Contactless identification and authentication of a person
The system addresses the complexity of existing identification and authentication methods by using a contactless, voice-based authentication process integrated with a blockchain, eliminating the need for active device operation and official documents, and enhancing security and hygiene.
Patent Information
- Application Number
- DE102022106241
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-03-17
- Publication Date
- 2025-06-05
- Estimated Expiration
- 2042-03-17
AI Technical Summary
Existing methods for personal identification and authentication often require active operation of technical devices, such as smartphones, and the presence of official documents, making the process cumbersome and requiring a checking person.
A system comprising a physical terminal, a networking unit, and databases that allows for contactless identification and authentication using voice input, gestures, or mimicry, without the need for active device operation or official documents, and utilizes a blockchain for secure and tamper-proof documentation.
The system simplifies and secures the identification and authentication process by eliminating the need for active device operation and official documents, providing a contactless, hygienic, and tamper-proof method that is easy to understand and implement.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The invention relates to a system for identifying and authenticating a person, as well as a method for identifying and authenticating a person.
[0002] In the following, the terms identification and authentication are differentiated as follows: Identification serves the sole purpose of being able to distinguish one person, in the sense of an individual, from other persons using a specific method of assignment. The term identification leaves open whether the assignment to a specific individual is correct, or, for example, fraudulent or otherwise incorrect. Only through authentication is the assignment substantiated by evidence, so that it can then be assumed that the identification has been carried out correctly. Typically, such authentication is carried out by comparing the image on a person's identity card that the person presents. The name on the identity card alone would be sufficient for identification according to the above definition, but it does not prove that it is actually the identity card that clearly belongs to the person.The image comparison by another person performing the check constitutes authentication, i.e., confirmation that the identification is also considered verified and true. Another example to illustrate the distinction between the two terms "identification" and "authentication" arises when entering a username and password into a website interface: According to the classification of terms outlined above, entering the username corresponds to identification, and entering the password corresponds to authentication, since it can be assumed that the password alone, due to its secret handling, is sufficient to assume that only the person authorized to hold the access data knows the password and thus authenticates the identifying username.
[0003] Various methods for managing sensitive, personal data are known in the prior art. Although deviating from the above classification of the terms identification and authentication, in this context DE 10 2019 217 738 A1 relates to a method for controlling and monitoring the distribution of a user's verified personal user data on a plurality of provider servers, on which the user data is stored in user databases in full or in a distributed manner, wherein the user data has a plurality of field identifiers and field contents associated therewith, with an electronic device accessible via a network and having a blockchain, wherein chronologically and irreversibly sequenced transactions are stored in the blockchain in the form of data records, each of which comprises: a timestamp of the time the data record was stored in the blockchain; a user ID of the user;a provider ID of one of the providers to which one of the provider servers is assigned; one or more of the field identifiers of the verified user data, but not their associated field contents;an electronic user signature of the user, which is created from a private user key and which can be authenticated by means of a public user key previously stored in the blockchain under the user ID, information that the user allows a specific new provider access or confirmation of the correctness of the field contents assigned to the field identifiers by the provider and / or allows and / or prohibits a specific provider access to the field contents assigned to the field identifiers, with the step: controlling and monitoring the distribution of verified personal user data of a user on the plurality of provider servers to the extent of the user ID, provider ID, field contents assigned to the field identifiers stored in the data records of the blockchain and the information which allows or prohibits the new provider or provider from using the aforementioned technical measures;
[0004] In particular, this document uses a blockchain to store, in a publicly accessible and verifiable manner, state-of-the-art technology, information on which provider is permitted to pass on or otherwise use which type of user data for which user.
[0005] Furthermore, without referring to a specific state-of-the-art document, personally conducted identification and authentication procedures are known, analogous to those mentioned above, in which, for example, the image on an identity card is compared with a person's actual appearance. However, this requires a verifying person, as well as, for example, an identity card, passport, or other officially issued document, which the person to be identified and authenticated must carry for this purpose. In addition, procedures are also known that use an electronic device and a camera mounted thereon, again in particular through a personal verification by a verifying person of the camera image and the image on such an official document.The disadvantage, however, is that the person to be identified and authenticated must provide the above-mentioned electronic device with a camera.
[0006] DE 10 2019 114 850 A1 further relates to a wall-mountable authentication device for authenticating a user of a building locking system, comprising: a control unit, an image capture device connected to the control unit, a sound recording / output device connected to the control unit, a device for wirelessly transmitting / receiving data connected to the control unit, a touch-sensitive screen connected to the control unit, and an interface module connected to the control unit for connecting the authentication device to at least one door actuator.
