IP Library › Granted Patent US 12,301,566
Granted Patent B2
US 12,301,566 · App. 18/394,883 · Granted May 13, 2025

Biometric electronic signature authenticated key exchange token

Inventors: Phillip H. Griffin (Raleigh, NC); Jeffrey J. Stapleton (O'Fallon, MO)
Assignee: Wells Fargo Bank, N.A.
H04L63/0861H04L9/3242H04L9/3247H04L63/061H04L63/0807H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,301,566
App. No.
18/394,883
Granted
May 13, 2025
Kind
B2
Abstract

A biometric electronic signature authenticated key exchange (“BESAKE”) token processing system. The system includes a storage location having a plurality of biometric reference templates. The system further includes an authentication computing system having a processor and instructions. The instructions configured to cause the authentication computing system to receive a signing party identifier and the BESAKE token from a signing party. The BESAKE token having a biometric sample encrypted using an encryption key. The instructions further configured to generate a decryption key and decrypt the encrypted biometric sample from the BESAKE token. The instructions further configured to match the biometric sample with a biometric reference template and transmit to a biometric service provider computing system a match request. The instructions further configured to determine a signing party identity via a binary match value. The binary match value relating to a result of matching the biometric sample with the biometric reference template.

Claims (36)

1. A method, comprising:

generating a first cryptographic key using a first knowledge factor corresponding to an identifier identifying a signing party;

decrypting a biometric electronic signature authenticated key exchange (“BESAKE”) token using the first cryptographic key, wherein the BESAKE token is encrypted using a second cryptographic key derived using a second knowledge factor;

determining a biometric sample and the second knowledge factor from the decrypted BESAKE token; and

authenticating the signing party in response to determining that the biometric sample matching a biometric reference template and in response to verifying a timestamp corresponding to the BESAKE token.

2. The method of claim 1 , wherein the BESAKE token is decrypted via a same encryption algorithm used by the signing party to encrypt the BESAKE token.

3. The method of claim 1 , further comprising:

sending a request to a biometric service provider (“BSP”) computing system, the request comprising the biometric sample; and

receiving a value indicating whether the biometric sample matches the biometric reference template associated with the identifier.

4. The method of claim 1 , wherein the BESAKE token comprises a record for the biometric sample, the record is encrypted using the second cryptographic key.

5. The method of claim 1 , wherein the signing party is authenticated in response to determining that the second knowledge factor matching the first knowledge factor.

6. The method of claim 1 , wherein the second knowledge factor fails to match the first knowledge factor.

7. A system, comprising at least one memory and at least one processor, wherein the at least one processor is configured to:

generate a first cryptographic key using a first knowledge factor corresponding to an identifier identifying a signing party;

decrypt a biometric electronic signature authenticated key exchange (“BESAKE”) token using the first cryptographic key, wherein the BESAKE token is encrypted using a second cryptographic key derived using a second knowledge factor;

determine a biometric sample and the second knowledge factor from the decrypted BESAKE token; and

authenticate the signing party in response to determining that the biometric sample matching a biometric reference template and in response to verifying a timestamp corresponding to the BESAKE token.

8. The system of claim 7 , wherein the BESAKE token is decrypted via a same encryption algorithm used by the signing party to encrypt the BESAKE token.

9. The system of claim 7 , wherein the at least one processor is further configured to:

sending a request to a biometric service provider (“BSP”) computing system, the request comprising the biometric sample; and

receiving a value indicating whether the biometric sample matches the biometric reference template associated with the identifier.

10. The system of claim 7 , wherein the BESAKE token comprises a record for the biometric sample, the record is encrypted using the second cryptographic key.

11. The system of claim 7 , wherein the signing party is authenticated in response to determining that the second knowledge factor matching the first knowledge factor.

