Systems and methods for peer-to-peer identity verification
The contactless card system facilitates secure and efficient peer-to-peer identity verification by transmitting identity data through NFC, enhancing security and user experience with controlled access management.
Patent Information
- Application Number
- JP2022566171
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-04-30
- Filing Date
- 2021-04-27
- Publication Date
- 2025-12-10
- Estimated Expiration
- 2041-04-27
AI Technical Summary
Peer-to-peer identity verification systems face challenges in ensuring secure and efficient identity assertion without requiring additional input, due to varying security standards and platform compatibility issues.
A contactless card system with a processor and memory, utilizing NFC technology, allows for peer-to-peer identity verification by transmitting identity data through a communication field, enabling notification and access control between devices without additional input, and allowing users to accept or deny access to specified information.
Enhances security and user experience by providing consistent identity verification across different platforms, improving efficiency and reducing the need for additional verification factors.
Smart Images

Figure 0007783833000001 
Figure 0007783833000002 
Figure 0007783833000003
Abstract
Description
[Technical Field]
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims priority to U.S. Patent Application No. 16 / 864,028, filed April 30, 2020, the entire disclosure of which is incorporated herein by reference.
[0002] Technical Field The present disclosure relates to systems and methods for peer-to-peer identity verification. [Background technology]
[0003] In peer-to-peer interactions, disconnections often occur while verifying a user's identity, and there is no source of information that verifies an individual's identity assertion in a secure manner. There are also limitations in handling permissions and application integration. For example, applications may apply different standards to identity assertions or may seek different information for verification purposes. This may result in one application verifying the user while another does not, resulting in different levels of security. Additional input of verification factors or other actions may be required to reach an appropriate level of security. As another example, applications may be based on different platforms that may not be fully compatible, which may reduce communication and functionality between applications and reduce efficiency. Summary of the Invention [Problem to be solved by the invention]
[0004] These and other drawbacks exist. Therefore, what is needed is a system and method for peer-to-peer identity verification that provides improved security and an improved user experience in controlled permission handling and application integration without requiring the input of additional factors. [Means for solving the problem]
[0005] An embodiment of the present disclosure provides an identity verification system including a contactless card with a processor and a memory. The system may include one or more applications including instructions for execution on one or more devices. A first application may be configured to transmit identity data after entry of the contactless card into a communication field. The first application may include instructions for execution on a first client device. A second application may be configured to receive a notification based on the identity verification process. The second application may include instructions for execution on the second client device. The notification may include an option indicating requested access to specified information about the first user. The option may further include a selection to accept or deny access to the specified information about the first user. The first application may be configured to receive the requested access to the specified information about the first user based on a selection of the option. The application may be configured to determine a function associated with the contactless card after the first entry into the communication field. The application may be configured to request additional information based on the determination. The one or more applets may be configured to send a generated tokenized link to an application after the second entry into the communication field based on the requested additional information, and the application may be configured to send the link to obtain the requested additional information.
[0006] An embodiment of the present disclosure provides a method of identity verification. The method may include transmitting identity data by a first application including instructions for execution on a first client device after a contactless card enters a communication field. The method may also include receiving a notification based on identity verification processing of the identity data in a second application including instructions for execution on a second client device. The notification includes options indicating requested access to specified information about the first user, the options including accepting or denying access to the specified information about the first user. The method may also include receiving the requested access to the shareable specified information about the first user based on a selection of the options.
[0007] Embodiments of the present disclosure provide a computer-readable non-transitory medium comprising computer-executable instructions for execution on a processor. The medium includes steps of transmitting identity data related to identity verification by a first application using at least one selected from the group of near field communication (NFC) scanning and image capture of a contactless card, performing an identity verification process on the transmitted identity data, determining a result based on the identity verification process, sending a notification to a second application based on the result, customizing at least one selected from a group of specified information related to the first user and accessing the specified information related to the first user, and receiving a notification including an option associated with requested access to the specified information related to the first user based on the identity verification process of the identity data, and receiving the requested access to the specified information related to the first user based on a selection of the option, wherein the notification further includes a message that an application including instructions for execution on the first client device is communicating with the contactless card and is requesting access to the specified information related to the first user, and the second application includes instructions for execution on a second client device different from the first client device. [Brief explanation of the drawings]
[0008] [Figure 1] 1 illustrates an identity verification system according to an exemplary embodiment. [Figure 2A] 1 is a diagram of a contactless card according to an exemplary embodiment; [Figure 2B] 1 is a diagram of a contact pad of a contactless card according to an exemplary embodiment. [Figure 3] 1 illustrates a method for identity verification according to an exemplary embodiment. [Figure 4] 1 illustrates a method for identity verification according to an exemplary embodiment. [Figure 5] 1 illustrates a method for identity verification according to an exemplary embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0009] The various embodiments of the present disclosure, together with further objects and advantages thereof, may best be understood by reference to the following description taken in conjunction with the accompanying drawings.
[0010] The following description of the embodiments provides non-limiting representative examples, including reference numerals, to particularly explain the features and disclosure of different aspects of the present invention. It should be recognized that the described embodiments can be implemented separately or in combination with other embodiments from the description of the embodiments. Those skilled in the art who review the description of the embodiments should be able to learn and understand the described different aspects of the present invention. The description of the embodiments should facilitate understanding of the present invention to the extent that other examples, even if not specifically covered, will be understood to be in line with the application of the present invention if they are within the knowledge of those skilled in the art who read the description of the embodiments.
[0011] By utilizing NFC mobile and transmitting device capabilities, two individuals can be made identifiable to one another using the systems and methods disclosed herein. A user's card may be scanned by one device, in which case the other device is notified. This notification provides the option to accept or deny access to the user's identity information. Upon acceptance, the user may receive relevant contact information about the other user. No additional input is required, regardless of device type. This represents an improvement over existing implementations by providing better and more consistent security with controlled permission handling and application integration without requiring the input of additional factors for identity verification. In addition to increased security, the user experience is improved, and identification can be performed more efficiently and effectively. Furthermore, identity can be confirmed by revealing only a minimal amount of data (i.e., handing the card to another person), which can be further reduced by the card user retaining control of their card and tapping their card on the other user's device.
[0012] 1 illustrates an identity verification system 100 according to an example embodiment. Identity verification system 100 may include a transmitting device 105, a first application 110, a second application 115, a network 120, a server 125, and a database 130. Although FIG. 1 illustrates a single example of a component of system 100, system 100 may include any number of components.
[0013] System 100 may include transmitting device 105. Transmitting device 105 may comprise a contactless card or other device described herein. As further described in FIGS. 2A-2B below, transmitting device 105 may include one or more processors 102 and memory 104. Memory 104 may include one or more applets 106 and one or more counters 108. Transmitting device 105 may be in data communication with one or more devices 112 and 117. For example, transmitting device 105 may transmit data to client devices 112 and 117 over network 120. In some embodiments, transmitting device 105 may be configured to transmit data to client device 117 over network 120 after client devices 112 and 117 enter one or more communication fields. In some embodiments, transmitting device 105 may be configured to transmit data after each client device 112 and 117 enters one or more communication fields one or more times. Each entry is associated with a gesture, including but not limited to a tap, a swipe, a wave, and / or any combination thereof.
