FINGERPRINT MULTI-FACTOR AUTHENTIFIER
A fingerprint authentication system generates a long password by combining biometric data with a user-provided code using encryption, ensuring secure and user-friendly password management without storing sensitive information, addressing the challenges of short password forgetfulness and biometric data vulnerability.
Patent Information
- Application Number
- DE112021005333
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-11-18
- Filing Date
- 2021-10-13
- Publication Date
- 2026-02-12
- Estimated Expiration
- 2041-10-13
AI Technical Summary
Existing fingerprint authentication systems face challenges in ensuring secure and user-friendly password management, as short passwords are easily forgotten and biometric data is sensitive and cannot be replaced if lost, while traditional methods require storing sensitive information on local and server units.
A method that generates a long password by combining a scanned biometric image converted into a string with a user-provided password, using format-preserving encryption to create a falsified fingerprint minutiae dataset that is unique and easily remembered, without storing the biometric information or short password on any unit, allowing for easy password updates and enhanced security.
The solution provides a secure and user-friendly authentication system where the long password is easy to remember and difficult to compromise, with no biometric data stored, enhancing security and reducing the risk of unauthorized access.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
BACKGROUND OF THE INVENTION
[0001] The present invention relates generally to computer systems and in particular to computer systems, computer-aided methods and computer program products for a fingerprint multi-factor authenticator.
[0002] Fingerprint-based biometric systems are rapidly gaining acceptance as one of the most effective technologies for authenticating users in a wide range of applications, such as logging into personal computers (PCs), physical access control, and mobile phone login. A typical fingerprint verification system operates in two stages. During login, a user's fingerprint is captured, and its characteristic features are extracted and stored as a template. During verification, a new fingerprint is requested and compared to the stored template to confirm the presumed identity of the user.The characteristic features used by most fingerprint-based systems are the so-called minutiae (papillaries), which are local features of the pattern that are stable and robust under the conditions of fingerprint deposit. To achieve a standardized approach across different fingerprint recognition systems, an international standard for representing minutiae templates, ISO / IEC 19794-2, has been defined.
[0003] Document US 2016 / 0358010A1 describes a computing device for processing fingerprint pattern data, wherein the computing device comprises modules configured to generate transformed fingerprint pattern data from original fingerprint minutiae pattern data, where minutiae are represented at least by Cartesian or polar coordinates and an inherent minutiae direction, and wherein the computing device is configured to generate corresponding mega-environmental data for each minutiae of the original fingerprint minutiae data.
[0004] Document US 2011 / 0126024A1 describes how biometric data, appropriately transformed, is captured by a biometric input device in a standalone computer device and used in conjunction with a PlN to authenticate the user to the device.
[0005] Document US 2012 / 0218079A1 describes dynamic elements within an RFID card. Specifically, card information is dynamically updated using a biometric image scanner (e.g., for passive fingerprint scanning).
[0006] Document US 2019 / 0354988A1 describes a partial fingerprint and iris payment device comprising means for capturing partial fingerprints and irises, means for capturing payment fingerprints and irises, and a storage and matching unit; wherein the payment fingerprint and iris capture device serves to extract, during the user's payment, a fingerprint and iris of the user, each corresponding to the partial fingerprint and / or iris; and wherein the storage and matching unit serves, during the user's payment, to compare the partial fingerprint and / or iris with the fingerprint and / or iris, respectively, and, upon successful matching, to send a payment instruction. SUMMARY
[0007] Embodiments of the present invention relate to a fingerprint multi-factor authenticator. An exemplary computer-based method, which is not to be understood as a limitation, comprises randomly removing one or more features from a data record of a user's fingerprint image and generating a falsified data record of the fingerprint image. The generation of the falsified data record includes combining it with a user input code using an encryption method, wherein the falsified data record is recoverable based on the user's input code. The method further comprises registering the falsified data record to authenticate the user.
[0008] Other embodiments of the present invention implement features of the method described above in computer systems and computer program products.
[0009] Further technical features and advantages are achieved through the techniques of the present invention. Embodiments and aspects of the invention are described in detail herein and are considered part of the claimed subject matter. For better understanding, reference is made to the detailed description and the drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] The details of the exclusive rights described herein are fully set forth and expressly claimed in the illustrative claims at the end of the description. The above statements, as well as other features and advantages of the embodiments of the invention, will become clear from the following detailed description in conjunction with the accompanying drawings, in which: Fig. 1 shows a block diagram of an exemplary computer system for use in conjunction with one or more embodiments of the present invention; Fig. 2 shows a block diagram of a system for client-side generation of a multi-factor password, for authentication and / or updating for a user according to one or more embodiments of the present invention; Fig. 3 shows a flowchart of a process for client-side generation of a multi-factor password for a user according to one or more embodiments of the present invention; Fig. 4 shows a flowchart of a process for authentication with client-side generation of a multi-factor password for the user according to one or more embodiments of the present invention; Fig. 5 shows a flowchart of a process for updating a falsified fingerprint after successful login / authentication with client-side generation of a multi-factor password for the user according to one or more embodiments of the present invention; Fig. 6 shows an exemplary data set of fingerprint minutiae based on an analysis of the fingerprint image according to one or more embodiments of the present invention; Fig. 7 an example of minutiae fields in the fingerprint minutiae dataset in Fig. 6 according to one or more embodiments of the present invention; Fig. 8 shows a partial view of a data set of fingerprint minutiae, with compact arrows marking fields that can be selected for scrambling according to one or more embodiments of the present invention; Fig. 9 a partial view of exemplary minutiae fields in the exemplary dataset of fingerprint minutiae in Fig. Figure 8 shows, with compact arrows marking minutiae fields which can be selected for scrambling according to one or more embodiments of the present invention; Fig. 10 shows a flowchart of a computer-aided method for client-side generation of a multi-factor password, for authentication and / or updating according to one or more embodiments of the present invention; Fig. 11A shows ridges and grooves on a fingerprint image according to one or more embodiments of the present invention; Fig. 11B shows individual areas and key points in fingerprint images according to one or more embodiments of the present invention; Fig. 12 exemplary fingerprint classes according to one or more embodiments of the present invention are shown; Fig. 13A shows a fingerprint image according to one or more embodiments of the present invention; Fig. 13B an orientation image of the fingerprint image in Fig. 13A shows one or more embodiments of the present invention. Fig. Figure 13C shows a frequency pattern of the fingerprint image according to one or more embodiments of the present invention. Fig. 14 shows a fingerprint image which, according to one or more embodiments of the present invention, transitions into the corresponding orientation image; Fig. 15A shows a terminal minutiae according to one or more embodiments of the present invention; Fig. 15B shows a branching minutiae according to one or more embodiments of the present invention; Fig. 15C shows ends and branches according to one or more embodiments of the present invention; Fig. 16 shows a cloud computing environment according to one or more embodiments of the present invention; Fig. Figure 17 shows the layers of the abstraction model according to one or more embodiments of the present invention. DETAILED DESCRIPTION
[0011] According to one or more embodiments of the invention, a long password for user authentication is generated by incorporating a scanned biometric image, converted into a string, into a user-provided password. In particular, according to one or more embodiments of the invention, the biometric information and a user password are combined in such a way that the biometric information is not easily recognizable, and the user can generate a new user password using the same biometric information if the password is lost, thus creating a new long password. The resulting long password has the advantage of being sufficiently long to prevent unauthorized recovery, while the short user password remains easy to remember, as the user only needs to remember the short user password portion.
