WO2020040634A1 - Intégration d'authentification de réponse biométrique et de défi - Google Patents

Intégration d'authentification de réponse biométrique et de défi Download PDF

Info

Publication number
WO2020040634A1
WO2020040634A1 PCT/MY2019/050047 MY2019050047W WO2020040634A1 WO 2020040634 A1 WO2020040634 A1 WO 2020040634A1 MY 2019050047 W MY2019050047 W MY 2019050047W WO 2020040634 A1 WO2020040634 A1 WO 2020040634A1
Authority
WO
WIPO (PCT)
Prior art keywords
biometric
user
server
authenticator
capture apparatus
Prior art date
Application number
PCT/MY2019/050047
Other languages
English (en)
Inventor
Ahmad Syarif MUNALIH
Alwyn Goh
Hoon Sin Cheong
Galoh Rashidah Haron
Original Assignee
Mimos Berhad
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Mimos Berhad filed Critical Mimos Berhad
Publication of WO2020040634A1 publication Critical patent/WO2020040634A1/fr

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3271Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using challenge-response
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3218Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using proof of knowledge, e.g. Fiat-Shamir, GQ, Schnorr, ornon-interactive zero-knowledge proofs
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3226Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
    • H04L9/3231Biological data, e.g. fingerprint, voice or retina

Abstract

La présente invention concerne un système (100) et un procédé (100a, 300, 500) pour une authentification biométrique sécurisée sur la base d'un schéma d'authentification à deux facteurs, à savoir l'interaction défi-réponse et le calcul à connaissance nulle (ZK). Le système de la présente invention comprend au moins un utilisateur (102) et au moins un appareil de capture (104) côté client et au moins un serveur (106) côté serveur. Le serveur (106) stocke uniquement le modèle biométrique haché tandis qu'une clé d'authentifiant est cachée derrière l'interaction défi-réponse. L'interaction défi-réponse et le calcul ZK se traduiront par plusieurs calculs d'authentification et conduiront à des comparaisons du modèle biométrique haché avec les données biométriques présentées.
PCT/MY2019/050047 2018-08-23 2019-08-23 Intégration d'authentification de réponse biométrique et de défi WO2020040634A1 (fr)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
MYPI2018001483 2018-08-23
MYPI2018001483 2018-08-23

Publications (1)

Publication Number Publication Date
WO2020040634A1 true WO2020040634A1 (fr) 2020-02-27

Family

ID=69593348

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/MY2019/050047 WO2020040634A1 (fr) 2018-08-23 2019-08-23 Intégration d'authentification de réponse biométrique et de défi

Country Status (1)

Country Link
WO (1) WO2020040634A1 (fr)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112651007A (zh) * 2020-12-31 2021-04-13 暨南大学 一种基于数字水印的阈值谓词加密生物特征认证方法
US11500976B2 (en) 2020-11-03 2022-11-15 Nxp B.V. Challenge-response method for biometric authentication
CN115834088A (zh) * 2023-02-21 2023-03-21 杭州天谷信息科技有限公司 一种生物特征认证方法和系统

Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2002125049A (ja) * 2000-10-16 2002-04-26 Nippon Telegr & Teleph Corp <Ntt> 位置証明情報提供システム及び方法と、定置型端末、証明センタ及び証明書参照装置の動作方法並びに動作プログラムを記録した記録媒体
JP2003124921A (ja) * 2001-10-17 2003-04-25 Super Contents Distrubutions Ltd コンテンツ流通方法およびシステム
JP2008048263A (ja) * 2006-08-18 2008-02-28 Tokyo Institute Of Technology チャレンジ・レスポンス生体認証方法
US20090187986A1 (en) * 2008-01-23 2009-07-23 International Business Machines Corporation Authentication server, authentication method and authentication program
US20130174243A1 (en) * 2010-09-30 2013-07-04 Panasonic Corporation Biometric authentication system, communication terminal device, biometric authentication device, and biometric authentication method
US20150341349A1 (en) * 2014-05-23 2015-11-26 Fujitsu Limited Privacy-preserving biometric authentication

