EP1283474A1

Method and apparatus for personal identification

Abstract

A user-worn device 10a that is to be installed in user-worn equipment (wristwatch, eyeglasses, etc.) 30a that can be worn by a user, and a user device 20a that is to be installed in user equipment (card, mobile telephone, etc.) 40a to be used by the user are employed. The original information is divided to form a first information segment (1) and a second information segment (2). The first information segment (1) is stored in the user-worn device 10a and the second information segment (2) and the original information are stored in the user device 20a. The user-worn device 10a sends the first information segment (1) stored in its storage. The user device 20a combines the second information segment (2) stored in its storage with the received first information segment (1), forming a third piece of information. The identity of the user is authenticated if the third piece of information matches the original information. Once the identity of the user is authenticated, the user device 20a permits the use of the user equipment 40a.

EP1283474A1, drawing sheet 1
Sheet 1 of 22

Term

Term ended

Projected expiry passed 23 March 2021, 5.5 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

34 claims: 10 independent, 24 dependent

  1. 1
    A user authentication method for determining whether or not the user who is trying to use user equipment is the user who is authorized to use said user equipment, provided with    a step in which the original information is divided into a first information segment and a second information segment, and in which the first information segment is stored in a user-worn device worn by a user and the second information segment is stored in a device used by a user;a step in which the first information segment is sent from the user-worn device;a step in which the information is received by the user device;and    a step in which the identity of the user is authenticated when the original information can be reconstructed by combining the information received by the user device with the second information segment stored in the user device.
  2. 2
    The user authentication method according to Claim 1 wherein    the step in which the first information segment is sent from the user-worn device encrypts the first information segment before sending it, and    the step in which the information is received by the user device decrypts the received encrypted information.
  3. 3
    The user authentication method according to Claim 1 wherein    the step in which the first information segment is sent from the user-worn device inserts random noise into the first information segment, and    the step in which information is received by the user device removes the random noise from the received information.
  4. 4
    The user authentication method according to Claim 1 wherein the step in which the first information segment is sent from the user-worn device sends the first information segment wirelessly.
  5. 5
    The user authentication method according to Claim 1, further provided with    a step in which an information transmission request signal is sent from a user device, and wherein    the step in which the first information segment is sent from the user-worn device sends the first information segment when the user-worn device receives the information transmission request signal.
  6. 6
    A user authentication device for determining whether or not the user who is trying to use the user equipment is the user who is authorized to use said user equipment, provided with    a user-worn device to be worn by a user, and    a user device installed in the user equipment to be used by a user, wherein    the user-worn device has a first storage device for storing the first information segment obtained by dividing the original information into a first information segment and a second information segment, a modulation device for modulating the first information segment stored in the first storage device, and a first communication device, and    the user device has a second storage device for storing the second information segment obtained by dividing the original information into the first information segment and the second information segment, a second communication device, a demodulation device for demodulating the information received by the second communication device, and a user authentication device that authenticates the identity of the user if the original information can be reconstructed by combining the information demodulated by the demodulation device with the second information segment stored in the second storage device.
  7. 7
    The user authentication device according to Claim 6 wherein the user-worn device sends the first information segment at predetermined time intervals.
  8. 8
    The user authentication device according to Claim 6 wherein    the user device sends the information transmission request signal when user authentication is necessary, and    the user-worn device sends the first information segment when it receives the transmission request signal.
  9. 9
    The user authentication device according to Claim 6 wherein    the user-worn device encrypts the first information segment before sending it, and the user device has a decryption device for decrypting the received information.
  10. 10
    The user authentication device according to Claim 6 wherein    the user-worn device has a random noise insertion device for inserting random noise into the first information segment, and    the user device has a random noise removal device for removing the random noise from the received information.
  11. 11
    The user authentication device according to Claim 6 wherein the user device further has a read-out prohibition device that prohibits the reading of the second information segment stored in the second storage device if an unauthorized attempt is made to read out the second information segment.
  12. 12
    The user authentication device according to Claim 11 wherein the read-out prohibition device destroys the second storage device.
  13. 13
    The user authentication device according to Claim 6 wherein either the user-worn device or the user device or both contain an IC chip.
  14. 14
    The user authentication device according to Claim 13 wherein the IC chip is installed in a replaceable manner.
  15. 15
    The user authentication device according to Claim 6 wherein the user equipment is a card-shaped member.
  16. 16
    The user authentication device according to Claim 6 wherein the user equipment is a settlement card and the user authentication device permits the reading of the information stored in the settlement card if the identity of the user is authenticated.
  17. 17
    The user authentication device according to Claim 6 wherein the user equipment is a communication device.
  18. 18
    The user authentication device according to Claim 17 wherein the user authentication device permits the use of the communication device if the identity of the user is authenticated.
  19. 19
    A generation device for the user authentication device according to Claim 6 wherein the user device is provided with connection pins that can be connected to the connection pins of the user equipment.
  20. 20
