Personal authenticating method and recording medium recording personal authentication program
Abstract
(57) A summary and subject There is no security hole, an attestation system can be checked by the service provision side, and renewal of an authentication algorithm offers attestation environment with easy sufficient usage further. Solution means In the system by which center side equipment was connected with the user side terminal through the network, It faces performing personal authentication using human body information, and the user side terminal extracts the feature from human body information, and transmits the data in which this feature is shown to center side equipment, and center side equipment attests using the above-mentioned data and the registration data registered beforehand. Here, center side equipment enciphers the program for the feature extraction processing in the user side terminal, and transmits to the user side terminal. Moreover, the user side terminal hangs scramble on the data in which the feature is shown, and transmits to center side equipment. A fingerprint, a hand, etc. Can be used as human body information.
Term
Term ended
Projected expiry passed 13 August 2019, 7.1 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
19 claims: 3 independent, 16 dependent
- 1[Claims] 1. A personal authentication method for performing personal authentication using human body information in a system in which a user-side terminal and a center-side device are connected via a network. The processing means for performing the personal authentication is divided into at least one set of pre-process and post-process, and the boundary between the pre-process and the post-process is configured to be adaptively variable. In the personal authentication process, the user-side terminal is Human body information is input by the user's human body information input means, the pre-process processing is performed by the pre-process processing means using the information from the human body information input means as input, and the characteristics of the user generated by the pre-process processing means are described. The indicated feature data is transmitted to the center side device, The center side device is The feature data is input to perform post-process processing by the post-process processing means, and the user collation data generated by the post-process processing means is compared with the user registration data registered in advance by using the determination processing means. A personal authentication method characterized by determining whether or not the person is the person himself / herself. 【特許請求の範囲】 【請求項1】 利用者側端末とセンタ側装置がネットワークを介して接続されたシステムにおいて、人体情報を用いて個人認証を行う個人認証方法であって、 該個人認証を行う処理手段は、少なくとも1組の前工程と後工程に分割されており、該前工程と該後工程の境界は適応的に変動可能に構成されており、 該個人認証処理において、該利用者側端末は、 利用者の人体情報入力手段により人体情報を入力し、該人体情報入力手段からの情報を入力として前工程処理手段により前工程処理を行い、該前工程処理手段によって生成される利用者の特徴を示す特徴データをセンタ側装置に伝送し、 該センタ側装置は、 該特徴データを入力として後工程処理手段により後工程処理を行い、該後工程処理手段によって生成される利用者照合データを、判定処理手段を用いて、予め登録されている利用者登録データと比較することによって本人か否かを判定することを特徴とする個人認証方法。
- 11In a personal authentication processing system in which a user-side terminal and a center-side device are connected via a network and perform personal authentication using human body information, a computer is used as the center-side device that performs the personal authentication processing. A recording medium on which a personal authentication program to be functioned is recorded, and the means for performing the personal authentication process is divided into a pre-process and a post-process, and the boundary between the pre-process and the post-process can be adaptively changed. The user-side terminal has a pre-process processing means for performing the pre-process processing. The personal authentication program The post-process processing means that the user-side terminal performs the post-process processing by inputting the feature data of the human body information generated by the pre-process processing and the user collation data generated by the post-process processing means are registered in advance. A recording medium on which a personal authentication program is recorded, which comprises a determination processing means for determining whether or not the person is the person by comparing with the user registration data. 【請求項11】 利用者側端末とセンタ側装置がネットワークを介して接続された、人体情報を用いて個人認証を行う個人認証処理システムにおいて、コンピュータを該個人認証処理を行う該センタ側装置として機能させる個人認証プログラムを記録した記録媒体であって、該個人認証処理を行う手段は、前工程と後工程に分割されており、該前工程と該後工程の境界は適応的に変動可能に構成されており、該利用者側端末は該前工程処理を行う前工程処理手段を有し、 該個人認証プログラムは、 該利用者側端末が該前工程処理により生成した人体情報の特徴データを入力として後工程処理を行う後工程処理手段と、該後工程処理手段によって生成される利用者照合データを、予め登録されている利用者登録データと比較することによって本人か否かを判定する判定処理手段とを有することを特徴とする個人認証プログラムを記録した記録媒体。
- 16In a personal authentication processing system in which a user-side terminal and a center-side device are connected via a network and perform personal authentication using human body information, the user-side terminal that performs the personal authentication processing on a computer. A recording medium on which a personal authentication program is recorded, and a means for performing the personal authentication process is divided into a pre-process and a post-process, and the boundary between the pre-process and the post-process is configured to be adaptively variable. Has been The personal authentication program has a pre-process processing means for performing the pre-process processing. The pre-process processing means performs pre-process processing by inputting human body information from the human body information input means for inputting user's human body information, generates feature data indicating the characteristics of the user, and uses the feature data on the center side. A recording medium on which a personal authentication program is recorded, which is transmitted to an apparatus and the center side apparatus uses the feature data and user registration data to determine whether or not the person is the person. 【請求項16】 利用者側端末とセンタ側装置がネットワークを介して接続された、人体情報を用いて個人認証を行う個人認証処理システムにおいて、コンピュータを該個人認証処理を行う該利用者側端末として機能させる個人認証プログラムを記録した記録媒体であって、該個人認証処理を行う手段は、前工程と後工程に分割され、該前工程と該後工程の境界は適応的に変動可能に構成されており、 該個人認証プログラムは、該前工程処理を行う前工程処理手段を有し、 該前工程処理手段は利用者の人体情報を入力する人体情報入力手段からの人体情報を入力として前工程処理を行い、利用者の特徴を示す特徴データを生成し、該特徴データを該センタ側装置に伝送し、該センタ側装置では該特徴データ及び利用者登録データを用いて本人か否かを判定することを特徴とする個人認証プログラムを記録した記録媒体。
Independent claims3
255 paragraphs in 1 section, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Technical field to which the invention belongs]
The present invention relates to a personal authentication method and its device, and more particularly to a method and its device for performing authentication using physical feature information obtained from a sensor.
【0002】
[Conventional technology]
In explaining the conventional personal authentication method, first, security assurance in a service via a communication network will be described. Public key infrastructure (PKI method) has been well known as a means of ensuring security. FIGS. 13 and 14 are diagrams illustrating the outline and problems of the method.
【0003】
In the communication between Site A and Site B, Site B is the service provider, specifically a bank, credit company, content provider, and so on. Site A is the side that receives the service, specifically, the bank's automated teller machine, credit card store terminal, personal terminal, and so on. Here, the service provider needs to confirm whether the user at Site A is the person himself / herself.
【0004】
In the conventional public key cryptosystem, the user first requests the site B to issue a certificate prior to the start of communication, and the site B issues the certificate. Specifically, for the public key selected by the user, Site B issues a private key for the user at Site A and delivers it to the user, for example, by mail. The processing in communication is as follows.
【0005】
The user sends the public key of the certificate from Site A as a communication request (step 1). Site B generates a random number (step 2) and sends it to site A (step 3). The user uses his / her private key to encrypt the random number and transmit it to Site B (step 4). Site B uses the user's public key to decrypt it (step 5). Site B checks the random number sent to Site A and the random number obtained by decrypting the code, and if they match, authenticates the user as the person (step 6).
【0006】
In this process, if a person other than the user cannot use the private key, the random number is always sent from the user, so that the site B can authenticate the user. Here, since the private key is difficult to store when the number of digits increases, the user usually stores the private key in the storage device of Site A (computer, etc.) and manages it. However, in this case, there arises a problem that a person other than the user may have a chance to see the private key. If the private key is seen, there is a threat that a third party impersonates a legitimate user and receives the service.
【0007】
Therefore, a method of locking the storage area using, for example, a password is used so that a third party cannot access the storage device of Site A. However, passwords pose a threat of plagiarism. In addition, since the system administrator of Site A is in a situation where he / she can know the password, there is also a threat of plagiarism. In other words, public key cryptography is excellent in security measures between site B and site A, but security between the user and site A is insufficient, and there is a security hole here.
