WO2014037037A1 - Method and system for biometrical identification of a user - Google Patents
Method and system for biometrical identification of a user Download PDFInfo
- Publication number
- WO2014037037A1 WO2014037037A1 PCT/EP2012/067340 EP2012067340W WO2014037037A1 WO 2014037037 A1 WO2014037037 A1 WO 2014037037A1 EP 2012067340 W EP2012067340 W EP 2012067340W WO 2014037037 A1 WO2014037037 A1 WO 2014037037A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- biometrical
- user
- properties
- information
- terminal
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06V—IMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
- G06V40/00—Recognition of biometric, human-related or animal-related patterns in image or video data
- G06V40/10—Human or animal bodies, e.g. vehicle occupants or pedestrians; Body parts, e.g. hands
- G06V40/12—Fingerprints or palmprints
- G06V40/1365—Matching; Classification
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/32—User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/44—Program or device authentication
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06V—IMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
- G06V40/00—Recognition of biometric, human-related or animal-related patterns in image or video data
- G06V40/10—Human or animal bodies, e.g. vehicle occupants or pedestrians; Body parts, e.g. hands
- G06V40/12—Fingerprints or palmprints
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06V—IMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
- G06V40/00—Recognition of biometric, human-related or animal-related patterns in image or video data
- G06V40/10—Human or animal bodies, e.g. vehicle occupants or pedestrians; Body parts, e.g. hands
- G06V40/18—Eye characteristics, e.g. of the iris
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3226—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
- H04L9/3231—Biological data, e.g. fingerprint, voice or retina
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2211/00—Indexing scheme relating to details of data-processing equipment not covered by groups G06F3/00 - G06F13/00
- G06F2211/007—Encryption, En-/decode, En-/decipher, En-/decypher, Scramble, (De-)compress
Definitions
- the present invention relates to a method for biometrical identification of a user, comprising the steps of
- step c) Identifying the user based on a result of step c), and
- the present invention further relates a system for biometrical identification of a user, preferably for performing with a method according the one of the claims 1 - 10, comprising
- encoding means for encoding the inputted biometrical properties
- a sender for sending the encoded biometrical properties to a checking entity
- a receiver for receiving a response of an identification of the user and e) an output interface for outputting the response
- checking entity is connected to the first terminal, and configured to be operable to check the encoded biometrical information with corresponding provided biometrical user information
- a database connected to the first terminal and to the checking entity, wherein the database is configured to provide the biometrical user information.
- Fingerprint-based identification is gaining more and more popularity, e.g. corresponding fingerprint scanners are cheaper available. Fingerprint-based identification enables users to identify and authenticate themselves to local or remote entities such as login to a local computer or public institutes, electronic portals of governments or the like.
- the process of the fingerprint scanning and matching involves a fingerprint scanner, i.e. a device that copies an image of fingerprints.
- the fingerprint scanner is connected via a network, for example the internet, to a remote database server, for example hosted by a governmental agency.
- the fingerprint scanner receives a fingerprint candidate and transmits it via the network to the database server.
- the database server uses a fingerprint matching algorithm in order to match the candidate fingerprint to a fingerprint target stored in the database. If a correct target is found, then the database server transmits a response to the fingerprint scanner including the corresponding access policy associated with the correct fingerprint.
- Fingerprint scanners are usually installed in trusted environments such as airports, embassies, governmental agencies or the like. The reason is that users are generally reluctant to trust in fingerprint scanners if these scanners are deployed in uncontrolled environments like local shops, supermarkets, etc.. Users cannot check if the fingerprint scanners have been tampered with or not. Since those fingerprint scanners temporarily store and transmit personal sensitive material, i.e. fingerprints, there are considerable incentives for attackers to compromise such scanners.
- the aforementioned objectives are accomplished by a method of claim 1 and a system of claim 1 1.
- the method for biometrical identification of a user comprising the steps of
- step c) Identifying the user based on a result of step c), and
- step d Outputting a response of the identification according to step d).
- the method is characterized in that
- the encoded biometrical properties are provided as a biometrical challenge, and that
- step c) for performing step c) the biometrical challenge is decrypted, and that i) the response is verified.
- the system for biometrical identification of a user preferably for performing with a method according the one of the claims 1 -10, comprising a first terminal comprising
- encoding means for encoding the inputted biometrical properties
- a sender for sending the encoded biometrical properties to a checking entity
- a receiver for receiving a response of an identification of the user and e) an output interface for outputting the response
- checking entity is connected to the first terminal, and configured to be operable to check the encoded biometrical information with corresponding provided biometrical user information
- a database connected to the first terminal and to the checking entity, wherein the database is configured to provide the biometrical user information.
- the system is characterized by
- a protecting terminal connected to the first terminal, comprising
- biometrical information encrypts the biometrical information and to output the encrypted biometrical information via the second output interface and to provide the encrypted biometrical properties in form of a biometrical challenge and wherein the checking entity is configured to be operable to decrypt the biometrical challenge
- a verifying entity preferably the user, is configured to be operable to verify the response.
