EP4128696A1 - Procede et dispositif de fourniture a un terminal d'un premier utilisateur d'une signature biometrique d'un deuxieme utilisateur - Google Patents
Procede et dispositif de fourniture a un terminal d'un premier utilisateur d'une signature biometrique d'un deuxieme utilisateurInfo
- Publication number
- EP4128696A1 EP4128696A1 EP21717494.5A EP21717494A EP4128696A1 EP 4128696 A1 EP4128696 A1 EP 4128696A1 EP 21717494 A EP21717494 A EP 21717494A EP 4128696 A1 EP4128696 A1 EP 4128696A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- user
- biometric signature
- terminal
- radio signal
- obtaining
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
- H04W4/80—Services using short range communication, e.g. near-field communication [NFC], radio-frequency identification [RFID] or low energy communication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
- H04W12/065—Continuous authentication
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/32—User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/34—User authentication involving the use of external additional devices, e.g. dongles or smart cards
- G06F21/35—User authentication involving the use of external additional devices, e.g. dongles or smart cards communicating wirelessly
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/40—User authentication by quorum, i.e. whereby two or more security principals are required
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/30—Payment architectures, schemes or protocols characterised by the use of specific devices or networks
- G06Q20/32—Payment architectures, schemes or protocols characterised by the use of specific devices or networks using wireless devices
- G06Q20/327—Short range or proximity payments by means of M-devices
- G06Q20/3278—RFID or NFC payments by means of M-devices
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q20/00—Payment architectures, schemes or protocols
- G06Q20/38—Payment protocols; Details thereof
- G06Q20/40—Authorisation, e.g. identification of payer or payee, verification of customer or shop credentials; Review and approval of payers, e.g. check credit lines or negative lists
- G06Q20/401—Transaction verification
- G06Q20/4014—Identity check for transactions
- G06Q20/40145—Biometric identity checks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04B—TRANSMISSION
- H04B13/00—Transmission systems characterised by the medium used for transmission, not provided for in groups H04B3/00 - H04B11/00
- H04B13/005—Transmission systems in which the medium consists of the human body
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0861—Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/30—Security of mobile devices; Security of mobile applications
- H04W12/33—Security of mobile devices; Security of mobile applications using wearable devices, e.g. using a smartwatch or smart-glasses
Definitions
- the invention is in the field of biometric recognition implemented via communications initiated over a short range wireless channel. More precisely, the invention relates to a method for temporarily delegating to a first user authentication data of a second user resulting from a signal transmitted according to IBC technology, for Intra Body Communication in English, via the human body of two users.
- Biometric techniques exist today that allow a user to authenticate with a device or service, or secure a transaction. Such biometric techniques use characteristics specific to the user to recognize this user, for example their fingerprints, iris, palm print, voice, etc.
- NFC Near Field Communications
- the NFC signal thus picked up by the terminal carries characteristics specific to the user via the body of which the NFC signal was conducted.
- Such a signal therefore constitutes a biometric signature of the user.
- Such a biometric signature can then be used to authenticate the user, for example during transactions without wire with an NFC payment terminal, by comparing the signal picked up by the user's terminal with a reference signal learned beforehand for the user and for example stored on the terminal.
- the presence of the user is essential to validate the authentication of the user.
- the invention improves the state of the art. For this purpose, it relates to a method for providing a terminal of a first user with a biometric signature of a second user.
- a method for providing a terminal of a first user with a biometric signature of a second user is implemented by a transmitter device and comprises: generating a radio signal using near-field communication technology, transmitting said generated radio signal to the terminal of the first user, the radio signal being conducted via a channel using the electromagnetic wave conduction capabilities of the second user's body when the second user contacts or brushes a surface of the transmitting device and via a channel using the electromagnetic wave conduction capabilities of the first user's body when the first user comes into contact with or touches the second user, the signal conducted via the body of the first user and via the body of the second user comprising a signal representative of the biometric signature of the second user.
- the invention thus proposes a method allowing a user (second user) to delegate his biometric rights defined according to an IBC technology to another user (first user).
- the biometric rights of the second user correspond to a signal representative of a voluntary gesture by the second user when the latter touches or grazes a surface of a transmitter device emitting an NFC-type radio signal.
- a signal representative of a voluntary gesture by the second user is characteristic of the second user.
- the shape of the signal generated and transmitted via the user's body depends in particular on a certain number of characteristics specific to the wearer (body size, age, sex, tissue humidity, morphology internal tissues (bones, tendons, muscles), etc.). The analysis of such a signal (shape, power, etc.) makes it possible to identify characteristics specific to the user.
