Methods, systems, and computer program products for monitoring or controlling user access at service points.
The method and system provide secure and efficient biometric authentication at service points, addressing the inefficiencies and security concerns of existing methods by using biometric comparisons to control user access without central databases, ensuring seamless and secure user identification.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- OPTIML VISION INC
- Filing Date
- 2024-03-18
- Publication Date
- 2026-05-01
AI Technical Summary
Existing user authentication methods at service points are inconvenient, insecure, and impractical, particularly when dealing with large user databases, and they often compromise data privacy and security.
A method and system that uses biometric authentication at service points, involving a service point terminal that receives a data payload from a communication device, acquires a biometric sample, performs a comparison with stored templates, and transmits a data payload to a service access control system for user identification, ensuring secure and seamless access control without central biometric databases.
Enables secure, efficient, and user-friendly authentication of users at service points, maintaining data privacy and security, even with large user databases, by using biometric comparisons without the need for central storage or user effort.
Smart Images

Figure 2026514130000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of personal authentication based on personal biometric information. More specifically, the present invention provides a method, a system, and a computer program product for monitoring or controlling a user's access to a service at a service point (point-of-service).
Background Art
[0002] With the proliferation of electronic services, services managed or activated electronically, or services with electronic access control, individuals are routinely required to be authenticated as a prerequisite for accessing such services, or as a prerequisite for monitoring or controlling user access to such services. Without losing generality, examples of services include physical access, logical access, electronic access, payments, billing, charges, or any kind of monitoring, personalization, or privileges specific to a user. Without losing generality, examples of services include airline baggage check-in, airline check-in, airport security screening, immigration, boarding an airplane, airport lounge access, in-flight payments such as food and beverages, payment of airfare or additional charges such as excess baggage or seat selection, use of airfare vouchers for any purpose, hotel check-in, hotel payments, payment of hotel room charges, parking, payment of parking fees, retrieval of parked cars, use of swimming pools, use of lounges, car rental, payment of car rental fees, access to parking lots, exit from parking lots, use of restaurant loyalty discounts, electronic payments (by credit card, debit card, or bank account information), payments by customer account information, payment of tolls, and access to any location. This includes ordering food and other goods, picking up food and beverages at any location, including in stores and drive-throughs, access to computers, access to accounts, logging into computers, picking up children from school or daycare, purchasing restricted goods, proof of identity, access to sporting events, concerts, and shows, access to conferences and exhibitions, access to government buildings, security checks on the roadside, at entrances, or on premises, security checks for visitors, presenting identification to staff or readers or computing devices, access to government benefits such as medical care, discounted / free food, discounted / free clothing, driving privileges, toll privileges, seating privileges, or other privileges, personalization, surveillance, and access.
[0003] Electronic identity verification processes, and processes that control or monitor user access to services, typically implement some form of challenge-response based authentication. For example, a company providing an online service might identify users by a unique username and authenticate them using a password or PIN. In some implementations, the online service might issue a digital key / token to the user, who stores it on their personal device and exposes it to the online service to access their account. The user, on the other hand, can protect access to the digital key / token on their device by locking it and unlocking it with a password, PIN, or biometric information.
[0004] Some systems implement additional steps to enhance security. For example, an online service might send a code to the user's registered email address or phone number, and the user might send that code back to the online service in addition to, or instead of, their password. In another scenario, the user might provide knowledge that only they would know, such as their birthplace or the color of their first car.
[0005] In the real world, identifying and authenticating users using usernames / passwords at service points is extremely inconvenient and impractical. It is more common for companies to issue / accept physical keys, tokens, or cards for themselves or their agents / affiliates. Methods for presenting cards at a company's service point terminal vary, including magnetic stripes, contact, and contactless (RFID or NFC) secure chips. In some implementations, ID and authentication details are stored on the user's smartphone and exposed to the terminal via QR code®, NFC emulation, Bluetooth®, ultra-wideband radio, or Wi-Fi®. For example, Tesla®'s "phone-as-a-key" system pairs the user's smartphone with a specific terminal / asset (in this case, a Tesla vehicle) via Bluetooth®, and the smartphone's proximity to the vehicle is used for authentication.
[0006] Other solutions for identity verification or monitoring or controlling user access to services in the real world include biometrics. The type of biometric information may be any one of the following: voice, iris, retina, fingerprint, palm print, palm vein, periorbital, facial features, ear, DNA (deoxyribonucleic acid), scleral vein, finger shape, palm shape, gait, heart rate, blood vessels, signature, or biometrics based on other body parts. Biometric technology enables rapid and accurate identification of individuals by comparing a biometric sample taken at a service point (or authentication point) with one or more verified biometric templates associated with a person authorized to access a particular service, and granting access to the service if the acquired biometric sample matches one of the verified biometric templates. In certain biometric implementations, the verified biometric templates of a person authorized to access a particular service may be obtained from a trusted intermediary platform that acts as a repository of pre-verified biometric templates. An example of this approach is Amazon®'s "Amazon One" product. In this product, users register their biometric information with a central service, and at service points, a live sample of that user's biometric information is compared to the biometric information of all users registered with "Amazon One." While this solution offers convenience to users, the central database of biometric information is susceptible to hacking. Furthermore, with such a solution, the system becomes increasingly slow and unusable as the size of the registrant database grows. This approach is considered impractical when the number of registered users reaches several million.
[0007] Other solutions allow users to store digital tokens (e.g., PINs, passwords, or pre-signed or pre-authenticated verified biometric templates) on their personal devices (such as smartphones) and send these digital tokens from their personal devices to a service point for authentication. In specific implementations, users may need to take their smartphones out of their pockets or wallets, unlock them, launch applications, select menu options, and either display a QR code on their smartphone screen or bring their smartphones within a short distance (usually 10 meters) of the terminal to send the token or biometric template via a Near Field Communication (NFC) session. For example, PayPal's in-store payment system requires users to display a QR code from the PayPal app on their smartphones to the merchant's terminal for authentication and transaction confirmation. This solution is known to be insecure because physical items, including personal devices like smartphones, can be shared, lost, or stolen. As a compromise, the user's smartphone and / or the PayPal app may require unlocking with a PIN, password, or biometric information before being permitted to display the digital token. In another example, as described in the mobile driver's license standard ISO / IEC 18013-5, a user presents a pre-authenticated and verified biometric template on their personal smartphone to a service point terminal using either NFC or a QR code (registered trademark). The terminal then performs a one-to-one biometric comparison between the template and the actual biometric capture to verify the user's identity for services such as airport access. However, these solutions are not hands-free and require the user to go through several steps to be identified, leaving considerable inconvenience for the user.
[0008] Therefore, there is a need for a solution that can securely and accurately identify, authenticate, and / or monitor or control users' access to services at a service point, regardless of the number of users registered for authentication (i.e., regardless of the size of the database), without centrally storing a large biometric database that is easily hacked, without service point terminals deciphering user identity or location, and without services accessing users' biometric data. Furthermore, such a solution must ensure that service providers can seamlessly and uniquely identify and authenticate legitimate users at service points, while simultaneously ensuring data privacy and data security, and enabling user authentication with minimal (ideally no) effort on the user's side. [Overview of the project] [Means for solving the problem]
[0009] The present invention provides a method, system, and computer program product for monitoring or controlling user access to a service at a service point.
[0010] In one embodiment, the present invention includes a method for monitoring or controlling a user's access to services at a service point. The method includes performing the following steps in a service point terminal implementing a processor: (i) receiving a first data payload from a first communication device; (a) the data in the first data payload is based on a first data block stored in memory accessible by the first communication device, the first data block corresponds to a second data block stored in memory accessible by a service access control system; (b) at least one of the data in the first data payload, the first data block, or the second data block is associated with either a user, a service, or a user's access to a service; (ii) acquiring a biometric sample through a biometric sample acquisition sensor; (iii) performing a biometric comparison between the acquired biometric sample and a group of biometric templates stored in the memory of the service point terminal, the group of biometric templates including at least one user biometric template associated with a user; (c) the user biometric template is generated based on user biometric data associated with a user; (d) the user biometric template or user biometric data is received by the service point terminal from the first communication device; and (iv) transmitting a second data payload to the service access control system. The data in the second data payload is based on the data in the first data payload. Furthermore, the data in the second data payload enables the service access control system to identify the user based on the output from a calculation that includes the data in the second data payload and the data in the second data block.In one embodiment of this method, the service access control system is configured to respond to user identification by generating a control signal that permits or records the user's access to the service, the control signal being generated after a positive match determination is generated based on data output from a biometric comparison performed at a service point terminal, the positive match determination being generated in response to the identification of a predefined similarity between the acquired biometric sample and the user biometric template.
[0011] In another embodiment, the present invention provides a method for monitoring or controlling a user's access to a service at a service point terminal, the method comprising the steps of: (i) transmitting a first data payload to a service point terminal in a first communication device implementing a processor, (a) the data in the first data payload being based on a first data block stored in memory accessible by the first communication device, (b) the first data block corresponding to a second data block stored in memory accessible by a service access control system, and (c) at least one of the data in the first data payload or the first data block or the second data block being associated with either a user, a service, or a user's access to a service.
[0012] In this embodiment, the service point terminal is configured to (i) acquire a biometric sample through a biometric sample acquisition sensor, (ii) perform a biometric comparison between the acquired biometric sample and a group of biometric templates stored in the service point terminal memory, the group of biometric templates including at least one user biometric template associated with a user, (a) the user biometric template is generated based on user biometric data associated with the user, (b) the user biometric template or user biometric data is received by the service point terminal from a first communication device, and (iii) transmit a second data payload to a service access control system, (a) the data in the second data payload is based on the data in the first data payload, and (b) the data in the second data payload enables the service access control system to identify a user based on the output from a calculation including the data in the second data payload and the data in the second data block.
[0013] Furthermore, in this embodiment, the service access control system is configured to respond to user identification by generating a control signal that permits or records the user's access to the service based on the results of a calculation, the control signal being generated after a positive match determination is generated based on data output from a biometric comparison performed at the service point terminal, the positive match determination being generated in response to the identification of a predefined similarity between the acquired biometric sample and the user biometric template.
[0014] In yet another embodiment, the present invention provides a method for monitoring or controlling a user's access to a service at a service point terminal, the method comprising, in a service access control system implementing a processor, (i) storing a second data block in memory accessible by the service access control system, the second data block corresponding to a first data block stored in memory accessible by a first communication device, the first communication device configured to (a) transmit a first data payload to the service point terminal, (1) the data in the first data payload being based on a first data block, and (2) at least one of the data in the first data payload, the first data block, or the second data block being associated with either a user, a service, or a user's access to a service.
[0015] In this embodiment, the service point terminal is configured to (i) acquire a biometric sample through a biometric sample acquisition sensor, (ii) perform a biometric comparison between the acquired biometric sample and a group of biometric templates stored in the service point terminal memory, the group of biometric templates including at least one user biometric template associated with a user, (a) the user biometric template is generated based on user biometric data associated with the user, (b) the user biometric template or user biometric data is received by the service point terminal from a first communication device, and (iii) transmit a second data payload to a service access control system, (1) the data in the second data payload is based on the data in the first data payload, and (2) the data in the second data payload enables the service access control system to identify a user based on the output from a calculation including the data in the second data payload and the data in the second data block.
[0016] The service access control system is further configured to respond to user identification by generating control signals that permit or record the user's access to the service, the control signals being generated after a positive match determination is generated based on data output from biometric comparison performed at the service point terminal, the positive match determination being generated in response to the identification of a predefined similarity between the acquired biometric sample and the user biometric template.
[0017] Furthermore, the present invention provides a service point terminal configured to monitor or control user access to services at a service point.The service point terminal comprises at least one processor and at least one memory, and is configured to (i) perform the step of receiving a first data payload from a first communication device, (a) the data in the first data payload is based on a first data block stored in memory accessible by the first communication device, the first data block corresponds to a second data block stored in memory accessible by a service access control system, (b) the data in the first data payload or at least one of the first data block or the second data block is associated with either a user, a service, or a user's access to a service, (ii) acquire a biometric sample through a biometric sample acquisition sensor, and (iii) perform a biometric comparison between the acquired biometric sample and a set of biometric templates stored in the memory of the service point terminal, the set of biometric templates includes at least one user biometric template associated with a user, and (c) the user biometric template (d) The user biometric template or user biometric data is generated based on user biometric data associated with the user, (iv) the user biometric template or user biometric data is received at the service point terminal from the first communication device, (e) the second data payload is transmitted to the service access control system, (f) the data in the second data payload is based on the data in the first data payload, (g) the data in the second data payload enables the service access control system to identify the user based on the output from a calculation including the data in the second data payload and the data in the second data block, and the service access control system is configured to respond to the identification of the user by generating a control signal that permits or records the user's access to the service, the control signal being generated after a positive match determination is generated based on data output from a biometric comparison performed at the service point terminal, the positive match determination being generated in response to the identification of a predefined similarity between the acquired biometric sample and the user biometric template.
[0018] In another embodiment, the present invention provides a first communication device configured to monitor or control a user's access to a service at a service point. The first communication device comprises at least one processor and at least one memory, and is configured to perform the step of (i) transmitting a first data payload to a service point terminal, (a) the data in the first data payload is based on a first data block stored in memory accessible by the communication device, (b) the first data block corresponds to a second data block stored in memory accessible by a service access control system, and (c) at least one of the data in the first data payload or the first data block or the second data block is associated with either a user, a service, or a user's access to a service.
[0019] In this embodiment, the service point terminal is configured to (i) acquire a biometric sample through a biometric sample acquisition sensor, (ii) perform a biometric comparison between the acquired biometric sample and a group of biometric templates stored in the service point terminal memory, the group of biometric templates including at least one user biometric template associated with a user, (a) the user biometric template is generated based on user biometric data associated with the user, (b) the user biometric template or user biometric data is received by the service point terminal from a first communication device, and (iii) transmit a second data payload to a service access control system, (a) the data in the second data payload is based on the data in the first data payload, and (b) the data in the second data payload enables the service access control system to identify a user based on the output from a calculation including the data in the second data payload and the data in the second data block.
[0020] Furthermore, in this embodiment, the service access control system is configured to respond to user identification by generating a control signal that permits or records the user's access to the service based on the results of a calculation, the control signal being generated after a positive match determination is generated based on data output from a biometric comparison performed at the service point terminal, the positive match determination being generated in response to the identification of a predefined similarity between the acquired biometric sample and the user biometric template.
[0021] Furthermore, the present invention provides a service access control system configured to enable secure biometric authentication at a service point terminal in connection with a service provision request to a user. The service access control system comprises at least one server, the at least one server comprising at least one processor and at least one memory, the service access control system is configured to (i) store a second data block in memory accessible by the service access control system, the second data block corresponding to a first data block stored in memory accessible by a first communication device, the first communication device is configured to (a) transmit a first data payload to a service point terminal, (1) the data in the first data payload is based on a first data block, and (2) at least one of the data in the first data payload, the first data block, or the second data block is associated with either a user, a service, or a user's access to a service.
[0022] In this embodiment, the service point terminal is configured to (i) acquire a biometric sample through a biometric sample acquisition sensor, (ii) perform a biometric comparison between the acquired biometric sample and a group of biometric templates stored in the service point terminal memory, the group of biometric templates including at least one user biometric template associated with a user, (a) the user biometric template is generated based on user biometric data associated with the user, (b) the user biometric template or user biometric data is received by the service point terminal from a first communication device, and (iii) transmit a second data payload to a service access control system, (1) the data in the second data payload is based on the data in the first data payload, and (2) the data in the second data payload enables the service access control system to identify a user based on the output from a calculation including the data in the second data payload and the data in the second data block.
[0023] Furthermore, the service access control system is configured to respond to user identification by generating control signals that, based on the results of calculations, permit or record the user's access to the service. These control signals are generated after a positive match determination is generated based on data output from biometric comparison performed at the service point terminal, and the positive match determination is generated in response to the identification of a predefined similarity between the acquired biometric sample and the user biometric template.
[0024] In a specific embodiment of the service access control system, the second data payload is transmitted from the service point terminal to the service access control system in response to a positive match determination obtained as a result of biometric information comparison at the service point terminal, the positive match determination arising from a comparison between the acquired biometric information sample and the user biometric information template.
[0025] In one embodiment, the present invention relates to a computer program product for monitoring or controlling a user's access to services at a service point, the computer program product comprising a non-temporary computer-readable medium having computer-readable program code embodied therein, the computer-readable program code, at a service point terminal on which a processor is implemented, (i) receives a first data payload from a first communication device, (a) the data in the first data payload is based on a first data block stored in memory accessible by the first communication device, the first data block corresponds to a second data block stored in memory accessible by a service access control system, and (b) the data in the first data payload or the first data block or the second data At least one of the blocks is associated with either a user, a service, or a user's access to a service, and includes instructions for performing each step: (ii) acquiring a biometric sample through a biometric sample acquisition sensor; (iii) performing a biometric comparison between the acquired biometric sample and a set of biometric templates stored in the memory of a service point terminal, the set of biometric templates including at least one user biometric template associated with a user; (c) the user biometric template being generated based on user biometric data associated with the user; (d) the user biometric template or user biometric data being received at the service point terminal from a first communication device; and (iv) transmitting a second data payload to the service access control system. The data in the second data payload is based on the data in the first data payload. Furthermore, the data in the second data payload enables the service access control system to identify a user based on the output from a calculation including the data in the second data payload and the data in the second data block.In one embodiment of this method, the service access control system is configured to respond to the identification of a user by generating a control signal that permits or records the user's access to a service, the control signal being generated after a positive match determination is generated based on data output from a biometric information comparison executed at a service point terminal, the positive match determination being generated in response to the identification of a predefined similarity between the acquired biometric information sample and the user biometric information template.
