Secure biometric verification of identity
Abstract
A high-security ID card (100) incorporates integrated memory for biometric data, as well as an integrated sensor for biometric data capture. The integrated processor (100) on the card (100) performs a matching test to verify that the biometric data recorded is the same as locally stored biometric data. Any data forwarding from the control card (100) is further confirmed and / or further processed only if the match result is positive. Most preferably, the chip (100) ISO standard chip card. In one embodiment, the ISO standard chip card acts as a firewall to protect and process protected biometric data for the use of the security processor (114) to protect against malicious external attacks through the ISO standard chip card interface. In another case, the security processor (114) is interleaved by the ISO standard chip card interface and the unencoded ISO standard chip card processor (112) blocking any external communication until the fingerprint of the user is reconciled with a previously stored fingerprint. When flipping the user's finger over the sensor block (110), they provide real-time feedback to help optimize positioning of the user's finger.

Term
Term ended
Projected expiry passed 8 April 2025, 1.5 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
28 claims: 2 independent, 26 dependent
- 1Intelligente Erkennungskarte, wobei die Karte enthält:einen auf der Karte befindlichen Speicher, um Bezugsdaten zu speichern, einen auf der Karte befindlichen Sensor, um biometrische Daten direkt zu gewinnen, einen auf der Karte befindlichen Mikroprozessor, um die gewonnenen biometrischen Daten mit entsprechend gespeicherten Bezugsdaten innerhalb eines vorgegebenen Schwellenwerts zu vergleichen und nur dann eine BestätigungsMeldung zu erzeugen, wenn innerhalb eines vorgegebenen Schwellenwerts eine Übereinstimmung besteht, und eine Einrichtung, um die Bestätigungs-Meldung mit einem externen Netzwerk zu kommunizieren.
- 2Erkennungskarte gemäß Anspruch 1, wobei die BestätigungsMeldung zumindest Auszüge aus den gespeicherten Bezugsdaten aufweist.
- 3Erkennungskarte gemäß Anspruch 2, wobei die BestätigungsMeldung zumindest Auszüge aus den gewonnenen biometrischen Daten aufweist.
- 4Erkennungskarte gemäß Anspruch 3, wobei die BestätigungsMeldung zu einem abgesetzten Beglaubigungs-System übertragen wird, um eine zusätzliche Bestätigung durchzuführen.
- 5Erkennungskarte gemäß Anspruch 4, wobei das abgesetzte Beglaubigungs-System abgesetzt gespeicherte Bezugsdaten aufweist, die sich von den lokal gespeicherten Bezugsdaten unterscheiden.
- 6Erkennungskarte gemäß Anspruch 4, wobei der auf der Karte befindliche Mikroprozessor einen anderen ÜbereinstimmungsAlgorithmus verwendet, als er beim abgesetzten Beglaubigungs-System verwendet wird.
- 7Erkennungskarte gemäß Anspruch 2, wobei das gesamte Übereinstimmungs-Verfahren von dem auf der Karte befindlichen frfr·· frfr fr fr · •fr fr fr fr ··· · · fr··· fr··· · · ···· ·· . , · ·· frfr ·· ·· · ··· Prozessor ausgeführt wird und keine gewonnenen biometrischen Datenwerte zum Netzwerk übertragen werden.
- 8Erkennungskarte gemäß Anspruch 2, wobei sowohl die zuerst gewonnenen biometrischen Daten als auch irgendwelche andere private Informationen, die in dem auf der Karte befindlichen Speicher gespeichert sind, nicht für irgendwelche externe Prozesse zur Verfügung stehen.
- 9Erkennungskarte gemäß Anspruch 2, wobei die Karte mit einer ISO-SmartCard kompatibel ist.
- 10Erkennungskarte gemäß Anspruch 9, wobei die Karte weiters einen ISO-SmartCard Prozessor enthält.
- 11Erkennungskarte gemäß Anspruch 10, wobei der SicherheitsProzessor, der zum Speichern und Verarbeiten der geschützten biometrischen Daten verwendet wird, funktionell vom ISO-SmartCard Prozessor durch ein Zugangsschutzsystem (firewall) getrennt ist.
- 12Erkennungskarte gemäß Anspruch 10, wobei alle externen Daten zum und vom Sicherheits-Prozessor über den ISOSmartCard Prozessor laufen.
- 13Erkennungskarte gemäß Anspruch 10, wobei alle externen Daten zum und vom ISO-SmartCard Prozessor über den Sicherheits-Prozessor laufen.
- 14Erkennungskarte gemäß Anspruch 10, wobei der SicherheitsProzessor einen ersten Anschluss, der dazu verwendet wird, um Daten während eines Ladevorgangs zu laden, sowie einen zweiten Anschluss besitzt, der mit einem externen Netzwerk verbunden ist.
- 15Erkennungskarte gemäß Anspruch, wobei der erste Anschluss dauernd außer Betrieb gesetzt wird, nachdem der Ladevorgang beendet wurde. ft · · · · · · • ft ft ftftftft ft • ftft ftftftft • ft ftft ftft · · ·»
- 16Erkennungskarte gemäß Anspruch 10, wobei der SicherheitsProzessor, der zum Speichern und Verarbeiten der geschützten biometrischen Daten dient, funktionell vom ISOSmartCard Prozessor durch ein Zugangsschutzsystem (firewall) getrennt ist.
- 17Erkennungskarte gemäß Anspruch 10, wobei:die Karte einen oberen Magnetstreifen-Bereich und einen unteren geprägten Bereich enthält;der biometrische Sensor ein Fingerabdruck-Sensor ist;und sowohl der Sicherheits-Prozessor, als auch der ISOSmartCard Prozessor und der Fingerabdruck-Sensor in einem mittleren Bereich zwischen dem oberen Bereich und dem unteren Bereich angeordnet sind.
- 18Erkennungskarte gemäß Anspruch 2, wobei die biometrischen Daten Fingerabdruck-Daten aufweisen und der Sensor ein Fingerabdruck-Sensor ist, der Daten vom Finger eines Benutzers gewinnt, der auf dem Sensor angeordnet ist.
- 19Erkennungskarte gemäß Anspruch 18, wobei eine EchtzeitRückfrage erfolgt, während der Benutzer seinen Finger über dem Fingerabdruck-Sensor bewegt, wodurch eine optimale Anordnung des Fingers über dem Sensor erleichtert wird.
- 20Erkennungskarte gemäß Anspruch 18, wobei der Übereinstimmungs-Vorgang einen Hybrid-Übereinstimmungsalgorithmus verwendet, der sowohl Minutien als auch das gesamte räumliche Verhältnis in den gewonnenen biometrischen Daten berücksichtigt.
- 21Erkennungskarte gemäß Anspruch 18, wobei der Fingerabdruck-Sensor eine Folie aus kristallinem Silizium enthält, die von einer Rückwand getragen wird.
- 22Erkennungskarte gemäß Anspruch 21, wobei die Rückwand eine glasfaserverstärkte Epoxyd-Schicht enthält, die zwischen zwei Metallschichten eingeschlossen ist. • · · · • * · · • · « ··· • · · · 99 9
- 23Erkennungskarte gemäß Anspruch 18, wobei die Rückwand mit einem Trägerrahmen verstärkt ist.
- 24Erkennungskarte gemäß Anspruch 1, wobei die Karte weiters eine Einrichtung enthält, um die Verwendung der Karte auf einen vorgegebenen Ort zu beschränken, zumindest für einige der gewonnenen Daten.
- 25Erkennungskarte gemäß Anspruch 1, wobei zumindest einige der gewonnenen biometrischen Daten und der Bezugsdaten zu einem getrennten Beglaubigungs-Server übertragen werden, um die Identität eines Benutzers sicher zu bestätigen, bevor irgendeine Bewilligung eines Online-Zugriffs auf einen Applikations-Server erfolgt, um sichere Finanztransaktionen zu verarbeiten, die diesen Benutzer betreffen.
