WO2022010338A1 - System and method for biometric authentication - Google Patents
System and method for biometric authentication Download PDFInfo
- Publication number
- WO2022010338A1 WO2022010338A1 PCT/MY2020/050169 MY2020050169W WO2022010338A1 WO 2022010338 A1 WO2022010338 A1 WO 2022010338A1 MY 2020050169 W MY2020050169 W MY 2020050169W WO 2022010338 A1 WO2022010338 A1 WO 2022010338A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- authentication
- user
- registration
- unit
- encryption
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/64—Protecting data integrity, e.g. using checksums, certificates or signatures
- G06F21/645—Protecting data integrity, e.g. using checksums, certificates or signatures using a third party
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/32—User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/62—Protecting access to data via a platform, e.g. using keys or access control rules
- G06F21/6209—Protecting access to data via a platform, e.g. using keys or access control rules to a single file or object, e.g. in a secure envelope, encrypted and accessed using a key, or with access control rules appended to the object itself
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0861—Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0894—Escrow, recovery or storing of secret information, e.g. secret key escrow or cryptographic key storage
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3226—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
- H04L9/3231—Biological data, e.g. fingerprint, voice or retina
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/50—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using hash chains, e.g. blockchains or hash trees
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2107—File encryption
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/21—Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/2117—User registration
Definitions
- the present invention relates broadly to the field of biometric authentication. More particularly, the present invention relates to a system and method for biometric authentication by storing a biometric template in a database.
- Biometric authentication is considered as the strongest form of authentication as a biometric feature for a user is unique and is highly complex to duplicate.
- a biometric reader device includes an imaging sensor for capturing an image of the biometric feature such as fingerprint, palm print, face print and the like. During registration, the biometric feature is captured and converted into a reference template which is then stored in a local and/or remote storage for verification during authentication process.
- biometric features are complicated to duplicate, storage of the template is one of the main problems faced in biometric authentication systems which are vulnerable to external hacker or internal administrator.
- a simple scenario would be when a hacker gains a digital copy of a biometric template stored in the system of a target person. The hacker can use it to access into systems that require biometric authentication to proceed.
- Blockchain was introduced as a network of nodes storing immutable blocks of data time-stamped, secured and bound to each other by cryptographic principles. It is like a distributed ledger or decentralized database storing continuously updated digital records of who owns what. Unlike traditional database such as utilized by banks, governments, accountants, etc., blockchain has a network of replicated databases that are synchronized and visible to public within the network. The network is not publicly available but rather only invited organizations can join the network. Each node channel has its own ledger and thus is a totally separated network. Data between channel members are shared through the channel but not between channels. It is possible to communicate between channels but this has to be specifically managed through applications or Digital contract. Otherwise, by design there is a complete data separation between channels.
- Blockchain creates blocks in an append-only structure, wherein a block once created cannot be deleted or updated. Any new updates shall be included and added as a new block and each block has its own hash value before adding onto the chain of blocks. While adding a new block, a hash value of the last block is included to the new block, as shown in FIGURE 4, which makes it impossible to change or delete data within each block.
- United States patent application no.: US 2018/0285879 A1 discloses a system and method for blockchain-based identity and transaction platforms, wherein identity information (e.g., a photo) for a person is encrypted and stored in a blockchain as part of enrolling the person as a user in a blockchain-based identity and transaction platform. During authentication, the stored information is compared with an identity information inputted with an authentication request.
- identity information e.g., a photo
- the present disclosure proposes a system and method for biometric authentication.
- the system comprises an input unit for inputting a biometric feature of a user as a registration data during user registration and as an authentication data during user authentication.
- An encryption unit encrypts the registration data during the user registration and encrypts the authentication data during the user authentication.
- a communication unit forwards the encrypted registration data to a storage unit for storage during the user registration and retrieves the stored registration data from the storage unit during the user authentication.
- An authentication unit compares the retrieved registration data with the encrypted authentication data during the user authentication and authenticates the user if a comparison score reaches a predefined threshold.
- the encryption unit parses the registration data into multiple registration data portions and encrypts each registration data portion using an encryption algorithm.
- the communication unit forwards each encrypted registration data portion to a different storage location in the storage unit.
- the encryption unit parses the authentication data into the multiple authentication data portions and encrypts each authentication data portion using the encryption algorithm.
- the communication unit retrieves the encrypted registration data portions corresponding to the user from the storage locations.
- the authentication unit compares each encrypted authentication data portion with corresponding encrypted registration data portion to generate a comparison score and authenticates the user if the comparison score reaches a threshold.
- the encryption unit encrypts each pair of authentication data portion and registration data portion using a different encryption algorithm.
- the encryption unit includes a set of pre-stored encryption algorithms and dynamically chooses one of the encryption algorithms based on type of biometric feature, number of parsed data portions or any other factors related to encryption process.
- the present invention parses the registration data, encrypts each parsed data portions and stores each encrypted data portion at a different storage location.
