Identification system and apparatus
Abstract
Problem to be solved.To carry out identification via a network while ensuring the reliability of the authentication of a living body.
Solution.With respect to the result of collation by a living body authentication system, collation related data imparted with double digital signatures of a living body authentication device 50 and a secure medium 40 are transmitted to an authentication server 10 via the network.

Term
Term ended
Projected expiry passed 30 October 2021, 4.9 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
9 claims: 6 independent, 3 dependent
- 1[Claims] [Claim 1] An identity verification system for confirming the identity of a user by a biometric authentication method. For each user, a user registration authority for issuing user certificates and user private keys based on public key cryptography, and For each biometric device, a device certificate authority for issuing device certificates and device private keys based on public key cryptography, and The device certificate and device private key issued by the device certification authority are stored in advance, and when it is confirmed that the user is the person by a predetermined biometric authentication method, the device secret is obtained with respect to the obtained personal identification information. A biometric authentication device that attaches the first digital signature with a key and the device certificate and sends it, When the user certificate and user private key issued by the user registration authority are stored in advance and the identity verification information, the first digital signature, and the device certificate transmitted from the biometric authentication device are received, the first digital is received. A user signature device that performs signature processing with the user private key on the signature and transmits the obtained second digital signature, the identity verification information, the device certificate, and the user certificate. A client device having a medium holding unit that detachably holds the user signature device and connected to the biometric authentication device, and a client device. When the client device is connected to the client device via a network and receives the second digital signature, identity verification information, device certificate, and user certificate transmitted from the user signing device, the user registration authority and the device certification authority are referred to. While verifying the user certificate and the device certificate, or verifying the second digital signature, and when the verification results of each certificate and the second digital signature are valid, the identity verification information is obtained. Authentication device to authenticate and An identity verification system characterized by being equipped with. 【特許請求の範囲】 【請求項1】 生体認証方式により、ユーザが本人である旨を確認するための本人確認システムであって、 各ユーザ毎に、公開鍵暗号方式に基づくユーザ証明書及びユーザ秘密鍵を発行するためのユーザ登録局と、 各生体認証機器毎に、公開鍵暗号方式に基づく機器証明書及び機器秘密鍵を発行するための機器認証局と、 前記機器認証局により発行された機器証明書及び機器秘密鍵が予め格納され、所定の生体認証方式により前記ユーザが本人である旨を確認したとき、得られた本人確認情報に対して前記機器秘密鍵による第1デジタル署名と前記機器証明書とを付与して送信する生体認証機器と、 前記ユーザ登録局により発行されたユーザ証明書及びユーザ秘密鍵が予め格納され、前記生体認証機器から送信された本人確認情報、前記第1デジタル署名及び前記機器証明書を受信すると、この第1デジタル署名に対して前記ユーザ秘密鍵による署名処理を施し、得られた第2デジタル署名、前記本人確認情報、前記機器証明書及び前記ユーザ証明書を送信するユーザ署名装置と、 前記ユーザ署名装置を着脱自在に保持する媒体保持部を有し、前記生体認証機器に接続されたクライアント装置と、 前記クライアント装置にネットワークを介して接続され、前記ユーザ署名装置から送信された第2デジタル署名、本人確認情報、機器証明書及びユーザ証明書を受信すると、前記ユーザ登録局及び前記機器認証局を参照しながら前記ユーザ証明書及び前記機器証明書を検証し、又は前記第2デジタル署名を検証し、前記各証明書と前記第2デジタル署名との検証結果がそれぞれ正当のとき、前記本人確認情報を認証する認証装置と、 を備えたことを特徴とする本人確認システム。
- 5A biometric authentication device that attaches a first digital signature to the identity verification information that confirms the identity of the user by a biometric authentication method and sends it together with a device certificate, and a biometric authentication device for confirming the identity verification information. It is used in an identity verification system including an authentication device and a client device for transmitting the identity verification information obtained by the biometric authentication device to the authentication device via a network, and is attached to and detached from a medium holding portion of the client device. It is a user signature device that can be freely held. A user information storage means in which a user certificate and a user private key based on a public key cryptosystem are stored in advance, and A receiving means for receiving the identity verification information transmitted from the biometric authentication device, the first digital signature, and the device certificate. A signature verification means for verifying the first digital signature received by the receiving means based on the device certificate, and When the verification result by the signature verification means is valid, the signature generation means for performing the signature processing by the user private key in the user information storage means for the first digital signature, and the signature generation means. A transmission means for transmitting the second digital signature obtained by the signature generation means, the identity verification information, the device certificate, and the user certificate into the client device, and A user signature device characterized by being equipped with. 【請求項5】 生体認証方式によりユーザが本人である旨を確認する本人確認情報に第1デジタル署名を付与して機器証明書と共に送出する生体認証機器と、前記本人確認情報を確認するための認証装置と、前記生体認証機器により得られた本人確認情報をネットワークを介して前記認証装置に送信するためのクライアント装置とを備えた本人確認システムに用いられ、前記クライアント装置の媒体保持部に着脱自在に保持されるユーザ署名装置であって、 予め公開鍵暗号方式に基づくユーザ証明書及びユーザ秘密鍵が格納されたユーザ情報格納手段と、 前記生体認証機器から送信された本人確認情報、前記第1デジタル署名及び前記機器証明書を受信する受信手段と、 前記受信手段により受信された第1デジタル署名を前記機器証明書に基づいて検証する署名検証手段と、 前記署名検証手段による検証結果が正当のとき、この第1デジタル署名に対して前記ユーザ情報格納手段内のユーザ秘密鍵による署名処理を施す署名生成手段と、 前記署名生成手段により得られた第2デジタル署名、前記本人確認情報、前記機器証明書及び前記ユーザ証明書を前記クライアント装置内に送信する送信手段と、 を備えたことを特徴とするユーザ署名装置。
- 6The identity verification information, the device certificate, the user certificate, and the identity verification information are signed by the device private key corresponding to the device certificate and the user private key corresponding to the user certificate, respectively. This is an authentication device for authenticating the identity verification information when a digital signature is received from a client device via a network. A receiving means for receiving the digital signature, the identity verification information, the device certificate, and the user certificate. Certificate verification means for verifying the device certificate and user certificate received by the receiving means while communicating with the issuer of each certificate. When the verification result by the certificate verification means is valid, the signature verification means for verifying the digital signature based on each certificate and the signature verification means. When the verification result by the signature verification means is valid, the identity verification information authentication means for authenticating the identity verification information and the identity verification information authentication means. An authentication device characterized by being equipped with. 【請求項6】 本人確認情報及び機器証明書と、ユーザ証明書と、前記本人確認情報が前記機器証明書に対応する機器秘密鍵及び前記ユーザ証明書に対応するユーザ秘密鍵によりそれぞれ署名処理されてなるデジタル署名とをクライアント装置からネットワークを介して受信したとき、前記本人確認情報を認証するための認証装置であって、 前記デジタル署名、前記本人確認情報、前記機器証明書及び前記ユーザ証明書を受信する受信手段と、 前記受信手段により受信された機器証明書及びユーザ証明書を当該各証明書の発行元と通信しながら検証するための証明書検証手段と、 前記証明書検証手段による検証結果が正当なとき、前記各証明書に基づいて前記デジタル署名を検証する署名検証手段と、 前記署名検証手段による検証結果が正当なとき、前記本人確認情報を認証する本人確認情報認証手段と、 を備えたことを特徴とする認証装置。
- 7A biometric authentication device for confirming the identity of a user by a biometric authentication method. A device information storage means in which a device certificate and a device private key based on a public key cryptosystem are stored in advance, and A reading means for reading the user's biological information and A collation means that collates the biometric information obtained by the reading means with the user's reference information separately transmitted, and if both match, sends out identity verification information indicating legitimacy. A signature generation means for performing signature processing and performing signature processing by the device private key in the device information storage means for the identity verification information sent from the verification means. A transmission means for transmitting the first digital signature obtained by the signature generation means, the identity verification information, and the device certificate, and A biometric authentication device characterized by being equipped with. 【請求項7】 生体認証方式により、ユーザが本人である旨を確認するための生体認証機器であって、 予め公開鍵暗号方式に基づく機器証明書及び機器秘密鍵が格納された機器情報格納手段と、 前記ユーザの生体情報を読取る読取り手段と、 前記読取り手段により得られた生体情報と別途送信されたユーザの参照情報とを照合し、両者が一致すると、正当を示す本人確認情報を送出する照合手段と、 前記照合手段から送出された本人確認情報に対して、前記機器情報格納手段内の機器秘密鍵による署名処理と施す署名生成手段と、 前記署名生成手段により得られた第1デジタル署名、前記本人確認情報及び前記機器証明書を送信する送信手段と、 を備えたことを特徴とする生体認証機器。
- 8[Claim 8] A device certificate based on a public key cryptosystem when an issuance request or issuance permission is received from a certificate authority for each biometric authentication device for confirming the identity of the user by the biometric authentication method. And a device certificate authority characterized by issuing a device private key. 【請求項8】 生体認証方式により、ユーザが本人である旨を確認するための各生体認証機器に対し、認定局から発行要求又は発行許可を受けたとき、公開鍵暗号方式に基づく機器証明書及び機器秘密鍵を発行することを特徴とする機器認証局。
