Biometric payment instrument and method for managing a biometric payment instrument

The payment instrument uses a trust evaluator to authenticate users with incomplete enrollment data by computing a representativeness index, addressing fraud risks and enhancing security in biometric transactions.

WO2026002677A1PCT designated stage Publication Date: 2026-01-02THALES DIS FRANCE SA
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2025/066642
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-28
Filing Date
2025-06-13
Publication Date
2026-01-02

AI Technical Summary

Technical Problem

Conventional biometric payment instruments require a complete enrollment process with a predefined threshold of biometric data to authenticate users, posing a potential fraud risk when the enrollment is not finalized, as financial institutions are reluctant to accept transactions based on a low number of stored templates.

Method used

A payment instrument with a biometric sensor and a trust evaluator that computes a representativeness index, allowing authentication even when the enrollment is not finalized, by using a matching score and a trust result based on predefined rules and historical data to assess the user's representativeness.

Benefits of technology

Enhances security by authenticating users with incomplete enrollment data, reducing fraud risk through dynamic assessment of biometric data representativeness and adaptively managing enrolled data, ensuring secure financial transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025066642_02012026_PF_FP_ABST
    Figure EP2025066642_02012026_PF_FP_ABST
Patent Text Reader

Abstract

The invention is a biometric payment instrument (10) comprising a biometric sensor (54), enrolled biometric data (11), and a matching unit (13) that computes a matching score (12) by comparing captured biometric data with enrolled data. The instrument includes an enrollment completion indicator (15) and a trust evaluator (16) that computes a representativeness index (14) reflecting user representation quality. The instrument generates a trust result (19) by verifying the representativeness index meets predefined rules (17) and authenticates users using both the matching score and trust result during transactions.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] BIOMETRIC PAYMENT INSTRUMENT AND METHOD FOR MANAGING A

[0002] BIOMETRIC PAYMENT INSTRUMENT

[0003] (Field of the invention)

[0004] The present invention relates to methods for managing payment instruments embedding a biometric sensor . It relates particularly to methods of managing biometric payment instruments deployed in the field .

[0005] (Background of the invention)

[0006] Face-to- face financial transactions can be done today through the interaction of a payment instrument with a connected banking terminal , and the exchange of a payload with a remote server . For example , the financial transaction can be a payment transaction carried out via a Point-Of-Sale ( POS ) terminal . Alternatively, the financial transaction can be a cash withdrawal transaction carried out via an ATM (Automated Teller Machine ) terminal . Such transactions are called in-person transactions ( or proximity transactions ) because the cardholder is at the same location as the terminal .

[0007] Conventional banking terminals can communicate with a payment instrument through a contact communication protocol ( e . g . payment instrument inserted in the reader of the terminal ) or contactless communication protocol ( e . g . payment instrument is placed in proximity to the reader of the terminal ) .

[0008] A payment instrument can be a payment smart card embedding a biometric sensor like a fingerprint sensor . Usually, a biometric payment card has a non-volatile memory storing biometric reference data previously enrolled and a matching unit designed to compute a matching score by comparing a biometric candidate data captured by the biometric sensor with the registered biometric reference data . The matching score aims at authenticating the cardholder ( i . e . card user ) .

[0009] Usually, the biometric authentication feature becomes available on a smart card when the enrollment process has been finali zed . This happens when a certain amount of biometric reference data has been registered . In other words , the biometric authentication is activated on conventional smart cards only when the number of enrolled registered biometric reference data ( also called enrolled biometric data ) reaches a predefined threshold . Typically, the value of such a threshold is set between 12 and 20 .

[0010] Thus , while the enrollment operation is not finali zed, conventional biometric cards cannot authenticate a user by using their embedded biometric sensor and enrolled biometric reference data .