- the present invention improves protection of the biometric feature and thus preventing a fraudulent access to confidential data without complicating authentication process.
- FIGURE 1 shows a block diagram of the system for biometric authentication, in accordance with an exemplary embodiment of the present invention.
- FIGURE 2 shows a flow diagram of the method for biometric authentication, in accordance with an exemplary embodiment of the present invention.
- FIGURE 3 shows a schematic flow diagram of iris based authentication process, in accordance with an exemplary embodiment of the present invention.
- FIGURE 4 shows a block representation of blocks within a traditional blockchain.
- FIGURE 1 shows a block representation of the system for biometric authentication, in accordance with an exemplary embodiment of the present invention.
- the system (10) comprises an input unit (11 ), an encryption unit (12), a communication unit (13), a storage unit (14) and an authentication unit (15).
- the encryption unit (12) is connected between the input unit (11), communication unit (13) and the authentication unit (15) through a wired and/or wireless connection.
- the communication unit (13) is connected to the storage unit (14) and the authentication unit (15) through a wired and/or wireless connection.
- the input unit (11) inputs a biometric feature of a user, wherein the input unit (11) includes a scanning device for scanning the biometric feature.
- the biometric feature is fingerprint, palm print, face print, iris, retina and the like.
- the scanning device includes but not limited to optical scanner, capacitive scanner and ultrasound scanner.
- the encryption unit (12) receives and encrypts the inputted biometric feature using an encryption algorithm to generate an encryption data.
- the encryption unit (12) parses the inputted biometric feature into multiple data portions and encrypts each data portion using the encryption algorithm to generate multiple encryption data.
- the encryption unit (12) parses the inputted biometric feature into multiple data portions and encrypts each data portion using a different encryption algorithm to generate multiple encryption data.
- the encryption unit (12) includes an algorithm storage module (not shown) for storing a set of parsing algorithms and encryption algorithms and an algorithm selection module (not shown) for selecting a parsing algorithm and one or more encryption algorithms.
- the encryption algorithm includes a hashing algorithm such as Secure Hashing Algorithm (SHA) 1 , Rivest-Shamir-Adleman (RSA) algorithm, SHA3 and Research and Development in Advanced Communications Technologies in Europe (RACE) Integrity Primitives Evaluation (RIPE) Message Digest (RIPEMD)-160 algorithm.
- SHA Secure Hashing Algorithm
- RSA Rivest-Shamir-Adleman
- RACE Research and Development in Advanced Communications Technologies in Europe
- RIPE Integrity Primitives Evaluation
- RIPEMD Message Digest
- the selection of the parsing algorithm and the encryption algorithms are based on one or more pre-configured factors such as type of biometric feature, number of parsed data portions and the like, or by a random manner, rotational manner, etc. Additionally, the selection of encryption algorithm may be based on the parsing algorithm.
- the encryption unit (12) outputs the encryption data to the communication unit (13) which in turn transmits the encryption data to the storage unit (14) for storage.
- the communication unit (13) transmits each encryption data to a different storage locations in the storage unit (14).
- the storage unit (14) may include multiple storage databases, and the communication unit (13) includes a selection module (not shown) for selecting a storage location among the databases for storing each encryption data. The selection module may select the storage location in a random manner or based on a preselected factor.
- an indexing module (not shown) in the storage unit (14) generates a composite key including a portion of one or more of the encryption data i.e. hash segment, and address of a storage location of each encryption data. Further, the indexing module creates an index table using the composite key, wherein the index table stores composite keys generated during each user registration process. In a preferred embodiment, the indexing module follows a pre-configured algorithm to obtain a portion of the encryption data for generating the composite key and obtains the addresses from the selection module of the communication unit (13).
- the encryption unit (12) outputs the encryption data to the authentication unit (15). Furthermore, during the user authentication, the communication unit (13) retrieves the stored encryption data corresponding to the user and transfers the retrieved data to the authentication unit (15).
- the authentication unit (15) transmits a portion of the encryption data generated during the user authentication to the communication unit (13).
- the communication unit (13) uses the received encryption data portion to obtain the address of each storage location of the corresponding stored encryption data in the storage unit (14).
- the communication unit (13) compares the received encryption data portion with the composite keys stored in the index table to identify the composite key including the matching encryption data portion and obtains one or more addresses stored in the composite key including the matching encryption data portion.
- the communication unit (13) retrieves each stored encryption data and transfers the same to the authentication unit (15) which compares each retrieved data with the corresponding encryption data received from the encryption unit (12) to generate a comparison score.
- the authentication unit (15) includes a calculation module (not shown) for calculating an average of the comparison scores.
- the authentication unit (15) authenticates the user by outputting an authentication signal to a security module (not shown) to allow the user to access one or more resources (not shown) secured by the security module.
- the security module is a secured storage space e.g. software file, folder, drive and/or server, for storing one or more confidential data.
