Secure biometric verification of identity
Abstract
A high security identification card includes an on-board memory for stored biometric data and an on-board sensor for capturing live biometric data. An on-board processor on the card performs a matching operation to verify that the captured biometric data matches the locally stored biometric data. Only if there is a positive match is any data transmitted from the card for additional verification and/or further processing. Preferably, the card is ISO SmartCard compatible. In one embodiment, the ISO SmartCard functions as a firewall for protecting the security processor used for storing and processing the protected biometric data from malicious external attack via the ISO SmartCard interface. In another embodiment, the security processor is inserted between the ISO SmartCard interface and an unmodified ISO SmartCard processor and blocks any external communications until the user's fingerprint has been matched with a previously registered fingerprint. Real-time feedback is provided while the user is man

Term
Term ended
Expired 5 April 2025, 1.5 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
58 claims: 6 independent, 52 dependent
- 1IŠRADIMO APIBRĖŽTIS 1. Intelektuali identifikavimo kortelė, turinti:joje įrengtą atmintį informacinių duomenų saugojimui;joje įrengtą jutiklį gyvų biometrinių duomenų nuskaitymui;joje įrengtą mikroprocesorių, nuskaitytų biometrinių duomenų palyginimui iš anksto nustatyto slenksčio ribose su atitinkamais atmintyje išsaugotais informaciniais duomenimis ir verifikavimo pranešimo generavimui tik tuomet, jei duomenys sutampa iš anksto nustatyto slenksčio ribose;ir priemonę verifikavimo pranešimo persiuntimui į išorinį tinklą, besiskirianti tuo, kad verifikavimo pranešimas turi mažiausiai ištraukas iš nuskaitytų biometrinių duomenų.
- 2Identifikavimo kortelė pagal 1 punktą, besiskirianti tuo, kad verifikavimo pranešimas yra perduodamas į nutolusią autentifikavimo sistemą papildomam verifikavimui.
- 3Identifikavimo kortelė pagal 2 punktą, besiskirianti tuo, kad nutolusi autentifikavimo sistema turi atokiai saugomus informacinius duomenis, kurie skiriasi nuo lokaliai saugomų informacinių duomenų.
- 4Identifikavimo kortelė pagal 2 punktą, besiskirianti tuo, kad kortelės mikroprocesorius naudoja skirtingą palyginimo algoritmą nei tas, kurį naudoja nutolusi autentifikavimo sistema.
- 5Identifikavimo kortelė pagal 1 punktą, besiskirianti tuo, kad kortelė yra suderinama su ISO SmartCard.
- 6Identifikavimo kortelė pagal 5 punktą, besiskirianti tuo, kad joje esantis procesorius yra apsaugos procesorius, naudojamas apsaugotų biometrinių duomenų saugojimui ir apdorojimui ir tuo, kad dar turi ISO SmartCard procesorių.
- 7Identifikavimo kortelė pagal 6 punktą, besiskirianti tuo, kad apsaugos procesorius yra funkciškai atskirtas užkarda nuo ISO SmartCard procesoriaus.
- 8Identifikavimo kortelė pagal 6 punktą, besiskirianti tuo, kad visi išoriniai duomenys į ir iš apsaugos procesoriaus praeina per ISO SmartCard procesorių.
- 9Identifikavimo kortelė pagal 6 punktą, besiskirianti tuo, kad visi išoriniai duomenys į ir iš ISO SmartCard procesoriaus praeina per apsaugos procesorių.
- 10Identifikavimo kortelė pagal 6 punktą, besiskirianti tuo, kad apsaugos procesorius turi pirmąją jungtį, naudojamą duomenų įvedimui duomenų įvedimo proceso metu, ir antrąją jungtį, prijungtą prie išorinio tinklo.
- 11Identifikavimo kortelė pagal 10 punktą, besiskirianti tuo, kad pirmoji jungtis yra nuolatinai atjungiama užbaigus duomenų įvedimo procesą.
- 12Identifikavimo kortelė pagal 6 punktą, besiskirianti tuo, kad:kortelė turi viršutinę magnetinės juostelės sritį ir apatinę reljefišką sritį;biometrinis jutiklis yra pirštų atspaudų jutiklis;ir apsaugos procesorius, ISO SmartCard procesorius ir pirštų atspaudų jutiklis yra įrengti vidurinėje srityje tarp viršutinės srities ir apatinės srities.
- 13Identifikavimo kortelė pagal 1 punktą, besiskirianti tuo, kad į biometrinių duomenų sudėtį įeina pirštų antspaudų duomenys, o jutiklis yra pirštų atspaudų jutiklis, kuris nuskaito duomenis nuo naudotojo piršto, uždėto ant jutiklio.
- 14Identifikavimo kortelė pagal 13 punktą, dar turinti:indikatorių piršto padėties realaus laiko grįžtamojo ryšio tiekimui, kol naudotojas manipuliuoja savo pirštu virš pirštų atspaudų jutiklio, tuo būdu palengvinant optimalų piršto nustatymą virš jutiklio.
- 15Identifikavimo kortelė pagal 13 punktą, besiskirianti tuo, kad palyginimo procesas naudoja hibridinį palyginimo algoritmą, kuris atsižvelgia tiek į atskiras detales, tiek į bendrą erdvinį nuskaitytų biometrinių duomenų vaizdą.
- 16Identifikavimo kortelė pagal 13 punktą, besiskirianti tuo, kad pirštų atspaudų jutiklis turi kristalinio silicio sluoksnelį, uždėtą ant pagrindo plokštės.
- 17Identifikavimo kortelė pagal 16 punktą, besiskirianti tuo, kad pagrindo plokštė turi stiklo epoksido dervos sluoksnį, įterptą tarp dviejų metalo sluoksnių.
- 18Identifikavimo kortelė pagal 16 punktą, besiskirianti tuo, kad pagrindo plokštė yra sustiprinta nešiklio rėmu, juosiančiu silicio sluoksnelį.
- 19Identifikavimo kortelė pagal 1 punktą, besiskirianti tuo, kad kortelė dar turi apribojimo priemonę, leidžiančią kortelę naudoti iš anksto nustatytoje vietoje.
- 20Identifikavimo kortelė pagal 1 punktą, besiskirianti tuo, kad mažiausiai kai kurie nuskaityti biometriniai ir informaciniai duomenys yra perduodami į atskirą autentifikavimo serverį saugiam naudotojo tapatybės verifikavimui prieš suteikiant tiesioginį priėjimą prie programų serverio saugių finansinių transakcijų šio naudotojo vardu atlikimui.
- 21Identifikavimo kortelė pagal 1 punktą, besiskirianti tuo, kad atsakant į palyginimo užklausą, susijusią su konkrečiu bandymu užsiregistruoti konkrečiame programų serveryje, kuris išduoda teigiamą palyginimo rezultatą autentifikavimo serveryje, aktyvuojamas saugus trijų pakopų autentifikavimo protokolas, kuriame užklausos ženklų seka yra išsiunčiama iš autentifikavimo serverio į identifikavimo kortelę, tuomet identifikavimo kortelė naudoja užklausos ženklų seką ir palyginimo užklausą atsakymo generavimui, kurį ji po to persiunčia į programų serverį, tuomet programų serveris persiunčia atsakymą į užklausą į autentifikavimo serverį, kuris patikrina, ar atsakymas į užklausą yra galiojantis.
- 22Identifikavimo kortelė pagal 1 punktą, besiskirianti tuo, kad kortelės išvestis yra panaudojama gauti fiziniam priėmimui į saugią sritį.
- 23Identifikavimo kortelė pagal 22 punktą, besiskirianti tuo, kad įrašai apie sėkmingus ir nesėkmingus bandymus prisijungti yra aptarnaujami kortelės.
- 24Identifikavimo kortelė pagal 1 punktą, besiskirianti tuo, kad ši priemonė turi mažiausiai vieną:elektrinio kontakto sąsajos įtaisą;ir belaidę persiuntimo sąsajos įtaisą.
