the read / write device is a camera.
[0029] For the reasons explained above, a camera is preferred because it makes it particularly easy to use, for example, a smartphone, as a read / write device.
[0030] According to another embodiment, the sensor of the read / write device is a fingerprint sensor of the read / write device.
[0031] As explained, this can also be conceived by configuring the read / write devices accordingly.
[0032] According to another implementation, collecting raw biometric data includes: performing liveness detection on the user.
[0033] For example, when the sensor of the read / write device is a camera used to generate images for fingerprint extraction, this liveness detection can include recording images of the finger at different angles or specific movement patterns that must be imitated during recording. For this purpose, video can also be recorded, in which finger bending movements or other movements can be identified, since movement in three-dimensional space always has specific patterns. In this way, for example, it is possible to effectively detect spoofing attempts by a user to keep a pre-recorded image in the camera, because such an image is inherently two-dimensional and differs from the recording of the corresponding three-dimensional object (or finger) when recorded at different angles.
[0034] Furthermore, it is conceivable that a user's pulse could be identified, for example, by dynamically tracking image recordings and filtering them accordingly. This method could also, for example, identify attempts to deceive users based on physical force.
[0035] In addition, it is conceivable to additionally use infrared sensors or other suitable sensors (such as temperature sensors) to measure the temperature of the fingers (or, when biometric data is based on facial recognition, to measure the temperature of the face as well), thereby also identifying spoofing attempts.
[0036] When a physical biometric sensor (such as a fingerprint sensor) of a read / write device is used to collect raw biometric data, conductivity measurement, temperature measurement, etc., can also be used directly with the physical biometric sensor for liveness detection.
[0037] To detect spoofing attempts, generally speaking, alternatively, machine learning algorithms or other algorithms utilizing trained neural networks can be used, independent of the method of liveness detection. In general, separating the acquisition and processing of biometric data from the registration and storage of biometric data in a data carrier allows more computing power to be devoted to such algorithms (but also, for example, to the processing of the raw biometric data itself), because the corresponding computational operations do not need to be performed using the limited resources of the data carrier (e.g., a card), but can be performed, for example, on a high-performance server or other computing device, such as on the read / write device itself or on the described remote computing device.
[0038] According to another embodiment, obtaining biometric data further includes: processing the collected raw biometric data, wherein the processed raw biometric data corresponds to the biometric data used as a data carrier.
[0039] Processing biometric data includes preprocessing raw biometric data into a corresponding template so that the template can later be used in authentication processes utilizing biometric sensors on data carriers (e.g., during authorized payment processes when the data carrier is a biometric payment card). As explained above, raw biometric data includes unprocessed biometric data, which is usable biometric data. As will be further described below, processing may in particular include extracting corresponding features for the template.
[0040] Processing of raw biometric data can also include filtering, edge enhancement, and other methods to identify and extract relevant features.
[0041] According to another embodiment, the processing of the raw biometric data is performed by a read / write device.
[0042] According to another embodiment, processing of raw biometric data includes: transmitting the raw biometric data to a remote computing device, and processing the raw biometric data by the remote computing device to obtain biometric data. The remote computing device transmits the biometric data to a read / write device.
[0043] Raw biometric data is processed by remote computing devices to generate biometric data, offering the advantage of greater computing power. These remote computing devices can be, for example, servers or computing centers belonging to the issuer or a third party. Furthermore, processing on remote computing devices eliminates software tampering at the read / write end, further enhancing security against spoofing or fraud.
[0044] According to another embodiment, data transmission between the remote computing device and the read / write device is performed in an encrypted manner.
[0045] This encryption can be performed individually for the user and / or card, either locally (on the read / write device) or on the server side (on the remote computing device). Here, encryption can be applied not only to both directions of communication (i.e., data transmission from the raw biometric data to the remote computing device and data transmission from the remote computing device to the read / write device), but also only to the transmission of processed biometric data from the remote computing device to the read / write device.
[0046] Encryption can be performed in a symmetric or asymmetric manner. In the case of symmetric encryption, it is preferable to perform encryption on the server side so that the symmetric key does not need to be stored on the read / write device.
[0047] According to another embodiment, the processing of raw biometric data includes: extracting relevant biometric features from the raw biometric data to uniquely identify a user, and generating biometric data using the relevant biometric features, such that the biometric data can be used by a data carrier to identify a user.