【0008】
To make up for this, attempts have begun to authenticate individuals using human information such as fingerprints instead of passwords. So far, as one of the personal authentication methods under consideration, a method using a card with a fingerprint authentication sensor called an all-in-one card has been known. This card has a fingerprint input sensor built into a thin card, and when the user touches the sensor with a finger, the image is stored in a temporary storage device inside the card, and feature extraction is performed by image processing. The feature is collated with the fingerprint feature collected from the user in the same manner in advance, and it is determined whether or not the feature matches. The authentication result is output from the card. According to this method, fingerprints are a characteristic of an individual's body and vary from person to person, eliminating the threat of being plagiarized as soon as they look like a password. Combining this method with a conventional public key cryptosystem seems to solve the security hole problem at first glance.
【0009】
[Problems to be Solved by the Invention]
However, there are some problems with the above method. The first problem is the threat on the interface between the card and the computer. That is, since access to the area where the private key is stored depends on the 1-bit information of whether or not the person is authenticated as the person output from the card, there is a threat that the signal is stolen between the card and the personal computer (interface). There is. If this interface information is stolen, a third party can impersonate the user.
【0010】
The second problem is the threat of stealing the private key directly from the computer. That is, since there are persons who can access the private key storage area such as the system administrator of the personal computer, the private key may be stolen through, for example, these persons. This point is a problem that cannot be solved even if the password is changed to fingerprint input. The third problem is the problem of authentication accuracy evaluation that depends on the card manufacturer. That is, since the authentication is closed inside the card, the reliability of the authentication has to depend on the card manufacturer. However, originally, it is desirable that the service provider determines the authentication accuracy in consideration of the risk of the service. For example, in a bank's automatic deposit payment service, it may be desired to control the accuracy of personal authentication according to the amount of deposit withdrawal. For high-value withdrawals, the accuracy of personal authentication is high, and for low-value deposit withdrawals, usability is prioritized.
【0011】
As a service provider, there are cases where you want to check (evaluate) the reliability of authentication in-house or by a third-party organization, but it is difficult to evaluate the accuracy because everything is done secretly inside the card. In other words, there is a problem that it is difficult to evaluate the authentication algorithm and compare it with other algorithms. The fourth problem is the threat of deciphering the contents due to theft of the terminal. In the case of the conventional method of performing fingerprint authentication on the site A side, there is a threat that the authentication device (terminal) of site A is stolen by a third party, the authentication program is decrypted, and the contents are illegally rewritten or copied. .. Such threats actually occur in card-type public telephones and card-type pachinko machines. Although these devices are not intended for personal authentication, they write confidential information such as fee information on the card and process usage fees. Once the device is stolen and the processing inside is decrypted, a large number of counterfeit cards will be issued, which may become a social problem.
【0012】
The fifth problem is the problem of upgrading the authentication algorithm. Although related to the second and fourth problems, if the authentication algorithm is decrypted by a third party or a similar authentication device (terminal or authentication card) is forged, the service provider will immediately be an individual. I would like to change the authentication method, but it takes a lot of effort to update the software for each terminal of Site A. Furthermore, if the authentication device is composed of hardware called a card, updating the authentication algorithm requires changing the card itself, collecting the card distributed to the user and distributing a card with a new authentication method. The labor and cost to do so will be extremely enormous.
【0013】
The sixth issue is the ease of use of authentication. From the viewpoint of improving the convenience of the user and the serviceability of the service provider, it is desirable that the personal authentication method can be selected from a plurality of methods as long as a predetermined reliability is ensured. A modality selection function is desired in future personal authentication systems, but conventionally, there has been no personal authentication method having such flexibility.
【0014】
The present invention has been made in view of the above points. It has the following purposes. First, the first purpose is to realize personal authentication of users without security holes in the communication environment. That is, in the communication environment between Site A and Site B, there was a security hole between the user and Site A in the conventional method, but in the present invention, this is eliminated and the user and Site B are eliminated. Achieve reliable authentication between.
【0015】
The second purpose is to enable the service provider to check the authentication accuracy. That is, an environment in which the authentication process based on human body information is closed from the viewpoint of the service provider as in the past, for example, an environment in which the service provider can evaluate the site A or a card owned by the user. Realize with. The third purpose is to facilitate the update of the authentication algorithm. That is, it provides an environment in which the authentication algorithm can be updated immediately when there is a threat such as decryption by a third party in the authentication algorithm, or when it is desired to wait for flexibility in authentication due to a service change.
【0016】
The fourth purpose is to make authentication easier to use. That is, from the viewpoint of improving the convenience of the user and the serviceability of the service provider side, it is possible to select a plurality of human body information on the premise that a predetermined authentication reliability is ensured.
【0017】
[Means for solving problems]
In order to achieve the above object, the present invention is configured as follows. The present invention is a personal authentication method for performing personal authentication using human body information in a system in which a user-side terminal and a center-side device are connected via a network, and the processing means for performing the personal authentication is at least one. It is divided into a set of pre-process and post-process, and the boundary between the pre-process and the post-process is configured to be adaptively variable. In the personal authentication process, the user-side terminal is a user's. Human body information is input by the human body information input means (BioIN), the pre-process processing is performed by the pre-process processing means (ProFow) using the information from the human body information input means (BioIN) as an input, and the pre-process processing means (ProFow) The feature data (Kaz) indicating the characteristics of the user generated by is transmitted to the center side device, and the center side device receives the feature data (Kaz) as an input and performs the post-process processing by the post-process processing means (ProLat). By performing and comparing the user verification data (Aki) generated by the post-process processing means (ProLat) with the user registration data (AKI) registered in advance using the determination processing means (ProCOM). Determine if you are the person.
【0018】
In the above configuration, with respect to the adaptive variation of the feature data (Kaz) at the boundary between the at least one set of pre-processes and the post-processes, the center-side device is a new pre-process processing means (new ProFow) and a new post-process processing. A means (new ProLat) is generated as a set, the new pre-process processing means (new ProFow) is transmitted to the user-side terminal, and the user-side terminal transmits the new pre-process processing means (new ProFow). The new feature data (new Kaz) different from the previous one is generated by using the new feature data (new Kaz), and the center side device uses the new post-process processing means (new ProLat) as input to the user matching data. You can also generate (Aki).
【0019】
Further, in the above configuration, in the present invention, with respect to the adaptive variation of the feature data (Kaz) at the boundary between the at least one set of the pre-process and the post-process, the center-side device is the pre-process processing means (ProFow). By linking to the data conversion means (SXPro, etc.) that applies data conversion such as scrambling to the feature data (Kaz), and by linking to the post-process processing means (ProLat), the data conversion is applied. Data (Kaz <sup>-1</sup>Data decoding calculation method (SXPro) that calculates user verification data (Aki) by inputting) <sup>-1</sup>Etc.) are generated as a set, and the data conversion means (SXPro, etc.) is transmitted to the user-side terminal, and the user-side terminal transmits the data conversion means (SXPro, etc.) to the pre-process processing means (SXPro, etc.). By linking to ProFow), new feature data (new Kaz) different from the previous one is generated, and the center side device takes the new feature data (new Kaz) as an input and inputs the data to the post-process processing means (ProLat). Decoding calculation method (SXPro <sup>-1</sup>Etc.) may be linked to generate user verification data (Aki).
【0020】
Further, in the above configuration, regarding the storage of the user registration data (AKI), the center-side device has an encryption means (ProProj or the like) such as mapping conversion of the user registration data (AKI) and a mapping decoding or the like. Decryption means (ProProj <sup>-1</sup>Etc.) are prepared as a set, and the encrypted data (AKI) obtained by performing mapping conversion or the like on the user registration data (AKI) using the encryption means (ProProj etc.) <sup>-1</sup>) Is transmitted to the user's terminal, and the encrypted data (AKI) <sup>-1</sup>After confirming that the user registration data (AKI) is normally transmitted, the user registration data (AKI) is erased from the center-side recording medium, and the user-side terminal is encrypted transmitted from the center-side device. User registration data (AKI) <sup>-1</sup>Etc.) are recorded on a recording medium, and regarding the use of the user registration data (AKI) at the time of personal authentication, the user-side terminal uses the center-side device with the encrypted user registration data (AKI). <sup>-1</sup>Etc.), and the center-side device is an encryption means (ProProj) such as mapping decoding. <sup>-1</sup>Etc.) and encrypted data (AKI) such as the mapping conversion <sup>-1</sup>Etc.), and after obtaining the user registration data (AKI), the determination processing means (ProCOM) may be used to compare the data with the user verification data (Aki).
