EP0334616B1

Method and system for personal identification.

Abstract

This record has no abstract on file.

EP0334616B1, drawing sheet 1
Sheet 1 of 3

Term

Term ended

Expired 21 March 2009, 17.5 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

8 claims: 8 independent, 0 dependent

  1. 1
    A system for issuing authorized personal identification cards (10) and for preventing unauthorized use thereof, comprising:issuing terminal means (76) for issuing a plurality of personal identification cards (10);each of said cards having stored therein a first data string (20) with a portion (20a) thereof derived from a physical characteristic of an authorized user of the card, each of said cards (10) also having stored therein a signature (22) derived from a second data string (Q) using a private key (P₁,P₂) of a public-key cryptosystem pair, the public-key cryptosystem pair also having a public key (M), the second data string (Q) being derived from the first data string (20) using a predetermined one-way function (F) and having a length substantially less than the length of the first data string (20);and    transaction terminal means (78) including at least one transaction terminal for receiving a personal identification card (10) offered to effect a transaction using the transaction terminal, the personal identification card (10) having the first data string (20) and a received signature (22) stored therein, wherein the transaction terminal (78) comprises means, using the public key (M) of the public-key cryptosystem pair, for verifying that the received signature (22) can be generated from the first data string (20), means responsive to the verifying means for generating a representation from the first data string, and means for displaying (96) the representation and an indication of whether the received signature (22) can be generated from the first data string (20) to enable an operator of the transaction terminal (78) to verify that the user of the offered personal identification card (10) is authorized to effect a transaction. System zur Ausgabe von autorisierten persönlichen Identifikationskarten (10) und zur Verhinderung ihrer unberechtigten Verwendung, welches enthält: ein Ausgabeterminal (76) zur Ausgabe einer Vielzahl von persönlichen Identifikationskarten (10), wobei auf jeder der Karten eine erste Datenreihe (20) mit einem Teil (20a) gespeichert ist, der von physikalischen Charakteristika eines autorisierten Anwenders der Karte stammt, wobei jede der Karten (10) ferner eine Signatur (22) gespeichert aufweist, die von einer zweiten Datenreihe (Q) unter Verwendung eines privaten Schlüssels (P₁, P₂) eines offenen Krpytosystempaars enthält, wobei das offene Kryptosytempaar außerdem einen offenen Schlüsel (M) aufweist, wobei die zweite Datenreihe (Q) aus der ersten Datenreihe (20) abgeleitet ist, in dem eine vorbestimmte Einwegfunktion (F) verwendet ist und die eine Länge aufweist, die beträchtlich kleiner als die Länge der ersten Datenreihe (20) ist;und mit einem Übertragungsterminal (78), das wenigstens ein Übertragungsterminal zur Aufnahme einer persönlichen Identifikationskarte (10) enthält, mit der eine Übertragung unter Verwendung des Übertragungsterminals möglich ist, wobei die persönliche Identifikationskarte (10) eine erste Datenreihe (20) und eine darin aufgenommene Signatur (22) enthält, wobei das Übertragungsterminal (78) Mittel enthält, welche den offenen Schlüssel (M) des Offen-Schlüssel-Kryptosystempaars verwenden, um sicherzustellen, daß die empfangene Signatur (22) aus der ersten Datenreihe (20) abgeleitet werden kann, Mittel, die auf die Überprüfungsmittel ansprechen, um eine Darstellung aus der ersten Datenreihe zu erzeugen, und Mitteln zur Anzeige (96) der Darstellung und eine Anzeige, ob die empfangene Signatur (22) aus der ersten Datenreihe (20) erzeugt werden kann, um einem Bediener des Übertragungsterminals (78) zu bestätigen, daß der Verwender der angebotenen persönlichen Identifikationskarte (10) autorisiert ist, die Übertragung zu bewirken. Système servant à produire des cartes d'identification pour personnel autorisé (10) et à empêcher leur utilisation par du personnel non autorisé, comprenant :    un moyen de production à terminal (76) servant à produire une pluralité de cartes d'identification de personnel (10) ;chacune desdites cartes ayant stocké, en son sein, une première suite de données (20), avec une partie (20a) de cette dernière déduite d'une caractéristique physique d'un utilisateur autorisé de la carte, chacune desdites cartes (10) ayant également, stocké en son sein, une empreinte numérique (22) déduite d'une deuxième suite de données (Q) utilisant une clé privée (P₁, P₂) d'un couple de système de chiffrage à clé publique, le système de