Authentication device, authentication method, program, and information processing device
By comparing the authentication information converted from biological information in user authentication, the problem of leakage risk during biological information storage is solved, and user authentication without storing biological information is realized, which reduces risks and costs.
Patent Information
- Application Number
- CN202080062522.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-09-12
- Filing Date
- 2020-08-28
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2040-08-28
AI Technical Summary
In the case where biological information is stored in a server or the like, there is a risk of leakage of biological information as user personal information, and security measures need to be taken to prevent leakage.
User authentication is performed by using bioinformatics without storing bioinformatics. The specific implementation method is to perform user authentication by comparing the answer information with the correct answer information. The answer information is generated by using the biological information conversion authentication information for authentication, and the authentication information is generated by using the biological information conversion basic information for generation.
It realizes the use of biological information for user authentication without storing biological information, reducing the risk of biological information leakage, while avoiding the cost of managing and preserving biological information.
Smart Images

Figure CN114641966B_ABST
Abstract
Description
Technical Field
[0001] The present technology relates to an authentication device, an authentication method, a program, and an information processing device, and more particularly, to an authentication device, an authentication method, a program, and an information processing device that can perform user authentication using biometric information without storing the biometric information. Background Art
[0002] In recent years, biometric authentication has attracted attention as a technology for performing user authentication with high convenience and anti-counterfeiting properties. Biometric authentication is a technology for performing user authentication using biometric information of a person such as a fingerprint or an iris.
[0003] For example, Patent Document 1 describes a technology for incorporating biometric information into a secret key and a public key and performing a signature. The technology described in Patent Document 1 distributes a public key generated based on a feature amount of biometric information and verifies the signature.
[0004] On the other hand, typically, in the case of performing user authentication using biometric information without using a secret key and a public key, user authentication is performed by comparing biometric information stored in a server or the like with biometric information read from a user.
[0005] Citation List
[0006] Patent Document
[0007] Patent Document 1: Japanese Patent Application Laid-Open No. 2013-123142 Summary of the Invention
[0008] Problems to be Solved by the Invention
[0009] However, in the case where biometric information is stored in a server or the like, there is a risk of leakage of biometric information as personal information of a user, and security measures need to be taken to prevent the leakage.
[0010] In view of this situation, the present technology is configured, and the present technology can perform user authentication using biometric information without storing the biometric information.
[0011] Solutions to the Problems
[0012] The authentication device according to the first aspect of the present technology includes: an authentication unit configured to perform user authentication by comparing answer information with correct answer information, the answer information being generated by converting authentication information using biometric information for authentication, and the authentication information being generated by converting basic information using biometric information for generation.
[0013] The information processing apparatus according to the second aspect of the present technology includes: a reading unit that reads biological information for generation; and a conversion unit that converts basic information into authentication information using the biological information for generation.
[0014] In the first aspect of the present technology, user authentication is performed by comparing answer information with correct answer information, the answer information being generated by converting authentication information using biological information for authentication, and the authentication information being generated by converting basic information using biological information for generation.
[0015] In the second aspect of the present technology, biological information for generation is read, and basic information is converted into authentication information using the biological information for generation. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 is a diagram showing an exemplary configuration of an authentication system;
[0017] Figure 2 is a diagram showing a processing flow at the time of purchase and when using a ticket;
[0018] Figure 3 is a diagram showing an example of biological information used in the authentication system;
[0019] Figure 4 is a diagram showing an exemplary configuration of an authentication information issuing device;
[0020] Figure 5 is a diagram showing an example of a conversion rule;
[0021] Figure 6 is a diagram showing an example of template conversion;
[0022] Figure 7 is a diagram showing an exemplary configuration of an authentication device;
[0023] Figure 8 is a diagram showing an example of an answer template at the time of authentication;
[0024] Figure 9 is a flowchart for explaining the authentication template issuing process;
[0025] Figure 10 is a flowchart for explaining the authentication process;
[0026] Figure 11 is a diagram showing an example of a slipper on which an authentication template is printed;
[0027] Figure 12 is a diagram showing a state where the slippers are scattered;
[0028] Figure 13 It is a diagram showing an example of a presentation method;
[0029] Figure 14 It is a diagram showing the processing flow of the authentication system when purchasing an electronic ticket;
[0030] Figure 15 It is a diagram showing the processing flow of the authentication system when using an electronic ticket;
[0031] Figure 16 It is a block diagram showing an exemplary configuration of a server and a mobile terminal when purchasing an electronic ticket;
[0032] Figure 17 It is a block diagram showing an exemplary configuration of a server and a mobile terminal when using an electronic ticket;
[0033] Figure 18 It is a diagram showing an example of a basic template conversion method using biometric information of multiple users;
[0034] Figure 19 It is a diagram showing an example of a method for conversion and a method for verifying an authentication template converted using biometric information of multiple users;
[0035] Figure 20 It is a block diagram showing an exemplary configuration of computer hardware. Detailed Implementation Modes
[0036] Hereinafter, modes for implementing the present technology will be described. The description will be made in the following order.
[0037] 1. Overview of the Authentication System
[0038] 2. Exemplary Configuration of Each Device
[0039] 3. Operations of Each Device
[0040] 4. Second Embodiment
[0041] 5. Third Embodiment
[0042] 6. Fourth Embodiment
[0043] 7. Modifications
[0044] 8. Exemplary Configuration of a Computer
[0045] <1. Overview of the Authentication System>
[0046] First, an overview of the authentication system to which the present technology is applied will be described.
[0047] The authentication system applying the present technology is used for events such as those held by gathering a large number of people in a stadium or a hall. In such an event, generally, a user purchases a ticket, presents the ticket, and then enters the event venue.
[0048] When a user enters the event venue, there is a situation where user authentication is performed to confirm that the purchaser of the ticket is the same as the visitor presenting the ticket and about to enter the event venue. The authentication system applying the present technology is used to perform user authentication to confirm whether the purchaser of the ticket is the same as the visitor using biometric information.
[0049] Figure 1 is a diagram showing an exemplary configuration of the authentication system.
[0050] Figure 1 The authentication system 1 in includes an authentication information issuing device 11 and an authentication device 12. The authentication information issuing device 11 and the authentication device 12 are connected to each other via a network such as the Internet or a local area network (LAN).
[0051] The authentication information issuing device 11 is an information processing device that issues tickets. A user can purchase a ticket by operating the authentication information issuing device 11. The authentication information issuing device 11 is installed in a store such as a convenience store.
[0052] On the other hand, the authentication device 12 is a device that performs user authentication to confirm that the purchaser of the ticket is the same as the visitor. The authentication device 12 is installed at the entrance of the event venue or the like.
[0053] In the authentication information issuing device 11 and the authentication device 12, a sensor for reading the user's biometric information is provided. User authentication is performed using the biometric information read by the sensor.
[0054] Figure 2 is a diagram showing the processing flow when purchasing and using a ticket.
[0055] Figure 2 The processing shown on the left represents the processing when purchasing a ticket, and the processing shown on the right represents the processing when using a ticket. The processing shown on the left is the processing performed by the authentication information issuing device 11, and the processing shown on the right is the processing performed by the authentication device 12.