[0014] The system 100 may include a first application 110. For example, the first application 110 may include instructions for execution on a first device 112. The first application 110 may communicate with any component of the system 100. For example, the first device 112 may execute one or more applications, such as the first application 110, that enable network and / or data communication with one or more components of the system 100 and transmit and / or receive data. The first device 112 may include one or more processors 113 coupled to memory 114. For example, the first device 112 may be a computer with network capabilities. As referred to herein, a computer with network capabilities may include a computing device or a communications device, including, for example, but not limited to, a server, network appliance, personal computer, workstation, telephone, handheld PC, personal digital assistant, contactless card, thin client, fat client, Internet browser, or other device. The first device 112 may be a mobile device, for example, the mobile device may include an iPhone, iPod, iPad, or any other mobile device running the iOS operating system from Apple, any device running Microsoft's Windows mobile operating system, any device running Google's Android operating system, and / or any other smartphone, tablet, or similar wearable mobile device.
[0015] The first device 112 may include processing circuitry and may include additional components, including processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and anti-tamper hardware, required to perform the functions described herein. The first device 112 may further include a display and input devices. A display may be any type of device for presenting visual information, such as a computer monitor, flat-panel display, and mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. An input device may include any device for inputting information into a user's device that is available and supported by the user's device, such as a touchscreen, keyboard, mouse, cursor control device, touchscreen, microphone, digital camera, video recorder, or camcorder. These devices may be used to input information and to interact with the software and other devices described herein. In some embodiments, the first device 112 may include at least one selected from the group of a mobile device, a wearable device, a point of sales (POS) system, a kiosk, and a terminal.
[0016] The system 100 may include a second application 115. The first application 115 may include instructions for execution on a second device 117. The second application 115 may communicate with any component of the system 100. For example, the second device 117 may execute one or more applications, such as the second application 115, that enable network and / or data communication with one or more components of the system 100 and transmit and / or receive data. The second device 117 may include one or more processors 116 connected to memory 118. For example, the second device 117 may be a computer with network capabilities. As referred to herein, a computer with network capabilities may include a computing device or a communications device, including, for example, but not limited to, a server, network appliance, personal computer, workstation, telephone, handheld PC, personal digital assistant, contactless card, thin client, fat client, Internet browser, or other device. The second device 117 may be a mobile device, for example, the mobile device may include an iPhone®, iPod®, iPad® from Apple®, or any other mobile device running the iOS® operating system, any device running Microsoft's Windows® mobile operating system, any device running Google's Android® operating system, and / or any other smartphone, tablet, or similar wearable mobile device.
[0017] The second device 117 may include processing circuitry and may include additional components necessary to perform the functions described herein, including processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and anti-tamper hardware. The second device 117 may further include a display and input devices. The display may be any type of device for presenting visual information, such as a computer monitor, flat panel display, and mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. The input devices may include any device for inputting information into the user's device that is available and supported by the user's device, such as a touch screen, keyboard, mouse, cursor control device, touch screen, microphone, digital camera, video recorder, or camcorder. These devices may be used to input information and to interact with the software and other devices described herein. In some embodiments, the second device 117 may include at least one selected from the group of a mobile device, a wearable device, and a kiosk.
[0018] System 100 may include network 120. In some embodiments, network 120 may be one or more of a wireless network, a wired network, or any combination of a wireless network and a wired network, and may be configured to connect to any one of the components of system 100. For example, client devices 112 and 117 may be configured to connect to server 125 via network 120. In some embodiments, network 120 may include one or more of a fiber optic network, a passive optical network, a cable network, an Internet network, a satellite network, a wireless local area network (LAN), a Global System for Mobile Communication (GSM), Personal Communications Services (PCS), a personal area network, a wireless application protocol, a multimedia message service, an enhanced messaging service (EMS), a short message service, a time division multiplexing based system, a code division multiple access based system, D-AMPS, Wi-Fi, Fixed Wireless Data (FWD), IEEE 802.11b, 802.15.1, 802.11n, and 802.11g, Bluetooth, NFC, radio frequency identification (RFID), Wi-Fi, and the like.
[0019] Additionally, network 120 may include, but is not limited to, telephone lines, fiber optics, IEEE Ethernet 902.3, a wide area network, a wireless personal area network, a LAN, or a global network such as the Internet. Furthermore, network 120 may support an Internet network, a wireless communication network, a cellular network, or the like, or any combination thereof. Network 120 may further include one or more of the exemplary types of networks described above, operating as a standalone network or cooperating with one another. Network 120 may utilize one or more protocols of one or more network components to which it is communicatively connected. Network 120 may translate between one or more protocols of network devices and other protocols. While network 120 is depicted as a single network, it should be appreciated that, according to one or more embodiments, network 120 may comprise multiple interconnected networks, such as the Internet, a service provider network, a cable television network, an enterprise network such as a credit card association network, and a home network.
[0020] Client devices 112 and 117 may communicate with one or more servers 125 over one or more networks 120 and may operate with server 125 as a respective front-end to back-end pair. Client devices 112 and 117 may send one or more requests to server 125, for example, from mobile device applications 110 and 115 executing thereon. The one or more requests may be associated with search data from server 125. Server 125 may receive one or more requests from client devices 112 and 117. Based on the one or more requests from client applications 110 and 115, server 125 may be configured to search for the requested data. Server 125 may be configured to send the received data to client applications 110 and 115 in response to the one or more requests.
[0021] System 100 may include one or more servers 125. In some embodiments, server 125 may include one or more processors 127 coupled to memory 129. Server 125 may be configured as a central system, server, or platform that controls and accesses various data to perform multiple workflow operations at different times. Server 125 may be configured to connect to one or more client devices 112 and 117. Server 125 may be in data communication with client applications 110 and 115. For example, server 125 may be in data communication with client applications 110 and 115 via one or more networks 120.
[0022] System 100 may include one or more databases 130. Database 130 may comprise a relational database, a non-relational database, or other database implementation, or any combination thereof, including multiple relational and non-relational databases. In some embodiments, database 130 may comprise a desktop database, a mobile database, or an in-memory database. Furthermore, database 130 may be hosted internally by devices 112 and 117, or database 130 may be hosted externally to devices 112 and 117, for example, by server 125, by a cloud-based platform, or on any storage device in data communication with devices 112 and 117. In some embodiments, database 130 may be in data communication with any number of components of system 100. For example, server 125 may be configured to retrieve requested data sent by applications 110 and 115 from database 130. Server 125 may be configured to transmit data received from database 130 to client applications 110 and 115 over network 120 in response to one or more transmitted requests. In other embodiments, client applications 110 and 115 may be configured to transmit one or more requests for the requested data from database 130 over network 120.
