Authentication method and authentication system
By using local hash function and Hamming distance calculation in hidden state, the problem of long processing time in secure calculation based on secret sharing method is solved, and fast and secure authentication processing is achieved.
Patent Information
- Application Number
- CN202380090445.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-06-27
- Filing Date
- 2023-10-31
- Publication Date
- 2025-08-08
AI Technical Summary
Security calculation based on secret sharing method takes a long time in authentication processing, resulting in inefficient processing.
The local hash function is used to calculate the hash value in an obscure state, and through the XOR operation and Hamming distance method, the registered feature quantity used for authentication processing is quickly selected to reduce the calculation quantity and communication quantity.
The speed of authentication processing is accelerated, processing efficiency is improved, and the obscurity and security of feature quantities are ensured.
Smart Images

Figure CN120457429A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to an authentication method and the like in which an authentication (identity verification) system performs authentication processing of biometric information (biometric information) in a hidden (confidential) state through secure computation (multi-party secure computation) based on a secret sharing method (scheme). Background Art
[0002] As a technology related to the secret sharing method, there is a technology described in Non-Patent Document 1. Non-Patent Document 1 proposes a privacy-preserving nearest neighbor search.
[0003] Prior art literature
[0004] Non-patent literature
[0005] Non-Patent Literature 1: "Privacy-Preserving Approximate Nearest Neighbor Search: A Construction and Experimental Results", Computer Security Symposium 2019 Summary of the Invention
[0006] Problems to be solved by the invention
[0007] However, in secure computations based on secret sharing, since multiple computing devices perform computations while communicating with each other, the computations take time, and therefore the authentication process performed by such secure computations also takes time.
[0008] Therefore, an authentication method or the like is provided that can speed up the authentication process performed by secure calculation based on a secret sharing method.
[0009] Technical solutions to solve problems
[0010] A technical solution disclosed herein involves an authentication method in which an authentication system performs authentication processing of biometric information in a concealed state through secure calculation based on a secret sharing method, comprising: in a concealed state, using a locality-preserving hash function to calculate a hash value based on a first feature quantity of the biometric information; converting the hash value from a first integer share (share, fragment) to a binary share, wherein the first integer share is a share of a secret share that uses an integer with a first bit (bit) number to split (disperse, divide, distribute) a value, and the binary share is a share of a secret share that uses bits to split a value; in the conversion of the hash value Then, in a concealed state, a step of calculating an XOR bit string by performing an XOR operation on the hash value and a registered (registered) hash value; a step of converting the XOR bit string from the binary share to a second integer share, wherein the second integer share is a share of the secret share of the value split using an integer of a second digit smaller than the first digit; a step of calculating, in a concealed state, a Hamming distance between the hash value and the registered hash value by calculating the sum of multiple bit values contained in the XOR bit string after the conversion of the XOR bit string; and a step of using the Hamming distance to determine whether the registration feature quantity corresponding to the registered hash value is used for the authentication process.
[0011] In addition, these general or specific technical solutions can be implemented through systems, devices, methods, integrated circuits, computer programs, or non-transitory recording media such as computer-readable CD-ROMs, or through any combination of systems, devices, methods, integrated circuits, computer programs, and recording media.
[0012] Effects of the Invention
[0013] According to an authentication method and the like according to one technical solution of the present disclosure, it is possible to speed up the authentication process performed by secure calculation based on a secret sharing method. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 This is a block diagram showing the configuration (structure) of the authentication system in the embodiment.
[0015] Figure 2 This is a block diagram showing the configuration of a terminal device in an embodiment.
[0016] Figure 3 This is a block diagram showing the configuration of a providing device in an embodiment.
[0017] Figure 4 This is a block diagram showing the configuration of a computing device in an embodiment.
[0018] Figure 5This is a block diagram showing the configuration of an authentication device in an embodiment.
[0019] Figure 6 This is a timing chart showing the operation (work) in the initialization phase (phase) in the embodiment.
[0020] Figure 7 This is a sequence diagram showing operations in the registration phase in the embodiment.
[0021] Figure 8 This is a sequence diagram showing the registration process in the embodiment.
[0022] Figure 9 This is a sequence diagram showing the operations in the authentication phase in the embodiment.
[0023] Figure 10 This is a sequence diagram showing the authentication process in the embodiment.
[0024] Figure 11 It is a schematic diagram showing a table in the embodiment.
[0025] Figure 12 This is a conceptual diagram showing a display screen of an authentication result in the embodiment.
[0026] Figure 13 This is a block diagram showing the configuration of a providing device in Modification 1.
[0027] Figure 14 This is a timing chart showing the operation in the initialization phase in Modification Example 1.
[0028] Figure 15 This is a sequence diagram showing the authentication process in Modification 1.
[0029] Figure 16 This is a sequence diagram showing the registration process in Modification Example 2.
[0030] Figure 17 This is a block diagram showing the configuration of a terminal device in Modification 3.
[0031] Figure 18 This is a block diagram showing the configuration of a providing device in Modification 3.
[0032] Figure 19 This is a block diagram showing the configuration of a computing device in Modification 3.
[0033] Figure 20 This is a block diagram showing the configuration of an authentication device in Modification 3.
[0034] Figure 21 This is a timing chart showing the operation in the initialization phase in Modification Example 3.
[0035] Figure 22 This is a sequence diagram showing the operation in the registration phase in Modification 3.
[0036] Figure 23 This is a sequence diagram showing the registration process in Modification 3.
[0037] Figure 24 This is a sequence diagram showing the operations in the authentication phase in Modification 3.
[0038] Figure 25 This is a sequence diagram showing the authentication process in Modification 3.
[0039] Figure 26 This is a block diagram showing the configuration of a terminal device in Modification 4.
[0040] Figure 27 This is a block diagram showing the configuration of a providing device in Modification 4.
[0041] Figure 28 This is a block diagram showing the configuration of a computing device in Modification 4.
[0042] Figure 29 This is a block diagram showing the configuration of an authentication device in Modification 4.
[0043] Figure 30 This is a timing chart showing the operation in the initialization phase in Modification Example 4.
[0044] Figure 31 This is a sequence diagram showing the operation in the registration phase in Modification 4.
[0045] Figure 32 This is a sequence diagram showing the registration process in Modification 4.
[0046] Figure 33 This is a sequence diagram showing the operation of the authentication phase in Modification Example 4.
[0047] Figure 34 This is a sequence diagram showing the authentication process in Modification 4.
[0048] Figure 35 It is a block diagram showing the configuration of an authentication system in the embodiment and multiple modifications.
[0049] Figure 36 This is a flowchart showing the operation of the authentication system in the embodiment and multiple modifications. DETAILED DESCRIPTION
[0050] Advances in machine learning have made it possible to convert multiple facial images into multiple feature quantities, and to use these features to calculate the similarity between multiple facial images. This has enabled highly accurate face authentication, leading to the development of various face authentication services.
[0051] Facial images used for authentication are private information and are therefore best kept secret (hidden) from anyone other than the user. Furthermore, it is known that facial images can be inferred from feature values. Therefore, not only the facial image but also the feature values should be kept secret from anyone other than the user. Furthermore, the learning model that converts facial images into feature values for face authentication, for example, is the property of the service provider. Public disclosure of such a learning model could lead to misuse. Therefore, it is also best to keep the learning model confidential.
[0052] Therefore, for example, the facial image, feature quantity, and learning model are kept secret using a secret sharing method. Then, through secure calculation based on the secret sharing method, authentication processing is performed while the facial image, feature quantity, and learning model remain secret.
[0053] In this authentication process, during the registration phase, multiple features corresponding to multiple facial images of multiple users are registered in a table, hidden. Then, during the authentication phase, features are derived from the user's facial images using a learning model through secure computation and compared with the features registered in the table. This allows authentication to proceed while maintaining the confidentiality of the facial images, features, and learning model.
[0054] On the other hand, this method uses secure computation to compare features derived from facial images with all features registered in a table. Furthermore, secure computation based on secret sharing requires time because multiple computing devices perform computations while communicating with each other. Therefore, the computational cost of secure computation to compare features derived from facial images with all features registered in a table becomes enormous.
[0055] Non-Patent Document 1 proposes a privacy-preserving nearest neighbor search. Specifically, a hash function is used to compress a vector into a Boolean vector with Boolean values as its elements. Furthermore, to calculate the distance between two vectors, the Hamming distance between the two Boolean vectors is calculated. This allows for a rapid nearest neighbor search. This nearest neighbor search can potentially speed up the authentication process.
[0056] However, in secure computations based on secret sharing, multiple computing devices perform computations while communicating with each other. Therefore, if processing efficiency is insufficient, communication traffic will increase, leading to processing delays. In secure computations based on secret sharing, the nearest neighbor search described in Non-Patent Document 1 may not be sufficiently efficient. Consequently, authentication processing performed using secure computations based on secret sharing may not be sufficiently fast.
[0057] Therefore, a technical solution of the present disclosure involves an authentication method of Example 1, in which an authentication system performs authentication processing of biometric information in a concealed state through secure calculation based on a secret sharing method, comprising: a step of calculating a hash value according to a first feature quantity of the biometric information using a locality-preserving hash function in a concealed state; a step of converting the hash value from a first integer share to a binary share, wherein the first integer share is a share of a secret share obtained by splitting a value using an integer of the first digit, and the binary share is a share of a secret share obtained by splitting a value using bits; after the conversion of the hash value, in a concealed state, The steps of calculating an XOR bit string by performing an exclusive OR operation on the hash value and the registration hash value; converting the XOR bit string from the binary share to a second integer share, wherein the second integer share is a share of a secret share using an integer whose second digit is smaller than the first digit; calculating the Hamming distance between the hash value and the registration hash value by calculating the sum of multiple bit values included in the XOR bit string in a concealed state after the conversion of the XOR bit string; and determining whether a registration feature corresponding to the registration hash value is used for the authentication process using the Hamming distance.
[0058] This allows efficient selection of registered features for authentication. Consequently, the computational complexity of the authentication process can be reduced. Furthermore, using binary shares, the XOR bit string can be efficiently calculated. Furthermore, using the second integer share corresponding to the integer number less than the first, the sum of the multiple bit values included in the XOR bit string can be efficiently calculated and represented. Consequently, the authentication process can be accelerated.