- the second terminal adds metadata- information, preferably encrypted.
- the second terminal may add information, for example information about the second terminal itself, to the biometrical information of the user.
- information for example information about the second terminal itself
- properties of the second terminal could be implemented in the metadata information so that the database respectively the checking entity could use this information when checking the biometrical information with corresponding stored information.
- a key for encryption may be included in the metadata- information.
- lifetime-information of the second terminal are included in the metadata-information. Lifetime-information reflect a "freshness" of the second terminal enabling for example to reflect one-time second terminals for encryption which further enhances the security.
- biometrical property data and data identifiers are included in the biometrical raw data, wherein the data identifiers are well-defined and assigned to the different biometrical property data.
- fingerprints as biometrical property of the user and assumed that the database has stored fingerprints of fingers with corresponding indices a scanned fingerprint pertaining one of these fingers, has a reduced that an adversary not knowing a priori the fingerprints of these indices guessing the correct association fingerprint index. Therefore security is further enhanced.
- the result of step e) includes, preferably is provided in form of, the identifier corresponding to the checked biometrical information of the biometrical raw data.
- a fingerprint scanner may be used to output this result to the user enabling the user to decide if the fingerprint scanner is to be trusted or if the user has used a rogue scanner.
- the result is provided unencrypted.
- the lifetime-information is provided in form of a nonce.
- a unique nonce for example an incremental counter provides a very simple and easy-to-implement way to reflect the "freshness" respectively lifetime of the second terminal.
- the result of step e) includes a result of a performed function on the lifetime-information.
- the result of the performed function on the lifetime-information is provided to be human-readable. This enables for example users to an easy and quick recognition, if the first terminal is to be trusted e.g. for example a QR-codes/barcodes may be provided.
- the protecting terminal is a pad, preferably a one-time pad.
- the pad is lightweight and easy to transport even in high numbers.
- a further advantage of a pad is that it is very cost-effective.
- the second input interface comprises optical means, preferably a camera.
- a camera for example a pad encryption can be emulated. Since current mobile phone cameras are of very high precision a corresponding software on the mobile phone can take a photo of a fingerprint or other biometrical properties of a user, encrypt the image suing pad-cryptography. The user may place the mobile phone for example on a fingerprint reader in order to transmit the encrypted fingerprint to the checking entity respectively the database.
- One of the further advantages of a camera is, that users nowadays have in general mobile phones equipped with a camera with sufficient resolution. Therefore users do not have to carry further hardware.
- the pad preferably the one-time pad, comprises a transparency layer.
- Each transparency layer present a one-time pad token used for encryption.
- the user can easily acquire a set of transparencies from the government when registering its fingerprints and can use them one at the time subsequently.
- steps a)-i) are performed at least twice. This further reduces the impersonation probability of the method.
- Fig. 1 shows different biometrical property data with corresponding data identifiers according to a first embodiment of the present invention
- Fig. 2 shows a system according to a second embodiment of the present invention.
- Fig. 1 shows different biometrical property data with corresponding data identifiers according to a first embodiment of the present invention.
- indices of fingers denoted with “1 ", "2”, ... of the left and right hand corresponding to the fingerprints of the respective fingers of a human user are shown.
- Fig. 2 shows a system according to a second embodiment of the present invention.
- a fingerprint reader FPR is shown.
- the fingerprint reader is connected to a checking entity 2 and the checking entity 2 is further connected to a database 3.
- the database 3 fingerprints of the fingers of the left and right hand according to figure 1 as well as the corresponding indices are stored.
- the fingerprint reader FPR comprises a display response region DR for displaying a response corresponding to a challenge and a second region FPC for fingerprint challenge.
- the fingerprint reader FPR When the user would like to use the fingerprint reader FPR the user first takes his one-time pad 1 together with encrypted metadata EMD stored on it and puts on the one-time pad 1 its fingerprint FP.
- the one-time pad 1 encodes and encrypts the fingerprint data.
- the fingerprint reader FPR When the user then submits its encrypted fingerprint and the metadata EMD via the one-time pad 1 i.e. puts the one-time pad 1 on the fingerprint challenge region FPC of the fingerprint reader FPR, the fingerprint reader FPR encodes a corresponding challenge to the database 3.
- This challenge provides an encrypted fingerprint of any of the finger indices or any combination of pairs of these indices, for example chosen at random.
- the database 3 Upon receiving the fingerprint challenge FPC the database 3 performs a fingerprint matching algorithm after it has decrypted the encrypted metadata and the encrypted fingerprint data.
- a result of the fingerprint matching algorithm is used for response including the number of the finger indices that the user has used.
