TW201947454A - Secure enrolment of biometric data - Google Patents

Secure enrolment of biometric data Download PDF

Info

Publication number
TW201947454A
TW201947454A TW107115429A TW107115429A TW201947454A TW 201947454 A TW201947454 A TW 201947454A TW 107115429 A TW107115429 A TW 107115429A TW 107115429 A TW107115429 A TW 107115429A TW 201947454 A TW201947454 A TW 201947454A
Authority
TW
Taiwan
Prior art keywords
biometric measurement
measurement data
secure
biometric
processing unit
Prior art date
Application number
TW107115429A
Other languages
Chinese (zh)
Inventor
何賽 伊格納西歐 韋恩特格爾斯特 拉維恩
金 克里斯汀 荷姆伯爾斯泰德
霍爾根 法蘭德森
彼得 羅伯特 羅伊
Original Assignee
挪威商斯外普公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 挪威商斯外普公司 filed Critical 挪威商斯外普公司
Priority to TW107115429A priority Critical patent/TW201947454A/en
Publication of TW201947454A publication Critical patent/TW201947454A/en

Links

Abstract

To provide improved security during enrolment of a user onto a biometric smartcard 105, a secure enrolment processing unit 203 is used to ensure that the biometric data cannot be easily intercepted. A method of enrolling of the user onto the biometric smartcard 105 comprises reading a fingerprint of the user using a fingerprint sensor 201 on the enrolment processing unit 203, extracting biometric data corresponding to the fingerprint, the extraction being performed in a secure processing environment of the enrolment processing unit 203, converting the biometric data to secure biometric data within the secure processing environment, and then transmitting the secure biometric data from the enrolment processing unit to the smartcard 105. The user's biometric data is thus only transmitted in a secure format.

Description

生物特徵量測資料之安全登記Safe registration of biometric measurement data

本發明關於在登記程序期間生物特徵量測資料的安全性。The present invention relates to the security of biometric measurement data during the registration process.

生物特徵量測授權裝置(譬如指紋授權智慧卡),已愈來愈廣泛被使用。舉例來說,已被提出用於生物特徵量測授權之智慧卡包含通行卡、信用卡、金融卡、預付卡、會員卡、身份識別卡等。智慧卡係電子卡,能夠譬如透過非接觸式技術(如無線射頻識別(RFID)及近場通信(NFC))儲存資料,及與使用者及/或外部裝置交互作用。此等卡可與感測器交互作用,以傳達資訊以存取、授權交易等。亦已知其他利用生物特徵量測授權(譬如指紋授權)之裝置,且此等裝置包含電腦記憶體裝置、建築物出入管制裝置、軍事技術、車輛等。Biometric measurement authorization devices (such as fingerprint authorization smart cards) have been used more and more widely. For example, smart cards that have been proposed for biometric measurement authorization include pass cards, credit cards, financial cards, prepaid cards, membership cards, identity cards, and the like. Smart cards are electronic cards that can store data and interact with users and / or external devices, such as through contactless technologies such as radio frequency identification (RFID) and near field communication (NFC). These cards can interact with sensors to convey information for access, authorize transactions, and more. Other devices using biometric measurement authorization (such as fingerprint authorization) are also known, and these devices include computer memory devices, building access control devices, military technology, vehicles, and the like.

在一系統中,生物特徵量測資料被儲存於譬如一智慧卡之一實體裝置上,需以一安全方式登記該裝置之使用者。也就是說,使用者之生物特徵量測識別符必須被掃描,且生物特徵量測資料(譬如一生物特徵量測影像或由該生物特徵量測影像歸納之一生物特徵量測模板)儲存於該裝置上。期望能夠達成而不致危及使用者隱私。In a system, biometric measurement data is stored on a physical device such as a smart card, and the user of the device needs to be registered in a secure manner. That is, the user's biometric measurement identifier must be scanned, and biometric measurement data (such as a biometric measurement image or a biometric measurement template summarized from the biometric measurement image) is stored in On the device. Expect to do so without compromising user privacy.

某些生物特徵量測授權智慧卡包含一內建生物特徵量測感測器。儘管對自我登記(即使用一內建指紋感測器將指紋登記於該裝置上)之使用者有利,然這亦對該生物特徵量測授權裝置加諸額外限制,由於如果該裝置依此方式運作,該內建感測器必須附帶地能夠登記新生物特徵量測資料。舉例來說,這可需要具有較佳解析度或較大尺寸之感測器,及/或可能必須要較大程度之電功率。例如,在一指紋作為該生物特徵量測資料之情況下,通常允許根據一局部指紋來識別一使用者,然而登記通常需要一完整指紋及反覆之指紋掃描來建立一完整指紋「模板」來用於以後之使用者身份認證。如此,使用相同感測器於登記來當作授權並非總是理想的。Some biometric measurement authorized smart cards include a built-in biometric measurement sensor. Although beneficial to users who self-enroll (i.e., enroll their fingerprints on the device using a built-in fingerprint sensor), this also places additional restrictions on the biometric measurement authorization device, because if the device is in this way In operation, the built-in sensor must be incidentally capable of registering new biometric measurements. For example, this may require a sensor with a better resolution or larger size, and / or may require a greater degree of electrical power. For example, when a fingerprint is used as the biometric measurement data, it is usually allowed to identify a user based on a partial fingerprint. However, registration usually requires a complete fingerprint and repeated fingerprint scans to create a complete fingerprint "template" for use. User authentication in the future. As such, it is not always ideal to use the same sensor for registration as authorization.

