Protection of a biometric access control
Abstract
Access control method in an access control system (10) comprising: an access control server (12) adapted to control an access; at least one biometric signal sensor (11); and an interface device (13) adapted to be related, on the one hand, with the control server and, on the other hand, with the sensor; said access being authorized to at least one person that has a reference signal associated with corresponding biometric information; managing the control server and the interface device, on the one hand, a common parameter that takes different values over time and, on the other hand, respectively a first and a second non-reversible transformation function, said transformation functions being first and second parameterized according to at least said common parameter; said procedure comprising the following steps: a. at the sensor level, pick up a biometric signal and provide said biometric signal captured to the interface device; b. at the interface device level, obtaining a transformed biometric signal by applying the first transformation function to an element between a group comprising at least one characteristic derived from said captured biometric signal and said captured biometric signal; and transmitting (14) said transformed biometric signal destined to the control server; c. at the control server level, make a comparison of the transformed biometric signal with at least one comparison signal, said comparison signal corresponding to a signal resulting from the application of the second transformation function to an initial signal derived from the signal of reference; and d. Based on this comparison, decide whether an access is authorized.

Term
0.4 yearsto projected expiry
Projected expiry 15 February 2027, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
15 claims: 9 independent, 6 dependent
- 1ES 2 385 608 T3 REIVINDICACIONES 1. Procedimiento de control de acceso en un sistema de control de acceso (10) que comprende:un servidor de control de acceso (12) adaptado para controlar un acceso;al menos un sensor de señal biométrica (11);y un dispositivo de interfaz (13) adaptado para estar relacionado, por una parte, con el servidor de control y, por otra parte, con el sensor;autorizándose dicho acceso a al menos una persona que tiene asociada una señal de referencia que comprende información biométrica correspondiente;gestionando el servidor de control y el dispositivo de interfaz, por una parte, un parámetro común que toma valores diferentes con el paso del tiempo y, por otra parte, respectivamente una primera y una segunda función de transformación no reversible, siendo dichas funciones de transformación primera y segunda parametrizadas en función al menos de dicho parámetro común;comprendiendo dicho procedimiento las siguientes etapas: /a/ a nivel del sensor, captar una señal biométrica y proporcionar dicha señal biométrica captada al dispositivo de interfaz;/b/ a nivel del dispositivo de interfaz, obtener una señal biométrica transformada aplicando la primera función de transformación a un elemento de entre un grupo que comprende al menos una característica derivada de dicha señal biométrica captada y dicha señal biométrica captada;y transmitir (14) dicha señal biométrica transformada con destino al servidor de control;/c/ a nivel del servidor de control, efectuar una comparación de la señal biométrica transformada con al menos una señal de comparación, correspondiendo dicha señal de comparación a una señal resultante de la aplicación de la segunda función de transformación a una señal inicial derivada de la señal de referencia;y /d/ basándose en dicha comparación, decidir si se autoriza un acceso.
- 2Procedimiento de control de acceso según la reivindicación 1, en el que los valores del parámetro común son función de los valores de un contador, gestionado a nivel del dispositivo de interfaz y del servidor, del número de señales biométricas transformadas que son transmitidas y recibidas respectivamente por el dispositivo de interfaz y el servidor.
- 3Procedimiento de control de acceso según una cualquiera de las anteriores reivindicaciones, en el que, al estar sincronizados el servidor de control de acceso y el dispositivo de interfaz en una referencia temporal común, los valores del parámetro común son función del valor de la referencia temporal común.
- 4Procedimiento de control de acceso según una cualquiera de las anteriores reivindicaciones, en el que los valores del parámetro común se registran a nivel del dispositivo de interfaz y en el que cada nuevo valor del parámetro común se transmite al servidor de control.
- 5Procedimiento de control de acceso según una cualquiera de las anteriores reivindicaciones, en el que el sistema de control de acceso controla el acceso a una pluralidad de tipos de aplicaciones y en el que con dicha pluralidad de tipos de aplicaciones se asocia respectivamente una pluralidad de pares de una primera función de transformación no reversible a nivel del dispositivo de interfaz y de una segunda función de transformación no reversible a nivel del servidor de control.
- 6Procedimiento de control de acceso según una cualquiera de las anteriores reivindicaciones, en el que la señal inicial comprende la señal de referencia y en el que la aplicación de la primera y la aplicación de la segunda función de transformación parametrizadas no reversibles son equivalentes.
