Secure biometrics transactions

WO2026182930A1PCT designated stage Publication Date: 2026-09-03VISA INTERNATIONAL SERVICE ASSOCIATION
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/US2026/015121
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-02-26
Filing Date
2026-02-12
Publication Date
2026-09-03

Smart Images

  • Figure US2026015121_03092026_PF_FP_ABST
    Figure US2026015121_03092026_PF_FP_ABST
Patent Text Reader

Abstract

User provides their biometric data by scanning their body part to a reader, and thereafter their account information to the reader. The account information is transmitted to a processing network computer, which generates and provides a non-transaction token identifying the account to the biometric service provider. The biometric service provider stores the biometric template along with the non-transaction token. During a transaction, the user provides their biometric data to the reader. The biometric data is transmitted to the biometric service provider along with transaction data. The biometric service provider identifies the biometric template, looks up the corresponding non-transaction token using the biometric template, and sends the non-transaction token and the transaction data to the processing network computer. The processing network computer uses the non-transaction token to identify a corresponding network token, and processes the transaction using the network token and the transaction data.
Need to check novelty before this filing date? Find Prior Art

Description

PATENT Attorney Docket No.: 079900-1524916 Client Reference No.: 9451 WO01SECURE BIOMETRICS TRANSACTIONSCROSS-REFERENCE TO RELATED APPLICATIONS

[0001] This application claims priority to Greek Application No. 20250100148 filed on February 26, 2025, the contents of which are incorporated by reference in their entirety for all purposes.BACKGROUND

[0002] Data security is an issue in transactions involving user biometric data and user credentials, because they are considered sensitive information. If they are obtained by hackers or eavesdroppers when they are stored or being transmitted between computers, they can be used to conduct unauthorized transactions. It can take valuable time, and computing resources to remedy impact of compromised user credentials.

[0003] Embodiments of the disclosure address these and other problems, individually and collectively.SUMMARY

[0004] One embodiment is related to a computer-implemented method comprising: receiving, by a biometric service provider computer from a reader device, a biometric sample and transaction data associated with a transaction. The method further comprises determining, by the biometric service provider computer, a biometric vector based on the biometric sample; and discarding the biometric sample. The method also comprises matching, by the biometric service provider, the biometric vector to a biometric template. The biometric service provider retrieves a first token associated with the biometric template. The first token is a non-transaction token thatis not valid for conducting transactions. The biometric service provider discards the biometric vector. The method further includes transmitting, by the biometric service provider, the transaction data to a processing network computer. The processing network computer processes the transaction using the transaction data and a second token associated with the first token.

[0005] In some embodiments, the method further comprises, prior to receiving the biometric sample, receiving, by the biometric service provider from the reader device, a transient token. The transient token is generated by the processing network computer in association with a user credential and provided to the reader device. The biometric service provider computer transmits to the processing network computer a token request message comprising the transient token. The biometric service provider computer receives the first token from the processing network computer and an enrollment biometric sample. The biometric service provider computer generates the biometric template based on the enrollment biometric sample, and discards the enrollment biometric sample. The method further comprises storing, by the biometric service provider, the biometric template in a database of biometric templates in association with the first token.

[0006] Another embodiment can include a biometric service computer comprising a processor, and a computer readable medium. The computer readable medium comprises code, executable by the processor, to perform the above method(s).

[0007] Further details regarding embodiments of the disclosure can be found in the Detailed Description and the Figures.BRIEF DESCRIPTION OF THE DRAWINGS

[0008] FIG. 1 shows a method and system for enrolling a user biometric to a transaction processing system according to some embodiments.

[0009] FIG. 2 shows a block diagram of an exemplary processing network computer.

[0010] FIG. 3 shows a block diagram of an exemplary biometric service provider computer.

[0011] FIG. 4 shows a block diagram of an exemplary reader device.

[0012] FIG. 5 show a reader device method for enrolling a user biometric according to some embodiments.

[0013] FIG. 6 shows a method for processing a transaction using biometric verification according to embodiments of the disclosure.

[0014] FIG. 7 shows a reader device method for processing a transaction using biometric verification according to some embodiments.

[0015] FIG. 8 shows a method for processing a transaction using biometric verification according to embodiments of the disclosure.DETAILED DESCRIPTION

[0016] Prior to discussing embodiments of the disclosure, some terms can be described in further detail.

[0017] A “user” may include an individual. In some embodiments, a user may be associated with one or more personal accounts and / or mobile devices. The user may also be referred to as a cardholder, account holder, or consumer in some embodiments.

[0018] A “user device” may be a device that is operated by a user. Examples of user devices may include a mobile phone, a smart phone, a card, a personal digital assistant (PDA), a laptop computer, a desktop computer, a server computer, a vehicle such as an automobile, a thin-client device, a tablet PC, etc. Additionally, user devices may be any type of wearable technology device, such as a watch, earpiece, glasses, etc. The user device may include one or more processors capable of processing user input. The user device may also include one or more input sensors for receiving user input. As is known in the art, there are a variety of input sensors capable of detecting user input, such as accelerometers, cameras, microphones, etc. The user input obtained by the input sensors may be from a variety of data input types, including, butnot limited to, audio data, visual data, or biometric data. The user device may comprise any electronic device that may be operated by a user, which may also provide remote communication capabilities to a network. Examples of remote communication capabilities include using a mobile phone (wireless) network, wireless data network (e.g., 3G, 4G or similar networks), Wi-Fi, Wi-Max, or any other communication medium that may provide access to a network such as the Internet or a private network.

[0019] An “access device” may be any suitable device for providing access to an external computer system. An access device may be in any suitable form. Some examples of access devices include point of sale (POS) devices, cellular phones, PDAs, personal computers (PCs), tablet PCs, hand-held specialized readers, set-top boxes, electronic cash registers (ECRs), automated teller machines (ATMs), virtual cash registers (VCRs), kiosks, security systems, access systems, Websites, and the like. An access device may use any suitable contact or contactless mode of operation to send or receive data from, or associated with, a portable communication device. In some embodiments, where an access device may comprise a POS terminal, any suitable POS terminal may be used and may include a reader, a processor, and a computer-readable medium. A reader may include any suitable contact or contactless mode of operation. For example, exemplary card readers can include radio frequency (RF) antennas, optical scanners, bar code readers, or magnetic stripe readers to interact with a portable communication device. An exemplary reader may include a biometric reader.

[0020] A “biometric” may be any human characteristic that is unique to an individual. For example, a biometric may be a person's fingerprint, voice sample, face, DNA, retina, etc.

[0021] A “biometric reader” may include a device for capturing data from an individual's biometric sample. Examples of biometric readers may include fingerprint readers, front-facing cameras, microphones, and iris scanners.

[0022] A “biometric sample” may include data obtained by a biometric reader. The data may be either an analog or digital representation of the user's biometric, generated prior to determining distinct features needed for matching. For example,a biometric sample of a user's face may include image data. In another example, a biometric sample of a user's voice may include audio data.

[0023] A “biometric template” or “biometric sample template” may include a file containing distinct characteristics extracted from a biometric sample that may be used during a biometric authentication process. For example, a biometric template may be a binary mathematical file representing the unique features of an individual's face, fingerprint, eye, hand or voice needed for performing accurate authentication of the individual. For example, the biometric template may include geometric representation of an individual fingerprint, facial geometry, etc.

[0024] A “biometric vector” may be a mathematical representation of a biometric sample. According to various embodiments, the biometric vector may be irreversible (e.g., cannot be reverse engineered to obtain the underlying biometric sample).

[0025] A “resource provider” may be an entity that can provide a resource such as goods, services, information, and / or access. Examples of resource providers includes merchants, data providers, transit agencies, governmental entities, venue and dwelling operators, etc. A “merchant” may typically be an entity that engages in transactions and can sell goods or services, or provide access to goods or services.