[0012] As computers become increasingly powerful, short passwords can be used. Long passwords are difficult to remember and are avoided by most users. Biometric information such as fingerprint data is sensitive and cannot be replaced if lost. While a password manager can be helpful, a traditional master password is still required to access the password manager itself.
[0013] According to one or more embodiments of the invention, for increased security, a very long password can be generated in such a way that it is easy to remember using a short user password. No password file needs to be stored on a specific user unit. According to one or more embodiments, no biometric information needs to be transmitted over the internet or the network, and no original format of the scanned biometric image (e.g., the fingerprint) is stored on any unit. Furthermore, according to one or more embodiments, existing scanning methods can be used to obtain the fingerprint image, and the fingerprint image can be converted into a string. The user can then be prompted to enter a user code / PIN / password, which is a short user password.The string representing the fingerprint image and the short user password (i.e., the user code / PIN entered by the user) can be combined using a procedure defined by an application, such that the resulting string cannot be easily decoded to break it down into its original components. According to the present explanation, no biometric information and / or a short user password need to be stored locally and / or on the server. The user only needs to remember the user password component, not the fingerprint part. The user can log in anywhere a scanner and appropriate software are available for this function. If the short password is lost and / or compromised, the biometric information is difficult for an unauthorized person to recover.The user can change the long password by changing the short user password (e.g., user code / PIN) and can then use the changed short user password along with their fingerprint to generate a new long password. The long password can also still be used for encryption based on the existing password.
[0014] Fig. Figure 1 shows a computer system 100 according to one or more embodiments of the invention. The computer system 100 can be an electronic computer system that includes and / or uses a number or combination of data processing units and networks that utilize various data transmission technologies described herein. The computer system 100 can be easily scalable, expandable, and modular, and capable of being adapted to different services or of having certain features changed independently of others. For example, the computer system 100 can be a server, a desktop computer, a laptop computer, a tablet computer, or a smartphone. According to some examples, the computer system 100 can be a cloud computing node.Computer System 100 can be generally described in connection with instructions executable by a computer system, such as program modules, which are executed by a computer system. In general, program modules can be routines, programs, objects, components, logic, data structures, and so on, which perform specific tasks or process certain abstract data types. Computer System 100 can be used in distributed cloud computing environments, where tasks are performed by remote processing units connected by a data transmission network. In a distributed cloud computing environment, program modules can reside on local as well as remote storage media of the computer system, including mass storage devices.
[0015] The computer system 100 according to Fig. 1 has one or more central processing units (CPUs) 101a, 101b, 101c, etc. (collectively or generally referred to as processor(s) 101). The processors 101 can be a single-core processor, a multi-core processor, a data processing cluster, or any number of other configurations. The processors 101, also referred to as processing units, are connected via a system bus 102 to a system memory 103 and various other components. The system memory 103 can contain a read-only memory (ROM) 104 and a random-access memory (RAM) 105. The ROM 104 is connected to the system bus 102 and can contain a basic input / output system (BIOS) or its successor, such as a Unified Expandable Firmware Interface (UEFI), which controls certain basic functions of the computer system 100.RAM is a read / write memory connected to the system bus 102 and used by the processors 101. System memory 103 provides temporary storage space for executing instructions during operation. System memory 103 can contain random access memory (RAM), read-only memory, flash memory, or any other suitable storage system.
[0016] The computer system 100 has an input / output (I / O) adapter 106 and a data transfer adapter 107, which are connected to the system bus 102. The I / O adapter 106 can be a SCSI adapter (Small Computer System Interface) that exchanges data with a hard disk 108 and / or another similar component. The I / O adapter 106 and the hard disk 108 are collectively referred to herein as mass storage 110.
[0017] Software 111 for execution on the computer system 100 can be stored in the mass storage device 110. The mass storage device 110 is an example of a physical storage medium readable by the processors 101, on which the software 111 is stored in the form of instructions for execution by the processors 101 to make the computer system 100 function as described herein with reference to the various figures. Examples of computer program products and the execution of such instructions are discussed in detail herein. The data transmission adapter 107 connects the system bus 102 to a network 112, which can be an external network that allows the computer system 100 to exchange data with other such systems.According to one embodiment, an operating system is stored jointly on a part of the system memory 103 and the mass storage 110, which can be any suitable operating system for controlling the functions of the various components shown in FIG: 1.
[0018] Further input / output units are shown, connected to the system bus 102 via a screen adapter 115 and an interface adapter 116. According to one embodiment, the adapters 106, 107, 115, and 116 can be connected to one or more I / O buses, which are connected to the system bus 102 via an intermediate bus bridge (not shown). A display 119 (e.g., a screen or a display monitor) is connected to the system bus 102 through the screen adapter 115, which may include a graphics controller to improve the performance of graphics-intensive applications and a video controller. A keyboard 121, a mouse 122, a speaker 123, a fingerprint scanner 124, etc., can be connected to the system bus 102 via the interface adapter 116, which may, for example, contain a super I / O chip that combines several unit adapters into a single integrated circuit.Suitable I / O buses for connecting peripheral devices such as hard disk controllers, network adapters, and graphics adapters typically include common protocols such as PCI (Peripheral Component Interconnect) and PCIe (Peripheral Component Interconnect Express). This is according to... Fig. 1 configured computer system 100 thus includes processing capabilities in the form of processors 101 and storage capabilities such as system memory 103 and mass storage 110, input devices such as the keyboard 121 and mouse 122 and output capabilities such as the speaker 124 and the screen 119.
[0019] According to some embodiments, the data transmission adapter 107 can transmit data using any suitable interface or protocol, such as Internet SCSI and the like. The network 112 can be a cellular network, a radio network, a wide area network (WAN), a local area network (LAN), the Internet, and the like. An external data processing unit can be connected to the computer system 100 through the network 112. According to some examples, the external data processing unit can be an external web server or a cloud computing node.
[0020] It should be clear that the block diagram of Fig. 1. It should not be displayed that the computer system 100 all in Fig. The computer system should contain the components shown in point 1. Rather, it can contain arbitrarily fewer or additional suitable components, which are located in 100. Fig. 1 are not shown (e.g., additional memory components, embedded controllers, modules, additional network interfaces, etc.). Furthermore, the embodiments described herein with reference to computer system 100 can be implemented with any suitable logic, wherein, in this sense, the logic may comprise, in various embodiments, any suitable hardware (e.g., a processor, an embedded controller, or an application-specific integrated circuit, and the like), software (e.g., an application, and the like), firmware, or any suitable combination of hardware, software, and firmware.
[0021] Fig. Figure 2 shows a block diagram of a system 200 for client-side generation of multi-factor passwords, for authentication and / or updating for a user according to one or more embodiments of the present invention. Fig. Figure 2 shows a computer system 202 connected to one or more units and / or computer systems 270. The computer system 202 is configured to generate a long password for the user based on a short password and biometric information, to confirm the long password after subsequent input, and / or to update the long password at predetermined intervals. The computer system 202 is configured to allow access, after authentication, to the computer system 202, one or more units and / or computer systems 270, a network, etc. Elements of the computer system 100 can be used in or integrated with the computer system 202, along with units and / or computer systems 270, to function as discussed herein.According to one or more embodiments, the computer system 202 can exchange data with units and / or computer systems 270 via wireless and / or wired connections of the network 206.