[0023] In some embodiments, the exemplary procedures according to the present disclosure described herein may be performed by a processing and / or computing device (e.g., a computer hardware device). Such a processing / computing device may be, for example, in whole or in part, or may include, but is not limited to, a computer / processor. The computer / processor may include, for example, one or more microprocessors and may use instructions stored on a computer-accessible medium (e.g., RAM, ROM, hard drive, or other storage device). For example, the computer-accessible medium may be part of the memory of the client device 112, 117 and / or the server 125, or other computer hardware device.
[0024] In some embodiments, a computer-accessible medium (e.g., as described herein above, a storage device such as a hard disk, a floppy disk, a memory stick, a CD-ROM, RAM, ROM, etc., or a collection thereof) may be provided (e.g., in communication with a processing device). The computer-accessible medium may have executable instructions stored thereon. Additionally or alternatively, a storage device may be provided separate from the computer-accessible medium, which may provide instructions to the processing device, e.g., to configure the processing device to perform certain example procedures, processes, and methods, as described herein.
[0025] The first application 110 may be configured to transmit identity data after entry of the contactless card 105 into the communication field of the device 112. The entry may occur via one or more gestures, including, but not limited to, a tap, a swipe, a wave, and / or any combination thereof. As described above, the first application 110 may include instructions for execution on the first client device 112. In some embodiments, the identity data may be transmitted to the device 117. In some embodiments, the identity data may be transmitted to the server 125. Without limitation, the identity data may include at least one selected from the group of a name, an address, an account number, a credit card number, a social security number, a password, a one-time passcode, and biometric information (e.g., a fingerprint, facial recognition, voice recognition, a retinal scan).
[0026] The second application 115 may be configured to receive one or more notifications based on the identity verification process. As described above, the second application 115 may include instructions for execution on the second client device 117. Without limitation, the identity verification process may include a comparison between the identity data and the reference data. In some embodiments, the reference data may be stored on the server 125. In other embodiments, the reference data may be retrieved by the server 125 from the database 130. For example, the server 125 may send one or more requests to the database 130 to retrieve data such as the reference data. The database 130 may be configured to transmit the data such as the reference data in response to one or more requests from the server 125. In some embodiments, the server 125 may be configured to perform the identity verification process. For example, the server 125 may be configured to compare the identity data with the reference data to determine a result. Server 125 may be configured to compare at least one selected from the group of a name, an address, an account number, a credit card number, a social security number, a password, a one-time passcode, and biometric information (e.g., fingerprint, facial recognition, voice recognition, retinal scan), and / or any combination thereof, with reference data. For example, server 125 may be configured to compare passwords and one-time passcodes with reference passwords and reference one-time passcodes.
[0027] In some embodiments, server 125 may be configured to improve security by requiring one or more additional comparisons to perform one or more iterations of the identity verification process. Continuing with the previous embodiment, server 125 may be configured to compare, without limitation, the password and one-time passcode with the reference password and reference one-time passcode, and then compare the account number of the identity data with the reference account number. For example, server 125 may send one or more requests to database 130 to retrieve data such as reference data, including but not limited to, the reference account number. Database 130 may be configured to transmit data such as reference data, including but not limited to, the reference account number, in response to one or more requests from server 125.
[0028] The server 125 may be configured to determine a result based on the identity verification process. In some embodiments, the result of the identity verification process may include a match between the identity data and the reference data. In other embodiments, the result of the identity verification process may include a mismatch between the identity data and the reference data. Without limitation, the mismatch may trigger a comparison of at least one selected from the group of a name, an address, an account number, a credit card number, a social security number, a password, a one-time passcode, and biometric information (e.g., a fingerprint, facial recognition, voice recognition, retinal scan) with the reference data. For example, the original request may include a comparison between a password and reference password data, whereas the updated request after determining a mismatch may include a password and one-time passcode and reference password and one-time passcode data. In another embodiment, the original request may include a comparison between an account number and a reference account number, and the updated request after determining a mismatch may include a comparison between the biometric information and the reference biometric comparison. In some embodiments, the requested identity data may be the same as the updated request for identity data after determining a mismatch. The server 125 may be configured to send one or more notifications to the second application 115 based on the results.
[0029] In some embodiments, second application 115 may be configured to perform a pre-verification process before displaying one or more notifications. For example, second application 115 may be configured to perform a pre-verification process by requiring authentication of one or more login credentials before displaying the notification. Second application 115 may be configured to display the one or more notifications. In some embodiments, the at least one login credential may include a password credential. In some embodiments, the at least one login credential may include a biometric credential. For example, the biometric credential may include at least one selected from the group of a fingerprint, facial recognition, voice recognition, a retina scan, and / or any combination thereof. In other embodiments, the one or more login credentials may comprise a password credential, a biometric credential, and / or any combination thereof.
[0030] In some embodiments, the at least one notification may include options indicating requested access to the specified information about the first user. For example, the options may include a selection to accept or deny access to the specified information about the first user. In some embodiments, the second application 115 may be configured to modify at least one selected piece of the group of specified information about the first user to access the specified information about the first user. In some embodiments, the notification may further include a message that the first client application 110 of the first device 112 is communicating with the contactless card 105 and is requesting access to the specified information about the first user. In some embodiments, the notification may further include a menu of shareable specified information about the first user. In some embodiments, the notification may be configured to allow a response to be shared from which the user may select and / or search for additional information. In this manner, the identity of a first user may be confirmed by revealing only a minimal amount of data, including but not limited to, handing over a transmitting device or card to a second user; this may be further reduced by the card user retaining control of their card and gesturing their card itself at the other user's device, e.g., tapping, swiping, waving, and / or any combination thereof. Without limitation, the menu may include at least one selected from the group of first name, last name, gender, IP address, email address, address, phone number, transaction information (e.g., merchant, location, purchased goods / services, purchase price, purchase terms, return and refund policy), transaction history (e.g., transaction information for previous transactions), account information, date of birth, and / or any combination thereof. In some embodiments, the menu may be customized to include the same or different parameters for different users and / or different devices.For example, a menu may be customized to include only email addresses and phone numbers for one user associated with the mobile device, while the menu may be customized to include only account information and birthdates for other users associated with the mobile device. In another embodiment, the menu may be customized to include only transaction information for users associated with the kiosk. The menu may also be customized based on previous recognition and / or verification of different users and / or different devices, thereby including saved settings for each of the customized menu parameters associated with different users and / or different devices.
[0031] The first application 110 may be configured to receive requested access to specified information about the first user based on the selection of an option. For example, the first application 110 may be configured to receive access to specified information about the first user based on the selection of an accepted access. In some embodiments, the selection of an option may be associated with a predetermined duration before a timeout of the requested access. In some embodiments, when the timeout of the requested access expires, the identity verification process may end and no longer provide a selection of options. In other embodiments, when the timeout of the requested access expires, the identity verification process may begin again for the same or a different predetermined duration.
[0032] In some embodiments, access to specified information about the first user may be associated with one or more permissions that may be overridden by the second application 115. For example, at least one permission may include a geographic restriction. In this case, the second application 115 may be configured to revoke access to specified information about the first user based on the geographic restriction, such that access is provided only when the first application 110 is within a predetermined distance from the second device 117 within a given location.