- 25Intelektuali identifikavimo kortelė, turinti:joje įrengtą jutiklį gyvų biometrinių duomenų nuskaitymui;joje įrengtą pirmą procesorių, kuris yra sujungtas su joje įrengtu minėtu jutikliu, joje įrengtą minėtą pirmą procesorių, turintį atmintį informacinių duomenų saugojimui, joje įrengtą minėtą pirmą procesorių, nuskaitytų biometrinių duomenų palyginimui iš anksto nustatyto slenksčio ribose su atitinkamais atmintyje išsaugotais informaciniais duomenimis, ir verifikavimo pranešimo generavimui tik tuomet, jei duomenys sutampa iš anksto nustatyto slenksčio ribose;antrą joje įrengtą procesorių, sujungtą su joje įrengtu minėtu pirmu procesoriumi, identifikavimo kortelės funkcijų vykdymui, verifikavimo pranešimas įjungiantis minėtą antrą joje esantį procesorių;ir bendravimui su išoriniu tinklu sąsają, sujungtą su vienu iš joje įrengtu minėtu pirmu procesoriumi arba joje įrengtu minėtu antru procesoriumi.
- 26Identifikavimo kortelė pagal 25 punktą, besiskirianti tuo, kad joje įrengtas minėtas antras procesorius yra ISO SmartCard procesorius.
- 27Identifikavimo kortelė pagal 26 punktą, besiskirianti tuo, kad joje įrengtas pirmas procesorius yra funkciškai atskirtas užkarda nuo ISO SmartCard procesoriaus.
- 28Identifikavimo kortelė pagal 26 punktą, besiskirianti tuo, kad visi išoriniai duomenys į ir iš joje įrengto pirmo procesoriaus pereina per ISO SmartCard procesorių.
- 29Identifikavimo kortelė pagal 26 punktą, besiskirianti tuo, kad visi išoriniai duomenys į ir iš ISO SmartCard procesoriaus pereina per joje esantį pirmą procesorių.
- 30Identifikavimo kortelė pagal 29 punktą, besiskirianti tuo, kad joje įrengtas pirmas procesorius turi pirmąją jungtį, naudojamą duomenų įvedimui įvedimo proceso metu, ir antrąją jungtį, prijungtą prie išorinio tinklo.
- 31Identifikavimo kortelė pagal 25 punktą, dar turinti:joje įrengtą lokacijos detektorių, identifikavimo kortelės esamai lokacijai nustatyti;ir prietaisą, priklausomai nuo defektuotos lokacijos, apribojantį kortelės naudojimą.
- 32Identifikavimo kortelė pagal 31 punktą, besiskirianti tuo, kad joje įrengtas minėtas lokacijos detektorius turi:globalinio padėties nustatymo palydovo (GPS) signalų imtuvą.
- 33Intelektuali identifikavimo kortelė pagal 25 punktą, dar turinti:indikatorių piršto padėties realaus laiko grįžtamojo ryšio tiekimui, kol naudotojas manipuliuoja savo pirštu virš pirštų atspaudų jutiklio, tuo būdu palengvinant optimalų piršto nustatymą virš jutiklio.
- 34Identifikavimo kortelė pagal 25 punktą, besiskirianti tuo, kad minėta sąsaja turi mažiausiai vieną:belaidę sąsają, sujungtą su joje įrengtu minėtu antru procesoriumi;ir laidinę elektrinę sąsają, sujungtą su joje įrengtu minėtu antru procesoriumi.
- 35Identifikavimo kortelė pagal 34 punktą, besiskirianti tuo, kad minėta belaidė sąsaja yra suderinama su ISO antena, naudojama tiek duomenims, tiek energijai perduoti.
- 36Identifikavimo kortelė pagal 34 punktą, besiskirianti tuo, kad minėta sąsaja dar turi:apsaugos anteną, kuri per galios grandinę yra sujungta su joje įrengtu minėtu pirmu procesoriumi, ši apsaugos antena tik tiekia energiją joje įrengtam minėtam pirmam procesoriui.
- 37Identifikavimo kortelė pagal 36 punktą, besiskirianti tuo, kad minėta apsaugos antena per galios grandinę taip pat tiekia energiją joje įrengtam minėtam jutikliui.
- 38Intelektualios identifikavimo kortelės naudotojo identifikavimo būdas, intelektuali identifikavimo kortelė turinti joje įrengtą atmintį informaciniams duomenims saugoti ir joje įrengtą biometrinį jutiklį, šis būdas, turintis:gyvų biometrinių duomenų nuskaitymą panaudojant joje įrengtą jutiklį nuskaitytų biometrinių duomenų palyginimą nustatyto slenksčio ribose su atitinkamais informaciniais duomenimis, išsaugotais joje įrengtoje atmintyje;verifikavimo pranešimo generavimą tik tuo atveju, jei yra sutapimas nustatyto slenksčio ribose;ir verifikavimo pranešimo perdavimą į išorinį tinklą, besiskiriantis tuo, kad verifikavimo pranešimas turi mažiausiai ištraukas iš nuskaitytų biometrinių duomenų.
- 39Būdas pagal punktą 38, dar turintis:verifikavimo pranešimo perdavimą į nutolusią autentifikavimo sistemą papildomam verifikavimui.
- 40Būdas pagal punktą 39, dar turintis:informacinių duomenų saugojimą nutolusioje autentifikavimo sistemoje, kurie yra skirtingi nuo informacinių duomenų, išsaugotų identifikavimo kortelėje.
- 41Būdas pagal punktą 39, besiskiriantis tuo, kad palyginimo algoritmas, naudojamas identifikavimo kortelėje yra skirtingas nei palyginimo algoritmas, naudojamas nutolusioje autentifikavimo sistemoje.
- 42Būdas pagal punktą 38, dar turi:mažiausiai kai kurių nuskaitytų biometrinių duomenų ir informacinių duomenų perdavimą į atskirą autentifikavimo serverį, saugiam varotojo tapatybės verifikavimui prieš suteikiant tiesioginį priėmimą prie programų serverio, saugioms finansinėms transakcijoms šio naudotojo vardu atlikimui.
- 43Būdas pagal punktą 38, dar turintis:palyginimo užklausos, susijusios su konkrečiu bandymu užsiregistruoti konkrečiame programų serveryje, priėmimą;ir saugų trijų pakopų autentifikavimo protokolo paleidimą, jei teigiamas palyginimo rezultatas į palyginimo užklausos atsaką yra išduodamas, autentifikavimo protokolas, turintis: užklausos ženklų sekos išsiuntimą iš autentifikavimo serverio į identifikavimo kortelę: užklausos atsakymo, paremto užklausos ženklų seka ir palyginimo užklausa, identifikavimo kortelėje generavimą;užklausos atsakymo persiuntimą į programų serverį užklausos atsakymo persiuntimą iš programų serverio į autentifikavimo serverį ir patikrinimą, autentifikavimo serveryje, ar užklausos atsakymas yra galiojantis.
- 44Intelektualios identifikavimo kortelės naudotojo identifikavimo būdas, intelektuali identifikavimo kortelė, turinti joje įrengtą atmintį informacinių duomenų saugojimui, joje įrengtą biometrinį jutiklį apsaugos procesorių ir ISO kortelės procesorių, šis būdas turintis:gyvų biometrinių duomenų nuskaitymą, panaudojant joje įrengtą jutiklį nuskaitytų biometrinių duomenų palyginimą, panaudojant apsaugos procesorių, su atitinkamais informaciniais duomenimis, išsaugotais joje įrengtoje atmintyje, nustatyto slenksčio ribose;verifikavimo pranešimo generavimą, panaudojant apsaugos procesorių, tik tuo atveju, jei yra sutapimas nustatyto slenksčio ribose, ISO kortelės procesorių aktyvuojantį verifikavimo pranešimą;ir ISO kortelės procesoriaus aktyvavimą, jei naudotojo identiškumas yra patvirtintas.
- 45Būdas pagal punktą 44, dar turintis:duomenų įvedimą įvedimo proceso metu per pirmąją jungtį į apsaugos procesorių;ir pirmos jungties nuolatinį atjungimą, užbaigus duomenų įvedimo procesą.
- 46Būdas pagal punktą 44, besiskiriantis tuo, kad visi išoriniai duomenys į ir iš ISO kortelės praeina per apsaugos procesoriaus antrą jungtį.
- 47Būdas pagal punktą 44, besiskiriantis tuo, kad visi išoriniai duomenys į ir iš apsaugos procesoriaus praeina per ISO kortelės procesorių.
- 48Būdas pagal punktą 44, besiskiriantis tuo, kad į biometrinių duomenų sudėtį įeina pirštų antspaudų duomenys, o jutiklis yra pirštų atspaudų jutiklis, kuris nuskaito duomenis nuo naudotojo piršto, uždėto ant jutiklio.