- 26Erkennungskarte gemäß Anspruch 25, wobei in Abhängigkeit von einer Übereinstimmungs-Anforderung, die einen bestimmten eingeloggten Versuch bei einem bestimmten Applikations-Server betrifft, der eine positive Übereinstimmung beim Beglaubigungs-Server erzeugt, ein sicheres DreiwegeBeglaubigungsprotokoll ausgeführt wird, bei dem der Beglaubigungs-Server eine Challenge-Zeichenfolge zur Erkennungskarte aussendet, wobei die Erkennungskarte dann die Challenge-Zeichenfolge und die ÜbereinstimmungsAnforderung dazu verwendet, um eine Challenge-Antwort zu erzeugen, die dann zum Applikations-Server weitergeleitet wird, wobei der Applikations-Server dann die ChallengeAntwort zum Beglaubigungs-Server weiterleitet, der dann beglaubigt, ob die Challenge-Antwort gültig ist.
- 27Erkennungskarte gemäß Anspruch 1, wobei der Ausgang von der Karte dazu verwendet wird, um einen physischen Zugriff in einen sicheren Bereich zu erhalten.
- 28Erkennungskarte gemäß Anspruch 27, wobei ein Bericht von erfolgreichen und erfolglosen Zugriffsversuchen auf der Karte festgehalten wird.
Independent claims28
227 paragraphs in 7 sections, as filed
SUMMARY
To get an improved identification card for
To provide verification of biometric data, the card (100) has, in addition to a memory, a sensor (110) for the direct acquisition of biometric data and a microprocessor. By means of the microprocessor, the biometric data obtained are compared with stored reference data and, depending on whether they match these reference data, a confirmation message is generated which can be communicated with an external network.
<img file="AT500802A2_D0001.tif" />
SUBMITTED *
<img file="AT500802A2_D0002.tif" />
H soo ') ι ϋΰ -ί
SECURE BIOMETRIC VERIFICATION OF CROSS REFERENCES FOR THE
IDENTITY IN THE APPLICATIONS CONCERNED
This motion is based on and claims priority from Interim Motions 60 / 409.716, September 10, 2002 (number 7167-102P1), 60 / 409.715, September 10, 2002 (number 7167103P), 60 / 429.919, November 27, 2002 ( Number 7167-104P), 60 / 433.254, December 13, 2002 (number 7167-105P) and 60 / 484.692,
3. July 2003 (number 7167-106P), to which reference should be made here in their entirety.
BACKGROUND
Computerization, and particularly Internet technology, has enabled greater access to data, including financial data, medical data, and personal data, as well as facilities to carry out financial or other transactions in which confidential data is updated or exchanged.
In general, passwords are used to protect the confidentiality of such data. However, the passwords are often based on date of birth or phone number, which are easy to guess, but not secure at all. Furthermore, a complicated, randomly generated password can often be stolen easily. Access systems based on a password are therefore vulnerable to criminal attacks, resulting in dangers and damage to industry and economy, but also to human life. There is therefore a need for an improved method for securing data and for protecting this data from unauthorized access.
Biometric data can include precise details that are difficult to obtain but easy to analyze (for example, as a result of the minutiae of a fingerprint) or overall patterns that are easy to obtain but difficult to analyze (for example, the spatial features of neighboring turns of a fingerprint) .
There are encrypted algorithms that generate a digital • 9 • · · · ···· · · • · · · ···· 9 • • 9 99 ·· 99 · ·· ·· 99 · 9 · ·· «
Need a key that is only accessible to authorized users. Without the correct key, the encrypted data can only be decrypted into a usable format with a significant investment of time and resources, and only if certain characteristics of the unencrypted data are known (or at least predictable).
Patent application JP 60-029868 published in Japan, February 15, 1985, in the name of Tamio SAITO, teaches an individual identification system that uses an identification card with an integrated memory to register encrypted biometric data obtained from the card holder. The biometric data can include a voice print, a fingerprint, a physical appearance and / or a biological test. In operation, the data on the card are read out and deciphered in order to compare them with corresponding data obtained from the person showing the card. Such a system enables an individual to be identified unambiguously with a high degree of accuracy. Since the biometric data are obtained and processed with an external device, it is difficult to protect the information stored on the card against possible alteration and / or identity theft.
An improved identification card has been proposed which has a data driven multiprocessor chip on the card to provide a hardware firewall that both encrypts and isolates the biometric data stored on the card, thereby providing much greater protection against a unauthorized change of the stored data is delivered. The actual matching process, however, was carried out in the same external reader terminal with which the biometric data was obtained directly, making it potentially vulnerable to fraudulent manipulation from outside.
SUMMARY
A first embodiment of a highly secure identification card not only has a memory located on the card for the stored biometric data, but also a sensor located on the card in order to obtain the biometric data directly. A remote authentication system contains a secure database that contains the biometric data. A processor located on the card carries out a preparatory matching process in order to confirm that the biometric data obtained match the locally stored biometric data. Only if there is a positive local match will any data obtained or any sensitive stored data be transmitted to the remote authentication system for additional confirmation and further processing. As an additional protection against malicious attacks, the locally stored data preferably differ from the remotely stored data, the local correspondence and the remote correspondence preferably being carried out using different correspondence algorithms. Even if the card, the locally stored data and / or the local terminal to which the card is connected are compromised, there is a high probability that the remote authentication system will still be able to detect the attempted interference .
A second embodiment furthermore has a memory located on the card for the stored biometric data, a sensor located on the card in order to obtain the biometric data directly, and a processor located on the card. In this embodiment, however, the entire matching process is carried out by the processor located on the card, neither the originally obtained biometric data nor any other private information stored in the memory located on the card being made accessible to any external method . Instead, a confirmation message is generated as a function of a successful match between the newly acquired biometric data and the previously acquired biometric data. The confirmation message causes the card to work similarly to a conventional ISO SmartCard if a successful / unsuccessful entry of a conventional personal identification number (PIN) erΦ φ · · · · • · φ φ · Φ · Φ • · · · · · · φφ ·· ·· follows, although additional security is guaranteed by a more secure confirmation procedure. In these two above-mentioned embodiments, the stored biometric data and any associated, locally stored encryption algorithms or keys for the encryption are preferably loaded onto the card at the time at which the output to the card holder is originally made, so that any subsequent external Traffic is deterred, thereby further improving the integrity of the stored biometric data and the entire verification process.
In one embodiment, the ISO smart card works as an access protection system (firewall) in order to protect the security processor, which is used to store and process the protected biometric data, from malicious external attacks via the ISO smart card interface. In another embodiment, the security processor is inserted between the ISO SmartCard interface and an unchanged ISO SmartCard processor, blocking any external communications until the user's finger pressure matches a previously registered fingerprint.
In a preferred embodiment of a highly secure identification card with the possibility of a fingerprint match located on the card, real-time feedback takes place while the user moves his finger over the fingerprint sensor, whereby an optimal arrangement of the finger over the sensor is facilitated. This feedback not only reduces the computational complexity, but it also provides additional means of distinguishing between an inexperienced user and a fraudulent user, thereby further reducing the possibility of false rejections and / or assumptions. In another preferred embodiment, the fingerprint sensor is held in a carrier which gives it additional rigidity.
In an exemplary application, the biometric data obtained and / or a display for the identity of the card holder is encrypted and entered into a transaction network that includes a financial institution as well as has its own authentication server prior to any authorization for on-line access to confidential data or any automated process to complete a secure transaction. In another exemplary application, the output from the card is used to obtain physical access to a secure area. With both applications, a record of successful and unsuccessful access attempts can be made either on the card or on an external security server or on both.
DRAWINGS
In the drawings shows:
1 shows an embodiment of an intelligent card with a biometric confirmation, located on the card, of the identity of the person presenting the card;
FIG. 2 shows a flowchart showing an exemplary method for assisting the user in an optimal arrangement of a finger on the fingerprint sensor; FIG.
3 shows a functional block diagram of a biometric confirmation system which can provide both local and remote confirmation of the identity of a person who presents a secure identification card; Fig. 4th a functional block diagram of an exemplary biometric verification card showing various physical data paths used during the initial loading of the cardholder's biometric data and during verification of the cardholder's identity to a remote application;
5 shows an alternative embodiment of the exemplary biometric confirmation card of FIG. 4, which is intended for use with an unmodified ISO SmartCard CPU;
6 is a flowchart showing the communication between an exemplary application and an exemplary confirmation card, in which for · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · ·) · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · · for ····· ·) · for · for only local confirmation of the identity of the card holder is carried out;
7 is a flow diagram similar to the flow diagram of FIG. 6 but modified for use with the exemplary biometric confirmation card of FIG. 5;
8 shows a second embodiment of an intelligent card with a biometric confirmation located on the card, which can be connected to a local terminal either wirelessly or via an electrical connection;
Figure 9 is a section through the card of Figure 8;
10 is a circuit diagram of an exemplary fingerprint sensor; and
FIG. 11 shows an embodiment of a support structure for the sensor from FIG. 10.