[0026] In another embodiment, the present invention provides a computer program product for monitoring or controlling a user's access to a service at a service point terminal, the computer program product including a non-transitory computer-readable medium having computer-readable program code embodied therein, the computer-readable program code including instructions for performing, at a first communication device implementing a processor, (i) a step of transmitting a first data payload to the service point terminal, (a) the data within the first data payload being based on a first data block stored in a memory accessible by the first communication device, (b) the first data block corresponding to a second data block stored in a memory accessible by a service access control system, and (c) at least one of the data within the first data payload, the first data block, or the second data block being associated with any one of a user, a service, or the user's access to a service.
[0027] In this embodiment, the service point terminal is configured to (i) acquire a biometric sample through a biometric sample acquisition sensor, (ii) perform a biometric comparison between the acquired biometric sample and a group of biometric templates stored in the service point terminal memory, the group of biometric templates including at least one user biometric template associated with a user, (a) the user biometric template is generated based on user biometric data associated with the user, (b) the user biometric template or user biometric data is received by the service point terminal from a first communication device, and (iii) transmit a second data payload to a service access control system, (a) the data in the second data payload is based on the data in the first data payload, and (b) the data in the second data payload enables the service access control system to identify a user based on the output from a calculation including the data in the second data payload and the data in the second data block.
[0028] Furthermore, in this embodiment, the service access control system is configured to respond to user identification by generating a control signal that permits or records the user's access to the service based on the results of a calculation, the control signal being generated after a positive match determination is generated based on data output from a biometric comparison performed at the service point terminal, the positive match determination being generated in response to the identification of a predefined similarity between the acquired biometric sample and the user biometric template.
[0029] In yet another embodiment, the present invention is a computer program product for monitoring or controlling a user's access to services at a service point terminal, the computer program product including a non-transitory computer-readable medium having computer-readable program code embodied therein, the computer-readable program code including, in a service access control system implementing a processor, instructions for performing the steps of: (i) storing a second data block in a memory accessible by the service access control system, the second data block corresponding to a first data block stored in a memory accessible by a first communication device, the first communication device being configured to: (a) transmit a first data payload to the service point terminal, (1) the data in the first data payload being based on the first data block, and (2) at least one of the data in the first data payload or the first data block or the second data block being associated with any one of a user, a service, or the user's access to a service.
[0030] In this embodiment, the service point terminal is configured to (i) acquire a biometric sample through a biometric sample acquisition sensor, (ii) perform a biometric comparison between the acquired biometric sample and a group of biometric templates stored in the service point terminal memory, the group of biometric templates including at least one user biometric template associated with a user, (a) the user biometric template is generated based on user biometric data associated with the user, (b) the user biometric template or user biometric data is received by the service point terminal from a first communication device, and (iii) transmit a second data payload to a service access control system, (1) the data in the second data payload is based on the data in the first data payload, and (2) the data in the second data payload enables the service access control system to identify a user based on the output from a calculation including the data in the second data payload and the data in the second data block.
[0031] The service access control system is further configured to respond to user identification by generating control signals that permit or record the user's access to the service, the control signals being generated after a positive match determination is generated based on data output from biometric comparison performed at the service point terminal, the positive match determination being generated in response to the identification of a predefined similarity between the acquired biometric sample and the user biometric template.
[0032] A computer program product according to the present invention may be configured to perform one or more embodiments of the specific method of the present invention as described in the following specification. [Brief explanation of the drawing]
[0033] [Figure 1] A first embodiment of a system environment in which the present invention can be implemented is shown. [Figure 2]A second embodiment of a system environment in which the present invention can be implemented is shown. [Figure 3] This is a flowchart showing a method for biometric authentication at a service point terminal according to the teachings of the present invention. [Figure 4] This flowchart shows a first embodiment of a specific method step related to the method shown in Figure 3, in which a match determination based on biometric information comparison performed at the service point terminal is performed at the service point terminal. [Figure 5A] This flowchart shows another embodiment of a specific method step related to the method shown in Figure 3, in which a matching determination based on biometric information comparison performed at a service point terminal is generated in the service access control system. [Figure 5B] This flowchart shows the method steps relating to a specific embodiment of the method schematically shown in Figure 3. [Figure 6] An embodiment of a first communication device configured to carry out the teachings of the present invention is shown. [Figure 7] This document describes one embodiment of a service access control system configured to implement the teachings of the present invention. [Figure 8] This figure shows an example of a service point terminal configured to implement the teachings of the present invention. [Figure 9] This is a communication flow diagram illustrating a non-limiting embodiment of an implementation of a method according to the teachings of the present invention. [Figure 10] This is a communication flow diagram illustrating a non-limiting embodiment of an implementation of a method according to the teachings of the present invention. [Figure 11] This document describes an exemplary computer system of a type in which one or more methods, method steps, or features of the present invention may be implemented. [Modes for carrying out the invention]
[0034] This invention relates to the field of personal identification based on biometric information. More specifically, the invention provides methods, systems, and computer program products for monitoring or controlling a user's access to services at a point of service.
[0035] The present invention is implemented within a system environment 100 as shown in Figure 1. The system environment 100 includes a first communication device 102, a service access control system 104, and a service point terminal 106.
[0036] The first communication device 102 may include any processor-based electronic communication device or communication terminal configured to implement data processing functions, network communication functions, and / or wireless communication functions. In various non-limiting embodiments, the first communication device 102 may include any portable computer, tablet computer, phablet, mobile phone, smartphone, personal digital assistant, wearable device (such as a smartwatch, smart glasses, smart lenses, or smart clothing), or any other portable communication device configured to implement data processing functions, network communication functions, and / or wireless communication functions. In one embodiment, the first communication device 102 may be configured according to the device configuration shown in Figure 6. The configuration and functions of the first communication device 102 for carrying out the present invention will be described in further detail below.
[0037] The service access control system 104 may include any processor-based electronic data processing system configured to implement data processing functions and / or network communication functions. In one embodiment, the service access control system 104 includes a server or data processing device implementing at least one processor. In another embodiment, the service access control system 104 includes a server or data processing device implementing multiple processors operating in a network configuration or a distributed computing configuration to implement the functions of the service access control system 104. In one embodiment, the service access control system 104 may be configured according to the device configuration shown in Figure 7. The configuration and functions of the service access control system 104 for carrying out the present invention will be described in further detail below.
[0038] The service point terminal 106 may include any processor-based electronic device or terminal configured to implement data processing functions, biometric information sample acquisition functions, biometric information comparison functions, network communication functions, and / or wireless communication functions. In one embodiment, the service point terminal 106 may implement such functions directly or via one or more peripheral or auxiliary devices coupled to the service point terminal 106 by communication. In various non-limiting embodiments, the service point terminal 106 may include any of the following: a portable computer, tablet computer, phablet, mobile phone, smartphone, personal digital assistant, point-of-sale (POS) terminal, POS kiosk, cash register, electronic door lock, checkpoint device, or gate control device that controls or selectively permits access to restricted access areas (e.g., sporting event venues, flights, vehicle rentals, accommodations, concerts, performances, movies, public transport, etc.). In one embodiment, the service point terminal 106 may be configured according to the device configuration shown in Figure 8. The configuration and functionality of the service point terminal 106 for carrying out the present invention will be described in further detail below.
[0039] Figure 2 shows an alternative embodiment of the system environment 100, which, in addition to the first communication device 102, the service access control system 104, and the service point terminal 106, includes (i) an access point device 108 configured to broadcast radio signals or beacons over a limited range or short distance that the first communication device 102 can receive, (ii) a trusted intermediary platform 110 configured to network communicate with one or both of the first communication device 102 and the service access control system 104, and (iii) an access control device 112 configured to restrict or control access to products or services or locations.
[0040] To implement the solution of the present invention, the service access control system 104 is configured to implement a solution that enables monitoring or controlling user access to services from one or more enterprises, services, or service providers on behalf of such enterprises, services, or service providers, and / or a solution that ensures that only authorized users of such services can access the services. For this purpose, the service access control system 104 is configured to (i) communicate with a first communication device 102 that is associated with or operated by one or more authorized users of such services for the purpose of receiving user requests to access such services, and (ii) communicate with one or more service point terminals 106 located at locations where services are intended to be provided to authorized users for the purpose of determining whether a requester of services present at one or more such service point terminals 106 is actually an authorized user. Each service point terminal 106 may then be configured to communicate with (i) the first communication device 102 and (ii) the service access control system 104.
[0041] In certain embodiments (for example, the embodiment shown in Figure 2), access to the service may be controlled by an access control device 112. The access control device 112 may be integrated into the service point terminal 106 or it may be separate from the service point terminal 106. In embodiments where access to the service is controlled by the access control device 112, the service access control system 104 may be configured to communicate with the access control device 112 over a network, and may also be configured to send control signals to the access control device 112 for the purpose of selectively enabling or disabling access to the service via the access control device 112. In one embodiment, the functions of the access control device may be performed manually by a person, such as a security guard or immigration officer, who can physically prevent access to the user.
[0042] In other embodiments where the access control device 112 is integrated within the service point terminal 106, or where the service point terminal 106 is configured to perform the functions of the access control device 112, the service access control system 104 may be configured to send control signals to the service point terminal 106 for the purpose of selectively enabling or disabling access to services via the service point terminal 106. In yet another embodiment, the service access control system 104 is integrated within the service point terminal 106, or alternatively, the service point terminal 106 is configured to perform the functions of the service access control system 104, and in such an embodiment, the service access control system 104 may be configured to internally send control signals within the service point terminal 106 for the purpose of selectively enabling or disabling access to services via the service point terminal 106. In embodiments where the service point terminal 106 software and the service access control system 104 software run on the same processor, the software is isolated from each other, for example, running in separate processes and / or separate containers, so that biometric data is inaccessible from the service access control system 104. For example, a service access control system could simply display the user's passport details on a screen, allowing security personnel or immigration officers to verify and compare them to the user's name on their boarding pass, and then physically grant or deny access to the security checkpoint.
[0043] For the purposes of the present invention, a regular user has an existing user account or user ID generated and / or stored by the relevant company, service, service provider, or its agent or affiliate. A user may register for a user account using a username and password, and / or provide strong personal authentication information such as a driver's license, home address, or social security number. The company may have used personal authentication technology to verify the personal authentication information. In one embodiment, information corresponding to a regular user, user account, or user ID is stored in a database associated with the relevant company, service, or service provider, which may be accessible by the service access control system 104. In another embodiment, a user may provide account information or service information when using the service. For example, a user may provide a boarding pass with their name and flight details when accessing the service.
[0044] Each authorized user configures (or provisions) a first communication device 102 owned, controlled, or operated by the authorized user, or associated with the authorized user, to enable secure biometric authentication of the user at one or more service point terminals 106. In one embodiment, configuring or provisioning (preparing) the first communication device 102 includes downloading application software associated with the relevant enterprise, service, service provider, or service access control system 104 to the first communication device 102.
[0045] In a further embodiment, the application software may require the user to provide consent to access a company or service at one or more service point terminals 106. The configuration and / or provisioning of the first communication device 102 may further include the user registering one or more biometric information corresponding to the user with the first communication device 102. The registered biometric information is stored in the memory of the first communication device 102 as encrypted or unencrypted biometric information templates. The registered biometric information may be obtained from the user through a live biometric information capture process performed using one or more sensors integrated into or coupled to the first communication device 102. In another embodiment, the registered biometric information may be read from a file, received through an application programming interface (API), received from a biometric information database maintained by a third party, extracted from a photograph encoded as a QR code (registered trademark), extracted from a photograph of a photo ID document (such as a driver's license or passport), or read from an NFC chip on an ID document such as a biometric passport. In certain embodiments, biometric data may be registered as a biometric template valid for the purpose of carrying out the present invention only after the biometric data has been authenticated or verified (for example, after the acquired biometric data has been verified against a government-issued photo ID or a third-party ID), or only after the biometric data has been verified by a company or service provider.
[0046] Provisioning the first communication device 102 further includes storing a first data block in memory accessible by the first communication device 102, and storing a second data block in memory accessible by the service access control system 104, where the first data block corresponds to the second data block. At least one of the first or second data block is associated with a user, or a request from a user, or a request from the first communication device 102, for accessing or receiving one or more services.
[0047] The correspondence between the first data block and the second data block can be defined by one or more predefined sets of functions. In various embodiments, (i) the first data block is generated based on data in a data payload received by the first communication device 102 from the service access control system 104 or a trusted intermediary; (ii) the second data block is generated based on data in a data payload received by the service access control system 104 from the first communication device 102 or a trusted intermediary; (iii) each of the first and second data blocks contains a set of data included in the other of the first and second data blocks; (iv) the first and second data blocks are identical; (v) one of the first and second data blocks is derived from the other of the first and second data blocks; or (vi) each of the first and second data blocks is generated based on at least one of a common shared secret data block or a common key derivation function. In various embodiments, one or both of the first and second data blocks may include or be derived from user biometric data or data derived from user biometric data, a digital token or digital key assigned to the user, or any data records associated with the user, such as the user's email address, telephone number, customer number, reservation number, flight number, seat number, order number, driver's license details, passport details, date of birth, social security number, bank account details, credit / debit card details, etc. In one embodiment, one or both of the first and second data blocks may include a user biometric template or a cryptographic hash of user biometric data. In one embodiment, data from the first data block or the second data block, or data from both data blocks, may be manually entered into the system by keying the data using a keyboard or other input method.
[0048] In one embodiment, both the first data block and the second data block are generated by the first communication device 102, the first data block is stored in the memory of the first communication device 102 (or in memory accessible by the first communication device 102), and the second data block is transmitted from the first communication device 102 to the service access control system 104, and the second data block is stored in memory accessible by the service access control system 104.
[0049] In another embodiment, both the first and second data blocks are generated by the service access control system 104, the second data block is stored in memory accessible by the service access control system 104, the first data block is transmitted from the service access control system 104 to the first communication device 102, and the first data block is stored in the memory of the first communication device 102 (or in memory accessible by the first communication device 102).
[0050] In another embodiment, the first data block is generated by the first communication device 102 and stored in the memory of the first communication device 102 (or memory accessible by the first communication device 102), and the second data block is generated by the service access control system 104 and stored in memory accessible by the service access control system 104. Here, each of the first and second data blocks is generated using a shared secret or a shared secret algorithm.
[0051] In another embodiment, at least one of the first data block and the second data block is generated by a trusted intermediary platform 110 implementing a processor. In an embodiment where the first data block is generated by the trusted intermediary platform 110 implementing a processor, the first data block is transmitted to a first communication device 102 and stored in the memory of the first communication device 102 (or memory accessible by the first communication device 102). In an embodiment where the second data block is generated by the trusted intermediary platform 110 implementing a processor, the second data block is transmitted to a service access control system 104 and stored in memory accessible by the service access control system 104.
[0052] In certain embodiments, one or both of the first and second data blocks may be generated and stored in the first communication device 102 and the service access control system 104, respectively, in response to a request initiated by the first communication device 102 for access to a particular service or a particular instance of a service. In other embodiments, one or both of the first and second data blocks may be associated with a user of the first communication device 102, or a particular user access, or a user request for access to a particular service or a particular instance of a service.
[0053] In one embodiment, a first data block is generated based on data in a data payload received by the first communication device 102 from the service access control system 104 or a trusted intermediary. In another embodiment, a second data block is generated based on data in a data payload received by the service access control system 104 from the first communication device 102 or a trusted intermediary.
[0054] The first communication device 102 may be configured to receive radio signals based on one or more wireless communication protocols or standards, such as cellular communication protocols (e.g., GSM®, CDMA, EDGE, 3G, LTE, 4G, or 5G), Wi-Fi®, Bluetooth®, Bluetooth Low Energy®, NFC (Near Field Communication), IoT (Internet of Things), ultra-wideband, or RFID (Radio Frequency Identification) communication protocols.
[0055] In one embodiment, the first communication device 102 may be configured to initiate the transmission of a first data payload to a service point terminal 106 in response to the detection of a trigger event, the first data payload comprising data based on a first data block stored in the memory of the first communication device 102 (or memory accessible by the first communication device 102). For the purposes of the present invention, the “first data payload” may include any portion of data or one or more data packets transmitted from the first communication device 102 to the service point terminal 106, except for data included solely to enable the delivery of transmission data or data packets.
[0056] In one embodiment, a trigger event detected by the first communication device 102 (i.e., the detected trigger event triggers the commencement of transmission of a first data payload to the service point terminal 106) may include the first communication device 102 receiving a predefined radio signal (e.g., a beacon signal) transmitted from the service point terminal 106 or from the access point device 108. In other embodiments, a trigger event detected by the first communication device 102 may include (i) a triggered time-based alarm or alert, (ii) a triggered location-based alarm or alert, or (iii) a notification or signal received from the service access control system 104. In one embodiment, the first communication device 102 transmits a first data payload in response to (i) the first communication device 102 entering a zone (or a predefined neighborhood) near the service point terminal 106 (the distance between the first communication device and the service point terminal is between 1 meter and 1000 meters), (ii) the first communication device 102 receiving a radio signal transmitted from the service point terminal 106 or a radio signal transmitted from an access point device 108 that is communicated with the service point terminal 106, or (iii) a time alarm, location alarm, or notification generated within the first communication device 102 or received from the service access control system 104.
[0057] In one embodiment, following the detection of a trigger event, the first communication device 102 begins transmitting a first data payload to a destination network address. The destination network address is received by the first communication device within one or more data packets received from a service point terminal 106 or access point device 108. The destination network address may include the network address of the service point terminal 106 or access point device 108.
