Multi-biometric authentication system
Abstract
Systeme d'authentification biometrique. Le systeme de l'invention comprend un organe central 10 et des modules d'authentification M1, M2, M3 utilisant des caracteres biometriques differents. Ces modules sont mis en oeuvre par l'organe central selon l'authentification a effectuer. Application au contrôle d'acces.

Term
Term ended
Projected expiry passed 22 July 2008, 18.2 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
5 claims: 1 independent, 4 dependent
- 1REVENDICATIONS 1. Système d'authentification mu 11i-biomêtrique caractérisé par Le fait qu'iL comprend :- un organe central (10) de contrôle et de gestion, 5 - plusieurs modules (H1, M2, M3) d'authentification bioraétrique aptes à effectuer chacun un test d'authentification à l'aide d’un caractère biométrique déterminé, ce caractère étant différent d'un module à l'autre, 10 - un moyen de liaison (40) entre l'organe central (10) et les différents modules (N1, M 2 , M 3 ), cet organe central étant apte à commander la mise en oeuvre d'au moins un des modules, de recueillir le résultat du test effectué par chaque module mis en 15 oeuvre et de combiner les résultats obtenus.
- 2Système selon la revendication 1, caractérisé par Le fait que les caractères biométriques utilisés sont pris dans le groupe qui comprend notamment la voix, les empreintes digitales, la signature 20 manuscrite, le fond de l'oeil, la forme de la main.
- 3Système selon La revendication 1, caractérisé par le fait que l'organe central (10) de contrôle et de gestion est apte à choisir de manière aléatoire la mise en oeuvre d'un module d'authentification (M1, 25 «2, H3).
- 4Système selon la revendication 1, caractérisé par le fait que l'organe central (10) de contrôle et de gestion est apte à hiérarchiser la mise en oeuvre des modules d'authentification, un premier module CM1 ) 30 étant mis en oeuvre pour un premier test, un deuxième module (M2) n'étant mis en oeuvre que si le premier test a été passé avec succès et ainsi de suite.
- 5Système selon la revendication 1, caractérisé par le fait que l'organe central de contrôle et de gestion est constitué par une carte électronique comprenant un microprocesseur, une mémoire de programme, une mémoire de travail et des liaisons série.
Independent claims5
63 paragraphs in 2 sections, as filed
DESCRIPTION
MULTI-BIOMETRIC AUTHENTICATION SYSTEM
The present invention relates to a multi-biometric authentication system.
It finds an application in the implementation of access control procedures. By access control, we mean both physical access control (access to a laboratory, establishment, room, etc.) and access control to a computer system or to computer data.
During a biometric access control, the user is required to have a biometric character. which is authenticated by an appropriate system. This biometric character can be the voice, the fingerprints, the handwritten signature, the fundus of the eye, the shape of the hand, etc. Information captured by an appropriate sensor is compared to a reference and the result of the comparison allows or denies the requested access. The reference is previously stored either in a memory card held by the user, or in a database linked to the system.
There are many bio-African authentication systems using one or the other of the aforementioned characters. The operation of these systems is based on the testing of a single biometric character; this test is very often associated with the verification of a confidential code.
If, for accidental reasons (aphonia, momentary degradation of the fingerprint, eye infection, wrist injury, etc.), the user is not in normal conditions to undergo authentication, he is rejected, even if he is in good faith. In addition, for certain systems, the user must comply with the constraints brought about by the verification of a confidential code.
The uniqueness of the authentication parameter implicates, for user comfort and access security, very low error rates for the recognition system. This results in long execution times and a high cost due to the great complexity of the software and the sensors.
The aim of the invention is precisely to remedy these drawbacks. To this end, the invention proposes to combine several biometric authentication means implementing different biometric characters, these means being under the control of a central control and management body.
Due to the many possible means of authentication, the system of the invention is immune to external nuisances (ambient noise in the case of voice authentication, hostile atmosphere, salient products, humidity, for the other means of authentication) which run the risk of hampering its operation since the central body can select one of the authentication means which escapes said nuisances without it being necessary to modify the structure of the system.
The system of the invention also makes it possible to adapt the selected authentication means to the user, according to the stability of their biometric characters.
The combination of authentication means also makes it possible to prioritize the accesses and to manage the degree of security according to the access levels. Authentication based on a set of biometric characters allows access at the HIGHEST security level, while authentication based on a single character allows access at the lowest security level.
According to another variant of implementation, it is possible to increase the degree of security by leaving to the central body the initiative for the choice of the biometric test to be operated, this choice being determined by a random mechanism, the user naturally having to have references for each type of authentication, in the uncertainty of the character that will be chosen.
It is thus understood that the system of the invention is not satisfied with juxtaposing different authentication systems but that it combines, through the central body, different authentication means. From this combination arise new functions (freedom from external nuisances, prioritization of controls, random choice, etc.) and new and advantageous results (lower cost, modularity, flexibility, reliability).