[0059] In addition, the authentication method of Example 2 involved in a technical solution of the present disclosure can also be based on the authentication method of Example 1. In the step of determining whether the registration feature corresponding to the registration hash value is used for the authentication process, when the Hamming distance between the hash value and the registration hash value is included in the first M Hamming distances in ascending order among the N Hamming distances between the hash value and the N registration hash values including the registration hash value, it is determined that the registration feature corresponding to the registration hash value is used for the authentication process.
[0060] This makes it possible to accurately select a registered feature amount corresponding to a registered hash value having a small Hamming distance with respect to the processing target hash value as a registered feature amount used for the authentication process.
[0061] In addition, the authentication method of Example 3 involved in a technical solution of the present disclosure may also be based on the authentication method of Example 1 or Example 2, and also include: when the registered feature quantity is used for the authentication process, the step of using the first feature quantity or the similarity between the second feature quantity obtained from the first feature quantity and the registered feature quantity to determine whether the authentication process is successful or not.
[0062] This makes it possible to accurately determine whether or not the biometric information authentication process is successful, using the similarity between the first feature amount or the second feature amount of the biometric information and the registered feature amount.
[0063] In addition, the authentication method of Example 4 involved in a technical solution of the present disclosure may also include, on the basis of the authentication method of any one of Examples 1 to 3, a step of releasing the hidden state of the Hamming distance, and in the step of determining whether the registered feature quantity is used for the authentication process, using the Hamming distance that has been released from the hidden state, determining whether the registration feature quantity corresponding to the registration hash value is used for the authentication process.
[0064] This can speed up the process of using the Hamming distance. Therefore, it is possible to speed up the process of determining whether the registered feature amount is used for the authentication process using the Hamming distance.
[0065] In addition, the authentication method of Example 5 involved in a technical solution of the present disclosure may also include, on the basis of the authentication method of Example 3, a step of releasing the hidden state of the similarity, and in the step of determining whether the authentication process is successful or not, the similarity that has been released from the hidden state is used to determine whether the authentication process is successful or not.
[0066] This can speed up the process of using the similarity. Therefore, it is possible to speed up the process of determining whether the authentication process is successful or not using the similarity.
[0067] In addition, in the authentication method of Example 6 according to one technical solution of the present disclosure, in addition to the authentication method of any one of Examples 1 to 5, the registration hash value may be converted from the first integer share to the binary share and registered.
[0068] This allows the process of converting the registered hash value from the first integer fraction to the binary fraction to be omitted during the authentication phase, thereby speeding up the authentication process.
[0069] In addition, the authentication method of Example 7 involved in a technical solution of the present disclosure may also include, based on the authentication method of any one of Examples 1 to 6, a step of secretly sharing the biometric information; and a step of calculating the first feature value used for the authentication process based on the biometric information in a hidden state.
[0070] This makes it possible to anonymize the process of calculating the first feature value used for the authentication process based on the biometric information, and to more reliably anonymize the first feature value used for the authentication process.
[0071] In addition, the authentication method of Example 8 involved in a technical solution of the present disclosure may also include, based on the authentication method of any one of Examples 1 to 6, a step of calculating the first feature value used for the authentication process based on the biometric information; and a step of secretly sharing the first feature value.
[0072] This makes it possible to quickly calculate the first feature value used for authentication processing based on biometric information, regardless of secure calculation using a secret sharing method.
[0073] In addition, the authentication method of Example 9 involved in a technical solution of the present disclosure may also include, based on the authentication method of any one of Examples 1 to 6,: a step of calculating the first feature value based on the biometric information; a step of secretly sharing the first feature value; and a step of calculating the second feature value used for the authentication process based on the first feature value in a hidden state.
[0074] This allows for rapid calculation of the first feature value based on biometric information, independent of secure calculations using secret sharing. Furthermore, the calculation of the second feature value used for authentication based on the first feature value can be made anonymous, making it possible to more reliably maintain the anonymity of the second feature value used for authentication.
[0075] In addition, the authentication method of Example 10 involved in a technical solution of the present disclosure may also include, based on the authentication method of Example 3 or Example 5, a step of calculating the similarity between the first feature quantity or the second feature quantity and the registered feature quantity using an intermediate value calculated and registered based on the registered feature quantity and independently of the first feature quantity or the second feature quantity.
[0076] This allows the calculation and registration of intermediate values for similarity calculation before the authentication phase, and the calculation of similarity during the authentication phase using the calculated and registered intermediate values, thereby speeding up the authentication process.
[0077] In addition, the authentication method of Example 11 involved in a technical solution of the present disclosure can also be based on the authentication method of any one of Examples 1 to 10, and the device for inputting the biometric information during the registration stage of the biometric information is the same as the device for inputting the biometric information during the authentication stage of the biometric information.
[0078] This allows authentication processing to be performed using a common device in both the registration and authentication stages, thereby simplifying the configuration of the authentication system.
[0079] In addition, the authentication method of Example 12 involved in a technical solution of the present disclosure may also include, based on the authentication method of any one of Examples 1 to 11, a step of obtaining the biometric information through a medium recording the biometric information during the registration stage of the biometric information.
[0080] This allows biometric information to be acquired through a medium rather than directly from a living body, thereby enabling more flexible preparation of registration hash values corresponding to biometric information.
[0081] Furthermore, a program according to Example 13 according to one aspect of the present disclosure is a program for causing a computer system to execute the authentication method according to any one of Examples 1 to 12.
[0082] This makes it possible to implement the authentication method as a program, thereby achieving the same effects as achieved by the authentication method through the program.
[0083] In addition, a technical solution of the present disclosure involves an authentication system of Example 14, which has a plurality of computing devices that perform authentication processing of biometric information in a concealed state through secure calculation based on a secret sharing method, wherein the plurality of computing devices, in a concealed state, use a hash function that maintains locality to calculate a hash value based on a first feature quantity of the biometric information; convert the hash value from a first integer share to a binary share, wherein the first integer share is a secret sharing share that uses an integer of the first digit to split the value, and the binary share is a secret sharing share that uses bits to split the value; after the conversion of the hash value, In a concealed state, an XOR bit string is calculated by performing an exclusive OR operation on the hash value and the registered hash value; the XOR bit string is converted from the binary share to a second integer share, where the second integer share is a share of the secret share using an integer whose second digit is smaller than the first digit; after the conversion of the XOR bit string, in a concealed state, the Hamming distance between the hash value and the registered hash value is calculated by calculating the sum of multiple bit values contained in the XOR bit string; and the Hamming distance is used to determine whether the registration feature corresponding to the registered hash value is used for the authentication process.
[0084] This allows efficient selection of registered features for authentication. Consequently, the computational complexity of the authentication process can be reduced. Furthermore, using binary shares, the XOR bit string can be efficiently calculated. Furthermore, using the second integer share corresponding to the integer number less than the first, the sum of the multiple bit values included in the XOR bit string can be efficiently calculated and represented. Consequently, the authentication process can be accelerated.
[0085] Furthermore, these general or specific technical solutions can be implemented through systems, devices, methods, integrated circuits, computer programs, or non-transitory recording media such as computer-readable CD-ROMs, or through any combination of systems, devices, methods, integrated circuits, computer programs, and recording media.
[0086] The following embodiments are described using the accompanying drawings. The embodiments described below are general or specific examples. The numerical values, shapes, materials, components, configuration positions of components, connection methods, steps, and the order of steps shown in the following embodiments are examples and are not intended to limit the scope of the claims.
[0087] Here, a facial image is used as biometric information. However, biometric information is not limited to facial images, and fingerprint information, retinal information, iris information, vein information, or DNA information may also be used.
[0088] Here, for example, capturing a face and generating a facial image may be referred to as capturing a facial image. Training a learning model corresponds to causing the learning model to learn.
[0089] In addition, encrypting information corresponds to splitting the information or making the information anonymous. In addition, decrypting information corresponds to releasing the information from the splitting or releasing the information from the anonymity (anonymization). In addition, here, decrypting the hidden information to obtain the information is sometimes simply expressed as decrypting the information.
[0090] In this example, three computing devices perform secure computations based on secret sharing. However, secure computations based on secret sharing can be performed by two computing devices or by four or more computing devices. Furthermore, secure computations based on secret sharing do not necessarily have to be performed by all computing devices; they can be performed by two of the computing devices.
[0091] (Implementation Method)
[0092] Figure 1 This is a block diagram showing the configuration of the authentication system in the embodiment. Figure 1, an authentication system 500 is shown. This computer system, also referred to as a hidden authentication system, performs biometric authentication using secure computations based on secret sharing. The authentication system 500 includes a terminal device 100, a provisioning device 200, computing devices 300, 310, and 320, and an authentication device 400.
[0093] The terminal device 100 is a user's computer device and can also be described as a user terminal device. During the registration phase, the terminal device 100 captures the user's facial image, encrypts the facial image based on a secret sharing method, and sends it to the computing devices 300, 310, and 320.
[0094] The providing device 200 is a computer device that provides data and can also be described as a server or a data providing device. The providing device 200 provides the threshold, feature learning model, and HashNet learning model to the computing devices 300 , 310 , and 320 .
[0095] Here, the threshold is used to determine authentication success or failure. A feature learning model is a learning model used to calculate feature quantities from facial images. Specifically, a facial image is input to the feature learning model, and the feature learning model outputs feature quantities. A HashNet learning model, also referred to simply as a HashNet, is a learning model used to calculate hash values from feature quantities. Specifically, the HashNet learning model inputs feature quantities and outputs a hash value.
[0096] Furthermore, feature quantities represent the characteristics of facial images and are used in authentication. Feature quantities can also be represented by vectors or tensors. In other words, feature quantities can also be expressed as feature vectors or feature tensors.
[0097] As the feature quantity learning model, ArcFace (registered trademark) or DeepFace can be used.
[0098] The HashNet learning model is an example of a locality-preserving hash function. Other locality-preserving hash functions can also be used in place of the HashNet learning model. Other locality-preserving hash functions can also be different from those used in the machine learning model. A locality-preserving hash function has the property that the closer two features are, the smaller the Hamming distance between their hash values.