[0058] In one embodiment, the first data payload may be associated with a user of the first communication device 102, or a user request for access to a specific user, or to a specific service or a specific instance of a service.
[0059] The service point terminal 106 is configured to receive data from one or more user communication devices, and such data can be stored in memory accessible from the service point terminal 106. The data received by the service point terminal 106 may include data transmitted by the first communication device 102 in response to the detection of a trigger event (e.g., a first data payload), and any biometric data associated with a legitimate user or operator of the first communication device 102. In an embodiment, the biometric data associated with a legitimate user or operator of the first communication device 102 is included in the first data payload transmitted by the first communication device 102 in response to the detection of a trigger event.
[0060] In one embodiment, the service point terminal 106 may be integrated with the access point device 108 or be coupled to the access point device 108 in a way that allows communication with it.
[0061] Furthermore, the service point terminal 106 is configured to acquire one or more biometric samples associated with an individual or object through one or more sensors integrated within or coupled to the service point terminal 106. In one embodiment, one or more sensors are configured and positioned to acquire at least one biometric sample of an individual or object present in a biometric sampling zone or biometric capture area associated with the service point terminal 106. Furthermore, the service point terminal 106 performs or executes biometric comparisons between (i) the acquired one or more biometric samples associated with an individual or object present in the biometric capture area and (ii) a set of biometric templates stored in a memory accessible by the service point terminal 106. The service point terminal 106 may implement strategies to reduce the number of comparisons performed between the acquired one or more biometric samples and the set of biometric templates stored in a memory accessible by the service point terminal 106. Exemplary strategies may include, for example, reducing the number of sets by checking the distance of a first communication device from the service point terminal 106 by measuring the signal strength of a wireless communication signal. Another exemplary strategy is to stop the comparison process when a match is found, or to reduce the number of comparisons using other filtering techniques. The set of biometric templates stored in memory accessible by the service point terminal 106 includes biometric templates transmitted by one or more first communication devices 102.
[0062] In one embodiment, at least one of the biometric templates transmitted by the first communication device 102 is generated based on user biometric data associated with the user or operator of the first communication device 102. In one embodiment, the user biometric template or user biometric data is transmitted from the first communication device 102 to the service point terminal 106 in response to the detection of a trigger event (of the type described above) by the first communication device 102. In one embodiment, the user biometric data is transmitted from the first communication device 102, used by the service point terminal 106, and generates a user biometric template. The user biometric template is stored in a group of biometric templates in memory accessible by the service point terminal 106. In another embodiment, the user biometric template is transmitted from the first communication device 102 to the service point terminal 106. The user biometric template or user biometric data may be transmitted from the first communication device 102 to the service point terminal 106 in response to a detected trigger event (e.g., a trigger event of the type described above). In one embodiment, the group of biometric templates stored in the memory of the service point terminal 106 includes at least one additional biometric template that is different from the user biometric template. In one embodiment, the additional biometric template is generated based on additional biometric data that is different from the user biometric data. In a more specific embodiment, the additional biometric template or additional biometric data is received by the service point terminal 106 from a second communication device, which is different from the first communication device 102 from which the user biometric template associated with the user is received.
[0063] In a specific embodiment of the present invention, the data in the first data payload (based on a first data block and transmitted from the first communication device 102 to the service point terminal 106) includes a user biometric template or user biometric data received by the service point terminal 106 from the first communication device 102. In another embodiment of the present invention, the first data payload includes (i) data based on a first data block and (ii) a user biometric template or user biometric data received by the service point terminal from the first communication device 102. In yet another embodiment of the present invention, the user biometric template or user biometric data is transmitted from the first communication device 102 to the service point terminal 106 in an additional data payload different from the first data payload.
[0064] In one embodiment, the service point terminal 106 may be configured to check the validity, authenticity, or impersonation of acquired biometric data samples to eliminate any fraudulent attempts to circumvent one or more biometric security systems. In an embodiment, the service point terminal 106 may be configured to compare the acquired biometric data sample with a set of biometric templates stored in the service point terminal 106's memory, the set of biometric templates including biometric data of individuals prohibited from accessing the service ("negative list"), and to generate a signal when a positive match is found, which is used to issue a warning or to prevent fraudulent attempts by previously known unauthorized persons to circumvent one or more biometric security systems. In this embodiment, the biometric templates in the negative list are different from the biometric templates of one or more legitimate users received from the first communication device 102.
[0065] Furthermore, the service point terminal 106 is configured to transmit a second data payload to the service access control system 104, and the data in the second data payload is based on the data in the first data payload. In one embodiment, the data in the second data payload is identical to the data in the first data payload. In another embodiment, the data in the second data payload is data extracted from the data in the first data payload. In another embodiment, the data in the second data payload is output from an implemented data processing function that receives the data in the first data payload as input. For the purposes of the present invention, the “second data payload” may include any portion of the data or one or more data packets transmitted from the service point terminal 106 to the service access control system 104, except for data included solely to enable the delivery of the transmission data or data packets.
[0066] In one embodiment, the service point terminal 106 transmits a second data payload to the service access control system 104 in response to a positive match determination being made as a result of biometric information comparison. As a result, the service access control system 104 signals to the service access control system 104 that the result of the biometric information comparison was positive and that the data in the received second data payload corresponds to the data in the first data payload (and therefore the data in the first data block) that the first data block is (i) associated with a user whose biometric identification led to a positive match determination, or (ii) associated with a user request for access to a particular user access, or to a particular service or a particular instance of a service. In this embodiment, the service point terminal 106 generates a match determination itself (i.e., a positive match determination or a negative match determination) based on the output from the biometric information comparison, or initiates the generation of a match determination at another device and receives the match determination from that device.
[0067] In an alternative embodiment, the service point terminal 106 transmits to the service access control system 104 the output of each biometric comparison between (i) each acquired biometric sample associated with an individual or object present in the biometric information capture area and (ii) each biometric template in a group or subset of biometric templates stored in memory accessible by the service point terminal 106. For each transmitted output of a biometric comparison, the service point terminal 106 generates and transmits a corresponding second data payload to the service access control system 104. The data in the second data payload is based on the data in the first data payload associated with the specific biometric template received by the service point terminal 106 and compared with the acquired biometric sample. In other words, the data in the second data payload corresponding to the transmitted output of a biometric comparison is based on the data in the first data payload received (from the first communication device 102 at the service point terminal 106) together with, or in correspondence with, the biometric template used as input for a biometric comparison between the biometric template and a biometric sample acquired or captured at the service point terminal 106.
[0068] As a result, in this embodiment, for each biometric sample acquired by the service point terminal 106, the service point terminal 106 transmits to the service access control system 104: (i) a set of biometric comparison outputs, including individual outputs resulting from each comparison between the acquired biometric sample and each of the biometric templates in the group or subset of biometric templates stored in memory accessible by the service point terminal 106; and (ii) for each individual output of the biometric comparison transmitted to the service access control system 104, a second data payload, including data based on the data in a first data payload associated with the biometric template used as input to the biometric comparison that produced the individual output. In this embodiment, the service access control system 104 either generates a match determination (i.e., a positive match determination or a negative match determination) based on the set of outputs from the biometric comparison received from the service point terminal 106, or initiates the generation of a match determination at another device and receives the match determination from that device based on the set of outputs from the biometric comparison received from the service point terminal 106.
[0069] In addition to the above, in certain embodiments, the service point terminal 106 may have an access control device 112 built-in or coupled with an access control device 112, which may be configured to restrict or control access to products, services, or locations. In such embodiments, the service point terminal is configured to receive a control signal from the service access control system 104 that allows a user access to products, services, or locations restricted by the access control device 112, thereby causing or initiating the operation of the access control device 112 to allow the user access to products, services, or locations.
[0070] In various non-limiting embodiments, the access control device 112 may include any of the following: a portable computer, tablet computer, phablet, mobile phone, smartphone, personal digital assistant, POS terminal, POS kiosk, cash register, vending machine or vending cabinet, electronic door lock, checkpoint device, security barrier, or gate control device that controls or selectively permits access of authorized individuals to an access-restricted area (e.g., a sporting event venue, flight, vehicle rental, accommodation, concert, performance, movie, public transport, etc.).
[0071] The service access control system 104 is configured to receive at least one second data payload transmitted by the service point terminal 106 and to perform a calculation involving the data in the second data payload and a second data block stored in memory accessible by the service access control system 104, the calculation may include comparison, addition, subtraction, multiplication, division, or other calculation functions such as encryption, decryption, or encryption functions, or combinations thereof. If a determination is made (based on the output of the calculation) that a correlation exists between the second data payload and the second data block, it can be concluded that the second data payload was generated based on the data in the first data block corresponding to the second data block (because the second data payload is generated based on the first data payload which was generated based on the first data block). Furthermore, by confirming that the second data payload corresponds to (or is related to) the biometric information comparison that led to the positive match determination, the service access control system 104 can conclude that the user whose acquired biometric information led to the positive match determination is indeed a legitimate user who can use the service that is access-controlled by the service point terminal 106.
[0072] Accordingly, the service access control system 104 is configured to respond to (i) a determination that a correlation has been identified between the second data payload and the second data block, based on the output of a calculation using the data in the received second data payload and the second data block stored in a memory accessible to the service access control system 104, and (ii) a determination that the second data payload corresponds to (or is associated with) a biometric comparison that has resulted in a positive match, by generating a control signal to permit or record access of a user whose acquired biometric information has resulted in a positive match to a product, service, or location controlled or restricted by the service point terminal 106 and / or access control device 112, thereby responding to (i) a determination that a correlation has been identified between the second data payload and the second data block, based on the output of a calculation using the data in the received second data payload and the second data block stored in a memory accessible to the service access control system 104, and (ii) a determination that the second data payload corresponds to (or is associated with) a biometric comparison that has resulted in a positive match. The service access control system 104 may be configured to transmit the control signal to the service point terminal 106 and / or access control device 112.
[0073] As described above, in one embodiment of the present invention, the service point terminal 106 transmits a second data payload to the service access control system 104 only if a positive match is determined as a result of the biometric information comparison. Consequently, in this embodiment, the service access control system 104 is configured to respond to the receipt of the second data payload from the service point terminal 106 by generating and transmitting a control signal to the service point terminal 106 and / or the access control device 112.
[0074] As described above, in an alternative embodiment, for each biometric sample acquired by the service point terminal 106, the service point terminal 106 and / or access control device 112 transmit to the service access control system 104: (i) a set of biometric comparison outputs, each including an individual output resulting from each comparison between the acquired biometric sample and each of the biometric templates in the group of biometric templates stored in memory accessible by the service point terminal 106; and (ii) for each individual output of the biometric comparison transmitted to the service access control system 104, a second data payload, each including data based on the data in a first data payload associated with the biometric template used as input to the biometric comparison that resulted in the individual output.
[0075] In this embodiment, the service access control system 104 is configured to respond to (i) a determination that a correlation has been identified between the second data payload and the second data block, based on the output of a calculation using the data in the received second data payload and the second data block stored in a memory accessible to the service access control system 104, and (ii) a determination that the second data payload corresponds to (or is associated with) a biometric comparison that has resulted in a positive match, by generating a control signal that permits or records access to a product, service, or location controlled or restricted by the service point terminal 106 and / or the access control device 112, for users whose acquired biometric information has resulted in a positive match.
[0076] Figure 3 is a flowchart illustrating a method for monitoring or controlling a user's access to services at a service point terminal, according to the teachings of the present invention. The method of Figure 3 can be implemented within a system environment 100 as shown in Figures 1 and / or 2. In one embodiment, the system elements of the system environment 100 may be configured according to the description of the system elements provided above. In a particular embodiment, the first communication device 102, the service point terminal 106, and the service access control system 104 may be configured according to one or more embodiments of the present invention described above.
[0077] The method in Figure 3 begins in step 302, which includes detecting a trigger event in the first communication device 102. A trigger event is an event that the first communication device 102 is configured to recognize as a signal to initiate the transmission of registered biometric data (e.g., biometric template) associated with a legitimate user or operator of the first communication device 102 from the first communication device 102 to the service point terminal 106.
[0078] In one embodiment, a trigger event detected by the first communication device 102 may include the first communication device receiving a predefined radio signal (e.g., a beacon signal) transmitted from a service point terminal 106 or access point device 108. In another embodiment, a trigger event detected by the first communication device 102 may include any of the following: (i) a triggered time-based alarm or alert; (ii) a triggered location-based alarm or alert; or (iii) a notice or signal received from a service access control system 104; or (iv) the first communication device 102 entering a zone near (or within the physical vicinity of) the service point terminal 106, i.e., the distance between the first communication device 102 and the service point terminal 106 is in the range of 1 meter to 1000 meters.
[0079] In step 304, following the detection of a trigger event, the first communication device 102 transmits a first data payload associated with a request to provide a service to the user to the service point terminal 106. The data in the first data payload is based on a first data block stored in the memory of the first communication device 102 (or memory accessible by the first communication device 102), the first data block corresponding to a second data block stored in memory accessible by the service access control system 104.
[0080] Furthermore, the first communication device 102 transmits a user biometric template or user biometric data associated with the user or operator of the first communication device 102 to the service point terminal 106. In one embodiment, the user biometric template or user biometric data is retrieved from the memory of the first communication device 102 and transmitted to the service point terminal 106.
[0081] In a specific embodiment of step 304 of this method, the data in the first data payload (transmitted from the first communication device 102 to the service point terminal 106 based on the first data block) includes a user biometric template or user biometric data. In another embodiment, the first data payload transmitted in step 304 includes (i) data based on the first data block, and (ii) a user biometric template or user biometric data. In yet another embodiment, in addition to transmitting the first data payload, step 304 further includes transmitting the user biometric template or user biometric data from the first communication device 102 to the service point terminal 106 in an additional data payload different from the first data payload.
[0082] In one embodiment of step 304, when the first communication device 102 transmits user biometric data to the service point terminal 106, the service point terminal 106 may generate a user biometric template based on the received user biometric data and store the user biometric template in a group of biometric templates in memory accessible by the service point terminal 106.
[0083] Step 306 includes initiating or performing at the service point terminal 106 a step of acquiring a biometric sample of a user via one or more biometric sample acquisition sensors that are controlled by the service point terminal 106, coupled to the service point terminal 106, or integrated within the service point terminal 106. In one embodiment, one or more biometric sample acquisition sensors are configured and positioned to acquire at least one biometric sample of an individual or object present in a biometric sampling zone or biometric capture area associated with the service point terminal 106.
[0084] Step 308 includes performing a biometric comparison between the acquired biometric sample and a set of biometric templates stored in the service point terminal memory, the set of biometric templates including at least one user biometric template associated with a user (either transmitted to the service point terminal 106 in accordance with the teachings of step 304 or generated by the service point terminal 106). In one embodiment, the set of biometric templates stored in memory accessible by the service point terminal 106 includes biometric templates transmitted by one or more user communication devices and / or biometric templates generated based on biometric data transmitted by one or more user communication devices. The biometric comparison may include a comparison based on one or more biometric comparison methods or algorithms and may produce encrypted or decrypted biometric comparison results or biometric comparison outputs as output. The biometric comparison may be performed or initiated by the service point terminal 106. In one embodiment, the set of biometric templates stored in the memory of the service point terminal 106 includes at least one additional biometric template different from the user biometric template. In one embodiment, the additional biometric template is generated based on additional biometric data different from the user biometric data. In a more specific embodiment, additional biometric templates or additional biometric data are received by the service point terminal 106 from a second communication device, which is different from the first communication device 102 from which user biometric templates associated with the user are received.
[0085] Step 310 includes transmitting a second data payload from the service point terminal 106 to the service access control system 104, wherein the data in the second data payload is based on the data in the first data payload. In one embodiment, the data in the second data payload is identical to the data in the first data payload. In another embodiment, the data in the second data payload is data extracted from the data in the first data payload. In yet another embodiment, the data in the second data payload is output from an implemented data processing function that has received the data in the first data payload as input.
[0086] Step 312 of the method includes the service access control system 104 generating a control signal that permits the provision of a service to a user, or recording user access to a service, wherein (i) the control signal is generated following a positive match determination based on the data output of a biometric comparison, and (ii) the control signal is generated in response to the output of a data calculation that results in the identification of a user (or a service to a user) by correctly identifying a correlation or correspondence between a second data payload and data in a second data block. In one embodiment, the control signal is transmitted from the service access control system 104 to a service point terminal 106 and / or an access control device 112.
[0087] In one embodiment of the method shown in Figure 3, the service point terminal 106 is configured to perform a biometric information comparison step and a step of generating (or receiving from another device) a match determination based on the results of the biometric information comparison. In a more specific embodiment, the service point terminal is configured such that each second data payload transmitted from the service point terminal 106 to the service access control system 104 in step 310 is a second data payload generated based on a first data payload, the first data payload being transmitted from a first communication device 102, which also transmitted a user biometric information template in step 304, the transmitted user biometric information template generating a positive match determination when compared with the biometric information sample acquired in step 306.
[0088] Figure 4 is a flowchart illustrating specific method steps related to this embodiment, in which a match determination based on biometric information comparison performed at the service point terminal 106 is generated at the service point terminal 106. In one embodiment, the method steps of Figure 4 may be carried out in a specific embodiment of steps 308 to 312 of the method of Figure 3.
[0089] In step 402, following or as part of the biometric comparison in step 308, the service point terminal 106 generates a biometric match determination based on the biometric comparison performed at the service point terminal 106. The biometric match determination may include either a positive match determination (i.e., the acquired biometric sample is considered sufficiently similar when compared to at least one biometric template in the biometric template set) or a negative match determination (i.e., the acquired biometric sample is considered sufficiently different from all biometric templates in the biometric template set).