[0022] Fig. Figure 3 illustrates a flowchart of a process 300 for client-side generation of multi-factor passwords for a user according to one or more embodiments of the present invention. The process 300 is described with reference to Fig. 2 described. Software applications 204 on computer system 202 are configured to request and / or receive a code / PIN and a fingerprint image from a user 210 as user input in block 302. The user input code, for example, the sequence of digits 0486, can be entered using any input device such as a keyboard, mouse, touchscreen, microphone, etc. A biometric scanner / converter 230 is configured to scan the finger of user 210 in order to obtain the fingerprint image via the fingerprint scanner 124. The biometric scanner / converter 230 can be integrated into or connected to computer system 202. The software applications 204 are configured to digitize the user input code, which is the short user password, into a binary string of zeros and ones (e.g., 0 and 1) in block 304.The digitized user entry code is used for the subsequent steps discussed herein. The user entry code can be a short PIN, for example, a four-digit code used as a short user password.
[0023] The software applications 204 on the computer system 202 are configured to convert the received fingerprint image into a data record 220 of the fingerprint minutiae of the fingerprint image in block 306. The data record of fingerprint minutiae can also be referred to as a fingerprint minutiae template or simply as a template. Fig. Figure 6 is an exemplary dataset 220 of fingerprint minutiae based on analyzing the fingerprint image and extracting the features. The dataset 220 of fingerprint minutiae can utilize the standard ISO / IEC 19794-2:2005. The software applications 204 can include and / or utilize one or more suitable algorithms for analyzing the fingerprint image and extracting the minutiae, which is known to those skilled in the art.
[0024] The software applications 204 on computer system 202 are configured to randomly remove some and / or all minutiae above a minimum possible minutiae threshold from block 308 and then digitize the fingerprint minutiae dataset 220. Depending on the resolution of the fingerprint scanner and the finger's position on the sensor, a high-quality fingerprint image can contain between 25 and 80 minutiae. To determine a match between two sets of fingerprints, the software applications 204 can identify a match of between 12 and 20 points (or minutiae). In the fingerprint minutiae dataset 220, "n" denotes the number of minutiae fields. Fig. Figure 7 shows an example of minutiae fields in dataset 220 of fingerprint minutiae. Fig. Each of the minutiae contains the X-field, the Y-field, the direction, and the papillary ridge type. A match between two sets of fingerprints can be established if, for example, 12 minutiae match. For illustrative purposes, and not as a limitation, it can be assumed that 12 minutiae must match before a fingerprint match can be established, and that the exemplary minimum threshold for minutiae is 22. Accordingly, the software applications are configured to ensure that at least 22 minutiae remain for (subsequent) comparison after minutiae have been randomly removed from the dataset of 220 fingerprint minutiae.For example, a fingerprint minutiae dataset has 25 minutiae, and accordingly, the software applications 204 can remove at most 25 - 22 = 3 minutiae (or minutiae values) from the fingerprint minutiae dataset to comply with the example minimum minutiae threshold of 22 minutiae. After the minutiae have been randomly removed, the software applications 204 digitize the values of all remaining minutiae into strings of zeros and ones (0 and 1) in the fingerprint minutiae dataset 220. Furthermore, the real data can be additionally masked by omitting or modifying some information to generate further unknowns. The more unknowns there are, the more difficult it becomes to gain unauthorized access.Starting with a fingerprint minutiae dataset, or fingerprint template, which, according to the following discussion, eventually leads to a corrupted fingerprint minutiae dataset that is constantly changing, it becomes increasingly difficult to gain unauthorized access if there is only a single stored fingerprint template. It is assumed that there are, on average, 25 minutiae per scanned fingerprint, and that the software applications 204 randomly omit or modify 3 minutiae, such that the software applications 204 select 3 out of 25 minutiae to be omitted. Accordingly, the number of combinations 3 out of 25 (without regard to order) is: C = (N!) / [k! (Nk)!] = 25! / [3! (22!)] = 2300 combinations. Accordingly, the number 2.300 an increase in the random combinations used to modify the data set 220 of fingerprint minutiae, ensuring that each of the new fingerprint scans is unique.
[0025] The software applications 204 on computer system 202 are configured to run in block 310 of Fig. 3. Form a falsified dataset 220 of fingerprint minutiae by merging the dataset 220 of fingerprint minutiae (from which minutiae have been randomly removed) and the digitized user code (i.e., a PIN or short password). According to one or more embodiments, the merging / scrolling can be done using format-preserving encryption, also known as format-preserving encryption (FPE), where the encryption is performed in such a way that the output (e.g., the ciphertext) is in the same format as the input (e.g., the unencrypted text). This makes it significantly more difficult for an unauthorized person to use brute-force techniques (e.g., rainbow tables, mountaineering, etc.).) in an attempt to determine which password code rearranges the falsified fingerprint minutiae record / template to produce the actual fingerprint minutiae record / template, since all incorrect password codes decrypt the falsified fingerprint minutiae record / template to reveal it as the legitimate fingerprint minutiae record / template. One or more minutiae fields are scrambled using the user code such that fingerprint minutiae record 220 becomes the falsified fingerprint minutiae record 224. It should be obvious that the minutiae fields can be randomly omitted before, after, and / or during the scrambling, although random omission before scrambling might be more effective.The software applications 204 may contain and / or use various algorithms or techniques for scrambling certain minutia fields using the user input code. As an illustrative example, the value of the minutia fields (0 to 255) is modified based on the user input code (e.g., 0486) to generate different values from 0 to 255 for the minutia fields in a way that can be reversed during authentication. For an input code of 0486 (from which, for example, "48" is selected) and a minutia field with the value 115, scrambling results in 115 + 48 = 163. The scrambled value is then reversed if it is greater than (>) 255. The software applications 204 are configured to also populate the attribute fields when they generate more minutias. Additionally and / or alternatively, the fields for the x and y minutiae positions are based on the input code (e.g.The input code 0486 is modified to generate various valid positions in a way that can be reversed during authentication. For example, using a value from 0 to 512 for the x-coordinate and a value from 0 to 512 for the y-coordinate, while simultaneously using the input code 0486, x = 213 and the addition of 86 result in a scrambled x-value of 299, and y = 24 and the addition of 68 result in a scrambled y-value of 102. If either x-value or y-value is greater than 512, that value is wrapped cyclically. Furthermore, the direction angle field of the minutiae position (which generally ranges between 0 and 255) can be modified based on the user input code (e.g., 0486) to generate various valid angles analogous to the examples discussed herein.While simple modifications using additions have been discussed for illustrative purposes, more complex modifications and steps are conceivable and can be used. Furthermore, other fingerprint minutiae fields can also be modified. According to one or more embodiments, the scrambling can be performed slightly differently on each user unit (e.g., on computer system 202). In other words, the falsification / scrambling algorithm has a random seed value that makes each unit unique by using the minutiae value + user input code + random seed value = scrambled minutiae value, and then the scrambled value is cyclically redrawn when an overflow occurs above the required value for the scrambled minutiae field. The units can use the same algorithm as above, but with the addition of a unique unit field for each unit (e.g.,A unique field (= 7) was added. Using the unique field and again the example user input code 0486, the resulting value would be 115 + 48 + 7 = 163 + 7 = 170. This unique unit field serves as the random starting value.
