DE102015114367A1

Device and method for authenticating and authorizing persons

Abstract

The invention relates to a device (1) for authenticating and authorizing persons. The device (1) has a housing (2), at least one display device, at least one energy store (11), a carrier element (10) with a storage element arranged on the carrier element (10), and a scanning device (3) ) To record biometric characteristics of the person. Within the storage element, comparison data of the biometric features for authenticating the person can be stored. The device (1) is configured to transmit a data packet with authentication information of the user to a system requested for access after the user is authenticated by the inclusion of biometric features on the device (1) to be authorized for the system, In which all information on the use is stored. The device (1) is closed in this case in such a way that the data are transferred exclusively in the direction from the device (1) to the system, and that a change, erasure or readout of the data stored in the memory element is prevented. The invention also relates to a method for registering the device to a registerable component of a system to which the device requests access, as well as to a method for authenticating and authorizing persons with the device on the system to be joined. Wherein the transmission of the data exclusively takes place in the direction from the device (1) to the system, and that a change, erasure or readout of the data stored in the memory element is prevented. The invention also relates to a method for registering the device to a registerable component of a system to which the device requests access, as well as to a method for authenticating and authorizing persons with the device on the system to be joined. Wherein the transmission of the data exclusively takes place in the direction from the device (1) to the system, and that a change, erasure or readout of the data stored in the memory element is prevented. The invention also relates to a method for registering the device to a registerable component of a system to which the device requests access, as well as to a method for authenticating and authorizing persons with the device on the system to be joined.

DE102015114367A1, drawing sheet 1
Sheet 1 of 3

Term

Projected expiry 28 August 2035.