    A user authentication device for determining whether or not the user who is trying to use the user equipment is the user who is authorized to use said user equipment, provided with    N (where N is an integer that is 3 or greater) user-worn devices to be worn by the user, and    a user device installed in the user equipment to be used by the user, wherein    the first through (N - 1)-th user-worn devices have first through N-th storage devices and first through (N - 1)-th communication devices for sending the information stored in the first through (N - 1)-th storage devices, respectively,    the user device is provided with the N-th storage device, the N-th communication device, and a user authentication device,    the first through (N - 1)-th storage devices store the first through (N - 1)-th information segments out of the first through N-th information segments formed by dividing the original information, and    the N-th storage device stores the N-th information segment out of the first through N-th information segments formed by dividing the original information, and the user authentication device authenticates the identity of the user if the original information can be reconstructed by combining the information received by the communication device with the information stored in the N-th storage device.
  21. 21
    A user authentication method for determining whether or not the user who is trying to use the user equipment is the user who is authorized to use said user equipment, provided with    a step in which the original information is divided into a first information segment and a second information segment, and the first information segment is stored in a user-worn device worn by the user and the second information segment is stored in a device used by the user;a step in which the first information segment is sent from the user-worn device;a step in which the first information segment is received by the user device;a step in which the first information segment received by the user device and the second information segment stored in the user device are sent from the user device to an authentication center;a step in which the authentication center receives the first information segment and the second information segment sent from the user device, and    a step in which the identity of the user is authenticated when the original information can be reconstructed by combining the first information segment with the second information segment received by the authentication center.
  22. 22
    The user authentication method according to Claim 21 wherein    the step in which the first information segment received by the user device and the second information segment stored in the user device are sent from the user device to an authentication center encrypts both the first information segment received by the user device and the second information segment stored in the user device using a public key before sending it to the authentication center, and    the step in which the authentication center receives the first information segment and the second information segment decrypts the received information using the secret key that corresponds to the public key used by the user device.
  23. 23
    A user authentication method for determining whether or not the user who is trying to use the user equipment is the user who is authorized to use said user equipment, provided with    a step in which the original information is divided into a first information segment and a second information segment, and in which the first information segment is stored in the user-worn device to be worn by the user and the second information segment is stored in the user device to be installed in the user equipment to be used by the user;a step in which a public key is divided into a first public key and a second public key, and in which the first public key is stored in the user-worn device and the second public key is stored in the user device;a step in which the first information segment and the first public key are sent from the user-worn device;a step in which the user device receives the first information segment and the first public key;a step in which the first information segment received by the user device and the second information segment stored in the user device are encrypted using the public key obtained by combining the first public key received by the user device with the second public key maintained by the user device before sending the encrypted information to an authentication center;a step in which the authentication center receives the encrypted information, and    a step in which the encrypted information received by the authentication center is decrypted into the first information segment and the second information segment using the secret key that corresponds to the public key being used by the user device, and in which the identity of the user is authenticated if the original information can be reconstructed by combining the decrypted first information segment with the second information segment.
  24. 24
    A user authentication device for determining whether or not the user who is trying to use the user equipment is the user who is authorized to use said user equipment, provided with    a user-worn device to be worn by the user,    a user device installed in the user equipment to be used by the user, and    an authentication center, wherein    the user-worn device has a first storage device for storing the first information segment obtained by dividing the original information into a first information segment and a second information segment, and a first communication device for sending the first information segment stored in the first storage device;the user device has a second storage device for storing the second information segment obtained by dividing the original information into the first information segment and the second information segment, a second communication device, and a third communication device for sending the first information segment received by the second communication device and the second information segment stored in the second storage device to the authentication center;and    the authentication center has a user authentication device that authenticates the identity of the user if the original information can be reconstructed by combining the first information segment with the second information segment sent from the user device.
  25. 25
    The user authentication device according to Claim 24 wherein    the user-worn device has an encryption device for encrypting the first information segment received by the second communication device and the second information segment stored in the second storage device, and    the authentication center has a decryption device for decrypting the encrypted information sent from the user device.
  26. 26
    The user authentication device according to Claim 25 wherein    the encryption device performs encryption using a public key, and    the decryption device performs decryption using the secret key that corresponds to the public key.
  27. 27