[0007] US 2019 / 0147672 A1 further relates to a system for multi-factor physical authentication. In one embodiment, a method for accessing a credential in a facility using multi-factor physical authentication may include receiving a unique identifier from a person at a first electronic interface in a facility; a computer processor presents a task to a person and receives a response to the task at a second interface;
[0008] The object of the invention is to improve, in particular to simplify, the identification and authentication of a person.
[0009] The invention is based on the features of the independent claims. Advantageous developments and refinements are the subject of the dependent claims.
[0010] A first aspect of the invention relates to a system for identifying and authenticating a person upon entry to an event, comprising a physical terminal at the entrance to the event, a networking unit, a computing unit, and one or more databases in which at least one data record is stored and assigned to the person, wherein the data record comprises a desired type of authentication of the person selected in advance by the person as well as authentication information defined and stored in advance by the person in the desired type of authentication, wherein the type of authentication is a voice input, in particular a password or a passphrase, and / or a gesture and / or a facial expression of the person, wherein the physical terminal is designed toto identify the person and, based on the identification, to submit a request to the networking unit for linking the identified person to the data record assigned to the identified person, wherein the networking unit does not store any personal data of the person, but only has a link table with stored links between persons and an associated virtual address of a data record of a respective person and is designed to transmit at least the stored authentication information to the computing unit by means of a corresponding request to the one or more databases containing the data record associated with the identified person, wherein the physical terminal is designed to sensorily detect an input from the person for authentication and to transmit it to the computing unit in the form of detected authentication information,and wherein the computing unit is designed to compare the acquired authentication information with the authentication information stored in the data record assigned to the identified person and, if the match is positive, to evaluate the identified person as authenticated.
[0011] The networking unit preferably comprises the computing unit for comparing the stored authentication information with the acquired authentication information. Alternatively, at least one of the databases comprises the computing unit. Preferably, each data record in the one or more databases is stored encrypted to comply with existing data protection regulations and to prevent liability issues in the event of hacker attacks.
[0012] Preferably, the communication between the physical terminal device and the networking unit is encrypted. Furthermore, the communication between the networking unit and the at least one database is preferably encrypted. Preferably, asymmetric encryption is used in each case, in which the respective encryption partners only exchange their public keys without having to exchange private keys.
[0013] It can also be provided that a key pair consisting of a public key and a private key belonging to the person is used. In particular, the physical terminal device is designed to wirelessly identify the person by means of an identification device carried by the person through the transmission of the public key. If the person's associated private key is also stored in the at least one database, the at least one database is in particular able to transmit the stored identification information to the computing unit using the person's private key and, if desired, to also release personal data of the identified person from the at least one database in encrypted form for further use on the physical terminal device to the physical terminal device or, in particular, for encrypted transmission to an external unit.
[0014] As an alternative to the above-mentioned identification of the person by the physical device by means of wireless transmission of a public key (a so-called "public key") of a key pair for asymmetric encryption, such identification can be performed by the person's voice input on the physical device, for example, by stating their name or a unique identification number. Alternatively, the person can be identified by facial recognition using a camera on the physical device. Further, preferably contactless, information transmissions from the person to the physical device are possible.
[0015] In particular, the at least one database is not part of the networking unit, but is physically and logically separated from it. Furthermore, there are preferably differences in the access rights, in particular the network-related access rights, between the one or more databases and the networking unit, such that, in particular, a plurality of physical terminal devices has unrestricted access to the networking unit, but not direct access to the one or more databases, whereas the networking unit, and particularly preferably only the networking unit, has access to the one or more databases.
[0016] The one or more databases can be understood as a single, logically distinct database in a physical unit, or as a database with distributed physical storage media, or even as logically separate and independent databases maintained, for example, by different operators. In the latter case, the system is even more flexible, as identification and authentication can advantageously be carried out for any number of providers, contractual partners, and other entities and persons, each in their own way. However, the networking unit for all these providers and all databases preferably remains the same.
[0017] An advantageous effect of the invention is that identification and, in particular, authentication takes place without actively operating a technical device such as a smartphone, nor does it require carrying an officially issued document. The person to be identified also does not need to carry a camera on an electronic device. Furthermore, both identification and authentication can be performed contactless, which is more convenient for the person and also more hygienic.The two consecutive steps required by the person make the identification and authentication process highly secure and, at the same time, easy for the person to understand (first: depositing the authentication information; second: confirming the authentication information while the person is physically present in the area of / on the physical device using voice input, facial expressions, gestures such as an "OK" sign symbolized with the fingers, or similar). Therefore, the authentication result is highly tamper-proof. Another advantage is that the networking unit does not store any sensitive, critical, or personal data of a person, but merely serves as an intermediary between the physical device and one or more databases.The networking unit therefore serves in particular the purpose of linking data streams and merging the physical terminal device used and at least one database to be addressed in order to request the desired data set.