- 7Procedimiento de control de acceso según una cualquiera de las anteriores reivindicaciones, en el que la señal inicial derivada de la señal de referencia, correspondiente a la al menos una persona autorizada, se obtiene mediante aplicación de una función de transformación inicial no reversible a la señal de referencia;y en el que la primera función de transformación equivale a una combinación de la segunda función de transformación y de dicha función de transformación inicial.
- 8Procedimiento de control de acceso según una cualquiera de las anteriores reivindicaciones, en el que se asocia un identificador con el dispositivo de interfaz y/o con la al menos una persona a la que se autoriza el acceso y en el que el servidor de control gestiona una asociación de la al menos una señal de comparación con dicho identificador; ES 2 385 608 T3 comprendiendo además dicho procedimiento, antes de la etapa /c/, las siguientes etapas:- obtener, a nivel del dispositivo de interfaz, un identificador correspondiente a la señal biométrica captada;- transmitir al servidor de control dicho identificador;y - a nivel del servidor de control, recuperar la señal de comparación asociada a dicho identificador recibido.
- 9Dispositivo de interfaz (13) en un sistema de control de acceso (10) que comprende además, por una parte, un servidor de control de acceso (12) adaptado para controlar un acceso; y, por otra parte, al menos un sensor de señal biométrica (11); autorizándose dicho acceso a al menos una persona que tiene asociada una señal de referencia que comprende información biométrica correspondiente; comprendiendo dicho dispositivo de interfaz:- una unidad de gestión (133) adaptada para gestionar, por una parte, un parámetro, común con el servidor de control, que toma valores diferentes con el paso del tiempo y, por otra parte, una función de transformación no reversible, siendo dicha función de transformación parametrizada en función de al menos dicho parámetro común;- una primera unidad de interfaz (131) adaptada para recibir una señal biométrica captada desde el sensor;- una unidad de transformación (135) adaptada para transformar una señal biométrica captada en una señal biométrica transformada aplicando la función de transformación a un elemento de entre un grupo que comprende al menos una característica derivada de dicha señal biométrica captada y dicha señal biométrica captada;y - una segunda unidad de interfaz (132) adaptada para cooperar con un dispositivo de transmisión (15) adaptado para transmitir una señal biométrica transformada por la unidad de transformación con destino al servidor de control.
- 10Dispositivo de interfaz (13) según la reivindicación 9, en el que los valores del parámetro común son función de los valores de un contador, gestionado por la unidad de gestión (133), del número de señales biométricas transformadas que se envían respectivamente al servidor.
- 11Dispositivo de interfaz (13) según la reivindicación 9 ó 10, en el que, al estar sincronizados el servidor de control de acceso y el dispositivo de interfaz en una referencia temporal común, los valores del parámetro común son función del valor de la referencia temporal común.
- 12Dispositivo de interfaz (13) según una cualquiera de las reivindicaciones 9 a 11, en el que los valores del parámetro común se registran a nivel del dispositivo de interfaz y en el que cada nuevo valor del parámetro común se transmite al servidor de control.
- 13Sensor de señal biométrica (11) que comprende un dispositivo de interfaz según una cualquiera de las reivindicaciones 9 a 12.
- 14Servidor de control de acceso (12) en un sistema de control de acceso (10) que comprende además al menos un sensor de señal biométrica (11); y un dispositivo de interfaz (13) adaptado para estar relacionado, por una parte, con el servidor de control y, por otra parte, con el sensor; autorizándose dicho acceso a al menos una persona que tiene asociada una señal de referencia que comprende información biométrica correspondiente; comprendiendo dicho servidor de control:- una unidad de interfaz (121) adaptada para recibir una señal biométrica transformada proporcionada por dicho dispositivo de interfaz (13);- una unidad de gestión (123) adaptada para gestionar, por una parte, un parámetro, común con el dispositivo de interfaz, que toma valores diferentes con el paso del tiempo y, por otra parte, una función de transformación no reversible, siendo dicha función de transformación parametrizada en función de al menos dicho parámetro común;- una unidad de transformación (122) adaptada para transformar al menos una señal inicial derivada de la al menos una señal de referencia en al menos una señal de comparación mediante aplicación de la función de transformación a dicha señal inicial;- una unidad de comparación (124) adaptada para efectuar una comparación de la señal biométrica transformada recibida con la al menos una señal de comparación;y - una unidad de decisión (125) adaptada para decidir si se autoriza un acceso basándose en la comparación ES 2 385 608 T3 efectuada por la unidad de comparación.
