METHOD FOR BIOMETRIC REGISTRATION AND BIOMETRIC DEVICE
Patent Information
- Application Number
- DE102025122170
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2025-06-05
- Publication Date
- 2026-08-27
- Estimated Expiration
- 2045-06-05
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
TECHNICAL AREA The present disclosure relates to a method for biometric registration and a biometric device. BACKGROUND The use of any newly developed biometric system can begin with biometric registration. The registration process is intended to ensure the high quality of the registered biometric characteristics. Since the registered biometric characteristic is used as a second factor for user authentication, user identity must also be verified during registration. WO 2023 / 205 216 A1 discloses a method for processing a transaction from a biometric payment card in a payment network on a network server, wherein the method comprises: receiving current transaction data from the biometric payment card during an ongoing transaction, the transaction data comprising: a transaction counter value associated with the current transaction; a biometric matching result; biometric matching results corresponding to previous transactions prior to the current transaction; retrieving historical transaction data and biometric history data relating to biometric matching results received by the payment network when approving the last transaction; and comparing the received current transaction data with the historical transaction data to identify potentially fraudulent use of the payment card. JAYASINGHE, D. [et al.]: Enhancing EMV Online PIN Verification. In: 2015 IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), 20-22 August 2015, Helsinki, Finland, pp. 808-817. DOI: 10.1109 / Trustcom.2015.451 reveals details of the online PIN procedure. Cryptographic nonce. In: Wikipedia, the free encyclopedia. Revision as of 22.05.2025. URL: https: / / en.wikipedia.org / w / index.php?title=Cryptographic_nonce&oldid=1291716808 reveals what is meant by "nonce". SUMMARY A method for biometric registration according to claim 1 and a biometric device according to claim 10 are provided. Further embodiments are described in the dependent claims. A procedure for biometric registration is provided.The procedure involves, in response to activation via a contactless transaction, registering transaction-specific information of the contactless transaction, obtaining a biometric pattern, requesting user verification, obtaining transaction-specific information during the user verification transaction, in response to successful user verification, comparing the transaction-specific information obtained during user verification with the transaction-specific information of the contactless transaction, and if the comparison determines that the transaction-specific information obtained during user verification matches the transaction-specific information of the contactless transaction, storing the biometric pattern as at least part of a biometric reference pattern for biometric user verification. A biometric device is provided. The biometric device includes a biometric sensor, a processor, memory, and a wireless transaction device and is designed for biometric registration, wherein the biometric registration includes: in response to activation, via a contactless transaction, registering transaction-specific information of the contactless transaction, obtaining a biometric pattern, requesting user verification, obtaining transaction-specific information during user verification, in response to successful user verification, comparing the transaction-specific information obtained during user verification with the transaction-specific information of the contactless transaction, and if, as a result of the comparison, it is determined that the transaction-specific informationwhich were obtained during user verification, match the transaction-specific information of the contactless transaction, storing the biometric pattern in memory as at least part of a biometric reference pattern for biometric user verification. Experts will recognize additional features and advantages upon reading the following detailed description and examining the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS The present disclosure is illustrated by way of example, but not as a limitation, in the figures of the accompanying drawings, in which the same reference numerals refer to similar or identical elements. The elements of the drawings are not necessarily to scale relative to one another. The features of the various illustrated examples can be combined unless they are mutually exclusive. Fig. 1 schematically represents a method for biometric registration according to various embodiments. Fig. 2 schematically represents a method for biometric registration according to various embodiments. Fig. 3 schematically represents a method for biometric registration according to various embodiments. Fig. 4 schematically represents a method for biometric registration according to various embodiments.Figures 5A to 5C illustrate a method for biometric registration according to various embodiments. Figure 6 is a schematic representation of a biometric device according to various embodiments. Figure 7 shows a flowchart of a method for biometric registration according to various embodiments. DETAILED DESCRIPTION Different aspects of the disclosure are provided for devices, and different aspects of the disclosure are provided for methods. It is understood that the basic properties of the devices also apply to the methods and vice versa. Therefore, for the sake of brevity, a duplicate description of such properties may have been omitted. The term "atomic transaction" is to be understood as an indivisible and irreducible series of operations that are carried out on the card during a registration / payment transaction, such that either all or none occur. A simple and seamless registration process for the user is highly desirable. Against this background, a registration process was developed, known as "register at payment" or "silent registration". This is based on a principle in which the user's fingerprint is registered at a terminal during a payment transaction. Initial transactions can capture the user's fingerprint templates, and registration can of course be completed after a few transactions without the user noticing. Since more and more payment transactions are being carried out as contactless payments, these contactless payment transactions should also allow