Biometric identification method

WO2026131585A1PCT designated stage Publication Date: 2026-06-25BANKS & ACQUIRERS INT HLDG SAS
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
BANKS & ACQUIRERS INT HLDG SAS
Filing Date
2025-12-15
Publication Date
2026-06-25

AI Technical Summary

Technical Problem

The existing biometric enrollment process for palm vein authentication is time-consuming and cumbersome, requiring users to register multiple biometric data points in-store, which can be improved for enhanced efficiency and security.

Method used

A progressive biometric enrollment method that records a first biometric data point during initial account creation on a mobile device and finalizes the enrollment with a secure terminal, allowing simultaneous acquisition of a second biometric data point during subsequent identification, using a combined sensor to enhance security and streamline the process.

Benefits of technology

Significantly reduces the time spent in-store for enrollment while maintaining high security by leveraging dual biometric authentication, enabling seamless transactions without additional manual data entry.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2025087008_25062026_PF_FP_ABST
    Figure EP2025087008_25062026_PF_FP_ABST
Patent Text Reader

Abstract

The present invention relates to a method for identifying an individual in a system (1), the method being characterized in that the method comprises implementing the steps of: (A) biometrically enrolling the individual, the biometric enrolment step comprising the recording of at least one personal datum, and of a first reference biometric datum acquired from a first biometric trait of the individual; (B) identifying the individual by comparing a first candidate biometric datum acquired from the first biometric trait of the individual with a plurality of first account reference biometric data, the identification step comprising the simultaneous acquisition of the first candidate biometric datum and of a second candidate biometric datum acquired from a second biometric trait of the individual, the second biometric trait being different from the first biometric trait; (C) recording the second candidate biometric datum as a second reference biometric datum, so as to complete the biometric enrolment of the individual.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Description

[0002] Title of the invention: Biometric identification method.

[0003] GENERAL TECHNICAL FIELD

[0004] The present invention relates to the field of authentication / identification. In particular, it concerns a method for the biometric identification of an individual, having an enrollment component, especially for the implementation of a transaction.

[0005] STATE OF THE ART

[0006] Traditionally, merchants have an electronic payment terminal (POS) on which payment can be made using a bank card, possibly after entering a PIN code.

[0007] Recently, fully biometric POS terminals have been proposed on which there is no longer any need to present a bank card: the user is identified by presenting their biometric feature directly on the POS terminal (equipped with a suitable sensor), and a dematerialized (tokenized) card is associated with their identity, which is used for payment.

[0008] To ensure maximum security, the use of palm venous biometry, i.e., mapping the vascular patterns of the palm of the hand, was specifically chosen. The principle is as follows:

[0009] 1. Enrollment: Customers register their palm veins and link them to their in-store payment methods.

[0010] 2. Acquisition: At checkout, customers place their hand over a sensor integrated into the payment terminal. This sensor uses near-infrared light to capture the unique vein patterns under the skin. 3. Verification: The captured vein pattern (candidate biometric data) is compared to reference biometric data associated with each already enrolled user.

[0011] 4. Payment processing: In the event of a successful match, the payment is processed using the linked card information.

[0012] Generally, biometric authentication uses several biometric methods, referred to as "modalities," to increase security and, more importantly, to still allow the user to pay in case of technical difficulties with a particular biometric. Modalities can be ranked according to their security level.

[0013] Thus, vein biometrics is typically the first-order biometric, and a second-order biometric is generally "visual" palm biometrics based simply on the shape of the palm and the lines of the hand, i.e., without the vein network, similarly to facial recognition. The term "palmar print" refers to the image of the palm under visible light, and "vein print" refers to the vein pattern of the palm under infrared light.

[0014] Indeed, it is possible in a single acquisition of the palm of the hand to obtain the palmar impression and the venous impression by simply increasing the width of the spectrum.

[0015] And if the system fails to identify the user based on their vein pattern for any reason, it attempts to do so based on the palm print so as not to block the payment.

[0016] This method is entirely satisfactory, but the enrollment process could be improved, especially if there are multiple options. Currently, the user must spend time in-store creating an account, entering the associated information, and registering a reference biometric data point for each option.

[0017] The present invention improves the situation. PRESENTATION OF THE INVENTION

[0018] The present invention therefore relates, in a first aspect, to a method for identifying an individual in a system, characterized in that it comprises the implementation of steps of:

[0019] (A) Biometric enrollment of said individual, comprising a substep (a1) of recording at least one personal data, and a substep (a2) of recording a first biometric reference data acquired on a first biometric trait of the individual with a first sensor of a biometric terminal of said system or of a mobile terminal of the individual;

[0020] (B) Identification of said individual by comparing a first candidate biometric data acquired on said first biometric trait of the individual with the first sensor of the biometric terminal with a plurality of first reference biometric data of accounts, including the simultaneous acquisition of said first candidate biometric data and a second candidate biometric data acquired on a second biometric trait of the individual, different from the first biometric trait, with a second sensor of the biometric terminal;

[0021] (C) recording of the second candidate biometric data as the second reference biometric data, so as to complete the biometric enrollment of said individual.