- the radio signal intended for the terminal of the first user is modified on the one hand when transmitting through the body of the second user and on the other hand when transmitting through the body of the first user.
- the terminal of the first user therefore receives a radio signal carrying the characteristics of the second user and the characteristics of the first user.
- the biometric signature of the second user can be obtained either from the analysis of the radio signal intended for the terminal of the first user or encoded in a frame of the radio signal.
- the biometric signature of the second user may correspond to the signal representative of the voluntary gesture of the second user or else to a group of characteristic data obtained by analyzing the shape and the power of this signal.
- the invention thus enables secure transmission of the biometric signature of the second user to the terminal of the first user. Indeed, such a transmission requires the presence of the second user and a voluntary gesture on his part to activate the transmission.
- the supply method further comprises the initialization of at least one validity criterion associated with the biometric signature of the second user, the validity criterion being encoded in a frame of the radio signal. issued.
- the delegation is set up is done in a controlled manner by the second user.
- the initialization of a validity criterion makes it possible to control the use by the first user of the biometric signature of the second user who has been delegated to him.
- the second user can thus set a criterion to be validated during the use of his biometric signature by the first user.
- a criterion can correspond to a number of uses of the biometric signature, or else to a maximum amount not to be exceeded during a payment transaction or even a combination of the two.
- the validity criterion may be an identifier or a code to be verified when the biometric signature is used by the first user.
- the generation of the radio signal comprises: obtaining a group of data characteristic of the second user from a radio signal transmitted by the transmitting device and received by a terminal of the second user via a channel using the electromagnetic wave conduction capabilities of the second user's body when the second user contacts or brushes a surface of the sending device, encoding the group of characteristic data of the second user into the radio signal to the destination of the first user's terminal.
- the characteristic data of the voluntary gesture of the second user are obtained by the sending device and encoded in the radio signal intended for the terminal of the first user.
- the terminal of the first user it is not necessary to analyze the form and the power of the signal received by the terminal of the first user to extract the signal representative of the voluntary gesture of the second user or the data characteristic of this voluntary gesture from the received radio signal. by the terminal of the first user.
- the invention also relates to a method for obtaining by a terminal of a first user a biometric signature of a second user.
- Such a method of obtaining is implemented by the terminal of the first user and comprises: receiving a radio signal transmitted by a transmitting device according to a near-field communication technology, via a channel using the conduction capacities of electromagnetic wave of the body of the second user when the second user contacts or brushes a surface of the transmitting device and through a channel using the electromagnetic wave conduction capabilities of the body of the first user when the first user contacts or touches the second user, obtaining from the received radio signal the biometric signature of the second user, storing in a secure memory space of the terminal of the first user of the biometric signature of the second user obtained.
- the obtaining method further comprises decoding from the received radio signal and storing a validity criterion associated with the biometric signature of the second user.
- obtaining the biometric signature of the second user comprises decoding a group of data characteristic of the second user.
- the characteristic data of the second user are directly encoded in a frame of the radio signal received by the terminal.
- obtaining the biometric signature of the second user comprises extracting a signal characteristic of the second user from the radio signal received and from a signal characteristic of the first user previously memorized by the terminal.
- the biometric signature of the second user is not encoded in the radio signal.
- the radio signal received is representative of the convolution of the voluntary gesture of the second user and of the deformation of this gesture by the transfer function of the first user.
- the biometric signature of the second user is then obtained by a de-convolution of the signal radio received using a characteristic signal (or transfer function) of the first user which has been learned beforehand.
- obtaining the biometric signature of the second user comprises obtaining a group of data characteristic of the second user from the characteristic signal of the second user extracted.
- This particular embodiment of the invention makes it possible to use fewer resources to store the biometric signature of the second user because only the characteristic points of the signal representative of the voluntary gesture of the second user are stored and not the entire signal.
- the use of the biometric signature of the second user by the first user is simplified, since subsequent authentication is performed by comparing characteristic data from signals representative of the user's voluntary actions.
- the invention also relates to a method for authenticating a first user using a biometric signature of a second user, implemented by an authentication device.
- Such an authentication method comprises: receiving, from a terminal of the first user, data representative of the biometric signature of the second user, obtaining data characteristic of the second user from data representative of the biometric signature of the second user, the comparison of the characteristic data of the second user obtained with reference characteristic data of the second user, when the characteristic data of the second user obtained correspond to the reference characteristic data of the second user, validation of the authentication of the first user .
- the authentication method further comprises: obtaining from the data received, at least one validity criterion associated with the biometric signature, verifying that the validity criterion is satisfied, the validation of the authentication of the first user being implemented only when the validity criterion is satisfied.