[0048] For example, for fingerprints, extracting biometric features to uniquely identify a user from the collected raw biometric data can include extracting representative features of the fingerprint, such as corresponding bifurcations, nodes, loops, whorls, etc., which are known in principle from fingerprint analysis. For example, such features can be extracted from recorded fingerprint image data. For facial biometric features, the extracted features can include, for example, facial features based on geometric arrangement and texture characteristics. Then, the extracted features are recorded in a "template," which corresponds to biometric data that can later be used for comparison by the biometric sensors on the data carrier. However, this enumeration is merely exemplary.
[0049] As described above, the corresponding feature extraction can be performed, for example, using machine learning algorithms that utilize trained neural networks or in any other suitable manner.
[0050] According to another implementation, the user is authenticated at the data carrier issuer via a software application on the read / write device.
[0051] Such software applications may include, for example, an application (App) for smartphones provided by the issuer of the data carrier, which can be installed, for example, from an app store. Preferably, the entire method (except for the steps of providing the data carrier and the read / write device) is performed by a single software application configured to perform the corresponding steps and to guide the user when registering biometric data. Taking a biometric payment card issued by a bank as an example, such a software application may be integrated into the bank's online banking application (Online-Banking-App), meaning that the corresponding functionality can be integrated into the online banking application.
[0052] According to another embodiment, transmitting the obtained biometric data to a data carrier via a contactless interface of the read / write device includes: verifying the read / write device relative to the data carrier beforehand.
[0053] This verification of the read / write device relative to the data carrier ensures that the read / write device is authorized to transmit biometric data to the data carrier for registration. For example, the software application used on the read / write device to perform registration or transmit data to the data carrier can be verified relative to the data carrier in an appropriate manner, such that the data carrier, for example, only accepts biometric data transmitted from a software application provided by the data carrier's issuer. For this purpose, suitable digital certificates or other appropriate means can be used, for example.
[0054] According to another implementation, the read / write device is the user's mobile device.
[0055] For example, the read / write device could be a smartphone with a camera and an NFC interface.
[0056] According to another implementation, biometric data includes the user's fingerprint data.
[0057] In summary, the disclosed method provides a possibility for registering biometric data in a corresponding data carrier (particularly a card-shaped biometric data carrier using a biometric sensor) without requiring additional hardware to be delivered with the data carrier. This eliminates the associated additional costs. Furthermore, by performing two-factor authentication on the user, such as in banking applications, the registration can be guaranteed to be bound to the user's identity in accordance with PSD2. However, while a user can still register the fingerprints of others (e.g., family members), this cannot be completely ruled out by any method. In such cases, it constitutes a significant breach by the user and can be addressed through the bank's terms of service.
[0058] Compared to known NFC-based application methods, this approach offers significant improvements in user operability. The steps of fingerprint recording are separated from card registration. Therefore, users no longer need to simultaneously operate the mobile phone (or generally, the reader / writer), the card, and the fingerprint sensor. Furthermore, only a brief holding of the card near the NFC interface (or other contactless interface) is required to transfer biometric data (i.e., the corresponding template) to the data carrier. Thus, prolonged contact that could lead to interruptions is eliminated. In particular, photographing a finger is much simpler than multiple registrations on a biometric sensor on the data carrier. Moreover, known optical methods for liveness detection can be applied, unaffected by the limited resources (storage space, computing power) of fingerprint sensors on card-like data carriers. If local data protection regulations permit, fingerprints could even be compared to previously registered fingers on the server side, for example, to more closely link them to the user's identity. It is even conceivable that using templates pre-stored on the server (and encrypted for each user) could significantly simplify the registration of cards or subsequent cards for a single user. Attached Figure Description
[0059] Figure 1 An architecture for performing a method for registering biometric data in a data carrier is shown.
[0060] Figure 2 It shows, for example, that can be utilized in Figure 1 The flowchart shown illustrates a method for registering biometric data in a data carrier, executed by the system architecture. Detailed Implementation
[0061] The illustrations in the accompanying drawings are schematic and not drawn to scale. If the same reference numerals are used in different drawings in the following description, those reference numerals denote the same or similar elements. However, the same or similar elements may also be denoteed by different reference numerals.
[0062] Figure 1 A highly schematic illustration shows a method 100 for performing the registration of biometric data in a data carrier 10 (e.g., referring to...). Figure 2 The architecture of method 100 described herein. Here, registering biometric data should be understood as storing biometric reference data for the first time (or again) in data carrier 10, which is later used by data carrier 10 for comparison during the authentication process utilizing data carrier 10.