[0026] In blocks 312 and 314, the falsified fingerprint minutiae dataset 224 is encrypted and stored for later authentication, while the original fingerprint image and minutiae are not stored. Blocks 310 and 312 are executed individually and / or concurrently. Block 312 can be executed optionally. For example, the encryption algorithm (e.g., through format-preserving encryption) can incorporate the user code into the encryption process and thereby simultaneously or nearly simultaneously scramble minutiae fields in fingerprint minutiae dataset 220 to form a falsified fingerprint minutiae dataset 224 and encrypt the falsified fingerprint minutiae dataset 224. The software applications 204 can contain and / or use different encryption algorithms that can be decrypted using the user input code.Examples of algorithms suitable for encryption and / or scrambling include hash functions, symmetric encryption algorithms, asymmetric encryption algorithms, format-preserving encryption, etc. It should be clear that the falsified fingerprint data set 224 is a long password representative of user 210, while user 210 only needs to remember the user input code, which is a short password (e.g., a four-digit PIN). The long password is generated automatically and is a result of the fingerprint and the user input code, neither of which is stored on computer system 202.
[0027] Fig. Figure 4 illustrates a flowchart of a process 400 for authentication with client-side generation of a multi-factor password for the user according to one or more embodiments of the present invention. Blocks 402, 40, and 406 are analogous to blocks 302, 304, and 306 discussed above and are only briefly discussed here. In this scenario, the user 210 requests access to, for example, a computer system 202, units and / or computer systems 270, a network 206, etc., and must authenticate before access is granted. The software applications 204 on the computer system 202 are configured to receive the user input code and a new record 240 of fingerprint minutiae in blocks 402, 404, and 406, convert the new fingerprint image into a new record 240 of fingerprint minutiae, and digitize the user input code. The user input code should be the same user input code as before (e.g.,...).B. 0486). The software applications 204 on the computer system 202 are configured to decrypt the falsified fingerprint minutiae data set 224 in block 408 using the user input code and to reverse the falsification / jumble of the falsified fingerprint minutiae data set 224 using the user input code by reversing the operations performed on the jumbled minutiae fields in block 410. According to one or more embodiments, blocks 408 and 410 can be executed simultaneously and / or nearly simultaneously, since the encryption technique / algorithm can instantaneously decrypt the falsified data set 224 and reverse the falsification / jumble of the fingerprint minutiae.The software applications 204 on computer system 202 are configured to use the falsified fingerprint minutiae dataset 224 to reconstruct the fingerprint image 280 of user 210 that was previously scanned. Because minutiae were randomly removed from fingerprint minutiae dataset 220, the reconstructed fingerprint image 280 has fewer minutiae than the original fingerprint previously obtained, but the number of minutiae is still at or above the minimum minutiae threshold discussed in Block 308. As mentioned above, a match between two fingerprints can be established if 12 to 20 points / minutiae match, and in the exemplary scenario, the exemplary minimum minutiae threshold is 22.Accordingly, the reconstructed fingerprint image 280 has at least 22 minutiae and / or was reconstructed using at least 22 minutiae values. The software applications 204 may include and / or use one or more suitable algorithms or techniques for reconstructing a fingerprint image from a dataset of fingerprint minutiae, which should be clear to a person skilled in the art.
[0028] The software applications 204 on computer system 202 are configured to run in block 412 of Fig. 4. Compare the new fingerprint image and / or the new fingerprint minutiae record 240 with the recovered fingerprint image 280 or fingerprint minutiae record 220, respectively. The software applications 204 on computer system 202 are configured to determine, in the event of a match, that the user has authenticated successfully and grant access in block 414. The software applications 204 on computer system 202 are configured to determine, in the event of a lack of match, that authentication has failed and deny access in block 416.
[0029] Fig. Figure 5 illustrates a flowchart of a process 500 for updating a falsified fingerprint after a successful login / authentication with client-side generation of a multi-factor password for the user according to one or more embodiments of the present invention. The software applications 204 on the computer system 202 are configured to periodically update the falsified fingerprint and / or the falsified fingerprint minutiae dataset. According to one or more embodiments, the falsified fingerprint and / or the falsified fingerprint minutiae dataset can be updated after each successful login. Similarly, blocks 308, 310, and 312 are updated using the new fingerprint image in the form of blocks 508, 510, and 512. Fig. 5 repeated. The software applications 204 on the computer system 202 are configured to, for example, after successful authentication of the user 210, remove some and / or all minutiae above a minimum minutiae threshold from the new fingerprint minutiae record 240 and then digitize the new fingerprint minutiae record 240 in block 508. The software applications 204 on the computer system 202 are configured to create a new falsified fingerprint record 244 in block 510 by merging fingerprint minutiae record 240 and the digitized user code (i.e., the PIN or a short password) and by encrypting the falsified fingerprint minutiae record 244 in block 512.The software applications 204 on the computer system 202 are configured to store the new falsified record 244 of fingerprint minutiae in block 514 instead of the older version of the falsified record 224 of fingerprint minutiae.
[0030] The following section discusses the scrambling of the minutiae fields. To illustrate, example minutiae fields created using the user input code in the Fig. 8 and Fig. If the 9 characters are to be scrambled / distorted, compact striped arrows are used. As mentioned above, scrambling can be a type of format-preserving encryption, but other types of encryption can also be used. Fig. Figure 8 shows a partial view of an example dataset of fingerprint minutiae, in which compact striped arrows indicate one or more fields that can be selected for scrambling by the software applications 204. The software applications 204 can randomly select one or more fields to be scrambled in Fig. Select 8. Fig. Figure 9 shows a partial view of exemplary minutiae fields from the number n minutiae fields in the exemplary dataset of fingerprint minutiae, where the compact striped arrows again denote one or more minutiae fields that can be selected for scrambling by the software applications 204. Likewise, the software applications 204 in Fig. 9 one or more minutiae fields are selected at random.
[0031] Regarding further details contained in the fingerprint minutiae dataset and their description of the fingerprint image, a fingerprint is an image of the dermis of a fingertip, created when a finger is pressed against a flat surface. The main structural features of a fingerprint consist of a pattern of interlocking papillaries (also called papillary ridges) and grooves according to Fig. 11A, which often run parallel. In general, fingerprint patterns exhibit one or more areas where the papillary ridges take on specific shapes (characterized by strong curvature, frequent ends, etc.). These areas (also called singularities or singular regions) can be classified into three types: loop, delta, and whorl, which are described in Fig. Figure 11B shows that singular regions belonging to the loop, delta, and vortex types are typically characterized by n-, Δ-, and O-shapes, respectively. Fig. 11B are singular areas illustrated by white outlines and core points by small circles in fingerprint images. Fig. Figure 12 shows singular areas commonly used to classify fingerprints, which assign a fingerprint to a class from a set of distinct classes, thus simplifying the search and retrieval process. Fig. Figure 12 shows the five most common classes of the Galton-Henry classification scheme: arch, tented arch, left loop, right loop, and whorl, with the positions of the singularities graphically indicated. (1) Arch fingerprints have ridges that enter from one side, lead to a small bulge, and exit on the opposite side: there is no singularity. (2) Tented-arch fingerprints resemble arch fingerprints, but some papillary ridges have a strong curvature, and there is only one loop and one delta (usually vertically oriented). (3) Left / right loop fingerprints have one or more ridges that enter from the left (right) side, reverse direction, and exit on the entry side; there is a loop and a delta singularity: the loop is usually on the left (right) side of the delta with respect to the vertical axis.(4) Whorl fingerprints contain two loop singularities (or a single whorl which can be regarded as two opposing loops at the same location) and two delta singularities; the whorl class is the most complex, and in one classification scheme this class is further divided into several subclasses. Various fingerprint comparison algorithms (which may be included in and / or used by the software applications 204) align the fingerprint images to a center point (kernel), which is usually defined as the position of the uppermost loop singularity or as the point of greatest papillary ridge curvature for fingerprints corresponding to that in . Fig. 11B shown bow class belong to.
