Contactless transaction authentication

The system uses a chip-enabled card and electronic devices to authenticate identity in contactless transactions by combining biometric data, geographic location, and timestamp verification, addressing the challenge of identity verification in socially distanced interactions.

JP2025529803APending Publication Date: 2025-09-09CAPITAL ONE SERVICES LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025508809
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-08-16
Filing Date
2023-08-14
Publication Date
2025-09-09

AI Technical Summary

Technical Problem

The challenge of establishing identity and trust in contactless interactions is exacerbated by social distancing measures, which hinder traditional methods of identification and verification, particularly in a technologically changing world where visual identity verification is often not possible.

Method used

A system utilizing a chip-enabled card and electronic devices to register and authenticate identity through biometric data, geographic location, and timestamp verification, combined with proximity data and machine learning to determine a confidence score for contactless transactions.

Benefits of technology

Enables reliable authentication of individuals in contactless transactions by verifying physical presence and identity using a combination of data points, ensuring secure and efficient interactions while maintaining social distancing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025529803000001_ABST
    Figure 2025529803000001_ABST
Patent Text Reader

Abstract

Disclosed embodiments include aspects related to authentication of contactless interactions. Identification information is provided from multiple sources. A chip-enabled card may be registered to an individual and include identification information associated with that information. The identification information is obtained during a contactless transaction. The individual's identity can be verified based on the identification information. The chip-enabled card is read by a card reader at a specific location that provides physical presence information. In one example, the identification information from the chip-enabled card can be compared with other identification information to determine whether there is a match or mismatch. A confidence score can be calculated based on the amount and type of information provided. If the confidence score meets a threshold, the individual's identity can be verified.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] [CROSS-REFERENCE TO RELATED APPLICATIONS] This application claims priority to U.S. Patent Application No. 17 / 888,830, filed August 16, 2022, the disclosure of which is incorporated herein by reference in its entirety.

[0002] The present disclosure relates to authentication of contactless interactions. [Background technology]

[0003] Identification is important in many social interactions for establishing a level of trust and contact between individuals. Unfortunately, close contact is not always possible, often making it difficult to establish identity and trust. For example, with increased reliance on social distancing, traditional close contact is not possible. Social distancing refers to a standard aimed at mitigating or preventing the transmission of infectious diseases, typically achieved by maintaining physical distance between individuals. In recent examples, the optimal distance has settled on 6 feet (or 2 meters) to effectively mitigate or prevent disease transmission. Furthermore, social distancing typically refers to measures that encourage avoiding large group gatherings.

[0004] Transmission of the disease can be reduced by minimizing the probability that infected individuals come into physical contact with non-infected individuals. Unfortunately, physical distancing between individuals and the occasional wearing of masks to reduce the spread of disease make identification difficult.

[0005] Furthermore, because many of today's interactions are accomplished via text messages (e.g., SMS (Short Message Service) and IM (Instant Message)), visual identity verification is often not possible. Identity verification to establish trust and contact is becoming increasingly important in today's technologically changing world. Summary of the Invention

[0006] The following presents a simplified summary in order to provide a basic understanding of some aspects of the disclosed subject matter. This summary is not an extensive overview, and it is not intended to identify key / critical elements or to delineate the scope of the claimed subject matter. Its sole purpose is to present some concepts in a simplified form as a prelude to the more detailed description that is presented later.

[0007] According to one aspect, a disclosed embodiment includes a system comprising a processor coupled to a memory containing instructions that, when executed by the processor, cause the processor to: register a chip-enabled card containing first identity data of an individual; request second identity data about the individual from a computing device during a contactless transaction, the second identity data including at least one of biometric data, a timestamp, or the geographic location of the computing device; and read the first identity data from the chip-enabled card, the first identity data including at least one of the biometric data, the timestamp, or the geographic location data of the chip-enabled card. The instructions further cause the processor to: compare the first identity data with the second identity data; and, if a match exists between the first identity data and the second identity data, authenticate the identity of the individual for the contactless transaction based on the results of the comparison. In one example, the chip-enabled card is read by a contactless card reader. Furthermore, the geographic location data may include proximity data determined by triangulation or fencing of near-field wireless technology. The biometric data may include a fingerprint, a facial scan, a voiceprint, or a photograph or video of the individual. The instructions may further cause the processor to collect second identity data in response to a request from one or more computing devices. The instructions may further cause the processor to calculate a confidence score based on the first identity data and the second identity data and determine a match if the confidence score meets a predetermined threshold. Furthermore, the predetermined threshold may be based on the requested data or the type of contactless transaction.