registration as a "silent registration". However, ensuring user authenticity during the contactless registration phase can be more difficult than with contact transactions, where the user PIN can be easily verified during an atomic transaction. Furthermore, multiple sub-submissions may often be required to complete the registration. In such a case, the situation may differ between an initial sub-submission capture—a new biometric device, such as a biometric chip card, without a "reference template"—and subsequent sub-submission captures, where the already registered sub-submission can allow the newly captured sub-submission to be checked against the already registered sub-submission(s)—in other words, the already registered sub-submission(s) can serve as one or more "reference templates." A biometric registration process, particularly for initial sub-template verification, can involve a payment application capturing and temporarily storing a candidate sub-template during a contactless transaction. The contactless transaction is then canceled and reverts to a contact-based transaction. During the contact-based transaction, user authenticity is confirmed through user PIN verification (for example, offline verification based on comparing the entered PIN with a secure PIN).using a secure element) the reference PIN stored on the chip card, or as online verification by the card issuer, who receives the entered PIN in an encrypted transaction from a reader, for example after a GAC (Generate Application Cryptogram) command, compares it with the reference PIN and returns the result of the comparison to the reader), and the payment application then sets (registers) the candidate template. This means that a "reference template" is now embedded in the card. During subsequent contactless transactions, the payment application can acquire additional candidate templates, check them against the reference, and enrich the reference if there is a match. If a completed template, for example for the user's first finger, is already available during the registration of the user's second finger, a contactless transaction with successful fingerprint verification can optionally be used to check user authenticity. If no match is found, the payment application can save the candidate, cancel and fall back to the contact-based transaction, and can validate the candidate using the process described above. In various embodiments, as described above, point-of-sale (POS) registration can be used as a fingerprint template registration technique on payment cards during transactions. It may be intended to proceed with registration during the first few transactions, thus eliminating the need for a dedicated registration device and improving user convenience. In the current implementation, a template of the finger can be captured during each successful contactless (CL) transaction if a finger is present on the sensor. If the capture template is of sufficient quality, the template can be finalized. Once sufficient templates have been completed, the biometric template can be activated via offline / online PIN, issuer scripts, or implicit activation. After activation, the registered fingerprint is ready for use as a cardholder verification method (CVM) for contact-based or contactless (CL) transactions. One weakness of such a procedure may be that an application for which the biometric feature, e.g., the partial template, needs to be registered, such as a payment app, cannot reliably determine whether the candidate partial template cached during the previous contactless transaction was captured as part of the same subsequent transaction, which also includes the contact-based or contactless transaction for verifying user authenticity, or during a different transaction, possibly much later. In other words, an attacker may attempt to register their fingerprint through a contactless transaction that can be canceled, but the temporarily stored biometric feature, awaiting final user authentication, can then be validated by the real user during the next contact-based or contactless transaction with successful user verification. Furthermore, requiring PIN validation for the registration of each template can significantly delay the registration process. This can negatively impact the customer experience, neglecting the importance of convenience and intuitiveness during POS registration. Various implementations can be provided to reduce the risk of such an attack. In various implementations, information (e.g., transaction-specific) provided to a biometric device (for example, a biometric chip card) during any contactless payment transaction can be stored along with the sub-submission candidate. This information may include, for example, the time and date of the transaction, the transaction amount, the transaction identification number, and merchant and / or terminal constants. During the next transaction expected to validate the sub-template, the payment application can verify user authenticity (e.g., by verifying an entered PIN, such as in a contact-based transaction, or by using fingerprint authentication from a previously registered finger of the user, such as in a contactless transaction) and can additionally compare information provided by the terminal for this new transaction with the information stored along with the sub-template verification candidate awaiting verification. The comparison might be designed, for example, to verify that the date and time are consistent, such as that less than a few minutes elapsed between the contactless transaction during which the sub-template was captured and the current authentication transaction.