[0056] The service provider side of the management activity needs to prepare in advance a basic template as a type of basic information and a correct answer template as a type of correct answer information. The basic information is the information used to generate authentication information for user authentication. The basic template uses images to represent the basic information and is used to generate an authentication template, which is a type of authentication information when purchasing a ticket. The correct answer information is the information paired with the basic information and is used to verify the validity of the authentication information. The correct answer template uses images to represent the correct answer information and is used to verify the validity of the authentication template when using the ticket. The authentication information is the information generated from the basic information using the user's biometric information, provided to the user, and used for user authentication. The authentication template uses images to represent the authentication information, is generated from the basic template using the user's biometric information, provided to the user by printing on the ticket, etc., and is used for user authentication.
[0057] The basic template is prepared in advance in the authentication information issuing device 11. In addition, the correct answer template is prepared in advance in the authentication device 12. The basic template and the correct answer template can be the same information or different information. Hereinafter, the case where the basic template and the correct answer template are the same information will be mainly described.
[0058] As Figure 2 shown on the left side of , the user makes the authentication information issuing device 11 read the fingerprint as biometric information when purchasing a ticket. Figure 2 The spiral shown represents the user's fingerprint. Operations such as selecting an activity or paying a fee are performed when purchasing a ticket.
[0059] The authentication information issuing device 11 extracts the feature amount of the read fingerprint and converts the basic template based on the extracted feature amount in order to issue the authentication template. Since the authentication template is the information generated based on the feature amount of the fingerprint, the authentication template is different information for each purchaser (user).
[0060] For example, as the authentication template, different two-dimensional codes are issued for each purchaser. In Figure 2 the example of , different two-dimensional codes are issued for each user A and B who are ticket purchasers.
[0061] The authentication information issuing device 11 provides the authentication template to the user by printing the authentication template on a paper ticket, etc. The user receives the ticket printed with the authentication template and carries the ticket when using the ticket.
[0062] As Figure 2 shown on the right side of , when using the ticket, the user makes the authentication device 12 read the authentication template and the fingerprint printed on the ticket.
[0063] The authentication device 12 extracts the feature amount of the read fingerprint and converts the authentication template based on this feature amount in order to restore the correct answer template. The correct answer template is restored by an inverse conversion corresponding to the conversion at the time of releasing the authentication template.
[0064] When the fingerprint read by the authentication device 12 is the same as the fingerprint used when purchasing the ticket, this indicates that the correct answer template has been restored from the authentication template. When the correct answer template is restored, the authentication device 12 presents information indicating that the purchaser of the ticket matches the visitor.
[0065] Users who have received such a display are allowed to enter the event venue as users who have been successfully authenticated.
[0066] On the other hand, when the fingerprint read by the authentication device 12 is different from the fingerprint used when purchasing the ticket, this indicates that it is impossible to restore the correct answer template from the authentication template. When it is impossible to restore the correct answer template, the authentication device 12 presents information indicating that the purchaser of the ticket does not match the visitor.
[0067] Users who have received such a presentation are prohibited from entering the event venue as users who have failed user authentication.
[0068] In Figure 2 In the example in, when the fingerprint of user A is read in the user authentication based on the QR code issued by using the fingerprint of user A, the correct answer template is correctly restored. In addition, when the fingerprint of user B is read in the user authentication based on the QR code issued by using the fingerprint of user B, the correct answer template is correctly restored. Therefore, the user authentication is successful.
[0069] On the other hand, when the fingerprint of user C is read in the user authentication based on the QR code issued by using the fingerprint of user B, the correct answer template is not correctly restored. Therefore, the user authentication of user C fails.
[0070] As described above, in the authentication system 1, the biometric information used for user authentication is not saved and is only used when converting the correct answer template or the authentication template. Therefore, biometric information can be used to authenticate users without the risk of biometric information leakage.
[0071] In addition, the service provider side can perform user authentication using biometric information without the cost of managing, saving, and discarding biometric information.
[0072] In addition, because each biological entity uses unique information, users can enjoy a security strength similar to that of a physical key without the trouble of carrying the key and any risk of losing the key.
[0073] Note that not only fingerprints, but also various types of biometric information can be used for the above user authentication.
[0074] Figure 3 is a diagram showing an example of biometric information used in the authentication system 1.
[0075] As Figure 3 shown, in addition to fingerprints, biometric information such as palm prints, finger veins, faces, irises, voices, or otoacoustic emissions can also be used.
[0076] These biometric information can be used alone or in various ways to improve accuracy. The type of biometric information can be changed according to the usage.
[0077] In addition, the authentication information issuing device 11 and the authentication device 12 have a function for checking whether the read biometric information has sufficient quality, so that feature amounts can be extracted.
[0078] <2. Exemplary Configuration of Each Device>
[0079] Configuration of the Authentication Information Issuing Device 11
[0080] Figure 4 is a diagram showing an exemplary configuration of the authentication information issuing device 11. Figure 4 At least some of the function units shown are implemented by a central processing unit (CPU) of a computer included in the authentication information issuing device 11 executing a predetermined program.
[0081] As Figure 4 shown, the authentication information issuing device 11 includes a biometric information reading unit 51, a biometric information feature amount extraction unit 52, a template conversion unit 53, a conversion rule storage unit 54, a basic template storage unit 55, and an authentication template output unit 56.
[0082] The biometric information reading unit 51 includes sensors for reading the above various types of biometric information. The biometric information reading unit 51 reads the biometric information of the user and checks the quality.
[0083] In the case where the quality of the biometric information is insufficient, the biometric information reading unit 51 reads the biometric information again. On the other hand, in the case where the quality of the biometric information is sufficient, the biometric information reading unit 51 outputs the read biometric information to the biometric information feature amount extraction unit 52 as the biometric information for generation.
[0084] The biometric information feature amount extraction unit 52 extracts feature amounts from the biometric information for generation provided by the biometric information reading unit 51.
[0085] As a feature quantity of biological information, it is necessary to be sufficient to convert the feature quantity of the basic template by the template conversion unit 53 in a subsequent stage. For example, necessary feature quantities are set according to the basic template. Then, in the case of extracting the set feature quantities, it is determined that sufficient feature quantities have been extracted.
[0086] Note that in the case where it is impossible to extract sufficient feature quantities from a single piece of biological information, feature quantities can be extracted from multiple pieces of biological information.
[0087] In the case where sufficient feature quantities can be extracted, the biological information feature quantity extraction unit 52 outputs the feature quantities extracted from the biological information to the template conversion unit 53.
[0088] The template conversion unit 53 converts the basic template into an authentication template using the feature quantities provided by the biological information feature quantity extraction unit 52. The basic template is stored in advance in the basic template storage unit 55 and is acquired by the template conversion unit 53.
[0089] The method for converting the basic template is stored in advance in the conversion rule storage unit 54 as a conversion rule.
[0090] Figure 5 is a diagram showing an example of the conversion rule.
[0091] For example, the basic template is converted in units of regions obtained by dividing the entire basic template into multiple regions. Then, as Figure 5 shown, the type of feature quantity for the conversion of each region of the basic template and the method for converting each region are set as conversion rules.