- 9An identity verification system for confirming the identity of a user by a biometric authentication method. For each user, a user registration authority for issuing user certificates and user private keys based on public key cryptography, and For each biometric device, a device certificate authority for issuing device certificates and device private keys based on public key cryptography, and When the user certificate and user private key issued by the user registration authority are stored in advance and the identity verification information, the first digital signature, and the device certificate transmitted from the outside are received, the first digital signature is received. A user signature device that performs a signature process using the user private key and transmits the obtained second digital signature, the identity verification information, the device certificate, and the user certificate. A client device having a medium holding unit for detachably holding the user signature device and having a communication function, and a client device. When the second digital signature, identity verification information, device certificate, and user certificate transmitted from the user signing device are received via the client device, the user certification is performed with reference to the user registration authority and the device certification authority. An authentication device that verifies the certificate and the device certificate, or verifies the second digital signature, and authenticates the identity verification information when the verification results of each certificate and the second digital signature are valid. An identity verification system characterized by being equipped with. 【請求項9】 生体認証方式により、ユーザが本人である旨を確認するための本人確認システムであって、 各ユーザ毎に、公開鍵暗号方式に基づくユーザ証明書及びユーザ秘密鍵を発行するためのユーザ登録局と、 各生体認証機器毎に、公開鍵暗号方式に基づく機器証明書及び機器秘密鍵を発行するための機器認証局と、 前記ユーザ登録局により発行されたユーザ証明書及びユーザ秘密鍵が予め格納され、外部から送信された本人確認情報、前記第1デジタル署名及び前記機器証明書を受信すると、この第1デジタル署名に対して前記ユーザ秘密鍵による署名処理を施し、得られた第2デジタル署名、前記本人確認情報、前記機器証明書及び前記ユーザ証明書を送信するユーザ署名装置と、 前記ユーザ署名装置を着脱自在に保持する媒体保持部を有し、通信機能を備えたクライアント装置と、 前記ユーザ署名装置から送信された第2デジタル署名、本人確認情報、機器証明書及びユーザ証明書を前記クライアント装置を介して受信すると、前記ユーザ登録局及び前記機器認証局を参照しながら前記ユーザ証明書及び前記機器証明書を検証し、又は前記第2デジタル署名を検証し、前記各証明書と前記第2デジタル署名との検証結果がそれぞれ正当のとき、前記本人確認情報を認証する認証装置と、を備えたことを特徴とする本人確認システム。
Independent claims6
403 paragraphs in 1 section, as filed
Description: TECHNICAL FIELD [Detailed description of the invention]
【0001】
[Technical field to which the invention belongs]
The present invention relates to an identity verification system and device that perform identity verification using a biometric authentication method, and more particularly to an identity verification system and device that can perform identity verification via a network while guaranteeing the reliability of biometric authentication. ..
【0002】
[Conventional technology]
In general, a biometrics method based on human biometric information is widely known as a kind of identity verification method. Here, the biometric authentication method is a technique for determining whether or not an individual is a person by collating the unique biological characteristics of each individual with the biometric information of each individual registered in advance. The biological information is information (quantified) of biological features in a broad sense such as fingerprints, irises, retinas, faces, voices, keystrokes, and signs.
【0003】
In this way, unlike existing authentication methods such as passwords, the biometric authentication method uses biometric features that are not likely to be forgotten or lost, so the burden on each individual user (hereinafter referred to as the user) is light. It is a confirmation method. In addition, since the biological characteristics are premised on those that are difficult to replicate, they are effective in preventing spoofing attacks and the like.
【0004】
At present, with the spread of open networks represented by the Internet, it is being considered to introduce a biometric authentication method for network communication such as electronic commerce.
【0005】
However, when the biometric authentication method is introduced into network communication, the verification result and biometric information may be stolen or falsified on the network. However, this possibility can be reduced by combining it with secure media such as public key infrastructure and IC cards (smart cards).
【0006】
On the other hand, a more accurate identity verification system has been realized by a composite biometric authentication system that comprehensively verifies the identity by combining a plurality of types of biometric authentication.
【0007】
[Problems to be Solved by the Invention]
However, the above-mentioned identity verification system has no particular problem in the present case where it is applied to a closed system, but according to the consideration of the present inventor, it is applied to an open network in the near future. The following problems (a) to (d) are expected to occur.
【0008】
(a) When the identity verification system authenticates the communication partner via the network, it is difficult to know whether the execution environment (client environment) of the identity verification is really safe and reliable.
【0009】
That is, the identity verification system needs to confirm whether or not the biometric authentication device and verification algorithm, which are different for each user, have been tampered with, whether or not they are at the required level (reliable level), and whether or not they are legitimate. There is. However, this confirmation is extremely difficult.
【0010】
(b) Regarding problem (a), the identity verification system needs to protect the request level or its response from theft or tampering on the network when communicating the request level to the user side.
【0011】
For example, an entity that provides a service informs the user of the requirement level that satisfies the security policy of the provided service at the time of biometric authentication, and confirms that the biometric authentication device and matching algorithm on the user side exceed the requirement level. Then. In this case, the request level or its response must not be stolen or tampered with on the network.
【0012】
(c) Since the collation algorithm of the identity verification system and the biometric authentication device such as the collation device and the reader are assumed to be used in a closed system, there are many cases where there is no connectivity between manufacturers. In particular, the collation algorithm may extract biological information that differs from each other among manufacturers for the same biological feature. Therefore, the biometric information extracted by the collation algorithm of company A cannot often be used as the pre-registered biometric information (hereinafter, also referred to as reference information) of the collation algorithm of company B.
【0013】
(d) An authentication platform that has a mechanism to solve the above-mentioned problems (a) to (c) and can be used in common by each user using an open network is required.
【0014】
The present invention has been made in consideration of the above circumstances, and an object of the present invention is to provide an identity verification system and an apparatus capable of performing identity verification via a network while guaranteeing the reliability of biometric authentication.
【0015】
[Means for solving problems]
The first invention is an identity verification system for confirming the identity of a user by a biometric authentication method, and issues a user certificate and a user private key based on the public key cryptography for each user. A user registration authority for issuing a device certificate and a device private key based on a public key cryptosystem for each biometric authentication device, and a device certificate and device issued by the device authentication authority. When the private key is stored in advance and it is confirmed that the user is the person by a predetermined biometric authentication method, the first digital signature by the device private key and the device certificate are attached to the obtained personal identification information. The biometric authentication device to be attached and transmitted, the user certificate issued by the user registration authority, and the user private key are stored in advance, and the identity verification information transmitted from the biometric authentication device, the first digital signature, and the device. Upon receiving the certificate, the user who performs the signature processing with the user private key on the first digital signature and transmits the obtained second digital signature, the identity verification information, the device certificate, and the user certificate. A client device having a signature device and a medium holding unit for detachably holding the user signature device, connected to the biometric authentication device via a network, and transmitted from the user signature device. Upon receiving the second digital signature, identity verification information, device certificate, and user certificate, the user certificate and the device certificate are verified or the device certificate is verified with reference to the user registration authority and the device authentication authority. It is an identity verification system including an authentication device that verifies the second digital signature and authenticates the identity verification information when the verification results of each of the certificates and the second digital signature are valid.
【0016】
Here, as the identity verification information, for example, the collation result and / or the biometric information can be used. Further, as a user signature device, a personal and portable device such as an IC card or a smart card can be used.
【0017】
In this way, since the double digital signature of the biometric authentication device and the user signature device is given to the identity verification information by the biometric authentication method, the identity verification can be performed via the network while guaranteeing the reliability of the biometric authentication. Can be executed.
【0018】
In the second invention, in the first invention, the authentication device includes a request level notification means for notifying the client device of the biometric authentication level required by the service based on the service request received from the client device. It is an identity verification system.
【0019】
Thereby, in addition to the action of the first invention, it is possible to guarantee that the obtained identity verification information satisfies the biometric authentication level (collation accuracy of the biometric authentication method, strength of tamper resistance, etc.) required by the service side. it can.
【0020】
In the third invention, in the second invention, when a plurality of biometric authentication devices are connected, the client device includes the biometric authentication evaluation data described in the device certificate of each biometric authentication device. It is an identity verification system provided with a biometric authentication method or a biometric authentication device selection means for selecting a biometric authentication method or a biometric authentication device that satisfies the required level based on the created authentication device connection list.