(after entering the PIN or fingerprint authentication). Alternative or additional comparisons can ensure that the transaction amount, device and / or merchant data, transaction ID, etc. are similar or identical for both transactions. Only when user authenticity (PIN or fingerprint verified and transaction approved) is confirmed and the additional information (e.g., date, time, amount, etc.) has been verified as consistent, can the payment application "lock" and register the candidate sub-submission. In other words, during an initial contactless transaction, a (e.g., preliminary) reference template may be captured, and the transaction (TXN) may be rejected, forcing a user to perform a contact-based or another contactless transaction. During the contactless transaction for reference template capture, transaction information such as the time and date of the transaction, transaction amount, merchant and device constants can be captured and stored. During the subsequent transaction for reference template finalization via a cardholder verification process (CVM), the previous contactless transaction details can be verified to check for consistency. When verifying whether the date and time are consistent, for example, whether less than "N" minutes have elapsed between the contactless and the contact-based transaction, and when verifying the transaction amount, the terminal and merchant data for both transactions may be similar. If a successful transaction (offline or online) can take place and consistency can be successfully verified, the reference template can be considered authenticated and therefore final. If not, the captured template can be discarded and the reference template capture process can be restarted. A similar verification process can be applied in various embodiments to any sub-templates that could not be matched with the reference template until it is determined that the registration process is complete. In other words, during subsequent contactless transactions, a new template can be captured, and the new template can be verified against the finalized reference template. If the new template matches the reference template, no further transaction may be required for completion. The new template can be finalized directly. However, if the new template does not match the reference template, the new template can be considered a new reference template, and thus the reference template capture process described here can be activated. After a few initial reference templates, subsequent templates can have a high probability of matching and can therefore be safely finalized without requiring a further cardholder verification (CVM) procedure by the user. The examples described here provide embodiments of a biometric registration method that approves a captured biometric feature as (part of) a biometric reference, which may be used for user authentication in subsequent transactions only if two conditions are met: 1) user authentication must be successfully provided (e.g., a PIN may need to be entered or fingerprint authentication performed with a previously registered finger), and 2) additional information stored when the biometric feature was captured must meet a matching criterion with corresponding additional information obtained in connection with providing user authentication. For example, it may be required that a payable amount, a merchant, a transaction ID, a date, etc., are identical between the two transactions, and it may be required, for example, that the time between the two transactions differs by no more than a predetermined period of time, e.g., a few minutes. Each of Figs. 1, 2, 3 to 4 schematically illustrates a method for biometric registration according to different embodiments. Fig. 1 schematically illustrates in a visualization 100, which includes several fields a) to f), a method for biometric registration according to different embodiments. As indicated in fields a) and b), a biometric device 104 may, in various embodiments, initially be provided without a stored biometric reference pattern. For this reason, a memory section 102, as illustrated in field a), may be empty (a corresponding stage of the procedure is indicated by the “1”). In various alternative embodiments (see, for example, Fig. 3 and / or Fig. 4, which are described later), the biometric device 104 may be provided with at least one stored biometric reference pattern, and the procedure according to various embodiments may be applied to extend the stored biometric reference pattern and / or to store additional biometric reference patterns. The biometric device 104 can, for example, be or include a chip card (as illustrated in the figures). It is understood that any other biometric device designed for wireless transactions in combination with biometric authentication can be understood as representing a biometric device 104 according to various embodiments, for example, a biometric smartwatch, a biometric smart ring, a biometric tablet, etc. The procedure involves activation via a contactless transaction. The contactless transaction that activates the registration procedure can, for example, involve positioning the biometric device 104 within a transaction area of a reader 106, such as a payment terminal. The biometric device 104 and the reader 106 can form a biometric system 105. The procedure also includes registering transaction-specific information 110 of the contactless transaction. The transaction-specific information may, for example, include at least one of a group of transaction-specific information, where the group consists of: a date and time of the transaction, a payable amount, a transaction number of a payment transaction, a respective identification of a reader that activated the contactless transaction and the contact-based transaction, a name associated with the reader, and a transaction certificate that uniquely identifies the transaction. Alternatively or additionally, any other transaction-specific information suitable for comparison for consistency during a subsequent transaction, as described below, may be used. The method further involves obtaining a biometric pattern. The biometric device 104 may include a biometric sensor that can be used to obtain the biometric pattern. For example, a fingerprint may be obtained by a fingerprint sensor, but any other biometric sensor provided as part of the biometric device 104 may be equally suitable. The activation and acquisition of the biometric pattern and transaction-specific information 110 are illustrated in field b) of Fig. 1. The biometric pattern and the associated transaction-specific information can, for example, be stored in the memory section. In Fig. 1, this is shown in field b) as the entry 102_t1, where the "t" indicates that the entry is temporary and awaits authentication (or deletion). The process also includes requesting user verification and obtaining transaction-specific information during the user verification transaction. The codes SW6985 and AAC shown in Fig. 1 are examples and / or representative of notifications that user authentication based on the received biometric pattern was unsuccessful and that user verification by another method is required. Field c) illustrates an example of user verification based on the provision of a secret number, such as a personal identification number (PIN). A reference for the PIN may be stored in memory in various embodiments, for example, in the same memory