Device and method for authenticating and authorizing persons
Abstract
The invention relates to a device (1) for authenticating and authorizing persons. The device (1) has a housing (2), at least one display device, at least one energy store (11), a carrier element (10) with a storage element arranged on the carrier element (10), and a scanning device (3) ) To record biometric characteristics of the person. Within the storage element, comparison data of the biometric features for authenticating the person can be stored. The device (1) is configured to transmit a data packet with authentication information of the user to a system requested for access after the user is authenticated by the inclusion of biometric features on the device (1) to be authorized for the system, In which all information on the use is stored. The device (1) is closed in this case in such a way that the data are transferred exclusively in the direction from the device (1) to the system, and that a change, erasure or readout of the data stored in the memory element is prevented. The invention also relates to a method for registering the device to a registerable component of a system to which the device requests access, as well as to a method for authenticating and authorizing persons with the device on the system to be joined. Wherein the transmission of the data exclusively takes place in the direction from the device (1) to the system, and that a change, erasure or readout of the data stored in the memory element is prevented. The invention also relates to a method for registering the device to a registerable component of a system to which the device requests access, as well as to a method for authenticating and authorizing persons with the device on the system to be joined. Wherein the transmission of the data exclusively takes place in the direction from the device (1) to the system, and that a change, erasure or readout of the data stored in the memory element is prevented. The invention also relates to a method for registering the device to a registerable component of a system to which the device requests access, as well as to a method for authenticating and authorizing persons with the device on the system to be joined.

Term
Projected expiry 28 August 2035.
- Priority and filed
- Published
- Today
- Projected expiry
10 claims: 10 independent, 0 dependent
- 1Device (1) For authenticating and authorizing persons, comprising a housing (2), At least one display device, at least one energy store (11), A carrier element (10) With a bearing10) And at least one transmission element (12), characterized, that - a scanning device (3) For receiving biometric characteristics of the person, wherein comparison data of the biometric features for authenticating the person can be stored within the storage element, - the device (1) Is configured to transmit a data packet with authentication information of the user to a system requested after access by the user by recording biometric features on the device (1) Is authenticated to be authorized for the system in which all information for usage is stored, and - the device (1) Is closed in such a way that the transmission of the data exclusively in the direction from the device (1) To the system, and that a change, erasure or read-out of the data stored in the memory element is prevented. Vorrichtung (1) zum Authentifizieren und Autorisieren von Personen, aufweisend ein Gehäuse (2), mindestens eine Anzeigevorrichtung, mindestens einen Energiespeicher (11), ein Trägerelement (10) mit einem auf dem Trägerelement (10) angeordneten Speicherelement sowie mindestens ein Übertragungselement (12), dadurch gekennzeichnet, dass – eine Scanvorrichtung (3) zur Aufnahme biometrischer Merkmale der Person ausgebildet ist, wobei innerhalb des Speicherelements Vergleichsdaten der biometrischen Merkmale zum Authentifizieren der Person hinterlegbar sind, – die Vorrichtung (1) derart konfiguriert ist, ein Datenpaket mit Authentifizierungsinformationen des Nutzers an ein um Zugang ersuchtes System zu übertragen, nachdem der Nutzer durch die Aufnahme biometrischer Merkmale an der Vorrichtung (1) authentifiziert ist, um für das System, in welchem sämtliche Informationen zur Nutzung hinterlegt sind, autorisiert zu werden, und – die Vorrichtung (1) geschlossen derart ausgebildet ist, dass die Übertragung der Daten ausschließlich in Richtung von der Vorrichtung (1) zum System erfolgt und dass ein Verändern, Löschen oder Auslesen der im Speicherelement hinterlegten Daten verhindert wird.
- 2Device (1) According to claim 1, characterized, That the device (1) Is configured to initiate self-destruction of the storage element after a certain number of successive erroneous attempts to record biometric features. Vorrichtung (1) nach Anspruch 1, dadurch gekennzeichnet, dass die Vorrichtung (1) derart konfiguriert ist, nach einer bestimmten Anzahl aufeinanderfolgender fehlerhafter Versuche der Aufnahme biometrischer Merkmale eine Selbstzerstörung des Speicherelements auszulösen.
- 3Device (1) According to claim 1 or 2, characterized, That the housing (2) Has a multilayer wall, two outer layers of the wall being made of a plastic and an inner layer of a metal. Vorrichtung (1) nach Anspruch 1 oder 2, dadurch gekennzeichnet, dass das Gehäuse (2) eine mehrschichtige Wandung aufweist, wobei zwei äußere Schichten der Wandung aus einem Kunststoff und eine innere Schicht aus einem Metall ausgebildet sind.
- 4Device (1) According to claim 3, characterized, Characterized in that the inner layer of metal is connected to an attachment arranged on the storage element, wherein the attachment, when the housing (2) Physically destroys the storage element. Vorrichtung (1) nach Anspruch 3, dadurch gekennzeichnet, dass die innere Schicht aus Metall mit einem an dem Speicherelement angeordneten Aufsatz verbunden ausgebildet ist, wobei der Aufsatz bei einem Öffnen des Gehäuses (2) das Speicherelement physikalisch zerstört.
- 5Use of a device (1) According to one of claims 1 to 4 for authenticating and authorizing persons In the case of financial transactions in the field of payment transactions and / or For locking systems and / or access systems of buildings or vehicles and / or - for logins on computer systems or network systems as computer-based login procedures and / or - as an identification medium for identifying the user against authorities. Verwendung einer Vorrichtung (1) nach einem der Ansprüche 1 bis 4 zum Authentifizieren und Autorisieren von Personen – bei Finanztransaktionen im Zahlungsverkehr und/oder – für Schließsysteme und/oder Zugangssysteme von Gebäuden oder Fahrzeugen und/oder – für Anmeldungen an Rechnersystemen oder Netzwerksystemen als computergestützte Login-Verfahren und/oder – als Identifikations-Medium zur Identifikation des Nutzers gegenüber Behörden.
- 6A method of registering a device (1) For authenticating and authorizing persons according to any one of claims 1 to 4 to a registerable component of a system to be joined, comprising the steps of:- indicating a contact between the device (1) And the registerable component, as well as requesting the user to record biometric characteristics, - recording the biometric characteristics of the user and storing biometric data in the device (1), - generating and transmitting a one-to-one identification identifier from the device (1) To the registerable component, Receiving and storing the identification identifier within a database of the system to be registered for registering the user, - sending a message from the device (1) To the registerable component and displaying the message through the registerable component. Verfahren zum Registrieren einer Vorrichtung (1) zum Authentifizieren und Autorisieren von Personen nach einem der Ansprüche 1 bis 4 an einer registerfähigen Komponente eines beizutretenden Systems, aufweisend folgende Schritte: – Anzeigen eines Kontaktes zwischen der Vorrichtung (1) und der registerfähigen Komponente sowie Auffordern zur Aufnahme biometrischer Merkmale des Nutzers, – Aufnehmen der biometrischen Merkmale des Nutzers und Speichern von biometrischen Daten in der Vorrichtung (1), – Erzeugen und Senden einer eineindeutigen Identifikationskennung von der Vorrichtung (1) an die registerfähige Komponente, – Empfangen und Ablegen der Identifikationskennung innerhalb einer Datenbank des beizutretenden Systems zum Registrieren des Nutzers, – Senden einer Meldung von der Vorrichtung (1) an die registerfähige Komponente und Anzeigen der Meldung durch die registerfähige Komponente.
