IP Library › Granted Patent US 12,432,065
Granted Patent B2
US 12,432,065 · App. 17/895,431 · Granted Sep 30, 2025

Biometric sensor on portable device

Inventors: Yuexi Chen (Foster City, CA); Garth Petersen (Belmont, CA)
Assignee: Visa International Service Association
H04L9/3231H04L9/3234H04L9/3239H04L9/3247H04L63/0853H04L63/0861H04L63/126H04L2463/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,432,065
App. No.
17/895,431
Granted
Sep 30, 2025
Kind
B2
Abstract

A method and system for secure remote digital interactions through the use of biometric templates is disclosed. In one example, the method includes an interaction that prompts the use of obtaining a first biometric template and comparing it to a second biometric template to determine if they match. The match process is performed on a portable device.

Claims (36)

1. A method comprising:

establishing a communication between a user device and a computer operating a host site in an interaction between the host site and a user of the user device;

receiving, by the computer, a cryptogram encoding (i) a biometric match result, access data from a portable device, and interaction data comprising a transaction amount, or (ii) a derivative of the biometric match result, the access data from the portable device and the interaction data comprising the transaction amount, wherein the user device received the cryptogram and the access data from the portable device, and wherein the biometric match result is a match indicator or a no match indicator;

generating, by the computer, an authorization request message comprising the access data, the cryptogram, and the biometric match result or the derivative of the biometric match result; and

transmitting, by the computer, the authorization request message to a remote server computer, wherein the remote server computer is programmed to verify the cryptogram, by decrypting the cryptogram to recover inputs to the cryptogram including (i) the interaction data comprising the transaction amount, the access data and the biometric match result, or (ii) the derivative of the interaction data comprising the transaction amount, the access data, and the biometric match result, by comparing the interaction data comprising the transaction amount from the cryptogram to the interaction data comprising the transaction amount in the authorization request message, and by comparing the access data in the cryptogram to the access data in the authorization request message, and is programmed to analyze the biometric match result, and to allow the interaction to continue based on the verification of the cryptogram and based on the analysis of the biometric match result.

2. The method of claim 1 , wherein the portable device is in the form of a card.

3. The method of claim 2 wherein the access data comprises a credit card number or a debit card number.

4. The method of claim 1 , wherein the interaction data includes a time of the interaction.

5. The method of claim 1 , wherein the remote server computer is an authorizing entity computer that provides access to secure data.

6. The method of claim 1 , wherein the interaction is a payment transaction.

7. The method of claim 6 , wherein the authorization request message further comprises the biometric match result.

8. The method of claim 6 , wherein the authorization request message further comprises the biometric match result, a matching confidence value, and an indicator of a type of biometric verification performed.

9. The method of claim 1 , wherein the computer is a resource provider computer.

10. The method of claim 1 , further comprising:

receiving, by the computer, an authorization response message from the remote server computer.

11. The method of claim 10 , wherein the remote server computer is a processing computer.

12. The method of claim 1 , further comprising:

wherein the authorization request message is transmitted to the remote server computer via a transport computer, and the method further comprises:

receiving, by the computer, an authorization response message from the remote server computer.

13. A system comprising:

a computer comprising:

a processor; and

a non-transitory computer readable medium comprising code, executable by the processor for implementing operations comprising:

establishing, a communication between a user device and the computer operating a host site in an interaction between the host site and a user of the user device;

receiving, by the computer, a cryptogram encoding (i) a biometric match result, access data from a portable device, and interaction data comprising a transaction amount, or (ii) a derivative of the biometric match result, the access data from the portable device, and the interaction data comprising the transaction amount, wherein the user device received the cryptogram and the access data from the portable device, and wherein the biometric match result is a match indicator or a no match indicator;

generating an authorization request message comprising the access data, the cryptogram, and the biometric match result or the derivative of the biometric match result; and

transmitting the authorization request message to a remote server computer; and

the remote server computer in communication with the computer, wherein the remote server computer is programmed to is programmed to verify the cryptogram, by decrypting the cryptogram to recover inputs to the cryptogram including (i) the interaction data comprising the transaction amount, the access data and the biometric match result, or (ii) the derivative of the interaction data comprising the transaction amount, the access data, and the biometric match result, by comparing the interaction data comprising the transaction amount from the cryptogram to the interaction data comprising the transaction amount in the authorization request message, and by comparing the access data in the cryptogram to the access data in the authorization request message, and is programmed to analyze the biometric match result, and to allow the interaction to continue based on the verification of the cryptogram and based on the analysis of the biometric match result.