第1圖顯示一用於如何可使用一分離之登記生物特徵量測感測器將使用者登記於一生物特徵量測智慧卡105上之先前技術。以指紋生物特徵量測作為範例來說明,但其他生物特徵量測,譬如一語音簽章,亦可依相同方式儲存。FIG. 1 shows a prior art for how a user can be registered on a biometric measurement smart card 105 using a separate registered biometric measurement sensor. The fingerprint biometric measurement is taken as an example for description, but other biometric measurements, such as a voice signature, can also be stored in the same way.

指紋登記模組101包括至少與用於智慧卡105上之指紋感測器之品質一樣高的指紋感測器,指紋登記模組101被用來擷取使用者之指紋。指紋登記模組101部署於使用者待登記之一位置處,且被內含於一登記管理裝置102中。登記管理裝置102之目的係管理登記。這可為登記管理裝置102提供之眾多功能之一,該登記管理裝置可在銀行業務方案中提供眾多其他功能,譬如提供自動提款機(ATM)服務。The fingerprint registration module 101 includes a fingerprint sensor of at least as high quality as the fingerprint sensor used on the smart card 105. The fingerprint registration module 101 is used to capture a user's fingerprint. The fingerprint registration module 101 is deployed at a position to be registered by the user, and is contained in a registration management device 102. The purpose of the registration management device 102 is to manage registration. This can be one of the many functions provided by the registration management device 102, which can provide many other functions in the banking solution, such as providing an automatic teller machine (ATM) service.

登記管理裝置102能夠藉由在一液晶顯示器(LCD)螢幕或相似者上給予指令,以引導登記者完成登記程序。此等指令可為:伸出常用手指、轉手指向左、轉手指向右、轉手指向上、轉手指向下、以及用力壓下與登記完成。The registration management device 102 can instruct the registrant to complete the registration procedure by giving instructions on a liquid crystal display (LCD) screen or the like. These instructions can be: extending a common finger, turning a finger to the left, turning a finger to the right, turning a finger up, turning a finger down, and pressing down and completing registration.

登記模組101之指紋掃描器的輸出係經由登記管理裝置102、及連接至登記管理裝置102之一控制邏輯103處理。在登記管理裝置102之一常用或習知實施例中,指紋影像被構成為可直接寫至卡片105之一記憶體104的一形式。生物特徵量測資料之一複本經常亦儲存於銀行控制之一伺服器106上。The output of the fingerprint scanner of the registration module 101 is processed by the registration management device 102 and a control logic 103 connected to the registration management device 102. In a commonly used or known embodiment of the registration management device 102, the fingerprint image is configured as a form that can be directly written to a memory 104 of the card 105. A copy of the biometric measurement data is also often stored on a bank-controlled server 106.

卡片105可實體地位於登記管理裝置102之本體內,或者可位於外部且經由適當之實體或無線連接而連接。The card 105 may be physically located within the registration management device 102 itself, or may be located externally and connected via an appropriate physical or wireless connection.

一旦登記後,智慧卡105即可藉對比登記模板與一內建指紋感測器107所掃描之一指紋來授權交易或相似者。Once registered, the smart card 105 may authorize a transaction or the like by comparing the registration template with a fingerprint scanned by a built-in fingerprint sensor 107.

由於強烈期望且確實在某些國家需要一生物特徵量測影像或其描述(譬如一細節清單)未保存在一公共可存取位置,因此這類系統發生一問題。A problem with such systems arises because there is a strong desire and indeed the need in some countries for a biometric measurement image or its description (such as a list of details) not kept in a publicly accessible location.

一旦該生物特徵量測資料儲存於該生物特徵量測裝置上,即因其儲存於一安全記憶體內且僅在一安全處理器內處理,而非常難由一未經授權人員存取。然而,在第1圖所描繪之方法中,該生物特徵量測影像儲存於登記管理系統102之記憶體中未加密,且因此已存取登記管理系統102之記憶體的任何人皆可取得。登記管理系統102通常為一銀行營業處之一電腦的一部份。該登記管理裝置102非常可能由一連網個人電腦(PC)組成,其經由一通用序列匯流排(USB)電纜連附至登記模組101。由於系統簡單,因此一未經授權人員可由多個入口點試圖截取及擷取指紋影像。此外,儲存生物特徵量測資料之一中央資料庫106可出現駭客之期望之目標或相似者。Once the biometric measurement data is stored on the biometric measurement device, it is very difficult to be accessed by an unauthorized person because it is stored in a secure memory and processed only in a secure processor. However, in the method depicted in FIG. 1, the biometric measurement image stored in the memory of the registration management system 102 is not encrypted, and therefore anyone who has accessed the memory of the registration management system 102 can obtain it. The registration management system 102 is usually part of a computer in a bank office. The registration management device 102 is likely to be composed of a networked personal computer (PC), which is connected to the registration module 101 via a universal serial bus (USB) cable. Because the system is simple, an unauthorized person can attempt to capture and capture fingerprint images from multiple entry points. In addition, one of the central databases 106 storing the biometric measurement data may appear as a target or similar of the hacker.

第1圖中所示方法之一附帶問題在於,處理指紋影像(譬如提取指紋模板)之電腦程式係在電腦102內處理。用於實施此程序之演算法經常高度地私有的,且期望防範逆向工程(reverse engineering)。One of the problems with the method shown in FIG. 1 is that a computer program for processing fingerprint images (such as extracting a fingerprint template) is processed in the computer 102. The algorithms used to implement this program are often highly proprietary and are expected to prevent reverse engineering.