- 7Method for authenticating and authorizing persons with a device (1) According to one of claims 1 to 4 to a system to be joined, comprising the following steps:- acquiring the biometric characteristics of the user and comparing the biometric data with data stored in the device (1) Biometrics, - authenticating the user and initiating an operation of sending to authorize the user upon agreement of the compared biometric data, - transmitting a signal stored in the device (1) As information to the system to be joined, and - Disabling and disabling the device (1) After the process of sending the information, Reception and reception of the transferred information by the system to be joined;- sending the one-to-one identification number to a central database system, and comparing the identification number with data stored in the database system, - Authorize the user when the data and data are matched - Enable to perform as well as perform the operation requested by the user. Verfahren zum Authentifizieren und Autorisieren von Personen mit einer Vorrichtung (1) nach einem der Ansprüche 1 bis 4 an einem beizutretenden System, aufweisend folgende Schritte: – Aufnehmen der biometrischen Merkmale des Nutzers und Vergleichen der biometrischen Daten mit in der Vorrichtung (1) gespeicherten biometrischen Daten, – Authentifizieren des Nutzers und Einleiten eines Vorgangs des Sendens zum Autorisieren des Nutzers bei Übereinstimmung der verglichenen biometrischen Daten, – Übertragen einer in der Vorrichtung (1) abgelegten eineindeutigen Identifikationskennung als Informationen an das beizutretende System sowie – Abschalten und Deaktivieren der Vorrichtung (1) nach dem Vorgang des Sendens der Informationen, – Empfang und Aufnahme der übertragenen Informationen durch das beizutretende System und – Senden der eineindeutigen Identifikationsnummer an ein zentrales Datenbanksystem sowie Vergleich der Identifikationsnummer mit im Datenbanksystem hinterlegten Daten, – Autorisieren des Nutzers bei Übereinstimmung der Daten und – Freigabe zum Durchführen sowie Durchführen des vom Nutzer angeforderten Vorgangs.
- 8A method according to claim 6 or 7, characterized, Characterized in that fingerprints of two different fingers of the user are recorded as biometric features, the process of transmission being initiated by scanning the fingerprints at a distance of at most five seconds. Verfahren nach Anspruch 6 oder 7, dadurch gekennzeichnet, dass als biometrische Merkmale Fingerabdrücke zweier unterschiedlicher Finger des Nutzers aufgenommen werden, wobei der Vorgang des Sendens durch das Scannen der Fingerabdrücke im Abstand von höchstens fünf Sekunden eingeleitet wird.
- 9Method according to one of Claims 7 or 8, characterized, That in the apparatus (1) Is transmitted over a period of five seconds to the system to be joined. Verfahren nach einem der Ansprüche 7 oder 8, dadurch gekennzeichnet, dass die in der Vorrichtung (1) abgelegte eineindeutige Identifikationskennung über einen Zeitraum von fünf Sekunden an das beizutretende System übertragen wird.
- 10Method according to one of Claims 6 to 9, characterized, Characterized in that the one-to-one identification code is formed from fields comprising data, a first field being data of a date and time stamp, a second field being a serial number of the device1) As well as a customer number of the user and a third field have a check sum for checking the integrity of the transmitted data, the serial number and the customer number being encrypted by means of a 256-bit key based on the date and time stamp. Verfahren nach einem der Ansprüche 6 bis 9, dadurch gekennzeichnet, dass die eineindeutige Identifikationskennung aus Feldern mit Daten gebildet wird, wobei ein erstes Feld Daten eines Datums- und Zeitstempels, ein zweites Feld eine Seriennummer der Vorrichtung (1) sowie eine Kundennummer des Nutzers und ein drittes Feld eine Kontrollsumme zur Überprüfung der Integrität der übertragenen Daten aufweisen, wobei die Seriennummer und die Kundennummer mittels eines 256-bit-Schlüssels auf Basis des Datums- und Zeitstempels verschlüsselt werden.
Independent claims10
75 paragraphs in 1 section, as filed
The invention relates to a device for authenticating and authorizing persons. The device has a housing, at least one display device, at least one energy store, a carrier element with a storage element arranged on the carrier element, and at least one transmission element. The invention further relates to a method for registering the device to a registerable component of a system to which the device requests access, as well as a method for authenticating and authorizing persons with the device on the system to be joined.
Devices known from the prior art as tools for a limited access to closed rooms or to closed electronic systems limited to specific persons or groups of persons are only ensured during the personal possession of the respective person. There is the risk that unauthorized persons can acquire the device and provide access to it. The tools for access to closed rooms include any type of mechanical key for opening a lock, for example for locking devices on doors or office buildings, rooms or rooms, garage doors, vehicles, lockers or safes, letterboxes, suitcases or bags. In addition to the mechanical keys, electronic or electromagnetic systems, such as magnetic card keys, are also common. The electronic or electromagnetic systems can in this case be designed with a wireless transmitter, such as a key for the motor vehicle, with a fingerprint recognition or with an electromagnetic high-frequency identification technique, briefly also referred to as RFID for "radio-frequency identification" Which are also known as transponders. The transponders are conventionally designed either as a card or a key holder or are integrated in a mechanical key. The tools for access to completed electronic systems include applications such as online banking, such as mobile phones or tablets via SMS with PIN, mobile payment methods for parking meters or tickets, direct registrations for order applications such as Amazon, Or credit card functions and payment functions with debit cards, EC cards or payback cards with direct debit or with signature. The PIN is to be understood as a personal identification number or secret number which, depending on the application, is known or known to only one or a few persons.
The state of the art also includes systems and devices for authenticating persons and for the subsequent access authorization, such as identity cards, password-protected access points to computers or personal computers, to company networks or to wireless networks, above-mentioned banking application methods with a password and, where appropriate, with PIN, EC cards Or credit cards with PIN, customer cards or payment cards. Other systems and devices for authentication include encrypted environments, such as company storage drives, intranet with critical data, access to virtual private networks, VPN for short, and so-called tokens as hardware components for identifying and authenticating users for access to computer systems From a PIN, a token number, A user name and a password. Tokens are also referred to as electronic keys or chip keys.
In order to log on to a local computer system or to a computer network, the user is usually prompted to enter a user name and a password associated with the user name. The login procedure is very unsafe, as the username and / or password can be forgotten. In this case, a clear password password or the password is stored in a password container application to avoid the uncertainty, the combination of the user name and password The password can be intercepted when sending via the local network. In addition, the user is asked at regular intervals to think more and more complex passwords, which must be remembered and still be exposed to the above-mentioned dangers.
Payments with credit cards or account cards are usually made either by signature or by entering the PIN. The signature on the back of a credit card is easy to imitate in most cases, however, with sufficient exercise. This restricts the protection against the misuse of the credit card to storage in a safe place and the exclusive use by the legal owner. The PIN of a credit card is stored on a magnetic strip integrated in the card. The magnetic stripe can thereby be duplicated by various fraudulent methods or spied out of a numerical input device or in some other way acquired by unauthorized persons. A loss of the credit card is often recognized only with a considerable delay,As well as for the withdrawal of cash at appropriate machines.