[0092] In Figure 5 the example, as a first conversion rule, in order to convert the [x1, y1, x2, y2] region of the basic template, the width of the valley line of the fingerprint is set. Here, the [x1, y1, x2, y2] region is defined as a rectangular region whose coordinates [x1, y1] and [x2, y2] are set as diagonal vertices. For the conversion of the [x1, y1, x2, y2] region, a conversion method in the case where the width of the valley line is equal to or less than 0.1 mm, etc. is set.
[0093] Furthermore, as a second conversion rule, the number of valley line portions with a curvature of 90R is set for the conversion of the [x3, y3, x4, y4] region of the basic template. For the conversion of the [x3, y3, x4, y4] region, a conversion method in the case where the number of valley line portions with a curvature of 90R is equal to or less than five, etc. is set.
[0094] As described above, the template conversion unit 53 performs the conversion according to the conversion rules set by associating each region of the basic template with the type of feature quantity and the conversion method.
[0095] Figure 6 It is a diagram showing an example of template conversion.
[0096] As Figure 6 shown in the center of, as feature amounts that are fingerprints of biological information, for example, it is assumed that the width of valley lines, the interval between valley lines, the frequency of valley lines (main axis), the frequency of valley lines (second axis), the size of sweat glands, the density of sweat glands, a part of valley lines with a curvature of 180R, and a part of valley lines with a curvature of 90R can be extracted by the biological information feature amount extraction unit 52.
[0097] In this case, the template conversion unit 53 divides the basic template into a plurality of regions and performs conversion on each region according to the conversion rules Figure 5 described. In addition, conversion is performed by changing the region of the basic template as the target and the conversion method of each feature amount.
[0098] For example, a rectangular region ([x1, y1, x2, y2] region) in the basic template included in Figure 6 the circle C1 on the left is converted into a rectangular region included in the circle C1' in the authentication template based on the valley line width of the fingerprint feature amount.
[0099] In addition, a rectangular region ([x3, y3, x4, y4] region) in the basic template included in Figure 6 the dashed circle C2 on the left is converted into a rectangular region included in the circle C2' in the authentication template based on the part of valley lines with a curvature of 90R of the fingerprint feature amount.
[0100] In this way, after the image of the basic template is converted into binary data, for example, this data is converted into a QR code as the authentication template. For example, in order to convert the image of the basic template into binary data, base64 (Base64 encoding) is used. The authentication template generated by the template conversion unit 53 is output to Figure 4 the authentication template output unit 56 in.
[0101] The authentication template output unit 56 prints the authentication template provided from the template conversion unit 53 on a ticket and outputs the ticket. The authentication template can be output as an image file and sent to a mobile terminal, for example, a smart phone used by a user.
[0102] Note that even in the case where the authentication template is stolen, it is difficult to decrypt biological information from the authentication template. Therefore, for the user, the risk of biological information leakage is very small.
[0103] In addition, an authentication template can be printed on a bill using ink that can only be read at a specific wavelength invisible to the naked eye. For example, this enables handling of cases where it is preferable not to print the authentication template in a form visible to the naked eye due to reasons such as design.
[0104] Configuration of Authentication Device 12
[0105] Figure 7 is a diagram showing an exemplary configuration of the authentication device 12. Figure 7 At least some of the functional units shown in are implemented by a CPU of a computer included in the authentication device 12 executing a predetermined program.
[0106] As Figure 7 shown, the authentication device 12 includes a biometric information reading unit 61, a biometric information feature quantity extraction unit 62, an authentication template reading unit 63, a template conversion unit 64, a conversion rule storage unit 65, an authentication unit 66, a correct answer template storage unit 67, and an authentication result display unit 68.
[0107] The biometric information reading unit 61 includes sensors for reading various types of the above biometric information. The biometric information reading unit 61 reads the same type of biometric information as that read by the authentication information issuing device 11. The biometric information reading unit 61 reads the biometric information of a user and checks the quality.
[0108] In the case where the quality of the biometric information is insufficient, the biometric information reading unit 61 reads the biometric information again. On the other hand, in the case where the quality of the biometric information is sufficient, the biometric information reading unit 61 outputs the read biometric information as biometric information for authentication to the biometric information feature quantity extraction unit 62.
[0109] The biometric information feature quantity extraction unit 62 extracts a feature quantity from the biometric information for authentication provided by the biometric information reading unit 61 and outputs the feature quantity to the template conversion unit 64.
[0110] The authentication template reading unit 63 includes sensors for reading an authentication template. The authentication template reading unit 63 reads the authentication template and outputs the authentication template to the template conversion unit 64.
[0111] The template conversion unit 64 uses the feature quantity provided by the biological information feature quantity extraction unit 62 to convert the authentication template provided by the authentication template reading unit 63 into an answer template as a type of answer information, and outputs the converted answer template to the authentication unit 66. The answer information is information generated from the authentication information using the biological information of the user, and when verifying the authentication information, it is compared with the correct answer information. The answer template represents the answer information using an image, and when the authentication unit 66 in the subsequent stage verifies the authentication template, the answer template is compared with the correct answer template. According to the biological information read for authentication, the answer template generated by conversion can be information that is the same as or different from the correct answer template.
[0112] The method for converting the authentication template is pre-stored in the conversion rule storage unit 65 as a conversion rule. Similar to the conversion of the basic template, the authentication template is divided into multiple regions, and each region's feature quantity is used according to the conversion rule to convert the authentication template.
[0113] The authentication unit 66 performs user authentication by comparing the answer template provided by the template conversion unit 64 with the correct answer template obtained from the correct answer template storage unit 67. Specifically, the authentication unit 66 calculates the similarity between the answer template and the correct answer template, and performs user authentication based on the calculated similarity.
[0114] When the similarity between the answer template and the correct answer template exceeds a predetermined threshold, the authentication unit 66 determines that the user who has purchased the ticket matches the user who is the target of user authentication (the user who is about to enter the event venue) by reading the biological information for authentication, etc. On the other hand, when the similarity between the answer template and the correct answer template is equal to or less than the predetermined threshold, the authentication unit 66 determines that the user who has purchased the ticket does not match the user who is to be the target of user authentication by reading the biological information for authentication, etc.
[0115] Figure 8 is a diagram showing an example of the answer template at the time of authentication. As described above, the basic template and the correct answer template can be the same information or different information. Figure 8 A in shows an example of the case where the basic template and the correct answer template are the same information, Figure 8 B in shows an example of the case where the basic template and the correct answer template are different information.
[0116] In Figure 8 the example in A, as described above, the basic template 1, which is the same information as the correct answer template, is reversibly converted into an authentication template when issuing the ticket.
[0117] Regarding the above, at the time of authentication, the template conversion unit 64 performs an inverse conversion corresponding to the conversion from the basic template to the authentication template, so as to convert the authentication template into the answer template 1.
[0118] At this time, when the fingerprint used at the time of issuing the ticket is the same as the fingerprint used at the time of authentication, the answer template 1 generated by the inverse conversion is restored to the same information as the correct answer template 1. Then, the authentication unit 66 determines that the answer template 1 matches the correct answer template 1 obtained from the correct answer template storage unit 67.