[0011] (Summary of the Invention)

[0012] Last generation of fingerprint sensors and matching algorithms are now powerful enough to allow success ful match operations based on very low amount of enrolled biometric data ( also named reference templates ) . For example , a smart card can now authenticate a user based on its embedded biometric feature while only one biometric data has been enrolled into the card . Thus , although the enrollment operation is not finali zed, a biometric card can still authenticate the user based on the biometric data already enrolled in the card .

[0013] However, some financial institutions can be reluctant to accept financial transactions secured by a user authentication based on a very low number of stored biometric reference templates , considering this is a potential fraud risk . Since it is easier to enroll one biometric data than a large number of biometric data, they may consider that an attacker could succeed in enrolling a biometric data corresponding to a hacker that could be improperly used by the card to authenticate the hacker instead of the genuine user .

[0014] It would be useful to mitigate the risks due to the fact that the user authentication can be carried out by the card although the enrollment process is not finali zed ( i . e . based on a low number of biometric reference data ) and to take appropriate measures .

[0015] The present invention aims at solving the above- mentioned technical problem .

[0016] An obj ect of the present invention is a payment instrument assigned to a user and able to participate to a financial transaction . The payment instrument includes a biometric sensor, a set comprising one or more enrolled biometric data, and a matching unit which is designed to compute a matching score by comparing a biometric candidate data captured by the biometric sensor with at least one enrolled biometric data of the set . The payment instrument comprises an indicator reflecting whether the enrollment process of the set is completed or not . The payment instrument comprises a trust evaluator configured to compute a representativeness index that reflects a level of representativeness of the user by the set , said representativeness index being separate from said indicator . The payment instrument is configured to generate a trust result by checking that the representativeness index satis fies a predefined rule and to contribute to user authentication to authori ze the financial transaction by using both said matching score and said trust result .

[0017] The matching unit is configured to contribute to user authentication when the indicator shows that the enrollment process of the set is not completed . That is , in a preferred embodiment , the payment instrument is configured to authenticate the user for the purposes of the current financial transaction even i f the enrollment process is not finali zed in the payment instrument .

[0018] Advantageously, the set may include a plurality of enrolled biometric data and the trust evaluator may be configured to compute the representativeness index based on notable relationships between the enrolled biometric data of the set .

[0019] Advantageously, the payment instrument may be configured to compute the representativeness index using a proportion of enrolled biometric data having an overlapping surface compared to the total number of enrolled biometric data of the set .

[0020] Advantageously, the set may include a plurality of enrolled biometric data and the trust evaluator may be configured to compute the representativeness index based on an history of use of the enrolled biometric data of the set .

[0021] Advantageously, the payment instrument may comprise an audit unit configured to identi fy a selected enrolled biometric data belonging to the set as being to be deleted by detecting that the selected enrolled biometric data has a degree of representativeness of the user lower than a preset threshold .

[0022] Advantageously, the set may include a plurality of enrolled biometric data and the audit unit may be configured to identi fy said selected enrolled biometric data as being to be deleted based on a combination of an history of use of the enrolled biometric data of the set and notable relationships between the enrolled biometric data of the set .

[0023] Advantageously, the audit unit may be configured to identi fy said selected enrolled biometric data before the financial transaction starts or after the financial transaction ends .

[0024] Advantageously, the financial transaction may be a payment transaction or a cash withdrawal transaction .

[0025] Advantageously, the payment instrument may be a smart card, a ring, a keychain, a watch, or a bracelet .

[0026] Another obj ect of the present invention is a method for managing a payment instrument assigned to a user and able to participate to a financial transaction . The payment instrument includes a biometric sensor, a set including one or more enrolled biometric data, and a matching unit designed to compute a matching score by comparing a biometric candidate data captured by the biometric sensor with at least one enrolled biometric data of the set . The payment instrument comprises an indicator reflecting whether the enrollment process is completed in the payment instrument or not . The payment instrument comprises a trust evaluator that computes a representativeness index reflecting a level of representativeness of the user by said set , said representativeness index being separate from said indicator . The matching unit contributes to user authentication when the indicator shows that the enrollment process of the set is not completed . The method comprises the step of generating by the payment instrument a trust result by checking that the representativeness index satis fies a predefined rule , and the step of contributing to the user authentication to authori ze the financial transaction by using both said matching score and said trust result .