[0032] From the fingerprint in Fig. 13A A papillary ridge pattern can be successfully described by the directional image, which is a discrete matrix whose elements represent the local orientation of the in Fig. The papillary ridges shown in 13B are characterized by the exemplary element [x, y] of the directional image, represented as angle Φ. xy defined by the tangent to the fingerprint papillary ridges in the corresponding local neighborhood of the image with the in Fig. The horizontal axis shown in Figure 14 forms the basis of this calculation. Similarly, the local papillary ridge frequency (defined as the number of papillary ridges per unit length) can be determined using a formula shown in [reference missing]. Fig. The frequency pattern shown in 13C can be successfully represented. 13B is a directional image of the fingerprint in Fig. 13A, while Fig. 13C is a frequency pattern of the fingerprint, in which lighter blocks in the pattern indicate areas of higher frequency. At a more detailed level, other important features can be identified, called minutiae. Minutiae are irregularities in the papillary ridges that can be classified into various types: end, branch, island, spot, lake, and so on. Usually, only a rough classification, as in the Fig. 15A, Fig. 15B and Fig. 15C is applied, in which the two classification types end (the point at which a papillary ridge abruptly ends) and branch (the point at which a papillary ridge branches into two ridges) play a role. A minuciate point can be classified according to its type, the coordinates x and y, and the direction θ according to the Fig. 15A and Fig. 15B will be defined. Fig. Figure 15A illustrates an end minutiae where (x, y) are the minutiae coordinates and θ is defined as the mean direction of the tangents to the two grooves enclosing the end and is measured counterclockwise to the right from the horizontal axis. Fig. Figure 15B illustrates a branching minuctia where θ is defined as the mean direction of the tangents to the two papillary ridges enclosing the terminal groove and is measured counterclockwise to the right from the horizontal axis. Fig. 15C illustrates ends (white circles) and branches (grey circles) in an example fingerprint.
[0033] The ISO / IEC 19794-2:2005 standard specifies data formats for representing fingerprints based on minutiae and defines a general data set format that can contain one or more templates of one or more fingerprints. The ISO / IEC 19794-2:2005 standard is intended for use in a wide range of applications involving automatic fingerprint recognition. The standard defines relevant terms, describes how the type, position, and orientation of minutiae are to be determined, and specifies the permissible formats for storing the data. The standard is used to reconstruct the fingerprint image.The Fingerprint Minutiae Record Format defines the basic data elements used to represent a fingerprint based on minutiae, and optionally, extended data formats to capture additional data such as the number of papillaries and the location of singularities. The table summarizes the record structure and the main fields (including all fields required to reconstruct the fingerprint image). The fingerprint minutiae record contains record header data with general information (for example, the image size) and the number of fingerprints represented (finger views). For each finger view, the corresponding single-finger record contains minutiae data (mandatory) and extended data (optional).For each minuzie, the corresponding finger minuzie record (2 bytes) contains the minuzie type (end, branch, or other), where "other" is defined as a minuzie type that can be matched to any type (this can denote either an unknown type or a type other than end / branch). The finger minuzie record contains the position x and y of the minuzie, expressed in pixels of the coordinate system, and the values in the... Fig. 15A and Fig. 15B measures the direction θ of the minutiae, recorded as one byte in units of 1.40625 (360 / 256) degrees. The finger minutiae dataset also includes a minutiae quality score ranging from 1 (lowest quality) to 100 (highest quality), or 0 if no quality data is provided. The extended data is intended to contain additional information that can be used by the comparison algorithm.
[0034] Among the many advantages of one or more embodiments of the invention is the ability to fully utilize format-preserving encryption, a technique already used for credit cards, to make it more difficult to gain unauthorized access using brute force techniques. This is achieved when attempting to identify which user input code reverses the falsification of the falsified fingerprint data set in order to generate the genuine fingerprint data set, since all attempted user input codes decrypt the falsified fingerprint template, revealing it to be the legitimate fingerprint data set. The complete end-to-end system and method are novel.By automatically deleting the previously stored falsified fingerprint minutiae dataset from the previous fingerprint scan, which was falsified with the user entry code and stored during login, and by replacing it with a rescanned fingerprint containing a new falsified fingerprint minutiae dataset at any time and / or at any given time (e.g., at predetermined intervals), it becomes significantly more difficult for an unauthorized person to simply try all user entry codes and then analyze the results of the attempts to identify the most likely genuine fingerprint minutiae dataset. Removing (or altering) some fingerprint minutiae to create unique yet valid fingerprint images further increases robustness against unauthorized access.
[0035] Fig. Figure 10 is a flowchart of a computer-aided method 1000 for client-side generation, authentication, and updating of a multi-factor password according to one or more embodiments of the present invention. The software applications 204 on the computer systems 202 are configured to randomly remove one or more features of a data record (e.g., data record 220 of fingerprint minutiae) of a fingerprint image of a user 210 in block 1002. The software applications 204 on the computer systems 220 are configured to generate a falsified data record (e.g., the falsified data record 224 of fingerprint minutiae) of the fingerprint image in block 1004 by combining it with a user input code (e.g., with the input code 0486) using an encryption technique, wherein the falsified data record is recoverable using the user input code.The software applications 204 on the computer systems 202 are configured to record the falsified data set in block 1006 for the (subsequent) authentication of user 210.
[0036] The creation of the falsified fingerprint image record further includes converting the fingerprint image record into a string (e.g., fields of record 220 of fingerprint minutiae can be converted into strings), digitizing the user input code (e.g., 0486) into another string, and concatenating the string with the other string. The user input code is not stored locally on computer system 202 and / or on other computer systems. The fingerprint image is not stored locally on computer system 202 and / or on other computer systems. The software applications 204 on computer systems 202 are configured to, in response to receiving a new fingerprint entered by the user, convert the falsified record (e.g., the falsified record 224 of fingerprint minutiae) into a new falsified record (e.g.,the new falsified record 244 of the fingerprint minutiae) of the new fingerprint. The falsified record is continuously / automatically updated by a new falsified record of a new fingerprint at a predetermined interval, for example, after each successful authentication, after a predetermined number of successful authentications, periodically on a specific date (e.g., weekly, monthly, etc.), etc. The software applications 204 are configured to retrieve the falsified record (e.g., the falsified record 224 of the fingerprint minutiae) in response to receiving a new fingerprint and user input code entered by the user, and to update the falsified record of the fingerprint image with the user input code (e.g.,(using the user input code 0486) to decrypt the string, convert the string back into the fingerprint image record, and compare the fingerprint image record with a new record of the new fingerprint. The software applications 204 are configured to determine authentication as successful if the record matches the new fingerprint record, i.e., if the (previously stored) fingerprint minutiae record 220 matches the new fingerprint minutiae record 240, and to determine authentication as unsuccessful if the record does not match the new fingerprint record.
