Biometric authentication using two thresholds
By employing a multi-threshold biometric authentication method, and through multiple tests and log-likelihood ratio analysis, the false rejection rate and false acceptance rate are reduced, thereby improving the accuracy and security of biometric authentication.
Patent Information
- Application Number
- CN202080101442.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-05-28
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2040-05-28
AI Technical Summary
Existing biometric authentication methods have high false rejection and false acceptance rates, which affect user experience and security.
A multi-threshold biometric authentication method is adopted, which determines the user's identity by performing multiple tests, using the log-likelihood ratio and different models. This includes a first test and a second test. Based on the likelihood ratio and a predetermined threshold, it is decided whether to perform further tests to finally determine the user's identity.
Significantly reduces false rejection and false acceptance rates, improves user experience and system security, and provides better recognition accuracy, especially in multiple testing scenarios.
Smart Images

Figure CN115552489B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for performing biometric authentication, and a system and computer program adapted to perform such a method for performing biometric authentication. Background Technology
[0002] Biometric authentication is a security process that uses the biological or biometric characteristics of a user (or person) U1 to verify (or authenticate / test / check) that user U1's identity. Many methods for performing such biometric authentication are known. This authentication can be based on one or more of, for example: facial characteristics; voice characteristics; fingerprints; eye characteristics (e.g., iris or retinal patterns); and so on. During biometric authentication, input... X It is obtained from (or provided by) the user U1 whose identity will be authenticated, where the input X Based on (or representing) one or more biological or biometric characteristics of user U1—this input X Biometric authentication can be obtained or derived, for example, based on one or more of the following: captured images of one or more of the user's face or eyes(s); fingerprint data obtained from a fingerprint scanner; captured / recorded user's voice (which may or may not be pre-defined spoken words); and so on, depending on which biometric features the authentication system intends to use. The purpose of biometric authentication is then to determine the input... X Is it by pre-booked user U? D Provide (or based on pre-booked user U) D or with pre-booked user U D Related, or from pre-booked user U D (Acquired), for example, whether the captured image of a user's face or one or more of their eyes corresponds to a predetermined user U. D The face or (one or more) eyes; whether the obtained fingerprint data corresponds to the pre-defined user U. D One or more fingerprints; whether the captured voice corresponds to the pre-defined user U. D The voice; etc. If it is determined that the user U1 being tested is the pre-booked user U... D Then user U1 can be processed accordingly, as if they were the reserved user U1. D The same (e.g., passing a passport check; being granted access to facilities, data, or equipment; being permitted to perform certain actions; etc.); if it is determined that the user U1 being tested is not the intended user U1. D Then user U1 can be processed accordingly, as if they were not the pre-booked user U1. DThe same applies (e.g., failing passport control; being denied access to facilities, data, or equipment; being prevented from performing certain actions; etc.). For example, equipment (e.g., a computer or smartphone) may belong to a specific person. D And may expect to perform biometric authentication on the person U1 who wishes to log in or use the device, to check whether that person U1 is the owner U. D And then only the certified owner U is allowed. D Log in and use the device.
[0003] Associated with biometric authentication are false rejections and false acceptances. If biometric authentication fails to accept a correctly declared identity—that is, if the tested user U1 is indeed the intended user U1—then false rejections will occur. D However, the biometric authentication incorrectly determined that the tested user U1 was not the intended user U1. D A false rejection occurs if the biometric authentication accepts an incorrectly declared identity, i.e., the tested user U1 is not the intended user U1. D However, the biometric authentication incorrectly identified the tested user U1 as the pre-booked user U1. D If the biometric authentication fails, a false acceptance occurs. A false rejection relates to the (inconvenience) experienced by the legitimate user—following a false rejection, the legitimate user may, for example, need to repeat biometric authentication or contact the system administrator. A false acceptance relates to the security of biometric authentication—following a false acceptance, an unauthorized or incorrect user may, for example, be able to access data or devices they would normally not be able to / permitted to access, or may be able to perform tasks they would normally not be able to / permitted to perform.
[0004] The aim is to provide a method for biometric authentication that offers both low false rejection and false acceptance rates. Summary of the Invention
[0005] According to a first aspect of the present invention, a method for performing biometric authentication for a first user is provided, the method comprising:
[0006] Execute one or more first tests, wherein for each first test, executing the first test includes:
[0007] The first input for the first test is obtained based on one or more biometric features of the first user;
[0008] When the corresponding first log-likelihood ratio of the first likelihood and the second likelihood does not exceed the corresponding first threshold of the first test, it is determined that the first user is not the intended user, wherein the first likelihood is the likelihood of the corresponding first input obtained based on a first model, in which the input is obtained from the intended user, and wherein the second likelihood is the likelihood of the corresponding first input obtained based on a second model, in which the input is obtained from one or more users other than the intended user;
[0009] When the corresponding first log-likelihood ratio exceeds the corresponding second threshold of the first test, the first user is determined to be the predetermined user, and the corresponding second threshold is greater than the corresponding first threshold; and
[0010] When the corresponding first log-likelihood ratio exceeds the corresponding first threshold and the corresponding first log-likelihood ratio does not exceed the corresponding second threshold, either (a) determine to execute a further first test when the number of times the first test has been executed is less than the predetermined maximum number of times, or (b) determine to execute a second test when the number of times the first test has been executed is equal to the predetermined maximum number of times;
[0011] The second test includes:
[0012] The second input for the second test is obtained based on one or more biometric features of the first user; and
[0013] When the ratio of the second log-likelihood of the third likelihood and the fourth likelihood exceeds the third threshold, the first user is determined to be the predetermined user, wherein the third likelihood is based on the likelihood of the first model receiving the corresponding second input, and wherein the fourth likelihood is based on the likelihood of the second model receiving the second input.
[0014] When the second log-likelihood ratio does not exceed the third threshold, it is determined that the first user is not the intended user.
[0015] In some embodiments of the first aspect, for each first test, the corresponding first log-likelihood ratio is r ( X (j) )=log p(X (j) | l g )−log p(X (j) | l i ),in X (j) It is the corresponding first input of the first test. l g It is the first model, and li This is the second model. In this embodiment, for each first test, determining that the first user is not the predetermined user when the corresponding first log-likelihood ratio of the first likelihood and the second likelihood does not exceed the corresponding first threshold includes one of the following steps: (a) calculating r ( X (j) ), and if r ( X (j) )< i L (j) If so, then it is determined that the first user is not the reserved user, where i L (j) (a) The corresponding predetermined threshold for the first test; or (b) Calculate And if If so, then it is determined that the first user is not the reserved user, where i L (j) The first test is a predetermined threshold; or (c) a metric is calculated based on the ratio between the first likelihood and the second likelihood, and the metric is compared to the threshold based on the corresponding first threshold. Additionally or alternatively, in this embodiment, for each first test, determining that a first user is a predetermined user when the corresponding first log-likelihood ratio exceeds the corresponding second threshold includes one of the following steps: (a) calculating... r ( X (j) ), and if r ( X (j) )> i R (j) Then, the first user is determined to be the reserved user, wherein i R (j) (a) The corresponding predetermined threshold for the first test; or (b) Calculate And if Then, the first user is determined to be the reserved user, wherein i R (j) (c) The metric is calculated based on the ratio between the first likelihood and the second likelihood, and the metric is compared with the threshold based on the corresponding second threshold.
[0016] In some embodiments of the first aspect, the second log-likelihood ratio is r ( X (N) )=log p(X(N) | l g )−log p(X (N) | l i ),in X (N) It is the second input. l g It is the first model, and l i This is the second model. In this embodiment, determining that the first user is the predetermined user when the second log-likelihood ratio of the third likelihood and the fourth likelihood exceeds a third threshold may include one of the following steps: (a) calculating r ( X (N) ), and if r ( X (N) )> i (N) Then, the first user is determined to be the reserved user, wherein i (N) It is a predetermined threshold; or (b) calculation And if Then, the first user is determined to be the reserved user, wherein i (N) (c) A predetermined threshold is used; or (d) a metric is calculated based on the ratio between the third likelihood and the fourth likelihood, and the metric is compared with the threshold based on the third threshold.
[0017] In some embodiments of the first aspect, the one or more biometric features are based on one or more of the following: the face of a first user; the voice of a first user; one or more fingerprints of a first user; or one or more eyes of a first user.