In the case of access methods based on the use of a mechanical key or an electronic or electromagnetic access card, for example a motor vehicle safety device or a building safety device, any person who is in possession of the key or the card can open the appropriate access. In most cases, there is no user query, for example via a PIN or an optical control. In the case of loss, the key or the access card can be used by any person who acquires possession thereof.
The systems, devices and methods for the authentication of persons known from the prior art are complex, cost-intensive and associated with high demands on the user's memory. Thus, each active member of society is forced to use a larger set of the various tools and access methods enumerated. The use requires that all necessary data be safely carried with you and / or the data are memorized and also assigned to one another, such as the correct PIN to telephone, EC card, credit card or online banking.
In addition, each active member of the company must identify itself in various places and in different situations by means of personal documents, such as identity cards, such as a social security pass, a company identity card or a stage ID, or a passport or driving license. On the one hand, the personal papers are relatively counterfeit-proof by a large number of unchanging features, but on the other hand they always require unconditional carrying along and are not secure with a certain degree of criminal energy. Likewise, commonly used online procedures are to be misused without major technical effort and thus uncertain.
A large proportion of the requirements for authentication systems can be ensured over short distances with the transmission of data between devices by radio. These include, for example, the abovementioned electromagnetic high-frequency identification technology RFID, the near-field communication, also abbreviated as NFC for "near field communication", or Bluetooth. The data transmission over short distances by radio, in which an object is held and identified at a short distance to a reader, is used, for example, in the case of contactless credit cards, smartphones designed as smartphones, tablets or personal computers.
From the <patcit><text>WO 2011 028874 A1</text></patcit> A personalized multifunctional access device with an individualized form of authentication and data exchange control emerges. In this case, bidirectional data are exchanged between the multifunctional access device and the system to which the access is requested via local transmission facilities, such as NFC, RFID or Bluetooth. The data are transmitted, for example, via the Internet or an intranet or a computer software. By means of the computer, data is interrogated by the multifunctional access device, exchanged and processed with the multifunctional access device. The personalized multifunctional access device, which allows an operating system to extend the basic functions and the interaction with other devices, Calculated from a plurality of data contained within the device by means of mathematical cryptography key sets, and also has a slot and a connection capability with an SD card, also referred to as a "Secure Digital Memory Card", to transmit a plurality of data to and from the SD card. The multifunctional access device actively uses data exchange with other devices via radio, cable or removable media.
In the <patcit><text>"US 2007 0197261 A1</text></patcit> A component embodied as a general-purpose key is described which can be integrated into operating systems of devices, such as mobile telephones, from different manufacturers. The general-purpose key communicates, for example, with an existing software via the Internet, also for updating and downloading software, and can be found via the Global Position Determination System (GPS). The general-purpose key is coupled for bidirectional data exchange with other devices and systems to which the access is desired.
Against the widespread insecurity and abuse, additional security measures, such as fingerprint scanners, for example, for a mobile telephone and access controls for entry into sensitive business areas, iris scanners or similar systems have been developed and used. However, these security systems offer either very limited security or are extremely complex to implement and manage in other systems, such as biometric access control.
The systems known from the prior art have comprehensively considerable safety gaps. In particular, it can not be ensured that the systems are used exclusively by the authorized person. The systems can be misused by unauthorized persons. The conventional systems,Devices and methods for authenticating persons are also extremely complex, cost-intensive and / or associated with high demands on the user's memory.
The object of the invention is to provide a device and methods for authenticating and authorizing, respectively, identifying and verifying a present person for a desired access, for example, to a spatially or electronically terminated system. The device is thereby to meet the highest safety requirements and to combine as many safety functions as possible in everyday life. In this case, the device should be easy to operate and make changes to the existing authorization process neither on the active side of the user as a user nor on the passive side of the system to which access is to be granted.
The object is achieved by the objects and methods having the features of the independent claims. Further developments are given in the dependent patent claims.
The object is achieved by a device according to the invention for authenticating and authorizing persons. The device has a housing, at least one display device, at least one energy store, a carrier element with a storage element arranged on the carrier element, and at least one transmission element.
According to the concept of the invention, the device is designed with a scanning device for receiving biometric characteristics of the person. Within the storage element, comparison data of the biometric features for authenticating the person can be stored. According to the invention, the device is configured to transmit a data packet with authentication information of the user as the person to be authenticated and authorized to a system requested for access after the user is authenticated by the inclusion of biometric features on the device to be authorized for the system In which all information on the use is stored. The device is also closed,
In addition to the storage element, a computing unit is advantageously arranged on the carrier element. The apparatus is preferably configured to send the data over a fixed period of five seconds to the system requested for access. It is advantageous that the display device is formed from at least one light-emitting diode. The scanning device is preferably designed for receiving a fingerprint or an iris or voice as biometric features.
According to a preferred embodiment of the invention, the device is configured to initiate self-interference of the storage element after a certain number of successive erroneous attempts to record biometric features. For example, with the input of three successive false fingerprints or incorrect combinations of fingerprints, self-destruction of the memory contents is triggered, which makes an abuse of the device impossible.
According to a development of the invention, the housing has a multilayer wall. In this case, two outer or outer layers of the wall are made of a plastic material and an inner layer of a metal is formed. The wall of the housing is preferably three-layered, the metal layer being arranged between the two outer plastic layers. The housing and thus the device advantageously has the form of an ellipsoid.
A further preferred embodiment of the invention consists in that the inner layer of the wall of the housing, which is formed from metal, is connected as a mechanical sheath between the housing and the components placed within the housing with an attachment arranged on the storage element. In this case, the attachment is designed such that the storage element is physically destroyed when the housing is opened. The attachment is advantageously designed as a rotary cutting mechanism.
The advantageous embodiment of the invention, in particular with regard to high security, limited space requirements and easy handling, makes it possible to use the device for authenticating and authorizing persons in financial transactions in payment transactions and / or for locking systems and / or access systems for buildings or vehicles And / or for logging on computer systems or network systems as computer-assisted login methods and / or as identification medium for identifying the user against authorities.
The object is also achieved by a method according to the invention for registering a device for authenticating and authorizing persons on a registerable component of a System. The system which is called for by the device to be accessed is understood as the system to be assisted. The method has the following steps:<ul list-style="bullet"><li>- indicating a contact between the device and the registerable component, as well as requesting the user to record biometric characteristics,</li><li>- acquiring the biometric characteristics of the user and storing biometric data in the device,</li><li>- generating and transmitting a one-to-one identification tag from the device to the registerable component,</li><li>Receiving and storing the identification identifier within a database of the system to be registered for registering the user,</li><li>- sending a message from the device to the registerable component and displaying the message by the registerable component.</li></ul>
The indication of the message may relate to the fact that the device has been successfully or not successful in recording the biometric features by the device.