本發明提供一種準備生物特徵量測資料以登記一使用者、以及發放一生物特徵量測認證裝置給一使用者的方法,該生物特徵量測認證裝置包括一內建生物特徵量測感測器及一安全處理環境,該方法包括:使用一登記處理單元之一生物特徵量測感測器來讀取該使用者之一生物特徵量測識別符,該登記處理單元具有一安全處理環境且與該生物特徵量測認證裝置分離;提取與該生物特徵量測識別符對應之生物特徵量測資料,該提取在該登記處理單元之該安全處理環境中實施;轉換加密該生物特徵量測資料以產生安全生物特徵量測資料,該加密在該登記處理單元之該安全處理環境內實施;及從該登記處理單元發送該安全生物特徵量測資料至一裝置提供者,該裝置提供者發放生物特徵量測認證裝置;藉該裝置提供者將該生物特徵量測資料載入該生物特徵量測認證裝置;及在載入該安全生物特徵量測資料於該生物特徵量測裝置後,發放該生物特徵量測認證裝置給該使用者。The invention provides a method for preparing biometric measurement data to register a user and issuing a biometric measurement authentication device to a user. The biometric measurement authentication device includes a built-in biometric measurement sensor. And a secure processing environment, the method includes: using a biometric measurement sensor of a registration processing unit to read a biometric measurement identifier of the user, the registration processing unit having a secure processing environment and communicating with The biometric measurement authentication device is separated; the biometric measurement data corresponding to the biometric measurement identifier is extracted, and the extraction is implemented in the secure processing environment of the registration processing unit; the biometric measurement data is encrypted and converted to Generating secure biometric measurement data, the encryption being implemented in the secure processing environment of the registration processing unit; and sending the secure biometric measurement data from the registration processing unit to a device provider, the device provider issuing a biometric Measurement authentication device; the device provider loads the biometric measurement data into the biometric measurement Card device; and in loading the security biometric measurement data after the biometric measuring device, the issuance of biometric authentication device for measuring the user.

上述登記處理單元免除將原始生物特徵量測資料發送至或通過一登記管理系統(譬如一計算終端機(computing terminal)或相似者)之需求。反而,該生物特徵量測資料在該登記處理單元被直接接收,其在此處係在該安全環境內處理。這將限制一未經授權人員可能截取資料之存取點的數量。上述配置現在提供僅單一容易存取點(single easy-to-access)來截取該生物特徵量測資料,即在從該登記處理單元發送至該生物特徵量測裝置期間。然而,在此點被截取之任何生物特徵量測資料已被轉換成安全生物特徵量測資料,因此無法輕易地被利用。如此,上述登記處理單元使該使用者之資料更難以被竊取。The registration processing unit eliminates the need to send or pass the original biometric measurement data to or through a registration management system (such as a computing terminal or the like). Instead, the biometric measurement data is received directly at the registration processing unit, where it is processed within the secure environment. This will limit the number of access points that an unauthorized person may intercept data. The above configuration now provides only a single easy-to-access to intercept the biometric measurement data, that is, during transmission from the registration processing unit to the biometric measurement device. However, any biometric measurement data intercepted at this point has been converted into safe biometric measurement data and therefore cannot be easily used. In this way, the registration processing unit makes it more difficult for the user's data to be stolen.

如本文所用,請了解術語「安全處理環境」係指一防竄改硬體平台,其能夠安全地代管(host)應用軟體、及其機密的且加密的資料。一安全處理環境通常包括至少一安全處理器及一安全記憶體。該處理器及記憶體可作為單一積體電路。一常見之安全處理環境範例係用於一付款卡中之安全元件。As used herein, please understand that the term "secure processing environment" refers to a tamper-resistant hardware platform that can securely host application software and its confidential and encrypted data. A secure processing environment usually includes at least one secure processor and a secure memory. The processor and memory can be used as a single integrated circuit. A common example of a secure processing environment is a secure element used in a payment card.

此外,術語「安全生物特徵量測資料」係指已依一防止未經授權人員能夠取回初始生物特徵量測資料之方式修飾的生物特徵量測資料。例如,該修飾可包括加密、或其他用於混淆該資料之可逆程序。該卡片較佳地包括一逆轉該程序之手段,譬如具有一預儲存的金鑰或使用一公用的金鑰、或具有一預儲存的演算法來解擾(descramble)該資料。在其他實施例中,該修飾可能為不可逆的,譬如其包括雜湊(hashing)或相似者。In addition, the term "safe biometric measurement data" refers to biometric measurement data that has been modified in a manner that prevents unauthorized persons from being able to retrieve the initial biometric measurement data. For example, the modification may include encryption, or other reversible procedures used to obfuscate the material. The card preferably includes a means to reverse the process, such as having a pre-stored key or using a public key, or having a pre-stored algorithm to descramble the data. In other embodiments, the modification may be irreversible, such as it includes hashing or the like.

在一實施例中,該生物特徵量測資料可藉一與該生物特徵量測認證裝置相關聯之金鑰加密。該金鑰可為一公用加密金鑰。該生物特徵量測認證裝置能夠將該安全生物特徵量測資料解密。例如,該生物特徵量測認證裝置可包括一私用解密金鑰,其與該公用加密金鑰對應。可藉由將該安全生物特徵量測資料直接載入該生物特徵量測認證裝置(即未解密)以將該生物特徵量測資料載入該生物特徵量測認證裝置。In one embodiment, the biometric measurement data may be encrypted by a key associated with the biometric measurement authentication device. The key can be a public encryption key. The biometric measurement authentication device can decrypt the secure biometric measurement data. For example, the biometric measurement and authentication device may include a private decryption key corresponding to the public encryption key. The biometric measurement data can be directly loaded into the biometric measurement authentication device (ie, not decrypted) to load the biometric measurement data into the biometric measurement authentication device.