[0008] According to another aspect, the disclosed embodiments may include a method including executing instructions on a processor to cause the processor to perform operations associated with contactless authentication. The operations include requesting first identity data from an individual associated with the contactless interaction, requesting presentation of a chip-enabled card registered to the individual and including second identity data associated with the individual, and comparing the first identity data with the second identity data. The operations further include determining a physical location based on at least one of the first identity data and the second identity data, and authenticating the identity of the individual if the comparison results in a match and the physical location is within a predetermined distance from another individual involved in the contactless interaction. The operations further include determining a match if a similarity between the first identity data and the second identity data meets a predetermined threshold. The operations further include determining a confidence score based on the first identity data and the second identity data. The confidence score captures the amount and strength of the provided identity data. The operations may include preventing authentication of the identity if the confidence score meets a predetermined threshold, and preventing authentication of the identity if the confidence score meets a predetermined threshold determined based on the type of interaction or the requested data. The operations may further include reading the chip-enabled card with a contactless card reader and requesting first identity data from the smartphone. Furthermore, the operations may further include determining a physical location based on Global Positioning System coordinates associated with the smartphone. Furthermore, the operations may further include extracting the physical location as the first identity data from metadata of either an image or video provided by the smartphone, and determining the physical location from proximity data associated with triangulation or fencing of short-range wireless technology.

[0009] According to yet another aspect, the disclosed embodiments may include a computer-implemented method. The method may include receiving first identity information from an individual's smartphone associated with a contactless interaction; acquiring second identity information from the individual's chip-enabled card via a contactless card reader; determining a location of the individual based on at least one of location information from the first identity information or the location of the contactless card reader; comparing the first identity information with the second identity information to determine whether a match or mismatch exists; if a match exists, determining a confidence score based on the amount and type of identity information available; and authenticating the identity of the individual if the confidence score meets a predetermined threshold and the location is a predetermined distance from another entity involved in the contactless interaction. The computer-implemented method may further include authenticating the identity of the individual if the confidence score meets a predetermined threshold based on the type of interaction.

[0010] To the accomplishment of the foregoing and related ends, certain illustrative aspects of the claimed subject matter are described herein in connection with the following description and the annexed drawings. These aspects are indicative of various ways in which the subject matter may be practiced, all of which are intended to be within the scope of the disclosed subject matter. Other advantages and novel features will become apparent from the following detailed description when considered in conjunction with the drawings. [Brief explanation of the drawings]

[0011] [Figure 1] An outline of the embodiment will be given below. [Figure 2] Another embodiment will be outlined. [Figure 3] FIG. 1 is a block diagram illustrating an exemplary authentication system. [Figure 4] FIG. 1 is a block diagram illustrating another exemplary authentication system. [Figure 5] 10 illustrates an exemplary user interface for requesting confirmation of physical presence. [Figure 6] 10 illustrates another exemplary user interface for requesting confirmation of physical presence. [Figure 7] FIG. 1 is a flow diagram illustrating a method for authenticating a contactless transaction according to an embodiment. [Figure 8] FIG. 10 is a flow diagram illustrating another method for authenticating contactless transactions based on the accessibility of a registered chip-enabled card, according to an embodiment. [Figure 9] FIG. 1 is a block diagram illustrating a suitable operating environment for aspects of the subject disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0012] Various aspects of the subject disclosure will now be described in more detail with reference to the accompanying drawings, wherein like numerals generally refer to like or corresponding elements throughout. It should be understood, however, that the drawings and the associated detailed description are not intended to limit the claimed subject matter to the particular forms disclosed. Rather, the intention is to cover all modifications, equivalents, and alternatives falling within the spirit and scope of the claimed subject matter.

[0013] Situations where the need to maintain social distancing requires physical presence benefit from the ability to establish an individual's identity in a contactless or socially distanced transaction or interaction. Depending on the context of the transaction, a combination of factors may be used to establish an individual's identity while maintaining social distancing. Electronic devices may be employed to transmit data or requests for data to authenticate identity in a contactless transaction.

[0014] The details disclosed herein generally relate to establishing an individual's identity in a contactless transaction (e.g., authentication for a contactless transaction or interaction). A contactless transaction is a face-to-face transaction that maintains social distancing so that individuals can transact at a distance (e.g., 6 feet or 2 meters). An electronic device is used to establish the individual's identity. For example, the electronic device can be used to capture or transmit a photo or video of the individual taken during the transaction, establish identity based on biometric data and a timestamp (e.g., via a facial scan or facial recognition, voiceprint or voice recognition), and verify the individual's physical presence during the transaction. Biometric data can include a fingerprint, facial scan, or voiceprint and can be used to confirm the individual's identity. The biometric data may be captured via an electronic device equipped with a fingerprint scanner or a camera for taking photos or videos.

[0015] One or more embodiments herein may include using a chip-enabled card (e.g., a chip-enabled card) to further establish an individual's identity in a contactless transaction. An individual may be provided with a chip-enabled card that is registered to the individual with the individual's authentication data (e.g., identity information, biometric data). The chip-enabled card can be used during a contactless transaction to verify physical presence for the contactless transaction. The chip-enabled card can be physically swiped (e.g., with a contact or contactless card reader) during a transaction requiring physical presence, also providing verification of physical presence. Additionally, the chip-enabled card can provide a timestamp and geographic location data for the time and location the card was swiped. Thus, the chip-enabled card can provide an additional source of data points that can be used in combination with other data points to establish an individual's identity.