[0099] Each of the computing devices 300, 310, and 320 is a computer device that performs data operations and may also be referred to as a data computing device. Specifically, during the registration phase, the computing devices 300, 310, and 320 receive a concealed facial image from the terminal device 100, calculate concealed feature quantities based on the concealed facial image, and perform registration processing based on the concealed feature quantities. Furthermore, during the authentication phase, the computing devices 300, 310, and 320 receive a concealed facial image from the authentication device 400, calculate concealed feature quantities based on the concealed facial image, and perform authentication processing based on the concealed feature quantities.
[0100] Authentication device 400 is a computer device that accepts authentication requests. Specifically, during the authentication phase, authentication device 400 captures a facial image of the user, encrypts the facial image using a secret sharing method, and transmits it to computing devices 300, 310, and 320. Furthermore, during the authentication phase, authentication device 400 receives a secret authentication result from computing devices 300, 310, and 320, decrypts the result, and utilizes it. For example, authentication device 400 may display the authentication result or perform processing corresponding to the authentication result.
[0101] Figure 2 1 is a block diagram showing the configuration of the terminal device 100 in the embodiment. The terminal device 100 includes a sensing unit 101 , a separation unit 102 , a storage unit 103 , and a communication unit 104 .
[0102] The sensing unit 101 is a sensor that senses biological information. Specifically, the sensing unit 101 captures a facial image of the user.
[0103] The splitting unit 102 is a processing circuit that encrypts information using a secret sharing method. Specifically, the splitting unit 102 encrypts the facial image captured by the sensing unit 101 to derive a concealed facial image. Furthermore, the splitting unit 102 obtains a user ID for identifying the user from the storage unit 103 and encrypts the user ID to derive a concealed user ID.
[0104] The storage unit 103 is a memory for storing information. The storage unit 103 may be a volatile memory or a non-volatile memory. Specifically, the storage unit 103 stores a user ID.
[0105] The communication unit 104 is a processing circuit for performing communication. Specifically, the communication unit 104 transmits the confidential feature value and the confidential user ID derived by the separation unit 102 to the arithmetic devices 300 , 310 , and 320 .
[0106] Figure 32 is a block diagram showing the configuration of the providing apparatus 200 in the embodiment. The providing apparatus 200 includes a learning model setting unit 201 , a threshold setting unit 202 , a splitting unit 203 , and a communication unit 204 .
[0107] The learning model setting unit 201 is a processing circuit that sets the learning model. Specifically, the learning model setting unit 201 trains a feature learning model and a HashNet learning model. More specifically, the learning model setting unit 201 trains the feature learning model to derive features from facial images that accurately determine authentication success or failure. Furthermore, the learning model setting unit 201 trains the HashNet learning model to derive hash values from features that exhibit the following property: the closer two features are, the smaller the Hamming distance between the two hash values.
[0108] The threshold setting unit 202 is a processing circuit that sets the threshold used in the authentication process. Specifically, the threshold setting unit 202 sets a threshold that accurately determines whether the authentication is successful or not. The threshold setting unit 202 can select a threshold from multiple threshold candidates or use machine learning to set the threshold.
[0109] The splitting unit 203 is a processing circuit that encrypts information based on a secret sharing method. Specifically, the splitting unit 203 encrypts the feature learning model, the HashNet learning model, and the threshold to derive the hidden feature learning model, the hidden HashNet learning model, and the hidden threshold.
[0110] The communication unit 204 is a processing circuit for performing communication. Specifically, the communication unit 204 transmits the hidden feature quantity learning model, the hidden HashNet learning model, and the hidden threshold to the computing devices 300 , 310 , and 320 .
[0111] Figure 4 This is a block diagram showing the configuration of a computing device 300 in an embodiment. The computing device 300 includes a storage unit 301, a secret feature calculation unit 302, a secret hash value calculation unit 303, a secret candidate extraction unit 304, a secret similarity calculation unit 305, a secret authentication unit 306, and a communication unit 307. The computing devices 310 and 320 also include multiple components similar to those included in the computing device 300.
[0112] The storage unit 301 is a memory for storing information. The storage unit 301 can be either volatile or non-volatile. Specifically, the storage unit 301 stores the hidden feature value learning model and hidden HashNet learning model sent from the provision device 200. Furthermore, the storage unit 301 stores the hidden facial image and hidden user ID sent from the terminal device 100. Furthermore, the storage unit 301 stores the hidden facial image sent from the authentication device 400.
[0113] Furthermore, multiple private hash values, private features, and private user IDs for multiple users are stored in the storage unit 301. Specifically, the private hash values, private features, and private user IDs for multiple users are stored in a table (registered user table) within the storage unit 301.
[0114] The above information is divided based on the secret sharing method and stored in the three storage units 301 of the computing devices 300 , 310 and 320 .
[0115] The hidden feature calculation unit 302 is a processing circuit within the computing devices 300, 310, and 320 that performs secure computations based on a secret sharing method. Specifically, the hidden feature calculation unit 302 calculates hidden features based on the hidden facial image and the hidden feature learning model. More specifically, the hidden feature calculation unit 302 derives hidden features from the hidden facial image using the hidden feature learning model.
[0116] The secret hash value calculation unit 303 is a processing circuit within the computing devices 300, 310, and 320 that performs secure calculations based on secret sharing. Specifically, the secret hash value calculation unit 303 calculates a secret hash value based on the secret feature and the secret HashNet learning model. More specifically, the secret hash value calculation unit 303 derives the secret hash value from the secret feature via the secret HashNet learning model.
[0117] The secret candidate extraction unit 304 is a processing circuit that performs secure calculations based on a secret sharing method in the computing devices 300, 310, and 320. Specifically, the secret candidate extraction unit 304 extracts one or more secret feature candidates from a plurality of secret feature values based on a secret hash value.
[0118] More specifically, the secret candidate extraction unit 304 calculates the secret Hamming distance between the secret hash value calculated by the secret hash value calculation unit 303 and each of the secret hash values stored in the storage unit 301. The secret candidate extraction unit 304 extracts one or more secret feature value candidates based on the secret Hamming distance.
[0119] The secret similarity calculation unit 305 is a processing circuit that performs secure calculations based on the secret sharing method in the computing devices 300, 310, and 320. Specifically, the secret similarity calculation unit 305 calculates the secret similarity between each of one or more secret feature value candidates and the secret feature value.
[0120] The anonymous authentication unit 306 is a processing circuit within the computing devices 300, 310, and 320 that performs secure computations based on secret sharing. Specifically, the anonymous authentication unit 306 generates an anonymous authentication result based on the anonymous similarity and the anonymous threshold. The authentication result indicates whether the authentication was successful or not. If the authentication result indicates successful, it may also indicate the user ID.
[0121] More specifically, the anonymity authentication unit 306 determines whether the highest anonymity similarity is greater than the anonymity threshold. If the highest anonymity similarity is greater than the anonymity threshold, the anonymity authentication unit 306 determines that authentication is successful. On the other hand, if the highest anonymity similarity is less than the anonymity threshold, the anonymity authentication unit 306 determines that authentication is unsuccessful.
[0122] The communication unit 307 is a processing circuit for communication. Specifically, the communication unit 307 receives the hidden feature value learning model and the hidden HashNet learning model from the provision device 200. Furthermore, the communication unit 307 receives the hidden facial image and the hidden user ID from the terminal device 100. Furthermore, the communication unit 307 receives the hidden facial image from the authentication device 400. Furthermore, the communication unit 307 transmits the hidden authentication result to the authentication device 400.
[0123] Figure 5 4 is a block diagram showing the configuration of an authentication device 400 in the embodiment. The authentication device 400 includes a sensing unit 401 , a separation unit 402 , an authentication result decryption unit 403 , and a communication unit 404 .
[0124] The sensing unit 401 is a sensor that senses biological information. Specifically, the sensing unit 401 captures a facial image of the user.
[0125] The splitting unit 402 is a processing circuit that encrypts information based on a secret sharing method. Specifically, the splitting unit 402 encrypts the facial image captured by the sensing unit 401 to derive a concealed facial image.
[0126] The authentication result decryption unit 403 is a processing circuit that decrypts information based on a secret sharing method. Specifically, the authentication result decryption unit 403 decrypts the secret authentication result sent from the computing devices 300, 310, and 320 to derive the authentication result.
[0127] The communication unit 404 is a processing circuit for communication. Specifically, the communication unit 404 transmits the secret feature value derived by the separation unit 402 to the computing devices 300, 310, and 320. In addition, the communication unit 404 receives the secret authentication result from the computing devices 300, 310, and 320.
[0128] Figure 6 This is a sequence diagram showing the operations of the initialization phase in the embodiment. First, the providing device 200 uses the previously collected learning data to train the feature learning model and the HashNet learning model. In addition, the providing device 200 sets the threshold for determining whether the authentication is successful (S101).
[0129] Next, the providing device 200 encrypts the feature learning model, HashNet learning model, and threshold using a secret sharing method to derive the hidden feature learning model, hidden HashNet learning model, and hidden threshold (S102). The providing device 200 then transmits the hidden feature learning model, hidden HashNet learning model, and hidden threshold to the computing devices 300, 310, and 320 (S103).
[0130] The computing devices 300 , 310 , and 320 store the hidden feature quantity learning model, the hidden HashNet learning model, and the hidden threshold value ( S104 ).
[0131] Figure 7 This is a sequence diagram illustrating the operations during the registration phase of the embodiment. First, the terminal device 100 captures a facial image of the user (S201). Next, the terminal device 100 encrypts the user ID and facial image to derive a concealed user ID and concealed facial image (S202). The terminal device 100 then transmits the concealed user ID and concealed facial image to the computing devices 300, 310, and 320 (S203).
[0132] The computing devices 300 , 310 , and 320 perform a registration process based on the hidden user ID and the hidden facial image ( S204 ).
[0133] Figure 8 This is a sequence diagram illustrating the registration process (S204) in the embodiment. First, the computing devices 300, 310, and 320 calculate hidden features (S301). Specifically, the computing devices 300, 310, and 320 derive hidden features from the hidden facial image using a hidden feature learning model. Next, the computing devices 300, 310, and 320 calculate hidden hash values (S302). Specifically, the computing devices 300, 310, and 320 derive hidden hash values from the hidden features using a hidden HashNet learning model.
[0134] Then, the computing devices 300 , 310 , and 320 add the confidential user ID, the confidential feature amount, and the confidential hash value to the table to store the confidential user ID, the confidential feature amount, and the confidential hash value ( S303 ).