[0018] According to a second aspect of the invention, a system is provided that is arranged to perform biometric authentication for a first user, the system being adapted to:
[0019] Execute one or more first tests, wherein for each first test, executing the first test includes:
[0020] The first input for the first test is obtained based on one or more biometric features of the first user;
[0021] When the ratio of the corresponding first log-likelihood of the first likelihood and the second likelihood does not exceed the corresponding first threshold of the first test, it is determined that the first user is not the intended user, wherein the first likelihood is the likelihood of the corresponding first input obtained based on a first model, in which the input is obtained from the intended user, and wherein the second likelihood is the likelihood of the corresponding first input obtained based on a second model, in which the input is obtained from one or more users other than the intended user;
[0022] When the corresponding first log-likelihood ratio exceeds the corresponding second threshold of the first test, the first user is determined to be the predetermined user, and the corresponding second threshold is greater than the corresponding first threshold; and
[0023] When the corresponding first log-likelihood ratio exceeds the corresponding first threshold and the corresponding first log-likelihood ratio does not exceed the corresponding second threshold, either (a) determine to execute a further first test when the number of times the first test has been executed is less than the predetermined maximum number of times, or (b) determine to execute a second test when the number of times the first test has been executed is equal to the predetermined maximum number of times;
[0024] The second test includes:
[0025] The second input for the second test is obtained based on one or more biometric features of the first user; and
[0026] When the ratio of the second log-likelihood of the third likelihood and the fourth likelihood exceeds the third threshold, the first user is determined to be the predetermined user, wherein the third likelihood is based on the likelihood of the first model receiving the corresponding second input, and wherein the fourth likelihood is based on the likelihood of the second model receiving the second input.
[0027] When the second log-likelihood ratio does not exceed the third threshold, it is determined that the first user is not the intended user.
[0028] In some embodiments of the second aspect, for each first test, the corresponding first log-likelihood ratio is r ( X (j) )=log p(X (j) | l g )−log p(X (j) | l i ),in X (j) It is the corresponding first input of the first test. l g It is the first model, and l iThis is the second model. In this embodiment, for each first test, determining that the first user is not the predetermined user when the corresponding first log-likelihood ratio of the first likelihood and the second likelihood does not exceed the corresponding first threshold includes one of the following steps: (a) calculating r ( X (j) ), and if r ( X (j) )< i L (j) If so, then it is determined that the first user is not the reserved user, where i L (j) (a) The corresponding predetermined threshold for the first test; or (b) Calculate And if If so, then it is determined that the first user is not the reserved user, where i L (j) The first test is a predetermined threshold; or (c) a metric is calculated based on the ratio between the first likelihood and the second likelihood, and the metric is compared to the threshold based on the corresponding first threshold. Additionally or alternatively, in this embodiment, for each first test, determining that a first user is a predetermined user when the corresponding first log-likelihood ratio exceeds the corresponding second threshold includes one of the following steps: (a) calculating... r ( X (j) ), and if r ( X (j) )> i R (j) Then, the first user is determined to be the reserved user, wherein i R (j) (a) The corresponding predetermined threshold for the first test; or (b) Calculate And if Then, the first user is determined to be the reserved user, wherein i R (j) (c) The metric is calculated based on the ratio between the first likelihood and the second likelihood, and the metric is compared with the threshold based on the corresponding second threshold.
[0029] In some embodiments of the second aspect, the second log-likelihood ratio is r ( X (N) )=log p(X (N)| l g )−log p(X (N) | l i ),in X (N) It is the second input. l g It is the first model, and l i This is the second model. In this embodiment, determining that the first user is the predetermined user when the second log-likelihood ratio of the third likelihood and the fourth likelihood exceeds a third threshold may include one of the following steps: (a) calculating r ( X (N) ), and if r ( X (N) )> i (N) Then, the first user is determined to be the reserved user, wherein i (N) It is a predetermined threshold; or (b) calculation And if Then, the first user is determined to be the reserved user, wherein i (N) (c) A predetermined threshold is used; or (d) a metric is calculated based on the ratio between the third likelihood and the fourth likelihood, and the metric is compared with the threshold based on the third threshold.
[0030] In some embodiments of the second aspect, the one or more biometric features are based on one or more of the following: the face of a first user; the voice of a first user; one or more fingerprints of a first user; or one or more eyes of a first user.
[0031] According to a third aspect of the invention, a computer program is provided that, when executed by one or more processors, causes the one or more processors to perform the method according to the first aspect or any embodiment thereof. The computer program may be stored on a computer-readable medium. Attached Figure Description
[0032] Embodiments of the invention will now be described by way of example only with reference to the accompanying drawings, in which:
[0033] Figure 1 An example of a computer system is illustrated schematically;
[0034] Figure 2 A system for performing biometric authentication according to some such embodiments is schematically illustrated;
[0035] Figure 3 The diagram illustrates two probability density functions. f g and f i ;
[0036] Figure 4 The diagram shows ER minmax ( α Example plot;
[0037] Figure 5 This is a flowchart illustrating a method for performing biometric authentication for a first user according to some embodiments of the present invention; and
[0038] Figure 6 This is a flowchart illustrating a method for operating an authentication system according to some embodiments of the present invention. Detailed Implementation
[0039] Certain embodiments of the invention are described in the following description and accompanying drawings. However, it will be understood that the invention is not limited to the described embodiments, and some embodiments may not include all the features described below. It will be apparent, however, that various modifications and changes may be made herein without departing from the broader spirit and scope of the invention as set forth in the appended claims.
[0040] 1 - Basic Mathematical Foundations
[0041] As mentioned, the purpose of biometric authentication is to: provide input from (or originate from) a first user U1 and based on (or represent) one or more biological or biometric characteristics of the first user U1. X In the case of determining whether the first user U1 is a reserved or specific user U1 D This can be formalized as a hypothesis test, where the null hypothesis is... H 0 is X Originating from pre-order user U D (or by pre-booked user U) D Provided, or based on or corresponding to a pre-defined user U D ), and in which alternative assumptions H 1 is X Not derived from pre-order user U D (or not by pre-booked user U) D Provided, or not based on or corresponding to the pre-defined user U D One possible test is to compare likelihoods. p ( X | H 0) and p (X | H 1), of which p ( X | H j )(for j= 0,1) is for the input X Assumptions of the evaluation H j The probability density function, for example, by calculating the log-likelihood ratio. r ( X )=log p(X | H 0)−log p(X | H 1). The natural logarithm is used in the following text, but it will be understood that other logarithms can be used (where the examples and equations are updated accordingly). r ( X The value of ) can be compared with the threshold. i Compare, and if r ( X )> i ,but H 0 is accepted (i.e., it is determined that user U1 is the pre-booked user U). D ), and if r ( X )< i ,but H 1 was accepted and H 0 was rejected (i.e., it was determined that user U1 was not the intended user U). D What will be understood is, regarding if r ( X )= i To accept or to refuse H 0 is a design choice.
[0042] Likelihood p ( X | H 0) and p ( X | H 1) can be determined based on the model. l g and l i ,in l g It is from the pre-booked user U D Obtain the first model as input, and in which l i It is among them, except for pre-booked users U D A second model that provides input to one or more users other than the one mentioned above, i.e. l gIt is a pre-booked user U D The model, and l i It is one or more "imposters" (i.e., in addition to the pre-registered user U) D The model (for users other than those mentioned above). Then, the model... l g and l i They represent the assumptions respectively. H 0 and H 1. Then, these models can be used to separately apply the likelihood. p ( X | H 0) and p ( X | H 1) Calculated as p ( X | l g )and p ( X | l i This allows the log-likelihood ratio to be calculated as... r ( X )=log p(X | l g )−log p(X | l i ).
[0043] The model will be described later. l g and l i Examples and properties.
[0044] Given that each represents a "real" user (i.e., a pre-booked user U), D ) and one or more "imposters" (i.e., in addition to the pre-booked user U) D Test input from users other than themselves X random variables X g and X i In the case of random variables r ( X g )and r ( X i It can be assumed that it has a corresponding Gaussian distribution, i.e. and How can the corresponding mean be estimated? m g and m i and corresponding variance s 2 g and s 2 i Examples will be described later. Random variables r ( X g )and r ( X i The corresponding probability density function of ) f g and f i Then:
[0045]
[0046] and
[0047] .
[0048] Using a well-known error function ,random variable r ( X g )and r ( X i The cumulative distribution function of ) F g and F i yes:
[0049]
[0050] and
[0051] .
[0052] The following analysis assumes that the following design choices were made: if r ( X )= i ,but H 0 was rejected. However, as mentioned above, those skilled in the art will appreciate that this is merely a design choice, and the following analysis can be readily adapted to it if... r ( X )= i but H Examples where 0 is accepted.
[0053] when H When 0 is true but rejected, it means the user U1 being tested is the pre-booked user U. DHowever, the biometric authentication incorrectly determined that user U1 was not the pre-booked user U1. D At this time, a Type I error (or false rejection or false positive) occurs. Therefore, the probability of a Type I error is... p FP It can be expressed as:
[0054]
[0055] (in t Parameterized for p FP The expression, and represents the parameterized threshold. i ).
[0056] As mentioned above, p FP This relates to the (inconvenience) experienced by the actual user—that is, the user U1 being tested is indeed the intended user U. D However, biometric authentication is p FP The probability incorrectly determines that user U1 is not the pre-booked user U. D (And therefore inconvenient). p FP The lower the value, the better the convenience for the actual user.
[0057] when H When 0 is false but accepted, it means that the user U1 being tested is not the intended user U. D However, the biometric authentication incorrectly identified user U1 as the pre-booked user U1. D At this time, a Type II error (or false acceptance or false negative) occurs. Therefore, the probability of a Type II error is... p FN It can be expressed as:
[0058]
[0059] (in t Parameterized for p FN The expression, and represents the parameterized threshold. i ).