chiffrage à clé publique ayant également une clé publique (M), la deuxième suite de données (Q) étant déduite de la première suite de données (20) à l'aide d'une fonction univoque prédéterminée (F) et ayant une longueur sensiblement inférieure à la longueur de la première suite de données (20) ;et    un moyen de mouvement à terminal (78), comprenant au moins un terminal de mouvement destiné à recevoir une carte d'identification de personnel (10) présentée afin d'effectuer un mouvement à l'aide d'un terminal de mouvement, la carte d'identification de personnel (10) présentant la première suite de données (20) et une empreinte (22) reçue, stockée en son sein, dans lequel le terminal de mouvement (78) comprend un moyen, utilisant la clé publique (M) du couple de système de chiffrage à clé publique, servant à vérifier que l'empreinte (22) reçue peut être produite par la première suite de données (20), un moyen réagissant au moyen de vérification, afin de produire une représentation à partir de la première suite de données, et un moyen (96) servant à afficher la représentation et une indication du fait que l'empreinte (22) reçue peut être produite par la première suite de données (20), afin de permettre à un opérateur du terminal de mouvement (78) de vérifier que l'utilisateur de la carte d'identification de personnel (10) présentée est autorisé à effectuer un mouvement.
  2. 2
    A system according to Claim 1, wherein the issuing terminal means (76) includes at least one issuing terminal for one or more independent issuers of authorized personal identification cards (10), each of the independent issuers having a distinctive public-key cryptosystem pair unknown to the other issuers. System nach Anspruch 1, bei dem das Ausgabeterminal (76) wenigstens ein Ausgabeterminal für einen oder mehrere unabhängige Ausgeber von autorisierten persönlichen Identifikationskarten (10) enthält, wobei jede der unabhängigen Ausgeber ein bestimmtes Offen-Schlüssel-Kryptosystempaar verwendet, das den anderen Ausgebern unbekannt ist. Système selon la revendication 1, dans lequel le moyen de production à terminal (76) comprend au moins un terminal de production pour un ou plusieurs émetteurs indépendants de cartes d'identification de personnel autorisé (10), chacun des émetteurs indépendants présentant un couple de système de chiffrage à clé publique distinctive, inconnu des autres émetteurs.
  3. 3
    A system for allowing authorized users of personal identification cards (10) to effect transactions via at least one transaction terminal (78), comprising a plurality of cards (10) each having stored therein a signature (22) which is the digital signature of a second data string (Q), the second data string (Q) being derived from a first data string (20) derived from a physical characteristic associated with a respective user, the second data string (Q) being derived from the first data string (20) using a predetermined one-way function (F) and having a length substantially less than the length of the first data string (20), the signature (22) stored in each of said cards (10) having been derived with the same private key (P₁,P₂) of a public-key cryptosystem pair also having a public key (M); and at least one transaction terminal (78) having means for controlling:(1) the retrieval of the first data string (20) and the signature (22) stored in an inserted card;(2) the digital verification of the signature (22) with the use of the public key (M) of the public-key cryptosystem pair;(3) the generation of a pictorial representation from the first data string (20);and(4) the effecting of a transaction only if the signature (22) is verified and the pictorial representation matches the user. System, es autorisierten Verwendern von persönlichen Identifkationskarten (10) zu ermöglichen, eine Übertragung über wenigstens ein Übertragungsterminal (78) zu bewirken, das eine Vielzahl von Karten (10) enthält, die jeweils eine Signatur (22) aufweisen, welche die digitale Signatur einer zweiten Datenreihe (Q) ist, wobei die zweite Datenreihe (Q) aus einer ersten Datenreihe (20) abgeleitet ist, die von physikalischen Charakteristika bezüglich des entsprechenden Nutzers abgeleitet ist und wobei die zweite Datenreihe (Q) aus der ersten Datenreihe (20) unter Verwendung einer vorbestimmten Einwegfunktion (F) abgeleitet ist und eine Länge aufweist, die beträchtlich geringer als die Länge der ersten Datenreihe (20) ist, wobei die Signatur (22), die in jeder der Karten (10) gespeichert ist, mit dem gleichen privaten Schlüssel (P₁, P₂) eines Offen-Schlüssel-Kryptosystempaars abgeleitet ist, das ebenfalls einen offenen Schlüssel (M) aufweist, und mit wenigstens einem Übertragungsterminal (78), mit Mitteln zur Steuerung (1) des Ermittelns