METHOD AND SYSTEM FOR SMOOTH IDENTIFICATION OF A PERSON
Patent Information
- Application Number
- DE602020052070
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2019-12-04
- Filing Date
- 2020-12-01
- Publication Date
- 2025-05-28
- Estimated Expiration
- 2040-12-01
AI Technical Summary
Existing identification methods using biometrics often require complex and insecure mechanisms to ensure data confidentiality and controlled use, which can infringe on individual privacy and create friction in the identification process.
A method and system that utilize a token containing an encrypted biometric template, split into two parts, where one part is stored on a mobile terminal and the other on a server database, allowing for frictionless identification by merging and decrypting the token during access control.
This approach ensures secure and private biometric identification without requiring users to perform specific actions, maintaining data confidentiality and respecting individual privacy while enabling seamless access control.
Description
[0001] The invention relates to a method and a system for identifying individuals, without friction, while respecting their freedom and their privacy.
[0002] The guarantor of compliance with the General Data Protection Regulation ensures that the storage of biometric data and its use respect the privacy of individuals.
[0003] Therefore, the implementation of an identification process using biometrics requires the establishment of complex mechanisms with a high level of security guaranteeing data confidentiality and controlled use.
[0004] Document US 2013 / 339749 discloses a method for identifying an individual, the biometric data associated with that individual being stored in a smart card.
[0005] Document US 2013 / 262873 discloses a method and system for user authentication.
[0006] The technical teaching of document US 2003 / 088782 concerns the storage of biometric data at the network level.
[0007] The object of the invention is in particular to offer a method and a system allowing the identification of an individual without friction, meeting the objectives of respect for privacy.
[0008] The word "token" is used in the remainder of the description to designate a set of data containing at least one encrypted biometric model specific to an individual for their authentication and other information which will be used for their identification (a data encryption key, an identifier Id, etc.).
[0009] The invention is defined by independent claims 1 and 6.
[0010] The invention relates to a method for identifying an individual from biometric data within a system comprising a control device, a server on which a signature and encryption application is installed, such that it comprises at least the following steps: enrolling an individual and acquiring the individual's biometric data, transmitting said biometric data to said server which generates a biometric template M, said server via its signature and encryption application signs and encrypts the biometric template, generates a token containing at least said biometric template M and identification data, dividing the encrypted token into at least two parts T 1 , T 2 , transmitting a first part of the token T 1 for storage on a mobile terminal of the individual and a second part of the token T 2 to a database of a server separate from the storage, controlling identity data of the individual, detecting the mobile terminal of the individual by the control device, pairing the detected mobile terminal with the control device, recovering the first part of the token T 1 and the second part of the token T 2 , using frictionless communication,then merge the two parts of the token to find the initial token T, decrypt the token and verify its signature, return the corresponding biometric template, in parallel, acquire biometric data from the individual, compare the biometric data to the biometric template and trigger the opening of the control means if the data match.
[0011] Frictionless communication is, for example, a Bluetooth, Ultrasound, or Wifi Aware type connection, known to those skilled in the art.
[0012] Biometric data can be physical characteristics of the face, the method acquires an image of the face and generates a corresponding biometric template for control.
[0013] According to another embodiment, the method takes into account fingerprints, acquires the individual's fingerprints and generates the corresponding biometric models for the control step.
[0014] A QR Code can be used as the support for the first part of the token.
[0015] For example, we generate an encrypted token and separate it into two parts by performing the following steps: generation of an AES 256 encryption key, encryption of the biometric template, creation of a token containing the AES 256 key and the encrypted biometric template, transmission of the AES key, T 1 , for storage on the individual's mobile terminal, transmission of the part T 2 , of the encrypted biometric template in the server database.
[0016] According to another unclaimed embodiment, generating and separating the token into two parts may comprise the following steps: two AES 256 keys are generated, biometric data blocks are alternately encrypted with one of the keys, then a first half of each encrypted block and a first key are transmitted for storage on the mobile terminal and a second half of each encrypted block and a second key for storage on the server.
[0017] The process is used to check a traveler's identity when passing through checkpoints at an airport.
[0018] The invention also relates to a system for identifying an individual from biometric data within a system comprising a control device, a server, said individual being equipped with a mobile terminal, characterized in that it comprises at least the following elements: an enrollment device configured to acquire the identity information and the biometric data of the individual, a means for transmitting said data to the server, the server comprises an application for generating a biometric template, encrypting a biometric template and generating a token, an application configured to separate said token into at least two parts and generate a first part of the token T 1 transmitted for storage in a memory of the mobile terminal of the individual and a second part of the token T 2 transmitted to a database of said server separate from the memory, and comprises an application for merging said parts of the token during access control, the access control device is equipped with: i.of a communication module with the server, of mobile telephone detection means, of an application configured to detect a mobile telephone, to pair it, of an application configured to carry out a comparison between a biometric model and data acquired at the level of the control portal, ii. of a mechanism allowing the passage of the individual.
