IP Library › Granted Patent US 11,463,257
Granted Patent B2
US 11,463,257 · App. 16/761,648 · Granted Oct 4, 2022

Biometric sensor on portable device

Inventors: Yuexi Chen (Foster City, CA); Garth Petersen (Belmont, CA)
Assignee: Visa International Service Association
H04L9/3231H04L9/3234H04L9/3239H04L9/3247H04L63/0853H04L63/0861H04L63/126H04L2463/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,463,257
App. No.
16/761,648
Granted
Oct 4, 2022
Kind
B2
Abstract

A method and system for secure remote digital interactions through the use of biometric templates is disclosed. In one example, the method includes an interaction that prompts the use of obtaining a first biometric template and comparing it to a second biometric template to determine if they match. The match process is performed on a portable device.

Claims (36)

1. A method comprising:

establishing, a first communication between a user device and a resource provider computer operating a host site in an interaction between the host site and a user of the user device;

after establishing the first communication, establishing, a second communication between the user device and a portable device of the user;

capturing, by the portable device, a biometric sample of the user;

converting, by the portable device, the biometric sample into a first biometric template;

comparing, by the portable device, the first biometric template with a second biometric template stored on the portable device, and determining a match result;

receiving, by the portable device from the resource provider computer, via the user device, interaction data comprising a transaction amount;

generating, by the portable device, a cryptogram by encrypting at least the interaction data comprising the transaction amount, access data stored on the portable device, and the match result, or a derivative of the interaction data comprising the transaction amount, the access data, and the match result with an encryption key; and

transmitting, by the portable device, the cryptogram and the access data stored on the portable device, to the resource provider computer via the user device, wherein the resource provider computer generates and transmits an authorization request message comprising the access data, the transaction amount and the cryptogram to a remote server computer, which verifies the cryptogram by decrypting the cryptogram to recover inputs to the cryptogram including the interaction data comprising the transaction amount and the match result, or the derivative of the interaction data comprising the transaction amount, the access data, and the match result, analyzes the match result or the derivative of the interaction data comprising the transaction amount, the access data, and the match result, verifies the cryptogram by comparing the interaction data comprising the transaction amount from the cryptogram to the interaction data comprising the transaction amount in the authorization request message, and by comparing the access data in the cryptogram to the access data in the authorization request message, and allows the interaction to continue using the access data based upon the verification of the cryptogram and the analysis of the match result.

2. The method of claim 1 , wherein the encryption key is symmetric key.

3. The method of claim 1 , wherein the portable device is in the form of a card.

4. The method of claim 1 , wherein the derivative of the interaction data is a hash of the interaction data and wherein the method further comprises:

hashing the interaction data.

5. The method of claim 1 , wherein the biometric sample is a fingerprint, a retinal scan, a facial scan, or a voice sample.

6. The method of claim 1 , wherein the remote server computer is an authorizing entity computer configured to allow or deny access to secure data.

7. The method of claim 1 , wherein the remote server computer is a processing computer.

8. The method of claim 1 , further comprising, prior to receiving the interaction data:

transmitting, by the portable device to the remote server computer, a request for the interaction data.

9. A portable device capable of being coupled to a user device, the user device capable of establishing, a first communication between the user device and a resource provider computer operating a host site in an interaction between the host site and a user of the user device, comprising:

a processor;

a memory; and

a computer readable medium, the computer readable medium comprising code, executable by the processor, to implement a method comprising:

after establishing the first communication, establishing, a second communication between the user device and the portable device of the user;

capturing, a biometric sample of the user;

converting, the biometric sample into a first biometric template;

comparing, the first biometric template with a second biometric template stored on the portable device, and determining a match result;

receiving from the resource provider computer, via the user device, interaction data comprising a transaction amount;

generating, a cryptogram by encrypting at least the interaction data comprising the transaction amount, access data stored on the portable device, and the match result, or a derivative of the interaction data comprising the transaction amount, the access data stored on the portable device, and the match result, with an encryption key; and

transmitting, the cryptogram and the access data stored on the portable device, to the resource provider computer via the user device, wherein the resource provider computer generates and transmits an authorization request message comprising the access data, the transaction amount and the cryptogram to a remote server computer, which verifies the cryptogram by decrypting the cryptogram to recover inputs to the cryptogram including the interaction data and the match result, or the derivative of the interaction data and the match result, analyzes the match result or the derivative of the interaction data comprising the transaction amount, the access data, and the match result, verifies the cryptogram by comparing the interaction data comprising the transaction amount from the cryptogram to the interaction data comprising the transaction amount in the authorization request message, and by comparing the access data in the cryptogram to the access data in the authorization request message, and allows the interaction to proceed using the access data based upon the verification of the cryptogram and the analysis of the match result.

10. The portable device of claim 9 , wherein the encryption key is a symmetric key.

11. The portable device of claim 9 , wherein the portable device is in the form of a card.

12. The portable device of claim 9 , wherein the portable device is in the form of a phone.

13. The portable device of claim 9 , wherein the biometric sample is a fingerprint, a retinal scan, a facial scan, or a voice sample.

14. The portable device of claim 9 , wherein the portable device comprises a reader device configured to read data from the portable device.

15. The portable device of claim 9 , wherein the encryption key is stored in the memory and wherein the memory is a secure memory.

16. The portable device of claim 9 , wherein the interaction data comprises a time stamp.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 7, 2020
From: CHEN, YUEXI; PETERSEN, GARTH
To: VISA INTERNATIONAL SERVICE ASSOCIATION
Reel/Frame 052601/0145 →
Continuity (1)
Related Publication 20210184857A1 · Jun 17, 2021
Cited By (1)
US 12,432,065