14. The computer of claim 13 , wherein the operations further comprise:

receiving, by the computer, an authorization response message from the remote server computer.

15. The computer of claim 14 , wherein the computer is a resource provider computer.

16. The computer of claim 14 , wherein the authorization request message further comprises a timestamp, a matching confidence value, and an indicator of a type of biometric verification performed.

17. The computer of claim 13 , wherein the cryptogram is formed using a symmetric key on the user device.

18. The computer of claim 13 , wherein the host site is a Web site.

19. The computer of claim 13 , wherein the authorization request message further comprises the derivative of the biometric match result and an amount, wherein the derivative of the biometric match result is a hash of the biometric match result.

20. The computer of claim 13 , wherein the authorization request message further comprises an amount.

Continuity (2)
Continuation 16761648
Related Publication 20220407709A1 · Dec 22, 2022
References Cited (41)
US 11463257B2 · Chen et al. · 2022 [cited by applicant]
US 11664996B2 · Choi · 2023 [cited by examiner]
US 20010000045A1 · Yu · 2001 [cited by examiner]
US 20050238212A1 · Du · 2005 [cited by applicant]
US 20050240778A1 · Saito · 2005 [cited by applicant]
US 20100131414A1 · Tame · 2010 [cited by examiner]
US 20100185871A1 · Scherrer · 2010 [cited by applicant]
US 20130179346A1 · Kumnick · 2013 [cited by examiner]
US 20140164154A1 · Ramaci · 2014 [cited by applicant]
US 20150237046A1 · Chang et al. · 2015 [cited by applicant]
US 20150379250A1 · Saito et al. · 2015 [cited by applicant]
US 20160019539A1 · Hoyos · 2016 [cited by applicant]
US 20160067261A1 · Zimmermann et al. · 2016 [cited by applicant]
US 20160072802A1 · Hoyos · 2016 [cited by applicant]
US 20160110721A1 · Russell · 2016 [cited by examiner]
US 20160267261A1 · Tooley, II · 2016 [cited by applicant]
US 20160269403A1 · Koutenaei et al. · 2016 [cited by applicant]
US 20170017783A1 · Willis et al. · 2017 [cited by applicant]
US 20170126672A1 · Jang · 2017 [cited by applicant]
US 20180019994A1 · Chang · 2018 [cited by examiner]
US 20190139051A1 · Kopf · 2019 [cited by applicant]
CN 105959287A · 2016 [cited by applicant]
KR 20150097059A · 2015 [cited by applicant]
WO 2006014205A2 · 2006 [cited by applicant]
WO WO2017019972A1 · 2017 [cited by examiner]
WO 2017122055A1 · 2017 [cited by applicant]
WO 2017197974A1 · 2017 [cited by applicant]
U.S. Appl. No. 16/761,648 , “Corrected Notice of Allowability”, Jul. 27, 2022, 2 pages. [cited by applicant]
U.S. Appl. No. 16/761,648 , “Final Office Action”, Mar. 10, 2022, 27 pages. [cited by applicant]
U.S. Appl. No. 16/761,648 , “First Action Interview Office Action Summary”, Nov. 3, 2021, 27 pages. [cited by applicant]
U.S. Appl. No. 16/761,648 , “First Action Interview Pilot Program Pre-Interview Communication”, Sep. 28, 2021, 25 pages. [cited by applicant]
U.S. Appl. No. 16/761,648 , “Notice of Allowance”, Jun. 14, 2022, 9 pages. [cited by applicant]
EP17930626.1 , “Extended European Search Report”, Oct. 20, 2020, 8 pages. [cited by applicant]
EP17930626.1 , “Office Action”, Jul. 8, 2022, 8 pages. [cited by applicant]
PCT/US2017/060226 , “International Search Report and Written Opinion”, Aug. 7, 2018, 12 pages. [cited by applicant]
PCTUS2017060226 , “International Preliminary Report on Patentability”, May 22, 2020, 9 pages. [cited by applicant]
SG11202004111R , “Written Opinion”, Nov. 11, 2021, 7 pages. [cited by applicant]
CN201780097675.4 , “Notice of Decision to Grant”, Jun. 28, 2023, 8 pages. [cited by applicant]
Gordon et al., “Biometric Security Mechanism in Mobile payment”, 2010 Seventh International Conference on Wireless and Optical Communications Networks—(WOCN), 13 pages. [cited by applicant]
SG11202004111R , “Notice of Decision to Grant”, Jul. 24, 2023, 6 pages. [cited by applicant]
CN201780097675.4 , “Office Action”, Feb. 10, 2023, 16 pages. [cited by applicant]