[0026] An “acquirer” may typically be a business entity (e g., a commercial bank) that has a business relationship with a particular merchant or other entity. Some entities can perform both issuer and acquirer functions. Some embodiments may encompass such single entity issuer-acquirers. An acquirer may operate an acquirer computer, which can also be generically referred to as a “transport computer.”

[0027] A “credential” may be any suitable information that serves as reliable evidence of worth, ownership, identity, or authority. A credential may be a string of numbers, letters, or any other suitable characters, as well as any object or document that can serve as confirmation. Examples of credentials include value credentials, identification cards, certified documents, access cards, passcodes and other login information, etc.

[0028] A “token” may be a substitute value for a credential. A token may be a string of numbers, letters, or any other suitable characters. Examples of tokens include payment tokens, access tokens, personal identification tokens, etc.

[0029] A “cryptogram” may include a piece of obscured text such as encrypted text. A cryptogram may be formed by encrypting input data with an encryption key such as a symmetric encryption key. In some embodiments, a cryptogram is reversible so that the inputs that are used to form the cryptogram can be obtained using the same symmetric key to perform a decryption process. In some embodiments, if input data is encrypted using a private key of a public / private key pair, the cryptogram may also be a digital signature. A digital signature may be verified with a public key of the public / private key pair. In some embodiments, a cryptogram may include a dCW (dynamic card verification value).

[0030] In some embodiments, the cryptogram can encode data elements including an account identifier such as primary account number, a variable data element such as a counter, a time of day, or interaction value, and other information. Such data may be included using an encryption process such as DES, triple DES, or AES using suitable encryption keys. The encryption keys may also be UDKs or unique derived keys, and may be generated based upon device specific information such as an account number, which may be encrypted using a master derivation key (MDK). The cryptogram can be verified by another computer such a remote computer by either decrypting the cryptogram to and verifying the decrypted contents with other data (e.g., an account number stored on file), or by encrypting other inputs and then comparing the encrypted result to the cryptogram.

[0031] A “token request message” may be an electronic message for requesting a token. A token request message may include information usable for identifying a payment account or digital wallet, and / or information for generating a token. For example, a token request message may include payment credentials, mobile communication device identification information (e.g., a phone number or MSISDN), a digital wallet identifier, information identifying a tokenization service provider, a merchant identifier, a cryptogram, and / or any other suitable information. Information included in a token request message can be encrypted (e.g., with an issuer-specifickey). In some embodiments, the token request message may include a flag or other indicator specifying that the message is a token request message.

[0032] A “token response message” may be a message that responds to a token request. A token response message may include an indication that a token request was approved or denied. A token response message may also include a token, mobile communication device identification information (e.g., a phone number or MSISDN), a digital wallet identifier, information identifying a tokenization service provider, a merchant identifier, a cryptogram, and / or any other suitable information. Information included in a token response message can be encrypted (e.g., with an issuer-specific key). In some embodiments, the token response message may include a flag or other indicator specifying that the message is a token response message.

[0033] A “server computer” may include a powerful computer or cluster of computers. For example, the server computer can be a large mainframe, a minicomputer cluster, or a group of servers functioning as a unit. In one example, the server computer may be a database server coupled to a Web server. The server computer may be coupled to a database and may include any hardware, software, other logic, or combination of the preceding for servicing the requests from one or more client computers.

[0034] An “authorization request message” may be an electronic message that requests authorization for an interaction. In some embodiments, it is sent to a transaction processing computer and / or an issuer of a payment card to request authorization for a transaction. An authorization request message according to some embodiments may comply with International Organization for Standardization (ISO) 8583, which is a standard for systems that exchange electronic transaction information associated with a payment made by a user using a payment device or payment account. The authorization request message may include an issuer account identifier that may be associated with a payment device or payment account. An authorization request message may also comprise additional data elements corresponding to “identification information” including, by way of example only: a service code, a CW (card verification value), a dCW (dynamic card verification value), a PAN (primary account number or “account number”), a payment token, a username, an expirationdate, etc. An authorization request message may also comprise “transaction information,” such as any information associated with a current transaction, such as the transaction value, merchant identifier, merchant location, acquirer bank identification number (BIN), card acceptor ID, information identifying items being purchased, etc., as well as any other information that may be utilized in determining whether to identify and / or authorize a transaction.

[0035] An “authorization response message” may be a message that responds to an authorization request message. In some cases, it may be an electronic message reply to an authorization request message generated by an issuing financial institution or a transaction processing computer. The authorization response message may include, by way of example only, one or more of the following status indicators: Approval -- transaction was approved; Decline -- transaction was not approved; or Call Center -- response pending more information, merchant must call the toll-free authorization phone number. The authorization response message may also include an authorization code, which may be a code that a credit card issuing bank returns in response to an authorization request message in an electronic message (either directly or through the transaction processing computer) to the merchant's access device (e.g., PCS equipment) that indicates approval of the transaction. The code may serve as proof of authorization.

[0036] An “authorizing entity” may be an entity that authorizes a request. Examples of an authorizing entity may be an issuer, a governmental agency, a document repository, an access administrator, etc. An authorizing entity may operate an authorizing entity computer. An “issuer” may refer to a business entity (e.g., a bank) that issues and optionally maintains an account for a user. An issuer may also issue payment credentials stored on a user device, such as a cellular telephone, smart card, tablet, or laptop to the consumer, or in some embodiments, a portable device.

[0037] The term “verification” and its derivatives may refer to a process that utilizes information to determine whether an underlying subject is valid under a given set of circumstances. Verification may include any comparison of information to ensure some data or information is correct, valid, accurate, legitimate, and / or in good standing.

[0038] A “processor” may include a device that processes something. In some embodiments, a processor can include any suitable data computation device or devices. A processor may comprise one or more microprocessors working together to accomplish a desired function. The processor may include a CPU comprising at least one high-speed data processor adequate to execute program components for executing user and / or system-generated requests. The CPU may be a microprocessor such as AMD's Athlon, Duron and / or Opteron; IBM and / or Motorola's PowerPC; IBM's and Sony's Cell processor; Intel's Celeron, Itanium, Pentium, Xeon, and / or XScale; and / or the like processor(s).

[0039] A “memory” may be any suitable device or devices that can store electronic data. A suitable memory may comprise a non-transitory computer readable medium that stores instructions that can be executed by a processor to implement a desired method. Examples of memories may comprise one or more memory chips, disk drives, etc. Such memories may operate using any suitable electrical, optical, and / or magnetic mode of operation.

[0040] Embodiments provide techniques for user authentication and transaction processing by mapping biometric identifiers to transaction tokens. The biometric data and the account data are stored and accessed by different entities such that no one entity (e.g., no third-party entity) has access to account data and biometric data at a given time. For example, a user provides their biometric data by scanning their body part (e.g., palm) to a reader (e.g., an access device), and the biometric data (or a biometric data vector derived from the biometric data) is converted to a biometric template by a biometric service provider. After the biometric template is created, the biometric data is discarded. The user also provides their account information to the reader. The account information is transmitted to a processing network computer, which generates and provides a non-transaction token identifying the underlying account to the biometric service provider. The biometric service provider stores the biometric template along with the nontransaction token, which is not valid for conducting transactions. During a transaction, the user provides their biometric data to the reader. The biometric data or a biometric data vector (generated by the reader) is transmitted to the biometricservice provider along with transaction data (e.g., merchant identifier and transaction amount). The biometric service provider identifies the biometric template, looks up the corresponding non-transaction token using the biometric template, and sends the non-transaction token and the transaction data to the processing network computer. The processing network computer uses the non-transaction token to identify a corresponding network token, and processes the transaction using the network token and the transaction data. According to various embodiments, the provisioning of the non-transaction token and network token may be during an enrollment step prior to payment.

[0041] Embodiments are directed towards techniques for processing a transaction with a user biometric sample by mapping biometric templates to transaction tokens. A user can initiate a transaction by providing a biometric sample to a reader device. Using the biometric sample, embodiments can authenticate the user and process the transaction in a single flow. Embodiments orchestrate token providing and exchange processes between a biometric service provider computer and a processing network computer to enable separate storage of sensitive data.