- This response maybe sent in plaintext form and displayed to the user using a display of the fingerprint reader FPR. If the user sees in the display of the fingerprint reader FPR a response that matches the fingerprint challenge FPC the user may assume that the fingerprint reader communicates with a correct checking entity 2 and database 3. In this way an untrusted fingerprint reader cannot trick with overwhelming probability any user to submit its fingerprint without communicating the fingerprint immediately to the database 3.
- the response of the database 3 or the checking entity 2 may be sent in plaintext form an untrusted fingerprint reader is not able to extract any meaningful information about the fingerprint inputted by the user. Even if the checking entity 2 does not find a match in the database 3 for the fingerprint FP, the checking entity 2 outputs a plaintext answer to the randomly from a set of possible answers.
- the database 3 and the one-time pad 1 maybe provided with corresponding public/private keys, for example for each one-time pad 1 a seed s is chosen uniformly at random.
- the one-time pad encryption maybe then G(s).
- the checking entity 2 may then easily recover the encrypted fingerprint using its private key and the "encrypted metadata" field in the transmitted biometrical information.
- the checking entity 2 may then check the database 3 for matching fingerprints.
- the checking entity 2 outputs then a response to the user challenge FPC.
- This computation is specific to the case where users rely on a camera snapshot; since fingerprints of each finger index are stored in the database 3 the user may decode the same fingerprint twice within one fingerprint challenge FPC, hence a total of 42 possibilities.
- the user can repeat the protocol many times to reduce the probability of guessing. Further for example more than 2 fingers may be inputted and then checked by the checking entity 2 which also then reduces the probability of guessing.
- the present invention provides a biometrical protector to achieve full privacy/secrecy in biometrical extraction, in particular of fingerprints.
- the present invention further enables constructing a stateless one-time pad protector wherein a key to decrypt the biometrical protector is encoded within the biometrical protector itself in the EMD field.
- the present invention further provides encrypting the biometrical input by users as a challenge/response mechanism to enable mutual authentication between end parties, i.e. the checking entity and the onetime pad.
- the present invention enables privacy-preserving biometric extraction in spite of untrusted biometric readers as well as a mutual authentication between users and checking entities, for example database servers without the need to agree on secrets using and untrusted biometric reader.
- the present invention does not require considerable modification to existing biometrical readers and to the operation of databases.
- the present invention does not penalize non-privacy aware users. Users that do not wish to follow the method according to the present invention may simply use conventional insecure biometrical identification.
- the present invention increases the trust of users in biometrical readers as means to support their large scale deployment.
- the present invention prevents impersonation of biometrical information by means of replay attacks.
- the present invention ensures full secrecy of the biometrical properties to any external party, i.e.
- the present invention ensures mutual authentication between end parties without requiring modifications/changes to the current operation of biometrical readers, in particular fingerprint readers.
- the present invention can be easily implemented with conventional methods and systems installed on the database or checking entity side to ensure privacy-preserving biometrical property matching.
- the present invention is not solely specific to fingerprints, but can although be used to enable the secure and privacy-preserving retinal scan/extraction. Other biometrics such as voice recognition, etc. may also be used.
Landscapes
- Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- General Engineering & Computer Science (AREA)
- Multimedia (AREA)
- Human Computer Interaction (AREA)
- General Health & Medical Sciences (AREA)
- Health & Medical Sciences (AREA)
- Life Sciences & Earth Sciences (AREA)
- Biodiversity & Conservation Biology (AREA)
- Biomedical Technology (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Ophthalmology & Optometry (AREA)
- Collating Specific Patterns (AREA)
Description
METHOD AND SYSTEM FOR BIOMETRICAL IDENTIFICATION OF
A USER
The present invention relates to a method for biometrical identification of a user, comprising the steps of
a) Inputting biometrical properties of a user,
b) Encoding the biometrical properties,
c) Checking the encoded biometrical properties with corresponding provided biometrical user information,
d) Identifying the user based on a result of step c), and
e) Outputting a response of the identification according to step d).
The present invention further relates a system for biometrical identification of a user, preferably for performing with a method according the one of the claims 1 - 10, comprising
a first terminal comprising
a) an input interface for biometrical properties of a user,
b) encoding means for encoding the inputted biometrical properties, c) a sender for sending the encoded biometrical properties to a checking entity,
d) a receiver for receiving a response of an identification of the user and e) an output interface for outputting the response,
wherein the checking entity is connected to the first terminal, and configured to be operable to check the encoded biometrical information with corresponding provided biometrical user information and
a database, connected to the first terminal and to the checking entity, wherein the database is configured to provide the biometrical user information.
Although applicable to biometrical properties of users in general, the present invention will be described with regard to fingerprints as biometrical property of a user.