【0021】
Thereby, in addition to the action of the second invention, an appropriate biometric authentication method or biometric authentication device can be selected from a plurality of biometric authentication devices without fixing the biometric authentication method to be used.
【0022】
The fourth invention is an operation of dynamically changing the contents of the authentication device connection list so as to add the biometric authentication device when a new biometric authentication device is connected to the client device in the third invention. It is an identity verification system equipped with means for changing the target.
【0023】
Thereby, in addition to the action of the third invention, a new biometric authentication device can be easily and surely added.
【0024】
Although each of the above inventions is expressed by the name of "system", the present invention is not limited to this, and may be expressed by other names or categories such as "device", "method", and "program" as a whole or each.
【0025】
BEST MODE FOR CARRYING OUT THE INVENTION
Hereinafter, each embodiment of the present invention will be described with reference to the drawings. The identity verification system described in each embodiment is a system that provides an arbitrary service (WWW service, etc.) via a network, and is a client device (personal computer, workstation, etc.) in response to an identity verification request such as logon to a service. The service provider can verify that the identity of the person has been confirmed in a legitimate and safe environment. Here, the network connection line is assumed to be a general-purpose open network represented by the Internet, but may be a local network such as LAN or a dedicated line.
【0026】
(First Embodiment) FIG. 1 is a schematic diagram showing a configuration of an identity verification system according to the first embodiment of the present invention. This identity verification system includes a user registration authority 1, an certification authority 2, a device certification authority 3, an authentication server 10, a client device 20, a medium reader 30, a secure medium 40, and a biometric authentication device 50.
【0027】
Here, the user registration authority 1 performs the initial user registration, and corresponds to the user certificate (user's public key certificate) and the user private key (corresponding to this public key certificate) based on the user's registration application. A function to issue a private key of a public key encryption method, a function to store the issued user information in the secure medium 40, a reference information presented at the time of issuance, and a bioauthentication compatible list (bioauthentication method corresponding to the reference information). ) Is stored in the secure medium 40, and the user certificate is transmitted to the authentication server 10 by access from the authentication server 10.
【0028】
Here, as shown in FIG. 2, the reference information includes a header (biometric authentication compatible list), standard biometric information (eg, standard fingerprint reference information, standard face reference information), and biometric authentication method specific information (eg, fingerprint). It has items of authentication method A specific information, fingerprint authentication method B specific information, and face authentication method C specific information).
【0029】
Examples of reference information are defined by biometric information read by a biometric information sensor (fingerprint image before extraction in the case of fingerprint authentication), data after feature extraction processing corresponding to different collation algorithms, standardization organizations, and the like. There is data according to the format, or a combination thereof. The selection of reference information in the initial registration depends on the judgment of the user or the usage pattern of the system.
【0030】
The certification authority 2 evaluates the verification accuracy (false rejection rate, false acceptance rate, response rate, etc.) and the strength of tamper resistance of the biometric authentication device 50, and certifies the biometric authentication level satisfied by the biometric authentication device 50 to be evaluated. Specifically, it has a function of certifying the biometric authentication device 50 based on an application from the manufacturer of the biometric authentication device 50 and notifying the device certification authority 3 of the certification contents.
【0031】
Here, the biometric authentication level indicates the overall performance (safety performance, verification performance, etc.) of the biometric authentication device 50 alone to be certified.
【0032】
Any standard can be used as the collation accuracy evaluation standard, but it is desirable to use, for example, a standardized collation accuracy evaluation standard specified by a standardization body or the like. The same applies to the tamper resistance evaluation criteria.
【0033】
The device certification authority 3 issues a device certificate to the biometric authentication device 50 certified by the certification authority 2. Specifically, when the certificate authority 2 issues an issuance request or issuance permission, the device certification is issued. Issue a document (device public key certificate). The device certification authority 3 may be provided in the same element (computer or the like such as a server) as the certification authority 2. Although each station 2 and 3 may be a simple configuration example as shown in FIG. 1, it is also possible to make each station 2 and 3 independent as an identity verification guarantee base of this system. A detailed description of another form of the identity verification guarantee platform composed of the certification authority 2 and the device certification authority 3 will be described later.
【0034】
As shown in Fig. 3, the device certificate includes the field, version, public key for which the device certificate is issued, the serial number of the device certificate, signature algorithm, expiration date, device certificate issuer, and device certificate issuance. It includes data for each item of the target, biometric device manufacturer, biometric device evaluation standard, biometric device evaluation result, and digital signature, and may be accompanied by evaluation items such as safety.
【0035】
The device certificate may be in the format of an X.509 certificate, which is a generally popular public key certificate, or may be in a newly defined format. At this time, field items not specified in the X.509 certificate can be used by defining them as private extended areas. Further, the field items shown in FIG. 3 are examples, and may be appropriately modified. The biometric device evaluation standard indicates the evaluation standard used at the time of certification by the device certification authority 3. The biometric authentication device evaluation result may be any one showing the evaluation result according to each evaluation standard, and may be, for example, an index or an ID showing the evaluation result.
【0036】
The authentication server 10 belongs to a system that provides services, and includes a communication unit 11, a request response unit 12, a certificate verification unit 13, a level verification unit 14, and a result verification unit 15, as shown in FIG.
【0037】
Here, the communication unit 11 is for communication between the client device 20 on the network and the request response unit 12 or the certificate verification unit 13 in the local server 10.
【0038】
The request response unit 12 has a function of sending a response such as a level request to the client device 20 to the communication unit 11 in response to a request received from the client device 20 via the network and the communication unit 11, and level collating this level request. It has a function to send to the part 14.
【0039】
The certificate verification unit 13 receives the verification result-related data (device certificate, user certificate, verification result, signature data SM [SD [verification result]]) received from the client device 20 via the network and the communication unit 11. It has a function of verifying the validity of each certificate while referring to the user registration authority 1 and the device certification authority 3, and when the verification result is valid, the verification-related data is sent to the level verification unit 14.
【0040】
Here, SM [] means the digital signature of the secure medium 40 for the data SD [verification result] in [parentheses], and SD [collation result] is for the data collation result in [parentheses]. It means the digital signature of the biometric device 50.
【0041】
As for the verification process of the validity of the certificate, for example, whether or not each certificate is within the expiration date, and whether or not each certificate is revoked by CRL (Certificate Revocation List) which is a revocation list of public key certificates. It verifies whether or not the digital signature of each certificate is valid, and whether or not each certificate authority in the certificate trust path is reliable.
【0042】
The level collation unit 14 collates the evaluation result data (and / or the evaluation standard data) of the device certificate with the level request received from the request response unit 12 among the collation result related data received from the certificate verification unit 13. , It has a function to send the collation result related data to the result verification unit 15 when the evaluation result data satisfies the level requirement.
【0043】
The result verification unit 15 has a function of verifying the signature data SM [SD [verification result]] of the collation result-related data received from the level collation unit 14 based on each certificate and verifying the validity of the collation result. There is.
【0044】
As shown in FIG. 5, the client device 20 has a communication unit 21 and an authentication control program unit 22, and includes other components (monitor, mouse, keyboard, etc.) (not shown).
【0045】
The communication unit 21 is for executing communication between the authentication control program unit 22 and the authentication server 10.
【0046】
The authentication control program unit 22 is realized by an authentication control program that resides and operates when the system operates, and is a functional unit for controlling the identity verification process of the client device 20, and operates when accessing the authentication server 10. It is necessary, and when it is not operating, it is started by calling a communication interface (browser, etc.) or by a user's operation. The authentication control program may be included in the OS, or may be a program outside the OS such as application software or middleware.
【0047】
Specifically, the authentication control program unit 22 includes a communication data control unit 23, a biometric authentication selection unit 24, and a biometric authentication device addition / deletion unit 25.
【0048】
The communication data control unit 23 controls the transfer of communication data (eg, reference information, collation result, signature data SM, SD) between the client device 20 and the secure medium 40 or the biometric authentication device 50 during the biometric authentication process. It is done and does not affect the content of communication data.
【0049】
The biometric authentication selection unit 24 has a function of selecting a biometric verification algorithm (verification routine) that satisfies the biometric authentication request level received from the authentication server 10 based on the biometric authentication device connection list received from the secure medium 40.
【0050】
Here, in the biometric device connection list, as shown in FIG. 6, the device name, the target biometric information, the matching algorithm, the manufacturer, and the biometric authentication level are described for each biometric authentication device 50 connected to the client device 20. It is a thing.
【0051】
The biometric authentication device addition / deletion unit 25 adds / deletes the corresponding content on the biometric authentication device connection list when the biometric authentication device 50 is added / deleted. At the time of addition, the device certificate sent from the additionally connected biometric authentication device 50 is verified, and when it is valid, the corresponding data is added to the biometric authentication device connection list. When deleting, the corresponding data is deleted from the biometric device connection list.