[0063] In the illustrated embodiment, the reader / writer 20 of the user's mobile device 20, in the form of a smartphone 20, has at least one sensor 21, particularly a camera 21 (but may also include, for example, a fingerprint sensor), configured to record image data. Furthermore, the reader / writer 20 has a contactless interface 22 (preferably an NFC interface 22) capable of establishing contactless connections with other devices, particularly with the data carrier 10 (e.g., a card-like data carrier 10, such as a dual-interface chip card used as a payment card, proof of identity, or similar function). For this purpose, the data carrier 10 also has a contactless interface 12. The data carrier 10 has an integrated biometric sensor 11, for example, for authorizing a user to use the data carrier 10 (in the case of a payment card, for example, for authorizing a payment process). The biometric sensor 11 can be, for example, a fingerprint sensor 11. For the biometric sensor 11 to be used in the authorization process of the data carrier, the corresponding biometric data of the authorized user must first be collected and stored in the data carrier 10. This process is typically referred to as "registration." Although registration can theoretically be carried out before the data carrier 10 is delivered to the authorized user, it is usually done by the user himself after the data carrier 10 is delivered to / delivered to the user.
[0064] The read / write device 20 is configured to establish a communication connection with the remote computing device 30. This communication connection can be established, for example, via a wide area network (WAN), such as the Internet, a local area network (LAN), or any other suitable data connection 31. The remote computing device 30 can be, for example, the server of the issuer of the data carrier 10, or it can be the server of a third party, such as the corresponding service provider.
[0065] Below, refer to the diagram shown. Figure 2 (Continue to refer to) Figure 1 (Use flowcharts to illustrate usage) Figure 1 A method 100 for registering biometric data in a data carrier 10 using a read / write device 20 and a remote computing device 30.
[0066] The method 100 will now be illustrated with an example application scenario in which a bank provides a customer with a card-shaped data carrier 10 in the form of a payment card having a fingerprint sensor 11 as a biometric sensor 11, and the customer registers their fingerprint in the data carrier 10. However, it should be understood that this is merely one example of the use of method 100, and other data carriers 10 can be used in other applications, and other biometric sensors 11 can also be used to perform the method, since in principle any biometric sensor requires stored reference data.
[0067] Method 100 begins, for example, by sending a card-shaped data carrier 10 from a bank to a user (e.g., a bank customer) and by providing a read / write device 20, here in the form of a smartphone 20, to the user.
[0068] Then, in the second step, method 100 continues by authenticating the user 120 as an authorized user of the data carrier 10 at the issuer (i.e., the bank in this case). This can be done, for example, by having the customer install a corresponding software application on the read / write device 20. For example, an existing online banking application can be used for this purpose, which allows the customer to log in to the corresponding account at the bank.
[0069] After the customer authenticates at the issuer, the method continues by obtaining 130 units of biometric data to be registered on the data carrier at the read / write device. Here, obtaining the 130 units of biometric data can be performed through three alternative methods, which correspond to... Figure 2 The three branches are shown in the image.
[0070] Biometric data may have been collected during an earlier registration process and exists / stored as a corresponding template on remote computing device 30, thus requiring only further transmission to read / write device 20 via data connection 31. Figure 2 (The left branch). Then, obtaining 130 biometric data includes receiving 131 data from the remote computing device 30. Alternatively, it is conceivable that the biometric data (e.g., a corresponding protected data set for a software application) is already stored in the read / write device 20 itself. In this case, obtaining 130 biometric data includes retrieving data from the corresponding memory of the read / write device 20.
[0071] However, when biometric data is not yet available (whether in the read / write device or in the remote computing device 30), Figure 2When the middle and right branches of the biometric data are to be updated using the latest data, obtaining the biometric data 130 may first include acquiring the raw biometric data 132 using the sensor 21 of the read / write device 20, preferably the camera 21 of the read / write device 20 (however, other sensors 21 of the read / write device 20 may also be used, as described above). For this purpose, for fingerprints, for example, a corresponding image of the user's finger 40 is preferably acquired using the camera 21. When the biometric feature is not a fingerprint, other corresponding images (e.g., eyes, etc.) may be acquired instead of the image of the finger 40. In principle, method 100 can be used with any type of biometric data, as long as the read / write device 20 and the corresponding data carrier 10 contain the corresponding sensors. The use of fingerprint data is merely exemplary. Optionally, during the acquisition of the raw biometric data 132, a liveness detection as described above may be performed to ensure that no tampering has been performed.