【0021】
Further, regarding the storage of the user registration data (AKI), the user-side terminal has an encryption means (ProProj, etc.) such as a mapping conversion of the user registration data (AKI) and a cryptanalysis means (ProProj, etc.) such as a mapping decryption. ProProj <sup>-1</sup>Etc.) are prepared as a set, the encryption means (ProProj etc.) is transmitted to the center side device, and the center side device uses the encryption means (ProProj etc.) and the user registration data (AKI). Encrypted data (AKI) that has undergone mapping conversion, etc. <sup>-1</sup>Etc.) and has a means to delete the user registration data (AKI), and regarding the use of the user registration data (AKI) at the time of personal authentication, the user side terminal is the center side device. The decryption method (ProProj) <sup>-1</sup>Etc.), and the center-side device uses the decryption means (ProProj). <sup>-1</sup>User registration data (AKI) encrypted using the user registration data (AKI, etc.) <sup>-1</sup>Etc.), and after obtaining the user registration data (AKI), it can be compared with the user verification data (Aki) by using the determination processing means (ProCOM).
【0022】
Further, in the above configuration, an encryption means (ProProj or the like) such as the mapping conversion and a decryption means (ProProj or the like) such as the mapping decoding are performed. <sup>-1</sup>Etc.) may be recorded as a program (ProSET) so that it can be updated as needed. Further, in the above configuration, transmission of various processing means from the center-side device to the user-side terminal and transmission of feature data (Kaz) indicating the characteristics of the user from the user-side terminal to the center-side device. With respect to, the center-side device transmits the pre-process processing means (ProFow) to the user-side terminal using the public key Pk (siteA) of the user-side terminal, and the user-side terminal uses the public key Pk (siteA) of the user-side terminal. The pre-process processing means (ProFow) is taken out using the private key Sk (siteA), the pre-process processing means (ProFow) is operated, the feature data (Kaz) is calculated, and the secret key Sk (siteA) is used. The feature data (Kaz) is encrypted and transmitted to the center-side device, and the center-side device uses the public key Pk (siteA) of the user-side terminal to encrypt the feature data (Kaz). Can also be taken out and the post-process processing can be carried out.
【0023】
In the above configuration, the user-side terminal stores and manages the private key Sk (siteA) in the folder of the user-side terminal using the password PW of the user UA as a key, and the user UA stores and manages the password PW. You may make the private key Sk (siteA) available by entering. Further, in the above configuration, the human body information input means (BioIN) for inputting the human body information of the user UA is a card-type fingerprint input device, which accumulates fingerprint images and causes the user side terminal to perform the same. The pre-process processing means (ProFow) having a function of transmitting an image and possessed by the user-side terminal is a feature element disclosure program, and the user feature element Kaz calculated by the program is a fingerprint. The post-process processing means (ProLat), which is a ridge direction field vector and is possessed by the center-side device, is an authentication data generation secret program, user registration data (AKI) calculated by the program, and use. The person matching data (Aki) may be a numerically converted multidimensional vector.
【0024】
Further, in the above configuration, regarding the division of at least one set of the pre-process and the post-process of the processing means for performing personal authentication, each processing means is divided into a plurality of n (n is a natural number) set, and the user-side terminal. Sends the result of the first pre-process to the center-side device, the center-side device executes the first post-process using the processing result as an input, and transmits the result to the user-side terminal. Then, the user-side terminal performs the nth pre-process using the result as an input, transmits the result to the center-side device, and the center-side device receives the result as an input and performs the nth-th pre-step. The post-process may be carried out and the user verification data may be calculated.
【0025】
As described above, according to the present invention, the process of personal authentication is divided into the processing on the terminal side and the processing on the center side, and the data indicating the characteristics is transmitted from the terminal side, so that the human body information itself is transmitted. The amount of data transmission can be reduced as compared with the case, and higher security can be obtained than when the authentication result is transmitted. In addition, security can be further enhanced by encrypting or scrambling the transmitted data. In addition, the service provider can check the authentication accuracy. In addition, the registration data can be placed on the user's terminal, further improving security and convenience for the user.
【0026】
In addition, the center-side device can send the optimum program to the terminal side, and the authentication algorithm can be easily updated. Furthermore, there is no security hole between the user and the terminal on the user side, and reliable authentication is possible. In order to achieve the above object, the present invention can also be configured as follows.
【0027】
The present invention functions as a center-side device that performs personal authentication processing on a computer in a personal authentication processing system that performs personal authentication using human body information in which a user-side terminal and a center-side device are connected via a network. It is a recording medium on which the personal authentication program to be performed is recorded, and the means for performing the personal authentication process is divided into a pre-process and a post-process, and the boundary between the pre-process and the post-process is configured to be adaptively variable. The user-side terminal has a pre-process processing means for performing the pre-process, and the personal authentication program is a feature data (Kaz) of human body information generated by the user-side terminal by the pre-process. By comparing the post-process processing means that performs the post-process processing with) as an input and the user verification data (Aki) generated by the post-process processing means with the user registration data (AKI) registered in advance. It has a determination processing means (ProCOM) for determining whether or not the person is the person.
【0028】
In the above configuration, regarding the adaptive variation of the feature data (Kaz) at the boundary between the pre-process and the post-process, the personal authentication program uses the new pre-process processing means (new ProFow) and the processing on the user-side terminal. A means for generating a new post-process processing means (new ProLat) for a set, a means for transmitting the new pre-process processing means (new ProFow) to the user-side terminal, and the user-side terminal A means for generating user matching data (Aki) using the new post-process processing means (new ProLat) by inputting new feature data (new Kaz) generated using the new pre-process processing means (new ProFow). You may have it.
【0029】
Further, in the above configuration, the personal authentication program has a scramble means (SXPro) for scrambling the feature data (Kaz) by linking to the pre-process processing means (ProFow), and the post-process processing means (ProFow). By linking to ProLat), the scrambled feature data (Kaz) <sup>-1</sup>) Is input to calculate the user verification data (Aki) (SXPro) <sup>-1</sup>) As a set, a means for transmitting the scrambling means (SXPro) to the user-side terminal, and the new feature data (the new feature data) generated by the user-side terminal using the scrambling means (SXPro). With the new Kaz) as an input, the calculation means (SXPro) is sent to the post-process processing means (ProLat). <sup>-1</sup>) May act as a linking processing means to generate user verification data (Aki).
【0030】
Further, in the above configuration, regarding the storage of the user registration data (AKI), the personal authentication program has a mapping conversion means (ProProj) and a mapping decoding means (ProProj) of the user registration data (AKI). <sup>-1</sup>) Is prepared as a set, and the map conversion data (AKI) obtained by performing the map conversion on the user registration data (AKI) using the map conversion means (ProProj). <sup>-1</sup>) To the terminal on the user side and the mapping conversion data (AKI) <sup>-1</sup>) Is transmitted normally, and then when the user registration data (AKI) is deleted from the recording medium on the center side and when the user registration data (AKI) is used for personal authentication. Decoding means (ProProj) <sup>-1</sup>The mapping conversion data (AKI) transmitted by the user-side terminal using). <sup>-1</sup>), And after obtaining the user registration data (AKI) by decoding, the user verification data (Aki) and the user registration data (AKI) are obtained using the determination processing means (ProCOM). It is also possible to have a means of comparison.
【0031】
Further, in the above configuration, the human body information is a fingerprint, and the pre-process processing means (ProFow) held by the user-side terminal is a feature element disclosure program, and the feature data calculated by the program. (Kaz) is a ridge direction field vector of the fingerprint, and the post-process processing means (ProLat) is an authentication data generation secret program, user registration data (AKI) calculated by the program, and use. The person matching data (Aki) may be a numerically converted multidimensional vector.
