Biometric orchestration systems, platforms, and methods of facilitating biometric verification of individuals

The biometric orchestration system addresses inefficiencies and security issues in existing systems by facilitating seamless biometric verification and transaction processing, reducing fraud and costs through centralized biometric data management and integration.

WO2026072845A1PCT designated stage Publication Date: 2026-04-02VERIFONE INC

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-09-25
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Existing biometric authentication systems for contactless transactions are inefficient and pose security issues, leading to higher transaction costs and liability for merchants due to card-not-present fraud, as there is no centralized biometric data repository and integration into transaction systems is cumbersome.

Method used

A biometric orchestration system that receives biometric information, determines routing, communicates with target biometric identification systems, generates identification data packets, and integrates with biometric vaults and digital wallets to facilitate seamless biometric verification and transaction processing.

Benefits of technology

Enables secure, efficient biometric verification, reducing fraud and transaction costs by transforming card-not-present transactions into card-present transactions, while ensuring data security and compliance with cybersecurity standards.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure US2025048013_02042026_PF_FP_ABST
    Figure US2025048013_02042026_PF_FP_ABST
Patent Text Reader

Abstract

Provided herein are systems and methods for authenticating users during payment transactions and other types of interaction events using biometric information. The disclosed systems involve a biometric orchestration platform that receives biometric data of a user from a biometric module or device, intelligently routes this data to a biometric verification service, and retrieves a positive identification if a match is found. This identification is then used in various ways, e.g., to retrieve a payment card token linked to the user's authorized payment method.
Need to check novelty before this filing date? Find Prior Art

Description

PATENT APPLICATIONAttorney Docket No.: VFI-4049-WOBIOMETRIC ORCHESTRATION SYSTEMS, PLATFORMS, AND METHODS OF FACILITATING BIOMETRIC VERIFICATION OF INDIVIDUALSCross-Reference to Related Applications

[0001] This application claims the benefit of and priority to U.S. Provisional Patent Application Serial No. 63 / 699,323, filed on September 26, 2024, U.S. Provisional Patent Application Serial No. 63 / 743,229, filed on January 8, 2025, and U.S. Provisional Patent Application Serial No. 63 / 744,194, filed on January 11, 2025, which are titled “METHODS AND SYSTEMS FOR CONTACTLESS TRANSACTIONS USING BIOMETIRC INFORMATION”, the entire disclosures of which are incorporated herein by reference. This application also claims the benefit of and priority to U.S. Provisional Patent Application Serial No. 63 / 762,604, filed on February 24, 2025 and titled “BIOMETRIC PAYMENT SYSTEMS, BIOMETRIC VERIFICATION INFRASTRUCTURE FOR PAYMENT SYSTEMS, AND METHODS OF ENABLING BIOMETRIC PAYMENTS”, the entire disclosure of which is incorporated herein by reference.Field of the Disclosure

[0002] The present disclosure relates generally to systems and methods for identification, authenticating, and verifying individuals using the individuals' biometric information, and more specifically to biometric systems, infrastructure, and methods for facilitating biometricbased transactions.Background

[0003] Traditional payment transactions utilizing a credit card or debit card typically require entering payment information such as the card number into a merchant’s point of sale (POS) terminal. The POS terminal connects to a payment network to transmit the obtained information and validate and approve the payment transaction. For payment transactions using a debit card, the user enters a personal identification number (PIN) to verify themselves as the cardholder and to authorize the transaction. This is used as evidence that the cardholder is present with the payment card at the time of purchase, creating a “card present” (CP) payment transaction.

[0004] Similarly, with some contactless payments, the user may only “tap” or otherwise present a payment card using near-field communication (NFC) to a POS to verify that thePATENT APPLICATIONAttorney Docket No.: VFI-4049-WO cardholder is present with the payment card at the time of purchase. Thus, this is also a CP payment transaction even though it is nearly or completely contactless.

[0005] In contrast, with other contactless payments, there is no payment card presented and thus it is a card-not-present (CNP) transaction. This lack of the payment card presents an opportunity for fraud, and as a result the merchant pays significantly higher transaction fees for CNP transactions than for CP transactions. For a merchant with many transactions, this can result in significantly higher costs.

[0006] Biometric verification of a cardholder for contactless transactions is one method to prevent fraud with what is essentially a CNP transaction. Since the biometric information is utilized to verify the user as the cardholder (even though the card is not physically presented), the transaction effectively becomes a CP transaction rather than a CNP transaction, and the merchant has lower transaction fees and less liability for the transaction. Thus, utilizing biometric authentication of a user for a contactless transaction can represent a significant financial benefit for the merchant. However, existing methods and systems for the biometric authentication of a user for a contactless transaction remain inefficient and potentially present security issues.Summary of the Disclosure

[0007] As described herein, traditional payment systems and payment transactions, especially card-not-present (CNP) transactions, are susceptible to fraud, leading to higher transactions costs and increased liability for merchants. While biometric verification can help reduce fraud by effectively returning a CNP transaction into a CP transaction, existing methods and systems for biometric authentication can be inefficient and present significant security issues. For example, there is not one centralized biometric data repository that all current and potential customers share and each biometric identification service may operate according to its own specifications and requirements. This ultimately makes it exceedingly difficult to seamlessly integrate biometric identification for verification or authentication purposes in payment transaction systems. Further, not only do the biometric vaults have to perform efficiently to effectively match any number of types of biometric information, but the biometric vaults must also trust the requesting party and the endpoint destination of biometric identification. Thus, there is a technical challenge in handling biometric information with due care while also coordinating the efficient and seamless integration into transaction-related systems.PATENT APPLICATIONAttorney Docket No.: VFI-4049-WO

[0008] According to one embodiment of the present disclosure, a method of orchestrating biometric authentication of an individual is provided. The method involves: (i) receiving, at a biometric orchestration system comprising one or more processors configured to perform at least part of a biometric identification protocol, biometric information of the individual from a biometric device; (ii) determining, at the biometric orchestration system, biometric routing information for the biometric information of the individual, wherein the biometric routing information indicates a target biometric identification system to use to generate a biometric identification for the individual; (iii) communicating, to the target biometric identification system, at least the biometric information of the individual obtained by the biometric device, wherein the target biometric identification system is configured to determine whether a match for the biometric information of the individual exists within a target biometric vault; (iv) receiving, from the target biometric identification system, a biometric identification for the individual generated by the target biometric identification system; (v) generating, at the biometric orchestration system, a biometric identification data packet based on the biometric identification received for the individual; and (vi) communicating, from the biometric orchestration system and to the biometric device, the biometric identification data packet.

[0009] In one aspect, the biometric information of the individual is received from the biometric device as part of a secured information package, the secured information package further comprising a first biometric data structure encoding a first set of one or more biometric parameters from the biometric information of the individual, the first biometric data structure having a first predetermined format.

[0010] In one aspect, the first predetermined format is defined by the biometric orchestration system.

[0011] In one aspect, the biometric orchestration system comprises a biometric registry storing a plurality of encoded biometric data structures and corresponding biometric routing information for a plurality of individuals, wherein each encoded biometric data structure of the plurality of encoded biometric data structures also has the first predetermined format, and wherein the biometric routing information for the individual is determined by: searching the plurality of encoded biometric data structures stored in the biometric registry and returning the biometric routing information corresponding to the encoded biometric data structure matching the first biometric data structure.

[0012] In one aspect, the first biometric data structure further encodes a consumer platform identifier and / or a biometric vault identifier in accordance with the first predetermined format.PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO

[0013] In one aspect, the biometric routing information for the individual is determined by extracting the consumer platform identifier and / or the biometric vault identifier from the first biometric data structure.

[0014] In one aspect, the secured information package further comprises a second biometric data structure encoding a second set of one or more biometric parameters from the biometric information of the individual, the second biometric data structure having a second predetermined format that is different than the first predetermined format.

[0015] In one aspect, the biometric information of the individual is communicated from the biometric orchestration system to the target biometric identification system in the form of the second biometric data structure, the target biometric identification system being configured to determine whether a match for the biometric information of the individual exists within the target biometric vault based on the second set of one or more biometric parameters encoded into the second biometric data structure.

[0016] In one aspect, the biometric information of the individual communicated to the target biometric identification system includes raw biometric information.

[0017] In one aspect, the method further involves receiving, from the target biometric identification system, non-biometric information associated with the individual in response to returning a positive biometric identification indicating that a match for the biometric information of the individual was found. The non-biometric information may include payment card-related information, loyalty- and / or rewards-related information, and / or biographical information of the individual. The biometric identification data packet generated for the individual may include the positive biometric identification and the non-biometric information.

[0018] In one aspect, the method further involves retrieving, via the biometric orchestration system and from a digital wallet or other service provider, non-biometric information associated with the individual in response to receiving a positive biometric identification of the individual indicating that a match for the biometric information of the individual was found. The non-biometric information may include payment card-related information, loyalty- and / or rewards-related information, and / or biographical information of the individual. The biometric identification data packet generated for the individual may include the positive biometric identification and the non-biometric information.

[0019] In one aspect, the biometric orchestration system is located remotely from the biometric device, the biometric information of the individual is received from the biometricPATENT APPLICATIONAttorney Docket No.: VFI-4049-WO device over one or more communications networks, and the biometric identification data packet is communicated to the biometric device over the one or more communications networks.

[0020] In one aspect, the biometric orchestration system is located remotely from the target biometric identification system, the biometric information of the individual is communicated to the target biometric identification system over the one or more communications networks, and the biometric identification for the individual is received by the biometric orchestration system over the one or more communications networks.

[0021] In one aspect, the biometric identification for the individual is a tentative or a negative biometric identification if a match for the biometric information of the individual is not found within a predetermined confidence threshold. The biometric identification data packet generated based on the tentative or the negative biometric identification may comprise a request for new or updated biometric information.

[0022] In one aspect, the biometric information of the individual comprises a fingerprint, palm print, palm vein geometry, retina or iris scan, vein pattern, facial geometry, voice pattern, and / or speech data.

[0023] According to another embodiment of the present disclosure, a biometric orchestration system configured to be in communication with a plurality of biometric devices is provided. The biometric orchestration system includes: (i) a communication interface configured to enable communication with the plurality of biometric devices over one or more communications networks; (ii) one or more computer processors; and (iii) a non-transitory computer-readable storage medium storing instructions to be executed by the one or more computer processors. When executed by the one or more computer processors, the instructions cause the biometric orchestration system to perform a biometric identification protocol including the following operations: (i) receive biometric information of the individual from a first biometric device; (ii) determine biometric routing information for the biometric information of the individual, wherein the biometric routing information indicates a target biometric identification system to use to generate a biometric identification for the individual; (iii) communicate, to the target biometric identification system, at least the biometric information of the individual, wherein the target biometric identification system is configured to determine whether a match for the biometric information of the individual exists within a target biometric vault; (iv) receive, from the target biometric identification system, a biometric identification for the individual generated by the target biometric identification system; (v) generate a biometric identification data packet based on the biometric identification receivedPATENT APPLICATIONAtorney Docket No.: VFI-4049-WO for the individual; and (vi) communicate, to the first biometric device, the biometric identification data packet.

[0024] In one aspect, the biometric information of the individual is received from the first biometric device as part of a secured information package, the secured information package further comprising a first biometric data structure encoding a first set of one or more biometric parameters from the biometric information of the individual, the first biometric data structure having a first predetermined format.

[0025] In one aspect, the first predetermined format is defined by the biometric orchestration system.

[0026] In one aspect, the biometric orchestration system further includes a biometric registry storing a plurality of encoded biometric data structures and corresponding biometric routing information for a plurality of individuals, wherein each encoded biometric data structure of the plurality of encoded biometric data structures also has the first predetermined format. The biometric routing information for the individual may be determined by searching the plurality of encoded biometric data structures stored in the biometric registry and returning the biometric routing information corresponding to the encoded biometric data structure matching the first biometric data structure.

[0027] In one aspect, the first biometric data structure further encodes a consumer platform identifier and / or a biometric vault identifier in accordance with the first predetermined format.

[0028] In one aspect, the biometric routing information for the individual is determined by extracting the consumer platform identifier and / or the biometric vault identifier from the first biometric data structure.

[0029] In one aspect, the secured information package further comprises a second biometric data structure encoding a second set of one or more biometric parameters from the biometric information of the individual, the second biometric data structure having a second predetermined format that is different than the first predetermined format.

[0030] In one aspect, the biometric information of the individual is communicated from the biometric orchestration system to the target biometric identification system as the second biometric data structure, the target biometric identification system being configured to determine whether a match for the biometric information of the individual exists within the target biometric vault based on the second set of one or more biometric parameters encoded into the second biometric data structure.PATENT APPLICATIONAttorney Docket No.: VFI-4049-WO

[0031] In one aspect, the biometric identification protocol further includes: receiving, from the target biometric identification system, non-biometric information associated with the individual in response to returning a positive biometric identification indicating that a match for the biometric information of the individual was found. The non-biometric information may include payment card-related information, loyalty- and / or rewards-related information, and / or biographical information of the individual. The biometric identification data packet generated for the individual may then include the positive biometric identification and the non-biometric information.

[0032] In one aspect, the biometric identification protocol further includes retrieving, from a digital wallet or other service provider, non-biometric information associated with the individual in response to receiving a positive biometric identification of the individual indicating that a match for the biometric information of the individual was found. The nonbiometric information may include payment card-related information, loyalty- and / or rewards- related information, and / or biographical information of the individual. The biometric identification data packet generated for the individual may then include the positive biometric identification and the non-biometric information.

[0033] These and other aspects of the various embodiments will be apparent from and elucidated with reference to the embodiments described hereinafter.Brief Description of the Drawings

[0034] In the drawings, like reference characters generally refer to the same parts throughout the different views. The figures showing features and ways of implementing various embodiments and are not to be construed as being limiting to other possible embodiments falling within the scope of the attached claims. Also, the drawings are not necessarily to scale, emphasis instead generally being placed upon illustrating the principles of the various embodiments.

[0035] FIG. l is a schematic of a biometric transaction system deployed at a merchant site showing POI and biometric module integration illustrated in accordance with aspects of the present disclosure.

[0036] FIG. 2 is a layered architecture of the biometric transaction ecosystem including merchant, orchestration, vault, and consumer platform domains illustrated in accordance with aspects of the present disclosure.PATENT APPLICATIONAttorney Docket No.: VFI-4049-WO

[0037] FIG. 3 is a system diagram showing the interaction between user devices, biometric routing, verification services, and POI devices illustrated in accordance with aspects of the present disclosure.

[0038] FIG. 4A is a schematic diagram of the enrollment process for a consumer into a biometric verification service illustrated in accordance with aspects of the present disclosure.

[0039] FIG. 4B is a flow diagram illustrating the steps of biometric vector generation and storage during consumer enrollment illustrated in accordance with aspects of the present disclosure.

[0040] FIG. 5 is a method diagram showing steps for completing a biometric card-present payment transaction illustrated in accordance with aspects of the present disclosure.