[0060] As mentioned above, p FN This relates to the security of biometric authentication systems / methods—that is, the user U1 being tested is not the intended user U. D However, biometric authentication is p FN The probability incorrectly determines that user U1 is the pre-booked user U. D (And security may be considered compromised).p FN The lower the value, the better the security.
[0061] p FP and p FN One or both can be used to set i To execute the value r (X)< i For example, in a focus on user convenience, testing... p FP target value β FP >0 can be chosen to be as low as desired, where the corresponding selection i The value of makes
[0062] .
[0063] Similarly, with a focus on security, targeting p FN target value β FN >0 can be chosen to be as low as desired, where the corresponding selection i The value of makes
[0064] .
[0065] The so-called equal error rate (EER) can be used to define i The value provides a measure of the validity of biometric authentication. Used to obtain EER i Value (i.e., i EER )yes t The value, for this t The value, And EER is then defined as The lower the EER value, the more secure and convenient the biometric authentication is for users.
[0066] example 1 As an example of the above methods for biometric authentication, consider the parameter values of two Gaussian distributions: m g =2.73、 s 2 g =0.44、 m i =−1.86 and s 2 i =0.90. Figure 3 The corresponding probability density function is illustrated in the figure.f g and f i . i EER It can be determined as (e.g., numerically). i EER EER ≈0.84 and EER ≈0.0022.
[0067] Enhancements to the method described above for performing biometric authentication will now be described. These enhancements achieve better security and / or better user convenience, as will become apparent. The same underlying model is used in this enhanced method of biometric authentication. l g and l i .
[0068] In the case of this enhanced method utilizing biometric authentication, instead of using only a single threshold... i To execute r ( X )< i Instead of a single test, multiple thresholds are used, as illustrated below, where one or more tests are performed for a single biometric authentication. Specifically, the first type of test (referred to herein as the first test) can be performed once or multiple times, up to a maximum number of times. M The second type of test (referred to as the second test in this article) can then be executed (if the first test has already been executed). M Next and depending on the first M (Results of the first test). Therefore, at most... N This test, among which N = M +1. The parameter will be used in the following text. j To indicate the current test being executed, where j The range is from 1 to N ,and j It was initialized to 1. M The value of is predetermined and can be any positive integer; therefore, similarly, N The value is predetermined and can be any positive integer greater than 1. In fact, it can be set to... N The value of is because this represents the maximum number of tests a given biometric authentication user will need to undergo (whether they are the first or second test), where M The value is based on N This is to set or determine, because M = N -1. Some embodiments can be implemented to use MThe value, without explicitly using N The value (for example, see later) Figure 5 (As discussed); similarly, some embodiments can be implemented using N The value, without explicitly using M The value; and some embodiments can be implemented using M The value and N The value—this is a design choice.
[0069] In particular, the first j The first test was executed, among which the first test was performed. j Input of the first test X (j) To calculate r ( X (j) ), and: (a) if for the first j The first threshold of the first test i L (j) , r ( X (j) )< i L (j) ,but H 1 was accepted and H 0 was rejected (i.e., it was determined that user U1 was not the intended user U). D (b) If for the first j The second threshold of the first test i R (j) , r ( X (j) )> i R (j) ,in i R (j) > i L (j) ,but H 0 is accepted (i.e., it is determined that user U1 is the pre-booked user U). D (c) However, if i L (j) < r ( X (j) )< i R (j) Then the conclusion of the first test is either (i) if j < MThen another first test will be performed (in this case, j It will increment by 1, making the ()th j +1) the first test is then executed); or (ii) if j = M Then the second test will be executed (in this case, the second test will be the first one executed). N (Number of tests) - therefore, the first test is executed the most. M Next, and if the first test has already been performed. M Next i L (M) < r ( X (M) )< i R (M) If so, then the second test will be performed.
[0070] In some embodiments, in the j In the first test, if r ( X (j) )= i L (j) ,but H 0 is rejected, while in other embodiments, if r ( X (j) )= i L (j) Then, depending on the situation, further first or second tests may be performed: this is a design choice. Similarly, in some embodiments, in the first... j In the first test, if r ( X (j) )= i R (j) ,but H 0 is accepted, while in other embodiments, if r ( X (j) )= i R (j) If necessary, further first or second tests may be performed: again, this is a design choice.
[0071] Each of one or more first tests includes obtaining the corresponding first input. X (j) First input X (j) It can be used to obtain inputX The input is obtained in the same way as discussed above. X (j) Belongs to input X The same type (i.e., they both involve the same biological or biometric characteristics and can be based on the same model). l g and l i Let's analyze it.
[0072] For the second test, calculate r ( X (N) ), and: (a) if for the third threshold i (N) , r ( X (N) )< i (N) ,but H 1 was accepted and H 0 was rejected (i.e., it was determined that user U1 was not the intended user U). D (b) If for the third threshold i (N) , r ( X (N) )> i (N) ,but H 0 is accepted (i.e., it is determined that user U1 is the pre-booked user U). D In some embodiments, if r ( X (N) )= i (N) ,but H 0 is accepted, while in other embodiments, if r ( X (N) )= i (N) ,but H 0 rejected: Again, this is a design choice.
[0073] The second test includes obtaining a second input. X (N) Second input X (N) It can be used to obtain input X The second input is obtained in the same way as discussed above. X (N) Belongs to input XThe same type (i.e., they both involve the same biological or biometric characteristics and can be based on the same model). l g and l i Let's analyze it.
[0074] The following analysis assumes that the following design choices were made: in the... j If during the first test r ( X (j) )= i L (j) ,but H 0 was rejected, and if in the second test r ( X (N) )= i (N) ,but H 0 was rejected, and if r ( X (j) )= i R (j) If so, further first or second tests will be performed as appropriate. The following analysis also assumes that each corresponding first input... X (j) (for j =1,2,..., N -1) and second input X (N) random variables r ( X (j) )(for j =1,2,..., N -1) and r ( X (N) Each of the corresponding first inputs is independent and associated with a single biometric authentication. X (j) (for j =1,2,..., N -1) and second input X (N) random variables r ( X (j) )(for j =1,2,..., N -1) and r ( X (N)The distributions are identical. Specifically, as mentioned above, given the "real" users (i.e., the pre-booked users U)... D ) and one or more "imposters" (i.e., in addition to the pre-booked user U) D Test input from users other than themselves X (j) (or X (N) random variables X g and X i In the case of random variables r ( X g )and r ( X i It can be assumed that it has a corresponding Gaussian distribution, i.e. and As mentioned earlier, how can the corresponding mean be estimated? m g and m i and corresponding variance s 2 g and s 2 i Examples will be described later.
[0075] Therefore, the maximum number of tests is within it. N Equals 2 (that is, M In the embodiment where =1), the probability of a Type I error and the probability of Type II error It is given by the following formula:
[0076]
[0077]
[0078] (in t L (1) , t R (1) , t (2) Parameterized for and These expressions, and represent parameterized thresholds. i L (1) , i R (1) and i(2) )
[0079] Make
[0080] .
[0081] and One or both can be used to set i L (1) , i R (1) and i (2) The values are used to perform the first and second tests described above. For example, in a focus on user convenience, for target value β FP >0 can be chosen to be as low as desired, where the corresponding selection i L (1) , i R (1) and i (2) The value of makes
[0082]
[0083] There may be more than one triplet that satisfies this condition. i L (1) , i R (1) , i (2) ), any one of them can be selected. In some embodiments, the triplet of values ( i L (1) , i R (1) , i (2) ) was selected, making The value should be as small as possible.
[0084] example 2 Considering parameters m g , s 2 g , m i and s 2i The value is the same as the value in Example 1 above, and is set β FP =0.0022, which determines that for i L (1) ≈0.68 i R (1) ≈2.62 and i (2) ≈0.89, The probability of a false negative in this example is about 273 times smaller than the corresponding value in Example 1, which is a significant improvement for security.
[0085] Similarly, with a focus on security, targeting target value β FN >0 can be chosen to be as low as desired, where the corresponding selection i L (1) , i R (1) and i (2) The value of makes
[0086]
[0087] Similarly, there may be more than one triplet that satisfies this condition. i L (1) , i R (1) , i (2) ), any one of them can be selected. In some embodiments, the triplet of values ( i L (1) , i R (1) , i (2) ) was selected, making The value should be as small as possible.
[0088] example 3 Considering parameters m g , s 2 g , m i and s 2i The value is the same as the value in Example 1 above, and is set β FN =0.0022, which determines that for i L (1) ≈−0.59、 i R (1) ≈1.20 and i (2) ≈0.14, The probability of false positives in this example is about 2850 times smaller than the corresponding value in Example 1, which is a significant improvement for the convenience of real users.
[0089] You can use the adapted EER method to set it. i L (1) , i R (1) and i (2) The value of . Let the function u Defined by the following formula:
[0090]
[0091] And let
[0092]
[0093] Then, i L (1) , i R (1) and i (2) The value can be set to what it has achieved. ER minmax of t L (1) , t R (1) and t (2) The value of . Similarly, there may exist more than one triplet that satisfies this. i L (1) , i R (1) , i (2) Any one of them can be selected.