  1. Priority and filed
  2. Published
  3. Today
  4. Projected expiry

10 claims: 10 independent, 0 dependent

  1. 1
    Device (1) For authenticating and authorizing persons, comprising a housing (2), At least one display device, at least one energy store (11), A carrier element (10) With a bearing10) And at least one transmission element (12), characterized, that - a scanning device (3) For receiving biometric characteristics of the person, wherein comparison data of the biometric features for authenticating the person can be stored within the storage element, - the device (1) Is configured to transmit a data packet with authentication information of the user to a system requested after access by the user by recording biometric features on the device (1) Is authenticated to be authorized for the system in which all information for usage is stored, and - the device (1) Is closed in such a way that the transmission of the data exclusively in the direction from the device (1) To the system, and that a change, erasure or read-out of the data stored in the memory element is prevented. Vorrichtung (1) zum Authentifizieren und Autorisieren von Personen, aufweisend ein Gehäuse (2), mindestens eine Anzeigevorrichtung, mindestens einen Energiespeicher (11), ein Trägerelement (10) mit einem auf dem Trägerelement (10) angeordneten Speicherelement sowie mindestens ein Übertragungselement (12), dadurch gekennzeichnet, dass – eine Scanvorrichtung (3) zur Aufnahme biometrischer Merkmale der Person ausgebildet ist, wobei innerhalb des Speicherelements Vergleichsdaten der biometrischen Merkmale zum Authentifizieren der Person hinterlegbar sind, – die Vorrichtung (1) derart konfiguriert ist, ein Datenpaket mit Authentifizierungsinformationen des Nutzers an ein um Zugang ersuchtes System zu übertragen, nachdem der Nutzer durch die Aufnahme biometrischer Merkmale an der Vorrichtung (1) authentifiziert ist, um für das System, in welchem sämtliche Informationen zur Nutzung hinterlegt sind, autorisiert zu werden, und – die Vorrichtung (1) geschlossen derart ausgebildet ist, dass die Übertragung der Daten ausschließlich in Richtung von der Vorrichtung (1) zum System erfolgt und dass ein Verändern, Löschen oder Auslesen der im Speicherelement hinterlegten Daten verhindert wird.
  2. 2
    Device (1) According to claim 1, characterized, That the device (1) Is configured to initiate self-destruction of the storage element after a certain number of successive erroneous attempts to record biometric features. Vorrichtung (1) nach Anspruch 1, dadurch gekennzeichnet, dass die Vorrichtung (1) derart konfiguriert ist, nach einer bestimmten Anzahl aufeinanderfolgender fehlerhafter Versuche der Aufnahme biometrischer Merkmale eine Selbstzerstörung des Speicherelements auszulösen.
  3. 3
    Device (1) According to claim 1 or 2, characterized, That the housing (2) Has a multilayer wall, two outer layers of the wall being made of a plastic and an inner layer of a metal. Vorrichtung (1) nach Anspruch 1 oder 2, dadurch gekennzeichnet, dass das Gehäuse (2) eine mehrschichtige Wandung aufweist, wobei zwei äußere Schichten der Wandung aus einem Kunststoff und eine innere Schicht aus einem Metall ausgebildet sind.
  4. 4
    Device (1) According to claim 3, characterized, Characterized in that the inner layer of metal is connected to an attachment arranged on the storage element, wherein the attachment, when the housing (2) Physically destroys the storage element. Vorrichtung (1) nach Anspruch 3, dadurch gekennzeichnet, dass die innere Schicht aus Metall mit einem an dem Speicherelement angeordneten Aufsatz verbunden ausgebildet ist, wobei der Aufsatz bei einem Öffnen des Gehäuses (2) das Speicherelement physikalisch zerstört.
  5. 5
    Use of a device (1) According to one of claims 1 to 4 for authenticating and authorizing persons In the case of financial transactions in the field of payment transactions and / or For locking systems and / or access systems of buildings or vehicles and / or - for logins on computer systems or network systems as computer-based login procedures and / or - as an identification medium for identifying the user against authorities. Verwendung einer Vorrichtung (1) nach einem der Ansprüche 1 bis 4 zum Authentifizieren und Autorisieren von Personen – bei Finanztransaktionen im Zahlungsverkehr und/oder – für Schließsysteme und/oder Zugangssysteme von Gebäuden oder Fahrzeugen und/oder – für Anmeldungen an Rechnersystemen oder Netzwerksystemen als computergestützte Login-Verfahren und/oder – als Identifikations-Medium zur Identifikation des Nutzers gegenüber Behörden.
  6. 6