[0037] It should be clarified from the outset that the implementation of the teachings set forth herein is not limited to a cloud computing environment, although this disclosure contains a detailed description of cloud computing. Rather, embodiments of the present invention can be implemented together with any type of data processing environment, now known or subsequently invented.
[0038] Cloud computing is a service delivery model that enables seamless, on-demand network access to a shared pool of configurable computing resources (e.g., networks, network bandwidth, servers, processing power, main memory, storage, applications, virtual machines, and services) that can be rapidly provisioned and released with minimal management overhead or interaction with a service provider. This cloud model can have at least five characteristics, at least three service models, and at least four implementation models.
[0039] The properties are as follows: On-Demand Self-Service: A cloud user can unilaterally and automatically provide data processing functions such as server time and network storage as needed, without requiring human interaction with the service provider. Broad Network Access: Functions are available over a network, accessed through standard mechanisms that support use by heterogeneous thin or thick client platforms (e.g., mobile phones, laptops, and PDAs). Resource pooling: The provider's data processing resources are pooled to serve multiple users using a multi-tenant model, with various physical and virtual resources being dynamically allocated and reassigned as needed. There is a perceived location independence, as the user generally has no control over or knowledge of the exact location of the provided resources, but may be able to define a location at a higher level of abstraction (e.g., country, state, or data center). Rapid Elasticity: Features can be deployed quickly and elastically for rapid horizontal scaling (scale out), in some cases automatically, and released quickly for rapid scale-in. To the user, the available features often appear unlimited and can be purchased in any quantity at any time. Measured Service: Cloud systems automatically control and optimize resource usage by employing a measurement function at a certain level of abstraction appropriate for the type of service (e.g., storage, processing, bandwidth, and active user accounts). Resource usage can be monitored, controlled, and reported, thereby creating transparency for both the provider and the user of the service.
[0040] The service models are as follows: Software as a Service (SaaS): The functionality provided to the user consists of using the provider's applications running in a cloud infrastructure. These applications are accessible from various client devices via a thin-client interface, such as a web browser (e.g., web-based email). The user does not manage or control the underlying cloud infrastructure, including the network, servers, operating systems, storage, or even individual application functions, with the possible exception of limited user-specific application configuration settings. Platform as a Service (PaaS): The function provided to the user is to deploy applications created or obtained by the user, using programming languages and tools supported by the provider, within the cloud infrastructure. The user does not manage or control the underlying cloud infrastructure, including networks, servers, operating systems, or storage, but has control over the deployed applications and potentially over configurations of the application hosting environment. Infrastructure as a Service (IaaS): The functionality provided to the user consists of supplying processing, storage, networking, and other basic data processing resources, enabling the user to deploy and run any software, including operating systems and applications. The user does not manage or control the underlying cloud infrastructure but has control over operating systems, storage, deployed applications, and potentially limited control over selected network components (e.g., host firewalls).
[0041] The following are the deployment models: Private Cloud: The cloud infrastructure is operated solely for one organization. It can be managed by the organization or a third party and can be located on the organization's own premises or on external premises. Community Cloud: This cloud infrastructure is shared by multiple organizations and supports a specific user community with shared concerns (e.g., mission, security requirements, policies, and regulatory compliance considerations). It can be managed by the organizations themselves or a third party and can be located on-premises or external premises. Public Cloud: The cloud infrastructure is made available to the general public or a large industry group and is owned by an organization that sells cloud services. Hybrid Cloud: The cloud infrastructure is a composition of two or more clouds (private, community or public) that remain separate entities but are connected by a standardized or proprietary technology that enables data and application portability (e.g. cloud audience distribution for load balancing between clouds). A cloud computing environment is service-oriented, focusing on statelessness, low coupling, modularity, and semantic interoperability. At the heart of cloud computing lies an infrastructure that comprises a network of interconnected nodes.
[0042] With reference to Fig. Figure 16 illustrates the cloud computing environment 50. As shown, the cloud computing environment 50 has one or more cloud computing nodes 10 with which local data processing units used by cloud users, such as the electronic assistant (PDA, personal digital assistant) or mobile phone 54A, the desktop computer 54B, the laptop computer 54C, and / or the automotive computer system 54N, can exchange data. The nodes 10 can exchange data with each other. They can be grouped physically or virtually into one or more networks, such as private, community, public, or hybrid clouds (not shown), as described above, or into a combination thereof. This enables the cloud computing environment 50 to offer infrastructure, platforms, and / or software as a service, for which a cloud user does not need to maintain resources on a local data processing unit.It should be noted that the types of in . Fig. The data processing units 54A to N shown in Figure 16 are intended to be illustrative only, and the data processing nodes 10 and the cloud computing environment 50 can exchange data with any type of computer unit via any type of network and / or any type of network-accessible connection (e.g., using a web browser).
[0043] With reference to Fig. 17 shows a set of functional abstraction layers that are used by the cloud computing environment 50 ( Fig. 16) will be provided. It should be clear from the outset that the in Fig. The components, layers, and functions shown in Figure 17 are intended to be illustrative only, and embodiments of the invention are not limited to them. As shown, the following layers and corresponding functions are provided:
[0044] A hardware and software layer 60 comprises hardware and software components. Examples of hardware components include: mainframe computers 61; servers based on the RISC (Reduced Instruction Set Computer) architecture 62; servers 63; blade servers 64; storage units 65; and networks and network components 66. In some embodiments, software components include network application server software 67 and database software 68.
[0045] A virtualization layer 70 provides an abstraction layer from which the following examples of virtual entities can be provided: virtual servers 71, virtual storage 72, virtual networks 73, including virtual private networks, virtual applications and operating systems 74; and virtual clients 75.
[0046] In one example, the administration layer 80 can provide the functions described below. Resource provisioning 81 provides the dynamic procurement of data processing resources and other resources used to perform tasks within the cloud computing environment. Metering and pricing 82 provides cost tracking for the use of resources within the cloud computing environment and billing for the use of these resources. In one example, these resources might include application software licenses. Security provides identity verification for cloud users and tasks, as well as protection for data and other resources. A user portal 83 provides users and system administrators with access to the cloud computing environment.Service scope management (84) provides the allocation and management of cloud computing resources so that the required service objectives are met. Service level agreement (SLA) planning and fulfillment (85) provides the advance planning and procurement of cloud computing resources for which a future requirement is anticipated, in accordance with an SLA.
[0047] A workload layer 90 provides examples of the functionality for which the cloud computing environment can be used. Examples of workloads and functions that can be provided by this layer include: mapping and navigation 91; software development and lifecycle management 92; delivery of training in virtual classrooms 93; data analytics processing 94; transaction processing 95; and software applications running in workloads and functions 96 (e.g., software applications 204, encryption / decryption algorithms, etc.).
