Nova Patents
JP2003143136A

Identification system and apparatus

Abstract

Problem to be solved.To carry out identification via a network while ensuring the reliability of the authentication of a living body.

Solution.With respect to the result of collation by a living body authentication system, collation related data imparted with double digital signatures of a living body authentication device 50 and a secure medium 40 are transmitted to an authentication server 10 via the network.

JP2003143136A, drawing sheet 1
Sheet 1 of 5

Term

Term ended

Projected expiry passed 30 October 2021, 4.9 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

9 claims: 6 independent, 3 dependent

  1. 1
    [Claims] [Claim 1] An identity verification system for confirming the identity of a user by a biometric authentication method. For each user, a user registration authority for issuing user certificates and user private keys based on public key cryptography, and For each biometric device, a device certificate authority for issuing device certificates and device private keys based on public key cryptography, and The device certificate and device private key issued by the device certification authority are stored in advance, and when it is confirmed that the user is the person by a predetermined biometric authentication method, the device secret is obtained with respect to the obtained personal identification information. A biometric authentication device that attaches the first digital signature with a key and the device certificate and sends it, When the user certificate and user private key issued by the user registration authority are stored in advance and the identity verification information, the first digital signature, and the device certificate transmitted from the biometric authentication device are received, the first digital is received. A user signature device that performs signature processing with the user private key on the signature and transmits the obtained second digital signature, the identity verification information, the device certificate, and the user certificate. A client device having a medium holding unit that detachably holds the user signature device and connected to the biometric authentication device, and a client device. When the client device is connected to the client device via a network and receives the second digital signature, identity verification information, device certificate, and user certificate transmitted from the user signing device, the user registration authority and the device certification authority are referred to. While verifying the user certificate and the device certificate, or verifying the second digital signature, and when the verification results of each certificate and the second digital signature are valid, the identity verification information is obtained. Authentication device to authenticate and An identity verification system characterized by being equipped with. 【特許請求の範囲】 【請求項1】 生体認証方式により、ユーザが本人である旨を確認するための本人確認システムであって、 各ユーザ毎に、公開鍵暗号方式に基づくユーザ証明書及びユーザ秘密鍵を発行するためのユーザ登録局と、 各生体認証機器毎に、公開鍵暗号方式に基づく機器証明書及び機器秘密鍵を発行するための機器認証局と、 前記機器認証局により発行された機器証明書及び機器秘密鍵が予め格納され、所定の生体認証方式により前記ユーザが本人である旨を確認したとき、得られた本人確認情報に対して前記機器秘密鍵による第1デジタル署名と前記機器証明書とを付与して送信する生体認証機器と、 前記ユーザ登録局により発行されたユーザ証明書及びユーザ秘密鍵が予め格納され、前記生体認証機器から送信された本人確認情報、前記第1デジタル署名及び前記機器証明書を受信すると、この第1デジタル署名に対して前記ユーザ秘密鍵による署名処理を施し、得られた第2デジタル署名、前記本人確認情報、前記機器証明書及び前記ユーザ証明書を送信するユーザ署名装置と、 前記ユーザ署名装置を着脱自在に保持する媒体保持部を有し、前記生体認証機器に接続されたクライアント装置と、 前記クライアント装置にネットワークを介して接続され、前記ユーザ署名装置から送信された第2デジタル署名、本人確認情報、機器証明書及びユーザ証明書を受信すると、前記ユーザ登録局及び前記機器認証局を参照しながら前記ユーザ証明書及び前記機器証明書を検証し、又は前記第2デジタル署名を検証し、前記各証明書と前記第2デジタル署名との検証結果がそれぞれ正当のとき、前記本人確認情報を認証する認証装置と、 を備えたことを特徴とする本人確認システム。
  2. 5