that provides memory section 102, or in a different memory. In various embodiments, in response to successful user verification (the check symbol between field c) and field d), for example, a confirmed match between the PIN reference and the entered PIN), a transaction-specific information 112 obtained during user verification can be compared with the transaction-specific information 110 of the contactless transaction. In other words, the same type of transaction-specific information 110 that was stored during the contactless transaction can also be determined during the user verification transaction (in Fig. 1 this is a contact-based transaction, as illustrated in field c), for example, during both transactions the transaction time can be recorded, or the amount to be paid, the transaction ID, etc., or any combination thereof. If, as a result of the comparison (illustrated in field d), it is determined that the transaction-specific information 112 obtained during user verification matches the transaction-specific information 110 of the contactless transaction (illustrated by the check symbol between fields d) and e)), in other words, in response to the determination of a match between the transaction-specific information 110 and the transaction-specific information 112, the biometric pattern is stored, at least as part of a biometric reference pattern for biometric user verification. This is indicated by removing the "t" for "temporary" from the reference 102_1, which is stored in memory section 102. This stage of the procedure can be referred to as stage "2", as indicated in field e) of Fig. 1. At this point, the biometric registration can be completed or continued, for example during an additional transaction, e.g. an additional payment transaction, which can be carried out using the same reader 106 or a different reader, e.g. at a different location and / or at a different time. If either of the two comparisons / verifications fails, the temporarily stored biometric pattern remains unconfirmed and cannot be used to authenticate the user. This is illustrated by the arrows between fields c) and f) (for a failed user verification, e.g., if no PIN is provided upon request or an incorrect PIN is provided) and between fields d) and f) (for the comparison between the transaction-specific information 112 obtained during user verification, which is determined to match the transaction-specific information 110 of the contactless transaction, resulting in a missing match). It should be noted that a "match" may not necessarily require that the information from the transaction-specific information 112 obtained during user verification and the transaction-specific information 110 be identical. While this may be required if the information is, for example, a payable amount, a date, a merchant, or the like, which remains constant between the contactless transaction and the user verification transaction, in the case of the time when the information is obtained, it may even be necessary that the time of the transaction at which the biometric feature is captured and the time of the transaction during which user verification is provided are similar (e.g.,(between a few seconds and a few minutes apart), but are not identical, since the two transactions are executed sequentially and therefore cannot be assigned the same time information. Each of Figs. 2, 3 to 4 schematically illustrates variations of the embodiments described in connection with Fig. 1 of the biometric registration method according to different embodiments. Since many of the features and processes described in the context of Figures 2 to 5C are similar to or identical to those described in connection with Figure 1, duplications of the respective descriptions are omitted. Instead, differences between the respective embodiments are highlighted. Fig. 2 schematically illustrates in a visualization 200, which includes several fields a) to f), a method for biometric registration according to different embodiments. In the embodiment of Fig. 1, user verification is obtained via a contact-based transaction in which a PIN is entered. In the embodiment of Fig. 2, user verification can be obtained by providing the (e.g., online) PIN without a contact-based transaction (see field c) of Fig. 2). In this case, reactivating the contactless transaction may require a contactless tap (in other words, another type of contactless transaction, illustrated in field c2) of Fig. 2. This means that user verification and, based on this and on a match between the transaction-specific information 110 and the transaction-specific information 112, biometric registration can be achieved even without a contact-based transaction. Fig. 3 schematically illustrates in a visualization 300, which includes several fields a) to f), a method for biometric registration according to different embodiments. In the embodiments of Fig. 1 and Fig. 2, a starting point for the biometric registration process is a biometric device 104 which has not yet stored a biometric reference pattern. In the embodiment shown in Fig. 3, a biometric reference pattern has already been stored in memory section 102: In field a), this is indicated by the stored entry of memory section 102, which is labelled 102_1. The biometric reference pattern can, for example, be a result of the biometric registration process illustrated in conjunction with Fig. 1 or Fig. 2 (hence the indication that the starting point of the process shown in Fig. 3 is stage “2”), but it can also be the result of other techniques for providing the biometric device with the biometric reference pattern that is present when the biometric registration process of the embodiment shown in Fig. 3 is initiated. For example, an issuer of the biometric device can store the biometric reference pattern. This means that an additional biometric profile will now be obtained. Otherwise, the embodiment of Fig. 3 differs from the embodiment shown in the context of Fig. 1 in that the biometric reference pattern already stored can serve as a reference for the newly acquired additional reference pattern, which can be temporarily stored in the memory section 102, as indicated by the reference 102_t2, together with the respective transaction-specific information 110. Before user verification is requested, it can be checked (see field b2 in Fig. 3) if there is at least a partial match between the biometric reference pattern already stored in the memory section and the additional biometric pattern. While the match may be complete, a partial match is