Contactless authentication method and system
Decentralizing biometric data storage in user devices through a contactless authentication system with wireless communication improves security and reduces costs by enabling efficient user authentication.
Patent Information
- Application Number
- EP2021703477
- Authority / Receiving Office
- EP · EP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-02-17
- Filing Date
- 2021-02-10
- Publication Date
- 2025-10-29
- Estimated Expiration
- 2041-02-10
AI Technical Summary
Existing authentication systems face security limitations due to centrally located biometric data, leading to high costs and potential vulnerabilities.
A contactless authentication system where biometric data is stored on user devices, utilizing short-range and long-range wireless communication to authenticate users, with a mobile terminal generating and signing an authentication request, and an authentication server verifying user access rights and generating an authorization token.
Enhances security and reduces costs by decentralizing biometric data storage, allowing for efficient and secure user authentication without the need for continuous server connection.
Smart Images

Figure IMGF0001 
Figure IMGF0002
Abstract
Description
[0001] The invention relates to a contactless authentication method for a person or individual. It finds application, for example, in controlling access to a secure area. It can also be used for transaction validation.
[0002] Many applications implement a process for authenticating individuals. For example, when you want to control access to a website for a specific person. Authentication is also required to pass through a boarding gate at an airport or to access a train.
[0003] In the context of financial transactions, it is also necessary to authenticate oneself before executing a transaction.
[0004] Various authentication methods are described in the prior art.
[0005] For example, patent application WO 2004 / 100083 describes an authentication system that uses an authentication card in which biometric data is stored.
[0006] French patent FR 2922672 discloses a method and system for contactless biometric authentication. The authentication system comprises one or more personal authentication devices, a terminal equipped with biometric means that generates a user's biometric information, and wireless communication means. The personal authentication device includes a memory for storing the biometric data of the device holder. In this system, biometric information is distributed to several personal authentication devices, resulting in limited security. The biometric data comparison device is located within each of the personal authentication devices, leading to a high cost for the device. This system notably enhances security during the authentication process.
[0007] US patent application 2019 / 139342 A1 discloses a secondary reader and a method of controlling said secondary reader when connected to a door reader of an existing installed door operating device to provide a method of communication not supported by the door reader.
[0008] The idea of the present invention is to propose a system and method of authentication in which biometric data is not located centrally, but at the level of the user device.
[0009] The invention thus relates to an authentication system for one or more users comprising an authentication server, at least one access control device and a mobile terminal equipping a user.
[0010] The access control system of such a system includes: a biometric data reader, a wireless communication module suitable for proximity communications, a processor configured to produce and cause the continuous emission by the communication module of a signal containing the identifier of the access control device and an unpredictable challenge.
[0011] According to the invention, the mobile terminal of such a system comprises: first means of short-range communication to exchange information with the access control device and second means of long-range communication to exchange information with the authentication server, a biometric database, a processor configured to generate and sign an authentication request R q and then transmit the latter to the authentication server by the second means of communication in response to the capture by the first means of communication of the signal continuously emitted by the access control device, said authentication request R q containing the identifier of the access control device and the unpredictable challenge from said captured signal.
[0012] According to the invention, the authentication server of such a system comprises: a database containing for a given user an identifier and access rights, long-range communication means, a processor configured to, upon receipt of the authentication request R q issued by the mobile terminal: a. verify the signature of the authentication request R q to authenticate the user, b. compare the identifier of the user thus authenticated and the identifier of the access control system contained in the authentication request R q, with the data stored in the database containing for a given user an identifier and access rights so as to determine if the user has access rights to an area controlled by the access control device, c. if the user has such access rights: i.generate an authentication token including the unpredictable challenge, the user identifier and the access rights to an area controlled by the access control device and, ii. cause the transmission of said authentication token by said long-range communication means to the mobile terminal sending said authentication request R q . .
[0013] Furthermore, according to the invention, the mobile terminal processor is also configured to transmit said authentication token issued by said authentication server with biometric data contained in the biometric database of the mobile terminal, to the access control device by the first means of short-range communication.
[0014] The access control device's processor is also configured to, upon receiving the authentication token transmitted by the mobile terminal: verify the validity of the unpredictable challenge and the user's access rights to this area using the authentication token, and compare biometric data captured by its biometric data reader with the biometric data provided with said authorization token and, generate an access denial or access authorization signal depending on whether the biometric data captured by the biometric data reader differs or not from the biometric data provided with said authorization token.