- the security module may also be an electronic lock coupled to a security gate, lift, vehicle, vending machine, point-of-sale (POS) and the like.
- FIGURE 2 shows a flow diagram of a method for biometric authentication in accordance with an exemplary embodiment of the present invention.
- the method (20) comprises the steps of: registering a user using a biometric feature of the user (21 ) and authenticating the user using the biometric feature (22). While registering the user, the biometric feature is inputted as a registration data at an inputting unit and the registration data is encrypted at an encryption unit and then stored in a storage unit. Furthermore, while authenticating the user, the biometric feature is inputted as an authentication data at the inputting unit and the authentication data is encrypted at an encryption unit and then compared with the encrypted registration data stored in the storage unit.
- the registration data is parsed into multiple registration data portions and each registration data portion is encrypted using an encryption algorithm. Furthermore, each encrypted registration data portion is stored at a different storage location in a storage unit.
- the authentication data is parsed into multiple authentication data portions and each authentication data portion is encrypted. Furthermore, the encrypted registration data portions corresponding to the user are retrieved from the corresponding storage locations, and each encrypted registration data portion is compared with the corresponding encrypted authentication data portion to generate a comparison score. If the comparison score reaches a threshold, the user is authenticated.
- the user is registered by using an iris of the user as the registration data, as shown in FIGURE 3.
- An imaging device captures an image of an eye of the user and extracts the iris from the eye image.
- the extracted iris is parsed into four equal portions to form a 2X2 matrix and each iris portion is hashed using a hashing algorithm at a digital contract to generate four hashed templates #l, #ll, #lll and #IV.
- Each of the hashed templates #l, #ll, #lll and #IV is stored at a different block in a blockchain database, wherein no two blocks storing the hashed templates #l, #ll, #lll and #IV are adjacent to one another.
- the imaging device captures an image of the eye and extracts the iris form the eye image.
- the extracted iris is parsed into four equal portions to form a 2X2 matrix same as the 2X2 matrix generated during the user registration.
- Each iris portion is hashed at the digital contract to generate four hashed input data #i, #ii, #iii and #iv using the same hashing algorithm that is used during the user registration to generate the four hashed templates #l, #ll, #lll and #IV.
- the hashed templates #l, #ll, #lll and #IV stored in the blocks are retrieved and compared with the corresponding hashed input data #i, #ii, #iii and #iv to generate a comparison score.
- the hashed template #l is compared with the hashed input #i to generate a first comparison score and the hashed template #ll is compared with the hashed input #ii to generate a second comparison score.
- the hashed templates #lll and #IV are compared with the corresponding hashed inputs #iii and #iv to generate a third comparison score and a fourth comparison score, respectively.
- An average of the four comparison scores is computed, and if the average reaches a threshold, an authentication signal is outputted for authenticating the user.
- each registration -authentication data portion pair may be encrypted using a different encryption algorithm which is selected based on one or more factors.
- the top left portion of the iris image captured for user registration and the top left portion of the iris image captured for user authentication form a top left pair of registration data portion and authentication data portion.
- other three portions of the iris image captured for user registration form three pairs of registration data portion and authentication data portion with the corresponding portions of the iris image captured for user authentication.
- Each pair of registration data portion and authentication data portion may be encrypted using a different encryption algorithm.
- two pairs may be encrypted using one encryption algorithm, while the other two pairs may be encrypted using another encryption algorithm.
- the iris image may also be parsed, horizontally, vertically, diagonally or radially of equal width.
- the biometric feature is split into multiple portions and each portion is separately hashed using a same or different hashing algorithm and is stored in different storage locations. If anyone attempts to wrongfully obtain the biometrics of a user, all template portions corresponding to the user need to be identified in the blockchain. Further, dynamic encryption of each portion of the same templates enhances protection of the template. By this way, the present invention is capable of improving security of template storage in a blockchain database without compromising or complicating the authentication process.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- General Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- General Health & Medical Sciences (AREA)
- Health & Medical Sciences (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Biomedical Technology (AREA)
- Computing Systems (AREA)
- Bioethics (AREA)
- Biodiversity & Conservation Biology (AREA)
- Life Sciences & Earth Sciences (AREA)
- Collating Specific Patterns (AREA)
Abstract
The present invention relates to a system and method for biometric authentication, wherein the system (10) comprises an input unit (11), an encryption unit (12), a communication unit (13) and a storage unit (14). The input unit (11) inputs a biometric feature of a user as a registration data during user registration and as an authentication data during user authentication. The encryption unit (12) encrypts the registration data during the user registration and encrypts the authentication data during the user authentication. The communication unit (13) forwards the encrypted registration data to the storage unit (14) for storage during the user registration and retrieves the stored registration data from the storage unit (14) during the user authentication. The authentication unit (15) compares the retrieved registration data with the encrypted authentication data during the user authentication and authenticates the user if a comparison score reaches a predefined threshold.
