Identity Based on Revocable Biometric Impressions
By using user-specific data in the biometric authentication system for one-way processing and generating processed blots, the problem of biometric blots cannot be revoked in traditional systems is solved, and higher user privacy and authentication system security is achieved.
Patent Information
- Application Number
- CN201980072454.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2018-11-01
- Filing Date
- 2019-10-29
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2039-10-29
AI Technical Summary
In traditional biometric authentication systems, once the biometric blot is known, the alternative biometric blot cannot be republished, resulting in the user being unable to revoke their biometric authentication.
The processed blot is generated by one-way processing using user-specific data during the registration phase, rather than using biometric blots directly. User-specific data may be a private key in a hash salt or a public/private key pair, and one-way processing may include a hash or a digital signature.
This enables users to revoke their biometric blots, preventing biometric blots from being abused, and enhancing the security of user privacy and authentication systems.
Smart Images

Figure CN112997188B_ABST
Abstract
Description
BACKGROUND OF THE INVENTION
[0001] Biometrics is the measurement of physiological characteristics of a living entity, which is most often a human. Biometrics is often used for the purpose of identifying humans and / or controlling human access to resources. For example, biometrics can include fingerprints, facial features, palm vein patterns, hand geometry, iris patterns, retina patterns, etc. For use by a computing system, the appropriate biometrics are converted into computer-readable code, which is often referred to as a "biometric print".
[0002] For example, many mobile devices have a fingerprint scanner that allows a human user to register fingerprints (e.g., one fingerprint per finger) for the purpose of later accessing the mobile phone. Those fingerprints are stored on the mobile device as a set of biometric prints, one biometric print for each registered fingerprint. Later, if the user desires to unlock the mobile device or use a restricted feature of the mobile device, the user can rescan one of the registered fingers that they have registered, and the registered finger is matched against the registered fingerprint. Such fingerprint rescan is an alternative to other forms of gaining access to the mobile device, such as perhaps entering a password.
[0003] The matching occurs by converting the fingerprint to be rescaned into a new biometric print. The new biometric print is then compared against each of the registered biometric prints until a sufficiently similar registered biometric print is found, or until all of the registered biometric prints have been examined without a match. If a matching registered biometric print is found, the mobile device unlocks itself and / or enables the restricted feature of the mobile device.
[0004] The subject matter claimed herein is not limited to embodiments that solve any disadvantages such as those described above or operate only in environments such as those described above. Rather, this background is only provided to illustrate an exemplary technical field in which some embodiments described herein may be practiced. SUMMARY OF THE INVENTION
[0005] The principles described herein allow a user to revoke a biometric print, which is computer-readable code representing the user's biometrics (e.g., fingerprint). Traditionally, given knowledge of the process used to calculate a biometric print from a biometric, the same sample biometric would always result in the same biometric print. This means that once the biometric print is known, there is no way to reissue an alternative biometric print for the user. In contrast, the principles described herein allow a biometric print to be revoked.
[0006] Using biometrics for authentication involves two phases: an enrollment phase and a later matching phase. In the enrollment phase, the user along with his / her biometric data is enrolled in the authentication system. When it is determined that the biometric is from the same user, the enrolled biometric data will be used in future matching phases. In the matching phase, the user provides a current biometric which is used to generate current biometric data (also referred to herein as the "processed imprint"), and the authentication system can use the current biometric data for authentication by matching the current biometric data with the enrolled biometric data.
[0007] According to the principles described herein, enrollment occurs by generating a processed imprint based on at least two pieces of information. First, there is the biometric imprint to be enrolled. Second, there is user-specific data that is, or corresponds to, user-specific data recognized by the authentication system as being associated with the user. By performing a one-way processing of the biometric imprint using the user-specific data, the processed imprint is generated. One-way processing is a process where the original input of the process cannot be derived from the output. An example is hashing the input, or signing the input with a private key.
[0008] As a first example, the user-specific data can be a hash salt for the user, and the one-way processing can be hashing the biometric imprint together with the user's salt hash (perhaps with chain-hashing). As a second example, the user-specific data can be the private key in a public key / private key pair associated with the user. In this second example, the one-way processing includes digitally signing the biometric imprint (or a hashed version or perhaps a chain-hashed version of the biometric imprint) using the private key. The authentication system has access to the public key in the public key / private key pair and can thus verify that the user signed using the corresponding private key.
[0009] The processed imprint rather than the biometric imprint is then provided to the authentication system for later authenticating the user using the processed imprint and the user-specific data recognized by the authentication system as being associated with the user. Thus, anyone looking at the communication channel with the authentication system will not discover the actual biometric imprint.
[0010] The processed biometric can be revoked by invalidating the user-specific data. For example, the user's hash salt can be revoked, or the public key / private key pair can be invalidated. This means that any processed imprint generated from the biometric imprint will not be recognized as long as the processed imprint was also generated using the invalidated user-specific data.
[0011] During a match, the user later provides a current biometric (e.g., fingerprint of a registered finger), which causes the generation of a current biometric footprint. For each of a plurality of users, user-specifics are obtained for that user, and for each user at least one processed footprint is generated based on the current biometric footprint. The processed footprints are used by an authentication system to match the provided current processed footprint against each of the registered processed footprints. If a match is found, the user is identified as the user associated with the matching registered processed footprint.
[0012] Some embodiments described herein also prevent the replay of biometric footprints. Thus, even if another party gains improper access to the biometric footprint, the user will not be able to use the biometric footprint to pretend that they are the user when authenticating to the authentication system using the biometric footprint. According to at least some of these embodiments, this is accomplished by making the one-way processing include a chained hash.
[0013] The present invention content is provided in a simplified form to introduce a selected set of concepts that will be further described in the following detailed description. The present invention content is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to assist in determining the scope of the claimed subject matter. Brief Description of the Drawings
[0014] To describe the manner in which the above and other advantages and features of the present invention can be obtained, the present invention briefly described above will be described in more detail with reference to specific embodiments of the present invention illustrated in the drawings. Accordingly, these drawings only depict example embodiments of the present invention and should not be considered as limiting the scope of the present invention. In view of this, the example embodiments of the present invention will be described and explained with reference to the drawings, in which:
[0015] Figure 1 A system in which the principles described herein can operate is illustrated, the system including a user who interacts with a client computing system for the purpose of registering a biometric with an authentication system and later matching the biometric for authenticating the user;
[0016] In addition to various data flows associated with registration being Figure 2 illustrated, Figure 2 also illustrated is a system identical to the Figure 1 system;
[0017] Figure 3 A flowchart of a method for registering a user to enable revocable biometric authentication of the user is illustrated;
[0018] Figure 4AIllustrates a first example, in which the user-specific data is a hash salt, and the one-way processing is a single hashing operation that is a combination of a biometric imprint and the hash salt;
[0019] Figure 4B Illustrates a second example, in which the user-specific data is the private key in a public key / private key pair, and the one-way processing is using the private key to digitally sign the biometric imprint;
[0020] Figure 4C Illustrates a third example, in which the user-specific data is a hash salt, and the one-way processing is a chained hashing operation that is a combination of a biometric imprint and the hash salt;
[0021] Figure 4D Illustrates a fourth example, in which the user-specific data is a private key, and the one-way processing is a chained hashing operation on the biometric imprint, followed by digitally signing the result using the private key;
[0022] Figure 5 is a system similar to the system in Figure 2 except that more elements of the current authentication system are illustrated and the data flow associated with matching is also shown;
[0023] Figure 6 Illustrates a flowchart of a method for identifying (matching) a user to an authentication system after registering the user; and
[0024] Figure 7 Illustrates an example computer system in which the principles described herein can be employed. Detailed Description
[0025] The principles described herein allow a user to revoke a biometric imprint, which is a computer-readable code representing the user's biometric (e.g., fingerprint). Traditionally, given knowledge of the process used to calculate the biometric imprint from the biometric, the same sample biometric would always result in the same biometric imprint. This means that once the biometric imprint is known, there is no way to reissue an alternative biometric imprint for the user. In contrast, the principles described herein allow the biometric imprint to be revoked.