【0032】
By installing the program recorded on the above recording medium on the computer, the personal authentication method of the present invention can be executed. In order to achieve the above object, the present invention can be further configured as follows. According to the present invention, in a personal authentication processing system in which a user-side terminal and a center-side device are connected via a network to perform personal authentication using human body information, a computer is used as the user-side terminal that performs the personal authentication processing. A recording medium on which a functioning personal authentication program is recorded, the means for performing the personal authentication process is divided into a pre-process and a post-process, and the boundary between the pre-process and the post-process is configured to be adaptively variable. The personal authentication program has a pre-process processing means for performing the pre-process processing, and the pre-process processing means inputs human body information from a human body information input means (BioIN) for inputting human body information of a user. The pre-process processing is performed to generate feature data (Kaz) indicating the characteristics of the user, and the feature data (Kaz) is transmitted to the center-side device, and the feature data (Kaz) and the user are transmitted to the center-side device. The registration data (AKI) is used to determine whether or not the person is the person.
【0033】
In the above configuration, with respect to adaptive variation of feature data (Kaz) at the boundary between the pre-process and the post-process, the personal authentication program uses a new pre-process processing means (new ProFow) transmitted from the center-side device. It may be possible to have a means for generating new feature data (new Kaz) different from the previous one by using the data. Further, in the above configuration, regarding the storage of the user registration data (AKI), the personal authentication program has a mapping conversion means (ProProj) and a mapping decoding means (ProProj) of the user registration data (AKI).<sup>-1</sup>) Is prepared as a set, and has a means for transmitting the mapping conversion means (ProProj) to the center-side device, and the center-side device performs mapping conversion on the AKI using the mapping conversion means (ProProj). Map conversion data (AKI) <sup>-1</sup>) Is stored and the user registration data (AKI) is deleted, and the personal authentication program further uses the user registration data (AKI) at the time of personal authentication in the center-side device as the mapping decoding means. (ProProj <sup>-1</sup>) Is transmitted, and the center-side device is the mapping decoding means (ProProj). <sup>-1</sup>) To the mapping conversion data (AKI) <sup>-1</sup>) May be deciphered.
【0034】
Further, in the above configuration, the human body information input means (BioIN) for inputting the human body information is a card-type fingerprint input device, which accumulates the fingerprint image and transmits the image to the user-side terminal. The pre-process processing means (ProFow) having a function may be a feature element publishing program, and the feature data (Kaz) calculated by the program may be a ridge direction field vector of a fingerprint. ..
【0035】
The personal authentication method of the present invention can also be executed by installing the program recorded on the above recording medium on the computer. Further functions and features of the present invention will be described in detail with reference to the accompanying drawings in the embodiments of the invention.
【0036】
BEST MODE FOR CARRYING OUT THE INVENTION
Next, the personal authentication system according to the embodiment of the present invention will be described with reference to the drawings. FIG. 1 shows the basic configuration of the personal authentication system according to the embodiment of the present invention. Note that FIG. 1 shows the main components, and details will be described in each embodiment.
【0037】
In the present embodiment, the site A is provided with a processing device 1 such as a personal computer that executes processing according to a predetermined program, and BioIN as a means for inputting human body information of the user UA. BioIN is connected to the processor. Further, the monitor 3 for displaying the screen is connected to the processing device 1. The processing device is provided with a pre-process program ProFow for extracting feature elements, a program GUI for displaying guide information such as a biodata acquisition method on the monitor 3, and a communication means 5 for communicating with other devices. In addition, BioIN, ProFow, etc. are symbols indicating each component, and hereinafter, the element may be referred to only by the symbol. The same applies to the elements newly described below.
【0038】
Now, as an example of BioIN, there is a fingerprint input sensor. Fingerprint detection methods include optical and capacitive methods. For example, a fingerprint image with 300x300 pixels, 8-bit gradation, and 500dpi performance is output. ProFow and GUI may be transmitted from Site B, or recorded on a CD-ROM or floppy disk, and mailed to them may be installed at Site A.
【0039】
Site B is provided with a processing device 7 such as a computer that executes processing according to a predetermined program. The processing device 7 may be referred to as a center-side device or an authentication server. The processing device 7 is input with the biometric authentication registration data AKI or the post-process programs ProLat, AKI and Aki that calculate the authentication data Aki by inputting the user characteristic element Kaz calculated at the service provider site A, which will be described later. The authentication data comparison program ProCom for comparison is provided. In addition, it has a communication means 9 and communicates with the processing device 1 of the site A via the network 11.
【0040】
The outline of the operation is as follows. The detailed operation will be described later. When a service request is reqed from site A to site B by the operation of user UA, site B instructs the user to put his finger on the sensor through the screen of site A. Specifically, when the GUI program is activated, the type and direction of the finger placed on the sensor are instructed in an interactive manner with the user. You can get a fingerprint image by putting your finger on it according to the instruction. Site A extracts the feature element Kaz and transmits it to Site B. As a method of transmission, for example, a method in which site A holds a public key and a private key based on a public key cryptosystem in advance, and the feature element Kaz is encrypted using the private key and transmitted can be considered. Regarding the management of the private key, it is conceivable to set up a folder for storing the private key on site A and use the password PW as a storage key to open and close this folder. In other words, the user follows the instructions of the GUI program, puts his finger on the sensor, inputs the PW, retrieves the private key, encrypts using this private key, and transmits it to site B.
【0041】
When Site B receives the encrypted Kaz, it uses the public key to decrypt it and obtain the Kaz. Next, the post-process program ProLat is operated with Kaz as the input, and the authentication data Aki is calculated with the feature element Kaz as the input. The data that has been processed by ProLat is called authentication data Aki in the sense that it enables user authentication.
【0042】
The authentication data Aki is compared with the biometric registration data AKI calculated in a similar manner prior to communication. This program is the authentication data comparison program ProCOM. A specific processing example of ProCOM is threshold processing. If Aki meets a predetermined threshold condition compared to AKI, the user UA is authenticated as the person himself / herself, and if not, it is not authenticated.
【0043】
Next, the function of ProFow that performs the feature element extraction process among the above-mentioned components will be described in more detail. The output from the fingerprint input sensor is taken into a processing device such as a personal computer, and noise removal processing and thinning processing of the fingerprint image are performed as image processing, and small block division processing and small block processing are performed as feature element extraction processing. Cut / branch point detection processing in the inside, ridge vector detection processing in the small block, etc. are executed. Here, the cut / branch point map in the small block (this is called the maneuver) or the ridge vector in the small block is called the user's characteristic element Kaz.
【0044】
Figure 2 shows an example when Kaz is a ridge vector. Dividing a 300x300 pixel into blocks of 10x10 pixels creates a small block of 30x30. Since I don't know where my finger touches the sensor, after capturing the image, I first make a rough alignment (translation and rotation). For the alignment, the error minimum method by shift matching or the matching of maneuver information may be used. After alignment, if the fingerprint ridge is detected for each small block and the direction is represented by, for example, 16 directions and represented by 4 bits, Kaz is a 900-dimensional (4 bits for each dimension) vector as shown in Fig. 3. become.
【0045】
Even if the position of the finger is roughly adjusted, this ridge vector changes depending on the timing of placing the finger on the sensor, the pressing pressure, the elasticity of the skin, and the like. In other words, it shows different characteristics for each individual with a certain fluctuation. Next, the calculation process for obtaining the authentication data Aki by the post-process processing program ProLat will be described. Variable transformation and expansion into different dimensional feature spaces can be considered as calculations to obtain Aki from Kaz.
【0046】
First, a specific example of variable transformation will be described below. It is assumed that the ridge vector is obtained as shown in FIG. Each dimension indicates the direction of the fingerprint, but it is a discrete value. Figure 4 (a) shows the concept of finding the sum of two fingerprint ridges. Here, the fingerprint may be clearly detected or blurred. When the upper ridge is blurred and not clear, the sum of the two fingerprint ridges is a vector with a larger clockwise rotation than in Fig. 4 (a), as shown in Fig. 4 (b). The part that is easily blurred may be common among individuals or closed within the individual.