[0090] In step 404, in response that the biometric matching determination includes a positive matching determination, the service point terminal 106 transmits a second data payload from the service point terminal to the service access control system (as described in method step 310).
[0091] The method shown in Figure 3 can then proceed to the implementation of step 312.
[0092] In an alternative embodiment of the method in Figure 3, the service point terminal 106 is configured to perform or initiate a biometric comparison step and to transfer the output from each biometric comparison, regardless of (or regardless of) whether the result of the biometric comparison is a positive match. In this embodiment, the output corresponding to all biometric comparisons between the acquired biometric sample and a biometric template stored in a memory accessible to the service point terminal 106 is transmitted in step 310 from the service point terminal 106 to the service access control system 104, along with a separate second data payload corresponding to each of the comparisons. Each of these separate second data payloads is generated based on a first data payload transmitted in step 304 from a separate first communication device 102, which also transmitted the specific user biometric template used as input to the comparison in step 306. In this embodiment, the match determination corresponding to each transferred biometric comparison output is performed or implemented by the service access control system 104. In response to a positive match determination, the service access control system 104 analyzes or processes the second data payload transmitted together with or associated with the biometric comparison output (which led to the positive match determination) (or performs data calculations involving the second data payload) to identify a correlation or correspondence between the second data payload and the data in the second data block stored in memory accessible from the service access control system 104.
[0093] Figure 5A is a flowchart illustrating specific method steps related to this alternative embodiment, in which a match determination based on biometric information comparison performed at the service point terminal 106 is generated or initiated at the service access control system 104. In one embodiment, the method steps of Figure 5A may be carried out in specific embodiments of steps 308 to 312 of the method of Figure 3.
[0094] Step 502 includes transmitting encrypted or unencrypted data output from the biometric comparison performed in step 308 to the service access control system 104 from the service point terminal 106. In a particular embodiment, individual outputs corresponding to all biometric comparisons performed in step 308 between the acquired biometric sample and a biometric template stored in memory accessible by the service point terminal 106 are transmitted in step 310 from the service point terminal 106 to the service access control system 104, along with a second data payload corresponding to each transmitted biometric comparison. Such a second data payload is generated based on the first data payload transmitted in step 304 from the first communication device 102, which also transmitted the user biometric template used as input for the comparison in step 306.
[0095] For each encrypted or unencrypted data output transferred in step 502, step 504 includes the service access control system 104 generating a biometric matching determination based on the encrypted or unencrypted data output. In a particular embodiment where the biometric matching determination is generated based on encrypted data, the encrypted data may be decrypted first, and the generated biometric matching determination may be based on the decrypted data. In other embodiments, the biometric matching determination may be based on encrypted data without requiring the data to be decrypted first.
[0096] In step 506, in response to the biometric matching determination (in step 504) including a positive matching determination, the service access control system 104 identifies a second data payload from the data payload received from the service point terminal 106 that was transmitted to the service access control system 104 (from the service point terminal 106) together with or in association with the biometric comparison data that led to the positive matching determination. The service access control system 104 then analyzes or processes the identified second data payload (or performs a data calculation including the identified second data payload) to identify a correlation or correspondence between the second data payload and data in a second data block stored in memory accessible to the service access control system 104. Once a correlated or corresponding second data block is identified, the service access control system 104 identifies a user or user request for one or more services associated with the identified second data block. Identifying this user or user request for one or more services is possible because, as described above, when provisioning the first communication device 102 and / or the service access control system 104, at least one of the second data blocks or corresponding first data blocks provisioned to the service access control system 104 and the first communication device 102, respectively, is associated with the user or a request from the user or a request from the first communication device 102 to access or receive one or more services. Therefore, by identifying the second data block correlated with the positive match determination generated by the service access control system 104, it is possible to correlate the positive match determination with a user request for one or more services, and as a result of the positive match determination, it is also possible to confirm that the user who generated the user request actually exists at the service point terminal 106.Therefore, as a result of the above implementation, the service access control system 104 can generate a control signal in step 312 (of the method in Figure 3) that permits the provision of the requested service to the user, and can transmit this control signal to the service point terminal 106, or alternatively to the access control device 112.
[0097] The following details of embodiments of the present invention will be described in reference to Figures 1 to 5A.
[0098] In one embodiment, a first data payload generated by the first communication device 102 includes a current timestamp (t). The service access control system 104 extracts data from the transmitted second data payload and determines whether the value of the timestamp (t) is within a predefined acceptable time interval from the time the user of the first communication device 102 initiated a request for access to the service in response to a trigger event. The service access control system 104 generates a control signal that permits the provision of service to the user, provided that the value of the timestamp (t) is within the predefined acceptable time interval.
[0099] In one embodiment, the data in the first data payload may be encrypted using an asymmetric encryption algorithm with encryption key K1. The service access control system 104 extracts data from the transmitted second data payload, decrypts the data with encryption key K2, and uses this data to generate a control signal that identifies the user and / or authorizes the provision of services to the user. In one embodiment, a corresponding pair of asymmetric encryption algorithm keys K1 and K2 can be shared between the service access control system 104 and the first communication device 102. In one embodiment, K1 may be a public key and K2 a private key. In another embodiment, K1 may be a private key and K2 a public key.
[0100] In one embodiment, a symmetric encryption key K is shared between the service access control system 104 and the first communication device 102. In one embodiment, the data of the first data payload is encrypted using an asymmetric encryption algorithm with the encryption key K. The service access control system 104 extracts data from the transmitted second data payload, decrypts the data using the encryption key K, and uses this data to identify the user and / or as a condition for generating a control signal that permits the provision of services to the user.
[0101] In one embodiment, a user of the first communication device 102 provisions the first communication device 102 with a document security object (SOD), a data group 1 (DG1) data object, and a data group 2 (DG2) data object corresponding to the user's passport or ID card by communicating with the NFC chip in the biometric passport or ID card and receiving data objects from the NFC chip.
[0102] In one embodiment, the service point terminal 106 receives the DG2 data object and SOD as part of a first data payload and uses the SOD to check the authenticity of the biometric data contained in the DG2 data object as a condition for performing biometric comparison and / or as a condition for allowing the user to provide the requested service.
[0103] In another embodiment, the service point terminal 106 receives a DG2 data object in a first data payload and transmits a hash of the DG2 as part of a second data payload. The service access control system 104 stores the hash of the DG2 from the SOD as part of a second data block and compares it with the hash of the DG2 received in the second data payload. Equality of the two hashes is used as a condition to allow the requested service to be provided to the user.
[0104] In one embodiment, the service access control system 104 uses SOD to determine the authenticity of the data contained in the DG1 data object as a condition for allowing the requested service to be provided to the user.
[0105] In one embodiment, the service access control system 104 or the biometric matching controller 822 can access a secret key SK for homomorphic encryption, and the first communication device 102 can access the corresponding public key PK. The first communication device 102 uses the public key PK to homomorphically encrypt the biometric template and includes it in the first data payload for transmission. In step 308, the service point terminal 106 performs a biometric comparison in the encrypted domain. In step 504, the service access control system 104 or the biometric matching controller 822 homomorphically decrypts the biometric comparison result and uses it to generate a match / mismatch determination.
[0106] In one embodiment, in addition to the homomorphically encrypted biometric template, the service point terminal 106 also receives a corresponding DG2 data object encrypted with a symmetric key as part of the first data payload. If a positive match determination is made in step 504 for the biometric template, the service point terminal gains access to the corresponding symmetric key, decrypts the corresponding DG2 data object, and checks the authenticity of the corresponding biometric data contained in the DG2 data object. If a positive match determination is not made in step 504, the corresponding symmetric key is inaccessible to the service point terminal 106 (i.e., it cannot be accessed). Furthermore, the service point terminal 106 checks whether the biometric data in the DG2 data object is from the same person from whom the live biometric sample led to a positive match determination. In one embodiment, this check succeeds (or returns a positive result) only if a positive match determination is made as a result of a second biometric comparison between the live biometric sample and the biometric data from the DG2 data object. In another embodiment, this check succeeds (or returns a positive result) only if a positive match is determined as a result of the third biometric comparison between the biometric data from the DG2 data object and the corresponding homomorphically encrypted biometric template. In this case, the biometric match determination controller 822 homomorphically decrypts the biometric comparison result. In another embodiment, the check succeeds or fails based on the combination of the second and third biometric comparison results.
[0107] In one embodiment, a symmetric key is generated by the first communication device 102, encrypted with the public key of the biometric matching controller, decrypted by the biometric matching controller 822, and transmitted to the service point terminal 106 in response to a positive match determination. In another embodiment, a shared symmetric key is established between the first communication device 102 and the biometric matching controller 822 using a secure key exchange algorithm. First exemplary embodiment
[0108] A first exemplary embodiment of the present invention, more generally described in relation to Figures 1 to 5A, is as follows: In this embodiment, implementation begins with a user of a first communication device 102 initiating a request for access to or reception of a service whose access is controlled by a service access control system 104. A secure communication session (e.g., via the HTTPS protocol) is established between the first communication device 102 and the service access control system 104. Within the secure communication session, the service access control system 104 authenticates the identity of the requesting user, and upon successful authentication of the user, the first communication device 102 is provisioned with a first data block, and the service access control system 104 (or memory accessible by the service access control system 104) is provided with a second data block. The first data block corresponds to the second data block, and the correspondence between the first and second data blocks is defined by one or more predefined sets of functions. For example, both the first and second data blocks are equal to a secure random number X associated with the user account.
[0109] The first communication device 102 is provisioned with registered biometric information corresponding to the user, or has already been provisioned, and the registered biometric information is stored in the memory of the first communication device 102 as a biometric information template.
[0110] If the first communication device 102 is within a defined physical proximity range (e.g., within a positional radius of 1000 meters) of a service point terminal 106 that can access the requested service, the first communication device 106 establishes a secure communication session with the service point terminal 106. The first communication device 102 can determine that it is within the defined physical proximity range in any variety of ways, such as based on GPS data or based on the reception of a near-range beacon signal from the service point terminal 106 or an access point device 108 located in a defined vicinity of the service point terminal 106.
[0111] The first communication device 102 can authenticate the service point terminal 106 and confirm that the service point terminal 106 is a terminal that has the authority to provide the requested service or to control access to the requested service.
[0112] The first communication device 102 generates a first data payload containing a first data block (x) and a cryptographic hash of the current timestamp (t), i.e., H(x,t). The first data payload and a biometric template corresponding to the user are transmitted from the first communication device 102 to the service point terminal 106. The biometric template may be transmitted from the first communication device 102 within the first data payload or within an additional data payload. The service point terminal 106 may then be configured to discard the received biometric template and / or the corresponding first data payload after a predetermined time interval (e.g., 1 hour) from the time they were received from the first communication device 102.
[0113] Subsequently, the service point terminal 106 collects a live biometric sample from the user while the user is in the biometric sampling zone or biometric capture area associated with the service point terminal 106. The live biometric sample is compared with biometric template data received by the service point terminal 106 from one or more user communication devices. If no positive match is found, the user in the biometric sampling zone or biometric capture area associated with the service point terminal 106 is not permitted access to the requested service / service provided by the service point terminal 106. If a positive match is found (i.e., a positive match determination is generated), the service point terminal 106 sends a second data payload containing the cryptographic hash of the first data block H(x,t) to the service access control system 104 via a secure communication session initiated between the service point terminal 106 and the service access control system 104.
[0114] The service access control system 104 extracts data from the transmitted second data payload and determines whether the value of the timestamp (t) used to generate the cryptographic hash (H(x,t)) is within a predefined acceptable time interval from the time the user of the first communication device 102 initiated a request for access to the service in response to a trigger event. In response to the determination that the value of the timestamp (t) is within the predefined value of the timestamp (t), the service access control system 104 searches for a second data block that is computationally determined to match or correspond to the data in the cryptographic hash H(x,t) received from the service point terminal 106. In this example, the service access control system 104 searches for x for each user account. i Search for H(x iThe system calculates H(x,t) and compares it with the received H(x,t). If the two values are equal, a match is found. If a match is found, or a corresponding second data block is found, the user's identity is verified, and the service access control system 104 generates a control signal instructing the service point terminal 106 (or access control device 112) to allow the user residing in the biometric sampling zone or biometric capture area associated with the service point terminal 106 to receive access to the requested service / service provided by the service point terminal 106. If no such match or corresponding second data block is found, the user is not provided with access. Second exemplary embodiment
[0115] A second exemplary embodiment of the present invention, more generally described in relation to Figures 1 to 5A, is as follows:
[0116] In this embodiment, the implementation begins with the user of the first communication device 102 communicating with the NFC chip in the biometric passport or ID card and receiving data objects from the NFC chip, thereby provisioning the first communication device 102 with the document security object (SOD), data group 1 (DG1) data object, and data group 2 (DG2) data object corresponding to the user's passport or ID card.
[0117] Subsequently, the first communication device 102 initiates a request for access to or reception of a service whose access is controlled by the service access control system 104. A secure communication session is initiated between the first communication device 102 and the service access control system 104. Within the secure communication session, the service access control system 104 authenticates the identity of the user who made the request. The first communication device 102 sends the SOD and DG1 data object to the service access control system 104. The service access control system 104 verifies the SOD using a digital signature from the issuing authority, verifies the authenticity of the data in the DG1 data object using the SOD, and if the verification is successful, reads the DG2 hash from the SOD and stores it in a second data block associated with the user identified based on the data in the DG1 data object (for example, based on passport number, or name and date of birth).
[0118] The first communication device 102 stores the DG2 data object as a biometric information template in its memory.
[0119] If the first communication device 102 is within a defined physical proximity range (e.g., within a positional radius of 1000 meters) of a service point terminal 106 that can access the requested service, the first communication device 102 establishes a secure communication session with the service point terminal 106. The first communication device 102 can determine that it is within the defined physical proximity range in any variety of ways, such as based on GPS data or based on the reception of a near-range beacon signal from the service point terminal 106 or an access point device 108 located in a defined vicinity of the service point terminal 106.
[0120] The first communication device 102 can authenticate the service point terminal 106 and confirm that the service point terminal 106 is a terminal that has the authority to provide the requested service or to control access to the requested service.
[0121] The first communication device 102 generates a first data payload containing a DG2 data object (which functions as a biometric information template) corresponding to the user and transmits it to the service point terminal 106. The service point terminal 106 calculates a hash of the data in the DG2 data object. The service point terminal 106 may then be configured to discard the data in the first data payload after a predetermined time interval (e.g., 1 hour) from the time it receives it from the first communication device 102.
[0122] Subsequently, the service point terminal 106 collects a live biometric sample from the user while the user is present in the biometric sampling zone or biometric capture area associated with the service point terminal 106. The live biometric sample is compared by the service point terminal 106 with biometric template data of a DG2 data object that has been received from one or more user communication devices and passed an authenticity check. If no positive match is found (i.e., no match is found), the user present in the biometric sampling zone or biometric capture area associated with the service point terminal 106 is not permitted access to the requested service / service provided by the service point terminal 106. If a positive match is found (i.e., a positive match determination is generated), the service point terminal 106 sends a second data payload containing the DG2 hash to the service access control system 104 via a secure communication session initiated between the service point terminal 106 and the service access control system 104.
[0123] The service access control system 104 determines whether the DG2 hash from the transmitted second data payload matches the DG2 hash corresponding to any user authorized to access services controlled by the service access control system 104. If a match is found, or if an SOD containing the corresponding DG2 hash is found, the user's identity is verified, and the service access control system 104 generates a control signal instructing the service point terminal 106 (or access control device 112) to allow the user residing in the biometric information sampling zone or biometric information capture area associated with the service point terminal 106 to receive access to the requested service / service provided by the service point terminal 106. If there is no match, access is not provided to the user. Third exemplary embodiment
[0124] A third exemplary embodiment of the present invention, more generally described in relation to Figures 1 to 5A, is described below. The following description of this exemplary embodiment describes the main features of this embodiment, but in various more specific embodiments, implementations of this exemplary embodiment may include other features described in relation to any of Figures 1 to 5A and Figures 6 to 10.
[0125] In this exemplary embodiment, the present invention includes a method implemented on a processor-equipped service point terminal 106 for monitoring or controlling user access to services at a service point.
[0126] This method begins with the service point terminal 106 acquiring a biometric information sample of the user through a biometric information sample acquisition sensor.
[0127] Subsequently, the service point terminal 106 performs or starts a biometric information comparison. The biometric information comparison is performed between the acquired biometric information sample and the group of biometric information templates stored in the memory of the service point terminal 106. In one embodiment, the group of biometric information templates includes a plurality of biometric information templates, each of which includes a user's biometric information template and at least one additional biometric information template that is different from the user's biometric information template.
[0128] In a more specific embodiment, each biometric template within the biometric template group is either transmitted from the respective communication device to the service point terminal or generated based on biometric data transmitted from the respective communication device to the service point terminal. In an even more specific embodiment, for each biometric template within the biometric template group, the service point terminal 106 also receives the associated data payload corresponding to the biometric template from the respective communication device and stores the associated data payload or the data derived from the associated data payload in the associated data block in the memory of the service point terminal 106.
[0129] In one embodiment of the present invention, each associated data payload received by the service point terminal 106 is based on an associated communication device data block stored in the memory of the respective communication device that transmitted the associated data payload. The associated communication device data block corresponds to an associated service access control system data block stored in a memory accessible by the service access control system 104.