[0026] Authentication using biometrics involves two phases: an enrollment phase and a later matching phase. In the enrollment phase, the user and his / her biometric data are enrolled in the authentication system. When it is determined that the biometric is from the same user, the enrolled biometric data will be used in future matching phases. In the matching phase, the user provides a current biometric, which is used to generate current biometric data (also referred to herein as a "processed imprint"), and the authentication system can use this current biometric data for authentication by matching the current biometric data with the enrolled biometric data.
[0027] According to the principles described herein, enrollment occurs by generating a processed imprint based on at least two pieces of information. First, there is the biometric imprint to be enrolled. Second, there is user-specific data that is, or corresponds to, user-specific data recognized by the authentication system as being associated with the user. By performing a one-way processing of the biometric imprint using the user-specific data, a processed imprint is generated. One-way processing is a process where the original input of the process cannot be derived from the output. An example is hashing the input, or signing the input with a private key.
[0028] As a first example, the user-specific data can be a hash salt for the user, and the one-way processing can be hashing the biometric imprint together with the user's salt hash (perhaps with chained hashing). As a second example, the user-specific data can be the private key in a public key / private key pair associated with the user. In this second example, the one-way processing includes using the private key to digitally sign the biometric imprint (or a hashed or perhaps chained-hashed version of the biometric imprint). The authentication system has access to the public key in the public key / private key pair and can thus verify that the user signed using the corresponding private key.
[0029] The processed imprint rather than the biometric imprint is then provided to the authentication system for later use in authenticating the user using the processed imprint and the user-specific data recognized by the authentication system as being associated with the user. Thus, anyone looking at the communication channel with the authentication system will not discover the actual biometric imprint.
[0030] The processed biometric can be revoked by invalidating the user-specific data. For example, the user's hash salt can be revoked, or the public key / private key pair can be invalidated. This means that any processed imprint generated from the biometric imprint will not be recognized as long as the processed imprint was also generated using the invalidated user-specific data.
[0031] During a match, the user later provides a current biometric (e.g., a fingerprint of a registered finger), which causes the generation of a current biometric footprint. For each of a plurality of users, user-specifics are obtained for that user, and for each user at least one processed footprint is generated based on the current biometric footprint. The processed footprints are used by an authentication system to match the provided current processed footprint against each of the registered processed footprints. If a match is found, the user is identified as the user associated with the matching registered processed footprint.
[0032] Some embodiments described herein also prevent the replay of biometric footprints. Thus, even if another party obtains improper access to the biometric footprint, that user will not be able to use the biometric footprint to pretend that they are the user when authenticating to the authentication system using the biometric footprint. According to at least some of these embodiments, this is accomplished by making the one-way processing include performing a chained hash.
[0033] First, a system including a user, a client computing system, and an authentication system will be described with reference to Figure 1 Then, registering a user's biometric with the authentication system will be described with reference to Figure 2 、 Figure 3 and Figure 4A Thereafter, matching a user's biometric to authenticate the user will be described with reference to Figure 5 and Figure 6 Then additional examples of one-way processing will be described with reference to Figure 4B 、 Figure 4C and Figure 4D Finally, an example computing system will be described with reference to Figure 7 The example computing system can be a client computing system and / or an authentication system.
[0034] Figure 1 FIG. illustrates a system 100 in which the principles described herein can operate. System 100 includes User A interacting with client computing system 110. System 100 also includes authentication system 120. Client computing system 110 and authentication system 120 can each be constructed as described below for computing system 700 with respect to Figure 7 .
[0035] As Figure 1As illustrated, user A has biometric 101. The biometric is symbolically illustrated as a circle. Biometric 101 can be any measurable physiological characteristic or combination of characteristics of user A that distinguishes user A from the vast majority of other users. By way of example, biometric 101 can be a fingerprint, facial feature, palm vein pattern, hand geometry, iris pattern, retina pattern, etc. Biometric 101 is illustrated as including four biometrics 101A, 101B, 101C, and 101D. However, ellipsis 101E indicates that user 101 has enumerable physiological characteristics that are largely unique to that user and can thus be used to identify that user.
[0036] Client computing system 110 also includes a biometric imprint capture component 111, a one-way processing component 112, and a communication component 113. These components 111, 112, and 113 can be software components and / or hardware components of client computing system 110. For example, if client computing system 110 is constructed as described for Figure 7 computing system 700 below, each of biometric imprint capture component 111, one-way processing component 112, and communication component 113 can be constructed as described for Figure 7 executable component 706.
[0037] Using biometrics for authentication includes two phases: an enrollment phase and a later matching phase. In the enrollment phase, the user and his / her biometric data are enrolled in the authentication system. When it is determined that the biometric is from the same user, the enrolled biometric data will be used in future matching phases. In the matching phase, the user uses a current biometric (or more specifically, current biometric data generated from the current biometric), and the authentication system can use the current biometric data to authenticate by matching the current biometric data with the enrolled biometric data.
[0038] Now reference will be made to Figure 2 and Figure 3 to describe an example enrollment process. In addition to various data flows associated with enrollment being Figure 2 illustrated, Figure 2 system 200 identical to system 100 of Figure 1 is also illustrated. Figure 3 A flowchart of method 300 for enrolling a user to enable revocable biometric authentication of the user is illustrated. Method 300 can be executed for each of a plurality of biometric imprints of the user. Now method 300 of Figure 2 will be described with frequent reference to system 200 of Figure 3 below.
[0039] Method 300 includes obtaining a biometric footprint of a user (act 301). A biometric footprint is a computer-readable representation of a user's biometrics. For example, in Figure 2 , User A provides some of his / her biometrics 101 (specifically, biometrics 101A, 101B, and 101D) to client computing system 110. Biometric footprint capture component 111 generates a biometric footprint 201 for each of the provided biometrics 101A, 101B, and 101D. For example, biometric footprint capture component 111 generates a biometric footprint 201A that digitally represents biometric 101A, a biometric footprint 201B that digitally represents biometric 101B, and a biometric footprint 201D that digitally represents biometric 101D.