- 15Sistema de control de acceso que comprende:- un sensor de señal biométrica según la reivindicación 13;- un dispositivo de interfaz (13) según una cualquiera de las reivindicaciones 9 a 12;y 5 - un servidor de control de acceso (12) según la reivindicación 14.
Independent claims15
117 paragraphs in 6 sections, as filed
ES 2 385 608 T3
DESCRIPTION
Protection of a biometric access control.
The present invention concerns access control and, more particularly, access control based on a biometric analysis, that is, an analysis of individual physical characteristics.
In order to guarantee the security of certain information, an access control of people can be implemented based on a biometric analysis of people. These controls can be based on an analysis of morphological characteristics, such as, for example, fingerprints, retina, iris or face, and even on an analysis of behavioral characteristics, such as, for example, characteristics relative to a signature dynamic, or even a typing dynamic on a keyboard. These controls can also be based on a combination of these different types of analysis.
The implementation of such access controls is generally intended to protect information that only a defined group of people is authorized to access. That information may be located, for example, on a physical site and, in such a case, access control consists of controlling a person's physical access to that site. It can also be accessible through a computer system and, in this case, access control consists of controlling access to that computer system.
Whatever the type of information and the type of access to that information, a biometric control system generally comprises an access control server that manages a database that stores comparison signals respectively corresponding to characteristics of individuals. authorized to access that information. It also comprises a plurality of access control sensors that are adapted to capture a biometric signal to be controlled in relation to a person who intends to access the information and to cooperate with a transmission device in order to transmit the control server. biometric signal captured. For example, when biometric access control is based on characteristics of a fingerprint, the comparison signals correspond to digital images of fingerprints of the group of persons authorized to access the information or persons authorized hereinafter. Thus, in an access control of one person, the latter places their finger on one of the access control sensors of the system. An image of that person's fingerprint is then captured, which is then transmitted in the form of a biometric signal to the control server, which is then in a position to compare the received captured biometric signal and the comparison signals stored in the base. of data, in order to determine if the person who intends to access the information is part of the group of people authorized to do so.
A biometric signal comprises individual characteristics that do not or practically do not evolve over time. Thus, it is important to protect the confidentiality of such biometric signals in such access control systems.
To this end, document US 6 836 554 discloses a control system in which the comparison signals and the captured biometric signals to be controlled are stored and manipulated in a transformed form, obtained by applying it to the captured biometric signal. of a non-reversible transformation function. More specifically, in order for the control server to learn the comparison signals with which the signals received in an access control will be compared, the sensor captures, in an initialization phase, a biometric signal from an authorized person, then This captured signal is transformed by applying a transformation function corresponding to the controlled person, before being sent, thus transformed, to the control server. The latter stores it in order to be able to carry out an access control by comparing the received signal and the stored signals.
In this way, the server directly stores the comparison signals in a transformed form corresponding to the form in which it also receives the respective captured signals.
Thus, a potential attacker can only intercept a transformed biometric signal, since the signals stored and exchanged are in a transformed form. Furthermore, from the transformed form of an intercepted biometric signal, a potential attacker is not able to recover the original biometric signal, since the transformation function that has been applied is non-reversible.
On the other hand, if a potential attacker retrieves a comparison signal from the database or even intercepts a biometric signal to be controlled during its transmission between a sensor and the control server, then it is able to reproduce that signal again. transformed biometric intercepted, in any context, in order to access protected information.
Document US 6 836 554 proposes, in the case where the security of such a system is compromised by such an attack based on a new reproduction of the transformed biometric signal, to replace the transformation function corresponding to the transformed biometric signal by a new function transformation.
However, in such a case, the server is then expected to learn the new comparison token
ES 2 385 608 T3 corresponding to an authorized person, as in the initialization phase described above. A complexity and a cumbersomeness of such transformation function change management derives from this, since a new registration of the comparison signal is then required.
Document WO02 / 095657 effectively proposes a method to avoid re-reproduction of a transmitted biometric signal when using single-use functions, but these functions are reversible.
The present invention tries to remedy the aforementioned drawbacks.