DETAILED DESCRIPTION
Smart card
The term “smart card” or “smart card” is used here in a broad sense to refer to any physical object small enough to be held, hung around your neck, or otherwise carried with you has a microprocessor which can store, process and communicate digitally coded information relating to or relating to a particular card holder. A well-known example of such a smart card is the ISO (International Standards Organization) SmartCard, which is the same size and shape as a conventional credit card, but has a flash memory for storing data relating to the user and a microprocessor, which can be programmed with a powerful encryption algorithm that shows whether a PIN (personal identification number), received by a user terminal matches or does not match an encrypted PIN stored on the card, thereby providing a greater degree of confidence that the person presenting the card is the real card holder than • frfrfr frfr fr frfr • frfrfr for frfrfr for · • frfrfr which is based only on a visual comparison of signatures and / or a physical similarity.
Reference should now be made to FIG. 1, which shows an embodiment of an intelligent card with a biometric confirmation located on the card. The card 100 is generally made of a plastic and has the overall appearance of a conventional credit card with approximately the dimensions as defined in ISO 7816 at approximately 53.98 x 85.6 mm and a thickness of approximately 0.76 mm or more .
Similar to a conventional credit card, the card 100 has a free upper area 102 which extends transversely across the entire width of the card to form a magnetic stripe (as defined by ISO 7811-2 and 7811-6) on the back of the card will carry), on which conventionally coded alphanumeric information about the card holder and any associated account can be stored, whereby the card 100 can be used in a conventional magnetic stripe reader. However, since any data embedded in the magnetic stripe can easily be changed, such a magnetic stripe is only intended for use in certain applications where the need for backward compatibility with older magnetic stripe-based terminals outweighs a possible security breach that a magnetic stripe in the system brings in.
The upper area 102 can also be used to carry various measures to prevent fraud, for example a forgery-proof color photo of the card holder and / or a hologram logo of the card issuer. The lower area 104 of the card 100 can be used in a conventional manner for embossed information (as defined by ISO 7811-1), for example for the name of the card holder, for the identification of a numbered account (or card) and for an expiry date, in order to be able to use the card 100 in a conventional card printer.
• · · · ·· ··· • · · · · ··· · • · t · · · · • · · ·· · · ·· ·· ·· ·· ·· ···
The upper area 102 and the lower area 104 are separated by a central area 106 in which a row of 8 visible iSO SmartCard contact connections 108 are embedded, which provide a convenient electrical connection between the card and corresponding contacts on a card reader. With this device, not only data but also a voltage supply as well as clock signals and control signals can be exchanged between the reader and the card, as specified in ISO 7816-3.
On the right side of the area 106 a sensor field 110 can be seen which is used to obtain fingerprint data from the finger of the card holder. The card is preferably provided with an ID code which is unique to the sensor 110 or some other electronic component embedded in the card, for example a code in the format of a conventional IP and / or MAC address.
Furthermore, FIG. 1 shows, in a simplified manner, various additional electronic components which interact with the contact connections 108 and the sensor 110 in order to provide greater functionality and, in particular, better security than would otherwise be possible.
In one embodiment, the ISO smart card compatible processor 112 is directly connected to ISO contact terminals 108 to provide an electrical connection to an external ISO compatible card reader (not shown), thereby not only providing a power supply for the Electronics located on the card but also to provide a device to transfer data between the card and any external communication software, security software, a transaction software and / or another application software that runs on the card reader or on any associated computer devices that are networked with the card reader.
Although in the embodiment shown the data path between the card 100 and the external card reader is shown as a wired connection using an ISO-standardized SmartCart contact arrangement, it can be seen that ·· ·· ·· «· ·· ···· · • «· · ·· ··· ···· * · ·· · ···· 9 9 9 9 9 • ·· ·· ·· ·· · ·· · Λ 9 9 9 9 9 99 9 for others Embodiments other transmission techniques can be used, for example USB or RS 232C or SPI (serial) connections, possibly wirelessly via RF (radio frequency), microwave and / or IR (infrared) connections.
Although the embodiment described receives the voltage supply from the card reader, other embodiments can also have a voltage supply located on the card, for example a solar cell or a battery. Such a voltage supply located on the card can be advantageous, for example, when the mechanical interface between the card 100 and a certain type of card reader is constructed in such a way that the user cannot access the fingerprint sensor 110 when the contacts 108 with the corresponding connections are connected within the card reader, whereby the fingerprint data of the user must then be obtained, when the card 100 is not wired directly to the card reader.
Security processor
As can be seen, the security processor 114 is located between the iSO processor 112 and the sensor 110 in order to provide secure processing and storage of the data obtained as well as a secure access protection system (firewall) to protect the data and the programs contained in their Dedicated memory are stored to protect against an unsuitable access attempt via the ISO processor 112, as will be described later. Such an access protection system (firewall) can be constructed in such a way that it only lets through encrypted data which use a key for the encryption which is based on a uniquely assigned network address or is otherwise unique for the special card, for example data from a previously stored one Fingerprint pattern or a uniquely assigned device number, for example a CPU number or the number of a fingerprint sensor, are derived. In another embodiment, the firewall only allows data through which contains unique identification data from a previous transmission or data. In still further embodiments, the Zu • A ·· • ·
999 · ·.
In a further embodiment (not shown), the security processor 114 is directly connected to the ISO contacts 108 and works as a safe guard between the ISO processor 112 and the ISO contacts 108. Such an alternative structure has the advantage that the additional security by security processor 114 and sensor 110 without compromising any security features that may already be included in ISO processor 112.
The security processor 114 preferably has a non-volatile semiconductor memory or non-semiconductor memory, for example an FRAM, OTP, E<sup>2</sup>PROM, MRAM, MROM to store a pre-registered fingerprint pattern and / or other personal biometric information. In other embodiments, some or all of the functions of the security processor 114 may be implemented in the ISO processor 112, and / or some or all of the functions of the ISO processor 112 may be implemented in the security processor 114. Such a combined implementation can still have an access protection system for the software (software firewall) between different functions, which is particularly advantageous if the device has been implemented in a method that does not allow any subsequent modification of the stored software programs. On the other hand, both processors 112, 114 can be separate processors in a single multiprocessor stage that is designed to protect each processor from any interference by the other process running on a different processor. An example of such a multiprocessor stage is the DDMP (data driven multiple processor) from Sharp, Japan.
Although these various sensors and contacts as well as other electronic components, such as the printed circuit boards or other electrical wiring, are connected via • · • ·
9
9 99
9 The preferred arrangement in the central area 106 between the upper area 102 and the lower area 104 protects them from being connected to one another, preferably completely contained within the body of the card 100 so that they are protected from wear and tear and external contamination against possible damage from conventional magnetic stripe readers, embossing and printing devices that have a mechanical interface with other areas.
LED feedback
Light-emitting diodes (LEDs) 116a, 116b are controlled by the security processor 114 and provide the user with visible feedback. In the embodiment shown, they are arranged in the lower region 104, preferably at a point on that side edge of the card which is remote from the contact connections 108. In any case, the LEDs II6a, 116b are preferably arranged where they cannot be damaged during an embossing process and where they are visible when the card is inserted into a conventional ISO SmartCard reader and / or while the user's fingers are over the fingerprint sensor 110 is placed. For example :
in confirmation mode:
- RED flashes:
- blinking stops:
- RED flashes once:
- GREEN flashes long once in registration mode
- GREEN flashes:
- blinking stops:
- RED flashes once:
- GREEN flashes once waiting for the finger
Finger is placed on the sensor no match possible, finger has to be moved
Match, finger can be removed waiting for the finger
Finger is arranged on the sensor no registration possible, finger must be moved registered, finger can be removed • · ···· ···· · ·
9 9 9 9 9 9 9 9
99 99 99 99 9 • · ·· · «· · 9 9 9 in release mode:
- GREEN and RED flashing: ready to delete
- GREEN flashes once: deleted
There are many ways in which the user can arrange their finger for a successful match or registration before a rejection message is transmitted. In one embodiment, a rejection message is transmitted to the authentication server only if the user removes their finger before receiving the green ok indication or if a predetermined time limit has been exceeded. Such a process not only educates the user to optimally position his finger over the sensor, which not only reduces the complexity of the calculation, but also enables the use of more precisely discriminating threshold values. This visual feedback also provides a psychological basis for distinguishing between an inexperienced user (who typically keeps trying until they get the correct arrangement) and a fraudulent user (who typically doesn't want to attract attention and walks away before their malicious intent is recognized) . The end result is a significant reduction in the possibility of false rejections and / or false assumptions.