Fingerprint-based identification is gaining more and more popularity, e.g. corresponding fingerprint scanners are cheaper available. Fingerprint-based
identification enables users to identify and authenticate themselves to local or remote entities such as login to a local computer or public institutes, electronic portals of governments or the like. The process of the fingerprint scanning and matching involves a fingerprint scanner, i.e. a device that copies an image of fingerprints. The fingerprint scanner is connected via a network, for example the internet, to a remote database server, for example hosted by a governmental agency. When a user puts one of his fingers on the fingerprint scanner, the fingerprint scanner receives a fingerprint candidate and transmits it via the network to the database server. The database server then uses a fingerprint matching algorithm in order to match the candidate fingerprint to a fingerprint target stored in the database. If a correct target is found, then the database server transmits a response to the fingerprint scanner including the corresponding access policy associated with the correct fingerprint.
Fingerprint scanners are usually installed in trusted environments such as airports, embassies, governmental agencies or the like. The reason is that users are generally reluctant to trust in fingerprint scanners if these scanners are deployed in uncontrolled environments like local shops, supermarkets, etc.. Users cannot check if the fingerprint scanners have been tampered with or not. Since those fingerprint scanners temporarily store and transmit personal sensitive material, i.e. fingerprints, there are considerable incentives for attackers to compromise such scanners. In the non-patent literature of Mauro Barni, Tiziano Bianchi, Dario Catalano, Mario Di Raimondo, Ruggero Donida Labati, Pierluigi Failla, Dario Fiore, Riccardo Lazzeretti, Vincenzo Piuri, Fabio Scotti, Alessandro Piva, Privacy-preserving fingercode authentication, Proceedings of the 12th ACM workshop on Multimedia and security, September 09-10, 2010, Roma, Italy and in the non-patent literature of Yan Huang, Lior Malka, David Evans, Jonathan Katz: Efficient Privay-Presering Biometric Identification, Proceedings of NDSS 201 1 a prevention of database servers from learning any information about fingerprints is described while executing a fingerprint matching algorithm. Assuming that the fingerprint scanner
is honest or trusted privacy preserving fingerprint matching algorithms are proposed.
However, the methods described therein rely on trusted fingerprint scanners. It is therefore a disadvantage, that such fingerprint scanners can only be used in a controlled, i.e. secure environment. A further disadvantage is that rogue fingerprint scanners may try to impersonate users therefore provide an increased risk for stealing personal data. It is therefore an objective of the present invention to provide a method and a system for biometrical identification of a user which enable obtaining biometrical data in untrusted environments which are more secure.
It is a further objective of the present invention to provide a method and a system for biometrical identification of a user which are easy to implement and cost effective.
It is an even further objective of the present invention to provide a method and a system for biometrical identification of a user which do not penalize non-privacy aware users.
According to the invention the aforementioned objectives are accomplished by a method of claim 1 and a system of claim 1 1. According to claim 1 the method for biometrical identification of a user, comprising the steps of
a) Inputting biometrical properties of a user,
b) Encoding the biometrical properties,
c) Checking the encoded biometrical properties with corresponding provided biometrical user information,
d) Identifying the user based on a result of step c), and
e) Outputting a response of the identification according to step d).
According to claim 1 the method is characterized in that
f) the inputted biometrical properties of the user are encrypted prior to step b) and that
g) the encoded biometrical properties are provided as a biometrical challenge, and that
h) for performing step c) the biometrical challenge is decrypted, and that i) the response is verified.
According to claim 1 1 the system for biometrical identification of a user, preferably for performing with a method according the one of the claims 1 -10, comprising a first terminal comprising
a) an input interface for biometrical properties of a user,
b) encoding means for encoding the inputted biometrical properties, c) a sender for sending the encoded biometrical properties to a checking entity,
d) a receiver for receiving a response of an identification of the user and e) an output interface for outputting the response,
wherein the checking entity is connected to the first terminal, and configured to be operable to check the encoded biometrical information with corresponding provided biometrical user information and
a database, connected to the first terminal and to the checking entity, wherein the database is configured to provide the biometrical user information.
According to claim 1 1 the system is characterized by
a protecting terminal, connected to the first terminal, comprising
a2) a second input interface for input biometrical properties of a user, and
b2) a second output interface wherein an output interface of the second terminal is connected to the input interface of the first terminal, and
being configured to be operable to
encrypt the biometrical information and to output the encrypted biometrical information via the second output interface and to provide the encrypted biometrical properties in form of a biometrical challenge and wherein
the checking entity is configured to be operable to decrypt the biometrical challenge
and by
a verifying entity, preferably the user, is configured to be operable to verify the response.
According to the invention it has first been recognized, that a privacy-preserving biometric extraction in spite of untrusted biometric readers or scanners is enabled. According to the invention it has further been first recognized, that a mutual authentication between users and a database without the need to agree on secrets using an untrusted biometric reader is enabled.
According to the invention it has further been first recognized, that existing biometric readers and operation of databases require only few modifications.
According to the invention it has further been first recognized, that an impersonation of biometrical data by means of replay attacks is prevented. Further features, advantages and preferred embodiments are described in the following subclaims.