[0040] Ellipsis 201E indicates that biometric footprint capture component 111 may generate biometric footprints 201 for other biometrics 101 provided by User A. The absence of biometric footprint 201C is only for explaining that User A has many biometrics and not all of those biometrics need to be provided. Indeed, biometric footprint capture component 111 may not be equipped to capture all of the user's biometrics. For example, biometric footprint capture component 111 can be a fingerprint reader that only captures fingerprints. Biometric footprint capture component 111 can be constructed the same as any biometric footprint capture component, whether a biometric footprint capture component that exists now or one that has not yet been developed. The exact structure of biometric footprint capture component 111 is not important to the broader principles described herein and is only explained for context.
[0041] Reference Figure 3 , different from a conventional biometric system, method 300 further includes obtaining user-specific data (act 302), which is, or corresponds to, user-specific data recognized by the authentication system as being associated with the user. For example, in Figure 2 , one-way processing component receives user-specific data 202 specific to User A.
[0042] In addition, method 300 includes generating a processed footprint (act 303) by performing one-way processing of the biometric footprint using the obtained user-specific data. One-way processing is a processing in which the original input of the processing cannot be derived from the output of the processing. An example of one-way processing of processing a biometric footprint using user-specific data will be described below with reference to Figures 4A to 4D .
[0043] For example, in Figure 2In [the figure], the one-way processing component 112 uses user-specific data to perform one-way processing on at least some of the biometric imprints in the biometric imprint 201, thereby generating a processed imprint 203. For example, the one-way processing component 112 uses user-specific data 202 to perform one-way processing on the biometric imprint 201A, thereby generating a corresponding processed imprint 203A. Similarly, the one-way processing component 112 uses user-specific data 202 to perform one-way processing on the biometric imprint 201B, thereby generating a corresponding processed imprint 203B. This represents an embodiment in which user-specific data is specific to a user but can be used for multiple biometric imprints of that user. The fact that the biometric imprint 201 is the original biometric imprint is represented by each biometric imprint in the biometric imprint 201 being an upward-pointing triangle. The processed imprint 203 is a processed version of the biometric imprint, represented by each processed imprint in the processed imprint 203 being a downward-pointing triangle. The same symbols are also used in Figure 5 In.
[0044] Figure 4A Illustrates a simple example 400A, in which the user-specific data 202 is a hash salt 201A and the one-way processing is a single hashing operation. In Figure 4A In, a combination of the biometric imprint 401A and the hash salt 402A is provided to the hashing component 410A to generate a processed imprint 411A. For example, assume the hash salt 402A is S 用户A , the biometric imprint 401A is p 1 , and the hashing function is h(x). In this case, the one-way processing can be defined as h(p 1 , S 用户A ). If this is done for multiple imprints p 1 to p n , then the template or digest of the imprints (template 用户A ) can be defined as in Equation 1 below. Template 用户A = [h(p 1 , S 用户A ), h(p 2 , S 用户A ),..., h(p n , S 用户A )] (1)
[0045] In the example of Equation 1, the user-specific data is the user's hash salt, and the one-way processing includes hashing the biometric imprint together with the user's hash salt (also known as performing salted hashing of the biometric imprint), resulting in a processed imprint.
[0046] In an alternative embodiment, the user-specific data is also specific to a particular biometric imprint. For example, Figure 2 illustrates user-specific data 202A that is specific to user A and also specific to biometric imprint 201A, and user-specific data 202B that is specific to user A and also specific to biometric imprint 201B. In this case, the one-way processing component 112 uses the user-specific data 202A to perform one-way processing on the biometric imprint 201A, thereby generating the corresponding processed imprint 203A. Similarly, the one-way processing component 112 uses the user-specific data 202B to perform one-way processing on the biometric imprint 201B, thereby generating the corresponding processed imprint 203B. Equation 2 illustrates an example of a template in which there are multiple hash salts [S 用户A1 , S 用户A2 ,..., S 用户An , each hash salt being for the same user A, but each hash salt corresponding to a different imprint [p 1 , p 2 ,..., p n of that user.
[0047] Template 用户A = [h(p 1 , s 用户A1 ), h(p 2 , S 用户A2 ),..., h(p n , S 用户An )] (2)
[0048] Reference will be made further herein to Figure 4A the example and Equations 1 and 2, although additional examples will be described with reference to Figures 4B to 4D later, but this will be after the description of matching with reference to Figure 5 and Figure 6 .
[0049] The lack of a processed imprint 203D simply means that the principles described herein do not require one-way processing of every biometric imprint 201 captured by the client computing system 110. However, one-way processing is indeed performed on all biometric imprints captured by the client computing system, but it may also be performed on only some of the biometric imprints captured by the client computing system, or perhaps even only one biometric imprint.
[0050] Method 300 then causes the processed imprint to be provided to the authentication system (action 304). For example, in Figure 2In this case, the communication component 113 can provide the processed imprint 202 to the authentication system 120. For example, a digest of multiple processed imprints can be provided to the authentication system 120. This digest of the processed imprint can be used for later authentication of User A in one or more matching phases.
[0051] Recall that the first of the two phases associated with biometric identification is the enrollment phase described above with reference to Figure 2 and Figure 3 Now, the subsequent matching phase will be described with reference to Figure 5 system 500 and Figure 5 method 600. The matching phase can be executed each time a user authenticates himself / herself to the authentication system after the enrollment phase.
[0052] Figure 5 is a system 500 similar to Figure 2 system Figure 2 200, except that more elements of the authentication system 120 are now illustrated in the form of an authentication system 520. For example, depending on the type of one-way processing performed at the client computing system 110, the authentication system 520 can use a preprocessing component 541 to perform additional one-way processing. Additionally, the authentication system 520 includes a matching component 542 that performs matching of the received processed imprint (or preprocessed processed imprint) with the enrolled processed imprint. When the authentication system 120 is constructed as described below for the computing system 700, each of the preprocessing component 541 and the matching component 542 can be constructed as described below for Figure 7 executable component 706. Further, in Figure 5 the data flow associated with matching is illustrated, while Figure 2 illustrates the data flow associated with enrollment.
[0053] The authentication system 520 includes registered processed imprints 510 associated with multiple users. For example, there are processed imprints 203A and 203B (i.e., processed imprint 203) associated with user A, processed imprints 512A and 512B (i.e., processed imprint 512) associated with user B, processed imprints 513A and 513B (i.e., processed imprint 513) associated with user C, and processed imprints 514A and 514B (i.e., processed imprint 514) associated with user D. Additionally, the authentication system 500 has user-specific data 521 to user-specific data 524 (i.e., user-specific data 520) respectively associated with each of users A to D. Similarly, the authentication system 500 may have processing information 531 to processing information 534 (i.e., processing information 530) respectively associated with each of users A to D. For illustrative purposes only, the authentication system 520 is illustrated as including processed imprints 510, user-specific data 520, and processing information associated with only four users A, B, C, and D. However, the authentication system may include such data for any number of users.