A first aspect of the present invention proposes an access control method in an access control system comprising an access control server adapted to control access, at least one biometric signal sensor; and an interface device adapted to be related, on the one hand, to the control server and, on the other hand, to the sensor.
Controlled access is authorized to at least one person who has associated a reference signal comprising corresponding biometric information.
The control server and the interface device, on the one hand, manage a common parameter that takes different values over time and, on the other hand, store respectively a first and a second non-reversible transformation function, said functions being first and second parameterized according to at least the common parameter.
The procedure comprises the following stages:
/ a / at the sensor level, capturing a biometric signal and providing the captured biometric signal to the interface device;
/ b / at the interface device level, obtaining a transformed biometric signal by applying the first transformation function to an element from a group comprising at least one characteristic derived from said captured biometric signal and said captured biometric signal; and transmitting the transformed biometric signal to the control server;
/ c / at the control server level, make a comparison of the transformed biometric signal with at least one comparison signal, the comparison signal corresponding to a signal resulting from the application of the second transformation function to an initial signal derived from the reference signal; and / d / based on the comparison, decide whether to authorize an access.
By virtue of these provisions, since the first transformation function applied to the captured biometric signal and the second transformation function applied to the initial signal derived from the reference signal are both determined based on a common parameter whose value evolves in As a function of time, an attack based on replaying an intercepted transformed biometric signal can be advantageously avoided. Indeed, with each change in the value of the common parameter, the applied transformation function can thus correspond to a different transformation from the one that has just been applied for the preceding control. This differently parameterized transformation function is determined both by the person to be monitored and by the monitoring server. Consequently, for the same person controlled at different times, differently transformed or deformed biometric signals are processed according to such control, making it impossible to attack such a procedure based on the new reproduction of an intercepted transformed biometric signal.
In such a context, a transformation change to be applied to a captured image is simple to implement and does not require a new registration of a reference biometric signal each time, as is the case in the prior art.
The first transformation function is adapted to be applied either directly to the biometric signal captured by the sensor, or to be applied to one or more biometric characteristics derived from the captured biometric signal, that is, extracted from the captured biometric signal, for example by using an algorithm known to the person skilled in the art.
The initial signal or initial signals obtained on the server side correspond either to directly captured signals, or to characteristics extracted from captured biometric signals, depending on the element of the group in question to which the first transformation function is applied.
In an embodiment of the present invention, it is possible to determine an evolution of the common parameter that makes it possible to modify, for each access control, the transformation to be applied to the biometric signal captured by the sensor from a person. A less rapid evolution of the values of the common parameter can be expected in certain cases. This evolution of the common parameter can be advantageously determined as a function of the level of security to be achieved in the control system in question.
ES 2 385 608 T3
In an embodiment of the present invention, the values of the common parameter for the control server and for the interface device are a function of the values of a counter, managed at the interface device and the server, of the number of signals transformed biometric that are transmitted and received respectively by the interface device and the control server.
In this context, the counters respectively managed by the server and by the sensor have substantially synchronous values and, therefore, can be advantageously used to determine the value of the common parameter. It can be envisaged that, regularly, after N biometric signals captured and transmitted from the sensor to the server, the common parameter increases, N being an integer that can be advantageously defined as a function of the security level sought for such control of access.
In a variant, since the access control server and the sensor are synchronized in a common time reference, the values of the common parameter are a function of that common time reference.
Thus, it can be envisaged to increase the common parameter after each period of time T, this period T being able to be defined as a function of the level of security sought in the control system in question.
Common parameter values may correspond to values recorded at the interface device level. In such a case, each new value of the common parameter, used to parameterize the transformation function, is transmitted from the interface device to the control server.
In an embodiment of the present invention, the access control system controls access to a plurality of types of applications, such as physical access at a physical site, access to a computer database on a network information technology and access to a banking service also on a computer network. In such a context, a plurality of pairs are respectively associated with said plurality of types of applications, formed on the one hand by a first non-reversible transformation function at the interface device level and, on the other hand, by a second non-reversible transformation function. reversible at the control server level. Thus, advantageously, a high level of security can be obtained without thereby modifying the parameterization of the transformation function with each control, since each application of a different type can then be controlled by implementing a different transformation function. Consequently, a potential attacker, if he intercepts a transformed signal to be controlled, is not able to 'reproduce again' that intercepted transformed signal to access a controlled application of another type of the system.