sufficient to be considered a match. For example, the biometric reference pattern and the additional biometric pattern may both be fingerprints, and they may have at least a partial overlap that qualifies (check between fields b2 and b3)) to verify the additional biometric pattern as the biometric reference pattern and either extend the already stored biometric reference pattern or generate a new biometric reference pattern (see field b3). A phase with two biometric reference patterns can be designated as Phase 3. If the comparison with the biometric reference pattern fails (cross symbol between field b2) and field c)), the procedure can be continued as described in the context of Fig. 1 (requesting user verification and providing it through a contact-based transaction (see field c) of Fig. 3), comparing the transaction-specific information (field d) of Fig. 3) and storing the temporarily stored additional biometric pattern as the additional biometric reference pattern (new, non-temporary entry 102_2 in field e)) or deleting the temporary entry (see field f) of Fig. 3). Alternatively (not shown), user verification and subsequent processes can be performed as shown in conjunction with Fig. 2, using another contactless user verification and another contactless tap instead of contact-based user verification. Fig. 4 schematically illustrates in a visualization 400, which includes several fields a) to f), a method for biometric registration according to different embodiments. The biometric registration method shown in Fig. 4 differs from the method shown in Fig. 3 in that two biometric reference patterns are already provided in memory section 102 at the start of the method. This can, for example, correspond to phase “3” of the method described in connection with Fig. 3, or the biometric reference patterns may have been stored in another way, for example as shown in connection with Fig. 3. Another difference between the biometric registration method shown in Fig. 4 and the method of Fig. 2 may be that the newly acquired biometric pattern (which is temporarily stored together with the corresponding transaction-specific information, as indicated by the label 102_t3) can be compared with any of the biometric reference patterns already in existence, and that only in the event of a mismatch with both reference patterns is the biometric registration procedure carried out, as described in the context of any one of Fig. 1, Fig. 2 and / or 3 (fields c) to f) from Fig. 4). Each of the Figs. 5A to 5C schematically illustrates in respective visualizations 500, 501 and 502, each containing several fields a) to f), methods for biometric registration according to different embodiments. The embodiment shown in Fig. 5A can differ from the embodiments illustrated in Fig. 1, Fig. 2, Fig. 3 to Fig. 4 (and in particular Fig. 1 and Fig. 2, which both also illustrate the beginning of a new registration for which no template has yet been registered) in that at the starting point of the process at least one registered fingerprint is already available in memory section 102E and can be used for user authentication using the silent registration process during the registration of, for example, another finger of the user. In this embodiment, memory section 102 etc. refers to the memory section used for the new registration process, e.g., of the next finger. This means that, as an alternative to providing a PIN, fingerprint user authentication can be performed (shown as the second alternative in field c)). Such biometric authentication can represent a consumer device cardholder verification procedure (CDCVM). Fingerprint user authentication can, for example, be performed as a contactless transaction. Regardless of whether the newly received fingerprint template is authenticated or not, the fingerprint already registered in memory section 102E remains unchanged. In summary, the biometric registration method shown in Fig. 5A may be essentially similar or identical to those described in Fig. 1 and Fig. 2, except for user authentication, which is based on fingerprint authentication using a previously registered fingerprint. The previously registered fingerprint may have been stored using, for example, the biometric registration method described above, for instance in the context of Figures 1, 2, 3 to 4, e.g., as a silent registration. Alternatively, the previously registered fingerprint may have been registered using, for example, a prior art method, and only the registration of further fingerprints of the user may be carried out using the (silent) biometric registration of the various embodiments. The embodiment shown in Fig. 5B may differ from the embodiment shown in Fig. 5A in a similar way to how the embodiment of Fig. 3 differs from that of Fig. 1, namely in that at the starting point of the biometric registration process a verified template is already stored in memory section 102_1 and a different fingerprint template is obtained. In the embodiment shown in Fig. 5B, authentication can be carried out, as in the embodiment shown in Fig. 5A, as an alternative to PIN authentication, for example, using the already registered fingerprint (e.g., of another finger of the user). The embodiment shown in Fig. 5C may differ from the embodiment shown in Fig. 5B in a similar way to how the embodiment of Fig. 4 differs from that of Fig. 3, namely in that at the starting point of the biometric registration process two verified templates are already stored in the memory sections 102_1, 102_2 and a different fingerprint template is obtained. In the embodiment shown in Fig. 5C, authentication, as in the embodiment shown in Fig. 5A and Fig. 5B, can be carried out as an alternative to PIN authentication, for example, using the already registered fingerprint (e.g., of another finger of the user). The embodiment shown in Fig. 5C is, mutatis mutandis, to be understood as executable for further subsequent templates. Memory section 102E can serve as an exemplary embodiment for a predefined number of verified templates that may be required for the successful completion of the registration process, the predefined number being defined depending on the use case. Fig. 6 is a schematic representation of a biometric device 104 according to various embodiments. The biometric device 104, e.g. a biometric chip card or another type of contactless biometric device, may include a biometric sensor 660, for example a fingerprint sensor or another type of biometric sensor. The biometric device 104 may also include a processor 668, for example a