【0052】
The medium reader 30 has a function of holding the secure medium 40 detachably and a function of an interface between the secure medium 40 and the client device 20.
【0053】
The secure medium 40 has tamper resistance and cannot access internal information by any means other than legitimate access means. It is equipped with a function to prevent the leakage of internal information by erasing the internal information even against attacks such as unauthorized reading of internal information by physical means. For example, an IC card with an anti-tamper function can be applied.
【0054】
Specifically, as shown in FIG. 7, the secure medium 40 includes a secure communication unit 41, a secure media control unit 42, a personal information management unit 43, a signature generation unit 44, and a signature verification unit 45.
【0055】
The secure communication unit 41 is provided between the secure media control unit 42 and the outside, and its main purpose is to authenticate an external communication partner, authenticate the communication content, and conceal the communication content, and exchange keys. It includes processing, communication partner authentication processing, data authentication processing, encryption / decryption processing, and the like. As the information for proving oneself in secure communication, a user certificate and a user private key managed by the personal information management unit 43 may be used.
【0056】
The secure media control unit 42 individually controls the personal information management unit 43, the signature generation unit 44, and the signature verification unit 45 based on the communication content received from the secure communication unit 41. Mainly, the secure communication unit When the verification result from the biometric authentication device 50, the signature data SD [verification result] and the device certificate are received from 41, the signature data SD [verification result] is verified by the signature verification unit 45 based on the device certificate. When the verification result of the signature verification unit 45 is "valid", the signature data SD [verification result] is signed by the signature generation unit 44 based on the user private key in the personal information management unit 43, and the signature generation unit 44 It has a function to send the obtained signature data SM [SD [verification result]], verification result, device certificate, and user certificate to the authentication server 10 as verification result-related data to the secure communication unit 41.
【0057】
The personal information management unit 43 manages the user private key, the user certificate, and the reference information so that they can be read / written from the secure media control unit 42. The user certificate is a public key certificate issued to the user by the user registration authority 1, and is digitally signed by the private key of the user registration authority 1. The user private key is a private key corresponding to the user certificate. Further, in order to reduce the burden of authentication processing, the public key certificate of the authentication server 10 or the public key certificate of the root certificate authority of the authentication server 10 may be stored.
【0058】
The signature generation unit 44 digitally signs the verification result by the biometric authentication device and the signature data SD [verification result] received from the secure media control unit 42 with the user private key corresponding to the user certificate. The double signature data SM [SD [verification result]] and the collation result are sent to the secure medium control unit 42.
【0059】
The signature verification unit 45 verifies the signature data SD [verification result] based on the verification result by the biometric authentication device received from the secure media control unit 42, the signature data SD [verification result], and the device certificate, and the verification result is obtained. When it is valid, the verification result "valid" for permitting the signature by the signature generation unit 44 is sent to the secure medium control unit 42.
【0060】
The biometric authentication device 50 is a module connected to the client device 20 and having a sensor function for reading biometric information such as fingerprints and irises from the living body and a function for collating the read biometric information with pre-registered biometric information. ..
【0061】
The biometric authentication device 50 has tamper resistance, and as shown in FIG. 8, the secure communication unit 51, the biometric authentication device control unit 52, the device information management unit 53, the reading unit 54, the collation unit 55, and the signature generation unit 56. It has.
【0062】
The biometric authentication device 50 is evaluated and certified by the certification authority 2 in accordance with the determined evaluation criteria, such as reading accuracy, verification accuracy evaluation such as false rejection rate and other person tolerance rate, and performance such as tamper resistance. The certified bio-authentication device 50 receives a device certificate (device public key certificate) for the bio-authentication device 50 as a proof of certification from the certification authority 2 and is issued by the device certification authority 3. The private key corresponding to (hereinafter referred to as the device private key) is stored in the secure area (device information management unit 53) of the biometric authentication device 50.
【0063】
The secure communication unit 51 has the main purpose of authenticating the communication partner, authenticating the communication content, and concealing the communication content, and is used for key exchange processing, communication partner authentication processing, data authentication processing, and encryption / decryption processing. Etc. are included. As information for proving oneself in secure communication, a device certificate and a device private key managed by the device information management unit 53 may be used.
【0064】
The biometric authentication device control unit 52 controls each of the functional units 51, 53 to 56 in the biometric authentication device 50, and mainly has a function of sending reference information received from the secure communication unit 51 to the collation unit 55. It also has a function of transmitting the verification result received from the signature generation unit 56, the signature data SD [verification result], and the device certificate to the secure medium 40 via the secure communication unit 51.
【0065】
The device information management unit 53 manages the device private key and, if necessary, the device certificate. That is, the device certificate may be managed in a repository such as an external directory server, if desired.
【0066】
As shown in FIG. 3, the device certificate is a public key certificate issued to the biometric authentication device 50, digitally signed with the private key of the device certificate authority 3, and is a device secret. The key is the private key corresponding to the device certificate.
【0067】
The reading unit 54 performs a process of reading the biological information and sends the read biological information to the collating unit.
【0068】
The collation unit 55 reads the reference information (biological information registered in advance in the secure medium 40) sent from the secure medium 40 and received from the biometric authentication device control unit 52, and the collation information (read) read by the reading unit 54. It operates by a biometric collation routine that collates biometric information or information obtained by subjecting the biometric information to a feature extraction process peculiar to a collation algorithm), and has a function of sending the collation result to the signature generation unit 56. The biological collation routine also performs processing specific to the collation algorithm, such as feature extraction processing, when it is required.
【0069】
The signature generation unit 56 digitally signs the verification result received from the verification unit 55 with the device private key corresponding to the device certificate of the device information management unit 53, and obtains the signature data SD [verification result] and verification. It has a function to send the result and the device certificate to the biometric authentication medium control unit 52.
【0070】
Next, the operation of the identity verification system configured as described above will be described.
【0071】
(Biometric device certification) As shown in FIG. 9, a vendor having a biometric device manufacturer (hereinafter referred to as a vendor) device 4 presents the biometric authentication device 50 or its specifications to the certification bureau 2 and presents the biometric device 50 or its specifications. Request biometric level certification for authentication device 50.
【0072】
The certification authority 2 performs certification based on this certification request, and provides the issuance request and the device certificate information to the device certification authority 3.
【0073】
The device certification authority 3 issues a device certificate based on the provided contents, and sends the device certificate to the vendor 4.
【0074】
When the vendor 4 stores the device certificate, the vendor 4 stores the device certificate in the device information management unit 53 of each biometric authentication device 50.
【0075】
(User initial registration) When the user receives the service using the identity verification system, the user performs the initial registration of the user to the user registration station 1.
【0076】
When the user registration station 1 receives a registration application from the user, it inquires about the user's identity (ST1), determines whether or not to allow the initial registration (ST2), and if not, returns to step ST1. , If the initial registration is permitted, the user certificate and user private key will be issued to the user (ST3). At this time, it is preferable to use a general PKI framework for the public key infrastructure of the user certificate.
【0077】
At the same time, when the user selects a biometric authentication method and collects biometric information by this biometric authentication method (ST4), the user presents the biometric information as reference information (ST5).
【0078】
Based on this presentation content, the user registration station 1 generates a biometric authentication compatible list showing the biometric authentication method corresponding to the reference information (ST6), and the issued user certificate and user private key, reference information, and biometrics. The authentication correspondence list is stored in the personal information management unit 53 of the secure medium 40 (ST7), and is also registered in the own station 1 to end the process.
【0079】
(Identity verification) The client device 20 accesses a service that requires user identity verification by a user operation. At this time, the authentication server 10 on the service side sends an identity verification request to the client device 20. Specifically, when the service-side authentication server 10 receives a service request from the client device 20, it establishes a connection with the authentication control program unit 22 of the client device 20 on another channel and notifies the client device 20 of the identity verification request. To do.
【0080】
The client device 20 calls the authentication control program unit 22 based on this identity verification request. The authentication control program unit 22 is always started or is started by calling a start program.
【0081】
As shown in FIG. 11, the authentication control program unit 22 displays a screen requesting the insertion of the secure medium 40 owned by the user (ST11), and confirms whether or not the secure medium 40 is inserted (ST12). ..
【0082】
When it is confirmed that the secure medium 40 is inserted, the authentication control program unit 22 starts the secure communication path construction process between the secure medium 40 and the authentication server 10 (ST13).
【0083】
The purpose of the secure communication path construction process here is to build a reliable communication path between the secure medium 40 and the authentication server 10. As a specific example, a method using a challenge-and-response method based on a public key cryptosystem for mutual authentication will be described, but the method is not limited to this, and other means may be used.