According to a preferred embodiment the second terminal adds metadata- information, preferably encrypted. One of the advantages is, that the second terminal may add information, for example information about the second terminal itself, to the biometrical information of the user. For example properties of the second terminal could be implemented in the metadata information so that the database respectively the checking entity could use this information when checking the biometrical information with corresponding stored information. Alternatively or additionally a key for encryption may be included in the metadata- information.
According to a further preferred embodiment lifetime-information of the second terminal are included in the metadata-information. Lifetime-information reflect a
"freshness" of the second terminal enabling for example to reflect one-time second terminals for encryption which further enhances the security.
According to a further preferred embodiment different biometrical property data and data identifiers are included in the biometrical raw data, wherein the data identifiers are well-defined and assigned to the different biometrical property data. In case of fingerprints as biometrical property of the user and assumed that the database has stored fingerprints of fingers with corresponding indices a scanned fingerprint pertaining one of these fingers, has a reduced that an adversary not knowing a priori the fingerprints of these indices guessing the correct association fingerprint index. Therefore security is further enhanced.
According to a further preferred embodiment the result of step e) includes, preferably is provided in form of, the identifier corresponding to the checked biometrical information of the biometrical raw data. By providing the result including the identifier a fingerprint scanner may be used to output this result to the user enabling the user to decide if the fingerprint scanner is to be trusted or if the user has used a rogue scanner. According to a further preferred embodiment the result is provided unencrypted. One of the advantages is, that resources like computational resources for encryption are saved, since the result is provided unencrypted, i.e. in plaintext form. A further advantage is, that this does not reduce the security of the method since for example an untrusted fingerprint scanner is not able to require any meaningful information about the inputted fingerprint of the user.
According to a further preferred embodiment the lifetime-information is provided in form of a nonce. A unique nonce, for example an incremental counter provides a very simple and easy-to-implement way to reflect the "freshness" respectively lifetime of the second terminal.
According to a further preferred embodiment the result of step e) includes a result of a performed function on the lifetime-information. This enables to further increase the resilience of the method to possible guessing attacks.
According to a further preferred embodiment the result of the performed function on the lifetime-information is provided to be human-readable. This enables for example users to an easy and quick recognition, if the first terminal is to be trusted e.g. for example a QR-codes/barcodes may be provided.
According to a preferred embodiment of the system according to claim 10 the protecting terminal is a pad, preferably a one-time pad. One of the advantages is, that the pad is lightweight and easy to transport even in high numbers. A further advantage of a pad is that it is very cost-effective.
According to a further preferred embodiment the second input interface comprises optical means, preferably a camera. With a camera for example a pad encryption can be emulated. Since current mobile phone cameras are of very high precision a corresponding software on the mobile phone can take a photo of a fingerprint or other biometrical properties of a user, encrypt the image suing pad-cryptography. The user may place the mobile phone for example on a fingerprint reader in order to transmit the encrypted fingerprint to the checking entity respectively the database. One of the further advantages of a camera is, that users nowadays have in general mobile phones equipped with a camera with sufficient resolution. Therefore users do not have to carry further hardware.
According to a further preferred embodiment the pad, preferably the one-time pad, comprises a transparency layer. Each transparency layer present a one-time pad token used for encryption. For example the user can easily acquire a set of transparencies from the government when registering its fingerprints and can use them one at the time subsequently.
According to a further preferred embodiment steps a)-i) are performed at least twice. This further reduces the impersonation probability of the method.
There are several ways how to design and further develop the teaching of the present invention in an advantageous way. To this end it is to be referred to the patent claims subordinate to patent claims 1 and 10 on the one hand and to the following explanation of preferred embodiments of the invention by way of
example, illustrated by the figure on the other hand. In connection with the explanation of the preferred embodiments of the invention by the aid of the figure, generally preferred embodiments and further developments of the teaching will we explained. In the drawing the only
Fig. 1 shows different biometrical property data with corresponding data identifiers according to a first embodiment of the present invention;
Fig. 2 shows a system according to a second embodiment of the present invention.
Fig. 1 shows different biometrical property data with corresponding data identifiers according to a first embodiment of the present invention. In Fig. 1 indices of fingers denoted with "1 ", "2", ... of the left and right hand corresponding to the fingerprints of the respective fingers of a human user are shown.
Fig. 2 shows a system according to a second embodiment of the present invention.
In Fig. 2 a fingerprint reader FPR is shown. The fingerprint reader is connected to a checking entity 2 and the checking entity 2 is further connected to a database 3. In the database 3 fingerprints of the fingers of the left and right hand according to figure 1 as well as the corresponding indices are stored. Further the fingerprint reader FPR comprises a display response region DR for displaying a response corresponding to a challenge and a second region FPC for fingerprint challenge.