[0019] The access control device may be an airport gate, the biometric template is a face and the device is equipped with a camera suitable for recording in real time the face of an individual presenting themselves at the gate after pairing.
[0020] The enrollment device is, for example, a free-access registration terminal.
[0021] Other characteristics, details and advantages of the invention will emerge on reading the description given with reference to the appended drawings given as non-limiting examples and which represent, respectively: as far as the figure 1 , an illustration of the steps of enrolling an individual and the generation of a token representing his identity, as regards the figure 2 , an illustration of the steps for verifying data presented by an individual, with regard to the figure 3 , an example of generating a token, as far as the figure 4 , a method of splitting a token into two parts.
[0022] The following description is given for illustrative purposes and is not intended to be limiting. The medium for part of the token is a QR Code. Identity control is that of a traveler within an airport, via the passage of one or more control gates to access a "secure" area, with limited access, cross a border, board a plane.
[0023] There figure 1 illustrates an example of enrolling an individual's data. The individual has a mobile terminal 1, such as a smartphone or a tablet, which will allow them to communicate with the control terminals and to memorize part of their identity data allowing them to authenticate themselves.
[0024] The mobile terminal 1 comprises communication means (antenna, transmitter, receiver) 10, a processor 11 configured to execute the steps of the method, an application 12 used to have part of a token stored in a secure container 13. The application 12 comprises for example the following functionalities: import (scan) a new token, manage a token, consult information on its movement, give and / or withdraw consent.
[0025] The traveler will enroll at a self-service check-in terminal or kiosk in an airport. The enrollment kiosk 2 is equipped with a device and an application 21 for displaying a QRCode containing at least part of the token. The QRCode is stored for a limited period in a temporary memory 22 of the kiosk. The check-in terminal 2 comprises, for example, a keyboard 23 or a physical interface that allows the traveler to enter their identity data.
[0026] The system comprises a server 3 equipped with a data signature and encryption application 31, an application 32 configured to generate a biometric model, an application 36 to generate a QRCode or any other equivalent support, a data fusion application 35, a database 33 or memory storing part of the token, and communication means 34 to communicate with the kiosk 2 during the enrollment phase and an access gate 5 during the identity control phase ( figure 2 ).
[0027] The traveler will register at the kiosk in order to be able to complete a journey through the airport which will be based on biometric authentication, 101. During this registration phase, the individual gives his explicit consent for the use of his personal data and his biometrics, according to a consent process known to those skilled in the art (dialogue HMI to request and accept the explicit consent of the traveler). Then, the traveler 1 communicates his identity data to the kiosk, for example by entering his personal data at the keyboard or by reading his passport via the kiosk reading application and acquires the biometric data necessary for authentication. The kiosk 2 transmits this biometric data, 102, to the server 3 which via its application generates a biometric model, for example of a face, by mechanisms known to those skilled in the art.
[0028] Server 3, via its signature and encryption application, will sign and encrypt the biometric template M and generate a token that includes at least the biometric template M. It stores the encrypted token in a temporary memory, 104. This token T is then split into N parts of variable sizes. From the N parts of the token, in the example two parts T 1 , T 2 , the server will: save 105 the second part T 2 of the token in a database 33, for example integrated into the server, generate 106 a QRCode supporting a first part T 1 of the token which it transmits to the kiosk 2 for display. A method of token generation and token splitting into multiple parts is explained below.
[0029] The individual traveler will scan the QR Code located on the kiosk with his smartphone equipped with the application which records the data contained in the QR Code in its memory 13, 107. The result of the scan is verified by a process known to those skilled in the art. He will use this part of the token for the identity check carried out by the control gates or access gates.
[0030] There figure 2 illustrates the access and use of the token during a check at an access gate. Biometric identification of an individual requires the traveler's consent or authorization, which they gave when registering at the kiosk.
[0031] In this example, an access gate 5 is equipped with a communication module 51 with the server, means 52 for detecting smartphones compatible with the system, an application 53 configured to select a smartphone, the closest for example, and to pair it 201, an application 54 which will perform a comparison between a biometric model and data acquired at the control gate, an image of the person for example. The result of the application is translated for example in the form of a signal which will trigger a mechanism 60 for opening the gate.
[0032] The dialogue or exchange of data between the access gate 5 and the traveler's mobile terminal is carried out, for example, by means of frictionless communication, for example of the Bluetooth Low Energy, Ultrasound, Wifi Aware type, etc. The connection between the server and the access gate is a standard connection known to those skilled in the art.