[0027] Advantageously, the set may include a plurality of enrolled biometric data and the trust evaluator may compute the representativeness index using notable relationships between the enrolled biometric data of the set .

[0028] Advantageously, the payment instrument may compute the representativeness index using a proportion of enrolled biometric data having an overlapping surface compared to the total number of enrolled biometric data of the set .

[0029] Advantageously, the set may include a plurality of enrolled biometric data and the trust evaluator may compute the representativeness index based on an history of use of the enrolled biometric data of the set . Advantageously, the payment instrument may comprise an audit unit which identi fies a selected enrolled biometric data belonging to the set as being to be deleted by detecting that said selected enrolled biometric data has a degree of representativeness of the user lower than a preset threshold .

[0030] (Brief description of the drawings)

[0031] Other characteristics and advantages of the present invention will emerge more clearly from reading the following description of a number of preferred embodiments of the invention with reference to the corresponding accompanying drawings in which :

[0032] Fig . 1 shows a diagram of architecture of a payment instrument according to an example of the invention,

[0033] Fig . 2 shows a flow diagram for managing a biometric payment instrument according to an example of the invention,

[0034] - Fig . 3 shows an history log stored in the payment instrument according to an example of the invention,

[0035] - Fig . 4 shows a first exemplary set of enrolled biometric data stored in the payment instrument according to a first example of the invention, and

[0036] - Fig . 5 shows a second exemplary set of enrolled biometric data stored in the payment instrument according to a second example of the invention . (Detailed description of the preferred embodiments)

[0037] The invention may apply to any type of biometric payment instrument usually associated to a user ( also called cardholder ) . The payment instrument may be implemented in a wide variety of device such as physical smart card, smartwatch, or wearable device for instance .

[0038] Figure 1 depicts a diagram of architecture of a payment instrument according to an example of the invention .

[0039] In this example , the payment instrument 10 is a physical banking card intended to be used by its associated genuine user 50 ( i . e . bank customer or cardholder ) for financial transactions like payment transactions or cash withdrawals .

[0040] The payment instrument 10 embeds a secure element 20 comprising a hardware processing unit , a non-volatile memory storing program instructions of an operating system 22 , and of at least one banking application 23 designed to contribute to payment services and transactions like payment or cash withdrawal .

[0041] The payment instrument 10 can be a proximity card comprising a contactless unit 21 able to communicate through a contactless protocol as defined by the ISO 14443 standard or Near Field Communications (NFC ) standards for instance .

[0042] In some embodiments , the payment instrument can be configured to communicate through a contact communication protocol in addition to the contactless communication protocol . In some embodiments , the payment instrument can be configured to communicate through a contact communication protocol only .

[0043] The payment instrument 10 comprises a fingerprint sensor 54 and a set 11 comprising one or more biometric reference data enrolled during a previous phase . The payment instrument 10 comprises a matching unit 13 which is designed to compute a matching score 12 by comparing a biometric candidate data captured by the biometric sensor with one or more biometric reference data belonging to the set 11 of previously enrolled biometric reference data .

[0044] The payment instrument 10 comprises an indicator 15 that reflects whether the enrollment process of the set 11 is completed ( finali zed) or not .

[0045] The payment instrument 10 comprises a trust evaluator 16 which is configured to compute a representativeness index 14 reflecting a level of representativeness of the user by the set 11 . The representativeness index 14 is separate from the indicator 15 and stored in the memory of the payment instrument .

[0046] The payment instrument 10 comprises a predefined rule 17 intended to assess a security level associated with the content of the set 11 of enrolled biometric reference data .