較佳地,該生物特徵量測資料包括一生物特徵量測模板。一生物特徵量測模板係提取自一生物特徵量測影像且定義該生物特徵量測識別符之特徵之集合。例如,在一指紋之情況下,該模板可包括定義出複數個在該指紋影像中偵測到之細節(minutiae)的資料。在其他配置中,該模板可譬如定義出該等細節之相對位置。在其他更進一步的實施例中,該模板可定義出指紋之非細節(non-minutiae)特徵。用於實施該模板提取之軟體可為高度機密的,且因此僅儲存於一安全環境內防止一未經授權人員竊取所使用之演算法。Preferably, the biometric measurement data includes a biometric measurement template. A biometric measurement template is a set of features extracted from a biometric measurement image and defining the biometric measurement identifier. For example, in the case of a fingerprint, the template may include data defining a plurality of minutiae detected in the fingerprint image. In other configurations, the template may define, for example, the relative positions of the details. In still further embodiments, the template may define non-minutiae features of the fingerprint. The software used to implement the template extraction can be highly confidential and therefore stored only in a secure environment to prevent an unauthorized person from stealing the algorithms used.

該登記處理單元可被配置成連接至一計算裝置。在某些實施例中,該登記處理單元可被配置成從該計算裝置汲取電力。在某些實施例中,該登記處理單元可被配置成從該計算裝置接收命令。The registration processing unit may be configured to be connected to a computing device. In some embodiments, the registration processing unit may be configured to draw power from the computing device. In some embodiments, the registration processing unit may be configured to receive a command from the computing device.

在某些實施例中,該登記處理單元可提供一輸出(output)至該計算裝置,譬如顯示於該計算裝置之一螢幕上。在其他實施例中,該登記處理單元可包括一顯示界面,且可被配置成透過該顯示界面提供一輸出至該使用者。例如,該顯示器可包括一液晶顯示器(LCD)或相似者。In some embodiments, the registration processing unit may provide an output to the computing device, such as being displayed on a screen of the computing device. In other embodiments, the registration processing unit may include a display interface, and may be configured to provide an output to the user through the display interface. For example, the display may include a liquid crystal display (LCD) or the like.

該輸出可包括對該登記處理單元之一使用者的指令,及/或該登記處理單元之狀態之一指示,及/或與該登記處理單元連通之一生物特徵量測裝置。The output may include an instruction to a user of the registration processing unit, and / or an indication of a status of the registration processing unit, and / or a biometric measurement device in communication with the registration processing unit.

該登記處理單元較佳地被配置成,不發送該(原始)生物特徵量測影像、及/或該(原始)生物特徵量測資料至該登記處理單元外部之任何裝置。也就是說,該使用者之生物特徵量測資料絕不離開該登記處理單元,除了處於一安全形式外。The registration processing unit is preferably configured not to send the (original) biometric measurement image and / or the (original) biometric measurement data to any device external to the registration processing unit. That is, the user's biometric measurement data never leaves the registration processing unit, except in a secure form.

該生物特徵量測識別符較佳地係一指紋生物特徵量測(fingerprint biometric)。該生物特徵量測資料可為一指紋模板,其可包括代表複數個細節之資料。應用軟體可被配置成處理藉該生物特徵量測感測器掃描到之一指紋影像,以識別出複數個細節及生成該生物特徵量測模板。如上所述,用於實施此型處理之演算法經常被周密地保護。The biometric measurement identifier is preferably a fingerprint biometric. The biometric measurement data may be a fingerprint template, which may include data representing a plurality of details. The application software may be configured to process a fingerprint image scanned by the biometric measurement sensor to identify a plurality of details and generate the biometric measurement template. As mentioned above, the algorithms used to implement this type of processing are often carefully protected.

該方法可包括將該安全生物特徵量測資料發送至一遙遠位置,譬如至一遙遠位置處之一裝置提供者,如未與該登記處理單元在相同地點者。例如,該裝置提供者可離該登記處理單元至少1公里,且可至少10公里遠。The method may include sending the secure biometric measurement data to a remote location, such as to a device provider at a remote location, if it is not in the same location as the registration processing unit. For example, the device provider may be at least 1 km from the registration processing unit, and may be at least 10 km away.

該方法可包括在該生物特徵量測裝置上之一安全處理環境內回復該安全生物特徵量測資料成生物特徵量測資料。該生物特徵量測資料及/或該安全生物特徵量測資料可儲存於該生物特徵量測裝置上之一安全記憶體內。The method may include restoring the secure biometric measurement data into biometric measurement data in a secure processing environment on the biometric measurement device. The biometric measurement data and / or the secure biometric measurement data may be stored in a secure memory on the biometric measurement device.

較佳地,該方法不包括在一安全處理環境外部(譬如不在該登記處理單元或該生物特徵量測裝置之處理環境中時)將該安全生物特徵量測資料回復成生物特徵量測資料的步驟。Preferably, the method does not include returning the secure biometric measurement data to the biometric measurement data outside a secure processing environment (for example, when not in the processing environment of the registration processing unit or the biometric measurement device). step.