der ersten Datenreihe (20) und der Signatur (22), die auf der Karte gespeichert sind,(2) der digitalen Verifikation der Signatur (22) unter Verwendung des offenen Schlüssels (M) des Offen-Schlüssel-Kryptosystempaars,(3) der Erzeugung einer Bilddarstellung aus der ersten Datenreihe (20) und(4) der Bewirkung einer Übertragung, nur dann, wenn die Signatur (22) verifiziert ist und die bildliche Darstellung dem Anwender entspricht. Système servant à permettre à des utilisateurs autorisés de cartes d'identification de personnel (10) d'effectuer des mouvements via au moins un terminal de mouvement (78), comprenant une pluralité de cartes (10), présentant chacune, en son sein, une empreinte (22), qui est l'empreinte numérique d'une deuxième suite de données (Q), la deuxième suite de données (Q) étant déduite d'une première suite de données (20), déduite d'une caractéristique physique associée à un utilisateur respectif, la deuxième suite de données (Q) étant déduite de la première suite de données (20) à l'aide d'une fonction univoque prédéterminée (F) et ayant une longueur sensiblement inférieure à la longueur de la première suite de données (20), l'empreinte (22), stockée dans chacune desdites cartes (10), ayant été déduite avec la même clé privée (P₁, P₂) d'un couple de système de chiffrage à clé publique ayant une clé publique (M) ;et au moins un terminal de mouvement (78) présentant un moyen servant à commander : (1) l'extraction de la première suite de données (20) et de l'empreinte (22) stockée dans une carte insérée;(2) la vérification numérique de l'empreinte (22) à l'aide de la clé publique (M) du couple de système de chiffrage à clé publique ;(3) la production d'une représentation graphique de la première suite de données (20) ;et(4) la réalisation d'un mouvement, seulement si l'empreinte (22) est vérifiée et que la représentation graphique est adaptée à l'utilisateur.
  4. 4
    A terminal (76) for initializing personal identification cards (10) to be used with at least one transaction terminal (78), each card (10) having a memory (16) therein, comprising means for assigning a first data string (20) having a portion (20a) thereof which is derived from a physical characteristic of a user whose card is to be initialized, means for mapping the first data string (20) with a predetermined one-way function (F) to generate a second data string (Q) having a length substantially less than the length of the first data string (20), means for deriving a digital signature (22) from the second data string (Q), the signature of each user being derived with use of a private key (P₁,P₂) of a public-key cryptosystem pair also having a public key (M), and means for controlling the storing in a user card (10) of the respective derived digital signature (22). Terminal (76) d'initialisation de cartes d'identification de personnel (10), destiné à être utilisé avec au moins un terminal de mouvement (78), chaque carte (10) ayant, en son sein, une mémoire (16), comprenant un moyen servant à attribuer une première suite de données (20), dont une partie (20a) est déduite d'une caractéristique physique d'un utilisateur dont la carte doit être initialisée, un moyen servant à tracer une carte de la première suite de données (20) avec une fonction univoque prédéterminée (F), afin de produire une deuxième suite de données (Q) ayant une longueur sensiblement inférieure à la longueur de la première suite de données (20), un moyen servant à déduire une empreinte numérique (22) à partir de la deuxième suite de données (Q), l'empreinte de chaque utilisateur étant déduite d'une clé privée (P₁, P₂) d'un couple de système de chiffrage à clé publique ayant également une clé publique (M), et un moyen servant à commander le stockage d'une carte d'utilisateur (10) de l'empreinte numérique (22) déduite respective. Terminal (76) zur Initialisierung persönlicher Identifikationskarten (10) zur Verwendung mit wenigstens einem Übertragungsterminal (78), wobei jede Karte (10) einen Speicher (16) enthält, mit Mitteln zur Zuordnung einer ersten Datenreihe (20) mit einem Teil (20a), der aus physikalischen Charakteristika eines Verwenders abgeleitet ist, dessen Karte zur initialisieren ist, Mitteln zur Abbildung der ersten Datenreihe (20) mit einer vorbestimmten Einwegfunktion (F) zur Erzeugung einer zweiten Datenreihe (Q) mit einer Länge, die beträchtlich kleiner als die Länge der ersten Datenreihe (20) ist, Mitteln zur Ableitung einer digitalen Signatur (22) aus der zweiten Datenreihe (Q), wobei die Signatur jedes Verwenders unter Verwendung eines privaten Schlüssels (P₁, P₂) eines Offen-Schlüssel-Kryptosystempaars abgeleitet ist, das außerdem einen offenen Schlüssel (M) aufweist, und Mitteln zur Steuerung der Speicherung auf der Anwenderkarte (10) der entsprechend abgeleiteten digitalen Signatur (22).