[0022] According to advantageous and non-limiting characteristics:

[0023] The system further comprises at least one server including data storage means storing an account database, the server being connected to the biometric terminal via a network, said at least one personal data item, the first biometric reference data item, and the second biometric reference data item being transmitted to said server for recording in the account database. Enrollment (A) comprises:

[0024] (a) Creation of an account of said individual on a mobile terminal of said individual, comprising said substep (a1) of recording at least one personal data, and said substep (a2) of recording a first biometric reference data acquired on a first biometric trait of the individual with a first sensor of said mobile terminal.

[0025] (b) Transmission of a request to finalize said account containing a unique identifier of said account from the mobile terminal to a biometric terminal of said system;

[0026] (c) Authentication of said individual by comparing a first candidate biometric data acquired on said first biometric trait of the individual with a first sensor of the biometric terminal, with the first reference biometric data of the account associated with said unique identifier transmitted;

[0027] (d) Validation of said individual's account.

[0028] The said substep (a1) further includes the registration of a means of payment of said individual, said account being for biometric payment in said system by means of said means of payment; said biometric terminal being preferably an electronic payment terminal.

[0029] The recording (C) of the second candidate biometric data is implemented only if none of a plurality of second reference account biometric data coincides with the second candidate biometric data.

[0030] The identification (B) of said individual first includes comparing the second candidate biometric data with said plurality of second reference biometric data from accounts, then, if no second reference biometric data matches the second candidate biometric data, comparing the first candidate biometric data acquired on said first biometric trait of the individual with the first sensor of the biometric terminal with a plurality of first reference biometric data from accounts, and recording (C) the second candidate biometric data. Said first sensor and second sensor of the biometric terminal are identical.

[0031] The first biometric feature is a palm print and the second biometric feature is a vein print.

[0032] According to a second aspect, the invention proposes a method for the implementation of a transaction by an individual, on a biometric terminal of a system, said biometric terminal being an electronic payment terminal, characterized in that it comprises, following the implementation of the method according to the first aspect of identifying said individual in the system, the implementation of a step (D) of using by said biometric terminal the data of a means of payment of the individual associated with the individual's account for the implementation of the transaction.

[0033] According to a third aspect, the invention proposes a biometric terminal of a system comprising a first sensor and a second sensor, characterized in that it includes data processing means configured to, following the biometric enrollment of said individual with recording of at least one personal data and a first reference biometric data acquired on a first biometric trait of the individual:

[0034] - Identify said individual by comparing a first candidate biometric data acquired on said first biometric trait of the individual with the first sensor with a plurality of first reference biometric data of accounts, including the simultaneous acquisition of said first candidate biometric data and a second candidate biometric data acquired on a second biometric trait of the individual, different from the first biometric trait, with the second sensor;

[0035] - to record the second candidate biometric data as the second reference biometric data, so as to complete the biometric enrollment of said individual. According to a fourth and a fifth aspect, the invention relates to a computer program product comprising code instructions for executing a method according to one of the first aspects of identifying said individual in a system, or a method according to the second aspect for implementing a transaction by the individual, on a biometric terminal of the system; and a computer-readable storage means on which is recorded a computer program product comprising code instructions for executing a method according to the first aspect of identifying said individual in a system, or a method according to the second aspect for implementing a transaction by the individual, on a biometric terminal of the system.

[0036] PRESENTATION OF THE FIGURES

[0037] Other features and advantages of the present invention will become apparent from the following description of a preferred embodiment. This description will be given with reference to the accompanying drawings, in which:

[0038] [Fig. 1] Figure 1 is a diagram of a system for implementing the process according to the invention;

[0039] [Fig. 2a] Figure 2a is a flowchart illustrating the steps of a first embodiment of the process according to the invention;

[0040] [Fig. 2b] Figure 2b is a flowchart illustrating the steps of a second embodiment of the process according to the invention.

[0041] DETAILED DESCRIPTION

[0042] Architecture

[0043] The present invention relates to methods for: - biometric identification of an individual in a system 1 (which also constitutes a method for biometric enrollment of said individual), and

[0044] - for the implementation of a particular transaction on an electronic payment terminal (POS) of system 1 following the identification of the individual.

[0045] System 1 is thus typically the computer system of a store or, more generally, of a merchant, but the notion of transaction can be in a broad sense, beyond payment: for example, system 1 could be that of a secure building or of a company, and identification for the purpose of access control.

[0046] System 1 generally has a local network 30, i.e. a private network interconnecting the equipment that is part of this system 1, possibly through a VPN (the local network 30 may itself be composed of several subnets connected via a public wide area network 20 such as the internet - thanks to said VPN).

[0047] In all cases, the processes are preferentially implemented in an environment such as that shown in Figure 1.

[0048] Biometric enrollment refers to the construction of an individual's account (also called a profile) allowing for the subsequent identification of that user in the system in a purely biometric manner.