    A biometric authentication device that attaches a first digital signature to the identity verification information that confirms the identity of the user by a biometric authentication method and sends it together with a device certificate, and a biometric authentication device for confirming the identity verification information. It is used in an identity verification system including an authentication device and a client device for transmitting the identity verification information obtained by the biometric authentication device to the authentication device via a network, and is attached to and detached from a medium holding portion of the client device. It is a user signature device that can be freely held. A user information storage means in which a user certificate and a user private key based on a public key cryptosystem are stored in advance, and A receiving means for receiving the identity verification information transmitted from the biometric authentication device, the first digital signature, and the device certificate. A signature verification means for verifying the first digital signature received by the receiving means based on the device certificate, and When the verification result by the signature verification means is valid, the signature generation means for performing the signature processing by the user private key in the user information storage means for the first digital signature, and the signature generation means. A transmission means for transmitting the second digital signature obtained by the signature generation means, the identity verification information, the device certificate, and the user certificate into the client device, and A user signature device characterized by being equipped with. 【請求項5】 生体認証方式によりユーザが本人である旨を確認する本人確認情報に第1デジタル署名を付与して機器証明書と共に送出する生体認証機器と、前記本人確認情報を確認するための認証装置と、前記生体認証機器により得られた本人確認情報をネットワークを介して前記認証装置に送信するためのクライアント装置とを備えた本人確認システムに用いられ、前記クライアント装置の媒体保持部に着脱自在に保持されるユーザ署名装置であって、 予め公開鍵暗号方式に基づくユーザ証明書及びユーザ秘密鍵が格納されたユーザ情報格納手段と、 前記生体認証機器から送信された本人確認情報、前記第1デジタル署名及び前記機器証明書を受信する受信手段と、 前記受信手段により受信された第1デジタル署名を前記機器証明書に基づいて検証する署名検証手段と、 前記署名検証手段による検証結果が正当のとき、この第1デジタル署名に対して前記ユーザ情報格納手段内のユーザ秘密鍵による署名処理を施す署名生成手段と、 前記署名生成手段により得られた第2デジタル署名、前記本人確認情報、前記機器証明書及び前記ユーザ証明書を前記クライアント装置内に送信する送信手段と、 を備えたことを特徴とするユーザ署名装置。
  3. 6
    The identity verification information, the device certificate, the user certificate, and the identity verification information are signed by the device private key corresponding to the device certificate and the user private key corresponding to the user certificate, respectively. This is an authentication device for authenticating the identity verification information when a digital signature is received from a client device via a network. A receiving means for receiving the digital signature, the identity verification information, the device certificate, and the user certificate. Certificate verification means for verifying the device certificate and user certificate received by the receiving means while communicating with the issuer of each certificate. When the verification result by the certificate verification means is valid, the signature verification means for verifying the digital signature based on each certificate and the signature verification means. When the verification result by the signature verification means is valid, the identity verification information authentication means for authenticating the identity verification information and the identity verification information authentication means. An authentication device characterized by being equipped with. 【請求項6】 本人確認情報及び機器証明書と、ユーザ証明書と、前記本人確認情報が前記機器証明書に対応する機器秘密鍵及び前記ユーザ証明書に対応するユーザ秘密鍵によりそれぞれ署名処理されてなるデジタル署名とをクライアント装置からネットワークを介して受信したとき、前記本人確認情報を認証するための認証装置であって、 前記デジタル署名、前記本人確認情報、前記機器証明書及び前記ユーザ証明書を受信する受信手段と、 前記受信手段により受信された機器証明書及びユーザ証明書を当該各証明書の発行元と通信しながら検証するための証明書検証手段と、 前記証明書検証手段による検証結果が正当なとき、前記各証明書に基づいて前記デジタル署名を検証する署名検証手段と、 前記署名検証手段による検証結果が正当なとき、前記本人確認情報を認証する本人確認情報認証手段と、 を備えたことを特徴とする認証装置。
  4. 7