- 49Būdas pagal punktą 48, dar turintis:piršto padėties realaus laiko grįžtamojo ryšio tiekimą, kol naudotojas manipuliuoja savo pirštu virš pirštų atspaudų jutiklio, tuo būdu palengvinant optimalų piršto nustatymą virš jutiklio.
- 50Būdas pagal punktą 44, besiskiriantis tuo, kad palyginimo procesas naudoja hibridinį palyginimo algoritmą, kuris atsižvelgia tiek į atskiras detales, tiek į bendrą erdvinį nuskaitytų biometrinių duomenų vaizdą.
- 51Būdas pagal punktą 44, dar turintis:piršto padėties realaus laiko grįžtamojo ryšio tiekimą, kol naudotojas manipuliuoja savo pirštu virš pirštų atspaudų jutiklio, tuo būdu palengvinant optimalų piršto nustatymą virš jutiklio.
- 52Būdas pagal punktą 44, besiskiriantis tuo, kad minėtas verifikavimo pranešimo perdavimas turi mažiausiai vieną:perdavimą per belaidę sąsają, sujungtą su ISO kortelės procesoriumi;ir perdavimą per laidinę elektrinę sąsają, sujungtą su ISO kortelės procesoriumi.
- 53Būdas pagal punktą 52, besiskiriantis tuo, kad minėta belaidė sąsaja yra suderinama su ISO antena, naudojama tiek duomenų, tiek energijos perdavimams.
- 54Būdas pagal punktą 52, dar turintis:energijos tiekimą apsaugos procesoriui per apsaugos anteną ir galios grandinę, sujungtą su apsaugos procesoriumi, kortelė aprūpinama apsaugos antena ir galios grandine.
- 55Būdas pagal punktą 54, dar turintis:energijos perdavimą įjoję įrengtą biometrinįjutiklį per apsaugos anteną ir galios grandinę.
- 56Intelektualios identifikavimo kortelės naudotojo identifikavimo aparatas, intelektuali identifikavimo kortelė, turinti joje įrengtą atmintį informacinių duomenų saugojimui ir joje įrengtą biometrinį jutiklį šis aparatas, turintis:prietaisą gyvų biometrinių duomenų nuskaitymui, panaudojant joje įrengtą jutiklį prietaisą nuskaitytų biometrinių duomenų palyginimui iš anksto nustatyto slenksčio ribose su atitinkamais joje įrengtoje atmintyje išsaugotais informaciniais duomenimis;prietaisą verifikavimo pranešimo generavimui tik tuomet, jei duomenys sutampa iš anksto nustatyto slenksčio ribose;ir prietaisą verifikavimo pranešimui perduoti į išorinį tinklą, besiskiriantis tuo, kad verifikavimo pranešimas turi mažiausiai ištraukas iš nuskaitytų biometrinių duomenų.
- 57Intelektualios identifikavimo kortelės naudotojo identifikavimo aparatas, intelektuali identifikavimo kortelė, turinti joje įrengtą atmintį informacinių duomenų saugojimui, joje įrengtą biometrinį jutiklį apsaugos procesorių ir ISO kortelės procesorių, šis aparatas, turintis:prietaisą gyvų biometrinių duomenų nuskaitymui, panaudojant joje įrengtą jutikl į prietaisą nuskaitytų biometrinių duomenų palyginimui, panaudojant apsaugos procesorių, iš anksto nustatyto slenksčio ribose su atitinkamais joje įrengtoje atmintyje išsaugotais informaciniais duomenimis;prietaisą verifikavimo pranešimo generavimui, panaudojant apsaugos procesorių, tik tuomet, jei duomenys sutampa iš anksto nustatyto slenksčio ribose, verifikavimo pranešimas aktyvuojantis ISO kortelės procesorių;ir prietaisą aktyvuojantį ISO kortelės procesorių, jei naudotojo identiškumas yra patvirtintas.
- 58Aparatas pagal punktą 57, dar turintis:indikatorių piršto padėties realaus laiko grįžtamojo ryšio tiekimui, kol naudotojas manipuliuoja savo pirštu virš pirštų atspaudų jutiklio, tuo būdu palengvinant optimalų piršto nustatymą virš jutiklio.
Independent claims58
169 paragraphs, as filed
Globalization and, in particular, Internet technologies make it easier to access data, including financial, medical, personal data, and to conduct financial and other transactions quickly, where confidential data is updated or exchanged.
it is common for passwords to keep the confidentiality of such data, but most passwords use a birth date or a phone number that is easy to guess and therefore unsafe. In addition, even complex random passwords are often stolen. In this way, password data systems are not protected against criminal hacking, which puts the industry and the economy and even human lives at risk. Consequently, there is a need for an improved way of securing data and protecting it against unauthorized access.
Biometrics can include precise details that are difficult to grab but easy to analyze (such as fingerprint details), or entire patterns that are easy to grab but difficult to analyze (such as distances between adjacent spiral strands of fingerprints).
Currently, encryption algorithms are being developed that require a digital key that only an authorized user has. Without a proper key, the encrypted data can only be decrypted into a proper format after a considerable amount of time and effort, and only when certain characteristics of the unencrypted data are known (or at least predictable).
1985 Japanese patent application JP60-029868 of February 15, 2008 to Tamio SAITO describes an identity verification system that uses an identity card with an integrated memory to register encrypted biometric cardholder data. The biometric data may be voice, fingerprints, physical appearance and / or biological analysis data. Card data is read and decrypted during use for comparison with the corresponding data taken from the card issuer. Such a system allows for a fairly accurate identification of the registered individual. However, since the biometric data is read and processed by an external device, it is difficult to protect the data stored on the card from tampering and / or theft.
An improved identity verification card with a data-driven multiprocessor chip is known to provide a security firewall that encrypts and insulates the biometric data stored on the card, thus significantly protecting against unauthorized tampering with the card. However, the actual comparison process was performed on the same external scanner terminal that reads live biometrics and is potentially not protected from malicious external actions.
The high security identification card described in the first embodiment has not only a local storage for biometric data, but also a local sensor for reading live biometric data. The remote authentication system has a secure database with biometrics. The card processor performs a preliminary check to verify that the biometric data being scanned matches the biometric data stored on the card. Only in case of a positive result, the scanned data or the data stored in memory is sent to the remote authentication system for further comparison and further processing. To protect against malicious attack, the data stored on the card is optimally different from the data stored remotely, and both the card and the remote data are compared using different comparison algorithms. Therefore, if an unauthorized intrusion attempt is made to the card or to the local terminal to which the card is connected, there is a good chance that the remote authentication system will be able to detect this intrusion attempt.
The card described in the second embodiment also has a local memory for storing biometric data, a local sensor for reading live biometric data, and a local processor. However, in this embodiment, the entire comparison process is performed on a local processor and both live read data and other "private" information stored in the card memory are not accessible to any external process. In this case, only a confirmation message is generated if the newly scanned biometrics and the previously scanned biometrics match. This confirmation message allows the card to operate in a manner similar to a standard ISO SmartCard; after the successful / unsuccessful introduction of a regular Personal Identification Number (PIN), but with the added protection afforded by a more secure verification process. In either of these embodiments, the biometrics stored on the card and any associated decryption algorithm or key are optimally stored on the card at the time of issuance to the card user in a manner that prevents access to the card, further improving the integrity of the biometric data stored on the card. the verification process.
In one embodiment, the ISO SmarCard acts as a firewall to protect the security processor used to store and process biometric data from external hacking via the ISO SmartCard interface. In another embodiment, the security processor is sandwiched between the ISO SmarCard interface and the unmodified SmartCard processor and blocks any communication to the exterior until the user's fingerprint is matched with a previously registered fingerprint.
One embodiment of the implementation of the high security identification card with the card's fingerprint comparison feature provides real-time feedback where the user manipulates a finger over the fingerprint sensor, thereby facilitating optical finger positioning over the sensor. This feedback not only facilitates computation but also provides additional tools to distinguish the inexperienced user from the rogue user and thus reduces the likelihood of the first and / or second occurrences. In another embodiment, the fingerprint sensor is provided on a carrier for added rigidity.
In one embodiment, the scanned biometric data and / or cardholder identity is encrypted and entered into an operating network consisting of a financial institution and a separate authentication server before accessing confidential data or any automated process for performing a secure transaction. In another embodiment, the card output is used to physically enter the secure area. In either of these, successful and unsuccessful attempts can be logged on either the card, the external security server, or both.