12. The system of claim 7 , wherein the second knowledge factor fails to match the first knowledge factor.

13. At least one non-transitory processor readable medium comprising processor-readable instructions, such that, when executed, causes at least one processor to:

generate a first cryptographic key using a first knowledge factor corresponding to an identifier identifying a signing party;

decrypt a biometric electronic signature authenticated key exchange (“BESAKE”) token using the first cryptographic key, wherein the BESAKE token is encrypted using a second cryptographic key derived using a second knowledge factor;

determine a biometric sample and the second knowledge factor from the decrypted BESAKE token; and

authenticate the signing party in response to determining that the biometric sample matching a biometric reference template and in response to verifying a timestamp corresponding to the BESAKE token.

14. The non-transitory processor readable medium of claim 13 , wherein the BESAKE token is decrypted via a same encryption algorithm used by the signing party to encrypt the BESAKE token.

15. The non-transitory processor readable medium of claim 13 , wherein the at least one processor is further caused to:

sending a request to a biometric service provider (“BSP”) computing system, the request comprising the biometric sample; and

receiving a value indicating whether the biometric sample matches the biometric reference template associated with the identifier.

16. The non-transitory processor readable medium of claim 13 , wherein the BESAKE token comprises a record for the biometric sample, the record is encrypted using the second cryptographic key.

17. The non-transitory processor readable medium of claim 13 , wherein the signing party is authenticated in response to determining that the second knowledge factor matching the first knowledge factor.