Patent Citations (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2002125049A (ja) * 2000-10-16 2002-04-26 Nippon Telegr & Teleph Corp <Ntt> 位置証明情報提供システム及び方法と、定置型端末、証明センタ及び証明書参照装置の動作方法並びに動作プログラムを記録した記録媒体
JP2003124921A (ja) * 2001-10-17 2003-04-25 Super Contents Distrubutions Ltd コンテンツ流通方法およびシステム
JP2008048263A (ja) * 2006-08-18 2008-02-28 Tokyo Institute Of Technology チャレンジ・レスポンス生体認証方法
US20090187986A1 (en) * 2008-01-23 2009-07-23 International Business Machines Corporation Authentication server, authentication method and authentication program
US20130174243A1 (en) * 2010-09-30 2013-07-04 Panasonic Corporation Biometric authentication system, communication terminal device, biometric authentication device, and biometric authentication method
US20150341349A1 (en) * 2014-05-23 2015-11-26 Fujitsu Limited Privacy-preserving biometric authentication

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11500976B2 (en) 2020-11-03 2022-11-15 Nxp B.V. Challenge-response method for biometric authentication
CN112651007A (zh) * 2020-12-31 2021-04-13 暨南大学 一种基于数字水印的阈值谓词加密生物特征认证方法
CN112651007B (zh) * 2020-12-31 2023-05-23 暨南大学 一种基于数字水印的阈值谓词加密生物特征认证方法
CN115834088A (zh) * 2023-02-21 2023-03-21 杭州天谷信息科技有限公司 一种生物特征认证方法和系统

Similar Documents

Publication Publication Date Title
US11811936B2 (en) Public/private key biometric authentication system
US9887989B2 (en) Protecting passwords and biometrics against back-end security breaches
EP3343831B1 (fr) Procédé et appareil d&#39;authentification d&#39;identité
US8862888B2 (en) Systems and methods for three-factor authentication
US11410175B2 (en) System and method for authentication with out-of-band user interaction
US10848304B2 (en) Public-private key pair protected password manager
US10924289B2 (en) Public-private key pair account login and key manager
US10909230B2 (en) Methods for user authentication
US7783893B2 (en) Secure biometric authentication scheme
US11764971B1 (en) Systems and methods for biometric electronic signature agreement and intention
US20070038863A1 (en) System and Method for Decoupling Identification from Biometric Information in Biometric Access Systems
CN106330850A (zh) 一种基于生物特征的安全校验方法及客户端、服务器
JP2017175244A (ja) 1:n生体認証・暗号・署名システム
US9882719B2 (en) Methods and systems for multi-factor authentication
WO2020040634A1 (fr) Intégration d&#39;authentification de réponse biométrique et de défi
CN108141363A (zh) 用于认证的装置,方法和计算机程序产品
US20200106771A1 (en) Systems and methods for authenticating users within a computing or access control environment
US11799642B2 (en) Biometric public key system providing revocable credentials
CN113836554A (zh) 基于区块链管理凭证信息的方法及电子设备、存储介质
US11483166B2 (en) Methods and devices for enrolling and authenticating a user with a service
WO2007008789A2 (fr) Systeme et procede permettant de decoupler l&#39;identification d&#39;informations biometriques dans des systemes d&#39;acces biometriques
KR102602214B1 (ko) 2차원 코드를 기반으로 신용카드를 보유하고 있는 사용자에 대한 2채널 인증을 수행하는 사용자 인증 서버 및 그 동작 방법
WO2023181163A1 (fr) Système de collationnement, dispositif de collationnement, procédé de collationnement et programme
KR20160020314A (ko) 전자서명을 이용하여 대출서비스를 제공하기 위한 장치 및 그 방법
GB2498931A (en) Verifying the origin of content or a product by using user-identifiable authentication messages

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19851561

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 19851561

Country of ref document: EP

Kind code of ref document: A1