More precisely, the present invention relates to a biometric authentication system characterized in that it comprises:
- a central control and management body,
- several biometric authentication modules each capable of performing a d test<sup>1</sup> authentication using a determined biometric character, this character being different from one module to another,
a means of connection between the central body and the different modules, this central body being able to control the implementation of at least one of the modules and to collect the result of the test 'carried out by each module implemented.
In any event, the characteristics of the invention will appear better in the light of the description which follows. This description relates to exemplary embodiments given by way of explanation and in no way limiting, and it refers to the appended drawings, in which:
- Figure 1 shows the architecture of the system of the invention,
- Figure 2 illustrates an example of adaptation of the system to hierarchical access levels,
- Figure 3 shows a fingerprint authentication module.
FIG. 1 refers to an embodiment using electronic cards. It goes without saying that the invention is not limited to this technique even if it seems, at the present time, to be the most advantageous.
The architecture of figure 1 shows:
a motherboard 10 constituting a central control and management body; this card comprises a microprocessor, for example of the 68000 type from MOTOROLA, a program memory, a working memory and serial links;
various modules M1, M2, M3, etc ... for biometric authentication, each comprising a sensor 20 and a specific processing card 30;
<td></td><td> -</td><td>a 40 bus, for example</td><td>of</td><td>type VME</td><td colspan="2">like r-</td>
<td>cialis</td><td>through</td><td>the MOTOROLA Company;</td><td></td><td></td><td></td><td></td>
<td></td><td> -</td><td>various organs like</td><td>a</td><td colspan="2">computer</td><td>host</td>
<td>50 and one</td><td colspan="2">Memory card reader</td><td> 60.</td><td></td><td></td><td></td>
<td></td><td>The</td><td>operation of i</td><td>this</td><td>system</td><td>is</td><td>the</td>
following.
The system is built around the motherboard comprising the microprocessor. This card coordinates the various cards connected to it via the bus and manages exchanges with the outside world.
The functions specific to the authentication mode used are grouped together on the card provided for this purpose, in order to ensure the modularity of the whole.
The most complex calculations are performed on this board, using specialized circuits (correlator, signal processor, etc.). More basic calculations can be processed by the motherboard microprocessor.
There is a priori no functional hierarchy between the different cards which constitute the system of the invention. The position of the specific cards on the bus is irrelevant. The choice of this architecture reinforces the modularity of the system and will allow all future developments to be adapted to it (new means of authentication, use of more efficient processors or algorithms, etc.).
System-user dialogue is effected, for example, by means of a liquid crystal screen and function keys connected to the motherboard.
Different references can be stored in a memory card. In this case, the Card Reader 60 is integrated into the system.
Serial links located on the motherboard allow communication with the host computer.
It is possible to envisage several operating modes of the system depending on the security level chosen if:
a) In the case of access to a single security level, the system can randomly choose a means of authentication for which the user has a reference. If Authentication fails, the system can either authorize a new attempt with the same means, or choose another.
b) In the case of access to several security levels (for example the case of a computer system in which one distinguishes a part accessible to any user and another reserved for those responsible for the system) a combination of different means of authentication allows you to prioritize access.
This last variant is illustrated in Figure 2:
- for access to the first level N1, a single parameter is tested using a module M1, for access to the second level N2, an additional test is performed by the module M2,
- And so on.
The user, to have access to the highest level of security (N3) must successfully pass the tests of the lower levels (N1, N2).
It is also p.possible to combine the lowest level of security with the least efficient means of authentication.
Whatever the chosen operating mode, for each type of authentication, the information comes from a sensor adapted to the chosen biometric character. This information is transferred to and processed by the card, which operates in conjunction with the motherboard.
We can describe three types of authentication, which are, moreover, of a known type:
at. Fingerprint authentication:
Figure 3 shows the structure of the authentication module used. It comprises three elements: an optical sensor 20, an acquisition and digitization card 30/1 and a correlation card 30/2.
The sensor 20 was the subject of a French patent application N ° EN / 88 02803 of March 4, 1988.
The image of the imprint is obtained as follows: the user places his index finger 21 on a prism 23 of right triangular section, illuminated in parallel by a system 26 on one of its square faces. The latent image is transported by the beam emerging from the other square face of the prism, deflected by total reflection on the prism 24. This image is formed by a special objective 27 on the plane of a matrix 29 of the coupling device type. of charges (CCD).
After capture by a circuit 31, the image is digitized in binary form by the circuit 32 and then stored in a fast memory 34, called image memory, on the correlation card 30/2.
The user's reference is transferred from the smart card or from the database to a memory called reference memory 35. This memory represents the most significant part of the footprint.
A circuit 36 performs the correlation between the data of the image memory and those of the reference memory.
The results of the correlation are sent to the 68000 microprocessor of the motherboard by the bus 40. These results validate or not the authentication.
