IP Library › Granted Patent US 12,361,422
Granted Patent B2
US 12,361,422 · App. 18/130,094 · Granted Jul 15, 2025

Biometric-based identity verification using zero-knowledge proofs

Inventors: Andras Ferenczi (Peoria, AZ); Alaric Eby (Scottsdale, AZ); Subrahmanyam Venkata Vishnuvajhala (Phoenix, AZ)
Assignee: AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.
G06Q20/40145G06Q20/3829
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,361,422
App. No.
18/130,094
Granted
Jul 15, 2025
Kind
B2
Abstract

Disclosed are various embodiments for verifying a consumer's identity during card-not-present (CNP) transactions using biometric data (e.g., fingerprint, retina scan, iris scan, handprint, voice sample, face scan, etc.) of the consumer obtained using a biometric security device. A zero-knowledge proof algorithm is used to verify the identity of a user initiating a transaction without disclosing personal information (e.g., biometric data) of the user to the issuer, merchant, recipient and/or other party, thereby preserving the privacy of the user.

Claims (40)

1. A system, comprising:

a client device comprising a processor and a memory; and

machine-readable instructions stored in the memory that, when executed by the processor, cause the client device to at least:

transmit a request to initiate a transaction to a transaction terminal;

receive a verification request from the transaction terminal, the verification request requesting verification of a user associated with the transaction and the client device, the verification request including transaction details associated with the transaction;

send a signature request to a biometric security device, the signature request including the transaction details;

receive signed transaction details and a public key from the biometric security device, the signed transaction details being signed using a private key generated based at least in part on biometric data associated with the user;

generate a proof of membership using a prover kit and the public key; and

transmit the proof of membership, the public key and the signed transaction details to the transaction terminal as a response to the verification request.

2. The system of claim 1 , wherein the proof of membership comprises a zero-knowledge proof configured to verify an identity of the user associated with the transaction.

3. The system of claim 1 , wherein the prover kit is part of a zero-knowledge proof algorithm, and when executed, the machine-readable instructions further cause the client device to at least receive the prover kit from a security provider.

4. The system of claim 1 , wherein the biometric data comprises at least one of a fingerprint, a handprint, a retinal scan, a facial scan, or a voice sample.

5. The system of claim 1 , wherein the biometric security device is integrated with the client device.

6. The system of claim 1 , wherein the public key is derived from the private key.

7. The system of claim 1 , wherein the biometric security device is communicatively coupled to the client device via a wired or wireless connection.

8. A method, comprising:

transmitting a request to initiate a transaction to a transaction terminal;

receiving a verification request from the transaction terminal, the verification request requesting verification of a user associated with the transaction and a client device, the verification request including transaction details associated with the transaction;

sending a signature request to a biometric security device, the signature request including the transaction details;

receiving signed transaction details and a public key from the biometric security device, the signed transaction details being signed using a private key generated based at least in part on biometric data associated with the user;

generating a proof of membership using a prover kit and the public key; and

transmitting the proof of membership, the public key and the signed transaction details to the transaction terminal as a response to the verification request.

9. The system of claim 8 , wherein the proof of membership comprises a zero-knowledge proof configured to verify an identity of the user associated with the transaction.

10. The system of claim 8 , wherein the prover kit is part of a zero-knowledge proof algorithm, and further comprising receiving the prover kit from a security provider.

11. The system of claim 8 , wherein the biometric data comprises at least one of a fingerprint, a handprint, a retinal scan, a facial scan, or a voice sample.

12. The system of claim 8 , wherein the biometric security device is integrated with the client device.

13. The system of claim 8 , wherein the public key is derived from the private key.

14. The system of claim 8 , wherein the biometric security device is communicatively coupled to the client device via a wired or wireless connection.

15. A non-transitory, computer-readable medium, comprising machine-readable instructions that, when executed by a processor of a client device, cause the computing device to at least

transmit a request to initiate a transaction to a transaction terminal;

receive a verification request from the transaction terminal, the verification request requesting verification of a user associated with the transaction and the client device, the verification request including transaction details associated with the transaction;

send a signature request to a biometric security device, the signature request including the transaction details;

receive signed transaction details and a public key from the biometric security device, the signed transaction details being signed using a private key generated based at least in part on biometric data associated with the user;

generate a proof of membership using a prover kit and the public key; and

transmit the proof of membership, the public key and the signed transaction details to the transaction terminal as a response to the verification request.

16. The non-transitory, computer-readable medium of claim 15 , wherein the proof of membership comprises a zero-knowledge proof configured to verify an identity of the user associated with the transaction.

17. The non-transitory, computer-readable medium of claim 15 , wherein the prover kit is part of a zero-knowledge proof algorithm, and when executed, the machine-readable instructions further cause the client device to at least receive the prover kit from a security provider.

18. The non-transitory, computer-readable medium of claim 15 , the biometric data comprises at least one of a fingerprint, a handprint, a retinal scan, a facial scan, or a voice sample.

19. The non-transitory, computer-readable medium of claim 15 , wherein the biometric security device is integrated with the client device.