    A method of registering a device (1) For authenticating and authorizing persons according to any one of claims 1 to 4 to a registerable component of a system to be joined, comprising the steps of:- indicating a contact between the device (1) And the registerable component, as well as requesting the user to record biometric characteristics, - recording the biometric characteristics of the user and storing biometric data in the device (1), - generating and transmitting a one-to-one identification identifier from the device (1) To the registerable component, Receiving and storing the identification identifier within a database of the system to be registered for registering the user, - sending a message from the device (1) To the registerable component and displaying the message through the registerable component. Verfahren zum Registrieren einer Vorrichtung (1) zum Authentifizieren und Autorisieren von Personen nach einem der Ansprüche 1 bis 4 an einer registerfähigen Komponente eines beizutretenden Systems, aufweisend folgende Schritte: – Anzeigen eines Kontaktes zwischen der Vorrichtung (1) und der registerfähigen Komponente sowie Auffordern zur Aufnahme biometrischer Merkmale des Nutzers, – Aufnehmen der biometrischen Merkmale des Nutzers und Speichern von biometrischen Daten in der Vorrichtung (1), – Erzeugen und Senden einer eineindeutigen Identifikationskennung von der Vorrichtung (1) an die registerfähige Komponente, – Empfangen und Ablegen der Identifikationskennung innerhalb einer Datenbank des beizutretenden Systems zum Registrieren des Nutzers, – Senden einer Meldung von der Vorrichtung (1) an die registerfähige Komponente und Anzeigen der Meldung durch die registerfähige Komponente.
  7. 7
    Method for authenticating and authorizing persons with a device (1) According to one of claims 1 to 4 to a system to be joined, comprising the following steps:- acquiring the biometric characteristics of the user and comparing the biometric data with data stored in the device (1) Biometrics, - authenticating the user and initiating an operation of sending to authorize the user upon agreement of the compared biometric data, - transmitting a signal stored in the device (1) As information to the system to be joined, and - Disabling and disabling the device (1) After the process of sending the information, Reception and reception of the transferred information by the system to be joined;- sending the one-to-one identification number to a central database system, and comparing the identification number with data stored in the database system, - Authorize the user when the data and data are matched - Enable to perform as well as perform the operation requested by the user. Verfahren zum Authentifizieren und Autorisieren von Personen mit einer Vorrichtung (1) nach einem der Ansprüche 1 bis 4 an einem beizutretenden System, aufweisend folgende Schritte: – Aufnehmen der biometrischen Merkmale des Nutzers und Vergleichen der biometrischen Daten mit in der Vorrichtung (1) gespeicherten biometrischen Daten, – Authentifizieren des Nutzers und Einleiten eines Vorgangs des Sendens zum Autorisieren des Nutzers bei Übereinstimmung der verglichenen biometrischen Daten, – Übertragen einer in der Vorrichtung (1) abgelegten eineindeutigen Identifikationskennung als Informationen an das beizutretende System sowie – Abschalten und Deaktivieren der Vorrichtung (1) nach dem Vorgang des Sendens der Informationen, – Empfang und Aufnahme der übertragenen Informationen durch das beizutretende System und – Senden der eineindeutigen Identifikationsnummer an ein zentrales Datenbanksystem sowie Vergleich der Identifikationsnummer mit im Datenbanksystem hinterlegten Daten, – Autorisieren des Nutzers bei Übereinstimmung der Daten und – Freigabe zum Durchführen sowie Durchführen des vom Nutzer angeforderten Vorgangs.
  8. 8
    A method according to claim 6 or 7, characterized, Characterized in that fingerprints of two different fingers of the user are recorded as biometric features, the process of transmission being initiated by scanning the fingerprints at a distance of at most five seconds. Verfahren nach Anspruch 6 oder 7, dadurch gekennzeichnet, dass als biometrische Merkmale Fingerabdrücke zweier unterschiedlicher Finger des Nutzers aufgenommen werden, wobei der Vorgang des Sendens durch das Scannen der Fingerabdrücke im Abstand von höchstens fünf Sekunden eingeleitet wird.
  9. 9
    Method according to one of Claims 7 or 8, characterized, That in the apparatus (1) Is transmitted over a period of five seconds to the system to be joined. Verfahren nach einem der Ansprüche 7 oder 8, dadurch gekennzeichnet, dass die in der Vorrichtung (1) abgelegte eineindeutige Identifikationskennung über einen Zeitraum von fünf Sekunden an das beizutretende System übertragen wird.
  10. 10
    Method according to one of Claims 6 to 9, characterized, Characterized in that the one-to-one identification code is formed from fields comprising data, a first field being data of a date and time stamp, a second field being a serial number of the device1) As well as a customer number of the user and a third field have a check sum for checking the integrity of the transmitted data, the serial number and the customer number being encrypted by means of a 256-bit key based on the date and time stamp. Verfahren nach einem der Ansprüche 6 bis 9, dadurch gekennzeichnet, dass die eineindeutige Identifikationskennung aus Feldern mit Daten gebildet wird, wobei ein erstes Feld Daten eines Datums- und Zeitstempels, ein zweites Feld eine Seriennummer der Vorrichtung (1) sowie eine Kundennummer des Nutzers und ein drittes Feld eine Kontrollsumme zur Überprüfung der Integrität der übertragenen Daten aufweisen, wobei die Seriennummer und die Kundennummer mittels eines 256-bit-Schlüssels auf Basis des Datums- und Zeitstempels verschlüsselt werden.