Description
SYSTEM AND METHOD FOR BIOMETRIC AUTHENTICATION
FIELD OF THE DISCLOSURE
The present invention relates broadly to the field of biometric authentication. More particularly, the present invention relates to a system and method for biometric authentication by storing a biometric template in a database.
BACKGROUND
Biometric authentication is considered as the strongest form of authentication as a biometric feature for a user is unique and is highly complex to duplicate. In general, a biometric reader device includes an imaging sensor for capturing an image of the biometric feature such as fingerprint, palm print, face print and the like. During registration, the biometric feature is captured and converted into a reference template which is then stored in a local and/or remote storage for verification during authentication process.
Even though biometric features are complicated to duplicate, storage of the template is one of the main problems faced in biometric authentication systems which are vulnerable to external hacker or internal administrator. A simple scenario would be when a hacker gains a digital copy of a biometric template stored in the system of a target person. The hacker can use it to access into systems that require biometric authentication to proceed.
Blockchain was introduced as a network of nodes storing immutable blocks of data time-stamped, secured and bound to each other by cryptographic principles. It is like a distributed ledger or decentralized database storing continuously updated digital records of who owns what. Unlike traditional database such as utilized by banks, governments, accountants, etc., blockchain has a network of replicated databases that are synchronized and visible to public within the network.
The network is not publicly available but rather only invited organizations can join the network. Each node channel has its own ledger and thus is a totally separated network. Data between channel members are shared through the channel but not between channels. It is possible to communicate between channels but this has to be specifically managed through applications or Digital contract. Otherwise, by design there is a complete data separation between channels.
Blockchain creates blocks in an append-only structure, wherein a block once created cannot be deleted or updated. Any new updates shall be included and added as a new block and each block has its own hash value before adding onto the chain of blocks. While adding a new block, a hash value of the last block is included to the new block, as shown in FIGURE 4, which makes it impossible to change or delete data within each block.
United States patent application no.: US 2018/0285879 A1 discloses a system and method for blockchain-based identity and transaction platforms, wherein identity information (e.g., a photo) for a person is encrypted and stored in a blockchain as part of enrolling the person as a user in a blockchain-based identity and transaction platform. During authentication, the stored information is compared with an identity information inputted with an authentication request.
However, there is still a need in the art for a system and method for biometric authentication which improves security of template storage in a database without compromising or complicating the authentication process.
SUMMARY
The present disclosure proposes a system and method for biometric authentication. The system comprises an input unit for inputting a biometric feature of a user as a registration data during user registration and as an authentication data during user authentication. An encryption unit encrypts the registration data during the user registration and encrypts the authentication data during the user authentication. A communication unit forwards the encrypted registration data to a storage unit for storage during the user registration and
retrieves the stored registration data from the storage unit during the user authentication. An authentication unit compares the retrieved registration data with the encrypted authentication data during the user authentication and authenticates the user if a comparison score reaches a predefined threshold.
In one aspect of the present invention, during the user registration, the encryption unit parses the registration data into multiple registration data portions and encrypts each registration data portion using an encryption algorithm. The communication unit forwards each encrypted registration data portion to a different storage location in the storage unit.
During the user authentication, the encryption unit parses the authentication data into the multiple authentication data portions and encrypts each authentication data portion using the encryption algorithm. The communication unit retrieves the encrypted registration data portions corresponding to the user from the storage locations. The authentication unit compares each encrypted authentication data portion with corresponding encrypted registration data portion to generate a comparison score and authenticates the user if the comparison score reaches a threshold.
In another embodiment of the present invention, the encryption unit encrypts each pair of authentication data portion and registration data portion using a different encryption algorithm. Optionally, the encryption unit includes a set of pre-stored encryption algorithms and dynamically chooses one of the encryption algorithms based on type of biometric feature, number of parsed data portions or any other factors related to encryption process.
The present invention parses the registration data, encrypts each parsed data portions and stores each encrypted data portion at a different storage location. By this way, the present invention improves protection of the biometric feature and thus preventing a fraudulent access to confidential data without complicating authentication process.
Various objects, features, aspects and advantages of the inventive subject matter will become more apparent from the following detailed description of preferred
embodiments, along with the accompanying drawing figures in which like numerals represent like components.
BRIEF DESCRIPTION OF THE ACCOMPANYING DRAWINGS In the figures, similar components and/or features may have the same reference numerals. Further, various components of the same type may be distinguished by following the reference numerals with a second numeral that distinguishes among the similar components. If only the first reference numeral is used in the specification, the description is applicable to any one of the similar components having the same first reference numeral irrespective of the second reference numeral.
FIGURE 1 shows a block diagram of the system for biometric authentication, in accordance with an exemplary embodiment of the present invention.
FIGURE 2 shows a flow diagram of the method for biometric authentication, in accordance with an exemplary embodiment of the present invention.