[0033] In another embodiment, the at least one permission may include pre-authorized verification. For example, the second application 115 may be configured to revoke access to specified information about the first user if the first application 110 has not received pre-authorized verification. In some embodiments, the pre-authorized verification may be part of an authorization list that has already authorized the first application 110 to receive the requested access. In some embodiments, the pre-authorized verification may be based, for example, on whether the first application 110 has previously received the requested access within a predetermined time period, prior transaction history, and / or any combination thereof.
[0034] In another embodiment, the at least one permission may include at least one selected from personally identifiable information, transaction type, merchant type, and / or any combination thereof. For example, the second application 115 may be configured to revoke access to specified information about the first user if the request includes any portion of personally identifiable information, including, but not limited to, first name, last name, email, age, gender, date of birth, location, insurance information, and / or any combination thereof, unless previously authorized and / or partially redacted.
[0035] In another embodiment, the second application 115 may be configured to revoke access to specified information about the first user if the request does not match an authorized transaction type, such as a transaction for payment, personally identifiable information, and / or any combination thereof.
[0036] In another embodiment, the second application 115 may be configured to revoke access to specified information regarding the first user if the request does not match an authorized merchant type, such as a doctor, pharmacist, financial institution, grocery store, government entity, etc. For example, the second application 115 may be configured to revoke access to specified information regarding the first user if the request does not include a matching identifier associated with a merchant or merchant type, such as a doctor, pharmacist, financial institution, grocery store, government entity, etc.
[0037] In another embodiment, the second application 115 may be configured to disable access to the specified information about the first user if the request is made above a predetermined threshold, such as excessively frequent requests within a given time period. The second application 115 may also be configured to disable access to the specified information about the first user if the request is made on an unusual or otherwise irregular day, time, and / or any combination thereof. For example, if the request is not made during normal business hours or is made on a day and / or time that does not match previous request history, access to the specified information about the first user may be disabled by the second application. Thus, when evaluating whether to disable access to the specified information about the first user, the second application 115 may be configured to determine whether the request matches previous requests by the user and / or device.
[0038] In some embodiments, the second application 115 may include instructions for execution on a second client device 117 that is different from the first client device 112 on which the first application 110 includes instructions for execution. For example, the second application 115 may include instructions for execution on a mobile device, whereas the first application 110 may include instructions for execution on a kiosk. It is also understood that, as described herein, a user is not limited to being a person. In some embodiments, a user may include or be associated with any device. For example, it may include a lockbox for retrieving one or more items, such as packages. In another embodiment, it may include a device associated with a pharmacy, a store, a school, a restaurant, a hotel, an airport, a vehicle, a market, a garage, a residential or non-residential building, etc.
[0039] Figure 2A shows one or more transmitting devices 200. The transmitting devices 200 may reference or include the same or similar components of the transmitting device or contactless card 105, as described above with respect to Figure 1. Figures 2A and 2B show a single example of components of the transmitting device 200, although any number of components may be utilized.
[0040] Transmitting device 200 may be configured to communicate with one or more components of system 100. Transmitting device 200 may comprise a contactless card, which may comprise a payment card such as a credit card, debit card, or gift card issued by service provider 205 displayed on the front or back of card 200. In some embodiments, contactless card 200 is not related to payment cards and may include, but is not limited to, identification cards. In some embodiments, the payment card may comprise a dual-interface contactless payment card. Contactless card 200 may comprise a substrate 210, which may include a single layer or one or more laminated layers of plastic, metal, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl acetate chloride, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium, palladium, gold, carbon, paper, and biodegradable materials. In some embodiments, contactless card 200 may have physical characteristics that conform to the ID-1 format of the ISO / IEC 7810 standard, or contactless cards may conform to the ISO / IEC 14443 standard. However, it is understood that contactless card 200 according to the present disclosure may have different characteristics, and the present disclosure does not require that the contactless card be implemented as a payment card.
[0041] Contactless card 200 may include identification information 215 displayed on the front and / or back of the card and a contact pad 220. Contact pad 220 may be configured to establish contact with another communication device, including, but not limited to, a user device, a smartphone, a laptop, a desktop, or a tablet computer. Contactless card 200 may include processing circuitry, an antenna, and other components not shown in FIG. 2A . These components may be located behind contact pad 220 or elsewhere on substrate 210. Contactless card 200 may also include a magnetic strip or tape, which may be located on the back of the card (not shown in FIG. 2A ).
[0042] As shown in Figure 2B, the contact pad 220 of Figure 2A may include processing circuitry 225, including a microprocessor 230 and memory 235, for storing and processing information. It is understood that processing circuitry 225 may include additional components, including processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and anti-tamper hardware, required to perform the functions described herein.
[0043] The memory 235 may be a read-only memory, a write-once-read-many memory, or a read / write memory, such as RAM, ROM, and EEPROM, and the contactless card 200 may include one or more of these memories. Read-only memory is programmable at the factory to be read-only or one-time programmable. One-time programmability provides the opportunity to be written once and then read multiple times. Write-once-read-many memory may be programmed at a time after the memory chip leaves the factory. Once the memory is programmed, it is not rewritten but is read multiple times. Read / write memory may be programmed and reprogrammed multiple times after leaving the factory, and it may be read many times.
[0044] Memory 235 may be configured to store one or more applets 240, one or more counters 245, and a customer identifier 250. One or more applets 240 may include one or more software applications configured to run on one or more contactless cards, such as a Java Card applet. However, it is understood that applet 240 is not limited to a Java Card applet and may instead be any software application operable on a contactless card or other device with limited memory. One or more counters 245 may comprise a numeric counter sufficient to store an integer. Customer identifier 250 may include a unique alphanumeric identifier assigned to a user of contactless card 200, which may distinguish the contactless card user from other contactless card users. In some embodiments, customer identifier 250 may identify both the customer and the account assigned to the customer, and may further identify the contactless card associated with the customer's account.
[0045] Although the processor and memory components of the exemplary embodiments described above are described with reference to contact pads, the present disclosure is not so limited. These components may be implemented external to or completely separate from the pads 220, or may be implemented as additional components in addition to the processor 230 and memory 235 components provided within the contact pads 220.
[0046] In some embodiments, contactless card 200 may include one or more antennas 255. One or more antennas 255 may be disposed within contactless card 200 around processing circuit 225 of contact pad 220. For example, one or more antennas 255 may be integrated into processing circuit 225, or one or more antennas 255 may be used in conjunction with an external booster coil. As another example, one or more antennas 255 may be external to contact pad 220 and processing circuit 225.
[0047] In one embodiment, the coil of the contactless card 200 may act as a secondary winding of an air-core transformer. The terminal may communicate with the contactless card 200 by interrupting power or amplitude modulation. The contactless card 200 may use gaps in the contactless card's power connection to infer data transmitted from the terminal. The power connection may be maintained functionally through one or more capacitors. The contactless card 200 may communicate in the reverse direction by switching a load or modulating the load on the contactless card's coil. The load modulation may be detected in the terminal's coil through interference.