[0042] A first token may be used among a biometric service provider computer and a processing network computer to identify a user account. The first token may be generated during enrollment. After enrollment, the biometric service provider computer may store the first token in association with data related to the user’s biometric (e.g., a biometric template), and the processing network computer may separately store the first token in association with a second token. The second token may be associated with sensitive information that can be utilized for a transaction, such as a payment token that can be used to conduct transactions. The second token may be a proxy for a user credential. The first token is a non-transaction token, which may be an account reference. Advantageously, no one entity has access to account data and biometric data at a given time.

[0043] Prior to conducting a transaction, the user completes an enrollment process to link a user credential (e.g., a bank account credential) to a first token that can be presented in subsequent transactions. During the enrollment process, the user provides the user credential (e.g., by tapping their payment card) to a reader deviceand the reader device obtains a transient token for the user credential via the processing network computer. According to various embodiments, the transient token may be generated using a first type of information for a first user, and a second type of information for a second user. Varying the way the transient token is generated renders the transient token more secure and hard (if not impossible) to replicate.

[0044] Continuing with the enrollment process, the reader device passes the transient token to a biometric service provider computer, which uses the transient token to initiate an authentication process between the user and an authorizing entity (e.g., an issuer bank that issued the bank account and user credential). If the authentication is successful, the user is prompted to provide an enrollment biometric sample. For example, a user provides their biometric sample by scanning their body part (e.g., palm) to a reader (e.g., an access device). The biometric service provider can translate the enrollment biometric sample into a biometric template, and delete the enrollment biometric sample.

[0045] The biometric service provider computer additionally obtains a first token for the transient token, and stores the first token in association with the biometric template. For example, the biometric service provider computer may transmit the transient token to the processing network computer in a token request message. Upon receiving the transient token, the processing network can detokenize the transient token to obtain the user credential, and retrieve a second token (e.g., a network token, a payment token) for the user credential. Then, a first token is generated, stored in association with the second token, and sent to the biometric service provider. The biometric service provider computer can store the first token in association with the biometric template. After enrollment, the processing network computer can delete the transient token.

[0046] Moreover, no single entity has access to both the biometric template and the second token at once. As explained above, the second token can be used to conduct transactions (e.g., can serve as a form of payment in a transaction). Both the biometric service provider computer and the processing network computer use the first token as an account reference, so that during a transaction, the first token can be exchanged between parties instead of sensitive user data.

[0047] During a transaction, the user may again provide a biometric sample (e.g., scan the same palm as during enrollment), and the biometric service provider computer can convert the biometric sample to a biometric vector, and delete the biometric sample. The biometric service provider computer can identify the user by comparing the biometric vector to a plurality of biometric templates (corresponding to enrolled users) and determine the biometric template that matches the biometric vector. Using the matching biometric template, the biometric service provider computer can look up the first token, and send the first token to the processing network computer. The processing network computer can use the first token to identify the second token. The processing network computer can then facilitate the transaction using the second token.

[0048] Although payment transactions are discussed in detail, embodiments are not limited thereto. Other embodiments can include interactions that include access to secure data (e.g., secure and sensitive information), secure locations (e.g., transit terminals), etc.

[0049] FIG. 1 shows a method for enrolling a biometric to a transaction processing system according to embodiments. FIG. 1 shows a user 100, a reader device 102, a processing network computer 104, a biometric service provider computer 106, and an authorizing entity computer 110. The processing network computer 104 can be in operable communication with the reader device 102, the biometric service provider computer 106, and the authorizing entity computer 110. The reader device 102 can communicate with the user 100, the biometric service provider computer 106, and the authorizing entity computer 110.

[0050] For simplicity of illustration, a certain number of components are shown in FIG. 1. It is understood, however, that embodiments may include more than one of each component. In addition, some embodiments may include fewer than or greater than all of the components shown in FIG. 1.

[0051] Messages between at least the devices of the system in FIG. 1 can be transmitted using a secure communications protocol such as, but not limited to, File Transfer Protocol (FTP); HyperText Transfer Protocol (HTTP); Secure HypertextTransfer Protocol (HTTPS), SSL, ISO (e.g., ISO 8583) and / or the like. The communications network may include any one and / or the combination of the following: a direct interconnection; the Internet; a Local Area Network (LAN); a Metropolitan Area Network (MAN); an Operating Missions as Nodes on the Internet (OMNI); a secured custom connection; a Wide Area Network (WAN); a wireless network (e.g., employing protocols such as, but not limited to a Wireless Application Protocol (WAP), l-mode, and / or the like); and / or the like. The communications network can use any suitable communications protocol to generate one or more secure communication channels. A communications channel may, in some instances, comprise a secure communication channel, which may be established in any known manner, such as through the use of mutual authentication and a session key, and establishment of a Secure Socket Layer (SSL) session.

[0052] Before providing a detailed description of the steps shown in FIG. 1 , an overview of the various components is provided next.

[0053] FIG. 2 shows a block diagram of an exemplary processing network computer 104. FIG. 2 shows a processing network computer 104 and a token vault 130. The processing network computer 104 can tokenize credentials, detokenize tokens, and facilitate transactions. The processing network computer 104 can include one or more computers that generate, process, and maintain tokens. For example, the processing network computer 104 may include or be in communication with a token vault 130 where the generated tokens are stored. The token vault may maintain a one-to-one mapping between a token (e.g., a second token) and a credential represented by the token. Additionally, or alternatively, the token database can maintain mappings of tokens to tokens (e.g., a first token to a second token).

[0054] The processing network computer 104 can include functionality for facilitating the processing of interactions. The processing network computer 104 may include data processing subsystems, networks, and operations used to support and deliver authorization services, exception file services, and clearing and settlement services. The processing network computer 104 may be included in a transaction processing network. An exemplary transaction processing network may include VisaNet™. Transaction processing networks such as VisaNet™ are able to processcredit card transactions, debit card transactions, and other types of commercial transactions. VisaNet™, in particular, includes a VIP system (Visa Integrated Payments system) which processes authorization requests and a Base II system which performs clearing and settlement services. The processing network computer 104 may use any suitable wired or wireless network, including the Internet.

[0055] The processing network computer 104 may comprise a processor 104-A, which may be coupled to a system memory 104-B and an external communication interface 104-C. A computer readable medium 104-D may also be operatively coupled to the processor 104-A.

[0056] The computer readable medium 104-D may comprise a number of software modules including a communication module 104-D1, an encryption module 104-D2, a token providing module 104-D3, a token exchange module 104-D4, and an enrollment facilitation module 104-D5.

[0057] The computer readable medium 104-D may comprise code, executable by the processor 104-A, for performing a method comprising: receiving from a reader device, a biometric sample and transaction data associated with a transaction; determining a biometric vector based on the biometric sample; discarding the biometric sample; matching the biometric vector to a biometric template; retrieving a first token associated with the biometric template, wherein the first token is a nontransaction token that is not valid for conducting transactions; discarding the biometric vector; and transmitting the first token and the transaction data to a processing network computer, wherein the processing network computer retrieves a second token stored in association with the first token and processes the transaction using the second token and the transaction data.

[0058] The encryption module 104--D2 may comprise code that includes any suitable algorithms to encrypt and decrypt data in embodiments. Suitable algorithms may include DES, tripe DES, AES, etc. It may also store keys that can be used with such algorithms. The encryption module 104-D2 may utilize symmetric or asymmetric encryption techniques to encrypt and / or verify data.