Figure 1 illustrates one embodiment of a SmarCard for verifying a person's identity.
Figure 2 is a diagram illustrating a process for assisting the user to place a finger over a fingerprint sensor.
Figure 3 is a functional block diagram of a biometric verification system capable of locating the identity of a person presenting an identity card, both locally and remotely.
Fig.4 is a functional block diagram of a biometric verification card with different physical data paths for use in retrieving biometric data from a primary cardholder and transmitting the cardholder's identity to remote processing
Fig. 5 shows an alternative embodiment of the biometric verification card of Fig. 4, which is intended for use with an unmodified ISO SmartCard processor.
Fig.6 is a diagram showing the relationship between a sample application and a sample verification card, where only the cardholder's identity is verified locally.
Figure 7 is a diagram similar to Figure 6 modified for use with the biometric verification card of Figure 5.
Figure 8 shows a second embodiment of a SmartCard with biometric verification, which can be connected to a local terminal either wirelessly or by electrical connection.
Fig. 9 is a cross-sectional view of the card of Fig. 8.
Fig. 10 is a diagram of a fingerprint sensor.
Fig. 11 shows one embodiment of the sensor carrier of Fig. 10.
SmartCard
As used herein, the terms "smart card" or "intelligent card" generally mean any physical object which is small enough to be held in a hand, worn, necked or otherwise, and which has a microprocessor, capable of storing, processing and sending digitally encrypted information related to a specific cardholder. One example of such a card is the ISO (International Standarts Organization) SmartCard, which is a regular credit card in size and shape but has a pulsed memory, user data storage, and a microprocessor that can be programmed with a powerful encryption algorithm that specifies whether the PIN (Persons Identification Number) obtained from the terminal corresponds to the PIN entered on the card, all the more so as to ensure that the person presenting the card is the real owner of the card than would be possible with a verification system that simply visually checks the similarity between signatures and physical appearance.
Fig. 1 shows one embodiment of a SmartCard with biometric verification implemented therein. Card 1 is usually made of plastic and is similar to a regular credit card, measuring approximately 53.98 x 85.6 mm by ISO 7816 and having a thickness of approximately 0.76 mm or more.
Similar to a regular credit card, card 1 has a free top area 2 that extends across the entire length of the card to accommodate the magnetic strip (as specified in ISO 7811-2 & 7811-6) on the back of the card, where standard alphanumeric information can be recorded. about the cardholder and any associated account, ensuring that Card 1 can be read by a standard magnetic card reader. However, since any information recorded on magnetic tape can be easily changed, such magnetic tape is for limited use, where backward compatibility with older magnetic tape terminals is more important than the security that magnetic tape cannot provide to the system.
The top area 2 can also be used to mount various security features such as a fake color card holder image and / or a card issuer holographic mark. The lower area of card 1 can be used in the usual way for information such as cardholder's name, account (or card) number, expiration date, embossed (as defined in ISO 7811-1), so that card 1 can be processed in the usual way printer.
The upper region 2 and the lower region 3 are separated by a central region 4, which is provided with a group of eight visible ISO SmartCard contacts 5, which provide a normal electrical connection between the card and the corresponding card reader contacts. They ensure the transmission of not only data, but also power, time and control signals between the reader and the card as specified in ISO 7816-3.
On the right side of area 4 is a sensor 6 which is used to scan the cardholder's fingerprint. Ideally, the card is provided with a unique ID code that is compatible with sensor 6 and other electronic components provided on the card, such as a standard IP and / or MAC address format code.
Also, the card shown in FIG. 1 is provided with a number of additional electronic components which, together with the contact group 5 and the sensor 6, provide the card with more functionality and, in particular, security than would otherwise be achieved.
In one embodiment of the invention, the ISO SmartCard-compatible processor 7 is directly coupled to the contact group 5, thereby enabling it to be connected to an unshown external ISO-compatible card reader not only to supply card electronics but also for data transfer between the card and any any external communications programs, security programs, transaction programs and / or other applications, installed on the card reader or any computer device associated with the card reader.
Although in the embodiment described the data path between the card 1 and the external card reader is wired using the ISO specified SmartCard card contact equipment, it is obvious that in other embodiments other communication technologies such as USB or RS 232C or SPI (serial) may be used. connections via wireless RF (radio frequency), microwave and / or IR (infrared) communication channels.
In addition, while in the embodiment described the card is powered by a card reader, other cards may have a power source, such as a solar cell or battery, incorporated into the card. Such an on-board power source is useful when, for example, the mechanical connection between the card 1 and a particular type of card reader is such that the user cannot access the fingerprint sensor 6 when the contacts 5 are connected to the respective connectors inside the card reader. Thus, the user's fingerprints must be read when card 1 is not directly connected to the card reader.
Security processor
As can be seen in the figure, the security processor (central processing unit CPU) 8 is connected between the ISO processor 7 (CPU) and the sensor 6 and is designed for the secure processing and storage of scanned data and as a firewall to prevent unauthorized access to data and programs recorded to its dedicated memory via an ISO processor 7 as described below. Such a firewall may be designed to pass only encrypted data using an encryption key based on a unique dedicated network address or otherwise unique to a particular card, such as data previously stored on a fingerprint pattern or a unique assigned device number such as a CPU (CPU) or fingerprint sensor number. In another embodiment, the firewall skips only data that has unique identification data from a previous transmission or data. In yet other embodiments, the firewall applies different keys to different operations and uses these keys to redirect data to the corresponding different partition of the processor or memory.
In another embodiment not shown, the protection processor 8 is directly connected to the ISO contacts 5 and acts as a protection filter between the ISO processor 7 and the ISO contacts 5. Such additional installation provides the additional protection provided by the protection processor 8 and sensor 6 without compromising any protective functions, which can already be incorporated into an ISO processor 7.
The security processor 8 optimally has non-volatile semiconductor or non-volatile memory such as FRAM, OTP, E<sup>2</sup>PROM, MRAM, MROM for storing previously scanned fingerprints and / or other biometric information. In other embodiments, some or all of the functions of the security processor 8 may be implemented in the ISO processor 7 and / or some or all of the functions of the ISO processor 7 may be implemented in the security processor 8. Such a combined installation will preserve the firewall between the various features, which would be particularly useful if the device had a process installed that would prevent any subsequent modification of the recorded programs. Alternatively, both processors 7, 8 may be separate processors in one multiprocessor device to protect each process from interference from any other process in the other processor. One example of such a multiprocessor device is a DDMP (Data Driven Multiple Processor) device manufactured by Sharp (Japan).
Although these various sensors, contacts and other electronic components, as well as printed circuits or other electrical connections to which they are interconnected, are fully incorporated inside the card 1 housing in such a way as to protect against wear and external contamination, the optimum location in the mid-range Within the range of 4 between the upper region 2 and the lower region 3 further protects them from possible damage by conventional magnetic tape meters, stamping machines and printing devices that mechanically contact all of these areas.
LEDs
The LEDs 9a, 9b are controlled by the security processor 8 and provide the user with visual feedback. In this illustrated example, they are positioned in the lower region 3, preferably at the edge of the card furthest from the contacts 5. In any case, the LEDs 9a, 9b are positioned where they will not be damaged during stamping and will be visible when the card is inserted into a standard ISO SmartCard reader and / or when the user's finger is placed on the fingerprint sensor 6. For example:
In verification mode:
• blinking RED: waiting for finger placement • stopped blinking: finger placed on sensor • RED blinking once: cannot compare, moving finger • green blinking once: compared, OK, removable finger
In registration mode:
• GREEN blinking: waiting for finger placement • stopped blinking: finger placed on sensor • RED blinking once: cannot register, finger moving • GREEN blinking once: OK, removable finger
In delete mode:
• GREEN and RED blinking: ready to delete • GREEN blinking once: deleted
Ideally, the user is allowed to place his or her finger on the sensor multiple times for successful comparison or registration before transmitting a negative message. In one embodiment, a negative message is issued only if the user has removed his or her finger without receiving a green OK signal, or if a predefined time limit has been exceeded. Not only does this process teach the user to properly place their finger over the sensor, which not only simplifies computation, but also allows for more differentiated thresholds. This visual feedback allows you to psychologically distinguish between an inexperienced user (who will usually try as many times as he has properly placed his finger over the sensor) and a phony user (who usually does not pay attention and will leave until his malicious intentions are revealed). The end result is the likelihood of significantly reduced false negatives and / or false positives.