In this context, it can further be envisaged that the plurality of pairs of non-reversible transformation functions are respectively associated with different common parameters.
The initial signal may comprise the reference signal. In such a case, the application of the first and the application of the second non-reversible parameterized transformation function are equivalent.
In an embodiment of the present invention, the initial signal derived from the reference signal, corresponding to the authorized person or persons, is obtained by applying a non-reversible initial transformation function to the reference signal, so that the initial signal is a previously transformed signal. In this context, the first transformation function is equivalent to a combination of the second transformation function and the initial transformation function.
By proceeding in this way, the biometric reference signals relating to the persons for whom access is authorized are stored in a previously transformed form. Such an embodiment makes it possible to protect the confidentiality of the biometric characteristics, which, for their part, cannot be modified for a given person.
In an embodiment of the present invention, an identifier is associated with the interface device and / or with the at least one person to whom access is authorized and the control server manages an association of the at least one access signal. comparison with said identifier of that person. In such a case, the process may further comprise, before step / c /, the following steps:
- obtaining, at the interface device, an identifier corresponding to the captured biometric signal;
- transmitting said identifier to the control server; Y
- at the control server level, recovering the comparison signal associated with said received identifier.
Thus, by virtue of the management by the control server of an association of a comparison signal corresponding to a person for whom access is authorized and an identifier of that person and / or the interface device, the server is in provision to more efficiently retrieve the comparison signal from its database based on the identifier it receives from the person being monitored in the control system.
In such an embodiment of the present invention, the control system can then be used as
4ES 2 385 608 T3 authentication system of a person. Indeed, in such an implementation, the server is in a position to authenticate the person being controlled based on the identifier and the transformed biometric signal received.
The control system according to an embodiment of the present invention can also be used as an identification system. In this case, the initial signal obtained by the server is associated with an identifier of the person for whom access is authorized. Thus, the server is in a position to identify a person based on a transformed biometric signal. Indeed, when the server decides that the received transformed biometric signal corresponds to an initial signal, then it is in a position to retrieve an identifier of the corresponding person being monitored and, thereby, to identify that person.
Advantageously, in the case of an identification in which the transformations applied to the captured images change with each new access control of the same person, the information that passes between the user side and the server does not allow a potential attacker to detect when the same person is identified by a system according to the present invention.
A second aspect of the present invention proposes an interface device in an access control system that comprises, on the one hand, also an access control server adapted to control an access and, on the other hand, at least one signal sensor biometric. Access is authorized to at least one person who has associated a reference signal comprising corresponding biometric information. The interface device may comprise:
- a management unit adapted to manage, on the one hand, a parameter, common with the control server, which takes different values over time and, on the other hand, a non-reversible transformation function, said function being parameterized in function of at least said common parameter;
- a first interface unit adapted to receive a biometric signal captured from the sensor;
- a transformation unit adapted to transform a captured biometric signal into a transformed biometric signal by applying the transformation function to an element from a group comprising at least one characteristic derived from said captured biometric signal and said captured biometric signal; Y
- a second interface unit adapted to cooperate with a transmission device (15) adapted to transmit a biometric signal transformed by the transformation unit to the control server.
The common parameter values may evolve as specified according to the first aspect of the present invention.
In an embodiment of the present invention, the second interface unit of the interface device is adapted to cooperate with a transmission device in order to transmit the transformed signal, this transmission device being either included in the transmission device. interface, or even external to this interface device.
A third aspect of the present invention proposes a biometric signal sensor comprising an interface device according to the second aspect of the present invention.
This sensor can comprise the device for transmitting the transformed biometric signal destined for the control server.
A fourth aspect of the present invention proposes an access control server in an access control system that further comprises at least one biometric signal sensor and an interface device adapted to be related, on the one hand, to the control server. and, on the other hand, with the sensor.
The control server can comprise:
- an interface unit adapted to receive a transformed biometric signal provided by said interface device;
- a management unit adapted to manage, on the one hand, a parameter, common with the interface device, which takes on different values over time and, on the other hand, a non-reversible transformation function, said transformation function parameterized as a function of at least said parameter common to said initial signal;
- a transformation unit adapted to transform at least one initial signal derived from the at least one reference signal into at least one comparison signal by applying the transformation function;
- a comparison unit adapted to carry out a comparison of the received transformed biometric signal with the at least one comparison signal; Y
ES 2 385 608 T3
- a decision unit adapted to decide whether an access is authorized based on the comparison made by the comparison unit.