[0119] On the other hand, in Figure 8 the example of B, at the time of issuing the ticket, the basic template 1 is irreversibly converted into the authentication template.
[0120] Regarding the above, at the time of authentication, the template conversion unit 64 further converts the authentication template into the answer template 2.
[0121] At this time, when the fingerprint used at the time of issuing the ticket is the same as the fingerprint used at the time of authentication, the answer template 2 generated by the conversion is converted into the same information as the correct answer template 2 different from the correct answer template 1. Then, the authentication unit 66 determines that the answer template 2 matches the correct answer template 2 obtained from the correct answer template storage unit 67.
[0122] Note that the correct answer template storage unit 67 pre-stores the information expected due to performing two conversions on the basic template 1 at the time of issuance and authentication, as the correct answer template 2.
[0123] The information indicating the user authentication result determined in this way is output from the authentication unit 66 to Figure 7 the authentication result display unit 68 in
[0124] The authentication result display unit 68 presents the result of the user authentication of the authentication unit 66, for example, by displaying the result on a display. Note that the result of the user authentication can be clearly presented to the user who reads their biometric information, or can be presented only to the service provider side that manages the activity, in order to respond according to the result of the user authentication.
[0125] <3. Operations of Each Device>
[0126] Here, the operations of each device having the above configuration will be described.
[0127] Operations of the Authentication Information Issuing Device 11
[0128] First, the authentication template issuance process of the authentication information issuing device 11 will be described with reference to the Figure 9 flowchart in
[0129] In step S1, the biological information reading unit 51 reads the biological information for generation.
[0130] In step S2, the biological information reading unit 51 determines whether the quality of the biological information is sufficient.
[0131] In the case where the quality of the biological information is determined to be insufficient in step S2, the process returns to step S1, and the reading of the biological information is repeated until biological information with sufficient quality is obtained. Note that in the case where the reading of the biological information fails a predetermined number of times, the process ends.
[0132] On the other hand, in the case where the quality of the biological information is determined to be sufficient in step S2, the process proceeds to step S3.
[0133] In step S3, the biological information feature quantity extraction unit 52 extracts the feature quantity from the biological information for generation.
[0134] In step S4, the biological information feature quantity extraction unit 52 determines whether the extracted feature quantity has sufficient information content.
[0135] In the case where the extracted feature quantity is determined not to have sufficient information content in step S4, the process returns to step S1, and the subsequent processing is executed.
[0136] On the other hand, in the case where the extracted feature quantity is determined to have sufficient information content in step S4, the process proceeds to step S5.
[0137] In step S5, the template conversion unit 53 uses the feature quantity of the biological information for generation and converts the basic template into an authentication template according to the conversion rule.
[0138] In step S6, the authentication template output unit 56 outputs the authentication template.
[0139] Operation of the authentication device 12
[0140] Next, the authentication process of the authentication device 12 will be described with reference to Figure 10 the flowchart in.
[0141] In step S11, the authentication template reading unit 63 reads the authentication template held by the user.
[0142] In step S12, the biological information reading unit 61 reads the biological information for authentication.
[0143] In step S13, the biological information reading unit 61 determines whether the quality of the biological information is sufficient.
[0144] When it is determined in step S13 that the quality of the biological information is insufficient, the process returns to step S12, and the reading of the biological information is repeated until biological information with sufficient quality is obtained. Note that when the reading of the biological information fails a predetermined number of times, the process ends.
[0145] On the other hand, when it is determined in step S13 that the quality of the biological information is sufficient, the process proceeds to step S14.
[0146] In step S14, the biometric information feature quantity extraction unit 62 extracts feature quantities from the biometric information for authentication.
[0147] In step S15, the biometric information feature quantity extraction unit 62 determines whether the extracted feature quantities have sufficient information content.
[0148] When it is determined in step S15 that the extracted feature quantities do not have sufficient information content, the process returns to step S12 and subsequent processing is performed.
[0149] On the other hand, when it is determined in step S15 that the extracted feature quantities have sufficient information content, the process proceeds to step S16.
[0150] In step S16, the template conversion unit 64 uses the feature quantities of the biometric information for authentication to convert the authentication template into an answer template according to the conversion rules.
[0151] In step S17, the authentication unit 66 performs user authentication by comparing the answer template with the correct answer template.
[0152] In step S18, the authentication result display unit 68 presents the result of user authentication.
[0153] As described above, the authentication system 1 can perform user authentication using biometric information without storing the biometric information. Since information unique to the biological subject is used, security strength similar to that of a physical key can be enjoyed without the trouble of carrying a key and any risk of losing the key.
[0154] Since the authentication system 1 has a mechanism for converting templates using biometric information, a system that can perform user authentication with a simple system configuration can be realized.
[0155] In addition, the authentication system 1 can operate the device independently when purchasing and when using tickets.
[0156] Note that, for example, the authentication system 1 is used as the time for issuing tickets for a concert or the like and the time for authentication. In this case, only users who have been successfully authenticated can enter the venue for the concert or the like, thereby preventing ticket resale.
[0157] For example, the authentication system 1 is used to issue tickets for entertainment parks such as amusement parks and manage repeat visitors using the tickets. In this case, only users who have been successfully authenticated can re-enter the entertainment park, so only the purchaser of the ticket can be allowed to re-enter the entertainment park.
[0158] For example, the authentication system 1 is used to place an order and receive the order at a food court or the like. In this case, it is easy to confirm that the person who placed the order and the person who received the meal are the same person.
[0159] <4. Second Embodiment>
[0160] The authentication system 1 can be used to manage rental items. For example, in the case where the lent slippers are scattered in an inn or the like, the user who has lost the lent slipper uses the authentication system 1 to find his / her own slipper.
[0161] Figure 11 is a diagram showing an example of a slipper on which an authentication template is printed.
[0162] As Figure 11 shown on the left side of, when lending out the slipper, the facial image of the user borrowing the slipper is read by the authentication information issuing device 11 as biometric information for generation. The authentication information issuing device 11 extracts feature amounts from the read facial image and converts the basic template into an authentication template using the feature amounts of the face.
[0163] Figure 11 The black dots on the facial image on the left side indicate the feature points of the face from which the authentication information issuing device 11 extracts feature amounts.
[0164] As Figure 11 shown on the right side of, the slipper H on which a two-dimensional code as the authentication template generated by the authentication information issuing device 11 is printed is lent to the user. Note that the two-dimensional code printed on the slipper H is printed with a transparent ink that can only be confirmed at a predetermined wavelength.
[0165] Figure 12 is a diagram showing the state where the slippers are scattered.
[0166] As Figure 12 shown on the right side of, it is assumed that the slippers H1 to H7 are scattered on the floor of the inn. In this case, the camera 81 provided on the ceiling reads the facial image of the user who is looking for the slipper, who has lent the slipper as biometric information for authentication, and reads the authentication templates respectively printed on the slippers H1 to H7.
[0167] The camera 81 serves as the biometric information reading unit 61 and the authentication template reading unit 63 of the authentication device 12. The template conversion unit 64 converts the two-dimensional codes respectively read from the slippers H1 to H7 into answer templates using the feature amounts of the face.
