Biometric identity verification system

The biometric identity verification system addresses the challenge of fast and secure access control by using mobile device-stored QR codes and BLE modules for wireless verification, ensuring rapid and accurate identity confirmation with compliance to data protection laws.

WO2025226253A1PCT designated stage Publication Date: 2025-10-30ONES BILISIM TEKNOLOJILERI ANONIM SIRKETI
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/TR2025/050396
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2025-10-30

AI Technical Summary

Technical Problem

Existing biometric identity verification systems face challenges in providing high security and ease of use while ensuring fast identity verification without storing personal data on institutional infrastructure, leading to increased sensitivity and duration of identification.

Method used

A biometric identity verification system where individuals store a digital QR code containing biometric data and access authorizations on their mobile devices, enabling wireless transmission and verification using BLE modules, allowing fast and secure access control without scanning cards or devices, utilizing a temporary limited-duration database for data storage and comparison.

Benefits of technology

Enables rapid and accurate biometric verification with high security, compliance with data protection regulations, and reduced False Match Rate by storing data only on user devices and deleting it after use, ensuring offline operation and minimal intervention.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000014_0000
    Figure 00000014_0000
  • Figure 00000014_0001
    Figure 00000014_0001
  • Figure 00000014_0002
    Figure 00000014_0002
Patent Text Reader

Abstract

The present invention relates to a biometric identity verification system to be used in a biometric identity verification process, wherein a QR code is generated containing the individual's biometric data as well as other data that also include the person's identity verification authorizations, such as location, time, number of uses, last access date, institution information, institution Card ID, National Identity ID, and Passport ID, and this QR code is stored only within an application on the user's mobile device (2); and when the user (3) arrives at the access location, the QR code or the data containing biometric information is transmitted through secure wireless communication to biometric identity verification devices (1) and the verification is performed accordingly.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] BIOMETRIC IDENTITY VERIFICATION SYSTEM PCT

[0002] Technical Field

[0003] The present invention relates to a biometric identity verification system to be used in a biometric identity verification process for the purposes of authorization or access control, and it pertains to a system in which a QR code, which includes the person's biometric data, location, time, number of uses, last access date, institution information, institution Card ID, National Identity ID, Passport ID, and other data that contain the person's identity verification authorizations, is stored only within the application on the user's mobile device, and when the person arrives at the access location, the QR code or the data containing biometric information is transmitted to the biometric identity verification devices through secure wireless communication and verification is performed.

[0004] Background Art

[0005] Nowadays, biometric-based identity verification systems, which have begun to be used for ensuring physical security and identity inspection at locations requiring high security, are coming to the forefront. In such facilities, in order to perform biometric-based identity control, the biometric data of the individuals who will pass through are collected and stored in a database, which is kept either within biometric identity verification devices (match on device), on a central server (match on server), or on a hybrid infrastructure. When the person arrives at the biometric device, the data captured from the person (captured data) is compared with all biometric data previously recorded in the database (enrolled data), and the person who shows the highest similarity and exceeds the identity verification threshold value defined by the institution is identified (identification). In such biometric identification systems, depending on the characteristics of the biometric system used in projects that contain databases with a high number of individuals, the sensitivity of identification decreases, and the duration of identification increases. In recent times, the fact that individuals' biometric data are considered critical personal data and the emergence of laws and opinions in the global market advocating that such data should not be stored within identity verification devices or systems have come to the forefront.

[0006] For this reason, identity verification methods in which biometric data are stored on media such as plastic cards or mobile devices, which are personally held by individuals, are gaining value in the global market. In such identity verification systems, the biometric data stored in the user's institutional card or mobile device must be brought close to the biometric identity verification device to be scanned, and only then can biometric identity verification be performed. Due to this, biometric identity verification using biometric data stored in cards or mobile devices takes significantly more time than earlier single-method identity verification techniques such as cardbased systems.

[0007] Currently, no solution has been developed that provides both high security and ease of use, enabling a user to perform biometric identity verification in a fast and highly secure manner without having to scan their phone or card when arriving at the biometric identity verification device.

[0008] Summary of the Invention

[0009] In situations that require a high level of security and at the same time necessitate high-speed biometric identity verification, an infrastructure has been targeted that enables the process to be performed without storing personal data within institutional infrastructures.