[0041] FIG. 6 is a process flow diagram for a biometric card-present transaction using a biometric module and orchestration platform illustrated in accordance with aspects of the present disclosure.

[0042] FIG. 7 is a process flow diagram for a biometric card-not-present transaction using stored payment credentials illustrated in accordance with aspects of the present disclosure.

[0043] FIG. 8 is a process diagram for retrieving and applying loyalty information using biometric authentication illustrated in accordance with aspects of the present disclosure.

[0044] FIG. 9 is a process diagram for verifying a consumer’s age using biometric authentication illustrated in accordance with aspects of the present disclosure.

[0045] FIG. 10 is a flowchart for a biometric check-in process at a point-of-interaction device illustrated in accordance with aspects of the present disclosure.

[0046] FIG. 11 is a diagram of a point-of-interaction device shown in accordance with certain aspects of the present disclosure.

[0047] FIG. 12 is a diagram of a point-of-interaction device showing internal components and interfaces illustrated in accordance with aspects of the present disclosure.

[0048] FIG. 13 is a diagram of a biometric module including processor, memory, sensors, and communication interfaces illustrated in accordance with aspects of the present disclosure.

[0049] FIG. 14 is a representation of a POS terminal and biometric module showing hardware and software components illustrated in accordance with aspects of the present disclosure.

[0050] FIG. 15 is a schematic of a cloud-based biometric verification platform with processing and storage components illustrated in accordance with aspects of the present disclosure.PATENT APPLICATIONAttorney Docket No.: VFI-4049-WO

[0051] FIG. 16 is a flow diagram of a biometric user interface application for transaction processing illustrated in accordance with aspects of the present disclosure.

[0052] FIG. 17A-17N are screenshots and interface flows for a biometric user interface application, from check-in to receipt, illustrated in accordance with aspects of the present disclosure.

[0053] FIG. 18 is a second biometric user interface application flow for completing a transaction illustrated in accordance with aspects of the present disclosure.

[0054] FIG. 19A-19L are screenshots and interface flows for a second biometric UI, including scanning, exceptions, and payment confirmation illustrated in accordance with aspects of the present disclosure.

[0055] FIG. 20 is a method diagram summarizing the steps for authenticating a user and completing a biometric transaction illustrated in accordance with aspects of the present disclosure.Detailed Description of Embodiments

[0056] Provided herein are systems and methods for authenticating a user for payment transaction purposes. More specifically, provided herein are biometric authentication systems and processes for completing payment transactions and customizing merchant-consumer interactions using consumer biometric information. In particular aspects of the present disclosure, consumers may self-register or enroll in a biometric authentication service that stores consumer biometric information in a secure, biometric information data storage system. Then, when a participating consumer engages with a merchant, a biometric-enabled point-of- interaction (POI) device can securely obtain and communicate consumer biometric information to the biometric authentication service for consumer identification and authentication. In embodiments, the biometric transaction systems and platforms enable payment transactions using only biometric information (i.e., without the need for presenting a physical payment card or otherwise providing payment card information through, e.g., a digital wallet). These biometric transaction systems and platforms also enable merchants to customize their offerings and tailor merchant-consumer interactions using biometric information of participating consumers.

[0057] It will be appreciated by those of ordinary skill in the art that the payment technology sector is strictly regulated by a number of different national and international organizations, which mandate robust data security and consumer protection protocols. Key frameworks likePATENT APPLICATIONAtorney Docket No.: VFI-4049-WO the Payment Card Industry Data Security Standard (PCI DSS 4.0) and Europe’s Revised Payment Services Directive (PSD2) require the use of encryption and anonymization protocols to protect cardholder data and require multi-factor authentication (MFA) for certain applications. It is also anticipated that these cybersecurity and data privacy standards will continue to evolve as new technologies and exploits are developed. Accordingly, in various respects, the biometric transaction systems, platforms, and processes described herein provide many advantages over conventional biometric-based authentication methods and systems, which may not be secure enough or otherwise suitable for integration with existing financial transaction infrastructure based on current and future cybersecurity and data privacy standards.

[0058] According to further aspects, the biometric transaction systems, platforms, and processes described herein also provide a number of improvements to payment processing technologies, including providing more options for consumers to choose how to complete payment transactions, allowing merchants and consumers greater ability to customize and tailor offerings and merchant-consumer interactions, and eliminating the need for consumers to carry and provide physical cards (e.g., payment cards as well as loyalty / rewards cards, etc.), among other advantages. As described herein, such advantages can be provided in a user-friendly and merchant-friendly manner. For example, the benefits of the biometric transaction technologies of the present disclosure may extend the functionality of existing POI devices and use existing payment rails available to merchants while still ensuring appropriate data security and privacy protections.

[0059] Turning now to FIG. 1, an exemplary biometric transaction system 100 is illustrated in accordance with certain aspects of the present disclosure. In embodiments, at least a portion of the biometric transaction system 100 may be deployed at a merchant site, including but not limited to, retail stores, convenience stores, restaurants and bars, hotels, pharmacies, entertainment venues, markets and fairs, and / or the like.

[0060] As shown, the biometric transaction system 100 can include certain on-premises (i.e., “on-prem”) hardware 110, such as a point-of-interaction (“POI”) device 120 and a biometric module 130. In embodiments, the POI device 120 can be a point-of-sale (“POS”) device, a payment terminal, a tablet or smartphone being used as a POS device, a self-service kiosk, a digital directory or wayfinding kiosk, a self-service checkout station, an interactive display, and / or the like. In some embodiments, the POI device 120 may comprise the biometric module 130, i.e., the biometric module 130 is integrated with the POI device 120. In other embodiments, the POI device 120 and the biometric module 130 may be separate devices thatPATENT APPLICATIONAttorney Docket No.: VFI-4049-WO are merely in secure communication with one another. In still further embodiments, the biometric module 130 may be attached to and in communication with the POI device 120, but not fully integrated into the POI device 120.

[0061] According to some aspects of the present disclosure, the POI device 120 may be utilized by merchants and consumers to complete payment transactions in exchange for goods and / or services. In some embodiments, these payment transactions may involve handling payment card information provided by payment cards physically present at the point-of-sale, i.e., in a card-present (“CP”) transaction. In other embodiments, these payment transactions may involve handling payment card information provided by payment cards not physically present at the point-of-sale, i.e., in a card-not-present (“CNP”) transaction.

[0062] However, as described herein, biometric module 130 and the POI device 120 may operate together in order to perform payment transactions using biometric information provided by the consumer at the point-of-sale. In particular embodiments, such payment transactions may be contactless biometric transactions, CP biometric-initiated transactions, and / or the like.

[0063] In embodiments, the POI device 120 can receive a request for a biometric-initiated transaction, e.g., from a consumer. Traditionally, the consumer would be required to present a payment card to the merchant (via the POI device 120) to initiate the financial transaction. However, as described herein, the consumer is able to provide biometric information and thus a payment card is not required to be physically present. In particular embodiments, the consumer may request a biometric-initiated payment transaction by selecting a corresponding menu option provided using the POI device 120, which triggers the POI device 120 initiate a biometric verification protocol using the biometric module 130. However, it is also possible for the merchant to trigger the biometric verification protocol upon request by the consumer, e.g., the consumer may verbally request a biometric-initiated payment transaction and the merchant may operate the POI device 120 to effectuate the biometric verification protocol. In any case, executing the biometric verification protocols of the biometric module 130 allow the merchant to ultimately process the transaction via a payment processor, e.g., payment processor 160.

[0064] In embodiments, the biometric module 130 is configured to obtain biometric information of a consumer, who typically must be in proximity to the biometric device 130 in order to provide the biometric information. As mentioned above, the biometric module 130 may be a component of the POI device 120 or may be separate or remote from the POI devicePATENT APPLICATIONAtorney Docket No.: VFI-4049-WO120 but otherwise in communication with the POI device 120. Thus, the biometric device 130 may be triggered or initiated to obtain biometric information of a consumer upon receiving a request or command from the POI device 120. In response to the command or request for biometric authentication of a consumer from the POI device 120, the biometric module 130 can execute a preprogrammed or predetermined biometric authentication protocol (described in more detail below) that includes obtaining biometric information from the consumer.

[0065] The biometric information obtained by the biometric module 130 may be any measurable biological / physical and / or behavioral characteristic, or combination of such characteristics, that can be used to reliably identify an individual. For example, the biometric information can include biological / physical characteristics such as a fingerprint, palm print, palm vein geometry, retina or iris scan, vein patern, facial geometry or characteristics, voice pattern, or other biological / physical characteristic, including combinations thereof. As another example, the biometric information include behavioral characteristics such as a habit or pattern that identifies a user. Other biometrics are possible.

[0066] More specifically, in certain embodiments, the biometric module 130 comprises or is otherwise in communication with one or more sensors that obtain the biometric information, including but not limited to, a camera that uses visible light or other wavelengths of light to obtain a scan of a consumer’ s face, a fingerprint or palm scanner that obtains a scan of the consumer’s fingerprint or palm print, an audio sensor that obtains voice / speech data from the consumer, and / or the like. Other devices and sensors configured to obtain biometric information are possible.

[0067] Once obtained, the biometric information may be utilized immediately to perform the biometric authentication, and / or the biometric information may be stored in short-term or long-term memory for future use (e.g., training purposes, quality control purposes, or other authorized uses).

[0068] In embodiments, the biometric device 130 can transmit at least the biometric information to a remote biometric verification service 150, including the biometric orchestration system 221, 320 via a communications network 140 for the purpose of verifying or authenticating a consumer’s identity. In some embodiments, additional information such as transaction information (e.g., transaction amount, description of the goods and services, date and time, etc.), merchant information (e.g., merchant identifier, description of the merchant, etc.), or other information as necessary. In particular embodiments, the information transmitted to the biometric verification service 150 from a biometric device (e.g., the biometric modulePATENT APPLICATIONAtorney Docket No.: VFI-4049-WO130) does not include payment card information. Nevertheless, the transmitted information may be encrypted, signed, or otherwise secured or packaged before it is communicated to the biometric verification service 150. As described herein, this information transmitted to the biometric orchestration system 221, 320 from the biometric device 130 may be referred to as a secured information package.

[0069] In embodiments, the communications network 140 can include one or more interconnected networks, including one or more wired and / or wireless networks. For example, the communications network 140 may include a Bluetooth network, a Zigbee network, a WiFi network, a cellular network, a satellite network, an infrared network, an optical network, a near field communication network, and / or the like, including combinations thereof. In particular embodiments, the communications network 140 may include a personal area network (PAN), a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a global area network (GAN), and / or the like, including combinations thereof.

[0070] Accordingly, as described in more detail below, the biometric module 130 comprises a communications network interface that enables communication with other components of the system 100 as well as the biometric verification service 150.

[0071] In embodiments, the biometric verification service 150 may be configured to or otherwise capable of utilizing the obtained biometric information to authenticate or verify the identity of a participating consumer. The biometric verification service 150, also referred to herein as a biometric verification platform, can comprise or otherwise be in communication with one or more databases of participating consumers. These databases may part of or otherwise referred to herein as biometric vaults. The biometric vaults may store biometric information for individuals enrolled in the biometric payment ecosystem described herein, which may be collected and managed through one or more consumer platforms (e.g., card issuer / networks, fintech / wallets / social, merchant / acquirers, etc.) as described in more detail below. In other words, the biometric vaults can store verified biometric information associated with verified users, as well as other identifying information such as their name, age, date of birth, address, and / or other information.

[0072] As described herein, the biometric vaults and the biometric orchestration system 150 can be specially adapted for storing, processing, and communicating biometric information. For example, the biometric orchestration system 150 and the biometric vaults may utilize specialized data structures, encryption schemes, access and / or search functions, and validation procedures, given the nature and sensitivity of the biometric information being handled.PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO

[0073] Importantly, according to some embodiments of the present disclosure, the biometric vaults may also store payment information provided by participating consumers, such as primary account numbers, customer engagement information, payment card tokens issued by a token service provider, and / or the like. As described herein, customer engagement information refers to information (generally provided or supplied by the customer) that allows merchants to provide experiences tailored to the particular customer, such as by providing customize user interfaces or automatically interacting with various incentive programs. In particular examples, the customer engagement information may include information related to an incentives program, a loyalty program, a rewards program, and / or a membership that the customer participates in, and / or similar services. Thus, in embodiments, the biometric vaults may also utilize specialized data structures, encryption schemes, access and / or search functions, and validation procedures, given the nature and sensitivity of the payment information being handled.

[0074] In any case, when the biometric orchestration system 150 receives a biometric identification request from, e.g., a biometric module 130, the biometric orchestration system 150 interoperates with the biometric vaults to perform a biometric identification protocol to verify the identity of a customer. In embodiments, the result of the biometric verification can be a biometric identification, which may be a positive biometric identification (i.e., the consumer is positively identified based on the biometric information obtained) or a negative biometric identification (i.e., the consumer is not able to be identified based on the biometric information obtained).

[0075] In particular embodiments, a negative biometric identification may occur when the biometric information obtained by the biometric module 130 is of insufficient quality to allow for a match. In further embodiments, a tentative biometric identification may occur when the search identifies a potential match, but the potential match is not of sufficient quality or above a predetermined threshold to definitively identify the user. In such embodiments, the biometric orchestration system 150 may return an indication that no match was found, or may issue a request to the biometric module 130 for new or updated biometric information.

[0076] In embodiments, when the biometric identification is positive, i.e., the biometric verification returns a match of sufficient quality or above a predetermined threshold to definitively identify a participating consumer, the biometric orchestration system 150 can create and send a positive identification data packet to the biometric module 130 via the communications network 140. In embodiments, the positive identification data packet canPATENT APPLICATIONAttorney Docket No.: VFI-4049-WO include relevant or necessary information for completing a merchant-consumer transaction, identifying loyalty or rewards programs, tailoring a merchant-consumer experience, and / or the like. For example, in particular embodiments, the positive identification data packet comprises at least a payment card token associated with a payment method authorized by the participating consumer.

[0077] According to particular aspects of the present disclosure, the payment card token may be a randomly generated or algorithmically derived digital identifier that that replaces sensitive payment card information like a consumer’ s primary account number (“PAN”) during a transaction. In embodiments, a payment card token may be generated when a consumer enrolls in the biometric verification ecosystem described herein. The payment card token is generally created and issued by a token service provider, i.e., a payment network such as Visa, Mastercard, American Express, etc. In some embodiments, the payment card token may be uniquely generated in connection with a certain consumer platform, such as a ApplePay, Google Pay, PayPal, another digital wallet provider, and / or the like. In further embodiments, the payment card token may be uniquely generated in connection with the biometric orchestration system 150, i.e., the payment card token is domain restricted and only valid for biometrically-verified transactions.