microprocessor. The biometric device 104 may further include a memory 662, for example, a non-volatile memory, or a combination of a non-volatile and a volatile memory. The memory 662 may include a memory section 102, which may be configured to store biometric reference patterns, as described above. The biometric reference patterns may be stored in the non-volatile part of the memory 662, whereas the temporary storage of the biometric pattern and / or associated transaction-specific information, as described above, may optionally be performed in the non-volatile memory and / or the volatile memory. The biometric device 104 may further include a wireless transaction device 664 and may be configured for biometric registration. The biometric device 104 may, for example, be configured for biometric registration as described above, as described above in connection with any one of Figs. 1, 2, 3 to 4. Biometric registration can include the following: in response to activation, via a contactless transaction; registering transaction-specific information of the contactless transaction; obtaining a biometric sample; requesting user verification; obtaining transaction-specific information during user verification, in response to successful user verification; comparing the transaction-specific information obtained during user verification with the transaction-specific information of the contactless transaction;and if, as a result of the comparison, it is determined that the transaction-specific information obtained during user verification matches the transaction-specific information of the contactless transaction, the biometric pattern is stored in memory as at least part of a biometric reference pattern for biometric user verification. In various embodiments, the biometric device 104, in particular the processor 668 (optionally in combination with the memory 662, the wireless transaction device 664 and / or the biometric sensor 660), can be configured as a secure element. The secure element can be designed for cryptographic functions for the secure handling of data processed by the biometric device 104. Fig. 7 shows a flowchart 700 of a method for biometric registration according to different embodiments.The procedure involves, in response to activation, via a contactless transaction, registering transaction-specific information of the contactless transaction (in 710), obtaining a biometric pattern (in 720), requesting user verification (in 730), obtaining transaction-specific information during the user verification transaction (in 740), in response to successful user verification (750), comparing the transaction-specific information obtained during user verification with the transaction-specific information of the contactless transaction, and if the comparison determines that the transaction-specific information obtained during user verification matches the transaction-specific information of the contactless transaction (in 760),Storing the biometric pattern as at least part of a biometric reference pattern for biometric user verification (in 770). The following are several examples: Example 1 is a procedure for biometric registration.The procedure involves, in response to activation via a contactless transaction, registering transaction-specific information of the contactless transaction, obtaining a biometric pattern, requesting user verification, obtaining transaction-specific information during the user verification transaction, in response to successful user verification, comparing the transaction-specific information obtained during user verification with the transaction-specific information of the contactless transaction, and if the comparison determines that the transaction-specific information obtained during user verification matches the transaction-specific information of the contactless transaction, storing the biometric pattern as at least part of a biometric reference pattern for biometric user verification. In Example 2, the subject of Example 1 may optionally include that the transaction-specific information contains at least one group of transaction-specific information, the group consisting of: a date and time of the transaction; a payable amount; a transaction number of a payment transaction; a respective identification of a reader device that enabled the contactless transaction and the contact-based transaction; a name associated with the reader device; and a transaction certificate that uniquely identifies the transaction. In Example 3, the item from Example 1 or 2 may optionally include the user verification containing or consisting of a secret number. In Example 4, the item from Example 3 can optionally include user verification during a newly initiated contact-based transaction, before a contactless tap that initiates a continuation of the initial contactless transaction, or during a subsequent contactless transaction that requests user authentication via an already registered finger. In Example 5, the item from any of Examples 1 to 4 may optionally further include: initiating an additional contactless transaction; registering transaction-specific information of the additional contactless transaction; obtaining an additional biometric pattern; comparing the additional biometric pattern with the stored biometric reference pattern; and, if the comparison reveals a match between the stored biometric reference pattern and the additional biometric pattern, extending the stored biometric reference pattern to include the additional biometric pattern. In Example 6, the item from Example 5 may optionally further include, if the comparison reveals a missing match between the stored biometric reference pattern and the additional biometric pattern: requesting additional user verification; obtaining additional transaction-specific information during the additional user verification; and, in response to successful additional user verification, comparing the additional transaction-specific information obtained during the additional user verification with the transaction-specific information of the additional contactless transaction.and if, based on the comparison, it is determined that the additional transaction-specific information obtained during the additional user verification matches the transaction-specific information of the additional contactless transaction, the additional biometric pattern is stored as at least part of an additional biometric reference pattern for biometric user verification. In Example 7, the subject matter of Example 3 and one of claims 6 or 7 may