[0016] Depending on the transaction context, a combination of factors (e.g., a mesh of trust or data collection) may be used to establish an individual's identity in a contactless transaction while maintaining social distancing. For example, timestamps and geographic location data can be used to verify an individual's physical presence at the time of the transaction. Geofencing can be used to alert an individual or servicer (e.g., a person or machine) to their nearby presence. Bluetooth Low Energy beacon triangulation can be employed to calculate the distance between the individual and the servicer via their respective devices. If biometric data, such as photographs and videos, are captured during the transaction, biometric data, such as facial recognition of facial biometric patterns and voice recognition of voiceprints, can also be used to confirm an individual's identity and verify their physical presence. For example, photographs and videos can provide metadata, such as the time and location of the photograph or video. Facial and voice recognition may be employed to identify individuals. Instead of using video, audio clips may be recorded for voice recognition. Individuals transacting together can see each other, and electronic devices can assist, such as by providing a zoom option through the camera lens. Additionally, proximity data can be determined to provide verification (e.g., confirmation) of physical presence. Proximity data can estimate physical proximity between individuals or devices through Bluetooth Low Energy beacon triangulation, geofencing, or information obtained from Wi-Fi.

[0017] Examples of transactions that could benefit from the ability to establish an individual's identity remotely include, but are not limited to, obtaining a national identification card or driver's license, notarizing a document, verifying the identity of a delivery person, verifying the identity of a customer, and signing documents such as a mortgage settlement. Contactless transactions can be reliably authenticated using a combination of data points. A transaction such as signing a document for a mortgage settlement may require a higher confidence score and more data points than a typical goods delivery service.

[0018] Referring to Figure 1, an overview of an embodiment 100 is shown. Figure 1 illustrates an individual 110 conducting four separate contactless transactions, where the individual 110 interacts directly with one or more individuals or servicers using an electronic device 125 in contactless transactions 120, 140, 160, and 180. The one or more individuals or servicers are associated with one or more electronic devices used in the contactless transactions. For example, the individual 110 and the one or more individuals or servicers can send data and request data using their respective electronic devices.

[0019] Individual 110 and one or more individuals or servicers are provided with respective chip-enabled cards that are registered with the individual or servicer. The chip-enabled card may be registered with the identity (e.g., name, address, date of birth) of the individual associated with the chip-enabled card. If the chip-enabled card is available during a transaction, the chip-enabled card may provide an additional data point to verify that the individual associated with the chip-enabled card is physically present for the contactless transaction.

[0020] For example, the individual 110 may be provided with a chip-enabled card 115. The chip-enabled card 115 is registered to the individual 110 including the individual's 110 identity information. If the chip-enabled card 115 is accessible (e.g., available or present) during a contactless transaction, the electronic device 125 may read the chip-enabled card 115 for the identity information registered on the chip-enabled card 115. When reading the chip-enabled card 115, timestamp and geographic location data may also be collected to provide additional data points for identity verification and physical presence verification during a contactless transaction.

[0021] A servicer, such as banking official 130, may also be provided with a chip-enabled card, such as chip-enabled card 135, to allow individual 110 to authenticate or verify the identity of banking official 130. It is contemplated that banking official 130 will be provided with chip-enabled card 135 to use while employed and in a personal capacity. It is contemplated that banking official 130 will be provided with another chip-enabled card for use in a personal capacity and additional chip-enabled cards for use at other workplaces.

[0022] In a contactless transaction 120, the individual 110 transacts or interacts directly with the banking official 130. The individual 110 and the banking official 130 may communicate using their respective electronic devices. Data or a request for data may be transmitted between the individual 110 and the banking official 130 via their respective electronic devices. For example, the individual 110 may transmit data or a request for data via the electronic device 125 to the electronic device 137 of the banking official 130. Just as the individual 110 must provide identity verification to the banking official 130 to receive a service, the individual 110 may also request data from the banking official 130 to verify who is providing the service.

[0023] Sometimes, a transaction involves multiple parties. Contactless transaction 140 shows individual 110 transacting with group 150. Individual 110 can interact directly with group 150. Individual 110 and group 150 can communicate using their respective electronic devices. Group 150 may share a single device, or individuals within group 150 may have their own devices. For example, individual 150a, individual 150b, and individual 150c each have their own electronic device. Data or requests for data are transmitted between individual 110 and group 150 via their respective electronic devices. Individual 110 can request data from individual 150a, individual 150b, and individual 150c, or vice versa. Individuals 150a, 150b, and 150c are assigned chip-enabled cards that are swiped to transmit data to individual 110.

[0024] Machine transactions are also possible. For example, in a contactless transaction 160 (e.g., contact with another individual), the individual 110 conducts a transaction with an ATM (automated teller machine) 170. In machine transactions such as contactless transaction 160, the transaction occurs at the machine itself. For example, in a contactless transaction 160, the individual 110 can enter data directly into the ATM 170 without using the electronic device 125. The ATM 170, or another servicer that is a machine, may have components similar to those in the electronic device 125. For example, the ATM 170 has a data collection component that can collect data (e.g., identity information, biometric data, timestamps, geographic location data, and proximity data) and a card reader for reading the chip-enabled card 115.