[0049] Thus, in practical terms, each user account in System 1 is defined by a unique identifier and is associated with at least one piece of personal data (surname, first name, address, etc.), at least one initial biometric reference data point for the user, and at least one second biometric reference data point for the user. As we will see, each account is also preferably associated with at least one piece of technical data defining a use of the account, in particular the data of a payment method for the user (in the case of identification for processing a transaction, for example, the data of a digital bank card) or access rights (in the case of identification for secure access), etc.The first biometric data is acquired on a first biometric trait of the individual (or simply "biometrics" of the individual) and the second biometric data is acquired on a second biometric trait of the individual, different from the first biometric trait.

[0050] The first and second biometric traits can be any known biometric trait used in authentication / identification, for example the face, a fingerprint, an iris, a palm print, a vein pattern, etc. The first biometric trait is preferably of rank 2 and the second biometric trait of rank 1.

[0051] Therefore, the preferred biometric feature is the palm print, and the preferred biometric feature is the vein pattern. Both are palm biometrics, but the palm print is a simple visual biometric (similar to facial biometrics), whereas the vein pattern is a biometric of the palm's venous network, i.e., under the skin, which is not visible in a simple palm image and requires a specific sensor. Furthermore, enrollment of this latter biometric is more complex.

[0052] System 1 includes at least one biometric terminal 10 which is typically an enrollment and, where appropriate, identification terminal, for example, a terminal at the store reception.

[0053] Alternatively, it could be a store electronic payment terminal (POS), i.e., at the checkout, or even a mobile terminal. In all cases, system 1 can include a large number of terminals 10, possibly of various types. It is also possible that several terminals 10 from the same system 1 may be involved in turn (for example, a first biometric terminal 10 for enrollment, a second biometric terminal 10 for initial identification, a third biometric terminal 10 for a second identification, etc.).

[0054] A biometric terminal 10 is defined as any terminal suitable for identification / authentication within system 1 and forming part of that system 1, i.e., a secure terminal and not an external terminal. It can be operated by a trusted person, such as an employee, to prevent fraud.

[0055] In the remainder of this description, we will refer to it as an enrollment terminal or an identification terminal, as appropriate, but again, either one or both of these roles can be assigned to any terminal 10 according to the invention. This terminal may be an existing terminal already adapted for traditional enrollment as described in the introduction to this application (in addition to the present method(s) that are the subject of the invention).

[0056] As will be seen, each terminal 10 includes at least one first sensor 14 for acquiring the first biometric data on the first biometric feature, and a second sensor 15 for acquiring the second biometric data on the second biometric feature (i.e., biometric sensors). Preferably, and as shown in Figure 1, the first and second sensors can in practice be combined, i.e., the same sensor 14, 15 can acquire both the first and second biometric data, either because this sensor "sees" both features simultaneously, or because it has an extended acquisition range.

[0057] Thus, preferably the sensor 14 is an optical sensor such as a camera, especially with an extended spectrum, i.e. in visible light + Infrared.

[0058] This is particularly suitable in the case where the first and second biometric traits are respectively the palm print and the vein print: a single sensor 14 can observe the palm of the hand (for example placed on the upper surface of the terminal 10 or just next to it, pointing upwards) and produce the two biometric data based on the two parts of the spectrum.

[0059] It should be understood, however, that the present process is not limited to any particular choice of biometrics or sensors, the latter even being, in practice, connected peripherals. For example, one can easily imagine that the first biometric feature is the palm print and the second biometric feature is the face, the two corresponding biometric data points being acquired respectively by two distinct sensors (but of the same type – simple cameras) and positioned differently (for example, on the upper surface of the terminal 10 to observe the palm, and on the ceiling to observe the face).

[0060] The terminal 10 may also conventionally include data processing means 11 (such as a processor), data storage means 12 (memory), an interface 13 for entering account data (for example a touch screen), wireless proximity communication means (for example NFC, see below), etc.

[0061] System 1 advantageously includes a central server 3 for managing user accounts (particularly those created via terminal 10). It can be connected via the local network 30 of system 1 to the terminal(s) 10 and to any non-biometric POS terminals (it is entirely possible that the system includes "ordinary" POS terminals that are not capable of implementing enrollment). Alternatively, it can be used as a terminal 10, for example, in a case where there is a single secure terminal dedicated to enrollment at the store's reception desk. Generally, the server 3 also includes data processing means 31 and data storage means 32, the latter preferentially storing a user account database, particularly in a secure manner (specifically encrypted for the protection of personal data).

[0062] Referring to Figure 1, we also advantageously have a mobile terminal 2 belonging to the individual wishing to enroll (i.e., create and activate their account to be able to identify themselves biometrically with system 1). This is typically a personal terminal such as a smartphone. Mobile terminal 2, like terminal 10, is itself a biometric terminal, but it is not part of system 1 (i.e., it is outside the local network 30).