[0048] Figure 3 illustrates a method 300 for identity verification according to an example embodiment, which may reference or include the same or similar components of the system 100 of Figure 1 and the transmitting device 200 of Figures 2A and 2B.
[0049] At block 305, method 300 includes entering a card into a communication field of the device. For example, the entry may occur via one or more gestures, including, but not limited to, a tap, a swipe, a wave, and / or any combination thereof. As described above, the first application may include instructions for execution on the first client device. In some embodiments, the entry may be performed by a card user. In other embodiments, the entry may be performed by a client device user.
[0050] At block 310, the method 300 may include transmitting identity data by a first application including instructions for execution on the first client device after the contactless card enters the communication field. The identity data may include, without limitation, at least one selected from the group of: name, address, account number, credit card number, social security number, password, one-time passcode, and biometric information (e.g., fingerprint, facial recognition, voice recognition, retinal scan).
[0051] At block 315, method 300 may include performing an identity verification process on the identity data. Without limitation, the identity verification process may include a comparison between the identity data and reference data. In some embodiments, the reference data may be stored on a server. In other embodiments, the reference data may be retrieved from a database by the server. For example, the server may send one or more requests to the database to retrieve data such as the reference data. The database may be configured to transmit data such as the reference data in response to one or more requests from the server. In some embodiments, the server may be configured to perform the identity verification process. For example, the server may be configured to compare the identity data with the reference data to determine a result. In other embodiments, a second application may be configured to perform the identity verification process. For example, the second application may be configured to compare the identity data with reference data stored on a second device to determine a result.
[0052] The server and / or the second application may be configured to compare at least one selected from the group of a name, an address, an account number, a credit card number, a social security number, a password, a one-time passcode, and biometric information (e.g., a fingerprint, facial recognition, voice recognition, a retinal scan), and / or any combination thereof, with the reference data. For example, the server may be configured to compare the password and the one-time passcode with the reference password and the reference one-time passcode.
[0053] In some embodiments, the server and / or the second application may be configured to improve authentication security by requesting one or more additional comparisons to perform one or more iterations of the identity verification process. Continuing with reference to the previous embodiment, the server may be configured to compare, without limitation, the password and one-time passcode with the reference password and reference one-time passcode, and then compare the account number of the identity data with the reference account number. For example, the server may send one or more requests to a database to retrieve data such as reference data, including but not limited to the reference account number. The database may be configured to send data such as reference data, including but not limited to the reference account number, in response to the one or more requests from the server.
[0054] In other embodiments, the second application may be configured to compare the identity data with reference data accessible to the second device, for example, by submitting a request or retrieving the reference data from a server. In some embodiments, the result of the identity verification process may include a match between the identity data and the reference data. In some embodiments, the result of the identity verification process may include a mismatch between the identity data and the reference data. In some embodiments, if the result includes a mismatch, the identity verification process may terminate, and the identity verification process may be restarted by the server and / or the second application by requesting additional information and / or information different from the original request to compare the identity data with the reference data. Without limitation, a mismatch may trigger a comparison of at least one selected from the group of name, address, account number, credit card number, Social Security number, password, one-time passcode, and biometric information (e.g., fingerprint, facial recognition, voice recognition, retinal scan) with the reference data. For example, the original request may include a comparison between a password and reference password data, whereas the updated request after determining a mismatch may include a password and one-time passcode and reference password and one-time passcode data. In another embodiment, the original request may include a comparison between an account number and a reference account number, whereas the updated request after determining a mismatch may include a comparison between biometric information and the reference biometric comparison. In some embodiments, the requested identity data may be the same as the updated request for identity data after determining a mismatch.
[0055] The server may be configured to determine a result based on the identity verification process. The server may be configured to send one or more notifications to the second application based on the result. In other embodiments, the second application may be configured to determine a result based on the identity verification process. In other embodiments, the second application may be configured to send one or more notifications based on the result.
[0056] At block 320, method 300 may include receiving, at a second application including instructions for execution on the second client device, a notification based on the identity verification process of the identity data. The notification includes options indicating requested access to specified information about the first user, including options to accept or deny access to the specified information about the first user. For example, the second application may be configured to receive one or more notifications based on the identity verification process.
[0057] In some embodiments, the second application may be configured to perform a pre-verification process before displaying the one or more notifications. For example, the second application may be configured to perform the pre-verification process by requiring authentication of one or more login credentials before displaying the notifications. The second application may be configured to display the one or more notifications. In some embodiments, the at least one login credential may include a password credential. In some embodiments, the at least one login credential may include a biometric credential. For example, the biometric credential may include at least one selected from the group of a fingerprint, facial recognition, voice recognition, a retina scan, and / or any combination thereof. In other embodiments, the one or more login credentials may comprise a password credential, a biometric credential, and / or any combination thereof.
[0058] In some embodiments, the at least one notification may include options indicating requested access to specified information about the first user. For example, the options may include a selection to accept or deny access to the specified information about the first user. In some embodiments, the second application may be configured to modify at least one selected from a group of specified information about the first user to access the specified information about the first user. In some embodiments, the notification may further include a message that a first client application on the first device is communicating with the contactless card and is requesting access to the specified information about the first user. In some embodiments, the notification may further include a menu of shareable specified information about the first user. For example, the menu may include at least one selected from the group of first name, last name, gender, IP address, email address, address, telephone number, transaction information, account information, date of birth, and / or any combination thereof. In some embodiments, the menu may be customized to include the same or different parameters for different users and / or different devices. For example, a menu may be customized to include only email addresses and phone numbers for one user associated with the mobile device, while the menu may be customized to include only account information and birthdates for other users associated with the mobile device. In another embodiment, the menu may be customized to include only transaction information for users associated with the kiosk. The menu may also be customized based on previous recognition and / or verification of different users and / or different devices, thereby including saved settings for each of the customized menu parameters associated with different users and / or different devices.
[0059] At block 325, method 300 may include receiving requested access to shareable specified information about the first user based on the selection of an option. For example, a first application may be configured to receive requested access to specified information about the first user based on the selection of an option associated with a customized menu. For example, a first application may be configured to receive access to specified information about the first user based on the selection of the accepted access. In some embodiments, the selection of the option may be associated with a predetermined duration before a timeout of the requested access. In some embodiments, when the timeout of the requested access expires, the identity verification process may end and no longer provide a selection of options. In other embodiments, when the timeout of the requested access expires, the identity verification process may be initiated again for the same or a different predetermined duration.
[0060] In some embodiments, access to specified information about the first user may be associated with one or more permissions that can be overridden by the second application. For example, at least one permission may include a geographic restriction. In this case, the second application may be configured to override access to specified information about the first user based on the geographic restriction, such that access is provided only when the first application is within a predetermined distance from the second device within a given location.
[0061] In another embodiment, the at least one permission may include pre-authorized verification. For example, the second application may be configured to revoke access to specified information about the first user if the first application has not received pre-authorized verification. In some embodiments, the pre-authorized verification may be part of an authorization list that already authorizes the first application to receive the requested access. In some embodiments, the pre-authorized verification may be based, for example, on whether the first application has previously received the requested access within a predetermined time period, prior transaction history, and / or any combination thereof.