[0054] Figure 6 A flowchart of method 600 is illustrated, where method 600 is for identifying a user to an authentication system after registering the user. Method 600 may be executed in Figure 5 system 500. Thus, system 500 will now be frequently referred to in describing Figure 5 method 600. Actions performed by a client computing system (e.g., Figure 6 the client computing system 110 of Figure 1 , Figure 2 and Figure 5 ) are represented under the "Client" heading in the left column of Figure 6 . Actions performed by an authentication system (e.g., Figure 1 , Figure 2 the authentication system 120 of Figure 5 or the authentication system 520 of Figure 6 ) are represented under the "Authentication System" heading in the right column of
[0055] The client computing system acquires a biometric imprint of the user (action 601). For example, in Figure 5In this case, the biometric imprint capture component 111 captures the biometric 101B of user A to generate a biometric imprint 501B. The biometric imprint 501B is likely to be the same as or very similar to the biometric imprint 201B, which was previously captured from the same biometric 101B by the biometric imprint capture component 111 during registration. However, unlike the registration phase, perhaps a single biometric imprint is generated from a single biometric. As an example, during registration, the user may have registered all of his / her fingers. However, when authenticating at a later time during the matching phase, perhaps the user only uses a single finger for authentication.
[0056] Then, multiple processed imprints are generated from a single biometric imprint, rather than generating a single processed imprint from that single biometric imprint. Specifically, in Figure 6 the contents of the box 610 can be executed for each of a plurality of users (e.g., for each of users A, B, C, and D).
[0057] More specifically, user-specific data is obtained, which is, or corresponds to, the respective user-specific data of the user (action 611). For example, in Figure 5 the one-way processing component 112 receives the biometric imprint 501B, as well as the user-specific data 521 to user-specific data 524 for each of users A, B, C, and D. The one-way processing component then generates corresponding processed imprints for each of those users by performing corresponding one-way processing of the more recent biometric imprint using the respective obtained user-specific data (action 612). The client computing system 110 can obtain the user-specific data 521 to user-specific data 524 from the authentication system 520.
[0058] For example, assume that the more recently received biometric imprint 501B is symbolized as p 未知 and the salt hashes for each of users A through N are defined by the set [S 用户A , S 用户B ,..., S 用户N . Then, the processed imprints are generated by hashing the biometric imprint p 未知 for each salt in the salt. In this case, the set of processed imprints can be defined by Equation 3 below.
[0059] [h(p 未知 , S 用户A ), h(p 未知 , S 用户B ), …, h(p 未知 , S 用户N )] (3)
[0060] In Figure 5 the example, the processed imprints include processed imprint 502A generated from biometric imprint 501B using user-specific data 521, processed imprint 502B generated from biometric imprint 501B using user-specific data 522, processed imprint 502C generated from biometric imprint 501B using user-specific data 523, and processed imprint 502D generated from biometric imprint 501B using user-specific data 524.
[0061] Method 600 then includes causing the processed imprints for each of a plurality of users to be provided to an authentication system for authentication of a particular user (action 615). For example, in Figure 5 this case, communication component 113 provides processed imprint 502 (including each of processed imprints 502A, 502B, 502C, and 502D) to authentication system 520.
[0062] Method 600 then proceeds to the authentication system, which attempts to match the biometrics to identify a particular user. Specifically, the authentication system accesses the current processed imprint (action 621). In Figure 5 this case, authentication system 520 receives processed imprints 502A through 502D. The authentication system may also perform some preprocessing of the processed imprints (action 622). Scenarios in which preprocessing may be beneficial will be further described with reference to Figure 4C and Figure 4D below.
[0063] The contents of box 630 can then be executed for each of a plurality of users to determine which, if any, of the registered users the most recently scanned user is. As part of this process, the authentication system determines that the processed imprint was generated using user-specific data (action 631). In the case of a salt hash, this is implicit when matching the user to the matching processed imprint. Finally, if the hash was not generated based on a valid salt hash, the matching processed imprint cannot be found.
[0064] The authentication system also accesses the set of registered processed imprints for the corresponding user (action 632). The authentication system determines whether there is a match between the current processed imprint and any of the registered processed imprints in the set of registered processed imprints for the corresponding user (decision box 633). If not (the "No" in decision box 633), then the authentication system checks whether there is a match for the next user, or if not, fails to identify the user (action 634). If so (the "Yes" in decision box 633), then the authentication system determines that the corresponding user is identified (action 635).
[0065] For example, in Figure 5 , in the presence of users A, B, C, and D, the authentication system 120 can determine whether any of the processed imprints in the more recent processed imprint 502 match those registered processed imprints 203A and 203B, 512A and 512B, 513A and 513B, and 514A and 514B. In the salt hash example of Equation 3, the authentication system would determine that h(p 未知 , s 用户A ) is within the template 用户A (the "Yes" in decision box 633 when evaluating user A), because h(p 未知 , S 用户A ) would match h(p 2 , S 用户A ) (see Equation 1). This same match allows the authentication system to know that the processed imprint h(p 未知 , S 用户A ) was indeed generated by user A (action 631 when evaluating user A). Thus, determining whether a processed imprint was indeed generated from user-specific data is performed as part of the following operation: determining whether any of the current processed imprints in the current processed imprint match any of the registered processed imprints in the set of registered processed imprints for the corresponding user.
[0066] Once a matching user is found, there is no need to continue evaluating additional users (action 635). However, suppose the processed imprint h(p 未知 , S 用户A ) has not yet matched any of the registered processed imprints for user A. In this case, the matching process moves to the next user (action 634), which is user B. Since h(p 未知 , S 用户B ) does not match any of the registered imprints for user B (since p 未知(is not a biometric footprint for User B), so this results in no match being found ("No" in decision box 633), causing the next user (User C) to be evaluated (action 634). Since h(p 未知 , S 用户C ) does not match any of the registered footprints in the registered footprints for User C (since p 未知 is not a biometric footprint for User C), so this results in no match being found ("No" in decision box 633), causing the last user (User D) to be evaluated (action 634). Finally, since h(p 未知 , S 用户D ) does not match any of the registered footprints in the registered footprints for User D (since p 未知 is not a biometric footprint for User D), so this results in no match being found ("No" in decision box 633), causing the last user (User D) to be evaluated (action 634).
[0067] There may also be some final one-way processing of the currently processed footprint (action 622). This may not be the case when the processing being performed is a single hash of the biometric. However, when the entire one-way processing involves performing chained hashes a predetermined number of times, this is likely to be the case. This preprocessing will be further described below with reference to Figure 4C and Figure 4D . However, for now, this specification continues with the description of Figure 4B .