When the user would like to use the fingerprint reader FPR the user first takes his one-time pad 1 together with encrypted metadata EMD stored on it and puts on the one-time pad 1 its fingerprint FP. The one-time pad 1 encodes and encrypts the fingerprint data. When the user then submits its encrypted fingerprint and the metadata EMD via the one-time pad 1 i.e. puts the one-time pad 1 on the fingerprint challenge region FPC of the fingerprint reader FPR, the fingerprint
reader FPR encodes a corresponding challenge to the database 3. This challenge provides an encrypted fingerprint of any of the finger indices or any combination of pairs of these indices, for example chosen at random. Upon receiving the fingerprint challenge FPC the database 3 performs a fingerprint matching algorithm after it has decrypted the encrypted metadata and the encrypted fingerprint data. A result of the fingerprint matching algorithm is used for response including the number of the finger indices that the user has used. This response maybe sent in plaintext form and displayed to the user using a display of the fingerprint reader FPR. If the user sees in the display of the fingerprint reader FPR a response that matches the fingerprint challenge FPC the user may assume that the fingerprint reader communicates with a correct checking entity 2 and database 3. In this way an untrusted fingerprint reader cannot trick with overwhelming probability any user to submit its fingerprint without communicating the fingerprint immediately to the database 3. Although the response of the database 3 or the checking entity 2 may be sent in plaintext form an untrusted fingerprint reader is not able to extract any meaningful information about the fingerprint inputted by the user. Even if the checking entity 2 does not find a match in the database 3 for the fingerprint FP, the checking entity 2 outputs a plaintext answer to the randomly from a set of possible answers.
To provide encryption the checking entity 2 respectively the database 3 and the one-time pad 1 maybe provided with corresponding public/private keys, for example for each one-time pad 1 a seed s is chosen uniformly at random. The one-time pad encryption maybe then G(s). The "encrypted metadata" of the onetime pad is then C=Fencrypted, PK (S, N, server), where N denotes a unique nonce, for example an incremental counter to reflect the freshness of the one-time pad 1 , "server" is an ID of the checking entity 2 and F is the function to perform the encryption. After receiving the encrypted metadata C the checking entity 2 may then easily recover the encrypted fingerprint using its private key and the "encrypted metadata" field in the transmitted biometrical information. The checking entity 2 may then check the database 3 for matching fingerprints. The checking
entity 2 outputs then a response to the user challenge FPC. For example a probability that an adversary that does not know a priori the fingerprints of fingers with corresponding indexes for example 2, 3, 4, 7, 8, 9 in guessing the response is bounded by 1/42=2,4%. This computation is specific to the case where users rely on a camera snapshot; since fingerprints of each finger index are stored in the database 3 the user may decode the same fingerprint twice within one fingerprint challenge FPC, hence a total of 42 possibilities. The user can repeat the protocol many times to reduce the probability of guessing. Further for example more than 2 fingers may be inputted and then checked by the checking entity 2 which also then reduces the probability of guessing.
In summary the present invention provides a biometrical protector to achieve full privacy/secrecy in biometrical extraction, in particular of fingerprints. The present invention further enables constructing a stateless one-time pad protector wherein a key to decrypt the biometrical protector is encoded within the biometrical protector itself in the EMD field. The present invention further provides encrypting the biometrical input by users as a challenge/response mechanism to enable mutual authentication between end parties, i.e. the checking entity and the onetime pad.
The present invention enables privacy-preserving biometric extraction in spite of untrusted biometric readers as well as a mutual authentication between users and checking entities, for example database servers without the need to agree on secrets using and untrusted biometric reader. The present invention does not require considerable modification to existing biometrical readers and to the operation of databases. The present invention does not penalize non-privacy aware users. Users that do not wish to follow the method according to the present invention may simply use conventional insecure biometrical identification. The present invention increases the trust of users in biometrical readers as means to support their large scale deployment. The present invention prevents impersonation of biometrical information by means of replay attacks. The present invention ensures full secrecy of the biometrical properties to any external party, i.e. that is neither the user nor the checking entity and/or database. The present
invention ensures mutual authentication between end parties without requiring modifications/changes to the current operation of biometrical readers, in particular fingerprint readers. The present invention can be easily implemented with conventional methods and systems installed on the database or checking entity side to ensure privacy-preserving biometrical property matching.
Many modifications and other embodiments of the invention set forth herein will come to mind the one skilled in the art to which the invention pertains having the benefit of the teachings presented in the foregoing description and the associated drawings. Therefore, it is to be understood that the invention is not to be limited to the specific embodiments disclosed and that modifications and other embodiments are intended to be included within the scope of the appended claims. Although specific terms are employed herein, they are used in a generic and descriptive sense only and not for purposes of limitation.
The present invention is not solely specific to fingerprints, but can although be used to enable the secure and privacy-preserving retinal scan/extraction. Other biometrics such as voice recognition, etc. may also be used.