[0018] According to an advantageous embodiment, the physical terminal is an actuated system, in particular one of the following: a robot manipulator, an automated vehicle, a lockable access system to a facility accessible or driveable, or a machine for releasing objects. This distinguishes the physical terminal from a regular user computer, such as those used in offices.
[0019] According to an advantageous embodiment, the authentication method is a voice input, in particular a password or passphrase, and / or a gesture and / or facial expression of the person, wherein the physical terminal device is designed to sensorily detect a contactless input from the person for authentication. Contactless input is advantageously more convenient and hygienic for the person.
[0020] According to a further advantageous embodiment, the one or more databases are each configured to accept requests, in particular network-related requests, solely from the networking unit. This is comparable to a firewall known in the prior art, in which requests from certain addresses are permitted and all other requests are rejected. Accordingly, according to this embodiment, the respective database has such a filter to process only network-related requests for the output of a data set from the networking unit.
[0021] According to a further advantageous embodiment, the physical terminal is designed to identify the person by means of a wireless identification device carried by the person.
[0022] The identification device for wirelessly transmitting information to identify the person can, for example, be a smartphone carried by the person with a Bluetooth module, Wi-Fi module, near-field communication module, or radio data module according to one of the 3G, 4G, or 5G standards or similar. Alternatively, the identification device can be a transponder carried specifically for this purpose.
[0023] According to a further advantageous embodiment, the networking unit is designed to document the authentication process of the identified person in a blockchain in chronologically and irreversibly arranged data or in a tangle.
[0024] A blockchain is a dynamic list of records that grows through the continuous addition of new records. Using cryptographic methods, a new verification value is generated for each new record added to the entire list and added to the list, ensuring a verifiable link between the records. Therefore, it is impossible to make undetected tampering with older records. This documentation allows for later provability of the authentication process.
[0025] According to a further advantageous embodiment, the networking unit is designed to extract the desired type of authentication for the identified person from the data record assigned to the identified person and to transmit it to the physical terminal, wherein the physical terminal is designed to output information about the predefined type of authentication to the person and / or to accept only an input from the person within the predefined type.
[0026] According to a further advantageous embodiment, the networking unit is a logically delimitable unit instead of being implemented on clearly defined computers, but rather is implemented decentrally on a plurality of computers, in particular any private user computers, and the information of the networking unit about the link of a respective person to a respective data set between the computers is kept consistent and up-to-date by mutual updates.
[0027] By using a network unit as a decentralized hosted infrastructure, the traceability of the authentication process is ensured in a forgery-proof manner. This allows even the operator of the physical device to prove that the authentication was carried out correctly. This is not the case with handwritten signatures, for example.
[0028] According to a further advantageous embodiment, the networking unit is physically and directly connected to at least one database and arranged in a physically common unit with the one or more databases.
[0029] According to a further advantageous embodiment, the data set comprises additional personal data of the person, which are released by the one or more databases for further use on the physical terminal or for forwarding to an external unit only after successful authentication of the identified person.
[0030] According to a further advantageous embodiment, the contactless input of the person for authentication comprises a voice input for selecting data to be released from the additional personal data, wherein the computing unit is designed to transmit a command to the one or more databases for releasing the data according to the voice input of the person.
[0031] Using this embodiment, the person to be authenticated consents to the release of certain personal data intuitively and quickly, for example, via voice and / or gestures. The data to be released is specified, for example, by the person's voice input, "only release name and address" or "release my age."
[0032] A further aspect of the invention relates to a method for identifying and authenticating a person upon entry to an event, comprising the steps: - Identifying a person through a physical device at the entrance to the event, - based on the identification: submitting a request to a networking unit for linking the identified person to a data record assigned to the identified person by the physical terminal device, wherein the data record is stored in one or more databases and has a desired type of authentication of the person selected in advance by the person as well as authentication information defined and stored in advance by the person in the desired type of authentication, wherein the type of authentication is a voice input, in particular a password or a passphrase, and / or a gesture and / or a facial expression of the person, - Assigning the identified person to the data record belonging to the person by means of a corresponding request to the one or more databases by the networking unit, whereby the networking unit does not store any personal data of the person, but only has a link table with stored links between persons and an associated virtual address of a data record of a respective person, and transmitting at least the stored authentication information of the identified person to the computing unit, - Sensory detection of an input from the person for authentication by the physical terminal device, and transmission of the detected input in the form of detected authentication information to the computing unit, and - Comparing the recorded authentication information with the stored authentication information of the identified person by the computing unit, and evaluating the identified person as authenticated if the computing unit positively checks for a match.