[0047] The matching unit 13 can be configured to generate a trust result 19 by checking that the representativeness index satis fies the predefined rule 17 and to contribute to user authentication to authori ze or not a financial transaction in progress by using both the trust result 19 and the matching score computed by the matching unit 13 .

[0048] The representativeness index 14 can be called maturity index or global enrolment maturity index ( GEMI ) .

[0049] According to the invention, the matching unit 13 can be configured to contribute to user authentication (using a candidate biometric data captured by the sensor 54 ) when the indicator 15 shows that the enrollment process of the set 11 is not completed . Thus , during a financial transaction, even i f the enrollment phase is not finali zed, the matching unit 13 can be authori zed to authenticate the user based on the already enrolled items of the set 11 and a biometric candidate data captured by the biometric sensor 54 . In other words , the matching unit 13 can be empowered to authenticate the user for the purposes of the current financial transaction even i f the enrollment process is not finali zed in the payment instrument 10 .

[0050] That is , in a preferred embodiment , the payment instrument is configured to authenticate the user for the purposes of the current financial transaction even i f the enrollment process is not finali zed in the payment instrument .

[0051] In practice , the matching unit 13 may not read the value of the indicator 15 and try to authenticate the user independently of the indicator 15 .

[0052] In some embodiments , the set 11 may include a plurality of enrolled biometric data and the trust evaluator 16 can be configured to compute the representativeness index 14 based on notable relationships between the enrolled biometric data of the set 11 .

[0053] For instance , the trust evaluator 16 can be configured to compute the representativeness index 14 as a proportion of enrolled biometric data having an overlapping surface area compared to the total number of enrolled biometric data of the set 11 . In case of fingerprint , an overlapping surface area corresponds to a same part of a finger from which at least two enrolled biometric data have been created . In other words , an overlapping surface is a subset of remarkable points ( like minutia ) of a finger that is shared between two or more enrolled biometric data . Such a way to compute the representativeness index 14 aims at checking that the enrolled biometric data of the set 11 are originated from a unique user . The predefined rule 17 could be that the proportion of enrolled biometric data having an overlapping surface should be above a speci fic threshold ( like 75% or 90% ) or even equal to 100% .

[0054] Figure 5 depicts an example the set 11 comprise three enrolled biometric data . Two of them (R1 & R2 ) have a shared surface area while the third one (R3 ) is entirely separate from the other two (no overlap of surface areas ) . In such a case , the value computed for the representativeness index 14 could be equal to 66% (because two thirds of the enrolled biometric data overlap . )

[0055] In another example , the trust evaluator 16 can be configured to compute the representativeness index 14 as the ratio of unshared surface area corresponding to the ratio of surface area covered only by one enrolled biometric data compared to the total surface area covered by all enrolled biometric data of the set 11 . Such a way to compute the representativeness index 14 aims to detect that the enrolled biometric data do not share a common surface area which is too large . To illustrate the purpose , a set containing three enrolled biometric data covering a large surface area would be better than a set containing five files enrolled biometric data whose surface area are almost equal . The associated predefined rule 17 could be that the ratio of unshared surface area should be larger than a preset threshold like 30% , 60% or 80% .

[0056] In another example , the trust evaluator 16 can be configured to compute the representativeness index 14 as a value reflecting whether, when the number of enrolled biometric data belonging to the set 11 is higher than a preset number ( e . g . 12 or 15 ) , each enrolled biometric data of the set 11 has its surface area partially in common with at least two ( or three ) other enrolled biometric data belonging to the set 11 .

[0057] Such a case is depicted at Figure 4 where each of the enrolled biometric data ( of the set 11 ) has a shared surface area with two or more other enrolled biometric data .

[0058] Advantageously, the trust evaluator 16 can be configured to compute the representativeness index 14 according to the above-presented examples to check both that the surfaces of the enrolled biometric data are suf ficiently diversi fied and that the enrolled biometric data come from a single user . In such a case , the trust evaluator 16 can use a composite predefined rule 17 for checking each part of the computed representativeness index 14 .