[0078] As described herein, the payment card token may include, for example, a token value, a token type, a token domain, a token expiration, token metadata, cryptographic elements, a mapping reference, and / or the like. The payment card token may be characterized as shown in Table 1 below:PATENT APPLICATIONAttorney Docket No.: VFI-4049-WOTABLE 1. CARD TOKEN PROPERTIESToken Value • Randomly generated or algorithmically derived string that replaces the consumer’s PAN• May preserve the formatting of the consumer’s PAN (e.g., a 16-digit string)Token Type • Indicates the use case for the token (e.g., device-specific, merchant-specific, single-use, multi-use, etc.)Token Domain • Indicates the scope in which the token is valid (e.g., for a specific merchant, device, etc.)Token Expiration • A timestamp or date indicating when the token becomes invalidToken Metadata • Indicates additional relevant information, such as a particular device, who requested the token (i.e., a particular consumer platform like ApplePay, PayPal, Google Pay, etc.), and / or the likeCryptographic Elements • May be a cryptogram used to secure the token, or a pointer to specific encryption keys used for token generation and validation, and / or the likeMapping Reference • A reference used by the payment network to link the token to the consumer’ s PAN

[0079] According to certain aspects of the present disclosure, the information transmitted between the biometric orchestration system 150 and the biometric module 130 may be validated and secured for cybersecurity and data privacy purposes. For example, the information sent to the biometric orchestration system 150 may be encrypted by the biometric module 130 before being sent, and the biometric orchestration system 150 may store or otherwise have access to the encryption keys necessary to decrypt or otherwise access all or part of the encrypted data. Similarly, the positive identification data packet sent to the biometric module 130 from the biometric orchestration system 150 can be encrypted at the biometric orchestration system 150 before being sent, and the biometric module 130 may store or otherwise have access to the encryption keys necessary to decrypt or otherwise access all or part of the encrypted data.

[0080] After a positive biometric identification is made and a positive identification data packet is returned to the biometric module 130, the biometric module 130 may then create and communicate a transaction payload to the POI device 120. In embodiments, the transaction payload can include at least the network token obtained from the biometric orchestration system 150. In further embodiments, the transaction payload may include additionalPATENT APPLICATIONAtorney Docket No.: VFI-4049-WO information such as transaction information (e.g., transaction amount, description of the goods and services, date and time, etc.), merchant information (e.g., merchant identifier, description of the merchant, etc.), or other information as necessary. In certain embodiments, one or more parts of the transaction information may be modified based on customer engagement information associated with the customer and the transaction. For example, the customer engagement information may include a loyalty discount or incentive that reduces the initial transaction amount, and thus the transaction payload will include the modified transaction information, e.g., the reduced transaction amount.

[0081] In particular embodiments, the biometric module 130 and the POI device 120 may interoperate to create the transaction payload. That is, according to some embodiments, the biometric module 130 may share some or all of the information contained in the positive identification data packet with the POI device 120, which then creates the transaction payload instead of the biometric module 130.

[0082] In some additional embodiments, the transaction payload may also include a unique identifier used to secure the transaction. As described herein, the unique identifier is a nonce, i.e., a unique, random or algorithmically derived number that serves as a secure payment code or number that expires after a short period of time (e.g., within minutes). The nonce can be used when transmitting a payment request to the acquirer / payment processor 160. In embodiments, the unique identifier may be a 16-digit nonce, and / or a 16 byte string of 16 digits (if encoded using ASCII or UTF-8). However, other formats and encodings are possible.

[0083] According to some embodiments, the payment or POS terminal 120, 360 generates the transaction nonce and communicates it to the biometric module 130, 350. Alternatively, the biometric module 130, 350 can generate the transaction nonce and communicate it to the payment or POS terminal 120, 360.

[0084] In either case, the transaction nonce may be created automatically such as when a user initiates a biometric transaction via the payment or POS terminal 360, 380. Alternatively, the transaction nonce may be created once the user is verified by the biometric verification service (as confirmed by receipt of the information communicated from the biometric verification service to the biometric module 130, 350, for example). Other timeframes or steps for generation of the transaction nonce are possible. Specific methods for generating and utilizing nonces are known in the art.

[0085] Once the transaction payload is created, the POI device 120 can transmit the transaction payload to a payment processor 160 (sometimes referred to herein as an acquirer orPATENT APPLICATIONAttorney Docket No.: VFI-4049-WO a merchant acquirer) via a communications network 140 as part of a payment request. In embodiments, the transaction payload may be signed, encrypted, and / or otherwise secured by the POI device 120 before being sent to the payment processor 160. The payment processor 160 then processes the payment request, coordinating with the appropriate card network and the card issuer (e.g., the cardholder’s bank) for approval based on the information in the transaction payload. In some embodiments, the POI device 120 may utilize a payment gateway to facilitate the online transaction and authorize the payment transfer after ensuring that user funds are available. The payment gateway may include an existing gateway like Stripe, PayPal, Adyen, PayU, and / or the like.

[0086] If approved, the payment processor 160 may settle the appropriate funds into a merchant account and return a payment success status code to the POI device 120. Otherwise, if the payment request is denied, the payment processor 160 will not settle any funds and return a payment unsuccessful status code to the POI device 120. It will be appreciated that the payment request may be denied for a variety of reasons, though typically it will be due to financial reasons (e.g., insufficient funds, overlimit transaction, etc.) or security reasons (e.g., fraud detection, suspicious transactions, etc.), rather than due to identification of the user given the methods and systems described or otherwise envisioned herein.

[0087] Upon receiving the successful / unsuccessful status code, the POI device 120 can convey an appropriate message to the merchant and consumer, e.g., by displaying a corresponding message on a display screen, creating a physical or digital receipt, and / or the like.

[0088] Thus, as described, various aspects of a biometric transaction ecosystem are provided by the present disclosure. Additional details, features, and components of the biometric transaction ecosystem are described below. Further, various aspects of biometric transaction ecosystems may be supplemented, substituted, or otherwise adjusted as also described below.

[0089] For example, with reference to FIG. 2, the biometric transaction ecosystems 200 described herein may include components and sub-systems distributed across multiple domains or layers, such as a merchant domain 210, a biometric orchestration layer 220, a biometric vault infrastructure 230, and a consumer platform domain 240.

[0090] Starting within the merchant domain 210, a merchant may operate one or more onpremises biometrically-enabled point-of-interaction (POI) devices 211 (e.g., the integrated hardware 110), including but not limited to one or more payment terminals. In somePATENT APPLICATIONAtorney Docket No.: VFI-4049-WO embodiments, the merchant domain 210 can also include online marketplaces accessible through a web browser or application on consumers’ personal electronic devices 212 (e.g., smartphones, tablets, computers, etc.) that are equipped with a biometric reader capable of collecting biometric information from the consumer.

[0091] In embodiments, the devices 211, 212 within the merchant domain 210 can interoperate with a biometric orchestration platform 221, like the remote biometric verification service 150, which resides in the biometric orchestration layer 220. As shown in the example of FIG. 2, the biometric orchestration platform 221 may be referred to as a biometric switch and can include an EMV cloud module, a biometric registry, a biometric routing module, and a payment orchestration module. As described herein, the biometric orchestration platform 221 can coordinate biometric verification processes between the merchant domain, the biometric vaults, and the consumer platforms in order to generate a unique biometric payment token that is used by the payment networks to complete a transaction.

[0092] In embodiments, the biometric orchestration platform 221 can interoperate with one or more biometric vaults 231 that store biometric data for participating consumers, i.e., consumers enrolled in the biometric payment / loyalty / rewards program. As shown in the example of FIG. 2, the biometric vaults 231 may be a proprietary biometric vault associated with the biometric orchestration service provider, or may be provided by a third party, such as a fintech, bank, or other payment network service provider.

[0093] In particular embodiments, the biometric vault infrastructure 230 may interoperate with one or more consumer platforms 241A, 421B, 241C within a consumer platform domain 240 in order to retrieve details about consumers’ payment accounts, rewards / loyalty programs, membership benefits, and / or the like associated with the consumers’ biometric data. In some embodiments, the consumer platforms 241 A, 421B, 241C may also facilitate the enrollment of consumers into a biometric transaction service and collect consumers’ biometric data. In other words, the participating consumer platforms 241A, 241B, 241C may offer a biometric enrollment service that enables consumers to provide biometric data and register with a biometric transaction service provider. In embodiments, the consumer platforms 241A, 421B, 241C may be provided by card issuers / networks, fintech / wallet / social companies, specific merchants or acquirers, and / or the like. Each consumer platform 241A, 421B, 241C may be accessed in a variety of ways, such as through smartphones, computers, and / or the like.

[0094] As also shown in the example of FIG. 2, the biometric orchestration platform 221 can interoperate with one or more payment networks, such as Mastercard®, Visa®, AmericanPATENT APPLICATIONAtorney Docket No.: VFI-4049-WOExpress®, Discover®, JCB®, Diners Club International, and / or the like, in order to process payment transfers in accordance with the biometric verification protocols described herein. In particular aspects, the biometric orchestration platform 221 may generate a biometric payment token and / or payload that is used by the payment networks to complete a transaction, as described herein.

[0095] Turning now to FIG. 3 and subsequent figures, further aspects of the biometric transaction systems of the present disclosure are illustrated and described. As shown in the example of FIG. 3, the biometric transaction system 300 comprises or is in local and / or remote communication with one or more of a user device 310, a biometric routing platform 320 which comprises or is in communication with a biometric verification system 330, a biometric vault 340, a POI device including a POS device 380 and / or a terminal 360, and a biometric module 350. In particular embodiments, the biometric transaction system 300 may also include an estate management module 370. In still further embodiments, the biometric transaction system 300 may be in communication with a loyalty service provider 392 or a restricted transaction verification system that certifies an customer for a restricted transaction (e.g., an age verification service provider 390, etc.), and / or other similar service providers.

[0096] As described herein, the biometric routing service 320 can be an orchestration layer or switch, like biometric orchestration platform 221 and / or the biometric orchestration system 150. Although only a single biometric verification system 330 and biometric vault 340 are shown in the example of FIG. 3, it should be appreciated that the biometric routing service 320 can be configured as the interface between a plurality of different POI devices (like the terminal 360 and POS device 380) and a plurality of different biometric verification services 330 and / or biometric vaults 340. In particular embodiments, the plurality of different POI devices may be part of a network of POI devices provided by a specific merchant or group of merchants, which may be distributed geographically at different locations and managed by an estate management module 370.

[0097] As described herein, the estate management module 370 can include a collection of hardware and / or software components that facilitate control or management of the devices 360, 380 and / or the biometric module 350. According to an embodiment, the estate management module 370 can be utilized to download software to these devices 350, 360, 380, to manage one or more parameters of the devices 350, 360, 380, and / or to communicate status information regarding the devices 350, 360, 380 (e.g., for managing the deployment of devices, for diagnostic purposes, and / or the like).PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO

[0098] Accordingly, as described herein, the biometric routing service 320 can direct a biometric authentication request comprising a consumer’s biometric data to the appropriate biometric verification system 330, i.e., a target biometric verification system. In particular embodiments, the biometric routing service 320 may utilize information in an authentication request to determine where to direct the biometric authentication request and associated biometric data.

[0099] As shown in the example of FIG. 3 and subsequent figures, the user device 310 may be a mobile device or non-mobile device configured to enable capture and transmission of biometric information. Examples of user devices 310 can include, but is not limited to, smartphones, tablets, laptops, desktops, kiosks, and / or other types of devices. In embodiments, the user device 310 can be configured to obtain and provide information to other components of the system, including but not limited to identification information, biometric information, loyalty information, and payment information.

[0100] According to certain aspects of the present disclosure, the biometric verification system 330 can be configured to securely receive and process consumer biometric data in order to identify a biometric identification of a consumer. These and other use cases of the biometric transaction system 300 are discussed in more detail below.

[0101] For example, with reference to FIGS. 4 A and 4B, the biometric transaction system 300 can be utilized to enroll consumers into a biometric transaction / payment program. In particular, with reference to FIG. 4 A, a schematic diagram of a transaction system 300 utilized for enrollment of a consumer into a biometric verification service is illustrated in accordance with certain aspects of the present disclosure.

[0102] As shown, at step 1, the biometric routing platform 320 receives, from a user device 310 (or a software application loaded onto the user device 310), a request from a consumer to enroll in the biometric verification service. The enrollment request comprises at least some relevant enrollment information, including but not limited to, the consumer’s name, phone number, or email address, biometric information such as a face scan raw image, a palm scan raw image of one or both hands, consumer preferences, loyalty information, consumer payment information such as PAN, card expiration date, and / or the like, as well as payment card tokens (from a payment card network), and / or other types of information relevant to the enrollment of the consumer. As such, in particular embodiments, the payment card token may be generated at the enrollment stage, i.e., before the customer attempts a biometric payment transaction.PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO

[0103] In some embodiments, the enrollment information may include an identification of a particular biometric verification system 330 or a particular biometric vault 340 that the consumer must or wishes to use.

[0104] At step 2, the biometric routing platform 320 then sends some or all of the enrollment information to the target biometric verification system 330. At step 3, the biometric verification system 330 can save some or all of the enrollment information, such as the raw image data and biometric vector (discussed in more detail below), and may further create and assign a biometric ID unique to the consumer. At step 4, some or all of the enrollment information is saved, along with the unique biometric ID created for the consumer, in a corresponding biometric vault 340. In particular embodiments, the biometric verification system 330 does not store the raw biometric data of the consumer in the biometric vault 340, i.e., only the biometric ID may be stored in the biometric vault 340 in accordance with certain aspects of the present disclosure.

[0105] At steps 5 and 6, the biometric verification system 330 may return an enrollment confirmation and / or any other necessary enrollment information to the biometric routing platform 320, which can then send that confirmation to the user device 310. The consumer is thus successfully enrolled in the biometric verification service and able to participate in biometric-based interactions and transactions as described herein. According to an embodiment, if there are any errors or enrollment issues along the process (e.g., collection of inadequate raw biometric data, etc.), the biometric routing platform 320 can send that error or enrollment issue information to the user device 310, which can facilitate correction of the error or enrollment issue.

[0106] With reference to FIG. 4B, the enrollment process is further illustrated in the flow diagram shown in accordance with additional aspects of the present disclosure. In particular, a process for enrolling in the biometric payment ecosystem is illustrated where a consumer enrolls through a mobile application, e.g., a mobile app on a user device 310.

[0107] In a first step, the consumer initiates the enrollment process and provides certain raw biometric information (e.g., a photograph, palm print, fingerprint, etc.). This biometric information may be transmitted to the biometric routing platform 320 along with other enrollment information as part of an enrollment request as described above.

[0108] In a second step, a biometric software module (sometimes referred to as the ‘Bio SDK’) residing within the biometric routing platform 320 is utilized to convert the raw biometric information into a proprietary biometric vector. This biometric vector encodes onePATENT APPLICATIONAtorney Docket No.: VFI-4049-WO or more biometric parameters (e.g., VI, Rl, x2, xl, zl, etc. shown in FIG. 4B) based on the biometric information submitted by the consumer during the enrollment process.

[0109] In a third step, the biometric software module at the biometric routing platform 320 then converts the biometric information to a specified data structure based on an orchestration template specified by the orchestration platform. As shown, the data structure can provision space for storing a consumer platform identifier along with the biometric vector generated for the consumer. In embodiments, the consumer platform identifier is an identification code that indicates which consumer platform was used to enroll the consumer in the biometric payment ecosystem 200.

