Identification card
Abstract
The invention relates to individual identification cards that have a high degree of security. The identification card includes a memory for storing the reference data, a real biometric data acquisition sensor, a first processor for comparing the biometric data collected with the corresponding reference data stored within a predetermined threshold and for generating a verification message in the case when the result of comparing the data is within the predetermined threshold, and means for transmitting the verification message to an external network for additional verification of a remote identification system.

Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
25 claims: 1 independent, 24 dependent
- 1Revendicări:I. Cartel! de identificare, ce confine incorporate in ea о memorie pentru stocarea datelor de referinț!, un senzor pentru colectarea datelor biometrice reale, primul procesor pentru compararea datelor biometrice colectate cu datele de referinț! corespunz!toare stocate in limitele unui prag predeterminat și pentru generarea unui mesaj de verificare in cazul când rezultatul compar!rii datelor se ail! in limitele pragului predeterminat, și mijloace pentru transmiterea mesajului de verificare unei rețele exteme, pentru о verificare suplimentar! de un sistem de identificare la distant!.
- 2Cartel! de identificare, conform revendic!rii 1, caracterizat! prin aceea că mesajul de verificare include cel pufin câteva fragmente din datele de referinț! stocate.
- 3Cartel! de identificare, conform revendic!rii 2, caracterizat! prin aceea că mesajul de verificare include cel pufin câteva fragmente din datele biometrice colectate.
- 4Cartel! de identificare, conform revendic!rii 1, caracterizat! prin aceea c! sistemul de identificare la distant! include date de referinț! colectate la distanț! care difer! de datele de referinț! stocate local.
- 5Cartel! de identificare, conform revendic!rii 1, caracterizat! prin aceea c! in primul procesor este utilizat un algoritm de potrivire diferit de cel utilizat de sistemul de identificare la distanța.
- 6Cartel! de identificare, conform revendic!rii 1, caracterizat! prin aceea c! procesul de potrivire este realizat de c!tre primul procesor și nici un fel de date biometrice colectate nu se transmit la rețeaua extern!.
- 7Cartel! de identificare, conform revendicarii 1, caracterizat! prin aceea c! datele biometrice colectate original, precum și orice alt! informație „privat!” stocate in memorie nu sunt expuse la oarecare procese externe.
- 8Cartel! de identificare, conform revendic!rii 1, caracterizat! prin aceea c! cartela este compatibil! cu un Smart-Card ISO.
- 9Cartel! de identificare, conform revendicarii 8, caracterizat! prin aceea c! mai confine un procesor Smart-Card ISO.
- 10Cartel! de identificare, conform revendicarii 9, caracterizat! prin aceea c! primul procesor utilizat pentru stocarea și prelucrarea datelor biometrice protejate este separat de procesorul Smart-Card ISO printr-un firewall. II. Cartela de identificare, conform revendicarii 9, caracterizat! prin aceea c! toate datele exterioare transmise la și de la primul procesor tree prin procesorul Smart-Card ISO.
- 1112. Cartel! de identificare, conform revendic!rii 9, caracterizat! prin aceea c! toate datele exterioare transmise la și de la procesorul Smart-Card ISO tree prin primul procesor.
- 1213. Cartel! de identificare, conform revendic!rii 1, caracterizat! prin aceea c! primul procesor confine prima conexiune pentru introducerea datelor in timpul unui proces de încarcare și a doua conexiune unit! cu о rețea externa.
- 1314. Cartel! de identificare, conform revendic!rii 13, caracterizat! prin aceea c! prima conexiune este deconectat! permanent dup! finisarea procesului de înc!rcare.
- 1415. Cartel! de identificare, conform revendic!rii 1, caracterizat! prin aceea c! cartela confine о regiune cu band! magnetic! superioar! cu о regiune in relief inferioara, un senzor pentru colectarea MD 4012 B2 2010.01.31 datelor biometrice, care reprezint! un senzor de amprente, un procesor de securitate, totodat! procesorul Smart-Card ISO și senzorul de amprente sunt plasate in mijlocul cartelei.
- 1516. Cartel! de identificare, conform revendicarii 15, caracterizat! prin aceea c! datele biometrice includ datele dactiloscopice, iar senzorul de amprente reprezint! un senzor dactiloscopic care colecteaza datele de la degetele utilizatorului aflate pe acesta.
- 1617. Cartel! de identificare, conform revendicării 16, caracterizat! prin aceea c! se asigura feedback m timp real în momentul când utilizatorul manipuleaza cu degetul pe sesizorul dactiloscopic, facilitând prin aceasta plasarea optim! a degetului pe acesta.
- 1718. Cartel! de identificare, conform revendic!rii 16, caracterizat! prin aceea c! in procesul de potrivire este utilizat un algoritm de potrivire hibrid care tine cont atât de șabloanele amprentelor digitale, cât și de pozifiile în spațiu în datele biometrice colectate.
- 1819. Cartel! de identificare, conform revendicării 16, caracterizat! prin aceea c! sesizorul dactiloscopic confine о plac! din siliciu cristalin susfinut! de о plac!-suport.
- 1920. Cartel! de identificare, conform revendicarii 19, caracterizat! prin aceea c! placa-suport confine un compozit sticl! - râșin! epoxidic! plasat intre doua straturi de metal.
- 2021. Cartel! de identificare, conform revendic!rii 19, caracterizat! prin aceea c! placa-suport este fixat! de о carcas! portanta ce cuprinde о placa de siliciu.
- 2122. Cartel! de identificare, conform revendic!rii 1, caracterizat! prin aceea c! cartela mai confine mijloace pentru limitarea utiliz!rii cartelei într-o localitate predeterminat!.
- 2223. Cartel! de identificare, conform revendic!rii 1, caracterizat! prin aceea c! primul procesor asigura faptul c! cel pufin unele din datele biometrice colectate și datele de referinf! sunt transmise la un server de identificare separat, pentru verificarea sigur! a identitafii unui utilizator, pâna la acordarea accesului on-line la un server de aplicafii, pentru prelucrarea tranzacfiilor fmanciare de siguranf! cu implicarea utilizatorului dat.
- 2324. Cartel! de identificare, conform revendic!rii 23, caracterizat! prin aceea c! drept raspuns la о solicitare de potrivire referit! la о încercare privat! de inregistrare la serverul de aplicafii particular, care produce о potrivire pozitiv! la serverul de identificare, se execut! un protocol de identificare sigur! cu trei canale, in care se expediaza о secvenfa cu caracter de confirmare de la serverul de identificare la cartela de identificare, cartela de identificare utilizeaz! apoi secventa cu caracter de confirmare și solicitare de potrivire pentru a genera un raspuns de confirmare pe care il transmite apoi la serverul de aplicafii, apoi serverul de aplicafii transmite raspunsul de confirmare la serverul de identificare, care verifica dac! raspunsul de confirmare este valabil.
- 2425. Cartela de identificare, conform revendicarii 1, caracterizat! prin aceea c! rezultatele de pe cartel! sunt utilizate pentru obfinerea accesului fizic la о zon! securizat!.
- 2526. Cartel! de identificare, conform revendic!rii 24, caracterizat! prin aceea c! pe cartel! se menfin înregistrârile încerc!rilor reușite și nereușite de acces.
Independent claims25
198 paragraphs in 4 sections, as filed
Description:
The invention relates to the identified identification cards that possess a high degree of security.
The request is based on the priority of provisional applications 60/409716 filed on September 10, 2001 (file number 7167- 102P1), 60/409715 filed on September 10, 2002 (file number 7167-103P), 60/429919 filed on November 27, 2002 ( file filer 7167-104P), 60/433254 filed December 13, 2002 (file number 7167-105P), and 60/484692 filed July 3, 2002 (file number 7167-106P), which are hereby incorporated herein totally by reference.
Computerization, especially the Internet, provides access to data, including financial data, medicated data, personal data, through means that increase financial transactions and other transactions, in which changes with confidential data are updated.
Passwords are commonly used to maintain the confidentiality of such data; however, passwords are often based on the date of birth or a phone number that is simple to guess and not at all secure. Moreover, even о randomly generated complicated password can often be easily stolen. Password-based data access systems are thus vulnerable to criminal attacks resulting in laughter and damage to Industry and the economy and even to the lives of individuals. As a result, an improved method of data security and data protection against unauthorized access is required.
Biometric data may include precise details that are difficult to capture but easy to analyze (such as the sequence of fingerprint details) or general patterns that are easy to capture, but difficult to analyze (such as spiral or adjacent spherical features. Do you have fingerprints).
There are encryption algorithms that require a digital key only available to authorized users. Without the appropriate key, encrypted data can be decrypted in a format that can be used only with time-consuming investments and processing resources, and even then, only if certain characteristics of the encrypted data are known (or at least predictable).
The Japanese patent application published JP 60-029868 dated February 15, 1985 under the name of Tamio SAITO describes an individual identification system, which uses an integrated ID card or memory for recording the encrypted biometric data obtained from the card holder. Biometric data may include о fingerprint, fingerprint, physical appearance, and / or о biological assessment. In use, the data on the card are read and decrypted for comparison with the corresponding data captured by the person presenting the card. Such a system allows a registered person to be positively identified with a high degree of accuracy [1].
The disadvantage of this card is that it is difficult to protect the information stored on the card against a possible change and / or identity theft.
The identification card according to the invention removes the disadvantage mentioned above in that it contains embedded in it a memory for storing reference data, a sensor for collecting real biometric data, the first processor for comparing the collected biometric data with the corresponding reference data stored within a predetermined threshold and for generating a verification message if the result of the data comparison is within the predetermined threshold, and means for transmitting the verification message to an external relay for о further verification of a remote identification system. The verification message includes at least a few fragments from the stored reference data or from the collected biometric data.
The remote identification system includes remote reference data collected that differs from the locally stored reference data.
In the first processor a matching algorithm different from that used by the remote identification system is used.
The matching process is performed by the first processor and no biometric data collected is transmitted to the external refinery.
The biometric data originally collected, as well as any other "private" information stored in memory, are not exposed to any external processes.
The card is compatible with an ISO (International Standards Organization) Smart-Card. The identification card also contains an ISO Smart-Card processor.
The first processor used for storing and processing protected biometric data is separated from the ISO Smart-Card processor by a firewall.
All external data transmitted to and from the first tree processor via the ISO Smart-Card processor and vice versa.
The first processor confines the first connection for data entry during a loading process and the second connection together with the external о refea!
The first connection is permanently disconnected after the charging process is completed.
The identification card borders the upper magnetic stripe region with the lower embossed region, a sensor for collecting biometric data, which represents a fingerprint sensor, a security processor, at the same time the ISO Smart-Card processor and the fingerprint sensor are placed in the middle. card.
MD 4012 B2 2010.01.31
Biometric data includes fingerprint data, and the fingerprint sensor represents! a fingerprint sensor that collects data from the user's fingers on it.
Real-time feedback is provided when the user manipulates the finger on the fingerprint sensor, thus facilitating optimal placement of the finger on it.
In the matching process, a hybrid matching algorithm is used that takes into account both the fingerprint templates and the positions in space in the collected biometric data.
The fingerprint sensor encloses a crystalline silicon plate supported by a support plate. The support plate contains a composite glass! - epoxy resin placed between two layers of metal at the same time! support plate is fixed! of о carcas! Carrier! what does о like! of silicon.
The identification card also contains means for limiting the use of the card in a predetermined locality.
The first processor ensures! the fact that! at least some of the collected biometric data and the reference data! they are transmitted to a separate identification server, for sure verification! identified a user, up to! when granting online access to an application server, for processing financial security transactions! with the involvement of the given user.
As a response to the matching request о what do I mean! to о private test! registration to the particular application server, which produces о positive match! on the identification server, it runs! a secure identification protocol! with three channels, in which they ship! о sequence! with confirmation character from the identification server to the identification card, ID card uses! then the sequence with confirmation character and matching request to generate a confirmation response which it then sends to the application server, then the application server sends the confirmation response to the identification server, which I check! if! the confirmation answer is valid.
The results on the cartel! are used to obtain physical access to the area! secure !.
The identification card records the records of successful and unsuccessful access attempts.
The invention is explained! through the drawings in fig. 1-11, which represent !:
FIG. 1, о variant! to make a smart card with biometric verification! on the poster! of the identity of the person I present! card;
FIG. 2, block diagram for a user assistance process in optimal placement! a finger on the fingerprint sensor;
FIG. 3, block diagram of the functioning of the biometric verification system! for о local verification! and о remote checking! identify a person;
FIG. 4, block diagram of operation with different physical data for use during the initial loading of the biometric data of the card holder! and during the verification of your identity, be on the remote application!
FIG. 5, о variant! Alternative achievement! of the biometric identification card! of FIG. 4, for use with the о CPU Smart - Card ISO;
FIG. 6, block diagram of the realization between the о application and the identification card in which it is made! only local verification! identified the owner of the card!
FIG. 7, block diagram for the use of the biometric identification card! of FIG. 5;
FIG. 8, о high! variant! for the identification card with biometric verification !, which can be connected! at a local or radio terminal;
FIG. 9, cross section! of the identification card in fig. 8;
FIG. 10, the connection diagram of an example fingerprint sensor;
FIG. ll, or variant! for making an assembly - support for the sensor in fig. 10.
The term cartel! identification is used in a generic sense to refer to any physical object that is small enough to be finished in the hand !, worn around the neck or otherwise by о person! and which includes a microprocessor capable of storing, processing and communicating digitally encoded information that concerns or is otherwise related! with an individual card processor! An example well known ID cards is also an ISO Smart-Card, which has the same size and shape! physical! with о cartel! conventional credit but which includes о flash memory for storing user specific data and a microprocessor that can be programmed with a powerful indie encryption algorithm! if! a PIN (Personal Identification Number) received from a user terminal matches whether or not it has an encrypted PIN stored on the card !, thus ensuring a higher degree of confidence c! the person I present! the card is the real holder of the card! than would be possible in a verification system that is based! mainly on о visual composition! of signatures and / or physical similarities.
Fig. 1 illustrate! о variant! to make a Smart-Card with biometric verification! on the poster! Card 100 is made! generally made of a plastic material and has the global appearance of a conventional credit card, with approximate dimensions as those specified in ISO 7816 of about 53.98 x 85.6 mm and thickness of about 0.76 mm or more.
Similar to the о cartel! by conventional credit, card 100 includes о upper region! free! 102 that extends across the whole transverse film! of the card for holding a magnetic strip (as specified by ISO 7811-2 & 7811-6) on the back surface of the card, on which alpha-numerically encoded information about the card holder and any associated account can be stored, thus allowing the use of the card 100 in a band reader! magnetic! convenfional. However, because any data is included in the magnetic strip! they can be easily modified! о such a band! magnetic! is had! intended only for use in certain applications, where the need for
MD 4012 B2 2010.01.31 backward compatibility with older magnetic stripe terminals outweighs the potential security degradation on the magnetic stripe it brings to the system.
The upper region 102 may also be used to support various fraud prevention measures, such as a color photo counterfeit resistant to the card holder and / or a holographic logo of the card issuer. The bottom region 104 of the card 100 can be used conventionally for embossed information (as specified by ISO 7811-1), such as the name of the card holder, a numeric account identifier (or card), and an expiration date. , to allow the use of the card 100 in a conventional printer.
The upper region 102 and the lower region 104 are separated by the middle region 106 in which a set of 8 ISO 108 Smart-Card visible surfaces is included, which provides a convenient electrical connection between the card and the corresponding contacts on a card reader. . By this means not only the data, but also the energy, the timing and control signals can be exchanged between the reader and the card, as specified in ISO 7816-3.
On the right side of region 106, a sensor surface 110 is visible, which is used to capture fingerprint data from the finger of the card holder. The card is preferably provided with an ID code that is unique to the sensor 110 or other electronic component embedded in the card, for example, a code in the format of a conventional IP and / or MAC address.
In FIG. 1 also schematically indicates several additional electronic components that cooperate with the contact surface 108 and the sensor 110 to provide greater functionality and, in particular, better security than would otherwise be possible.
In one embodiment, the ISO 112 Smart-Card compatible processor is directly connected to the ISO 108 contact surfaces to provide о electrical connection to an external (compatible) ISO compatible card reader, thereby not only providing power to the electronic parts. on the card, but also a means of communication that has data between the card and any external communication software, security software, transactional software, and / or other software applications running on the card reader or any associated computing devices related to the card reader.
Although in the embodiment described the data path between the card 100 and the external card reader is in the form of a wired link that uses the ISO specified Smart-Card contacts, it should be understood that in other embodiments, it may also be used. , other transmission technologies such as USB or RS 232C or SPI (serial) connections, possibly through RF (Radio Frequency), microwave and / or IR (IfraRoşu) communications links.
Also, although the described embodiment receives energy from the card reader, other embodiments may have a source of energy on the card, such as a photovoltaic cell or a battery. Such an energy source on the card may be advantageous, for example, if the mechanical interface between the card 100 and a particular type of card reader is such that the fingerprint sensor 110 is not accessible to the user when the contacts 108 are connected to the appropriate internal links. card reader, and thus the fingerprint data of the user must be captured when card 100 is not wired directly to the card reader.
Security processor
As illustrated, the security processor 114 is linked between the ISO 112 processor and the sensor 110 to ensure secure processing and storage of captured data, as well as a secure firewall to protect the data and programs stored in its memory, used for any access attempt. improper through the ISO 112 processor, as will be described below. Such a firewall can be designed to allow only encrypted data to be passed using the о encryption key that is uniquely assigned or otherwise unique to the particle card, such as data extracted from a fingerprint template. previously stored or a uniquely assigned device number, such as CPU number or fingerprint sensor number. In other embodiments, the firewall lets only pass data that contain unique identifying data from the previous transmission. In other embodiments, the firewall maintains different keys for different applications, and uses those keys to direct the data to a particular processor or to different parts of memory.
In other embodiments (not shown), the security processor 114 is directly connected to the ISO 108 contacts and acts as a secure gatekeeper between the ISO 112 processor and the ISO 108. The alternative arrangement has the advantage of providing additional security allowed by the security processor. 114 and sensor 110, make any possible compromise of a security feature that can already be incorporated into the ISO 112 processor.
Security processor 114 preferably includes semiconductor or non-semiconductor non-volatile memory, such as FRAM, OTP, E<sup>2</sup>PROM, MRAM, MROM, for storing a previously registered imprint model and / or other personal biometric information. In other embodiments, some or all of the functions of the security processor 114 may be implemented in the ISO 112 processor and / or some or all of the functions of the ISO 112 processor may be implemented in the security processor 114. Such a combined implementation can still maintain a software firewall between the various endpoints, which would be advantageous especially if the device was implemented with a process that did not allow any subsequent modification of the stored software. Alternatively, both processors 112, 114 may be separate processors in a single multiprocessor device designed to protect each process from any interference with another process running on a different processor. An example of such a multiprocessor device is Sharp's DDMP (Data Driven Multiple Processor) from Japan.
MD 4012 B2 2010.01.31
Although these sensors, contacts, and other various electronic components, as well as the printed circuits or other electrical installations with which they are interconnected, are preferably all fully incorporated inside the body of the card 100 so that they are protected from abrasion and extreme contaminants, favorite location! from the middle region 106 between the upper region 102 and the lower region 104 further protects them from possible damage! from conventional magnetic tape readers, embossing printers, and printing equipment that mechanically interfaces with those other regions.
Feedback with light-emitting diodes
The electroluminescent diodes 116a, 116b are controlled by the security processor 114 and provide! visible feedback to the user. In the embodiment illustrated, they are located in the lower region! 104, preferably in a location on the side edge! of the card, away from the contact surfaces 108. In any case, the electroluminescent diodes 116a, 116b are preferably located where they will not be damaged during any embossing printing process and where they will be visible when the card is inserted! in a conventional ISO Smart-Card editor and / or while the user's finger is placed on the fingerprint sensor 110. For example:
In verification mode:
- R.OȘU blinks: finger is waiting
- stop blinking: finger placed on the sensor
- RED blinks о given!: Unable to! I agree !, ok for finger movement
- GREEN о long blink! о given !: OK, ok for finger removal
In registration mode
- GREEN blinks: finger is waiting
- stop blinking: the finger placed on the sensor
- RED blinks о given!: Unable to! enter, ok for finger movement
- GREEN blinks о given !: written, ok for finger removal
In delete mode
- GREEN and RED blink: ready to delete
- GREEN flashes once: deleted
Preferably, the user is offered! several opportunities to position your finger for successful Match or Enrollment before submitting any negative report. In a variant! To achieve this, a negative report is sent to the authentication server only if! the user removed his finger before receiving the indication ok green, or if! о limit was exceeded! predetermined times. Such a process not only instructs the user for optimal placement! of the finger on the sensor, thus reducing computational complexity, but also allows the use of more distinctive thresholds. This visible feedback is awesome! also о base! psychological for distinguishing between an inexperienced user (who will typically try until he or she succeeds in placement) and a dishonest user (who typically does not want to attract attention and will leave before his malicious intentions are discovered). The net result is a significant reduction in the probability of false negatives and / or false positives.
Fig. 2 illustrated! an example of a process to assist the user in placing the finger on sensor 110. In block 150, the electroluminescent diode! WHEEL 116b flashes. Once! what a finger was detected (block 152), electroluminescent diode! it stops blinking and a test is performed (block 154) for image quality (elongated regions defined corresponding to the punctures and depths on the skin of the finger). If! the quality is perfect! (branch NO 156), the single flashing of the electroluminescent diode RED 116b instructs the user to move his or her finger in a different position (block 158); otherwise it is done! a second test (block 162) (branch DA 160) to determine if the same finger was placed in the same position as the one used to register the user such that a relatively simple matching algorithm s! can verify that the active data matches the stored data, at a predetermined threshold, checking through this if! the active finger is the same as the finger that was initially registered (branch DA 164) and the electroluminescent diode! GREEN 116a is activated! (block 166) long enough (block 168) to check if! successful match was achieved! and the user can lift his finger. Alternatively, yes! the matching threshold has not been passed (branch NO 170), о single blinking of the electroluminescent diode RED 116b (block 158) instructs the user to move his finger to a different position and the process is repeated.
Examples of network architectures
It has to be done! now referring to FIG. 3 illustrating! о variant! possible! for the realization of a biometric verification system capable of both local and remote verification! of the identity of a person presenting о the poster! secure identification. It includes three main components: a client terminal 200, an application server 202, and an authentication server 204. Client terminal 200 includes active capture functionality! and local processing! of a user's fingerprint, for locally processed data encryption, and for secure communication with the application server and the authentication server, preferably on the Internet, using the addressing scheme and TCPIP transmission protocol, the protection against malicious access being provided by the IP firewall devices 206 conventional. In other embodiments, the firewall devices 206 may be provided with filters and encryption encoder / decoder encoding! the data transmitted after! what these have been verified as authorized data and which decode! the data received before the decision is made! these are actually authorized data, using for example an encryption algorithm, such as DES 128. By this means,
MD 4012 B2 2010.01.31 Firewall 206 can classify the data as authorized or potentially malicious based not only on the beginning block of the message, but also on the content of the message.
Client terminal 200 may be implemented as a dedicated web application, or may be implemented in software installed on a programmable office computer, laptop or other workstation or personal computer controlled by a user-generated operating system, such as Windows XXX, OS, X, Solaris XX, Linux or Free BSD. Client terminal 200 preferably includes up-to-date "negative" databases (for example, lost or stolen card identities, or restrictions on a particular card or group of cards) that allow for an additional security measure.
Application server 202 includes functionality for conducting a transaction or otherwise responding to instructions from the remote user to the client terminal 200 after the user's identity has been verified by the authentication server 204. Authentication server 204 includes functionality for secure communication both with client terminal 200 and with application server 202, for storing authentic fingerprint data and other information about previously registered users, for comparing stored data with encrypted active data received from the terminal customer 200, and to communicate to the application server 202 if the specified active fingerprint data matches the specified stored fingerprint data.
More specifically, the client terminal 200 also includes two main components: о fixed card reader component 208 which includes an internet browser terminal 210 and о card reader interface 108a (which may be a simple USB cable ending with a set of electrical contacts to form the electrical connection with the contact surfaces Smart-Card ISO 108) and о portable card reader components 100 '. In one embodiment, the portable component 100 may be о card 100, described above, including the fingerprint sensor 110, the security processor 114, and the ISO 112 SmartCard processor.
The application server 202 also includes an internet server interface that includes the firewall 206 and an internet browser 214, as well as a transactional application module 216 and a validation module 218. If the application server and the application module 216 are legacy devices that have not been designated to communicate externally via TCP / IP, the firewall 206 may be replaced by a suitable protocol converter incorporating the validation module 218 and саге аге о fixed IP address. The application service server can be operated, for example, by a third party who wishes to provide services over the internet to an authorized user.
Authentication server 204 further comprises о internet server interface 220, a processing module 222 which includes a fingerprint matching algorithm 224, and о database 226 for storing fingerprints and other authentic information collected from individuals at the time. that those persons were registered in the system and their identity was guaranteed to be satisfactory to the system operator. As a further enhancement of security, the data stored for any particular person is not preferably stored on the application server as a single sequence of information, but each item is stored separately and any required indexes or relays that link those items are accessible only through an appropriate key that is kept as part of the person's private data in the authentication server.
In certain embodiments, the fixed reader 208 and / or the portable card 100 may also be equipped with an integral Global Positioning Satellite (GPS) receiver 212 which may provide useful information about the current reader and card slot at or about the time when there is a particular transaction! In particular, the data on the housing from the GPS receiver 212 can be used to deactivate (permanently or temporarily) the reader and / or the card if any of them are moved to the position where their use is not authorized. Position can also be automatically determined by means other than GPS, for example, using caller location technology PHS (Japanese cell phone), or position sensors that respond to local variations of terrestrial electromagnetic fields. In the particular case of a GPS equipped card, the various GPS components including antennas, signal amplifiers, AD converter and sampling and mening circuits, and digital position calculator are preferably all part of a single integrated circuit or discrete devices mounted on о single circuit board, which is integrated with, embedded in, or laminated by the body of the card.
Card architecture for ISO cards with ISO matching processor interfaces on the card
Fig. 4 is a functional block diagram of an example biometric verification card compatible with ISO-Smart-card 100 or 100 'with different physical data paths for use during the initial upload of the biometric data of the card holder and during the verification of the identity of the holder of card to о apply to the remote.
In particular, in addition to the ISO 112 processor described above, the security processor 114, the fingerprint sensor 110, the electroluminescent diodes 116a, 116b and the optional GPS receiver 212, only the ISO 112 processor being connected directly to the card reader 208 via the interface surfaces. Smart-card contact ISO 108, shows a separate charging module 300 and the associated temporary connection 302, which provides direct communication with the security processor 114 during the initial registration of the user. It should be noted that the ISO 112 processor communicates with the security processor 114 via the TO 304, 306 portals, while the temporary loading connection 302 is connected to a separate I / O port 308. The security processor is preferably programmed so that any data sensitive to the data or software is accessible only from portal 308 and not from the portal.
MD 4012 B2 2010.01.31 portals 304 and 306, thereby avoiding any possibility of malicious access to these sensitive data after connection 302 has been disabled.
Most commercially available ISO processors have at least two I / O portals, and some have at least three. Only one of these portals (I / O 1) is designated for the conventional ISO Smart-card serial data connection 108 to the external ISO compatible card reader 208. Other or additional I / O portals preferably provide dedicated wired communication between the ISO 112 processor and the security processor 114 which acts as a hardware firewall to block any malicious attempt to reprogram the security processor 114 or gain access to any sensitive information that may have been previously captured by the sensor 110 or which may otherwise be stored in the processor 114. In the particular case of an ISO processor with more than two I / O lines, it is possible to present more than two static status information states on the dedicated communication path between the ISO processor and the security processor, such as 1) Ready , 2) Busy, 3) Error, and 4) Taken even when the security processor is completely unpowered. Of course, even if only one I / O portal is available, the four states can be transmitted dynamically as serial data.
Possible commands and data that can be transmitted between the ISO CPU and the security CPU via the I / O 2 and I / O 3 ISO interfaces are the following:
- commands to register or authenticate a user, to whom the security CPU will send the registration result or the authentication result for local storage and / or transmission to the remote application;
- Fingerprint information in the form of a template (reference) can be sent from the security CPU to the ISO CPU for storing the ISO Smart-Card memory for transmission to remote applications. For increased security of sensitive personal information, reference data can be encrypted by the security CPU before being sent to the ISO CPU.
The load connection 302 provides direct connection to the security CPU 114 which bypasses any firewall protection allowed by the ISO connection and associated dedicated I / O portals 304 and 306, while communication between the ISO 112 CPU and the ISO 208 reader is maintained so that the power should also be available for security CPU 114, mainly used during the initial registration of a particular user's card, and is protected against unauthorized access.
Fig. 5 illustrates an alternative embodiment of the example of the biometric verification card in FIG. 4, which is intended for use with an unmodified ISO Smart-card CPU. In particular, the ISO 112 'CPU no longer has to perform any gateway function between the card reader 208 and the security CPU 114', neither during normal use nor during the loading time, and so it can be any approved ISO CPU, unchanged in in any way and used only in a manner that is absolutely transparent to both the 208 card reader and any extraneous application. In such an alternative embodiment, the security CPU 114 'acts as a transparent firewall between the ISO 112' CPU and any external application, if the captured fingerprint matches the stored fingerprint, and blocks all such communications, if the captured fingerprint is not matches the stored fingerprint.
Card initialization and protection of stored data
Guillotine
In one embodiment, the initially manufactured card has a prominent projection circuitry extension that provides direct connection to the security CPU, as well as to the port of the ISO interface and / or any discrete memory on the card. This direct connection interface is used only for card testing and fingerprint data recording and includes the signal that allows the registration process. After registration is complete, this circuit extension is mechanically removed by cutting so no further registration is possible, and the security CPU memory is accessible only through ISO CPU and the firewall mentioned earlier between ISO and security CPU.
on safe
In another embodiment, the security CPU has a type of memory that once the fingerprint template has been registered, the memory will then be inaccessible. An example of such memory is the single-use PROM (OTP) which is similar in construction to EEPROM, but is opaque to UV and thus cannot be erased. Another example is Flash ROM which can only be made readable after registration is completed, for example, by applying sufficient current to a portion of the signal path for Validation or Address, or Data, to form о physical interruption ("security") in that signal path.
Examples of authentication processes
In one embodiment, an example of an authentication process involves capturing physical fingerprint data, for example, using optical or pressure, or conductive, or capacitive, or acoustic, or elastic, or photographic data at the client terminal used by the person. which accesses to connect to the application service server, which are then sent (preferably in encrypted form) to a separate fingerprint authentication server. The fingerprint authentication server compares the captured fingerprint data with a fingerprint file, which includes the user's recorded fingerprint data, using authentication software, and if the data matches, the authentication server sends a validation instruction to the application service server.
In another embodiment, the user accesses the WEB browser of the fingerprint authentication server, which confines the fingerprint files, where all the fingerprints are pre-registered along with the individual data, such as name, address and date of birth. The secure fingerprint authentication server, which the user accesses through a secure protocol, such as HTTPS format, sends
MD 4012 B2 2010.01.31 then о instruction to the client terminal to capture the user's fingerprint at the client terminal. In response to the instructions displayed by the client terminal browser, the user places his / her chosen finger on the fingerprint sensor and the fingerprint capture software that is resident in the client terminal captures a fingerprint, for example, a pixel-based image with a high resolution. from 25 pm to 70 pm and 12.5 mm surface<sup>2</sup> up to 25 mm<sup>2</sup> with a sensitivity level of 8 bifi.
The secure fingerprint authentication server receives the fingerprint data together with a user ID, as well as the Internet IP address and / or the individual fingerprint sensor code (MAC address) and / or cookie, and / or any unique code or other information that identifies the particular person or terminal (for example, details from the о previous conversation between the client terminal and the secure fingerprint authentication server), when comparing the received fingerprint data with a fingerprint file, which is the fingerprint data pre-registered with the user ID, individual information, such as name, address, date of birth, record, driver's license, social assistance number etc., using authentication software, which can be detail comparison and / or comparison with fast Fourier transform.
At the beginning of the authentication process, the web server 214 for the relevant application instructs the user visually or audibly to place his / her finger on the fingerprint sensor 110 and to click the mouse button or its keyboard to announce through the software. capturing fingerprints from the security processor 114. Then, the captured user's fingerprint data is sent in encrypted format (for example, using HTTPS Secure Encrypted Transmission Protocol (RSA) to Web server 220 and fingerprint authentication server 2 04 through ISO 112 processor and Web browser 210 of client terminal 200. If the captured data matches the corresponding data from its database 226, the fingerprint authentication server 204 validates the user's identity at both the client terminal 200 and the application server 202.
An example of a preferred embodiment will now be described using a three-way authentication protocol and о single-use password as a hash character coding sequence with reference to FIG. 3:
- the web browser 210 of the client terminal 200 accesses the corresponding web interface 214 of the application server 202 with о request to access the application process 216;
- Web interface 214 of the application server 202 responds with the log-in screen information and the instructions related to it for accessing the application process 216;
- client terminal 200 instructs the ISO 112 processor to activate the security processor 114;
- the ISO 112 processor triggers the security processor 114;
- the security processor 114 waits for the fingerprint data from the fingerprint sensor 110 and when the valid data is received, it extracts a digital fingerprint model that is forwarded to the web browser 210 through the ISO 112 processor;
- Web browser 210 sends о encrypted version of the extracted fingerprint template to the authentication server 204 accompanied by (or encrypted with) the related information about the involved card 100 'and the card reader 208, such as ft. user ID, IP address of the client terminal 200, and / or the wired ID code (MAC address) of sensor 110;
- the web interface 220 of the authentication server 204, upon receiving the extracted fingerprint model together with other information from the client terminal 200, sends this information to the fingerprint matching processor 222;
- under the control of matching software 224, the fingerprint matching processor 222 uses the received user ID or other specific user-specific related information to retrieve an appropriate reference fingerprint model from the database 226 and compares the fingerprints captured with the reference fingerprint template;
- the result (appropriate or inappropriate) is stored in a log of the access history along with the related information identifying the terminal 200, the card 100 'user ID and the application processor 216, and the control is resumed to the web interface of the authentication server 204;
- if the result is correct, the web interface 220 of the authentication server 204 generates a о single-use password in the form of a challenge character sequence that is transmitted to the client terminal 200, and uses this challenge character sequence as a hash code to encrypt related information that they save as the appropriate challenge response for possible future reference;
- Client terminal 200 uses the challenge character sequence as a hash code to encrypt о previously stored unencrypted copy of the related related information, which it then sends to the web interface 214 of the application server 202 as part of its response to the log application process. -in the;
- the web interface 214 of the application server 202, upon receiving the related information hash converted, sends them to the application processor 216 which associates them with the on-going attempt to open a session from that client server and, in order to confirm the appropriate result, forwards the related information received hash by the client terminal using the challenge sequence fumigated by the authentication server in response challenge;
- Web interface 220 of the authentication server 204, upon receiving the challenge response from the application server, submits that response to the application processor 216 which compares it with its previously saved reference copy of the expected response to determine if the user's identity was actually authenticated;
MD 4012 B2 2010.01.31
- any authenticated user identity information resulting from this comparison is then returned to the application processor 216 via the web interface 220 of the authentication server 204 and the validation interface 218 of the application server 202;
- Validation interface 218 uses authentication to confirm that the user identity established in the initial attempt to open a session has been validated;
- Once the user's identity has been confirmed, the web interface 220 goes to the direct communication with the web browser 210 of the client terminal 200 through the web interface 214 of the application server 202.
Fig. 6 illustrates an alternative authentication process in which the entire match is made on the ISO compatible card in fig. 4 by the security CPU 114 and no external authentication server 204 is used. The left side of FIG. 6 illustrates the functions performed by the application server 202, while the right side illustrates the functions performed by the ISO 100 smart-card.
Then a Smart-card 100 is inserted into the card reader 208, an RST reset signal is sent from the card reader to both ISO CPU (START block 502) and security CPU 114 (fingerprint checking block 504). ) and both receive VCC power from the 208 card reader. The ISO CPU responds with ATR (Answer-to-Reset) message and communicates PPS (Protocol and Parameters Selection) as needed (block 506). At the same time, the fingerprint CPU enters the standby state for receiving the fingerprint data and when the data is received from the sensor 110, it performs the authentication process (block 504).
When the initial request command is sent by the application processor 216 to the ISO 112 CPU (block 508), the ISO CPU interrogates (block 510) the security CPU about the authentication status. If the answer is positive, the ISO CPU responds to the application by executing the requested command (block 412). Otherwise (an error message or no response from security CPU 114), it does not respond to the requested command, but waits for a new first request (block 508b).
Assuming that the fingerprint was verified and the first response was received on time and determined to be appropriate for application 216 (block 514), the request / response process is continued (blocks 516, 518, 520) until the predetermined verification time is exceeded, time in which no request was received from the applications (block 522), or the application failed to receive the expected response (block 524). ''
Fig. 7 is similar to the block diagram of FIG. 6, but modified for use with the example of the biometric verification card in fig. 5. The extreme left side of fig. 7 illustrates the functions performed by the application server 202, the next column corresponds to the reader 208, the next column describes the contacts ISO 108, the next column indicates the functions performed by the security CPU 114, while the extreme right side indicates the functions performed by an ISO 112 smart-card CPU. unchanged:
- When either a smart card is inserted into a card reader or the application software starts operating a card reader device, a reset signal 550 is sent from the card reader 208 to the security CPU 114;
- shortly after the security CPU receives the reset signal 550, it sends an appropriate reset signal 552 to the ISO 112. CPU, concurrently, the security CPU waits for the fingerprint data from the fingerprint sensor;
- upon receiving the reset signal 552, the CPU ISO makes an ATR (Answer-to-Reset) 554 and then communicates PPS (Protocol and Parameters Selection) as needed;
- as soon as the security CPU 114 receives ATR (Answer-to-Reset) from the ISO CPU, it transfers it to the card reader (block 556), including any associated PPS commands;
- meanwhile, if the security CPU receives the fingerprint data, it executes the authentication process described above. In the case that the authentication test results in Pass, this state is reduced for a specific period of time. If the result is Error, security CPU 114 waits for new fingerprint data;
- upon execution of the application, о command request 558 is sent to the security CPU, which transfers о command request 560 to the ISO CPU and also transfers its correct response 562 to the card reader only if the security CPU is still in the Pass state previously mentioned or if the last correct answer had the bit with more data (test block 564);
- otherwise (branch No 566), the fingerprint CPU generates о fictitious request 568 and о transfers to the ISO CPU and also transfers the resulting Er 570 response to the card reader 216, thereby maintaining the proper synchronization between the sequence numbers in the requests and answers.
Encryption and security
Prior to transmission to any external network, any sensitive data and / or authentication result is preferably encrypted, possibly using DES encryption, or Two Fish. The encryption key can be based on the data of the captured or stored fingerprints, the user ID code, the unique code assigned to the sensor, the memory address, the adjacent memory data, other functionally related data, о previous conversation (transaction), IP address, code terminal, or о assigned password. Alternatively, sensitive data can be sent over the Internet using the HTTPS secure protocol.
To ensure even greater security, a virtual private gateway, such as DES hardware encryption and decryption, can be introduced between the secure fingerprint authentication server and the redo connection, and properly between the application service server. and the connection of the refea. Thus, using a virtual gateway or virtual private network (VPN), sensitive data is
MD 4012 B2 2010.01.31 additionally protected by an additional encryption layer, for example, both DES 128 (typically used in VPN) and RS A (used by HTTPS).
For applications with special security! all communications must be included with additional layers of security. In particular, message-starting blocks from a lower layer can be encrypted into a higher layer.
Radio communications
Other embodiments may include о dual interface for operation with both contacts (ISO 7816) and radio (ISO 1443 A or B), and preferably incorporate о multi-interface power supply unit that allows interoperability between ISO 7816, ISO 1443 A contacts. , ISO 1443 B, ISO 15693 and HID radio legacy systems (among others), all on the same card. Alternatively, the card may include preparations for other radio communication technologies, such as Bluetooth (short range) or cellular (medium range), or microwave (long range).
It must now be woven with reference to fig. 8 illustrating a smart card with biometric verification on the card that can be connected to a local terminal either radio or through an electrical connector. For the most part, the card is similar in construction and architecture with the embodiment of fig. 1 described above, and the same numbers (possibly separated by a single quotation mark) designate similar elements. In particular, the ISO 112 CPU is indicated in a different position (below, instead of one of the side parts of the contacts 108), but it has similar functionality! as described above.
The antenna ISO 132 contains two loops located generally along the periphery of the card 100 and provides о ISO compatible radio interface for the ISO 112 CPU for both data and energy similar to that allowed by the wired electrical interface 108. In addition, о security antenna 134 (in the example described, inside the antenna 132 and consisting only of a loop) provides о separate power source for the security CPU 114 through a DC-DC voltage stabilizer 120. Because there is no direct connection to the radio data, except through ISO 112 CPUs, the sensitive data stored in the security CPU 114 are not compromised by such radio interfaces. Alternatively, as mentioned above in connection with the embodiments, having only wired connections to external oral reading and the external network, the functionality of the two processors may be combined, or the external interface may be through security CPU 114 instead of ISO CPU. 112, where appropriate radio security measures should be incorporated in the architecture thus modified!
Fig. 9 represents a cross section through the card in FIG. 8. It should be noted that most of the components described are contained in a central core 126, with the upper protection layer 122 extending only the contact surfaces 108. The operating area of the sensor 110 is accessible through an upper window of the upper layer 122 and a lower window of the PCB 134 which is disposed between the upper layer 122 and the central core 126 and which provides the necessary electrical connections between the various electronic components and serves as a linking contact. on the ground, for protection against electrostatic voltage surrounding the active region of the sensor 110.
Also visible is a lower layer 124 and magnetic strip 128.
Fingerprint sensor
Fig. 10 is an example of a sensor connection scheme 110, wherein о array 400 of sensor cells 402 is arranged in rows 404 and columns 406. As described, each cell 402 includes о activation gate 410 and a transducer 412. О the fingerprint is formed by the ridges and recesses of the skin on one finger. Each transducer 412 of the sensor cell supports mechanical and / or electrical change when one of these ridges reaches the immediate vicinity of cell 402 of matrix 400, which actually fumigates a digitized image of the fingerprint based on the variations of micropression on the sensor surface caused by the ridges. and the depths on the tip of the finger. It should be noted that although each 412 translator has been described as a single variable capacitor, there are different types of translators that can respond to the presence of one of these ridges of human skin. In the particular example of a pressure-sensitive thin film transducer, the film is deformed in the vicinity of the cell and generates a charge which is stored in a capacitor connected to that cell. The voltage on the capacitor is thus a function of the mechanical effort exerted by the deformation of the piezo material which, in turn, is a function related to the situation where above the cell there is a lift or a recess. When a signal from the associated column driver 414 switches the gate of cell 410 to start and associated line driver 416 is grounded, that voltage appears on the output circuit of line 418, and is converted into an 8-bit digital signal. in output driver 420. To maximize the deformation detection of the piezo material, the piezoelectric material can be formed on elastic material, such as о polyamide or it can simply be a piezoelectric polyamide material. Other examples of analog translator technologies that can be implemented with similar matrix organization include variable resistors and variable capacities. Alternatively, each cell can be made up of a simple digital switch that provides a single bit of information; In this case, additional bits of information can be generated by providing more cells on the same surface or by sampling each cell at a higher frequency. О such alternative embodiment excludes the need for any A / D converter.
In an example embodiment, the sensor is only 0.33 mm thick and is durable enough to be embedded in a Smart-Card and is not affected by static electricity, elements or condition (hot, dry, hot, cold) user's skin. The typical size of the sensor unit cell 110 is 25 gm to 70 gm. The sensor example has a sensitive surface о of 12.5 mm<sup>2 </sup>up to 25 mm<sup>2</sup> and о 8-bit multi-level sensitivity. Such a sensor can be manufactured by one
MD 4012 B2 2010.01.31 TFT (Thin Film Transistor) matrix and a pressure sensitive capacitor, such as a thin film of piezo material, such as barium oxide and titanium or barium oxide and strontium, and includes a top electrode that covers and protects the entire sensitive surface. If a mechanical effort is applied, a corresponding load is generated which is stored in the piezo thin film capacitor. Alternatively, a pressure-based sensor can be manufactured as a о TFT array (Thin Film Transistor) together with a thin film capacitor, and a pressure sensitive capacitor, such as a sheet of pressure-conducting material. , such as о sheet of dispersion of carbon fiber, metal (such as copper or tin, or silver), paper based on glass fiber or coated carbon fiber, or metal, dispersed elastic material (such as in silicon), and о top electrode sheet, which covers the entire sensitive surface.
An A / D converter in the output circuit 420 then converts the analog electrical signal into the digital electrical signal. Each thin-film transistor selectively switches о the shared line interconnection in the voltage on the capacitor associated with it, so the voltage on each capacitor can be read and, thus, each deformation of the cell can be measured. Preferably, the entire column of thin-film transistors is switched simultaneously, and thus a number of cells (for example 8) in a selected column can be read in parallel at different line interconnections. The interconnection of multiple gates as lines and columns reduces the number of interconnections, while parallel reading of multiple cells from different lines of the same column reduces the read time for the entire array. The output voltage from the sensor can be amplified with a differential amplifier. such an amplifier can be sampled and kept for analog to digital conversion (A / D converter).
The substrate may be glass (such as non-alkaline glass), stainless steel, aluminum, ceramic (such as aluminum oxide), paper, epoxy resin glass, but is preferably a thin sheet of crystalline silicon. The thin film semiconductor material may be amorphous silicon, polysilicon, diamond, or any other thin semiconductor film. The piezoelectric material may be о piezoelectric ceramic, such as lead zirconate-titanium (PZT) thin film, preferably thicknesses in the range of 0.1 to 50.0 µm, or a thin film material of piezoelectric polyamide polymer. The interconnection material can be: Ti / Ni / Cu, Al, Cr / Ni / Au, Ti / Ni / Au, Ti / Ni / Au, Al / Au, W / Cu, W / Au.
Fig. 11 illustrates a carrier assembly for a sensor formed on a thin crystalline silicon substrate. The crystalline silicon has excellent electrical properties and facilitates the integration of the sensor matrix with the required driver and the output circuits, however the relatively large and thin sheet of silicone will bend and crack when subjected to localized surface pressure. The illustrated carrier provides a more rigid structure than would be provided with a silicon sheet of the same thickness.
As illustrated, the monolithic silicon sheet 430 is approximately 0.1 mm thick and is surrounded by a frame of equal thickness 432 glass in epoxy resin, which is mounted on the plate 434 also made of glass in epoxy resin and about 0.05 mm thick. The frame 432 and the plate 434 can be easily constructed using conventional PCB technology. In particular, the upper and lower surfaces of the plate 434 are coated with a thin layer of copper 436 separated by a glass core in epoxy resin. Frame 432 includes a number of bonding surfaces 440 around the outer periphery for connection to the security processor 114. The thin silicon plate 430 is bonded by epoxy resin to frame 432 and plate 434, and the active regions are electrically coupled to the respective electrical paths in frame 430 by conventional bonding with wires 442 in the outer outer edge portions 444 of silicon 430 surrounding the upper electrode. of protection 446.
Matching algorithms
For local processing on the plate, where processing power is limited and where only 1: 1 simple matching with a single sample of reference is expected, the fingerprint matching software can be based on relatively straightforward concentrates of the details derived from those. two models. For example, the grayscale image of a fingerprint can be reduced to two values, black and white, and the three-dimensional ridges are converted into two-dimensional sub-lines (vectors). Therefore, the accuracy of the method is subject, among other problems, to lack of clarity, conglutination, distortion, partial lack of line segments and other effects. Although the method of details is in principle less precise, it requires more computing resources and offers the possibility of compatibility with many existing databases.
For processing to a remote authentication server, where greater computing power is available and more precise differentiation may be required, for example a РОС (Phase Only Correlation) matching algorithm can be used. РОС is an identification algorithm based on macroscopic matching of whole images. Conversely, РОС matches structural information over a wide range from details to the overall image. Thus, РОС is capable of providing solid accuracy against noise, such as conglutination and partial omission. In principle, the РОС method is free from the adverse effects of position shift and brightness differences, is fast (about 0.1 s for о offline matching) and has high accuracy. For example, the РОС software can perform о comparison with the frequency of firing of the two fingerprint models using о two-dimensional first order Fourier transform (2DFFT). 2DFFT converts о digital data matrix, representing о the two-dimensional physical distribution of the fingerprint, in frequency frequency, in other words, it reverses the spatial distribution, where the higher density model has a higher frequency step. О transformation can be used
MD 4012 B2 2010.01.31 rotation to fit the frequency step model. The matching with the РОС models has an additional advantage over the matching with the detail vector, because it is not misleading by the common defects of the registered imprint model that the РОС 1 would recognize as noise, but the о analysis of the details will be interpreted as meaningful data. .
For particular demanding applications, a hybrid approach can provide even greater accuracy and security than any particular method. For example, you can use о methodology on details at the capture point, while on the remote server you can use о РОС methodology. As another example, the matching process can analyze both detail and spatial relationships to produce a combined score that takes into account the results of both.
Applied ii
The technology described above ensures a high level of security for multiple applications, both commercial and government. Depending on the needs of each application, multiple secure applications can coexist and operate on the same card and / or on the same authentication server. In one embodiment, a single card may contain up to 24 independent and secure applications. For example, the technology will allow / deny access (physically and / or logically), identify the precise location and / or movement of personnel, and / or track participants' lists while operating other secure applications, each completely isolated and secured by the other.
Among the applications currently considered are: ID / access to the airport
- security of buildings
- access to hotel rooms and billing
- hospital
- online games
- entertainment downloaded
- birth certificate
- access to the computer
- driving license -TWIG
- electronic wallet
- emergency medical information
- Explosive license
- access to government & military facilities
- HAZMAT license
- card for medical care & benefits
- parking access
- passport
- pilot's license
- ID / access of portals
- proof of insurance
- social assistance card
- credit travel card
- visa or entry / exit permit
- voter registration card
- social assistance card & food stamps
For many of these applications, the memory included in the card also preferably ensures the secure storage of various types of private personal information, which are accessible only when the registered card holder has proved his identity and has been granted such access. Examples of such private information are:
- Administrative information, such as name, address, date of birth, place of birth, nationality, religion, membership of organizations, social assistance number, driver's license number, passport number, and immigration information, such as visa type , visa expiration, citizenship etc.
- Financial information, such as wallet, Visa, MasterCard, American Express, etc., bank information, such as bank name, bank balance, money transfer information, IRS number, bankruptcy records, information about money transfers, etc.
- Physiological or health information, such as: biometric information for identifying persons, such as height, weight, fingerprints, iris, retina, hand size, bone structure, voice, DNA; the blood group; results in medical diagnostic tests; medical history; medicafii; insurance information; psychological and physiological responses to certain stimuli, etc.
- Event-information, such as criminal record, crimes, contraventions, crimes.
- Emergency information, such as cemetery, relatives and other contact information, lawyer information, religious information.
- Education, workbook, including attended schools, diplomas, employers in connection with FDD.
- Data access history (stores the access history data in and from the card).
MD 4012 B2 2010.01.31
- Information related to ID, such as the model of the fingerprint, the model of the fingerprint processed, the results of the fingerprint model.
- Words, such as a permanent password, a password! temporarily !, and / or password! unique! use.
- Encryption keys, such as о public key !, о personal key !, and / or о single-use key !. Now we will describe an example of a card registration system!
Applicant: Complete! о request and о send, including preferably о photography and fingerprints. For most applicants, о inspection of the origin documents and о simple cross-checking! of information sent to one or more of the available government and commercial databases should! be sufficient to establish the true identity rate of the person.
After! what the identity of the applicant has been verified! thus, the applicant continues! to о issuing station !, where any information considered! necessary! by the card issuer! is charged! on the poster! The applicant places his fingerprint on the sensor on the card! Once! what the fingerprint is placed! satisfactory on the sensor and loaded! on the card !, pl! the card on the card! receives an electric shock that burns certain fuses that will prevent anyone s! series ever! in that area! of the card again. Then, the plume is here! (like a cord). At that time, the cards can only be read! or written through the ISO contact card reader or the ISO radio system.
In the case of a networked authentication server, some or all of the same data that is loaded on the card! they are also transmitted in form! encrypted! to the remote server !, possibly supplemented with additional data that is not normally stored on the card !, but which may be necessary for certain applications with high security !.
Contents4
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| BR0314428A | Cites | Brazil | Search report |
| SU1003773A3 | Cites | Soviet Union (until 1991) | Search report |
| DE10393215T5 | Cites | Germany | Search report |
| BG109092A | Cites | Bulgaria | Search report |
| CN1695163A | Cites | China | Search report |
| SU1833872A1 | Cites | Soviet Union (until 1991) | Search report |
| RU2002123356A | Cites | Russian Federation | Search report |
| AU2003274907A1 | Cites | Australia | Search report |
| MD20040204A | Cites | Republic of Moldova | Search report |
| AU2004257174A1 | Cites | Australia | Search report |
| RU2297667C2 | Cites | Russian Federation | Search report |
| CA2498288A1 | Cites | Canada | Search report |
| AT500802A2 | Cites | Austria | Search report |
67 members in 43 offices
Priority claims24
| Document | Office | Kind | Date |
|---|---|---|---|
| 40971502 | United States of America | P | |
| 40971502 | United States of America | P | |
| 40971602 | United States of America | P | |
| 40971602 | United States of America | P | |
| 42991902 | United States of America | P | |
| 42991902 | United States of America | P | |
| 43325402 | United States of America | P | |
| 43325402 | United States of America | P | |
| 48469203 | United States of America | P | |
| 48469203 | United States of America | P | |
| 0328602 | United States of America | W | |
| 0328602 | United States of America | W | |
| 60409715 | – | – | – |
| 60409716 | – | – | – |
| 60429919 | – | – | – |
| 60433254 | – | – | – |
| 60484692 | – | – | – |
| PCTUS03028602 | – | – | – |
| US20020409715P | – | – | – |
| US20020409716P | – | – | – |
| US20020429919P | – | – | – |
| US20020433254P | – | – | – |
| US20030484692P | – | – | – |
| WO2003US28602 | – | – | – |
Members67
| Document | Office | Kind | |
|---|---|---|---|
| UY27970A1 | Uruguay | A1 | |
| CA2498288A1 | Canada | A1 | |
| WO2004025545A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2003274967A1 | Australia | A1 | |
| PA8581901A1 | Panama | A1 | |
| PE20040351A1 | Peru | A1 | |
| WO2004025545A3 | World Intellectual Property Organization (WIPO) | A3 | |
| TW200411572A | Taiwan Province of China | A | |
| US2004129787A1 | United States of America | A1 | |
| FI20050253A | Finland | A | |
| FI20050253A7 | Finland | A7 | |
| LU91144B1 | Luxembourg | B1 | |
| SE0500539L | Sweden | L | |
| AR041226A1 | Argentina | A1 | |
| EP1537526A2 | European Patent Office (EPO) | A2 | |
| DK200500499A | Denmark | A | |
| NO20051783L | Norway | L | |
| AP2005003281A0 | African Regional Intellectual Property Organization (ARIPO) | A0 | |
| MA27430A1 | Morocco | A1 | |
| KR20050074950A | Republic of Korea | A | |
| BR0314428A | Brazil | A | |
| BR0314428A | Brazil | A | |
| DE10393215T5 | Germany | T5 | |
| RU2005110924A | Russian Federation | A | |
| MD20050099A | Republic of Moldova | A | |
| HU0500646A2 | Hungary | A2 | |
| HUP0500646A2 | Hungary | A2 | |
| BG109092A | Bulgaria | A | |
| CN1695163A | China | A | |
| ECSP055720A | Ecuador | A | |
| MXPA05002752A | Mexico | A | |
| MXPA05002752A | Mexico | A | |
| PL375780A1 | Poland | A1 | |
| CZ2005209A3 | Czechia | A3 | |
| EA200500476A1 | Eurasian Patent Organization (EAPO) | A1 | |
| SK50292005A3 | Slovakia | A3 | |
| JP2006501583A | Japan | A | |
| LT2005035A | Lithuania | A | |
| LV13365B | Latvia | B | |
| AT500802A2 | Austria | A2 | |
| LT5344B | Lithuania | B | |
| ZA200502663B | South Africa | B | |
| LT2006029A | Lithuania | A | |
| RS20050213A | Serbia | A | |
| TR2005002225T2 | Türkiye | T2 | |
| TR200502225T2 | Türkiye | T2 | |
| LT5403B | Lithuania | B | |
| AT500802A3 | Austria | A3 | |
| TNSN05068A1 | Tunisia | A1 | |
| US7278025B2 | United States of America | B2 | |
| EA008983B1 | Eurasian Patent Organization (EAPO) | B1 | |
| NZ539208A | New Zealand | A | |
| US2008019578A1 | United States of America | A1 | |
| RU2339081C2 | Russian Federation | C2 | |
| CN100437635C | China | C | |
| MD4012B2This record | Republic of Moldova | B2 | |
| ES2336983A2 | Spain | A2 | |
| ES2336983R | Spain | R | |
| AP2205A | African Regional Intellectual Property Organization (ARIPO) | A | |
| ES2336983B1 | Spain | B1 | |
| JP4673065B2 | Japan | B2 | |
| JP2011090686A | Japan | A | |
| TWI366795B | Taiwan Province of China | B | |
| US8904187B2 | United States of America | B2 | |
| IL167360A | Israel | A | |
| US2015379250A1 | United States of America | A1 | |
| MY161401A | Malaysia | A |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Patent for invention lapsed due to non-payment of fees (with right of restoration)LapsedKA4A | KA4A |
Numbers
- Publication
- 0000004012
- Publication, DOCDB
- 4012
- Publication, EPODOC
- MD4012
- Application
- 20050099
- Application, DOCDB
- 20050099
- Application, EPODOC
- MD20050000099
Titles3
- English
- Identification card
- Romanian
- Cartelă de identificare
- Russian
- Идентификационная карточка
Classification
- CPC, 11
- G06K19/07
- G06K19/077
- G06F21/32
- G06K19/07354
- H04L9/3231
- H04L2209/805
- H04L9/3271
- G07C9/26
- G07C9/257
- G06F21/34
- G06F21/35
- IPC, 6
- G06K19 07
- G06F21 32
- G06F21 34
- G06K19 073
- G06T7 00
- G07C9 00