A fifth aspect of the present invention proposes an access control system comprising:
- a biometric signal sensor according to the third aspect of the present invention;
- an interface device according to the second aspect of the present invention; Y
- an access control server according to the fourth aspect of the present invention.
Other aspects, objectives and advantages of the invention will become apparent upon reading the description of one of its embodiments.
The invention will also be better understood with the aid of the drawings, in which:
Figure 1 illustrates an architecture of different entities comprised in an access control system according to an embodiment of the present invention; and Figure 2 illustrates a sensor network in an access control system according to an embodiment of the present invention.
In the following sections, the term 'biometric signal' is understood to mean a signal from a biometric sensor applied to a person.
Such a biometric signal may correspond to an image captured of a fingerprint of the person in question, or also to a captured image of an iris, or an image of the face or part of the face of that person.
By the term 'reference signal' is meant a biometric signal of a person for whom controlled access is authorized according to an embodiment of the present invention. A reference signal is provided by a biometric sensor, without a transformation function being applied in the sense of the present invention.
The term 'initial signal derived from a reference signal' is understood to be either directly the reference signal, or even the reference signal previously transformed by applying an initial transformation.
An initial signal is a signal available to the server. This can, for example, be stored in a database managed by the server, or even be provided to the server by any means of transmission.
In the following sections, the common parameter is substantially synchronized at the level of the interface device and the control server, so that the same parameter is used at the moment when a captured biometric signal is transformed at the level of the interface device and into the moment when the signal thus transformed is received and processed at the control server level.
A non-reversible transformation function in the sense of the present invention can be any non-reversible function that makes it possible to transform or even deform an image into a deformed image. In particular, one of the transformation functions described in US 6 836 554 can be used.
In the case where the sensor captures a fingerprint image, the transformation function can be a function whose application consists of a deformation of the image in the spatial domain. The image to be transformed can thus be decomposed into a plurality of parts and subsequently said image parts thus obtained can be distributed in a specified different spatial distribution.
In the present case, the common parameter can serve, for example, to specify a new distribution of the parts of the original image. This may also consist of defining new shapes of the different parts of the image to be distributed according to the specified distribution. It is also possible to envisage taking into account the two common parameters mentioned above in combination.
In the case where the sensor captures an image of the face or a part of the face, the transformation function can also be a deformation function of the image captured in the spatial domain. The image can be decomposed, also in the present case, into a plurality of parts. Subsequently, some contours of those parts thus obtained can be modified, thus implying a different deformation of the different parts for which the contours have been modified.
In the present case, the common parameter may correspond, for example, to the number of parts that make up the image to be transformed. This may also correspond to the modification imposed on at least some of the contours of some of the parts of the image to be transformed.
(5
ES 2 385 608 T3
In the case where the sensor captures an image of the iris, the transformation function can also be a deformation function of the image captured in the spatial domain. For example, a view of the iris can be broken down into a plurality of angular sectors. Next, the application of the transformation function may consist of modifying at least some of the angles of those angular sectors thus obtained, reducing some angles and increasing some others.
In the present case, the common parameter can be used to determine a change in the reduction and / or increase of some of these angles.
It can be envisaged to parameterize such a transformation function by means of a plurality of common parameters, as defined in the present description.
Figure 1 illustrates an architecture of different entities comprised in an access control system according to an embodiment of the present invention.
In the following sections, solely by way of example, the present invention is described in its application to a physical access control of people in a given physical site, by means of a biometric control based on biometric fingerprint characteristics. In such a context, a biometric signal sensor according to an embodiment of the present invention is located, for example, in an access door to a building whose entrance is controlled according to an embodiment of the present invention. Thus, if access is authorized, the opening of that door can be foreseen.
Such an access control system comprises an access control server 12 that may have comparison signals intended to be compared with a received transformed signal to be controlled. It further comprises a biometric signal sensor 11 and an interface device 13.
In such an access control system, the biometric signal sensor 11 comprises a first interface unit 111 adapted to capture an image of a fingerprint of a person who intends to access the protected building according to an embodiment of the present invention. This further comprises a second interface unit 112 adapted to provide the interface device 13 with a biometric signal thus captured.