[0110] Accordingly, in some embodiments, the biometric vector standardized according to the orchestration template may be tagged, encoded, embedded with, or otherwise associated with the consumer platform identifier. As described herein, the biometric platform 320 (i.e., the biometric switch 221) may comprise a biometric registry (as also shown in FIG. 2), which can store the at least standardized biometric vector and the associated consumer platform identifier. Thus, in particular embodiments, the enrollment process 400 may include an additional step of storing and / or updating the biometric registry of the biometric platform 221, 320 with the consumer’s enrollment information.[OHl] As shown in FIG. 4B, the enrollment process 400 can then include, in a fourth step, communicating at least the consumer’s biometric vector to an appropriate biometric vault 340, i.e., a target biometric vault. According to a fifth step or aspect of the enrollment process 400, the consumer biometric vault may create a data entry that associates together the raw biometric information (e.g., photograph, palm print, fingerprint, etc.) provided by the consumer, the proprietary biometric vector generated from the biometric information, as well as the orchestration-specified biometric vector, which is stored in the biometric vault 340.

[0112] With reference to FIGS. 5 to 7, exemplary transaction workflows utilizing the biometric transaction systems 100, 200, 300 are illustrated in accordance with various aspects of the present disclosure.

[0113] For example, with reference to FIG. 5, a first method 500 of authenticating a consumer’s biometric identity while completing a payment transaction is illustrated. As shown, a POS device 380 is utilized for a transaction and, at step 1, transaction information (e.g., the amount of the transaction) is sent to a POS terminal 360 (which may be the same as or different from the POS 380). At step 2, a participating consumer can use the terminal 360 to select an option to pay using biometric information. At step 3, the terminal 360 invokes the biometricPATENT APPLICATIONAtorney Docket No.: VFI-4049-WO module 350, i.e., sends a biometric authentication request to the biometric module 350, which triggers the biometric module 350 to perform a biometric-based transaction protocol. At step 4, the consumer provides the biometric information to the biometric module 350, e.g., through a scan or some other method, depending on the type of biometric information required. According to an embodiment, the user provides biometric data such as fingerprint, palm print, palm vein geometry, retina or iris scan, vein patern, facial geometry or characteristics, voice pattern, or other biological / physical characteristic, including combinations thereof.

[0114] At step 5, the biometric data is sent to the biometric orchestration system 320. The orchestration system 320 determines, on the basis of information received from the biometric module 350, to which biometric verification system 330 to direct the request.

[0115] At step 6, the biometric orchestration system 320 sends the biometric data to the target biometric system 330.

[0116] At step 7, the biometric verification system 330 processes the biometric data to find the user’s matching biometric ID, and at step 8, the identified biometric ID is used to retrieve associated information from the biometric vault 340 (which here includes payment information).

[0117] At step 9, the payment information, which may be in the form of a payment token, is sent back to the biometric system 330, which then sends the information to the biometric orchestration system 320 at step 10.

[0118] At step 11, the biometric orchestration system 320 sends the information to the POS terminal 360, 380, such as via the biometric module 350.

[0119] At step 12, the returned information is utilized by the biometric module 350 to simulate a “tap” of payment card to the POS terminal 360, 380, thereby providing the payment information. It should be appreciated that in this manner, the transaction can be considered a “card present” or “CP” transaction, even though the consumer did not provide a physical or digital payment card.

[0120] Finally, at step 13, the transaction is processed with this payment information using known methods for transaction processing, e.g., through an acquirer / payment processor 160, 222 as described above.

[0121] With reference to FIG. 6, another process 600 for authenticating a consumer’s biometric identity while completing a payment transaction is illustrated. As shown, the consumer can utilize their biometrics information to complete a “card present” payment transaction. In particular, the customer checks-in via the terminal (e.g., terminal 120, 211, 360),PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO which activates the biometric module (e.g., biometric module 130, 350) to collect the consumer’s biometric information. The consumer provides their biometric information (e.g., by scanning their face, palm print, fingerprint, etc.) using the biometric module 130, 350. In some embodiments, the biometric module 130, 350 may provide a preview of the biometric data collected to the terminal. The terminal 120, 211, 360 may show the consumer a preview of the biometric scan for approval / confirmation.

[0122] Once the biometric module 130, 350 completes the biometric scan, the biometric module 130, 350 may perform a liveness check process and encrypt the biometric information before transmitting the biometric information to the biometric orchestration platform 150, 221, 320 (i.e., the biometric switch).

[0123] At the orchestration platform level (e.g., the orchestration layer 220), the biometric switch 221, 320 will look-up biometric routing information based on the biometric information received from the biometric module 130, 350. For example, as mentioned above, the biometric information can include a consumer platform identifier and an orchestration-specified biometric vector. The biometric switch 221, 320 may utilize a biometric vault registry to perform the look-up process.

[0124] Once the relevant biometric vault 231, 340 has been identified, a biometric data payload comprising the raw biometric information, the orchestration-specified biometric vector, and optionally other data is generated and transmitted to the relevant biometric vault 231, 340. The biometric vault 231, 340 receives this biometric data payload, validates the information, and matches the biometric data based on the biometric information stored within the vault (e.g., biometric information provided by the consumer during an enrollment process). In particular embodiments, these steps may be performed with the biometric vault 231, 340 in conjunction with a biometric verification system 330, as described above.

[0125] When a valid biometric match has been found, the biometric identification is transmitted back to the biometric orchestration system 221, 320. The biometric orchestration system 221, 320 may then transmit the validated biometric ID to a consumer platform 240, which can return the customer’s name, points, and a payment token.

[0126] In embodiments, the biometric orchestration system 221, 320 may then transmit the biometric ID to the biometric module 130, 350 and / or the point-of-interaction device 120, 211 (i.e., the payment terminal 360).

[0127] The merchant can supply transaction information to the point-of-interaction device 120, 211, 360, such as by scanning items that the consumer wishes to purchase. The consumerPATENT APPLICATIONAtorney Docket No.: VFI-4049-WO then selects, via the point-of-interaction device 120, 211, 360, a biometric-enabled payment platform. As shown in the example of FIG. 6, the payment method encompasses a “card present” transaction. However, it should be understood that “card present” transactions may be completed using certain payment services, such as PayPal®, assuming that they offer biometric payment services.

[0128] As shown, the terminal 120, 211, 360 requests a payment method from the biometric module 130, 350. The biometric module 130, 350 requests a network token from the biometric switch 221, 320, which fetches network tokens based on the platform token mentioned earlier. The biometric switch returns 221, 320 the network token to the biometric module 130, 350. The biometric module 130, 350 then generates a contactless card-present payload, activates a near-field communication (NFC) antenna, and transmits the contactless card-present payload to the terminal 120, 211, 360.

[0129] The terminal 120, 211, 360 may then transmit the payment credentials to an acquirer / payment processor 160, 222 via existing payment rails, gateways, DTH, etc. The acquirer and / or transaction processor 160, 222 will authorize the payment credentials and if successful, return a success message to the terminal 120, 211, 360. Otherwise, a payment failure message may be returned. The terminal 120, 211, 360 may then convey the success / failure to the consumer.

[0130] Turning to FIG. 7, a related process 700 for authenticating a consumer’s biometric identity while completing a payment transaction is illustrated. In particular, the consumer can utilize biometrics to complete a “card not present” transaction, i.e., a transaction using payment credentials only. As shown in the example of FIG. 7, the customer checks-in via the terminal 120, 211, 360, which activates the biometric module 130, 350 to scan the consumer. The consumer provides their biometric information (e.g., by scanning their face, palm print, fingerprint, etc.) using the biometric module 130, 350. In some embodiments, the biometric module 130, 350 may provide a preview of the biometric data collected to the terminal 120, 211, 360. The terminal 120, 211, 360 may show the consumer a preview of the biometric scan for approval / confirmation.

[0131] Once the biometric module 130, 350 completes the biometric scan, the biometric module 130, 350 may perform a liveness check process and encrypt the biometric information before transmitting the biometric information to the biometric orchestration system 221, 320 (i.e., the biometric switch).PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO

[0132] At the orchestration platform level, the biometric orchestration system 221, 320 will look-up biometric routing information based on the biometric information received from the biometric module 130, 350. For example, as mentioned above, the biometric information sent to the biometric orchestration system 221, 320 can include a consumer platform identifier or biometric vault identifier encoded into an orchestration-specified biometric vector, which the orchestration system 221, 320 may extract. The biometric orchestration system 221, 320 may utilize a biometric vault registry to perform the look-up process.

[0133] Once the relevant biometric vault 231, 340 has been identified, a biometric data payload comprising the raw biometric information, the orchestration-specified biometric vector, and optionally other data is generated and transmitted to the relevant biometric vault 231, 340. The biometric vault 231, 340 receives this biometric data payload, validates the information, and matches the biometric data based on the biometric information stored within the vault (e.g., biometric information provided by the consumer during an enrollment process). In particular embodiments, these steps may be performed with the biometric vault 231, 340 in conjunction with a biometric verification system 330, as described above.

[0134] When a valid biometric match has been found, the biometric identification is transmitted to the biometric orchestration system 221, 320. The biometric orchestration system 221, 320 may then transmit the validated biometric ID to a consumer platform 241 A, 24 IB, 241C. In response to receiving the validated biometric ID, the consumer platform 241 A, 241B, 241C can then return customer information to the biometric orchestration system 221, 320, including but not limited to, the customer’s name, points, and payment credentials for the customer.

[0135] In embodiments, the biometric orchestration system 221, 320 may then transmit the biometric ID and the customer information (including at least the payment credentials) to the biometric module 130, 350, which communicates the validated biometric ID to the point-of- interaction device (e.g., devices 110, 120, 360). The point-of-interaction device 110, 120, 360 may be configured to provide a personalized experience to the consumer based on the validated biometric ID and customer information. For example, the terminal 110, 120, 360 may display a welcome message with name and loyalty / customer points available for use at the merchant’ s location.

[0136] The merchant can supply transaction information to the point-of-interaction device 110, 120, 360, such as by scanning items that the consumer wishes to purchase. The consumer then selects, via the point-of-interaction device 110, 120, 360, a biometric-enabled paymentPATENT APPLICATIONAtorney Docket No.: VFI-4049-WO platform. As shown in the example of FIG. 7, the payment method encompasses a “card not present” transaction, i.e., based on stored payment credentials. It should be understood that “card not present” transactions may be completed using various payment services as described above.

[0137] As shown, the terminal 110, 120, 360 then utilizes the customer information (e.g., the payment credentials) and the transaction information to generate a transaction payload with the payment credentials. The payment credentials and transaction payload may be transmitted from the terminal 110, 120, 360 to an acquirer and / or transaction processor 160, 222 via existing payment rails, gateways, DTH, etc. The acquirer and / or transaction processor 160, 222 will authorize the payment credentials and if successful, return a success message to the terminall lO, 120, 360. Otherwise, a payment failure message may be returned. The terminal 110, 120, 360 may then convey the success / failure to the consumer.

[0138] As mentioned above, the biometric transaction systems 100, 200, 300 may also be utilized to biometrically authenticate consumers for the purposes of loyalty / rewards programs, age verification, transaction check-ins, and / or other similar interaction events. As such, according to various embodiments of the present disclosure, the biometric identification system and / or the targeted biometric vault may return non-biometric information associated with a verified individual, including payment card-related information, incentive program information, loyalty- and / or rewards-related information, biographical information, identitybased information of the individual (e.g., age, gender, nationality or citizenship, etc.), socioeconomic information of the individual (e.g., credit score, employment status, etc.), geographic information of the individual (residential address, country or region, etc.), legal or regulatory information of the individual (criminal record, immigration status, sanctions or watchlist inclusion, licensing or certification status, etc.), and health-related information of the individual (medical conditions, disability status, vaccination records, mental health status, etc.).

[0139] For example, with reference to FIG. 8, a loyalty / rewards process 800 is illustrated in which a biometric transaction system 300 is utilized to invoke a loyalty service provider 392. As shown, a POS 380 is utilized for a transaction and at step 1, where transaction information (e.g., the amount of the transaction) is sent to a POS terminal 360 (which may be the same as or different from the POS 380). At the step 2, the user can select an option to retrieve loyalty information (and optionally pay) using their biometric information. At step 3, the terminal 360 invokes a biometric module 130, 350 to collect and utilize the consumer’s biometric information for loyalty information retrieval or authentication.PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO

[0140] At step 4, the user provides the biometric information, which can be performed using any method for providing any biometric information. According to an embodiment, the user provides biometric data such as fingerprint, palm print, palm vein geometry, retina or iris scan, vein pattern, facial geometry or characteristics, voice pattern, or other biological / physical characteristic, including combinations thereof.

[0141] At step 5, the biometric data is sent to the biometric orchestration system 221, 320. The biometric orchestration system 221, 320 determines, on the basis of information received from the biometric module 130, 350, which biometric system 330 to direct the request.

[0142] At step 6, the biometric orchestration system 221, 320 sends the biometric data to the determined biometric system 330. At step 7, the biometric system 330 processes the biometric data to find the user’s matching biometric ID, and at step 8, the identified biometric ID is used to retrieve associated information from the biometric vault 340 (which here includes loyalty information and optionally payment information).

[0143] At step 9, the loyalty information (and optionally payment information, such as in the form of a payment token) is sent back to the biometric system 330, which sends the information to the biometric orchestration system 221, 320 at step 10.

[0144] At steps 11 and 12, the biometric orchestration system 221, 320 sends the information to the POS terminal 360, such as via the biometric module 350. In particular embodiments, the loyalty information is sent to the POS 380 at step 13, which can send the information to a loyalty service provider 392 as a loyalty redemption request at step 14. The loyalty service provider 392 can return an adjustment to the transaction amount (or other offers). With this information, a consumer-tailored effect can be achieved based on the biometric verification, which in this case, means that the POS 380 sends an updated total amount or other relevant information to the POS terminal 360, which then processes payment information using known methods for transaction processing.

[0145] Similarly, with reference to FIG. 9, an age verification process 900 is illustrated in which a biometric transaction system 300 is utilized to invoke an age verification service provider 390. As shown, a POS 380 is utilized for a transaction and at step 1, where transaction information (e.g., the amount of the transaction) is sent to a POS terminal 360 (which may be the same as or different from the POS 380). At the step 2, the user can select an option to perform an age verification using their biometric information. At step 3, the terminal 360 invokes a biometric module 130, 350 to collect and utilize the consumer’s biometric information for age verification retrieval or authentication.PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO

[0146] At step 4, the user provides the biometric information, which can be performed using any method for providing any biometric information. According to an embodiment, the user provides biometric data such as fingerprint, palm print, palm vein geometry, retina or iris scan, vein pattern, facial geometry or characteristics, voice pattern, or other biological / physical characteristic, including combinations thereof.

[0147] At step 5, the biometric data is sent to the biometric orchestration system 221, 320. The biometric orchestration system 221, 320 determines, on the basis of information received from the biometric module 130, 350, which biometric system 330 to direct the request.