[0068] Figure 4B illustrates one-way processing 400B that can be performed by the one-way processing component 112 of Figure 1 , Figure 2 and Figure 5 . In this case, the one-way processing is digitally signing and the user-specific data is the private key in a public key / private key pair. The one-way processing includes a signature component 410B that uses the private key 402B to digitally sign the biometric footprint 401B to generate a processed footprint 411B in the form of a signed biometric footprint. In this case, the user-specific data is the private key 402B in the public key / private key pair associated with the user. The corresponding public key is the user-specific data recognized by the authentication system as being associated with the user. The authentication system 520 can use the public key to determine that the processed footprint 411B was indeed signed by the user (e.g., in action 631). If the authentication system 520 cannot make this determination, then the user is not determined to be a match (action 634).
[0069] Figure 4CIllustrated is another example 400C of one-way processing of a biometric imprint. In this case, the chained hash component 410C performs a predetermined number of chained hashes on the combination of the biometric imprint 401C and the salt hash 402C according to the chain length 403C. The hash salt 402 can be user-specific data (e.g., user-specific data 520). The chain length 403C can be processing information (e.g., processing information 530). The client computing system 110 can obtain this information from the authentication system 520.
[0070] As in traditional biometric systems, if a valid salted hash can be obtained, the hash performed on the biometric imprint together with the hash salt may still be compromised. In other words, if an attacker can obtain the salted hash h(p A , S x ) for a user, then this salted hash can be replayed to the authentication system and will be treated as a valid match. To address this issue, the processed imprint (i.e., the salted hash) is repeatedly rehashed the number of times set. This is written as y = h 用户A (x), where y is the Nth chain in the hash chain (i.e., h n (x) = h[(h(h(h(..h(x))))))). n
[0071] For example, assume a piece of data x is hashed 100 times to result in y = h 100 (x). The authentication system can advertise the hash function h it supports, and the expected number of chains 100. To prove the user has access to data x, the client computing system performs the hash chain on x up to 99 times, providing the authentication system y' = h 99 (x). Given that the hash function is computationally irreversible, the authentication system knows that the publicly known h 100 (x) cannot be used to compute h 99 (x). So when it receives y', the system performs a simple test to determine if h(y') = y. If this is true, the authentication system knows that the client computing system indeed has access to x, and rolls the chain back one, broadcasting y' = h 99 (x) as the new chain element. The next attempt to prove x to the authentication system will have to compute the 98th hash chain of x and present the computed 98th hash chain of x to the authentication system.
[0072] During registration, the authentication system will determine the appropriate chain length for the user. In our example, we chose a chain length of 100. Once the chain is exhausted, the user will have to re-register to continue using the authentication system. To limit the user's inconvenience and avoid user re-registration, the user can be prompted to use another mechanism to authenticate themselves, which can lead to a re-chain of the imprint.
[0073] Currently, let's look at a simpler case where, once the chain is exhausted, registration will be required to continue using the system. The authentication system can notify the client computing system 1) how many times to perform the chain hash in order to register the digest of the processed footprint (e.g., 100), and 2) hash the salt S 用户A . This represents Figure 3 an example of the action of obtaining user-specific data (action 302).
[0074] In the case where the chain length is determined, registration will be performed as before, but the template will now be constructed as in Equation 4 below:
[0075] Template 用户A =[h 100 (p 1 , S 用户A ), h 100 (p 2 , S 用户A ),..., h 100 (p n , S 用户A )] (4)
[0076] In this state, each footprint has a chain length of 100, which allows a specific footprint to be used up to 100 times before registration is required.
[0077] To perform the matching, the footprint of the unknown user is hashed as before according to Equation 5 below:
[0078] [h(p 未知 , S 用户A ), h(p 未知 , S 用户B ), …, h(p 未知 , S 用户N )] (5)
[0079] Once the digest is ready, the matching is slightly changed, especially in the case where the unknown user is compared with User A. Using the above template, template 用A =[h 100 (p 1 , S 用户A ), h 100 (p 2 , s 用户A ),..., h 100 (p n , S 用户A ), the client computing system will note that each footprint digest is chained up to 100 times, so the client computing system will use h(p 未知 , s 用户A ) to generate the 99th chain, resulting in h 99 (p未知 , s 用户A ). This is an example of a one-way process performed in action 612 in Figure 6 . The salted chained hash h 99 (p 未知 , s 用户A ) is then provided to the authentication system, which hashes the result again to result in h 100 (p 未知 , S 用户A ).
[0080] The system then compares this new, chained digest with each digest in template 用户A . For the purposes of this example, let's assume that the processed footprint of the unknown user matches the 3rd footprint digest in the template. At this point, the system confirms that the identity of the unknown user is User A. Since the chained salted hash h 99 (p 未知 , S 用户A ) is sent over the network, for security, assume that the chained salted hash might have been obtained by an unauthorized user. To prevent the replay of h 99 (p 未知 , s 用户A ), the authentication system then rolls back the chain length for User A by one to result in the template as defined in Equation 6 below.
[0081] Template 用户A = [h 99 (p 1 , s 用户A ), h 99 (p 2 , s 用户A ), h 99 (p 3 , s 用户A ),..., h 99 (p n , s 用户A )] (6)
[0082] At this point, the system is ready to use the template again. Next time, however, the authentication system instructs that the footprint of the chained hash for chain length 98 be provided. Suppose the user then provides a new unknown biometric footprint p 新1 . The client computing system then provides the salt for the chained hash h 98 (p 新1 , S 用户A ) at that time.
[0083] More generally, the authentication system keeps track of the number of connections to be performed in a one-way process for each user, and decrements the link count for that user when the user is successfully authenticated. This allows the authentication system to instruct the client computing system what one-way process to perform for which user.
[0084] For example, and for illustrative purposes only, assume that the current chain length for user A is 99, for user B is 82, for user C is 90, and for user D is 15. In this case, the client computing system would provide the authentication system with sixteen different processed footprints, 4 for user A (one with chain length 14, one with chain length 81, one with chain length 89, and one with chain length 98), 4 for user B (again with chain lengths 14, 81, 89, and 98), 4 for user C (with the same 4 chain lengths), and 4 for user D (with the same chain lengths).
[0085] Now, imagine that user A is identified for an authentication. The current chain length for user A would be decremented from 99 to 98. The current chain length for user B would remain at 82, for user C would remain at 90, and for user D would remain at 15. At the next authentication, the client computing system would still provide the authentication system with sixteen different processed footprints, 4 for user A (one with chain length 14, one with chain length 81, one with chain length 89, and one with chain length 97), 4 for user B (again with chain lengths 14, 81, 89, and 97), 4 for user C (with the same 4 chain lengths), and 4 for user D (with the same chain lengths). If user D is authenticated, the current chain length for user D would be decremented to 14.