The object is also achieved by means of a method according to the invention for authenticating and authorizing persons with a device at a system to be joined. The system which is requested by the device for access is again understood as the system to be assisted. The method has the following steps:<ul list-style="bullet"><li>- acquiring the biometric characteristics of the user and comparing the biometric data with biometric data stored in the device,</li><li>- authenticating the user and initiating an operation of sending to authorize the user upon agreement of the compared biometric data,</li><li>Transferring a one - to - one identification identifier stored in the device as information to the system to be joined, and</li><li>- disabling and disabling the device after the process of sending the information,</li><li>Reception and reception of the transferred information by the system to be joined;</li><li>- sending the one-to-one identification number to a central database system, and comparing the identification number with data stored in the database system,</li><li>- Authorize the user when the data and data are matched</li><li>- Enable to perform as well as perform the operation requested by the user.</li></ul>
According to an advantageous embodiment of the invention, fingerprints of two different fingers of the user are recorded as biometric features, the process of transmission being initiated by scanning the fingerprints at a distance of at most five seconds. During the process of transmission, the one-to-one identification identification stored in the device is transferred as information to the registerable component or to the system to be joined.
According to a further development of the invention, the one-to-one identification identifier stored in the device is transmitted to the system to be joined over an adjustable period of five seconds.
The one-to-one identification identifier is preferably formed from fields with data. In this case, a first field comprises data of a date and time stamp, a second field a serial number of the device, a customer number of the user, and a third field a control sum for checking the integrity of the transmitted data. The serial number and the customer number are advantageously encrypted using a 256-bit key based on the date and time stamp.
The device as well as the methods for authenticating and authorizing persons is as a universal key, for example <ul list-style="bullet"><li>- for a door lock or door lock of a room, a building, a garage, within a company premises, a hotel - can be released for booking or payment for the booked period - or a vehicle - private, company, car hire, but also</li><li>As access for a mobile telephone, a personal computer or a computer network, or</li><li>For identification against applications on a mobile telephone, personal computer or a computer network by short - term authorization of the user or</li><li>- can be used to release transactions by means of short-term authorization by the user.</li></ul>The apparatus and the method for authenticating and authorizing persons may also be used as identification medium for identifying the user against authorities such as the police and security services, for example as a personnel ID, driving license, passport, EU residence permit, entry permit, For example health insurance or social insurance. For all uses as universal conclusions, the user has the device according to the invention, is merely a release or an activation of the device<figref>1</figref> Necessary - the user has the According to the invention, a single output and transfer to the user is necessary.
The device as well as the method for authenticating and authorizing persons also have advantages for companies. The legal user of the device can be assigned in all areas, the assignment is centrally assigned or withdrawn, both in data processing, for example via directory services, as well as to premises or information sources such as remote locking of mobile phones, intranet access or the like. Secure access to premises, company computers or computer networks can be made possible and time recording can be used.
The unambiguous identification of the authorized user does not allow misuse, for example, of health insurance data. The device<figref>1</figref> Is much safer than any current insurance card, even with picture. There is always a clear assignment of each service, a central and immediate intervention in permissions or a login into the personal area of the website. On the device, machine-readable certificates for authorities can be deposited. All information on the authorized person, which is deposited in the administrative systems, can be immediately retrieved and displayed, such as pictures, fingerprints or search information. Machine-readable driving licenses can be checked immediately, EU residence permits are immediately readable. By harmonizing the machine readability of ID cards, the system can also be used internationally, The identity of foreign nationals can also be read by the national border police. Visas can be stored exactly in time. In the case of a system-internal linking of the information to the person, a clearly facilitated checking of the person is possible, whereby the device merely indicates clearly which person is involved. The rest of the information is stored in the original systems, as has been the case so far, and is only made visible to the responsible agents. There is no need to change the previous software. In the original systems and are only made visible to the responsible agents. There is no need to change the previous software. In the original systems and are only made visible to the responsible agents. There is no need to change the previous software.
For banks and transactional payment systems, the device can be enabled for various functions, such as online banking via the personal computer or the mobile telephone, the use of a Maestro card or a credit card, in which case no different cards need to be dispensed. Different passwords and PIN for the different applications and functions are no longer required. No more misuse of the cards is possible. Complex and different identification procedures, including all combinations of user names and passwords as well as different PIN procedures, are dispensed with. A previously unachieved transaction security is provided.
For private individuals there are further advantages with regard to customer loyalty systems such as Payback, Miles-and-More or hotel chains, ticket systems in public transport, paying parking tickets, tickets, flight tickets or concert tickets. There are no collections of different cards of different systems with different PINs, no paper cards or mechanical keys, which can be forgotten or lost.
The device may be issued to private individuals by banks, insurance companies, authorities, companies, service providers, such as hotel operators or landlords. The device is activated once by the user, and any functions can be released or added.
The device according to the invention and the method for authenticating and authorizing persons have a number of advantages. Utilizing available technologies for encryption and near-transmission authentication, such as NFC, RFID, or Bluetooth, a universally applicable device for authenticating and authorizing, respectively, identifying and verifying an attendant is provided for most everyday applications. The device meets all safety requirements and goes far beyond the possibilities of the prior art of known systems, can not be misused by unauthorized persons and offers the user a drastic simplification in everyday life through a multitude of possible uses.
The device can only be activated by the assigned user, for example via the recognition of fingerprints, the scanning of the iris or the recognition of the voice. The contents of the system can not be deleted, read or overwritten. Since, even with a great deal of technical effort, a fingerprint for activation can be falsified, imprints of at least two fingers are requested in a selection of ten fingers, so that a plurality of possible combinations result which makes an abuse of the device nearly impossible. All storage contents are also obtained using conventional methodsEncrypted and readable only after delivery of the at least double fingerprint. New functions of the device can be released only by the issuing institutions, the user being present and having to release the transaction with at least double fingerprint.
The entirety of the functions ensures that the device can only be used by the authorized person. A lost or disguised device would not be usable for an unauthorized person, even in the case of an abduction or killing of the authorized person, a further use of the device by an unauthorized person can be virtually excluded. Accordingly, the device could even be provided with the address and / or telephone number of the authorized person or, for example, an institution issuing the device, in order to motivate a return of the device. The institutions issuing the device or the users of the systems to be enabled, such as employers, online shops and banks, have the advantage of a uniform, Easy to manage and unmatched secure system. The device reduces the cost as a form of a universally applicable key, since no different systems and administrations are necessary, since the device replaces a variety of cards and keys, the environment helps to reduce the weight as well as the size of purse and handbags. The user does not have to memorize a large number of different PINs or is not in danger of being denied access to the system when the PIN is forgotten. Countless changing combinations of users and passwords are no longer required. It does not ask for a PIN or send it over a network, so that no data can be tracked. Thus the device with the personally bound authorization method is substantially safer than the known signature methods or card PIN methods. In addition, the security is significantly increased for all parties because the device does not require any data exchange, but merely transmits a data packet with authentication information after the user has logged on to the device with the delivery of biometric features. The device is not based on the exchange of data for authentication, either internally or over the wide area networks. Thus, when using local computer systems or computer networks, no user information is transmitted over networks so that the logon information is not intercepted, decrypted and abused. The device provides a secure, Personally-bound authorization process for both local applications as well as for use in local networks and broadband networks such as Internet shopping or similar applications. For reasons of data security, the device can not be coupled to other devices, exchanges data, or communicates over other media, but merely sends a single authentication or unique confirmation that the authorized user of the device is present at a particular time at a particular location . The device does not allow bidirectional coupling to bidirectional data exchange, for example by cable or radio, with external devices or the use of mobile, interchangeable media. Furthermore, the device is not designed with an operating system, For example, an extension of the basic functions or even the interaction with other devices. The device is designed as a closed system without the possibility of altering, erasing or reading data once stored in the device. The usage information is stored in the respective system to which the access is requested.