The interface device 13 comprises a management unit 133 adapted to manage, on the one hand, a common parameter with the control server, which takes different values with the passage of time and, on the other hand, a first non-reversible transformation function , this function being parameterized according to at least the common parameter. It also comprises a first interface unit 131 adapted to receive the biometric signal captured from the sensor. It also comprises a transformation unit 135 adapted to transform the captured biometric signal received by the first interface unit into a transformed biometric signal. It further comprises a second interface unit 132 adapted to allow the transmission of the biometric signal transformed by the transformation unit to the control server 12.
It can be envisaged that the second interface unit cooperates with a transmission device 15 adapted to effectively carry out the transmission of the transformed biometric signal destined for the control server. This transmission device 15 can be located in the sensor or in the interface device, or even separate from the sensor 11 and the interface device 13.
A control server 12 according to an embodiment of the present invention may comprise a management unit 123 adapted to manage, on the one hand, a parameter, common with the interface device 13, which takes different values with the passage of time and , on the other hand, a second non-reversible transformation function, this function being parameterized as a function of at least the common parameter.
This also comprises a transformation unit 122 adapted to transform signals derived from the reference signals into respective comparison signals by applying the second transformation function.
This server 12 further comprises an interface unit 121 adapted to receive a transformed biometric signal provided by the interface device 13. It also comprises a comparison unit 124 adapted to perform a comparison of the received transformed biometric signal with the comparison signals, thus as a decision unit 125 adapted to decide whether to authorize an access based on the comparison made by the comparison unit 124.
In an embodiment of the present invention, the sensor 11 and the interface device 13 are different entities so that, advantageously, the interface device is removable and mobile independently of the biometric signal sensor 11. Thus, it can be provided that each person who intends to enter the building has such an interface device 13.
In a variant, the interface device 13 can be included in the sensor 11, so that the two entities become one. In this case, provision can be made for the sensor and thus the interface device to be fixed at the entrance door of the building to which access is protected.
Ί
ES 2 385 608 T3
In the latter case, the sensor can be adapted to receive the common parameter of the person being monitored through any registration interface. Next, this parameter is used at the interface device level in order to parameterize the first transformation function.
This parameter is then sent to the server, so that it can also parameterize the second transformation function. Thus, the common parameter, in the first place, is registered by the person who intends to access the building and is then sent to the control server. By proceeding in this way, the respective transformation functions can be correctly parameterized in order, on the one hand, to provide a captured biometric signal transformed by the first transformation function parameterized by the common parameter at the sensor level and, on the other hand, of obtaining comparison signals corresponding to the transformed reference signals by applying a transformation function equivalent to the first transformation function.
It can be envisaged that the control server 12 has the reference signals directly. In such a case, the application of the first transformation function can be directly equivalent to the application of the second transformation function.
In a variant, the control server can have initial signals derived from the reference signals, these initial signals corresponding to the reference signals previously transformed by applying an initial transformation function. In such a case, it can be envisaged that the application of the first transformation function is equivalent to the combined application of the second function and the initial transformation function.
These initial signals can be made available to the server 12, for example by means of a database in which they are stored and to which the server has access, or even by any other means.
In an embodiment of the present invention, a person therefore has an interface device 13, which this connects to a biometric signal sensor 11 located near the door that the person intends to pass through. Then, for example, he places his index finger on sensor 11. Sensor 11 captures an image of that person's index fingerprint. Subsequently, that sensor 11 provides that biometric image to the connected interface device 13, in the form of a biometric signal. This biometric signal is received at the level of the first interface unit 131 of the interface device 13.
It is then provided to the transformation unit 135. The latter transforms that captured biometric signal by applying the first transformation function, parameterized with the value of the common parameter, provided by the management unit 133. The value of this common parameter it evolves over time in a substantially synchronous manner at the level of the management unit 133 of the interface device 13 and at the level of the management unit 123 of the control server 12.
In this way, a transformed biometric signal is obtained, which is transmitted at the level of the second interface unit 132. This interface unit is adapted to cooperate with a transmission device 15 that can either be located in conjunction with this second interface unit, or either be a separate entity from the interface device.
Then, that transformed biometric signal 14 is transmitted to the control server 12. In order to process that transformed biometric signal, the control server 12 obtains transformed reference signals according to a transformation function similar to that applied at the device level. interface 13.