- the authentication method further comprises: updating said at least one validity criterion, sending the first user to the terminal of said at least one updated validity criterion. day.
- the validity criterion corresponds to at least one of the following criteria: a maximum number of uses of the biometric signature, a maximum amount authorized during a payment transaction, a cumulative amount maximum authorized during successive payment transactions, an identifier, a code.
- the validity criterion is satisfied when a value of the validity criterion is positive or when a value of the validity criterion corresponds to a predetermined value.
- the invention also relates to a sender device configured to provide a terminal of a first user with a biometric signature of a second user, comprising a processor and a memory configured for:
- the invention also relates to a terminal of a first user configured to obtain a biometric signature from a second user, comprising a processor and a memory configured for:
- the invention also relates to an authentication device for authenticating a first user using a biometric signature of a second user, comprising a processor and a memory configured for:
- characteristic data of the second user from data representative of the biometric signature of the second user, Compare the characteristic data of the second user obtained with reference characteristic data of the second user, When the characteristic data of the second user obtained correspond to the reference characteristic data of the second user, validate the authentication of the first user.
- the invention also relates to a computer program comprising instructions for implementing the supply method or the obtaining method or the authentication method mentioned above according to any one of the particular embodiments described above. , when said program is executed by a processor.
- These methods can be implemented in various ways, in particular in wired form or in software form.
- These programs can use any programming language, and be in the form of source code, object code, or intermediate code between source code and object code, such as in a partially compiled form, or in any other. desirable shape.
- the invention also relates to a recording medium or information medium readable by a computer, and comprising instructions of a computer program as mentioned above.
- the aforementioned recording media can be any entity or device capable of storing the program.
- the medium can comprise a storage means, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or else a magnetic recording means, for example a hard disk.
- the recording media can correspond to a transmissible medium such as an electrical or optical signal, which can be conveyed via an electrical or optical cable, by radio or by other means.
- the programs according to the invention can in particular be downloaded from an Internet type network.
- the recording media can correspond to an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in the execution of the method in question.
- FIG. 1A illustrates an implementation of the delegation to a user USR1 of a biometric signature of a user USR2 according to a particular embodiment of the invention.
- FIG. IB illustrates authentication of the user USR1 from the biometric signature of the user USR2 with an authentication device, according to a particular embodiment of the invention.
- FIG. 2 illustrates the steps of the method for providing a biometric signature and the steps of the method for obtaining the biometric signature according to a particular embodiment of the invention.
- FIG. 3 illustrates the steps of the method for providing a biometric signature according to another particular embodiment of the invention.
- FIG. 4 illustrates the steps of the process for obtaining a biometric signature according to another particular embodiment of the invention.
- FIG. 5 illustrates the steps of the authentication method according to a particular embodiment of the invention.
- Figure 6 illustrates the simplified structure of a transmitter device configured to implement steps of the method of providing a biometric signature according to a particular embodiment of the invention.
- FIG. 7 illustrates the simplified structure of a terminal configured to implement steps of the method of obtaining a biometric signature according to a particular embodiment of the invention.
- FIG. 8 illustrates the simplified structure of an authentication device configured to implement steps of the authentication method according to a particular embodiment of the invention.
- the invention allows a user (USR2 in Figure IA) to delegate a biometric signature, or biometric rights to a third party (USR1 in Figure IA).
- a user USR2 in Figure IA
- a third party USR1 in Figure IA
- the invention is based on an IBC-type technology according to which the Voluntary User Gesture (USR2) is the biometric reference or signature.
- FIG. 1A illustrates the implementation of the delegation to the user USR1 of the biometric signature of the user USR2.
- the user USR2 chooses at least one criterion Cr for the validity of the delegation.
- a criterion can be a number of times the user USR1 will have the right to use the biometric signature of the user USR2 to authenticate himself with a service, for example to carry out a banking or payment transaction. . This number is chosen by the user USR2 for example on an interface of an NFC transmitter device 10.
- the validity criterion Cr can also be a transaction amount not to be exceeded.
- the validity criterion Cr can also be an identifier or code to be transmitted to the payment service in addition to the biometric signature of the user USR2.
- This code can be defined by the user USR2 when setting up the delegation. For example, when the user USR2 sets up the delegation, he uses a dedicated application on his terminal or on the sending device 10 via which he declares the setting up of the delegation by providing information such as the identifier of the. user USR1, the code to verify when user USR1 wants to authenticate with a service using the biometric signature of user USR2. This information is transmitted and stored on a server managing the biometric signature delegation, in association with the reference biometric signature or reference signal of the user USR2.