[0168] The authentication unit 66 designates a two-dimensional code converted from the biometric information read from a user (the user who is looking for the slippers lent by the user) who reads the biometric information for authentication, based on the similarity between each answer template and the correct answer template.
[0169] The authentication result display unit 68 presents that the slippers on which the two-dimensional code designated by the authentication unit 66 is printed are the slippers lent to the user.
[0170] Figure 13 is a diagram showing an example of the presentation method.
[0171] As Figure 13 shown, the projector 82 installed on the ceiling presents to the user that the slippers H2 are the slippers lent to the user, for example, by illuminating the periphery of the slippers H2 surrounded by the dotted circle. Here, the projector 82 serves as the authentication result display unit 68 of the authentication device 12.
[0172] As described above, the user can get help to find out what the user has borrowed.
[0173] In addition, the authentication system 1 can be applied to a system for managing whether rental items (such as slippers) are returned.
[0174] Note that above, the case of printing the authentication template with invisible transparent ink has been described. However, regardless of the design, a seal on which the authentication template is printed can be attached to slippers or the like.
[0175] In addition, not only the authentication template is printed, but also an IC chip storing data indicating the authentication template can be embedded in slippers or the like. In this case, the authentication device 12 reads the data stored in the IC chip as the authentication template.
[0176] For example, in the case where the biometric information of the user is stored in the IC chip, the authentication template is unnecessary. However, there is a risk of leakage of biometric information as personal information, and it is necessary to discard the biometric information reliably. In this case, the cost of processing biometric information is high.
[0177] On the other hand, by using the authentication template instead of the biometric information as the data stored in the IC chip, this cost can be reduced.
[0178] <5. Third Embodiment>
[0179] Some functions of the authentication information publishing device 11 and the functions of the authentication device 12 can be provided in the mobile terminal. By using a mobile terminal having such functions, tickets are purchased and used as described above.
[0180] Hereinafter, an example will be described in which a user purchases an electronic ticket using a mobile terminal and enters an event venue.
[0181] Figure 14 : is a diagram showing the processing flow of the authentication system when purchasing an electronic ticket.
[0182] Figure 14 The authentication system in the embodiment includes a server 101 and a mobile terminal 102. Figure 1 The function of the authentication information issuing device 11 in the example is shared by the server 101 and the mobile terminal 102 .
[0183] The server 101 is, for example, a server device installed in a secure area. A service provider who manages activities using an authentication system sets a basic template to the server 101 in advance.
[0184] The mobile terminal 102 includes a device such as a smartphone, a tablet terminal, or a personal computer, etc. For example, a user purchases an electronic ticket according to a guide or the like presented by an application installed in the mobile terminal 102 .
[0185] When purchasing a ticket, the mobile terminal 102 obtains a basic template from the server 101, such as Figure 14 Note that data is exchanged between the server 101 and the mobile terminal 102 using secure communication.
[0186] In the mobile terminal 102, a sensor for reading the user's biometric information is provided. When purchasing an electronic ticket, the mobile terminal 102 reads the user's fingerprint, for example, and converts the basic template acquired from the server 101 into an authentication template using the feature amount of the read fingerprint. The data of the generated authentication template is saved in the mobile terminal 102 as an electronic ticket.
[0187] Then, the user who has purchased the electronic ticket brings the mobile terminal 102 which saves the electronic ticket when using the electronic ticket.
[0188] Figure 15 is a diagram showing a processing flow of the authentication system when an electronic ticket is used.
[0189] and Figure 14 Same as the authentication system in Figure 15 The authentication system in the embodiment includes a server 101 and a mobile terminal 102. Figure 1 The function of the authentication device 12 in is shared by the server 101 and the mobile terminal 102.
[0190] When using an electronic ticket, the server 101 stores a correct answer template. The service provider sets the correct answer template in advance to the server 101. In addition, the server 101 uses the answer template received from the mobile terminal 102 to perform user authentication.
[0191] The mobile terminal 102 reads the fingerprint of the user, and converts the authentication template stored in the mobile terminal 102 into an answer template using the feature amount of the read fingerprint. As Figure 15 shown by the arrow #1 in, the mobile terminal 102 sends the data of the answer template to the server 101.
[0192] In addition, as Figure 15 shown by the arrow #2 in, the mobile terminal 102 receives the result of the user authentication performed by the server 101, and displays the result on the display provided in the mobile terminal 102. The user shows, for example, the user authentication result displayed on the mobile terminal 102 to the service provider in order to receive a response according to the user authentication result from the service provider.
[0193] Figure 16 is a block diagram showing an exemplary configuration of the server 101 and the mobile terminal 102 when purchasing an electronic ticket.
[0194] As Figure 16 shown, the server 101 includes a conversion rule storage unit 54, a basic template storage unit 55, and a communication unit 111.
[0195] Note that in Figure 16 , components that are the same as those of the authentication information publishing device 11 in Figure 4 are denoted by the same reference numerals. Overlapping descriptions will be appropriately omitted.
[0196] The communication unit 111 obtains information indicating the conversion rule and the basic template from the conversion rule storage unit 54 and the basic template storage unit 55 respectively, and sends the obtained information and template to the mobile terminal 102.
[0197] On the other hand, as Figure 16 shown, the mobile terminal 102 includes a biometric information reading unit 51, a biometric information feature amount extraction unit 52, a template conversion unit 53, an authentication template output unit 56, and a communication unit 121.
[0198] The communication unit 121 receives the information indicating the conversion rule and the basic template sent from the server 101, and outputs the received information to the template conversion unit 53.
[0199] In the template conversion unit 53, based on the conversion rule provided by the communication unit 121, the basic template provided by the communication unit 121 is converted based on the biometric information for generation provided by the biometric information feature amount extraction unit 52, and an authentication template is generated. The authentication template generated by the template conversion unit 53 is provided to the authentication template output unit 56.
[0200] Figure 17It is a block diagram showing an exemplary configuration of the server 101 and the mobile terminal 102 when using electronic bills.
[0201] As Figure 17 shown, the server 101 includes a conversion rule storage unit 65, an authentication unit 66, a correct answer template storage unit 67, and a communication unit 111.
[0202] Note that in Figure 17 the components that are the same as those of the authentication device 12 in Figure 7 are denoted by the same reference numerals. Overlapping descriptions will be appropriately omitted.
[0203] The communication unit 111 obtains information indicating the conversion rule from the conversion rule storage unit 65 and outputs the information to the mobile terminal 102. In addition, the communication unit 111 receives the answer template sent from the mobile terminal 102 and outputs the answer template to the authentication unit 66.
[0204] The authentication unit 66 performs user authentication by comparing the answer template obtained from the mobile terminal 102 with the correct answer template stored in the correct answer template storage unit 67. The authentication unit 66 outputs information indicating the user authentication result to the communication unit 111.
[0205] The communication unit 111 sends the information indicating the user authentication result provided by the authentication unit 66 to the mobile terminal 102.
[0206] On the other hand, as Figure 17 shown, the mobile terminal 102 includes a biometric information reading unit 61, a biometric information feature quantity extraction unit 62, a template conversion unit 64, an authentication result display unit 68, and a communication unit 121.
