IP Library Granted Patent US 12,282,539
Granted Patent B2
US 12,282,539 · App. 17/703,115 · Granted Apr 22, 2025

Delegated biometric authentication

Inventors: Sunpreet Singh Arora (San Mateo, CA); Maliheh Shirvanian (Cupertino, CA)
Assignee: Visa International Service Association
G06F21/45H04L63/0861H04L63/0884
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,282,539
App. No.
17/703,115
Granted
Apr 22, 2025
Kind
B2
Abstract

A delegated biometric authentication system and related methods are disclosed. Using the system, a user can securely delegate biometric authentication to a public device from his communication device. This public device may be an Internet of things device that is not owned by the user, such as a computer, smart TV, tablet, etc. The public device may operate in a public place, such as a hotel or library. The communication device may be the users own smartphone or tablet, etc. A fuzzy vault process can be used to store the user's biometric template in the system Embodiments preserver the user's privacy without compromising authentication security and user convenience.

Claims (48)

1. A method comprising:

receiving, by an authentication server computer, from a public device, a validation request message, the validation request message including an identifier of a communication device associated with a user;

transmitting, by the authentication server computer, to the communication device, a delegation confirmation message;

receiving, by the authentication server computer, from the communication device, a delegation confirmation response;

transmitting, by the authentication server computer, to a token server computer, a request for an interaction token;

receiving, by the authentication server computer, from the token server computer, the interaction token; and

transmitting, by the authentication server computer, to the communication device, the interaction token, wherein the communication device locks the interaction token in a data vault using a biometric template associated with the user.

2. The method of claim 1 , wherein the data vault was formed using a fuzzy vault scheme.

3. The method of claim 1 , wherein the communication device transmits the data vault to the public device which stores the data vault.

4. The method of claim 1 , wherein the data vault comprises a number of random points.

5. The method of claim 1 , wherein the communication device is a mobile phone.

6. The method of claim 1 , wherein the communication device transmits the data vault to the public device which stores the data vault, and wherein the communication device is a mobile phone and the public device is a computational device generally accessible to the public.

7. The method of claim 1 , wherein the validation request message further comprises a user identifier.

8. The method of claim 1 , wherein the delegation confirmation message comprises a prompt which requests confirmation from the user of the communication device regarding a desire to delegate biometric authentication to the public device.

9. The method of claim 1 , wherein the interaction token can be used for has a limited number of interactions for which the interaction token can be used by the user.

10. The method of claim 1 , wherein the data vault is in the form of a two-dimensional array of points comprising a plurality of biometric points and a plurality of random points.

11. The method of claim 1 , wherein the authentication server computer maintains a registry of users and communication devices.

12. The method of claim 1 , wherein the interaction token is a substitute for a credential.

13. The method of claim 1 , wherein the biometric template is derived from a face scan, an iris scan, a retina scan, a thumbprint scan, or a voice recording.

14. An authentication server computer comprising:

a processor; and

a non-transitory computer readable medium comprising code, when executed by the processor, causes the authentication server computer to perform operations comprising:

receiving, from a public device, a validation request message, the validation request message including an identifier of a communication device associated with a user;

transmitting to the communication device, a delegation confirmation message;

receiving from the communication device, a delegation confirmation response;

transmitting to a token server computer, a request for an interaction token;

receiving from the token server computer, the interaction token; and

transmitting to the communication device, the interaction token, wherein the communication device locks the interaction token in a data vault using a biometric template associated with the user.

15. The authentication server computer of claim 14 , wherein the interaction token is a substitute for a credential.

16. The authentication server computer of claim 14 , further comprising a database comprising a registry of users and communication devices.

17. The authentication server computer of claim 14 , wherein the identifier of the communication device is a phone number.

18. The authentication server computer of claim 14 , wherein the validation request message further comprises a user identifier.

19. A system comprising:

an authentication server computer comprising

a first processor, and

a first non-transitory computer readable medium comprising code, when executed by the first processor, causes the authentication server computer to perform operations comprising:

receiving, from a public device, a validation request message, the validation request message including an identifier of a communication device associated with a user,

transmitting to the communication device, a delegation confirmation message,

receiving from the communication device, a delegation confirmation response,

transmitting to a token server computer, a request for an interaction token,

receiving from the token server computer, the interaction token, and

transmitting to the communication device, the interaction token, wherein the communication device locks the interaction token in a data vault using a biometric template associated with the user; and

the token server computer comprising,

a second processor, and

a second non-transitory computer readable medium comprising code, when executed by the second processor, causes the authentication server computer to perform operations comprising,

receiving the request for the interaction token from the authentication server computer, and

transmitting the interaction token to the authentication server computer.