[0010] Individuals store within the applications on their mobile devices a digital QR code that contains their own biometric data as well as other data that determine their access authorizations (for example, institution card number, location, permitted number of accesses, last access date, institution information, institution Card ID, National Identity ID, Passport ID, etc.).

[0011] When individuals arrive at the access location, after the information transmitted by the BLE module or modules located within the biometric device or as a separate device is detected by the phone, the QR code containing biometric data or a data file stored within the phone is encrypted and transmitted in one or more sequential data packets to the BLE module inside the biometric device or to an externally located BLE device. Thanks to the biometric template and access authorization data contained in the provided QR code or data file, these devices will be able to perform biometric identity verification without relying on any central system.

[0012] This identity verification to be performed will establish an infrastructure that enables the person to complete the process quickly during the access phase by performing biometric verification only on the biometric device, without scanning any card or mobile device.

[0013] During these door access processes, the identity detection process will be carried out only with the biometric data retained for a predefined period of time and generated only by the individuals located within the BLE coverage area, which increases the accuracy of identity verification and also enables the identification process to be completed in a much shorter time. In this form, the approach subject to the invention will enable the development of a biometric identity, access, and authorization control system that produces fast results, operates offline and wirelessly, and is compliant with KVKK and GDPR, by performing biometric verification and access control based only on the data obtained from a specific group of people through wireless data transmission methods and only within a defined time window.

[0014] Description of the Figures Illustrating the Invention

[0015] Figure 1 - A schematic view of the biometric identity verification device that is the subject of the invention.

[0016] Figure 2 - A schematic view of the BLE communication device that is the subject of the invention.

[0017] Figure 3 - A schematic view of a mobile device communicating with the biometric identity verification device that is the subject of the invention.

[0018] Figure 4 - A schematic view of the biometric identity verification device, the BLE communication device, several users, the door access point, and the ROI (Region of Interest) area established by BLE modules, all of which are related to the invention. The elements shown in the figures that define the invention have been numbered in order to better understand the invention. The correspondences of these numbers are provided below.

[0019] 1. Biometric identity verification device

[0020] 2. Mobile device

[0021] 3. User

[0022] 4. Door access point

[0023] 5. QR code

[0024] 6. BLE module

[0025] 7. BLE communication device

[0026] Detailed Description of the Invention

[0027] The biometric identity verification system subject to the invention essentially comprises a biometric identity verification device (1) equipped with a BLE module (6) and a mobile device (2) also equipped with a BLE module (6). In cases where the user (3) wants to pass through a door access point (4) or prove that they have access or authorization rights, the ability to prove such access authorization biometrically, wirelessly, and preferably with minimal intervention in an automatic manner will be achieved through the interaction between the biometric identity verification device (1) and the mobile device (2). Thus, biometric verification of the users (3) and access control will be performed via the biometric identity verification system.

[0028] When the user (3), with their mobile device (2), enters the area covered by the BLE module (6) inside the biometric identity verification device (1) or the BLE communication device (7), the mobile device (2) and / or the application within it, either with the user's permission or automatically, transmits biometric data— digitally stored and including biometric informationvia the BLE module (6) to the biometric identity verification device (1) or the BLE communication device (7) in one or more BLE messages.

[0029] The biometric identity verification device (1) is capable of reading the live biometric components of the user (3) through biometric readers located on it. If the biometric data provided digitally by the user (3) and the live biometric data read are consistent, the verification of the user (3) will be considered successful. If the system is integrated with an access control infrastructure, the biometric identity verification device (1) will additionally check the access authorization associated with the biometric data and will either grant or deny access accordingly.

[0030] The BLE communication device (7) is a piece of hardware equipped with a BLE module (6), used to increase the coverage area and frequency of communication between the biometric identity verification device (1) and the mobile device (2). The BLE communication device (7) transmits the biometric data it receives from the surrounding mobile devices (2) to the biometric identity verification devices (1) to which it is connected. During this process, the biometric identity verification devices (1) can also collect biometric data themselves via the BLE module (6) integrated within them. In this way, it becomes possible to collect user data from a broader coverage area.