Fig. 2 illustrates an exemplary process for assisting the user to place his finger on the sensor 6. In the position containing the unit 10, the red LED 9b flashes. When the finger is detected (block 11), the LED stops blinking and the image quality test (block 12) is performed (elongated areas corresponding to finger skin bumps and indentations are detected). If the quality is poor (NOT on branch 13), one blink of red LED 9b instructs the user to move their finger to another position (block 14); otherwise, (YES at branch 15), a second test (block 16) is performed to determine if the same finger used to register the user is placed in the same location so that a relatively simple comparison algorithm can verify that the live data is within certain limits. memorized data so that the live finger is the same as the finger that was recorded (YES at branch 17), and activating a green LED 9a (block 18) for a period (block 19) sufficient to verify that the comparison has been successfully performed and the user can now remove his or her finger. Alternatively, if the comparison did not meet the set limits (NE branch 20), a single blink of red LED 9b instructs the user to reposition their finger and the process is repeated.
Examples of network structures
Figure 3 illustrates one possible embodiment of a biometric verification system capable of performing both a local and a remote person presenting a secure identification card. It consists of three main components: client terminal 21, application server 22, and authentication server 23. The client terminal 21 reads and processes live fingerprints, encryption-processed data, and communicates securely, preferably over the Internet, with an application and authentication server protected from unauthorized access by conventional IP firewalls 24 using an IP / TCP addressing scheme and communication protocol. In other embodiments, firewalls 24 may include filters and encryption / decryption devices that encrypt verified transmitted data into authorized data and which decrypts the received data before verifying that it is indeed authorized data, using, for example, an encryption algorithm such as DES128. By these means, firewall 26 can distinguish authorized data from potentially malicious not only the message header, but also the message content.
Client Terminal 21 may be implemented as a dedicated network device or may be implemented in a program installed on a programmable desktop or portable computer or other workstation or personal computer having common Windows XXX, OS X, Solaris XX, Linux, or Free BSD operating systems. Ideally, the client terminal 21 has up-to-date "negative" databases (such as a list of lost or stolen cards, a card or a group of card liens) that provide additional safeguards.
The application server 22 performs transactions or otherwise responds to instructions from a remote user at the user terminal 21 after the authentication server 23 has confirmed the identity of the user. Authentication server 23 securely communicates with both client terminal 21 and application server 22 for storing authentic fingerprint data and other information related to previously registered users in comparison with encrypted live data received from client terminal 21, and informing the application server 22 whether or not the specified fingerprints are identical to the stored fingerprints.
More specifically, the client terminal 21 additionally has two main components: a fixed card reader 25 having a web browser terminal 26, a card reader interface 5a (which may be a simple USB cable with electrical contacts at the back for connection to ISO SmartCard card contacts 5). ) and a portable SmartCard component Γ. In one embodiment, the portable component 1 'may comprise a SmarCard 1 described above having a fingerprint sensor 6, a security processor 8 and an ISO SmartCard card processor 7.
Application server 22 further includes a web server interface having a firewall 24 and a web browser 27, as well as a transaction module 28 and a validation module 29. In the event that the application server and application module 28 are devices that are not intended to communicate externally via IP / TCP protocol , firewall 24 may be replaced by a corresponding protocol converter having a validation module 29 and a fixed IP address. The application server may be managed, for example, by a third party that seeks to provide the service to an authorized user online.
The authentication server 23 further includes a web server interface 30, a processing module 31 having a fingerprint comparison algorithm 32, and a database 33 for storing fingerprints and other authentic information collected from users at the time of their registration with the system, solely for system operation. For security reasons, each personal data is not stored on the application server as a simple sequence of information, but each entry is recorded individually and any required indexes or links linking these records are only accessed with the corresponding key that forms part of the personal private data authentication server.
Place
In certain embodiments, the fixed scanner 25 and / or the portable card 1 "may include a built-in Global Positioning Satellite (GPS) receiver 34, which may provide useful information about the current position of the scanner and card at a particular or approximate time. a specific action was taken. In particular, position data from the GPS receiver 34 may be used to deactivate the scanner and / or card (permanently or temporarily) if any of it is moved to an unauthorized location. Alternatively, positioning can be done automatically by other means than GPS, such as using PHS (Japanese cell phone) caller location technology, or by positioning sensors that respond to local changes in the earth's electromagnetic fields. If the card has a GPS receiver, the various GPS components, including the antenna, signal amplifier, A / D converter and digital processor for calculating position, form part of a single integrated circuit or are separate devices mounted on a single card that is integrated with the card body, built into or laminated with it.
Structure of an ISO card with a built-in comparison function
ISO processor interfaces
Fig.4 is a functional block diagram of an exemplary ISO SmartCard-compatible biometric verification card 1 or T with different physical data paths for use in the initial processing of the cardholder's biometric data and the cardholder's identity check for remote processing.
In addition to the ISO processor 7, security processor 8, fingerprint sensor 6, LEDs 9a, 9b and optional GPS receiver 34 described above, when only the ISO processor 7 is directly connected to the card reader 25 via ISO SmartCard contacts 5, a separate charging is shown here. a terminal 35 and a temporary connection 36 associated therewith, which provides a direct connection to the security processor 8 during initial user registration. It should be noted that the ISO processor 7 communicates with the protection processor 8 on the I / O ports 37, 38, while the temporary charging connector 36 is connected to a separate I / O port 39. The security processor is optimally programmed such that any important and security-related data or software is only accessible from port 39 and not from ports 37 and 38, thus preventing any possible malicious attempts to access this important data thereafter. when connector 36 is disconnected.
Most popular ISO processors have at least two I / O ports, some have at least three. Only one of these ports (l / O 1) is for connecting a standard SmartCard serial data connector 5 to an external ISO compatible card reader 25. One or two additional I / O ports optimally provide a dedicated wired connection between the ISO processor 7 and the security processor 8, which acts as a hardware barrier to block any malicious attempts to reprogram the security processor 8 or access any relevant information previously scanned by sensor 6 or otherwise stored in processor 8. In this particular case, where the ISO processor has more than two I / O lines, it is possible to display more than two static status information in a dedicated communication path between the ISO processor and the protection processor, such as: 1) Ready, 2) Busy, 3) Error and 4) Done even when the protection processor is completely disconnected from the power supply. Of course, even if there is only one l / O port, these four conditions can be transmitted dynamically as serial data.
The possible commands and data that can be transmitted between the ISO CPU and the protection CPU via the ISO interfaces I / O2 and I / O 3 are as follows:
• Commands to register or establish the user identity under which the protection CPU will send the logging or authentication result to local storage and / or forward to remote customization.
• Fingerprint information as a template (link) can be sent from the protection CPU to the ISO CPU for storage in the ISO SmartCard memory for subsequent transmission for remote use.
the charging connector 36 provides a direct connection to the security CPU 8, which bypasses any firewall provided for the ISO connector and associated dedicated I / O ports 37 and 38, while maintaining communication between the ISO CPU 7 and the ISO reader 25 so that power is provided to the security CPU 8. This is primarily used during primary card sign-up for a specific user and should protect against unauthorized access.
Fig. 5 shows an alternative embodiment of the biometric verification card of Fig. 4, which is intended for use with an unmodified ISO smartcard CPU. Specifically, the ISO CPU 7 'is no longer required to perform any network interface functions between the card reader 25 and the protection CPU 8', either during normal use or charging, and as such may be any ISO approved chip, in no way modified and used only in a way that is absolutely accessible to both the card reader 25 and any external application. In this embodiment, the security CPU 8 'acts as a transparent barrier between the ISO CPU 7' and any external application if the scanned fingerprint matches the stored data, and blocks all communications if the scanned fingerprint data does not match the stored data.
Card initialization and data protection
In one embodiment, the original card has a protruding extension of the printed circuitry that allows it to be directly connected to the security CPU, as well as to parts of the ISO interfaces and / or to any individual card memory. This direct connection interface is only used for card testing and fingerprint logging and has a signal that allows the registration process to take place. After registration is complete, the schema extension is mechanically cut off so that no subsequent registration can be performed, and the memory of the protection CPU can only be accessed through the ISO CPU and the aforementioned firewall between the ISO CPU and the protection CPU.
Fuse
In another embodiment, the security CPU has the kind of memory that becomes unavailable after fingerprint registration. One example of such memory is a single-use PROM ("OTP") memory, which is similar in design to EEPROM but UV resistant and therefore cannot be erased. Another example is Flash ROM memory, which is made read-only after the registration procedure, for example by supplying sufficient current to the authorization, address or data signal path, forming a physical break ("fuse") in this signal path.