【0084】
The communication path is basically constructed by the secure communication units 41 and 11. Further, although it is assumed that the mutual public key certificates are held by each other, a payload for transmitting the certificate may be provided in the transmitted message and transmitted. Both the public key and the private key of the public key cryptosystem described here can be encrypted and decrypted.
【0085】
When the secure medium 40 receives the secure communication path construction process start message, it generates a random number challenge C1 and sends it to the authentication server 10.
【0086】
On the authentication server 10, challenge C1 is set to its own private key Sk.<sub>S</sub>Encrypts with and generates response R1.
【0087】
Authentication server 10 generates challenge C2, along with response R1 and the biometric level required by the service, as well as the user's public key (user certificate) Cert.<sub>U</sub>Encrypt with and send the encrypted data.
【0088】
The secure medium 40 uses this encrypted data as the user private key Sk.<sub>U</sub>Decrypt with to get response R1 and challenge C2. Response R1 is the public key of authentication server 10 Cert<sub>S</sub>If it is verified and judged to be valid, share Challenge C2 as a session key for data encryption.
【0089】
Similarly, an example in which the secure medium 40 generates a session key will be described. Upon receiving the secure communication path construction process start message, the secure medium 40 generates a random number challenge C1 and sends it to the authentication server 10.
【0090】
In the authentication server 10, the challenge C1 and the biometric authentication level required by the service are set to the private key Sk of the authentication server 10.<sub>S</sub>The response R1 is generated by encryption with the above, and the response R1 is transmitted to the secure medium 40.
【0091】
In the secure medium 40, the response R1 is set to the public key Cert of the authentication server 10.<sub>S</sub>If it is verified by and it is judged to be valid, generate challenge C3 and public key Cert of the server.<sub></sub><sub>S</sub>Encrypt with. User private key Sk on encrypted challenge C3', challenge C1 and response R1<sub>U</sub>Digitally sign with and send to authentication server 10 with the encrypted challenge C3'.
【0092】
The authentication server 10 verifies the digital signature, and if it determines that it is valid, decrypts the encrypted challenge C3'and obtains the challenge C3. Share Challenge C3 as a session key for data encryption.
【0093】
By the way, the authentication control program unit 22 performs the secure communication path construction process, determines whether or not the secure communication path is secured by judging that each other's communication partners are legitimate (ST14), and if not secured, processes. However, when it is secured, it receives a biometric authentication compatible list from the secure medium 40 (ST15).
【0094】
The biometric authentication selection unit 24 of the authentication control program unit 22 has the required biometric authentication level based on the biometric authentication level required from the service side and the biometric authentication connection device list as shown in FIG. 6 received from the secure medium 40. Select a biometric matching algorithm (hereinafter also referred to as a biometric matching routine) that satisfies the conditions (ST16). The population of the combination at this time is a usable biometric matching routine obtained from the intersection of the biometric level and the biometric connection device list.
【0095】
The biometric authentication level here refers to the overall performance level when a single biometric authentication device 50 or a combination of a plurality of biometric authentication devices 50 is used. The authority provided to the user can be controlled by the biometric authentication level required by this service. In other words, for services that require a high security level, it is possible to perform flexible identity verification such as requiring a higher biometric authentication level.
【0096】
At the time of this selection, the authentication control program unit 22 determines whether or not a combination of biometric matching routines that can satisfy the biometric authentication level can be determined (ST17), and if it cannot be determined, the process ends, but can be determined. Occasionally, the secure medium 40 is notified of this determined biometric routine.
【0097】
The secure medium 40 determines the biometric authentication device 50 from this biometric matching algorithm, and shifts to the matching process by this device 50.
【0098】
At the start of the collation process, as shown in FIG. 12, the secure medium 40 directly constructs a secure communication path with the biometric authentication device 50 via the authentication control program unit 22 (ST21).
【0099】
The secure communication path here is intended to protect the transmission path between the device 50 and the medium 40 and to mutually authenticate that the device of the communication partner is legitimate. As an example of a specific secure communication path construction process, a method in which the secure medium 40 and the biometric authentication device 50 are performed by using the public key (public key certificate) and the private key of the public key cryptography that are mutually owned. is there.
【0100】
The biometric device 50 transmits the device certificate to the secure medium 40. The secure medium 40 verifies the device certificate, and if it is valid, generates an encryption key (session key) of the common key encryption method and encrypts it with the device certificate.
【0101】
At this time, the digital signature is digitally signed with the private key corresponding to the user certificate stored in the secure medium 40, and the digital signature is transmitted to the biometric authentication device 50 together with the user certificate.
【0102】
The biometric device 50 verifies the user certificate and digital signature and decrypts the encrypted session key. Data encryption for secure communication is performed using this session key.
【0103】
At this time, it is desirable that the secure medium 40 and the biometric authentication device 50 store the public key certificate of the organization (root certificate authority, device certificate authority 3, etc.) that authenticates each other's public key certificate in advance. Any means may be separately obtained from a repository or the like. The communication between the secure medium 40 and the biometric authentication device 50 is performed via the authentication control program unit 22, but the communication path is omitted in FIG. 1 for the convenience of the drawing.
【0104】
The secure medium 40 transmits reference information to the biometric authentication device 50 when the secure communication path is established (ST22).
【0105】
When the biometric authentication device 50 receives the reference information, the biometric authentication device 50 notifies the authentication control program unit 22 to display a screen prompting the user to present the biometric information.
【0106】
Specifically, in the case of fingerprint verification, a message such as "Please put your finger on the reading unit" is displayed on the screen. To confirm that the preparation for presenting biological information is completed, confirm by means such as inputting the return key or pressing the OK button on the screen.
【0107】
After confirming that the biometric authentication device 50 is ready to present the biometric information, the biometric authentication device 50 reads the biometric information by the reading unit 54 and passes the read biometric information to the collating unit 55. The collation unit collates the collation information with the received reference information (ST23).
【0108】
The collation unit 55 determines the match / mismatch between the two (ST24), and when the two match, digitally signs the collation result valid (OK) with the device private key (ST25), and obtains the signature data SD [ Verification result], the verification result and the device certificate are transmitted to the secure medium 40. On the other hand, the collation unit 55 cancels the authentication process when the two do not match as a result of step ST24.
【0109】
If necessary, the secure medium 40 and the authentication control program unit 22 are notified of the authentication failure as identity verification information, and a message such as "authentication failed" is displayed on the screen. In addition, as an example of the screen display items at this time, information on whether the verification is successful or unsuccessful (the verification reliability by percentage etc. may be included), the biometric authentication method used (including the biometric authentication device 50), and the use. Examples include the biometric authentication level of the biometric authentication method (comprehensive level when multiple uses are used).
【0110】
The secure medium 40 verifies the signature data SD [verification result], and if it is valid, digitally signs it with the user private key, and the obtained signature data SM [SD [verification result] is subjected to the verification result and the device certificate. And the data related to the verification result with the user certificate attached is transmitted to the authentication control program unit 22.
【0111】
The authentication control program unit 22 transmits this collation result-related data to the authentication server 10. Here, since the collation result-related data is encrypted by the shared session key, it is difficult for anyone other than the secure medium 40 and the authentication server 10 to know the contents.
【0112】
In the authentication server 10, the certificate verification unit 13 applies the collation result-related data (device certificate, user certificate, SM [SD [verification result]]) received from the client device 20 via the network and communication unit 11. On the other hand, the validity of each certificate is verified with reference to the user registration authority 1 and the device certification authority 3, and when the verification result is valid, the verification-related data is sent to the level verification unit 14.
【0113】
The level collation unit 14 collates the evaluation result data (and / or the evaluation standard data) of the device certificate with the level request received from the request response unit 12 among the collation result related data, and the evaluation result data is the level request. When the condition is satisfied, the collation result related data is sent to the result verification unit 15.
【0114】
The result verification unit 15 verifies the signature data SM [SD [verification result]] among the collation result-related data based on each certificate, and verifies the validity of the collation result. Here, if the collation result is valid, the identity verification is completed, and the service side provides the service to the client device 20.
【0115】
(Addition of biometric authentication device) When adding / deleting the biometric authentication device 50, the biometric authentication device addition / deletion unit 25 adds / deletes the corresponding content on the biometric authentication device connection list. At the time of addition, the device certificate sent from the additionally connected biometric authentication device 50 is verified, and when it is valid, the corresponding data is added to the biometric authentication device connection list. When deleting, the corresponding data is deleted from the biometric device connection list.
【0116】
As described above, according to the present embodiment, since the double digital signature of the biometric authentication device 50 and the secure medium 40 is given to the verification result by the biometric authentication method, the reliability of the biometric authentication is guaranteed. Identity verification can be performed over the network.
【0117】
That is, it is possible to guarantee the validity of the result of the biometric authentication verification process or the read process in a remote place via the network and that the result was performed in a safe environment, and the problem considered by the present inventor (a). Can be solved.