Claims
1. Method for biometrical identification of a user,
comprising the steps of
a) Inputting biometrical properties of a user,
b) Encoding the biometrical properties,
c) Checking the encoded biometrical properties with corresponding provided biometrical user information,
d) Identifying the user based on a result of step c), and
e) Outputting a response of the identification according to step d).
c h a r a c t a r i z e d i n that
f) the inputted biometrical properties of the user are encrypted prior to step b) and that
g) the encoded biometrical properties are provided as a biometrical challenge, and that
h) for performing step c) the biometrical challenge is decrypted, and that i) the response is verified.
2. Method according to claim 1 , characterized in that metadata-information, preferably encrypted, is added.
3. Method according to one of the claims 1 -2, characterized in that lifetime- information are included in the metadata-information.
4. Method according to one of the claims 1 -3, characterized in that different biometrical properties are inputted and data identifiers are included, wherein the data identifiers are well-defined and assigned to the different biometrical properties.
5. Method according to claim 4, characterized in that a result of step d) includes, preferably is provided in form of, the data identifier corresponding to the checked biometrical challenge.
6. Method according to one of the claims 1 -5, characterized in that the result is provided unencrypted.
7. Method according to one of the claims 1 -6, characterized in that the lifetime- information is provided in form of a nonce.
8. Method according to one of the claims 3-6, characterized in that the result of step d) includes a result of a performed function on the lifetime-information.
9. Method according to one of the claims 7-8, characterized in that the result of the performed function on the lifetime-information is provided to be human- readable.
10. Method according to one of the claims 1 -9, characterized in that steps a)-i) are performed at least twice.
1 1. System for biometrical identification of a user, preferably for performing with a method according the one of the claims 1 -10, comprising
a first terminal (FPR) comprising
a) an input interface for biometrical properties of a user,
b) encoding means for encoding the inputted biometrical properties, c) a sender for sending the encoded biometrical properties to a checking entity (2),
d) a receiver for receiving a response of an identification of the user and e) an output interface for outputting the response,
wherein the checking entity (2) is connected to the first terminal (FPR), and configured to be operable to check the encoded biometrical information with corresponding provided biometrical user information and
a database (3), connected to the first terminal (FPR) and to the checking entity (2), wherein the database (3) is configured to provide the biometrical user information, c h a r a c t e r i z e d b y
a protecting terminal (1 ), connected to the first terminal (FPR), comprising
a2) a second input interface for input biometrical properties of a user, and
b2) a second output interface wherein an output interface of the second terminal is connected to the input interface of the first terminal, and being configured to be operable to
encrypt the biometrical information and to output the encrypted biometrical information via the second output interface and to provide the encrypted biometrical properties in form of a biometrical challenge and wherein
the checking entity is configured to be operable to decrypt the biometrical challenge
and by
a verifying entity, preferably the user, is configured to be operable to verify the response.
12. System according to claim 1 1 , characterized in that the protecting terminal (1 ) is a pad, preferably a one-time pad.
13. System according to one of the claims 1 1 -12, characterized in that the second input interface comprises optical means, preferably a camera.
14. System according to claim 12, characterized in that the pad, preferably the one-time pad, comprises a transparency layer.
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US14/404,483 US9613250B2 (en) | 2012-09-05 | 2012-09-05 | Method and system for biometrical identification of a user |
| PCT/EP2012/067340 WO2014037037A1 (en) | 2012-09-05 | 2012-09-05 | Method and system for biometrical identification of a user |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| PCT/EP2012/067340 WO2014037037A1 (en) | 2012-09-05 | 2012-09-05 | Method and system for biometrical identification of a user |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2014037037A1 true WO2014037037A1 (en) | 2014-03-13 |
Family
ID=47010506
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/EP2012/067340 Ceased WO2014037037A1 (en) | 2012-09-05 | 2012-09-05 | Method and system for biometrical identification of a user |
Country Status (2)
| Country | Link |
|---|---|
| US (1) | US9613250B2 (en) |
| WO (1) | WO2014037037A1 (en) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN109194846A (en) * | 2018-10-08 | 2019-01-11 | 陕西师范大学 | A kind of EMD (n, m, δ) adapting to image steganographic method based on complexity |
| CN115169406A (en) * | 2022-07-15 | 2022-10-11 | 中国人民解放军国防科技大学 | Instantaneous phase fingerprint feature enhancement method based on empirical mode decomposition |
Families Citing this family (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103685197A (en) * | 2012-09-24 | 2014-03-26 | 腾讯科技(深圳)有限公司 | Client information acquisition method and server |