[0130] In the specific embodiment described above, the user's biometric template, or the user's biometric data on which the user's biometric template was generated, is received by the service point terminal 106 from the first communication device 102. Furthermore, at least one additional biometric template different from the user's biometric template, or the biometric data on which the at least one additional biometric template was generated, is received by the service point terminal 106 from a second communication device. This second communication device is different from the first communication device 102.
[0131] Subsequently, the service point terminal 106 transmits a second data payload to the service access control system 104. In one embodiment of the present invention, the second data payload transmitted from the service point terminal 106 to the service access control system 104 includes data from or based on a data block identified from among related data blocks stored in the memory of the service point terminal 106, each of which corresponds to a biometric template in the biometric template group. In a particular embodiment, the data in the second data payload is derived from the user's biometric template or from the user's biometric data on which the user's biometric template was generated.
[0132] Identified data blocks are identified from among the related data blocks based on (i) a positive match determination obtained by comparing the user's biometric data sample with a matching biometric data template within the biometric data template group, and (ii) determining that a specific related data block that stores either the related data payload corresponding to the matching biometric data template or data derived from the related data payload corresponding to the matching biometric data template is an identified data block.
[0133] In one embodiment, the data in the second data payload allows the service access control system to determine whether a user is permitted to access the service. In one embodiment, the service access control system 106 determines whether a user is permitted to access the service based on the output of a calculation that includes the data in the second data payload and the data in one or more associated service access control system data blocks.
[0134] In one embodiment, the service point terminal 106 is further configured to transmit homomorphic encrypted data output from biometric information comparison to the service access control system 104. In this embodiment, the service access control system 104 is configured to generate a match determination based on the output homomorphic encrypted data. Subsequently, in response to the generated match determination containing a positive match determination, the identified data block is identified from among the associated data blocks.
[0135] In one embodiment, the service access control system 104 is configured to respond to a determination (based on data in a second data payload) that a user is permitted to access a service by generating a control signal that permits or records the user's access to the service. In a particular embodiment of the present invention, the associated data payload (corresponding to the matching biometric template) includes or is based on a current timestamp, and the service access control system 104 is configured to generate a control signal only if the timestamp falls within a predefined time interval.
[0136] In one embodiment of the present invention, the service access control system 104 is configured to generate a control signal that permits or records a user's access to the service only when it is determined that the user's biometric template or the user's biometric data on which the user's biometric template was generated is authentic.
[0137] In the embodiments of the present invention described above, the user's biometric information template, or the user's biometric information data on which the user's biometric information template was generated, is inaccessible from the service access control system 104. For example, the service point terminal 106 may be configured so that the user's biometric information template, or the user's biometric information data on which the user's biometric information template was generated, is not transmitted to the service access control system 104.
[0138] In various embodiments of this third exemplary embodiment of the present invention, one or more of the method steps shown in Figure 9 or Figure 10 may be additionally performed (as described in detail above). Fourth exemplary embodiment
[0139] A fourth exemplary embodiment of the present invention, more generally described in relation to Figures 1 to 5A, is described below.
[0140] In this fourth exemplary embodiment, the present invention includes a method for monitoring or controlling a user's access to services at a service point. This method is performed on a first communication device 102 implementing a processor. The method performed on the first communication device 102 implementing a processor includes transmitting (i) a user biometric data or a user biometric template that enables the generation of a user biometric template, and (ii) a data payload corresponding to the user biometric template or the user biometric data to a service point terminal 106.
[0141] In an embodiment of this method, the service point terminal 106 is configured to (i) acquire a user's biometric information sample through a biometric information sample acquisition sensor, (ii) perform a biometric information comparison between the acquired biometric information sample and a group of biometric information templates stored in the service point terminal memory, and (iii) transmit a second data payload to the service access control system 104.
[0142] The biometric information template group includes multiple biometric information templates, each of which includes a user biometric information template and at least one additional biometric information template that is different from the user biometric information template. In one embodiment, each biometric information template in the biometric information template group is generated based on biometric information data transmitted from each communication device to the service point terminal 106, or transmitted from each communication device to the service point terminal.
[0143] In a particular embodiment of this method, for each biometric template in the biometric template group, the service point terminal 106 also receives an associated data payload corresponding to the biometric template from the respective communication device and stores the associated data payload or data derived from the associated data payload in an associated data block in the memory of the service point terminal 106. In a further embodiment, each associated data payload received by the service point terminal is based on an associated communication device data block stored in the memory of the respective communication device that transmitted the associated data payload, and the associated communication device data block corresponds to an associated service access control system data block stored in memory accessible by the service access control system.
[0144] In a specific embodiment, at least one additional biometric template different from the user's biometric template, or the biometric data on which the at least one biometric template was generated, is received by the service point terminal 106 from a second communication device. This second communication device is different from the first communication device 102.
[0145] In one embodiment of this method, the second data payload transmitted from the service point terminal to the service access control system includes data from a data block identified from among related data blocks stored in the memory of the service point terminal 106, or data based on the identified data block, where each related data block corresponds to a biometric template in the biometric template group. In a specific embodiment, the data in the second data payload is derived from the user's biometric template, or from the user's biometric data on which the user's biometric template was generated.
[0146] The identified data block is identified from among the associated data blocks based on (i) a positive match determination obtained as a result of comparing the user's biometric data sample with a matching biometric data template in the biometric data template group, and (ii) determining a specific associated data block as the identified data block that stores either an associated data payload corresponding to the matching biometric data template or data derived from the associated data payload corresponding to the matching biometric data template. The data in the second data payload allows the service access control system 104 to determine whether the user is permitted to access the service. In one embodiment, the service access control system 104 determines whether the user is permitted to access the service based on the output of a calculation that includes the data in the second data payload and the data in one or more associated service access control system data blocks.
[0147] In certain embodiments, the service access control system 104 is configured to respond to a determination that a user is permitted to access a service by generating a control signal that permits or records the user's access to the service. In certain embodiments, the associated data payload includes or is based on a current timestamp, and the service access control system 104 is configured to generate a control signal only if the timestamp falls within a predefined time interval.
[0148] In one embodiment, the service access control system 104 is configured to generate a control signal that permits or records the user's access to the service only when it is determined that the user's biometric template, or the user's biometric data on which the user's biometric template was generated, is authentic.
[0149] In the embodiments of the present invention described above, the user's biometric information template, or the user's biometric information data on which the user's biometric information template was generated, cannot be accessed from the service access control system 104.
[0150] In a particular embodiment of this embodiment, the service point terminal 106 further transmits homomorphic encrypted data output from biometric information comparison to the service access control system 104, where (i) the service access control system is configured to generate a match determination based on the output homomorphic encrypted data, and (ii) in response that the generated match determination includes a positive match determination, the identified data block is identified from among the associated data blocks.
[0151] In various embodiments of this fourth exemplary embodiment of the present invention, one or more of the method steps shown in Figure 9 or Figure 10 may be additionally performed (as described in detail above). Fifth exemplary embodiment
[0152] A fifth exemplary embodiment of the present invention, more generally described in relation to Figures 1 to 5A, is described below. The following description of this exemplary embodiment describes the main features of this embodiment, but in various more specific embodiments, implementations of this exemplary embodiment may include other features described in relation to Figures 1 to 5A and Figures 6 to 10.
[0153] In this embodiment, the present invention includes a method implemented in a processor-implemented service access control system 104 for monitoring or controlling user access to services at a service point.
[0154] This method includes receiving a second data payload from a service point terminal 106 in the service access control system 104, wherein the step of receiving the second data payload precedes each of the following steps: (i) acquiring a user's biometric information sample through a biometric information sample acquisition sensor, and (ii) performing a biometric information comparison between the acquired biometric information sample and a group of biometric information templates stored in the memory of the service point terminal.
[0155] In one embodiment, the biometric information template group includes a plurality of biometric information templates, the plurality of biometric information templates includes a user's biometric information template and at least one additional biometric information template that is different from the user's biometric information template.
[0156] In a more specific embodiment, each biometric template within the biometric template group is generated based on biometric data transmitted from the respective communication device to the service point terminal 106, or based on biometric data transmitted from the respective communication device to the service point terminal. In an even more specific embodiment, for each biometric template within the biometric template group, the service point terminal 106 also receives an associated data payload corresponding to that biometric template from the respective communication device, and stores the associated data payload or the data derived from the associated data payload in an associated data block in the memory of the service point terminal 106.
[0157] In one embodiment of the present invention, each associated data payload received by the service point terminal 106 is based on an associated communication device data block stored in the memory of the respective communication device that transmitted the associated data payload. The associated communication device data block corresponds to an associated service access control system data block stored in a memory accessible by the service access control system 104.
[0158] In the specific embodiment described above, the user's biometric template, or the user's biometric data on which the user's biometric template was generated, is received by the service point terminal 106 from the first communication device 102. Furthermore, at least one additional biometric template different from the user's biometric template, or the biometric data on which the at least one additional biometric template was generated, is received by the service point terminal 106 from a second communication device. This second communication device is different from the first communication device 102.
[0159] Subsequently, the service point terminal 106 transmits a second data payload to the service access control system 104. In one embodiment of the present invention, the second data payload transmitted from the service point terminal 106 to the service access control system 104 includes data from or based on a data block identified from among related data blocks stored in the memory of the service point terminal 106, each of which corresponds to a biometric template in the biometric template group. In a particular embodiment, the data in the second data payload is derived from the user's biometric template or from the user's biometric data on which the user's biometric template was generated.
[0160] Identified data blocks are identified from among the associated data blocks based on (i) a positive match determination obtained by comparing the user's biometric data sample with a matching biometric data template within the biometric data template group, and (ii) determining that a specific associated data block that stores either the associated data payload corresponding to the matching biometric data template or data derived from the associated data payload corresponding to the matching biometric data template is the identified data block.
[0161] In one embodiment, the data in the second data payload allows the service access control system to determine whether a user is permitted to access the service. In one embodiment, the service access control system 106 determines whether a user is permitted to access the service based on the output of a calculation that includes the data in the second data payload and the data in one or more associated service access control system data blocks.
[0162] In one embodiment, the service point terminal 106 is further configured to transmit homomorphic encrypted data output from biometric information comparison to the service access control system 104. In this embodiment, the service access control system 104 is configured to generate a match determination based on the output homomorphic encrypted data. Subsequently, in response to the generated match determination containing a positive match determination, the identified data block is identified from among the associated data blocks.
[0163] In one embodiment, the service access control system 104 is configured to respond to a determination (based on data in a second data payload) that a user is permitted to access a service by generating a control signal that permits or records the user's access to the service. In a particular embodiment of the present invention, the associated data payload (corresponding to the matching biometric template) includes or is based on a current timestamp, and the service access control system 104 is configured to generate a control signal only if the timestamp falls within a predefined time interval.
[0164] In one embodiment of the present invention, the service access control system 104 is configured to generate a control signal that permits or records a user's access to the service only when it is determined that the user's biometric template or the user's biometric data on which the user's biometric template was generated is authentic.
[0165] In the embodiments of the present invention described above, the user's biometric information template, or the user's biometric information data on which the user's biometric information template was generated, is inaccessible from the service access control system 104. For example, the service point terminal 106 may be configured so that the user's biometric information template, or the user's biometric information data on which the user's biometric information template was generated, is not transmitted to the service access control system 104.
[0166] In various embodiments of this third exemplary embodiment of the present invention, one or more of the method steps shown in Figure 9 or Figure 10 may be additionally performed (as described in detail above). Sixth exemplary embodiment
[0167] A sixth exemplary embodiment of the present invention, more generally described in relation to Figures 1 to 5A, is shown in the flowchart of Figure 5B and described in more detail below. The method steps of Figure 5B include a specific embodiment of the method that is more generally described (and described in relation to Figure 3). The following description of this exemplary embodiment will focus on the main features of this embodiment, but in various more specific embodiments, implementations of this exemplary embodiment may include other features described in relation to any of Figures 1 to 5A and Figures 6 to 10.
[0168] In an embodiment of the method shown in Figure 5B, the present invention includes a method for monitoring or controlling user access to services at a service point, which is at least partially performed on a processor-equipped service point terminal 106.
[0169] Step 502A includes the service point terminal 106 receiving multiple datasets from one or more communication devices 102. The multiple datasets may be received from a single communication device 102, or at least one of the multiple datasets may be received from a first communication device 102 and at least another of the multiple datasets may be received from a communication device other than the first communication device 102. Each dataset in the multiple datasets corresponds to a different person and includes that person's biometric data. In one embodiment, the biometric data corresponding to a person may include a biometric template corresponding to that person.
[0170] Step 504A includes acquiring a biometric sample from a person using a biometric sample acquisition sensor. In one embodiment, the biometric sample is acquired from a person present in a biometric sampling zone or biometric capture area associated with the service point terminal 106. In one embodiment, step 504A is initiated or performed at the service point terminal 106.
[0171] Step 506A includes comparing the acquired biometric data sample with the biometric data of each of several datasets. In one embodiment, step 506A is initiated or performed at the service point terminal 106.
[0172] In step 508A, the service point terminal 106 selects a dataset from among multiple datasets, and the selection of the dataset is based on a positive match determination obtained as a result of comparing the acquired biometric data sample with the biometric data in the selected dataset.
[0173] Step 510A includes sending a data payload from the service point terminal 106 to the service access control system 104, the data payload being sent including data extracted from or derived from data within a selected dataset.
[0174] In step 512A, the service access control system 104 determines whether the person from whom the biometric information sample was taken in step 504A (i.e., the person present at the service point terminal) is permitted to access the service. This determination is made based on the data in the data payload transmitted from the service point terminal 106 (in step 510A).
[0175] In step 514A, in response to the determination that the person is permitted to access the service, the service access control system 104 generates a control signal to permit or record the person's access to the service.
[0176] In one embodiment of the method shown in Figure 5B, the data in the selected dataset is based on the associated communication device dataset stored in the memory of the communication device that received the selected dataset at the service point terminal. Furthermore, the associated communication device dataset corresponds to or is associated with the associated service access control system dataset stored in memory accessible by the service access control system.
[0177] In a more specific embodiment of this method, the determination that a person from whom a biometric information sample has been taken is permitted to access the service is based on the output of a computation that includes the transmitted data payload and at least one associated service access control system dataset stored in memory accessible by the service access control system.
[0178] In one or more specific embodiments of the method shown in Figure 5B, the biometric data contained in one or more of the selected dataset, multiple datasets, and acquired biometric samples is inaccessible from the service access control system.
[0179] In one embodiment of this method, (i) the dataset includes an additional data element which is the output of an encryption function or derived from the output of an encryption function, and (ii) the additional data element is indecipherable or undecryptable at the service point terminal.
[0180] In one embodiment of this method, the wireless connection or wireless communication session used by the service point terminal to receive the dataset lasts for less than 3 minutes.
[0181] In one embodiment of this method, the determination that a person from whom a biometric sample has been taken is permitted to access the service is conditional on verifying the authenticity of some data within the selected dataset.
[0182] In one embodiment of the method, biometric data within a dataset is homomorphically encrypted so that it cannot be decrypted or decrypted by a service point terminal.
[0183] In another embodiment of the method, the biometric data in the dataset is homomorphically encrypted so that it cannot be decrypted or decrypted by the service point terminal unless the dataset is the dataset selected in step 508A.
[0184] In a more specific embodiment of the method, (i) one or more datasets received by the service point terminal 106 from one or more communication devices 102 (i.e., in step 502A) each include encrypted supplemental biometric data, the supplemental biometric data being undecipherable or undecipherable at the service point terminal unless the dataset is the dataset selected in step 508A, and (ii) the determination that a person present at the service point terminal 106 is authorized to access the service is subject to verification of the authenticity of the supplemental biometric data.
[0185] In a more specific embodiment of this method, (i) the determination that a person from whom a biometric sample has been obtained is permitted to access the service is conditional on a positive match being obtained as a result of a comparison between supplemental biometric data and the biometric sample obtained by the biometric sample acquisition sensor, or (ii) the determination that a person from whom a biometric sample has been obtained is permitted to access the service is conditional on a positive match being obtained as a result of a comparison between supplemental biometric data and homomorphically encrypted biometric data contained within a selected dataset.
[0186] Figure 6 shows an example of a first communication device 600 configured to carry out the teachings of the present invention.
[0187] The first communication device 600 may include an instance of any processor-based electronic communication device or communication terminal, implementing any processor, configured to perform data processing functions, network communication functions, and / or wireless communication functions, and one or more of the method steps described above in relation to Figures 3 to 5B above. The first communication device 600 includes a display 602, a user interface 604, a processor 606, a network transceiver 608, and memory 610, the memory 610 may include temporary memory and / or non-temporary memory.In an exemplary embodiment, the memory 610 includes: (i) an operating system (not shown) configured to manage the hardware and software resources of the device and to provide common services to software programs implemented within the first communication device 600; (ii) a user biometric template repository 612 configured to store encrypted or unencrypted registered biometric / registered biometric templates; (iii) a first data block repository configured to store at least one first data block corresponding to a second data block generated during the provisioning of the first communication device and stored in memory accessible by the service access control system 104 (as described in detail above); and (iv) enabling the first communication device 600 to communicate with the service access control system 104 for the purpose of carrying out one or more methods of the present invention (e.g., any of the methods in Figures 3 to 5B). (v) optionally, a trusted intermediary interface 618 that enables the first communication device 600 to communicate with a trusted intermediary platform 110 for the purpose of enabling provisioning of the first communication device 600 with a first data block; (vi) a service point terminal interface 620 that enables the first communication device 600 to communicate with a service point terminal 106 for the purpose of carrying out one or more methods of the present invention (e.g., any of the methods in Figures 3 to 5B); and (vii) optionally, an access point device interface 622 that enables the first communication device 600 to receive communications from an access point device 108 for the purpose of triggering the transmission of biometric template data to an access point device 108 or a service point terminal 106 in accordance with a method described in more detail herein.