optionally include the additional user verification including or consisting of the secret number. In Example 8, the item from Example 7 can optionally include the additional user verification taking place during a newly initiated contact-based transaction, before a further contactless tap that initiates the continuation of the additional contactless transaction, or during a subsequent contactless transaction that requests user authentication via an already registered finger. In example 9, the item from any of examples 1 to 8 may optionally include the biometric pattern being a fingerprint. Example 10 is a biometric device comprising a biometric sensor, a processor, memory, and a wireless transaction device, and designed for biometric registration, wherein the biometric registration includes: in response to activation, via a contactless transaction, registering transaction-specific information of the contactless transaction; obtaining a biometric pattern; requesting user verification; obtaining transaction-specific information during user verification; in response to successful user verification, comparing the transaction-specific information obtained during user verification with the transaction-specific information of the contactless transaction;and if, as a result of the comparison, it is determined that the transaction-specific information obtained during user verification matches the transaction-specific information of the contactless transaction, the biometric pattern is stored in memory as at least part of a biometric reference pattern for biometric user verification. In Example 11, the subject of Example 10 may optionally include that the transaction-specific information contains at least one group of transaction-specific information, the group consisting of: a date and time of the transaction; a payable amount; a transaction number of a payment transaction; a respective identification of a reader device that enabled the contactless transaction and the contact-based transaction; a name associated with the reader device; and a transaction certificate that uniquely identifies the transaction. In Example 12, the item from Example 10 or 11 may optionally include the user verification containing or consisting of a secret number. In Example 13, the item from Example 12 can optionally include user verification during a newly initiated contact-based transaction, before a contactless tap that initiates the continuation of the initial contactless transaction, or during a subsequent contactless transaction that requests user authentication via an already registered finger. In Example 14, the item from Examples 10 to 13 can optionally be further configured to: initiate an additional contactless transaction; register transaction-specific information of the additional contactless transaction; obtain an additional biometric pattern; compare the additional biometric pattern with the stored biometric reference pattern; and if the comparison reveals a match between the stored biometric reference pattern and the additional biometric pattern, extend the stored biometric reference pattern to include the additional biometric pattern. In Example 15, the item from Example 14 can optionally be further configured to: if the comparison reveals a missing match between the stored biometric reference pattern and the additional biometric pattern, request additional user verification; obtain additional transaction-specific information during the additional user verification; in response to successful additional user verification, compare the additional transaction-specific information obtained during the additional user verification with the transaction-specific information of the additional contactless transaction;and if, based on the comparison, it is determined that the additional transaction-specific information obtained during the additional user verification matches the transaction-specific information of the additional contactless transaction, the additional biometric pattern is stored as at least part of an additional biometric reference pattern for biometric user verification. In Example 16, the item from Example 12 and one of Examples 14 or 15 may optionally include the additional user verification that includes or consists of the secret number. In Example 17, the item from Example 16 can optionally include the additional user verification taking place during a newly initiated contact-based transaction, before a further contactless tap that initiates a continuation of the additional contactless transaction, or during a subsequent contactless transaction that requests user authentication via an already registered finger. In example 18, the item from any of examples 10 to 17 may optionally include the biometric pattern being a fingerprint. Although specific examples are illustrated and described herein, it will be clear to those skilled in the art that a variety of alternative and / or equivalent implementations can be substituted for the specific examples shown and described without altering the scope of the present invention. This application is intended to cover all adaptations or variations of the specific examples discussed herein. Therefore, this invention is intended to be limited only by the claims and their equivalents. It should be noted that the methods and devices, including their preferred embodiments, as outlined in this document, can be used independently or in combination with other methods and devices disclosed herein. Furthermore, the features described in connection with a device are also applicable to a corresponding method, and vice versa. Moreover, all aspects of the methods and devices described in this document can be combined as desired. In particular, the features of the claims can be combined with one another as desired. It should be noted that the description and drawings merely illustrate the principles of the proposed methods and systems. Those skilled in the art are able to implement various arrangements which, although not expressly described or shown herein, embody the principles of the invention and are contained within its concept and scope of protection. Furthermore, all examples and embodiments presented in this document are expressly intended to serve only explanatory purposes, to facilitate the reader's understanding of the principles of the proposed methods and systems. Moreover, all statements herein that provide principles, aspects, and embodiments of the invention, as well as specific examples thereof, are intended to include their equivalents.