該方法可更包括在該安全生物特徵量測資料儲存後將該生物特徵量測裝置提供給該使用者。也就是說,一已登記的生物特徵量測裝置被提供給該使用者。該提供可包括藉由如郵件、信差或相似者傳送該已登記的生物特徵量測裝置給該使用者。The method may further include providing the biometric measurement device to the user after the safe biometric measurement data is stored. That is, a registered biometric measurement device is provided to the user. The providing may include transmitting the registered biometric measurement device to the user by, for example, mail, messenger, or the like.

該生物特徵量測識別符較佳地係一指紋生物特徵量測。該生物特徵量測資料可為一指紋模板,該指紋模板可包括代表複數個細節之資料。應用軟體可被配置成處理藉該生物特徵量測感測器掃描到之一指紋影像,以識別出該複數個細節及生成該生物特徵量測模板。如上所述,用於實施此型處理之演算法經常被周密保護。The biometric measurement identifier is preferably a fingerprint biometric measurement. The biometric measurement data may be a fingerprint template, and the fingerprint template may include data representing a plurality of details. The application software may be configured to process a fingerprint image scanned by the biometric measurement sensor to identify the plurality of details and generate the biometric measurement template. As mentioned above, the algorithms used to implement this type of processing are often carefully protected.

該生物特徵量測裝置較佳地係一裝置,其被配置成藉儲存之生物特徵量測資料與該裝置之一持有者(bearer)之生物特徵量測識別符作對比,來實施回應該持有者之認證的一動作。該生物特徵量測裝置可包括一內建生物特徵量測感測器,譬如一指紋感測器,以讀取該持有者之生物特徵量測識別符。The biometric measurement device is preferably a device configured to implement a response by comparing the stored biometric measurement data with the biometric measurement identifier of a bearer of the device. Act of holder's authentication. The biometric measurement device may include a built-in biometric measurement sensor, such as a fingerprint sensor, to read the biometric measurement identifier of the holder.

該生物特徵量測裝置可為以下任一者:一通行卡、一信用卡、一金融卡、一預付卡、一會員卡、一身份識別卡或相似者。該生物特徵量測裝置可為一智慧卡。該智慧卡較佳地具有一介於85.47公釐到85.72公釐之寬度及一介於53.92公釐到54.03公釐之間的高度。該智慧卡可具有一小於0.84公釐、且較佳地大約0.76公釐(譬如±0.08公釐)之厚度。更普遍地,該智慧卡可符合一智慧卡規格ISO 7816標準。The biometric measurement device may be any of the following: a pass card, a credit card, a financial card, a prepaid card, a membership card, an identity card, or the like. The biometric measurement device may be a smart card. The smart card preferably has a width between 85.47 mm and 85.72 mm and a height between 53.92 mm and 54.03 mm. The smart card may have a thickness of less than 0.84 mm, and preferably about 0.76 mm (for example, ± 0.08 mm). More generally, the smart card can comply with a smart card specification ISO 7816 standard.

依據本發明之一實施例,如第2圖所示,一不安全電腦202不實施任何演算法計算來登記。反而,一生物特徵量測處理單元203包括一設於電腦202與卡片105之間的安全微處理器。該安全微處理器如同智慧卡105之安全元件本身一樣難以侵入(hack)。According to an embodiment of the present invention, as shown in FIG. 2, an unsecure computer 202 does not perform any algorithm calculation to register. Instead, a biometric measurement processing unit 203 includes a secure microprocessor disposed between the computer 202 and the card 105. The secure microprocessor is as difficult to hack as the secure element of the smart card 105 itself.

在本實施例中,智慧卡105藉直接的智慧卡交流(譬如在一無接觸式的卡105情況下之一經由近場通信(NFC)連接),而連接至該單元203。In this embodiment, the smart card 105 is connected to the unit 203 by direct smart card communication (such as one of the case of a contactless card 105 via a near field communication (NFC) connection).

生物特徵量測處理單元203包括一指紋感測器201,該指紋感測器201至少與用於智慧卡105上之指紋感測器之品質一樣高,以擷取使用者之指紋。生物特徵量測處理單元203將藉由傳送指令給計算裝置202以顯示於一液晶顯示器(LCD)螢幕或相似者上引導登記者完成登記程序。該等指令可為:伸出常用手指、轉手指向左、轉手指向右、轉手指向上、轉手指向下、以及用力壓下與登記完成。The biometric measurement processing unit 203 includes a fingerprint sensor 201. The fingerprint sensor 201 is at least as high quality as the fingerprint sensor used on the smart card 105 to capture a user's fingerprint. The biometric measurement processing unit 203 will guide the registrant to complete the registration procedure by transmitting instructions to the computing device 202 for display on a liquid crystal display (LCD) screen or the like. Such instructions can be: extending a common finger, turning a finger to the left, turning a finger to the right, turning a finger up, turning a finger down, and pressing down and completing registration.

生物特徵量測處理單元203之指紋感測器201的輸出係藉生物特徵量測處理單元203之該安全微處理器處理,及一指紋模板被構成為可直接寫至卡片105之記憶體104。The output of the fingerprint sensor 201 of the biometric measurement processing unit 203 is processed by the secure microprocessor of the biometric measurement processing unit 203, and a fingerprint template is configured to be directly writeable to the memory 104 of the card 105.

生物特徵量測處理單元203內含控制從指紋感測器201傳送至卡片105之資料的手段。該手段可依以下更詳細說明之數種方式其中之一運作。The biometric measurement processing unit 203 includes a means for controlling data transmitted from the fingerprint sensor 201 to the card 105. This approach can operate in one of several ways, which are explained in more detail below.