[0188] For the purposes of the present invention, the first communication device 102,600 may be used by multiple authorized users (e.g., employees, dependent children, etc.), in which case each authorized user may be independently registered for biometric authentication on the device, and as a result, multiple biometric information templates corresponding to a specific user may be stored on the device. Similarly, in certain embodiments, the provisioning of the first communication device 102 and the service access control system 104 may involve an instance of a separate provisioning process for each authorized user. In certain embodiments, for each authorized user using the same first communication device, the first communication device 102 and the service access control system 104 may store separate sets of first and second data blocks.
[0189] Figure 7 shows an example of a service access control system 700 configured to implement the teachings of the present invention.
[0190] The service access control system 700 may include an instance of any processor-based electronic communication device or communication terminal, implementing any processor, configured to perform data processing functions, network communication functions, and / or wireless communication functions, and one or more of the method steps described above in relation to Figures 3 to 5B above. The service access control system 700 includes a display 702, a user interface 704, a processor 706, a network transceiver 708, and memory 710, the memory 710 may include temporary memory and / or non-temporary memory.In an exemplary embodiment, the memory 710 includes: (i) an operating system (not shown) configured to manage the hardware and software resources of a device and to provide common services to software programs implemented within the service access control system 700; (ii) a regular user data repository 712 configured to store account data and / or profile data corresponding to users registered to use the access control services of the service access control system 700; (iii) a second data block repository configured to store at least one second data block corresponding to a first data block generated during the provisioning of the first communication device (as described in detail above) and stored in memory accessible by the first communication device 102; and (iv) for the purpose of implementing one or more methods of the present invention (e.g., any of the methods in Figures 3 to 5B), the service access control system 700 is configured to access the first communication device 102 (and other communication devices) (v) a communication device interface 716 that enables communication with the service access control system 700, a trusted intermediary interface 718 that optionally enables the service access control system 700 to communicate with the trusted intermediary platform 110 for the purpose of enabling provisioning of the service access control system 700 by a second data block, (vi) a service point terminal interface 720 that enables the service access control system 700 to communicate with the service point terminal 106 for the purpose of carrying out one or more methods of the present invention (e.g., any of the methods in Figures 3 to 5B), (vii) a biometric matching determination controller 722 that optionally configures to carry out method step 504 of the method in Figure 5A, (viii) a data payload identification controller 724 that optionally configures to carry out method step 506 of the method in Figure 5A, and (ix) one or more control signal generators 726 that are configured to generate control signals in accordance with method step 312 of the method in Figure 3.In one embodiment, the homomorphic secret key SK is accessible only to the biometric matching controller 722 and is isolated from other parts of the access control system. In one embodiment, the biometric matching controller 722 cannot access or decrypt the data in the second data payload. In one embodiment, the biometric matching controller 722 cannot access the second data block.
[0191] Figure 8 shows an example of a service point terminal 800 configured to implement the teachings of the present invention.
[0192] The service point terminal 800 may include an instance of any processor-based electronic device or terminal implementing any processor, configured to perform data processing functions, biometric information sample acquisition functions, biometric information comparison functions, network communication functions, and / or wireless communication functions, as well as one or more of the method steps described above in relation to Figures 3 to 5B above. The service point terminal 800 includes a display 802, a user interface 804, a processor 806, a network transceiver 808, and memory 810, the memory 810 may include temporary memory and / or non-temporary memory.In an exemplary embodiment, the memory 810 includes (i) an operating system (not shown) configured to manage the device's hardware and software resources and to provide common services to software programs implemented within the service point terminal 800; (ii) a communication device interface 812 that enables the service point terminal 800 to communicate with a first communication device 102 (and other communication devices) for the purpose of carrying out one or more methods of the present invention (e.g., any of the methods in Figures 3 to 5B); (iii) a service access control system interface 814 that enables the service point terminal 800 to communicate with a service access control system 104 for the purpose of carrying out one or more methods of the present invention (e.g., any of the methods in Figures 3 to 5B); (iv) a biometric template repository 816 including temporary or non-temporary memory configured to searchably store and access user biometric templates received from one or more first communication devices 102; and (v) service access control system (vi) a biometric sensor controller 818 configured to control the operation of one or more sensors for the purpose of acquiring biometric samples corresponding to individuals or objects present in a biometric sampling zone or biometric capture area associated with the service point terminal 800; (vi) a biometric comparison controller 820 configured to perform method step 308 of the method in Figure 3; (vii) optionally a biometric match determination controller 822 configured to perform method step 402 of the method in Figure 4; (viii) a data payload generation controller 824 for generating a second data payload (according to the teachings of the method in Figure 3) for transmission to a service access control system 104; and (ix) optionally one or more access controllers 826 configured to allow or restrict a user's access to a requested service by controlling the operation of an access control device 112 which may be integrated into the service point terminal 800 or coupled to the service point terminal 800 by communication.
[0193] Figure 9 is a communication flow diagram illustrating a first embodiment of the method according to the present invention. As shown, one or more steps of the method are performed (e.g., entirely or partially) by a first communication device 102, a service access control system 104, and a service point terminal 106. In the illustrated communication flow diagram, the service point terminal 106 is unable to decipher any user's personally identifiable information other than the user's biometric data or biometric template, thus providing the user with privacy protection.
[0194] As shown in Figure 9, in step 902, before enabling the user to access the service, a first data block is provisioned on the first communication device 102. In one embodiment, the user downloads an application from an application store to their smartphone. The application instructs the user to point the smartphone's camera at the bottom of the first page of the passport. The application then takes a photograph or video of the passport page and reads the information in the machine-readable zone (MRZ) of the passport using optical character recognition (OCR). Alternatively, the application can take a photograph or video of the first page of the passport and read the text information using OCR. The application then instructs the user to touch the back of the smartphone, which has a built-in NFC antenna, to the back cover of the passport, which has a contactless secure chip. The application reads data from the secure chip and provisions a first data block on the user's smartphone based on the user's passport number and profile picture (biometric data) read from the passport chip.
[0195] As shown in Figure 9, in step 904, a second data block is provisioned in the service access control system 106 before the user is allowed to access the service. In one embodiment, the user can enter their passport number on a website operated by a company providing the service (e.g., an airline's website when booking an airline ticket). In another embodiment, the user can first log in to their account on the company's service (e.g., an airline's website) and then enter their passport number on the service access control system 106 (e.g., the airline's website).
[0196] As further shown in Figure 9, in step 912, the first communication device 102 transmits the data and biometric information template in the first data payload to the service point terminal 106 in response to the trigger event in step 910. In one embodiment, the data in the first data payload may include the user's passport number encrypted with the public key of the service access control system (e.g., the public key of the airline's server). The service point terminal 106 does not have access to the encryption key that can decrypt the data in the first data payload and therefore does not have access to the user's passport number. In one embodiment, the service point terminal 106 may transmit a signal (e.g., a beacon signal) via near-field radio communication, as shown in step 910 of Figure 9, and the first communication device 102 may be triggered in response to the reception of a radio signal (e.g., a Bluetooth Low Energy® beacon). In this embodiment, the physical proximity zone is determined by the Bluetooth® range, which is 100m to 400m indoors and 100m to 1000m outdoors. In this embodiment, the operating system of the first communication device 102 can launch an application in the background, and the application can establish a wireless connection with the service point terminal 106 in the background. Therefore, the user does not need to take the first communication device 102 (e.g., a smartphone) out of their pocket, launch an application, and request or accept a wireless connection, which provides great convenience to the user. However, in this embodiment, as shown in period 914 of Figure 9, the time that the first communication device 102 can transmit the first data payload and biometric information template to the service point terminal 106 over the wireless network is limited, and that time is typically up to 3 minutes. This transmission is made from the first communication device 102 to the service point terminal 106, as shown in step 912 of Figure 9.In one embodiment, unless the first communication device 102 remains in the zone in physical proximity or re-enters the zone, the first communication device 102 does not respond in the background to subsequent receptions of beacon signals from the service point terminal 106.
[0197] As shown in the embodiment of Figure 9, in step 930, the service point terminal 106 deletes the first data payload and biometric template received from the first communication device 102 from its memory upon expiration of the period indicated as 932. This period is typically several hours, more specifically ranging from 15 minutes to 48 hours. Before the end of period 932, in step 920, one or more live biometric samples are captured from the user by the service point terminal 106. In one embodiment, the biometric information may be facial features, and the service point terminal 106 may be activated when the user approaches and the camera detects the face, without requiring any other explicit action from the user. Although not shown in Figure 9, the memory of the service point terminal 106 may contain any number of data payloads and biometric templates of other users. These are received from other communication devices that enter the proximity zone of the service point terminal 106 within the template's expiration period. In one embodiment, the service point terminal 106 does not have a decryption key for decrypting the data in the payload and only has a set of biometric templates that do not contain other personally identifiable information. In one embodiment, the service point terminal 106 compares a live biometric sample of the user with all or a subset of biometric templates that have not expired, including the user's biometric template. In one embodiment, the service point makes a biometric match determination based on one or more biometric comparisons, and if a positive match determination is made, it transmits to the service access control system 104 by incorporating the corresponding data in the first data payload (e.g., the user's passport number encrypted with the airline's server's public key) as data in the second data payload, as shown in step 922 of Figure 9.
[0198] As shown in Figure 9, in step 924, the service access control system 104 identifies a user or a service to a user based on the result of a calculation involving the data in the second data payload and the second data block. In an embodiment, the data in the second data payload is decrypted using the service access control system 104's private key (e.g., the airline's server's private key) and compared with the data in the second data block (e.g., a passport number previously provided by the user to the airline). If the comparison is positive (e.g., the passport number stored as data in the second data block is the same as the passport number decrypted from the data in the second data payload), the service access control system 104 generates a control signal to permit a service to the user (e.g., permit the user to board an airline flight).
[0199] Figure 10 is a sequence diagram of a non-limiting exemplary embodiment of process 1000, showing an example of a system 100 comprising a first communication device 102, a service access control system 104, and a service point terminal 106 configured to carry out the teachings of the present invention. As shown, one or more steps of process 1000 are performed (e.g., entirely or partially) by the first communication device 102, the service access control system 104, and the service point terminal 106. In this embodiment, the service point terminal 106 cannot decode or correlate the user's personally identifiable information, including the user's biometric information. As a result, if a user enters the proximity zone of the service point terminal 102 multiple times, the service point terminal 102 cannot determine whether they are the same user, thus further enhancing user privacy protection.
[0200] As shown in Figure 10, in step 1012, the first communication device 102 transmits the first data payload to the service point terminal 106 in response to the trigger event in step 910. In one embodiment, the first communication device 102 encrypts the user's biometric template using homomorphic encryption with the public common-mode key (PK) of the service access control system 104. The first communication device 102 generates a secure random session key and uses that session key to encrypt data from the first data block (e.g., passport number) using a symmetric encryption algorithm. It also encrypts the session key using the public key of the service access control system 104. The first communication device 102 concatenates the homomorphically encrypted biometric template, the encrypted data from the first data block, and the encrypted session key, includes the concatenated data as the data in the first data payload, and in step 1012 transmits the first data payload to the service point terminal 106 over the wireless network.
[0201] As shown in Figure 10, in step 1020, the service point terminal 106 uses the evaluation key (EK) of the service access control system to compare one or more live biometric samples of users within the encrypted domain with a set of non-expired biometric templates, including the user's biometric template, and generates a homomorphically encrypted sequence of biometric comparison scores. In step 1022, the service point terminal 106 transmits the homomorphically encrypted sequence of biometric comparison scores to the service access control system 104. Furthermore, the service point terminal 106 creates a copy of the sequence of data from the first data payload, maintaining a one-to-one correspondence between the elements of the encrypted sequence of comparison scores transmitted to the service access control device 104.
[0202] As shown in Figure 10, in step 1024, the service access control system 104 decrypts the biometric comparison score using a homomorphic secret key (SK) and obtains a match determination by comparing it with a predefined threshold. If a positive match is found, in step 1026, it sends the index of the matching biometric template to the service point terminal 106. In step 1028, the service point terminal 106 sends a second data payload containing non-biometric data to the service access control system 104 from the first data payload corresponding to the received index. The service access control system 104 identifies the user in step 924 and generates a signal in step 926 to authorize service to the user. In step 1040, the service point terminal deletes the first data payload from its memory at the end of period 932.
[0203] Figure 11 shows an exemplary system 1100 of a type in which one or more methods, method steps, or features of the present invention may be carried out. The illustrated system 1100 includes a computer system 1102, which includes one or more processors 1104 and at least one memory 1106. The processors 1104 are configured to execute program instructions and may be real or virtual processors. It will be understood that the computer system 1102 does not imply any limitation with respect to the scope or functionality of the embodiments described. The computer system 1102 may include, but is not limited to, one or more general-purpose computers, programmed microprocessors, microcontrollers, integrated circuits, and other devices or arrangements of devices that can carry out the steps constituting the methods of the present invention. Exemplary embodiments of the computer system 1102 according to the present invention may include one or more servers, desktops, laptops, tablets, smartphones, mobile phones, mobile communication devices, tablets, phablets, and personal digital assistants. In one embodiment of the present invention, the memory 1106 may store software for carrying out various embodiments of the present invention. The computer system 1102 may have additional components. For example, the computer system 1102 may include one or more communication channels 1108, one or more input devices 1110, one or more output devices 1112, and storage 1114. An interconnection mechanism (not shown), such as a bus, controller, or network, interconnects the components of the computer system 1102. In various embodiments of the present invention, operating system software (not shown) provides an operating environment for various software running on the computer system 1102 using a processor 1104 and manages various functions of the components of the computer system 1102.
[0204] One or more communication channels 1108 enable communication with various other computing entities via a communication medium. The communication medium provides information such as program instructions or other data within the communication medium. The communication medium includes, but is not limited to, wired or wireless methods implemented using electrical, optical, RF, infrared, acoustic, microwave, Bluetooth®, or other transmission media.
[0205] One or more input devices 1110 may include, but are not limited to, a touchscreen, keyboard, mouse, pen, joystick, trackball, audio device, scanning device, or any other device capable of providing input to the computer system 1102. In one embodiment of the present invention, one or more input devices 1110 may be a sound card or similar device that accepts audio input in analog or digital format. One or more output devices 1112 may include, but are not limited to, a user interface on a CRT, LCD, LED display, or any other display associated with a server, desktop, laptop, tablet, smartphone, mobile phone, mobile communication device, tablet, phablet and personal digital assistant, printer, speaker, CD / DVD writer, or any other device that provides output from the computer system 1102.
[0206] Storage 1114 may include, but is not limited to, magnetic disks, magnetic tapes, CD-ROMs, CD-RWs, DVDs, any type of computer memory, magnetic stripes, smart cards, printed barcodes, or any other temporary or non-temporary media that can be used to store information and are accessible by the computer system 1102. In various embodiments of the present invention, storage 1114 may include program instructions for carrying out any of the embodiments described.
[0207] In one embodiment of the present invention, the computer system 1102 is part of a distributed network or part of a set of available cloud resources.
[0208] The present invention can be implemented in many ways, such as as a system, as a method, or as a computer program product such as a computer-readable storage medium or a computer network in which program instructions are communicated from a remote location.
[0209] The present invention can preferably be embodied as a computer program product for use with computer system 1102. The method described herein is typically implemented as a computer program product comprising a set of program instructions executed by computer system 1102 or any other similar device.
[0210] The set of program instructions may be a series of computer-readable codes stored in a computer-readable storage medium (storage 1114), such as a diskette, CD-ROM, ROM, flash drive, or hard disk, or it may be transmittable to a computer system 1102 via a modem or other interface device through a tangible medium including, but not limited to, one or more optical or analog communication channels 1108. The embodiment of the present invention as a computer program product may also take an intangible form using wireless technologies including, but not limited to, microwave, infrared, Bluetooth®, or other transmission technologies. These instructions may be preloaded into the system, recorded on a storage medium such as a CD-ROM, or made available for download via a network such as the Internet or a mobile phone network. The set of computer-readable instructions may embody all or part of the functions described above in this specification.
[0211] Therefore, the present invention implements a solution that enables service providers to securely and accurately identify and authenticate users at service points, and / or monitor or control users' access to services at service points, regardless of the number of users registered for identity verification (i.e., regardless of the size of the database), because the biometric information comparison process no longer depends on access to a centralized database of registered biometric information templates. Furthermore, the present invention provides a solution that ensures service providers can seamlessly and uniquely identify and authenticate legitimate users at service points, while simultaneously ensuring data privacy and data security, and enabling user authentication with minimal effort on the user's side.
[0212] Other advantages of the present invention include: (i) registered biometric data exists with the user in the first communication device; (ii) registered biometric data is securely shared by the first communication device only with the service point terminal, only for a short time, only when physically close, and only in the background without requiring explicit user action; (iii) the service access control system does not access the registered biometric data or acquired live biometric data samples; and (iv) since only a small fraction of the company's users are expected to be in the physical vicinity of the service point terminal, the biometric comparison list is significantly reduced, thereby greatly improving biometric identification accuracy and maintaining the ease of use of the system regardless of the total number of registrants.