[0048] This document describes various embodiments of the invention with reference to the accompanying drawings. Alternative embodiments of the invention are also conceivable without deviating from the scope of protection of this invention. The following description and the drawings specify various connections and positional relationships (e.g., above, below, adjacent, etc.) between elements. Unless otherwise specified, these connections and / or positional relationships can be direct or indirect, and the invention is not intended to be limited in this respect. Accordingly, a connection can refer to either a direct or an indirect connection, and a positional relationship between units can be either a direct or indirect positional relationship.Furthermore, various tasks and process steps described herein may be incorporated into a more comprehensive procedure or process with further steps or functionalities not described in detail herein.
[0049] One or more of the methods described herein may be implemented using any or a combination of the following technologies, which are generally known in the art: one or more discrete logic circuits with logic gates for implementing logical functions for data signals, an application-specific integrated circuit (ASIC) with associated combinational logic gates, one or more programmable gate arrays (PGAs), a field-programmable gate array (FPGA), etc.
[0050] For the sake of brevity, conventional techniques for generating and using aspects of the invention may not be described in detail. In particular, various aspects of data processing systems and special computer programs for implementing various technical features described herein are generally known. Accordingly, many implementation details are only briefly mentioned here or omitted entirely, without going into detail about generally known systems and / or processes.
[0051] According to some embodiments, various functions or actions can be performed at a specific location and / or in connection with the operation of one or more devices or systems. According to some embodiments, part of a specific function or action can be performed at a first unit or location, and the remainder of the function or action can be performed at one or more further units or locations.
[0052] The terms used herein serve only to describe individual embodiments and are not to be understood as limitations. The singular forms "a," "an," and "the" are used herein to include the plural forms unless otherwise indicated by the context. Furthermore, it should be clear that the terms "indicates" and / or "indicating," when used in this description, denote the presence of specified features, integers, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or their groups.
[0053] The corresponding structures, materials, actions, and equivalents of all means or steps, plus functional elements, in the following claims are intended to include all structures, materials, or actions for performing the function in combination with other expressly claimed elements. The present disclosure is provided for illustrative and descriptive purposes only and does not claim to be exhaustive or limited to the disclosed form. Many modifications and variants are obvious to those skilled in the art without deviating from the scope of protection of the disclosure. The embodiments have been chosen and described to best explain the basic ideas of the disclosure and its practical application, and to enable other skilled persons to understand the disclosure for various embodiments with different modifications suitable for the respective intended uses.
[0054] The diagrams shown herein are for illustrative purposes. Many variations of the diagram or the steps (or operations) described herein are possible without deviating from the scope of protection of the disclosure. For example, the actions can be performed in a different order, or actions can be added, removed, or modified. Furthermore, the term "connected" describes the existence of a signal path between two elements, but this should not be understood as a direct connection between the elements without intermediary elements / connections. All these variations are to be considered part of the present disclosure.
[0055] The following definitions and abbreviations are used for the interpretation of the claims and the description. The terms “include”, “include”, “contain”, “has”, “having”, “contains”, or “containing”, or any other variations thereof, are intended to represent non-exclusive inclusion. For example, a composition, mixture, process, method, article, or apparatus comprising a list of elements is not necessarily limited to those elements alone, but may also include other elements not expressly listed or inherent in such composition, mixture, process, method, article, or apparatus.
[0056] Furthermore, the term "exemplary" is used herein in the sense of "serving as an example, case, or illustration." Any embodiment or design described herein as "exemplary" should not necessarily be considered preferable or advantageous over other embodiments or designs. The terms "at least one" and "one or more" are to be understood as including any integer greater than or equal to one, i.e., one, two, three, four, etc. The term "a plurality" is to be understood as including any integer greater than or equal to two, i.e., two, three, four, five, etc. The term "connection" may include both an indirect and a direct connection.
[0057] The terms "approximately", "essentially", "approximately" and their variants are intended to express the degree of error associated with a measurement of the quantity in question, based on the equipment available at the time the application was filed. For example, the term "approximately" can encompass a range of ± 8%, 5%, or 2% of a given value.
[0058] The present invention may be a system, a method, and / or a computer program product at any possible level of integration. The computer program product may include a computer-readable storage medium (or media) containing computer-readable program instructions to induce a processor to execute aspects of the present invention.
[0059] A computer-readable storage medium can be a physical unit capable of retaining and storing instructions for use by a system to execute instructions. For example, a computer-readable storage medium can be an electronic storage unit, a magnetic storage unit, an optical storage unit, an electromagnetic storage unit, a semiconductor storage unit, or any suitable combination thereof, without limitation. A non-exhaustive list of more specific examples of computer-readable storage media includes the following: a removable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), and erasable programmable read-only memory (EPROM).Flash memory), static random-access memory (SRAM), removable compact storage disk-read-only memory (CD-ROM), a DVD (digital versatile disc), a USB flash drive, a floppy disk, a mechanically coded unit such as punched cards or raised structures in a groove on which instructions are stored, and any suitable combination thereof. A computer-readable storage medium shall not, in its use herein, be understood as volatile signals per se, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission medium (e.g., light pulses traveling through an optical fiber cable), or electrical signals transmitted by a wire.
[0060] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to individual data processing units or, via a network such as the internet, a local area network, a wide area network, and / or a wireless network, to an external computer or external storage device. The network may include copper transmission cables, fiber optic transmission lines, wireless transmission, routing computers, firewalls, switching units, gateway computers, and / or edge servers. A network adapter card or network interface in each data processing unit receives computer-readable program instructions from the network and forwards them for storage on a computer-readable storage medium within the respective data processing unit.
[0061] Computer-readable program instructions for executing the steps of the present invention can be assembly instructions, ISA (Instruction Set Architecture) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, or either source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, etc., as well as conventional procedural programming languages such as C or similar languages. The computer-readable program instructions can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server.In the latter case, the remotely located computer can be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be established with an external computer (for example, via the internet using an internet service provider). In some embodiments, electronic circuits, including, for example, programmable logic circuits, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs), can execute the computer-readable program instructions by using state information from the computer-readable program instructions to personalize the electronic circuits to perform aspects of the present invention.
[0062] Aspects of the present invention are described herein with reference to flowcharts and / or block diagrams or charts of methods, devices (systems), and computer program products according to embodiments of the invention. It is pointed out that each block of the flowcharts and / or block diagrams or charts, as well as combinations of blocks in the flowcharts and / or block diagrams or charts, can be executed by means of computer-readable program instructions.
[0063] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a specialized computer, or another programmable data processing device to create a machine, such that the instructions executed via the processor of the computer or other programmable data processing device generate a means of implementing the functions / steps specified in the block(s) of the flowcharts and / or block diagrams or charts.These computer-readable program instructions may also be stored on a computer-readable storage medium capable of controlling a computer, programmable data processing device and / or other units to function in a particular manner, such that the computer-readable storage medium on which instructions are stored has a manufactured product, including instructions that implement aspects of the function / step specified in the block(s) of the flowchart and / or block diagrams or charts.
[0064] The computer-readable program instructions can also be loaded onto a computer, other programmable data processing device, or other unit to cause the execution of a series of process steps on the computer or other programmable device or other unit in order to generate a process executed on a computer, such that the instructions executed on the computer, other programmable device, or other unit implement the functions / steps specified in the block(s) of the flowcharts and / or block diagrams or charts.