Further details, features and advantages of embodiments of the invention can be gathered from the following description of exemplary embodiments with reference to the accompanying drawings. It shows a device for authenticating and authorizing persons in one:
<figref>1a</figref>: View from above,
<figref>1b</figref>: Side view,
<figref>1c</figref>: View from below,
<figref>1d</figref>: Alternative embodiment in view from below,
<figref>2a</figref>: View from above with arrangement of single components inside and
<figref>2 B</figref>Image: Side view with arrangement of single components inside.
The <figref>1a</figref> to <figref>1c</figref> Show a device <figref>1</figref> For authenticating and authorizing persons in a view from above, according to <figref>1a</figref>, A side view, according to FIG <figref>1b</figref>, And and a view from below, according to FIG <figref>1c</figref>.
The device <figref>1</figref> Is equipped with a multilayer housing <figref>2</figref> In the form of an ellipsoid with three differently long half-axes a, bc. The ellipsoid has a non-uniform shape with a length of 40 mm, a width of 28 mm and a height of 12 mm with dimensions of the half-axes of a = 20 mm, b = 14 mm and c = 6 mm. The top<figref>2a</figref> And the bottom <figref>2 B</figref> Of the housing <figref>2</figref> Is determined by the half-axes a and b. The three-axis ellipsoid can also be designed with three equally long half-axes and thus as a ball or with a few equal-long half-axes and a third half-axis which deviates in length from the other and thus flattened or stretched. The housing<figref>2</figref> Is three-layered, the two outer layers being made of a plastic and the inner layer being made of a metal. The metal layer is arranged between the two plastic layers.
On the top <figref>2a</figref> Of the housing <figref>2</figref> According to; <figref>1a</figref>, Respectively visible to the outside for the user a scanning device <figref>3</figref> For a fingerprint, also referred to as a fingerprint reader, and two light-emitting diodes <figref>4</figref>, <figref>5</figref> educated. The scanning device<figref>3</figref> Has a circular shape with a diameter of approximately 10 mm. The first light-emitting diode<figref>4</figref>, Also referred to as a light-emitting diode or briefly LED, emits electromagnetic radiation of a wavelength that is visible to the eye as green. The second light-emitting diode<figref>5</figref> Emitted in comparison to the first light-emitting diode <figref>4</figref> Electromagnetic radiation of a wavelength which is visible to the eye as red. The light-emitting diodes<figref>4</figref>, <figref>5</figref> Each have a circular shape with a diameter of about 1.5 mm. The first light-emitting diode<figref>4</figref> Is for indicating the readiness of the device <figref>1</figref>To receive an input from the user. The second light-emitting diode<figref>5</figref> Signals malfunctions and malfunctions.
To receive the device <figref>1</figref>, For example on a key collar, is the housing <figref>2</figref> With a through hole <figref>6</figref> provided. The circular through hole<figref>6</figref> Has a diameter of about 5 mm and is provided with an inner reinforcement <figref>7</figref>, Preferably made of metal.
The housing <figref>2</figref> Is on one side toward the bottom <figref>2 B</figref> With a recess or a slit-shaped opening, from which, before the device is put into operation <figref>1</figref> A cover element made of plastic <figref>8th</figref> Out. The cover member<figref>8th</figref> Has the form of a thin strip and fills the recess with a height of about 0.25 mm and a width of about 5 mm. The opening and the covering element corresponding to the opening<figref>8th</figref> Are designed in dimensions such that the cover element <figref>8th</figref> Within the opening, in particular from the housing <figref>2</figref> Withdrawable.
Out <figref>1d</figref> Goes a device <figref>1</figref> For authenticating and authorizing persons in an alternative embodiment in view of below. The difference to the embodiment according to the<figref>1a</figref> to <figref>1c</figref> Consists in the formation of an energy storage device and the associated peripherals. While the first embodiment according to the<figref>1a</figref> to <figref>1c</figref> With at least one high-capacitance battery as energy storage device, which can be operated with a maximum utilization of ten to fifteen times a day for a period of approximately four years, the second embodiment is reduced <figref>1d</figref> At least one rechargeable accumulator as an energy store. For this reason, the second embodiment is instead of the opening and the cover member arranged in the opening<figref>8th</figref> With two contacts <figref>9</figref> For connecting a charging device for charging the energy storage device. The as charging contacts<figref>9</figref> For the accumulator on the housing <figref>2</figref> Are provided at the end of the through hole <figref>6</figref> In the longitudinal direction opposite side of the device <figref>1</figref> Respectively. The embodiment of the device<figref>1</figref> With the accumulator as energy storage device is to be preferred for more intensive uses of the above-mentioned embodiment.
In the <figref>2a</figref> and <figref>2 B</figref> Is the device <figref>1</figref> For authenticating and authorizing persons with an arrangement of individual components in the interior in a view from above, according to FIG <figref>2a</figref> And a side view, according to FIG <figref>2 B</figref>, Respectively.
Inside the housing <figref>2</figref> Are next to the scanning device <figref>3</figref> For the fingerprint and the light-emitting diodes <figref>4</figref>, <figref>5</figref> A carrier element <figref>10</figref>, Also referred to as a logic carrier, at least one energy store <figref>11</figref>, Which is designed as a long-life battery or accumulator, and transmission elements <figref>12</figref> Respectively. In the housing<figref>2</figref> A photo cell can also be integrated. The carrier element<figref>10</figref> Comprises a non-volatile memory element and an embedded computing unit. The transmission elements<figref>12</figref> Are designed, for example, as radio modules for NFC, RFID or Bluetooth in order to transmit data. In the alternative embodiment with at least one rechargeable accumulator as energy storage<figref>11</figref>, Are also the rechargeable accumulator and the cabling to the external charging contacts <figref>9</figref>, after <figref>1d</figref>, Within the housing <figref>2</figref> integrated. A non-volatile memory element is thereby capable of holding the data or information stored in the memory, such as a PROM for "Programmable Read Only Memory" or a SSD for "Solid State Drive", as a memory, even without an externally applied operating voltage. In contrast to a non-volatile memory element, there are memories which lose the data or information stored in the memory as soon as the externally applied operating voltage drops away, such as a RAM for "random access memory" or a working memory of a computer, which is known from DRAMs for " Dynamic Random Access Memories ".The through the opening from the housing <figref>2</figref> Outward and retractable cover element <figref>8th</figref> Prevents in the delivery state, that is to say before the device is put into operation <figref>1</figref>, The contact of the energy storage device <figref>11</figref> With the components to be supplied with electrical energy. The cover member<figref>8th</figref> Thus preventing inadvertent commissioning of the device <figref>1</figref> And unintended unloading of the energy storage device <figref>11</figref>. With the removal, that is, the process of extracting the cover member<figref>8th</figref> From the device <figref>1</figref>, Become the poles of the energy storage <figref>11</figref> With the components to be supplied with electrical energy, and the device <figref>1</figref> is started. The housing<figref>2</figref> Is formed with a spring element (not shown) which, in the delivery state of the device <figref>1</figref> Is tensioned. After removing the cover member<figref>8th</figref> Becomes the opening in which the cover member <figref>8th</figref> In the housing <figref>2</figref> Was tightly sealed, waterproof and dustproof. The spring element causes a movement of an elastic sealing element which, after reaching the end position, closes the opening in a sealing manner. The sealing member is formed of a soft plastic such as an elastomer having a length of about 7 mm and a width of about 1 mm.