[0033] The access gate after detection 201 searches for the identifier, known by the system, of the service on the smartphone making available the part of the token T 1 stored in the traveler's smartphone. The first part T 1 of the token is recovered 202 by the access gate 5 and transmitted 203 to the server 3 which analyzes its content, searches for the corresponding identifier Id of the traveler and, using this identifier will search, 204, for the second part of the token T 2 in its database 33. Then the server 3 will merge 206 the first part T 1 of the token and the second part T 2 returned 205 by the database. The merging of the two parts is triggered automatically upon receipt of the first part of the token. The reconstituted token is then decrypted via the server's encryption / decryption application, then the signature is verified in order to guarantee the authenticity of the data.The server then returns the biometric template M, 207, to the access gate which will perform a biometric comparison between the video stream from the camera and this biometric template.
[0034] When the data from the video stream matches the biometric template, the access gate triggers the opening of the passage to the traveler.
[0035] The access gate includes a 55 camera or equivalent device to capture the individual's image. The communication module can be a Bluetooth dongle, a Wi-Fi card, a speaker, etc.
[0036] The data is stored temporarily at the access control gate. At the server level, the data can be deleted after a certain period of time, or as soon as the individual withdraws their consent, according to an erasure process known to those skilled in the art.
[0037] An example of token splitting is to apply the following method: AES 256 encryption of the biometric template Token generation: AES 256 key + encrypted biometric template, Sending the AES key to the smartphone, T 1 Storage of the encrypted biometric template in the database, T 2 .
[0038] There figure 3 illustrates another unclaimed method of generating a token and the figure 4 an example of splitting the token into two parts.
[0039] 31 - The token generation method consists of chain cipher propagation encryption (AES PCBC).
[0040] The method uses an initialization vector of 30.
[0041] An “exclusive OR” is applied between an initialization vector 30 and the first plaintext block B 1 to obtain an XOR0 result.
[0042] The result of the “exclusive OR” XOR0 is encrypted with a first AES key, K 1 .
[0043] At the encryption output, an “exclusive OR” is applied between the initial plaintext block and the encrypted block B 1C to obtain an XOR 1 result.
[0044] An “exclusive OR” between the XOR 1 result and the second plaintext block B 2 to obtain an XOR 2 result.
[0045] The result of the XOR2 “exclusive OR” is encrypted with a second AES key.
[0046] This principle is applied to all subsequent blocks by alternating encryption with one of the two keys.
[0047] This mechanism ensures that all blocks are necessary to decrypt a block (i.e. to decrypt block B 2 , you need the key K 2 , the encrypted block B 1C and the decrypted block B 1 , which can only be decrypted using the key K 1 and the initialization vector).
[0048] There figure 4 illustrates the steps of separating or splitting a token into two parts.
[0049] 40 - Separation of data.
[0050] 41 - From a token, a first part of the token is generated containing: the initialization vector, the second encryption key K 2 and a part of each encrypted block.
[0051] 42 - A second part of the token is generated containing: the first encryption key K 1 and the other parts of each encrypted block.
[0052] 43 - Sending one of the two parts of the token to the smartphone.
[0053] 44 - Storage of the other part of the token on the server.
[0054] The above description is given for a QRCode type data carrier. Any other carrier can be used.
[0055] The token can be split into N parts depending on the storage capacity.
[0056] The example is given in the context of an identification process within an airport, but can be extended to a control within a station to access the train, or to any type of transport or reception infrastructure for people, or even within a company for the access control of employees or visitors.
[0057] The biometric data support may be a QR Code or any other support known to those skilled in the art.
[0058] The biometric model in the example was created from an image of an individual. Without departing from the scope of the invention, fingerprints, voice, etc. could also be used to enable identification.
[0059] The method according to the invention can also be applied to the control of an employee or a visitor within a company equipped with gates. The mobile terminal could be in the form of a smart badge comprising all of the functionalities just described.
[0060] The method and system according to the invention allow storage of data used to identify and authenticate an individual without friction, that is to say without the need for the user to have to perform a particular action (take out their passport or smartphone) and while respecting the rules of respect for privacy.