- User USR2 must then transmit their biometric signature to user USR1 in a secure manner.
- the user USR2 will on the one hand touch the NFC transmitter device 10 which transmits an NFC signal in IBC format, and on the other hand ask the user USR1 to stand near him.
- the user USR2 then performs his voluntary movement GV by touching or touching the surface of the transmitter device 10.
- Such a voluntary gesture GV corresponds for example to a determined movement of the hand or finger of the user USR2 on the surface that the user USR2 makes when he wishes to authenticate himself with a service.
- a voluntary gesture can simply consist of bringing your hand to the transmitter device 10.
- the NFC signal transmitted by the transmitter device 10 is modified and conducted by the body of the transmitter.
- the user USR2 then by the body of the user USR1 placed near the latter, to the terminal 11 of the user USR1.
- Such a modified and transmitted signal GV (t) corresponds to the signal also called Voluntary Gesture of the user USR2 carrying the characteristics of the user USR2.
- the terminal 11 of the user USR1 is equipped with a dedicated application making it possible to retrieve and store the biometric signature of the user USR2 from the signal GV (t) received.
- this or these validity criterion (s) Cr initialized by the user USR2 are encoded in a frame of the NFC signal GV (t) and recovered by terminal 11.
- the terminal 11 can store the signal GV (t) received directly or else extract from this signal a group of characteristic data Pi.
- the characteristic data group Pi can be coded in a frame of the NFC signal GV (t).
- the biometric signature (GV (t) or Pi) and the validity criterion (s) Cr are stored in a secure memory VLT of the terminal 11, also called a safe or "vault" in English.
- VLT secure memory
- the biometric signature and the validity criteria are stored in an encrypted manner.
- FIG. IB illustrates the authentication of the user USR1 from the biometric signature of the user USR2 with an authentication device 12.
- an authentication device 12 may be a server, a terminal. payment, an access point, etc.
- the user USR1 uses a dedicated application on his terminal 11 which accesses the secure space VLT of the terminal 11.
- the user USR1 for example dials a secret code allowing access to the secure area to be unlocked.
- the terminal 11 transmits to the authentication device 12 the biometric signature (GV (t) or Pi), and possibly the validity criteria or criteria Cr when they are present, and an identifier of the user USR2 if it does not. has not already provided it to the authentication device 12.
- Such a transmission can be carried out using wireless communication, for example Bluetooth, WI-FI, 4G or the like.
- the authentication device 12 verifies the or the validity criteria and whether the biometric signature transmitted corresponds to the reference biometric signature of the user USR2.
- FIG. 2 illustrates the steps of the method for providing a biometric signature and the steps of the method for obtaining the biometric signature according to a particular embodiment of the invention.
- the supply method is for example implemented by the sending device 10 of FIG. IA, and the obtaining method is for example implemented by the terminal 11 of the user USR1.
- At least one validity criterion is initialized by the user USR2 on the sending device 10.
- a criterion corresponds for example to a maximum number of times the biometric signature is used by the user USR1, or indeed to a maximum amount authorized during a payment transaction carried out by the user USR1 using the biometric signature of the user USR2, or even to a maximum cumulative amount authorized during successive payment transactions carried out by the user USR1 using the biometric signature of the user USR2.
- the validity criterion may be a code with several digits or letters defined by the user USR2.
- the validity criterion can be a combination of the aforementioned criteria.
- This initialized validity criterion is associated by the sending device 10 with the biometric signature of the user USR2. It can be transmitted by the sending device 10 to a server storing the reference biometric signature of the user USR2 and associated with an identifier of the user USR1 for example, for more security when using the biometric signature.
- the validity criterion is encoded by the transmitter device 10 in a field of a frame of a radio signal S2.
- This radio signal S2 is generated by the transmitter device 10 using near-field communication technology (NFC).
- the biometric signature of the user USR2 is also encoded in a frame of the generated radio signal S2.
- the biometric signature is represented by a group Pi of data characteristic of the user USR2 obtained from an NFC radio signal Si transmitted by the sending device 10 to a terminal of the user USR2 using the electromagnetic wave conduction capacities of the body of user USR2.
- the signal Si corresponds to the signal representative of the voluntary gesture of the user USR2.
- the group Pi of characteristic data of the user USR2 was obtained by the transmitter device 10. This preliminary phase is described in more detail in relation to FIG. 3.
- the transmitter device 10 transmits an NFC Si signal.
- the NFC Si signal is transmitted according to the IBC format.