[0135] Figure 9 This is a sequence diagram illustrating the authentication phase in accordance with an embodiment. First, authentication device 400 captures a facial image of the user (S401). Next, authentication device 400 encrypts the facial image to derive a concealed facial image (S402). Authentication device 400 then transmits the concealed facial image to computing devices 300, 310, and 320 (S403).
[0136] The computing devices 300, 310, and 320 perform authentication processing based on the concealed facial image (S404). Then, the computing devices 300, 310, and 320 transmit the concealed authentication result obtained through the authentication processing to the authentication device 400 (S405).
[0137] The authentication device 400 decrypts the hidden authentication result to derive the authentication result (S406). The authentication device 400 then utilizes the authentication result (S407). For example, the authentication device 400 performs processing corresponding to the authentication result. Furthermore, if the authentication result indicates successful authentication, the authentication device 400 may also perform processing based on the user ID also indicated in the authentication result.
[0138] Figure 10 This is a sequence diagram illustrating the authentication process (S404) in an embodiment. First, the computing devices 300, 310, and 320 calculate hidden features (S501). Specifically, the computing devices 300, 310, and 320 derive hidden features from the hidden facial image using a hidden feature learning model. Next, the computing devices 300, 310, and 320 calculate hidden hash values (S502). Specifically, the computing devices 300, 310, and 320 derive hidden hash values from the hidden features using a hidden HashNet learning model.
[0139] Next, the computing devices 300, 310, and 320 convert the secret hash value from integer shares to binary shares (S503). In other words, the computing devices 300, 310, and 320 convert the secret hash value from integer shares to binary shares.
[0140] For example, integer shares are shares for additive secret sharing, and binary shares are shares for XOR secret sharing. In other words, integer shares are shares for secret sharing using integers (i.e., integer units), while binary shares are shares for secret sharing using bits (i.e., bits). Here, a share corresponds to the data obtained through secret sharing.
[0141] Computing devices 300, 310, and 320 also convert each hidden hash value in the table from integer shares to binary shares. Here, assume that the table contains N data sets. Each data set contains a hidden user ID, a feature value, and a hash value. Computing devices 300, 310, and 320 convert the N hidden hash values in the table from integer shares to binary shares.
[0142] Next, the computing devices 300, 310, and 320 calculate the hidden Hamming distances between the hidden hash value corresponding to the authentication target data and each hidden hash value in the table. In other words, the computing devices 300, 310, and 320 calculate N hidden Hamming distances for each of the N hash values in the table (S504).
[0143] Specifically, computing devices 300, 310, and 320 calculate an XOR bit string by performing an exclusive OR operation between the hash value corresponding to the authentication target data and each hash value in the table, in a binary-shared hidden state. Here, an XOR bit string is a string (sequence) of bitwise exclusive ORs between two hash values.
[0144] Furthermore, the computing devices 300, 310, and 320 convert the hidden XOR bit string from a binary share to an integer share. At this time, the computing devices 300, 310, and 320 convert the hidden XOR bit string into a second integer share, which is different from the original first integer share.
[0145] Here, the first integer share is a share of the secret share obtained by splitting the value using an integer corresponding to the first digit (that is, in units of integers corresponding to the first digit). Furthermore, the second integer share is a share of the secret share obtained by splitting the value using an integer corresponding to the second digit smaller than the first digit (that is, in units of integers corresponding to the second digit).
[0146] The first digit may be the number of digits used to represent the value of the feature quantity, or the number of digits of each element of the feature vector or feature tensor corresponding to the feature quantity. The second digit may be the actual number of digits used to represent the hash value.
[0147] Furthermore, computing devices 300, 310, and 320 calculate the sum of the multiple bit values included in the XOR bit string as the Hamming distance while maintaining the secret state for each second integer fraction. This allows computing devices 300, 310, and 320 to efficiently calculate the secret Hamming distance between the secret hash value corresponding to the authentication target data and each secret hash value in the table.
[0148] Next, computing devices 300, 310, and 320 extract M data sets from the table in ascending order of concealed Hamming distance (S505). Specifically, computing devices 300, 310, and 320, in the concealed state of the second integer portion, sort the N data sets by the N Hamming distances and extract M data sets in ascending order of Hamming distance.
[0149] Here, N and M are natural numbers, and basically, M is smaller than N. If N is sufficiently small, that is, if N is smaller than a reference, M may be equal to N. In other words, M may be smaller than N.
[0150] Next, the computing devices 300, 310, and 320 calculate the secret similarity between the secret feature corresponding to the authentication target data and the secret feature of each of the M data sets. In other words, the computing devices 300, 310, and 320 calculate M secret similarities for the M secret feature of the M data sets (M secret feature candidate) (S506).
[0151] Specifically, computing devices 300, 310, and 320, in a concealed state according to the first integer share, calculate the similarity between the feature value corresponding to the authentication target data and the feature values of each of the M data sets through secure calculations. The more similar the two feature values are, the higher the similarity. The similarity can also correspond to Euclidean distance, cosine similarity, or a value obtained by processing these. Alternatively, the similarity can correspond to a value called a distance score.
[0152] Then, if the highest concealed similarity is above the concealed threshold, the computing devices 300 , 310 , and 320 extract the concealed user ID of the relevant data set ( S507 ).
[0153] Specifically, the computing devices 300 , 310 , and 320 determine whether the highest similarity among the M similarities calculated by the secure calculation is equal to or greater than a threshold value in the concealed state of the first integer share.
[0154] If the highest similarity is greater than the threshold, computing devices 300, 310, and 320 generate a hidden authentication result indicating successful authentication, extract the hidden user ID from the dataset corresponding to the highest similarity, and include it in the hidden authentication result. On the other hand, if the highest similarity is less than the threshold, computing devices 300, 310, and 320 generate a hidden authentication result indicating failed authentication.
[0155] Figure 11 This is a schematic diagram illustrating a table (registered user table) in an embodiment. The table includes a concealed user ID, a concealed hash value, and a concealed feature value. Furthermore, the table is distributed across three computing devices 300, 310, and 320. These three computing devices 300, 310, and 320 perform secure calculations using the concealed user ID, concealed hash value, and concealed feature value, maintaining their concealed state.
[0156] In the embodiment, hash values can be used to quickly extract candidates. Furthermore, by converting the hash value from integer fractions to binary fractions, exclusive OR (XOR) can be quickly calculated. Furthermore, by converting the XOR bit string back to integer fractions with a smaller number of bits, the sum of the bit values can be quickly calculated. Therefore, the Hamming distance can be quickly calculated and efficiently represented. This can speed up the authentication process.
[0157] Specifically, binary shares are based on bits and are therefore suitable for bit operations. First integer shares are based on integers whose first digit is larger than the second digit and are therefore suitable for processing relatively large values. Second integer shares are based on integers whose second digit is smaller than the first digit and are therefore suitable for processing relatively small values. This can speed up the authentication process.
[0158] Figure 12 This is a conceptual diagram showing a display screen of an authentication result in an embodiment. For example, the authentication device 400 receives a hidden authentication result and derives the authentication result by decrypting the hidden authentication result. Figure 12 It is displayed on the screen like this.
[0159] Specifically, if the authentication result indicates successful authentication, the authentication device 400 may display a message indicating successful authentication ("OK") on the screen. Alternatively, if the authentication result indicates failed authentication, the authentication device 400 may display a message indicating failed authentication ("NG") on the screen. Furthermore, the authentication device 400 may display a facial image captured by the authentication device 400, i.e., a facial image used in the authentication process, on the screen.
[0160] The following describes a plurality of variations applicable to the above-mentioned embodiments. One of the following variations can be applied to the above-mentioned embodiments, or two or more of the following variations can be combined and applied to the above-mentioned embodiments. In addition, the following descriptions that are the same as those in the above-mentioned embodiments may sometimes be omitted.
[0161] (Variation 1)
[0162] In the first variant, some processing is performed in plain text. In other words, some processing is performed independently of secure computation. Therefore, the authentication process is faster.
[0163] The terminal device 100 in the first modification has Figure 2 The components of the terminal device 100 shown are the same components.
[0164] Figure 13 : is a block diagram showing the configuration of the providing apparatus 200 in the first modification. The providing apparatus 200 in the first modification has Figure 3 The components of the providing device 200 are the same as those shown in the figure. However, the threshold value set by the threshold value setting unit 202 is not encrypted by the splitting unit 203 but is transmitted to the arithmetic devices 300 , 310 and 320 via the communication unit 204 .
[0165] The computing devices 300, 310, and 320 in the first modification have the same Figure 4 The components of the computing device 300 shown in FIG. However, after calculating the hidden Hamming distance, the concealed candidate extraction unit 304 decrypts the hidden Hamming distance to derive the Hamming distance, and uses the Hamming distance instead of the hidden Hamming distance for processing. Furthermore, after calculating the hidden similarity, the concealed similarity calculation unit 305 decrypts the concealed similarity to derive the similarity, and uses the similarity instead of the concealed similarity for processing.
[0166] The authentication device 400 in the first modification has Figure 5 The components of the authentication device 400 shown are the same components.
[0167] Figure 14 This is a timing diagram showing the operation of the initialization phase in Modification Example 1. First, Figure 6 Similarly to the example of , the providing apparatus 200 trains the feature quantity learning model and the HashNet learning model. In addition, the providing apparatus 200 sets a threshold value for determining whether the authentication is successful or not (S101).
[0168] Next, the providing device 200 encrypts the feature learning model and the HashNet learning model using a secret sharing method to derive the hidden feature learning model and the hidden HashNet learning model (S111). The threshold is not encrypted. The providing device 200 then transmits the hidden feature learning model, the hidden HashNet learning model, and the threshold to the computing devices 300, 310, and 320 (S112).
[0169] The computing devices 300 , 310 , and 320 store the hidden feature quantity learning model, the hidden HashNet learning model, and the threshold value ( S113 ).
[0170] The operation in the registration phase in Modification 1 is the same as Figure 7 The registration process in Modification 1 is the same as Figure 8 The registration process is the same as shown. The operation of the authentication phase in the modification example 1 is the same as Figure 9 The actions in the authentication phase shown are the same.
[0171] Figure 15 This is a sequence diagram showing the authentication process (S404) in Modification 1. Figure 10 Similarly to the example, the computing devices 300, 310, and 320 calculate the secret feature value (S501), calculate the secret hash value (S502), and convert the secret hash value from an integer share to a binary share (S503). In addition, the computing devices 300, 310, and 320 convert the N secret state hash values in the table from an integer share to a binary share.