[0213] In one embodiment, the present invention includes a method for monitoring or controlling a user's access to services at a service point. The method includes performing the following steps in a service point terminal implementing a processor: (i) receiving a first data payload from a first communication device; (a) the data in the first data payload is based on a first data block stored in memory accessible by the first communication device, the first data block corresponds to a second data block stored in memory accessible by a service access control system; (b) at least one of the data in the first data payload, the first data block, or the second data block is associated with either a user, a service, or a user's access to a service; (ii) acquiring a biometric sample through a biometric sample acquisition sensor; (iii) performing a biometric comparison between the acquired biometric sample and a group of biometric templates stored in the memory of the service point terminal, the group of biometric templates including at least one user biometric template associated with a user; (c) the user biometric template is generated based on user biometric data associated with a user; (d) the user biometric template or user biometric data is received by the service point terminal from the first communication device; and (iv) transmitting a second data payload to the service access control system. The data in the second data payload is based on the data in the first data payload. Furthermore, the data in the second data payload enables the service access control system to identify the user based on the output from a calculation that includes the data in the second data payload and the data in the second data block.In one embodiment of this method, the service access control system is configured to respond to user identification by generating a control signal that permits or records the user's access to the service, the control signal being generated after a positive match determination is generated based on data output from a biometric comparison performed at a service point terminal, the positive match determination being generated in response to the identification of a predefined similarity between the acquired biometric sample and the user biometric template.
[0214] In one embodiment of the present method, (i) the data in a first data payload based on a first data block includes a user biometric template or user biometric data, or (ii) the data in the first data payload includes (a) data based on the first data block and (b) a user biometric template or user biometric data received by a service point terminal from a first communication device, or (iii) the data in the first data payload is based on the first data block, and the user biometric template or user biometric data is transmitted from the first communication device to the service point terminal in an additional data payload different from the first data payload.
[0215] In one embodiment of the above method, the second data payload is transmitted from the service point terminal to the service access control system in response to a positive match determination being obtained as a result of biometric information comparison at the service point terminal, the positive match determination arising from a comparison between the acquired biometric information sample and the user biometric information template.
[0216] In an alternative embodiment of the present method, the service point terminal further transmits encrypted or unencrypted data output from the biometric comparison to a service access control system, which is configured to (i) generate a match determination based on the output encrypted or unencrypted data, and (ii) in response that the generated match determination includes a positive match determination, identify a second data payload associated with the user biometric template, and process the data in the second data payload to identify the user or the service to the user based on the data in the second data payload and the results of calculations relating to the second data block.
[0217] In another embodiment, the present invention provides a method for monitoring or controlling a user's access to a service at a service point, the method comprising the steps of (i) transmitting a first data payload to a service point terminal in a first communication device implementing a processor, (a) the data in the first data payload being based on a first data block stored in memory accessible by the first communication device, (b) the first data block corresponding to a second data block stored in memory accessible by a service access control system, and (c) at least one of the data in the first data payload or the first data block or the second data block being associated with either a user, a service, or a user's access to a service.
[0218] In this embodiment, the service point terminal is configured to (i) acquire a biometric sample through a biometric sample acquisition sensor, (ii) perform a biometric comparison between the acquired biometric sample and a group of biometric templates stored in the service point terminal memory, the group of biometric templates including at least one user biometric template associated with a user, (a) the user biometric template is generated based on user biometric data associated with the user, (b) the user biometric template or user biometric data is received by the service point terminal from a first communication device, and (iii) transmit a second data payload to a service access control system, (a) the data in the second data payload is based on the data in the first data payload, and (b) the data in the second data payload enables the service access control system to identify a user based on the output from a calculation including the data in the second data payload and the data in the second data block.
[0219] Furthermore, in this embodiment, the service access control system is configured to respond to user identification by generating a control signal that permits or records the user's access to the service based on the results of a calculation, the control signal being generated after a positive match determination is generated based on data output from a biometric comparison performed at the service point terminal, the positive match determination being generated in response to the identification of a predefined similarity between the acquired biometric sample and the user biometric template.
[0220] In one embodiment of this method, (i) the data in a first data payload based on a first data block includes a user biometric template or user biometric data, or (ii) the data in the first data payload includes (a) data based on the first data block and (b) a user biometric template or user biometric data, or (iii) the user biometric template or user biometric data is transmitted from a first communication device to a service point terminal in an additional data payload different from the first data payload.
[0221] In a particular embodiment of this method, a second data payload is transmitted from the service point terminal to the service access control system in response to a positive match determination obtained as a result of biometric comparison at the service point terminal, the positive match determination arising from a comparison between the acquired biometric sample and the user biometric template.
[0222] In an alternative embodiment of this method, the service point terminal further transmits encrypted or unencrypted data output from the biometric comparison to a service access control system, which is configured to (i) generate a match determination based on the output homomorphic encrypted data, and (ii) in response that the generated match determination includes a positive match determination, identify a second data payload associated with the user biometric template, and process the data in the second data payload to identify the user or a service to the user based on the data in the second data payload and the results of calculations relating to the second data block.
[0223] In yet another embodiment, the present invention provides a method for monitoring or controlling a user's access to a service at a service point terminal, the method comprising, in a service access control system implementing a processor, (i) storing a second data block in memory accessible by the service access control system, the second data block corresponding to a first data block stored in memory accessible by a first communication device, the first communication device configured to (a) transmit a first data payload to the service point terminal, (1) the data in the first data payload being based on a first data block, and (2) at least one of the data in the first data payload, the first data block, or the second data block being associated with either a user, a service, or a user's access to a service.
[0224] In this embodiment, the service point terminal is configured to (i) acquire a biometric sample through a biometric sample acquisition sensor, (ii) perform a biometric comparison between the acquired biometric sample and a group of biometric templates stored in the service point terminal memory, the group of biometric templates including at least one user biometric template associated with a user, (a) the user biometric template is generated based on user biometric data associated with the user, (b) the user biometric template or user biometric data is received by the service point terminal from a first communication device, and (iii) transmit a second data payload to a service access control system, (1) the data in the second data payload is based on the data in the first data payload, and (2) the data in the second data payload enables the service access control system to identify a user based on the output from a calculation including the data in the second data payload and the data in the second data block.
[0225] The service access control system is further configured to respond to user identification by generating control signals that permit or record the user's access to the service, the control signals being generated after a positive match determination is generated based on data output from biometric comparison performed at the service point terminal, the positive match determination being generated in response to the identification of a predefined similarity between the acquired biometric sample and the user biometric template.
[0226] In one embodiment of this method, (i) the data in the first data payload includes a user biometric template or user biometric data; (ii) the data in the first data payload includes (a) data based on a first data block and (b) a user biometric template or user biometric data; or (iii) the data in the first data payload is based on a first data block, and the user biometric template or user biometric data is transmitted from the first communication device to the service point terminal in an additional data payload different from the first data payload.
[0227] In a particular embodiment of this method, a second data payload is transmitted from the service point terminal to the service access control system in response to a positive match determination obtained as a result of biometric comparison at the service point terminal, the positive match determination arising from a comparison between the acquired biometric sample and the user biometric template.
[0228] In an alternative embodiment of this method, the service access control system (i) receives encrypted or unencrypted data output from biometric comparison, (ii) generates a match determination based on the output encrypted or unencrypted data, and (iii) identifies a second data payload associated with a user biometric template in response that the generated match determination includes a positive match determination, and processes the data in the second data payload to identify a user or a service to a user based on the data in the second data payload and the results of calculations 51 relating to the second data blocks.
[0229] Furthermore, the present invention provides a service point terminal configured to monitor or control user access to services at a service point.The service point terminal comprises at least one processor and at least one memory, and is configured to (i) perform the step of receiving a first data payload from a first communication device, (a) the data in the first data payload is based on a first data block stored in memory accessible by the first communication device, the first data block corresponds to a second data block stored in memory accessible by a service access control system, (b) at least one of the data in the first data payload or the first data block or the second data block is associated with either a user, a service, or a user's access to a service, (ii) acquire a biometric sample through a biometric sample acquisition sensor, and (iii) perform a biometric comparison between the acquired biometric sample and a group of biometric templates stored in the memory of the service point terminal, the group of biometric templates includes at least one user biometric template associated with a user, and (c) the user biometric template (d) The user biometric template or user biometric data is generated based on user biometric data associated with the user, (iv) a second data payload is transmitted to the service access control system, the data in the second data payload is based on the data in the first data payload, (f) the I data in the second data payload enables the service access control system to identify the user based on the output from a calculation including the data in the second data payload and the data in the second data block, and (g) the service access control system is configured to respond to the user identification by generating a control signal to permit or record the user's access to the service, the control signal being generated after a positive match determination is generated based on data output from a biometric comparison performed at the service point terminal, the positive match determination being generated in response to the identification of a predefined similarity between the acquired biometric sample and the user biometric template.
[0230] In one embodiment, the service point terminal is configured such that (i) the data in a first data payload based on a first data block includes a user biometric template or user biometric data received at the service point terminal from a first communication device; (ii) the first data payload includes (a) data based on the first data block and (b) a user biometric template or user biometric data received at the service point terminal from a first communication device; or (iii) the user biometric template or user biometric data is transmitted from the first communication device to the service point terminal in an additional data payload different from the first data payload.
[0231] In one embodiment, the second data payload is transmitted from the service point terminal to the service access control system in response to a positive match determination obtained as a result of biometric information comparison at the service point terminal, the positive match determination arising from a comparison between the acquired biometric information sample and the user biometric information template.
[0232] In an alternative embodiment, the service point terminal is further configured to transmit encrypted or unencrypted data output from biometric comparison to a service access control system, which is configured to (i) generate a match determination based on the output homomorphic encrypted data, and (ii) in response that the generated match determination includes a positive match determination, identify a second data payload associated with a user biometric template, and process the data in the second data payload to identify a user or a service to a user based on the data in the second data payload and the results of calculations relating to the second data block.
[0233] In another embodiment, the present invention provides a first communication device configured to monitor or control a user's access to a service at a service point. The first communication device comprises at least one processor and at least one memory, and is configured to (i) transmit a first data payload to a service point terminal, (a) the data in the first data payload is based on a first data block stored in memory accessible by the first communication device, (b) the first data block corresponds to a second data block stored in memory accessible by a service access control system, and (c) at least one of the data in the first data payload, the first data block, or the second data block is associated with either a user, a service, or a user's access to a service.
[0234] In this embodiment, the service point terminal is configured to (i) acquire a biometric sample through a biometric sample acquisition sensor, (ii) perform a biometric comparison between the acquired biometric sample and a group of biometric templates stored in the service point terminal memory, the group of biometric templates including at least one user biometric template associated with a user, (a) the user biometric template is generated based on user biometric data associated with the user, (b) the user biometric template or user biometric data is received by the service point terminal from a first communication device, and (iii) transmit a second data payload to a service access control system, (a) the data in the second data payload is based on the data in the first data payload, and (b) the data in the second data payload enables the service access control system to identify a user based on the output from a calculation including the data in the second data payload and the data in the second data block.
[0235] Furthermore, in this embodiment, the service access control system is configured to respond to user identification by generating a control signal that permits or records the user's access to the service based on the results of a calculation, the control signal being generated after a positive match determination is generated based on data output from a biometric comparison performed at the service point terminal, the positive match determination being generated in response to the identification of a predefined similarity between the acquired biometric sample and the user biometric template.
[0236] In one embodiment of the first communication device, the first communication device is configured such that (i) the data in a first data payload based on a first data block includes a user biometric template or user biometric data received from the first communication device at a service point terminal; (ii) the first data payload includes (a) data based on a first data block and (b) a user biometric template or user biometric data received from the first communication device at a service point terminal; or (iii) the user biometric template or user biometric data is transmitted from the first communication device to the service point terminal in an additional data payload different from the first data payload.
[0237] In a particular embodiment of the first communication device, the first communication device is configured as follows: In response to a positive match determination obtained as a result of biometric information comparison at the service point terminal, a second data payload is transmitted from the service point terminal to the service access control system, the positive match determination arising from a comparison between the acquired biometric information sample and the user biometric information template.
[0238] In an alternative embodiment of the first communication device, the first communication device is configured as follows: The service point terminal further transmits encrypted or unencrypted data output from biometric comparison to a service access control system, which is configured to (i) generate a match determination based on the output homomorphic encrypted data, and (ii) in response that the generated match determination includes a positive match determination, identify a second data payload associated with a user biometric template, and process the data in the second data payload to identify a user or a service to a user based on the data in the second data payload and the results of calculations relating to the second data block.
[0239] Furthermore, the present invention provides a service access control system configured to enable secure biometric authentication at a service point terminal in connection with a service provision request to a user. The service access control system comprises at least one server, the at least one server comprising at least one processor and at least one memory, the service access control system is configured to (i) store a second data block in memory accessible by the service access control system, the second data block corresponding to a first data block stored in memory accessible by a first communication device, the first communication device is configured to (a) transmit a first data payload to a service point terminal, (1) the data in the first data payload is based on a first data block, and (2) at least one of the data in the first data payload, the first data block, or the second data block is associated with either a user, a service, or a user's access to a service.
[0240] In this embodiment, the service point terminal is configured to (i) acquire a biometric sample through a biometric sample acquisition sensor, (ii) perform a biometric comparison between the acquired biometric sample and a group of biometric templates stored in the service point terminal memory, the group of biometric templates including at least one user biometric template associated with a user, (a) the user biometric template is generated based on user biometric data associated with the user, (b) the user biometric template or user biometric data is received by the service point terminal from a first communication device, and (iii) transmit a second data payload to a service access control system, (1) the data in the second data payload is based on the data in the first data payload, and (2) the data in the second data payload enables the service access control system to identify a user based on the output from a calculation including the data in the second data payload and the data in the second data block.
[0241] Furthermore, the service access control system is configured to respond to user identification by generating control signals that, based on the results of calculations, permit or record the user's access to the service. These control signals are generated after a positive match determination is generated based on data output from biometric comparison performed at the service point terminal, and the positive match determination is generated in response to the identification of a predefined similarity between the acquired biometric sample and the user biometric template.
[0242] In a specific embodiment of the service access control system, the second data payload is transmitted from the service point terminal to the service access control system in response to a positive match determination obtained as a result of biometric information comparison at the service point terminal, the positive match determination arising from a comparison between the acquired biometric information sample and the user biometric information template.
[0243] In one embodiment of a service access control system, (i) the data in a first data payload based on a first data block includes a user biometric template or user biometric data received at a service point terminal from a first communication device; (ii) the first data payload includes (a) data based on the first data block and (b) a user biometric template or user biometric data received at a service point terminal from a first communication device; or (iii) the user biometric template or user biometric data is transmitted from the first communication device to the service point terminal in an additional data payload different from the first data payload.
[0244] In an alternative embodiment of the service access control system, the service access control system (i) receives encrypted or unencrypted data output from biometric comparison, (ii) generates a match determination based on the output encrypted or unencrypted data, and (iii) identifies a second data payload associated with a user biometric template in response that the generated match determination includes a positive match determination, and processes the data in the second data payload to identify a user or a service to a user based on the data in the second data payload and the results of calculations relating to the second data block.
[0245] In one embodiment, the present invention relates to a computer program product for monitoring or controlling a user's access to services at a service point, the computer program product comprising a non-temporary computer-readable medium having computer-readable program code embodied therein, the computer-readable program code, at a service point terminal on which a processor is implemented, (i) receives a first data payload from a first communication device, (a) the data in the first data payload is based on a first data block stored in memory accessible by the first communication device, the first data block corresponds to a second data block stored in memory accessible by a service access control system, and (b) the data in the first data payload or the first data block or the second data At least one of the blocks is associated with either a user, a service, or a user's access to a service, and includes instructions for performing each step: (ii) acquiring a biometric sample through a biometric sample acquisition sensor; (iii) performing a biometric comparison between the acquired biometric sample and a set of biometric templates stored in the memory of a service point terminal, the set of biometric templates including at least one user biometric template associated with a user; (c) the user biometric template being generated based on user biometric data associated with the user; (d) the user biometric template or user biometric data being received at the service point terminal from a first communication device; and (iv) transmitting a second data payload to the service access control system. The data in the second data payload is based on the data in the first data payload. Furthermore, the data in the second data payload enables the service access control system to identify a user based on the output from a calculation including the data in the second data payload and the data in the second data block.In one embodiment of this method, the service access control system is configured to respond to user identification by generating a control signal that permits or records the user's access to the service, the control signal being generated after a positive match determination is generated based on data output from a biometric comparison performed at a service point terminal, the positive match determination being generated in response to the identification of a predefined similarity between the acquired biometric sample and the user biometric template.
[0246] In another embodiment, the present invention relates to a computer program product for monitoring or controlling a user's access to a service at a service point terminal, the computer program product comprising a non-temporary computer-readable medium having computer-readable program code embodied therein, the computer-readable program code comprising instructions for performing the step of (i) transmitting a first data payload to a service point terminal in a first communication device implementing a processor, (a) the data in the first data payload being based on a first data block stored in memory accessible by the first communication device, (b) the first data block corresponding to a second data block stored in memory accessible by a service access control system, and (c) at least one of the data in the first data payload or the first data block or the second data block being associated with either a user, a service, or a user's access to a service.
[0247] In this embodiment, the service point terminal is configured to (i) acquire a biometric sample through a biometric sample acquisition sensor, (ii) perform a biometric comparison between the acquired biometric sample and a group of biometric templates stored in the service point terminal memory, the group of biometric templates including at least one user biometric template associated with a user, (a) the user biometric template is generated based on user biometric data associated with the user, (b) the user biometric template or user biometric data is received by the service point terminal from a first communication device, and (iii) transmit a second data payload to a service access control system, (a) the data in the second data payload is based on the data in the first data payload, and (b) the data in the second data payload enables the service access control system to identify a user based on the output from a calculation including the data in the second data payload and the data in the second data block.