[0086] In another example, the chain length is specific to the user and the processed footprint. For example, again consider the case where A's template is as follows:
[0087] Template 用户A =[h 100 (p 1 , S 用户A ), h 100 (p 2 , S 用户A ),..., h 100 (p n , S 用户A )] (7)
[0088] Using the above template, the system will note that each footprint digest is chained up to 100 times, so it will use h(p 未知 , S 用户A) to generate the 99th chain to result in h 100 (p 未知 ,S 用户A ). The system then compares this new, chained digest with each digest in the template 用户A . For the purposes of this example, assume that the footprint of the unknown user matches the third footprint digest in the template.
[0089] At this point, the system has confirmed that the identity of the unknown user is User A. It then rolls back the third digest by one to result in the template for A being
[0090] Template 用户A =[h 100 (p 1 ,S 用户A ), h 100 (p 2 ,s 用户A ), h 99 (p 3 ,s 用户A ),..., h 100 (p n ,s 用户A )]
[0091] In the case where a particular footprint chain has been exhausted, the system will simply ask the user to perform the same process as detailed for revoking the chained template. This requires the user to prove who they are again and follow up by creating a new template for them with the re-captured biometric data. This template will have a new set of fully chained footprints that are ready to be used for matching again.
[0092] Although not as secure as the re-registration case, the system can choose a more user-friendly method to re-link footprints, as detailed below.
[0093] Assume that the user's footprint is in this state:
[0094] Template 用户A =[h 100 (p 1 ,,S 用户A ), h 100 (p 2 ,S 用户A ), h 2 (p 3 ,S 用户A ),..., h 100 (p n ,S 用户A )]
[0095] You will notice that the imprint of the third strand will be exhausted. The system has just authenticated the user, but the strand cannot be scrolled further. In this case, the system will use a modified solution that utilizes each imprint seed. Thus, the template will actually be designed as follows
[0096] Template 用户A =[h 100 (p 1 , s 1 用户A ), h 100 (p 2 , S 2 用户A ), h 2 (p 3 , s 3 用户A ),..., h 100 (p n , S n 用户A )]
[0097] where S n 用户A is the seed for the nth imprint for User A.
[0098] By adopting this model, we can now re-chain only the third imprint by utilizing the new third imprint seed, i.e., S 3 用户A , when the third imprint is exhausted. In this way, the new user template after re-chaining is
[0099] Template 用户A =[h 100 (p 1 , S 1 用户A ), h 100 (p 2 , S 2 用户A ), h 2 (p 3 , S 3′ 用户A ),..., h 100 (p n , S n 用户A )]
[0100] This solution will allow for an efficient user experience and allow for targeted revocation of imprints rather than templates, allowing only the imprints that have been compromised to be revoked and easily re-linking the imprints into the template without registration.
[0101] Figure 4DIllustrated is a final example 400D, in which the one-way process 410D includes performing a chain hash 410C on the biometric imprint 401A up to the chain length 403C times, followed by signing 410B the chain hash 412D using the private key 402B to generate a processed imprint 411D.
[0102] In each of the above, note that revocation of the processed imprint can be performed by simply notifying the authentication system that specific data is no longer valid. This causes the authentication system (at action 631) to determine that the user-specific data is no longer valid and, thus, the processed imprint generated from that user-specific data does not match the user. For example, in Figure 4A and Figure 4C , the hash salt can be invalidated. In Figure 4B and 4D , the public key can be invalidated.
[0103] Because the principles described herein operate in the context of a computing system, a computing system will be described with reference to Figure 7 . Computing systems are now taking on a wide variety of forms. A computing system can be, for example, a handheld device, appliance, laptop computer, desktop computer, mainframe, distributed computing system, data center, or even a device not conventionally considered a computing system, such as a wearable device (e.g., glasses, watch, band, etc.). In this specification and the claims, the term "computing system" is broadly defined to include any device or system (or combination thereof) that includes at least one physical and tangible processor and a physical and tangible memory capable of having computer-executable instructions thereon that can be executed by the processor. The memory can take any form and can depend on the nature and form of the computing system. The computing system can be distributed across a network environment and can include multiple constituent computing systems.
[0104] As Figure 7 illustrated, in its most basic configuration, a computing system 700 generally includes at least one hardware processing unit 702 and a memory 704. The memory 704 can be a physical system memory, which can be volatile, non-volatile, or some combination of the two. The term "memory" can also be used herein to refer to non-volatile mass storage devices, such as physical storage media. If the computing system is distributed, the processing, memory, and / or storage capabilities can also be distributed.
[0105] Computing system 700 has a number of structures on it that are often referred to as “executable components”. For example, the memory 704 of computing system 700 is illustrated as including executable component 706. The term “executable component” is a name for a structure that can be well understood by those of ordinary skill in the art in the field of computing, which is a structure that can be software, hardware, or a combination thereof. For example, when implemented in software, those of ordinary skill in the art will understand that the structure of an executable component can include software objects, routines, methods that can be executed on a computing system, whether such an executable component exists in the heap of the computing system or whether the executable component exists on a computer-readable storage medium.
[0106] In such a case, those of ordinary skill in the art will recognize that the structure of the executable component exists on a computer-readable medium such that when interpreted by one or more processors (e.g., by a processor thread) of the computing system, it causes the computing system to perform a function. Such a structure can be directly computer-readable by the processor (such as if the executable component is binary). Alternatively, the structure can be constructed (whether in a single stage or in multiple stages) to be interpretable and / or compilable so as to generate such a binary that is directly interpretable by the processor. When the term “executable component” is used, this understanding of the example structure of an executable component is well within the understanding of those of ordinary skill in the art in the field of computing.
[0107] The term “executable component” is also well understood by those of ordinary skill in the art to include structures implemented using only hardware or almost only hardware, such as within a field-programmable gate array (FPGA), an application-specific integrated circuit (ASIC), or any other special-purpose circuit. Thus, the term “executable component” is a term for a structure that is well understood by those of ordinary skill in the art in the field of computing, whether implemented in software, hardware, or a combination. In this specification, the terms “component” or “vertex” may also be used. As used in this specification, and in this context, this term (whether the term is modified by one or more modifiers) is also intended to be synonymous with the term “executable component” or a particular type of such an “executable component”, and thus also has a structure that is well understood by those of ordinary skill in the art in the field of computing.
[0108] In the following description, embodiments are described with reference to actions performed by one or more computing systems. If such actions are implemented in software, then in response to the execution of computer-executable instructions that make up an executable component, one or more processors (of the associated computing system performing the action) direct the operation of the computing system. For example, such computer-executable instructions can be embodied on one or more computer-readable media that form a computer program product. Examples of such operations involve the manipulation of data.
[0109] Computer-executable instructions (and the data being manipulated) can be stored in the memory 704 of the computing system 700. The computing system 700 may also include a communication channel 708 that allows the computing system 700 to communicate with other computing systems, for example, via a network 710.