[0172] Then, with Figure 10 Similarly to the example, the computing devices 300, 310, and 320 calculate the hidden Hamming distances between the hidden hash value corresponding to the authentication target data and each hidden hash value in the table. Specifically, the computing devices 300, 310, and 320 calculate N hidden Hamming distances for each of the N hash values in the table. Furthermore, the computing devices 300, 310, and 320 derive N Hamming distances by decrypting the N hidden Hamming distances (S511).
[0173] Next, the computing devices 300, 310, and 320 extract M data sets from the table in ascending order of Hamming distance (S512). Specifically, the computing devices 300, 310, and 320 sort the N data sets by the N Hamming distances and extract M data sets in ascending order of Hamming distance.
[0174] Then, with Figure 10Similarly to the example, the computing devices 300, 310, and 320 calculate the secret similarities between the secret feature corresponding to the authentication target data and the secret feature of each of the M data sets. In other words, the computing devices 300, 310, and 320 calculate M secret similarities for the M secret feature of the M data sets (M secret feature candidate). Furthermore, the computing devices 300, 310, and 320 derive M similarities by decrypting the M secret similarities (S513).
[0175] Then, if the highest similarity is above the threshold, the computing devices 300, 310, and 320 extract the anonymous user ID of the relevant data set (S514). Specifically, the computing devices 300, 310, and 320 determine whether the highest similarity among the M similarities calculated and decrypted by the secure calculation is above the threshold.
[0176] If the highest similarity is greater than the threshold, computing devices 300, 310, and 320 generate a hidden authentication result indicating successful authentication, extract the hidden user ID from the dataset corresponding to the highest similarity, and include it in the hidden authentication result. On the other hand, if the highest similarity is less than the threshold, computing devices 300, 310, and 320 generate a hidden authentication result indicating failed authentication.
[0177] As described above, in Modification 1, some processing is performed independently of secure calculations, thereby increasing the speed of authentication processing.
[0178] (Variation 2)
[0179] In the second variant, the secret hash value is converted to a binary share during the registration process. This allows the process of converting the secret hash value in the table into a binary share to be omitted during each authentication process. This speeds up the authentication process.
[0180] The terminal device 100 in the second modification has Figure 2 The components of the terminal device 100 shown are the same components.
[0181] The providing device 200 in the second modification has Figure 3 The components of the providing device 200 shown are the same components.
[0182] The computing devices 300, 310, and 320 in the second modification have the same Figure 4 The components of the computing device 300 are the same as those shown in FIG. However, during the registration process, the secret hash value calculation unit 303 also converts the secret hash value into binary shares after calculating the secret hash value. The converted secret hash value into binary shares is then stored in the table of the storage unit 301.
[0183] The authentication device 400 in the second modification has Figure 5 The components of the authentication device 400 shown are the same components.
[0184] The initialization phase in Modification 2 is similar to Figure 6 The operation of the initialization phase shown in FIG. 2 is the same as that of the registration phase in the modification example 2. Figure 7 The actions of the registration phase shown are the same.
[0185] Figure 16 is a sequence diagram showing the registration process (S204) in Modification 2. First, Figure 8 Similarly to the example of , the computing devices 300 , 310 , and 320 calculate the secret feature quantity ( S301 ) and calculate the secret hash value ( S302 ).
[0186] Afterwards, the computing devices 300, 310, and 320 convert the encrypted hash value from integer shares to binary shares (S321). Then, the computing devices 300, 310, and 320 store the encrypted user ID, encrypted feature, and encrypted hash value by adding them to the table (S322).
[0187] The operation of the authentication phase in Modification 2 is the same as Figure 9 The authentication process in the second variant is the same as Figure 10 The authentication process shown is essentially the same, except that the conversion of each hidden hash value in the table from integer shares to binary shares is omitted.
[0188] As described above, in Modification 2, the process of converting the secret hash value in the table into a binary share can be omitted for each authentication process, thereby increasing the speed of the authentication process.
[0189] (Variation 3)
[0190] In the third modification, the process of calculating the feature amount from the facial image is performed by the terminal device 100 or the authentication device 400 instead of the arithmetic devices 300 , 310 , and 320 .
[0191] Figure 17 : is a block diagram showing the configuration of the terminal device 100 in Modification 3. Figure 2 Compared with the example of , the terminal device 100 in the modification example 3 further includes a feature quantity calculation unit 131.
[0192] The feature calculation unit 131 is a processing circuit that calculates feature quantities based on biometric information. Specifically, the feature calculation unit 131 calculates feature quantities based on facial images and a feature learning model. More specifically, the feature calculation unit 131 derives feature quantities from facial images using the feature learning model.
[0193] In addition, in the terminal device 100 in the modification 3, Figure 2 Compared to the example, the following processing is performed. The decomposition unit 102 encrypts the features calculated by the feature calculation unit 131 instead of the facial image to derive the concealed features. The storage unit 103 stores the feature learning model transmitted from the providing device 200. The communication unit 104 receives the feature learning model from the providing device 200.
[0194] Figure 18 : is a block diagram showing the configuration of the providing apparatus 200 in the third modification. The providing apparatus 200 in the third modification has Figure 3 The components of the provision device 200 are the same as those shown. However, the feature learning model and the HashNet learning model set by the learning model setting unit 201 are not encrypted by the splitting unit 203 but are transmitted to the terminal device 100 and the authentication device 400 via the communication unit 204 .
[0195] Figure 19 3 is a block diagram showing the configuration of the computing device 300 in Modification 3. The computing device 310 and the computing device 320 also include the same components as those included in the computing device 300. Figure 4 Compared to the example of FIG. 3 , the arithmetic device 300 in the modification 3 does not include the concealed feature quantity calculation unit 302. In other words, the configuration related to the calculation of the feature quantity is removed.
[0196] The storage unit 301 stores the secret feature transmitted from the terminal device 100 or the authentication device 400. The secret hash value calculation unit 303 calculates a secret hash value based on the secret feature transmitted from the terminal device 100 or the authentication device 400. The secret similarity calculation unit 305 calculates the secret similarity between each of one or more secret feature candidate values and the secret feature transmitted from the terminal device 100 or the authentication device 400. The communication unit 307 receives the secret feature values from the terminal device 100 and the authentication device 400.
[0197] Figure 20 : is a block diagram showing the configuration of the authentication device 400 in Modification 3. Figure 5 Compared to the example of , the authentication device 400 in the modification 3 further includes a feature quantity calculation unit 431 and a storage unit 432 .
[0198] The feature calculation unit 431 is a processing circuit that calculates feature quantities based on biometric information. Specifically, the feature calculation unit 431 calculates feature quantities based on facial images and a feature learning model. More specifically, the feature calculation unit 431 derives feature quantities from facial images using the feature learning model.
[0199] The storage unit 432 is a memory for storing information. The storage unit 432 may be a volatile memory or a non-volatile memory. Specifically, the storage unit 432 stores the feature quantity learning model transmitted from the providing device 200.
[0200] In addition, with Figure 5 Compared to the example, the authentication device 400 in the third modification performs the following processing. The decomposition unit 402 encrypts the feature calculated by the feature calculation unit 431 instead of the facial image to derive the hidden feature. The communication unit 404 receives the feature learning model from the providing device 200.
[0201] Figure 21 This is a timing diagram showing the operation of the initialization phase in Modification Example 3. First, Figure 6 Similarly to the example, the providing device 200 trains the feature learning model and the HashNet learning model and sets the threshold (S101).
[0202] Next, the providing apparatus 200 transmits the feature learning model to the terminal apparatus 100 and the authentication apparatus 400 (S131). The terminal apparatus 100 and the authentication apparatus 400 each store the feature learning model (S132).
[0203] Next, the providing device 200 encrypts the HashNet learning model and the threshold using a secret sharing method to derive the hidden HashNet learning model and the hidden threshold ( S133 ). The providing device 200 then sends the hidden HashNet learning model and the hidden threshold to the computing devices 300 , 310 , and 320 ( S134 ).
[0204] The computing devices 300 , 310 , and 320 store the hidden HashNet learning model and the hidden threshold ( S135 ).
[0205] Figure 22 This is a timing diagram showing the operation of the registration phase in Modification 3. Figure 7 Similarly to the example of , the terminal device 100 captures a facial image of a user ( S201 ).
[0206] Next, the terminal device 100 calculates the feature quantity based on the facial image and the feature quantity learning model ( S231 ). Specifically, the terminal device 100 derives the feature quantity from the facial image via the feature quantity learning model.
[0207] Next, the terminal device 100 encrypts the user ID and the feature to derive the confidential user ID and the confidential feature ( S232 ) and transmits the confidential user ID and the confidential feature to the computing devices 300 , 310 , and 320 ( S233 ).
[0208] The computing devices 300 , 310 , and 320 perform registration processing based on the confidential user ID and the confidential feature amount ( S234 ).
[0209] Figure 23 is a sequence diagram showing the registration process (S234) in Modification 3. Figure 8 Compared to the example, the computing devices 300, 310, and 320 omit the calculation of the secret feature and calculate the secret hash value (S302) using the secret feature sent from the terminal device 100. Specifically, the computing devices 300, 310, and 320 derive the secret hash value from the secret feature via the secret HashNet learning model.
[0210] Then, with Figure 8 Similarly to the example of , the computing devices 300 , 310 , and 320 add the hidden user ID, the hidden feature amount, and the hidden hash value to the table to store the hidden user ID, the hidden feature amount, and the hidden hash value ( S303 ).
[0211] Figure 24 This is a sequence diagram showing the actions of the authentication phase in Modification 3. Figure 9 Similarly to the example of , the authentication device 400 captures a facial image of a user ( S401 ).
[0212] Next, the authentication device 400 calculates the feature quantity based on the facial image and the feature quantity learning model (S431). Specifically, the authentication device 400 derives the feature quantity from the facial image via the feature quantity learning model.
[0213] Next, the authentication device 400 encrypts the feature to derive the secret feature (S432). The authentication device 400 then sends the secret feature to the computing devices 300, 310, and 320 (S433). The computing devices 300, 310, and 320 perform authentication based on the secret feature (S434).