[0094] example4 Considering parameters m g , s 2 g , m i and s 2 i The value is the same as the value in Example 1 above. ER minmax It can be determined numerically, where for i L (1) ≈0.14 i R (1) ≈1.97 and i (2) ≈0.57 ,ER minmax ≈0.00012. In this example... ER minmax The value is about 18 times smaller than the EER in Example 1, which is a considerable improvement for both the convenience and security of real users.
[0095] What you will understand is that other methods can be used to set it. i L (1) , i R (1) and i (2) The value of depends on, for example, the expected balance between the false acceptance rate and the false rejection rate.
[0096] Maximum number of tests N Equals 2 (that is, M In the embodiment where =1), given that the first user U1 is a "real" user (i.e., the pre-booked user U), D ) or the first user U1 is an "imposter" (i.e., besides the reserved user U) D In the case of users other than those mentioned above, targeting m =1 and m =2 was executed exactly m The probabilities of each test are respectively and ,in:
[0097] .
[0098] It is important to note that This can be considered partly related to the security of biometric authentication, as attackers / impersonators might be able to obtain further information related to biometric authentication through a second test. To help mitigate this situation, some embodiments of the present invention may impose a maximum number of consecutive executions of the biometric authentication process that would result in a second test.
[0099] It should also be noted that, With real (pre-booked) user U D This relates to the (inconvenience) experienced. For example, one might expect to ensure... At most, it's a threshold. α (for some 0 < α <1), and then i L (1) , i R (1) and i (2) The value was set to reach the target. ER minmax ( α )of t L (1) , t R (1) and t (2) The value of , where:
[0100]
[0101] Right now, ER minmax ( α )yes ER minmax However, the minimization is constrained to the following triples ( t L (1) , t R (1) , t (2) ): Regarding this triple ( t L (1) , t R (1) , t (2) ), .
[0102] example5 Considering parameters mg , s 2 g , m i , s 2 i The value is the same as the value in Example 2 above, and i L (1) , i R (1) and i (2) The values are the same.
[0103]
[0104] Specifically, if 0.126 < α <1, then ER minmax ( α ) < 0.00012. For 0 < α <0.126, ER minmax ( α The value of ) can be determined numerically, and Figure 4 As shown in the image. As a specific example, if... α =0.01 (that is, if the probability that a real user needs to perform a second test is at most 0.01), then ER minmax (0.01)≈0.00063. The corresponding threshold is then: i L (1) ≈0.57 i R (1) ≈1.20 and i (2) ≈1.09. In the case of these values,
[0105]
[0106] ER minmax (0.01) is about 3.5 times smaller than the EER in Example 1 above, which means that even if the probability of a real user needing to perform a second test is limited to a value above 0.01, a good improvement in both convenience and security for real users can still be achieved.
[0107] In which N In cases where >1, at most [the value] will be executed. N In a typical scenario of this test, the probability of a Type I error. It can be calculated in the following way:
[0108] set up
[0109] And calculate
[0110]
[0111] in j =2,3,..., N .
[0112] Similarly, in which N In cases where >1, at most [the value] will be executed. N In a typical scenario of this test, the probability of a Type II error Alternatively, it can be calculated in the following way:
[0113] set up
[0114] And calculate
[0115]
[0116] in j= 2,3,..., N .
[0117] (in t L (1) , t R (1) ,..., t L (N-1) , t R (N-1) , t (N) Parameterized for and These expressions, and represent parameterized thresholds. i L (1) , i R (1) ,..., i L (N-1) , i R (N-1) , i (N) ).
[0118] and One or both can be used to set i L (1) , i R (1) ,..., i L (N-1) , i R (N-1) , i (N) The value is used to perform the above at most N This test. For example, when focusing on user convenience, targeting... target value β FP >0 can be chosen to be as low as desired, where the corresponding selection i L (1) , i R (1) ,..., i L (N-1) , i R (N-1) , i (N) The value of makes
[0119]
[0120] There may exist more than one vector that satisfies this condition. i L (1) , i R (1) ,..., i L (N-1) , i R (N-1) , i (N) ), any one of them can be selected. In some embodiments, the vector of values ( i L (1) , i R (1) ,..., i L (N-1) , i R (N-1) , i (N) ) can be selected, making The value should be as small as possible.
[0121] Similarly, with a focus on security, targeting target value β FN >0 can be chosen to be as low as desired, where the corresponding selection i L (1) , i R (1) ,..., i L (N-1) , i R (N-1) , i (N) The value of makes
[0122]
[0123] Similarly, there may be more than one vector that satisfies this condition. i L (1) , i R (1) ,..., i L (N-1) , i R (N-1) , i (N) ), any one of them can be selected. In some embodiments, the vector of values ( i L (1) , i R (1) ,..., i L (N-1) , i R (N-1) , i (N) ) can be selected, making The value should be as small as possible.
[0124] A further adapted EER method can be used to set it. i L (1) , i R (1) ,..., i L(N-1) , i R (N-1) , i (N) The value of . Let the function v Defined by the following formula:
[0125]
[0126] And let
[0127]
[0128] Then, i L (1) , i R (1) ,..., i L (N-1) , i R (N-1) , i (N) The value can be set to what it has achieved. of t L (1) , t R (1) ,..., t L (N-1) , t R (N-1) , t (N) The value of . Similarly, there may exist more than one vector with a value that satisfies this. i L (1) , i R (1) ,..., i L (N-1) , i R (N-1) , i (N) Any one of them can be selected.
[0129] Similarly, it will be understood that other methods can be used to set it. i L (1) , i R (1),..., i L (N-1) , i R (N-1) , i (N) The value of depends on, for example, the expected balance between the false acceptance rate and the false rejection rate.
[0130] In which N In cases where >1, at most [the value] will be executed. N In the typical scenario of this test, given that the first user U1 is a "real" user (i.e., the pre-booked user U1), D ) or the first user U1 is an "imposter" (i.e., besides the reserved user U) D In the case of users other than 1, m ≤ N Execution at the exact time m The probabilities of each test are respectively and , among which, if m < N :
[0131]
[0132]
[0133] And among them:
[0134] .
[0135] example 6 Considering parameters m g , s 2 g , m i and s 2 i The value is the same as the value in Example 1 above. It can be determined numerically, where for , ≈0.000015.
[0136] In this example The value is about 147 times smaller than the EER in Example 1, and also smaller than that in Example 4. ER minmax The value is about 8 times smaller, which is a significant improvement for both the convenience and security of real users. For this example,
[0137] .
[0138] It is important to note that This can be considered partly related to the security of biometric authentication, as attackers / impersonators may be able to obtain further information related to biometric authentication through more than one test. To help mitigate this situation, some embodiments of the present invention may impose a maximum number of consecutive executions of the biometric authentication process, resulting in more than one test.
[0139] It should also be noted that, With real (pre-booked) user U D This relates to the (inconvenience) experienced. For example, one might expect to ensure... At least the threshold 1− α (for some 0 < α <1), and then i L (1) , i R (1) ,..., i L (N-1) , i R (N-1) , i (N) The value was set to reach the target. of t L (1) , t R (1) ,..., t L (N-1) , t R (N-1) , t (N) The value of , but minimizing it is constrained to t L (1) , t R (1) ,..., t L (N-1) , t R (N-1) , t (N) The following values are given: For the stated values:
[0140] .
[0141] As mentioned above, input X (And similarly, (one or more) first inputs) X (j) (for j =1,2,..., M ) and second input X (N) The authentication system can be obtained or derived, for example, based on one or more of the following: one or more captured images of the user's face or eyes(s); fingerprint data obtained from a fingerprint scanner; capture / recording of the user's voice (which may or may not be pre-defined spoken words); and so on, depending on which biometric features the authentication system intends to use. The following discussion uses user voice (e.g., related to spoken words) as a model. l g and l i The generation and use of, and their corresponding averages m g and m i and corresponding variance s 2 g and s 2 i The exported example. However, what will be understood is the other types of user characteristics and the different types of input. X A similar method can be used.
[0142] enter X It can be a captured / recorded segment of speech from a single speaker. It can be derived from... X Generate representation input X The feature vector. For example, input X The system can be divided into multiple frames of a certain length, with or without a certain amount of overlap between adjacent frames. For example, a frame might be 10 ms long, and the overlap between adjacent frames might be 50%. In some embodiments, frames that do not meet certain predetermined criteria can be discarded—for example, frames that do not contain speech or are too quiet (i.e., do not meet the "loud enough" criterion) can be discarded. In other words, frames that meet certain predetermined criteria can be selected for further processing. Feature extraction can then be applied to the frames (or the frames selected based on the aforementioned criteria). This can be achieved in various ways, such as the well-known Mel-frequency cepstral coefficient (MFCC) based feature extraction—see LR Rabiner and BH Juang's "..." Fundamentals of Speech Recognition, Englewood Cliffs“NJ, PTR Prentice Hall, 1993, all of which are publicly available and are incorporated herein by reference. If these (selected / remaining) frames are numbered 1 to K And if n Indicating the number of MFCCs used, the method outputs for frames. j (in j =1,2,..., K ) eigenvectors What you will understand is that you can use input... X get K A set of eigenvectors Other methods, and as mentioned above, when input X Instead of voice segments, alternative methods can be used when different user characteristics are involved.