[0148] At step 6, the biometric orchestration system 221, 320 sends the biometric data to the determined biometric system 330. At step 7, the biometric system 330 processes the biometric data to find the user’s matching biometric ID, and at step 8, the identified biometric ID is used to retrieve associated information from the biometric vault 340 (which here includes identity and / or age information).

[0149] At step 9, the requested information (and optionally payment information, such as in the form of a payment token) is sent back to the biometric system 330, which sends the information to the biometric orchestration system 221, 320 at step 10.

[0150] At steps 11 and 12, the biometric orchestration system 221, 320 sends the information to the POS terminal 360, such as via the biometric module 350. In particular embodiments, the identity / age information is sent to the POS 380 at step 13, which can send the information to an age verification service provider 390 as an age verification request at step 14. The age verification service provider 390 can return a verification of the consumer’s age. With this information, a consumer-tailored effect can be achieved based on the biometric age verification, which in this case, means that the POS terminal 360, 380 can continue to process the transaction (e.g., an age-restricted transaction) or decline the transaction based thereon (e.g., if the consumer is not of-age).

[0151] According to additional embodiments of the present disclosure, the biometric transaction systems 100, 200, 300 can be used to validate the presence of a participating consumer, which may be useful in customizing or tailoring a merchant-consumer experience. For example, with reference to FIG. 10, a transaction check-in process 1000 is illustrated in accordance with certain aspects of the present disclosure. In particular, a process 1000 for initiating a biometric transaction at a point-of-interaction / point-of-sale device 110, 211 is shown. Although this particular embodiment involves checking in at a point-of-sale devicePATENT APPLICATIONAtorney Docket No.: VFI-4049-WO110, 211 which are typically located at a merchant’ s in-person location, it should be appreciated that an online portal 212 may also be used to conduct a transaction check in process 1000.

[0152] In a first step, the consumer checks in at the relevant point-of-interaction 110, 211, e.g., the point-of-sale device. This may include initiating an application at the point-of- interaction device 110, 21 land providing necessary biometric information at the point-of- interaction (via a biometric module 130, 350, for example).

[0153] In a second step, a biometric software module (sometimes referred to as the ‘Bio SDK’ or the biometric kernel) residing within the biometric module 130, 350 converts the biometric information to a template format based on an orchestration template.

[0154] In some embodiments, the template format may be a proprietary biometric vector that encodes one or more biometric parameters (e.g., VI, Rl, x2, xl, zl, etc. shown in FIG. 10) based on the biometric information submitted by the consumer during the check-in process 1000. In other embodiments, the biometric information may be converted directly into an orchestration-specified biometric vector, i.e., without any reliance on or knowledge of a proprietary biometric vector.

[0155] As described herein, the formatted biometric information can include at least the biometric vector, but may also include other data, such as a consumer platform identifier, the raw biometric data (e.g., raw image, fingerprint, etc.), and / or the like. The consumer platform identifier may also be referred to as a vault identifier, which identifies a particular biometric vault associated with the consumer’s biometric enrollment.

[0156] The formatted (e.g., vectorized) biometric information may then be transmitted to the biometric orchestration system 320, which uses the received information to look up the consumer’s biometric vector and the target biometric vault 241A, 241B, 241C using a biometric registry according to a third step.

[0157] Next, in a fourth step, the biometric orchestration system 320 may then transmit at least the raw biometric information and the biometric vector to the target consumer biometric vault 241A, 241B, 241C based on the consumer platform identifier. The consumer biometric vault 241 A, 241B, 241C receives the raw biometric information and the orchestration-specified biometric vector. In a fifth step, the consumer biometric vault 241 A, 241B, 241C uses the raw biometric information and the orchestration-specified biometric vector to perform matching and authentication. As described herein, it will be appreciated that the fourth and fifth steps may be performed with the biometric vault 241A, 241B, 241B, 340 in conjunction with a corresponding biometric verification system 330, as described above.PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO

[0158] Turning now to FIGS. 11 to 15, certain systems, devices, and components used in the biometric transaction systems 100, 200, 300 of the present disclosure are described and illustrated in further detail.

[0159] For example, with reference to FIG. 15, a schematic illustration of a payment or POS terminal 1100 is shown in accordance with aspects of the present disclosure. In particular embodiments, the terminals described above, e.g., terminals 120, 211, 360, may be embodied as described below.

[0160] In embodiments, the terminal 1100 comprises one or more processors 1120 capable of executing instructions stored in memory 1130 or storage 1160 or otherwise processing data to, for example, perform one or more steps of the method. Processor 1120 may be formed of one or multiple modules. Processor 1120 may take any suitable form, including but not limited to a microprocessor, microcontroller, multiple microcontrollers, circuitry, field programmable gate array (FPGA), application-specific integrated circuit (ASIC), a single processor, or plural processors.

[0161] Memory 1130 can take any suitable form, including a non-volatile memory and / or RAM. The memory 1130 may include various memories such as, for example LI, L2, or L3 cache or system memory. As such, the memory 1130 may include static random access memory (SRAM), dynamic RAM (DRAM), flash memory, read only memory (ROM), or other similar memory devices. The memory can store, among other things, an operating system. The RAM is used by the processor for the temporary storage of data. According to an embodiment, an operating system may contain code which, when executed by the processor, controls operation of one or more components of terminal 1100. It will be apparent that, in embodiments where the processor implements one or more of the functions described herein in hardware, the software described as corresponding to such functionality in other embodiments may be omitted.

[0162] User interface 1140 may include one or more devices for enabling communication with a user. The user interface 1140 can include, for example and without limitation, a display, a mouse, a keyboard, and / or the like, for receiving user commands. In some embodiments, user interface 1140 may include a command line interface or graphical user interface that may be presented to a remote terminal via communication interface 1150. The user interface 1140 may be located with one or more other components of the system 1100, or may located remote from the system 1100 and in communication via a wired and / or wireless communications network 140. According to an embodiment, the user interface 1140 enables the user and / or a merchantPATENT APPLICATIONAtorney Docket No.: VFI-4049-WO to initiate a transaction, enter information about goods or services, request biometric verification of age or access to loyalty programs, and / or any other functions described herein. For example, the user interface may enable a request to initiate a transaction by requesting to make a purchase of goods or services.

[0163] Communication interface 1150 may include one or more devices for enabling communication with other hardware devices, such as a biometric module 130, 350, as well as external systems like an acquirer / payment processor 160. For example, communication interface 1150 may include a network interface card (NIC) configured to communicate according to the Ethernet protocol. Additionally, communication interface 1150 may implement a TCP / IP stack for communication according to the TCP / IP protocols. Various alternative or additional hardware or configurations for communication interface 1150 will be apparent.

[0164] Storage 1160 may include one or more machine-readable storage media such as readonly memory (ROM), random-access memory (RAM), magnetic disk storage media, optical storage media, flash-memory devices, or similar storage media. In various embodiments, storage 1160 may store instructions for execution by processors 1120 or data upon which processors 1120 may operate. For example, storage 1160 may store an operating system 1161 for controlling various operations of terminal 1100.

[0165] It will be apparent that various information described as stored in storage 1160 may be additionally or alternatively stored in memory 1130. In this respect, memory 1130 may also be considered to constitute a storage device and storage 1160 may be considered a memory. Various other arrangements will be apparent. Further, memory 1130 and storage 1160 may both be considered to be non-transitory machine-readable media. As used herein, the term non- transitory will be understood to exclude transitory signals but to include all forms of storage, including both volatile and non-volatile memories.

[0166] While terminal 1100 is shown as including one of each described component, the various components may be duplicated in various embodiments. For example, as mentioned above, processor 1120 may include multiple microprocessors that are configured to independently execute the methods described herein or are configured to perform steps or subroutines of the methods described herein such that the multiple processors cooperate to achieve the functionality described herein. Further, where one or more components of terminal 1100 is implemented in a cloud computing system, the various hardware components may belong to separate physical systems. For example, processor 1120 may include a first processorPATENT APPLICATIONAtorney Docket No.: VFI-4049-WO in a first server and a second processor in a second server. Other variations and configurations are possible.

[0167] According to an embodiment, storage 1160 of terminal 1100 may store one or more algorithms, modules, and / or instructions to carry out one or more functions or steps of the methods described or otherwise envisioned herein. For example, storage 1160 may comprise, among other instructions or data, contactless transaction instructions 1162. In particular embodiments, the terminal 1100 may include a biometric applet and a bio ID interface as shown in FIGS. 3, 5, and 8, which enable the terminal 1100 to interoperate with a biometric module 130, 350. According to an embodiment, contactless transaction instructions 1162 direct the system 1100 to carry out one or more steps of the contactless transaction methods using the biometric modules 130, 350, as described or otherwise envisioned herein.

[0168] With reference to FIG. 12, additional aspects of the terminals 1100 are described and illustrated. In particular, as shown in FIG. 12, the terminals 120, 211, 360, 1100 may be a POI device 1200, or may form part of a POI device 1200. In addition to the aspects described above, the point-of-interaction device 1200 can include one or more processors 1202 and a machine- readable memory 1204 interconnected and / or in communication via a system bus 1206 containing conductive circuit pathways through which instructions (e.g., machine-readable signals) may travel to effectuate communication, tasks, storage, and the like. The point-of- interaction device 1200 can be connected to a power source (not shown), which can include an internal power supply and / or an external power supply. As mentioned above, the point-of- interaction device 1200 can also include one or more additional components, such as a user interface 1213, a display 1214, an input / output (I / O) interface 1212, a networking unit 1216, one or more card readers 1201, and the like, including combinations thereof. As shown, each of these components may be interconnected and / or in communication via the system bus 1206, for example.

[0169] In embodiments, the one or more card readers 1201 may include a magnetic stripe reader 1208 for reading and processing magnetic stripe data (e.g., Track I and Track II data) of payment cards, a smartcard reader 1203 for reading and processing chip-enabled payment cards, a contactless reader 1205 for reading and processing contactless data from a contactless- enabled payment card, and / or the like.

[0170] In embodiments, the one or more processors 1202 can include one or more highspeed data processors adequate to process payment card information, execute the program components described herein, and / or perform one or more operations of the methods describedPATENT APPLICATIONAtorney Docket No.: VFI-4049-WO herein. In particular embodiments, the one or more processors 1202 can include at least a secure processor 1230. The secure processor 1230 may be a processor that is housed in a secured or fortified part of the point-of-interaction device 1200, may be configured to control the high- security functions of the point-of-interaction device 1200, including but not limited to, managing encryption keys and libraries 1234 and / or protocols (e.g., VeriShield Crypto Library, AES, etc.), encrypting and decrypting sensitive cardholder information, managing card-reading interface modules 1201 to receive and process sensitive cardholder information, receive and transmit sensitive cardholder information to external destinations, and / or the like.

[0171] In further embodiments, the one or more processors 1202 can also include at least an application processor 1232. The application processor 1232 may be housed within the point- of-interaction device 1200 and may be configured to control the less sensitive functions of the point-of-interaction device 1200, including but not limited to controlling the display 1214.

[0172] In embodiments, the user interface 1213 may be configured to receive various forms of input from a user associated with the point-of-interaction device 1200. The user interface 1213 can include, but is not limited to, one or more of a keyboard, keypad, trackpad, trackball(s), capacitive keyboard, controller (e.g., a gaming controller), computer mouse, computer stylus / pen, a voice input device, and / or the like, including combinations thereof.

[0173] In embodiments, the display device 1214 may be configured to display information, including text, graphs, biometric information, selection menus, and / or the like. In particular embodiments, the display device 1214 may be configured to display transaction information related to one or more payment transactions. The display device 1214 can include, but is not limited to, a liquid crystal display (LCD), a light-emitting diode (LED) display, a touch screen or other touch-enabled display, a foldable display, a projection display, and so on, or combinations thereof.

[0174] In embodiments, the input / output (I / O) interface 1212 may be configured to connect and / or enable communication with one or more peripheral devices (not shown), including but not limited to additional machine-readable memory devices, diagnostic equipment, and other attachable devices. The I / O interface 1212 may include one or more I / O ports that provide a physical connection to the one or more peripheral devices. In some embodiments, the I / O interface 1212 may include one or more serial ports.

[0175] In embodiments, the communication interface 1216 may include one or more types of networking interfaces that facilitate wired and / or wireless communication between the point- of-interaction device 1200 and one or more external devices or systems, such as the acquirersPATENT APPLICATIONAttorney Docket No.: VFI-4049-WOI payment processors 160. That is, the communication interface 1216 may operatively connect the point-of-interaction device 1200 to one or more types of communications networks, which can include a direction interconnection, the Internet, a local area network (“LAN”), a metropolitan area network (“MAN”), a wide area network (“WAN”), a wired or Ethernet connection, a wireless connection, a cellular network, and similar types of communications networks, including combinations thereof. In some embodiments, the point-of-interaction device 1200 may communicate with one or more remote / cloud-based servers and / or cloudbased services, in order to verify payment card information and process financial transactions.

[0176] In embodiments, the memory 1204 can be variously embodied in one or more forms of machine accessible and machine-readable memory. In some embodiments, the memory 1204 includes a storage device (not shown), which can include, but is not limited to, a non-transitory storage medium, a magnetic disk storage, an optical disk storage, an array of storage devices, a solid-state memory device, and / or the like, as well as combinations thereof. The memory 1204 may also include one or more other types of memory, such as dynamic random-access memory (DRAM), static random-access memory (SRAM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), Flash memory, and / or the like, as well as combinations thereof. In embodiments, the memory 1204 may include a combination of different types of memory, including different types of transitory memory and different types of non-transitory memory.

[0177] The point-of-interaction device 1200 can be configured by software components stored in the memory 1204 to perform one or more processes of the methods described herein. More specifically, the memory 1204 can be configured to store data / information 1220 and computer-readable instructions 1222 that, when executed by the one or more processors 202, causes the point-of-interaction device 1200 to coordinate the biometric check-in, biometric loyalty access, biometric age verification, biometric transaction, and / or biometric payment methods described herein. Such data 1220 and the computer-readable instructions 1222 stored in the memory 1204 may form a biometric applet that may be incorporated into, loaded from, loaded onto, or otherwise operatively available to and from the point-of-interaction device 1200. Thus, in some embodiments, the biometric applet and / or one or more individual software packages may be stored in a local storage device of the memory 1204. However, in other embodiments, the biometric applet and / or one or more individual software packages may be loaded onto and / or updated from a remote server or service via a communications network.PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO

[0178] In particular embodiments, the memory 1204 may be configured to store a cryptographic library 1234, including the algorithms and keys necessary to support the secure encryption / decryption functions of the point-of-interaction device 1200. In embodiments, the portion of the memory 1204 storing the cryptographic library 1234 may be disposed within a secured or fortified section of the point-of-interaction device 1200 along with the secure processor 1230.