【0047】
In either case, conversion is possible if the tendency is known. Specifically, if the bias in the direction to be taken in a certain vector dimension is known (statistically obtained), this coefficient can be multiplied to change the discrete value. Such processing must be performed based on a large database of fingerprints, which is easy to perform on the site B server.
【0048】
Next, a specific example of expansion into a different dimensional feature space will be described. For each dimension (or a given subdimensional sequence) of the ridge vector, the confidence may be different. If the fingerprint can be clearly detected and the direction is stable, it can be said that the discrete value in that direction is high, but if multiple ridges are mixed in the small block of the sensor and the line is not clear, the discrete value is high. It can be said that the reliability of discrete values in the direction is low.
【0049】
Therefore, the reliability may be obtained for each block in this way, and the detected ridge vector may be multiplied by the reliability to perform collation processing. A feature space multiplied by reliability is distorted with respect to a feature space not multiplied by reliability, so it can be said to be a kind of different-dimensional feature space. Further, when there are a plurality of sensors and different characteristics can be obtained from each sensor, this integrated process is also performed by the post-process program ProLat. The details will be described later.
【0050】
Among the series of processes in the personal authentication system of the present invention, "a; image input process", "b; noise removal process", "c; thinning process", "d; ridge extraction process", "e; ridge block" Conversion processing (ridge vector extraction processing) F; Ridge end point / branch point extraction processing (maneuver extraction processing) G; Feature data scramble processing K; Feature data scramble decoding processing Ke; Feature data There are "weighting process", "co; multiple feature integration process", "sa; user collation data generation process", "system; registered data collation data comparison judgment process" and the like. In the present invention, not only the process up to "ki" is the pre-process and the process from "ku" is the post-process, but also "a, u, o, ki, ke, sa" is the pre-process, "a, e, ka," It is also possible to use "ku, ko, shi" as a post-process. In addition, other combinations are also possible. Adaptive division includes such division.
【0051】
Subsequently, the operation of the personal authentication system will be described with reference to the figures with reference to three examples. First, the user registration process performed prior to the start of communication in the first embodiment will be described with reference to the flow chart of FIG. When there is a certificate issuance request from the user UA using Site A, that is, a request to certify the public key (Step 0-1), Site B generates the private key of Site A (Step 1-1). Send this information to Site A as a certificate issuance (step 2). Up to this point, the authentication method is the same as that of the conventional public key cryptosystem.
【0052】
In the present invention, it is necessary to issue a biocertificate in order to receive the service. It is done by the following processing. When Site A requests a biometric certificate, Site B generates a biometrics program. Specifically, the GUI control program ProGUI, the pre-process program ProFow for extracting feature elements, the post-process program ProLat for generating authentication data, and the authentication data comparison program ProCOM are generated (step 1-2).
【0053】
ProGUI and ProFow are encrypted with Site A's public key Pk (siteA) and transmitted from Site B to Site A (step 3). Site A uses the private key Sk (siteA) to decrypt it and retrieve ProGUI and ProFow (step 5). Here, regarding the use of the private key Sk (siteA), the password PW may be used together (step 4). ProGUI is installed on Site A and instructs the user UA to enter fingerprints etc. interactively with the screen (step 6). Next, ProFow performs the feature element extraction process (step 7).
【0054】
Specifically, when the finger is placed on the sensor (step 7-1), the sensor acquires the fingerprint image FIN-Ima (7-2) and transmits it to the processing device at Site A. Next, the feature element extraction program ProFow is activated (7-3), and the resulting user feature element Kaz<sub>0</sub>Is extracted (step 7-4). Where the sign Kaz<sub>0</sub>0 in means at the time of registration, that is, the first time.
【0055】
Figure 5 shows Kaz<sub>0</sub>As a specific example of, the amount of information is shown. The raw data is 90KByte for 300X300 pixels, the direction field vector of the ridge is 5KByte, and the maneuver information that collects the branch points and endpoints of the fingerprint pattern is about 300Byte, all of which are feasible. Here mainly Kaz<sub>0</sub>As a concrete example of, consider the direction field vector of the ridge. In the case of the same vector, there are usually more than 1000 dimensions, so it is thought that it changes each time a finger is pressed. The details of the feature element extraction process will be described later.
【0056】
Then Kaz<sub>0</sub>Is encrypted with the private key Sk (siteA) and transmitted to site B (step 8-1). This means that it will be transmitted to Site B with the signature of the user of Site A. Site B uses the public key Pk (siteA) to Kaz<sub>0</sub>(Step 8-2). It can be seen that site B is definitely transmitted from A. Next, the post-process program ProLat for generating authentication data is activated, and the authentication registration data AKI<sub>0</sub>Is calculated (step 10). And AKI<sub>0</sub>Is locked and stored at Site B (step 20).
【0057】
Subsequently, the processing during communication in the first embodiment will be described with reference to FIG. When there is a service request from the user UA (step 1), Site B requires password and fingerprint input. After that, Kaz is processed by steps 4 to 8-2, which is the same as the user registration process.<sub>m </sub>(Meaning mth Kaz) is calculated, encrypted and transmitted to Site B, where Site B breaks the code and Kaz <sub>m </sub>To get. Next, the post-process program PloLat for generating authentication data is activated, and the authentication data Aki<sub>m </sub>Is calculated (step 10). And AKI<sub>0</sub>Remove from the safe (step 11), activate ProCom, and Aki <sub>m </sub>And AKI<sub>0</sub>Compare and Aki <sub>m </sub>Is AKI<sub>0</sub>If it is within the permissible range of, authenticate (step 12).
【0058】
Here, AKI<sub>0</sub>If you are psychologically reluctant to store on Site B, AKI<sub>0</sub>Data AKI encrypted with Site B's private key<sub>0</sub><sup>-1</sup>Is encrypted with the public key of site A and transmitted to site A, and at site A, this is solved with the private key of site A, and AKI<sub>0</sub><sup>-1</sup>May be stored at Site A. AKI at site B<sub>0</sub>When using, site B is from site A, AKI<sub>0</sub><sup>-1</sup>Is transmitted, solved with the private key of site B, AKI<sub>0</sub>May be regenerated and used.
【0059】
After verifying the identity of the user, Site B encrypts the content using Site A's public key Pk (siteA) and transmits it to Site A (step 30). At site A, the private key Sk (siteA) can be used to decrypt the code and obtain its contents (step 31). Next, a second embodiment will be described. The second embodiment is an embodiment of the invention for preventing the user UA's characteristic element Kaz from being stolen by a third party at Site A, and in the process of calculating Kaz at Site A, the site Performs scrambling on Kaz so that it can only be deciphered by B's scramble decoding program.
【0060】
Also, in order to prevent a third party on the site B side from easily reading the AKI calculated at site B, the AKI is mapped and transmitted to site A, and the mapped AKI is stored at site A. .. The mapping transformation here means, for example, when there is an n-dimensional feature space, the feature data is made meaningless by multiplying each dimension by a coefficient such as a random number. In addition, there is a method such as dividing by a random number multiplied by the mapping decoding and returning it to the original state.
【0061】
In addition, encryption and cryptanalysis (or decryption) are to further secure the feature code of each dimension by a common key cryptosystem, a public key cryptosystem, or the like. The user registration process in the second embodiment will be described with reference to FIG. Hereinafter, only the differences from FIG. 5 will be described. The figure is shown by the lower double line. When Site A requests Site B to issue a biocertificate (step 0-1), Site B, along with the feature element extraction program ProFow, scrambles Kaz's permutations with the scramble program SXPro by linking to ProFow. SXPro, a scramble decryption program that decrypts this scramble and restores Kaz<sup>-1</sup>To generate. Furthermore, together with the authentication data generation program ProLat, a mapping conversion program ProProj that makes it impossible to easily decode AKI by linking to the ProLat, and a program ProProj that decodes this mapping.<sup>-1</sup>, And generate a program ProCom that compares authentication data (step 1-2). ProFow and SXPro are transmitted from Site B to Site A prior to the start of communication. The two programs will be linked and the scrambled Kaz will be calculated.