[0143] Various types of models exist that can be used in embodiments of the present invention. l g and l i Examples include Hidden Markov Models (HMMs). Gaussian Mixture Models (GMMs) are a well-known model type—see, for example, https: / / en.wikipedia.org / wiki / Mixture_model and the works of DA Reynolds, TF Quatieri, and RB Dunn. Speaker verification using adapted Gaussian mixture models "Digital Signal Processing 10 (2000), pp. 19-41, all of which are incorporated herein by reference. This is to use a GMM-based approach to compute likelihood." p ( X | l g )and p ( X | l i ),let It is a vector with mean. Covariance Matrix ( j =1,2,..., M Gaussian density function. Gaussian mixture density function. It can be defined as a weighted sum of these Gaussian density functions. If the weights are... (for j =1,2,..., m If ) represents the GMM, then the GMM consists of a parameter set. To characterize, and
[0144] .
[0145] In AP Dempster, NM Laird and DB Rubin's " Maximum likelihood from incomplete data via the EM algorithm The Expectation-Maximization (EM) algorithm, proposed in the *Journal of the Royal Statistical Society: Series B (Methodological)*, vol. 39, no. 1 (1977), pp. 1–38 (all of its publications are incorporated herein by reference), is used to estimate parameters. l This is a well-known method. The algorithm combines the feature vector set, m The values of the parameters, the number of iterations used in the EM algorithm, and an initial value of a Gaussian density function are taken as input, and the estimated parameters are output. l .
[0146] Therefore, during the training phase, it is possible to learn from the actual speaker, U. D The first set of feature vectors is extracted from the provided training speech segments (as discussed above). This first set can be input into the EM algorithm to estimate the parameters. l g Similarly, it is possible to use one or more imposters (i.e., in addition to the real speaker U) D A second set of feature vectors is extracted from training speech segments (from users other than those mentioned above). This second set can be input into the EM algorithm to estimate parameters. l i .
[0147] For from the speech segment X The set of feature vectors extracted { x 1, x 2,..., x T}(in ,for j =1,2,..., T Log-likelihood p ( X | l g ) and log p ( X | l i ) can be calculated as:
[0148]
[0149] That is, likelihood p ( X| l g )and p ( X | l i ) can be calculated as:
[0150]
[0151] Makes it possible to calculate r ( X )=log p(X | l g )−log p(X | l i ).
[0152] To estimate the mean m g and variance s 2 g The real speaker U D of M g A collection of speech segments It can be obtained, and m g and s 2 g It can be estimated as:
[0153] .
[0154] Similarly, in order to estimate the mean m i and variance s 2 i One or more imposters (i.e., besides the real speaker U) D (users other than) M i A collection of speech segments It can be obtained, and m i and s 2 i It can be estimated as:
[0155] .
[0156] Based on these estimated means m g , m i and variance s 2g , s 2 i The threshold used for the testing phase (i.e., when performing biometric authentication) can be calculated as discussed above.
[0157] During the testing phase, test audio segments can be used. X Extract the feature vector set { x 1, x 2,..., x S Log-likelihood log p(X | l g ) and log p(X | l i ) and / or likelihood p ( X | l g )and p ( X | l i It can be calculated as discussed above:
[0158]
[0159] Right now:
[0160]
[0161] Therefore, it can be calculated during the testing phase. r ( X )=log p(X | l g )−log p(X | l i ).
[0162] What will be understood is that, in the above example discussion of audio speech segments, the input... X It is considered as a speech segment that is recorded / captured by the user and from which a set of feature vectors has been extracted. For subsequent processing. However, the input X It can be equivalently regarded as the actual feature vector obtained from the user via audio recording / capture and subsequent feature extraction. Viewing input X Other methods can be equally applied (e.g., input). X It can be a filtered / processed version of the audio recording / capture.
[0163] As discussed above, this can be applied to the model. l g and l i Other types of models can be used, and those models can be initialized accordingly during the training phase. l g and l i The corresponding method. In fact, the model l g and l i They do not necessarily need to belong to the same type. Since this modeling and training / initialization will be well known to those skilled in the art, no further details will be given in this document.
[0164] 2 - System Overview
[0165] Figure 1 An example of a computer system 100 is schematically illustrated. System 100 includes a computer 102. Computer 102 includes: storage medium 104, memory 106, processor 108, interface 110, user output interface 112, user input interface 114, and network interface 116, which can be linked together via one or more communication buses 118.
[0166] Storage medium 104 can be any form of non-volatile data storage device, such as one or more of hard disk drives, magnetic disks, solid-state storage devices, optical disks, ROMs, etc. Storage medium 104 can store an operating system for the processor 108 to execute in order to enable the computer 102 to function. Storage medium 104 can also store one or more computer programs (or software or instructions or code).
[0167] The memory 106 may be any random access memory (memory cell or volatile storage medium) suitable for storing data and / or computer programs (or software or instructions or code).
[0168] Processor 108 may be any data processing unit adapted to execute one or more computer programs (such as those stored on storage medium 104 and / or memory 106), some of which may be computer programs according to embodiments of the invention, or computer programs that, when executed by processor 108, cause processor 108 to perform methods according to embodiments of the invention and configure system 100 as a system according to embodiments of the invention. Processor 108 may include a single data processing unit, or multiple data processing units that operate in parallel, individually, or cooperatively with each other. In performing data processing operations according to embodiments of the invention, processor 108 may store data to storage medium 104 and / or memory 106, and / or read data from storage medium 104 and / or memory 106.
[0169] Interface 110 can be any unit that provides an interface to device 122, which is external to or removable from computer 102. Device 122 can be one or more data storage devices, such as optical discs, hard disks, solid-state storage devices, etc. Device 122 can have processing capabilities—for example, it can be a smart card. Therefore, interface 110 can access data from device 122, provide data to device 122, or interface with device 122 based on one or more commands it receives from processor 108.
[0170] User input interface 114 is configured to receive input from a user or operator of system 100. The user provides this input via one or more input devices (such as a microphone 125, a mouse (or other pointing device) 126, a camera (e.g., a webcam or integrated camera) 127, a fingerprint reader / detector 128, and / or a keyboard 124) connected to or communicating with user input interface 114. However, it will be appreciated that the user may provide input to computer 102 via one or more additional or alternative input devices (such as a touchscreen). Computer 102 may store the input received from the input device via user input interface 114 in memory 106 for subsequent access and processing by processor 108, or may pass it directly to processor 108 so that processor 108 can respond accordingly to the user input.
[0171] User output interface 112 is configured to provide graphical / visual and / or auditory output to a user or operator of system 100. Thus, processor 108 may be configured to instruct user output interface 112 to generate an image / video signal representing desired graphical output and to provide such signal to a monitor (or screen or display unit) 120 of system 100 connected to user output interface 112. Additionally or alternatively, processor 108 may be configured to instruct user output interface 112 to generate an audio signal representing desired audio output and to provide such signal to one or more speakers 121 of system 100 connected to user output interface 112.
[0172] Network interface 116 provides functionality for enabling computer 102 to download data from one or more data communication networks and / or upload data to one or more data communication networks.
[0173] What will be understood is that, Figure 1 The architecture of the system 100 illustrated and described above is merely exemplary, and different architectures (e.g., having a higher degree of integration) can be used in embodiments of the invention. Figure 1 The components shown are fewer, or with Figure 1 The components shown are compared to other computer systems 100 that have additional and / or alternative components. As an example, computer system 100 may include one or more of the following: personal computer; server computer; mobile phone; tablet device; laptop; television; set-top box; game console; other mobile device or consumer electronics device; and so on. Additionally, it is possible that some components of computer system 100 are not located in a personal computer, server system, or laptop, and are part of a computer network connected to the personal computer, server system, or laptop via network interface 116, and are located in the cloud of the computer network, or in a small computer device such as a mobile phone, smartphone, or smartwatch.
[0174] As discussed above, embodiments of the present invention perform biometric authentication so as to: given input provided by (or derived from) a first user U1 and based on (or representing) one or more biological / biometric characteristics of the first user U1. X In the case of determining whether the first user U1 is a reserved or specific user U1 D The first user U1 can be a user of computer system 100. In embodiments where the biological / biometric characteristics of the user U1 used to perform biometric authentication relate to aspects / features of the user's face or(s) eyes, then the input... XThis can be based on an image (of the user U1's face or(one or more) eyes) captured via camera 127. In embodiments where the biological / biometric characteristics of the user U1 used to perform biometric authentication relate to aspects / features of the user's voice, then the input... X This can be based on audio / sound captured / recorded via microphone 125 (of user U1's voice). In embodiments where the biological / biometric characteristics of user U1 used to perform biometric authentication involve aspects / features of one or more user fingerprints, then the input... X Input based on fingerprint data (from one or more fingers of user U1) captured via fingerprint reader / detector 128 can be obtained from the first user U1. It will be appreciated that embodiments of the invention may utilize additional or alternative mechanisms (e.g., via user input interface 114 and / or via interface 110 and device 122) to obtain input from the first user U1 based on one or more biological / biometric characteristics of the first user U1. X .