Claims
A method for biometric registration, the method comprising: in response to activation, via a contactless transaction, registering transaction-specific information (110) of the contactless transaction (710) provided to a biometric device (104) during the contactless transaction (710); obtaining a biometric pattern (720); canceling the contactless transaction; requesting user verification (730); obtaining transaction-specific information (112) during the user verification transaction; in response to successful user verification (650), comparing the transaction-specific information (112) obtained during the user verification with the transaction-specific information (110) of the contactless transaction (740);If the comparison determines that the transaction-specific information (112) obtained during user verification matches the transaction-specific information (110) of the contactless transaction (760), the biometric pattern shall be stored at least as part of a biometric reference pattern for biometric user verification (770). The method of claim 1, wherein the transaction-specific information (110, 112) comprises at least one of a group of transaction-specific information, the group consisting of: the date and time of the transaction; an amount to be paid; a transaction number of a payment transaction; a respective identification of a reading device that has activated the contactless transaction and the contact-based transaction; a name associated with the reading device; and a transaction certificate that uniquely identifies the transaction. Method according to claim 1 or 2, wherein the user verification includes or consists of a secret number. Method according to claim 3, wherein the user verification takes place during a newly initiated contact-based transaction or prior to a contactless tap that initiates a continuation of the initial contactless transaction. A method according to any one of claims 1 to 4, further comprising: initiating an additional contactless transaction; registering transaction-specific information about the additional contactless transaction; obtaining an additional biometric pattern; comparing the additional biometric pattern with the stored biometric reference pattern; if the comparison reveals a match between the stored biometric reference pattern and the additional biometric pattern, extending the stored biometric reference pattern to include the additional biometric pattern.The method of claim 5, further comprising: if the comparison reveals a missing match between the stored biometric reference pattern and the additional biometric pattern, requesting additional user verification; obtaining additional transaction-specific information during the additional user verification; in response to successful additional user verification, comparing the additional transaction-specific information obtained during the additional user verification with the transaction-specific information of the additional contactless transaction;If the comparison determines that the additional transaction-specific information obtained during the additional user verification matches the transaction-specific information of the additional contactless transaction, the additional biometric pattern shall be stored at least as part of an additional biometric reference pattern for biometric user verification. Method according to claim 3 and one of claims 5 or 6, wherein the additional user verification includes or consists of the secret number. Method according to claim 7, wherein the additional user verification takes place during a newly initiated contact-based transaction, prior to a further contactless tap that initiates the continuation of the additional contactless transaction, or during a subsequent contactless transaction that requests user authentication via an already registered finger. Method according to any one of claims 1 to 8, wherein the biometric pattern is a fingerprint. Biometric device (104) comprising a biometric sensor (660), a processor (668), a memory (662), and a wireless transaction device, and designed for biometric registration, wherein the biometric registration comprises: in response to activation, via a contactless transaction, registering transaction-specific information (110) of the contactless transaction provided to the biometric device (104) during the contactless transaction (710); obtaining a biometric pattern; canceling the contactless transaction; requesting user verification; obtaining transaction-specific information (112) during user verification; in response to successful user verification, comparing the transaction-specific information (112) obtained during user verification with the transaction-specific information (110) of the contactless transaction;If the comparison determines that the transaction-specific information (112) obtained during user verification matches the transaction-specific information (110) of the contactless transaction, the biometric pattern shall be stored in memory at least as part of a biometric reference pattern for biometric user verification. Biometric device (104) according to claim 10, wherein the transaction-specific information (110, 112) comprises at least one of a group of transaction-specific information, the group consisting of: date and time of the transaction; an amount to be paid; a transaction number of a payment transaction; a respective identification of a reading device that has activated the contactless transaction and the contact-based transaction; a name associated with the reading device; and a transaction certificate that uniquely identifies the transaction. Biometric device (104) according to claim 10 or 11, wherein the user verification includes or consists of a secret number. Biometric device according to claim 12, wherein user verification takes place during a newly initiated contact-based transaction, prior to a contactless tap initiating the continuation of the initial contactless transaction, or during a subsequent contactless transaction requesting user authentication via an already registered finger. Biometric device (104) according to one of claims 10 to 13, further configured to: initiate an additional contactless transaction; register transaction-specific information about the additional contactless transaction; obtain an additional biometric pattern; compare the additional biometric pattern with the stored biometric reference pattern; and if the comparison reveals a match between the stored biometric reference pattern and the additional biometric pattern, extend the stored biometric reference pattern to include the additional biometric pattern. Biometric device (104) according to claim 14, further designed to: if the comparison reveals a missing match between the stored biometric reference pattern and the additional biometric pattern, request additional user verification; obtain additional transaction-specific information during the additional user verification; in response to successful additional user verification, compare the additional transaction-specific information obtained during the additional user verification with the transaction-specific information of the additional contactless transaction;If the comparison determines that the additional transaction-specific information obtained during the additional user verification matches the transaction-specific information of the additional contactless transaction, the additional biometric pattern shall be stored at least as part of an additional biometric reference pattern for biometric user verification. Biometric device according to claim 12 and one of claims 14 or 15, wherein the additional user verification includes or consists of the secret number. Biometric device (104) according to claim 16, wherein the additional user verification takes place during a newly initiated contact-based transaction, prior to a further contactless tap that initiates a continuation of the additional contactless transaction, or during a subsequent contactless transaction that requests user authentication via an already registered finger. Biometric device (104) according to one of claims 10 to 17, wherein the biometric pattern is a fingerprint.
Citation Information
Patent Citations
Enrolment process for a biometric card and methods of use of a biometric card
WO2023205216A1