[0179] In further embodiments, the memory 1204 may include an application program interface (API) 1236 configured to facilitate the low-security features of the point-of- interaction device 1200, as described herein. In certain embodiments, this may include operating the display device 1214, generating / printing receipts, and / or the like. The API 1236 may be based on or otherwise compatible with one or more types of operating systems 1226, including but not limited to Verifone Secure OS, Engage VOS2, VAOS based on Android, and / or the like.

[0180] Accordingly, provided herein is a computer program product comprising a non- transitory computer-readable storage medium 1204 having stored thereon computer-readable instructions 1222 that, when executed by one or more processors (such as processors 1202), cause the one or more processors to perform one or more operations of the methods described herein.

[0181] Turning now to FIG. 13, a schematic illustration of a biometric module 1300 is shown in accordance with aspects of the present disclosure. The biometric modules 130, 350 described herein may be embodied in accordance with one or more aspects of the biometric module 1300 shown in FIG. 13.

[0182] According to an embodiment, biometric module 1300 comprises a processor 1320 capable of executing instructions stored in memory 1330 or storage 1360 or otherwise processing data to, for example, perform one or more steps of the method. Processor 1320 may be formed of one or multiple modules. Processor 1320 may take any suitable form, including but not limited to a microprocessor, microcontroller, multiple microcontrollers, circuitry, field programmable gate array (FPGA), application-specific integrated circuit (ASIC), a single processor, or plural processors.

[0183] Memory 1330 can take any suitable form, including a non-volatile memory and / or RAM. The memory 1330 may include various memories such as, for example LI, L2, or L3 cache or system memory. As such, the memory 1330 may include static random access memory (SRAM), dynamic RAM (DRAM), flash memory, read only memory (ROM), or other similarPATENT APPLICATIONAtorney Docket No.: VFI-4049-WO memory devices. The memory can store, among other things, an operating system. The RAM is used by the processor for the temporary storage of data. According to an embodiment, an operating system may contain code which, when executed by the processor, controls operation of one or more components of biometric module 1300. It will be apparent that, in embodiments where the processor implements one or more of the functions described herein in hardware, the software described as corresponding to such functionality in other embodiments may be omitted.

[0184] Communication interface 1350 may include one or more devices for enabling communication with other hardware devices. For example, communication interface 1350 may include a network interface card (NIC) configured to communicate according to the Ethernet protocol. Additionally, communication interface 1350 may implement a TCP / IP stack for communication according to the TCP / IP protocols. Various alternative or additional hardware or configurations for communication interface 1350 will be apparent.

[0185] Storage 1360 may include one or more machine-readable storage media such as readonly memory (ROM), random-access memory (RAM), magnetic disk storage media, optical storage media, flash-memory devices, or similar storage media. In various embodiments, storage 1360 may store instructions for execution by processor 1320 or data upon which processor 1320 may operate. For example, storage 1360 may store an operating system 1361 for controlling various operations of biometric module 1300.

[0186] It will be apparent that various information described as stored in storage 1360 may be additionally or alternatively stored in memory 1330. In this respect, memory 1330 may also be considered to constitute a storage device and storage 1360 may be considered a memory. Various other arrangements will be apparent. Further, memory 1330 and storage 1360 may both be considered to be non-transitory machine-readable media. As used herein, the term non- transitory will be understood to exclude transitory signals but to include all forms of storage, including both volatile and non-volatile memories.

[0187] While biometric module 1300 is shown as including one of each described component, the various components may be duplicated in various embodiments. For example, processor 1320 may include multiple microprocessors that are configured to independently execute the methods described herein or are configured to perform steps or subroutines of the methods described herein such that the multiple processors cooperate to achieve the functionality described herein. Further, where one or more components of biometric module 1300 is implemented in a cloud computing system, the various hardware components mayPATENT APPLICATIONAttorney Docket No.: VFI-4049-WO belong to separate physical systems. For example, processor 1320 may include a first processor in a first server and a second processor in a second server. Other variations and configurations are possible.

[0188] According to an embodiment, storage 1360 of biometric module 1300 may store one or more algorithms, modules, and / or instructions to carry out one or more functions or steps of the methods described or otherwise envisioned herein. For example, storage 1360 may comprise, among other instructions or data, contactless transaction instructions 1362. According to various embodiments, contactless transaction instructions 1362 may direct the biometric module 1300 to carry out one or more steps of the biometric check-in, biometric loyalty access, biometric age verification, biometric transaction, and / or biometric payment methods described herein. Such computer-readable instructions 1362 stored in the memory 1360 may form a biometric kernel that may be incorporated into, loaded from, loaded onto, or otherwise operatively available to and from the biometric module 1300, as shown in FIGS. 3, 5, 8, and 9. Thus, in some embodiments, the biometric kernel and / or one or more individual software packages may be stored in a local storage device of the memory 1304. However, in other embodiments, the biometric kernel and / or one or more individual software packages may be loaded onto and / or updated from a remote server or service via a communications network 140.

[0189] According to preferred embodiments, the biometric modules 1300 of the present disclosure comprises one or more sensor 1340 configured to obtain biometric information about user 1310. In the case of a biological / physical characteristic, the sensor 1340 may be a camera - using visible light or other wavelengths of light - configured to obtain an image such as an image of a user’s face. In further embodiments, biometric module 1300 can also include a sensor 1340 that is a fingerprint or palm scanner utilized to obtain fingerprint or palm biometric information. In still further embodiments, the sensor 1340 may be an audio sensor utilized to obtain voice information. Other sensors configured to obtain biometric information are possible.

[0190] With further reference to FIG. 14, a schematic representation a payment or POS terminal 120 and a biometric module 130 is shown in accordance with still further aspects of the present disclosure. The POS terminal 120 can be any of the terminals described or otherwise envisioned herein. Similarly, the biometric module 130 can be any of the biometric modules described or otherwise envisioned herein.PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO

[0191] More specifically, according to an embodiment, the terminal 120 comprises one or more of hardware components (“hw”), an operating system (OS), a biometric applet (sometimes referred to as a biometric SDK), a payment application, and / or a live preview application. The terminal 120 can be in communication with other components of a transaction system 100, 200, 300, such as through a communications network 140.

[0192] According to further embodiments, the biometric module 130 can comprise a user space with an encryption key management component, a biometric module services module, an estate management module or agent, and a biometric kernel. According to some embodiments, the biometric module 130 comprises a platform space with an operating system and drivers, and firmware. The platform space can further comprise physical components such as a face camera, palm camera, LEDs, Bluetooth, SOC, memory, 4G or other wireless communication module, USB, and power / batery source. The biometric module 130 can be a component of the payment terminal 120, or is otherwise in wired and / or wireless communication with the payment terminal 120.

[0193] Turning now to FIG. 15, a schematic representation of a remote, cloud-based biometric orchestration system 1500 is illustrated in accordance with aspects of the present disclosure. As described herein, the biometric orchestration system 150, 221, 320 may be embodied in accordance with the description of the biometric orchestration system 1500. That is, the biometric orchestration system 1500 may be any of the platforms 150, 221, 320 described or otherwise envisioned herein, and may comprise any of the components described or otherwise envisioned herein.

[0194] According to an embodiment, biometric orchestration system 1500 comprises a processor 1520 capable of executing instructions stored in memory 1530 or storage 1560 or otherwise processing data to, for example, perform one or more steps of the verification / authentication methods described herein. Processor 1520 may be formed of one or multiple modules. Processor 1520 may take any suitable form, including but not limited to a microprocessor, microcontroller, multiple microcontrollers, circuitry, field programmable gate array (FPGA), application-specific integrated circuit (ASIC), a single processor, or plural processors.

[0195] Memory 1530 can take any suitable form, including a non-volatile memory and / or RAM. The memory 1530 may include various memories such as, for example LI, L2, or L3 cache or system memory. As such, the memory 1530 may include static random access memory (SRAM), dynamic RAM (DRAM), flash memory, read only memory (ROM), or other similarPATENT APPLICATIONAtorney Docket No.: VFI-4049-WO memory devices. The memory can store, among other things, an operating system. The RAM is used by the processor for the temporary storage of data. According to an embodiment, an operating system may contain code which, when executed by the processor, controls operation of one or more components of biometric orchestration system 1500. It will be apparent that, in embodiments where the processor implements one or more of the functions described herein in hardware, the software described as corresponding to such functionality in other embodiments may be omitted.

[0196] Communication interface 1550 may include one or more devices for enabling communication with other hardware devices. For example, communication interface 1550 may include a network interface card (NIC) configured to communicate according to the Ethernet protocol. Additionally, communication interface 1550 may implement a TCP / IP stack for communication according to the TCP / IP protocols. Various alternative or additional hardware or configurations for communication interface 1550 will be apparent.

[0197] Storage 1560 may include one or more machine-readable storage media such as readonly memory (ROM), random-access memory (RAM), magnetic disk storage media, optical storage media, flash-memory devices, or similar storage media. In various embodiments, storage 1560 may store instructions for execution by processor 1520 or data upon which processor 520 may operate. For example, storage 1560 may store an operating system 1561 for controlling various operations of biometric orchestration system 1500.

[0198] It will be apparent that various information described as stored in storage 1560 may be additionally or alternatively stored in memory 1530. In this respect, memory 1530 may also be considered to constitute a storage device and storage 1560 may be considered a memory. Various other arrangements will be apparent. Further, memory 1530 and storage 1560 may both be considered to be non-transitory machine-readable media. As used herein, the term non- transitory will be understood to exclude transitory signals but to include all forms of storage, including both volatile and non-volatile memories.

[0199] While biometric orchestration system 1500 is shown as including one of each described component, the various components may be duplicated in various embodiments. For example, processor 1520 may include multiple microprocessors that are configured to independently execute the methods described herein or are configured to perform steps or subroutines of the methods described herein such that the multiple processors cooperate to achieve the functionality described herein. Further, where one or more components of biometric orchestration system 1500 is implemented in a cloud computing system, the variousPATENT APPLICATIONAtorney Docket No.: VFI-4049-WO hardware components may belong to separate physical systems. For example, processor 1520 may include a first processor in a first server and a second processor in a second server. Many other variations and configurations are possible.

[0200] According to an embodiment, storage 1560 of biometric orchestration system 1500 may store one or more algorithms, modules, and / or instructions to carry out one or more functions or steps of the methods described or otherwise envisioned herein, such as the biometric check-in, biometric loyalty access, biometric age verification, biometric transaction, and / or biometric payment methods described herein. For example, storage 1560 may comprise, among other instructions or data, user information 1562. The user information may be, for example, information about registered uses of the biometric orchestration system 1500. The information may be biometric information about each of the users, and may comprise other identification such as name, age, date of birth, address, and / or other information. The identification information is thus associated in storage with the biometric information.

[0201] Also described herein are certain user interface application flows which improve upon typical consumer interactions, including simplifying and expediting check-out processes, among other benefits. For example, as described herein, the biometric systems and payment terminals comprising or operatively connected to a biometric module as described above may include an application and / or software kit configured to provide a unique user interface according to a biometric user interface application flow. In particular embodiments, the application and / or software kit may provide such user interfaces via a POS terminal or POI device.

[0202] More specifically, with reference to FIG. 16, the application and / or software kit can be configured to provide a user interface according to a first exemplary biometric user interface application flow. As shown, the biometric user interface application flow includes: in a step1.1.1, providing a biometric check-in screen or portal; in one or more steps 1.2.1 and 1.2.2, providing a biometric scanning interface and performing a biometric identification process; optionally, in one or more steps 1.2.3 to 1.2.6, providing biometric exception interfaces in the event of a failure to verify the user’s identity biometrically; in one or more steps 1.3.1 and1.3.2, providing a user interface tailored to the user’s identity based on information connected with the user’s biometric identification; in a step 1.4.1, providing a customer cart showing intended purchases by the user; in a step 1.5.1, providing a user interface enabling the user to complete the intended purchases; and in one or more steps 1.6.1 to 1.6.3, processing the payments and providing a user interface enabling confirmation of the purchases.PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO

[0203] More specifically, as shown in FIGS. 17A through 17N, the first user interface application flow is illustrated in connection with a point-of-interaction terminal configured with a biometric module.

[0204] In FIG. 17A, a biometric check-in screen or portal is illustrated in connection with the step 1.1.1, which enables a user to select a biometric identification option to initiate the transaction process.

[0205] In FIG. 17B, a biometric scanning interface is provided in connection with steps 1.2.1 and 1.2.2, which may include one or more indicators signifying that a biometric scan is being performed. In embodiments, the biometric scanning interface may provide feedback or instructions assisting the user in completing the biometric scan (e.g., a viewing frame surrounding a live camera feed from the biometric module, etc.). In particular embodiments, the one or more indicators, the feedback, and instructions may be visual, audible, tactile, haptic, and / or combinations thereof. As shown in FIG. 17C, the biometric scanning interface may also indicate when a biometric scan was completed and is being processed.

[0206] In FIGS. 17D through 17F, a biometric exception interface may be provided via the point-of-interaction terminal in connection with one or more steps 1.2.3 to 1.2.6, in the event of a failure to verify the user’s identity biometrically. For example, as shown in FIG. 17D, the biometric exception interface can include a timeout exception wherein an adequate biometric scan is not captured within a predetermined period of time. In such embodiments, the interface may include recommendations for improving the quality of the biometric scan (e.g., by removing a hat or sunglasses, etc.).

[0207] In FIG. 17E, the biometric exception interface can include a “no match” exception, indicating that no biometric match was found for the user. In such embodiments, the interface may include information enabling the user to create and register a biometric profile.

[0208] In FIG. 17F, the biometric exception interface can include an “invalid face” exception, indicating that a biometric scan was completed but that the scan does not meet one or more biometric parameters set by the biometric module. In such embodiments, the interface may include the reason for the error and recommendations for improving the quality of the biometric scan (e.g., by removing a hat or sunglasses, etc.).

[0209] In FIG. 17G, the biometric exception interface can also include a “PIN requirement” exception, indicating that further verification of the user’s identity is required. In some embodiments, the additional verification of the user’s identity may be completed by inputing a PIN code. However, other verification methods are contemplated.PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO

[0210] Once the user’s identity is verified biometrically in accordance with the present disclosure, a merchant-specific user interface can be provided that is tailored to the user’s identity based on information connected with the user’s biometric identification. For example, as shown in FIG. 17H, the interface can display the purchase history connected with the biometrically verified user, as well as provide options and / or recommendations based thereon. Then, as shown in FIG. 171, the interface can include a merchant-specific selections that are not tailored to the user’s identification.

[0211] As shown in FIG. 17 J, once the user makes one or more selections via the user interface, those selections may be added to the user’s “cart.” It should be appreciated that the user’s cart may itemize all of the user’s selections and generate a summary (e.g., subtotal, tax, fees, total, etc.) for the transaction.

[0212] As shown in FIG. 17K, once the user is ready to complete the transaction, the user interface may provide a checkout interface including options for providing payment. In embodiments, the payment options can include one or more biometric payment options, and / or can automatically pull one or more card-on-file (COF) options based on the user’s biometric identification. In some embodiments, the payment options can include an option to pay with a conventional physical payment card.