[0175] In some embodiments of the present invention, biometric authentication is performed at the device of the first user U1, for example if the first user U1 is attempting to gain access to or log in to a mobile phone, laptop, personal computer, etc.
[0176] However, in other embodiments (which can be equally applied to situations where a first user U1 is attempting to gain access to or log in to a mobile phone, laptop, personal computer, etc.), at least some of the processes for biometric authentication can be performed separately from the device that initially receives input from user U1. Figure 2A system 200 for performing biometric authentication according to some such embodiments is schematically illustrated. System 200 may include user equipment 202, one or more servers 204 (and / or other devices / systems remote from / separated from user equipment 202), and one or more networks 206. For example, system 200 may provide cloud-based biometric authentication services. User equipment 202 and one or more servers 204 may be arranged to communicate with each other via or through network 206. Network 206 may be any kind of network suitable for transmitting or sending data from any of user equipment 202 and one or more servers 204 to another. For example, network 206 may include one or more of a local area network (LAN), wide area network (WAN), metropolitan area network (MAN), the Internet, wireless communication networks, cable networks, digital broadcasting networks, satellite communication networks, telephone networks, etc. User equipment 202 and one or more servers 204 may communicate on network 206 via any suitable communication mechanism / protocol to send data to each other. However, it will be appreciated that other communication scenarios are possible. User equipment 202 and one or more servers 204 may all be or may all include the above reference. Figure 1 The described one or more computer systems 100. For example, user equipment 202 and / or one or more servers 204 may be personal computers, server computers, laptops, mobile phones, tablet computers, televisions, etc.
[0177] For example, in Figure 2 In the case of system 200 shown, user equipment 202 can be used by a first user U1, wherein input X The input is obtained from the first user U1 at user equipment 202. User equipment 202 can then be configured to send / provide the obtained input to one or more servers 204 via network 206. X This allows one or more servers 204 to process the received input. X This performs biometric authentication for the first user U1. For example, the first user U1 might be attempting to access a service (e.g., financial / banking services) provided by one or more servers 204 that requires biometric authentication—if user U1's identity has already been verified based on input... X If the user's biometric authentication is verified, then one or more servers 204 can be configured to provide this service only to user U1. Alternatively, one or more servers 204 can simply be configured to... X To perform biometric authentication, and then provide the result of the biometric authentication back to user equipment 202 (for further processing by user equipment 202).
[0178] It will be understood that other deployment scenarios are possible, where various stages of the processing for biometric authentication are performed at different locations and / or by different entities.
[0179] 3 - Implementation of Biometric Authentication
[0180] Figure 5 This is a flowchart illustrating a method 500 for performing biometric authentication for a first user U1 according to some embodiments of the present invention. Method 500 can be performed by an authentication system (or module) – as mentioned above, the authentication system can take the following steps: Figure 1 The computer system 100 shown in the diagram (in isolation), as... Figure 2 The diagram shows a more distributed system 200, or any other processing architecture capable of executing method 500.
[0181] As discussed above, method 500 may involve performing one or more first tests, and optionally (depending on the result of one or more first tests) performing a second test. In method 500, steps 502-510 are steps that can be performed for the first test, some or all of which may be performed, while steps 506, 510, 514, and 516 are steps that can be performed for the second test, some or all of which may be performed. However, it will be appreciated that the first and second tests may use different sets of steps and / or use these steps but in a different order. In either case, the result of method 500 is either determining at step 506 that the first user U1 is not the intended user U D Either at step 510 it is determined that the first user U1 is the reserved user U D .
[0182] At step 502, the authentication system obtains the corresponding first input for the (current) first test being performed. X (j) The first input X (j) It is obtained based on one or more biological / biometric characteristics of the first user U1. The first input has already been discussed above. X (j) Properties and methods for obtaining the first input X (j) The methods and system components. The first user U1 can be prompted to interact with the authentication system, for example, through messages displayed on monitor 120, in order to provide / generate first input. X (j)(For example, by posing for an image to be captured by camera 127, or by speaking so that audio can be recorded by microphone 125, or by placing one or more fingers on fingerprint reader / detector 128 so that fingerprint data can be obtained).
[0183] At step 504, the authentication system determines whether the ratio between the first likelihood and the second likelihood, or the corresponding first log-likelihood ratio for the first likelihood and the second likelihood (for the (current) first test being performed), exceeds a first corresponding threshold (for the (current) first test being performed), wherein the first likelihood is obtained based on the first model to obtain the corresponding first input. X (j) The likelihood, in the first model, is that the input is from the pre-defined user U. D The second likelihood is obtained based on the second model to obtain the corresponding first input. X (j) The likelihood of the input in the second model is not from the pre-defined user U. D The obtained (i.e., when the input is from a user other than the pre-defined user U) D (When one or more users other than the one mentioned above are acquired).
[0184] Therefore, in some embodiments, the first and second models are respectively l g and l i And the first and second likelihoods are p ( X (j) | l g )and p ( X (j) | l i Step 504 may involve calculating the corresponding first log-likelihood ratio. r ( X (j) )=log p(X (j) | l g )−log p(X (j) | l i ), and identify the first threshold. i L (j) ,whether r ( X (j) )≤ i L (j) Alternatively, in At that time, step 504 may involve calculations. And indicate whether This is equivalent to determining whether r ( X (j) )≤ i L (j) It will be understood that there are other ways to test the corresponding log-likelihood ratio against the corresponding first threshold (e.g., calculating a metric / value based on the ratio between the first likelihood and the second likelihood, and comparing the metric / value against the threshold based on the corresponding first threshold), and some embodiments may therefore not actually involve directly calculating the log-likelihood ratio.
[0185] In some embodiments, two separate models can be implemented and maintained. l g and l i And can be calculated separately. p ( X (j) | l g )and p ( X (j) | l i (This allows, for example, the calculation) r ( X (j) )=log p(X (j) | l g )−log p(X (j) | l i Or it can be calculated In other embodiments, calculation can be performed without explicit computation. p ( X (j) | l g ) and / or p ( X (j) | l i In the case of ), calculate log p(X (j) | l g )−log p(X (j) | l i ), or ratio or first and second likelihood p ( X (j) | l g )and p ( X (j) | l i Other relationships between them can be determined accordingly in step 504.
[0186] If the corresponding first log-likelihood ratio does not exceed the corresponding first threshold, the process proceeds to step 506, where the authentication system determines that the first user U1 is not the intended user U. D Therefore, when the corresponding first log-likelihood ratio does not exceed the corresponding first threshold (or in response to the corresponding first log-likelihood ratio not exceeding the corresponding first threshold), the authentication system determines that the first user U1 is not the intended user U. D Then, subsequent steps can be performed depending on the nature and purpose of the biometric authentication; for example, the first user U1 can be denied access to devices, data, or services for which biometric authentication is required.
[0187] Otherwise, processing continues at step 508, where the authentication system determines whether the corresponding first log-likelihood ratio exceeds a corresponding second threshold, wherein the second threshold is greater than the first threshold. Continuing the example above, step 508 can identify whether the second threshold... i R (j) ,whether r ( X (j) )> i R (j) Similar to step 504, there are other ways to implement step 508 (e.g., calculating a metric / value based on the ratio between a first likelihood and a second likelihood, and comparing that metric / value to a threshold based on a corresponding second threshold). For example, step 508 could involve determining whether... .
[0188] Similar to step 504, for step 508, in some embodiments, two separate models can be implemented and maintained. l g and l i And can be calculated separately. p ( X (j) | l g )and p ( X(j) | l i (This allows, for example, the calculation) r ( X (j) )=log p(X (j) | l g )−log p(X (j) | l i ), or can be calculated In other embodiments, calculation can be performed without explicit computation. p ( X (j) | l g ) and / or p ( X (j) | l i In the case of ), calculate log p(X (j) | l g )−log p(X (j) | l i ), or ratio or first and second likelihood p ( X (j) | l g )and p ( X (j) | l i Other relationships between them can be determined accordingly in step 508.
[0189] If the corresponding first log-likelihood exceeds the corresponding second threshold, the process proceeds to step 510, where the authentication system determines that the first user U1 is the pre-selected user U. D Therefore, when the corresponding first log-likelihood exceeds the corresponding second threshold (or in response to the corresponding first log-likelihood exceeding the corresponding second threshold), the authentication system determines that the first user U1 is the intended user U. D Then, subsequent steps can be performed depending on the nature and purpose of the biometric authentication; for example, the first user U1 may be allowed access to devices, data, or services for which biometric authentication is required.