[0015] According to an advantageous embodiment, the access control device processor can also be configured to: issue and sign the unpredictable challenge over a short validity period.
[0016] The biometric data reader of the access control device of such a system according to the invention can be configured to acquire a fingerprint or alternatively include a camera configured to acquire facial features.
[0017] Short-range communication methods can advantageously use a contactless proximity communication protocol such as Bluetooth or NFC.
[0018] Similarly, long-range communication methods can use the HTTP / HTTPS protocol.
[0019] The mobile terminal used by the user can be a smartphone equipped with a smart card.
[0020] The invention further relates to a method of authenticating a user implemented within an infrastructure comprising an authentication server, an access control device and a mobile terminal equipping the user, said mobile terminal comprising a biometric database, the access control device emitting a signal containing its identifier and an unpredictable challenge.
[0021] Such a process involves the following steps: The mobile terminal captures the signal emitted by the access control device and signs and sends an authentication request R q to the authentication server. This authentication request R q contains the identifier of the access control device and the unpredictable challenge from the captured signal. Upon receiving the authentication request R q, the authentication server verifies the signature of the authentication request to authenticate the user and checks whether the user has access rights to an area controlled by the access control device by comparing the identifier of the authenticated user and the identifier of the access control system with the data stored in a database containing, for a given user, an identifier and data access rights from the authentication server. When the user is authorized,The authentication server generates an access authorization token containing the unpredictable challenge, the user's identifier, and said access rights to an area controlled by the access control device, and transmits said authorization token to the mobile terminal that issued said authentication request. The user's mobile terminal transmits said authentication token issued by said authentication server, along with biometric data contained in the mobile terminal's biometric database, to the access control device. Upon receiving said token, the access control device: a. acquires biometric data from the user to be authenticated by a biometric data reader; b. verifies the validity of the unpredictable challenge and the user's access rights to that area using the authentication token.and verifies whether the biometric data captured by the biometric data reader differs from the biometric data provided with said authorization token; c. issues an access authorization command if said biometric data is similar; d. issues a denial of authorization information if said biometric data is different.
[0022] According to an advantageous embodiment, such a process may include a step of generating by the access control device a control signal to open a gate equipping the access control device.
[0023] The step of acquiring biometric data from the user to be authenticated by the biometric data reader of the access control device may consist of acquiring a fingerprint.
[0024] Alternatively, the step of acquiring biometric data by the access control device reader may consist of acquiring an image of the user's face and for which the process includes a step of displaying said image on a screen adding a label valid or invalid depending on the result of the step of verifying the biometric data by the access control device.
[0025] Other features, details and advantages of the invention will become clearer upon reading the description made with reference to the accompanying drawings, which are given by way of non-limiting example and which represent, respectively:
[0026] There figure 1 , an example of an authentication system according to the invention,
[0027] There figure 2 , a diagram of the operation of the process according to the invention.
[0028] The example is given within the context of an access control infrastructure that includes, for example, several access control devices, a server, and multiple users. The infrastructure can authenticate one or more individuals in parallel. The detailed example that follows concerns the authentication of a single individual, or of a group of individuals when they are verified one by one.
[0029] The communication methods implemented in the infrastructure are wireless, short-range between a user and an access control device, and longer-range between a user and an authentication server. They allow for contactless information exchange between the various actors in the system.
[0030] As illustrated on the figure 1 An authentication system 1 according to the invention comprises an access control device 2, for example, an access door to a controlled area. The access control device 2 comprises a biometric reader 3, a processor 4, a non-permanent memory (temporary for the duration of data processing) 5, a communication module 6, and optionally a display device 7 for the result obtained from the comparison of the acquired biometric data and reference biometric data.
[0031] The biometric reader 3, for example, is configured to acquire a fingerprint. In this case, the processor will be configured to extract minutiae from the image resulting from the fingerprint acquisition and compare them with the data transmitted by the user. This reader could also be a camera when biometric control is based on facial recognition. The processor will then be configured to perform facial recognition by comparing it with the facial data contained in the authentication request issued by the user. This reader can also be configured for iris recognition or even for voice recognition using cepstral parameters.
[0032] The choice of biometric data will depend on the application and the number of users to be authenticated.