Claims
1. Method for identifying an individual on the basis of biometric data within a system comprising an access control device (5), an enrolment device (2) and a server (3), including: a. steps of enrolling (101, ..., 107) the individual consisting of: - acquiring (101) first biometric data of the individual by the enrolment device (2); - generating (103) a biometric model M on the basis of said first biometric data; - signing the biometric model, then encrypting (104) the signed biometric model on the basis of an encryption key, said signed and encrypted biometric model and the encryption key together forming a token T generated by the server; - recording (107) a first part T1 of said token T in a data memory (13) of a mobile terminal (1) held by the individual; - recording (105) a second part T2 of said token T within a database (33) of the server (3); b. verification steps (201, ..., 207) consisting of: - acquiring second biometric data of the individual by the access control device (5); - jointly using said second biometric data and the biometric model in order to cause or reject a triggering of the opening of the access control means; said method for identifying an individual being arranged in that: i. the method includes a transmission (102), by said enrolment device (2), of said first biometric data to the server (3) prior to the generation (103) of the biometric model M; ii. said generation (103) of the biometric model M on the basis of the first biometric data, the signing and the encryption of the latter (104) are carried out by said server (3), the latter containing an application for signing and encrypting a biometric model; iii. the first part T1 of the token T comprises the encryption key of the signed biometric model and an identifier Id of the individual; iv. the second part T2 of said token T comprises the signed and encrypted biometric model; v. the recording (107) of the first part T1 of said token T in a data memory (13) of the mobile terminal (1) held by the individual is preceded by: - a generation, by the server (3), of a QR code supporting said first part T1 of the token T that can be displayed by the enrolment device (2); - a transmission (106) of said QR code to the enrolment device (2); - a display, by said enrolment device (2), of said QR code supporting the first part T1 of said token T; - a scan of said QR code supporting said first part T1 of the token T displayed by the mobile terminal (1) held by the individual in order to find said first part T1 of said token T on the basis of said QR code scanned by said mobile terminal (1) held by the individual; vi. the joint use of said second biometric data and the biometric model in order to cause or reject a triggering of the opening of the access control means is preceded by: - a pairing of the mobile terminal (1) held by the detected individual with the access control device (5); - a transmission (202), by the mobile terminal (1), by means of frictionless communication, of the first part T1 of the token T recorded in the data memory (13) of said mobile terminal (1) to the access control device (5); - a transmission (203), by the access control device (5), of said first part T1 of the token T to the server (3); - a search (204) performed by said server (3) in the database (33) of said server (3) for a second part T2 of token T on the basis of the first part T1 of said token T; - a merging (206), by the server (3), of said first and second parts T1 and T2 of said token T in order to recover said token T; - a decryption, by the server (3), of the signed and encrypted biometric model comprised in said token T on the basis of the first part T1 of the latter and a verification of the signature of the biometric model; - a transmission of said decrypted biometric model by the server to the access control device (5); vii. the joint use of said second biometric data and the biometric model in order to cause or reject a triggering of the opening of the access control means consists of a comparison, by the access control device (5), of said acquired second biometric data with the decrypted and known biometric model of said access control device (5), the triggering of the opening of the access control means being caused if the acquired second biometric data correspond to the decrypted biometric model.
2. Method according to claim 1 such that the frictionless communication is a communication of the Bluetooth, ultrasonic or Wi-Fi Aware type.
3. Method according to one of claims 1 or 2 such that the first and second biometric data are physical characteristics of a face on the basis of an image of said face.
4. Method according to one of claims 1 or 2 such that the biometric data consist of fingerprints.
5. Method according to one of claims 1 to 4 such that the encryption (104) of the biometric model by said server (3) consists of: - generating the encryption key of the biometric model in the form of an AES 256 encryption key; - encrypting the biometric model as such on the basis of said AES 256 encryption key.
6. System for identifying an individual on the basis of biometric data comprising an enrolment device (2), an access control device (5), a server (3), said individual being equipped with a mobile terminal (1), said system being such that, in order to implement a method according to any one of the preceding claims: - the enrolment device (2) is configured to acquire identity information and first biometric data of the individual and contains a means of transmitting said first biometric data to the server (3); - the server (3) contains: ∘ an application (31) for generating a biometric model, for signing and encrypting a biometric model and for generating a token T containing said signed and encrypted biometric model M and the encryption key, o an application (32) configured to separate said token T into at least two parts and generate a first part of the token T1 transmitted by means of a QR code that can be displayed by the enrolment device (2) for storage, after said QR code has been scanned by the individual's mobile terminal (1), in a memory (13) of the latter and a second part of the token T2 transmitted to a database (33) of said server (3) that is separate from the memory (13) of the mobile terminal (1), ∘ an application (35) for merging said parts T1 and T2 of the token T during the access control, - the access control device (5) is equipped with: - a module for communicating (51) with the server (3), means of acquiring (55) second biometric data, means of detecting (52) a terminal (1), application software (53) configured to detect such a mobile terminal (1), and pair it, an application (54) configured to carry out a comparison between a biometric model and said second biometric data, - a mechanism (60) allowing the individual to pass through.
7. System according to claim 6 in which the access control device (5) is an airport security gate, the biometric model is that of a face, the means of acquiring (55) second biometric data consisting of a camera suitable for capturing, in real time, the face of an individual arriving at the security gate after said access control device (5) has been paired with the individual's mobile terminal (1), said mobile terminal (1) consisting of a smartphone or a tablet.
8. System according to one of claims 6 or 7 such that the enrolment device is a freely accessible check-in terminal.