FIG. 2 shows an exemplary method to assist the user in placing his finger on the sensor 110. In block 150, the RED LED 116b flashes. Once a finger has been scanned (block 152), the LED stops blinking and a check (block 154) is made of the image quality (defined elongated areas corresponding to the peaks and troughs of the skin of the finger). If the quality is poor (NO branch 156), a single blink of the RED LED 116b informs the user that he must move his finger to another location (block 158). Otherwise (YES branch 160), a second test (block 162) is performed to determine whether the same finger is in the same position that was used to register the user, so that a relatively simple match Algorithm can confirm that the direct data within a given threshold value meets the requirements
<img file="AT500802A2_D0003.tif" />
♦ · · · 9 9 9 9 9 99 9, confirming that the direct finger is the same finger that was originally registered (YES branch 164), and the GREEN LED 116a becomes sufficiently long (block 168) is put into operation (block 166) to confirm that a successful match was made and the user can now remove their finger. On the other hand, if the match threshold is not met (NO branch 170), a single blink of RED LED 116b (block 158) informs the user that they need to move their finger to another location and the process is repeated.
Exemplary network architectures
Reference is now made to FIG. 3, which shows a possible embodiment of a biometric confirmation system which can carry out both local and remote confirmation of the identity of a person who presents a secure identification card. The system has three main components: a client terminal 200, an application server 202 and an authentication server 204. The client terminal 200 works so that it can take the fingerprint of a user directly and process it locally in order to encrypt the locally processed data, and can establish secure communication with the application server and the authentication server, preferably via the Internet , using the IP / TCP addressing scheme and transmission protocol, protection against malicious access is provided by conventional IP access protection systems (firewalls) 206. In other embodiments, the access protection systems 206 may be comprised of filters and cipher encoders / decoders that encode transmitted data after confirming that it is approved data and decode received data before deciding whether it is authorized data, for example using an encryption algorithm such as DES128. The access protection system 206 can thus assess data not only on the basis of the message header but also on the basis of the message content as approved or possibly malicious data.
• φ φ φ φ φ φφφφ φφφφ φ φ φ · · · φφφφ φ φ φφ φφ φφ φφ φ • Φ φφ φφ φφ φ ΦΦΦ
The client terminal 200 can be implemented as a device of a dedicated network, or it can be implemented as software that is installed on a programmable desktop, notebook or other workstation or personal computer that is operated with a common operating system, for example Windows XXX , OS X, Solaris XX, Linux or Free BSD. The client terminal 200 preferably has up-to-date negative databases (for example identification data of lost or stolen cards or restrictions on a specific card or card groups), which provide an additional level of security.
The application server 202 operates to execute a transaction or otherwise respond to commands from the remote user at the client terminal 200 after the authentication server 204 has established the identity of the user. The authentication server 204 operates to establish secure communication with both the client terminal 200 and the application server 202 in order to store authenticated fingerprint data as well as other information pertaining to previously registered users to the stored Compare data with the encrypted direct data received from client terminal 200 and notify application server 202, whether the specific direct fingerprint data match the specific stored fingerprint data.
More specifically, the client terminal 200 further includes two main components: a fixed card reader 208, which component includes an Internet browser terminal 210 and a card reader interface 108a (which can be a simple USB cable that is in a Series of electrical connections ends in order to establish a corresponding electrical connection with the ISO SmartCard contact connections 108), as well as a portable component of the intelligent card 100 '. In one embodiment, the portable component 100 ′ may be the smart card 100 described above, including the fingerprint sensor 110, the security processor 114, and the ISO smart card processor 112.
The application server 202 furthermore contains an Internet server interface, which has the access protection system 206 and the Internet browser 214, as well as a transaction application module 216 and a validity module 218. If the application server and the application module 216 are legacy devices that are not designed to communicate externally using the IP / TCP protocol, the access protection system 206 can be replaced by a suitable protocol converter that contains the validity module 218 and has a fixed IP address. The application service server can, for example, be operated by a third party who is willing to provide services to an authorized user via the Internet.
The authentication server 204 further includes an Internet server interface 220, a processing module 222 which has a fingerprint matching algorithm 224, and a database 226 for storing fingerprint information and other authenticated information that was then collected from individuals, if these individuals have been registered in the system and their identity is guaranteed to the satisfaction of the system operator. As a further increase in security, the stored data for any particular individual are preferably not stored on the application server as the only sequence of information, but rather each value is stored separately, taking into account any required indices or relationships with which these values are connected can only be accessed with an appropriate key, which is kept as part of the private data of the individual in the authentication server.
arrangement
In certain embodiments, the fixed reader 208 and / or the portable card 100 can also be equipped with an integrated global positioning satellite (GPS) receiver 212 that provides useful information about the current location of the reader and the map to or from can deliver around the time a particular transaction takes place. In particular, the location data from the GPS receiver 212 can be used to then (either permanently or temporarily) save the reader and / or the card
9· · 9
9 if they are brought to a place where their use is not authorized. The location can also be determined other than with the GPS, for example using the PHS (Japanese mobile phone) call location method, or with location sensors that respond to local changes in the earth's electromagnetic field. If the map is equipped with GPS, the various GPS components, including the antenna, signal amplification, A / D converter and sample / hold stages, and the digital processor for calculating the location are preferably part of a single one integrated circuit or as discrete components on a single circuit board that is integrated into, embedded in, or laminated onto the body of the card.
Card architecture for an ISO card with adapting ISO processor interfaces located on the card
4 shows a functional block diagram of an exemplary biometric confirmation card 100 or 100 'compatible with the ISO SmartCard with various physical data paths that are used during the first loading of the biometric data of the card holder and during the confirmation of the identity of the card holder on a remote application be used.
In particular, in addition to the ISO processor 112 described above, the security processor 114, the fingerprint sensor 110, the LEDs 116a, 116b and the optional GPS receiver 212, only the ISO processor 112 is directly connected to the card reader 208 via the ISO SmartCard contact terminals 108 are connected, a separate charging module 300 and an assigned temporary connection 302 are shown, which provides direct communication with security processor 114 during the user's initial registration. It should be noted that the ISO processor 112 communicates with the safety processor 114 via I / O ports 304, 306, while the temporary load connection 302 is connected to a separate I / O port 308. The security processor is preferably programmed in such a way that sensitive, security-related data or software can only be accessed from connection 308 and · · ···· * · * · «« • · · 4 4 9 4 9 4 44 4 cannot be accessed from ports 304 and 306, eliminating any possibility of malicious access to this sensitive data, after link 302 has been taken out of service.
Most commercially available ISO processors have at least two I / O ports, while some have at least three. Only one of these connections (I / A1) is provided for the conventional serial data connection 108 of the ISO smart card with the external ISO-compatible card reader 208. The additional one or two I / O ports preferably provide dedicated hardwired communication between the ISO processor 112 and the security processor 114 that acts as a hardware access protection system to prevent any malicious attempts to re-establish the security processor 114 program or gain access to any sensitive information, which was previously obtained with the sensor 110 or can be stored in the processor 114 in some other way. In the special case of an ISO processor with more than two I / O lines, it is possible to display more than two states of static status information on the dedicated communication path between the ISO processor and the safety processor, for example 1) ready, 2) busy,
3) error, 4) run, even if the safety processor is completely shut down. Even if only one I / O connection is available, these four states can of course be transmitted dynamically as serial data.