| US20180082050A1 (en) * | 2013-09-08 | 2018-03-22 | Yona Flink | Method and a system for secure login to a computer, computer network, and computer website using biometrics and a mobile computing wireless electronic communication device |
| CN105069343A (en) * | 2015-08-26 | 2015-11-18 | 宇龙计算机通信科技(深圳)有限公司 | Fingerprint verification method, fingerprint verification apparatus and terminal |
| US10193895B2 (en) * | 2016-05-18 | 2019-01-29 | Abdulrahman Alhothaily | System and method for remote authentication with dynamic usernames |
| WO2020133344A1 (en) * | 2018-12-29 | 2020-07-02 | 深圳市汇顶科技股份有限公司 | Fingerprint identification device and electronic equipment |
| CN110166445A (en) * | 2019-05-06 | 2019-08-23 | 武汉大学 | A kind of the secret protection anonymous authentication and cryptographic key negotiation method of identity-based |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20050055557A1 (en) * | 1999-02-19 | 2005-03-10 | Kabushiki Kaisha Toshiba | Personal authentication system and portable unit and storage medium used therefor |
| US20050204149A1 (en) * | 2004-03-15 | 2005-09-15 | Sanyo Electric Co., Ltd. | Technology for authenticating person by data generated based on biological information |
| US20110302420A1 (en) * | 1999-04-30 | 2011-12-08 | Davida George I | System and method for authenticated and privacy preserving biometric identification systems |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7152045B2 (en) * | 1994-11-28 | 2006-12-19 | Indivos Corporation | Tokenless identification system for authorization of electronic transactions and electronic transmissions |
| US6141436A (en) * | 1998-03-25 | 2000-10-31 | Motorola, Inc. | Portable communication device having a fingerprint identification system |
| JP2005010826A (en) * | 2003-06-16 | 2005-01-13 | Fujitsu Ltd | Authentication terminal device, biometric information authentication system, and biometric information acquisition system |
-
2012
- 2012-09-05 WO PCT/EP2012/067340 patent/WO2014037037A1/en not_active Ceased
- 2012-09-05 US US14/404,483 patent/US9613250B2/en active Active
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20050055557A1 (en) * | 1999-02-19 | 2005-03-10 | Kabushiki Kaisha Toshiba | Personal authentication system and portable unit and storage medium used therefor |
| US20110302420A1 (en) * | 1999-04-30 | 2011-12-08 | Davida George I | System and method for authenticated and privacy preserving biometric identification systems |
| US20050204149A1 (en) * | 2004-03-15 | 2005-09-15 | Sanyo Electric Co., Ltd. | Technology for authenticating person by data generated based on biological information |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN109194846A (en) * | 2018-10-08 | 2019-01-11 | 陕西师范大学 | A kind of EMD (n, m, δ) adapting to image steganographic method based on complexity |
| CN115169406A (en) * | 2022-07-15 | 2022-10-11 | 中国人民解放军国防科技大学 | Instantaneous phase fingerprint feature enhancement method based on empirical mode decomposition |
Also Published As
| Publication number | Publication date |
|---|---|
| US9613250B2 (en) | 2017-04-04 |
| US20150186709A1 (en) | 2015-07-02 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| Punithavathi et al. | A lightweight machine learning-based authentication framework for smart IoT devices | |
| US9613250B2 (en) | Method and system for biometrical identification of a user | |
| CN107251477B (en) | System and method for securely managing biometric data | |
| Mohammed et al. | Current multi-factor of authentication: Approaches, requirements, attacks and challenges | |
| US11799642B2 (en) | Biometric public key system providing revocable credentials | |
| US11805122B2 (en) | Encryption parameter selection | |
| CN105264537A (en) | System and method for biometric authentication with device attestation | |
| US11115215B2 (en) | Methods and devices of enabling authentication of a user of a client device over a secure communication channel based on biometric data | |
| US20200050794A1 (en) | Securing sensitive data using distance-preserving transformations | |
| CN114547589A (en) | Privacy-protecting user registration and user authentication method and device | |
| CN114070571B (en) | Method, device, terminal and storage medium for establishing connection | |
| KR101750292B1 (en) | Portable finger vein reader and biometric authentication method thereof | |
| Shrivastava et al. | Network security analysis based on authentication techniques | |
| CN114868358B (en) | Privacy preserving biometric authentication | |
| Shashannk et al. | A Comprehensive Survey on Cutting-Edge ECC and PUF Algorithm to Enhance Security | |
| HK40103721B (en) | Biometric public key system providing revocable credentials | |
| HK40103721A (en) | Biometric public key system providing revocable credentials | |
| WO2025045377A1 (en) | Biometric authentication of a user | |
| Alshaikhli et al. | Security threats of finger print biometric in network system environment | |
| Sukumaran et al. | Critical File Access in Wireless Networks Using Multifactor Authentication | |
| HK40067134B (en) | Biometric public key system providing revocable credentials | |
| HK40067134A (en) | Biometric public key system providing revocable credentials | |
| Dhanalakshmi et al. | A secure pattern based near field authentication for P2P systems | |
| Nanavati | Biometric Data Safeguarding Technologies Analysis and Best Practices | |
| Aad et al. | 2014 Index IEEE Transactions on Information Forensics and Security Vol. 9 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 12769961 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 14404483 Country of ref document: US |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 12769961 Country of ref document: EP Kind code of ref document: A1 |