- Such a signal Si is modified when the user USR2 comes into contact with or touches a surface of the emitting device 10. This modified signal Si is carried by the body of the user USR2 to a terminal of the user USR2 which receives it. .
- the terminal of the user USR2 analyzes the signal Si received and extracts the group Pi of data characteristic of the user USR2. This data group Pi is then stored in a memory of the user's terminal USR2 and possibly transmitted to the sending device 10, via a return communication channel, for example in Bluetooth or WiFi.
- F ’analysis of the received signal is for example described in patent application WO2016001506A1.
- the transmitter device 10 obtains during a step E32, the data group Pi characteristics of the user USR2.
- This data group Pi can be obtained either from a memory of the transmitter device 10 or else received from the terminal of the user USR2, for example by Bluetooth or WiFi.
- the data group Pi characteristics of the user USR2 is encoded in a frame of the radio signal S2 generated by the transmitter device 10.
- the data group Pi characteristic of the user USR2
- the transmitter device 10 transmits the generated radio signal S2 to the terminal 11 of the user USR1, according to the IBC format.
- This signal S2 is conducted through a channel using the electromagnetic wave conduction capabilities of the body of the user USR2 when the user USR2 contacts or brushes a surface of the emitting device 10 and through a channel using the conduction capabilities of the user.
- the terminal 11 of the user USR1 receives the radio signal S2 transmitted by the transmitter device 10 using NFC near-field communication technology.
- the received S2 signal is a signal modified by conduction through the body of the user USR2 and conduction through the body of the user USR1.
- the terminal 11 decodes the validity criteria or criteria encoded in a frame of the received radio signal S2.
- the terminal 11 obtains from the received radio signal S2 the biometric signature of the user USR2.
- the biometric signature is encoded in a frame of the received radio signal S2
- the data Pi characteristic of the user USR2 are decoded from the radio signal S2.
- the biometric signature of the user USR2 is obtained from the analysis of the shape and the power of the signal S2.
- Step E25 is described in more detail according to this variant in relation to Figure 4.
- a characteristic signal GV (t) of the user USR2 is extracted from the received radio signal S2 and from a characteristic signal GV1 (t) of the user USR1 previously stored by the terminal 11.
- the signal S2 comes from a convolution of the signal emitted by the emitting device 10 by the transfer function representative of the conduction by the body of the user USR1 and by the transfer function representative of the conduction by the body of user USR2.
- the characteristic signal GV (t) of the user USR2 is therefore obtained by a de-convolution (or inverse convolution) of the signal S2 by the characteristic signal GV1 (t) of the user USR1.
- the biometric signature of the USR2 user is represented by the characteristic signal GV (t)
- this signal is stored as it is in the user terminal 11 USR1.
- the biometric signature of the user USR2 is represented by the data group Pi
- the data group Pi characteristic of the user USR2 is obtained from the characteristic signal GV (t) extract.
- the biometric signature (GV (t) or Pi) of the user USR2 is stored by the terminal 11 in a secure memory space of the terminal 11, with the criteria (s) validity decoded when present.
- the user USR1 is invited to initialize a secret code making it possible to lock access to the biometric signature of the user USR2 stored on his terminal 11.
- the biometric signature will therefore only be accessible on the terminal 11. 'after dialing the secret code by the user of the terminal 11.
- FIG. 5 illustrates steps of the authentication method according to a particular embodiment of the invention, in which the user USR1 uses the biometric signature of the user USR2 to authenticate himself.
- the authentication method is for example implemented by the authentication device 12 of FIG. IB.
- the user USR1 requests to be authenticated with the authentication device 12. For example, it may be a question of validating a payment transaction in the name of or on behalf of the user USR2. .
- This authentication request is for example implemented via a dedicated payment application installed on the terminal 11 and configured to communicate with the authentication device 12, for example a payment terminal.
- the user USR1 To request authentication using the biometric signature of the user USR2, the user USR1 must unlock access to the biometric signature stored on his terminal 11.
- the application for example invites the user USR2 to enter his secret code. to unlock access to the biometric signature and allow its transmission to the authentication device 12. If the user USR2 fails when entering the secret code, possibly after several attempts, the authentication process fails.
- the terminal 11 of the user USR1 transmits to the authentication device 12 the data representative of the biometric signature of the user USR2.
- data include in particular: an identifier of the user USR2, the biometric signature of the user USR2 in the form of a characteristic signal GV (t) or of a group of data Pi, and the associated validity criteria (s) to the biometric signature when they are present, and possibly an identifier of the first user.