These possible commands and data that are transferred between the ISO CPU and the safety CPU via the ISO interfaces I / O-2 and I / O-3 include the following:
Commands for registering or authenticating a user to whom the security CPU sends a result of the registration or a result of the authentication for local storage and / or transmission to a remote application;
- Fingerprint information can be sent as a template (reference value) from the security CPU to the ISO CPU in order to save it in the ISO SmartCard memory for transmission to remote applications. For increased security of sensitive personal information, the reference data can be obtained from the formations the reference data can be encrypted by the security CPU before it is sent to the ISO CPU.
Load connection 302 provides a direct connection to security CPU 114 which bypasses any protection from an access protection system provided by ISO connection and associated dedicated I / O ports 304 and 306, while possibly communicating between ISO-CPU 112 and the ISO reader 208 is maintained, so that a voltage supply is also available for the safety CPU 114. The connection is mainly used during the initial registration of the card for a specific user and should be protected against unauthorized access.
FIG. 5 shows an alternative embodiment of an exemplary biometric confirmation card from FIG. 4, which is intended for use with an unchanged ISO smart card CPU. In particular, the ISO CPU 112 'no longer needs to perform any network functions between the card reader 208 and the security CPU 114', either during normal operation or while loading, which means it can be any ISO-proven chip that has not been modified and only so used to be transparent to both the card reader 208 and any external application. In such an alternative embodiment, the security CPU 114 'operates as a transparent access protection system between the ISO-CPU 112' and an external application if the fingerprint taken matches the stored fingerprint, and it prevents any such communication if the fingerprint taken does not match matches the stored fingerprint.
Initializing a card and protecting the stored data
guillotine
In one embodiment, the originally manufactured card has a protruding extension with a printed circuit, which establishes a direct connection to the security CPU and at least to parts of the ISO interface and / or to a discrete memory located on the card frfr • frfrfr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr fr you This discrete connection interface is only used for checking the card and for registering the fingerprint data and has the signal with which the registration process is started. After registration is complete, this circuit extension is mechanically separated so that no further registration is possible, with the memory of the safety CPU only being accessed via the ISO CPU and the above-mentioned access protection system between the ISO CPU and the safety CPU can be.
Fuse
In another embodiment, the security CPU has a memory which can no longer be accessed once the registered fingerprint pattern has been written. An example of such a memory is the one-time PROM (OTP, one time PROM), which is similar in structure to an EEPROM, but is impermeable to UV and therefore cannot be erased. Another example of this is a FlashROM, which is only made readable after the end of the registration, for example by applying a sufficiently strong current to the switch-on or address or data signal path to create a physical interruption (fuse) in this signal path .
Exemplary authentication procedures
In one embodiment, an exemplary authentication method includes the acquisition of physical fingerprint data, for example using an optical method, a printing method, a conductive or a capacitive method, an acoustic or an elastic method or a photographic method at the client terminal, which is recorded by the accessing person is used to establish a connection with the application service server, the data then being transmitted (preferably in encrypted form) to a separate fingerprint authentication server. The fingerprint authentication server compares the taken fingerprint data with a fingerprint file containing the registered fingerprint data of the user, using an authentication • fr • fr • fr • •• for fr ··· · • frfr frfr ··· · · · ·· frfr frfr frfr fr
Software, the authentication server sending a switch-on command to the application service server if the data match.
In another embodiment, the user accesses the secure WEB browser of the fingerprint authentication server, which contains files of fingerprints in which all fingerprints are pre-registered together with individual data such as name, address and date of birth. The secure fingerprint authentication server, which the user accesses via a secure protocol, for example in HTTPS format, then sends a command to the client terminal to take the user's fingerprint at the client terminal. Depending on the commands that are displayed by the browser of the client terminal, the user places his selected finger on the fingerprint sensor, the software in the client terminal taking a digital fingerprint for taking the fingerprint, for example one on pixels based image with a resolution of 25 microns by 70 microns and an area of 12.5 mm by 25 mm, and it also has an 8-bit gray scale.
The secure fingerprint authentication server receives the fingerprint data together with the ID of the user and an IP Internet address and / or an individual code of the fingerprint sensor (MAC address) and / or a cookie and / or a one-time code or other information, with which the specific individual or the terminal (e.g. details of a previous conversation between the client terminal and the secure fingerprint authentication server) is recognized, whereupon it compares the received fingerprint data with a fingerprint file, which is the pre-registered fingerprint data together with the ID of the user, individual information, for example the name, the date of birth, a criminal record, the driver's license, the Social security number, etc., using authentication software, which can be a minutiae comparison or a comparison with a fast Fourier transform.
• 9 9 9 ·· · ··
9 9 9 9 9 9 9 · ·
9 9 9 9 9 9 9 · • 9 9 ·· ·· · 9 ·
99 99 99 9 999
At the beginning of the authentication process, the web server 214 for the application in question informs the user optically or acoustically that he should place his finger on the sensor for taking the fingerprint 110 and press his mouse button or a key on the keypad to thereby use the software for removal of the fingerprint in the security processor 114 in operation. The fingerprint data obtained from the user are then sent in an encrypted format (for example using the secure RSA-encrypted transmission protocol HTTPS) via the ISO processor 112 and the web browser 210 of the client terminal 200 to the web server 220 of the fingerprint authentication server 204. If the data obtained have been successfully matched with the corresponding data in its database 226, the fingerprint authentication server 204 declares the identity of the user to be valid, both to the client terminal 200 and to the application server 202.
An exemplary embodiment which is preferred, which uses a three-way authentication protocol and a one-time password as the coding sequence of hash characters, will now be described in connection with FIG. 3.
The web browser 210 of the client terminal 200 accesses the corresponding web interface 214 of the application server 202 with a request to access the application method 216.
The web interface 214 of the application server 202 responds with log-in information and relevant commands in order to access the application method 216.
The client terminal 200 instructs the ISO processor 112 to put the security processor 114 into operation.
The ISO processor 112 triggers the security processor 114.
The security processor 114 expects the fingerprint data from the fingerprint sensor 110, and if valid data is received, it then emits a digital fingerprint sample which is forwarded to the web browser 210 via the ISO processor 112.
The web browser 210 sends an encrypted version of the issued fingerprint pattern for authentication • ftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftftft
Server 204 to which relevant information about the card 100 'involved and the card reader 208 is attached (or encrypted with it), for example the ID of the user, the IP address of the client terminal 200 and / or a hard-wired ID code (MAC Address) of sensor 110.
The web interface 220 of the authentication server 204 forwards the information to the fingerprint matching processor 222 along with the other information from the client terminal 200 upon receipt of the submitted fingerprint sample.
Under the control of the matching software 224, the fingerprint matching processor 222 uses the received ID of the user or other pertinent information specific to the user to fetch a corresponding reference fingerprint pattern from the database 226, wherein it uses the obtained fingerprint. Compare the sample with the reference fingerprint sample.
The result (matched or not matched) is stored in a past memory together with the relevant information which identifies the terminal 200, the ID card of the user 100 'and the requesting application 216, with a controller returning to the interface of the authentication server 220 is sent.
If the result is a match, the authentication server 220 web interface then generates a one-time password in the form of a challenge string which is transmitted to the client terminal 200, using that the challenge string is a hash code to use the to encrypt relevant information, which he saves as a corresponding challenge response for possible future reference values.
The client terminal 200 uses the received challenge character string as a hash code in order to encrypt a previously stored, unencrypted copy of the relevant information, which is then sent to the web interface 214 of the application server 202 as part of its response. · · · · · ··· · · · · ·· ·· ·· ·· · ··· is forwarded to the recurring log-in attempt.
When the relevant hash-converted information is received, the web interface 214 of the application server 202 forwards it to the application service 216, where it is linked to a log-on attempt from this client server and the relevant information to confirm the matching result forwards received information which has been hash-converted by the client terminal using the challenge character string which the authentication server delivers as a challenge response.
- The web interface 220 of the authentication server 204, upon receipt of the challenge response from the application server, forwards this response to the authentication processor 222, which compares it with its previously saved reference copy of the expected challenge response to determine whether the The user's identity has actually been authenticated.
Any authenticated information about the identity of the user derived from this comparison is then passed back to the application process 216 via the web interface of the authentication server 220 and the validity interface 218 of the application server 202.
The validation interface 218 uses authentication to confirm the identity of the user as validated in the original log-on attempt.
Once the identity of the user has been confirmed, the authentication method 216 continues in order to communicate directly with the web browser 210 of the client terminal 200 via the web interface 214 of the application server 202.