[0207] The communication unit 121 receives the information indicating the conversion rule sent from the server 101 and outputs the information to the template conversion unit 64.
[0208] In the template conversion unit 64, according to the conversion rule provided by the communication unit 121, based on the feature quantity of the biometric information for authentication provided by the biometric information feature quantity extraction unit 52, the authentication template stored in the mobile terminal 102 is converted to generate an answer template. The answer template generated by the template conversion unit 53 is provided to the communication unit 121.
[0209] The communication unit 121 sends the answer template provided by the template conversion unit 64 to the server 101.
[0210] On the other hand, the communication unit 121 receives the information indicating the user authentication result sent from the server 101 and outputs the information to the authentication result display unit 68.
[0211] As described above, the biometric information of the mobile terminal 102 can be used to authenticate the user. In this case, the service provider can use the biometric information to perform user authentication without managing the biometric information of the user on the service provider side.
[0212] In addition, the user can be authenticated without causing the risk of leakage of the user's biometric information. In addition, the user can easily and securely use services such as purchasing electronic tickets using the mobile terminal 102.
[0213] Note that the server 101 can be installed in a locker (so-called luggage locker) in a station or a drop box. In this case, the user locks or unlocks the locker in the station or the drop box by having the mobile terminal 102 read the biometric information.
[0214] In a station or the like, there are lockers that can be locked with a transportation IC card. In the case where the user loses the IC card after locking the locker and another person picks up the IC card, the other person can unlock the locker locked by the valid user.
[0215] On the other hand, when unlocking the locker in the station using the mobile terminal 102, the biometric information of the person who has locked the locker is required when opening the locker. Therefore, a more secure service can be provided.
[0216] <6. Fourth Embodiment>
[0217] When purchasing a ticket, the biometric information of multiple users can be used to convert the basic template. Then, when using the ticket, one or more users among the multiple users having the biometric information for converting the basic template can be authenticated using the biometric information.
[0218] Figure 18 is a diagram showing an example of a basic template conversion method using the biometric information of multiple users.
[0219] As Figure 18 shown on the upper side of, for example, data combining basic templates 1 to 4 is preset to the authentication information issuing device 11 as the basic template.
[0220] When purchasing a ticket, the authentication information issuing device 11 reads the biometric information of multiple users as the biometric information for generation. A feature amount is extracted from the biometric information for generation, and the basic template is converted into an authentication template using the feature amount extracted from the biometric information for generation.
[0221] In Figure 18 , the authentication information issuing device 11 reads the biometric information of users A to D and converts the basic template into a two-dimensional code, which is the authentication template, using the feature amounts of the biometric information of all users.
[0222] Here, it is assumed that the group of ticket purchasers includes users A to D. Regardless of the number of users included in the purchaser group, an authentication template is issued.
[0223] The authentication template issued by the authentication information issuing device 11 is printed on a paper ticket or the like, and then is possessed by each user who reads the biometric information used for generation.
[0224] Figure 19 It is a diagram showing an example of a method for conversion and a method for verifying an authentication template that converts using biometric information of multiple users.
[0225] As Figure 19 shown on the lower side, the user brings the ticket printed with the authentication template possessed by each person in the purchaser group to the event venue.
[0226] When using the ticket, the authentication device 12 reads the authentication template printed on the ticket and reads one or more users' biometric information as the biometric information for authentication. A feature amount is extracted from the biometric information for authentication, and the authentication template is converted into an answer template using the feature amount extracted from the biometric information for authentication.
[0227] In Figure 19 the example on the left, as indicated by arrow #11, the biometric information of user B is read by the authentication device 12, and an answer template that correctly restores only answer template 2 out of correct answer templates 1 to 4 is generated.
[0228] Furthermore, in Figure 19 the example on the right, as indicated by arrow #12, the biometric information of users C and D is read by the authentication device 12, and an answer template that correctly restores only answer templates 3 and 4 out of correct answer templates 1 to 4 is generated.
[0229] In the authentication device 12, a correct answer template combining correct answer templates 1 to 4 is preset. The authentication device 12 compares the answer template with the correct answer template and determines whether the user who reads the biometric information for authentication at the time of issuing the authentication template is included in the purchaser group who reads the biometric information for generation, so as to perform user authentication.
[0230] Here, when a part of the answer template matches the correct answer template, the authentication device 12 presents information indicating that the user who reads the biometric information for authentication is a user included in the purchaser group.
[0231] The user who has received such a display is allowed to enter the event venue as a user who has been successfully authenticated.
[0232] In Figure 19In the example on the left, in user authentication based on an authentication template issued using the biometric information of a purchaser group, the biometric information of user B is read, and the correct answer template 2 is correctly restored. Therefore, it is determined that user B is included in the purchaser group, and user B is successfully authenticated.
[0233] In addition, in Figure 19 In the example on the right, in user authentication based on an authentication template issued using the biometric information of a purchaser group, the biometric information of users C and D is read, and the correct answer templates 3 and 4 are correctly restored. Therefore, it is determined that users C and D are included in the purchaser group, and users C and D are successfully authenticated.
[0234] Note that, for example, the scope of services provided in an event venue can be changed according to the similarity (matching rate) between the answer template converted using the biometric information of multiple or all users using a usage ticket and the correct answer template.
[0235] As described above, the authentication system 1 can perform user authentication based on an authentication template issued using the biometric information of multiple persons.
[0236] Note that this authentication method can be used to lock or unlock lockers in a station or a drop box. For example, when locking a locker in a station or a drop box, an authentication template converted using the biometric information read from multiple persons such as parents and children is issued. Then, a person who has locked the locker in the station or the drop box unlocks the locker in the station or the drop box using the authentication template.
[0237] In this way, the lockers in the drop box station can be used by a group including multiple persons.
[0238] In addition, this authentication method can be used to lock and unlock the door of a house. For example, when locking the door of a house, a key terminal that is the key to the door of the house holds an authentication template issued using the biometric information of all users included in the household. The user takes the key terminal out when going out.
[0239] When returning home, the user can activate a sensor set near the entrance of the house to read the biometric information and the authentication template held by the key terminal, and can open the door of the house. In the case where the key terminal is lost, even if another person who has found the key terminal makes the sensor read the biometric information of another person and the authentication template held by the key terminal, the answer template does not match the correct answer template. Therefore, the door of the house is not unlocked.
[0240] In addition, since it is difficult to decrypt the biometric information used to convert the basic template from the authentication template of the key terminal, the biometric information and the correct answer template used to unlock the door of the house are not leaked.
[0241] <7. Modification>
[0242] For example, visual information other than the above-mentioned images and two-dimensional codes can be used for basic information, authentication information, answer information, and correct answer information. As such visual information, for example, signals represented by a blinking pattern of light, color, etc., text information, etc. are assumed.
[0243] In addition, for example, auditory information and tactile information other than visual information can be used for basic information, authentication information, answer information, and correct answer information. As auditory information, for example, sound is assumed. As tactile information, for example, signals represented by patterns such as vibration, movement, heat, etc. are assumed. In this case, for example, waveforms representing patterns of auditory information and tactile information are converted according to the biological information of the user.