[0110] Although not all computing systems require a user interface, in some embodiments, the computing system 700 includes a user interface 712 for interfacing with a user. The user interface 712 may include an output mechanism 712A and an input mechanism 712B. The principles described herein are not limited to a precise output mechanism 712A or input mechanism 712B, as this will depend on the nature of the device. However, the output mechanism 712A may include, for example, speakers, displays, haptic outputs, holograms, virtual reality, etc. Examples of the input mechanism 712B may include, for example, microphones, touchscreens, holograms, virtual reality, cameras, keyboards, mice for other pointer inputs, any type of sensors, etc.
[0111] The embodiments described herein may include or utilize a special-purpose or general-purpose computing system including computer hardware, such as, for example, one or more processors and system memory, as discussed in more detail below. The embodiments described herein also include physical and other computer-readable media for carrying or storing computer-executable instructions and / or data structures. Such computer-readable media can be any available media that can be accessed by a general-purpose or special-purpose computing system. A computer-readable medium storing computer-executable instructions is a physical storage medium. A computer-readable medium carrying computer-executable instructions is a transmission medium. Thus, by way of example and not limitation, embodiments may include at least two distinctly different kinds of computer-readable media: storage media and transmission media.
[0112] Computer-readable storage media includes RAM, ROM, EEPROM, CD-ROM, or other optical disk storage, magnetic disk storage, or other magnetic storage devices, or any other physical and tangible storage medium that can be used to store the desired program code means in the form of computer-executable instructions or data structures and that can be accessed by a general-purpose or special-purpose computing system.
[0113] "Network" is defined as one or more data links that enable the conveyance of electronic data between computing systems and / or components and / or other electronic devices. When information is transmitted or provided to a computing system via a network or another communication connection (wired, wireless, or a combination of wired or wireless), the computing system appropriately views the connection as a transmission medium. The transmission medium can include a network and / or a data link that can be used to carry the desired program code in the form of computer-executable instructions or a data structure and that can be accessed by a general or special-purpose computing system. Combinations of the above should also be included within the scope of computer-readable media.
[0114] In addition, upon reaching various computing system components, program code means in the form of computer-executable instructions or a data structure can be automatically transferred from the transmission medium to a storage medium (and vice versa). For example, computer-executable instructions or a data structure received via a network or data link can be buffered in RAM within a network interface component (e.g., a "NIC") and then ultimately transferred to the computing system RAM and / or a less volatile storage medium at the computing system. Thus, it should be understood that a readable medium can be included in computing system components that also (or even primarily) utilize the transmission medium.
[0115] Computer-executable instructions include, for example, instructions and data that, when executed on a processor, cause a general-purpose computing system, a special-purpose computing system, or a special-purpose processing device to perform a certain function or group of functions. Alternatively or additionally, computer-executable instructions can configure a computing system to perform a certain function or group of functions. Computer-executable instructions can be, for example, binary, or instructions that have been translated in some way (such as compiled) before being directly executed by a processor, such as intermediate format instructions (such as assembly language), or even source code.
[0116] Those skilled in the art will understand that the present invention can be practiced in a network computing environment having many types of computing system configurations, including personal computers, desktop computers, laptop computers, messaging processors, handheld devices, multiprocessor systems, microprocessor-based or programmable consumer electronics, network PCs, minicomputers, mainframe computers, mobile phones, PDAs, pagers, routers, switches, data centers, wearable devices (such as glasses or watches), etc. The present invention can also be practiced in a distributed system environment in which both local and remote computing systems linked via a network (either via a wired data link, a wireless data link, or a combination of wired and wireless data links) perform tasks. In a distributed system environment, program components can be located in both local and remote memory storage devices.
[0117] Those skilled in the art will also understand that the present invention can be practiced in a cloud computing environment supported by one or more data centers or portions thereof. The cloud computing environment can be distributed, although this is not required. When it is distributed, the cloud computing environment can be distributed internationally within an organization and / or have components that are owned across multiple organizations.
[0118] In this specification and the appended claims, "cloud computing" is defined as a model for enabling on-demand network access to a shared pool of configurable computing resources (e.g., networks, servers, storage devices, applications, and services). The definition of "cloud computing" is not limited to any of the many other advantages that can be obtained from such a model when appropriately deployed.
[0119] For example, cloud computing is currently being adopted in the market to provide ubiquitous and convenient on-demand access to a shared pool of configurable computing resources. In addition, the shared pool of configurable computing resources can be rapidly provisioned via virtualization, issued with low administrative effort or service provider interaction, and then scaled accordingly.
[0120] The cloud computing model can consist of various characteristics, such as on-demand, self-service, broad network access, resource pooling, rapid elasticity, measured service, etc. The cloud computing model can also take the form of various application service models, e.g., Software as a Service ("SaaS"), Platform as a Service ("PaaS"), and Infrastructure as a Service ("IaaS"). Different deployment models such as private cloud, community cloud, public cloud, hybrid cloud, etc. can also be used to deploy the cloud computing model. In this specification and the claims, a "cloud computing environment" is an environment in which cloud computing is adopted.
[0121] Without departing from the spirit or essential characteristics of the present invention, the present invention can be embodied in other specific forms. The described embodiments should be considered illustrative in all respects and not restrictive. Therefore, the scope of the present invention is indicated by the appended claims rather than the foregoing description. All changes that fall within the meaning and scope of the equivalents of the claims shall be included within its scope.
Claims
1. A computing system, comprising: one or more processors; and one or more computer-readable storage media having computer-executable instructions thereon, the computer-executable instructions being configured such that when executed by the one or more processors, the computing system is configured to register a user for enabling revocable biometric authentication of the user by: obtaining a biometric imprint of the user, the biometric imprint being a computer-readable representation of the user's biometrics; obtaining user-specific data, the user-specific data being user-specific data identified by an authentication system as associated with the user or corresponding to user-specific data identified by the authentication system as associated with the user, and the user-specific data being appended to the biometric imprint; generating a processed imprint by performing a one-way processing of the biometric imprint using the obtained user-specific data, the one-way processing including chained hashing; and providing the processed imprint, rather than the biometric imprint, to the authentication system for later authentication of the user, the authentication of the user using the processed imprint and the user-specific data identified by the authentication system as associated with the user, invalidating the user-specific data at the authentication system causing the authentication system to no longer be able to authenticate the user based on the processed imprint, and authenticating the user using the processed imprint causing the authentication system to roll back the chain of the chained hashing; wherein when the chain cannot be further rolled back, each imprint seed is utilized for authentication; wherein the user-specific data is a hash salt of the user, and the one-way processing includes hashing the biometric imprint together with the user's hash salt to result in the processed imprint; wherein there are multiple hash salts for a user, the multiple hash salts being the basis for templates of different imprints of the user; and wherein the template is also based on each imprint seed of the user.
2. The computing system according to claim 1, wherein the obtained user-specific data is a private key in a public key / private key pair associated with the user, the user-specific data identified by the authentication system as associated with the user is the public key in the public key / private key pair, and the one-way processing includes digitally signing the biometric imprint using the private key to result in the processed imprint.