FIG. 6 shows an alternative authentication method in which all the matching on the ISO-compatible card of FIG. 4 is performed by the security CPU 114 and no external authentication server 204 is used. The left-hand side of Fig. 6 shows the functions that the application can perform. · · ···· · · · · · * * 9 9 ·· ·· ·· ·· ···
Server 202 executes, while the right-hand side shows those functions which are executed by the ISO smart card 100.
When a SmartCard 100 is inserted into the card reader 208, the card reader sends both the ISO-CPU (start block 502) and the fingerprint CPU 114 (fingerprint confirmation block 504) a reset signal RST, both of which have a voltage VCC from Card reader 208 received. The ISO-CPU then responds with an ATR (response to reset, answer-toreset) message and communicates as required, PPS (protocol and parameters selection) (block 506). At the same time, the fingerprint CPU pauses to receive fingerprint data, performing the authentication process (block 504) when data is received from the sensor 110.
When the original request command is sent from the application 216 to the ISO CPU 112 (block 508), the security CPU questions (block 510) the authentication status. If the answer is positive, the ISO-CPU responds to the application by executing the requested command (block 512). Otherwise (either in the event of an error message or no response from the safety CPU 114) it does not respond to the requested command, but waits for a new first request (block 508b).
Assuming that the fingerprint has been confirmed and the time of the first response has been received and it has been determined that it responds to the application 216 (block 514), the request / response process is continued (blocks 516, 518,
520) until a predetermined confirmation timeout has been exceeded, during which no requests are received from the application (block 522), or the application has not received an expected response (block 524).
FIG. 7 is similar to the flow diagram of FIG. 6, but has been modified for use with the exemplary biometric confirmation card of FIG. 5. On the far left, Fig. 7th the functions carried out by the application server 202, the next column corresponds to the reader 208, the next column shows the ISO contacts 108, the next column shows the functions of · · · · · · · ·· ·· ft ·· ·· ftft ftft ft ··· functions performed by the safety CPU 114, while on the far right those functions are shown that are performed by an unchanged ISO SmartCard CPU 112.
If either a smart card is inserted into a card reader or the application software starts the operation of a card reading device, a reset signal 550 is output from the card reader 208 to the security CPU 114.
- Soon after the security CPU receives the reset signal 550, it sends a corresponding reset signal 552 to the ISO-CPU 112. At the same time, the security CPU expects fingerprint data from the fingerprint sensor.
When the reset signal 552 is received, the ISO-CPU executes an ATR (answer-to-reset) response 554, whereupon it executes a PPS (protocol and parameters selection) if necessary.
As soon as the security CPU rll4 receives the ATR (answer-to-reset) from the ISO-CPU, it transmits it to the card reader (block 556), including any associated PPS commands.
- In the meantime, when the Security CPU receives fingerprint data, it carries out the authentication process described above. If the verification results of the authentication lead to a CONTINUE, the Continue status is retained for a certain time interval. If the result is ERROR, the security CPU is expecting new fingerprint data.
- When the application is executed, a command request 558 is sent to the security CPU, which transmits a command request 560 to the ISO-CPU, whereby it also only transmits its correct response 562 to the card reader if the security CPU continues in the above-mentioned CONTINUE -Status is, or if the last correct answer set the more data bit (test block 564).
- Otherwise (NO branch 566) the fingerprint CPU generates a dummy request 568 and transfers this to the ISO CPU, whereby it also generates the resulting ERR response · ♦ ·· ···· ·· · »« · ·
9 9 9 9 9 9 99
9999 9999 9 9
9 9 9 9 9 9 9 9
9 9 9 9 9 9 9 9 9 •9 99 99 99 9 999
570 to card reader 216, thereby maintaining proper synchronization between the sequence numbers in the requests and responses.
Encryption and security
Before being transmitted over any external network, any sensitive data and / or the authentication result is preferably encrypted, possibly using DES coding or Twofish encryption. The key for the encryption can be based on obtained or stored fingerprint data, the ID code of the user, a code uniquely assigned to the sensor, a memory address, neighboring data in the memory, other functionally related data, a previous conversation (transaction), an IP Address or an assigned password. On the other hand, sensitive data can be sent over the Internet using the secure HTTPS protocol.
To achieve even greater security, a virtual, private gateway computer, for example hardware DES encryption and decryption, can be used between the secure fingerprint authentication server and the network connection and thus between the application service server and the network connection. If such a virtual gateway computer or a virtual private network (VPN, virtual private network) is used, the sensitive data is additionally protected by an additional level of encryption, for example both DES 128 (typically used in VPN) and RSA (used in HTTPS ).
For particularly secure applications, all communications can be packaged in additional security levels. In particular, headers at a lower level can be encrypted to a higher level.
Wireless communication
Other embodiments can have a dual interface for both wired (ISO 7816) and wireless (ISO 1443 A or B) operation and preferably multi-interface - Have a voltage level that allows intermediate operation between ISO 7816 wired systems, ISO 1443 A, ISO 1443B, ISO 15693, and hi-fi wireless input systems (among others), all of which are on the card. On the other hand, the card can have devices for other wireless communication technologies, for example Bluetooth (short range) or mobile phone (medium range) or microwaves (long range).
Referring now to Figure 8, there is shown an intelligent card with an on-card biometric confirmation that can be connected to a local terminal either wirelessly or through an electrical connector. For the most part, in its construction and in its architecture, it is the same as the embodiment of Fig. 1 similar, the same reference numerals (possibly distinguished by a single quotation mark) denoting similar components. In particular, the ISO-CPU 112 is shown in a different location (below rather than next to one side of the contacts 108), but it has the same functionality as described above.
An ISO antenna 132 includes two loops generally around the edge of the card 100 and provides an ISO compatible wireless interface to the ISO CPU 112 for both data and power, similar to wired electrical Interface 108 supplies. In addition, a safety antenna 134 (in the example shown within the antenna 132 and only made up of a single loop) supplies a separate voltage source for the safety CPU 114 via a DC voltage converter 120. Since there is no direct connection for wireless data except via the ISO -CPU 112, the sensitive data stored in the security CPU 114 are not endangered by such a wireless interface. On the other hand, as mentioned above in connection with those embodiments that only have wired connections to the external reader and the external network, the functionality of the two processors can be combined, or the external interface can be via the security CPU 114 instead of via the ISO -CPU 112, with suitable wireless • ·
9
9
9
9 99
9 9 9
Security measures must be introduced into the architecture modified in this way.
FIG. 9 shows a section through the card of FIG. It should be noted that most of the components described are contained in a central core 126, with only contact connections 108 running through the upper protective layer 122. The operative area of the sensor 110 can be accessed through an upper window in the upper layer 122 and a lower window in the printed circuit board (PCB) 134 located between the upper layer 122 and the center core 126 and as required provides electrical connections between the various electronic components, as well as a ground connection for electrostatic discharges, which surrounds the active area of the sensor 110.
A lower layer 124 and a magnetic stripe 128 can also be seen.
Fingerprint sensor
FIG. 10 shows the exemplary circuit diagram for the sensor 110, in which an arrangement 400 of sensor cells 402 is aligned in rows 404 and columns 406. As can be seen, each cell 402 has an activation electrode 410 and a transducer 412. A fingerprint is formed from the bumps and pits of the skin on a finger. Each sensor cell transducer 412 undergoes a mechanical and / or electrical change when one of these bumps touches the immediate vicinity of the cell 402 within the assembly 400, thereby providing a digital image of the fingerprint based on micro-pressure changes across the sensor surface generated by the Elevations and depressions are caused on the fingertip. It should be noted that while each transducer 412 is shown as a single variable capacitor, there are several types of transducers that may be responsive to the presence of these bumps on human skin: In the specific example of a piezo pressure sensitive thin film transistor, the film near the cell is deformed, generating a charge which is formed in a condenser. · »·· ·» «·· · tor associated with this cell. The voltage on the capacitor is therefore a function of the mechanical stress that is formed by the deformation of the piezo material, which in turn is a function of whether there is an elevation or a depression above the cell. When a signal from the associated column driver 414 turns the control electrode 410 ON and the associated row driver 416 is grounded, this voltage appears on the output line of the row 418, and is converted into a digital 8-bit signal in the output driver 420. To maximize the sensing of the deformation of the piezoelectric material, the piezoelectric material can be formed on a resilient material, such as a polyamide, or it can simply be a piezoelectric polyamide material. Other exemplary analog conversion techniques that can be practiced with a similar arrangement include variable resistance and capacitance. On the other hand, each cell can consist of a simple digital switch that supplies only a single bit of information. In this case, additional bits of information can be generated by placing more cells in the same area or by scanning all cells at a higher frequency. In such an alternative embodiment, no A / D converters are required.