[0244] <8. Exemplary Configuration of a Computer>
[0245] The above-described series of processes can be executed by hardware or software. In the case where the series of processes are executed by software, a program included in the software is installed from a program recording medium into a computer included in dedicated hardware or, for example, a general-purpose personal computer.
[0246] Figure 20 FIG. is a block diagram showing an exemplary configuration of computer hardware for executing the above-described series of processes by a program.
[0247] A central processing unit (CPU) 1001, a read-only memory (ROM) 1002, and a random access memory (RAM) 1003 are interconnected via a bus 1004.
[0248] In addition, an input / output interface 1005 is connected to the bus 1004. The input / output interface 1005 is connected to an input unit 1006 including a keyboard, a mouse, etc. and an output unit 1007 including a display, a speaker, etc. In addition, the input / output interface 1005 is connected to a storage unit 1008 including a hard disk, a non-volatile memory, etc., a communication unit 1009 including a network interface, etc., and a drive 1010 for driving a removable medium 1011.
[0249] In the computer configured as described above, the CPU 1001 loads a program stored in the storage unit 1008, for example, into the RAM 1003 via the input / output interface 1005 and the bus 1004, and executes the program, thereby executing the above-described series of processes.
[0250] The program executed by the CPU 1001 is provided and installed in the storage unit 1008, for example, by recording the program in the removable medium 1011 or via a wired or wireless transmission medium such as a local area network, the Internet, or digital broadcasting.
[0251] Note that a program executed by a computer can be a program that performs processing in the order described herein in a time series manner, or a program that performs processing in parallel or at a necessary time, for example, when a call has been made.
[0252] Note that a system herein means a component of multiple components (devices, modules (parts), etc.), and it does not matter whether all components are in the same housing. Thus, multiple devices separately housed in different housings and connected via a network and a single device having multiple modules housed in one housing are both systems.
[0253] Note that the effects described herein are merely exemplary and are not limited thereto. In addition, there may be additional effects.
[0254] Embodiments of the present technology are not limited to the above embodiments, and various changes can be made without departing from the scope of the present technology.
[0255] For example, the present technology can have a cloud computing configuration, in which a single function is separately executed in cooperation by multiple devices via a network.
[0256] In addition, each step described with reference to the above flowchart can be executed by a single device, or can be divided and executed by multiple devices.
[0257] In addition, in the case where a step includes multiple processes, the multiple processes included in one step can be executed by a single device, or can be divided and executed by multiple devices.
[0258] <Example of configuration combination>
[0259] The present technology can have the following configuration.
[0260] (1) An authentication device, comprising:
[0261] An authentication unit configured to perform user authentication by comparing answer information with correct answer information, the answer information being generated by converting authentication information using biometric information for authentication, and the authentication information being generated by converting basic information using biometric information for generation.
[0262] (2) The authentication device according to (1), wherein
[0263] The authentication unit determines whether the user from whom the biometric information for generation is read is the same as the user from whom the biometric information for authentication is read based on the similarity between the answer information and the correct answer information.
[0264] (3) The authentication device according to (1) or (2), further comprising:
[0265] A reading unit configured to read biometric information for authentication; and
[0266] A conversion unit configured to convert authentication information into answer information using the biometric information for authentication.
[0267] (4) The authentication device according to (3) further includes:
[0268] An extraction unit configured to extract a feature amount of the biometric information for authentication, wherein
[0269] The conversion unit converts the authentication information into answer information using the feature amount.
[0270] (5) The authentication device according to (4), wherein
[0271] The extraction unit extracts multiple types of feature amounts of the biometric information for authentication, and
[0272] The conversion unit divides the authentication information into multiple parts and converts the authentication information into answer information using different feature amounts for each part.
[0273] (6) The authentication device according to any one of (3) to (5), wherein
[0274] The biometric information for authentication and the biometric information for generation include multiple types of biometric information, and the conversion unit converts the authentication information into answer information using the multiple types of biometric information.
[0275] (7) The authentication device according to any one of (3) to (6), wherein
[0276] The basic information is consistent with the correct answer information, and
[0277] The conversion unit converts the authentication information into answer information through an inverse conversion corresponding to the conversion from the basic information to the authentication information.
[0278] (8) The authentication device according to any one of (3) to (6), wherein
[0279] The conversion from the basic information to the authentication information is an irreversible conversion, and
[0280] The basic information is different from the correct answer information.
[0281] (9) The authentication device according to any one of (3) to (8), wherein
[0282] The conversion unit converts multiple pieces of authentication information into multiple pieces of answer information using the biometric information for authentication, and
[0283] The authentication unit designates authentication information for use in the conversion of biometric information to be generated, based on the similarity between multiple pieces of answer information and correct answer information, and the biometric information to be generated is read from a user whose biometric information is read for authentication.
[0284] (10) The authentication device according to any one of (1) to (9), wherein
[0285] authentication information is generated using biometric information to be generated of multiple users, and
[0286] the authentication unit determines whether the user from whom the biometric information read for authentication is included among the multiple users, based on the similarity between the answer information and the correct answer information.
[0287] (11) The authentication device according to any one of (1) to (10), further comprising:
[0288] a communication unit configured to receive answer information from another device and send information indicating the result of user authentication of the authentication unit to another device.
[0289] (12) The authentication device according to any one of (1) to (11), wherein
[0290] the biometric information to be generated and the biometric information for authentication include at least any one of finger vein, fingerprint, palmprint, voice, face, iris, or otoacoustic emission.
[0291] (13) An authentication method, comprising:
[0292] being executed by an authentication device,
[0293] performing user authentication by comparing answer information with correct answer information, the answer information being generated by converting authentication information using biometric information for authentication, and the authentication information being generated by converting basic information using biometric information to be generated.
[0294] (14) A program for causing a computer to execute processing, comprising:
[0295] performing user authentication by comparing answer information with correct answer information, the answer information being generated by converting authentication information using biometric information for authentication, and the authentication information being generated by converting basic information using biometric information to be generated.
[0296] (15) An information processing device, comprising:
[0297] a reading unit configured to read biometric information to be generated; and
[0298] A conversion unit configured to convert basic information into authentication information using biometric information for generation, wherein,
[0299] Convert the authentication information into answer information using biometric information for authentication, and perform user authentication by comparing the answer information with the correct answer information.
[0300] (16) The information processing apparatus according to (15), further comprising:
[0301] An extraction unit configured to extract a feature amount of biometric information, wherein,
[0302] The conversion unit divides the authentication information into multiple parts, and converts the authentication information using different types of feature amounts for each part.
[0303] (17) The information processing apparatus according to (15) or (16), wherein,
[0304] The biometric information for authentication and the biometric information for generation include multiple types of biometric information, and the conversion unit converts the basic information into authentication information using multiple types of biometric information.
[0305] (18) The information processing apparatus according to any one of (15) to (17), wherein,
[0306] The conversion unit converts the basic information into authentication information using the biometric information for generation of multiple users.