[0248] Furthermore, in this embodiment, the service access control system is configured to respond to user identification by generating a control signal that permits or records the user's access to the service based on the results of a calculation, the control signal being generated after a positive match determination is generated based on data output from a biometric comparison performed at the service point terminal, the positive match determination being generated in response to the identification of a predefined similarity between the acquired biometric sample and the user biometric template.
[0249] In yet another embodiment, the present invention provides a computer program product for monitoring or controlling a user's access to a service at a service point terminal. The computer program product includes a non-temporary computer-readable medium having computer-readable program code embodied therein, the computer-readable program code including instructions for performing the step of (i) storing a second data block in memory accessible by the service access control system in a service access control system implementing a processor, the second data block corresponding to a first data block stored in memory accessible by a first communication device, the first communication device configured to (a) transmit a first data payload to the service point terminal, (1) the data in the first data payload is based on a first data block, and (2) at least one of the data in the first data payload or the first data block or the second data block is associated with either a user, a service, or a user's access to a service.
[0250] In this embodiment, the service point terminal is configured to (i) acquire a biometric sample through a biometric sample acquisition sensor, (ii) perform a biometric comparison between the acquired biometric sample and a group of biometric templates stored in the service point terminal memory, the group of biometric templates including at least one user biometric template associated with a user, (a) the user biometric template is generated based on user biometric data associated with the user, (b) the user biometric template or user biometric data is received by the service point terminal from a first communication device, and (iii) transmit a second data payload to a service access control system, (1) the data in the second data payload is based on the data in the first data payload, and (2) the data in the second data payload enables the service access control system to identify a user based on the output from a calculation including the data in the second data payload and the data in the second data block.
[0251] The service access control system is further configured to respond to user identification by generating control signals that permit or record the user's access to the service, the control signals being generated after a positive match determination is generated based on data output from biometric comparison performed at the service point terminal, the positive match determination being generated in response to the identification of a predefined similarity between the acquired biometric sample and the user biometric template.
[0252] In any more specific embodiment of the embodiments of the present invention described above, the correspondence between the first data block and the second data block is defined by a predefined set of functions.
[0253] In any particular embodiment of the embodiments of the present invention described above, (i) a first data block is generated in a first communication device based on data in a third data payload received from a service access control system or a trusted intermediary, or (ii) a second data block is generated in a service access control system based on data in a fourth data payload received from the first communication device or a trusted intermediary.
[0254] In any exemplary embodiment of the embodiments of the present invention described above, (i) each of the first data block and the second data block contains a set of data contained in the other of the first data block and the second data block; (ii) the first data block and the second data block are identical; (iii) one of the first data block and the second data block is derived from the other of the first data block and the second data block; or (iv) each of the first data block and the second data block is generated based on at least one of a common shared secret data block or a common key derivation function.
[0255] In one or more embodiments of the present invention described above, the first communication device is configured to respond to a time alarm, location alarm, or notification from a service access control system by (i) initiating a wireless communication session with a service access control system or service point terminal, and (ii) initiating the transmission of a user biometric information template and a first data payload to the service point terminal via the wireless communication session.
[0256] In a more specific embodiment, the first communication device is configured to respond to the reception of a beacon signal transmitted from a service point terminal or from an access point device coupled to a service point terminal by communication with the service point terminal, by (i) initiating a short-range wireless communication session with a service point terminal or access point device, and (ii) initiating the transmission of a user biometric information template and a first data payload to the service point terminal via the short-range wireless communication session.
[0257] In a particular embodiment of the invention, a control signal is transmitted to an access control device, and upon receiving the control signal, the access control device is activated, enabling the user to access or receive a service, or to access or pass through an access-restricted location. The access control device may be communicatively coupled to, or include as part of, either a service point terminal or a service access control system.
[0258] In various embodiments of the present invention, (i) the data in the first data payload includes a user biometric template or user biometric data; (ii) the data in the first data payload includes (a) data based on a first data block and (b) a user biometric template or user biometric data; or (iii) the data in the first data payload is based on a first data block, and the user biometric template or user biometric data is received by a service point terminal from a first communication device in an additional data payload different from the first data payload.
[0259] In various embodiments of the present invention, the group of biometric templates stored in the service point terminal memory includes at least one additional biometric template different from the user biometric template, wherein (i) the additional biometric template is generated based on additional biometric data different from the user biometric data, and (ii) the additional biometric template or additional biometric data is received by the service point terminal from a second communication device, the second communication device being different from the first communication device.
[0260] In various embodiments of the present invention, the first communication device (i) enters a zone near a service point terminal, the distance between the first communication device and the service point terminal is in the range of 1 meter to 1000 meters, (ii) the first communication device receives a radio signal transmitted from the service point terminal or a radio signal transmitted from an access point device coupled to the service point terminal by communication, or (iii) transmits a first data payload in response to a time alarm, location alarm, or notification generated within the first communication device or received from a service access control system.
[0261] In various embodiments of the present invention, a second data payload is transmitted from the service point terminal to the service access control system in response to a positive match determination obtained as a result of biometric information comparison at the service point terminal, the positive match determination arising from a comparison between the acquired biometric information sample and the user biometric information template.
[0262] In various embodiments of the present invention, the service point terminal further transmits encrypted or unencrypted data output from biometric comparison to a service access control system, which is configured to (i) generate a match determination based on the output homomorphic encrypted data, and (ii) in response that the generated match determination includes a positive match determination, identify a second data payload associated with a user biometric template, and process the data in the second data payload to identify a user or service or access to a user's service based on the data in the second data payload and the results of calculations relating to the second data block.
[0263] In various embodiments of the present invention, (i) a first data block is generated in a first communication device based on data in a third data payload received from a service access control system or a trusted intermediary, or (ii) a second data block is generated in a service access control system based on data in a fourth data payload received from the first communication device or a trusted intermediary.
[0264] In various embodiments of the present invention, (i) each of the first and second data blocks contains a set of data included in the other of the first and second data blocks; (ii) the first and second data blocks are identical; (iii) one of the first and second data blocks is derived from the other of the first and second data blocks; (iv) the correspondence between the first and second data blocks is defined by a predefined set of functions; or (v) each of the first and second data blocks is generated based on at least one of a common shared secret data block or a common key derivation function.
[0265] In various embodiments of the present invention, (i) a control signal is transmitted to an access control device, and (ii) when the access control device receives the control signal, the operation of the access control device is triggered, allowing the user to (a) access or receive a service, or (b) access or pass through an access-restricted location.
[0266] In various embodiments of the present invention, the user biometric information template and the data in the first data payload are deleted from the service point terminal's memory after a predetermined period has expired, or in response to a time alarm or notification generated within the service point terminal or received from a service access control system or a first communication device.
[0267] In various embodiments of the present invention, (i) the data in the first data payload is the output of an encryption function or derived from the output of an encryption function and requires an encryption key for decryption, the encryption key being isolated from the service point terminal; (ii) the data in the first data payload is the output of a one-way function or derived from the output of a one-way function; or (iii) the data in the first data payload is the output of a cryptographic hash function or derived from the output of a cryptographic hash function.
[0268] In various embodiments of the present invention, (i) the data in the first data payload and the data in the second data payload are identical, (ii) the data in the second data payload is extracted from the data in the first data payload, or (iii) the data in the second data payload is generated by a function that takes the data extracted from the data in the first data payload as input.
[0269] In various embodiments of the present invention, the user biometric template and the data in the first data payload can be stored in the memory of the service point terminal after verifying that the user biometric template received from the first communication device has been signed, certified, or authenticated by a trusted entity.
[0270] In a particular embodiment of the present invention, the user biometric information template and the data in the first data payload stored in the memory of the service point terminal are deleted after a predetermined period has expired, or in response to a time alarm or notification from a service access control system or a first communication device.
[0271] In some embodiments of the present invention, both the biometric sample and the user biometric template correspond to the same biometric type, which is one of the following biometric types: voice-based, iris-based, retina-based, fingerprint-based, palm print-based, palmar vein-based, periorbital-based, facial feature-based, ear-based, DNA (deoxyribonucleic acid)-based, scleral vein-based, finger shape-based, palm shape-based, gait-based, heart rate-based, vascular-based, signature-based, or other body part-based biometric information. In other embodiments of the present invention, the biometric sample and the biometric template may correspond to a specific object associated with the user.
[0272] In one embodiment of the present invention, (i) the data in the first data payload and the data in the second data payload are identical, (iii) the data in the second data payload is generated by a function that takes data extracted from the data in the first data payload as input, or (iii) the data in the first data payload is encrypted data that requires at least one encryption key for decryption, and at least one encryption key is isolated from the service point terminal.
[0273] In one or more specific embodiments of the present invention, a first data block is transmitted from the service access control system to the first communication device via a secure communication session initiated between the first communication device and the service access control system.
[0274] While exemplary embodiments of the present invention are described and illustrated herein, it will be understood that they are merely illustrative. Those skilled in the art will understand that various modifications can be made in form and detail without departing from the scope of the invention as defined by the appended claims. Furthermore, the present invention as described herein can be adequately implemented without any elements not specifically disclosed herein, and in particular, certain embodiments considered specifically are intended to be implemented without any elements not specifically disclosed herein.
Claims
1. A method for monitoring or controlling access to services at a service point, wherein a service point terminal implementing a processor, A device receives multiple datasets from one or more communication devices, and each dataset in the multiple datasets corresponds to a different person and includes at least that person's biometric data. Using a biometric information sample acquisition sensor, biometric information samples are acquired from a person at the service point terminal. The acquired biological information sample is compared with the biological information data of each of the multiple datasets. A dataset is selected from the aforementioned multiple datasets, and the selection of the dataset is based on a positive agreement determination made as a result of comparing the acquired biometric data sample with the biometric data in the selected dataset. A data payload is transmitted to a service access control system, and the transmitted data payload includes data extracted from the data in the selected dataset, or data derived from the data in the selected dataset. This includes performing each step, The service access control system is configured to generate a control signal to permit or record a person's access to the service in response to a determination that the person from whom the biometric information sample has been obtained is permitted to access the service, the determination being made based on data in the transmitted data payload.
2. The data in the selected dataset is based on the associated communication device dataset stored in the memory of the communication device that received the selected dataset at the service point terminal. The aforementioned related communication device dataset corresponds to the related service access control system dataset stored in a memory accessible by the service access control system, The determination that the person from whom the biometric information sample is obtained is permitted to access the service is based on the output of a calculation that includes the transmitted data payload and at least one associated service access control system dataset stored in memory accessible by the service access control system. The method according to claim 1.
3. The biometric data within the selected dataset cannot be accessed by the service access control system. The method according to claim 1.
4. One of the aforementioned datasets includes an additional data element, and the additional data element is either the output of an encryption function or derived from the output of an encryption function. The aforementioned additional data elements cannot be deciphered by the service point terminal. The method according to claim 1.
5. The method according to claim 1, wherein the wireless connection or wireless communication session used to receive the selected dataset at the service point terminal lasts for less than three minutes.
6. The method according to claim 1, wherein the determination that a person from whom the biometric information sample has been obtained is permitted to access the service is conditional on verifying the authenticity of some data in the selected dataset.
7. The biometric data within one of the aforementioned datasets is homomorphically encrypted and cannot be decrypted by the service point terminal, or The biometric data within one of the aforementioned datasets is homomorphically encrypted and cannot be decrypted by the service point terminal unless that dataset is selected. The method according to claim 1.
8. One of the aforementioned datasets includes encrypted supplemental biometric data that cannot be decrypted by the service point terminal unless that dataset is selected. The determination that a person present at the service point terminal is authorized to access the service is conditional upon verification of the authenticity of the supplemental biometric data. The method according to claim 7.
9. The determination that a person whose biometric information sample has been acquired is permitted to access the service is conditional on a positive agreement being obtained as a result of a comparison between the supplemental biometric information data and the biometric information sample acquired by the biometric information sample acquisition sensor, or The determination that a person from whom the biometric information sample has been obtained is permitted to access the service is conditional on a positive match being obtained as a result of comparing the supplemental biometric information data with the homomorphically encrypted biometric information data contained in the selected dataset. The method according to claim 8.
10. A service point terminal for monitoring or controlling access to services at a service point, Processor and Equipped with memory, The aforementioned service point terminal is A device receives multiple datasets from one or more communication devices, and each dataset in the multiple datasets corresponds to a different person and includes at least that person's biometric data. Using a biometric information sample acquisition sensor, biometric information samples are acquired from a person at the service point terminal. The acquired biological information sample is compared with the biological information data of each of the multiple datasets. A dataset is selected from the aforementioned multiple datasets, and the selection of the dataset is based on a positive agreement determination made as a result of comparing the acquired biometric data sample with the biometric data in the selected dataset. A data payload is transmitted to a service access control system, and the transmitted data payload includes data extracted from the data in the selected dataset, or data derived from the data in the selected dataset. Configured to perform each step, The service access control system is configured to generate a control signal to permit or record the person's access to the service in response to a determination that the person from whom the biometric information sample has been obtained is permitted to access the service, and the determination is made based on the data in the transmitted data payload, in a service point terminal.
11. A method for monitoring or controlling user access to a service at a service point, wherein the service point terminal implements a processor, A biometric information sample of the user is acquired through a biometric information sample acquisition sensor. A comparison of the acquired biometric information sample with the biometric information template group stored in the memory of the service point terminal is performed. The second data payload is sent to the service access control system. This includes performing each step, The group of biometric templates includes a plurality of biometric templates, each of which includes a user's biometric template and at least one additional biometric template different from the user's biometric template. Each of the biometric information templates in the biometric information template group is generated based on biometric information data transmitted from each communication device to the service point terminal, or transmitted from each communication device to the service point terminal. For each of the biometric templates in the group of biometric templates, the service point terminal also receives the associated data payload corresponding to that biometric template from the respective communication device, and stores the associated data payload or the data derived from the associated data payload in the associated data block in the memory of the service point terminal. The user's biometric information template, or the user's biometric information data on which the user's biometric information template was generated, is received by the service point terminal from the first communication device. The at least one additional biometric template, which is different from the user's biometric template, or the biometric data on which the at least one biometric template was generated, is received by the service point terminal from a second communication device, and unlike the first communication device, The second data payload transmitted from the service point terminal to the service access control system includes data from a data block identified from the associated data blocks stored in the memory of the service point terminal, or data based on the identified data block, each of which associated data blocks corresponds to a biometric template in the biometric template group. The identified data block is, A positive match determination is obtained from comparing the user's biometric information sample with a matching biometric information template within the biometric information template group, Determining a specific associated data block as an identified data block is a data block that stores either an associated data payload corresponding to the matching biometric template, or data derived from the associated data payload corresponding to the matching biometric template. Based on this, it is identified from the aforementioned related data blocks, Based on the data in the second data payload, the service access control system can determine whether the user is permitted to access the service. A method comprising a service access control system configured to respond to a determination that a user is permitted to access the service by generating a control signal that permits or records the user's access to the service.
12. The user's biometric information template, or the user's biometric information data on which the user's biometric information template was generated, cannot be accessed from the service access control system. The method according to claim 11.
13. Each associated data payload received by the service point terminal is based on an associated communication device data block stored in the memory of the communication device that transmitted the associated data payload, and the associated communication device data block corresponds to an associated service access control system data block stored in the memory accessible by the service access control system. The service access control system determines whether the user is permitted to access the service based on the output of a calculation that includes the data in the second data payload and the data in one or more associated service access control system data blocks. The method according to claim 11.
14. The method according to claim 11, wherein the service access control system is configured to generate a control signal that permits or records a user's access to the service only when it is determined that the user's biometric template or the user's biometric data on which the user's biometric template was generated is authentic.
15. A service point terminal for monitoring or controlling access to services at a service point, Processor and Equipped with memory, The aforementioned service point terminal is The system acquires a sample of the user's biometric information through a biometric information sample acquisition sensor. A comparison of the acquired biometric information sample with the biometric information template group stored in the memory of the service point terminal is performed. The second data payload is sent to the service access control system. Configured to perform each step, The group of biometric templates includes a plurality of biometric templates, each of which includes a user's biometric template and at least one additional biometric template different from the user's biometric template. Each of the biometric information templates in the biometric information template group is generated based on biometric information data transmitted from each communication device to the service point terminal, or transmitted from each communication device to the service point terminal. For each of the biometric templates in the group of biometric templates, the service point terminal also receives the associated data payload corresponding to that biometric template from the respective communication device, and stores the associated data payload or the data derived from the associated data payload in the associated data block in the memory of the service point terminal. The user's biometric information template, or the user's biometric information data on which the user's biometric information template was generated, is received by the service point terminal from the first communication device. The at least one additional biometric template, which is different from the user's biometric template, or the biometric data on which the at least one biometric template was generated, is received by the service point terminal from a second communication device, and unlike the first communication device, The second data payload transmitted from the service point terminal to the service access control system includes data from a data block identified from the associated data blocks stored in the memory of the service point terminal, or data based on the identified data block, each of which associated data blocks corresponds to a biometric template in the biometric template group. The identified data block is, A positive match determination is obtained from comparing the user's biometric information sample with a matching biometric information template within the biometric information template group, Determining a specific associated data block as an identified data block is a data block that stores either an associated data payload corresponding to the matching biometric template, or data derived from the associated data payload corresponding to the matching biometric template. Based on this, it is identified from the aforementioned related data blocks, Based on the data in the second data payload, the service access control system can determine whether the user is permitted to access the service. The service access control system is configured to respond to a determination that the user is permitted to access the service by generating a control signal that permits or records the user's access to the service. Service point terminal.