【0062】
In the figure (step 7), when the user inputs a fingerprint, Kaz is scrambled by ProFow and SXPro.<sub>0, n</sub><sup>-1</sup>Is calculated (step 7-5). Here, n indicates the SXPro transmitted at the nth time. Here, ProFow is the first half of the program directly related to the fingerprint authentication algorithm that calculates Kaz, so it does not change frequently. On the other hand, SXPro is a scramble function of Kaz and is a program that is not directly related to the authentication algorithm, so it is changed frequently. For example, it may be changed each time an authentication request is made.
【0063】
In step 8-1, Kaz<sub>0, n</sub><sup>-1</sup>Encrypts with Site A's private key Sk (siteA) and transmits it to Site B. This means that it is transmitted to Site B with the signature of the user UA of Site A, which is decrypted using the public key Pk (siteA) and Kaz.<sub>0, n</sub><sup>-1</sup>(Step 8-2). By decrypting with the public key of Site A, you can see that it was definitely sent from Site A.
【0064】
In step 9, the scramble decryption program SXPro <sub>n </sub><sup>-1</sup>Using, user characteristic element Kaz<sub>0</sub>To restore. In step 10, the authentication data generation program (secret) ProLat is activated and the authentication registration data AKI<sub>0</sub>To calculate. In step 11, the nth mapping conversion program ProProj<sub>n </sub>Using, AKI<sub>0</sub>Map AKI<sub>0, n</sub><sup>-1</sup>To calculate. Since the mapping data is different each time, it is difficult to forge even if it is stored in either site A or B.
【0065】
Now, activate ProLat and AKI<sub>0</sub>And this result is ProProj <sub>n </sub>Instead of calculating AkI0, n-1 as the input of, ProLat and ProProj <sub>n </sub>Link to this and Kaz<sub>0</sub>Directly as AKI<sub>0, n</sub><sup>-1</sup>You may use the method of calculating. In step 12, AKI<sub>0, n</sub><sup>-1</sup>Is encrypted with the public key Pk (siteA) of site A and transmitted to site A. By using the public key, this encrypted data cannot be decrypted by anyone other than the user UA of site A, so it can be reliably sent to site A. In step 13, decrypt with the private key Sk (siteA) and AKI<sub>0, n</sub><sup>-1</sup>And in step 14, replace n with n-1 for the in-communication process shown in Figure 8 below, AKI<sub>0, n-1</sub><sup>-1</sup>Is stored (accumulated) at Site A.
【0066】
In steps 15-17, AKI<sub>0, n-1</sub><sup>-1</sup>After confirming that was reliably transmitted from Site B to Site A, Site B's AKI<sub>0</sub>Erase. By doing this, AKI<sub>0</sub>Does not remain on Site B or Site A, so it is safe against theft. Next, the processing during communication in the second embodiment will be described with reference to FIG. Hereinafter, only the parts different from FIG. 6 will be described.
【0067】
In step 1, if Site B has a service request, Site B will use the scramble program SXPro. <sub>n </sub>, The decryption program SXPro <sub>n </sub><sup>-1</sup>, Map conversion program ProProj <sub>n </sub>, Map decoding program ProProj <sub>n </sub><sup>-1</sup>To generate. In steps 7 and 8, when the user presses the mth finger, Kazm is obtained, which is scrambled to obtain Kazm-1. This and the authentication registration data AKI that was last mapped<sub>0, n-1</sub><sup>-1</sup>Is transmitted to site B using public key cryptography. Site B solves this in step 8-2, Kazm-1 and AKI<sub>0, n-1</sub><sup>-1</sup>To get.
【0068】
In step 10, using ProLat, Aki <sub>m </sub>ProProj, a program that calculates and decodes the mapping transformation used last time in step 11. <sub>n-1 </sub><sup>-1</sup>Using, AKI<sub>0, n</sub><sup></sup><sup>-1</sup>As input, AKI<sub>0</sub>To calculate. In step 12, Aki using ProCom<sub>m </sub>And AKI<sub>0</sub>Compare with. If Aki<sub>m </sub>Is AKI<sub>0</sub>If it is within the permissible range of, authenticate.
【0069】
In step 13, this mapping conversion program ProProj <sub>n </sub>Using, AKI<sub>0</sub>Map AKI<sub>0, n</sub><sup>-1</sup>To calculate. This will be the registration data for the next authentication. Here, AKI<sub>0</sub>Is Aki <sub>m </sub>It may be modified (updated) to reflect the value of. In this case AKI<sub>0</sub>Is AKI<sub>1</sub>And. In step 14, AKI<sub>0, n</sub><sup>-1</sup>Is transmitted to Site A using public key cryptography, and at Site A, where n is n-1, AKI<sub>0, n-1</sub><sup>-1</sup>Accumulate as.
【0070】
When the identity of the user UA is authenticated, the content is transmitted by the public key cryptosystem in the figure (30). Subsequently, a third embodiment will be described. In the third embodiment, the certification registration data AKI<sub>0</sub>Neither site A nor site B has. Map-transformed AKI<sub>0, n</sub><sup>-1</sup>Is stored at site B, and site A owns a decoding program for the mapping conversion. Site A transmits the mapping conversion decoding program from site A to site B at each authentication, and the program decodes the mapping conversion and AKI.<sub>0</sub>Take out, Aki<sub></sub><sub>m </sub>Compare with.
【0071】
Next, the user registration process in the third embodiment will be described with reference to FIG. Hereinafter, only the parts different from those in FIGS. 5 and 7 will be described. If there is a biocertificate issuance request in step 0-2, at site B, ProFow, SXPro<sub>n </sub>, SXPro <sub>n </sub><sup>-1</sup>, And the authentication data generation program (secret) ProLat, the mapping program set generation program ProSET, and the authentication data comparison program ProCom are generated.
【0072】
ProSET is the ProProj, ProProj described in Figure 7. <sup>-1</sup>Generate a set of. In step 50, using ProSET, this mapping conversion program ProProj<sub>n </sub>, Next mapping decoding program ProProj <sub>n </sub><sup>-1</sup>To generate. In step 8-1, Kaz using public key cryptography<sub>0, n</sub><sup>-1</sup>, And ProProj <sub>n </sub>To transmit.
【0073】
In step 11, ProProj <sub>n </sub>Using, AKI<sub>0</sub>Map AKI<sub>0, n</sub><sup>-1</sup>And in step 12, let n be n-1, and AKI<sub>0, n-1</sub><sup>-1</sup>Is registered and stored on Site B. Next, the process during communication in the third embodiment will be described with reference to FIG. In step 50, using ProSET, ProProj<sub>n </sub>, ProProj <sub>n </sub><sup>-1</sup>To generate. Further, in step 51, "ProProj, a mapping decoding program used this time," which was generated last time and stored in the memory.<sub>n-1 </sub><sup>-1</sup>Is read.
【0074】
In step 11, the previous mapping decoding program ProProj <sub>n-1 </sub><sup>-1</sup>AKI stored using<sub>0, n-1</sub><sup>-1</sup>Decode and AKI<sub>0</sub>To calculate. In step 12, using ProComn, Aki<sub>m </sub>And AKI<sub>0</sub>Compare and Aki <sub>m </sub>Is AKI<sub>0</sub>If it is within the permissible range of, authenticate. In step 13, this mapping conversion program ProProj<sub>n </sub>Using, AKI<sub>0</sub>Map AKI<sub>0, n</sub><sup>-1</sup>To calculate.
【0075】
In step 14, let n be n-1 and AKI<sub>0, n-1</sub><sup>-1</sup>To register. By steps 15 and 16, Site A is AKI<sub>0, n-1</sub><sup>-1</sup>Knows that it has been registered on Site B. In step 51, ProProj, where n is n-1<sub>n-1 </sub><sup>-1</sup>To store. In the above explanation, the communication between Site A and Site B has been described.
【0076】
However, the present invention is not limited to the configuration including the site A and the site B, and for example, a third station (certificate authority) may be provided between the site A and the site B. That is, when providing the service, the user registers himself / herself (request for issuance of a certificate) at Site C (certificate authority). From site C to the user UA of site A, programs similar to those transmitted from site B to site A in each of the above examples, such as ProFow and SXPro, are transmitted.