[0025] In a contactless transaction 180, the individual 110 interacts directly with the delivery person 190. The individual 110 and the delivery person 190 may communicate using their respective electronic devices. Data or requests for data are transmitted between the individual 110 and the delivery person 190 via their respective electronic devices. The individual 110 may use the electronic device 125 to transmit data to or request data from the delivery person 190. Geographic location data may be shared between devices to notify the individual 110 that the delivery person 190 is within a predetermined distance or to notify the delivery person 190 that the individual is nearby when they arrive at a delivery location. The chip-enabled card may be registered to the delivery person 190 and may include vehicle information used by the delivery person 190.

[0026] Communications in contactless transactions 120, 140, 160, and 180 are transmitted directly between electronic devices associated with the individuals and servicer involved. However, communications in contactless transactions 120, 140, 160, and 180 may be transmitted via a server. FIG. 2 illustrates an overview of another embodiment 200 employing a server 210. Similar to FIG. 1, FIG. 2 illustrates four separate contactless transactions involving contactless transactions 120, 140, 160, and 180. However, in FIG. 2, communications in contactless transactions 120, 140, 160, and 180 are not transmitted directly from device to device as in FIG. 1. In FIG. 2, communications are transmitted via a server 210 capable of storing and transmitting data. The server 210 may be a local server or a cloud server. A local server may offer advantages such as increased processing power, large data storage, and freed-up memory. A cloud server may also offer additional advantages such as scalability and security, among others.

[0027] 2, communications between individual 110 and bank official 130, group of individuals 150, ATM 170, and delivery person 190 are transmitted through server 210. For example, a communication from bank official 130 to individual 110 is received by server 210, which then transmits the communication to individual 110. Otherwise, the authentication process of FIG. 2 is similar to the authentication process of FIG. 1.

[0028] It is understood that electronic device 125 may be a mobile device owned by and registered to individual 110. However, it is also contemplated that an controlling entity, such as a banking institution, may provide the electronic device to the banking institution for use by a customer, such as individual 110, for a transaction, such as contactless transaction 120. Similarly, electronic device 137 may be a mobile device owned by and registered to banking associate 130. However, electronic device 137 may also be an electronic device provided by the banking institution to banking associate 130 for business purposes. For security reasons, it is contemplated that the electronic device may be identified and associated with an individual or business for use by the individual (e.g., a customer or an employee providing a service) in a contactless transaction.

[0029] 3 is a block diagram illustrating an exemplary authentication system 300 including a registration component 302, a communication component 304, a card reader 306, and an authentication component 308. For brevity, contactless transaction 120 will be described in more detail to illustrate the authentication process in other similar contactless transactions. Registration component 302 can register chip-enabled card 115 with individual 110, including the individual's 110 identity. Registration component 302 may also register chip-enabled card 135 with banking official 130, including the banking official's 130 identity. If the individual is a servicer, the individual's identity is associated with one or more managing entities. For example, because banking official 130 is a servicer, the identity of banking official 130 is associated with the bank (e.g., managing entity) that employs banking official 130.

[0030] During a contactless transaction, the communications component 304 can transmit data or requests for data between an electronic device, such as electronic device 125, and one or more electronic devices, such as electronic device 137, including identity information, biometric data, a timestamp, geographic location data, or proximity data. Bluetooth Low Energy beacon triangulation, geofencing, or Wi-Fi can determine proximity data. The biometric data may include a photo or video of the individual 110 or the servicer (e.g., bank associate 130).

[0031] If accessible during a contactless transaction, the card reader 306 can read the chip-enabled card 115 via the electronic device 125 for identity information, a timestamp, geographic location data, or proximity data associated with the individual 110 to verify the physical presence of the individual 110. Similarly, the card reader 306 can read the chip-enabled card 135 via the electronic device 137 for identity information associated with, for example, a banking official 130. Additionally, the card reader 306 can read the chip-enabled card 135 associated with the banking official 130 for identity information associated with the banking official 130 that reveals the name of the controlling entity (e.g., the name of the employer). The card reader 306 may be a contact or contactless reader employing near-field communication (NFC).

[0032] When the banking official 130 requests data from the individual 110, the request may be transmitted via the communications component 304. If the request is for biometric data, it may include a photograph or video of the individual 110 taken during the contactless transaction. However, the biometric data may also include a fingerprint and an audio clip or recording. In response to a request for a photograph from the banking official, the individual 110 may take a photograph with an electronic device and transmit the photograph to the banking official 130 via the communications component 304. Based on the received data, the banking official may use the electronic device 137 to authenticate the contactless transaction via the authentication component 308. In transactions where the servicer is a machine, such as contactless transaction 160, authentication may be in the form of granting access to an account associated with the transaction.

[0033] 4 is a block diagram illustrating another example authentication system 300 further including a data collection component 402 and a machine learning component 404. The data collection component 402 collects data associated with an individual on an electronic device and can collect requested data from one or more electronic devices. For example, in response to a request from a bank official 130 for biometric data, such as a photograph, the individual 110 can send the photograph to the bank official 130. The photograph is collected by the data collection component 402 and stored on the electronic device 137 or on the server 210.

