IP Library Granted Patent US 12,039,026
Granted Patent B2
US 12,039,026 · App. 17/596,998 · Granted Jul 16, 2024

Provisioning biometrics tokens

Inventors: Fabrice Jogand-Coulomb (Aix en Provence, FR); Calum Bunney (Marstrand, SE); Caleb Wattles (Paris, FR)
Assignees: ASSA ABLOY AB; HID Global CID SAS
G06F21/32G06F21/64H04L9/0825H04L9/3213H04L9/3231H04L9/3271
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,039,026
App. No.
17/596,998
Granted
Jul 16, 2024
Kind
B2
Abstract

A computing device implemented method of identity authentication comprises receiving a biometric token; performing a biometric capture of a user; converting the biometric capture into a biometric bitstream; recovering a predictable seed of data using the biometric bitstream and the biometric token; using the recovered predictable seed of data to produce challenge response data sent to a verifier device in response to a challenge message received from the verifier device; and verifying the challenge response data using identity data of the user.

Claims (49)

1. A computing device implemented method of identity authentication, the method comprising:

using a credential device:

receiving a biometric token, wherein the biometric token includes a predictable seed of data;

performing a biometric capture of a user;

converting the biometric capture into a biometric bitstream;

recovering the predictable seed of data using the biometric bitstream and the biometric token;

using the recovered predictable seed of data to produce challenge response data sent to a verifier device in response to a challenge message received from a verifier device; and

using the verifier device:

verifying the challenge response data using identity data of the user.

2. The method of claim 1 , wherein the recovering the predictable seed of data includes applying the biometric bitstream and the biometric token to an error correction code (ECC) algorithm to recover the predictable seed of data.

3. The method of claim 1 , wherein the recovering the predictable seed of data includes recovering a signing key used to sign the challenge response data.

4. The method of claim 1 , wherein the recovering the predictable seed of data includes recovering a split key used to sign the challenge response data.

5. The method of claim 4 , wherein the recovered split key is one of multiple split keys, and only a subset of the multiple split keys is needed for a valid signature of the challenge response data.

6. The method of claim 1 , wherein verifying the challenge response data includes verifying a digital signature of the challenge response data over a public key associated with the biometric token.

7. The method of claim 1 , wherein verifying the challenge response data includes verifying a digital signature over a public key included in the identity data of the user.

8. The method of claim 1 , including sending identity data to the credential device when the identity of the user is verified.

9. The method of claim 1 , including generating a split key on the credential device when the identity of the user is verified.

10. The method of claim 1 , including generating the biometric token for a split key and storing the biometrics biometric token on the credential device.

11. The method of claim 1 , including, using the verifier device:

producing another biometric capture of the user;

converting the other biometric capture into a biometric bitstream;

computing the biometric token using the biometric bitstream and secret data; and

sending the biometric token to the credential device.

12. The method of claim 11 , wherein the producing another biometric capture includes producing the other biometric capture using a stored biometric of the user.

13. The method of claim 1 , including, using the credential device:

sending a request for provision of identity data from the verifier device; and

receiving the biometric token and the challenge message in response to the request.

14. The method of claim 13 , including communicating the request for provision of identity data, the biometric token, and the challenge message between the credential device and the verifier device via an Internet network.

15. A computing device implemented method of identity authentication, the method comprising:

using a credential device:

transmitting a request message to a verifier device;

receiving a challenge message in response to the request message;

performing a biometric capture of a user and converting the biometric capture into a biometric bitstream;

recovering a signature key using the biometric bitstream and a biometric token stored in the credential device, wherein the biometric token includes the signature key;

using the recovered signature key to sign response data of a response to the challenge message; and

sending the signed response data to the verifier device.

16. The method of claim 15 , including the verifier device verifying the response data and associating identification data of the credential device to a secured account using the verifier device.

17. The method of claim 15 ,

wherein the recovering the signature key includes recovering a first split key using the biometric bitstream and the biometric token; and

wherein signing the response data includes signing the response data using the recovered first split key and a second split key stored in the credential device.

18. The method of claim 15 ,

wherein the recovering the signature key includes recovering a first split key using the biometric bitstream and the biometric token; and

wherein signing the response data includes signing the response data by threshold cryptography using the recovered first split key and a second split key stored in one of the credential device or an authentication server.

19. The method of claim 15 , wherein the request message and the challenge message are communicated between the credential device and the verifier device via an Internet network.

20. A non-transitory computer-readable storage medium including instructions that, when executed by processing circuitry of a credential device, cause the processing circuitry to perform acts comprising:

performing a biometric capture of a user and converting the biometric capture into a biometric bitstream;

recovering a signature key using the biometric bitstream and a biometric token, wherein the biometric token includes the signature key;

using the recovered signature key to sign data to sign response data for a response to a challenge message; and

sending the signed response data to the verifier device.

Assignments (5)
CHANGE OF NAME Recorded Oct 23, 2025
From: HID GLOBAL CID SAS
To: TOPPAN SECURITY SAS
Reel/Frame 073225/0558 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2025
From: ASSA ABLOY AB
To: TOPPAN SECURITY SAS
Reel/Frame 071533/0670 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2022
From: JOGAND-COULOMB, FABRICE
To: HID GLOBAL CID SAS
Reel/Frame 061290/0502 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEMNT AGREEMENT TO INCLUDE PAGE 4/4 THAT WAS INADVERTENTLY LEFT OFF WHEN PREVIOUSLY RECORDED AT REEL: 061255 FRAME: 0199. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Oct 3, 2022
From: BUNNEY, CALUM; WATTLES, CALEB
To: ASSA ABLOY AB
Reel/Frame 061592/0111 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2022
From: BUNNEY, CALUM; WATTLES, CALEB
To: ASSA ABLOY AB
Reel/Frame 061255/0199 →
Continuity (1)
Related Publication 20220300592A1 · Sep 22, 2022