IP Library › Granted Patent US 11,528,143
Granted Patent B2
US 11,528,143 · App. 16/908,412 · Granted Dec 13, 2022

Biometric identity verification systems, methods and programs for identity document applications and renewals

Inventors: Matthew Wease (St. Louis, MO); Regan E. Harmon (O'Fallon, MO); William Raymond Bowie (Lake St. Louis, MO); Christopher T. Scholl (Saint Peters, MO)
Assignee: MASTERCARD INTERNATIONAL INCORPORATED
H04L9/3231H04L9/3242H04L9/3247H04L63/0442H04L63/0861G06V40/1365G06V40/172G06V40/197H04L63/0272H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,528,143
App. No.
16/908,412
Granted
Dec 13, 2022
Kind
B2
Abstract

An automated identity verification computing device, system and method receives an encrypted renewal request from a user computing device including a biometric value, a digital passport object identifier, and request data. The computing device, system and method retrieves trusted biometric data based on the digital passport object identifier from an identity database, determine a verification score based on the trusted biometric data and the biometric value, and generates a renewal package including the verification score, the digital passport object identifier, and the request data. The computing device, system and method transmit the renewal package to a sponsoring authority computing device.

Claims (44)

1. An identity verification computing device for processing an identity document application, the identity verification computing device comprising one or more processors in communication with one or more memory devices and being configured to:

receive an encrypted identity document request from a user computing device including a biometric value, an identity document object identifier, and request data, wherein the encrypted identity document request is encrypted at the user computing device using a first, public encryption key, and wherein the biometric value includes (i) a representation of a biometric sample and (ii) an indicator of successful authentication of the biometric sample at the user computing device, wherein the indicator is further encrypted using a first portion of a second encryption key;

decrypt the identity document request using the first, public encryption key;

parse the identity document object identifier from the decrypted identity document request;

query a trusted identity database using the identity document object identifier to retrieve, from the trusted identity database, trusted biometric data, the trusted biometric data including (i) a representation of a trusted biometric sample used by a payment processing system for authenticating payment transactions initiated using the user computing device and (ii) a second portion of the second encryption key;

decrypt the indicator using the second encryption key to verify the indicator;

determine a verification score based on the trusted biometric data, the biometric value, and the verified indicator;

generate a data package including the verification score, the identity document object identifier, and the request data;

encrypt the data package; and

transmit the encrypted data package to a sponsoring authority computing device, the sponsoring authority computing device used to process the encrypted data package to determine whether to grant or deny the identity document request.

2. The identity verification computing device of claim 1 , being further configured to append a cryptographic signature to the data package, based on a hash value of the data package and a key value associated with the sponsoring authority computing device.

3. The identity verification computing device of claim 1 , being further configured to:

determine a biometric profile identifier based on the request data; and

retrieve trusted biometric data further based on the biometric profile identifier.

4. The identity verification computing device of claim 1 , wherein the representation of the biometric sample includes a hash value of a fingerprint image, and the representation of a trusted biometric sample includes the fingerprint image.

5. The identity verification computing device of claim 1 , wherein the user computing device includes a digital wallet application, the payment processing system associated with the digital wallet application, and wherein the identity verification computing device is configured to retrieve the trusted biometric data that is stored in the trusted identity data base by the payment processing system.

6. The identity verification computing device of claim 1 , wherein the identity document is at least one of digital passport renewal, driver's license renewal, visa renewal, and residence permit renewal.

7. The identity verification computing device of claim 1 , wherein the identity verification computing device comprises a server system.

8. A method of identity verification for processing an identity document application, the method including an identity verification computing device having one or more processors in communication with one or more memory devices, the method comprising:

receiving an encrypted identity document request from a user computing device including a biometric value, an identity document object identifier, and request data, wherein the encrypted identity document request is encrypted at the user computing device using a first, public encryption key, and wherein the biometric value includes (i) a representation of a biometric sample and (ii) an indicator of successful authentication of the biometric sample at the user computing device, wherein the indicator is further encrypted using a first portion of a second encryption key;

decrypting the identity document request using the first, public encryption key;

parsing the identity document object identifier from the decrypted identity document request;

querying a trusted identity database using the identity document object identifier to retrieve, from the trusted identity database, trusted biometric data, the trusted biometric data including (i) a representation of a trusted biometric sample used by a payment processing system for authenticating payment transactions initiated using the user computing device and (ii) a second portion of the second encryption key;

decrypting the indicator using the second encryption key to verify the indicator;

determining a verification score based on the trusted biometric data, the biometric value, and the verified indicator;

generating a data package including the verification score, the identity document object identifier, and the request data;

encrypting the data package; and

transmitting the encrypted data package to a sponsoring authority computing device, the sponsoring authority computing device used to process the encrypted data package to determine whether to grant or deny the identity document request.

9. The method of claim 8 , further comprising appending a cryptographic signature to the data package, based on a hash value of the data package and a key value associated with the sponsoring authority computing device.

10. The method of claim 8 , further comprising:

determining a biometric profile identifier based on the request data; and

retrieving trusted biometric data further based on the biometric profile identifier.

11. The method of claim 8 , wherein receiving an encrypted identity document request comprises receiving at least one of a digital passport renewal request, a driver's license renewal request, a visa renewal request, and a residence permit renewal request.

12. The method of claim 11 , wherein the identity verification computing device comprises a server system receiving trusted biometric usage data from the payment processing system, and wherein determining a verification score based on the trusted biometric data and the biometric value comprises evaluating a frequency of successful authentication of the biometric usage data by payment processing system.

13. A non-transitory computer readable medium that includes computer executable instructions for electronically verifying an identity of an identity document applicant, wherein when executed by at least one host computing device having at least one processor in communication with a memory device, the computer executable instructions cause the at least one host computing device to:

receive an encrypted identity document request from a user computing device including a biometric value, an identity document object identifier, and request data, wherein the encrypted identity document request is encrypted at the user computing device using a first, public encryption key, and wherein the biometric value includes (i) a representation of a biometric sample and (ii) an indicator of successful authentication of the biometric sample at the user computing device, wherein the indicator is further encrypted using a first portion of a second encryption key;

decrypt the identity document request using the first, public encryption key;

parse the identity document object identifier from the decrypted identity document request;

query a trusted identity database using the identity document object identifier to retrieve, from the trusted identity database, trusted biometric data, the trusted biometric data including (i) a representation of a trusted biometric sample used by a payment processing system for authenticating payment transactions initiated using the user computing device and (ii) a second portion of the second encryption key;

decrypt the indicator using the second encryption key to verify the indicator;

determine a verification score based on the trusted biometric data, the biometric value, and the verified indicator;

generate a data package including the verification score, the identity document object identifier, and the request data;

encrypt the data package; and

transmit the encrypted data package to a sponsoring authority computing device, the sponsoring authority computing device used to process the encrypted data package to determine whether to grant or deny the identity document request.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 22, 2020
From: WEASE, MATTHEW; HARMON, REGAN E.; BOWIE, WILLIAM RAYMOND; SCHOLL, CHRISTOPHER T.
To: MASTERCARD INTERNATIONAL INCORPORATED
Reel/Frame 053005/0312 →
Continuity (2)
Continuation 15847280 · Dec 19, 2017
Related Publication 20200322157A1 · Oct 8, 2020
Cited By (2)
US 12,512,997 US 12,580,911