[0059] In another example , the payment instrument can be configured to record an history of use (by the matching unit 13 ) of the enrolled biometric data of the set 11 .

[0060] Such an history can be stored in a log and reflect the sequence of comparison attempts performed by the matching unit 13 . For instance , the history can contain, for each comparison, an identi fier of the enrolled biometric data and the associated computed matching score .

[0061] Figure 3 depicts an history log created in the payment instrument according to an example of the invention .

[0062] The history log 24 contains a sequence of 9 matching scores that have been generated by the payment instrument during previous financial transactions involving the payment instrument 10 .

[0063] In order to clari fy the reading of the history log 24 shown at Figure 3 , a first row has been added to indicate the rank of each matching score of the sequence of matching scores .

[0064] The second row contains the value of the matching scores computed by the matching unit 13 . In this example , the matching score are expressed as percentage of matching between 0% and 100% .

[0065] The third row contains the identi fier of the enrolled biometric data for which the matching unit 13 computed the matching score stored in the second row . In this example , the identi fiers are expressed in the form Rx, where x stand for the number of the used enrolled biometric data . In this example , the set 11 comprises 6 enrolled biometric data . By reading the history 24 , it is visible that the first enrolled biometric data (Rl ) has been used three times by the matching unit 13 while the fourth enrolled biometric data (R4 ) has not been used by the matching unit 13 in the sequence of the last nine authentication attempts .

[0066] The trust evaluator 16 can be configured to compute the representativeness index 14 based on the history of use of the enrolled biometric data of the set 11 . For instance , assuming that the set 11 comprises N enrolled biometric data, the trust evaluator 16 could compute the representativeness index 14 as a ratio using the history for the N last financial transactions . The ratio could be the number of di f ferent enrolled biometric data that matched a candidate ( i . e . for which the computed matching score was above a preset threshold) divided by N . The associated predefined rule 17 could be that the computed ratio should be larger than a preset threshold like 20% , 40% , 70% or 80% .

[0067] Alternatively, the trust evaluator 16 could compute the representativeness index 14 as a ratio between the number of enrolled biometric data which never matched a biometric candidate ( or have never been used by the matching unit 13 ) and the number of enrolled biometric data belonging to the set 11 . The associated predefined rule 17 could be that the computed ratio should be lower than a preset threshold like 5% , 10% or 20% .

[0068] Advantageously, the trust evaluator 16 can be configured to compute the representativeness index 14 according to the three above-presented examples . In some embodiments , the representativeness index 14 ( GEMI ) can be computed as the weighted sum of each representativeness index presented above , each index having its own weight previously defined during a personali zation phase .

[0069] As can be understood by those skilled in the art , the representativeness index 14 can be generated according to di f ferent appropriate mathematical functions , in particular the GEMI can be an aggregation of as many representativeness subindexes .

[0070] In some embodiments , the banking application 23 can comprise a Card risk management unit including an enrolment maturity index of fline limit (EMIOL ) whose value can be defined by the issuer of the banking application during an initial personali zation phase . The Card risk management unit can be configured to generate the trust result 19 by checking (by applying predefined rule 17 ) that the representativeness index 14 reaches the EMIOL before validating the authentication of the user using the matching score computed by the matching unit 13 . I f the representativeness index 14 does reach the EMIOL, the Card risk management unit can be configured to apply conventional card risk management ( CRM) rules .

[0071] I f the representativeness index 14 does not reach the EMIOL, the Card risk management unit can be configured to send the computed representativeness index 14 to the remote bank server through a dedicated I ssuer Discretionary Data ( IDD) field as defined by EMVCo® speci fications . Then the remote bank server can take a transaction approval decision based on both the representativeness index 14 and transaction parameters like the transaction amount , the merchant type or the location of the Point-Of-Sale ( POS ) terminal for instance .