The scanning device <figref>3</figref> For the fingerprint is protected against accidental activation by a closure, for example a closure made of rubber. When removing the shutter of the scanning device<figref>3</figref> The recognition process is activated. The device<figref>1</figref> Is in an active state.
The housing <figref>2</figref>, The wall of which is formed from two layers of plastic, which in turn embed a layer of metal, is apart from the recesses for the scanning device <figref>3</figref>, The light-emitting diodes <figref>4</figref>, <figref>5</figref> And the opening for the cover member <figref>8th</figref> Completely closed and without the possibility of mechanical opening. In an attempt to make the housing<figref>2</figref> A mechanism connected to the metal layer destroys the storage element of the device <figref>1</figref> Physically, so the device <figref>1</figref> Becomes unusable and the stored data becomes unreadable. The mechanism here is as one on the carrier element<figref>10</figref> (Not shown), in particular as a rotary cutting mechanism. Thus, for example, in an attempt to enter the housing<figref>2</figref> , The metal layer formed as a middle layer is bent so that a mandrel is inserted into the non-volatile storage element and the logic of the device <figref>1</figref> And thus the device <figref>1</figref> Becomes useless.
Inside the housing <figref>2</figref> Is also a chamber <figref>13</figref> As an enclosed free volume for optional extensions of the device <figref>1</figref>, For example for extensions of the communication abilities. Inside the chamber<figref>13</figref> Further funnel modules or the like could be arranged. The chamber<figref>13</figref> Encloses a volume on the order of 15 mm × 10 mm × 7.5 mm.
The device <figref>1</figref> Is configured to send information or data exclusively over a period of five seconds and over a short distance. The device<figref>1</figref> Is not designed to receive data transmitted, for example, by radio or cable connections from other devices.
To the device <figref>1</figref> In operation, is the cover member <figref>8th</figref> To remove, that is to say from the housing <figref>2</figref> So as to make an electrical contact between the contact elements on the carrier element <figref>10</figref> Arranged components of the logic, such as the storage element and the computing unit, and the transmission elements <figref>12</figref> With the energy storage <figref>11</figref> As a power supply. By making the electrical contact, the arithmetic unit and main memory are put into operation, the arithmetic unit charging the operating system from the non-volatile memory element. The operating system checks whether biometric data, ie, data from two different fingerprints, are already stored. When the biometric data is stored, the device goes<figref>1</figref> Into an operating mode which is caused by a light of the first light-emitting diode <figref>4</figref> is shown. The first light-emitting diode<figref>4</figref> Illuminates for a period of half a second at intervals of five seconds and emits green light.
If no biometric data has yet been stored, the device becomes <figref>1</figref> In a request mode, which is arranged on the housing <figref>2</figref> By alternately illuminating the light-emitting diodes <figref>4</figref>, <figref>5</figref> is shown. To execute the request mode, the device<figref>1</figref> In the vicinity of a registerable component, for example a computer. The device<figref>1</figref> Is now to be registered directly in the database of the system to be joined. Is the device<figref>1</figref> But not near a registerable component, the registration function is turned off after 30 seconds to discharge the energy storage <figref>11</figref> to avoid. The operation of the registration can be restarted by the scanning device<figref>3</figref> For 30 seconds, which is again registered by means of a photo cell. The process of registration is then continued.
The proximity and contact with the device become the registerable component <figref>1</figref> Clearly displayed clearly and requested the delivery of two impressions of any different finger. Once the finger prints over the scanning device<figref>3</figref> And read in the device <figref>1</figref> Are sent to the device <figref>1</figref> Via a transmission element <figref>12</figref> A one-to-one identification identifier to the registerable component. The identification identifier is stored under the name or another individual identifier in the database of the system to be joined. The successful transmission process is carried out by a green light of the first light-emitting diode, which flashes briefly three times<figref>4</figref> Is displayed. However, if the scanned fingerprints are not usable or some other disturbance occurs, the second light-emitting diode flashes<figref>5</figref> Three times briefly red. In addition, a transmission element<figref>12</figref> A corresponding message is sent to the registerable component, which is clearly displayed by the device. When the impressions of the two different fingers in the storage element of the device<figref>1</figref> And all processes of registration are confirmed by the registerable component is no communication to the device <figref>1</figref>, That is, a transfer of data to the device <figref>1</figref>, More possible. The device<figref>1</figref> Sends only data and that only on request. Register the device<figref>1</figref> Does not require a central database to match the data with a user. This is the registration of the device<figref>1</figref> Also not recoverable. When the device is lost<figref>1</figref> Must perform the process of activation with a new device <figref>1</figref> Can be carried out again. A function for fully replicating a device<figref>1</figref> With an assumption of the identity of the user is conceivable.
To the device <figref>1</figref> And sending data in the later use of the apparatus <figref>1</figref> To be activated by means of the scanning device <figref>3</figref> The impressions of the two fingers of the user are scanned and compared with those within the device <figref>1</figref> Stored data. When the scanning is correct<figref>3</figref> Generated data of the fingerprints with those in the device <figref>1</figref> Stored data, the user is authenticated, and a transmitting operation for authorizing the user is initiated, the information for authorization being transmitted by radio. Alternative methods of authentication include the process of scanning the iris or recognizing the voice of the user. The transmission process is thereby activated by scanning the impressions of the two different fingers at a distance of at most five seconds. After successful authentication of the user, the transmission elements send<figref>12</figref> Over a period of five seconds which is within the device <figref>1</figref> Stored one-time identification code as a unique code and identify the user of the device <figref>1</figref> Clearly as the legitimate user. The process of sending is by a continuous green-emitting first light-emitting diode<figref>4</figref> Is displayed.
In a system failure after or during fingerprint scanning, the second light-emitting diode is illuminated <figref>5</figref> Is continuously red for a period of five seconds, which in turn repeats every ten seconds when the disturbance continues. If at least one of the fingerprints is not recognizable or processable, the light-emitting diode light up<figref>4</figref>, <figref>5</figref> Five times alternately for one second each. If the fingerprints were scanned, but are not identical with the stored fingerprint data, the second light-emitting diode lights up<figref>5</figref> Over a duration of ten seconds continuously red, while the first light-emitting diode <figref>4</figref> Every two seconds for a period of one second. In addition, the transmission elements<figref>12</figref> Transmits a fault message to the remote station, at which a clear-text warning can be displayed when a corresponding output unit, such as a screen or a light display of light-emitting diodes is formed.