[0033] Communication Module 6 is a wireless communication module designed for proximity communication. It transmits a signal containing, among other things, an SCA ID and a random or challenge. The challenge is unpredictable and is issued for a very short period of time, chosen to allow a user to trigger the authentication process. This very short period is primarily chosen to compensate for a clock synchronized with the SCA (time verification) and to avoid repeating the authentication request at the SCA level. The communication protocol can be the NFC (Near Field Communication) contactless proximity protocol, Wi-Fi, Bluetooth, etc.
[0034] The access control device 2 to a protected or secure area is, for example, equipped with a "gate" 8 which receives an opening order from the processor after data processing and user authentication.
[0035] Access control device 2 can also be equipped with a display screen that can show a person's face and the authentication result.
[0036] The authentication system according to the invention comprises a server 10 including a processor 11 configured to process an authentication request Rq issued by a user, a database 12 containing, for a user, the gate identifier SCA ID and their access rights to secure areas protected by access gates, and long-range communication means 13 for communicating and exchanging information with the user. These communication means use, for example, the HTTP / HTTPS protocol. An application 14 running on the processor 11 processes an authentication request Rq issued by the user in order to return an authentication token J. The authentication token contains the challenge generated by the access control device, the server signature S, and the user identifier, ID.
[0037] A site or zone will be defined by a set of access points or SCAs. Access to a zone by a user will require linking the user ID to the authorized access points (list of SCA IDs).
[0038] A user wishing to authenticate themselves in the system is equipped with a mobile terminal 16. The mobile terminal 16 includes a biometric database 17, a processor 18 configured to process the signal emitted by the access control device, short-range communication means 19a for exchanging information with terminal 2, and long-range communication means 19b for exchanging information with the server. The biometric data will be signed by a trusted third-party authority, for example, a company accredited by the government.
[0039] The mobile terminal is, for example, a smart phone or "smartphone", a tablet, a smart card, or any other equivalent device.
[0040] There figure 2 describes an example of the system's operation according to the invention.
[0041] Access control device 2 continuously emits a signal containing its SCA ID and a challenge "n", a random number with a validity period T over a short period, 210. The generation of the challenge is known to those skilled in the art and will not be detailed. At the end of the validity period T, a new challenge is generated.
[0042] The challenge n or random event consists of the following elements:
[0043] An unpredictable RND (Return on Development) datum,
[0044] An identifier that references access control device 2 in an infrastructure comprising multiple control terminals,
[0045] A public key of type RSA or ECDSA, under the control of the access control device (the private key is embedded in a secure element),
[0046] The challenge is accessible by all systems capable of capturing it via a nearby communication channel: Bluetooth / iBeacon, NFC, ultrasound.
[0047] The user's mobile terminal captures the signal S(ID SCA , n), 220, and sends an authentication request Rq to the server 10, 221.
[0048] The Rq authentication request includes the following elements:
[0049] The SCA ID identifier of the access control device,
[0050] The unpredictable data of the challenge, "n",
[0051] The S SCA signature of the access control device 2.
[0052] The authentication request R q is signed using an RSA or ECDSA type private key ( Elliptic Curve Digital Signature Algorithm ) under the user's control and embedded in a secure element of the user's mobile terminal. The secure element can be a SIM card, a secure memory area, etc.
[0053] The authentication request Rq is received, 230, by the authentication server 10 which verifies:
[0054] The S SCA signature of the access control device, which authenticates it within the access control infrastructure, 231,
[0055] The S Rq signature of the authentication request, in order to authenticate the user on the system, 232,
[0056] The user's permissions or rights, 233, to be in the area accessible by the access control system, by comparing the identifier contained in the request and the identifier of the access control system to the area, with the data stored in the reference database.
[0057] When the user does not have the right to access the area, the server may emit a signal, 234, indicating that access to the user is denied.
[0058] When the user has the right to access zone 235, the server will return an authorization token to the user containing:
[0059] The identity of the access control device and the challenge,
[0060] User permissions,
[0061] An SSA signature generated by an asymmetric private key of type RSA or ECDSA ( Elliptic Curve Digital Signature Algorithm), under the control of the server and certified by a Certification Authority (PKI - Public Key Infrastructure).
[0062] The different ways of generating keys will not be explained because they are known to those skilled in the art.
[0063] The user receives the authentication token J and will transmit the authentication token and biometric data to the access control device, 241.