[0063] Terminal 2 is only connected to system 1 via network 20 (a public wide area network such as the internet), specifically to server 3, and possibly indirectly to terminal 10.

[0064] It itself has at least one first sensor 24 for acquiring the first biometric data on the first biometric trait (typically a camera), but preferably said first biometric sensor 24 of the mobile terminal 2 is not capable of acquiring biometric data on said second biometric trait of the individual (i.e., second biometric data). In general, said mobile terminal 2 preferably does not include any sensor capable of acquiring biometric data on said second biometric trait of the individual. Put another way, we can say that preferably the first and second biometric traits are chosen such that terminal 2 (and generally ordinary mobile terminals) only have sensors for acquiring the first biometric data on the first trait, i.e., rank 2 but not rank 1.

[0065] It is worth noting that this is the case with smartphones and palm biometrics: every smartphone has a 24-inch camera-type sensor capable of acquiring a visible image of the palm (palm print), but not of observing the vein pattern (vein print). This configuration offers the highest level of security, as we will see later.

[0066] Furthermore, it remains entirely possible that terminal 2 may have at least one other sensor, possibly a biometric sensor, particularly for acquiring other biometric data on a different biometric trait (different from the first and second traits), but not used by the present method. For example, many smartphones may have a fingerprint sensor, which will not be used in the case of palm biometrics. In all cases, sensor 24 is referred to here as the first sensor (even if there is no other sensor) by analogy with the first sensor 14 of biometric terminal 10, as they both target the first biometric trait.

[0067] Typically, terminal 2 also usually has data processing means 21 (typically a processor), data storage means 22 (memory, for example flash), an interface 23 (for example a touch screen), wireless proximity communication means (for example NFC), etc., which are common for any mobile terminal such as a smartphone.

[0068] Progressive enrollment identification method The present method offers the advantage of significantly limiting the time spent in store in front of terminal 10 for enrollment, by allowing the individual to complete their enrollment in a manner, without sacrificing security.

[0069] With reference to figures 2a and 2b, which represent two embodiments thereof, the invention relates, in a first aspect, to a method of identifying said individual in system 1 beginning with a step (A) of biometric enrollment of said individual.

[0070] This enrollment includes at least one substep (a1) of recording at least one personal data, and a substep (a2) of recording a first biometric reference data acquired on a first biometric trait of the individual with a first sensor 14, 24 of a biometric terminal 10 of said system 1 or of a mobile terminal 2 of the individual, which will be described later.

[0071] This enrollment can be done in any known way, and in particular in store directly on a terminal 10 dedicated to enrollment, for example at the reception.

[0072] It should be noted that, generally, steps (a1) and (a2) can be performed in any order and in any known manner. For example, (a1) may involve the entry of at least one piece of personal data on an interface 13, 23 of the biometric terminal 10 of said system 1 or of the individual's mobile terminal 2, or its automatic retrieval from an identity document. Similarly, any payment data may be entered manually (bank card numbers) or obtained directly from a bank server.

[0073] Regarding (a2), in practice, several initial reference biometric data sets can be acquired and, if necessary, recorded to increase robustness. The goal is to create a biometric template that will be used in future identifications, as opposed to what is called a candidate biometric data set, i.e., a fresh data set. For example, in the case of a palm print, the individual can be asked to photograph their palm several times while slightly moving it. Additionally, terminal 10,2 can be configured to ask the individual to reacquire the initial biometric data set if it is of insufficient quality.

[0074] In the event that system 1 further includes a central server 3 storing an account database, said at least one personal data and first biometric reference data (and where applicable said means of payment data and / or second biometric reference data) are transmitted to said server 3 for registration in the account database (so as to be associated with said account of the individual being created).

[0075] It should be noted that although the second biometric will be necessary for identification, enrollment (A) generally does not include the recording of a second reference biometric data acquired on a second biometric trait of the individual, or at least not sufficiently for biometric identification to be implemented based on the second biometric. Indeed, first-order biometrics are generally much more complex to enroll than second-order biometrics; for example, while one acquisition is usually sufficient for a palm print, many will be required for a vein print.

[0076] The current process simply enrolls the first biometric data at this stage, making it quick and easy for the individual. The second biometric data will be enrolled later, naturally and potentially without the individual even realizing it. This is referred to as "progressive" enrollment because it occurs in several phases.

[0077] To rephrase, we understand that upon completion of enrollment (A), the individual's account is validated, i.e., the account creation is considered finalized, but only with regard to the initial biometric data. Biometric account validation will occur later.

[0078] In summary, this initial validation allows the use of the first biometric for user identification, but not yet the second biometric. According to a preferred embodiment, the time spent in-store at terminal 10 for enrollment can be further reduced by allowing the individual to complete the process on their own mobile terminal 2, for example, from home, without compromising security.

[0079] To achieve this, enrollment (A) begins advantageously with step (a) of creating an account for the individual on mobile terminal 2. It should be understood that while this step (a) allows for the creation of the account, it is not yet finalized and, in particular, not yet usable for identification. To rephrase, step (a) can be seen as a step for creating a "provisional" account, subject to confirmation. Again, this is a progressive enrollment process, as it unfolds in several phases.