18. The non-transitory processor readable medium of claim 13 , wherein the second knowledge factor fails to match the first knowledge factor.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2025
From: GRIFFIN, PHILLIP H.; STAPLETON, JEFFREY J.
To: WELLS FARGO BANK, N.A.
Reel/Frame 070860/0233 →
Continuity (6)
Continuation 17878713 · Aug 1, 2022
Continuation 16509905 · Jul 12, 2019
Continuation 15623213 · Jun 14, 2017
Continuation In Part 15169312 · May 31, 2016
Provisional Application 62439587 · Dec 28, 2016
Related Publication 20240129304A1 · Apr 18, 2024
References Cited (54)
US 5764789A · Pare, Jr. · 1998 [cited by examiner]
US 6757825B1 · MacKenzie et al. · 2004 [cited by applicant]
US 7039805B1 · Messing · 2006 [cited by applicant]
US 7178025B2 · Scheidt et al. · 2007 [cited by applicant]
US 7702107B1 · Messing · 2010 [cited by applicant]
US 7813822B1 · Hoffberg · 2010 [cited by applicant]
US 8316237B1 · Felsher et al. · 2012 [cited by applicant]
US 9158906B2 · Guajardo Merchan · 2015 [cited by examiner]
US 9692758B2 · Zeljkovic · 2017 [cited by examiner]
US 10242362B2 · Burgess · 2019 [cited by examiner]
US 10530577B1 · Pazhoor et al. · 2020 [cited by applicant]
US 20050154924A1 · Scheidt · 2005 [cited by examiner]
US 20050235148A1 · Scheidt et al. · 2005 [cited by applicant]
US 20070038867A1 · Verbauwhede et al. · 2007 [cited by applicant]
US 20090287837A1 · Felsher · 2009 [cited by applicant]
US 20100042841A1 · King et al. · 2010 [cited by applicant]
US 20100139667A1 · Atkinson · 2010 [cited by examiner]
US 20100235285A1 · Hoffberg · 2010 [cited by applicant]
US 20100317420A1 · Hoffberg · 2010 [cited by applicant]
US 20110138191A1 · Bond · 2011 [cited by applicant]
US 20130159021A1 · Felsher · 2013 [cited by applicant]
US 20130262873A1 · Read · 2013 [cited by examiner]
US 20140019766A1 · Takahashi et al. · 2014 [cited by applicant]
US 20140122888A1 · Yoon et al. · 2014 [cited by applicant]
US 20140164768A1 · Kruglick · 2014 [cited by applicant]
US 20140258718A1 · Isakow · 2014 [cited by examiner]
US 20140280264A1 · Fix · 2014 [cited by examiner]
US 20140354405A1 · Kocher · 2014 [cited by examiner]
US 20150215316A1 · Zeljkovic · 2015 [cited by examiner]
US 20150237046A1 · Chang · 2015 [cited by examiner]
US 20150280921A1 · Geoffrey · 2015 [cited by applicant]
US 20160020909A1 · Gardenes Linan · 2016 [cited by applicant]
US 20160203496A1 · Guerrero et al. · 2016 [cited by applicant]
US 20160330027A1 · Ebrahimi · 2016 [cited by applicant]
US 20170033930A1 · Costa et al. · 2017 [cited by applicant]
US 20170070497A1 · McCallum · 2017 [cited by examiner]
US 20170116615A1 · Burgess et al. · 2017 [cited by applicant]
US 20170344732A1 · Kohli · 2017 [cited by applicant]
US 20190097812A1 · Toth · 2019 [cited by applicant]
Accredited Standards Committee X9, Incorporated, ANSI X9.73-2010, Cryptographic Message Syntax-ASN.1 and XML, American National Standards Institute, Apr. 15, 2010, 89 pages. [cited by applicant]
Accredited Standards Committee X9, Incorporated, ANSI X9.84-2010, Biometric Information Management and Security for the Financial Services Industry, American National Standards Institute, Mar. 31, 2010, 172 pages. [cited by applicant]
Fong, et al., “A biometric authentication model using hand gesture images,” Biomedical Engineering Online, vol. 12, No. 111 (Oct. 30, 2013. 18 pages. [cited by applicant]
Gilady et al., “Intent Biometrics: An Enhanced Form of Multimodal Biometric Systems,” 28th International Conference on Advanced Information Networking and Applications Workshops (May 13, 2014-May 16, 2014. 5 pages. [cited by applicant]
Griffin, “Adaptive Weak Secrets for Authenticated Key Exchange,” Advances in Human Factors in Cybersecurity—Advances in Intelligent Systems and Computing, vol. 593, p. 16-25 (2018). [cited by applicant]
Griffin, “Transport Layer Secured Password-Authenticated Key Exchange,” Information Systems Security Association Journal, vol. 13, No. 6 (Jun. 2015). 6 pages. [cited by applicant]
Griffin, P., Biometric Knowledge Extraction for Multi-Factor Authentication and Key Exchange, Procedia Computer Sciences, vol. 61, Complex Adaptive Systems, Nov. 2-4, 2015, 6 pages. [cited by applicant]
Griffin, P., Telebiometric Authentication Objects, Procedia Computer Science, vol. 36, Complex Adaptive Systems, Philadephia, PA, Nov. 3-5, 2014, 8 pages. [cited by applicant]
Griffin, Phillip, “Secure Authentication on the Internet of Things,” IEEE Southeast Conference (2017). 5 pages. [cited by applicant]
International Telecommunication Union, Information technology—Open Systems Interconnection—The Directory: Public-key and attribute certificate frameworks, Series X: Data Networks, Open System Communications and Security… [cited by applicant]
International Telecommunication Union, Password-authenticated key exchange (PAK) protocol, Series X: Data Networks, Open System Communications and Security, ITU-T Recommendation X.1035, Feb. 2007, 12 pages. [cited by applicant]
Larmouth, “ASN.1 Complete,” Open Systems Solutions (May 31, 1999). 387 pages. [cited by applicant]
Manulis et al., “Secure Modular Password Authentication for the Web Using Channel Bindings,” Int. J. Inf. Secur., (Springer) Published online Sep. 12, 2016, 15:597-620. 24 pages. [cited by applicant]
Vicars, “American Sign Language Fingerspelling & Numbers: Introduction,” http://www.lifeprint.com/asl101/fingerspelling/fingerspelling.htm; American Sign Language University (2011). 6 pages. [cited by applicant]
Yang et al., “Consent Biometrics,” Department of Electrical and Computer Engineering IUPUI (2011). 6 pages. [cited by applicant]