For this purpose, it can be envisaged that the server stores, or at least has access to, the reference signals of the authorized persons and that it has the same transformation function as that which is managed by the management unit of the interface device 13 In this case, it applies to the reference signals that transformation function parameterized with the common parameter. The consequence of this are comparison signals corresponding to the reference signals transformed in the same way as, on the user side, the captured biometric signal to be controlled has been transformed.
Thus, the server compares the received transformed signal and the comparison signals described above, whereby it deduces whether or not the person being controlled is one of the authorized persons. This comparison aimed at comparing two images potentially captured differently, and then transformed, is not a strict comparison.
In another variant, the control server 12 only has reference signals in a previously transformed form, corresponding to the application of an initial transformation function on the non-reversible reference signals. Thus, protection is increased since, although an attacker can recover one of the signals available to the control server, he does not have access to the original reference signal.
In this variant, the management unit 123 of the control server 12 manages a second transformation function that differs from the first function of the interface device 13. Indeed, more specifically, the
ES 2 385 608 T3 first transformation function is equivalent to a combination of the second transformation function and the initial transformation function. However, the first and second transformation functions are parameterized, also in the present case, in the same way by the common parameter.
In an embodiment of the present invention, the access control system is further based on an identifier of the person to be controlled. Such a variant makes it possible to improve the signal processing performance at the level of the control server 12.
Indeed, in such a case, the control server manages an association of the comparison signals with the respective identifiers of the authorized persons in the control system. Next, the person being controlled provides his identifier to the server through, for example, the interface device, or even through any other interface that is offered to the person at the controlled entrance door. Thus, under such conditions, the control server is in a position to retrieve the comparison signal associated with the received identifier, without having to compare the received transformed captured biometric signal with a plurality of comparison signals.
Figure 2 illustrates a sensor network in an access control system according to an embodiment of the present invention. Thus, in this context, each of the system sensors can be located at different entrance doors of a physical site or even, among these sensors, some can be located together with computer stations to control access to computer data, for instance.
Two of them are carrying out access control and interface devices 13 are connected to them.
It can be envisaged that different non-reversible transform functions are used depending on the controlled applications.
In a control system according to an embodiment of the present invention, depending on the common parameter, it is in a position to modify the transformation of the biometric signals manipulated in the course of successive access controls for the same person, to the object to improve the reliability of controls. Indeed, depending on the level of reliability that is sought, a more or less rapid evolution of the common parameter can be defined.
Advantageously, it is even possible to easily define a variation of the common parameter with each of the controls executed for the same person, in order to guarantee complete protection against attacks based on the new reproduction of an intercepted transformed biometric signal.
Contents6
1 sheet
Sheet 1
12 members in 7 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 0601933 | France | A | |
| 0601933 | France | A | |
| 0601933 | France | – | |
| 2007000277 | France | W | |
| 2007000277 | France | W | |
| 0601933 | – | – | – |
| FR20060001933 | – | – | – |
| PCTFR2007000277 | – | – | – |
| WO2007FR00277 | – | – | – |
Members12
| Document | Office | Kind | |
|---|---|---|---|
| FR2898203A1 | France | A1 | |
| AU2007222279A1 | Australia | A1 | |
| CA2644496A1 | Canada | A1 | |
| WO2007101922A1 | World Intellectual Property Organization (WIPO) | A1 | |
| FR2898203B1 | France | B1 | |
| EP1997064A1 | European Patent Office (EPO) | A1 | |
| US2009033461A1 | United States of America | A1 | |
| AU2007222279B2 | Australia | B2 | |
| EP1997064B1 | European Patent Office (EPO) | B1 | |
| ES2385608T3This record | Spain | T3 | |
| US8680968B2 | United States of America | B2 | |
| CA2644496C | Canada | C |
Numbers
- Publication
- 2385608
- Publication, DOCDB
- 2385608
- Publication, EPODOC
- ES2385608T
- Application
- 7730988
- Application, DOCDB
- 07730988
- Application, EPODOC
- ES20070730988T
Titles2
- Spanish
- Protección de un control de acceso biométrico
- English
- Protection of a biometric access control
Classification
- CPC, 4
- G06F21/606
- G06F21/32
- G07C9/37
- G06V40/10
- IPC, 4
- G07C9 00
- G06F21 32
- G06F21 60
- G06F21 00