[0307] (19) The information processing apparatus according to any one of (15) to (18), wherein,
[0308] The reading unit further reads the biometric information for authentication, and
[0309] The conversion unit further converts the authentication information into answer information using the biometric information for authentication, and
[0310] The information processing apparatus further comprises:
[0311] A communication unit configured to send the answer information to an authentication device and receive information indicating the result of user authentication from the authentication device, and user authentication is performed by comparing the answer information with the correct answer information.
[0312] (20) The information processing apparatus according to any one of (15) to (19), wherein,
[0313] The conversion unit converts the basic information into authentication information according to a conversion rule provided from the outside.
[0314] List of reference numerals
[0315] 1 Authentication System
[0316] 11 Authentication Information Publishing Device
[0317] 12 Authentication Device
[0318] 51 Biological Information Reading Unit
[0319] 52 Biological Information Feature Quantity Extraction Unit
[0320] 53 Template Conversion Unit
[0321] 54 Conversion Rule Storage Unit
[0322] 55 Basic Template Storage Unit
[0323] 56 Authentication Template Output Unit
[0324] 61 Biological Information Reading Unit
[0325] 62 Biological Information Feature Quantity Extraction Unit
[0326] 63 Authentication Template Reading Unit
[0327] 64 Template Conversion Unit
[0328] 65 Conversion Rule Storage Unit
[0329] 66 Authentication Unit
[0330] 67 Correct Answer Template Storage Unit
[0331] 68 Authentication Result Display Unit
[0332] 81 Camera
[0333] 82 Projector
[0334] 101 Server
[0335] 102 Mobile Terminal
[0336] 111, 121 Communication Unit
Claims
1. An authentication device, comprising: an authentication unit configured to perform user authentication by comparing an answer template with a pre-stored correct answer template, the answer template being generated by converting an authentication template using biometric information of a user for authentication, the authentication template being generated by converting a basic template using biometric information of the user, the basic template representing basic information using an image, the basic information being information for generating authentication information for user authentication, and the authentication template being a two-dimensional code; a reading unit configured to read the biometric information of the user for authentication, output the biometric information to an extraction unit, the extraction unit being configured to extract various types of feature quantities of the biometric information of the user for authentication, and output the feature quantities to a conversion unit; an authentication template reading unit configured to read the authentication template and output the authentication template to the conversion unit; a conversion unit configured to convert the authentication template into the answer template using the various types of feature quantities and output the converted answer template to the authentication unit, wherein the conversion unit performs conversion based on a conversion rule set based on the type of feature quantity for converting the basic template and the method for converting the basic template; and the conversion from the basic template to the authentication template is an irreversible conversion, and the basic template is different from the correct answer template, wherein the process of converting the authentication template into the answer template using various types of feature quantities is to divide the authentication template into a plurality of rectangular regions, and convert the authentication template into the answer template according to the conversion rule using the feature quantity of each different region, the conversion rule including the relationship between each rectangular region and a corresponding different type of feature quantity and the conversion method corresponding to the type of each rectangular region and the feature quantity.
2. The authentication device according to claim 1, wherein the authentication unit determines whether the user of the biometric information read for generation matches the user of the biometric information read for authentication based on the similarity between the answer template and the correct answer template.
3. The authentication device according to claim 1, wherein the biometric information for authentication and the biometric information for generation include various types of biometric information, and the conversion unit converts the authentication template into the answer template using various types of biometric information.
4. The authentication device according to claim 1, wherein the conversion unit converts a plurality of the authentication templates into a plurality of the answer templates using the biometric information for authentication, and the authentication unit designates the authentication template converted using the biometric information for generation based on the similarity between the plurality of answer templates and the correct answer template, and the biometric information for generation is read from the user of the biometric information read for authentication.
5. The authentication device according to claim 1, wherein the authentication template is generated using the biometric information for generation of multiple users, and The authentication unit determines whether the user whose biometric information is read for authentication is included in the multiple users based on the similarity between the answer template and the correct answer template.
6. The authentication device according to claim 1, further comprises: A communication unit configured to receive the answer template from another device and send information indicating the result of user authentication of the authentication unit to the another device.
7. The authentication device according to claim 1, wherein, The biometric information for generation and the biometric information for authentication include at least any one of finger vein, fingerprint, palm print, voice, face, iris or otoacoustic emission.
8. An authentication method, comprises: Performed by an authentication device, User authentication is performed by comparing an answer template with a pre-stored correct answer template. The answer template is generated by converting an authentication template using the biometric information of the user for authentication. The authentication template is generated by converting a basic template using the biometric information of the user. The basic template uses an image to represent basic information, and the basic information is the information for generating the authentication information for user authentication. The authentication template is a two-dimensional code; Read the biometric information of the user for authentication, output the biometric information to an extraction unit, the extraction unit is configured to extract various types of feature quantities of the biometric information of the user for authentication, and output the feature quantities to a conversion unit; Read the authentication template and output the authentication template to the conversion unit; Convert the authentication template into the answer template using the various types of feature quantities, and output the converted answer template to the authentication unit; and Perform conversion based on the conversion rule set based on the type of feature quantity used to convert the basic template and the method of converting the basic template; and The conversion from the basic template to the authentication template is an irreversible conversion, and The basic template is different from the correct answer template, wherein, The process of converting the authentication template into the answer template using various types of feature quantities is to divide the authentication template into multiple rectangular regions, and convert the authentication template into the answer template according to the conversion rule using the feature quantities of each different region. The conversion rule includes the relationship between each rectangular region and the corresponding different type of feature quantity and the conversion method corresponding to each rectangular region and the type of feature quantity.
9. A computer storage medium, the computer storage medium includes a program, and when the program is executed by a computer including the computer storage medium, the computer performs processing, and the processing comprises: User authentication is performed by comparing an answer template with a pre-stored correct answer template. The answer template is generated by converting an authentication template using the biometric information of the user for authentication. The authentication template is generated by converting a basic template using the biometric information of the user. The basic template uses an image to represent basic information, and the basic information is the information for generating the authentication information for user authentication. The authentication template is a two-dimensional code; Read the biological information of the user for authentication, and output the biological information to an extraction unit, which is configured to extract various types of feature quantities of the biological information of the user for authentication, and output the feature quantities to a conversion unit; Read an authentication template and output the authentication template to the conversion unit; Convert the authentication template into the answer template using the various types of feature quantities, and output the converted answer template to an authentication unit; And Perform the conversion based on a conversion rule set based on the type of feature quantity used to convert the basic template and the method for converting the basic template; And The conversion from the basic template to the authentication template is an irreversible conversion, and The basic template is different from the correct answer template, where The process of converting the authentication template into the answer template using various types of feature quantities is to divide the authentication template into a plurality of rectangular regions, and convert the authentication template into the answer template according to the conversion rule using the feature quantities of each different region. The conversion rule includes the relationship between each rectangular region and the corresponding different type of feature quantity and the conversion method corresponding to the type of each rectangular region and the feature quantity.
Citation Information
Patent Citations
Biometric signature system
JP2013123142A
Methods and systems for multi-key veritable biometric identity authentication
CN106030668A
Identity authentication method, device and system
CN106330464A
Devices and methods for facilitating generation of cryptographic keys from a biometric
CN107852325A