The opposite takes that from the device <figref>1</figref> With a signal transmitted by radio, sends the one-to-one identification number via any media to a central database system, in which the data are matched. Upon agreement or a successful comparison of the data, the user is authorized and the requested transaction is carried out. If the data is matched and the shares are released, the transaction takes place as usual. If, however, the comparison does not match the data, the release of the transaction is rejected and the remote is clearly displayed as a warning. In the case of transactional payment systems, such as with credit cards or debit cards, the matching of the data, in particular of the identification number, is carried out with data from the database of the respective financial service provider. For locking systems,
After the one-time registration, the device <figref>1</figref> Is put into a transmit-only mode and operated in the transmit-only mode, which does not enable two-track communication in the sense of a bidirectional data exchange. The device<figref>1</figref> Can thus neither be read out nor a second time, for example with data from others Fingerprints, but, after scanning the impressions of the two fingers and authenticating the user, sends an identifier for only five seconds, which can be recorded by a radio receiver. After the operation of sending the information, the device is executed<figref>1</figref> Automatically switched off and deactivated. The device<figref>1</figref> Is thereby again set to a passive state, in which no data can be transmitted. The device which is watertight and dustproof and protected against impacts and magnetic influences<figref>1</figref> Has no serial numbers or similar identifiers which are visible or accessible from the outside. Individualization should be possible by means of a shrink sleeve, engraving or the like.
The function of the entire system is based on the integration into existing payment systems and transaction systems. Thereby additional, not from the device<figref>1</figref> Used during the execution of the process. The device<figref>1</figref> Is intended solely for the purpose of authorizing the present user against the transaction site, such as a payment point or a banking machine, to guarantee the authenticity of its identity at this moment. With the device<figref>1</figref> There can be no transaction, reinsurance or the like, since the device <figref>1</figref> Only within a short period of time sends a positive signal to a dedicated receiver and confirms that the trigger of the transaction with the owner of the device <figref>1</figref> . Any further functionality, such as storing additional information, rewriting, or changing the contents of the device<figref>1</figref> Is impossible to ensure maximum safety.
For financial transactions must be in addition to the device <figref>1</figref> The legal users will be present, as users and device <figref>1</figref> Are fixedly coupled to one another by the delivery and storage of the biometric data. The relationship between the device<figref>1</figref> And the legitimate user can not be changed or transferred after the biometric data has been stored once. In addition, there must be a database which is based on a central system of the output device of the device<figref>1</figref>, Ie, a bank or other transactional company. Furthermore, at the location of the transaction, a query system is necessary, which is connected to a device with the device<figref>1</figref> Compatible transmission technology. A fictitious transaction has the following steps. The legal user of the device<figref>1</figref> Decides for a product or service, wants to pay for it and goes to a suitable payment point. The provider of the product or service collects all data for the transaction and transfers the data from the local application. A display device, for example an LED on the cash register system of the provider, points to the user of the device<figref>1</figref> For authenticating and authorizing at least one biometric property such as scanning fingerprints or iris, or recognizing the voice. After successful authentication of the legitimate user, the device sends<figref>1</figref> A one-to-one identification identifier via a compatible transmission technique to the receiver of the system of the provider, which inserts the user name and a system-internal identifier, for example an identification number of the credit card, into the local application. The vendor's system sends the transaction request to the credit card company, the bank or other transactional systems via an existing network. As already known, the user is asked whether the user with the appropriate identification is authorized to carry out a transaction at the specified height. The company sends back a message, which consists merely of a confirmation or a rejection. Upon confirmation, to terminate the transaction, all entered data is collected from the vendor's system, sent to the enterprise, The transaction is executed against the account of the customer and the invoice is printed. In the case of refusal, the corresponding reason is transmitted and displayed on the system of the provider. For the described transaction, only a new data compilation is to be defined as a package type and content, since the actual transaction is carried out by the company as before, after authorization has been given to the system of the provider. The packet type with the data, also known as an authorization token, has the following fields: Date and time stamps with fourteen digits - MMTTYYYYHHMMSS, serial number of the device For the described transaction, only a new data compilation is to be defined as a package type and content, since the actual transaction is carried out by the company as before, after authorization has been given to the system of the provider. The packet type with the data, also known as an authorization token, has the following fields: Date and time stamps with fourteen digits - MMTTYYYYHHMMSS, serial number of the device For the described transaction, only a new data compilation is to be defined as a package type and content, since the actual transaction is carried out by the company as before, after authorization has been given to the system of the provider. The packet type with the data, also known as an authorization token, has the following fields: Date and time stamps with fourteen digits - MMTTYYYYHHMMSS, serial number of the device<figref>1</figref> And user number with up to sixteen digits each to ensure the uniqueness of the authorization request, as well as a control sum for verifying the integrity of the transmitted data with two digits. The date and time stamp as well as the checksum are the only non-encrypted fields, the serial number, and the customer number are encrypted using a 256-bit key set by the issuing company based on the date and time stamp. This prevents randomly truncated packets of one with the device<figref>1</figref> Authorized transaction can be used again for a transaction. Encryption using the date and time stamp means that each data packet can only be used once. If the authorization is unsuccessful, the user must biometrically at the device again<figref>1</figref> And send a new data packet. Since thedevice <figref>1</figref> Is used only for a different, more secure way of authorization than with a PIN, a signature, or similar security - related procedures, all previous ways of handling the transaction can be reused without further notice, which considerably simplifies the commissioning of the new procedure and merely enhances the interface system with A corresponding compatible transmission technique, such as a radio link.
Also for key systems or access systems, besides the device <figref>1</figref> The legal users will be present, as users and device <figref>1</figref> Are fixedly coupled to one another by the delivery and storage of the biometric data. The relationship between the device<figref>1</figref> And the legitimate user can not be changed or transferred after the biometric data has been stored once. In addition, there must be a database which is based on a central system of the output device of the device<figref>1</figref>, Ie the operator of the building or a security company. Furthermore, a detection system is necessary at the access point, such as a door, gate or the like, which is connected to a device which is connected to the device<figref>1</figref> Compatible transmission technology. A fictitious admission of the access has the following steps. The legal user of the device<figref>1</figref> Accedes to the access of his choice, authenticates and authorizes himself through at least one biometric property, such as scanning fingerprints or iris, or recognizing the voice. After successful authentication of the legitimate user, the device sends<figref>1</figref> A one-to-one identification identification via a compatible transmission technique to the receiver of the access system, The system-internal identifier is filtered out by the data packet. The receiver sends the request for access to the building's master computer via the existing network. As already known, the user is asked whether the user with the appropriate identification is authorized to open the desired access at this time. The host computer sends back a message that consists merely of a confirmation or a rejection. To terminate the process, the access is opened upon confirmation and if access is denied access is denied. For the described query, only a new data compilation is to be defined as a package type and content, since the actual query of authorization at the central master computer of the building management is carried out as before. The packet type with the data again has the following fields:<figref>1</figref> And sequential number of the user with up to sixteen digits each to ensure the uniqueness of the authorization request, as well as a control sum for checking the integrity of the transmitted data with two digits. The date and time stamp as well as the checksum are the only non-encrypted fields, the serial number and the serial number are encrypted using a 256-bit key set by the issuing company based on the date and time stamp. This prevents randomly truncated packets of one with the device<figref>1</figref> Authorized access again for access. Encryption using the date and time stamp means that each data packet can only be used once. If the authorization is unsuccessful, the user must biometrically at the device again<figref>1</figref> And send a new data packet. Since the device<figref>1</figref> Is used only for a different, more secure way of authorization than with a PIN, a magnetic card or similar security-prone procedures, which can not be unambiguously linked to a legitimate user, all previous ways of processing the access authorization can be reused without alteration, which is merely the exchange The existing number fields or the expansion of the interface system with a corresponding compatible transmission technique such as radio receivers. The access authorization procedure can be used for both commercial and private buildings.