    A user authentication device for determining whether or not the user who is trying to use the user equipment is the user who is authorized to use said user equipment, provided with    a user-worn device to be worn by the user,    a user device installed in the user equipment to be used by the user, and    an authentication center, wherein    the user-worn device has a first storage device for storing the first information segment formed by dividing the original information into a first information segment and a second information segment as well as the first public key obtained by dividing a public key into a first public key and a second public key, and a first communication device for sending the first information segment and the first public key stored in the first storage device;the user device has a second storage device for storing the second information segment formed by dividing the original information into the first information segment and the second information segment as well as the second public key obtained by dividing a public key into a first public key and a second public key, a second communication device, and a third communication device for encrypting the first information segment received by the second communication device and the second information segment stored in the second storage device using the public key formed by combining the first public key received by the second communication device with the second public key stored in the second storage device, before sending the encrypted information to the authentication center;and    the authentication center has a user authentication device that decrypts the encrypted information received from the user device using the secret key that corresponds to the public key being used by the user device, and which authenticates the identity of the user if the original information can be reconstructed by combining the decrypted first information segment with the second information segment.
  28. 28
    A generation device for a user authentication device comprised of    a user-worn device to be worn by a user and having a first storage device for storing the first information segment formed by dividing the original information into a first information segment and a second information segment, and a first communication device for sending the first information segment stored in the first storage device, and    a user device to be installed in user equipment to be used by a user, having a second storage device for storing the second information segment formed by dividing the original information into a first information segment and a second information segment, a second communication device, and a user authentication device that authenticates the identity of the user if the original information can be reconstructed by combining the information received by the second communication device with the second information segment;provided with    a processing device, an information-writing device, and a display device, wherein    the processing device forms a first information segment and a second information segment by dividing the original information being displayed on the display device based on the dividing line being displayed on the display device, and outputs the first information segment and the second information segment that have been formed to the information-writing device, and    the information-writing device writes the first information segment that is output from the processing device into the first storage device of the user-worn device and also writes the second information segment that is output from the processing device into the second storage device of the user device.
  29. 29
    A generation device for a user authentication device comprised of    a user-worn device to be worn by a user and having a first storage device for storing the first information segment formed by dividing the original information into a first information segment and a second information segment, and a first communication device for sending the first information segment stored in the first storage device, and    a user device to be installed in user equipment to be used by a user, having a second storage device for storing the second information segment formed by dividing the original information into a first information segment and a second information segment, a second communication device, and a user authentication device that authenticates the identity of the user if the original information can be reconstructed by combining the information received by the second communication device with the second information segment;provided with    a processing device, an information-writing device, and a display device, wherein    the processing device forms the first information segment and the second information segment by dividing the original information that has been input from an input device using the dividing method specified by the input device, and outputs the first information segment and the second information segment that have been formed to the information-writing device, and    the information-writing device writes the first information segment that is output from the processing device into the first storage device of the user-worn device and also writes the second information segment that is output from the processing device into the second storage device of the user device.
  30. 30
    The generation device for a user authentication device according to Claim 29, further provided with    a product discharge device, and wherein    the product discharge device discharges a user-worn device, into which the first information segment has been written, and a user device, into which the second information segment has been written, from product discharge ports.
  31. 31
    A generation method for a user authentication device, a first device that sends the first information segment, and that authenticates the identity of the user if the original information can be reconstructed by combining the first information segment received from the first device with the second information segment locally stored, provided with    a step for preparing a printed circuit board having an encryption device that generates both an encryption formula and a decryption formula, and that performs encryption using the encryption formula and decryption using the decryption formula;an encrypted code storage device for storing the encrypted code obtained by encrypting the original code using the encryption formula generated by the encryption device;and an original code storage device for storing both the decryption formula generated by the encryption device and the original code;a step for forming a first printed circuit board provided with the encryption device and the original code storage device, and a second printed circuit board provided with the encrypted code storage device, by cutting the printed circuit board;and    a step that uses the first printed circuit board as the second device and the second printed circuit board as the first device.
  32. 32
    The generation method for the user authentication device according to Claim 31 wherein    the encryption device generates an encryption formula and a decryption formula that change over time,    the encrypted code storage device stores and retains the encrypted code obtained by encrypting the original code using the encryption formula that is in effect when the printed circuit board is cut, and    the original code storage device stores both the decryption formula that is in effect when the printed circuit board is cut and the original code.
  33. 33
    The generation method for the user authentication device according to Claim 32 wherein the encryption device performs encryption and decryption using a chaos computation formula generated by a chaos generator.
  34. 34
    The generation method for the user authentication device according to Claim 31 wherein the step for cutting the printed circuit board cuts the printed circuit board at the cutting area formed therein.
Independent claims34