[0059] The token providing module 104-D3 may comprise code that causes the processor 104-A to provide tokens. For example, the token providing module 104-D3 may contain logic that causes the processor 104-A to generate a token (e.g., a transient token or a first token) and / or associate tokens with credentials or other tokens (e.g., a second token). In some embodiments, the token providing module 104-D3 may communicate with a token server to retrieve the token (e.g., a transient token or a first token) and / or associate tokens with credentials or other tokens (e.g., a second token). A token record may then be stored in a token record database of the token vault 130 indicating that the token is associated with (i.e., mapped to) a certain user or a certain set of payment credentials.

[0060] The token exchange module 104-D4 may comprise code that causes the processor 104-A to obtain data based on a token or credential. The token exchange module 104-D4 can comprise executable code searching the token vault 130 and transmitting token request messages to obtain data. For example, the token exchange module 104-D4 can comprise executable code for, upon receiving a first token, determining that the first token is stored in association with a second token in the token vault 130, and obtaining the second token. The token exchange module 104-D4 may additionally comprise code or software, executable by the processor 104-A, for transmitting a token request message comprising a credential to obtain a second token.

[0061] The enrollment facilitation module 104-D5 may comprise code that causes the processor 104-A to transmit messages to one or more entities to facilitate a token providing process.

[0062] The authorization processing module 104--D6 can comprise code, executable by the processor 104-A, for can comprise code, executable by the processor 404 to process, modify, and route authorization request and response messages.

[0063] FIG. 3 shows a block diagram of a biometric service provider computer 106 of a system according to an embodiment. The biometric service provider computer 106 may provide biometric verification services. The biometric service providercomputer 106 may be coupled to a biometric template database 170, whereby the biometric service provider computer 106 stores biometric templates and data associated with the biometric templates. For example, the biometric template database 170 may store a bi-directional mapping between a biometric template and a first token.

[0064] The biometric service provider computer 106 may comprise a processor 106-A, which may be coupled to a system memory 106-B and an external communication interface 106-C. A computer readable medium 106D may also be operatively coupled to the processor 106-A.

[0065] The computer readable medium 106-D may comprise a number of software modules including a communication module 106-D1, a biometric vector calculator 106-D2, a biometric vector conversion module 106-D3, a data deletion module 106-D4, and a biometric template providing module 106-D5.

[0066] The communication module 106-D1 may comprise code that causes the processor 106-A to generate messages, forward messages, reformat messages, and / or otherwise communicate with other entities.

[0067] The biometric vector calculator 106-D2 may comprise executable code that includes any suitable algorithms to calculate a biometric vector for a biometric sample. For example, the biometric vector calculator 106-D2, may comprise executable code for, upon receiving a biometric sample from a user, determining a biometric vector based on the biometric sample.

[0068] The biometric vector conversion module 106-D3 may comprise executable code for obtaining data based on a biometric vector. For example, the biometric vector conversion module 106-D3, in conjunction with the processor 106-A, can search the biometric template database 170 for a biometric template that matches a biometric vector, and obtain data associated with the matching biometric vector.

[0069] The data deletion module 106-D4 may comprise executable code for deleting data according to embodiments. For example, the data deletion module 106-D4 may comprise executable code for deleting biometric samples after they areconverted to biometric vectors, and deleting a biometric vector after a matching biometric template is determined.

[0070] The biometric template providing module 106-D5 may comprise executable code for determining a biometric template for a biometric sample and storing it in the biometric template database 170 with associated data. For example, the biometric template providing module 106-D5 may comprise executable code which creates a biometric template for an enrollment biometric sample received from a user during enrollment, and stores the biometric template in the biometric template database 170 with associated data (e.g., a first token).

[0071] FIG. 4 shows a block diagram of a reader device. In some embodiments, the reader device 102 may be a communication device (e.g., a mobile phone) that can be used to make payments or an access device (e.g., merchant POS). In other embodiments, the reader device 102 may be embodied in an access device (e.g., merchant POS). The exemplary reader device 102 may comprise a computer readable medium 102-B and a memory 102-C that can be present within the body 102-J of the reader device 102. The body 102-J may be in the form a plastic substrate, housing, or other structure. In some cases, the memory 102-C may be a secure element, and / or may also store information such as access data such as tokens, PANs, tickets, etc. Information in the memory 102-C may be transmitted by the reader device 102 to another device using an antenna 102-D or contactless element 102-1.

[0072] The computer readable medium 102-B may contain an enrollment application 102-B1, a biometric service provider application 102-B2, and an authentication application 102-B3. The enrollment application 102-B1 may comprise executable code for conducting an enrollment process according to embodiments. The enrollment application 102-B1 may comprise executable code for communicating with a user 100 and a processing network computer 104, such as presenting terms and conditions to a user, and receiving user input. For example, the enrollment application 102-B1 may comprise executable code for obtaining a user credential from the user 100 and transmitting it to the processing network computer 104.

[0073] The biometric service provider application 102-B2 may be associated with a biometric service provider computer 106 and comprise executable code for communicating with the biometric service provider computer 106. The authentication application 102-B3 may enable a user 100 to verify that they are the account holder associated with a user credential. For example, the authentication application 102-B3 can comprise executable code communicating with the user 100 and an authorizing entity computer 110 to perform an authentication process (e.g., one-time password) and determine an authentication decision.

[0074] In some embodiments, the reader device 102 may further include a contactless element 102-1, which is typically implemented in the form of a semiconductor chip (or other data storage element) with an associated wireless transfer (e.g., data transmission) element, such as an antenna. Data or control instructions that are transmitted via a cellular network may be applied to the contactless element 102-1 by means of a contactless element interface (not shown). Contactless element 102-1 may be capable of transferring and receiving data using a short-range wireless communication capability. Thus, the reader device 102 may be capable of communicating and transferring data or control instructions via both cellular network (or any other suitable wireless network - e.g. the Internet or other data network) and short-range communications. For example, the contactless element 102-I may enable the reader device 102, in conjunction with the processor 102 -A, to obtain a user credential from the user in a contactless interaction using NFC protocol.

[0075] The reader device 102 may also include a processor 102 -A (e.g., a microprocessor) for processing the functions of the reader device 102 and a display 102-G to allow a user to view information. The reader device 102 may further include input elements 102-E, a speaker 102-H, and a biometric reader 102-F. The reader device 102 may also include an antenna 102-D for wireless data transfer. The biometric reader 102-F may include hardware and / or software configured to obtain a biometric sample from a user. For example, the biometric reader 102-F may be a scanner configured to capture a scan of a user’s palm. In some embodiments, the biometric reader 102-F may include a biometric vector calculator 102-F1, which maycomprise executable code for determining a biometric vector from a biometric sample, and deleting the biometric sample after the biometric vector is determined.

[0076] In some embodiments, the biometric sample may include fingerprint data, retinal scan data, digital photograph data (e.g., facial recognition data), DNA data, palm print data, hand geometry data, iris recognition data, gait data, or other similar biometric identifier that would be appreciated by one of ordinary skill in the art with the benefit of this disclosure.

[0077] Referring back to FIG. 1, an enrollment process according to embodiments can now be described.

[0078] An authorizing entity computer 110 may manage accounts (e.g., bank accounts) on behalf of a number of users, wherein each account is identified by a user credential. A token service computer 108 may maintain mappings of user credentials to second tokens. In some embodiments, the token service computer 108 and the processing network computer 104 may be the same entity, and / or may be managed by the same entity.

[0079] In various embodiments, a second token may be a network token which replaces sensitive payment information in a transaction. The second token may be used by the processing network computer 104 during a transaction. For example, in a generic transaction, the processing network computer 104 may include a second token in an authorization request message.

[0080] A user 100 may have an account with the authorizing entity computer 110. In generic methods, the user 100 presents a user credential associated with the account each time that they conduct a transaction. In the exemplary method depicted in FIG. 1, the user 100 may wish to enroll with a biometric service provider computer 106 so that the user does not need to present a user credential (e.g., via a payment card or a mobile device) each time they conduct a transaction.