An example of the authentication process
In one embodiment of the invention, the authentication process comprises scanning physical data of fingerprints using, for example, optical, pressure, conductivity, capacitance, acoustic, elastic, or photographic technologies in a client terminal used by a person to contact an application server for subsequent transmission ( optimally encrypted forms) to a separate fingerprint authentication server. The fingerprint authentication server compares the scanned fingerprint data with the logged user fingerprint data in the file using the authentication software, and if the data overlap, the authentication server sends instructions to perform the action to the application server.
In another embodiment, the user accesses a secure web browser of the fingerprint authentication server, which contains fingerprint data files, where all fingerprints are pre-registered with personal data such as name, address and date of birth. The secure fingerprint authentication server, which the user accesses via a secure protocol such as the HTTPS format, then sends instructions to the client terminal to retrieve the user's fingerprints. Responding to the instructions displayed by the client terminal browser, the user places the selected finger on the fingerprint sensor, and the fingerprint scanner on the client terminal reads the fingerprints digitally, such as 25-70 microns pixels 12.5-25mm<sup>2</sup> 8-bit grayscale image area.
The Secure Fingerprint Authentication Server accepts fingerprint data along with the User ID as well as the Internet IP address and / or the fingerprint sensor unique code (MAC address) and / or "cookie" and / or unique code or other information identifying the an individual or terminal (for example, details from a previous conversation between the client terminal and the secure fingerprint authentication server), she then compares the accepted fingerprint data with the fingerprints in the file, which is a pre-recorded fingerprint data along with the user ID, personal information such as name, address, date of birth, criminal record, driver's license , social security certificate number, etc., using an authentication program, this can be a detailed or quick comparison of the Fourier transformation.
At the beginning of the authentication process, the network server 27 instructs the user to place his or her finger on the fingerprint scan sensor 6 with the image or sound and press the mouse or keyboard button to initiate the fingerprint scan program on the security processor 8. The scanned user finger data is then sent in an encrypted format (e.g., using the secure RSA encrypted transmission protocol HTTPS) to the fingerprint authentication server 23 network server 30 via the client processor 21's ISO processor 7 and network browser 26. If the scanned data match the corresponding data in the database 33, the fingerprint authentication server 23 provides the user with access to the client terminal 21 and the application server 22.
An example of an optimal embodiment using a three-step authentication protocol and a one-time password as a random character encryption sequence will now be described with reference to FIG. 3:
• The client terminal 21's network browser 26 directs to the corresponding application server 22 network interface 27 to request an application process (module) 28.
In response, the application server 22's network interface 27 provides LOG-IN information and corresponding application process 28 instructions.
• Client terminal 21 instructs the ISO processor 7 to activate the security processor 8.
• ISO processor 7 activates protection processor 8.
• The security processor 8 waits for the fingerprint data from the fingerprint sensor 6 and, when the appropriate data has been received, to output a digital fingerprint pattern that is transmitted to the web browser 26 via the ISO processor
7.
• The web browser 26 sends an encrypted version of the provided fingerprint pattern to the authentication server 23 along with information related to the used card T and the card reader 25 such as user ID, client terminal 21 address and / or sensor 6 ID code (MAC address). .
• The network interface 30 of the authentication server 23, upon receiving the provided fingerprint pattern along with other information from the client terminal 21, transmits this information to the fingerprint comparison processor 31.
• The fingerprint comparison processor 31, controlled by the comparison program 32, uses the received user ID or other user descriptive information to find the corresponding fingerprint pattern in the database 33 and compares the scanned fingerprint pattern to a specific fingerprint pattern.
• The result (matched or not) is stored in the access archive along with other information identifying the terminal 21, the user ID, the card T and the requesting application process 28, and the response is returned to the authentication server network interface 30.
• If the result matches, the authentication server network interface 30 generates a one-time character string request password that is passed to the client terminal 21 and uses this query character string as a random character code to encrypt the associated information, which it stores as a corresponding response to the request for action.
• The client terminal 21 uses an accepted query character sequence as a random character code to encrypt an unencrypted copy of previously stored related information, which it then transmits to the application server 22's network interface 27 as part of its response to the Log-ln (sign up) process.
• The application server 22's network interface 27, after converting the random character-related information, forwards it to an application process 28, which associates it with an attempt to register from the client server and forwards a matched result to the received related information that has been converted to the client terminal. using the query sequence provided by the authentication server as a response to the request.
The network interface 30 of the authentication server 23, after receiving a response from the application server, forwards the request to the authentication process 31, which compares it with a previously stored copy of the expected response to the request to determine whether the user is actually identified.
Any identified user information obtained from this comparison is then returned to the application process 28 via the authentication server network interface 30 and the application server 22 validation module 29.
• The validation module 29 uses authentication to verify the user identity set in the initial attempt to register.
• Once the user identity has been verified, the application process 28 directly contacts the client terminal 21's network browser 26 through the application server 22's network interface
27.
Fig. 6 shows an alternate version of the authentication process wherein the comparison is performed by the security CPU on the ISO compatible card shown in Fig.4 and no external authentication server 23 is used. The left side of Fig.6 shows the functions performed by application server 22 and the right side shows functions performed by ISO SmartCard 1.
When the SmartCard is inserted into the card reader 25, the RST reset signal is sent from the card reader to both the ISO CPU (START unit 40) and the security CPU 8 (fingerprint verification unit 41), and both receive power from the card to the VCC. scanner 25. The ISO CPU then responds with an ATR (Answer-to-Reset) message and communicates with the PPS (Protocol and Parameter Selection) as needed (Block 42). At the same time, the guard CPU goes into standby mode and waits for fingerprint data and, when the data is received from sensor 6, performs an authentication process (block 43).
When the application process 28 sends the initial request to the ISO CPU 7 (block 44), the ISO CPU requests (block 45) the protection processor about the authentication status. If the answer is positive, the ISO CPU responds to the application module request by executing a command (block 46). Otherwise (after receiving an error message or receiving no response from the protection CPU 8), it does not respond but waits for a new initial request (block 44b).
If the fingerprints were verified and the first response was received on time and the application module 28 was found to be responsive (block 47), then the request response process continues (blocks 48, 49, 50) until the predefined verification is exceeded. a break during which no request was received from the application module (block 51) or the application module did not receive the expected response (block 52).
Figure 7 is a diagram similar to Figure 6 but modified for use with the biometric verification card of Figure 5. The left side of Fig. 7 shows the functions performed by application server 22, the next column represents the reader 25, the other column represents the ISO contacts 5, the other column shows the functions performed by the security CPU 8, and the right side shows the functions performed by unmodified ISO SmartCards CPU 7:
• When the SmartCard is inserted in the card reader or the application activates the card reader, the reset signal 53 from the card reader 25 is sent to the security CPU 8.
• Immediately after the reset CPU receives the reset signal 53, it sends the corresponding reset signal 54 to the ISO CPU
7th At the same time, the security CPU waits for the fingerprint data from the fingerprint sensor.
• Upon receipt of the reset signal 54, the ISO CPU prepares an ATR response 55 and then communicates with the PPS (protocol and parameter selection) as needed.
• When the security CPU 8 receives an ATR (response to the positioning signal) signal from the ISO CPU, it transmits it to the card reader (block 56), including any related commands.
• At the same time, if the security CPU receives the fingerprint data, it starts the authentication process described above. If the authentication test is positive (PASS), this status is maintained for a period of time. If the result is negative (FAIL), the security CPU 8 is waiting for new fingerprint data.
• When the command is executed, command 57 is sent to the security CPU, which sends command 58 to the ISO CPU and also sends its exact response 59 to the card reader only if the security CPU status is still positive (PASS) or if the last correct response had a larger set of data bits (test block 60).
Otherwise (no branch 61), the guard CPU generates a fake request 62 and sends it to the ISO CPU and also sends the received ERR response 63 to the application process 28 via the card reader 208, thereby maintaining proper synchronization between the sequence numbers in the requests and responses.
Encryption and protection
Before transmitting data to any external network, all relevant data and / or authentication results are encrypted, if possible, using DES or TwoFish encryption. The encryption key is based on scanned or saved fingerprint data, user ID code, unique code assigned to the sensor, memory address, adjacent data in memory, other functionally related data, previous conversion (transaction), IP address, terminal code, or password provided. Alternatively, important data can be transmitted over the Internet using the secure HTTPS protocol.