[0080] In particular, step (a) may begin by obtaining a unique identifier for the individual, for example either by generating it directly, including randomly, or by transforming that of an existing ordinary customer account but lacking any biometrics.

[0081] Step (a) includes said substeps (a1) of recording at least one personal data, and advantageously any other technical data such as data of a means of payment of said individual, for example the data of a dematerialized bank card of the individual; and (a2) of recording a first biometric reference data acquired on the first biometric trait of the individual with the first sensor 24 of said mobile terminal 2. This data is associated with said account of the individual.

[0082] As explained, if system 1 also includes a central server 3 storing an account database, at least one personal data item and the first biometric reference data item (and, where applicable, the payment method data item and / or the second biometric reference data item) are transmitted to said server 3 for registration in the account database (so as to be associated with the individual's account currently being created). A marker may be associated with this account in the database to indicate that it is being created and is not yet usable for identification. In all cases, it is assumed that at the end of step (a) there is a "provisional" account for the individual comprising a unique identifier, at least one personal data item, and one biometric reference data item. Up to this point, the individual has been able to do everything on their terminal 2, without needing to go to a store.

[0083] To finalize account creation, a visit to biometric terminal 10 of system 1 is still required, but in a significantly streamlined manner. In other words, the security level afforded by the in-store procedure on a secure terminal is maintained, but most of the more cumbersome tasks (manual data entry, recording of the reference biometric data) can be completed beforehand, in a more convenient environment. The visit to terminal 10 can be very brief.

[0084] Indeed, it is sufficient, in a step (b), to transmit a request to finalize said account containing said unique identifier of said account from mobile terminal 2 to enrollment terminal 10.

[0085] Preferably, this step (b) is implemented via a proximity communication channel, in particular an optical channel or a near-field radio channel, which ensures that the individual is nearby (in the store) and has terminal 2: this is a first authentication factor.

[0086] Advantageously, the request is in the form of a QR code displayed by interface 23 of terminal 2, encoding the identifier. Any existing cryptographic technique can be used for this step.

[0087] The said QR code is then read by terminal 10, advantageously directly by the first biometric sensor 14 (which, it should be remembered, is advantageously a camera).

[0088] It should be noted that terminal 10 can be a payment terminal, i.e., the individual can complete step (b) and finalize the creation of their account simply by checking out. Subsequent checkouts can be made by presenting biometrics, without even needing mobile terminal 2 beforehand (since the account will then be operational, see below).

[0089] In this embodiment, the remainder of the enrollment process can be implemented automatically without further intervention from the individual. Thus, in step (c), the individual is authenticated by comparing a first candidate biometric data acquired on the first biometric feature of the individual with the first sensor 14 of the terminal 10, with the first reference biometric data of the account associated with the transmitted unique identifier.

[0090] Biometrics is therefore a second authentication factor, which allows for total security for this enrollment.

[0091] This typically involves accessing server 3 to obtain the first reference biometric data based on the transmitted unique identifier. For example, terminal 10 sends an authentication request to server 3, including the identifier and the first candidate biometric data. Server 3 accesses the first reference biometric data corresponding to the "provisional" account identified by the transmitted unique identifier and checks if it matches the received candidate biometric data (according to a known metric, such as Euclidean distance), and returns the result:

[0092] - If the said unique identifier does not exist, or is not that of an account currently being created, a comparison cannot be made. The individual will be offered the opportunity to create a new account directly on terminal 10, preventing fraud as it will require presentation of an identity document.

[0093] - if the unique identifier is correct but the individual has for example stolen terminal 2 from a third party, biometric authentication will be rejected and an alert will be issued.

[0094] If authentication is successful, in step (d) the individual's account is validated, i.e., the account creation is considered finalized, for example, by changing a marker in the database from "provisional" to "validated". Note that step (d) may include, if necessary, obtaining any missing personal (or other) data.

[0095] As explained, this validation only allows the first biometric to be used for user identification (and usually only that one). The optional marker may reflect whether the account is valid only for the first biometric, or also for the second.

[0096] It is noted that the aforementioned mobile terminal 2 generally does not include a sensor capable of acquiring biometric data on the individual's second biometric trait. Therefore, it is impossible to pre-register the second reference biometric data, unlike the first. This is precisely what makes the second biometric significantly more secure. The present method, which enrolls it separately, is thus all the more suitable.

[0097] Continuation of the progressive enrollment identification process

[0098] Once the account creation is finalized, it can be used for individual identification, and in particular for payment.

[0099] As explained, and especially if the first biometric is of rank two (this is the case of the palm print) it is necessary to continue the enrollment to add a second biometric of rank 1, and the present process will very cleverly allow this to be done during one or more identifications.