【0118】
Further, since the authentication server 10 notifies the client device of the biometric authentication level required by the service, the obtained verification result is the biometric authentication level required by the service side (the verification accuracy of the biometric authentication method, the strength of tamper resistance, etc.). ) Can be guaranteed, and the problem (b) considered by the present inventor can be solved.
【0119】
However, the configuration for notifying the biological requirement level is not essential, and it is only necessary to finally confirm that the biological requirement level is satisfied. For example, the biometric authentication device 50 having the highest biometric authentication level is selected on the client device 20 side, the verification result related data is sent to the authentication server 10, and the biometric authentication level is confirmed by referring to the device certificate on the authentication server 10 side. It may be configured to be used.
【0120】
In addition, when a plurality of biometric authentication devices 50 are connected, the biometric authentication selection unit 24 adds the biometric authentication evaluation data described in the device certificate of each biometric authentication device 50 to the authentication device connection list created. Based on this, the biometric authentication method or biometric device 50 that satisfies the required level is selected. Therefore, the appropriate biometric authentication method or biometric authentication device 50 is selected from a plurality of biometric authentication devices 50 without fixing the biometric authentication method to be used. can do.
【0121】
That is, the user or the system itself can select a free biometric authentication method as long as the biometric authentication level required by the authentication server 10 or the service using the identity verification system is satisfied without fixing the biometric authentication method to be used. Therefore, the problem (c) considered by the present inventor can be solved.
【0122】
In addition, the biometric device addition / deletion unit 25 dynamically changes the contents of the authentication device connection list so that when a new biometric device 50'is connected to the client device 20, the biometric authentication device 50' is added. Therefore, a new biometric authentication device can be easily and surely added.
【0123】
Thereby, for example, even when a new collation algorithm or biometric authentication device is newly updated, the collation algorithm or biometric authentication device can be easily added and / or discarded.
【0124】
Further, in the case of the composite biometric authentication system, since a plurality of biometric authentication methods are handled, it is necessary to register a plurality of biometric information such as fingerprint information, face information, and voice information in advance. For example, these can be easily registered.
【0125】
Further, even if the same biometric authentication method is used, since there are multiple types of matching algorithms, there are also multiple types of biometric information formats to be used (for example, even if the same fingerprint is used, different fingerprint information can be used between different matching algorithms. However, according to the biometric device addition / deletion unit 25, these can be easily registered.
【0126】
In addition, when any one of multiple types of biometric authentication methods is arbitrarily selected, whether or not the required level of the security policy is satisfied may change depending on the selected method, and the conventional identity verification service has a problem (a). ), It is extremely difficult to know whether or not the required level is satisfied, but according to the present embodiment, as described above, biometric authentication verification processing or biometric authentication verification processing is performed at a remote location via a network. It is possible to guarantee the correctness of the read-processed result and that it was performed in a safe environment.
【0127】
Further, since the user registration authority 1 and the device authentication authority 3 are provided, an authentication infrastructure that can be commonly used by each user can be realized, so that the problem (d) considered by the present inventor can be solved. Furthermore, since the authentication infrastructure is divided into two, the user registration authority 1 for the user and the device authentication authority 3 for the biometric authentication device 50, it can be realized without imposing an excessive burden on one station.
【0128】
Note that this embodiment is not limited to the configuration described above, and may be modified to a configuration in which the secure medium 40 is omitted and only the processing result of the biometric authentication device 50 is transmitted to the authentication server 10. In this case, the authentication server 10 guarantees only the biometric information read by the biometric authentication device 50 or the information (verification information) extracted from the biometric information.
【0129】
(Second Embodiment) FIG. 13 is a schematic diagram showing the configuration of the identity verification system according to the second embodiment of the present invention, and FIG. 14 is a schematic diagram showing the biometric authentication device of the system and its peripheral configuration. FIG. 15 is a schematic diagram showing the biometric verification server of the system and its peripheral configuration. The same parts as those in the above-mentioned drawings are designated by the same reference numerals, and detailed description thereof will be omitted. Mainly described. In each of the following embodiments, the description of the overlapping portion will be omitted in the same manner.
【0130】
That is, this embodiment is a modification of the first embodiment, and is intended to be applied to a biometric authentication device as a reading device having no collation function. Specifically, as shown in FIG. It includes a biometric authentication device 50a in which the collation unit 55 is omitted, and a biometric verification server 60 that is connected to the client device 20a and has a collation unit.
【0131】
Here, in the case of fingerprint authentication, for example, the biometric authentication device 50a is compatible with a reading device that has a reading unit 54 such as a fingerprint sensor (capacitive type, optical reading type, etc.) but does not have a collation function.
【0132】
As shown in FIG. 15, the biometric verification server 60 includes a secure communication unit 61, a user information management unit 62, a signature verification unit 63, a verification unit 64, and a signature generation unit 65.
【0133】
The secure communication unit 61 has a function of constructing a secure communication path with the secure medium 40 via the authentication control program unit 22 and performing secure communication with the secure medium 40.
【0134】
The user information management unit 62 stores a user certificate, a device certificate, a biometric verification server certificate, a biometric verification server private key, and reference information in advance. The reference information may not be managed by the user information management unit 62, but may be managed by the personal information management unit of the secure medium 40 as described above.
【0135】
When the signature verification unit 63 receives the signature data SM [SD [biological information]], biometric information, device certificate and user certificate from the secure medium 40 from the secure communication unit 61, the signature verification unit 63 refers to the user information management unit 62. , The function to verify the device certificate and the user certificate, and if it is valid, to verify the signature data SM [SD [biological information]] based on each certificate, and if the verification result is valid, the living body It has a function to send information to the collation unit 64.
【0136】
The collation unit 64 collates the biometric information received from the signature verification unit 63 with the reference information in the user information management unit 62, and if they match, the collation result "valid" is sent to the signature generation unit 65. Have. The collation unit 64 includes a plurality of bio-verification routines, and can select a collation routine corresponding to the contents of the device certificate.
【0137】
The signature generation unit 65 signs the collation result received from the collation unit 64 with the bio-verification server private key in the user information management unit 62, and the obtained signature data SS [verification result], the collation result and the bio-verification server certificate. Has a function of sending to the authentication control program unit 22 via the secure communication unit 61.
【0138】
Next, the operation of the identity verification system configured as described above will be described. (User initial registration) The initial registration of the user is the same as described above, but the reference information of the user is stored in the biometric verification server 60 or the secure medium 40.
【0139】
(Identity verification) The process up to the start of biometric authentication is the same as described above, and the procedure after the biometric information reading process will be described below as a different procedure.
【0140】
The biometric authentication device 50a digitally signs the read biometric information with the device private key, and transmits the obtained signature data SD [biometric information], biometric information, and device certificate to the secure medium 40. At this time, if necessary, processing (feature extraction, etc.) peculiar to the biometric matching routine may be performed.
【0141】
The secure medium 40 digitally signs the received signature data SD [biological information] with the user's private key, and then obtains the signature data SM [SD [biological information]], biometric information, user certificate, and device certification. The document is transmitted to the biometric verification server via the authentication control program unit 22. At this time, if necessary, the biological information may be encrypted.
【0142】
In the biometric verification server 60, as shown in FIG. 16, the signature verification unit 63 transfers the signature data SM [SD [biological information]], biometric information, device certificate, and user certificate from the secure medium 40 to the secure communication unit. Upon receiving from 61, the device certificate and the user certificate are verified with reference to the user information management unit 62, and if valid, the signature data SM [SD [biological information]] is obtained based on each certificate. Verify (ST31).
【0143】
Here, the signature verification unit 63 determines whether or not the signature is valid (OK) (ST32), and if the verification result is not valid (NG), rejects the verification process and ends the process. If the result is valid, the biometric information is sent to the collating unit 64.
【0144】
The collation unit 64 collates this biometric information with the reference information in the user information management unit 62, and if both match, sends a collation result "valid" to the signature generation unit 65.
【0145】
The signature generation unit 65 signs this verification result with the bio-verification server private key in the user information management unit 62, and obtains the signature data SS [verification result], the collation result, and the bio-verification server certificate in the secure communication unit 61. Is sent to the authentication control program unit 22 via.
【0146】
The authentication control program unit 22 transmits the signature data SS [verification result], the verification result, and the bio-verification server certificate to the authentication server 10. However, the authentication control program unit 22 transmits these data to the secure medium 40, and the signature data SM [SS [verification result]], the verification result, the bio-verification server certificate, and the user via the signature processing of the secure medium 40. It may be sent to the authentication server 10 as a certificate.
【0147】
In the authentication server 10, the certificate verification unit 13, the level verification unit 14, and the result verification unit 15 each confirm the contents received from the client device 20 in the same manner as described above.
