IP Library Granted Patent US 10,050,791
Granted Patent B2
US 10,050,791 · App. 14/380,535 · Granted Aug 14, 2018

Method for verifying the identity of a user of a communicating terminal and associated system

Inventors: Guillaume Berteau (Paris, FR); Bruno Benteo (Paris, FR)
Assignee: Morpho
H04L9/3231G06F21/32G06F21/34G06F21/35H04L9/3234H04L9/3271H04L63/0861H04W12/06H04L63/0823H04L2463/082H04W4/008H04W4/80
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,050,791
App. No.
14/380,535
Granted
Aug 14, 2018
Kind
B2
Abstract

A method for verifying identity of a user of a communicating terminal, including: a preliminary operation including: communicating a first piece of identity data of a user to at least one server, generating a second piece of identity data of the user from the server, the second piece of data defining a derived identity of the user, and storing the second piece of identity data in a secure memory of the terminal; an operation for identity verification, including: transmitting a token for encryption from the server to the terminal, using the second piece of data at the terminal at least to generate an encryption of the token, the encrypted token being transmitted to the server and verified by the server, and in a case of positive verification of the encrypted token by the server, the server validates the identity verification of the user of the terminal.

Claims (33)

1. A method for verifying identity of a user of a communicating terminal, the method comprising:

performing a preliminary operation, and thereafter, performing a current operation,

wherein the preliminary operation comprises:

communicating, via a reader, a first piece of identity data of the user to at least one server;

generating at the server a second piece of identity data of the user, the second piece of identity data being derived, at least in part, from the first piece of identity data;

transmitting the second piece of data from the server to the reader, and then from the reader to the terminal; and

storing the second piece of identity data in a secure memory of the terminal; and

wherein the current operation for identity verification comprises:

transmitting a token for encryption, from the server to the terminal without transiting through the reader;

using the second piece of data at the terminal at least to generate an encryption of the token, the encrypted token being transmitted to the server and verified by the server without transiting through the reader; and

in a case of positive verification of the encrypted token by the server, validating, by the server, the identity verification of the user of the terminal,

and wherein said reader, said server and said terminal are distinct.

2. The method of claim 1 , wherein the encryption uses a public key infrastructure, the second piece of identity data at least being used for generating an encryption key, and wherein the encryption key is used for encryption of the token.

3. The method of claim 1 , wherein the second piece of identity data is a digital certificate certifying a key pair.

4. The method of claim 1 , wherein, in the case of positive verification, the encrypted token is associated with a digital identification certificate for the user.

5. The method of claim 1 , wherein the communication of the first piece of identity data of the user to the server is authorized after verification of biometric data of the user of the terminal.

6. The method of claim 1 , wherein the current operation further comprises verification of user-specific data before initiating, on the terminal, the use of the second piece of data for encryption of the token.

7. The method of claim 1 , wherein a plurality of preliminary operations are executed, with a plurality of communications of the first piece of identity data of the user to a plurality of servers, each server generating the respective second pieces of identity data of the user, each second piece of data defining a derived identity of the user, each derived identity being specific to a service for which access is dependent on encrypted token verification on a server dedicated to the service.

8. The method of claim 1 , wherein the communication of the first piece of identity data to the server is carried out via the reader comprising a first module for short-range wireless or wired communication, and the terminal comprising a second module for short-range or wired communication, the second piece of data is transmitted from the server to the reader, then from the reader to the terminal by short-range wireless or wired communication, the short-range communication including near field communication (NFC), Wifi, or Bluetooth.

9. The method of claim 1 , wherein the transmitting the token for encryption or the encrypted token, between the server and the terminal, is performed via a device requesting access to a service associated with the server, access to the service being dependent on verification of the identity of the user from the user terminal in the current operation.

10. The method of claim 9 , wherein the transmitting the token for encryption or the encrypted token, between the terminal and the device, is performed by a short-range or wired communication, the terminal comprising a first module for short-range wireless or wired communication and the device comprising a second module for short-range wireless or wired communication, the short-range communication including near field communication (NFC), Wifi, or Bluetooth.