[0031] The digital biometric data received from the mobile devices (2) are the biometric data of the users (3) of those devices. These data are transmitted either with event-based permission from the users or automatically, in response to a request made via wireless protocols by the BLE communication devices (7) or the biometric identity verification device (1). This permission may be granted automatically if, for example, the biometric identity verification device (1) is a device belonging to the institution where the user (3) is employed. Since such devices are located at the door access point (4) of the building where the user (3) works, sharing biometric data may be a prerequisite for gaining access through the door. Similarly, if the same devices are used for access control in public transportation vehicles, automatic sharing may also be active. However, if biometric data are requested from a mobile device (2) by biometric identity verification devices (1) belonging to different institutions, the transmission of such biometric data can only be permitted through the approval of the user (3) and controlled via the mobile device (2).

[0032] The biometric identity verification devices (1) and BLE communication devices (7) located within the BLE wireless network area will announce via their own BLE modules (6)— whether they identify themselves or not— that they are requesting digital biometric data, to mobile devices (2) that also contain BLE modules (6). The digital biometric data of users (3) who have granted permission to share their digital biometric data will be received wirelessly via BLE and stored in a "temporary limited-duration database." The reason this database is referred to as a "temporary limited-duration database" is that the stored digital and live biometric data will either be deleted after a limited time period or erased after a successful match is achieved by the biometric identity verification device (1).

[0033] When the users (3) intend to pass through any door, turnstile, or to access a cabinet or device, in other words during any access request, biometric comparison-based verification will be performed via the biometric identity verification device (1) located on the respective door, turnstile, cabinet, or device. The biometric data shared by the users (3) belong to their own retina, fingerprint, face, palm print, vein map, etc. Using this biometric data, the biometric identity verification device (1) will capture the user's (3) live biometric data via biometric reading hardware. This live data will then be compared with the digital biometric data stored in the temporary limited-duration database, which at that moment has been collected wirelessly from all surrounding mobile devices (2). If the user's (3) live biometric data matches any of the digital biometric data in the temporary limited-duration database, and the authorization check also yields a positive result, then the biometric identity verification device (1) will grant access to the relevant door, turnstile, cabinet, or device.

[0034] Each digital biometric data file shared by the mobile device (2) also contains an "authorization element" that allows the system to verify whether access to the relevant door, turnstile, cabinet, or device is permitted. This "authorization element" is a piece of information that will be checked by the biometric identity verification device (1) either after or simultaneously with the comparison between the user's (3) live biometric data and their digital biometric data. Even if the digital biometric data collected at that moment matches the user (3), access permission will not be granted if the relevant "authorization element" does not allow access to the relevant door, turnstile, cabinet, or device. Furthermore, if desired, the system may be configured to perform this check in such a way that if the "authorization element" accompanying the digital biometric data— collected via wireless data transfer methods— does not contain the necessary access rights, then the relevant biometric data will not be stored at all in the "temporary limitedduration database" by the biometric identity verification device (1).

[0035] The most fundamental advantages of this invention can be listed as follows:

[0036] • The user (3) carries their own digital biometric data,

[0037] • This digital biometric data is carried on a mobile device (2) belonging to the user (3),

[0038] • The user (3) shares the digital biometric data along with the authorization element only with the biometric identity verification devices (1) either automatically or manually on a per-device basis,

[0039] • This data can only be shared when entering the Region of Interest (ROI) area of the BLE modules (6) located on the biometric identity verification devices (1) or the BLE communication devices (7),

[0040] • The live biometric data voluntarily provided by the user (3) via the biometric identity verification device (1) is deleted after comparison,

[0041] • The collected digital biometric data is automatically deleted after a certain period if the user (3) does not access the biometric identity verification device (1) using live biometric data,

[0042] • The digital and live biometric data verification is performed rapidly and with high accuracy using only a limited number of entries located within a "temporary limited-duration database" formed exclusively from those within the Region of Interest (ROI) area,

[0043] • For such verification, the user (3) merely needs to pass in front of a camera or sensor performing biometric scanning, or present their finger or palm.