【0148】
As described above, according to the present embodiment, even when the biometric authentication device 50a having no collation function is provided, the same effect as that of the first embodiment can be obtained.
【0149】
Supplementally, in the current biometric authentication, an application having a collation function is often placed in a client device 20 such as a personal computer, and the collation process is performed in the client device 20.
【0150】
However, it is difficult to guarantee that the inside of the client device 20 is a safe environment. Therefore, arranging a collation function using reference information such as a fingerprint template on the client device 20 is anxious in terms of security.
【0151】
Therefore, as a modification of the first embodiment, it is important to realize an identity verification system using a biometric authentication device 50a as a reading device and a biometric verification server 60) having a verification function installed outside the client device 20. There is.
【0152】
(Third Embodiment) FIG. 17 is a schematic diagram showing a configuration of an identity verification system according to a third embodiment of the present invention, and FIG. 18 is a schematic diagram showing a client device of the system and its peripheral configuration. ..
【0153】
That is, the present embodiment is a modification of the first embodiment, and the biomatching routine can be dynamically acquired even if there is no usable biomatching routine, and specifically, authentication. It includes a bio-verification routine acquisition unit 26 added to the control program unit 22b and a bio-verification routine DB (database) 70 connected to the client device 20b.
【0154】
Here, the biometric verification routine acquisition unit 26 acquires the biometric verification routine from the biometric verification routine DB based on the acquisition request from the biometric authentication selection unit 24, and controls the communication data of this biometric verification routine to the biometric authentication device 50. It can be sent to unit 23.
【0155】
The biometric verification routine DB70 stores a plurality of biometric verification routines in advance, and search conditions (eg, information of each biometric authentication device 50, data format and data type of reference information) notified from the biometric verification routine acquisition unit 26. , Biometric authentication level), it has a function to send a biometric verification routine that matches the search conditions to the biometric verification routine acquisition unit 26.
【0156】
However, the biometric authentication device 50 describes the biometric verification routine that can be used by its own verification unit 55 in the extended field of the device certificate at the time of certification by the certification authority 2. For example, it is preferable that the biological collation routine has a rule that it is categorized in advance by the target biological information, unique feature extraction processing, etc., and can be identified by the collation routine ID or the like.
【0157】
Next, the operation of the identity verification system configured as described above will be described. (Acquisition of biometric verification routine) As shown in FIG. 19, the above-mentioned steps ST11 to ST16 operate in the same manner. Subsequently, in step ST17b, the client device 20 does not have a combination that can satisfy the biometric authentication level required by the service when the biometric authentication selection unit 24 of the authentication control program unit 22 selects the biometric verification routine. If it is determined, an acquisition request is sent to the biometric verification routine acquisition unit 26 (ST18).
【0158】
In response to this acquisition request, the biometric verification routine acquisition unit 26 requests the information of each biometric authentication device 50 connected to the client device 20b, the data format and data type of the reference information stored in the secure medium 40, and the like. The biometric authentication level to be performed is notified to the biometric verification routine DB70, and the biometric verification routine that matches the conditions is acquired from the biometric verification routine DB70.
【0159】
The acquired biometric matching routine is sent to the corresponding biometric device 50. If necessary, the transmitted biometric verification routine may be digitally signed by the biometric verification routine DB70 or the like and verified by the biometric authentication device 50 or the authentication control program unit 22. In this case, the root CA public key certificate (or the public key itself) of the public key certificate of the biometric verification routine DB70 may be incorporated into the biometric authentication device 50 at the time of certification.
【0160】
As described above, according to the present embodiment, in addition to the effect of the first embodiment, the biomatching routine acquisition unit 26 dynamically performs the biomatching routine from the biomatching routine DB70 even when there is no biomatching routine available. Can be obtained in.
【0161】
Note that this embodiment is not limited to the modified example of the first embodiment, and may be a modified example of the second embodiment. In this case, the processing procedure may follow the processing procedure described in the second and third embodiments.
【0162】
(Fourth Embodiment) FIG. 20 is a schematic diagram showing a configuration of an identity verification guarantee base applied to the identity verification system according to the fourth embodiment of the present invention.
【0163】
That is, this embodiment is a modification of the first to third embodiments, and instead of the simple configuration of the certification authority 2 and the device certification authority 3, the certification authority 5 and the vendor (biometric authentication device manufacturer) 4c It has an identity verification guarantee base with a hierarchical structure of.
【0164】
Here, the accreditation body 5 includes an accreditation authority 2c and a vendor certification authority 6.
【0165】
The certification authority 2c has a function of sending an issuance request to the vendor certification authority 5 when the vendor 4c and the biometric authentication device 50 are certified by the request from the vendor 4c.
【0166】
The vendor certificate authority 6 has a function of issuing a vendor certificate (vendor's public key certificate) to the vendor 4c based on the issuance request received from the certificate authority 2c.
【0167】
The vendor 4c is equipped with a device certificate authority 3c. The device certificate authority 3c issues a device certificate to the biometric authentication device 50,50a based on the vendor certificate issued by the vendor certificate authority 6, and stores this device certificate in the biometric authentication device 50,50a. Has a function to do.
【0168】
Next, the operation of the identity verification guarantee board configured as described above will be described. Vendor 4c requires the Certificate Authority 2c to issue a vendor certificate. The certificate authority 2c determines whether the vendor certificate can be issued to the vendor 4c. The judgment criteria depend on the policy in the operation of the certificate authority 2c and are not specified in this embodiment.
【0169】
If the accreditation authority 2c determines that the vendor certificate can be issued, it requests the vendor certificate authority 6 to issue the vendor certificate. At this time, the necessary information of the vendor 4c (the information described in the general public key certificate may be used) is provided.
【0170】
Vendor Certificate Authority 6 issues a vendor certificate to Vendor 4c. Each item to be described is attached to the public key generated by the vendor certificate authority 6, and digitally signed with the public key certificate of the vendor certificate authority 6. Here, it is preferable that each item of the vendor certificate conforms to the field item defined in the X.509 certificate, but if there is a necessary item, an extended item may be added.
【0171】
The vendor 4c evaluates the biometric authentication device 50 manufactured by itself in accordance with the certification criteria of the certification authority 2c as described above, and issues a device certificate from the device certification authority 3c operated by the vendor 4c. However, the device certificate authority 3c may be an external component of the vendor 4c as long as it is trusted by the vendor 4c.
【0172】
The device certificate is similar to that shown in Figure 3, but is digitally signed by the vendor certificate. That is, in the trust hierarchy of the certification authority of the device certificate, the certification authority 2c is the highest, and the vendor certification authority 6 is next.
【0173】
Vendor 4c stores the issued device certificate in the biometric authentication device 50 that manufactured it. The device certificate issued at this time may be submitted to the certification authority 2c.
【0174】
The certificate authority 2c periodically audits the reliability of the vendor 4c by verifying the device certificate stored in the biometric device 50.
【0175】
At this time, as the verification target of the device certificate, the validity of the certificate itself and the items described in the device certificate are verified as in the first embodiment. The verification of the described items is performed by actually evaluating and verifying the consistency between the evaluation result of the biometric authentication device 50 described in the device certificate and the actual biometric authentication device 50.
【0176】
If it is determined to be fraudulent, the certificate authority 2c will revoked the device certificate and vendor certificate. That is, the certificate authority 2c lists the device certificate and the vendor certificate on the revocation list (CRL, ARL (Authority Revocation List), etc.). Also, when a certificate revocation request is presented by the authentication server 10 or the like, the same processing is performed.
【0177】
As described above, according to the present embodiment, even when the identity verification guarantee base having a hierarchical structure of the accreditation body 5 and the vendor 4c is provided, the effects of the first to third embodiments can be obtained. it can.
【0178】
The method described in each of the above embodiments is a program that can be executed by a computer, such as a magnetic disk (floppy (registered trademark) disk, hard disk, etc.), an optical disk (CD-ROM, DVD, etc.), a magneto-optical disk ( It can also be stored and distributed in a storage medium such as MO) or semiconductor memory.
【0179】
Further, the storage medium may be in any form as long as it is a storage medium capable of storing a program and readable by a computer.
【0180】
In addition, in order for the OS (operating system) running on the computer, database management software, network software, and other MW (middleware) based on the instructions of the program installed on the computer from the storage medium to realize this embodiment. You may execute a part of each process of.
【0181】
Further, the storage medium in the present invention is not limited to a medium independent of a computer, but also includes a storage medium in which a program transmitted by a LAN, the Internet, or the like is downloaded and stored or temporarily stored.
【0182】
Further, the storage medium is not limited to one, and the case where the processing in the present embodiment is executed from a plurality of media is also included in the storage medium in the present invention, and the medium configuration may be any configuration.
【0183】
The computer in the present invention executes each process according to the present embodiment based on a program stored in a storage medium, and is a system in which one device such as a personal computer and a plurality of devices are connected to a network. Any configuration such as the above may be used.