[0213] As shown in FIG. 17L, interface can provide an indication that the selection payment option for the transaction is being processed. Then, as shown in FIG. 17M, the interface can provide an indication that the payment was successful (or not successful). Finally, as shown in FIG. 17N, the interface can provide receipt information, such as a digital receipt and / or a scannable code (e.g., a bar code or QR code) for accessing a digital version of the receipt.

[0214] Turning now to FIG. 18, another embodiment of a user interface provided in accordance with a second exemplary biometric user interface application flow is illustrated. As shown, the biometric user interface application flow includes: in a step 2.1.1, providing a biometric check-in screen or portal; in one or more steps 2.2.1 and 2.2.2, providing a biometric scanning interface and performing a biometric identification process; optionally, in one or more steps 2.2.3 to 2.2.6, providing biometric exception interfaces in the event of a failure to verify the user’s identity biometrically; in a step 2.3.1, providing a user interface tailored to the user’s identity based on information connected with the user’s biometric identification; in a step 2.4.1, providing a user interface enabling the user to complete an intended transaction; and in one or more steps 2.5.1 to 2.5.3, processing the payments and providing a user interface enabling confirmation of the purchases.PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO

[0215] More specifically, as shown in FIGS. 19A through 19L, the second user interface application flow is illustrated in connection with a point-of-interaction terminal configured with a biometric module.

[0216] In FIG. 19A, a biometric check-in screen or portal is illustrated in connection with the step 2.1.1, which enables a user to select a biometric identification option to initiate the transaction process.

[0217] In FIGS. 19B and 19C, a biometric scanning interface is provided in connection with steps 2.2.1 and 2.2.2, which may include one or more indicators signifying that a biometric scan is being performed. In embodiments, the biometric scanning interface may provide feedback or instructions assisting the user in completing the biometric scan (e.g., a viewing frame surrounding a live camera feed from the biometric module, etc.). In particular embodiments, the one or more indicators, the feedback, and instructions may be visual, audible, tactile, haptic, and / or combinations thereof. As shown, the biometric scanning interface may also indicate the progress / status of the biometric scan and whether the biometric scan was completed and is being processed.

[0218] In FIGS. 19D through 19G, a biometric exception interface may be provided via the point-of-interaction terminal in connection with one or more steps 2.2.3 to 2.2.6, in the event of a failure to verify the user’s identity biometrically. For example, as shown in FIG. 19D, the biometric exception interface can include a timeout exception wherein an adequate biometric scan is not captured within a predetermined period of time. In such embodiments, the interface may include recommendations for improving the quality of the biometric scan (e.g., by removing a hat or sunglasses, etc.).

[0219] In FIG. 19E, the biometric exception interface can include a “no match” exception, indicating that no biometric match was found for the user. In such embodiments, the interface may include information enabling the user to create and register a biometric profile.

[0220] In FIG. 19F, the biometric exception interface can include an “invalid face” exception, indicating that a biometric scan was completed but that the scan does not meet one or more biometric parameters set by the biometric module. In such embodiments, the interface may include the reason for the error and recommendations for improving the quality of the biometric scan (e.g., by removing a hat or sunglasses, etc.).

[0221] In FIG. 19G, the biometric exception interface can also include a “PIN requirement” exception, indicating that further verification of the user’s identity is required. In somePATENT APPLICATIONAtorney Docket No.: VFI-4049-WO embodiments, the additional verification of the user’s identity may be completed by inputing a PIN code. However, other verification methods are contemplated.

[0222] Once the user’s identity is verified biometrically in accordance with the present disclosure, a merchant-specific user interface can be provided that is tailored to the user’s identity based on information connected with the user’s biometric identification. For example, as shown in FIG. 19H, the interface can display rewards or loyalty -program information connected with the biometrically verified user, as well as provide options and / or recommendations based thereon. In particular embodiments, the interface can enable the user to select and / or otherwise apply one or more rewards, points, or loyalty-program benefits to a transaction based on the biometric verification.

[0223] As shown in FIG. 191, once the user is ready to complete the transaction, the user interface may provide a checkout interface including options for providing payment. In embodiments, the payment options can include one or more biometric payment options, and / or can automatically pull one or more card-on-file (COF) options based on the user’s biometric identification. In some embodiments, the payment options can include an option to pay with a conventional physical payment card.

[0224] As shown in FIGS. 19 J, interface can provide an indication that the selection payment option for the transaction is being processed. Then, as shown in FIG. 19K, the interface can provide an indication that the payment was successful (or not successful). Finally, as shown in FIG. 19L, the interface can provide receipt information, such as a digital receipt and / or a scannable code (e.g., a bar code or QR code) for accessing a digital version of the receipt.

[0225] As described herein, certain embodiments of a user interface application flow are described, which may be provided via a point-of-interaction device connected to a biometric module of the present disclosure. It should be appreciated that, in accordance with these embodiments, the point-of-interaction device can be configured to receive user input, such as menu selections, payment selections and / or the like, and to update the interface based thereon.

[0226] Additionally, while certain user interface application flows, similar methods of operating the POI device and / or POS terminal will be apparent based on the present disclosure, including but not limited to methods of operating the POI device and / or POS terminal for verifying an enrolled user’s age, storing and retrieving loyalty or other historical or relevant information about an enrolled user, providing payment information about or for the user, and / or other functions.PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO

[0227] Thus, in accordance with these and other aspects described herein, methods of authenticating a user for a biometric transaction are described. With reference to FIG. 20, an exemplary method 2000 is illustrated according to some of these aspects.

[0228] At step 2005 of the method 2000, a biometric transaction system 100, 300 is provided.

[0229] At step 2010 of the method 2000, the payment or POS terminal 120, 360, 380 receives a request for a biometric transaction. As mentioned above, a consumer would typically need to present a payment card to the merchant or to the payment or POS terminal 120, 360, 380 to initiate the financial transaction. However, according to the embodiments of the present disclosure, the user is able to provide biometric information and thus a payment card is not required to be physically present. In further embodiments, the biometric transaction system 100, 300 may be used in lieu of a loyalty program card. That is, the biometric information (described below) may advantageously be used separately and / or in addition to the financial transaction request in order to access merchant-specific benefits, rewards, personalized recommendations, stored payment methods, and / or the like.

[0230] According to an embodiment, the request for a contactless transaction is initiated by the user requesting to purchase the goods or services. This can be accomplished, for example, by the merchant providing information about the goods or services being purchased by the purchaser or user, and / or the cost of those goods or services, to the payment or POS terminal 120, 360, 380. The terminal 120, 360, 380 will then initiate a verification protocol to verify the identity of the purchaser or user, which will allow the merchant to ultimately process the transaction via a payment processor.

[0231] At step 2015 of the method 2000, biometric module 130, 350 obtains biometric information of the user. The biometric module 130, 350 can be triggered or initiated to obtain biometric information of the user by a request or command from the payment or POS terminal 120, 360. For example, the terminal may receive or initiate a request for a contactless transaction, typically in response to a transaction request from a user, and thus may communicate that request for a contactless transaction to the biometric module 130, 350. In response to the command or request from the terminal, the biometric module 130, 350 initiates a preprogrammed or predetermined protocol to obtain biometric information from a user. Accordingly, the user typically must be in proximity to the biometric device or module 130, 350 in order to provide the biometric information. Thus, the biometric module 130, 350 obtainsPATENT APPLICATIONAtorney Docket No.: VFI-4049-WO the biometric information from the user in response to initiation of the preprogrammed or predetermined protocol.

[0232] At step 2020 of the method 2000, the biometric module 130, 350 may transmit information to a remote biometric verification service 150 (e.g., biometric orchestration system 320) for the purpose of verifying the user. The information is transaction information that comprises at least the obtained biometric information. According to an embodiment, the transaction information further comprises merchant information such as an identity of the merchant or any other relevant or necessary merchant information. According to another embodiment, the transaction information further comprises information about the transaction itself, such as an amount of the transaction, the goods or services intended to be purchased, date and time information, and / or any other relevant or necessary information. The transaction information can be encrypted or otherwise secured or packaged by the biometric module before it is communicated to the remote biometric verification service 250.

[0233] At step 2025 of the method 2000, the remote biometric verification service 150 identifies a biometric identification associated with the obtained biometric information. For example, as described above, the biometric verification service 320 interoperate with a biometric verification system 330 to process the obtained biometric information and search through the database of biometric information associated with registered users to identify a match to the obtained biometric information.

[0234] The search of the database of biometric information for registered users can have several possible outcomes. According to one possible outcome, no match is made between the obtained biometric information and any of the biometric information for registered users of the biometric verification service 150, 320, 330. For example, the user at the merchant requesting a contactless transaction may not be a registered user of the biometric verification service. As another example, the biometric information obtained by the biometric module 130, 350 may be of insufficient quality to allow for a match. According to another possible outcome, the search tentatively identifies a user, but the tentative match may not be of sufficient quality or above a predetermined threshold to definitively identify the user. Thus, the system 320, 330 may return information that no match was found, or may issue a request for new or updated biometric information by the biometric module 130, 350. The method may then return to step 2015 to obtain new or updated biometric information.

[0235] According to yet another possible outcome, the search may find a match of sufficient quality or above a predetermined threshold thus definitively identifying the user at the paymentPATENT APPLICATIONAtorney Docket No.: VFI-4049-WO terminal as being a registered user of the biometric verification service. According to an embodiment, the biometric identification comprises a payment card token as described above.

[0236] Thus, according to an embodiment, once an identification is made, the biometric verification service 150, 320, 330 can communicate relevant or necessary information to the biometric module 130, 350. The relevant or necessary information can comprise, for example, the identification of the user and the network token, among other possible information.

[0237] The biometric orchestration system 320 can package the information in any way sufficient to communicate the information, including with any encryption. Thus, for example, the biometric verification service 320 can encrypt the information communicated to the biometric module 130, 350, and the biometric module 130, 350 or the payment terminal 120, 360 will comprise the encryption keys necessary to decrypt the information.

[0238] At step 2030 of the method 2000, the biometric module 130, 350 receives the information communicated from the biometric verification service 150, 320, via the communications network 140. According to an embodiment in which the search at the biometric verification service found a match of sufficient quality or above a predetermined threshold thus definitively identifying the user at the payment terminal as being a registered user of the biometric verification service, the communicated information received by the biometric device or module comprises the identified network token. Other communicated information is possible.

[0239] At this stage, the identified network token may be utilized by the merchant’s payment terminal in order to access a merchant-specific loyalty network, including merchantspecific purchase histories, rewards, benefits, services, and / or the like. In embodiments, the customer information stored by the merchant in the merchant’s loyalty network may be used to authenticate and / or personalize customer experience, including by providing recommendations or personalized messaging, simplifying the checkout experience, and reducing wait times. In particular embodiments, the merchant-specific loyalty network can include stored payment methods authorized by the user for purchases at the trusted merchant, which can be used subsequently to perform payment transactions.

[0240] At step 2035 of the method 2000, a unique identifier (e.g., a transaction nonce) can be generated as described above for the particular transaction. According to an embodiment, the payment or POS terminal 120, 360 generates the transaction nonce and communicates it to the biometric module 130, 350. Alternatively, the biometric module 130, 350 can generate the transaction nonce and communicate it to the payment or POS terminal 120, 360.PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO

[0241] At step 2040 of the method 2000, the biometric transaction system 100, 200, 300 generates a transaction payload comprising at least the identified network token and the random transaction nonce. In embodiments, the transaction payload comprises other information such as information about the merchant, information about the transaction such as the amount of the transaction, and / or any other relevant or necessary information. According to an embodiment, the biometric module 130, 350 generates the contactless payload. Alternatively, the payment or POS terminal 120, 360 may generate the transaction payload.

[0242] At step 2045 of the method 2000, the biometric transaction system 100, 200, 300 communicates the generated transaction payload to a payment processor 160. The payment processor 160 can be any payment processor that the merchant engages for payment processing, as described above. According to an embodiment, the biometric transaction system 100, 200, 300 may communicate the generated transaction payload via a payment gateway that facilitates online transactions and serves to ensures that user funds are available and authorize the payment transfer. The payment gateway can be any of the known or developed payment gateways used for payments. The transaction payload can be encrypted or otherwise secured or packaged by the biometric transaction system 100, 200, 300 before it is communicated to the payment processor 160.

[0243] At step 2050 of the method 2000, the biometric transaction system 100, 200, 300 may receive information back from the payment processor 160 regarding the transaction. According to one embodiment, the information received by the biometric transaction system 100, 200, 300 is a denial of the transaction. According to another embodiment, the information received by the contactless transaction system 100, 200, 300 is approval of the transaction.

[0244] At step 2055 of the method 2000, the biometric transaction is completed. According to an embodiment in which the payment processor 160 denies the transaction, the biometric transaction is denied and no financial transfer is completed. According to an embodiment in which the payment processor 160 approves the transaction, a financial transfer is completed.

[0245] It should be appreciated that all combinations of the foregoing concepts and additional concepts discussed in greater detail below (provided such concepts are not mutually inconsistent) are contemplated as being part of the inventive subject matter disclosed herein. In particular, all combinations of claimed subject matter appearing at the end of this disclosure are contemplated as being part of the inventive subject matter disclosed herein. It should also be appreciated that terminology explicitly employed herein that also may appear in anyPATENT APPLICATIONAtorney Docket No.: VFI-4049-WO disclosure incorporated by reference should be accorded a meaning most consistent with the particular concepts disclosed herein.

[0246] All definitions, as defined and used herein, should be understood to control over dictionary definitions, definitions in documents incorporated by reference, and / or ordinary meanings of the defined terms.

[0247] The terms “individual”, “user”, and “consumer” are used herein synonymously and interchangeably unless otherwise specified explicitly or implicitly by the context of its use.

[0248] The indefinite articles “a” and “an,” as used herein in the specification and in the claims, unless clearly indicated to the contrary, should be understood to mean “at least one.”

[0249] The phrase “and / or,” as used herein in the specification and in the claims, should be understood to mean “either or both” of the elements so conjoined, i.e., elements that are conjunctively present in some cases and disjunctively present in other cases. Multiple elements listed with “and / or” should be construed in the same fashion, i.e., “one or more” of the elements so conjoined. Other elements may optionally be present other than the elements specifically identified by the “and / or” clause, whether related or unrelated to those elements specifically identified.

[0250] As used herein in the specification and in the claims, “or” should be understood to have the same meaning as “and / or” as defined above. For example, when separating items in a list, “or” or “and / or” shall be interpreted as being inclusive, i.e., the inclusion of at least one, but also including more than one, of a number or list of elements, and, optionally, additional unlisted items. Only terms clearly indicated to the contrary, such as “only one of’ or “exactly one of,” or, when used in the claims, “consisting of,” will refer to the inclusion of exactly one element of a number or list of elements. In general, the term “or” as used herein shall only be interpreted as indicating exclusive alternatives (i.e. “one or the other but not both”) when preceded by terms of exclusivity, such as “either,” “one of,” “only one of,” or “exactly one of.”