- the authentication device 12 Following receipt by the authentication device 12 of the data transmitted by the terminal 11 of the user USR1, during a step E52, the authentication device 12 obtains the validity criteria or criteria. In particular, when a code type criterion is received, the authentication device 12 obtains from a server the code initialized by the user USR2 during the implementation of the delegation of the biometric signature.
- the authentication device 12 verifies that the validity criteria (s) is (are) satisfied. For example, when the validity criterion corresponds to a maximum number of uses of the biometric signature, it is checked whether the maximum number of uses is strictly greater than 0. When the validity criterion corresponds to a maximum authorized amount, it is checked is checked if the maximum authorized amount is greater than or equal to the amount of the payment transaction to be validated. When the validity criterion corresponds to a maximum authorized cumulative amount, it is checked whether the maximum authorized cumulative amount is greater than or equal to the amount of the payment transaction to be validated. When the validity criterion corresponds to a code, it is verified that the code received is identical to the code initialized by the user USR2 when setting up the delegation of the biometric signature.
- the authentication process fails.
- the authentication device 12 calculates the data group Pi from the characteristic signal GV (t).
- the authentication device 12 compares the group of data Pi obtained with characteristic reference data Pi ref of the user USR2. These reference data Pi ref are obtained by the authentication device 12 from the identifier of the user USR2, either from a memory of the authentication device 12, or received from a server (not shown) .
- step E55 if the group of data Pi obtained does not correspond to the characteristic reference data Pi ref of the user USR2, the authentication process fails.
- the authentication device 12 validates the authentication of the user USR1 via the biometric signature of the user USR2.
- the validity criterion is updated.
- the value of the validity criterion is reduced by 1.
- the value of the validity criterion is set to 0. It is considered here that the user USR1 is authorized to use the biometric signature of the user USR2 only once.
- the validity criterion corresponds to a maximum authorized cumulative amount
- the value of the validity criterion is reduced by the amount of the transaction to be validated.
- the authentication device 12 sends to the terminal 11 of the user USR1 the updated validity criterion which is then stored by the terminal 11 in the secure memory space.
- Figure 6 illustrates the simplified structure of a transmitter device configured to implement steps of the method of providing a biometric signature according to a particular embodiment of the invention.
- the transmitter device 10 has the conventional architecture of a computer, and in particular comprises a memory MEM, a processing unit UT, equipped for example with a processor PROC, and controlled by the computer program PG stored in memory MEM.
- the computer program PG comprises instructions for implementing the steps of the method for providing a biometric signature as described above, when the program is executed by the processor PROC.
- the code instructions of the computer program PG are for example loaded into a memory before being executed by the processor PROC.
- the processor PROC of the processing unit UT notably implements the steps of the method for providing a biometric signature according to any one of the particular embodiments described in relation to FIGS. 1A, 2 and 3, according to the instructions of the computer program PG.
- the transmitter device 10 also comprises a near-field communication module ANT comprising in particular an antenna adapted to transmit signals on the radio channel and possibly via the human body and a modulator intended to adapt a digital signal produced by the processor into an electrical signal.
- modulated intended to be transmitted, via the antenna.
- the modulation operation performed by the modulator is for example an amplitude modulation: the signal is a 13.56 MHz signal modulated in amplitude with a modulation rate of about 10% (known characteristic of type B according to the standard NLC).
- the invention is not, however, limited to this type of modulation.
- the modulation is frequency modulation, less sensitive to interference, or phase modulation.
- the transmitter device 10 is provided with a contact surface, not shown, adapted to react in the immediate proximity of the user (contact, quasi-contact, touch, etc.) .
- this surface corresponds to the antenna, so that a modulated electrical signal emitted via the antenna is able to be carried by the body of the user which is in proximity to the surface.
- the antenna can be integrated into the surface. The surface is arranged to cooperate with the processing unit UT to implement the steps of the method of providing a biometric signature.
- the transmitter device 10 comprises a BT radio module of the Bluetooth or Wi-Li type intended in particular for exchanging data with the terminal 11 of the user USR1 and a terminal of the user USR2.
- the transmitter device 10 comprises a communication interface COM allowing the transmitter device 10 to establish communications via a fixed or mobile data network.
- the transmitter device 10 comprises an AFF display module, for example a screen and a user interaction module UI, for example a numeric keypad.
- AFF display module for example a screen
- UI user interaction module
- the transmitter device 10 is included in a terminal.
- FIG. 7 illustrates the simplified structure of a terminal 11 configured to implement steps of the method of obtaining a biometric signature according to a particular embodiment of the invention.
- the terminal li has the conventional architecture of a computer, and comprises in particular a memory MEM7, a processing unit UT7, equipped for example with a processor PROC7, and controlled by the computer program PG7 stored in memory MEM7.