在一配置中,該影像或模板係依據數個演算法其中之一而在生物特徵量測處理單元203中加密,且以封包傳送至卡片105。此等封包係就其何時傳送及到達該卡片記憶體來進行控制,使得每次僅傳送單一個封包。一旦卡片記憶體104接收到一封包,即命令生物特徵量測處理單元203傳送下一個封包。如此,絕不在一給定時間中傳送二個或更多封包。如此,一企圖從系統取回該影像之人員可僅在智慧卡105之記憶體104或生物特徵量測處理單元203內找到一完整影像,該智慧卡105之記憶體104與該生物特徵量測處理單元203二者皆安全。In one configuration, the image or template is encrypted in the biometric measurement processing unit 203 according to one of several algorithms and transmitted to the card 105 in a packet. These packets are controlled as to when they arrive and reach the card memory, so that only a single packet is transmitted at a time. Once the card memory 104 receives a packet, it instructs the biometric measurement processing unit 203 to transmit the next packet. As such, two or more packets are never transmitted in a given time. In this way, a person attempting to retrieve the image from the system can find a complete image only in the memory 104 or the biometric measurement processing unit 203 of the smart card 105, the memory 104 of the smart card 105 and the biometric measurement The processing unit 203 is both secure.

在一實作中,每一空白卡(blank card)105可由具有僅存在於卡片105本身中之一私用解密金鑰製造。該私用解密金鑰較佳地與智慧卡105唯一對應。一公用金鑰可被製造以提供給生物特徵量測處理單元203,譬如該生物特徵量測處理單元203可包含一公用金鑰的資料庫或生物特徵量測處理單元203能夠查詢一公用金鑰的中央資料庫。如此,一旦加密(即一旦再次儲存於一安全記憶體中),該生物特徵量測資料僅可由智慧卡105上之該私用金鑰解密。未加密生物特徵量測資料因此絕不儲存於一可存取記憶體中。In one implementation, each blank card 105 can be made from a private decryption key that has only one of the cards 105 itself. The private decryption key preferably corresponds uniquely to the smart card 105. A public key can be manufactured and provided to the biometric measurement processing unit 203. For example, the biometric measurement processing unit 203 can include a database of public keys or the biometric measurement processing unit 203 can query a public key Central database. In this way, once encrypted (that is, once stored in a secure memory again), the biometric measurement data can only be decrypted by the private key on the smart card 105. Unencrypted biometric measurement data is therefore never stored in an accessible memory.

理想上,無任何資料庫或其他紀錄(在智慧卡105本身之外)可排除於私用金鑰之外,如此將確保任何有惡意之人員無法存取此資料。Ideally, no database or other record (other than the smart card 105 itself) can be excluded from the private key, which will ensure that no malicious person can access this data.

一旦經授權之使用者的模板已被登記,智慧卡105即可實施回應該卡片持有者之身份之驗證的一動作,譬如授權一交易或相似者。這可藉比較該已登記指紋模板與一內建指紋感測器107掃描到之一指紋而達成。Once the template of the authorized user has been registered, the smart card 105 can perform an action in response to verification of the identity of the card holder, such as authorizing a transaction or the like. This can be achieved by comparing the registered fingerprint template with a fingerprint scanned by a built-in fingerprint sensor 107.

第3圖所示又一實施例,該實施例可運用一與第2圖中所示之生物特徵量測處理單元相似之生物特徵量測處理單元203。Another embodiment shown in FIG. 3 may use a biometric measurement processing unit 203 similar to the biometric measurement processing unit shown in FIG. 2.

在本方法中,該已加密生物特徵量測資料並非直接發送至智慧卡105,反而發送至一第三者,譬如用於安裝至一智慧卡105上之一卡片提供者。這將允許在一新智慧卡送至使用者之前,將該使用者登記於該新智慧卡上,由於如果該卡片在送達該使用者前被截取,而該卡片不可被欺詐使用,因此可更安全。In this method, the encrypted biometric measurement data is not sent directly to the smart card 105, but is instead sent to a third party, such as a card provider for installation on a smart card 105. This will allow a new smart card to be registered with the user before it is delivered to the user. If the card is intercepted before it is delivered to the user and the card cannot be used fraudulently, it can Safety.

在步驟301中,該使用者首先使用生物特徵量測處理單元203之指紋感測器201來掃描其指紋。In step 301, the user first uses the fingerprint sensor 201 of the biometric measurement processing unit 203 to scan his fingerprint.

其次,在步驟302中,生物特徵量測處理單元203從藉指紋感測器201擷取到之掃描指紋影像提取一指紋模板。步驟302係為可選用的,且在某些實作中,被發送之生物特徵量測資料可為該生物特徵量測影像本身或某些其他衍生之生物特徵量測。Next, in step 302, the biometric measurement processing unit 203 extracts a fingerprint template from the scanned fingerprint image captured by the fingerprint sensor 201. Step 302 is optional, and in some implementations, the biometric measurement data sent may be the biometric measurement image itself or some other derived biometric measurement.

在步驟303中,將待儲存於智慧卡105上之生物特徵量測資料加密。這可包含識別出與該使用者及/或其智慧卡105相關聯之一個或更多加密特性(encryption property),及依據此等特性加密該生物特徵量測資料。例如,此等特性可包含一使用之加密型態及一使用之加密金鑰。In step 303, the biometric measurement data to be stored on the smart card 105 is encrypted. This may include identifying one or more encryption properties associated with the user and / or its smart card 105, and encrypting the biometric measurement data based on the properties. For example, these characteristics may include a used encryption type and a used encryption key.