[0251] As used herein in the specification and in the claims, the phrase “at least one,” in reference to a list of one or more elements, should be understood to mean at least one element selected from any one or more of the elements in the list of elements, but not necessarily including at least one of each and every element specifically listed within the list of elements and not excluding any combinations of elements in the list of elements. This definition also allows that elements may optionally be present other than the elements specifically identified within the list of elements to which the phrase “at least one” refers, whether related or unrelated to those elements specifically identified.PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO

[0252] As used herein, although the terms first, second, third, etc. may be used herein to describe various elements or components, these elements or components should not be limited by these terms. These terms are only used to distinguish one element or component from another element or component. Thus, a first element or component discussed below could be termed a second element or component without departing from the teachings of the inventive concept.

[0253] Unless otherwise noted, when an element or component is said to be “connected to,” “coupled to,” or “adjacent to” another element or component, it will be understood that the element or component can be directly connected or coupled to the other element or component, or intervening elements or components may be present. That is, these and similar terms encompass cases where one or more intermediate elements or components may be employed to connect two elements or components. However, when an element or component is said to be “directly connected” to another element or component, this encompasses only cases where the two elements or components are connected to each other without any intermediate or intervening elements or components.

[0254] In the claims, as well as in the specification above, all transitional phrases such as “comprising,” “including,” “carrying,” “having,” “containing,” “involving,” “holding,” “composed of,” and the like are to be understood to be open-ended, i.e., to mean including but not limited to. Only the transitional phrases “consisting of’ and “consisting essentially of’ shall be closed or semi-closed transitional phrases, respectively.

[0255] It should also be understood that, unless clearly indicated to the contrary, in any methods claimed herein that include more than one step or act, the order of the steps or acts of the method is not necessarily limited to the order in which the steps or acts of the method are recited.

[0256] The above-described examples of the described subject matter can be implemented in any of numerous ways. For example, some aspects can be implemented using hardware, software or a combination thereof. When any aspect is implemented at least in part in software, the software code can be executed on any suitable processor or collection of processors, whether provided in a single device or computer or distributed among multiple device s / computers .

[0257] The present disclosure can be implemented as a system, a method, and / or a computer program product at any possible technical detail level of integration. The computer program product can include a computer readable storage medium (or media) having computer readablePATENT APPLICATIONAtorney Docket No.: VFI-4049-WO program instructions thereon for causing a processor to carry out aspects of the present disclosure.

[0258] The computer readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device. The computer readable storage medium can be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of the computer readable storage medium comprises the following: a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanically encoded device such as punch-cards or raised structures in a groove having instructions recorded thereon, and any suitable combination of the foregoing. A computer readable storage medium, as used herein, is not to be construed as being transitory signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission media (e.g., light pulses passing through a fiber-optic cable), or electrical signals transmitted through a wire.

[0259] Computer readable program instructions described herein can be downloaded to respective computing / processing devices from a computer readable storage medium or to an external computer or external storage device via a network, for example, the Internet, a local area network, a wide area network and / or a wireless network. The network can comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers and / or edge servers. A network adapter card or network interface in each computing / processing device receives computer readable program instructions from the network and forwards the computer readable program instructions for storage in a computer readable storage medium within the respective computing / processing device.

[0260] Computer readable program instructions for carrying out operations of the present disclosure can be assembler instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine dependent instructions, microcode, firmware instructions, statesetting data, configuration data for integrated circuitry, or either source code or object code written in any combination of one or more programming languages, comprising an object oriented programming language such as Smalltalk, C++, or the like, and proceduralPATENT APPLICATIONAtorney Docket No.: VFI-4049-WO programming languages, such as the “C” programming language or similar programming languages. The computer readable program instructions can execute entirely on the user’s computer, partly on the user’ s computer, as a stand-alone software package, partly on the user’s computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, comprising a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider). In some examples, electronic circuitry comprising, for example, programmable logic circuitry, field-programmable gate arrays (FPGA), or programmable logic arrays (PLA) can execute the computer readable program instructions by utilizing state information of the computer readable program instructions to personalize the electronic circuitry, in order to perform aspects of the present disclosure.

[0261] Aspects of the present disclosure are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to examples of the disclosure. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer readable program instructions.

[0262] The computer readable program instructions can be provided to a processor of a, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. These computer readable program instructions can also be stored in a computer readable storage medium that can direct a computer, a programmable data processing apparatus, and / or other devices to function in a particular manner, such that the computer readable storage medium having instructions stored therein comprises an article of manufacture comprising instructions which implement aspects of the function / act specified in the flowchart and / or block diagram or blocks.

[0263] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process, such that the instructions which execute on thePATENT APPLICATIONAtorney Docket No.: VFI-4049-WO computer, other programmable apparatus, or other device implement the functions / acts specified in the flowchart and / or block diagram block or blocks.

[0264] The flowchart and block diagrams in the Figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various examples of the present disclosure. In this regard, each block in the flowchart or block diagrams can represent a module, segment, or portion of instructions, which comprises one or more executable instructions for implementing the specified logical function(s). In some alternative implementations, the functions noted in the blocks can occur out of the order noted in the Figures. For example, two blocks shown in succession can, in fact, be executed substantially concurrently, or the blocks can sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and / or flowchart illustration, and combinations of blocks in the block diagrams and / or flowchart illustration, can be implemented by special purpose hardware-based systems that perform the specified functions or acts or carry out combinations of special purpose hardware and computer instructions.

[0265] Other implementations are within the scope of the following claims and other claims to which the applicant can be entitled.

[0266] While several inventive embodiments have been described and illustrated herein, those of ordinary skill in the art will readily envision a variety of other means and / or structures for performing the function and / or obtaining the results and / or one or more of the advantages described herein, and each of such variations and / or modifications is deemed to be within the scope of the inventive embodiments described herein. More generally, those skilled in the art will readily appreciate that all parameters, dimensions, materials, and configurations described herein are meant to be exemplary and that the actual parameters, dimensions, materials, and / or configurations will depend upon the specific application or applications for which the inventive teachings is / are used. Those skilled in the art will recognize, or be able to ascertain using no more than routine experimentation, many equivalents to the specific inventive embodiments described herein. It is, therefore, to be understood that the foregoing embodiments are presented by way of example only and that, within the scope of the appended claims and equivalents thereto, inventive embodiments may be practiced otherwise than as specifically described and claimed. Inventive embodiments of the present disclosure are directed to each individual feature, system, article, material, kit, and / or method described herein. In addition, any combination of two or more such features, systems, articles, materials, kits, and / orPATENT APPLICATIONAttorney Docket No.: VFI-4049-WO methods, if such features, systems, articles, materials, kits, and / or methods are not mutually inconsistent, is included within the inventive scope of the present disclosure.

Claims

PATENT APPLICATIONAtorney Docket No.: VFI-4049-WOClaimsWHAT IS CLAIMED IS:

1. A method of orchestrating biometric authentication of an individual, the method comprising: receiving, at a biometric orchestration system comprising one or more processors configured to perform at least part of a biometric identification protocol, biometric information of the individual from a biometric device; determining, at the biometric orchestration system, biometric routing information for the biometric information of the individual, wherein the biometric routing information indicates a target biometric identification system to use to generate a biometric identification for the individual; communicating, to the target biometric identification system, at least the biometric information of the individual obtained by the biometric device, wherein the target biometric identification system is configured to determine whether a match for the biometric information of the individual exists within a target biometric vault; receiving, from the target biometric identification system, a biometric identification for the individual generated by the target biometric identification system; generating, at the biometric orchestration system, a biometric identification data packet based on the biometric identification received for the individual; and communicating, from the biometric orchestration system and to the biometric device, the biometric identification data packet.

2. The method of claim 1, wherein the biometric information of the individual is received from the biometric device as part of a secured information package, the secured information package further comprising a first biometric data structure encoding a first set of one or more biometric parameters from the biometric information of the individual, the first biometric data structure having a first predetermined format.

3. The method of claim 2, wherein the first predetermined format is defined by the biometric orchestration system.PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO4. The method of claim 2, wherein the biometric orchestration system comprises a biometric registry storing a plurality of encoded biometric data structures and corresponding biometric routing information for a plurality of individuals, wherein each encoded biometric data structure of the plurality of encoded biometric data structures also has the first predetermined format, and wherein the biometric routing information for the individual is determined by: searching the plurality of encoded biometric data structures stored in the biometric registry and returning the biometric routing information corresponding to the encoded biometric data structure matching the first biometric data structure.

5. The method of claim 2, wherein the first biometric data structure further encodes a consumer platform identifier and / or a biometric vault identifier in accordance with the first predetermined format.

6. The method of claim 5, wherein the biometric routing information for the individual is determined by extracting the consumer platform identifier and / or the biometric vault identifier from the first biometric data structure.

7. The method of claim 2, wherein the secured information package further comprises a second biometric data structure encoding a second set of one or more biometric parameters from the biometric information of the individual, the second biometric data structure having a second predetermined format that is different than the first predetermined format.

8. The method of claim 7, wherein the biometric information of the individual is communicated from the biometric orchestration system to the target biometric identification system in the form of the second biometric data structure, the target biometric identification system being configured to determine whether a match for the biometric information of the individual exists within the target biometric vault based on the second set of one or more biometric parameters encoded into the second biometric data structure.PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO9. The method of claim 1, wherein the biometric information of the individual communicated to the target biometric identification system includes raw biometric information.

10. The method of claim 1, further comprising: receiving, from the target biometric identification system, non-biometric information associated with the individual in response to returning a positive biometric identification indicating that a match for the biometric information of the individual was found; wherein the non-biometric information includes payment card-related information, loyalty- and / or rewards-related information, and / or biographical information of the individual; and wherein the biometric identification data packet generated for the individual includes the positive biometric identification and the non-biometric information.

11. The method of claim 1, further comprising: retrieving, via the biometric orchestration system and from a digital wallet or other service provider, non-biometric information associated with the individual in response to receiving a positive biometric identification of the individual indicating that a match for the biometric information of the individual was found; wherein the non-biometric information includes payment card-related information, loyalty- and / or rewards-related information, and / or biographical information of the individual; and wherein the biometric identification data packet generated for the individual includes the positive biometric identification and the non-biometric information.

12. The method of claim 1, wherein the biometric orchestration system is located remotely from the biometric device, the biometric information of the individual is received from the biometric device over one or more communications networks, and the biometric identification data packet is communicated to the biometric device over the one or more communications networks.PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO13. The method of claim 10, wherein the biometric orchestration system is located remotely from the target biometric identification system, the biometric information of the individual is communicated to the target biometric identification system over one or more communications networks, and the biometric identification for the individual is received by the biometric orchestration system over the one or more communications networks.

14. The method of claim 1, wherein the biometric identification for the individual is a tentative or a negative biometric identification if a match for the biometric information of the individual is not found within a predetermined confidence threshold, wherein the biometric identification data packet generated based on the tentative or the negative biometric identification comprises a request for new or updated biometric information.

15. The method of claim 1, wherein the biometric information of the individual comprises a fingerprint, palm print, palm vein geometry, retina or iris scan, vein pattern, facial geometry, voice pattern, and / or speech data.

16. A biometric orchestration system configured to be in communication with a plurality of biometric devices, the biometric orchestration system comprising: a communication interface configured to enable communication with the plurality of biometric devices over one or more communications networks; one or more processors; and a non-transitory computer-readable storage medium storing instructions that, when executed by the one or more processors, causes the biometric orchestration system to perform a biometric identification protocol including the following operations: receive biometric information of an individual from a first biometric device; determine biometric routing information for the biometric information of the individual, wherein the biometric routing information indicates a target biometric identification system to use to generate a biometric identification for the individual; communicate, to the target biometric identification system, at least the biometric information of the individual, wherein the target biometric identification system is configured to determine whether a match for the biometric information of the individual exists within a target biometric vault;PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO receive, from the target biometric identification system, a biometric identification for the individual generated by the target biometric identification system; generate a biometric identification data packet based on the biometric identification received for the individual; and communicate, to the first biometric device, the biometric identification data packet.

17. The biometric orchestration system of claim 16, wherein the biometric information of the individual is received from the first biometric device as part of a secured information package, the secured information package further comprising a first biometric data structure encoding a first set of one or more biometric parameters from the biometric information of the individual, the first biometric data structure having a first predetermined format.

18. The biometric orchestration system of claim 17, wherein the first predetermined format is defined by the biometric orchestration system.

19. The biometric orchestration system of claim 17, further comprising: a biometric registry storing a plurality of encoded biometric data structures and corresponding biometric routing information for a plurality of individuals, wherein each encoded biometric data structure of the plurality of encoded biometric data structures also has the first predetermined format, and wherein the biometric routing information for the individual is determined by: searching the plurality of encoded biometric data structures stored in the biometric registry and returning the biometric routing information corresponding to the encoded biometric data structure matching the first biometric data structure.

20. The biometric orchestration system of claim 17, wherein the first biometric data structure further encodes a consumer platform identifier and / or a biometric vault identifier in accordance with the first predetermined format.

21. The biometric orchestration system of claim 20, wherein the biometric routing information for the individual is determined by extracting the consumer platform identifier and / or the biometric vault identifier from the first biometric data structure.PATENT APPLICATIONAtorney Docket No.: VFI-4049-WO22. The biometric orchestration system of claim 17, wherein the secured information package further comprises a second biometric data structure encoding a second set of one or more biometric parameters from the biometric information of the individual, the second biometric data structure having a second predetermined format that is different than the first predetermined format.

23. The biometric orchestration system of claim 22, wherein the biometric information of the individual is communicated from the biometric orchestration system to the target biometric identification system as the second biometric data structure, the target biometric identification system being configured to determine whether a match for the biometric information of the individual exists within the target biometric vault based on the second set of one or more biometric parameters encoded into the second biometric data structure.

24. The biometric orchestration system of claim 16, wherein the biometric identification protocol further includes the following operations: receive, from the target biometric identification system, non-biometric information associated with the individual in response to returning a positive biometric identification indicating that a match for the biometric information of the individual was found; wherein the non-biometric information includes payment card-related information, loyalty- and / or rewards-related information, and / or biographical information of the individual; and wherein the biometric identification data packet generated for the individual includes the positive biometric identification and the non-biometric information.

25. The biometric orchestration system of claim 16, wherein the biometric identification protocol further includes the following operations: retrieve, from a digital wallet or other service provider, non-biometric information associated with the individual in response to receiving a positive biometric identification of the individual indicating that a match for the biometric information of the individual was found; wherein the non-biometric information includes payment card-related information, loyalty- and / or rewards-related information, and / or biographical information of the individual; andPATENT APPLICATIONAtorney Docket No.: VFI-4049-WO wherein the biometric identification data packet generated for the individual includes the positive biometric identification and the non-biometric information.

Citation Information

Patent Citations

  • Differential processing of data streams based on protocols

    US11431595B1

  • Client-server security system and method

    US20070198849A1

  • Biometric payment

    US20190034934A1

  • Method and system for biometric payments

    US20220398595A1

Cited By

  • Transaction processing system, transaction processing device, and transaction processing method

    US20250307821A1