  5. 5
    A personal identification card (10) for use in effecting transactions via at least one transaction terminal (78), comprising a body portion (12), a memory (16) within said body portion for storing a signature (22), said signature (22) being the digital signature of a second data string (Q) derived from a first data string (20) having at least a portion (20a) thereof being derived from a physical characteristic of a respective card user, the second data string (Q) being derived from the first data string (20) using a predetermined one-way function (F) and having a length substantially less than the length of the first data string (20), wherein said signature (22) is derived from the second data string (Q) with the private key (P₁,P₂) of a public-key cryptosystem pair. Carte d'identification de personnel (10) destinée à être utilisée afin d'effectuer des mouvements via au moins un terminal de mouvement (78), comprenant une partie de corps (12), une mémoire (16) dans ladite partie de corps afin de stocker une empreinte (22), ladite empreinte (22) étant l'empreinte numérique d'une deuxième suite de données (Q) déduite d'une première suite de données (20), ayant au moins une partie (20a) déduite d'une caractéristique physique d'un utilisateur de carte respectif, la deuxième suite de données (Q) étant déduite de la première suite de données (20) à l'aide d'une fonction univoque prédéterminée (F) et ayant une longueur sensiblement inférieure à la longueur de la première suite de données (20), dans laquelle ladite empreinte (22) est déduite de la deuxième suite de données (Q) avec la clé privée (P₁, P₂) d'un couple de système de chiffrage à clé publique. Eine persönliche Identifikationskarte (10) zur Verwendung bei der Auslösung von Übertragungen über wenigstens ein Übertragungsterminal (78), die einen Grundkörper (12) enthält, einen Speicher (16) innerhalb des Grundkörperteils zur Speicherung einer Signatur (22), wobei die Signatur (22) die digitale Signatur einer zweiten Datenreihe (Q) ist, die aus einer ersten Datenreihe (20) abgeleitet ist, die wenigstens ein Teil (20a) dieser enthält, der aus einer physikalischen Charakteristik des entsprechenden Kartenverwenders abgeleitet ist, wobei die zweite Datenreihe (Q) aus der ersten Datenreihe (20) unter Verwendung einer vorbestimmten Einwegfunktion (F) abgeleitet ist und eine Länge aufweist, die beträchtlich kleiner als die Länge der ersten Datenreihe (20) ist, wobei die Signatur (22) aus der zweiten Datenreihe (Q) mit dem privaten Schlüssel (P₁, P₂) eines Offen-Schlüssel-Kryptosystems abgeleitet ist.
  6. 6
    A method for enabling an authorized user of a personal identification card (10) to effect a transaction using a transaction terminal (78), the personal identification card (10) having user-characteristic data (20) derived from a physical characteristic of the authorized user and which need not be retained secret, and a signature (22) of the user-characteristic data (20) derived from a private key (P₁,P₂) of a public-key cryptosystem pair, the public-key cryptosystem pair also including a public key (M), comprising the steps of:receiving the personal identification card (10) at the transaction terminal (78);digitally verifying, using the public key (M), whether the signature (22) on the personal identification card (10) received at the transaction terminal (78) can be generated from the user-characteristic data (20);and    if the signature (22) can be generated from the user-characteristic data (20) using the public key (M), displaying a representation of the user-characteristic data (20) on a display (96) of the transaction terminal (78) to enable an operator thereof to verify that the user is authorised to effect a transaction using the personal card. Procédé servant à permettre à un utilisateur autorisé d'une carte d'identification de personnel (10) d'effectuer un mouvement à l'aide d'un terminal de mouvement (78), la carte d'identification de personnel (10) ayant des données de caractéristique d'utilisateur (20) déduites d'une caractéristique physique de l'utilisateur autorisé et ne nécessitant pas d'être maintenues secrètes, et une empreinte (22) des données de caractéristique d'utilisateur (20) déduites d'une clé privée (P₁, P₂) d'un couple de système de chiffrage à clé publique, le couple de système de chiffrage à clé publique comportant également une clé publique (M), procédé comprenant les étapes de :    réception de la carte d'identification de personnel (10) au terminal de mouvement (78) ;vérification numérique, à l'aide de la clé publique (M), du fait que l'empreinte (22) située sur la carte d'identification de personnel (10), reçue au terminal