20. The non-transitory, computer-readable medium of claim 15 , wherein the public key is derived from the private key.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 4, 2023
From: FERENCZI, ANDRAS; EBY, ALARIC; VISHNUVAJHALA, SUBRAHMANYAM VENKATA
To: AMERICAN EXPRESS TRAVEL RELATED SERVICES COMPANY, INC.
Reel/Frame 064490/0992 →
Continuity (2)
Continuation 17148718 · Jan 14, 2021
Related Publication 20230237488A1 · Jul 27, 2023
References Cited (63)
US 7059531B2 · Beenau · 2006 [cited by examiner]
US 8527758B2 · Mansour · 2013 [cited by applicant]
US 9264902B1 · Ward · 2016 [cited by examiner]
US 10380566B2 · Klein · 2019 [cited by examiner]
US 10868672B1 · Farrugia · 2020 [cited by applicant]
US 10931663B2 · Roper · 2021 [cited by examiner]
US 11037165B2 · Perezleon · 2021 [cited by examiner]
US 11423403B2 · Spichek · 2022 [cited by examiner]
US 11537830B2 · Sinha · 2022 [cited by examiner]
US 12069182B2 · Annam · 2024 [cited by examiner]
US 20020023032A1 · Pearson · 2002 [cited by examiner]
US 20040098350A1 · Labrou · 2004 [cited by examiner]
US 20040215575A1 · Garrity · 2004 [cited by examiner]
US 20070052517A1 · Bishop · 2007 [cited by examiner]
US 20090132813A1 · Schibuk · 2009 [cited by examiner]
US 20090307142A1 · Mardikar · 2009 [cited by examiner]
US 20110060903A1 · Yoshida et al. · 2011 [cited by applicant]
US 20120210406A1 · Camenisch · 2012 [cited by applicant]
US 20150046707A1 · Atherton · 2015 [cited by applicant]
US 20150193777A1 · Aidasani · 2015 [cited by examiner]
US 20150220932A1 · Mardikar · 2015 [cited by examiner]
US 20160019523A1 · Uzo · 2016 [cited by examiner]
US 20180026413A1 · Dambach · 2018 [cited by applicant]
US 20180039964A1 · Sharma · 2018 [cited by examiner]
US 20180121925A1 · Gaikar · 2018 [cited by examiner]
US 20180211022A1 · Wagner · 2018 [cited by examiner]
US 20180268398A1 · Park · 2018 [cited by applicant]
US 20180268412A1 · Phadke · 2018 [cited by applicant]
US 20190043281A1 · Aman · 2019 [cited by applicant]
US 20200067907A1 · Avetisov · 2020 [cited by applicant]
US 20200126075A1 · Fisch · 2020 [cited by applicant]
US 20200167775A1 · Reese · 2020 [cited by examiner]
US 20200233943A1 · Adjaz · 2020 [cited by examiner]
US 20210049588A1 · Kamal · 2021 [cited by applicant]
US 20210103648A1 · Wagner · 2021 [cited by applicant]
US 20210224814A1 · Phadke · 2021 [cited by applicant]
US 20210287209A1 · Nelluri · 2021 [cited by examiner]
US 20210344674A1 · Chen · 2021 [cited by examiner]
US 20220044252A1 · Abouelenin · 2022 [cited by examiner]
US 20230137135A1 · Gupta · 2023 [cited by examiner]
US 20230353360A1 · Law · 2023 [cited by examiner]
US 20230410103A1 · Ferenczi · 2023 [cited by examiner]
AU 2020101940A4 · 2020 [cited by examiner]
CA 3021843A1 · 2019 [cited by examiner]
CN 106899552B · 2020 [cited by examiner]
EP 2343678A1 · 2011 [cited by applicant]
KR 1020170039642 · 2017 [cited by applicant]
KR 20250029064A · 2023 [cited by examiner]
RU 2547621C2 · 2015 [cited by examiner]
WO WO2006014205A2 · 2006 [cited by examiner]
WO WO2008023114A1 · 2008 [cited by examiner]
WO WO2017070707A1 · 2017 [cited by examiner]
WO WO2018234882A1 · 2018 [cited by examiner]
WO 2019171163A1 · 2019 [cited by applicant]
WO WO2019169470A1 · 2019 [cited by examiner]
WO WO2023072115A1 · 2023 [cited by examiner]
WO WO2023248213A1 · 2023 [cited by examiner]
Z. Saquib, M. Kumar, K. K. Kamal and B. Varyani, “Secure solution: One time mobile originated PKI,” 2017 Annual IEEE International Systems Conference (SysCon), Montreal, QC, Canada, 2017. https://ieeexplore.ieee.org/doc… [cited by examiner]
Y. Liu, G. Sun and S. Schuckers, “Enabling Secure and Privacy Preserving Identity Management via Smart Contract,” 2019 IEEE Conference on Communications and Network Security (CNS), Washington, DC, USA, 2019. https://iee… [cited by examiner]
Website entitled: “Online Shopping Secured with Visa”, https://usa.visa.com/pay-with-visa/featured-technologies/verified-by-visa.html downloaded Jan. 5, 2021 9:51:50 AM. [cited by applicant]
PCT International Search Report in co-pending, related PCT Application No. PCT/US2022/070071, mailed May 4, 2022. [cited by applicant]
Anonymous: “Zero-knowledge proof—Wikipedia”, Feb. 19, 2018 (Feb. 19, 2018). [cited by applicant]
European Search Report in Application No. 22740243.5-1218 dated Oct. 28, 2024. [cited by applicant]