FIGURE 3 shows a schematic flow diagram of iris based authentication process, in accordance with an exemplary embodiment of the present invention.
FIGURE 4 shows a block representation of blocks within a traditional blockchain. DETAILED DESCRIPTION
In accordance with the present disclosure, there is provided a system and method for biometric authentication, which will now be described with reference to the embodiments shown in the accompanying drawings. The embodiments do not limit the scope and ambit of the disclosure. The description relates purely to the embodiments and suggested applications thereof.
The embodiments herein and the various features and advantageous details thereof are explained with reference to the non-limiting embodiment in the
following description. Descriptions of well-known components and processes are omitted so as to not unnecessarily obscure the embodiments herein. The examples used herein are intended merely to facilitate an understanding of ways in which the embodiments herein may be practiced and to further enable those of skill in the art to practice the embodiment herein. Accordingly, the description should not be construed as limiting the scope of the embodiment herein.
The description hereinafter, of the specific embodiment will so fully reveal the general nature of the embodiments herein that others can, by applying current knowledge, readily modify or adapt or perform both for various applications such specific embodiment without departing from the generic concept, and, therefore, such adaptations and modifications should and are intended to be comprehended within the meaning and range of equivalents of the disclosed embodiments. It is to be understood that the phraseology or terminology employed herein is for the purpose of description and not of limitation.
FIGURE 1 shows a block representation of the system for biometric authentication, in accordance with an exemplary embodiment of the present invention. The system (10) comprises an input unit (11 ), an encryption unit (12), a communication unit (13), a storage unit (14) and an authentication unit (15). The encryption unit (12) is connected between the input unit (11), communication unit (13) and the authentication unit (15) through a wired and/or wireless connection. Furthermore, the communication unit (13) is connected to the storage unit (14) and the authentication unit (15) through a wired and/or wireless connection. The input unit (11) inputs a biometric feature of a user, wherein the input unit (11) includes a scanning device for scanning the biometric feature. In a preferred embodiment, the biometric feature is fingerprint, palm print, face print, iris, retina and the like. Similarly, the scanning device includes but not limited to optical scanner, capacitive scanner and ultrasound scanner.
The encryption unit (12) receives and encrypts the inputted biometric feature using an encryption algorithm to generate an encryption data. In a preferred embodiment, the encryption unit (12) parses the inputted biometric feature into multiple data portions and encrypts each data portion using the encryption algorithm to generate multiple encryption data. In alternate embodiment, the
encryption unit (12) parses the inputted biometric feature into multiple data portions and encrypts each data portion using a different encryption algorithm to generate multiple encryption data.
In a preferred embodiment, the encryption unit (12) includes an algorithm storage module (not shown) for storing a set of parsing algorithms and encryption algorithms and an algorithm selection module (not shown) for selecting a parsing algorithm and one or more encryption algorithms. Preferably, the encryption algorithm includes a hashing algorithm such as Secure Hashing Algorithm (SHA) 1 , Rivest-Shamir-Adleman (RSA) algorithm, SHA3 and Research and Development in Advanced Communications Technologies in Europe (RACE) Integrity Primitives Evaluation (RIPE) Message Digest (RIPEMD)-160 algorithm. Similarly, the biometric feature is parsed into rows, columns, matrix, concentric circles or any other two dimensional geometric shapes.
The selection of the parsing algorithm and the encryption algorithms are based on one or more pre-configured factors such as type of biometric feature, number of parsed data portions and the like, or by a random manner, rotational manner, etc. Additionally, the selection of encryption algorithm may be based on the parsing algorithm.
During a user registration, the encryption unit (12) outputs the encryption data to the communication unit (13) which in turn transmits the encryption data to the storage unit (14) for storage. Preferably, the communication unit (13) transmits each encryption data to a different storage locations in the storage unit (14). Alternatively, the storage unit (14) may include multiple storage databases, and the communication unit (13) includes a selection module (not shown) for selecting a storage location among the databases for storing each encryption data. The selection module may select the storage location in a random manner or based on a preselected factor.
Upon receiving the encryption data, an indexing module (not shown) in the storage unit (14) generates a composite key including a portion of one or more of the encryption data i.e. hash segment, and address of a storage location of each encryption data. Further, the indexing module creates an index table using the
composite key, wherein the index table stores composite keys generated during each user registration process. In a preferred embodiment, the indexing module follows a pre-configured algorithm to obtain a portion of the encryption data for generating the composite key and obtains the addresses from the selection module of the communication unit (13).
On the other hand, during a user authentication, the encryption unit (12) outputs the encryption data to the authentication unit (15). Furthermore, during the user authentication, the communication unit (13) retrieves the stored encryption data corresponding to the user and transfers the retrieved data to the authentication unit (15).