de mouvement (78), peut être produite à partir des données de caractéristique d'utilisateur (20) ;et    si l'empreinte (22) peut être produite à partir des données de caractéristique d'utilisateur (20) à l'aide de la clé publique (M), affichage d'une représentation des données de caractéristique d'utilisateur (20) sur un affichage (96) du terminal de mouvement (78), afin de permettre à son opérateur de vérifier que l'utilisateur est autorisé à effectuer un mouvement à l'aide de la carte de personnel. Verfahren zur Bewirkung einer Übertragung durch einen autorisierten Verwender einer persönlichen Identifikationskarte (10) unter Verwendung eines Übertragungsterminals (78), wobei die persönliche Identifikationskarte (10) anwendercharakteristische Daten (20) enthält, die aus physikalischen Charakteristika des autorisierten Verwenders abgeleitet sind und die nicht geheim zu halten sind, und einer Signatur (22) der anwendercharakteristischen Daten (20), die von einem privaten Schlüssel (P₁, P₂) eines Offen-Schlüssel-Kryptosystempaars abgeleitet ist, wobei das Offen-Schlüssel-Kryptosystempaar außerdem einen offenen Schlüssel (M) enthält, das die Schritte umfaßt: Annahme der persönlichen Identifkationskarte (10) an dem Übertragungsterminal (78), digitale Verifizierung unter Verwendung des offenen Schlüssels (M), ob die Signatur (22) auf der persönlichen Identifikationskarte (10), die vom Übertragungsterminal (78) aufgenommen ist, aus den anwendercharakteristischen Daten (20) erzeugt werden kann, und wenn die Signatur (22) aus den anwendercharakteristischen Daten (20) unter Verwendung des offenen Schlüssels (M) abgeleitet werden kann, Anzeige einer Darstellung der anwendercharakteristischen Daten (20) auf einem Display (96) des Übertragungsterminals (78), um dessen Bediener zu ermöglichen zu verifizieren, daß der Verwender berechtigt ist, eine Übertragung unter Verwendung der persönlichen Karte vorzunehmen.
  7. 7
    A method according to Claim 6, wherein both a representation of said physical characteristic of the authorized user, and an indication of the validity status of the signature (22) on the personal identification card (10) are displayed on a display of said transaction terminal (78), said representation being generated from the user-characteristic data (20) on the personal identification card (10). Procédé selon la revendication 6, dans lequel, à la fois, une représentation de ladite caractéristique physique de l'utilisateur autorisé et une indication de l'état de validité de l'empreinte (22) sur la carte d'identification de personnel (10) sont affichées sur un affichage dudit terminal de mouvement (78), ladite représentation étant produite à partir des données de caractéristique d'utilisateur (20) situées sur la carte d'identification de personnel (10). Verfahren nach Anspruch 6, bei dem sowohl eine Darstellung der physikalischen Charakteristika des autorisierten Verwenders, und eine Anzeige des Gültigkeitsstatus der Signatur (22) auf der persönliche Identifkationskarte (10) auf einem Display des Übertragungsterminals (78) angezeigt werden, wobei die Darstellung aus den anwendercharakteristischen Daten (20) auf der persönlichen Identifikationskarte (10) erzeugt ist.
  8. 8
    A method according to Claim 6 or 7, wherein said signature (22) of the user-characteristic data (20) is derived by:(i) generating an intermediate data string (Q) from the user-characteristic data using a predetermined one-way function (F), the intermediate data string (Q) being substantially smaller in size than said user-characteristic data;and(ii) deriving said signature (22) from said intermediate data string (Q) using said private key (P₁,P₂). Procédé selon la revendication 6 ou 7, dans lequel ladite empreinte (22) des données de caractéristique d'utilisateur (20) est déduite : (i) en produisant une suite de données (Q) intermédiaire à partir des données de caractéristique d'utilisateur, à l'aide d'une fonction univoque prédéterminée (F), la taille de la suite de données (Q) intermédiaire étant sensiblement inférieure à celle desdites données de caractéristique d'utilisateur ;et(ii) en déduisant ladite empreinte (22) à partir de ladite suite de données (Q) intermédiaire à l'aide de ladite clé privée (P₁, P₂). Verfahren nach Anspruch 6 oder 7, bei dem die Signatur (22) der anwendercharakteristischen Daten (20) abgeleitet sind durch (i) Erzeugen einer Zwischendatenreihe (Q) aus den anwendercharakteristischen Daten unter Verwendung einer vorbestimmten Einwegfunktion (F), wobei die Zwischendatenreihe (Q) beträchtlich kleiner in der Größe ist als die anwendercharakteristischen Daten ist, und(ii) Ableiten der Signatur (22) aus der Zwischendatenreihe (Q) unter Verwendung eines privaten Schlüssels (P₁, P₂).