In an exemplary embodiment, the sensor is only 0.33 mm thin and durable enough that it can be embedded in a SmartCard, exposed to static electricity, the components or the conditions (wet, dry, hot, cold) of the skin User is not affected. A typical uniform cell size of the sensor 110 is 25 microns by 70 microns and a typical cell jump is 25 microns by 70 microns. The exemplary sensor has a rectangular sensor area of 12.5 mm by 25 mm and a multi-level 8-bit sensitivity. Such a sensor can be made with an arrangement of thin film transistors TFT and pressure sensitive capacitors, such as those formed by a thin film piezomaterial such as titanium barium oxide or strontium barium oxide, with an upper electrode covering the entire scanning area and protects. If a mechanical «· · * ····« · · * ·· ···· ·· ··· • · · · · «·· · · ···· ···· ·» ··· « ·· »· · ·» ·· ·· ·· «···
When the load is applied, a corresponding charge is generated and stored in the thin-film piezo capacitor. On the other hand, a pressure-based sensor can be an arrangement of thin-film transistors TFT together with thin-film capacitors and pressure-sensitive capacitors, such as those formed by a sheet of a pressure-transmitting material, for example a rubber sheet with distributed carbon fibers, a metal (e.g. Copper or tin or silver), a paper based on coated carbon fibers or glass fibers, or an elastic material (e.g. silicone) with distributed metal, as well as an upper electrode foil that covers the entire sensor area.
The row and column drivers 416, 414 with the specially defined fingerprint sensor element 402 emit the electrical data to the output stage 420, whereby the physical input, which represents the fingerprint of the user, is converted into analog electrical data. An A / D converter in the output stage 420 then converts the analog electrical signal into a digital electrical signal. Each thin-film transistor optionally connects a multiple-use internal series connection with the voltage of its assigned capacitor, so that the voltage on each capacitor can be read out and thus the deformation of each cell can be measured. A whole column of thin film transistors is preferably switched simultaneously, whereby a number of cells (e.g. 8) in a selected column can be read out in parallel on two different row internal connections. The internal connection of multiple control electrodes to form rows and columns reduces the number of internal connections, while the parallel readout of several cells from different rows of the same column reduces the readout time for the entire arrangement. The output voltage from the sensor can be amplified with a suitable differential amplifier. The output of such an amplifier can be sampled and held for an analog / digital conversion (A / D converter).
The substrate can be glass (e.g. non-alkaline glass), stainless steel, aluminum, ceramic (e.g. aluminum)
4
4 »·· 44 44 4 444 umoxide), paper, glass fiber reinforced epoxy, but a thin film of crystalline silicon is preferred. The material of the thin film semiconductor can be amorphous silicon, polysilicon, diamond or any other semiconductor thin film. The piezoelectric material can be a piezoelectric ceramic such as bi-zirconate titanate (PZT) thin films, preferably between 0.1 to 50.0 microns in thickness, or a polymeric piezoelectric polyamide thin film material. The internal connection material can be Ti / Ni / Cu, Al, Cr / Ni / Au, Ti / Ni / Au, Al / Au, W / Cu, W / Au, W / Au.
11 shows a support structure for a sensor which is formed by a thin substrate made of crystalline silicon. Crystalline silicon has excellent electrical properties and makes it easy to integrate the sensor assembly with the required driver and output stages, but a relatively large and thin layer of silicon flexes and breaks when exposed to localized surface pressure. The carrier shown provides a much more rigid structure than would be the case with a silicon layer with the same overall thickness.
As can be seen, the monolithic layer of silicon 430 has a thickness of about 0.1 mm, and it is surrounded by an equally thick frame 432 made of glass fiber reinforced epoxy, which is attached to a rear wall 434, which also has a structure made of glass fiber reinforced epoxy and is about 0.05 mm thick. The frame 432 and backplane 434 can be easily assembled using any conventional printed circuit board (PCB) technique. In particular, the upper and lower surfaces of the rear wall 434 are covered with thin layers of copper 436, which are separated by a glass fiber reinforced epoxy core. The frame 432 has a number of solder terminals 440 on its outer edge in order to establish a connection with the security processor 114. The thin silicon chip 430 is epoxy bonded to the frame 432 and the wall 434, the active areas being electrically connected to the corresponding electrical points in the frame 430 via conventional wiring 422 on the exposed outer edge portions 444 of the silicon 430 • · · · ·· ··· • ftftft ···· · · • ftftft · · · ft ft ♦ ••••••• ft ft • · ·· ftft ftft · ftftft which surround the upper protective electrode 446.
Match algorithms
For local processing on the card where processing voltage is limited and only a simple 1: 1 match with a single reference value is attempted, the fingerprint match software can rely on a relatively simple forward comparison of minutiae from two patterns come. For example, the image of the gray scale of a fingerprint can be reduced to two values, white and black, with three-dimensional elevations being converted into two-dimensional thin lines (vectors). The accuracy of the method depends, among other problems, on blurring, sticking, distortion, a partial lack of line segments and other effects. Although the minutiae method is less precise in principle, it requires fewer computational resources and offers the possibility of compatibility with many existing databases.
For more powerful processing on a remote authentication server, where a power supply is available for processing and a more precise differentiation may be required, this can be, for example, a POC (phase only correlation) matching algorithm. The POC is a recognition algorithm based on a macroscopic correspondence of entire images. Conversely, the POC matches structural information over a wide range - from details to the entire image. The POC is thus able to deliver a stable accuracy against disturbances, for example against sticking and partial gaps. In principle, the POC method is free from adverse effects on positional shift and differences in brightness, it is fast (about 0.1 seconds for an off-line match), and it is very accurate. The POC software can, for example, carry out a spatial frequency comparison of the two fingerprint patterns using a two-dimensional first Fourier transform (2DFFT). The 2DFFT sets an arrangement of digital data, which has a • · · · · • 9 · · · · »··· · · Φ Φ
9 Φ Φ φ · «· φ φφφ represent the physical, two-dimensional spread of the fingerprint, in a frequency space. In other words: it is a backward division of space, in which a pattern with a higher density has a higher spatial frequency. A rotation transform can be used to adjust the frequency space pattern match. POC pattern matching has the further advantage of minutiae vector matching because it is not misled by common errors in the recorded fingerprint pattern which the POC would recognize as a disturbance, but a minutiae analysis would interpret it as meaningful data.
For particularly demanding applications, a hybrid approach can offer greater accuracy and security than either method alone. For example, a minutiae method can be used at the point of acquisition, while the POC method can run on a remote server. In another example, the matching process can analyze both minutiae and spatial relationships to produce a combined result that takes into account the results of both.
Applications
The technology described above provides a high level of security for many applications, both in business and in the public sector. Depending on the requirements for each application, a large number of secure applications can be present together and are in operation on the same card and / or on the same authentication server. In one embodiment, a single card can contain up to 24 independent and secure applications. For example, the technology allows / denies access (physically and / or logically), detects the exact location and / or movement of the personnel and / or monitored persons, while at the same time other secure applications are in operation, each of which is completely and securely controlled by the other is separated.
Among the applications currently under consideration, • · ••• for for ··· · · • •• for for ··· · • ·· forfr ·· forfr for ·· ·· forfr for * for frfrfr it following:
- Airport ID access
- building security
- Access to the hotel room and billing
- hospital
- Online games
- Downloaded entertainment media
- birth certificate
- Computer access
- Driver's license - Transport worker ID and authorization (TWIC)
- Electronic wallet
- Medical information in emergencies
- Explosives license
- Access to public and military facilities
- Concession for dangerous substances (HAZMAT)
- Card for health insurance and benefits
- Access to parking lots
- passport
- pilot license
- Port ID access
- Proof of insurance
- Social security card
- Certified traveling salesman card
- Visa or entry / exit permit
- electoral roll card
- Card for welfare and food stamps
For many of these applications, the memory on the card preferably also provides secure storage of various types of private, personal information, which can only be accessed if the registered card holder has proven his identity and has approved such access. Examples of such private information are:
- Authority information, e.g. name, address, date of birth, place of birth, nationality, religious denomination, membership in organizations, social security number, driver's license number, passport number and entry information, e.g. type of visa, expiry date of the visa, nationality, etc.