[0214] Then, with Figure 9 Similarly to the example of , the computing devices 300, 310, and 320 transmit the secret authentication result to the authentication device 400 (S405). The authentication device 400 decrypts the authentication result (S406) and uses the authentication result (S407).
[0215] Figure 25 is a sequence diagram showing the authentication process (S434) in Modification 3. Figure 10 Compared to the example, the computing devices 300, 310, and 320 omit the calculation of the secret feature and calculate the secret hash value (S502) using the secret feature sent from the authentication device 400. Specifically, the computing devices 300, 310, and 320 derive the secret hash value from the secret feature via the secret HashNet learning model.
[0216] The subsequent processing (S503 to S507) is similar to the above except that the hidden feature value sent from the authentication device 400 is used instead of the calculated hidden feature value. Figure 10 Same as the example.
[0217] As described above, in Modification 3, the process of calculating feature quantities from facial images is performed by terminal device 100 or authentication device 400, rather than by computing devices 300, 310, and 320. This allows for rapid calculation of feature quantities used for authentication based on facial images, independent of secure calculations using secret sharing. Consequently, the authentication process can be accelerated.
[0218] (Variation 4)
[0219] In Variation 4, the process of calculating feature quantities from facial images is divided into a front-end and a back-end. Specifically, the terminal device 100 and authentication device 400 calculate front-end feature quantities from the facial images. Then, the computing devices 300, 310, and 320 calculate back-end feature quantities based on the front-end feature quantities.
[0220] Figure 26 : is a block diagram showing the configuration of the terminal device 100 in Modification 4. Figure 2 Compared with the example of , the terminal device 100 in the modification example 4 further includes a front-end feature quantity calculation unit 141.
[0221] The front-end feature calculation unit 141 is a processing circuit that calculates feature quantities based on biometric information. Specifically, the front-end feature calculation unit 141 calculates front-end feature quantities based on facial images and a front-end feature quantity learning model. More specifically, the front-end feature calculation unit 141 derives front-end feature quantities from facial images using the front-end feature quantity learning model.
[0222] In addition, in the terminal device 100 in the modification 4, Figure 2 Compared to the example, the following processing is performed. The decomposition unit 102 encrypts the front-stage feature values calculated by the front-stage feature value calculation unit 141 instead of the facial image to derive the concealed front-stage feature values. The storage unit 103 stores the front-stage feature value learning model transmitted from the providing device 200. The communication unit 104 receives the front-stage feature value learning model from the providing device 200.
[0223] Figure 27 : is a block diagram showing the configuration of the providing apparatus 200 in the modification 4. The providing apparatus 200 in the modification 4 includes Figure 3 The components of the providing device 200 shown are the same components.
[0224] However, the learning model setting unit 201 trains the front-end feature quantity learning model, the back-end feature quantity learning model, and the HashNet learning model.
[0225] The front-end feature learning model is used to derive front-end features from biometric information, while the back-end feature learning model is used to derive back-end features from the front-end features. Furthermore, a hash value is calculated based on the front-end features. Furthermore, the back-end features are used to determine authentication success or failure.
[0226] The learning model setting unit 201 trains the front-end feature quantity learning model and the back-end feature quantity learning model so as to derive the back-end feature quantity that accurately determines whether authentication is successful or not from the face image.
[0227] The splitting unit 203 encrypts the subsequent feature value learning model, HashNet learning model, and threshold value to derive the concealed subsequent feature value learning model, concealed HashNet learning model, and concealed threshold value. The preceding feature value learning model set by the learning model setting unit 201 is not encrypted by the splitting unit 203 but is transmitted to the terminal device 100 and the authentication device 400 via the communication unit 204.
[0228] The communication unit 204 transmits the concealed second-stage feature learning model, the concealed HashNet learning model, and the concealed threshold to the computing devices 300, 310, and 320. The communication unit 204 also transmits the first-stage feature learning model to the terminal device 100 and the authentication device 400.
[0229] Figure 28 3 is a block diagram showing the configuration of the computing device 300 in Modification 4. The computing device 310 and the computing device 320 also include the same components as those included in the computing device 300. Figure 4 Compared with the example of FIG. 1 , the arithmetic device 300 in the fourth modification includes a concealed later-stage feature quantity calculation unit 341 instead of the concealed feature quantity calculation unit 302 .
[0230] The concealed second-stage feature calculation unit 341 is a processing circuit within the computing devices 300, 310, and 320 that performs secure computations based on a secret sharing method. Specifically, the concealed second-stage feature calculation unit 341 calculates second-stage features based on the first-stage features. More specifically, the concealed second-stage feature calculation unit 341 derives the concealed second-stage features from the concealed first-stage features transmitted from the terminal device 100 or the authentication device 400 via the concealed second-stage feature learning model transmitted from the provision device 200.
[0231] In addition, with Figure 4 Compared with the example of , the storage unit 301 stores the concealed front-end feature amount instead of the facial image, and stores the concealed back-end feature amount instead of the concealed feature amount.
[0232] In addition, with Figure 4 Compared to the example, the hidden hash value calculation unit 303 calculates a hidden hash value based on the hidden front-end feature transmitted from the terminal device 100 or the authentication device 400. The hidden candidate extraction unit 304 uses the hidden back-end feature (the hidden back-end feature candidate) instead of the hidden feature (the hidden feature candidate). The hidden similarity calculation unit 305 calculates the hidden similarity between each of the one or more hidden back-end feature candidates and the hidden back-end feature calculated by the hidden back-end feature calculation unit 341.
[0233] In addition, with Figure 4 Compared with the example of , the communication unit 307 receives the secret feature amount from the terminal device 100 and the authentication device 400, and receives the subsequent feature amount learning model instead of the feature amount learning model from the providing device 200.
[0234] Figure 29 : is a block diagram showing the configuration of the authentication device 400 in Modification 4. Figure 5 Compared with the example of , the authentication device 400 in the modification 4 further includes a front-end feature quantity calculation unit 441 and a storage unit 442.
[0235] The front-end feature calculation unit 441 is a processing circuit that calculates feature quantities based on biometric information. Specifically, the front-end feature calculation unit 441 calculates front-end feature quantities based on the facial image and the front-end feature learning model. More specifically, the front-end feature calculation unit 441 derives the front-end feature quantities from the facial image using the front-end feature learning model.
[0236] The storage unit 442 is a memory for storing information. The storage unit 442 may be a volatile memory or a non-volatile memory. Specifically, the storage unit 442 stores the previous feature quantity learning model transmitted from the providing device 200.
[0237] In addition, in the authentication device 400 in the modification 4, Figure 5 Compared with the example, the following processing is performed. The splitting unit 402 encrypts the front-end feature calculated by the front-end feature calculation unit 441 instead of the facial image to derive the concealed front-end feature. The communication unit 404 receives the front-end feature learning model from the providing device 200.
[0238] Figure 30 This is a sequence diagram showing the initialization phase in Modification 4. First, the provisioning device 200 uses previously collected learning data to train the front-end feature quantity learning model, the back-end feature quantity learning model, and the HashNet learning model. Furthermore, the provisioning device 200 sets a threshold for determining authentication success ( S141 ).
[0239] Next, the providing apparatus 200 transmits the previous stage feature quantity learning model to the terminal apparatus 100 and the authentication apparatus 400 (S142). The terminal apparatus 100 and the authentication apparatus 400 each store the previous stage feature quantity learning model (S143).
[0240] Next, the providing device 200 encrypts the subsequent feature value learning model, the HashNet learning model, and the threshold value using a secret sharing method, and derives the hidden subsequent feature value learning model, the hidden HashNet learning model, and the hidden threshold value (S144). The providing device 200 then transmits the hidden subsequent feature value learning model, the hidden HashNet learning model, and the hidden threshold value to the computing devices 300, 310, and 320 (S145).
[0241] The computing devices 300 , 310 , and 320 store the hidden later-stage feature quantity learning model, the hidden HashNet learning model, and the hidden threshold value ( S146 ).
[0242] Figure 31 This is a sequence diagram showing the operation of the registration phase in Modification 4. Figure 7 Similarly to the example of , the terminal device 100 captures a facial image of a user ( S201 ).
[0243] Next, the terminal device 100 calculates the front-end feature value based on the facial image and the front-end feature value learning model ( S241 ). Specifically, the terminal device 100 derives the front-end feature value from the facial image via the front-end feature value learning model.
[0244] Next, the terminal device 100 encrypts the user ID and the preceding feature to derive the concealed user ID and the preceding feature ( S242 ) and transmits the concealed user ID and the preceding feature to the computing devices 300 , 310 , and 320 ( S243 ).
[0245] The computing devices 300 , 310 , and 320 perform registration processing based on the concealed user ID and the concealed previous-stage feature amount ( S244 ).
[0246] Figure 32 is a sequence diagram showing the registration process (S244) in Modification 4. Figure 8 Compared to the example, the computing devices 300, 310, and 320 omit the calculation of the hidden feature value and calculate the hidden hash value (S302) using the hidden front-end feature value sent from the terminal device 100. Specifically, the computing devices 300, 310, and 320 derive the hidden hash value from the hidden front-end feature value via the hidden HashNet learning model.
[0247] Next, the computing devices 300, 310, and 320 calculate the hidden second-stage feature value (S341). Specifically, the computing devices 300, 310, and 320 derive the hidden second-stage feature value from the hidden first-stage feature value via the hidden second-stage feature value learning model.
[0248] Then, the computing devices 300 , 310 , and 320 add the hidden user ID, the hidden second-stage feature, and the hidden hash value to the table to store the hidden user ID, the hidden second-stage feature, and the hidden hash value ( S342 ).
[0249] Figure 33 This is a sequence diagram showing the actions of the authentication phase in Modification 4. Figure 9 Similarly to the example of , the authentication device 400 captures a facial image of a user ( S401 ).
[0250] Next, the authentication device 400 calculates the front-end feature value based on the facial image and the front-end feature value learning model ( S441 ). Specifically, the authentication device 400 derives the front-end feature value from the facial image via the front-end feature value learning model.
[0251] Next, the authentication device 400 encrypts the preceding feature to derive the concealed preceding feature (S442). The authentication device 400 then transmits the concealed preceding feature to the computing devices 300, 310, and 320 (S443). The computing devices 300, 310, and 320 perform authentication based on the concealed preceding feature (S444).