【0184】
Further, the computer in the present invention is not limited to a personal computer, but also includes an arithmetic processing unit, a microcomputer, and the like included in an information processing device, and is a general term for devices and devices capable of realizing the functions of the present invention by a program. ..
【0185】
The invention of the present application is not limited to each of the above embodiments, and can be variously modified at the implementation stage without departing from the gist thereof. In addition, each embodiment may be carried out in combination as appropriate as possible, in which case the combined effect can be obtained. Further, each of the above embodiments includes inventions at various stages, and various inventions can be extracted by an appropriate combination in a plurality of disclosed constitutional requirements. For example, when an invention is extracted by omitting some constituent requirements from all the constituent requirements shown in the embodiment, the omitted portion is appropriately supplemented by a well-known conventional technique when the extracted invention is carried out. It is something that is said.
【0186】
In addition, the present invention can be implemented in various modifications without departing from the gist thereof.
【0187】
[Effect of the invention]
As described above, according to the present invention, identity verification can be performed via a network while guaranteeing the reliability of biometric authentication.
[Simple explanation of drawings]
[Figure 1]
Schematic diagram showing the configuration of the identity verification system according to the first embodiment of the present invention. [Figure 2]
Schematic diagram for explaining reference information in the same embodiment [Fig. 3]
Schematic diagram for explaining the device certificate in the same embodiment [Fig. 4]
Schematic diagram showing the authentication server and its peripheral configuration in the same embodiment [Fig. 5]
Schematic diagram showing the client device and its peripheral configuration in the same embodiment [Fig. 6]
Schematic diagram for explaining the biometric device connection list in the same embodiment [Fig. 7]
Schematic diagram showing the secure medium and its peripheral configuration in the same embodiment [Fig. 8]
Schematic diagram showing the biometric authentication device and its peripheral configuration in the same embodiment [Fig. 9]
Schematic diagram for explaining the authentication operation of the biometric authentication device in the same embodiment [Fig. 10]
Flow chart for explaining user initial registration operation in the same embodiment [Fig. 11]
Flow chart for explaining the identity verification operation in the same embodiment [Fig. 12]
Flow chart for explaining the identity verification operation in the same embodiment [Fig. 13]
Schematic diagram showing the configuration of the identity verification system according to the second embodiment of the present invention. [Fig. 14]
Schematic diagram showing the biometric authentication device and its peripheral configuration in the same embodiment [Fig. 15]
Schematic diagram showing the biological verification server and its peripheral configuration in the same embodiment [Fig. 16]
Flow chart for explaining the operation in the same embodiment [Fig. 17]
Schematic diagram showing the configuration of the identity verification system according to the third embodiment of the present invention. [Fig. 18]
Schematic diagram showing the client device and its peripheral configuration in the same embodiment [Fig. 19]
Flow chart for explaining the collation routine acquisition operation in the same embodiment [Fig. 20]
Schematic diagram showing the configuration of the identity verification guarantee base applied to the identity verification system according to the fourth embodiment of the present invention. [Explanation of symbols]
1 ... User Registration Bureau 2 ... Certificate Authority 3,3c ... Device Certificate Authority 4, 4c ... Vendor 5 ... Vendor Certificate Authority 10 ... Authentication server 11,21 ... Communication Department 12 ... Request response section 13 ... Certificate Verification Department 14 ... Level collation 15 ... Result verification department 20,20a, 20b ... Client device 22 ... Authentication Control Program Department 23 ... Communication data control unit 24 ... Biometric selection section 25 ... Biometric device addition / deletion part 26 ... Bio-verification routine acquisition section 30 ... Media reader 40 ... Secure media 41,51,61 ... Secure Communication Department 42 ... Secure media control unit 43 ... Personal Information Management Department 44,56,65 ... Signature generator 45,63 ... Signature Verification Department 50,50a ... Biometric device 52 ... Biometric device control unit 53 ... Equipment Information Management Department 54 ... Reader 55,64 ... collation 60 ... Bio-verification server 62 ... User Information Management Department 70 ... Biomatching routine DB
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US8793499B2 | Cited by | United States of America | Applicant |
| US10366218B2 | Cited by | United States of America | Applicant |
| JP2014174560A | Cited by | Japan | Search report |
| JP2021519966A | Cited by | Japan | Search report |
| JP4859917B2 | Cited by | Japan | Examiner |
| US11929997B2 | Cited by | United States of America | Applicant |
| JP2012003648A | Cited by | Japan | Examiner |
| JP2012003648A | Cited by | Japan | Search report |
| JP2006011768A | Cited by | Japan | Examiner |
| JP2014211677A | Cited by | Japan | Search report |
| US11831409B2 | Cited by | United States of America | Applicant |
| JP2019012365A | Cited by | Japan | Search report |
| US7817825B2 | Cited by | United States of America | Applicant |
| JP2006197127A | Cited by | Japan | Examiner |
| US10282533B2 | Cited by | United States of America | Applicant |
| US10142114B2 | Cited by | United States of America | Applicant |
| US9122895B2 | Cited by | United States of America | Applicant |
| US10776464B2 | Cited by | United States of America | Applicant |
| US11265315B2 | Cited by | United States of America | Applicant |
| WO2007111234A1 | Cited by | World Intellectual Property Organization (WIPO) | Applicant |
| JP2007505420A | Cited by | Japan | Search report |
| US10637853B2 | Cited by | United States of America | Applicant |
| JP2007524275A | Cited by | Japan | Examiner |
| US10268811B2 | Cited by | United States of America | Applicant |
| JP2016502373A | Cited by | Japan | Search report |
| US10270748B2 | Cited by | United States of America | Applicant |
| JP2014211677A | Cited by | Japan | Search report |
| US11792024B2 | Cited by | United States of America | Applicant |
| US10404754B2 | Cited by | United States of America | Applicant |
| US8230483B2 | Cited by | United States of America | Applicant |
| US11868995B2 | Cited by | United States of America | Applicant |
| JP2008538628A | Cited by | Japan | Search report |
| JP2006129143A | Cited by | Japan | Examiner |
| US10237070B2 | Cited by | United States of America | Applicant |
| US10326761B2 | Cited by | United States of America | Applicant |
| JP2009169517A | Cited by | Japan | Search report |
| US10091195B2 | Cited by | United States of America | Applicant |
| JP2015529910A | Cited by | Japan | Search report |
| JP2018201235A | Cited by | Japan | Search report |
| JP2007172431A | Cited by | Japan | Search report |
| US8312521B2 | Cited by | United States of America | Applicant |
| US10762181B2 | Cited by | United States of America | Applicant |
| JP2019062281A | Cited by | Japan | Search report |
| JP2011526028A | Cited by | Japan | Search report |
| US10798087B2 | Cited by | United States of America | Applicant |
| US9112705B2 | Cited by | United States of America | Applicant |
| US10659457B2 | Cited by | United States of America | Applicant |
| EP3312750A1 | Cited by | European Patent Office (EPO) | Applicant |
| JP2016502373A | Cited by | Japan | Search report |
| JP2011209940A | Cited by | Japan | Search report |
| JP2014211677A | Cited by | Japan | Search report |
| US10366254B2 | Cited by | United States of America | Applicant |
| US10769635B2 | Cited by | United States of America | Applicant |
| US11042615B2 | Cited by | United States of America | Applicant |
| JP2013519176A | Cited by | Japan | Search report |
| JP2014211677A | Cited by | Japan | Search report |
| US7770207B2 | Cited by | United States of America | Applicant |
| US11816195B2 | Cited by | United States of America | Search report |
| EP3282737A1 | Cited by | European Patent Office (EPO) | Applicant |
| US10706132B2 | Cited by | United States of America | Applicant |
| JP2009043037A | Cited by | Japan | Search report |
| US10176310B2 | Cited by | United States of America | Applicant |
| JP2014174560A | Cited by | Japan | Search report |
2 priority claims, no other members on record
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 2001333432 | Japan | A | |
| JP20010333432 | – | – | – |
12 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of completion of termEXPY | EXPY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Written notification of patent or utility model registrationR151 | R151 | |
| First payment of annual fees (during grant procedure)A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedA521 | A521 | |
| Notification of reasons for refusalA131 | A131 | |
| Written request for application examinationA621 | A621 |
Numbers
- Publication
- 2003-143136
- Publication, DOCDB
- 2003143136
- Publication, EPODOC
- JP2003143136
- Application
- 333432
- Application, DOCDB
- 2001333432
- Application, EPODOC
- JP20010333432
Titles2
- Japanese
- 【発明の名称】本人確認システム及び装置
- English
- [Title of Invention] Identity Verification System and Device
Classification
- IPC, 5
- G06F15 00
- G06F21 32
- G06F21 34
- G06F21 44
- H04L9 32