An optional video card enables fingerprint entry to be controlled on a video monitor.
b. Voice authentication:
Voice authentication is currently based on the recognition of a password. It only requires one specific card, of a known type.
The voice signal is picked up by a microphone and then shaped on a card in order to be sampled and digitized. The information resulting from the conversation is transmitted to a signal processing processor (eg MOTOROLA DSP 56000), which has its own work and program memories. This processor extracts the parameters of the speech signal which are used for comparison with the reference. The result of the comparison is transmitted to the motherboard.
The use of the signal processing processor can be extended to speech synthesis, thereby improving the usability of the system,
vs. Authentication by handwritten signature:
Authentication by handwritten signature does not require a specific card. The user deposits his signature on a digitizing tablet, using a special pen connected to the tablet. A serial link transfers data to the motherboard (position, speed, acceleration).
The microprocessor located on the meter card analyzes the dynamic parameters calculated from information obtained from the tablet. Depending on the results obtained, it validates or not the authentication.
Contents2
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office | Category | Cited during |
|---|---|---|---|---|
| EP1050993A2 | Cited by | European Patent Office (EPO) | – | Search report |
| EP0762340A2 | Cited by | European Patent Office (EPO) | – | Search report |
| EP1081632A1 | Cited by | European Patent Office (EPO) | – | Search report |
| EP1045346A3 | Cited by | European Patent Office (EPO) | – | Search report |
| EP1130534A1 | Cited by | European Patent Office (EPO) | – | Search report |
| WO9801820A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search |
| WO0116871A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search |
| EP0944875A4 | Cited by | European Patent Office (EPO) | – | Search report |
| EP1050993A3 | Cited by | European Patent Office (EPO) | – | Search report |
| EP0762340A3 | Cited by | European Patent Office (EPO) | – | Search report |
| FR2805638A1 | Cited by | France | – | Search report |
| EP0944875A1 | Cited by | European Patent Office (EPO) | – | Search report |
| US6907134B1 | Cited by | United States of America | – | Applicant |
| EP1128334A1 | Cited by | European Patent Office (EPO) | – | Search report |
| EP0895750A3 | Cited by | European Patent Office (EPO) | – | Search report |
| EP1045346A2 | Cited by | European Patent Office (EPO) | – | Search report |
| EP1251468A2 | Cited by | European Patent Office (EPO) | – | Search report |
| US6205233B1 | Cited by | United States of America | – | Applicant |
| WO9837519A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search |
| EP1251468A3 | Cited by | European Patent Office (EPO) | – | Search report |
| WO0116871A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search |
| US6910628B1 | Cited by | United States of America | – | Search report |
| WO9801820A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search |
| US6386451B1 | Cited by | United States of America | – | Search report |
| EP0895750A2 | Cited by | European Patent Office (EPO) | – | Search report |
| WO9837519A1 | Cited by | World Intellectual Property Organization (WIPO) | – | International search |
| US6341170B2 | Cited by | United States of America | – | Applicant |
| US6687823B1 | Cited by | United States of America | – | Applicant |
| EP1081632A1 | Cited by | European Patent Office (EPO) | – | Search report |
| JP2002503362A | Cited by | Japan | – | Search report |
| US5815252A | Cited by | United States of America | – | Search report |
| US7623970B2 | Cited by | United States of America | – | Applicant |
| EP0082304A1 | Cites | European Patent Office (EPO) | X | Search report |
| EP0101772A1 | Cites | European Patent Office (EPO) | X | Search report |
| GB2053617A | Cites | United Kingdom | A | Search report |
| GB2148569A | Cites | United Kingdom | X | Search report |
| FR2432858A1 | Cites | France | Y | Search report |
| PROCEEDINGS OF THE 1976 CARNAHAN CONFERENCE ON CRIME COUNTERMEASURES, mai 1976, Kentucky, pages 23-30; W.HABERMAN: "Automatic identification of personnel through speaker and signature verification - system description and testing" | Non-patent | – | – | Search report |
3 priority claims, no other members on record
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 8809959 | France | A | |
| 8809959 | – | – | – |
| FR19880009959 | – | – | – |
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Notification of lapseLapsedST | ST | |
| Transmission of propertyBO 22/93 LIRE 8809959 AU LIEU DE 8809359TP | TP | |
| Transmission of propertyTP | TP |
Numbers
- Publication
- 2634570
- Publication, DOCDB
- 2634570
- Publication, EPODOC
- FR2634570
- Application
- 8809959
- Application, DOCDB
- 8809959
- Application, EPODOC
- FR19880009959
Titles2
- French
- SYSTEME D'AUTHENTIFICATION MULTIBIOMETRIQUE
- English
- Multi-biometric authentication system
Classification
- CPC, 3
- G07C9/32
- G07C9/257
- G06F18/256
- IPC, 3
- G06K9 62
- G06K9 68
- G07C9 00