[0252] Then, with Figure 9 Similarly to the example of , the computing devices 300, 310, and 320 transmit the secret authentication result to the authentication device 400 (S405). The authentication device 400 decrypts the authentication result (S406) and uses the authentication result (S407).
[0253] Figure 34 is a sequence diagram showing the authentication process (S444) in Modification 4. Figure 10 Compared to the example, the computing devices 300, 310, and 320 omit the calculation of the hidden feature quantity and calculate the hidden hash value (S502). Specifically, the computing devices 300, 310, and 320 derive the hidden hash value from the hidden front-end feature quantity via the hidden HashNet learning model.
[0254] Then, with Figure 10 Similarly to the example of , the computing devices 300, 310, and 320 convert the secret hash value from integer shares to binary shares (S503). In addition, the computing devices 300, 310, and 320 also convert each secret hash value in the table from integer shares to binary shares.
[0255] Then, with Figure 10 Similarly to the example of , the computing devices 300 , 310 , and 320 calculate the hidden Hamming distance between the hidden hash value corresponding to the authentication target data and each hidden hash value in the table ( S504 ).
[0256] Then, with Figure 10 Similarly to the example of , the computing devices 300 , 310 , and 320 extract M data sets from the table in ascending order of hidden Hamming distance ( S505 ).
[0257] Next, the computing devices 300, 310, and 320 calculate the hidden second-stage feature value (S541). Specifically, the computing devices 300, 310, and 320 derive the hidden second-stage feature value from the hidden first-stage feature value via the hidden second-stage feature value learning model.
[0258] Next, the computing devices 300, 310, and 320 calculate the concealed similarity between the concealed posterior-stage feature corresponding to the authentication target data and the concealed posterior-stage feature of each of the M data sets. Specifically, the computing devices 300, 310, and 320 calculate M concealed similarities for the M concealed posterior-stage feature of the M data sets (M concealed posterior-stage feature candidates) (S542).
[0259] Specifically, computing devices 300, 310, and 320, in a concealed state in a first integer fraction, calculate the similarity between the subsequent feature value corresponding to the authentication target data and the subsequent feature values of each of the M data sets through secure computation. The greater the similarity between the two feature values, the higher the similarity. The similarity can also correspond to Euclidean distance, cosine similarity, or a value derived by processing these. Alternatively, the similarity can correspond to a value known as a distance score.
[0260] Then, with Figure 10 Similarly to the example of , if the highest hidden similarity is above the hidden threshold, the computing devices 300 , 310 , and 320 extract the hidden user ID of the relevant data set ( S507 ).
[0261] As described above, in Modification 4, the process of calculating feature values from facial images is divided into the first stage and the second stage. This allows for rapid feature value calculation and more reliable concealment of feature value and its derivation process.
[0262] (Other Modifications)
[0263] Before obtaining the feature value corresponding to the authentication target data in the authentication stage, the intermediate value used for calculating the similarity may be calculated and registered (stored) in the registration stage. Furthermore, the similarity may be calculated using the registered (stored) intermediate value in the authentication stage.
[0264] For example, when the feature corresponding to the authentication object data is represented by a=(a0, a1, ..., an) and the feature stored in the table is represented by b=(b0, b1, ..., bn), the cosine similarity between the feature a and the feature b is calculated using the following formula (1).
[0265]
[0266] The following equation (2) included in equation (1) can be calculated before obtaining the feature amount a.
[0267]
[0268] During the registration process, computing devices 300, 310, and 320 may also register the intermediate values calculated as described above in a table. Furthermore, computing devices 300, 310, and 320 may also use the intermediate values registered in the table to calculate similarities during the authentication process. This can speed up the authentication process.
[0269] Furthermore, the terminal device 100 and the authentication device 400 may be the same device. For example, the terminal device 100 may operate as the authentication device 400 for authentication processing, and the authentication device 400 may operate as the terminal device 100 for registration processing.
[0270] Alternatively, the facial image used for registration can be obtained from a passport, driver's license, or Japanese Individual Number Card (ID card). In other words, the facial image can be obtained not directly but from a medium that records the facial image. The medium can be electronic, magnetic, or paper. Similarly, the user ID used for registration can be obtained from a passport, driver's license, or Japanese Individual Number Card.
[0271] In addition, the feature learning model, the front-end feature learning model, the back-end feature learning model, and the HashNet learning model do not need to be trained. In particular, in the case of no encryption, the existing learning model can be used.
[0272] Furthermore, for example, the plurality of components included in each device of the authentication system 500 may be formed of a circuit. Alternatively, the plurality of components included in each device may be formed of a processor and a memory.
[0273] (Unique composition and movement)
[0274] Hereinafter, unique configurations and operations in the above-described embodiment and a plurality of modified examples will be described.
[0275] Figure 35 1 is a block diagram showing a unique configuration of the authentication system 500 in the embodiment and multiple variations. Figure 35 As shown, authentication system 500 includes computing devices 300, 310, and 320 that perform biometric information authentication processing using secure calculations based on secret sharing. Furthermore, while three computing devices 300, 310, and 320 are shown here, authentication system 500 may include two computing devices or four or more computing devices.
[0276] Furthermore, the terminal device 100, the providing device 200, and the authentication device 400 may not be included in the authentication system 500. For example, they may be included in an external system. Alternatively, any one of the computing devices 300, 310, and 320 may play their roles.
[0277] Alternatively, if the user's features are registered in the initial state, the terminal device 100 may not be present. Furthermore, if the feature learning model, HashNet learning model, and thresholds are reflected in the computing devices 300, 310, and 320 in the initial state, the providing device 200 may not be present.
[0278] Alternatively, you can Figure 35 Authentication system 500 additional Figure 1 At least one of the terminal device 100, providing device 200 and authentication device 400 shown.
[0279] Figure 36 1 is a flowchart showing the unique operation of the authentication system 500 in the embodiment and multiple variations. Figure 35 The authentication system 500 may also include an authentication device 400. The authentication system 500 performs the authentication by performing Figure 36 The actions shown are used to perform authentication processing of biometric information in a hidden state through secure calculation based on the secret sharing method.
[0280] First, the computing devices 300, 310, and 320 of the authentication system 500 calculate a hash value from the first feature value of the biometric information using a locality-preserving hash function in a hidden state (S601). Next, the computing devices 300, 310, and 320 convert the hash value from the first integer share, which is a share of the secret share whose value is split using an integer of the first digit, to a binary share, which is a share of the secret share whose value is split using bits, in a hidden state (S602).
[0281] Next, after converting the hash value, computing devices 300, 310, and 320 calculate an XOR bit string by performing an exclusive OR operation on the hash value and the registered hash value in a concealed state (S603). Next, computing devices 300, 310, and 320 convert the XOR bit string from a binary share into a second integer share, which is a share of the secret share split using an integer with a second digit smaller than the first digit (S604).
[0282] Next, after converting the XOR bit string, the computing devices 300, 310, and 320 calculate the Hamming distance between the hash value and the registered hash value by calculating the sum of the multiple bit values included in the XOR bit string in a concealed state (S605). The computing devices 300, 310, and 320 then use the Hamming distance to determine whether the registered feature corresponding to the registered hash value has been used in the authentication process (S606).
[0283] This allows efficient selection of registered features for authentication. Consequently, the computational complexity of the authentication process can be reduced. Furthermore, using binary shares, the XOR bit string can be efficiently calculated. Furthermore, using the second integer share corresponding to the integer number less than the first, the sum of the multiple bit values included in the XOR bit string can be efficiently calculated and represented. Consequently, the authentication process can be accelerated.
[0284] For example, the computing devices 300, 310, and 320 may determine that the registration feature quantity corresponding to the registration hash value is used for authentication processing when the Hamming distance is included in the first M Hamming distances in ascending order among the N Hamming distances. This allows the registration feature quantity corresponding to the registration hash value with the smallest Hamming distance relative to the processing target hash value to be accurately selected as the registration feature quantity used for authentication processing.
[0285] Furthermore, for example, when the registered feature quantity is used for authentication, the computing devices 300, 310, and 320 may use the similarity between the first feature quantity or the second feature quantity derived from the first feature quantity and the registered feature quantity to determine the success or failure of the authentication process. This makes it possible to accurately determine the success or failure of the biometric authentication process using the similarity between the first feature quantity or the second feature quantity of the biometric information and the registered feature quantity.
[0286] Alternatively, for example, the computing devices 300, 310, and 320 may unmask the Hamming distance. Furthermore, the computing devices 300, 310, and 320 may use the unmasked Hamming distance to determine whether the registered feature corresponding to the registered hash value has been used for authentication. This can speed up the processing using the Hamming distance. Therefore, it is possible to speed up the processing using the Hamming distance to determine whether the registered feature has been used for authentication.
[0287] Furthermore, for example, computing devices 300, 310, and 320 can also unhide the similarity. Furthermore, computing devices 300, 310, and 320 can use the unhide similarity to determine the success or failure of the authentication process. This can speed up the process of using similarity. Therefore, it is possible to speed up the process of determining the success or failure of the authentication process using similarity.
[0288] Alternatively, for example, the registered hash value may be converted from the first integer fraction to a binary fraction before registration. This allows the conversion of the registered hash value from the first integer fraction to a binary fraction to be omitted during the authentication phase, thereby speeding up the authentication process.
[0289] Furthermore, for example, authentication device 400 of authentication system 500 may also perform secret sharing of biometric information. Computing devices 300, 310, and 320 may also calculate the first feature quantity used for authentication based on biometric information while maintaining a hidden state. This makes it possible to maintain the anonymity of calculating the first feature quantity used for authentication based on biometric information, making it possible to more reliably maintain the anonymity of the first feature quantity used for authentication.
[0290] Alternatively, for example, authentication device 400 of authentication system 500 can calculate a first feature quantity used in authentication processing based on biometric information. Furthermore, authentication device 400 can also perform secret sharing of the first feature quantity. This allows for rapid calculation of the first feature quantity used in authentication processing based on biometric information, independent of secure calculations using secret sharing. Consequently, authentication processing can be accelerated.
[0291] Alternatively, for example, authentication device 400 of authentication system 500 may calculate the first feature value based on biometric information. Furthermore, authentication device 400 may perform secret sharing of the first feature value. Furthermore, computing devices 300, 310, and 320 of authentication system 500 may calculate the second feature value used for authentication based on the first feature value in a concealed state.