[0081] A communication session between the entities shown in FIG. 1 may be established in step S101 when enrollment is initiated. An authentication flow at steps S109-S113 secures the communication channel and verifies the identity of the user 100. If the authentication is successful, the communication session is secured forenrollment. However, if the session fails at any given point (e.g., the user fails authentication, the credential is not eligible, the session times out, etc.), then the session may end early and the user 100 may be required to re-authenticate themselves.

[0082] At step S101, the user 100 initiates enrollment via a user interface on the reader device 102. As part of the enrollment process, terms and conditions, such as legal information and user operating regulations are provided to the user 100. If the user 100 agrees to the terms and conditions, the reader device 102 continues enrollment and prompts for a user credential. According to various embodiments, the enrollment process establishes a communication instance where messages transmitted by and received at the reader device 102 are all related as being part of the same instance.

[0083] At step S103, the user 100 provides their user credential to the reader device 103 using any suitable method. At step S103, the reader device 102 can obtain a user credential (e.g., using a user interface). In some embodiments, the user 100 taps their payment card to the reader device 102, and the reader device 102 obtains the user credential through NFC. In other embodiments, the user 100 manually inputs their user credential. The user credential may be a PAN associated with an account managed by authorizing entity computer 110.

[0084] At step S105, after the reader device 102 obtains the user credential, the reader device 102 can obtain a transient token from the processing network computer 104. The reader device 102 can transmit the captured user credential to the processing network computer 104 in a token request message. Upon receiving the token request message, the processing network computer 104 can generate and transmit the transient token in a token response message to the reader device 102. The transient token may be a limited use token (e.g., a short-term token that expires after 15 minutes) which references the user credential. Using the transient token instead of the user credential when sending messages between entities can limit exposure of personally identifiable information. Moreover, the transient token can enable the separation of the enrollment biometric sample and the user credential. According to various embodiments, the transient token is a non-transaction token thatcannot be used to conduct a transaction. For example, the transient token cannot be used in lieu of payment credential during a transaction.

[0085] At step S107, the reader device 102 can provide the transient token to the biometric service provider computer 106 to initiate authentication.

[0086] At step S109, account holder verification is initiated by the biometric service provider computer 106. Account holder verification can provide assurance that the user 100 is genuine and has the authority to request a biometric to be linked to the user credential. The biometric service provider computer 106 may use the transient token received in step S107 from the reader device to initiate a user authentication via the processing network computer 104. For example, the biometric service provider computer 106 may transmit a user authentication request comprising the transient token to the processing network computer 104 (e.g., a payer authentication request).

[0087] At step S111, upon receiving the transient token in the user authentication request from the biometric service provider computer 106, the processing network computer 104 may identify the user and the user account associated with the transient token, and may notify the authorizing entity computer 110 to authenticate the user 100.

[0088] At step S113, the authorizing entity computer 110 can initiate a user authentication flow with the user 100. At step S115, the user 100 can authenticate themselves to the reader device 102. A user interface of the reader device may obtain an authentication response based on user input. For example, the authorizing entity computer 110 may transmit a one-time passcode to a mobile phone of the user 100, and the user 100 may provide an authentication response by entering the one-time passcode to the reader device 102. At step S117, the reader device 102 can forward the authentication response received via the user interface to the authorizing entity computer 110 for verification. The authorizing entity computer 110 can determine if the user 100 is authenticated and transmit the authentication result to the reader device 102.

[0089] According to various embodiments, the authorizing entity computer 110 verification of the account holder may be performed via 3-D Secure Access ControlServer (ACS), mobile banking verification of the account holder with an authentication code, federated login systems, API functionality capable of generating, delivering, and validating data from the biometric service provider computer 106 and shared secrets, one-time password (OTP), activation code, or other shared secret between the authorizing entity computer 110 and the user 100. If the authorizing entity computer 110 determines that there is a need to verify the user 100 requesting enrollment through an explicit verification (e.g., using an OTP or activation code), the shared secret may be delivered to the user 100 through an out-of-band channel.

[0090] At step S119, the biometric service provider computer 106 may transmit a token request message comprising the transient token to the processing network computer 104.

[0091] At step S121, after receiving the transient token from the biometric service provider computer 106, the processing network computer 104 may obtain a second token. The processing network computer 104 may determine the user credential underlying the transient token (e.g., detokenizes the transient token to obtain the user credential), and may transmit a second token request message comprising the user credential to the token service computer 108. The token service computer 108 may generate or retrieve a second token, and transmit the second token to the processing network computer 104 in a token response message. In various embodiments, the second token may include a network token which can be used to process transactions.

[0092] At step S123, the processing network computer 104 determines (e.g., generates or receives) a first token, and stores it in association with the second token. For example, the processing network computer 104 may store a bi-directional mapping of the first token to the second token in a second token vault. While the second token is generated as a transaction token (e.g., can be used as form of payment in a transaction or funds transfer), the first token is a non-transaction token (e.g., it cannot be used as a form of payment in a transaction or funds transfer).

[0093] At step S125, the processing network computer 104 may transmit the first token to the biometric service provider computer 106 in a token response message.

[0094] At step S127, the processing network computer 104 may delete the transient token so that it no longer serves as a reference to the user credential. In some embodiments, the transient token expires. Deleting the transient token and / or setting an expiration of the transient token can improve data confidentiality and integrity because the transient token will be harder to re-use to obtain a user credential and / or obtain information related to the user credential. Additionally, limiting how long the transient token lives for can improve resource (e.g., resource access, account access, etc.) availability because information that can be used to access a resource associated with the user credential is not available after the deletion and / or expiration of the transient token.

[0095] At step S129, the reader device 102 may prompt and / or obtain an enrollment biometric via a user interface (e.g., including one or mor sensors). In certain embodiments, the reader device 102 prompts the user for an enrollment biometric sample and the user 100 provides the enrollment biometric sample to the reader device 102. For example, the user 100 may scan their palm and the reader device 102 can capture the enrollment biometric sample. Step S129 may occur while the successful authentication status of the user 100 is active. For example, if the authorizing entity computer 110 determines that the user 100 is authenticated and transmits the authentication result to the reader device 102 in step S113, step S129 may occur immediately after and / or responsive to receiving the authentication result.

[0096] At step S131, the reader device 102 transmits the enrollment biometric sample to the biometric service provider computer 106. As provided above, the enrollment process may establish a communication instance where messages transmitted by and received at the reader device 102 are all related as being part of the same instance. Accordingly, the biometric service provider computer 106 determine that the enrollment biometric sample is linked to the previously received transient token (or the first token received thereafter).

[0097] At step S133, the biometric service provider computer 106 may obtain the enrollment biometric sample and convert it to a biometric template. For example, in some embodiments, the biometric template is an encrypted derivative of the enrollment biometric sample. The biometric service provider computer 106 discards the enrollment biometric sample and stores the biometric template in association with the first token. The biometric template and the first token may be stored as a bidirectional mapping in a database of biometric templates. It is noted that the biometric service provider computer 106 stores the biometric template associated with the enrollment biometric sample rather than storing the enrollment biometric sample itself because the enrollment biometric sample may be more sensitive than the biometric template. For example, while the biometric sample may be used to identify the person, it is not possible to identify the person using only the biometric template. In various embodiments, the biometric service provider computer 106 may notify the user 100 once enrollment is complete (e.g., via the reader device 102) and / or another device associated with the user 100.

[0098] In other embodiments, a biometric service provider application on the reader device 102 converts the enrollment biometric sample to a biometric template and deletes the biometric sample on behalf of the biometric service provider computer 106. The biometric service provider application may send the biometric template, rather than the enrollment biometric sample, to the biometric service provider computer 106. In these embodiments, the enrollment biometric sample does not leave the reader device 102.