[0065] The flowcharts and block diagrams or charts in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this context, each block in the flowcharts or block diagrams or charts can represent a module, segment, or part of instructions that includes one or more executable instructions for performing the specified logical function(s). In some alternative embodiments, the functions specified in the block may occur in a different order than shown in the figures. For example, two blocks shown consecutively may in reality be executed essentially simultaneously, or the blocks may sometimes be executed in reverse order depending on the corresponding functionality.It should also be noted that each block of the block diagrams or charts and / or flowcharts, as well as combinations of blocks in the block diagrams or charts and / or flowcharts, can be implemented by special hardware-based systems that perform the specified functions or steps, or execute combinations of special hardware and computer instructions.
[0066] The descriptions of the various embodiments of the present invention are provided for illustrative purposes only and do not claim to be exhaustive or limited to the disclosed embodiments. Many modifications and variants will likely be obvious to those skilled in the art without altering the scope of protection and the essential content of the described embodiments. The terms used herein have been chosen to explain the basic concepts of the embodiments, their practical application, or technical improvements over commercially available technologies as clearly as possible, or to enable other experts to understand the embodiments described herein.
Claims
[1] Computer-assisted procedure that includes: Removing one or more minutiae fields from a number of minutiae fields of a data record of a user's fingerprint image (210) at random, leaving an updated number of minutiae fields in the data record, wherein the updated number of minutiae fields complies with a predetermined minimum threshold of minutiae fields; Generating a falsified record (224) of the fingerprint image with an updated number of minutiae fields, wherein the generation comprises merging at least one of the updated minutiae fields of the record with at least a part of a user input code using an encryption technique, without merging other minutiae fields of the updated number of minutiae fields with the user input code, such that the at least one of the updated minutiae fields in the falsified record has a changed value, wherein the falsified record is recoverable using the user input code; and Registering the falsified data record (224) to authenticate the user (210). [2] Computer-aided method according to claim 1, wherein generating the falsified data set (224) of the fingerprint image further comprises converting the data set of the fingerprint image into a string, digitizing the user input code into another string and merging the string with the other string. [3] Computer-aided method according to claim 1, wherein the user input code is not stored; and wherein the encryption technique comprises format-preserving encryption. [4] Computer-aided method according to claim 1, further comprising receiving a new fingerprint entered by the user (210); and updating the falsified data record (224) by a new falsified data record (244) of the new fingerprint. [5] Computer-aided method according to claim 1, wherein the falsified data record is automatically updated at a predetermined interval by a new falsified data record (244) of a new fingerprint of the user (210). [6] Computer-aided method according to claim 1, further comprising: receiving a new fingerprint entered by the user (210) and the user input code; Retrieving the corrupted data set (224); Decrypting the falsified fingerprint image data set (224) using the user input code to obtain a string; Converting the string back into the fingerprint image data set; and Comparing the fingerprint image with a new data set (240) of the new fingerprint. [7] Computer-aided method according to claim 6, further comprising: determining that authentication is successful if the data record matches the new data record (240) of the new fingerprint image; and Determine that authentication is unsuccessful if the record does not match the new record (240) of the new fingerprint. [8] System that features: a memory containing instructions readable by a computer; and one or more processors for executing computer-readable instructions, wherein the computer-readable instructions control the one or more processors to perform the following operations: Removing one or more minutiae fields from a number of minutiae fields of a data record of a user's fingerprint image (210) at random, leaving an updated number of minutiae fields in the data record, wherein the updated number of minutiae fields complies with a predetermined minimum threshold of minutiae fields; Generating a falsified record (224) of the fingerprint image with an updated number of minutiae fields, wherein the generation comprises merging at least one of the updated minutiae fields of the record with at least a part of a user input code using an encryption technique, without merging other minutiae fields of the updated number of minutiae fields with the user input code, such that the at least one of the updated minutiae fields in the falsified record has a changed value, wherein the falsified record is recoverable using the user input code; and Registering the falsified data record (224) to authenticate the user (210). [9] System according to claim 8, wherein generating the falsified data set (224) of the fingerprint image further comprises converting the data set of the fingerprint image into a string, digitizing the user input code into another string and merging the string with the other string. [10] System according to claim 8, wherein the user input code is not stored; and wherein the encryption technique comprises format-preserving encryption. [11] System according to claim 8, further comprising: receiving a new fingerprint entered by the user (210); and updating the falsified data record (224) with a new falsified data record (244) of the new fingerprint. [12] System according to claim 8, wherein the falsified data record is automatically updated at a predetermined interval by a new falsified data record (244) of a new fingerprint of the user (210). [13] System according to claim 8, further comprising: receiving a new fingerprint entered by the user (210) and the user input code; Retrieving the corrupted data set (224); Decrypting the falsified fingerprint image data set (224) using the user input code to obtain a string; Converting the string back into the fingerprint image data set; and comparing the fingerprint image data set with a new data set (240) of the new fingerprint. [14] System according to claim 13, further comprising: determining that authentication is successful if the data record matches the new data record (240) of the new fingerprint; and determining that authentication is unsuccessful if the data record does not match the new data record (240) of the new fingerprint. [15] Computer program product comprising a computer-readable medium containing program instructions, wherein the program instructions are executable by a processor to cause the processor to perform the following operations: Removing one or more minutiae fields from a number of minutiae fields of a data record of a user's fingerprint image (210) at random, leaving an updated number of minutiae fields in the data record, wherein the updated number of minutiae fields complies with a predetermined minimum threshold of minutiae fields; Generating a falsified record (224) of the fingerprint image with an updated number of minutiae fields, wherein the generation comprises merging at least one of the updated minutiae fields of the record with at least a part of a user input code using an encryption technique, without merging other minutiae fields of the updated number of minutiae fields with the user input code, such that the at least one of the updated minutiae fields in the falsified record has a changed value, wherein the falsified record is recoverable using the user input code; and Registering the falsified data record (224) to authenticate the user (210). [16] Computer program product according to claim 15, wherein generating the falsified data set (224) of the fingerprint image further comprises converting the data set of the fingerprint image into a string, digitizing the user input code into another string and merging the string with the other string. [17] Computer program product according to claim 15, wherein the user input code is not stored; and wherein the encryption technique comprises format-preserving encryption. [18] Computer program product according to claim 15, further comprising: receiving a new fingerprint entered by the user (210); and updating the falsified data record (224) with a new falsified data record (244) of the new fingerprint. [19] Computer program product according to claim 15, wherein the falsified data record is automatically updated at a predetermined interval by a new falsified data record (244) of the new fingerprint of the user (210). [20] Computer program product according to claim 15, further comprising: receiving a new fingerprint entered by the user (210) and the user input code; Retrieving the corrupted data set (224); Decrypting the falsified fingerprint image data set (224) using the user input code to obtain a string; Converting the string back into the fingerprint image data set; and Comparing the fingerprint image data set with a new data set (240) of the new fingerprint.
Citation Information
Patent Citations
Method and system for combining a PIN and a biometric sample to provide template encryption and a trusted stand-alone computing device
US20110126024A1
Dynamic information radio-frequency identification (RFID) card with biometric capabilities
US20120218079A1
Transformed Representation for Fingerprint Data with High Recognition Accuracy
US20160358010A1
Partial Fingerprint and Partial Iris Payment Device
US20190354988A1