[0072] After acquiring 132 raw biometric data, the raw biometric data (e.g., image data of the user's finger 40 recorded using camera 21) is processed 133 to generate biometric data usable by the biometric sensor 11 of the data carrier (i.e., corresponding comparison data for the subsequent authentication process using the biometric sensor 11). Processing 133 can be performed in any suitable manner, as detailed above, particularly using, for example, machine learning algorithms or other suitable algorithms. Here, relevant biometric features (e.g., fingerprint bifurcation, nodes, rings, whorls, etc.) that uniquely identify the user can be extracted 136 from the raw biometric data. Then, the final biometric data to be registered in the data carrier 10 can be generated 137 from the biometric features extracted in step 136. Here, as described above, a corresponding template is generated.
[0073] The processing of the raw biometric data 133 can be performed on the read / write device 20 itself. Figure 2 (the intermediate branch), but it can also be done on the remote computing device 30 ( Figure 2 (The right branch). Preferably, processing 133 is performed on the remote computing device 30. This allows for the utilization of greater computing power and prevents users or third parties from attempting software tampering on the read / write device 20.
[0074] When processing 133 is performed on remote computing device 30, i.e. according to Figure 2On the right branch, the raw biometric data (e.g., via data connection 31) collected by the read / write device 20 is first transmitted 134 to the remote computing device 30. Then, as already described, the remote computing device 30 processes the raw biometric data into biometric data and transmits the processed biometric data back to the read / write device 20. The step of receiving biometric data from the remote computing device 30 131, as described above, occurs at the point in time when the raw biometric data is first collected by the read / write device 20 and transmitted to the remote computing device 30 for processing to obtain usable biometric data.
[0075] Preferably, all communication between the read / write device 20 and the remote computing device 30 is encrypted; that is, the transmitted data is encrypted first. However, it is also conceivable to transmit only the processed biometric data in an encrypted manner, as this data is more sensitive than the original biometric data. Here, symmetric and asymmetric encryption methods can be used. In the case of symmetric encryption, it is preferable to perform symmetric encryption on the server side (i.e., on the remote computing device 30) so that the symmetric key does not need to be stored on the read / write device 20. Preferably, the key used should be personal to the user. This personal key can be stored, for example, on the remote computing device, or it can be derived there from the user's personal data for encryption.
[0076] After the biometric data is present at the read / write device, i.e., after receiving the biometric data from the remote computing device 131 (e.g., when the biometric data is already stored there, or when the raw biometric data is first transferred by the read / write device 20 to the remote computing device 30 and processed there 133), after retrieving the biometric data from the memory of the read / write device 20 itself (when the biometric data is already present there), or after the read / write device 20 itself processes the acquired raw biometric data 133, the biometric data is transferred to the data carrier 10 140. For this purpose, (e.g., as required by the software application) the data carrier 10 is kept close to the contactless interface 22 of the read / write device. Here, the biometric data is transferred to the data carrier 10 and stored there. Registration thus ends.
[0077] However, it is preferable to verify the read / write device 20 relative to the data carrier 10 before or simultaneously with transmitting the biometric data 140 to the data carrier 10, thereby ensuring that only authorized read / write devices 20 (or authorized software applications on read / write devices 20) register biometric data in the data carrier 10. Furthermore, to ensure that users only collect their biometric data on their own (trusted) data carriers, alternatively, users may be required to verify the data carrier in an appropriate manner at any point during method 100, but before transmitting the biometric data 140 to the data carrier 10. This can be achieved, for example, by inputting or acquiring a number or other suitable identifier applied to or otherwise sent together with the data carrier 10 (e.g., by scanning a QR code applied to the data carrier 10 using a camera), by briefly reading or "authenticating" the data carrier 10 using the contactless interface 22 of the read / write device 20 (e.g., using "Convego Tap" as described above, in which a challenge is transmitted to the data carrier 10 and signed by the data carrier 10. Based on the signature of the data carrier 10 and the PKI (Public Key Infrastructure), the trustworthiness of the data on the data carrier can be ensured) (e.g., by the user briefly bringing the data carrier 10 (or generally its contactless interface 12) close to the contactless interface 22 of the read / write device 20 so that the read / write device 20 can read the relevant data), or in any other suitable manner.
[0078] The method disclosed here reduces the probability of connection interruption during registration because the data carrier 10 only needs to briefly establish a connection with the contactless interface 22 when the biometric data 140 is actually transmitted to the data carrier 10. Furthermore, the user does not need to simultaneously and laboriously operate the biometric sensor 11 of the data carrier 10. Even if the connection is prematurely interrupted during transmission 140, the entire registration process does not need to be repeated because the acquisition and transmission of biometric data 140 are performed separately, and the corresponding data remains on the read / write device 20. In other words, it is only necessary to restart transmission 140 to the data carrier 10.