While retrieving the stored encryption data corresponding to the user requesting authentication, the authentication unit (15) transmits a portion of the encryption data generated during the user authentication to the communication unit (13). The communication unit (13) uses the received encryption data portion to obtain the address of each storage location of the corresponding stored encryption data in the storage unit (14). The communication unit (13) compares the received encryption data portion with the composite keys stored in the index table to identify the composite key including the matching encryption data portion and obtains one or more addresses stored in the composite key including the matching encryption data portion.
Based on the obtained addresses, the communication unit (13) retrieves each stored encryption data and transfers the same to the authentication unit (15) which compares each retrieved data with the corresponding encryption data received from the encryption unit (12) to generate a comparison score. The authentication unit (15) includes a calculation module (not shown) for calculating an average of the comparison scores.
If the average of the comparison scores reaches a threshold, the authentication unit (15) authenticates the user by outputting an authentication signal to a security module (not shown) to allow the user to access one or more resources (not shown) secured by the security module. In a preferred embodiment, the security module is a secured storage space e.g. software file, folder, drive and/or server,
for storing one or more confidential data. Alternatively, the security module may also be an electronic lock coupled to a security gate, lift, vehicle, vending machine, point-of-sale (POS) and the like.
FIGURE 2 shows a flow diagram of a method for biometric authentication in accordance with an exemplary embodiment of the present invention. The method (20) comprises the steps of: registering a user using a biometric feature of the user (21 ) and authenticating the user using the biometric feature (22). While registering the user, the biometric feature is inputted as a registration data at an inputting unit and the registration data is encrypted at an encryption unit and then stored in a storage unit. Furthermore, while authenticating the user, the biometric feature is inputted as an authentication data at the inputting unit and the authentication data is encrypted at an encryption unit and then compared with the encrypted registration data stored in the storage unit.
During user registration, the registration data is parsed into multiple registration data portions and each registration data portion is encrypted using an encryption algorithm. Furthermore, each encrypted registration data portion is stored at a different storage location in a storage unit. During user authentication, the authentication data is parsed into multiple authentication data portions and each authentication data portion is encrypted. Furthermore, the encrypted registration data portions corresponding to the user are retrieved from the corresponding storage locations, and each encrypted registration data portion is compared with the corresponding encrypted authentication data portion to generate a comparison score. If the comparison score reaches a threshold, the user is authenticated.
Entire functionality of the present invention is divided into two sections: 1 ) User registration, and 2) User authentication. Each section is explained in detail with an example in the forthcoming paragraphs.
In an embodiment, the user is registered by using an iris of the user as the registration data, as shown in FIGURE 3. An imaging device captures an image of an eye of the user and extracts the iris from the eye image. The extracted iris is parsed into four equal portions to form a 2X2 matrix and each iris portion is hashed using a hashing algorithm at a digital contract to generate four hashed
templates #l, #ll, #lll and #IV. Each of the hashed templates #l, #ll, #lll and #IV is stored at a different block in a blockchain database, wherein no two blocks storing the hashed templates #l, #ll, #lll and #IV are adjacent to one another.
During the user authentication, the imaging device captures an image of the eye and extracts the iris form the eye image. The extracted iris is parsed into four equal portions to form a 2X2 matrix same as the 2X2 matrix generated during the user registration. Each iris portion is hashed at the digital contract to generate four hashed input data #i, #ii, #iii and #iv using the same hashing algorithm that is used during the user registration to generate the four hashed templates #l, #ll, #lll and #IV. The hashed templates #l, #ll, #lll and #IV stored in the blocks are retrieved and compared with the corresponding hashed input data #i, #ii, #iii and #iv to generate a comparison score.
To be precise, the hashed template #l is compared with the hashed input #i to generate a first comparison score and the hashed template #ll is compared with the hashed input #ii to generate a second comparison score. Likewise the hashed templates #lll and #IV are compared with the corresponding hashed inputs #iii and #iv to generate a third comparison score and a fourth comparison score, respectively. An average of the four comparison scores is computed, and if the average reaches a threshold, an authentication signal is outputted for authenticating the user.
Even though the above embodiment is described using a single encryption algorithm for encrypting the registration data and the authentication data, it is to be understood that each registration -authentication data portion pair may be encrypted using a different encryption algorithm which is selected based on one or more factors. For example, in the above embodiment, the top left portion of the iris image captured for user registration and the top left portion of the iris image captured for user authentication form a top left pair of registration data portion and authentication data portion. Similarly, other three portions of the iris image captured for user registration form three pairs of registration data portion and authentication data portion with the corresponding portions of the iris image captured for user authentication.
Each pair of registration data portion and authentication data portion may be encrypted using a different encryption algorithm. Alternatively, two pairs may be encrypted using one encryption algorithm, while the other two pairs may be encrypted using another encryption algorithm. Furthermore, it is also possible to encrypt three pairs using one encryption algorithm and one pair using another encryption algorithm. Similarly, the iris image may also be parsed, horizontally, vertically, diagonally or radially of equal width.