[0062] In another embodiment, the at least one permission may include at least one selected from personally identifiable information, transaction type, merchant type, and / or any combination thereof. For example, the second application may be configured to revoke access to specified information about the first user if the request includes any portion of personally identifiable information, including, but not limited to, first name, last name, email, age, gender, date of birth, location, insurance information, and / or any combination thereof, unless previously authorized and / or partially redacted.
[0063] In another embodiment, the second application may be configured to revoke access to specified information about the first user if the request does not match an authorized transaction type, such as a transaction for payment, personally identifiable information, and / or any combination thereof.
[0064] In another embodiment, the second application may be configured to revoke access to specified information regarding the first user if the request does not match an authorized merchant type, such as a doctor, pharmacist, financial institution, grocery store, government entity, etc. For example, the second application may be configured to revoke access to specified information regarding the first user if the request does not include a matching identifier associated with a merchant or merchant type, such as a doctor, pharmacist, financial institution, grocery store, government entity, etc.
[0065] In another embodiment, the second application may be configured to disable access to the specified information about the first user if the request is made above a predetermined threshold, such as excessively frequent requests within a given time period. The second application may be configured to disable access to the specified information about the first user if the request is made on an unusual or otherwise irregular day, time, and / or any combination thereof. For example, if the request is not made during normal business hours or if the request is made on a day and / or time that does not match previous request history, access to the specified information about the first user may be disabled by the second application. Thus, when evaluating whether to disable access to the specified information about the first user, the second application may be configured to determine whether the request matches previous requests by the user and / or device.
[0066] In some embodiments, the second application may include instructions for execution on a second client device that is different from the first client device on which the first application includes instructions for execution. For example, the second application may include instructions for execution on a mobile device, whereas the first application may include instructions for execution on a kiosk. It is also understood that, as described herein, a user is not limited to being a person. In some embodiments, a user may include or be associated with any device. For example, it may include a lockbox for retrieving one or more items, such as packages. In another embodiment, it may include a device associated with a pharmacy, a store, a school, a restaurant, a hotel, an airport, a vehicle, a market, a garage, a residential or non-residential building, etc.
[0067] 4 illustrates a method 400 for identity verification according to an example embodiment, which may reference or include the same or similar components of the system 100 of FIG. 1, the transmitting device 200 of FIGS. 2A and 2B, and the method 300 of FIG. 3.
[0068] At block 405, method 400 may include one or more cards entering one or more communication fields of one or more devices. For example, the entry of each card may occur via one or more gestures, including, but not limited to, a tap, a swipe, a wave, and / or any combination thereof. A communication field may be associated with a single device or multiple devices. Each device may include an application containing instructions for execution thereon.
[0069] For example, a first user may be associated with a first device and a first card. A second user may be associated with a second device and a second card. The second card may enter the communication field of the first device, e.g., via one or more gestures. In some embodiments, the entry may be performed by the card user. In other embodiments, the entry may be performed by the client device user. The second card may be read by the first application to authorize access. For example, a user of a device having a communication field into which the card has entered, e.g., via a tap, a swipe, a wave, and / or any combination thereof, may be prompted to view the card user's identity and to confirm that the user is the intended user to be verified. For example, the device user may be prompted to accept when viewing the card user's identity and thereby confirming that the user is the intended user to be verified. Alternatively, the device user may be prompted to decline when viewing the card user's identity and thereby failing to confirm.
[0070] At block 410, method 400 may include transmitting identity data by a first application including instructions for execution on the first client device after the contactless card enters the communication field. The identity data may include, without limitation, at least one selected from the group consisting of a name, an address, an account number, a credit card number, a social security number, a password, a one-time passcode, and biometric information (e.g., a fingerprint, facial recognition, voice recognition, or retinal scan). The method may further include performing an identity verification process on the identity data. For example, the identity verification process may include a comparison between the identity data and reference data. In some embodiments, a server may be configured to perform the identity verification process. For example, the server may be configured to compare the identity data with the reference data to determine a result. In other embodiments, a second application may be configured to perform the identity verification process. For example, the second application may be configured to compare the identity data with reference data stored on the second device to determine a result. In other embodiments, the second application may be configured to compare the identity data with reference data accessible to the second device, for example by submitting a request or retrieving the reference data from a server.
[0071] In some embodiments, the server may be configured to determine a result based on the identity verification process. In some embodiments, the result may include a match between the identity data and the reference data. In some embodiments, the result may include a mismatch between the identity data and the reference data. Without limitation, the mismatch may trigger a comparison of at least one selected from the group of name, address, account number, credit card number, Social Security number, password, one-time passcode, and biometric information (e.g., fingerprint, facial recognition, voice recognition, retinal scan) with the reference data. For example, the original request may include a comparison between the password and the reference password data, whereas the updated request after determining the mismatch result may include the password and the one-time passcode and the reference password and one-time passcode data. In another embodiment, the original request may include a comparison between the account number and the reference account number, and the updated request after determining the mismatch result may include a comparison between the biometric information and the reference biometric comparison. In some embodiments, the requested identity data may be the same as the updated request for identity data after determining the mismatch result. The server may be configured to send one or more notifications to the second application based on the results. In other embodiments, the second application may be configured to determine a result based on the identity verification process. In other embodiments, the second application may be configured to send one or more notifications based on the results.
[0072] At block 420, method 400 may include transmitting approval after the application approves access by selecting a button. At block 425, method 400 may include, in response to the approval, presenting additional data about the second user by the first application. Without limitation, the additional data may include at least one selected from the group consisting of first name, last name, gender, IP address, email address, address, phone number, transaction information (e.g., merchant, location, purchased goods / services, purchase price, purchase terms, return and refund policy), transaction history (e.g., transaction information for previous transactions), account information, date of birth, and / or any combination thereof. In this manner, the first application may be configured to prompt for authorized access, where verification of the second user is required based on the additional presented data. Thus, this embodiment acts as a second verification of the second user to avoid obtaining a fraudulent card, in which case only minimal information about the second user is revealed.
[0073] Figure 5 illustrates a method 500 for identity verification according to an example embodiment. Figure 5 may reference or include the same or similar components of system 100 of Figure 1, transmitting device 200 of Figures 2A and 2B, method 300 of Figure 3, and method 400 of Figure 4.
[0074] At block 505, method 500 includes entering a card into a communication field of the device. For example, the entry may occur via one or more gestures, including, but not limited to, a tap, a swipe, a wave, and / or any combination thereof. As described above, the first application may include instructions for execution on the first client device. In some embodiments, the entry may be performed by a card user. In other embodiments, the entry may be performed by a client device user.
[0075] At block 510, the method 500 may include transmitting identity data by a first application including instructions for execution on the first client device after the contactless card enters the communication field. The identity data may include, without limitation, at least one selected from the group of: name, address, account number, credit card number, social security number, password, one-time passcode, and biometric information (e.g., fingerprint, facial recognition, voice recognition, retinal scan).