[0034] The machine learning component 404 can analyze the requested data and provide a confidence score. The confidence score may be determined based on the requested data or the type of contactless transaction. For example, a clear photograph may receive a higher confidence score than a less clear photograph. A video that reveals an individual's facial features and voice may receive a higher confidence score than a photograph. As such, the machine learning component 404 can employ facial recognition and voice recognition. The machine learning component 404 can also employ handwriting recognition to detect whether a signature belongs to the individual the transaction binds. The confidence score may also be based on the type of contactless transaction. For example, a confidence score for a delivery service such as the contactless transaction 180 may meet a predetermined threshold without requiring as much data as other transactions such as a mortgage settlement. In some examples, the confidence score may be based on a binary decision. In other examples, the confidence score may be a weighted decision. For example, if the delivery truck is not variable (e.g., identified or provided) in the contactless transaction 180, the confidence score may be based on a binary decision based on whether the delivery truck is an identified delivery truck or not. However, the identity of the delivery person may be variable based on the identity information provided by the delivery person. It is understood that the machine learning component 404 can extract timestamp data, geographic location data, and proximity data from the transmitted communication and provide a confidence score for verification of the physical presence of an individual in a contactless transaction.

[0035] FIG. 5 illustrates an exemplary user interface 500 for requesting confirmation of physical presence. The electronic device 125 illustrated in FIGS. 5 and 6 is a mobile device. However, the electronic device 125 is not limited to a mobile device. For example, the electronic device 125 may be an electronic device located within a bank. In FIG. 5 , a request 510 may be sent to the electronic device 125 associated with the individual 110 from another electronic device, such as the electronic device 137 associated with the bank official 130, as part of a contactless transaction. The request 510 may ask the individual 110, "Do you have a verification card?" In this example, the individual 110 sends a reply 520 answering "Yes." A follow-up request 530 may be sent to the individual 110 asking the individual 110 to "provide confirmation of your presence by tapping your card."

[0036] In response to the request 530, the individual 110 can tap the chip-equipped card 115 to the electronic device 125 so that the card reader 306 can read the chip-equipped card 115. In this non-limiting example, the card reader 306 is a contactless card reader that employs NFC to read the chip-equipped card 115 (e.g., card in general). Thus, by tapping the chip-equipped card 115 to the electronic device 125, information data stored on the chip-equipped card 115 can be read. For contactless card reading (e.g., without the need to insert or swipe a card), the individual 110 must turn on or enable NFC on the electronic device 125 to use this near-field wireless technology.

[0037] FIG. 6 illustrates another example user interface 600 for requesting verification of physical presence. In the example user interface 600, a request 610 is sent to the individual 110 via the electronic device 125. The request 610 asks the individual 110, "Do you have a verification card?" In response, the individual 110 sends a reply 520 answering "No." A follow-up request 630 may be sent to the individual 110, asking the individual 110 to "provide verification of your presence by taking and sending an image of yourself." The request 630 requests biometric data in the form of a photograph or image of the individual taken during the contactless transaction. The photograph may provide photo metadata including a timestamp, geographic location data, and information about the electronic device 125. This photo metadata may be used by the machine learning component 404 to determine a confidence score for verification of the individual's 110's physical presence in the contactless transaction. The individual in the contactless transaction can use the verification by the machine learning component 404 to authenticate the contactless transaction using the electronic device 137 via the authentication component 308. For example, based on a confidence score that meets a predetermined threshold, the machine learning component 404 can provide verification of the physical presence of the individual 110. The bank official 130 can use the provided verification, along with the bank official's 130 visual identification of the individual 110, to determine whether to authorize the contactless transaction 120.

[0038] 7 and 8, exemplary authentication methods 700 and 800 are depicted. For ease of explanation, the methods are illustrated and described using a series of blocks. However, it should be understood that some blocks may occur in a different order or concurrently with other blocks depicted and described herein, and the disclosed subject matter is not limited by the order of the blocks. Moreover, not all illustrated blocks are required to implement the methods described below. Furthermore, each block or combination of blocks may be implemented by computer program instructions provided to a processor to create a machine, the instructions executing on the processor creating means for performing the functions specified by the flowchart blocks. Additionally, authentication methods 700 and 800 are described in conjunction with specific examples for illustrative purposes only.

[0039] 7 is a flow diagram illustrating a method 700 for authenticating a contactless transaction. At 710, the authentication method 700 includes, via the registration component 302, registering a chip-enabled card containing the individual's identity information with an individual. At 720, during the contactless transaction, the authentication method 700 includes, via the communication component 304, transmitting data or a request for data between the electronic device and one or more electronic devices, the data including identity information, biometric data, a timestamp, geographic location data, or proximity data. At 730, if accessible during the contactless transaction, the authentication method 700 includes, via the card reader 306, reading the identity information, the timestamp, the geographic location data, or the proximity data from the chip-enabled card via the electronic device or one or more electronic devices for physical presence verification. At 740, the authentication method 700 includes, via the authentication component 308, authenticating the contactless transaction based on the data via the electronic device or one or more electronic devices.