[0072] In some embodiments , the payment instrument can comprise an audit unit 18 which is configured to identi fy a selected enrolled biometric data belonging to the set 11 as being to be deleted by detecting that this selected enrolled biometric data has a degree of representativeness of the user lower than a preset threshold .

[0073] The audit unit 18 can rely on the history of use (by the matching unit 13 ) of the enrolled biometric data of the set 11 to detect which enrolled biometric data never matched a biometric candidate or has never been used by the matching unit 13 during the last M financial transactions . The number M can be set as a fixed number ( like 10 or 20 ) or can depend on the number of enrolled biometric data belonging to the set 11 .

[0074] It can be noted that the matching unit 13 can compute two or more matching scores (using di f ferent enrolled biometric data ) during the same financial transaction for example when some of them failed to reach the minimum acceptable level to authenticate the user .

[0075] The audit unit 18 can be designed to consider that an enrolled biometric data which never leads to a success ful match during the last M financial transactions ( or match attempts ) has a degree of representativeness of the user which is too low and should be removed from the set 11 .

[0076] Separately or in addition to relying on history, the audit unit 18 can be configured to detect an enrolled biometric data has become useless based on the percentage of overlap between the surface area covered by one enrolled biometric data and the totality of the surface areas of all enrolled biometric data of the set 11 . The audit unit 18 can be designed to consider that an enrolled biometric data has a degree of representativeness of the user 50 which is too low i f the percentage of overlap is not in a preset range . A percentage of overlap lower than a first threshold ( like 5% or 15% ) can be interpreted as reflecting an enrolled biometric data too isolated from the others . A percentage of overlap higher than a second threshold ( like 88 % or 96% ) can be interpreted as reflecting an enrolled biometric data that is redundant with at least one other enrolled biometric data of the set 11 .

[0077] Separately or in addition to above-presented embodiments , the audit unit 18 can be configured to detect an enrolled biometric data has become useless based on the number of remarkable points ( like a minutia ) of the enrolled biometric data .

[0078] Such a cleaning operation may be required for certain categories of people such as children whose biometric parameters may change rapidly, manual workers whose fingers may wear out or people whose fingers are sensitive to seasonal changes , probably due to the ambient temperature of the degree of humidity .

[0079] In some embodiments , the audit unit 18 can be configured to identi fy the selected enrolled biometric data and to remove it from the set 11 when a financial transaction is in progress . In some embodiments , the audit unit 18 can be configured to identi fy the selected enrolled biometric data and to remove it from the set 11 before a financial transaction starts , after a financial transaction ends or even in the absence of financial transaction . Thus , by cleaning the content of the set 11 , the degree of representativeness of the user by the content of the set 11 can be improved even i f no financial transaction happens , provided that the payment instrument is powered either by an internal energy source or an external power supply .

[0080] It can be noted that the audit unit 18 can perform the cleaning treatment ( i . e . detection and removal of the selected enrolled biometric data ) even i f the biometric sensor or the matching unit is not triggered / used .

[0081] Although described as a smart card in the abovepresented embodiments , the payment instrument can have another form factor like a payment ring, a payment keychain, a watch embedding a payment application, or a payment bracelet .

[0082] Figure 2 depicts a flow diagram for managing a payment instrument according to an example of the invention .

[0083] The payment instrument can be the payment card of Figure 1 for example .

[0084] The payment instrument comprises an indicator 15 reflecting whether the enrollment process is completed in the payment instrument or not .

[0085] During a financial transaction, the matching unit 13 of the payment instrument 10 computes ( step S 10 ) a matching score by comparing a biometric candidate data captured by the biometric sensor 54 with at least one enrolled biometric data of the set 11 .

[0086] Then, the trust evaluator 16 of the payment instrument computes ( step S 12 ) a representativeness index 14 reflecting a level of representativeness of the user 50 of the payment instrument by said set . This representativeness index 14 is separate from the indicator 15 .