【0077】
Also, from site C to site B, programs similar to those generated at site B, such as ProLat and SXPro, <sup>-1</sup>, ProCom, etc. are transmitted. Subsequent processing may be performed between Site A and Site B in each example, or AKI may be calculated and stored at Site C. By making Site C (Certificate Authority) a highly reliable and neutral institution, it is possible to build a more secure system for managing personal characteristic information.
【0078】
Next, the safety of the present invention against various threats as described in the prior art will be described. (1) First, the security against threats during communication in the present invention will be described. As described above, in the present invention, various programs, Kaz, AKI, etc. that perform authentication processing are transmitted between sites A and B. The threat of data theft during transmission can be addressed by using a combination of public key cryptosystems.
【0079】
For example, when Site B attempts to reliably transmit the preprocessing program ProFow to Site A, Site B encrypts it with Site A's public key Sk (siteA) and transmits it to Site A. At site A, you can use your private key Sk (siteA) to decipher this and get ProFow. Also, when Kaz is to be transmitted from Site A to Site B, Site A encrypts it with the private key Sk (siteA) and transmits it, and Site B decrypts it with the public key Sk (siteA) to obtain it. This allows Site B to know that Kaz was definitely sent from Site A.
【0080】
(2) Regarding the security against threats between the user and Site A in the present invention, in the case of the authentication method using both the password and the fingerprint, if the fingerprint cannot be authenticated even if the password is stolen, Site B Since it does not authenticate the user, there are few threats. (3) Next, the security against threats when ProFow in the Site A terminal is decrypted will be explained.
【0081】
When ProFow is decrypted and copied, a pseudo terminal is created and a fingerprint sensor is connected to it to create an environment in which the ridge vector, which is one of Kaz, can be calculated. However, even if a person other than the user presses his finger against the sensor, the calculated Kaz is different from the legitimate user, so even if this Kaz is transmitted to Site B, Aki will be different and authentication will not be possible.
【0082】
(4) Also, regarding the threat that spoofing may be established by reading Kaz when a finger is pressed on a legitimate user sensor from ProFow in some way and transmitting this to Site B. Suspiciousness can be detected by detecting the fluctuation of Kaz at Site B, or by detecting the fluctuation of Aki calculated by inputting Kaz.
【0083】
That is, as described above, when a legitimate user UA presses a finger against the sensor, Kaz or Aki has a predetermined fluctuation. It is probabilistically unlikely that Kaz with several hundred dimensions will be input with exactly the same numerical value. Therefore, if the numerical values of Kaz and Aki are compared with the previous time and "abnormally high identity" is recognized, the threat of spoofing can be detected and avoidance processing can be taken as described later.
【0084】
(5) Kaz As a means to counter the threat of theft and counterfeiting, as described above, in the present invention, it is possible to scramble this in the calculation of Kaz. To do this, the program SXPro and the program SXPro that decrypts it.<sup>-1</sup>Is used. As mentioned earlier, Site B has SXPro and SXPro when trying to authenticate the user.<sup>-1</sup>Prepare a set of and transmit SXPro to Site A. Site A links ProFow and SXPro to generate a pre-process program newProFow for extracting new feature elements. The program changes with each certification request.
【0085】
Similarly, at Site B, SXPro <sup>-1</sup>And ProLat are linked to generate a new post-process program newProLat. newProLat calculates Aki or AKI by inputting scrambled Kaz. newProFow has a configuration that (1) activates ProFow and acts to scramble its output Kaz, and (2) scrambles the Kaz permutation while Kaz is calculated during the ProFow processing process. It is possible to have a configuration that acts on.
【0086】
In the former configuration, linking the two programs is easy, but there is a problem that the scrambling method is easy to decipher. The latter is difficult to forge Kaz unless the scramble algorithm is completely deciphered. Since site B will have half of the scrambled program, the threat of Kaz counterfeiting at site A can be avoided by adopting the configuration of (2).
【0087】
Next, the threat at Site B will be described. Even on the site B side that provides the service, there is a threat of fraudulent activity by spoofing by system administrators, employees, etc. Impersonation may be due to Kaz acquisition and counterfeiting, or AKI acquisition and Aki counterfeiting. Of these, for the acquisition of Kaz, it is difficult to read Kaz easily because Kaz does not become the input data of the program as it is by using the above-mentioned newProLat that is scrambled.
【0088】
The problem is the threat of stealing the authentication data Aki, which is the output of newProLat, or the biometric registration data AKI, which is the collated data. This is because if AKI is stolen, the same authentication data Aki can be forged and both can be entered into ProCOM, and authentication will be successful. Therefore, some users are reluctant to put AKI on the service provider side.
【0089】
(6) As a countermeasure, there is a method of managing the authentication registration data AKI not at site B but at site A after ensuring security. The details are as described above. (7) As another means of avoiding the threat of AKI theft, the AKI is stored at Site B, but the AKI is mapped (a kind of encryption is applied using a key), and the key for the inverse mapping is used at the site. The method of the present invention stored in A is effective.
【0090】
(8) Next, the workarounds when a threat such as spoofing is detected will be described. Since site B, which is the service provider, is in an environment where Kaz and AKI can be managed, it is possible to detect such fluctuations and estimate spoofing. In the present invention, since the preprocessing of authentication is performed using the program transmitted to Site A, the threat can be countered by replacing this program. Programs can be replaced without burdening users by using JAVA.
【0091】
In addition, when a threat such as spoofing is discovered by authentication with a certain sensor (for example, fingerprint), the GUI can be used to instruct the user to input other human body information from another sensor. Other sensors include handwriting, voice, facial images, and eye iris. As an example of this, examples of handwriting are shown in FIGS. 11 (a) to 11 (d).
【0092】
FIG. 11 (a) is a diagram showing an example of handwriting input tablet output, in which the X-axis, the Y-axis, and the pen pressure (P-axis) are output. Figures 11 (b) to (d) show the output when the time t is on the horizontal axis and the Y-axis, X-axis, and pen pressure (P-axis) are on the vertical axis. The output is about 1500 bytes of information, and the handwriting characteristics change depending on the start position, character size, and speed on the tablet. Therefore, in order to use it as authentication data, the position, character size, and time Needs normalization.
【0093】
Since the position and character size correspond to the values on the X-axis and Y-axis, they are normalized by adjusting the width of the maximum and minimum values. The time is normalized so that the time from start to end is constant. The normalized data is compared with the authentication registration data obtained in advance from the same user in the same manner.
【0094】
FIG. 12 is an example of comparison. The solid line in Fig. 12 (c) is the authentication registration data AKI, and the broken line is the authentication data Aki. For comparison between the two, for example, DP matching processing can be performed. As shown in the enlarged view of the square frame in the figure, the distance between the sample points of the two lines is obtained while sequentially moving the corresponding candidate points, and the distance is converged when the sum of the distances becomes the minimum. The result is a parameter that represents the gap between the two lines. Perform the same processing for the Y-axis, X-axis, and pen pressure (P-axis) to obtain the sum of the errors of each axis.
【0095】
Since the appearance of the error is different for each axis, it is possible to weight the axis with a large difference between individuals. Specifically, when considering the threat of spoofing, it is easy to forge the shape of letters, that is, the output of the Y-axis and X-axis, but it is difficult to forge because the pressure P is a hidden feature. Therefore, the P-axis feature may be weighted for authentication.
【0096】
If the sum of the errors obtained in this way is equal to or less than a predetermined threshold value, the person is collated. When handwriting is applied to the present invention, the pre-process and post-process of the program can be divided in various ways. For example, as ProFow processing, the Y-axis, X-axis, and pen pressure (P-axis) signal sequences (Kaz) It is possible to perform normalization, DP matching processing, error total processing, threshold processing, etc. as the processing of ProLat and ProCOM.