The biometric feature is split into multiple portions and each portion is separately hashed using a same or different hashing algorithm and is stored in different storage locations. If anyone attempts to wrongfully obtain the biometrics of a user, all template portions corresponding to the user need to be identified in the blockchain. Further, dynamic encryption of each portion of the same templates enhances protection of the template. By this way, the present invention is capable of improving security of template storage in a blockchain database without compromising or complicating the authentication process.
The terminology used herein is for the purpose of describing particular example embodiments only and is not intended to be limiting. As used herein, the singular forms "a", "an" and "the" may be intended to include the plural forms as well, unless the context clearly indicates otherwise.
The terms "comprises," "comprising," “including,” and “having,” are inclusive and therefore specify the presence of stated features, integers, steps, operations, elements, or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, or groups thereof.
The use of the expression “at least” or “at least one” suggests the use of one or more elements, as the use may be in one of the embodiments to achieve one or more of the desired objects or results.
While the foregoing describes various embodiments of the invention, other and further embodiments of the invention may be devised without departing from the basic scope thereof. The scope of the invention is determined by the claims that follow. The invention is not limited to the described embodiments, versions or
examples, which are included to enable a person having ordinary skill in the art to make and use the invention when combined with information and knowledge available to the person having ordinary skill in the art.
Claims
1 . A system (10) for biometric authentication, comprising: i. at least one input unit (11) for inputting a biometric feature of a user as a registration data during user registration and as an authentication data during user authentication; ii. at least one encryption unit (12) for encrypting said registration data during said user registration and for encrypting said authentication data during said user authentication; iii. at least one storage unit (14) for storage during said user registration; iv. at least one communication unit (13) for forwarding said encrypted registration data to said storage unit (14) for storage during said user registration and for retrieving said stored registration data from said storage unit (14) during said user authentication; v. at least one authentication unit (15) for comparing said retrieved registration data with said encrypted authentication data during said user authentication and authenticating said user if a comparison score reaches a predefined threshold, characterized in that, during said user registration,
- said encryption unit (12) parses said registration data into multiple registration data portions and encrypts each registration data portion; and
- said communication unit (13) forwards each encrypted registration data portion to a different storage location in said storage unit (14) for storage, and during said user authentication,
- said encryption unit (12) parses said authentication data into multiple authentication data portions and encrypts each authentication data portion;
- said communication unit (13) retrieves said encrypted registration data portions corresponding to said user from said storage locations; and
- said authentication unit (15) compares each encrypted registration data portion with corresponding encrypted
authentication data portion to generate at least one comparison score and authenticates said user if said comparison score reaches a threshold.
2. The system of claim 1 , wherein said encryption unit (12) includes: - an algorithm storage module for storing one or more encryption algorithms and parsing algorithms; and
- an algorithm selection module for selecting a parsing algorithm for parsing said registration data and said authentication data, and for selecting an encryption algorithm for encrypting each registration data portion and each authentication data portion.
3. The system (10) of claim 2, wherein said encryption unit (12) encrypts said registration data portions and said authentication data portions using an encryption algorithm.
4. The system (10) of claim 2, wherein said encryption unit (12) encrypts each registration-authentication data portion pair using a different encryption algorithm.
5. The system (10) of claim 2, wherein said encryption algorithms include a hashing algorithm.
6. The system (10) of claim 2, wherein said encryption unit (12) parses said registration data and said authentication data based on a parsing algorithm.
7. The system (10) of claim 1 , wherein said storage unit (14) includes at least one blockchain database.
8. A method (20) for biometric authentication, comprising the steps of: i. registering a user using at least one biometric feature of said user (21), wherein said biometric feature is inputted as a registration data at an input unit and said registration data is encrypted at an encryption unit and then stored in at least one storage unit; and ii. authenticating said user using said biometric feature (22), wherein said biometric feature is inputted as an authentication data at said input unit
and said authentication data is encrypted at an encryption unit and then compared with said encrypted registration data stored in said storage unit, characterized in that, said step of registering said user includes:
- parsing said registration data into multiple registration data portions;
- encrypting each registration data portion; and
- storing each encrypted registration data portion at a different storage location in said storage unit, and said step of authenticating said user includes:
- parsing said authentication data into multiple authentication data portions;
- encrypting each authentication data portion;
- retrieving said encrypted registration data portions corresponding to said user from said storage locations;
- comparing each encrypted registration data portion with corresponding encrypted authentication data portion to generate at least one comparison score; and
- authenticating said user if said comparison score reaches a threshold.
9. The method (20) of claim 8, wherein said step of encrypting includes:
- selecting a parsing algorithm from one or more parsing algorithms pre-stored in a storage module;
- parsing said biometric feature using said selected parsing algorithm;
- selecting at least one encryption algorithm from one or more encryption algorithms pre-stored in said storage module; and
- encrypting each data portion using said selected encryption algorithm.