在步驟304中,該已加密的生物特徵量測資料係從生物特徵量測處理單元203發送至一卡片提供者或相似者。在某些實施例中,這可僅發送至電腦202。在其他實施例中,該卡片提供者可距離該生物特徵量測處理單元遙遠,譬如用於銀行業務之卡片的中央卡片生產設施。該生物特徵量測資料在此階段已加密,且因此無法被截取該生物特徵量測資料之任何第三者使用。此外,甚至該卡片提供者無法存取該資料,而降低倘該卡片提供者受到一安全缺口(security breach)影響時該生物特徵量測資料及解碼資訊被竊取之風險。例如,即使該卡片提供者儲存該已加密的生物特徵量測資料之一集中式資料庫,倘該資料庫安全因該等解密金鑰僅儲存於個別卡片上而受到危害,則仍無法存取該資料庫。In step 304, the encrypted biometric measurement data is sent from the biometric measurement processing unit 203 to a card provider or the like. In some embodiments, this may only be sent to the computer 202. In other embodiments, the card provider may be remote from the biometric measurement processing unit, such as a central card production facility for cards used in banking. The biometric measurement data is encrypted at this stage, and therefore cannot be used by any third party who intercepts the biometric measurement data. In addition, even the card provider cannot access the data, which reduces the risk of the biometric measurement data and decoded information being stolen if the card provider is affected by a security breach. For example, even if the card provider stores a centralized database of the encrypted biometric measurement data, if the security of the database is compromised because the decryption keys are stored only on individual cards, it cannot be accessed The library.

其次,在步驟305中,該卡片提供者將該(仍加密)生物特徵量測資料置於該智慧卡上。智慧卡105包含必要之解密演算法及私用金鑰來解密該資料,其較佳地在製造之時預儲存於裝置上。Second, in step 305, the card provider places the (still encrypted) biometric measurement data on the smart card. The smart card 105 contains the necessary decryption algorithms and private keys to decrypt the data, which is preferably pre-stored on the device at the time of manufacture.

最後,在步驟306中,提供智慧卡105給該使用者。這可在一提供遠端卡(remote card)之情況下透過郵件、或可簡單地包括該卡片提供者位在生物特徵量測處理單元203當地之其他情況下將智慧卡105直接給該使用者。Finally, in step 306, the smart card 105 is provided to the user. This can be done by mail when a remote card is provided, or it can simply include the card provider's location in the biometric measurement processing unit 203 and other situations where the smart card 105 is directly given to the user .

101‧‧‧指紋登記模組101‧‧‧Fingerprint registration module

102‧‧‧登記管理裝置/登記管理系統102‧‧‧Registration management device / registration management system

103‧‧‧控制邏輯103‧‧‧Control logic

104‧‧‧記憶體104‧‧‧Memory

105‧‧‧智慧卡/卡片/空白卡105‧‧‧Smart Card / Card / Blank Card

106‧‧‧中央資料庫/伺服器106‧‧‧Central Database / Server

107‧‧‧內建指紋感測器107‧‧‧Built-in fingerprint sensor

201‧‧‧指紋感測器201‧‧‧Fingerprint sensor

202‧‧‧電腦/計算裝置202‧‧‧Computer / Computing Device

203‧‧‧生物特徵量測處理單元/安全登記處理單元/單元203‧‧‧Biometric measurement processing unit / security registration processing unit / unit

301‧‧‧步驟301‧‧‧step

302‧‧‧步驟302‧‧‧step

303‧‧‧步驟303‧‧‧step

304‧‧‧步驟304‧‧‧step

305‧‧‧步驟305‧‧‧step

306‧‧‧步驟306‧‧‧step

現在將經由僅作為範例且參考以下圖式來更詳細說明本發明之某些較佳的實施例,其中: 第1圖所示為用於將一使用者登記於一生物特徵量測智慧卡上的一先前技術配置; 第2圖所示為依據本發明之一實施例之用於將一使用者登記於一生物特徵量測智慧卡上的一配置;及 第3圖所示為依據本發明之另一實施例之將一使用者登記於一生物特徵量測智慧卡上的一方法。Some preferred embodiments of the present invention will now be described in more detail by way of example only and with reference to the following drawings, in which: FIG. 1 shows a method for registering a user on a biometric measurement smart card FIG. 2 shows a configuration for registering a user on a biometric measurement smart card according to an embodiment of the present invention; and FIG. 3 shows a configuration according to the present invention. Another embodiment is a method for registering a user on a biometric measurement smart card.

Claims (9)