[0076] At block 515, method 500 may include performing an identity verification process on the identity data. Without limitation, the identity verification process may include a comparison between the identity data and reference data. In some embodiments, the reference data may be stored on a server. In other embodiments, the reference data may be retrieved from a database by the server. For example, the server may send one or more requests to the database to retrieve data such as the reference data. The database may be configured to transmit data such as the reference data in response to one or more requests from the server. In some embodiments, the server may be configured to perform the identity verification process. For example, the server may be configured to compare the identity data with the reference data to determine a result. In other embodiments, a second application may be configured to perform the identity verification process. For example, the second application may be configured to compare the identity data with reference data stored on a second device to determine a result.
[0077] The server and / or the second application may be configured to compare at least one selected from the group of a name, an address, an account number, a credit card number, a social security number, a password, a one-time passcode, and biometric information (e.g., a fingerprint, facial recognition, voice recognition, a retinal scan), and / or any combination thereof, with the reference data. For example, the server may be configured to compare the password and the one-time passcode with the reference password and the reference one-time passcode.
[0078] In block 520, the server and / or application may be configured to improve authentication security by requesting one or more additional comparisons to perform one or more iterations of the identity verification process, such as one or more additional identity verification processes. Continuing with the previous example, the server may be configured to, without limitation, compare the password and one-time passcode with the reference password and reference one-time passcode, and then compare the account number of the identity data with the reference account number. For example, the server may send one or more requests to a database to retrieve data such as reference data, including but not limited to the reference account number. The database may be configured to send data such as reference data, including but not limited to the reference account number, in response to the one or more requests from the server.
[0079] In other embodiments, the second application may be configured to compare the identity data with reference data accessible to the second device, for example, by submitting a request or retrieving the reference data from a server. In some embodiments, the result of the identity verification process may include a match between the identity data and the reference data. In some embodiments, the result of the identity verification process may include a mismatch between the identity data and the reference data. In some embodiments, if the result includes a mismatch, the identity verification process may terminate, and the identity verification process may be restarted by the server and / or the second application by requesting additional information and / or information different from the original request to compare the identity data with the reference data. Without limitation, a mismatch may trigger a comparison of at least one selected from the group of name, address, account number, credit card number, Social Security number, password, one-time passcode, and biometric information (e.g., fingerprint, facial recognition, voice recognition, retinal scan) with the reference data. For example, the original request may include a comparison between a password and reference password data, whereas the updated request after determining a mismatch may include a password and one-time passcode and reference password and one-time passcode data. In another embodiment, the original request may include a comparison between an account number and a reference account number, whereas the updated request after determining a mismatch may include a comparison between biometric information and the reference biometric comparison. In some embodiments, the requested identity data may be the same as the updated request for identity data after determining a mismatch.
[0080] The server may be configured to determine a result based on the identity verification process. The server may be configured to send one or more notifications to the second application based on the result. In other embodiments, the second application may be configured to determine a result based on the identity verification process. In other embodiments, the second application may be configured to send one or more notifications based on the result.
[0081] At block 525, method 500 may include receiving, at a second application including instructions for execution on the second client device, a notification based on the identity verification process of the identity data. The notification includes options indicating requested access to specified information about the first user, the options including accepting or denying access to the specified information about the first user. For example, the second application may be configured to receive one or more notifications based on the identity verification process.
[0082] At block 530, the second application may be configured to perform a pre-verification process before displaying the one or more notifications. For example, the second application may be configured to perform the pre-verification process by requiring authentication entry of one or more login credentials before displaying the notifications. The second application may be configured to display the one or more notifications. In some embodiments, the at least one login credential may include a password credential. In some embodiments, the at least one login credential may include a biometric credential. For example, the biometric credential may include at least one selected from the group of a fingerprint, facial recognition, voice recognition, a retina scan, and / or any combination thereof. In other embodiments, the one or more login credentials may comprise a password credential, a biometric credential, and / or any combination thereof.
[0083] In some embodiments, the at least one notification may include an option indicating requested access to the specified information about the first user. For example, the option may include a selection to accept or deny access to the specified information about the first user. In some embodiments, the second application may be configured to modify at least one selected from a group of specified information about the first user to access the specified information about the first user. In some embodiments, the notification may further include a message that a first client application on the first device is communicating with the contactless card and is requesting access to the specified information about the first user.
[0084] At block 535, method 500 may include generating a customized menu of shareable designated information for the first user based on the user and / or device. In some embodiments, the notification may further include a menu of shareable designated information for the first user. For example, the menu may include at least one selected from the group of first name, last name, gender, IP address, email address, mailing address, phone number, transaction information, account information, date of birth, and / or any combination thereof. In some embodiments, the menu may be customized to include the same or different parameters for different users and / or different devices. For example, a menu may be customized to include only email addresses and phone numbers for one user associated with the mobile device, whereas the menu may be customized to include only account information and birth dates for other users associated with the mobile device. In another embodiment, the menu may be customized to include only transaction information for users associated with the kiosk. The menu may also be customized based on previous recognition and / or verification of different users and / or different devices, thereby including saved settings for each of the customized menu parameters associated with different users and / or different devices.
[0085] At block 540, method 500 may include revoking access to the specified information regarding the first user. In some embodiments, the requested access to the specified information regarding the first user may be received based on a selection of an option associated with a customized menu. For example, the first application may be configured to receive the requested access to the specified information regarding the first user based on the selection of the option. For example, the first application may be configured to receive access to the specified information regarding the first user based on the selection of the accepted access. In some embodiments, the selection of the option may be associated with a predetermined duration before a timeout of the requested access. In some embodiments, when the timeout of the requested access expires, the identity verification process may end and no longer provide a selection of options. In other embodiments, when the timeout of the requested access expires, the identity verification process may be initiated again for the same or a different predetermined duration.
[0086] Additionally, access to the specified information about the first user may be associated with one or more permissions that may be overridden by the second application. For example, at least one permission may include a geographic restriction. In this case, the second application may be configured to revoke access to the specified information about the first user based on the geographic restriction, such that access is provided only when the first application is within a predetermined distance from the second device within a given location.
[0087] In another embodiment, the at least one permission may include pre-authorized verification. For example, the second application may be configured to revoke access to specified information about the first user if the first application has not received pre-authorized verification. In some embodiments, the pre-authorized verification may be part of an authorization list that already authorizes the first application to receive the requested access. In some embodiments, the pre-authorized verification may be based, for example, on whether the first application has previously received the requested access within a predetermined time period, prior transaction history, and / or any combination thereof.
[0088] In another embodiment, the at least one permission may include at least one selected from personally identifiable information, transaction type, merchant type, and / or any combination thereof. For example, the second application may be configured to revoke access to specified information about the first user if the request includes any portion of personally identifiable information, including, but not limited to, first name, last name, email, age, gender, date of birth, location, insurance information, and / or any combination thereof, unless previously authorized and / or partially redacted.
[0089] In another embodiment, the second application may be configured to revoke access to specified information about the first user if the request does not match an authorized transaction type, such as a transaction for payment, personally identifiable information, and / or any combination thereof.