[0040] FIG. 8 is a flow diagram illustrating another authentication method 800 associated with a contactless transaction based on the accessibility of a registered chip-enabled card 115. At 810, the authentication method 800 includes transmitting data or a request for data via the communications component 304. At 820, the authentication method 800 may include determining whether the chip-enabled card 115 is accessible (e.g., available or present) by the individual 110. If yes, the process proceeds to 830. If no, the process proceeds to 840. At 830, the authentication method 800 may include reading the chip-enabled card 115. At 840, the authentication method 800 may include transmitting additional data or a request for data. At 850, the authentication method 800 may include determining whether the data is complete. If yes, the process proceeds to 860. If no, the process proceeds to 840. At 860, the authentication method 800 may include authenticating the identity of the individual associated with the contactless transaction based on the data.

[0041] Using the contactless transaction 120 as an example, based on the data transmitted from the electronic device 125 to the electronic device 137, the machine learning component 404 can provide verification of the physical presence of the individual 110 if the confidence score meets a predetermined threshold. The bank official 130 can use the provided verification along with the bank official's 130 visual observation of the individual 110 and the contactless transaction 120. The bank official can decide whether to authenticate the individual 110 associated with the contactless transaction 120. The authentication from the bank official 130 can be transmitted by the electronic device 137 to the electronic device 125 via the authentication component 308.

[0042] While many of the embodiments described herein employ a chip-enabled card to establish contactless identity, it should be understood that other embodiments exist that employ additional identity data, such as biometric data (e.g., fingerprint, facial recognition, voiceprint), in conjunction with (or alone) a chip-enabled card to establish contactless identity. For example, if a chip-enabled card is not available, biometric data can be employed in conjunction with (or separately from) the identity / characteristics and contextual data of the mobile device to verify identity. In other aspects, additional data, such as biometric data, may be employed in addition to a chip-enabled card (device or fob) to confirm identity in scenarios where more advanced identity verification is desired or required. These alternative embodiments are within the spirit or scope of the innovations disclosed and claimed herein.

[0043] As used herein, the terms "component" and "system," and their various forms (e.g., component, system, subsystem), are intended to refer to a computer-related entity that is either hardware, a combination of hardware and software, software, or software in execution. For example, a component may be, but is not limited to, a process running on a processor, a processor, an object, an instance, an executable, a thread of execution, a program, or a computer. As an example, both an application running on a computer and the computer can be a component. One or more components may reside within a process or thread of execution, and a component may be localized on one computer or distributed between two or more computers.

[0044] As used herein, the terms “infer” or “inference” generally refer to the process of inferring or estimating the state of a system, component, environment, or user from one or more observations, particularly those captured by events or data. Inference may be employed to identify contexts or actions or used to generate probability distributions over states. Inference may be probabilistic. For example, the computation of a probability distribution over states of interest may be based on a consideration of data or events. Inference can also refer to techniques employed for composing higher-level events from a set of events or data. Such inference will construct new events or new actions from observed events or a set of stored event data, regardless of whether the events are closely correlated in time, and whether the events and data come from one or more event and data sources.

[0045] The conjunction "or," as used in this specification and the appended claims, is intended to mean an inclusive "or" rather than an exclusive "or," unless otherwise specified or clear from the context. In other words, "'X' or 'Y'" means any inclusive permutation of "X" and "Y." For example, if "'A' employs 'X'," "'A' employs 'Y'," or "'A' employs both 'X' and 'Y'," then "'A' employs 'X' or 'Y'" is satisfied in any of these instances.

[0046] Furthermore, to the extent that the terms "comprise," "contain," "have," or variations thereof are used in either the detailed description or the claims, such terms are intended to be inclusive in the same manner as the term "comprising" is interpreted when employed as a transitional word in the claims.

[0047] To provide a context for the disclosed subject matter, Figure 9 and the following discussion are intended to provide a brief, general description of a suitable environment in which various aspects of the disclosed subject matter may be implemented. However, this suitable environment is merely exemplary and is not intended to suggest any limitation to the scope of use or functionality.

[0048] While the disclosed systems and methods are described above in the general context of computer-executable instructions for programs executed on one or more computers, those skilled in the art will appreciate that they may also be implemented in combination with other program modules, etc. Generally, program modules include routines, programs, components, data structures, etc. that perform particular tasks or implement particular abstract data types. Furthermore, those skilled in the art will appreciate that the systems and methods described above may be implemented with a variety of computer system configurations, including single-processor, multi-processor, or multi-core processor computer systems, minicomputer devices, server computers, and personal computers, handheld computing devices (e.g., personal digital assistants (PDAs), smartphones, tablets, watches, etc.), microprocessor-based or programmable consumer or industrial electronic devices, etc. They may also be implemented in distributed computing environments where tasks are performed by remote processing devices linked through a communications network. However, some, if not all, aspects of the disclosed subject matter may be implemented on stand-alone computers. In a distributed computing environment, program modules may be located in either or both local and remote memory devices.

[0049] 9, an exemplary computing device 900 (e.g., desktop, laptop, tablet, watch, server, handheld, programmable consumer or industrial electronic device, set-top box, gaming system, compute node, ...) is illustrated. The computing device 900 includes one or more processors 910, memory 920, a system bus 930, storage devices 940, input devices 950, output devices 960, and communication connections 970. The system bus 930 communicatively couples at least the aforementioned system components. However, in its simplest form, the computing device 900 may include one or more processors 910 coupled to memory 920, where the one or more processors 910 execute various computer-executable actions, instructions, and / or components stored in the memory 920.