[0292] This allows for rapid calculation of the first feature value based on biometric information, independent of secure calculations using secret sharing. Furthermore, the calculation of the second feature value used for authentication based on the first feature value can be made anonymous, making it possible to more reliably maintain the anonymity of the second feature value used for authentication.
[0293] Furthermore, for example, the computing devices 300 , 310 , and 320 may calculate the similarity between the first feature quantity or the second feature quantity and the registered feature quantity using an intermediate value calculated and registered based on the registered feature quantity independently of the first feature quantity or the second feature quantity.
[0294] Specifically, for example, the computing devices 300, 310, and 320 may calculate the similarity between the first feature quantity and the registered feature quantity using an intermediate value calculated and registered based on the registered feature quantity independently of the first feature quantity. Alternatively, for example, the computing devices 300, 310, and 320 may calculate the similarity between the second feature quantity and the registered feature quantity using an intermediate value calculated and registered based on the registered feature quantity independently of the second feature quantity.
[0295] This allows the calculation and registration of intermediate values for similarity calculation before the authentication phase, and the calculation of similarity during the authentication phase using the calculated and registered intermediate values, thereby speeding up the authentication process.
[0296] Alternatively, for example, the device used to input biometric information during the biometric information registration phase may be the same as the device used to input biometric information during the biometric information authentication phase. This allows the authentication process to be performed using the same device during both the registration and authentication phases, thereby simplifying the configuration of the authentication system.
[0297] Alternatively, for example, during the biometric information registration phase, biometric information can be obtained through a medium that records the biometric information. This allows biometric information to be obtained through the medium rather than directly from the subject. This allows for more flexible preparation of registration hash values corresponding to the biometric information.
[0298] Alternatively, for example, the first integer share may be a share used for secret sharing of biometric information, the first feature value, and the second feature value. The first digit may be the number of digits used to represent the first feature value, or may be larger than the number of digits in the hash value. The second integer share may also be a share used for secret sharing of the Hamming distance. The second digit may also be the number of digits used to represent the hash value. More specifically, the second digit may be equal to the number of digits in the hash value.
[0299] The above describes the technical solution of the authentication system according to the embodiment, but the technical solution of the authentication system is not limited to the embodiment. The embodiment can be modified as conceived by those skilled in the art, and multiple components in the embodiment can be arbitrarily combined.
[0300] For example, a process performed by a specific component in the embodiment may be performed by another component instead of a specific component. In addition, the order of multiple processes may be changed, or multiple processes may be performed in parallel. In addition, ordinal numbers such as 1 and 2 used in the description may be appropriately replaced, removed, or newly added. These ordinal numbers do not necessarily correspond to a meaningful order and may also be used to identify elements.
[0301] Furthermore, the authentication method including the steps performed by the various components of the authentication system may be executed by any system or device. In other words, the authentication method may be executed by the aforementioned authentication system or another system.
[0302] For example, part or all of the authentication method may be executed by a computer system including a processor, a memory, an input / output circuit, etc. In this case, the authentication method may be executed by the computer system executing a program for causing the computer system to execute the authentication method.
[0303] For example, the above-mentioned program causes the computer system to execute an authentication method, which is a method for the authentication system to perform authentication processing of biometric information in a hidden state through secure calculation based on a secret sharing method, including: in a hidden state, using a hash function that maintains locality to calculate a hash value based on a first feature quantity of the biometric information; a step of converting the hash value from a first integer share to a binary share, wherein the first integer share is a share of a secret share that uses an integer of a first digit to split a value, and the binary share is a share of a secret share that uses a bit to split a value; after the conversion of the hash value, in a hidden state , a step of calculating an XOR bit string by performing an exclusive OR operation on the hash value and the registration hash value; a step of converting the XOR bit string from the binary share to a second integer share, wherein the second integer share is a share of a secret share of a value split using an integer of a second digit smaller than the first digit; a step of calculating, in a concealed state, a Hamming distance between the hash value and the registration hash value by calculating the sum of multiple bit values included in the XOR bit string after the conversion of the XOR bit string; and a step of using the Hamming distance to determine whether a registration feature quantity corresponding to the registration hash value is used for the authentication process.
[0304] Furthermore, the above-mentioned program may be recorded on a non-transitory computer-readable recording medium such as a CD-ROM.
[0305] Furthermore, the various components of the authentication system's multiple devices may be comprised of dedicated hardware, general-purpose hardware that executes the aforementioned programs, or a combination thereof. Furthermore, the general-purpose hardware may be comprised of a memory storing the programs and a general-purpose processor that reads and executes the programs from the memory. The memory may be a semiconductor memory or a hard disk, and the general-purpose processor may be a CPU.
[0306] Alternatively, dedicated hardware may be composed of a memory and a dedicated processor, etc. For example, the dedicated processor may refer to the memory to execute the above-mentioned authentication method.
[0307] Furthermore, the components of the multiple devices in the authentication system may also be circuits. These circuits may be integrated into a single circuit or may be independent circuits. Furthermore, these circuits may correspond to dedicated hardware or general-purpose hardware that executes the aforementioned programs, etc.
[0308] Industrial applicability
[0309] The present disclosure can be used in an authentication method for performing authentication processing of biometric information through secure calculation based on a secret sharing method, and can be applied to a biometric authentication system, etc.
[0310] Description of Reference Numerals
[0311] 100 terminal device; 101, 401 sensing unit; 102, 203, 402 splitting unit; 103, 301, 432, 442 storage unit; 104, 204, 307, 404 communication unit; 131, 431 feature quantity calculation unit; 141, 441 front-end feature quantity calculation unit; 200 providing device; 201 learning model setting unit; 202 threshold setting unit; 300, 310, 320 computing device; 302 hidden feature quantity calculation unit; 303 hidden hash value calculation unit; 304 hidden candidate extraction unit; 305 hidden similarity calculation unit; 306 hidden authentication unit; 341 hidden back-end feature quantity calculation unit; 400 authentication device; 403 authentication result decryption unit; 500 authentication system.
Claims
1. An authentication method, wherein an authentication system performs authentication processing of biometric information in a hidden state through secure computation based on a secret sharing method, comprising: In a hidden state, a step of calculating a hash value based on a first feature value of the biometric information using a locality-preserving hash function; a step of converting the hash value from a first integer share to a binary share, wherein the first integer share is a share of a secret share that is split using an integer of a first digit, and the binary share is a share of a secret share that is split using bits; After the conversion of the hash value, in a hidden state, a step of calculating an XOR bit string by performing an exclusive OR operation between the hash value and the registered hash value; a step of converting the XOR bit string from the binary share into a second integer share, the second integer share being a share of a secret share of a value split using an integer of a second digit smaller than the first digit; After the conversion of the XOR bit string, in a concealed state, a step of calculating a Hamming distance between the hash value and the registered hash value by calculating a sum of a plurality of bit values included in the XOR bit string; A step of determining whether the registered feature amount corresponding to the registered hash value is used for the authentication process using the Hamming distance.
2. The authentication method according to claim 1, In the step of determining whether the registration feature quantity corresponding to the registration hash value is used for the authentication process, when the Hamming distance between the hash value and the registration hash value is included in the top M Hamming distances arranged in ascending order among the N Hamming distances between the hash value and N registration hash values including the registration hash value, it is determined that the registration feature quantity corresponding to the registration hash value is used for the authentication process.
3. The authentication method according to claim 1 or 2, further comprising: A step of determining success or failure of the authentication process using a degree of similarity between the first feature amount or a second feature amount obtained from the first feature amount and the registered feature amount when the registered feature amount is used for the authentication process.
4. The authentication method according to claim 1 or 2, It also includes the step of releasing the hidden state of the Hamming distance, In the step of determining whether the registered feature amount is used for the authentication process, it is determined whether the registered feature amount corresponding to the registered hash value is used for the authentication process using the Hamming distance in which the concealment state is released.
5. The authentication method according to claim 3, It also includes the step of releasing the hidden state of the similarity, In the step of determining whether the authentication process is successful or not, the success or failure of the authentication process is determined using the similarity after the concealment state is released.
6. The authentication method according to claim 1 or 2, The registered hash value is converted from the first integer share to the binary share and registered.
7. The authentication method according to claim 1 or 2, further comprising: performing a step of secret sharing of the biometric information; The step of calculating the first feature value used for the authentication process based on the biometric information in a hidden state.
8. The authentication method according to claim 1 or 2, further comprising: a step of calculating the first feature value used for the authentication process based on the biometric information; A step of secretly sharing the first feature value is performed.
9. The authentication method according to claim 1 or 2, further comprising: a step of calculating the first feature value based on the biometric information; performing a step of secret sharing of the first feature value; A step of calculating a second feature quantity used for the authentication process based on the first feature quantity in a hidden state.
10. The authentication method according to claim 3, further comprising: A step of calculating the similarity between the first feature quantity or the second feature quantity and the registered feature quantity using an intermediate value calculated and registered based on the registered feature quantity independently of the first feature quantity or the second feature quantity.
11. The authentication method according to claim 1 or 2, The means for inputting the biometric information at the biometric information registration stage is the same as the means for inputting the biometric information at the biometric information authentication stage.
12. The authentication method according to claim 1 or 2, comprising: In the biometric information registration phase, the biometric information is obtained through a medium recording the biometric information.
13. A program for causing a computer system to execute the authentication method according to claim 1 or 2.
14. An authentication system, A plurality of computing devices are provided for performing authentication processing of biometric information in a hidden state through secure calculation based on a secret sharing method. the plurality of computing devices, In a hidden state, a hash value is calculated based on the first feature of the biometric information using a locality-preserving hash function; Converting the hash value from a first integer share to a binary share, wherein the first integer share is a share of a secret share that is split using an integer of the first digit, and the binary share is a share of a secret share that is split using bits; After the conversion of the hash value, in a hidden state, calculating an XOR bit string by performing an exclusive OR operation on the hash value and the registered hash value; converting the XOR bit string from the binary share to a second integer share, the second integer share being a share of a secret share that splits a value using an integer of a second digit smaller than the first digit; After the conversion of the XOR bit string, in a concealed state, calculating a Hamming distance between the hash value and the registered hash value by calculating a sum of a plurality of bit values included in the XOR bit string; Using the Hamming distance, it is determined whether the registered feature amount corresponding to the registered hash value has been used for the authentication process.