[0099] As shown above, user biometrics and user credentials are stored and accessed by separate entities during enrollment. The biometric service provider computer 106 does not receive the user credential or the second token, and the processing network computer 104 does not receive user biometric data. When enrollment is complete, the biometric service provider computer 106 stores the first token (e.g., non-transaction token) with the biometric template, while the processing network computer 104 stores the first token in association with the second token. Accordingly, if either the biometric service provider computer 106 or the processing network computer 104 is breached, the data stored at either one of these entitiescannot be used by itself to successfully conduct a transaction or a transfer of funds. Additionally, by storing a biometric template and subsequently deleting the enrollment biometric sample, the enrollment biometric sample has a limited risk of exposure.

[0100] FIG. 5 illustrates a reader device method 500 for registering a user biometric to a user credential. The method 500 may relate to the method of FIG. 1 and the reader device 102 of FIG. 4.

[0101] Steps S502-S506 may be similar to steps S101-S103. At step S502, the reader device can receive user input initiating enrollment. At step S504, the reader device can present terms and conditions to the user and the user can accept. At step S506, the reader device can prompt for / request a user credential to register with a biometric. For example, the reader device may present a request for the user to input a user credential for a preferred payment method. The reader device may obtain the user credential from the user via any suitable method (e.g., a user interface).

[0102] At step S508, after receiving the user credential from the user, the reader device can determine if the user credential is eligible to be enrolled. For example, the reader device may check if the user credential is already enrolled, or if the authorizing entity computer supports enrollment. To determine eligibility, the reader device may transmit a request to the processing network computer to check the enrollment status associated with the user credential.

[0103] At step S510, if the user credential is ineligible, the reader device may proceed to step S513 when the reader device may request that the user provide a different credential. For example, if the reader device receives a response message indicating that the user credential is ineligible to enroll, the reader device may cause a user interface of the reader device to present a prompt that requests a different credential to be provided to the reader device (e.g., the user interface and / or another user interface of the reader device). Responsive to step S513 being performed, the method may proceed to step S506.

[0104] At step S510, if the user credential is eligible, the reader device requests that the user authenticate themselves. For example, if the reader device receives a response message indicating that the user credential is eligible to enroll, the readerdevice may launch an authentication application or authorizing entity computer application which prompts the user to authenticate themselves. For example, the reader device may ask the user to provide a code sent to their mobile device by the authorizing entity computer. The information collected during authentication may be transmitted to the authorizing entity computer for verification.

[0105] At step S512, after the user authenticates themselves to the reader device, the reader device can determine if the authentication is successful. For example, after transmitting the authentication information to the authorizing entity computer, the reader device may receive a response from the authorizing entity computer indicating whether or not the authentication is successful.

[0106] At step S514, if the authentication is successful, the reader device may request an enrollment biometric sample (e.g., from the user). The reader device may obtain the enrollment biometric sample from the user via a user interface. For example, in one embodiment the reader device comprises a biometric scanner user interface, and prompts the user to scan a body part (e.g. , user’s palm) over the biometric scanner until the biometric scanner sufficiently captures the enrollment biometric sample. The reader device may transmit the enrollment biometric sample to the biometric service provider computer, and may receive a response confirming receipt.

[0107] At step S516, the reader device can notify the user that the enrollment was successful. In some embodiments, the reader device may prompt the user for account information (e.g., present, using a user interface, a prompt for account information) such as a mobile phone number to be used for account management.

[0108] In various embodiments, the more than one user credential can be enrolled. For example, a first payment method may be linked to a left palm of the user and a second payment method may be linked to a right palm of the user.

[0109] After the user is enrolled (e.g., after step S133 of FIG.1 , after step S512), instead of providing the user credential, embodiments can enable the user to present a biometric sample corresponding to the enrollment biometric sample. As an example, if the enrollment biometric sample is of the user’s palm, the user may scan the samepalm to initiate a transaction. This method is described in further detail below with reference to FIG. 6.

[0110] FIG. 6 shows a method for processing a transaction using biometric verification according to some embodiments of the disclosure. FIG. 6 shows a user 100 (e.g. , user 100 described with respect to FIG. 1 ), a reader device 102 (e.g. , reader device 102 described with respect to FIG. 1), a processing network computer 104 (e.g., processing network computer 104 described with respect to FIG. 1), a biometric service provider computer 106 (e.g., biometric service provider computer 106 described with respect to FIG. 1), and an authorizing entity computer 110 (e.g., an authorizing entity computer 110 described with respect to FIG. 1), which may be the same as in FIG. 1.

[0111] At step S601, using a user device, the user 100 may request access to a resource (e.g., item, good, etc.) from a resource provider (not shown) operating the reader device 102. Prior to granting access to the resource, the resource provider may request payment from the user 100. The resource provider may input a value for the transaction (e.g., a payment amount) to the reader device 102, which may cause a user interface of the reader device to prompt the user 100 to provide a biometric sample. The user 100 may provide the biometric sample (e.g., scan their palm to the reader device 102) to initiate the transaction. The biometric sample is the same body part as provided during enrollment if the user it to be authenticated, otherwise authentication will fail.

[0112] At step S603, after the reader device 102 obtains the biometric sample from the user 100, the reader device 102 can transmit the biometric sample to the biometric service provider computer 106. The reader device 102 may additionally transmit transaction data to the biometric service provider computer 106. The transaction data may comprise the value for the transaction, resource provider identifiers, a time, and / or date of the transaction, etc.

[0113] At step S605, after (e.g., responsive to) receiving the biometric sample and transaction data from the reader device 102, the biometric service provider computer 106 may determine a biometric vector based on the biometric sample. Thebiometric vector may be a digital reference of the biometric sample which can be compared to the biometric template obtained during enrollment. For example, the biometric service provider computer 106 may derive a biometric vector from the biometric sample using a vector derivation algorithm. In various embodiments, the biometric vector is encrypted to obfuscate the biometric sample.

[0114] Atstep S607, after (e.g., responsive to) determining the biometric vector, the biometric service provider computer 106 may delete the biometric sample from memory. Deleting the biometric sample can optimize storage (e.g., by reducing storage capacity requirements, reducing a number of stored entries to be searched through) and enhance security. In the event of a data leak, biometric samples are prevented from being exposed when they are not stored in memory.

[0115] In other embodiments, steps S605 and S607 are skipped if the biometric service provider computer 106 determines that the data packet received from the reader device 102 includes a biometric vector instead of a biometric sample. In embodiments where step S605 is skipped, a biometric service provider application on the reader device 102 can determine the biometric vector of the biometric sample instead of the biometric service provider computer 106. The reader device 102 can then transmit the biometric vector to the biometric service provider computer 106 and discard the biometric sample. Such embodiments may provide different security improvements compared to embodiments where the biometric sample is transmitted to the reader device 102 because regardless of whether the reader device 102 would delete the biometric sample, the biometric sample is not exposed during a transmission process (e.g., the biometric sample may be sniffed, key logged, or otherwise obtained). Further, the biometric sample is not vulnerable to being exposed by the reader device 102 when the reader device 102 does not receive the biometric sample.

[0116] At step S609, the biometric service provider computer 106 can match the biometric vector to a biometric template to identify the user 100. The biometric service provider computer 106 can check a biometric template database (e.g., a database of biometric templates of enrolled users) for the biometric template that matches the biometric vector. For example, the biometric service provider computer106 may perform a number of comparisons (e.g., to a number of different biometric templates in the biometric template database) prior to determining the biometric template matches the biometric vector. By way of example, matching may be performed using cryptographic comparison. In various embodiments, cryptographic comparison may be accomplished by Secure Multi-Party Computation (SMPC), and / or Homomorphic Encryption (HE).

[0117] At step S611, after matching the biometric vector to the biometric template, the biometric service provider computer 106 may determine a first token. The first token may be stored in association with the biometric vector.

[0118] At step S613, after determining the first token, the biometric service provider computer 106 may transmit the first token and the transaction data to the processing network computer 104. The biometric service provider computer 106 may delete the biometric vector from memory (e.g., after transmitting the first token to the processing network computer, after matching the biometric vector to the biometric template).