[0050] The one or more processors 910 may be implemented as a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic, discrete gate or transistor logic, discrete hardware components, or any combination thereof designed to perform the functions described herein. A general-purpose processor may be a microprocessor, but alternatively, the processor may be any processor, controller, microcontroller, or state machine. The one or more processors 910 may also be implemented as a combination of computing devices, such as a combination of a DSP and a microprocessor, multiple microprocessors, a multi-core processor, one or more microprocessors in combination with a DSP core, or any other such configuration. In one embodiment, the one or more processors 910 may be a graphics processor unit (GPU) that performs calculations related to digital image processing and computer graphics.

[0051] Computing device 900 may include or otherwise interact with a variety of computer-readable media to facilitate control of the computing device to implement one or more aspects of the disclosed subject matter. Computer-readable media may be any available media accessible to computing device 900, including volatile and nonvolatile media, and removable and non-removable media. Computer-readable media may include two different, mutually exclusive types: storage media and communication media.

[0052] Storage media include volatile and nonvolatile, removable and non-removable media implemented in any method or technology for storage of information, such as computer-readable instructions, data structures, program modules, or other data. Storage media include memory devices (e.g., random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM)), magnetic storage devices (e.g., hard disks, floppy disks, cassettes, tapes), optical disks (e.g., compact disks (CDs), digital versatile disks (DVDs)), and solid-state devices (e.g., solid-state drives (SSDs), flash memory drives (e.g., cards, sticks, key drives)), or any other similar medium that stores, as opposed to transmitting or communicating, desired information accessible by computing device 900. Thus, storage media excludes modulated data signals, as well as those discussed with respect to communication media.

[0053] Communication media embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism and includes any information delivery media. The term "modulated data signal" means a signal that has one or more of its characteristics set or changed in such a manner as to encode information in the signal. By way of example, and not limitation, communication media includes wired media such as a wired network or direct-wired connection, and wireless media such as acoustic, radio frequency (RF), infrared and other wireless media.

[0054] Memory 920 and storage devices 940 are examples of computer-readable storage media. Depending on the configuration and type of computing device, memory 920 may be volatile (e.g., random access memory (RAM)), non-volatile (e.g., read-only memory (ROM), flash memory, etc.), or some combination of the two. As an example, a basic input / output system (BIOS), containing the basic routines for transferring information between elements within computing device 900, such as during start-up, may be stored in non-volatile memory, while volatile memory may act as external cache memory to, among other things, facilitate processing by one or more processors 910.

[0055] The one or more storage devices 940 include removable / non-removable, volatile / non-volatile storage media for storing large amounts of data for the memory 920. For example, the one or more storage devices 940 may include, but are not limited to, one or more devices such as a magnetic or optical disk drive, a floppy disk drive, a flash memory, a solid state drive, or a memory stick.

[0056] The memory 920 and one or more storage devices 940 include or store therein an operating system 980, one or more applications 986, one or more program modules 984, and data 982. The operating system 980 acts to control and allocate resources of the computing device 900. The applications 986, which may include one or both system software and application software, may take advantage of the management of resources by the operating system 980 through the program modules 984 and data 982 stored in the memory 920 or storage devices 940 to perform one or more actions. Thus, the applications 986, according to the logic provided by them, can transform the general-purpose computer 900 into a special-purpose machine.

[0057] All or a portion of the disclosed subject matter may be implemented using standard programming or engineering techniques to generate software, firmware, hardware, or any combination thereof, that controls computing device 900 to perform the disclosed functions. By way of example and not limitation, all or a portion of authentication system 300 may be, or form part of, an application 986, and may include one or more modules 984 and data 982 stored in memory or storage device 940 that, when executed by one or more processors 910, may provide functionality.

[0058] According to certain embodiments, the one or more processors 910 may correspond to a system-on-chip (SOC) or similar architecture that includes, or otherwise integrates, both hardware and software on a single integrated circuit substrate. Here, the one or more processors 910 may include not only one or more processors but also, among other things, one or more memory at least similar to the processors 910 and memory 920. Traditional processors include minimal hardware and software and rely extensively on external hardware and software. In contrast, SOC implementations of processors are more powerful because they embed hardware and software that achieve specific functionality with minimal or no dependency on external hardware and software. For example, authentication system 300 or related functionality may be incorporated within the hardware of a SOC architecture.

[0059] One or more input devices 950 and one or more output devices 960 may be communicatively coupled to the computing device 900. By way of example, the one or more input devices 950 may include, among others, a pointing device (e.g., a mouse, a trackball, a stylus, a pen, a touchpad), a keyboard, a joystick, a microphone, a voice user interface system, a camera, a motion sensor, and a global positioning satellite (GPS) receiver and transmitter. The one or more output devices 960 may correspond, by way of example, to, among others, a display device (e.g., a liquid crystal display (LCD), a light emitting diode (LED), a plasma, an organic light emitting diode display (OLED)), a speaker, a voice user interface system, a printer, and a vibration motor. The one or more input devices 950 and the one or more output devices 960 may be connected to the computing device 900 by a wired connection (e.g., a bus), a wireless connection (e.g., Wi-Fi, Bluetooth), or a combination thereof.