[0087] Then, the payment instrument generates ( step S 14 ) a trust result 19 by checking that the representativeness index 14 satis fies a predefined rule 17 .

[0088] Then the payment instrument contributes to the user authentication ( step S 16 ) to authori ze the financial transaction by using both the matching score 12 and the trust result 19 .

[0089] In some embodiments , the set 11 includes a plurality of enrolled biometric data and the payment instrument can compute ( step S 12 ) the representativeness index 14 based on notable relationships between the enrolled biometric data of the set 11 .

[0090] For example , the payment instrument can compute the representativeness index 14 using a proportion of enrolled biometric data having an overlapping surface area compared to the total number of enrolled biometric data of the set 11 .

[0091] In another example (which can be combined with the preceding one ) , the trust evaluator 16 can compute the representativeness index 14 based on an history of use (by the matching unit 13 ) of the enrolled biometric data of the set 11 . In another example , the payment instrument can comprise an audit unit 18 which identi fies a selected enrolled biometric data belonging to the set 11 as being to be deleted by detecting that the selected enrolled biometric data has a degree of representativeness of the user lower than a preset threshold . Then, the audit unit 18 removes the selected enrolled biometric data from the set 11 .

[0092] The audit unit 18 can perform identi fication and removal of the selected enrolled biometric data independently on the existence of a pending financial transaction . Notably, the audit unit 18 can perform identi fication and removal of the selected enrolled biometric data even i f no financial transaction is in progress .

[0093] The invention is not limited to the described embodiments or examples . In particular, the described examples and embodiments may be combined .

[0094] The invention is not limited to Banking smart cards and applies to any payment instruments embedding a biometric sensor and able to participate to a financial transaction .

[0095] The invention is not limited to payment instruments embedding a fingerprint sensor and applies to payment instruments embedding other types of biometric sensor . For instance , the biometric data captured by the sensor can be related to iris .

[0096] Thanks to some embodiments of the invention, the payment instrument can assess the degree of representativeness of the user 50 by its own set of already enrolled biometric data . Consequently, when an authentication of the cardholder is performed based on a biometric data captured by the biometric sensor, the payment instrument can adapt its contribution to the user authentication according to the trust result of a check involving both the representativeness index and a predefined rule . Depending on this trust result and a computed biometric matching score , the card may consider the user is success fully authenticated or require a remote server to complete the user authentication .

[0097] It can be noted that the representativeness index of the invention is di f ferent from parameters that can be chosen for setting the False Rej ection Rate ( FRR) and the False Acceptance Rate ( FAR) of the matching unit .

[0098] Thanks to some embodiments of the invention, the payment instrument can detect that an element of the set of enrolled biometric data is no longer suf ficiently representative of the user of the payment instrument and remove the detected enrolled biometric data from the set . In the same way, the payment instrument may detect biometric data unduly enrolled by a person di f ferent from the genuine user and delete wrong enrolled biometric data from the set of the payment instrument .

Claims

CLAIMS1. A payment instrument (10) assigned to a user (50) and able to participate to a financial transaction, the payment instrument including a biometric sensor (54) , a set (11) including one or more enrolled biometric data, and a matching unit (13) designed to compute a matching score (12) by comparing a biometric candidate data captured by the biometric sensor with at least one enrolled biometric data of the set, wherein the payment instrument comprises an indicator (15) reflecting whether an enrollment process of the set is completed or not, wherein the payment instrument comprises a trust evaluator (16) configured to compute a representativeness index (14) reflecting a level of representativeness of the user by said set, said representativeness index being separate from said indicator (15) , wherein the payment instrument is configured to generate a trust result (19) by checking that the representativeness index satisfies a predefined rule (17) and to contribute to user authentication to authorize the financial transaction by using both said matching score and said trust result, and wherein the matching unit (13) is configured to contribute to user authentication when the indicator (15) shows that the enrollment process of the set is not completed .