3. The computing system according to claim 1, wherein the obtained user-specific data is a private key in a public key / private key pair associated with the user, the user-specific data identified by the authentication system as associated with the user is the public key in the public key / private key pair, and the one-way processing includes performing chained hashing on the biometric imprint and digitally signing the chained-hashed biometric imprint using the private key to result in the processed imprint.
4. The computing system according to claim 1, wherein the biometric imprint is a specific biometric imprint, the processed imprint is a specific processed imprint, and the method further comprises: Obtain a plurality of other biometric imprints of the user; For each of the plurality of other biometric imprints of the user, perform the following operations: Obtain corresponding user-specific data, where the corresponding user-specific data is user-specific data identified by the authentication system as being associated with the user, or corresponding to user-specific data identified by the authentication system as being associated with the user, and the corresponding user-specific data is attached to the corresponding biometric imprint; Generate a corresponding processed imprint by performing a corresponding one-way process on the corresponding biometric imprint using the obtained corresponding user-specific data; And Cause the corresponding processed imprint, rather than the corresponding biometric imprint, to be provided to the authentication system for later authentication of the user, where the authentication of the user uses the corresponding processed imprint and the corresponding user-specific data identified by the authentication system as being associated with the user, and where invalidating the corresponding user-specific data at the authentication system causes the authentication system to no longer be able to authenticate the user based on the corresponding processed imprint.
5. The computing system according to claim 4, wherein the obtained user-specific data is the same for the specific biometric imprint and each of the plurality of other biometric imprints.
6. The computing system according to claim 4, wherein the obtained user-specific data for the specific biometric imprint is different from the obtained user-specific data for at least some of the plurality of other biometric imprints.
7. The computing system according to claim 6, wherein the obtained user-specific data is a hash salt, and the hash salt for the specific biometric imprint is different from the hash salts for at least some of the plurality of other biometric imprints.
8. The computing system according to claim 4, wherein the one-way process algorithm for the specific biometric imprint is different from the one-way process algorithms for at least some of the plurality of other biometric imprints.
9. The computing system according to claim 8, wherein the one-way process algorithm is a chained hash, and the number of links of the chained hash for the specific biometric imprint is different from the number of links of the chained hash for at least some of the plurality of other biometric imprints.
10. A method for registering a user to enable revocable biometric authentication of the user, the method comprising: Obtain a biometric imprint of the user, where the biometric imprint is a computer-readable representation of the user's biometrics; Obtain user-specific data, where the user-specific data is user-specific data identified by the authentication system as being associated with the user, or corresponding to user-specific data identified by the authentication system as being associated with the user, and the user-specific data is attached to the biometric imprint; Generating a processed imprint by performing a one-way processing of the biometric imprint using the obtained user-specific data, the one-way processing including a chained hash; and Providing the processed imprint, rather than the biometric imprint, to the authentication system for later authentication of the user, the authentication of the user using the processed imprint and the user-specific data identified by the authentication system as being associated with the user, wherein invalidating the user-specific data at the authentication system causes the authentication system to no longer be able to authenticate the user based on the processed imprint, and authenticating the user using the processed imprint causes the authentication system to roll back the chain of the chained hash; Wherein when the chain cannot be further rolled back, each imprint seed is utilized for authentication; Wherein the user-specific data is the user's hash salt, and the one-way processing includes hashing the biometric imprint together with the user's hash salt to result in the processed imprint; Wherein there are multiple hash salts for a user, and the multiple hash salts are the basis for templates of different imprints of the user; and Wherein the template is further based on each imprint seed of the user.
11. The method according to claim 10, the method is further used to identify the user to the authentication system after registering the user, the user being a specific user, the method further comprising: Obtaining a more recent biometric imprint of the specific user that was more recently received relative to the biometric imprint, the more recent biometric imprint being a computer-readable representation of a more recent biometric of the user; For each user of a plurality of users including the specific user, performing the following operations: Obtaining corresponding user-specific data, the corresponding user-specific data being the corresponding user-specific data identified by the authentication system as being associated with the corresponding user, or corresponding to the corresponding user-specific data identified by the authentication system as being associated with the corresponding user; and Generating a corresponding processed imprint by performing a corresponding one-way processing of the more recent biometric imprint using the obtained corresponding user-specific data; and Providing the processed imprint for each user of the plurality of users to the authentication system for authentication of the specific user.
12. The method according to claim 11, further comprising: Issuing an instruction to the authentication system for revoking the registration, whereby the authentication system invalidates the user-specific data so that any processed imprint based on the user-specific data is no longer available for identifying the user.
13. The method according to claim 11, for each user of the plurality of users, the corresponding one-way processing includes performing a chained hash of the biometric imprint together with the user's hash salt to result in the processed imprint, the chained hash being performed the number of times instructed by the authentication system, the number being specific to the user, and the number being decremented each time the corresponding user successfully authenticates to the authentication system.
14. A method for identifying a specific user using matching biometrics, the method comprises: accessing a current processed imprint generated by performing a one-way processing on a biometric imprint of a user using user-specific data, the biometric imprint being a computer-readable representation of the user's biometrics; for each user among a plurality of users including the specific user, accessing a set of registered processed imprints of the corresponding user, the processed imprints being formed by a chain hash of at least one biometric imprint of the specific user; determining whether the current processed imprint matches any of the registered processed imprints in the set of registered processed imprints of the corresponding user; and if there is a match, identifying the specific user as the corresponding user; and rolling back the chain of the chain hash of the at least one biometric imprint of the specific user; wherein when the chain cannot be further rolled back, each imprint seed is used for authentication; wherein the user-specific data is the user's hash salt, and the one-way processing includes hashing the biometric imprint together with the user's hash salt to result in the processed imprint; wherein there are multiple hash salts for a user, the multiple hash salts being the basis for templates of different imprints of the user; and wherein the template is also based on each imprint seed of the user.
15. The method according to claim 14, the access to the current processed imprint is performed as part of accessing a plurality of current processed imprints, each of the plurality of current processed imprints being generated by performing a different one-way processing on the biometric imprint of the user using user-specific data, the biometric imprint being a computer-readable representation of the user's biometrics; wherein determining whether there is a match is performed as part of determining whether any of the plurality of current processed imprints matches any of the registered processed imprints in the set of registered processed imprints of the corresponding user.
16. The method according to claim 15, wherein the different one-way processings of the biometric imprint all involve a chain hash of at least one biometric imprint, but at least some of the one-way processings differ in the number of links from the chain hash.
17. The method according to claim 16, wherein the authentication system keeps track of the number of links to be performed in the one-way processing on a per-user basis, and when a user is successfully authenticated, the number of links of the user is decremented.
18. The method according to claim 16, wherein the authentication system keeps track of the number of links to be performed in the one-way processing on a per-user-processed-imprint basis, and when the imprint is used to authenticate a user, the number of links of the user's processed imprint is decremented.
Citation Information
Patent Citations
Biometric data hashing, verification and security
US20170085562A1