[0100] Generally, an identification of said individual is carried out by comparing a first candidate biometric data acquired on said first biometric trait of the individual with the first sensor 14 of the biometric terminal 10 with a plurality of first reference biometric data of accounts (validated, themselves obtained by the enrollment process as described) and / or by comparing a second candidate biometric data acquired on said first biometric trait of the individual with the second sensor 15 of the biometric terminal 10 with a plurality of second reference biometric data of accounts (validated).

[0101] The objective is to determine the unique identifier of the individual's account, as being that of the account associated with the first reference biometric data coinciding with the first candidate biometric data acquired on said first biometric trait of the individual with the first sensor 14 of the biometric terminal 10, and / or that of the account associated with the second reference biometric data coinciding with the second candidate biometric data acquired on said second biometric trait of the individual with the second sensor 15 of the biometric terminal 10.

[0102] In this case, due to the lack of a second biometric currently being registered, the individual can only be identified on the basis of the first biometric.

[0103] The process thus includes a step (B) of comparing a first candidate biometric data acquired on said first biometric trait of the individual with the first sensor 14 of the biometric terminal 10 with a plurality of first reference biometric data of accounts.

[0104] However, the present process nevertheless proposes that step (B) include the simultaneous acquisition of the first candidate biometric data and the second candidate biometric data, particularly when the same sensor 14, 15 of terminal 10 allows the acquisition of both biometric data at the same time (first and second sensors combined).

[0105] More specifically, considering that the first biometric is rank 2 (secondary biometric) and the second biometric is rank 1 (primary biometric), preferably, step (B) begins by comparing the second candidate biometric data acquired on said second biometric trait of the individual with the second sensor 15 of the biometric terminal 10 with the plurality of second reference biometric data of accounts.

[0106] If no second biometric reference data is found that coincides with the second candidate biometric data, we can proceed to compare the first candidate biometric data acquired on said first biometric trait of the individual with the first sensor 14 of the biometric terminal 10 with a plurality of first biometric reference data of accounts.

[0107] The idea is to use the first biometric method as a fallback (second-tier), so that identification is still possible. It should be noted that since security is lower, the rights associated with this "degraded" identification may be more limited (for example, a transaction may only be authorized below a threshold amount such as €50). Alternatively, or in addition, fees may be implemented to compensate for the risk of a less secure transaction.

[0108] But ingeniously, the invention further proposes a step (C) of recording the second candidate biometric data as a second reference biometric data, so as to complete the biometric enrollment of said individual, and this if necessary until enough second reference biometric data are available to be able to identify the individual directly on the basis of the second biometric.

[0109] Indeed, it is recalled that step (B) directly includes the simultaneous acquisition of the first candidate biometric data and the second candidate biometric data on the biometric terminal 10, so that we already have both biometric data, and we are sure that they are from the same individual.

[0110] Step (B) is therefore unique because it performs both identification and enrollment: terminal 10 simply acquires the second candidate biometric data by default, and its role varies:

[0111] - either the second biometric is validated, and then the second candidate biometric data is used for identification;

[0112] - either the second biometric is not validated, and then the second candidate biometric data is used for enrollment

[0113] The recording (C) of the second candidate biometric data is advantageously implemented only if none of a plurality of second reference biometric data sets from accounts coincides with the second candidate biometric data set. In other words, this is the mode in which an automatic attempt is made to begin identification based on the second biometric data set, and if the second biometric data set fails but the first biometric data set succeeds, the system infers that the second biometric data set is not enrolled for the individual (or at least there are not enough second reference biometric data sets), and proceeds with recording (C).Note that alternatively, as explained, we can have an account marker indicating that the individual's account is not enrolled for the second biometric, so as to avoid recording the second candidate data if there was already at least one second reference biometric data that should have coincided with the second candidate biometric data, and we just have an error for example due to the quality of the acquisition.

[0114] The registration (C) can be done as in step (a2), if necessary by transmission to server 3 in order to complete the account database.

[0115] This identification-enrollment process is particularly useful when terminal 10 is an electronic payment terminal, for two reasons:

[0116] - we can achieve the dual biometric level (maximum security) without even going through reception;

[0117] - we repeatedly pass over an electronic payment terminal, which in practice allows the acquisition of several second reference data points if necessary, as explained.

[0118] Preferably, the process includes a new account validation, similar to step (d), thus enabling full use of the second biometric for individual identification. The account marker, if any, can be updated.

[0119] Naturally, step (B) can be repeated as many times as the individual needs to be identified, for example to implement various transactions (checkouts in the store), if necessary without step (C) (since there will be a matching based on the second biometric data).

[0120] Note that at each occurrence of step (B) terminal 10 may be a different terminal from system 1, and if so, itself a different terminal from the one on which enrollment (A) was carried out.

[0121] Note that in all cases it can be provided for, during subsequent identifications (B), that even if we manage to identify the individual by comparing the second candidate biometric data acquired on said second biometric trait of the individual with the second sensor 14 of the biometric terminal 10 with the plurality of second reference biometric data of accounts, we will still implement the comparison of the first candidate biometric data acquired on said first biometric trait of the individual with the first sensor 14 of the biometric terminal 10 with the plurality of first reference biometric data of accounts.

[0122] This allows for "strong" identification (2 factors) which may be desirable, for example, in a situation where maximum security is required (for example, for a transaction exceeding a threshold amount such as 500C).

[0123] According to a preferred embodiment and in accordance with Figure 2b, in the case where enrollment (A) includes an authentication step (c), this can, like identification (B), itself include the simultaneous acquisition of said first candidate biometric data and the second reference biometric data, on the enrollment terminal 10, again particularly when the same sensor 14, 15 of the terminal 10 allows the acquisition of both biometric data at the same time (first and second sensors combined).

[0124] Thus, even as the first candidate data for individual authentication is acquired (step (c)), the second reference data is already being acquired, minimizing the individual's interaction with the system. This is an original step because it performs both authentication and enrollment simultaneously (and of course, the same biometric terminal 10 performs both tasks).

[0125] In summary:

[0126] - We have a first simultaneous acquisition of said first candidate biometric data and of the second reference biometric data, during step (c) of enrollment (A);

[0127] - The other necessary second biometric data is acquired during subsequent identifications (B). Procedure for implementing a transaction

[0128] According to a second aspect, the invention relates to a method for implementing a transaction on the biometric terminal 10, the latter being an electronic payment terminal (EPT), following the identification process according to the second aspect, i.e., it is assumed that the individual has been identified, meaning that the unique identifier of that individual's account has been determined at the end of step (B). This third aspect further implies that the data of an individual's payment method, for example, the data of an individual's dematerialized bank card, have been associated with said individual's account, i.e., that substep (a1) of the enrollment process typically also included the registration of said payment method of said individual. In other words, the account created is for biometric payment in said system 1 using said payment method.

[0129] The process then includes a step (D) in which said terminal 10 uses the individual's payment method data associated with the individual's account (recorded in their account) to carry out the transaction. It is understood that the biometric terminal 10 is the same terminal on which the identification was obtained, and in practice, steps (B) to (D) are linked and indistinguishable by the individual.

[0130] Thus, the transaction is implemented automatically using the electronic payment method associated with his account, so that he does not need to do anything and in particular does not need to present any means of payment.

[0131] Therefore, preferably, step (D) does not include the use of any means of payment other than the electronic one (the one whose data is associated with his account).

[0132] In summary, we have an optimal user experience, while maintaining the highest level of security and greatly streamlining the enrollment process.

[0133] Note that we will not be limited to the context of a process for implementing a transaction, and that identification can be used for any useful purpose, for example in an access control process: the individual is, for example, authorized to pass through a secure door or open an application if their account is associated with data representing an access authorization.

[0134] Terminals

[0135] According to a third aspect, the invention relates to the biometric terminal 10 of a system 1 for the implementation of one or more of the processes according to the first and second aspects, i.e. an enrollment, identification and / or transaction terminal.

[0136] Thus, this terminal 10 includes, as explained, at least data processing means 11 and a memory 12, at least a first biometric sensor 14 and a second biometric sensor 15, possibly combined with the first sensor 14, and advantageously an interface 13 and / or near field communication means.

[0137] It is advantageously connected via network 20 and / or 30 to a server 3 of system 1.

[0138] The data processing means 31 are at least configured to, following the biometric enrollment of said individual with the recording of at least one personal data point (recording of a first reference biometric data point acquired on a first biometric trait of the individual), implement the steps consisting of:

[0139] - Identify said individual by comparing a first candidate biometric data acquired on said first biometric trait of the individual with the first sensor 14 with a plurality of first reference biometric data of accounts, including the simultaneous acquisition of said first candidate biometric data and a second candidate biometric data acquired on a second biometric trait of the individual, different from the first biometric trait, with the second sensor 15; - record the second candidate biometric data as second reference biometric data, so as to complete the biometric enrollment of said individual.

[0140] In the case of a transaction terminal 10, i.e., an POS terminal, the data processing means 11 can also be configured to:

[0141] - to use data from an individual's payment method associated with the individual's account for the implementation of the transaction.

[0142] According to another aspect, the invention proposes an assembly comprising the terminal 10 according to the fourth aspect, and a mobile terminal 2. It is naturally possible to have several terminals 10, 2.

[0143] This or these mobile terminals 2 also include, as explained, at least data processing means 21, a memory 22, and a biometric sensor 24, and advantageously an interface 23 and / or near field communication means.

[0144] The set may also include a server 3.

[0145] The data processing means 21 of mobile terminal 2 are configured to, when the account of said individual is created on mobile terminal 2:

[0146] - Acquire a first biometric reference data on a first biometric trait of the individual with the first sensor 24;

[0147] - record at least the said personal data and the first biometric reference data.

[0148] computer program product

[0149] According to a fourth and a fifth aspect, the invention relates to a computer program product comprising code instructions for the execution (on the data processing means 11, 21 of the terminals 10 and 2) of a method according to the first aspect of identifying said individual in a system 1, or a method according to the second aspect for carrying out a transaction by the individual, on a biometric terminal 10 of the system 1; as well as computer-readable storage means (for example the data storage means 12, 22 of the terminals 10 and 2) on which this computer program product is found.

Claims

DEMANDS 1. A method for identifying an individual in a system (1), characterized in that it comprises the implementation of steps of: (A) Biometric enrollment of said individual, comprising a substep (a1) of recording at least one personal data, and a substep (a2) of recording a first biometric reference data acquired on a first biometric trait of the individual with a first sensor (14, 24) of a biometric terminal (10) of said system (1) or of a mobile terminal (2) of the individual, the personal data and the first biometric reference data being associated with an account of the individual; (B) Identification of said individual by comparing a first candidate biometric data acquired on said first biometric trait of the individual with the first sensor (14) of the biometric terminal (10) with a plurality of first reference account biometric data, including the simultaneous acquisition of said first candidate biometric data and a second candidate biometric data acquired on a second biometric trait of the individual, different from the first biometric trait, with a second sensor (15) of the biometric terminal (10); (C) recording of the second candidate biometric data as the second reference biometric data, so as to complete the biometric enrollment of said individual.

2. A method according to claim 1, wherein said system (1) further comprises at least one server (3) comprising data storage means (32) storing an account database, the server (3) being connected to the biometric terminal (2) via a network (20, 30), said at least one personal data item, first biometric reference data item and 26 The second biometric reference data is transmitted to the server for registration in the account database.

3. A method according to any one of claims 1 and 2, wherein the enrollment (A) comprises: (a) Creation of an account of said individual on a mobile terminal (2) of said individual, comprising said substep (a1) of recording at least one personal data, and said substep (a2) of recording a first biometric reference data acquired on a first biometric trait of the individual with a first sensor (24) of said mobile terminal (2). (b) Transmission of a request to finalize said account containing a unique identifier of said account from the mobile terminal (2) to a biometric terminal (10) of said system (1); (c) Authentication of said individual by comparing a first candidate biometric data acquired on said first biometric trait of the individual with a first sensor (14) of the biometric terminal (10), with the first reference biometric data of the account associated with said unique identifier transmitted; (d) Validation of said individual's account.

4. A method according to any one of claims 1 to 3, wherein said substep (a1) further comprises the registration of a means of payment of said individual, said account being for biometric payment in said system (1) by means of said means of payment; said biometric terminal (10) preferably being an electronic payment terminal.

5. A method according to any one of claims 1 to 4, wherein the recording (C) of the second candidate biometric data is implemented only if none of a plurality of second reference account biometric data coincides with the second candidate biometric data.

6. A method according to claim 5, wherein the identification (B) of said individual comprises first comparing the second candidate biometric data with said plurality of second reference biometric data from accounts, then if no second reference biometric data coincides with the second candidate biometric data, comparing the first candidate biometric data acquired on said first biometric trait of the individual with the first sensor (14) of the biometric terminal (10) with a plurality of first reference biometric data from accounts, and recording (C) the second candidate biometric data.

7. Method according to any one of claims 1 to 6, wherein said first sensor (14) and second sensor (15) of the biometric terminal (10) are combined.

8. A method according to any one of claims 1 to 7, wherein said first biometric feature is a palm print and the second biometric feature is a vein print.

9. Method for implementing a transaction by an individual, on a biometric terminal (10) of a system (1), said biometric terminal (10) being an electronic payment terminal, characterized in that it comprises, following the implementation of the method of identifying said individual in the system (1) according to any one of claims 1 to 8, the implementation of a step (D) of using said biometric terminal (10) the data of a means of payment of the individual associated with the individual's account for the implementation of the transaction.

10. Biometric terminal (10) of a system (1) comprising a first sensor (14) and a second sensor (15), characterized in that it comprises data processing means (11) configured to, following biometric enrollment of said individual with recording of at least one personal data point and a first reference biometric data point acquired on a first biometric trait of the individual, the personal data point and the first reference biometric data point being associated with an account of the individual: - Identify said individual by comparing a first candidate biometric data acquired on said first biometric trait of the individual with the first sensor (14) with a plurality of first reference biometric data of accounts, including the simultaneous acquisition of said first candidate biometric data and a second candidate biometric data acquired on a second biometric trait of the individual, different from the first biometric trait, with the second sensor (15); - record the second candidate biometric data as the second reference biometric data, so as to complete the biometric enrollment of said individual.

11. Product computer program comprising code instructions for the execution of a method according to any one of claims 1 to 8 of identifying said individual in a system (1), or a method according to claim 9 for the implementation of a transaction by the individual, on a biometric terminal (10) of the system (1), when said program is executed on a computer.

12. Computer-readable storage means on which is recorded a computer program product comprising code instructions for the execution of a method according to any one of claims 1 to 8 of identifying said individual in a system (1), or a method according to claim 9 for the implementation of a transaction by the individual, on a biometric terminal (10) of the system (1).