[0190] Otherwise, the process continues at step 512, where the authentication system determines whether to perform another first test or to perform a second test. Specifically, if the first test has been performed a predetermined maximum number of times, the process continues at step 514 to perform the second test; conversely, if the first test has been performed less than the predetermined maximum number of times, the process returns to step 502 to perform a further first test. Therefore, when the corresponding first log-likelihood ratio exceeds the corresponding first threshold and the corresponding first log-likelihood ratio does not exceed the corresponding second threshold, step 512 determines either (a) to perform a further first test when the number of times the first test has been performed is less than the predetermined maximum number of times, or (b) to perform the second test when the number of times the first test has been performed is equal to the predetermined maximum number of times.
[0191] In some embodiments, method 500 may involve using a counter. j This serves as an index for the current first test, indicating the number of times the first test has been executed. Therefore, method 500 can initially set a counter... j Initialize to 1. Step 512 can then involve testing whether... j = M (in M (This refers to the predetermined maximum number of times the first test can be performed on it) – following the mathematical foundation presented above, in this embodiment, M = N -1. If j = M If the condition is met, the process continues at step 514; otherwise, the counter... j The value can be incremented by 1, and the process can return at step 502. However, it will be appreciated that there are many other ways to determine whether to perform the additional first test or the second test—for example, a counter. j It can be initialized to a value M (in M (This refers to the predetermined maximum number of times the first test can be performed on it) – following the mathematical foundation presented above, in this embodiment, M = N -1. In this case, step 512 may involve testing whether... j =1: If j If the counter equals 1, then the process continues at step 514; otherwise, the counter... j The value can be reduced by 1, and the process can return at step 502. Other mechanisms can be used similarly.
[0192] At step 514, the authentication system obtains input based on one or more biological / biometric characteristics of the first user U1. X (N)This can be achieved by obtaining / acquiring (one or more) first inputs at step 502. X (j) It is executed in the same way.
[0193] At step 516, the authentication system determines whether the ratio between the third likelihood and the fourth likelihood, or the second log-likelihood ratio for the third likelihood and the fourth likelihood, exceeds a third threshold, wherein the third likelihood is based on a first model (where the input is from a pre-defined user U). D (obtained) and obtain input X (N) The likelihood of, and where the fourth likelihood is based on the second model described above (where the input is not from the pre-defined user U). D (obtained) and obtain input X (N) The likelihood of [the third and fourth likelihoods]. Continuing the example above, the third and fourth likelihoods can be respectively […]. p ( X (N) | l g )and p ( X (N) | l i As discussed above, step 516 may involve calculating the second log-likelihood ratio. r ( X (N) )=log p ( X (N) | l g )−log p ( X (N) | l i ), and identify the third threshold i (N) ,whether r ( X (N) )> i (N) Alternatively, Therefore, step 516 may involve calculations. And indicate whether This is equivalent to determining whether r ( X (N) )> i (N)It will be understood that there are other ways to test the log-likelihood ratio against a third threshold (e.g., to calculate a metric / value based on the ratio between the third and fourth likelihoods and to compare that metric / value against the threshold based on the third threshold), and some embodiments may therefore not actually involve directly calculating the log-likelihood ratio.
[0194] Similar to steps 504 and 508, in some embodiments, two separate models can be implemented and maintained. l g and l i And can be calculated separately. p ( X (N) | l g )and p ( X (N) | l i (This allows, for example, the calculation) r ( X (N) )=log p(X (N) | l g )−log p(X (N) | l i ), or can be calculated In other embodiments, log can be calculated without explicit computation. p(X (N) | l g ) and / or log p(X (N) | l i In the case of ), calculate log p(X (N) | l g )−log p(X (N) | l i ), or ratio or third and fourth likelihood p ( X (N) | l g )and p ( X (N) | l iOther relationships between them can be determined accordingly in step 516.
[0195] If the second log-likelihood exceeds the third threshold, the process proceeds to step 510, where the authentication system determines that the first user U1 is the intended user U. D Therefore, when the second log-likelihood exceeds the third threshold (or in response to the second log-likelihood exceeding the third threshold), the authentication system determines that the first user U1 is the intended user U. D As described above, subsequent steps can then be performed depending on the nature and purpose of the biometric authentication; for example, a first user U1 may be allowed access to devices, data, or services for which biometric authentication is required.
[0196] Otherwise, the process proceeds to step 506, where the authentication system determines that the first user U1 is not the intended user U. D Therefore, when the second log-likelihood ratio does not exceed the third threshold (or in response to the second log-likelihood ratio not exceeding the third threshold), the authentication system determines that the first user U1 is not the intended user U. D Then, subsequent steps can be performed depending on the nature and purpose of the biometric authentication; for example, the first user U1 can be denied access to devices, data, or services for which biometric authentication is required.
[0197] As mentioned above, in some embodiments, the process never returns to step 502 because such embodiments can be arranged to perform exactly one first test (i.e., where...). M =1 (Example).
[0198] It will be understood that step 504 can be performed after step 508.
[0199] Figure 6 This is a flowchart illustrating a method 600 for operating an authentication system according to some embodiments of the present invention.
[0200] At step 602, one or more of the models used by the authentication system can be trained (or initialized) and / or updated. As discussed, biometric authentication can be model-based. l g and l i .
[0201] The details of this training / initialization have been explained above.
[0202] At step 604, one or more of the aforementioned thresholds for performing biometric authentication can be determined. The techniques for determining the thresholds have been described above. These thresholds can then be considered as predetermined thresholds—that is, they become predetermined once (and potentially based on one or more targets of false acceptance and false rejection) once (one or more) the model(s) have been trained.
[0203] At step 606, the authentication system can be configured. For example, the authentication system can be configured to use the threshold determined at step 604. Additionally, the authentication system can be configured to use any further updated parameters (e.g., if a maximum number of times is predetermined). M (It has been updated).
[0204] At step 608, the authentication system can then perform biometric authentication using the method 500 discussed above. As illustrated by dashed 610, the authentication system can perform multiple separate biometric authentications. As mentioned above, the number of consecutive times this can be performed when each separate biometric authentication involves more than one test can be limited to a predetermined maximum value—if this maximum value is reached, one or more further measures can be taken (e.g., the system or device may become locked, requiring a system administrator to unlock the system / device; model). l g It may require retraining; etc.
[0205] As illustrated by dotted line 612, the process can return to step 602, where the model(s) can be updated and / or retrained. For example, the model... l g It can be based on the time from the pre-booked user U D Additional biometric data acquired / collected (e.g., based on input obtained from the user each time a pre-defined user undergoes biometric authentication). X (j) and / or X (N) The model is periodically updated or retrained. In this way, the authentication system can be adapted to specific users over time, allowing the model to continuously improve. l g It can become more accurate and make false rejections less frequent.
[0206] 4 - Revision
[0207] It will be understood that the described method has been shown as individual steps performed in a specific order. However, those skilled in the art will appreciate that these steps can be combined or performed in different orders while still achieving the desired result.
[0208] What will be understood is that, instead, different statistical tests can be used (in addition to using the log-likelihood ratio).
[0209] It will be understood that embodiments of the invention can be implemented using a variety of different information processing systems. In particular, although the accompanying drawings and discussion provide exemplary computing systems and methods, these are presented merely to provide useful reference in discussing the various aspects of the invention. Embodiments of the invention can be implemented on any suitable data processing device, such as a personal computer, laptop, personal digital assistant, mobile phone, set-top box, television, server computer, etc. Of course, for the purposes of discussion, the descriptions of the systems and methods have been simplified, and they are merely one of many different types of systems and methods that can be used in embodiments of the invention. It will be understood that the boundaries between logical blocks are merely illustrative, and alternative embodiments may combine logical blocks or elements, or may impose alternative decompositions of functionality under various logical blocks or elements.
[0210] It will be understood that the functions mentioned above can be implemented as one or more corresponding modules in hardware and / or software. For example, the functions mentioned above can be implemented as one or more software components for execution by the system's processor. Alternatively, the functions mentioned above can be implemented as hardware, such as one or more field-programmable gate arrays (FPGAs), and / or one or more application-specific integrated circuits (ASICs), and / or one or more digital signal processors (DSPs), and / or one or more graphics processing units (GPUs) and / or other hardware arrangements. The method steps implemented in the flowcharts included herein or described above can all be implemented by their respective corresponding modules; multiple method steps implemented in the flowcharts included herein or described above can be implemented together by a single module.
[0211] It will be understood that, to the extent that embodiments of the invention are implemented by computer programs, one or more storage media and / or one or more transmission media storing or carrying the computer program form aspects of the invention. A computer program may have one or more program instructions or program code that, when executed by one or more processors (or one or more computers), implement embodiments of the invention. As used herein, the term "program" can be a sequence of instructions designed to execute on a computer system and may include subroutines, functions, procedures, modules, object methods, object implementations, executable applications, applets, service programs, source code, object code, bytecode, shared libraries, dynamic link libraries, and / or other sequences of instructions designed to execute on a computer system. Storage media may be disks (such as hard disks or floppy disks), optical disks (such as CD-ROMs, DVD-ROMs, or Blu-ray discs), or memory (such as ROMs, RAMs, EEPROMs, EPROMs, flash memory, or portable / removable memory devices), etc. Transmission media may be communication signals, data broadcasts, communication links between two or more computers, etc.