For better security, a virtual private network interface, such as DĖ hardware encryption and decryption hardware, can be inserted between the secure fingerprint authentication server and the network connection point, and between the application server and the network connection point, respectively. When you use such a Virtual Network Interface or Virtual Private Network (VPN), important data is additionally protected by an additional layer of encryption, such as DS 128 (commonly used in VPN VPN) and RSA (used by HTTPS).
For extra secure cases, all communications can be wrapped with additional layers of security. Specifically, message headers in the bottom layer can be encrypted in the top layer.
Wireless
In other embodiments, a dual interface can be provided for both contact (ISO 7816) and wireless (ISO 1443 A or B) operation and, ideally, has a multiaxial power supply that operates between ISO 7816 contact, ISO 1443 A, ISO 1443 B, ISO 15693 and HID wireless systems (among others) on one card. The card may also provide the ability to use other wireless technologies, such as Bluetooth (short-range) or mobile (medium-range) or microwave (long-range).
Fig. 8 shows a biometric verification SmartCard which can be connected to a local terminal wirelessly or electrically. For the most part, its structure and construction is similar to the card described above in Figure 1, and like elements are denoted by the same numerals. The ISO CPU 7 is located in a different location below the contacts 5 but performs a similar function as described above.
The ISO antenna 64 has two loops, typically mounted at the peripheral edge of the card 1, and provides ISO-compliant wireless connection to ISO CPU 7 for data transmission and power supply, much like the electrical connector 5. In addition, the security antenna 130 (installed, as described in the example, inside the antenna 64 and consisting of a single loop only) forms a separate power supply for the protection CPU 8 via a DC-DC voltage regulator 66. Since there is no direct wireless connection in this case, except for the ISO CPU 7, there is no risk of a wireless interface for distorting important data stored on the CPU 8. Alternatively, as mentioned above, in the case of embodiments having only wired connections to an external scanner and an external network, the dual-processor operation may be combined or the external connection may be provided via a security CPU 8 instead of an ISO CPU 7, in this case the means must be incorporated into the card structure so modified.
Fig. 9 is a cross-sectional view of the card of Fig. 8. Most of the described components are located in the central core 67, and only the contacts 5 extend through the upper protective layer 68. The functional surface of the sensor 6 is accessed through an upper window in the upper layer 68 and a lower window in the PCB 69 which is provided between the upper layer 68 and the central core 67 and provides electrical connection between various electronic components and an electrostatic discharge contact covering the active region of the sensor 6.
The lower layer 70 and the magnetic strip 71 are also visible.
Fingerprint sensor
Fig. 10 is a diagram of the sensor 6, in which the array 72 of the sensor elements 73 is formed of rows 74 and columns 75. As shown in fig. 10, each element 73 has an active inlet 76 and a transducer 77. Fingerprints are formed by finger skin bumps and indentations. Each sensor element transducer 77 is mechanically and / or electrically actuated when one of these finger skin bumps is in direct contact with the element 73 of the matrix 72, which produces a fingerprint image of changes in the micro-pressures formed by the bumps and recesses. Although each transducer 77 is depicted as a separate capacitor of variable capacitance, various types of transducers are provided which may respond to a single protrusion of human skin. In this particular pressure-sensitive thin-film piezo-converter, the film is deformed in the immediate vicinity of the element and generates a charge which is stored in the capacitor connected to the element. The capacitor voltage is a function of the mechanical voltage formed by the deformation of the piezo-material, which in turn is a function of what is above the element: protrusion or concavity. When the signal from the linked column driver 78 indicates that the cell input 76 is ON and the linked queue driver 79 is grounded, a voltage is generated at the end of the output line 80 which is converted to an 8-bit digital signal in the output driver 81. To increase the detection of the deformation of the piezoelectric material, the piezoelectric material may be formed on an elastic material such as polyimide or may simply be a polyimide piezoelectric material. Other analog converter technologies that can be implemented in a similar structure include variable resistances and variable capacitances. Alternatively, each element may consist of a single digital switch that provides only one bit of information. In this case, additional bits of information may be generated by placing more elements in the same area or by selecting each element at a higher frequency. Such an alternative embodiment does not require any A / D converters.
In the embodiment shown, the sensor is only 0.33 mm thick and is sufficiently wear resistant to be mounted on the SmartCard and is not affected by static electricity, wearer's skin elements or conditions (humidity, dryness, heat, cold). Typical sensor 6 elements have a length of 25 to 70 microns and a typical width of 25 to 70 mm. The sensor in this example has a scanning range of 12.5 x 25 mm and has an 8 bit level sensitivity. Such a sensor may be fabricated as a matrix of TFT (thin-film transistor) and pressure-sensitive capacitor formed, for example, from a thin-film piezoelectric material such as titanium barium oxide or strontium barium oxide and has an upper electrode that covers and protects the entire scanning area. If mechanical action is applied, the corresponding charge is generated and stored in a thin-layer piezo-capacitor. Alternatively, the pressure-sensitive sensor may be made as a TFT (thin-film transistor), a thin-film capacitor, a pressure-sensitive capacitor formed, for example, from a sheet of pressure-conducting material such as rubber dispersed in carbon fiber, metal (such as copper, tin or silver). ) coated carbon fiber or fiberglass based on paper or an elastic material (such as silicone) dispersed in metal and a top electrode sheet, which covers the entire scanning area, a matrix.
By row and column drivers 79, 78, a specific fingerprint sensor element 73 transmits electrical data to the output circuitry 81, thereby converting the physical user fingerprint input to analog electrical data. The A / D converter in the output circuit 81 then converts the analog electrical signal to a digital electrical signal. Each thin-film transistor optionally connects a common line-to-line voltage across the capacitor coupled to it so that the voltage of each capacitor can be read and the deformation of each element can be measured. Ideally, the entire column of thin-film transistors is connected simultaneously, so that multiple elements (e.g., 8) in a selected column can be scanned in parallel at different interconnections of rows. Combining multiple rows and columns reduces the number of connections, and parallel scanning of multiple elements from different rows in the same column reduces the scan time for the entire matrix. The sensor output voltage can be amplified by another amplifier. The output of such an amplifier can be used to convert an analog signal into a digital one (in an A / D converter).
The substrate may be glass (such as alkaline glass), stainless steel, aluminum, ceramics (such as aluminum oxide), paper, glass-epoxy resin composite, but thin film crystalline silicone is preferred. The thin-layer semiconductor may be made of amorphous silicone, polysilicon, diamond or any other thin-layer conductive material. The piezoelectric material may be a piezoelectric ceramic, such as lead-zirconate-titanate (PZT) films, which preferably has a thickness of 0.1 to 50.0 microns, or a thin-film polymeric piezoelectric polyimide. Ti / Ni / Cu, Al, Cr / Bi / Au, Ti / Ni / Au, Al / Au, W / Cu, W / Au, W / Au materials may be used for interconnections.
Fig. 11 shows the construction of a sensor formed on a crystalline silicone. Crystalline silicone has excellent electrical properties and facilitates the integration of the required drivers and output circuits into the sensor array, but the relatively large and thin sheet of silicone will shrink and last when pressed on its surface. The carrier shown gives the structure more rigidity than a silicone sheet of the same thickness.
As shown, the monolithic silicone sheet 82 is approximately 0.1 mm thick and is surrounded by a uniform thickness glass-epoxy resin frame 83 mounted on a base plate 84 also made on a 0.05-mm glass-epoxy resin structure. Frame 83 and substrate 84 can be easily fabricated using conventional printed circuit board (PCB) technology. Specifically, the upper and lower surfaces of the base 84 are coated with a thin layer of copper 85 separated by a core of glass-epoxy resin. The frame 83 has a plurality of solder points 86 on the periphery for connection to the protection processor 8. The thin silicone sheet 82 is glued with epoxy resin to frame 83 and substrate 84, and the active areas are electrically connected to respective electrical paths in frame 82 by conventional wiring 87 to open portions 89 of outer edge of silicone 82 surrounding the protective top electrode 88.
Comparison algorithms
For local card processing, where processing is limited and where only a simple 1: 1 comparison with a single sample is performed, the fingerprint comparison program may be based on a relatively simple comparison of the details obtained from the two patterns. For example, a gray fingerprint image can be reduced to two values - white and black - and the spatial bumps are converted into two-dimensional thin lines (vectors). The accuracy of the method depends, among other problems, on image blur, blur, distortion, lack of partial line segments, and other effects. Although the method of detail scanning is in principle not very accurate, it requires less computational resources and is compatible with most existing databases.