【0097】
It is also possible to set the normalization process as the pre-process, and DP matching, the error total processing for each axis, and the threshold value processing as the post-process. As described above, it is possible to use a plurality of biosensors, and in this case, the integrated processing of ProLat is important, but various integrated methods are possible. For example, (1) A method of calculating the distance between the authentication registration data AKI and the authentication data Aki in a multidimensional space with various feature elements Kaz as each dimension, and if it is within a predetermined threshold value, the authentication is established. .. Specifically, for example, a method of combining the m dimension of the fingerprint ridge vector and the n dimension of the X-axis foot + Y axis + P axis of the handwriting and authenticating with the m + n dimension, (2) Similarity obtained from each sensor. It is possible to obtain the degree (difference between the registered authentication data and the authentication data), multiply the certainty of the data by the weight, and perform the threshold processing.
【0098】
The program that realizes each of the above-mentioned components can be stored in a recording medium such as a CD-ROM or a floppy disk. By installing the program stored in the recording medium on the computer, it is possible to perform the processing of each processing apparatus of the present invention. It is also possible to pre-install the above program on the computer.
【0099】
The present invention is not limited to the above examples, and various modifications and applications can be made within the scope of the claims.
【0100】
[Effect of the invention]
According to the present invention, it is possible to obtain various effects shown below. (1) High security with few security holes In the personal authentication method using the physical characteristics of an individual, the feature of the present invention is that the entire authentication process is not performed at any one place such as a biosensor, a site A, or a site B. That is, the personal feature extraction program is divided into a plurality of parts, and the site A has a pre-process program and activates the program to extract the feature elements of the user. The feature element is sent to Site B. Site B has a post-process program and performs numerical conversion, normalization, matching processing with reference features, etc. of the feature element.
【0101】
In the present invention, since the division of the authentication process and the management of the authentication data are devised in this way, the user and the biosensor, the biosensor and the site A, the site A and the site B, and the site B and the site B administrator It is possible to configure the configuration so that there are no security holes in any part. Therefore, there is little threat that the algorithm will be easily decrypted if one of them is attacked.
【0102】
In this way, it has the effect of solving many of the security hole problems that have been pointed out in the past. (2) It is possible to realize authentication processing that is consistent with the service content. Since a series of programs for the pre-process and post-process of the certification process can be prepared on the site B side, the site B evaluates the algorithm by itself or by a public third party such as a certificate authority. You can get it, and after you are satisfied with it, you can provide a part of it to Site A. For the service side, it has the effect of being able to select an algorithm with authentication accuracy suitable for the service.
【0103】
(3) Easy to update and maintain the authentication method Since the preprocessing process program is sent from Site B to Site A, if there is a threat of decryption by a third party on Site A, the program can be updated immediately, so the threat can be promptly addressed. Has the effect of being eliminated. (4) Improved convenience of authentication A sensor is connected to the site A, and the pre-process program that processes the raw data of the sensor and calculates the user characteristic element is transmitted from the site B.
【0104】
Therefore, the user can connect various sensors to Site A at his / her own discretion and have the service provider send the pre-process program. Site B can also connect the biosensor to Site A and transmit its pre-process program to make it available when launching a new service. That is, it is easily possible to expand various biosensors. The more biosensors available, the more combinations can be selected.
【0105】
For example, for elderly people who have difficulty remembering passwords, people requiring long-term care such as dementia, children, etc., fingerprints can be used instead of passwords. Furthermore, for people who have a psychological resistance to fingerprints, for example, a face image, voice, handwriting, eye iris image, password, etc. should be combined on the premise that the desired authentication accuracy is ensured. Is possible.
【0106】
Furthermore, even from the service provider side, for example, the service is currently being implemented with a 4-digit password, and the user is requesting a service with a higher risk (specifically, a high-priced cash withdrawal service). In such a case, if it is considered that increasing the number of digits of the password will reduce the service, it is possible to perform fingerprint authentication in addition to the four digits of the password. If fingerprint authentication can obtain 4-digit accuracy, combining the two will achieve 8-digit authentication accuracy, which has the effect of allowing the service side to provide the service with peace of mind.
【0107】
(5) Low communication cost The information transmitted between the user and the service side is the personal feature element Kaz and the means for scrambling it, the authentication registration data AKI and the means for mapping it. The cost of communication is lower than when the raw data of human body information is sent as it is. (6) Crime prevention effect The service provider side or the authentication agency side (certificate authority side) at the intention of the service provider side is in a situation where the personal characteristic element Kaz, the authentication data Aki, etc. can be known. The characteristic of biometrics information is that there are fluctuations. For example, in the case of a fingerprint, even the same person changes slightly depending on the force of touching the sensor, the timing, and the like. Since this fluctuation is reflected in Kaz and Aki, the service provider who detects it can grasp this fluctuation.
【0108】
When authenticating with biometrics, a possible threat of fraud due to spoofing is to take a fingerprint and bring it closer to the sensor. In this case, since the living body does not directly touch the sensor, no fluctuation occurs, or the fluctuation is different from that of the living body. Therefore, by detecting this fluctuation, it is possible to estimate the use by spoofing. When suspicious things such as spoofing are found, it is possible to take measures such as changing from fingerprints to other biometrics such as handwriting and voice, which is highly safe.
【0109】
In addition, when a suspicious person is estimated, a crime prevention effect can be expected by switching to using a face image or using voice. In other words, if facial images and audio information are used, it is easier for suspicious persons to conduct criminal investigations, and there is a risk of crime, so it is thought that there is an effect of avoiding spoofing.
[Simple explanation of drawings]
[Figure 1]
It is a figure which shows the basic structure of the personal authentication system in this invention.
[Figure 2]
It is a figure which shows the extraction example when the characteristic element of a fingerprint is a ridge vector.
[Fig. 3]
It is a figure which shows the example of a ridge vector.
[Fig. 4]
It is a figure which shows the concept which calculated the sum of two fingerprint ridges.
[Fig. 5]
It is a figure which shows the user registration process in 1st Example.
[Fig. 6]
It is a figure which shows the process during communication in 1st Example.
[Fig. 7]
It is a figure which shows the user registration process in 2nd Example.
[Fig. 8]
It is a figure which shows the process during communication in 2nd Example.
[Fig. 9]
It is a figure which shows the user registration process in 3rd Example.
[Fig. 10]
It is a figure which shows the process during communication in 3rd Example.
[Fig. 11]
It is a figure for demonstrating the case where the handwriting is used as the human body information.
[Fig. 12]
It is a figure for demonstrating the comparison method when handwriting is used as human body information.
[Fig. 13]
It is a figure for demonstrating the public key cryptosystem in the prior art.
[Fig. 14]
It is a figure for demonstrating the public key cryptosystem in the prior art.
[Explanation of symbols]
1, 7 Processing equipment 3 monitor 5, 9 means of communication 11 Network
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US8064646B2 | Cited by | United States of America | Applicant |
| JP2007501981A | Cited by | Japan | Search report |
| JP2011090686A | Cited by | Japan | Search report |
| WO2005006732A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2006501583A | Cited by | Japan | Examiner |
| JP2015201040A | Cited by | Japan | Search report |
| US8027522B2 | Cited by | United States of America | Applicant |
| KR20030016611A | Cited by | Republic of Korea | Search report |
| JP2003157332A | Cited by | Japan | Search report |
| JP2018512669A | Cited by | Japan | Search report |
| JP4924718B2 | Cited by | Japan | Examiner |
| JP2006024095A | Cited by | Japan | Search report |
| US7532745B2 | Cited by | United States of America | Applicant |
| CN105635156A | Cited by | China | Search report |
| WO2009051250A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2003323622A | Cited by | Japan | Search report |
| JP2015201040A | Cited by | Japan | Search report |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 22945899 | Japan | A | |
| JP19990229458 | – | – | – |
Numbers
- Publication
- 2001-52182
- Publication, DOCDB
- 2001052182
- Publication, EPODOC
- JP2001052182
- Application
- 11229458
- Application, DOCDB
- 22945899
- Application, EPODOC
- JP19990229458
Titles2
- Japanese
- 【発明の名称】個人認証方法及び個人認証プログラムを記録した記録媒体
- English
- [Title of the Invention] A recording medium on which a personal authentication method and a personal authentication program are recorded.
Classification
- IPC, 4
- G06F15 00
- G06F21 32
- G06F21 33
- G06T7 00