[0044] In locations where a very high number of users need to access simultaneously— such as sports stadium entrances, metro or train stations— there are typically multiple access points (turnstiles) within a single area. In such facilities, under certain conditions, it is possible that hundreds of individuals may be present at once within the active area of the BLE modules (6). In these environments, collecting the "digital biometric data" and "authorization element data" belonging to many users (3), who are dispersed and whose mobile devices (2) are equipped with BLE modules (6), via a limited number of BLE modules (6) embedded in the biometric identity verification device (1) may present technical limitations. Therefore, BLE communication devices (7) capable of housing numerous BLE modules (6) may be deployed to cover a wide ROI area before the turnstiles. In such a deployment zone, the "digital biometric data" and "authorization element data" acquired at different times for various turnstiles / doors can be checked from a "temporary limited-duration database" that all turnstiles / doors can simultaneously access. In this way, it becomes possible to collect and quickly read the "biometric data" and "authorization element data" (which can be converted into alphanumeric series, image files, data files, or QR codes (5)) of hundreds of people who may be actively present in the area, via the biometric identity verification devices (1).

[0045] The temporary limited-duration database is a database that contains all the data acquired from the surroundings at any given moment. The live biometric data of users (3) will be compared with the data in this database (populated database). Limiting the retention period of the data stored in the database and continuously deleting it to reduce the number of records subject to comparison will reduce the False Match Rate (FMR: An empirical estimate of the probability (percentage of times) at which the system incorrectly accepts that a biometric sample belongs to the claimed identity when the sample actually belongs to a different subject (impostor). This metric is an algorithmic level verification error).

[0046] The invention is equipped with a protection mechanism that makes it impossible for the "digital biometric data" and "authorization element data" to be used by anyone other than the user (3). This protection mechanism is the ability of the "authorization element data" to be used for granting access permission only if it matches the user's (3) "live biometric data" with the "digital biometric data."

[0047] In conventional systems that grant multiple access permissions, one of two approaches is typically applied. The first involves performing the authorization check using an authorization element loaded onto a hardware device that does not contain biometric data. The second involves performing checks based on the user's (3) biometric data stored on a server of a data control center. While access control systems based on the user's (3) biometric data provide high security, they also introduce two main problems. The first issue is that the biometric data of users (3) is stored on a server that is not under the user's control. The second is that any biometric comparison among a large number of similar data increases the likelihood of false acceptance due to data similarities.

[0048] Thanks to the wireless communication established between the biometric identity verification device (1) and the mobile device (2), the following advantages are obtained:

[0049] • Users (3) do not need to scan a card,

[0050] • The biometric data of the user (3) is stored only on the mobile device (2) belonging to the user (3) for long-term storage,

[0051] • Biometric verification is performed solely based on the biometric data contained in the limited dataset within the "temporary limited-duration database."

[0052] Additionally, if needed or requested, the "digital biometric data" and "authorization data" may be converted into a QR code (5) and used by being read by a camera or reader of the biometric identity verification device (1) in case of a wireless communication issue.

[0053] The "authorization element" stored and shared together with the "biometric data" may include additional information such as a validity indicator, validity period, or, in the most general sense, the authorization level. By checking these additional pieces of information simultaneously, the determination of whether "the biometric data belongs to this person or not" can be reached at the same time as the conclusion of whether "the person's authorization level is appropriate or not," based solely on the biometric data.

[0054] All of these operations— reading the digital biometric data and the authorization element either via BLE modules (6) wirelessly or via the QR code (5) through a camera, and verifying the user (3) through live biometric data obtained from them— can be completed offline without requiring either the user (3) or the biometric identity verification device (1) to be connected to the internet or to a server. For this reason, the biometric identity verification device (1) does not need to be online, connected to any server, or store digital biometric data either in its memory or on a server.

[0055] The biometric identity verification device (1) will continuously attempt to collect "digital biometric data" and "authorization data" via BLE modules (6) and will write all such data into a temporary limited-duration database. If any user (3) arrives at a specific location to make an access request and attempts to scan their face, palm, fingerprint, or any other live biometric feature via the biometric readers of the biometric identity verification device (1), the comparison will be made using the data in this temporary limited-duration database.

[0056] The biometric identity verification device (1) will generate or deliver an approval message if a match between the live and digital biometric data is achieved and the corresponding authorization is validated. For example, if the biometric identity verification device (1) is used for access control, it may support communication protocols such as IP, Wiegand, or OSDP to forward one or more pieces of encrypted data contained in the "authorization data"— such as Institution Card ID, National ID, Passport ID, etc.— to the access control system within the institution to which it is connected, and may display feedback received from the access control system on its screen to inform the user (3). In this way, approval can be obtained without any biometric data being sent to a server, solely based on the "authorization data."