    A biometric authentication device for confirming the identity of a user by a biometric authentication method. A device information storage means in which a device certificate and a device private key based on a public key cryptosystem are stored in advance, and A reading means for reading the user's biological information and A collation means that collates the biometric information obtained by the reading means with the user's reference information separately transmitted, and if both match, sends out identity verification information indicating legitimacy. A signature generation means for performing signature processing and performing signature processing by the device private key in the device information storage means for the identity verification information sent from the verification means. A transmission means for transmitting the first digital signature obtained by the signature generation means, the identity verification information, and the device certificate, and A biometric authentication device characterized by being equipped with. 【請求項7】 生体認証方式により、ユーザが本人である旨を確認するための生体認証機器であって、 予め公開鍵暗号方式に基づく機器証明書及び機器秘密鍵が格納された機器情報格納手段と、 前記ユーザの生体情報を読取る読取り手段と、 前記読取り手段により得られた生体情報と別途送信されたユーザの参照情報とを照合し、両者が一致すると、正当を示す本人確認情報を送出する照合手段と、 前記照合手段から送出された本人確認情報に対して、前記機器情報格納手段内の機器秘密鍵による署名処理と施す署名生成手段と、 前記署名生成手段により得られた第1デジタル署名、前記本人確認情報及び前記機器証明書を送信する送信手段と、 を備えたことを特徴とする生体認証機器。
  5. 8
    [Claim 8] A device certificate based on a public key cryptosystem when an issuance request or issuance permission is received from a certificate authority for each biometric authentication device for confirming the identity of the user by the biometric authentication method. And a device certificate authority characterized by issuing a device private key. 【請求項8】 生体認証方式により、ユーザが本人である旨を確認するための各生体認証機器に対し、認定局から発行要求又は発行許可を受けたとき、公開鍵暗号方式に基づく機器証明書及び機器秘密鍵を発行することを特徴とする機器認証局。
  6. 9
    An identity verification system for confirming the identity of a user by a biometric authentication method. For each user, a user registration authority for issuing user certificates and user private keys based on public key cryptography, and For each biometric device, a device certificate authority for issuing device certificates and device private keys based on public key cryptography, and When the user certificate and user private key issued by the user registration authority are stored in advance and the identity verification information, the first digital signature, and the device certificate transmitted from the outside are received, the first digital signature is received. A user signature device that performs a signature process using the user private key and transmits the obtained second digital signature, the identity verification information, the device certificate, and the user certificate. A client device having a medium holding unit for detachably holding the user signature device and having a communication function, and a client device. When the second digital signature, identity verification information, device certificate, and user certificate transmitted from the user signing device are received via the client device, the user certification is performed with reference to the user registration authority and the device certification authority. An authentication device that verifies the certificate and the device certificate, or verifies the second digital signature, and authenticates the identity verification information when the verification results of each certificate and the second digital signature are valid. An identity verification system characterized by being equipped with. 【請求項9】 生体認証方式により、ユーザが本人である旨を確認するための本人確認システムであって、 各ユーザ毎に、公開鍵暗号方式に基づくユーザ証明書及びユーザ秘密鍵を発行するためのユーザ登録局と、 各生体認証機器毎に、公開鍵暗号方式に基づく機器証明書及び機器秘密鍵を発行するための機器認証局と、 前記ユーザ登録局により発行されたユーザ証明書及びユーザ秘密鍵が予め格納され、外部から送信された本人確認情報、前記第1デジタル署名及び前記機器証明書を受信すると、この第1デジタル署名に対して前記ユーザ秘密鍵による署名処理を施し、得られた第2デジタル署名、前記本人確認情報、前記機器証明書及び前記ユーザ証明書を送信するユーザ署名装置と、 前記ユーザ署名装置を着脱自在に保持する媒体保持部を有し、通信機能を備えたクライアント装置と、 前記ユーザ署名装置から送信された第2デジタル署名、本人確認情報、機器証明書及びユーザ証明書を前記クライアント装置を介して受信すると、前記ユーザ登録局及び前記機器認証局を参照しながら前記ユーザ証明書及び前記機器証明書を検証し、又は前記第2デジタル署名を検証し、前記各証明書と前記第2デジタル署名との検証結果がそれぞれ正当のとき、前記本人確認情報を認証する認証装置と、を備えたことを特徴とする本人確認システム。