11. The method of claim 1 , wherein the transmitting the token for encryption, from the server to the terminal, is performed using a mobile phone network, and the transmission of the encrypted token from the terminal to the server is performed via a device requesting access to a service associated with the server, access to the service being dependent on verification of the identity of the user from the user terminal in the current operation.

12. The method of claim 1 , wherein the transmitting the token for encryption, from the server to the terminal, is performed via a device requesting access to a service associated with the server, and the transmission of the encrypted token from the terminal to the server is performed using a mobile network, access to the service being dependent on verification of the identity of the user from the user terminal in the current operation.

13. A system for verifying the identity of a user, the system comprising:

a terminal;

a reader; and

a server,

wherein the reader comprises a first communication module configured to communicate a first piece of identity data of the user to a second communication module of the server,

wherein the server is configured to generate a second piece of identity data of the user, the second piece of identity data being derived, at least in part, from the first piece of identity data, and is configured to transmit the second piece of data to the reader,

wherein the terminal comprises a third communication module configured to receive the second piece of data from the reader,

wherein the terminal comprises a secure memory that stores the second piece of identity data, and

wherein the second communication module is configured to transmit a token for encryption to the third communication module of the terminal without transiting through the reader, wherein the terminal is configured to use the second piece of data at least to generate an encryption of the token, wherein the third communication module is configured to transmit the encrypted token to the second communication module of the server without transiting through the reader, wherein the server is configured to verify the encrypted token and validate, in case of positive verification of the encrypted token, the identity verification of the user of the terminal;

wherein said reader, said server and said terminal are distinct.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE PATENT NUMBER REPLACING 10158873 WITH 10185873 PREVIOUSLY RECORDED ON REEL 71930 FRAME 625. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded Apr 1, 2026
From: IDEMIA IDENTITY & SECURITY FRANCE
To: IDEMIA PUBLIC SECURITY FRANCE
Reel/Frame 075530/0067 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2025
From: IDEMIA IDENTITY & SECURITY FRANCE
To: IDEMIA PUBLIC SECURITY FRANCE
Reel/Frame 071930/0625 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY NAMED PROPERTIES 14/366,087 AND 15/001,534 PREVIOUSLY RECORDED ON REEL 048039 FRAME 0605. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Jan 17, 2024
From: MORPHO
To: SAFRAN IDENTITY & SECURITY
Reel/Frame 066343/0143 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE REMOVE PROPERTY NUMBER 15001534 PREVIOUSLY RECORDED AT REEL: 055314 FRAME: 0930. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 066629/0638 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE ERRONEOUSLY NAME PROPERTIES/APPLICATION NUMBERS PREVIOUSLY RECORDED AT REEL: 055108 FRAME: 0009. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 066365/0151 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY NAMED PROPERTIES 14/366,087 AND 15/001,534 PREVIOUSLY RECORDED ON REEL 047529 FRAME 0948. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY
Reel/Frame 066343/0232 →
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 055108 FRAME: 0009. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Feb 17, 2021
From: SAFRAN IDENTITY AND SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 055314/0930 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE RECEIVING PARTY DATA PREVIOUSLY RECORDED ON REEL 047529 FRAME 0948. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Oct 29, 2020
From: SAFRAN IDENTITY AND SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 055108/0009 →
CHANGE OF NAME Recorded Jan 9, 2019
From: MORPHO
To: SAFRAN IDENTITY & SECURITY
Reel/Frame 048039/0605 →
CHANGE OF NAME Recorded Aug 30, 2018
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY
Reel/Frame 047529/0948 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2014
From: BERTEAU, GUILLAUME; BENTEO, BRUNO
To: MORPHO
Reel/Frame 033592/0312 →
Priority Claims (1)
FR 12 51753 · Feb 27, 2012 · national
Continuity (1)
Related Publication 20150038118A1 · Feb 5, 2015