20. The system of claim 19 , further comprising the communication device.

Continuity (2)
Continuation 16589609 · Oct 1, 2019
Related Publication 20220215086A1 · Jul 7, 2022
References Cited (34)
US 9935948B2 · Schultz et al. · 2018 [cited by applicant]
US 10313317B2 · O'Regan et al. · 2019 [cited by applicant]
US 10826686B1 · Cho · 2020 [cited by examiner]
US 11321445B2 · Arora et al. · 2022 [cited by applicant]
US 12074974B2 · Palanisamy · 2024 [cited by examiner]
US 20060163344A1 · Nwosu · 2006 [cited by applicant]
US 20170169424A1 · Maddocks et al. · 2017 [cited by applicant]
US 20190356489A1 · Palanisamy · 2019 [cited by examiner]
US 20200275267A1 · Wang · 2020 [cited by examiner]
US 20210234848A1 · Harris · 2021 [cited by examiner]
US 20220156742A1 · Gupta · 2022 [cited by examiner]
US 20230062507A1 · Aabye · 2023 [cited by examiner]
US 20230342776A1 · O'Kane · 2023 [cited by examiner]
US 20230394482A1 · Scott · 2023 [cited by examiner]
CN 101369892A · 2009 [cited by applicant]
KR 20110065139A · 2011 [cited by applicant]
WO 2008069475A1 · 2008 [cited by applicant]
WO WO2018156068A1 · 2018 [cited by examiner]
WO 2018222211A1 · 2018 [cited by applicant]
EP20872369.2, “Extended European Search Report”, Oct. 27, 2022, 8 pages. [cited by applicant]
Rathgeb et al., “A Survey on Biometric Cryptosystems and Cancelable Biometrics”, Eurasip Journal on Information Security, vol. 2011, No. 1, Jan. 1, 2011, 25 pages. [cited by applicant]
EP20872369.2, “Supplementary European Search Report”, Nov. 15, 15, 1 page. [cited by applicant]
EP Application No. 20872369.2, “Extended Search Report”, Oct. 27, 2022, 9 pages. [cited by applicant]
U.S. Appl. No. 16/589,609 , “First Action Interview Pilot Program Pre-Interview Communication”, Oct. 29, 2021, 5 pages. [cited by applicant]
U.S. Appl. No. 16/589,609 , “Notice of Allowance”, Dec. 29, 2021, 11 pages. [cited by applicant]
Chabanne et al., “Delegating Biometric Authentication with the Sumcheck Protocol”, WISTP 2016: Information Security Theory and Practice, Lecture Notes in Computer Science, vol. 9895, Sep. 2016, pp. 236-244. [cited by applicant]
Gabhane et al., “Biometric Template Security Scheme using Fuzzy Vault”, International Journal of 6 Science and Research (IJSR), Computer Science & Engineering, vol. 5, Issue 3, Mar. 2016, pp. 2058-2060. [cited by applicant]
Gritti et al., “Privacy-Preserving Delegable Authentication in the Internet of Things”, Proceedings of the 34th ACM/SIGAPP Symposium on Applied Computing, Apr. 2019, pp. 861-869. [cited by applicant]
Juels et al., “A Fuzzy Vault Scheme”, RSA Laboratories Bedford, MA 01730, USA, and MIT Laboratory for Computer Science 200 Technology Square, Cambridge, MA 02139, 18 pages. [cited by applicant]
Nandakumar et al, “Fingerprint-based Fuzzy Vault: Implementation and Performance”, Apr. 16, 2007, Appeared in IEEE Transactions on Information Forensics and Security, Dec. 2007, 33 pages. [cited by applicant]
PCT/US2020/053032 , “International Search Report and Written Opinion”, Jan. 15, 2021, 11 pages. [cited by applicant]
Uludag et al., “Fuzzy Vault for Fingerprints”, Springer-Verlag Berlin Heidelberg 2005, T. Kanade, A. Jain, and N.K. Ratha (Eds.): AVBPA 2005, LNCS 3546, pp. 310-319, 2005. [cited by applicant]
Yun , “The Biometric Signature Delegation Method with Undeniable Property”, Journal of Digital Convergence, vol. 12, Issue 1, Jan. 2014, pp. 389-395. [cited by applicant]
SG11202202913T , “Written Opinion”, Jan. 8, 2025, 6 pages. [cited by applicant]