2. The payment instrument according to claim 1, wherein the set (11) includes a plurality of enrolled biometric data and wherein the trust evaluator (16) is configured to compute the representativeness index (14) based on notable relationships between the enrolled biometric data of the set.

3. The payment instrument according to claim 2, wherein the payment instrument is configured to compute the representativeness index (14) using a proportion of enrolled biometric data having an overlapping surface compared to the total number of enrolled biometric data of the set.

4. The payment instrument according to claim 2, wherein the set (11) includes a plurality of enrolled biometric data and wherein the trust evaluator (16) is configured to compute the representativeness index (14) based on an history of use of the enrolled biometric data of the set.

5. The payment instrument according to any of the preceding claims, wherein the payment instrument comprises an audit unit (18) configured to identify a selected enrolled biometric data belonging to the set (11) as being to be deleted by detecting that said selected enrolled biometric data has a degree of representativeness of the user lower than a preset threshold .

6. The payment instrument according to claim 5, wherein the set (11) includes a plurality of enrolled biometric data and wherein the audit unit (18) is configured to identify said selected enrolled biometric data as being to be deleted based on a combination of an history of use of the enrolled biometric data of the set and notable relationships between the enrolled biometric data of the set.

7. The payment instrument according to claim 5 or 6, wherein the audit unit (18) is configured to identify said selected enrolled biometric data before the financial transaction starts or after the financial transaction ends.

8. The payment instrument according to any of the preceding claims, wherein the financial transaction is payment transaction or a cash withdrawal transaction.

9. The payment instrument according to any of the preceding claims, wherein the payment instrument is a smart card, a ring, a keychain, a watch, or a bracelet.

10. A method for managing a payment instrument (10) assigned to a user (50) and able to participate to a financial transaction, the payment instrument including a biometric sensor (54) , a set (11) including one or more enrolled biometric data, and a matching unit (13) designed to compute (S10) a matching score (12) by comparing a biometric candidate data captured by thebiometric sensor with at least one enrolled biometric data of the set, wherein the payment instrument comprises an indicator (15) reflecting whether an enrollment process is completed in the payment instrument or not, wherein the payment instrument comprises a trust evaluator (16) that computes (S12) a representativeness index (14) reflecting a level of representativeness of the user by said set, said representativeness index being separate from said indicator (15) , wherein the matching unit (13) contributes to user authentication when the indicator (15) shows that the enrollment process of the set is not completed, and wherein the method comprises: generating (S14) by the payment instrument a trust result (19) by checking that the representativeness index satisfies a predefined rule (17) , and contributing to user authentication (S16) to authorize the financial transaction by using both said matching score and said trust result.

11. The method according to claim 10, wherein the set (11) includes a plurality of enrolled biometric data and wherein the trust evaluator (16) computes the representativeness index (14) based on notable relationships between the enrolled biometric data of the set .

12. The method according to claim 11, wherein the payment instrument computes the representativeness index (14) using a proportion of enrolled biometric data havingan overlapping surface compared to the total number of enrolled biometric data of the set.

13. The method according to claim 11 or 12, wherein the set (11) includes a plurality of enrolled biometric data and wherein the trust evaluator (16) computes the representativeness index (14) based on an history of use of the enrolled biometric data of the set.

14. The method according to claim 11, 12 or 13, wherein the payment instrument comprises an audit unit (18) which identifies a selected enrolled biometric data belonging to the set (11) as being to be deleted by detecting that said selected enrolled biometric data has a degree of representativeness of the user lower than a preset threshold.

Citation Information

Patent Citations

  • Conditional and situational biometric authentication and enrollment

    US10777030B2

  • Multi-factor signature authentication

    US10824842B2

  • Efficient prevention of fraud

    US20160247160A1

  • Distributed processing in authentication

    US8406478B2

  • Biometric payment card enrollment notification

    WO2022033769A1