Also for the registration on computer systems and network systems must be in addition to the device <figref>1</figref> The legal users will be present, as users and device <figref>1</figref> Are fixedly coupled to one another by the delivery and storage of the biometric data. The relationship between the device<figref>1</figref> And the legitimate user can not be changed or transferred after the biometric data has been stored once. In addition, a database must be available which is based on the computer system used or on a central system of the output device of the device<figref>1</figref>, That is the operator of the network system. Furthermore, a computer system is necessary, which is connected to a control unit connected to the device<figref>1</figref> Compatible transmission technology. A fictitious logon on the computer system or on the network system has the following steps. The legal user of the device<figref>1</figref> Starts the computer of the computer system or of the network system, which is the user of the device <figref>1</figref> Via a registration mask for authentication and authorization via at least one biometric property, such as the scanning of the fingerprints or the iris or the recognition of the voice. After successful authentication of the legitimate user, the device sends<figref>1</figref> A one-to-one identification identification via a compatible transmission technology to the computer as receiver of the computer system or of the network system, which filters out the system-internal identification from the data packet. The computer sends the access request either to a locally stored security database or to a central computer within the system. As already known, the user is asked whether the user with the appropriate identification is authorized to use the computer. The local or central computer sends back a message consisting only of a confirmation or a rejection. To terminate the process, the computer is allowed to be confirmed and the computer is denied when the computer is rejected and a corresponding message is sent to the system administrator.
This packet type with the data also has the following fields: Date and time stamp with fourteen digits - MMTTYYYYHHMMSS, serial number of the device <figref>1</figref> And sequential number of the user with up to sixteen digits each to ensure the uniqueness of the authorization request, as well as a control sum for checking the integrity of the transmitted data with two digits. The date and time stamp as well as the checksum are the only non-encrypted fields, the serial number and the serial number are encrypted using a 256-bit key set by the issuing company based on the date and time stamp. This prevents randomly truncated packets of one with the device<figref>1</figref> Can be used again for a registration. Encryption using the date and time stamp means that each data packet can only be used once. If the authorization is unsuccessful, the user must biometrically at the device again<figref>1</figref> And send a new data packet. Since the device<figref>1</figref> Is used only for a different, more secure way of authorization than with a user name in combination with a password or similar security - related procedures that can not be unambiguously linked to a legitimate user, all previous ways of processing the application can be reused as is The exchange of the previous registration mask or an expansion of the computers used with a corresponding compatible transmission technique, such as a radio connection.
A further advantage of the device <figref>1</figref> And the method for authenticating and authorizing, in particular, that only the user registered by the issuing company is present on the device <figref>1</figref> , Is that a loss of the device <figref>1</figref> Merely an expense of the new procurement and the reprogramming of the device <figref>1</figref> caused. In the event of a damage, a functional failure or an irreparable fault in the device<figref>1</figref> Is the device <figref>1</figref> Destroyed and replaced by a new one. A reprogramming of the device<figref>1</figref> To the authorized user is unique with a change of the serial number of the device <figref>1</figref> To correct the checksums in the subsequent authorization processes, such as transactions, access authorizations, or logins to computer systems or network systems. In contrast to the loss of, for example, account cards, credit cards, access cards or keys, the devices no longer under the control of the entitled user are left<figref>1</figref> No risk of misuse, as no unauthorized user is at the device <figref>1</figref> And the device <figref>1</figref> For further authorizations. Moreover, the serial number of the device<figref>1</figref> From the database of the service provider, so that even if authentication is successful on the device <figref>1</figref> No more successful authorization is possible.
The operating time of the device <figref>1</figref>, Which are not equipped with accumulators and the corresponding charging possibilities, ends with average use with ten to fifteen authorizations on the day after approximately three to four years. Devices<figref>1</figref> With batteries whose runtime has elapsed, as well as damaged devices, are disposed of because of the robust design of the housing <figref>2</figref> And the self-interference of the storage element when the housing is opened <figref>2</figref>, No possibility exists of the device <figref>1</figref> To replace the battery as an energy storage device. Devices which have become unusable<figref>1</figref> Are withdrawn by the issuing company and fed to a recycling cycle which separates all elements and provides for a re-use or environmentally-friendly destruction.
Reference list
<dl><dt>1</dt><dd> device</dd><dt>2</dt><dd> casing</dd><dt>2a</dt><dd> Top housing <figref>2</figref></dd><dt>2 B</dt><dd> Bottom housing <figref>2</figref></dd><dt>3</dt><dd> Scan device fingerprint</dd><dt>4</dt><dd> First light-emitting diode</dd><dt>5</dt><dd> Second light-emitting diode</dd><dt>6</dt><dd> Through hole</dd><dt>7</dt><dd> Reinforcing metal</dd><dt>8th</dt><dd> Cover element</dd><dt>9</dt><dd> Contact, charging contact accumulator</dd><dt>10</dt><dd> Carrier element</dd><dt>11</dt><dd> Energy storage</dd><dt>12</dt><dd> Transmission element</dd><dt>13</dt><dd> chamber</dd><dt>A, b, c</dt><dd> Length of the half-axle</dd></dl>
CITATES INCLUDED IN THE DESCRIPTION
This list of the documents cited by the applicant has been generated automatically and is included for the better information of the reader only. The list is not part of the German patent or utility model application. The DPMA accepts no liability for any errors or omissions.
Cited Patent Literature
<ul list-style="bullet"><li>WO 2011028874 A1 <b>[0010]</b></li><li>US 20070197261 A1 <b>[0011]</b></li></ul>
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| EP3520088B1 | Cited by | European Patent Office (EPO) | Filed by opponent |
| DE102018126308A1 | Cited by | Germany | Search report |
| US2007197261A1 | Cites | United States of America | Applicant |
| WO2011028874A1 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| US2014137235A1 | Cites | United States of America | Search report |
| AT506236A1 | Cites | Austria | Search report |
| US20140137235A1 | Cites | United States of America | – |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 102015114367 | Germany | A | |
| DE201510114367 | – | – | – |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | |
| Response to examination communicationR016 | R016 | |
| Request for examination validly filedR012 | R012 |
Numbers
- Publication
- 102015114367
- Publication, DOCDB
- 102015114367
- Publication, EPODOC
- DE102015114367
- Application
- 10114367
- Application, DOCDB
- 102015114367
- Application, EPODOC
- DE201510114367
Titles2
- English
- An apparatus and method for authenticating and authorizing persons
- German
- Vorrichtung und Verfahren zum Authentifizieren und Autorisieren von Personen
Classification
- CPC, 9
- G06Q20/30
- G07C9/00182
- G06F21/32
- G06F21/35
- G06F21/86
- G06F2221/2143
- G07C9/257
- G07C9/26
- G07C2009/0023
- IPC, 3
- H04L9 32
- G07C9 00
- G06K9 78