10. The method (20) of claim 8, wherein said step of comparing each encrypted registration data portion with corresponding encrypted authentication data portion includes:
comparing said encrypted registration data portions with corresponding encrypted authentication data portions to generate respective comparison scores; calculating an average score of said comparison scores; and outputting said average scare as a final comparison score.
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| MYPI2020003542A MY204633A (en) | 2020-07-08 | 2020-07-08 | System and method for biometric authentication |
| MYPI2020003542 | 2020-07-08 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2022010338A1 true WO2022010338A1 (en) | 2022-01-13 |
Family
ID=79553532
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/MY2020/050169 Ceased WO2022010338A1 (en) | 2020-07-08 | 2020-11-25 | System and method for biometric authentication |
Country Status (2)
| Country | Link |
|---|---|
| MY (1) | MY204633A (en) |
| WO (1) | WO2022010338A1 (en) |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN116684148A (en) * | 2023-06-08 | 2023-09-01 | 广西电网有限责任公司电力科学研究院 | A user terminal security authentication method and related device based on identity identification |
| US12380192B2 (en) * | 2022-10-27 | 2025-08-05 | Union Biometrics Co., Ltd. | Biometric authentication method capable of securely managing template pieces of biometric information with encryption |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP1564686A1 (en) * | 2003-03-31 | 2005-08-17 | Fujitsu Limited | Collator and register |
| JP2006293712A (en) * | 2005-04-11 | 2006-10-26 | Glory Ltd | System and method for personal authentication |
| WO2009146315A1 (en) * | 2008-05-27 | 2009-12-03 | Newport Scientific Research, Llc | Split template biometric verification system |
-
2020
- 2020-07-08 MY MYPI2020003542A patent/MY204633A/en unknown
- 2020-11-25 WO PCT/MY2020/050169 patent/WO2022010338A1/en not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP1564686A1 (en) * | 2003-03-31 | 2005-08-17 | Fujitsu Limited | Collator and register |
| JP2006293712A (en) * | 2005-04-11 | 2006-10-26 | Glory Ltd | System and method for personal authentication |
| WO2009146315A1 (en) * | 2008-05-27 | 2009-12-03 | Newport Scientific Research, Llc | Split template biometric verification system |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US12380192B2 (en) * | 2022-10-27 | 2025-08-05 | Union Biometrics Co., Ltd. | Biometric authentication method capable of securely managing template pieces of biometric information with encryption |
| CN116684148A (en) * | 2023-06-08 | 2023-09-01 | 广西电网有限责任公司电力科学研究院 | A user terminal security authentication method and related device based on identity identification |
Also Published As
| Publication number | Publication date |
|---|---|
| MY204633A (en) | 2024-09-06 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US10530577B1 (en) | Systems and methods for biometric key generation in data access control, data verification, and path selection in block chain-linked workforce data management | |
| US10678944B2 (en) | Method and system for managing personal information within independent computer systems and digital networks | |
| US20220052852A1 (en) | Secure biometric authentication using electronic identity | |
| CN104270338B (en) | Method and system for electronic identity registration and authentication login | |
| AU2020399657B2 (en) | Privacy-preserving biometric authentication | |
| CN103679436B (en) | A kind of electronic contract security system and method based on biological information identification | |
| EP3605373B1 (en) | Authentication method for a client over a network | |
| US20190311148A1 (en) | System and method for secure storage of electronic material | |
| US12184604B2 (en) | Domain name registration based on verification of entities of reserved names | |
| US20240013198A1 (en) | Validate digital ownerships in immutable databases via physical devices | |
| US20060112280A1 (en) | Method and system for secure transmission of biometric data | |
| WO2019199288A1 (en) | System and method for secure storage of electronic material | |
| US12088727B2 (en) | Block chain proof for identification | |
| US20240305459A1 (en) | Generating keys using controlled corruption in computer networks | |
| CN101340283A (en) | Multisystem biometric token | |
| AU2018100503A4 (en) | Split data/split storage | |
| US11823194B2 (en) | Decentralized biometric authentication platform | |
| Chiou | Secure Method for Biometric‐Based Recognition with Integrated Cryptographic Functions | |
| WO2022010338A1 (en) | System and method for biometric authentication | |
| US20190288833A1 (en) | System and Method for Securing Private Keys Behind a Biometric Authentication Gateway | |
| WO2021156746A1 (en) | A method, a system and a biometric server for controlling access of users to desktops in an organization | |
| Chand et al. | Biometric authentication using SaaS in cloud computing | |
| WO2009082199A1 (en) | Distributed biometric database and authentication system | |
| SG11202112139WA (en) | Methods and systems for trusted web authentication | |
| Durak et al. | BioLocker: A practical biometric authentication mechanism based on 3D fingervein |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 20943856 Country of ref document: EP Kind code of ref document: A1 |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| 122 | Ep: pct application non-entry in european phase |
Ref document number: 20943856 Country of ref document: EP Kind code of ref document: A1 |