[0090] In another embodiment, the second application may be configured to revoke access to specified information regarding the first user if the request does not match an authorized merchant type, such as a doctor, pharmacist, financial institution, grocery store, government entity, etc. For example, the second application may be configured to revoke access to specified information regarding the first user if the request does not include a matching identifier associated with a merchant or merchant type, such as a doctor, pharmacist, financial institution, grocery store, government entity, etc.
[0091] In another embodiment, the second application may be configured to disable access to the specified information about the first user if the request is made above a predetermined threshold, such as excessively frequent requests within a given time period. The second application may be configured to disable access to the specified information about the first user if the request is made on an unusual or otherwise irregular day, time, and / or any combination thereof. For example, if the request is not made during normal business hours or if the request is made on a day and / or time that does not match previous request history, access to the specified information about the first user may be disabled by the second application. Thus, when evaluating whether to disable access to the specified information about the first user, the second application may be configured to determine whether the request matches previous requests by the user and / or device.
[0092] In some embodiments, the second application may include instructions for execution on a second client device that is different from the first client device on which the first application includes instructions for execution. For example, the second application may include instructions for execution on a mobile device, whereas the first application may include instructions for execution on a kiosk. It is also understood that, as described herein, a user is not limited to being a person. In some embodiments, a user may include or be associated with any device. For example, it may include a lockbox for retrieving one or more items, such as packages. In another embodiment, it may include a device associated with a pharmacy, a store, a school, a restaurant, a hotel, an airport, a vehicle, a market, a garage, a residential or non-residential building, etc.
[0093] It is further noted that the systems and methods described herein may be tangibly embodied as one of a physical medium, such as, but not limited to, a compact disc (CD), a digital versatile disc (DVD), a floppy disk, a hard drive, a read-only memory (ROM), a random access memory (RAM), and other physical media capable of storing data. For example, a data storage device may include a random access memory (RAM) and a read-only memory (ROM), which may be configured to access and store data and information and computer program instructions. A data storage device may include a storage medium or other suitable type of memory (e.g., RAM, ROM, programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disk, optical disk, floppy disk, hard disk, removable cartridge, flash drive, any type of tangible and non-transitory storage medium, etc.), in which an operating system, application programs, including, for example, a web browser application, an email application, and / or other applications, and files, including data files, may be stored. The data storage of a computer system with network capabilities may include electronic information, files, and documents stored in a variety of ways, including, for example, flat files, indexed files, hierarchical databases, relational databases such as those created and maintained using software from Oracle® Corporation, Microsoft® Excel files, Microsoft® Access files, solid-state storage that may include flash arrays, hybrid arrays, or server-side products, enterprise storage that may include online or cloud storage, or any other storage mechanism. Also, the figures show various components (e.g., servers, computers, processors, etc.) separately.The functions described as being performed in various components may be performed in other components, the various components may be combined or separated, and other modifications may be made.
[0094] Various embodiments have been described hereinabove with reference to the accompanying drawings. However, it will be apparent that various changes and modifications may be made thereto and additional embodiments may be implemented without departing from the broader scope of the invention as set forth in the appended claims. The specification and drawings are, accordingly, to be regarded in an illustrative rather than a restrictive sense.
Claims
1. 1. An identity verification system comprising: a server comprising a processor and a memory, The above server is receiving a request from a first application running on a first client device to perform an identity verification process on the identity data after the contactless card enters a communication field generated by the first client device; Execute the above identity verification process, determining one or more outcomes based on the identity verification process; generating one or more notifications based on the one or more results; configured to send the one or more notifications to a second application executing on a second client device; the one or more notifications include options indicating requested access to the shareable information about the first user, the options including a choice to accept or deny access to the shareable information; Identity verification system.
2. The requested access is revocable based on one or more permissions.
10. The identity verification system of claim 1.
3. one or more of the permissions includes geographical restrictions; 3. The identity verification system of claim 2.
4. the geographical restriction includes a proximity requirement between the first application and the second application; 4. The identity verification system of claim 3.
5. the one or more permissions include pre-authorized verification; the pre-authorized verification is performed prior to sending the one or more notifications; 3. The identity verification system of claim 2.
6. the server being further configured to perform one or more iterations of the identity verification process; 10. The identity verification system of claim 1.
7. at least one of the one or more results includes a match or a mismatch between one or more subsets of the identity data and one or more subsets of the reference data; 10. The identity verification system of claim 1.
8. at least one result of the one or more results includes a discrepancy between the identity data and the reference data; 8. The identity verification system of claim 7.
9. the at least one result triggers a different comparison between the identity data and the reference data; 9. The identity verification system of claim 8.
10. 1. A method of identity verification performed by a server having a processor and a memory, the method comprising: receiving a request from a first application executing on a first client device to perform an identity verification process on identity data after a contactless card enters a communication field generated by the first client device; performing the identity verification process; determining one or more outcomes based on the identity verification process; and generating one or more notifications based on the one or more results; sending the one or more notifications to a second application executing on a second client device; the one or more notifications include options indicating requested access to the shareable information about the first user, the options including a choice to accept or deny access to the shareable information; method.
11. the one or more notifications allow for a response in which additional information is selected to be shared; The method of claim 10.
12. Selection of the option is associated with a predetermined duration before timeout of the requested access. The method of claim 10.
13. The requested access may be invalidated based on exceeding a predetermined threshold for a predetermined period of time. The method of claim 10.
14. The requested access may be revoked if the shareable information includes personally identifiable information about the first user. The method of claim 10.
15. The requested access may be invalidated if the request is made at a different time than the previous request history. The method of claim 10.
16. The requested access is invalid if the request is made outside of a predetermined time period. The method of claim 10.
17. 1. A non-transitory computer-readable medium comprising instructions that, when executed by a server having a processor and a memory, cause the server to perform a procedure including the following operations: The above steps are: receiving a request from a first application executing on a first client device to perform an identity verification process on identity data after a contactless card enters a communication field generated by the first client device; performing the identity verification process; determining one or more outcomes based on the identity verification process; and generating one or more notifications based on the one or more results; sending the one or more notifications to a second application executing on a second client device; the one or more notifications include options indicating requested access to the shareable information about the first user, the options including a choice to accept or deny access to the shareable information; Non-transitory computer-readable medium.
18. the identity verification process includes a comparison between the identity data and reference data; 20. The non-transitory computer-readable medium of claim 17.
19. If the comparison fails, the procedure further comprises performing a different comparison between the identity data and the reference data.
20. The non-transitory computer-readable medium of claim 18.
20. The method of claim 20, wherein the first client device and the contactless card are associated with the first user.
10. The identity verification system of claim 1.
Citation Information
Patent Citations
Personal information access control method, terminal, system and its program
JP2004038270A
Personal information sharing system, certification authority, web server, tamper-resisting device and program
JP2006058954A
Device, method, program and system for providing user information
JP2008152320A
System and method utilizing NFC technology to implement on-demand portable medical record
JP2009238225A
Transaction system for business and social networking
US20130276140A1