[0057] In this way, a record, transaction, or log information that does not contain the user's (3) personal data related to the access operation can be transmitted to a central software system located within the institution to which the biometric identity verification device (1) is connected or within a cloud infrastructure.

[0058] The primary advantage of the user's personal data being carried exclusively by the user (3) is that the entire system becomes fully compliant with KVKK (Personal Data Protection Law) and GDPR (General Data Protection Regulation). The fact that no biometric data is stored on the server or on the biometric identity verification device (1) is the most crucial element of this process. The "biometric data," which is stored long-term only on the mobile device (2) belonging to the user (3), will only be retained for a limited duration for verification purposes and will be deleted either after use or after a predefined period. The fields of application of the invention may be shaped according to need. However, in essence, it consists of process steps in which biometric data is stored / carried solely by the user (3) and is actively provided by the user (3) themselves to prove their identity.

[0059] In areas of application where critical security is required, it is advisable to use high-security systems resistant to spoofing, such as vein recognition or 3D facial recognition systems. Since many camera-based facial recognition systems rely solely on results obtained from a single camera image, it is possible to deceive the system using a printed face photograph, video, or mask. To prevent this, data obtained from stereo cameras that measure facial depth and thermal cameras can be used to determine whether the detected input is a real human or a photo, video, or mask. The inclusion of thermal camera data and stereo camera data in the biometric information will also enhance the depth of biometric verification and reduce error rates.

Claims

CLAIMS1. A biometric identity verification system for use in a biometric identity verification process for the purposes of authorization or access control,- comprising digital biometric data stored in a mobile device (2) in a form that is compatible with the user's own live biometric data and shareable as an alphanumeric string, image file, data file, or QR code (5) together with an authorization element,- a BLE module (6) enabling the mobile device (2) to transmit the user's (3) digital biometric data over a BLE wireless network,- a temporary limited-duration database in which digital biometric data collected via the BLE module (6) is stored, and- a biometric reader of a biometric identity verification device (1) capable of reading the user's live biometric data; characterized in that the biometric identity verification device (1) receives the user's (3) live biometric data as an access request, compares it with the digital biometric data stored in the temporary limited-duration database, and, upon establishing a match and authorization compliance, generates or delivers an approval message.

2. The biometric identity verification system according to claim 1, characterized in that it comprises BLE communication devices (7) equipped with BLE modules (6) for expanding the coverage area of the mobile device (2) and for transmitting the collected digital biometric data to the associated biometric identity verification devices (1).

3. The biometric identity verification system according to any one of claims 1 or 2, characterized in that the digital biometric data is transmitted via wireless protocols through BLE communication devices (7) or biometric identity verification devices (1) upon receiving the user's event-based or automatic permission.

4. The biometric identity verification system according to any one of claims 1 to 3, characterized in that it comprises a "temporary limited-duration database" in which the stored data is either deleted after a limited retention period or erased after a successfulmatch is achieved with a live biometric data received by the biometric identity verification device (1).

5. The biometric identity verification system according to claim 4, characterized in that the digital and live biometric data of the user (3) are compared and verified within the temporary limited-duration database during any access request.

6. The biometric identity verification system according to any one of claims 4 or 5, characterized in that the biometric identity verification device (1) grants access when the live biometric data of the user (3) matches any biometric data stored in the temporary limited-duration database during any access request.

7. The biometric identity verification system according to claim 6, characterized in that the biometric identity verification device (1) grants access only if, in addition to a match between the live biometric data and the biometric data in the temporary limited-duration database, the associated authorization element also indicates that access is permitted.

8. The biometric identity verification system according to claim 7, characterized in that the biometric identity verification device (1) does not store the biometric data in the "temporary limited-duration database" if the authorization element, collected simultaneously with the biometric data via wireless data transfer methods, does not indicate access permission for the requested resource.

Citation Information

Patent Citations

  • Local attribute verification using a computing device

    EP4199418A1

  • Identity verification method and devices

    GB2601824A

  • Permission-based system and network for access control using mobile identification credential

    US20220150711A1