• · • · φ φ φφφφ φ · φ φ · φ φφφφ φ φ φφ φ φ φφ φφ φ ·· φφ φφ φφ φ φφφ
- Financial information, e.g. electric wallet, credit card information Visa, MasterCard, American Express, etc., banking information, e.g. bank name, bank balance, information about money transactions, tax number, bankruptcy records, information about money transactions, etc.
- Physiological information or health information, e.g. biometric information for the identification of individuals, e.g. height, weight, fingerprints, iris, retina, hand size, bone structure, voice, DNA; Blood type; Results of medical diagnoses; medical history; medical treatments; Information about insurance; psychological and physiological responses to certain stimuli, etc.
- Information about incidents, e.g. records of criminal acts, crimes, misdemeanors, transgressions.
- Emergency information, e.g. cemetery, relative and other contact information, information about lawyers, information about religion.
- Education, professional life including school attendance, academic degree, employment with a company with regard to FDD.
- History of data access (stores the data of the access history inside and outside the card).
- Information relating to the identity, eg the pattern of the fingerprint, processed fingerprint patterns, results of the fingerprint pattern.
- Passwords, e.g. a permanent password, a temporary password and / or a one-time password.
- Keys for encryption, e.g. a public key, a private key and / or a unique key.
An exemplary card registration system will now be described.
The applicant: fills out and submits an application, preferably including a photograph and fingerprint. For most applicants, an examination of their documents should be carried out to determine their origin, as well as a simple cross-section
9 9 ·· 9 9 9 9 • Checking the information submitted against one or more public or commercial databases is sufficient to establish the true identity of the individual.
After his identity has been verified, the applicant goes to an issuing station where any information deemed necessary by the card issuer is loaded onto the card. The applicant gives their fingerprint on the sensor on the card. Once the fingerprint is satisfactorily placed on the sensor and loaded onto the card, the tab on the card receives an electrical surge that blows certain fuses, preventing anyone from rewriting anything in that particular area of the card can be. The small flap is then cut off / beheaded (similar to an umbilical cord). At this point, the card can only be read or written to using the ISO contact reader or the ISO wireless system.
If it is a networked authentication server, some or all of the data loaded onto the card will also be transmitted to the remote server in encrypted form, possibly supplemented with additional data not normally stored on the card, but for certain highly secure applications are required.
···· · · ·· • · ♦ * 9 · · · 9
4 9 9 4 4 94
9 4 4 4 4 9 » * • · ·· 4 9 · · · ·
Contents7
13 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| MD4012B2 | Cited by | Republic of Moldova | Search report |
67 members in 43 offices
Priority claims20
| Document | Office | Kind | Date |
|---|---|---|---|
| 40971502 | United States of America | P | |
| 40971502 | United States of America | P | |
| 40971602 | United States of America | P | |
| 40971602 | United States of America | P | |
| 42991902 | United States of America | P | |
| 42991902 | United States of America | P | |
| 43325402 | United States of America | P | |
| 43325402 | United States of America | P | |
| 48469203 | United States of America | P | |
| 48469203 | United States of America | P | |
| 20020409715 | – | – | – |
| 20020409716 | – | – | – |
| 20020429919 | – | – | – |
| 20020433254 | – | – | – |
| 20030484692 | – | – | – |
| US20020409715P | – | – | – |
| US20020409716P | – | – | – |
| US20020429919P | – | – | – |
| US20020433254P | – | – | – |
| US20030484692P | – | – | – |
Members67
| Document | Office | Kind | |
|---|---|---|---|
| UY27970A1 | Uruguay | A1 | |
| CA2498288A1 | Canada | A1 | |
| WO2004025545A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2003274967A1 | Australia | A1 | |
| PA8581901A1 | Panama | A1 | |
| PE20040351A1 | Peru | A1 | |
| WO2004025545A3 | World Intellectual Property Organization (WIPO) | A3 | |
| TW200411572A | Taiwan Province of China | A | |
| US2004129787A1 | United States of America | A1 | |
| FI20050253A | Finland | A | |
| FI20050253A7 | Finland | A7 | |
| LU91144B1 | Luxembourg | B1 | |
| SE0500539L | Sweden | L | |
| AR041226A1 | Argentina | A1 | |
| EP1537526A2 | European Patent Office (EPO) | A2 | |
| DK200500499A | Denmark | A | |
| NO20051783L | Norway | L | |
| AP2005003281A0 | African Regional Intellectual Property Organization (ARIPO) | A0 | |
| MA27430A1 | Morocco | A1 | |
| KR20050074950A | Republic of Korea | A | |
| BR0314428A | Brazil | A | |
| BR0314428A | Brazil | A | |
| DE10393215T5 | Germany | T5 | |
| RU2005110924A | Russian Federation | A | |
| MD20050099A | Republic of Moldova | A | |
| HU0500646A2 | Hungary | A2 | |
| HUP0500646A2 | Hungary | A2 | |
| BG109092A | Bulgaria | A | |
| CN1695163A | China | A | |
| ECSP055720A | Ecuador | A | |
| MXPA05002752A | Mexico | A | |
| MXPA05002752A | Mexico | A | |
| PL375780A1 | Poland | A1 | |
| CZ2005209A3 | Czechia | A3 | |
| EA200500476A1 | Eurasian Patent Organization (EAPO) | A1 | |
| SK50292005A3 | Slovakia | A3 | |
| JP2006501583A | Japan | A | |
| LT2005035A | Lithuania | A | |
| LV13365B | Latvia | B | |
| AT500802A2This record | Austria | A2 | |
| LT5344B | Lithuania | B | |
| ZA200502663B | South Africa | B | |
| LT2006029A | Lithuania | A | |
| RS20050213A | Serbia | A | |
| TR2005002225T2 | Türkiye | T2 | |
| TR200502225T2 | Türkiye | T2 | |
| LT5403B | Lithuania | B | |
| AT500802A3 | Austria | A3 | |
| TNSN05068A1 | Tunisia | A1 | |
| US7278025B2 | United States of America | B2 | |
| EA008983B1 | Eurasian Patent Organization (EAPO) | B1 | |
| NZ539208A | New Zealand | A | |
| US2008019578A1 | United States of America | A1 | |
| RU2339081C2 | Russian Federation | C2 | |
| CN100437635C | China | C | |
| MD4012B2 | Republic of Moldova | B2 | |
| ES2336983A2 | Spain | A2 | |
| ES2336983R | Spain | R | |
| AP2205A | African Regional Intellectual Property Organization (ARIPO) | A | |
| ES2336983B1 | Spain | B1 | |
| JP4673065B2 | Japan | B2 | |
| JP2011090686A | Japan | A | |
| TWI366795B | Taiwan Province of China | B | |
| US8904187B2 | United States of America | B2 | |
| IL167360A | Israel | A | |
| US2015379250A1 | United States of America | A1 | |
| MY161401A | Malaysia | A |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| RejectionREJ | REJ |
Numbers
- Publication, DOCDB
- 500802
- Publication, EPODOC
- AT500802
- Application
- 800905
- Application, DOCDB
- 80092005
- Application, EPODOC
- AT20050008009
Titles2
- English
- SECURED BIOMETRIC VERIFICATION OF IDENTITY CROSS REFERENCE TO RELATED APPLICATIONS
- German
- GESICHERTE BIOMETRISCHE ÜBERPRÜFUNG VON IDENTITÄT-KREUZVERWEISEN ZUR VERWANDTEN ANWENDUNGEN
Classification
- CPC, 11
- G06K19/07
- G06K19/077
- G06F21/32
- G06K19/07354
- H04L9/3231
- H04L2209/805
- H04L9/3271
- G07C9/26
- G07C9/257
- G06F21/34
- G06F21/35
- IPC, 6
- G06F21 32
- G06F21 34
- G06K19 07
- G06K19 073
- G06T7 00
- G07C9 00