一種發放一生物特徵量測認證裝置給一使用者的方法,該生物特徵量測認證裝置包括一內建生物特徵量測感測器及一安全處理環境,該方法包括: 使用一登記處理單元之一生物特徵量測感測器來讀取該使用者之一生物特徵量測識別符,該登記處理單元具有一安全處理環境且與該生物特徵量測認證裝置分離; 提取與該生物特徵量測識別符對應之生物特徵量測資料,該提取在該登記處理單元之該安全處理環境中實施; 加密該生物特徵量測資料以產生安全生物特徵量測資料,該加密在該登記處理單元之該安全處理環境內實施; 從該登記處理單元發送該安全生物特徵量測資料至一裝置提供者,該裝置提供者發放生物特徵量測認證裝置; 藉該裝置提供者將該生物特徵量測資料載入該生物特徵量測認證裝置;及 在載入該生物特徵量測資料於該生物特徵量測裝置後,發放該生物特徵量測認證裝置給該使用者。A method for issuing a biometric measurement authentication device to a user. The biometric measurement authentication device includes a built-in biometric measurement sensor and a secure processing environment. The method includes: using a registration processing unit; A biometric measurement sensor to read a biometric measurement identifier of the user, the registration processing unit has a secure processing environment and is separated from the biometric measurement authentication device; extracting and the biometric measurement The biometric measurement data corresponding to the identifier is extracted in the secure processing environment of the registration processing unit; the biometric measurement data is encrypted to generate safe biometric measurement data, and the encryption is in the registration processing unit. Implemented in a secure processing environment; sending the secure biometric measurement data from a registration processing unit to a device provider, the device provider issues a biometric measurement authentication device; Entering the biometric measurement authentication device; and loading the biometric measurement data in the biometric measurement Rear, which issued the authentication biometric measuring device to the user. 如申請專利範圍第1項所述之方法,其中該生物特徵量測資料係藉與該生物特徵量測認證裝置相關聯之一金鑰加密,其中藉由將該安全生物特徵量測資料直接載入該生物特徵量測認證裝置,以將該生物特徵量測資料載入該生物特徵量測認證裝置,且其中該生物特徵量測認證裝置能夠將該安全生物特徵量測資料解密。The method according to item 1 of the scope of patent application, wherein the biometric measurement data is encrypted by a key associated with the biometric measurement authentication device, and the secure biometric measurement data is directly loaded by Entering the biometric measurement authentication device to load the biometric measurement data into the biometric measurement authentication device, and the biometric measurement authentication device can decrypt the secure biometric measurement data. 如申請專利範圍第1項或第2項所述之方法,其中該裝置提供者與該登記處理單元距離遙遠。The method according to item 1 or 2 of the scope of patent application, wherein the device provider is far away from the registration processing unit. 如申請專利範圍第1項、第2項或第3項所述之方法,其中該生物特徵量測資料包括一生物特徵量測模板。The method as described in claim 1, 2, or 3, wherein the biometric measurement data includes a biometric measurement template. 如前述申請專利範圍中任一項所述之方法,其中該生物特徵量測資料絕不離開該登記處理單元,除了處於一安全生物特徵量測裝置的一形式外。The method according to any one of the aforementioned patent applications, wherein the biometric measurement data never leaves the registration processing unit, except in a form of a secure biometric measurement device. 如前述申請專利範圍中任一項所述之方法,其包括在該生物特徵量測裝置之該安全處理環境內回復該安全生物特徵量測資料成生物特徵量測資料。The method according to any one of the aforementioned patent application scopes, which includes restoring the safe biometric measurement data into biometric measurement data in the secure processing environment of the biometric measurement device. 如前述申請專利範圍中任一項所述之方法,其中該生物特徵量測裝置係一裝置,其被配置成藉儲存之生物特徵量測資料與該裝置之持有者之一生物特徵量測識別符作比較,來實施回應該持有者之認證的一動作。The method according to any one of the aforementioned patent applications, wherein the biometric measurement device is a device configured to borrow the stored biometric measurement data and the biometric measurement of one of the holders of the device The identifiers are compared to perform an action in response to the holder's authentication. 如前述申請專利範圍中任一項所述之方法,其中該生物特徵量測裝置係為一通行令牌、一身份令牌、一信用卡、一金融卡、一預付卡、及一會員卡中之一。The method according to any one of the aforementioned patent applications, wherein the biometric measurement device is one of a pass token, an identity token, a credit card, a financial card, a prepaid card, and a membership card. One. 如前述申請專利範圍中任一項所述之方法,其中該生物特徵量測識別符係一指紋生物特徵量測。The method according to any one of the aforementioned patent application scopes, wherein the biometric measurement identifier is a fingerprint biometric measurement.
TW107115429A 2018-05-07 2018-05-07 Secure enrolment of biometric data TW201947454A (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
TW107115429A TW201947454A (en) 2018-05-07 2018-05-07 Secure enrolment of biometric data

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
TW107115429A TW201947454A (en) 2018-05-07 2018-05-07 Secure enrolment of biometric data

Publications (1)

Publication Number Publication Date
TW201947454A true TW201947454A (en) 2019-12-16

Family

ID=69583042

Family Applications (1)

Application Number Title Priority Date Filing Date
TW107115429A TW201947454A (en) 2018-05-07 2018-05-07 Secure enrolment of biometric data

Country Status (1)

Country Link
TW (1) TW201947454A (en)

Similar Documents

Publication Publication Date Title
US11664997B2 (en) Authentication in ubiquitous environment
US10681025B2 (en) Systems and methods for securely managing biometric data
CN106576044B (en) Authentication in ubiquitous environments
CA2417901C (en) Entity authentication in electronic communications by providing verification status of device
US8806616B2 (en) System, method, and apparatus for allowing a service provider system to authenticate that a credential is from a proximate device
US7558965B2 (en) Entity authentication in electronic communications by providing verification status of device
CN100495430C (en) Biometric authentication apparatus, terminal device and automatic transaction machine
JP2004518229A (en) Method and system for ensuring the security of a computer network and personal identification device used within the system to control access to network components
JP2015088080A (en) Authentication system, authentication method, and program
JP2019004475A (en) Authentication under ubiquitous environment
GB2556625A (en) Secure enrolment of biometric data
WO2019161887A1 (en) Secure enrolment of biometric data
JP6690686B2 (en) Account opening system, account opening method, and program
TW201947454A (en) Secure enrolment of biometric data
EP4246404A2 (en) System, user device and method for an electronic transaction
JP2023179334A (en) Authentication method, authentication system, portable information device, and authentication device