[0119] At step S615, after receiving the first token and the transaction data from the biometric service provider computer 106, the processing network computer 104 may retrieve the corresponding second token using the first token. For example, the processing network computer 104 may use the first token to look up a mapping in a second token vault. The processing network computer 104 may determine that the first token is stored in association with the second token. The second token may be a proxy for a user credential.

[0120] In some embodiments the transaction data is encrypted (e.g., using a public / private key pair) such that the biometric service provider computer 106 does not see the transaction data. For example, at step S603 the reader device 102 may encrypt the transaction data using a public key of a public / private key pair. When the processing network computer 104 receives the encrypted transaction data at step S615, it deciphers the transaction data using the corresponding private key. However, because the biometric service provider computer 106 does not have the correspondingprivate key, the biometric service provider computer 106 cannot decipher the transaction data.

[0121] At step S617, the processing network computer 104 can generate and transmit an authorization request message to the authorizing entity computer 110. The authorization request message may comprise the second token. In some embodiments, the processing network computer 104 may additionally generate a cryptogram for the transaction and transmit it in the authorization request message. The authorizing entity computer 110 may make an authorization decision. The authorizing entity computer 110 may complete an account-level validation and authorization check using the information provided in the authorization request message. The authorizing entity computer 110 can send an authorization response message comprising the authorization decision to the processing network computer 104.

[0122] FIG. 7 shows a reader device method 700 for processing a transaction using biometric verification according to embodiments of the disclosure. The method 700 may relate to the method of FIG. 6 and the reader device 102 of FIG. 4.

[0123] At step S702, the reader device can retrieve transaction data. The reader device may receive the transaction data from a user interface. For example, a resource provider may input a transaction amount to the reader device using the user interface of the reader device. The transaction data may include a date of the transaction, a time of the transaction, and / or a set of resource provider identifiers (e.g., a merchant ID).

[0124] At step S704, the reader device can display the transaction amount and may present a prompt that requests a user credential to be provided. For example, the prompt may request the user to provide a user credential via biometric identification using a user interface of the reader device 102. By way of example, the user may be prompted to scan their palm to a user interface biometric scanner on the reader device. In other embodiments, other biometric reading devices, such as a microphone, a fingerprint reader, and / or a camera, etc. can be used by the readerdevice to retrieve a biometric sample. The data captured from the biometric scanner can be used to extract a biometric sample of the user.

[0125] At step S706, the successful capture of the biometric sample can initiate a matching process where the reader device interacts with the biometric service provider computer to cause the biometric service provider computer to match the biometric sample to a biometric template stored in a biometric template database accessible by the biometric service provider computer. The reader device may transmit the biometric sample and transaction data to the biometric service provider computer to determine a matching biometric template. The reader device may receive the result of the matching process (e.g., success or failure) from the biometric service provider computer

[0126] At step S708, if a matching biometric template is not found, the reader device may receive a failure response from the biometric service provider computer. Responsive to receiving the failure response, the reader device may present a prompt that requests a different biometric sample to be enrolled and / or submitted. The prompt may be presented using a user interface of the reader device and may be presented to the user.

[0127] At step S710, if the matching biometric template is found, the transaction processing process described in connection with FIG. 6 can be performed. The reader device can receive a notification of the authorization result indicating whether or not the transaction is authorized by the authorizing entity computer. If the authorization was successful, at step S714 the reader device may display a success message using a user interface of the reader device. Otherwise, at step S716 if the authorization was declined, a failure message may be displayed using a user interface of the reader device.

[0128] FIG. 8 shows a method for processing a transaction using biometric verification according to some embodiments of the disclosure. FIG. 8 shows a user 100 (e.g. , user 100 described with respect to FIG. 1 ), a reader device 102 (e.g. , reader device 102 described with respect to FIG. 1), a processing network computer 104 (e.g., processing network computer 104 described with respect to FIG. 1), a biometricservice provider computer 106 (e.g., biometric service provider computer 106 described with respect to FIG. 1), and an authorizing entity computer 110 (e.g., an authorizing entity computer 110 described with respect to FIG. 1), which may be the same as in FIG. 1.

[0129] Step S801 may be performed like step S601 described above.

[0130] At step S803, after the reader device 102 obtains the biometric sample from the user 100, a biometric service provider application on the reader device 102 may determine a biometric vector of the biometric sample. The biometric vector may be a digital reference of the biometric sample which can be compared to the biometric template obtained during enrollment. For example, the biometric service provider application may derive the biometric vector from the biometric sample using a vector derivation algorithm. In certain embodiments, the biometric vector is encrypted to obfuscate the biometric sample.

[0131] After (e.g., responsive to) determining the biometric vector, the biometric service provider application may delete the biometric sample from memory. Deleting the biometric sample can optimize storage (e.g., by reducing storage capacity requirements, reducing a number of stored entries to be searched through) and enhance security. In the event of a data leak, biometric samples are prevented from being exposed when they are not stored in memory.

[0132] The biometric service provider application can match the biometric vector to a biometric template to identify the user 100. The biometric service provider application can check a biometric template database (e.g., a database of biometric templates of enrolled users) for the biometric template that matches the biometric vector. For example, the biometric service provider application may perform a number of comparisons (e.g., to a number of different biometric templates in the biometric template database) prior to determining the biometric template matches the biometric vector. By way of example, matching may be performed using cryptographic comparison. In various embodiments, cryptographic comparison may be accomplished by Secure Multi-Party Computation (SMPC), and / or Homomorphic Encryption (HE).

[0133] After matching the biometric vector to the biometric template, the biometric service provider application may determine a first token associated with the biometric template. The first token may be stored in association with the biometric vector.

[0134] At step 803, the reader device 102 may generate a request for a first network token and a cryptogram. The request may include the first token. The request may be performed using an Application Programming Interface (API). The request may be transmitted to the biometric service provider computer 106. In certain embodiments, after (e.g., responsive to) transmitting the request to the biometric service provider computer 106, the reader device 102 may discard the biometric sample. In certain embodiments, after (e.g., responsive to) determining the first token, the reader device 102 may discard the biometric sample.

[0135] At step S805, the biometric service provider computer 106 may determine the first network token using the first token. In certain embodiments, the first network token is determined by performing a lookup based on the first token. The first network token may be determined by requesting the first network token from the processing network computer 104. The first network token may be associated with the reader device 102 and / or user 100. In certain embodiments, the first network token is managed by biometric service provider computer 106.

[0136] At step S807, the biometric service provider computer 106 may cause a cryptogram to be generated. The cryptogram may be generated based on transaction data such as a value for the transaction, a resource provider identifier, a time of the transaction, and / or a date of the transaction, etc. The cryptogram may be a one-time use cryptogram. The biometric service provider computer 106 may cause the cryptogram to be generated by requesting a token service computer (e.g., VISA token service (VTS)) to generate the cryptogram. In certain embodiments, the biometric service provider computer 106 generates the cryptogram. In certain embodiments, the biometric service provider computer 106 requests the cryptogram from the processing network computer 104 using the first token.

[0137] At step S808, the biometric service provider computer 106 may transmit the first token and / or the cryptogram to the processing network computer 104.

[0138] At step S809, the processing network computer 104 may determine a second network token and / or the cryptogram based on the first token. The second network token and / or the cryptogram may be associated with the first token. The first token may have been received by the processing network computer 104 from the biometric service provider computer 106.

[0139] At step S811, the processing network computer 104 may transmit the second network token and / or the cryptogram to the biometric service provider computer 106.

[0140] At step S813, the biometric service provider computer 106 may transmit the cryptogram and / or the second network token to the reader device 102. The second network token and / or the cryptogram may be encrypted (e.g., using a public key of the reader device 102).

[0141] At step S815, the reader device 102 may receive the cryptogram and / or the second network token from the biometric service provider computer 106. After (e.g., responsive to) receiving the cryptogram and / or the second network token, the reader device 102 may decrypt the cryptogram and / or the second network token (e.g., using a private key of the reader device 102).

[0142] At step S817, the reader device 102 may transmit the cryptogram and / or the second network token to the processing network computer 104. The reader device 102 may additionally transmit transaction data to the processing network computer 104.

[0143] At step S819, the processing network computer 104 may transmit the cryptogram and / or the second network token to the authorizing entity computer 110 (e.g., included in a transaction authorization request message). The processing network computer 104 may additionally transmit transaction data to the authorizing entity computer 110.

[0144] Embodiments of the disclosure have a number of technical advantages. Methods according to embodiments enable users to initiate an interaction by providing a biometric sample, while maintaining secure and separate access and storage of sensitive user data. Conveniently, users do not need to provide a user credential nor authenticate themselves at the time of each transaction. The use of tokens and separation of biometric data from other user data (e.g., a second token, a payment token) protects sensitive data from hacking or man-in-the middle attacks.

[0145] Embodiments further provide data security improvement (e.g., improvement in secure storage of sensitive information). According to embodiments, the biometric template and the transaction token are stored in a distributed manner (e.g., by at least two separate entities). As compared to a single entity storing both biometric data and transaction data, with embodiments, a data breach on an entity would result in less exposure of sensitive user information. For example, with embodiments, a data breach on the biometric service provider would not expose user transaction data, making it more difficult for a fraudster to conduct fraudulent transactions. Embodiments thus reduce the time and computing power used to identify and reverse fraudulent transactions.

[0146] Although the steps in the flowcharts and process flows described above are illustrated or described in a specific order, it is understood that embodiments may include methods that have the steps in different orders. In addition, steps may be omitted or added and may still be within embodiments.

[0147] Any of the software components or functions described in this application may be implemented as software code to be executed by a processor using any suitable computer language such as, for example, Java, C, C++, C#, Objective-C, Swift, or scripting language such as Perl or Python using, for example, conventional or object-oriented techniques. The software code may be stored as a series of instructions or commands on a computer readable medium for storage and / or transmission, suitable media include random access memory (RAM), a read only memory (ROM), a magnetic medium such as a hard-drive or a floppy disk, or an optical medium such as a compact disk (CD) or DVD (digital versatile disk), flash memory,and the like. The computer readable medium may be any combination of such storage or transmission devices.

[0148] Such programs may also be encoded and transmitted using carrier signals adapted for transmission via wired, optical, and / or wireless networks conforming to a variety of protocols, including the Internet. As such, a computer readable medium according to an embodiment may be created using a data signal encoded with such programs. Computer readable media encoded with the program code may be packaged with a compatible device or provided separately from other devices (e.g., via Internet download). Any such computer readable medium may reside on or within a single computer product (e.g., a hard drive, a CD, or an entire computer system), and may be present on or within different computer products within a system or network. A computer system may include a monitor, printer, or other suitable display for providing any of the results mentioned herein to a user.

[0149] The above description is illustrative and is not restrictive. Many variations will become apparent to those skilled in the art upon review of the disclosure. The scope of the invention should, therefore, be determined not with reference to the above description, but instead should be determined with reference to the pending claims along with their full scope or equivalents.

[0150] One or more features from any embodiment may be combined with one or more features of any other embodiment without departing from the scope of the invention.

[0151] As used herein, the use of "a," "an," or "the" is intended to mean "at least one," unless specifically indicated to the contrary.

Claims

WHAT IS CLAIMED IS:

1. A method comprising:receiving, by a biometric service provider computer from a reader device, a biometric sample and transaction data associated with a transaction;determining, by the biometric service provider computer, a biometric vector based on the biometric sample;discarding, by the biometric service provider computer, the biometric sample;matching, by the biometric service provider computer, the biometric vector to a biometric template;retrieving, by the biometric service provider computer, a first token associated with the biometric template, wherein the first token is a nontransaction token that is not valid for conducting transactions;discarding, by the biometric service provider computer, the biometric vector; andtransmitting, by the biometric service provider computer, the transaction data to a processing network computer, wherein the processing network computer processes the transaction using the transaction data and a second token associated with the first token.

2. The method of claim 1 , further comprising:prior to receiving the biometric sample, receiving, by the biometric service provider computer from the reader device, a transient token, wherein the transient token is generated by the processing network computer in association with a user credential and provided to the reader device;transmitting, by the biometric service provider computer to the processing network computer, a token request message comprising the transient token;receiving, by the biometric service provider computer, the first token from the processing network computer;receiving, by the biometric service provider computer, an enrollment biometric sample;generating, by the biometric service provider computer, the biometric template based on the enrollment biometric sample;discarding, by the biometric service provider computer, the enrollment biometric sample; andstoring, by the biometric service provider computer, the biometric template in a database of biometric templates in association with the first token.

3. The method of claim 2 wherein the second token is a proxy for the user credential.

4. The method of claim 2 wherein the transient token is a limited use token.

5. The method of claim 2, further comprising:prior to receiving the enrollment biometric sample, initiating, by the biometric service provider computer, an authentication process using the transient token.

6. The method of claim 1 , wherein the second token is a network token.

7. The method of claim 1 , further comprising:matching, by the biometric service provider computer, the biometric sample to the biometric vector by transaction data comprises a transaction amount, wherein the processing network computer processes the transaction by transmitting an authorization request message comprising the second token and the transaction amount to an authorizing entity computer.

8. The method of claim 1 , wherein the transaction data is encrypted by the reader device using a public key, and wherein the processing network computer processes the transaction by decrypting the transaction data with a private key corresponding to the public key to obtain a transaction amount, and transmitting an authorization request message to anauthorizing entity computer, wherein the authorization request message comprises the second token and the transaction amount.

9. The method of claim 1 , further comprising:retrieving, by the biometric service provider, the second token stored in association with the first token.

10. The method of claim 1 , wherein the second token includes a network token.

11. A biometric service provider computer comprising:a processor; anda computer readable medium comprising code, that when executed by the processor, causes the processor to perform steps comprising:receiving from a reader device, a biometric sample and transaction data associated with a transaction;determining a biometric vector based on the biometric sample; discarding the biometric sample;matching the biometric vector to a biometric template; retrieving a first token associated with the biometric template, wherein the first token is a non-transaction token that is not valid for conducting transactions;discarding the biometric vector; andtransmitting the transaction data to a processing network computer, wherein the processing network computer processes the transaction using the transaction data and a second token associated with the first token.

12. The biometric service provider computer of claim 11 , wherein the code, that when executed by the processor, further causes the processor to perform steps comprising:prior to receiving the biometric sample, receiving from the reader device, a transient token, wherein the transient token is generated by the processing network computer in association with a user credential and provided to the reader device;transmitting to the processing network computer, a token request message comprising the transient token;receiving the first token from the processing network computer; receiving an enrollment biometric sample;generating the biometric template based on the enrollment biometric sample;discarding the enrollment biometric sample; andstoring the biometric template in a database of biometric templates in association with the first token.

13. The biometric service provider computer of claim 12, wherein the second token is a proxy for the user credential.

14. The biometric service provider computer of claim 12, wherein the transient token is a limited use token.

15. The biometric service provider computer of claim 12 wherein the code, that when executed by the processor, further causes the processor to perform steps comprising:prior to receiving the enrollment biometric sample, initiating, by the biometric service provider computer, an authentication process using the transient token.

16. The biometric service provider computer of claim 11 , wherein the second token is a network token.

17. The biometric service provider computer of claim 11 , wherein the transaction data comprises a transaction amount, and the processing network computer processes the transaction by transmitting an authorization request message comprising the second token and the transaction amount to an authorizing entity computer.

18. The biometric service provider computer of claim 11 , wherein the biometric service provider computer comprises a database comprising mappings of biometric templates to first tokens.

19. The biometric service provider computer of claim 11 , wherein the biometric sample is a scan of a user’s palm.

20. The biometric service provider computer of claim 11 , wherein the reader device is a mobile phone.