[0064] The user's mobile terminal contains biometric data in memory, which is encrypted using an AES (Advanced Encryption Standard) symmetric key known to the infrastructure and the access control device, and which is signed by a trusted authority.
[0065] The mobile terminal application generates a random AES session key which it encrypts with the public key of the access control device.
[0066] The application encrypts the biometric data using the session key.
[0067] The user mobile terminal 16 transmits the following information to the access control device 2 via short-range communication means:
[0068] The authentication token J provided by the server,
[0069] Biometric data certified and encrypted twice.
[0070] The access control device 2 receives these elements 250 and simultaneously, 251, captures at least one biometric data point from the user to be authenticated. The access control device verifies, 252:
[0071] That the authentication request Rq occurred in the immediate vicinity of the biometric data capture by verifying the RND value contained in the request,
[0072] The user's access rights to this area are granted by means of the authentication token J generated by the authentication server, with biometric data being provided along with the token.
[0073] That the biometric data acquired at the level of the access control device and stored temporally are identical to the biometric data contained in the access request issued by the user.
[0074] When the biometric data does not match, the access control device will emit an access refusal signal, 253.
[0075] When the biometric data are identical, the user has the rights to access the area and the RND non-predictable data is valid, then the access control device emits an authorization signal, 254. This signal can take different forms.
[0076] In a classic access control system, the AES key is deployed in the SCAs, remotely or locally, by the SCA operator.
[0077] During enrollment by an issuing authority, the user will receive their encrypted and signed fingerprints.
[0078] In the case where the control is a facial recognition control, the authorization signal may include the display on a screen 7 ( figure 1 ) with a label allowing passage, for example a green V for valid passage. The refusal signal could be in the form of a red cross displayed on the user's face. For an access gate, the S passage signal allows the gate to open 8 ( figure 1 ) and the user's access to the secure area.
[0079] When the controlled biometric data is fingerprints, the signal can simply be the command that activates the unlocking of the gate or access door.
[0080] An access control device is, for example, a turnstile for accessing a secure site, an airport gate, an access control device for means of payment, etc.
[0081] When the infrastructure needs to authenticate several people in parallel, the control device will be equipped with several biometric data reading devices, several fingerprint readers, several cameras, and the processors will be chosen to process in parallel the different data acquired on several devices.
[0082] Authentication can also use several biometric parameters such as fingerprints, facial recognition, for example, as mentioned previously.
[0083] The method and system according to the invention offer, in particular, the following advantages:
[0084] The access control device can be autonomous and does not need to be connected to a server or a clock, because it uses a random or challenge with a limited duration in time.
[0085] The access control device stores biometric data for processing and not permanently.
[0086] It can also allow authentication control of several people in series or in parallel, due to its contactless operation.
Claims
1. A system for authenticating one or more users, comprising an authentication server (10), at least one access control device (2) and a mobile terminal (16) fitted to a user, characterized in that: - the access control device (2) comprises: ∘ a biometric data reader (3), ∘ a wireless communication module adapted for proximity communications (6), ∘ a processor (4) configured to produce and cause the communication module (6) to continuously transmit a signal containing the identifier of the access control device and a non-predictable challenge; - the mobile terminal (16) comprises: o first short-range communication means (19a) for exchanging information with the access control device (2) and second long-range communication means (19b) for exchanging information with the authentication server (10), o a biometric database (17), o a processor (18) configured to generate and sign an authentication request Rq and then transmit the latter to the authentication server via the second communication means (19b) in response to the capture by the first communication means (19a) of the signal continuously transmitted by the access control device (2), said authentication request Rq containing the identifier of the access control device (2) and the non-predictable challenge from said captured signal; - the authentication server (10) comprises: o a database (12) containing an identifier and access rights for a given user, o long-range communications means (13), o a processor (11) configured, on receiving the authentication request from the mobile terminal (16), to: ▪ check the authentication request signature to authenticate the user, ▪ compare the identifier of the user thus authenticated and the identifier of the access control system (2) contained in the authentication request Rq, with the data stored in the database (12) containing, for a given user, an identifier and access rights so as to determine whether the user has access rights to an area controlled by the access control device (2), ▪ if the user has such access rights: • generate an authentication token comprising the non-predictable challenge, the user identifier and access rights to an area controlled by the access control device (2), and • cause said authentication token to be transmitted by said long-range communication means (13) to the mobile terminal (16) transmitting said authentication request Rq, - the processor (18) of the mobile terminal (16) is further configured to transmit said authentication token transmitted by said authentication server (10) with biometric data contained in the biometric database (17) of the mobile terminal (16), to the access control device (2) via the first short-range communication means (19a), - the processor (4) of the access control device (2) is further configured, on receiving the authentication token transmitted by the mobile terminal (16), to: o check the validity of the non-predictable challenge and the user's access rights to this area by means of the authentication token, and compare biometric data captured by its biometric data reader (3) with the biometric data provided with said authorization token, and o generate an access refusal or access authorization signal depending on whether or not the biometric data captured by the biometric data reader (3) differs from the biometric data provided with said authorization token.