Claims
1. A method for performing biometric authentication for a first user, the method comprising: Execute one or more first tests, wherein for each first test, executing the first test includes: The first input for the first test is obtained based on one or more biometric features of the first user; When the ratio of the corresponding first log-likelihood of the first likelihood and the second likelihood does not exceed the corresponding first threshold of the first test, it is determined that the first user is not the intended user, wherein the first likelihood is the likelihood of the corresponding first input obtained based on a first model, in which the input is obtained from the intended user, and wherein the second likelihood is the likelihood of the corresponding first input obtained based on a second model, in which the input is obtained from one or more users other than the intended user; When the corresponding first log-likelihood ratio exceeds the corresponding second threshold of the first test, the first user is determined to be the predetermined user, and the corresponding second threshold is greater than the corresponding first threshold; and When the corresponding first log-likelihood ratio exceeds the corresponding first threshold and the corresponding first log-likelihood ratio does not exceed the corresponding second threshold, either (a) determine to execute a further first test when the number of times the first test has been executed is less than the predetermined maximum number of times, or (b) determine to execute a second test when the number of times the first test has been executed is equal to the predetermined maximum number of times; The second test includes: The second input for the second test is obtained based on one or more biometric features of the first user; and When the ratio of the second log-likelihood of the third likelihood and the fourth likelihood exceeds the third threshold, the first user is determined to be the predetermined user, wherein the third likelihood is based on the likelihood of the first model receiving the corresponding second input, and wherein the fourth likelihood is based on the likelihood of the second model receiving the second input. When the second log-likelihood ratio does not exceed the third threshold, it is determined that the first user is not the intended user.
2. The method of claim 1, wherein for each first test, the corresponding first log-likelihood ratio is r(X). (j) ) = log p(X (j) |λ g )-log p(X (j) |λ i ), where X (j) It is the corresponding first input of the first test, λ g It is the first model, and λ i It is the second model.
3. The method of claim 2, wherein determining that the first user is not the intended user for each first test, when the corresponding first log-likelihood ratio of the first likelihood and the second likelihood does not exceed a corresponding first threshold, comprises one of the following steps: (a) Calculate r(X) (j) ), and if r(X) (j) )<θ L (j) If θ is not the pre-booked user, then it is determined that the first user is not the pre-booked user. L (j) It is the corresponding predetermined threshold for the first test; or (b) Calculation And if Then it is determined that the first user is not the pre-booked user, where θ L (j) It is the corresponding predetermined threshold for the first test; or (c) Calculate a metric based on the ratio between the first likelihood and the second likelihood, and compare the metric with a threshold based on a corresponding first threshold.
4. The method of claim 2 or 3, wherein determining that a first user is the intended user when the corresponding first log-likelihood ratio exceeds the corresponding second threshold for each first test comprises one of the following steps: (a) Calculate r(X) (j) ), and if r(X) (j) )>θ R (j) Then, the first user is determined to be the pre-booked user, where θ R (j) It is the corresponding predetermined threshold for the first test; or (b) Calculation And if Then the first user is determined to be the pre-booked user, where θ R (j) It is the corresponding predetermined threshold for the first test; or (c) Calculate a metric based on the ratio between the first likelihood and the second likelihood, and compare the metric with the threshold based on the corresponding second threshold.
5. The method according to any one of claims 1 to 3, wherein the second log-likelihood ratio is r(X) (N) ) = logp(X (N) |λ g )-log p(X (N) |λ i ), where X (N) It is the second input, λ g It is the first model, and λ i It is the second model.
6. The method of claim 5, wherein determining that the first user is the predetermined user when the second log-likelihood ratio of the third likelihood and the fourth likelihood exceeds a third threshold comprises one of the following steps: (a) Calculate r(X) (N) ), and if r(X) (N) )>θ (N) Then, the first user is determined to be the pre-booked user, where θ (N) It is a predetermined threshold; or (b) Calculation And if Then the first user is determined to be the pre-booked user, where θ (N) It is a predetermined threshold; or (c) Calculate a metric based on the ratio between the third likelihood and the fourth likelihood, and compare the metric with a threshold based on a third threshold.
7. The method according to any one of claims 1 to 3, wherein the one or more biometric features are based on one or more of the following: the face of a first user; the voice of a first user; one or more fingerprints of a first user; one or more eyes of a first user.
8. A system configured to perform biometric authentication for a first user, the system being adapted to: Execute one or more first tests, wherein for each first test, executing the first test includes: The first input for the first test is obtained based on one or more biometric features of the first user; When the ratio of the corresponding first log-likelihood of the first likelihood and the second likelihood does not exceed the corresponding first threshold of the first test, it is determined that the first user is not the intended user, wherein the first likelihood is the likelihood of the corresponding first input obtained based on a first model, in which the input is obtained from the intended user, and wherein the second likelihood is the likelihood of the corresponding first input obtained based on a second model, in which the input is obtained from one or more users other than the intended user; When the corresponding first log-likelihood ratio exceeds the corresponding second threshold of the first test, the first user is determined to be the predetermined user, and the corresponding second threshold is greater than the corresponding first threshold. as well as When the corresponding first log-likelihood ratio exceeds the corresponding first threshold and the corresponding first log-likelihood ratio does not exceed the corresponding second threshold, either (a) determine to execute a further first test when the number of times the first test has been executed is less than the predetermined maximum number of times, or (b) determine to execute a second test when the number of times the first test has been executed is equal to the predetermined maximum number of times; The second test includes: The second input for the second test is obtained based on one or more biometric features of the first user; and When the ratio of the second log-likelihood of the third likelihood and the fourth likelihood exceeds the third threshold, the first user is determined to be the predetermined user, wherein the third likelihood is based on the likelihood of the first model receiving the corresponding second input, and wherein the fourth likelihood is based on the likelihood of the second model receiving the second input. When the second log-likelihood ratio does not exceed the third threshold, it is determined that the first user is not the intended user.
9. The system of claim 8, wherein for each first test, the corresponding first log-likelihood ratio is r(X). (j) ) = log p(X (j) |λ g )-log p(X (j) |λ i ), where X (j) It is the corresponding first input of the first test, λ g It is the first model, and λ i It is the second model.
10. The system of claim 9, wherein determining that a first user is not the intended user for each first test, when the corresponding first log-likelihood ratio of the first likelihood and the second likelihood does not exceed a corresponding first threshold, comprises one of the following steps: (a) Calculate r(X) (j) ), and if r(X) (j) )<θ L (j) If θ is not the pre-booked user, then it is determined that the first user is not the pre-booked user. L (j) It is the corresponding predetermined threshold for the first test; or (b) Calculation And if Then it is determined that the first user is not the pre-booked user, where θ L (j) It is the corresponding predetermined threshold for the first test; or (c) Calculate a metric based on the ratio between the first likelihood and the second likelihood, and compare the metric with a threshold based on a corresponding first threshold.
11. The system of claim 9 or 10, wherein determining that a first user is the intended user for each first test when the corresponding first log-likelihood ratio exceeds the corresponding second threshold comprises one of the following steps: (a) Calculate r(X) (j) ), and if r(X) (j) )>θ R (j) Then, the first user is determined to be the pre-booked user, where θ R (j) It is the corresponding predetermined threshold for the first test; or (b) Calculation And if Then the first user is determined to be the pre-booked user, where θ R (j) It is the corresponding predetermined threshold for the first test; or (c) Calculate a metric based on the ratio between the first likelihood and the second likelihood, and compare the metric with the threshold based on the corresponding second threshold.
12. The system according to any one of claims 8 to 10, wherein the second log-likelihood ratio is r(X) (N) ) = log p(X (N) |λ g )-log p(X (N) |λ i ), where X (N) It is the second input, λ g It is the first model, and λ i It is the second model.
13. The system of claim 12, wherein determining that the first user is the predetermined user when the second log-likelihood ratio of the third likelihood and the fourth likelihood exceeds a third threshold includes one of the following steps: (a) Calculate r(X) (N) ), and if r(X) (N) )>θ (N) Then, the first user is determined to be the pre-booked user, where θ (N) It is a predetermined threshold; or (b) Calculation And if Then the first user is determined to be the pre-booked user, where θ (N) It is a predetermined threshold; or (c) Calculate a metric based on the ratio between the third likelihood and the fourth likelihood, and compare the metric with a threshold based on a third threshold.
14. The system according to any one of claims 8 to 10, wherein the one or more biometric features are based on one or more of the following: the face of a first user; the voice of a first user; one or more fingerprints of a first user; one or more eyes of a first user.
15. A computer program product comprising instructions that, when executed by one or more processors, cause the one or more processors to perform the method according to any one of claims 1 to 7.
16. A computer-readable medium storing a computer program that, when executed by one or more processors, causes the one or more processors to perform the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Biometric authentication system, authentication client terminal, and biometric authentication method
CN101571920A
Systems and methods for performing fingerprint based user authentication using imagery captured using mobile devices
CN107438854A