[0033] Advantages and preferred developments of the proposed method result from an analogous and analogous transfer of the statements made above in connection with the proposed system.
[0034] Further advantages, features, and details will become apparent from the following description, in which at least one embodiment is described in detail—possibly with reference to the drawings. Identical, similar, and / or functionally equivalent parts are provided with the same reference numerals.
[0035] They show: Fig. 1: A method for identifying and authenticating a person according to an embodiment of the invention. Fig. 2: A system which is subject to the procedure Fig. 1 is used in a given situation.
[0036] The representations in the figures are schematic and not to scale.
[0037] Fig. Figure 1 shows a method for identifying and authenticating a person. The method is executed on a system 1 and applied in a situation as in Fig. 2. The description of the two figures is therefore summarized below and for a better understanding of the following description both the Fig. 1 as well as the Fig.2 can be used. The situation is as follows: At the entrance to an event for which bookings for access could only be purchased in advance and for which a lower age limit of eighteen years applies, the fence surrounding the event site is interrupted by an access route. The access route is blocked off by a lockable turnstile. A person who has made a corresponding booking online by the end of the ticket sales deadline in order to make a personal booking must identify and authenticate themselves at the turnstile using System 1. Once this process is successfully completed, the turnstile unlocks and the person is granted access to the event site. Once the person has been granted access, i.e., the person has passed through the unlocked turnstile, the turnstile locks again.In order to be able to carry out this process, the person already defined a desired type of authentication as "voice input" during their online booking two weeks before the day of the event to participate in the event. At the same time, after thinking of a password, they stored a voice input in the booking portal, which could have a maximum length of fifteen seconds. This stored voice input is analyzed in the booking portal using speech recognition, and the transformed data is stored in database 9 as authentication information, so that a voice input that is not exactly reproduced but identical in wording will be recognized by computing unit 7. Also stored in database 9 is the person's age, which was previously verified by ID card comparison.The stored voice input serves as stored authentication information as part of the data record in database 9, whereby the data record also contains the type of authentication as “voice input”.
[0038] In a first step, shortly before the start of the event, a person is identified S1 by the physical terminal 3, which in this embodiment comprises a Bluetooth communication module and the turnstile. The person carries a smartphone with a mobile Bluetooth communication module that functions as a wireless identification device. The person's smartphone sends a signature to the Bluetooth communication module of the physical terminal 3, whereby the signature is unique among all bookings issued for the event and whereby the signature can be clearly assigned to the person. The signature also contains a network address of the networking unit 5, which has a "distributed ledger" of a blockchain or a tangle. The use of such a "distributed ledger" in the networking unit 5 advantageously allows the authentication process to be proven retrospectively.This completes the step of identifying the person on the physical terminal device 3. Based on the identification, a request S2 is now sent to the networking unit 5 of the computing unit 7 for linking the identified person to a data record assigned to the identified person and to the virtual address of the database 9 storing the data record by the computing unit 7 of the physical terminal device 3. The networking unit 5 then assigns S3 the identified person to the data record belonging to the person by means of a corresponding request to the databases 9, wherein the networking unit 5 has a link table with stored links between persons and an associated virtual address of the respective data records of the persons for the purpose of this linking.The stored authentication information of the identified person is finally transmitted in encrypted form from the database 9 to the computing unit 7. After the person's voice input for authentication has been recorded S4 following a corresponding request by the computing unit 7 on a display unit, the recorded voice message is transmitted from the microphone to the physical terminal 3, analyzed by a speech recognition system, and compared with the stored authentication information of the identified person by the computing unit 7 as recorded authentication information. If the match check by the computing unit 7 is positive, the identified person is assessed as authenticated and is granted access through the turnstile.