2. The system according to claim 1, wherein the processor (4) of the access control device (2) is further configured to: - issue and sign the non-predictable challenge over a short validity period.
3. The system according to claim 1 or 2, wherein the biometric data reader (3) of the access control device (2) is configured to acquire a fingerprint.
4. The system according to claim 1 or 2, wherein the biometric data reader (3) of the access control device (2) comprises a camera configured to acquire the characteristics of a face.
5. The system according to one of claims 1 to 4, characterized in that the short-range communication means (6, 19a) use a contactless proximity communication protocol of the Bluetooth or NFC near-field type.
6. The system according to one of claims 1 to 5, characterized in that the long-range communication means (19b, 13) use the HTTP / HTTPS protocol.
7. The system according to one of claims 1 to 6, characterized in that the mobile terminal (16) equipping the user is a smart phone equipped with a smart card.
8. A method for authenticating a user implemented within an infrastructure comprising an authentication server (10), an access control device (2) and a mobile terminal (16) fitted to the user, said mobile terminal (16) comprising a biometric database (17), the access control device (2) transmitting a signal containing its identifier and a non-predictable challenge, characterized in that the method comprises the following steps: - the mobile terminal (16) captures (220) the signal transmitted by the access control device, and signs and transmits (221) an authentication request Rq to the authentication server (10), said authentication request Rq containing the identifier of the access control device (2) and the non-predictable challenge from said captured signal, - the authentication server (10), upon receipt (230) of the authentication request Rq, verifies the signature of the authentication request to authenticate the user and checks whether the user has access rights to an area controlled by the access control device (2) by comparing the identifier of the authenticated user and the identifier of the access control system with the data stored in a database (12) containing, for a given user, an identifier and access rights for data (12) of said authentication server (10), - when the user is not authorized, the authentication server (10) generates (234) a non-authorization signal, - when the user is authorized, the authentication server (10) generates (235) an access authorization token containing the non-predictable challenge, the user identifier and said access rights to an area controlled by the access control device (2), and transmits said authorization token to the mobile terminal (16) issuing said authentication request Rq, - the mobile terminal (16) of the user transmits said authentication token transmitted by said authentication server (10), together with biometric data contained in the biometric database (17) of the mobile terminal (16), to the access control device (2), - the access control device (2), on receiving said token: o acquires (251) biometric data from the user to be authenticated by a biometric data reader (3), o checks the validity of the non-predictable challenge and the access rights of the user to this area via the authentication token, o checks (252) that the biometric data captured by the biometric data reader (3) differs from the biometric data provided with said authorization token, o transmits (254) an access authorization command if said biometric data are similar, o transmits (253) a non-authorization message if said biometric data differs.
9. The method according to claim 8, comprising a step wherein the access control device generates a control signal for opening a gate (8) fitted to the access control device.
10. The method according to one of claims 8 or 9, for which the step of acquiring biometric data from the user to be authenticated by the biometric data reader (3) of the access control device (2) consists in acquiring a fingerprint.
11. The method according to one of claims 8 or 9, for which the step of acquisition by the reader (3) of biometric data of the access control device (2) consists in acquiring an image of the user's face and for which the method comprises a step of displaying said image on a screen by adding a valid or invalid label depending on the result of the step of checking of the biometric data by the access control device (2).
Citation Information
Patent Citations
CONTACTLESS BIOMETRIC AUTHENTICATION SYSTEM AND AUTHENTICATION METHOD
FR2922672A1
Smart authenticating card
WO2004100083A1
Method and system for managing door access by using beacon signal
EP3355281A1
Access control system and access control method using the same
US20190139342A1
Method for verifying a biometric authentication
US20190299932A1