[0060] The computing device 900 may include one or more communication connections 970 to enable communication with at least a second computing device 902 utilizing a network 990. The one or more communication connections 970 may include wired or wireless communication mechanisms to support network communications. The network 990 may correspond to a local area network (LAN) or a wide area network (WAN) such as the Internet. The second computing device 902 may be another processor-based device with which the computing device 900 can interact. In one example, the computing device 900 may execute the authentication system 300 for a first function, and the second computing device 902 may execute the authentication system 300 for a second function in a distributed processing environment. Additionally, the second computing device may provide a network-accessible service that stores source code, encryption keys, and the like that can be employed by the authentication system 300 executing on the computing device 900.

[0061] The foregoing includes examples of aspects of the claimed subject matter. Of course, it is not possible to describe every conceivable combination of elements or methodologies for purposes of describing the claimed subject matter, but those skilled in the art will recognize that many further combinations and permutations of the disclosed subject matter are possible. Accordingly, the disclosed subject matter is intended to embrace all such alterations, modifications, and variations that fall within the spirit and scope of the appended claims.

Claims

1. 1. A system comprising a processor coupled to a memory containing instructions, The instructions, when executed by the processor, cause the processor to: registering a chip-enabled card containing first identity data of an individual; During the contactless transaction, requesting from a computing device second identity data regarding the individual, the second identity data including at least one of biometric data, a timestamp, or a geographic location of the computing device; reading the first identity data from the chip-enabled card, the first identity data including at least one of biometric data, a timestamp, or geographic location data of the chip-enabled card; comparing the first identity data with the second identity data; if a match exists between the first identity data and the second identity data, authenticating the identity of the individual for the contactless transaction based on a result of the comparison; Execute system.

2. The system of claim 1 , wherein the chip-enabled card is read by a contactless card reader.

3. The system of claim 1 , wherein the geographic location data includes proximity data determined by triangulation or fencing of short-range wireless technologies.

4. The system of claim 1 , wherein the biometric data includes a fingerprint, a face scan, a voiceprint, or a photograph or video of the individual.

5. The system of claim 1 , wherein the instructions further cause the processor to collect the second identity data in response to the request from one or more computing devices.

6. The instructions cause the processor to: calculating a confidence score based on the first identity data and the second identity data; determining the match if the confidence score meets a predetermined threshold; Further execute The system of claim 1 .

7. The system of claim 6 , wherein the predetermined threshold is based on requested data or the type of the contactless transaction.

8. 1. A method comprising: executing instructions on a processor to cause the processor to perform operations associated with contactless authentication, The operation is requesting first identity data from an individual associated with the contactless interaction; requesting presentation of a chip-enabled card registered to the individual and including second identity data associated with the individual; comparing the first identity data with the second identity data; determining a physical location based on at least one of the first identity data and the second identity data; authenticating the identity of the individual if the comparison results in a match and the physical location is within a predetermined distance from other individuals involved in the contactless interaction; A method comprising:

9. The method of claim 8 , wherein the actions further comprise determining the match if a similarity between the first identity data and the second identity data meets a predetermined threshold.

10. The operations further include determining a confidence score based on the first identity data and the second identity data; The confidence score captures the amount and strength of the identity data provided. The method of claim 8.

11. The method of claim 10 , wherein the actions further include preventing identity authentication if the confidence score meets a predetermined threshold.

12. The method of claim 11 , wherein the actions further include preventing authentication of the identity if the confidence score meets a predetermined threshold determined based on a type of interaction.

13. The method of claim 11 , wherein the actions further include preventing authentication of the identity if the confidence score meets a predetermined threshold determined based on requested data.

14. The method of claim 8 , wherein the action further comprises reading the chip-enabled card with a contactless card reader.

15. The method of claim 8 , wherein the action further comprises requesting the first identity data from a smartphone.

16. The method of claim 8 , wherein the actions further include determining the physical location based on global positioning system coordinates associated with a smartphone.

17. The method of claim 8 , wherein the action includes extracting the physical location as first identity data from metadata of either an image or a video provided by a smartphone.

18. The method of claim 8 , wherein the actions further comprise determining the physical location from proximity data associated with short-range wireless technology triangulation or fencing.

19. 1. A computer-implemented method comprising: receiving first identity information from a smartphone of an individual associated with the contactless interaction; acquiring second identity information from the personal chip-enabled card with a contactless card reader; determining a location of the individual based on at least one of location information from the first identity information or a location of the contactless card reader; comparing the first identity with the second identity to determine whether a match or mismatch exists; If there is a match, determining a confidence score based on the amount and type of identity information available; authenticating the identity of the individual if the confidence score meets a predetermined threshold and the location is a predetermined distance from other entities involved in the contactless interaction; A method comprising:

20. 20. The method of claim 19, further comprising authenticating the identity of the individual if the confidence score meets a predetermined threshold based on a type of interaction.