[0039] Although the invention has been illustrated and explained in detail by preferred embodiments, the invention is not limited by the disclosed examples, and other variations may be derived therefrom by those skilled in the art without departing from the scope of the invention. It is therefore clear that numerous variations exist. It is also clear that exemplary embodiments are truly only examples and should not be construed as limiting the scope, possible applications, or configuration of the invention in any way.Rather, the preceding description and the description of the figures enable the person skilled in the art to implement the exemplary embodiments in concrete terms, whereby the person skilled in the art, with knowledge of the disclosed inventive concept, can make various changes, for example with regard to the function or arrangement of individual elements mentioned in an exemplary embodiment, without departing from the scope of protection defined by the claims and their legal equivalents, such as further explanations in the description. List of reference symbols 1 system 3 end device 5 Networking unit 7 Computing unit 9 Database S1 Identify S2 Submit S3 Assign S4 Capture S5 Compare
Claims
[1] System (1) for identifying and authenticating a person upon entry to an event, comprising a physical terminal (3) at the entrance to the event, a networking unit (5), a computing unit (7), and one or more databases (9) in which at least one data record is stored and assigned to the person, wherein the data record comprises a desired type of authentication of the person selected in advance by the person and authentication information defined and stored in advance by the person in the desired type of authentication, wherein the type of authentication is a voice input, in particular a password or a passphrase, and / or a gesture and / or a facial expression of the person, wherein the physical terminal (3) is designed toto identify the person and, based on the identification, to submit a request to the networking unit (5) for linking the identified person to the data record assigned to the identified person, wherein the networking unit (5) does not store any personal data of the person, but only has a linking table with stored links between persons and an associated virtual address of a data record of a respective person and is designed to transmit at least the stored authentication information to the computing unit (7) by means of a corresponding request to the one or more databases (9) containing the data record associated with the identified person, wherein the physical terminal (3) is designed to sensorily detect an input from the person for authentication and to transmit it to the computing unit (7) in the form of detected authentication information,and wherein the computing unit (7) is designed to compare the acquired authentication information with the authentication information stored in the data record assigned to the identified person and, if the match is positive, to evaluate the identified person as authenticated. [2] System (1) according to claim 1, wherein the physical terminal (3) is an actuated system (1), in particular one of: robot manipulator, automated vehicle, lockable access system to an accessible or driveable facility, machine for releasing objects. [3] System (1) according to one of the preceding claims, wherein the type of authentication is a voice input, in particular a password or a passphrase, and / or a gesture and / or a facial expression of the person, wherein the physical terminal (3) is designed to sensorily detect a contactless input of the person for the authentication. [4] System (1) according to one of the preceding claims, wherein the physical terminal (3) is designed to identify the person by means of a wireless identification device carried by the person. [5] System (1) according to one of the preceding claims, wherein the networking unit (5) is designed to document the authentication process of the identified person in a blockchain in chronologically and irreversibly arranged data or in a tangle. [6] System (1) according to one of the preceding claims, wherein the networking unit (5) is designed to extract the desired type of authentication for the identified person from the data record assigned to the identified person and to transmit it to the physical terminal (3), wherein the physical terminal (3) is designed to output information about the predefined type of authentication to the person and / or to accept only one input from the person within the predefined type. [7] System (1) according to one of the preceding claims, wherein the networking unit (5) is implemented decentrally on a plurality of computers and the information of the networking unit (5) about the link of a respective person to a respective data set is kept consistent and up-to-date between the computers by mutual updates. [8] System (1) according to one of the preceding claims, wherein the data set comprises additional personal data of the person, which are released by the one or more databases (9) for further use on the physical terminal (3) or for forwarding to an external unit only after successful authentication of the identified person. [9] System (1) according to claim 8, wherein the person's input for authentication comprises an input, in particular a voice input, for selecting data to be released from the additional personal data, wherein the computing unit is designed to transmit a command to the one or more databases (9) for releasing the data according to the person's input. [10] A method for identifying and authenticating a person upon entry to an event, comprising the steps of: - Identifying (S1) a person by means of a physical device (3) at the entrance to the event, - based on the identification: issuing (S2) a request to a networking unit (5) for linking the identified person to a data set assigned to the identified person by the physical terminal (3), wherein the data set is stored in one or more databases (9) and has a desired type of authentication of the person selected in advance by the person as well as authentication information defined and stored in advance by the person in the desired type of authentication, wherein the type of authentication is a voice input, in particular a password or a passphrase, and / or a gesture and / or a facial expression of the person, - Assigning (S3) the identified person to the data record associated with the person by means of a corresponding request to the one or more databases (9) by the networking unit (5), wherein the networking unit (5) does not store any personal data of the person, but only has a link table with stored links between persons and an associated virtual address of a data record of a respective person, and transmitting at least the stored authentication information of the identified person to the computing unit (7), - Sensory detection (S4) of an input from the person for authentication by the physical terminal (3), and transmission of the detected input in the form of detected authentication information to the computing unit (7), and - comparing (S5) the recorded authentication information with the stored authentication information of the identified person by the computing unit (7), and evaluating the identified person as authenticated if the computing unit (7) positively checks for agreement.
Citation Information
Patent Citations
Wall-mountable authentication device
DE102019114850A1
Systems and methods for multifactor physical authentication
US20190147672A1