[0079] Additionally, it should be noted that "comprising" or "having" does not exclude other elements or steps, and "a" or "an" does not exclude multiple. Furthermore, it should be noted that a feature or step described in one of the above embodiments may also be used in combination with other features or steps of other embodiments described above. Reference numerals in the claims should not be considered limiting.
[0080] List of reference numerals
[0081] 10 (card-shaped) data carrier, card
[0082] 11. Biometric sensors (data carriers), fingerprint sensors
[0083] 12 (Data carrier) contactless interface
[0084] 20 Read / write devices, mobile devices, smartphones
[0085] 21 (Read / Write Device) Sensors, Cameras, Fingerprint Sensors
[0086] 22. Contactless interface (for read / write devices), NFC interface
[0087] 30 remote computing devices
[0088] 31 Data Connection
[0089] 40 fingers
[0090] 100 methods
[0091] 110 provides data carriers and read / write devices.
[0092] 120 authenticates users
[0093] 130 Obtain Biometric Data
[0094] 131 Receive biometric data from a remote computing device
[0095] 132 Collects raw biometric data
[0096] 133 Processing raw biometric data
[0097] 134 transmits raw biometric data to a remote computing device
[0098] 136 Extracting Biometric Features
[0099] 137 generates biometric data
[0100] 140 transmits biometric data to a data carrier
[0101] 141 Verification of the read / write device
Claims
1. A method (100) for registering biometric data in a data carrier (10) having a biometric sensor (11) using a read / write device (20), the method (100) comprising: Provide (110) the data carrier (10) and the read / write device (20); Authorized users of the data carrier (10) are authenticated (120) at the issuer of the data carrier (10). Biometric data to be registered on the data carrier (10) is obtained (130) at the read / write device (20); The obtained biometric data is transmitted (140) to the data carrier (10) via the contactless interface (22) of the read / write device (20); and The biometric data received from the read / write device (20) is stored and registered (160) in the data carrier (10).
2. The method (100) according to claim 1, wherein, Obtaining (130) biometric data includes receiving (131) biometric data from a remote computing device (30) via a data connection (31).
3. The method (100) according to any one of the preceding claims, wherein, Obtaining (130) biometric data includes: acquiring (132) raw biometric data using the sensor (21) of the read / write device (20).
4. The method (100) according to claim 3, wherein, The sensor (21) of the read / write device (20) is a camera (21).
5. The method (100) according to claim 3, wherein, The sensor (21) of the read / write device (20) is the fingerprint sensor (21) of the read / write device.
6. The method (100) according to any one of claims 3 to 5, wherein, The collection of (132) biometric raw data includes: liveness detection of users.
7. The method (100) according to any one of claims 3 to 6, wherein, Obtaining (130) biometric data further includes: processing (133) the collected raw biometric data, wherein the processed raw biometric data corresponds to the biometric data used in the data carrier (10).
8. The method (100) according to claim 7, wherein, The processing (133) of the raw biometric data is performed by the read / write device (20).
9. The method (100) according to claim 7, wherein, The processing (133) of the raw biometric data includes: transmitting (134) the raw biometric data to a remote computing device (30), and processing (133) the raw biometric data by the remote computing device (30) to obtain biometric data; and The remote computing device (30) transmits biometric data to the read / write device (20).
10. The method (100) according to claim 9, wherein, Data transmission between the remote computing device (30) and the read / write device (20) is performed in an encrypted manner.
11. The method (100) according to any one of claims 7 to 10, wherein, The processing of the raw biometric data (133) includes: extracting (136) relevant biometric features from the raw biometric data to uniquely identify the user, and generating (137) biometric data using the relevant biometric features, such that the biometric data can be used by the data carrier (10) to identify the user.
12. The method (100) according to any one of the preceding claims, wherein, At the issuer of the data carrier (10), the user is authenticated (120) by a software application on the read / write device (20).
13. The method (100) according to any one of the preceding claims, wherein, Transmitting the obtained biometric data (140) to the data carrier (10) via the contactless interface (22) of the read / write device (20) includes: verifying the read / write device (20) in advance relative to the data carrier (10) (141).
14. The method (100) according to any one of the preceding claims, wherein, The read / write device (20) is the user's mobile device (20).
15. The method (100) according to any one of the preceding claims, wherein, The biometric data includes the user's fingerprint data.