- the PG7 computer program includes instructions for performing the steps of the method of obtaining a biometric signature as described above, when the program is executed by the PROC7 processor.
- the code instructions of the computer program PG7 are for example loaded into a memory before being executed by the processor PROC7.
- the processor PROC7 of the processing unit UT7 notably implements the steps of the method for obtaining a biometric signature according to any one of the particular embodiments described in relation to FIGS. 1A-2 and 4 and of the method authentication method described in relation to FIGS. 1B and 5, according to the instructions of the computer program PG7.
- the terminal 11 also comprises a near-field communication module ANT7 comprising in particular a CBB antenna adapted to receive signals on the radio channel and possibly via the human body, so that 'an electrical signal modulated and possibly transported by the body of the user is able to be received by the antenna, which is located in the terminal, in proximity to the human body, a demodulator intended to receive via the antenna a modulated electrical signal and to transform it into a digital signal intended to be transmitted to the processing unit UT7 and the software components (firmware, etc.) necessary for the implementation of CBB / IBC communications.
- ANT7 comprising in particular a CBB antenna adapted to receive signals on the radio channel and possibly via the human body, so that 'an electrical signal modulated and possibly transported by the body of the user is able to be received by the antenna, which is located in the terminal, in proximity to the human body, a demodulator intended to receive via the antenna a modulated electrical signal and to transform it into a digital signal intended to be transmitted to the processing unit UT7 and the
- the terminal 11 also includes a secure memory VLT configured to securely store on the terminal 11 the biometric signature of the user USR2 and the associated data (notably validity criterion).
- a VLT memory is secured by cryptographic means.
- the terminal 11 comprises a Bluetooth or Wi-Fi type BT7 radio module intended in particular to exchange data with an authentication device 12.
- the terminal 11 comprises a communication interface COM7 allowing the terminal 11 to establish communications via a mobile data network.
- the terminal 11 comprises a user interaction module INT, for example a touch screen.
- the terminal 11 is included in a smartphone.
- FIG. 8 illustrates the simplified structure of an authentication device 12 configured to implement steps of the authentication method according to a particular embodiment of the invention.
- the authentication device 12 has the conventional architecture of a computer, and in particular comprises a memory MEM8, a processing unit UT8, equipped for example with a processor PROC8, and controlled by the computer program PG8 stored in memory MEM8.
- the computer program PG8 includes instructions for implementing the steps of the authentication method as described above, when the program is executed by the processor PROC8.
- the code instructions of the computer program PG8 are for example loaded into a memory before being executed by the processor PROC8.
- the processor PROC8 of the processing unit UT8 notably implements the steps of the authentication method according to any one of the particular embodiments described in relation to FIGS. IB, and 5, according to the instructions of the computer program PG8.
- the authentication device 12 is included in a payment terminal.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Theoretical Computer Science (AREA)
- Signal Processing (AREA)
- General Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Business, Economics & Management (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Accounting & Taxation (AREA)
- Software Systems (AREA)
- Biomedical Technology (AREA)
- General Health & Medical Sciences (AREA)
- Health & Medical Sciences (AREA)
- Computing Systems (AREA)
- General Business, Economics & Management (AREA)
- Strategic Management (AREA)
- Finance (AREA)
- Measurement Of The Respiration, Hearing Ability, Form, And Blood Characteristics Of Living Organisms (AREA)
- Collating Specific Patterns (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR2003038A FR3108750A1 (fr) | 2020-03-27 | 2020-03-27 | Procédé et dispositif de fourniture à un terminal d’un premier utilisateur d’une signature biométrique d’un deuxième utilisateur. |
| PCT/FR2021/050482 WO2021191546A1 (fr) | 2020-03-27 | 2021-03-22 | Procede et dispositif de fourniture a un terminal d'un premier utilisateur d'une signature biometrique d'un deuxieme utilisateur |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP4128696A1 true EP4128696A1 (fr) | 2023-02-08 |
Family
ID=71111584