Processing on a remote authentication server with higher processing power may also require more accurate estimation, such as a POC (Phase Only Correlation) comparison algorithm. POC is an identification algorithm based on macroscopic comparison of full images. In contrast, POC compares a wide range of structural information - from detail to full image. Thus, the POC can provide greater accuracy with respect to various interferences such as adhesion and partial interruptions. In principle, the POC mode is unaffected by factors such as displacements in determining the position of the finger and differences in brightness, and is fast (autonomous comparison takes about 0.1 second) and very accurate. For example, the POC program can perform a space-frequency comparison of two fingerprint patterns using a planar first Fourier transform (“2DFFT”). 2DFFT converts a matrix of digital data representing the physical planar distribution of a fingerprint into a frequency space, in other words, a reverse space distribution where a denser pattern has a higher frequency of space. The swivel transformation can be used to compare the pattern in the frequency domain. Another advantage of POC pattern comparison is the comparison of detail vectors because it is not misled by common defects in the recorded fingerprint pattern, which is accepted by the POC as interference, but interpreted by detail analysis as meaningful data.
In special cases, the hybrid mode can provide more accuracy and security than any single mode. For example, the details methodology can be used on a scanning site and the POC methodology can be used on a remote server. Alternatively, the comparison process may analyze both details and gaps to produce a combined result that includes both results.
Application
The technology described above provides a high level of security for a variety of application functions, both commercial and governmental. Depending on the need, multiple secure recovery features may co-exist and run on the same card and / or server. In one embodiment, a single card may have up to 24 independent and secure reuse functions. For example, technology will provide / discipline access (physical and / or logical), pinpoint the exact location and / or movement of a person while performing other secure functions completely and securely separated from one another.
Intended use functions and locations include:
Airport ID / Entrance Building Security Entrance [hotel room and bill payment Hospital
Online games
Downloaded entertainment
birth certificate
Accessing Your Computer
Driver's license - TWIC
Electronic wallet
Urgent medical information
Permit to work with explosives
Authorization to enter government and military facilities
HAZMAT License
Medical Care and Discount Card
Parking
Passport
Pilot license
Port ID / Entrance
Insurance policy
Social Security Certificate
Trusted Traveler Card
Visa or entry / exit permit
Voter Registration Card
Allowances and Food Card
In many of the cases listed, the card memory also provides secure protection for the various types of private information that the cardholder can access when he or she proves his or her identity. Such private information is:
• Administrative information such as name, address, date and place of birth, nationality, religion, affiliation, social security number and immigration information such as visa type, validity, nationality, etc.
• Financial information such as Electronic Wallet, Visa, MasterCard, American Express, etc. Credit card information, Bank information such as bank name, bank balance, money order information, IRS number, bankruptcy records, etc.
• Physiological and health information such as personal biometric information such as height, weight, fingerprints, iris information, retinal information, arm size, bone structure, voice, DNA, blood type, medical history, medical history, prescription medication, insurance information, psychological and physiological responses to predisposing factors, etc.
• Criminal information such as crime, misconduct, violation of the rules.
• Critical information such as cemeteries, relatives and other contact information, attorney, religious information.
• Education, work history, including graduates, degree workplaces.
• Data access history (stores records of access to data on the card and off-card).
• ID information such as fingerprints, processed fingerprints, fingerprint processing results.
• Passwords such as permanent password, temporary password and / or one-time password.
• Encryption keys such as public key, private key and / or one-time key.
An example of a card registration system will now be described.
The applicant shall complete the application and provide it with a photograph and a fingerprint. To verify a person's true identity, the documents and information provided by him or her are cross-checked with information in state and commercial databases.
Once the identity has been verified, the applicant goes to the issuing station where the cardholder's information, which may be required, is recorded on the card. The applicant places his finger on the card sensor. When the finger is properly placed on the sensor and the fingerprint is recorded on the card, the card's continuation receives an electrical charge that burns certain fuses and no one else can record anything in the area. After that, the joint is cut / cut (much like the umbilical cord). Now the card can only be read or saved via an ISO contact reader or ISO wireless system.
Using a network authenticated server, some or all of the data stored on the card is transmitted in encrypted form to a remote server along with additional data that is not normally stored on the card, but may be required in certain high security applications.
10 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| JPS6029868A | Cites | Japan | Applicant |
59 members in 38 offices
Priority claims6
| Document | Office | Kind | Date |
|---|---|---|---|
| 40971602 | United States of America | P | |
| 48469203 | United States of America | P | |
| 20020409716P | – | – | – |
| 20030484692P | – | – | – |
| US20020409716P | – | – | – |
| US20030484692P | – | – | – |
Members59
| Document | Office | Kind | |
|---|---|---|---|
| UY27970A1 | Uruguay | A1 | |
| CA2498288A1 | Canada | A1 | |
| WO2004025545A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2003274967A1 | Australia | A1 | |
| WO2004025545A3 | World Intellectual Property Organization (WIPO) | A3 | |
| TW200411572A | Taiwan Province of China | A | |
| US2004129787A1 | United States of America | A1 | |
| FI20050253A | Finland | A | |
| LU91144B1 | Luxembourg | B1 | |
| SE0500539L | Sweden | L | |
| AR041226A1 | Argentina | A1 | |
| EP1537526A2 | European Patent Office (EPO) | A2 | |
| NO20051783L | Norway | L | |
| AP2005003281A0 | African Regional Intellectual Property Organization (ARIPO) | A0 | |
| MA27430A1 | Morocco | A1 | |
| KR20050074950A | Republic of Korea | A | |
| BR0314428A | Brazil | A | |
| DE10393215T5 | Germany | T5 | |
| RU2005110924A | Russian Federation | A | |
| MD20050099A | Republic of Moldova | A | |
| HU0500646A2 | Hungary | A2 | |
| HUP0500646A2 | Hungary | A2 | |
| BG109092A | Bulgaria | A | |
| CN1695163A | China | A | |
| MXPA05002752A | Mexico | A | |
| PL375780A1 | Poland | A1 | |
| CZ2005209A3 | Czechia | A3 | |
| EA200500476A1 | Eurasian Patent Organization (EAPO) | A1 | |
| SK50292005A3 | Slovakia | A3 | |
| JP2006501583A | Japan | A | |
| LT2005035A | Lithuania | A | |
| LV13365B | Latvia | B | |
| AT500802A2 | Austria | A2 | |
| LT5344B | Lithuania | B | |
| ZA200502663B | South Africa | B | |
| LT2006029A | Lithuania | A | |
| RS20050213A | Serbia | A | |
| TR2005002225T2 | Türkiye | T2 | |
| TR200502225T2 | Türkiye | T2 | |
| LT5403BThis record | Lithuania | B | |
| AT500802A3 | Austria | A3 | |
| US7278025B2 | United States of America | B2 | |
| EA008983B1 | Eurasian Patent Organization (EAPO) | B1 | |
| NZ539208A | New Zealand | A | |
| US2008019578A1 | United States of America | A1 | |
| RU2339081C2 | Russian Federation | C2 | |
| CN100437635C | China | C | |
| MD4012B2 | Republic of Moldova | B2 | |
| ES2336983A2 | Spain | A2 | |
| ES2336983R | Spain | R | |
| AP2205A | African Regional Intellectual Property Organization (ARIPO) | A | |
| ES2336983B1 | Spain | B1 | |
| JP4673065B2 | Japan | B2 | |
| JP2011090686A | Japan | A | |
| TWI366795B | Taiwan Province of China | B | |
| US8904187B2 | United States of America | B2 | |
| IL167360A | Israel | A | |
| US2015379250A1 | United States of America | A1 | |
| MY161401A | Malaysia | A |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Lapsed patentsLapsedMM9A | MM9A |
Numbers
- Publication, DOCDB
- 5403
- Publication, EPODOC
- LT5403
- Application
- 2006029
- Application, DOCDB
- 2006029
- Application, EPODOC
- LT20060000029
Titles2
- English
- SECURE BIOMETRIC VERIFICATION OF IDENTITY
- Lithuanian
- SAUGUS BIOMETRINIS TAPATYBĖS VERIFIKAVIMAS
Classification
- IPC, 2
- G06K19 077
- G07C9 00