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP21717494.5A Pending EP4128696A1 (fr) | 2020-03-27 | 2021-03-22 | Procede et dispositif de fourniture a un terminal d'un premier utilisateur d'une signature biometrique d'un deuxieme utilisateur |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US12250543B2 (fr) |
| EP (1) | EP4128696A1 (fr) |
| FR (1) | FR3108750A1 (fr) |
| WO (1) | WO2021191546A1 (fr) |
Families Citing this family (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20230090122A1 (en) * | 2020-03-10 | 2023-03-23 | Nec Corporation | Photographing control device, system, method, and non-transitory computer-readable medium storing program |
Family Cites Families (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2011134332A (ja) * | 2009-12-22 | 2011-07-07 | Korea Electronics Telecommun | 人体通信を用いた認証装置、人体通信を用いた認証機能を備えた携帯装置及び人体通信を用いた認証方法 |
| EP3075085B1 (fr) * | 2013-11-27 | 2020-01-08 | Shenzhen Goodix Technology Co., Ltd. | Dispositifs de communication portatifs pour des transactions et des communications sécurisées |
| KR102080747B1 (ko) * | 2014-03-28 | 2020-02-24 | 엘지전자 주식회사 | 이동 단말기 및 그것의 제어 방법 |
| FR3023090A1 (fr) | 2014-06-30 | 2016-01-01 | Orange | Dispositif de validation d'une transaction lors d'une communication radio mettant en oeuvre le corps humain |
| US11256792B2 (en) * | 2014-08-28 | 2022-02-22 | Facetec, Inc. | Method and apparatus for creation and use of digital identification |
| RU2665286C1 (ru) * | 2017-11-29 | 2018-08-28 | Самсунг Электроникс Ко., Лтд. | Устройство и способ для установления радиочастотной связи посредством прикосновения пользователя |
-
2020
- 2020-03-27 FR FR2003038A patent/FR3108750A1/fr not_active Withdrawn
-
2021
- 2021-03-22 EP EP21717494.5A patent/EP4128696A1/fr active Pending
- 2021-03-22 US US17/914,526 patent/US12250543B2/en active Active
- 2021-03-22 WO PCT/FR2021/050482 patent/WO2021191546A1/fr not_active Ceased
Also Published As
| Publication number | Publication date |
|---|---|
| FR3108750A1 (fr) | 2021-10-01 |
| WO2021191546A1 (fr) | 2021-09-30 |
| US20230141504A1 (en) | 2023-05-11 |
| US12250543B2 (en) | 2025-03-11 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3221815B1 (fr) | Procédé de sécurisation d'un jeton de paiement. | |
| FR2989799A1 (fr) | Procede de transfert d'un dispositif a un autre de droits d'acces a un service | |
| WO2002065414A1 (fr) | Procede et systeme de telepaiement | |
| US20160073263A1 (en) | Client, computing platform, and methods for conducting secure transactions | |
| EP3238150B1 (fr) | Procédé de sécurisation de transactions sans contact | |
| EP4305573B1 (fr) | Canal de paiement universel | |
| EP3252692B1 (fr) | Procédé de fourniture de données relatives à une transaction de paiement, dispositif et programme correspondant | |
| EP2943944A1 (fr) | Système et procédé d'autorisation de transactions électroniques à base audio | |
| FR3025377A1 (fr) | Gestion de tickets electroniques | |
| EP3552327B1 (fr) | Procédé de personnalisation d'une transaction sécurisée lors d'une communication radio | |
| WO2021191546A1 (fr) | Procede et dispositif de fourniture a un terminal d'un premier utilisateur d'une signature biometrique d'un deuxieme utilisateur | |
| WO2015033061A1 (fr) | Procédé d'authentification de transaction | |
| EP3588418A1 (fr) | Procédé de réalisation d'une transaction, terminal, serveur et programme d ordinateur correspondant | |
| WO2016207715A1 (fr) | Gestion securisee de jetons électroniques dans un telephone mobile. | |
| EP4285491A1 (fr) | Procédé et dispositif d'adaptation d'une communication en champ proche | |
| WO2015097402A1 (fr) | Transmission et traitement de données relatives a une transaction sans contact | |
| EP3987416A1 (fr) | Procede et dispositif d'authentification d'un utilisateur utilisant la conductivité du corps humain | |
| WO2019186041A1 (fr) | Procédé et dispositif d'authentification d'un utilisateur | |
| FR2850772A1 (fr) | Procede et dispositif de securisation de transactions electroniques effectuees sur un terminal non securise | |
| EP3570238B1 (fr) | Procédé de réalisation d'une transaction, terminal, serveur et programme d'ordinateur correspondant | |
| FR3119284A1 (fr) | Procédé et dispositif de transfert de données en champ proche. | |
| FR2903544A1 (fr) | Procede de securisation d'une authentification par utilisation de plusieurs canaux | |
| EP3223219A1 (fr) | Procédé de transfert de transaction, procédé de transaction et terminal mettant en oeuvre au moins l'un d'eux | |
| FR2988889A1 (fr) | Procede de realisation d'une transaction |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20221021 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| RAP3 | Party data changed (applicant data changed or rights of an application transferred) |
Owner name: ORANGE |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |