Method of identifying a natural person

The method and system enhance biometric identification security and flexibility by using hash-generated link and verification values in separate databases, addressing vulnerabilities and privacy concerns in multi-provider systems.

FR3150607B1Active Publication Date: 2025-07-04BANKS & ACQUIRERS INT HLDG SAS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2023007016
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-06-30
Publication Date
2025-07-04
Estimated Expiration
2043-06-30

AI Technical Summary

Technical Problem

Existing biometric identification systems face security vulnerabilities and inefficiencies when shared among multiple service providers, allowing attackers to compromise identities and lack flexibility in managing multiple profiles for individuals, while also risking personal data breaches.

Method used

A method and system that utilize hash functions and dedicated keys to generate link values and verification values, stored in separate databases, ensuring secure identification by comparing these values to confirm personal identifiers, allowing multiple profiles and revocation of identities without affecting others, and maintaining personal data privacy.

Benefits of technology

Enhances security by requiring attackers to access multiple databases and keys, supports multiple profiles, and ensures respect for personal data by eliminating the need for centralized filtering tables, enabling secure and flexible identification across multiple service providers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000030_0000
    Figure 00000030_0000
  • Figure 00000030_0001
    Figure 00000030_0001
  • Figure 00000031_0000
    Figure 00000031_0000
Patent Text Reader

Abstract

The invention relates to a method for identifying (200) a natural person, implemented by computer and comprising a step of generating (207) a link value, a step of obtaining (211) a verification value, associated with a corresponding link value in an identity database, and a step of obtaining (212), from the identity database, a personal identifier associated, in the identity database, with the link value. Figure for abstract: figure 3
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for identifying a natural person

[0001] The invention relates to a method and a system for identifying a natural person, in particular the biometric identification of a natural person.

[0002] A method for identifying a natural person comprises a step of collecting identity data, for example a biometric fingerprint provided by a biometric sensor, and a step of responding by providing a personal identifier, for example a name, an address or a number, associated with this identity data within an identity database. Such an identification method thus allows a natural person to be identified to various service providers, such as merchants.

[0003] Thus, an identification system generally comprises a secrets database comprising a list of secrets of respective natural persons, for example respective biometric fingerprints, and an identity database separate from the secret database and comprising the list of respective identifiers of these natural persons. The secrets database is managed by a secrets server and the identity database is managed by an identity server separate from the secrets server.

[0004] In one prior art, the secrets database and the identity database list the respective secrets and identifiers according to a common index. Therefore, when the secret server receives a secret, it compares it to the secrets in the secrets database. When it identifies a matching secret, it transmits the index number of this secret to the identity server. The identity server then returns the identifier having the same index number in the identity database.

[0005] This approach is not secure for mass use. In particular, if two people register at the same time, their respective index numbers may be reversed in one of the two databases.

[0006] In another state of the art, a unique digital value is generated when the natural person registers. It is associated in the secrets database with the secret of the natural person and in the identity database with the identifier of this natural person. It is this digital value which is sent by the secret server to the identity server. The identity server then returns the identifier associated with the same digital value in the identity database.

[0007] However, this approach is open to attack. Thus, an attacker with write access to one of the two bases could reverse numerical values, for example example A and B, of two natural persons. In such a case, if the secrets server collected the secret of person A, the identity server would return the identifier of person B.

[0008] To address this, another approach is proposed in Appendix A of the ISO 24745 standard proposal for the protection of biometric data. The unique numeric value is replaced, in the secret and identity databases, by a link value, called "common identifier (CI)" in the standard proposal. This link value is calculated using a public "message authentication code (MAC)" type hash function, taking as input both the secret of the natural person and the identifier of this natural person, as well as a parameterization key for the function. It is this link value that is sent by the secret server to the identity server. The identity server then returns the identifier associated with the same link value in the identity database. To corrupt this system, an attacker would have to generate this link value.He would therefore have to have access to both databases in writing, as well as to the dedicated key, which makes this attack difficult to carry out.

[0009] This approach, however, retains drawbacks in the event of mass adoption of the identification system, in particular if many service providers wish to use this system and if individuals wish to be able to be identified with several of these service providers.

[0010] One solution is to provide, for each service provider, a database of secrets and a database of identities dedicated to the natural persons registered with this service provider. However, the fleet of servers to be implemented and managed is then costly and difficult to maintain for the manager of the identification system. In addition, this requires a natural person to renew the registration and identification process for each service provider with which he or she wishes to be identified, which is tedious.

[0011] Another solution is to share a single database of identities and a single database of secrets of natural persons for all service providers, and to associate with it a table of filtering rules to select the service providers with which each natural person is registered. However, a single natural person cannot then have several distinct profiles, he or she has a single profile for all service providers. Similarly, revocation of the identity with a single service provider is impossible. Furthermore, if the identity of the natural person is compromised by one service provider, it is then compromised for all the others. In addition, the filtering table risks being exploited commercially, in particular to obtain information on the behavior of natural persons, which risks contravening the principles of respect for their personal data. Finally, this filter table risks being manipulated by a malicious attacker.

[0012] The invention aims in particular to provide a method and a system for identifying a natural person which, although implementing secret and identity databases shared by a large number of service providers, improves the security of the data of natural persons, the respect of their personal data, allows the revocation of identities from chosen service providers and allows the management of several profiles for the same natural person.

[0013] To this end, the invention relates to a method for identifying a natural person, implemented by computer and comprising the following steps:

[0014] - obtaining a code;

[0015] - obtaining a secret from the natural person;

[0016] - comparison of the secret of the natural person with secrets of a database of secrets;

[0017] - when a secret corresponding to the secret of the natural person in the database secret data is identified, generation of a link value from the secret and from the code, preferably from a hash function associated with a dedicated key;

[0018] - comparison of the generated link value to link values ​​of a database identity data separate from the secrets database or to link values ​​from a buffer database separate from the secrets database and the identity database;

[0019] - obtaining a verification value associated with the link value in the database identity data, or, the link value being a first link value of a chain of link values ​​in which each other link value is obtained from the previous link value, obtaining a verification value associated with a link value of the chain in the identity database or in a buffer database separate from the secrets database and the identity database,

[0020] - obtaining, from the identity database, an associated personal identifier, in the identity database, to the link value or to a link value in the link value chain,

[0021] - generation of a value to be verified from the received secret, the received code and the personal identifier obtained, preferably also from a hash function associated with a dedicated key;

[0022] - comparison of the generated value to be verified with the obtained verification value,

[0023] - when the generated value to be verified is identical to the obtained verification value, provision of the personal identifier obtained.

[0024] This method improves the security of the identification of the natural person. Indeed, this method works thanks to two values, the link value and the verification value calculated and compared to corresponding respective stored link and verification values. Concerning the link value, the corresponding link value is not stored in the secret database, but in a buffer database or in the identity database. A link value to be compared is generated from the obtained secret and from a code, the code being secret or public. These link values ​​make it possible to make the link between the secret and the code on the one hand, and the presence of a stored identity on the other hand. They also make it possible to make the link with possible following link values ​​of a chain of link values.However, these link values ​​do not allow to confirm that a personal identifier of the natural person actually corresponds to the obtained secret. This is why the value to be verified is generated from the same secret, the same code, but also from the personal identifier of the natural person. This verification value is compared to a corresponding verification value stored in the identity database or in a buffer database. These verification values ​​thus allow to confirm that a personal identifier of the natural person corresponds to the transmitted secret. Therefore, the personal identifier is provided as a result of the process. To corrupt the process and obtain the identifier, an attacker would therefore have to generate both the link value, or even the following link values, and the value to be verified, which is difficult.

[0025] This method allows the management of different profiles of the same user, thanks to the code: for the same secret, the user can associate another identifier, for example another address, with another code. Conversely, for the same identifier, the user can associate another secret with another code. The same natural person can therefore have several secrets for the same identifier and several identifiers for the same secret.

[0026] It follows from this profile management that this method allows the revocation of an identity from a single service provider without revoking it from the others. Indeed, by associating each code with a service provider, it is possible to destroy a profile corresponding to this code, while retaining, for the same natural person, the profiles associated with other codes.

[0027] It also follows from this profile management that this process improves respect for users' personal data. Indeed, by using different codes for the same natural person, it is no longer necessary to have a filtering table to associate a natural person with different service providers; it is sufficient to create a profile for each service provider by associating a specific code with it.

[0028] Other optional process features, taken alone or in combination, follow.

[0029] Advantageously, the method being a biometric identification method, the secret relates to a biometric fingerprint of the natural person, in particular the secret is a hashed value of a biometric fingerprint of the natural person, the secrets database is a biometric database comprising biometric fingerprints of natural persons.

[0030] Preferably, the code is:

[0031] - relating to a password provided by the natural person, in particular the code includes a hashed value of a password provided by the individual to the secret server; and / or

[0032] - relating to an entity, such as a merchant with whom the natural person performs its identification, in particular the code includes a public value of identification of the entity known by the secret server.

[0033] Thus, the code is either provided by the natural person and known only to him, or publicly known, for example attached to a merchant. The code of the process can therefore be used in several ways.

[0034] Advantageously, the method comprises the following steps, when the link value is a first link value of a chain of link values ​​in which each other link value is obtained from the previous link value:

[0035] - first, generation of a first historical value, of a string of values history, from the first link value,

[0036] - when a link value corresponding to the first generated link value is identified in the buffer database, generating a next link value, optionally last link value, of the link value chain, from the secret, the code and the first history value, preferably also from a hash function associated with a dedicated key, and generating a next history value from the next link value and the first history value, preferably also from a one-way function associated with a dedicated key,

[0037] - optionally, comparing the next link value to link values of a subsequent buffer database distinct from the buffer database, and generation of a subsequent link value and a subsequent history value, these comparison and generation steps being repeated until the generation of a last link value of the chain of link values,

[0038] - to obtain the associated personal identifier in the identity database, comparing the last link value in the link value chain to link values ​​in the identity database.

[0039] Thus, the databases are "chained" to each other, through one or more buffer databases, using the chains of link values ​​each calculated using the previous link value in the chain. An attacker would therefore have to have access to each of the buffer databases to corrupt the method. Furthermore, rather than simply determining a next link value based on the previous link value, the history value is calculated, which is based on the previous link value, and the next link value is calculated based on this history value. Since the history values ​​are not stored in the databases, it is impossible to find the next link value without recalculating each value successively using the previous ones. In other words, chaining the link values ​​using a history value therefore further improves the security of the method.

[0040] The invention also provides a method for registering a natural person in an identification system, implemented by computer and comprising the following steps:

[0041] - obtaining a code;

[0042] - obtaining a secret from the natural person;

[0043] - comparison of the secret of the natural person with secrets of a database of secrets;

[0044] - when no secret in the database matches the person's secret physical, generation of a link value specific to the natural person, from the secret of the natural person and the code, preferably from a hash function associated with a dedicated key;

[0045] - storage, in the secrets database, of the secret of the natural person, without storing either the link value or the code;

[0046] - generation, following receipt of this code and this secret, of an identifier personal of the natural person;

[0047] - generation of a verification value from the received secret, the received code and the personal identifier generated, preferably also from a hash function associated with a dedicated key;

[0048] - storage, in an identity database, of the personal identifier of the natural person associated with the link value and the verification value, or, the link value being a first link value in a chain of link values ​​in which each link value is obtained from the previous one, storing, in the identity database, the personal identifier associated with the last link value in the chain, and storing the verification value, in the identity database and associated with the personal identifier or in a buffer database, separate from the secret database and the identity database, associated with a value of chain link.

[0049] The invention also provides a system for identifying a natural person, comprising:

[0050] - a database of secrets comprising secrets of natural persons, and - an identity database comprising respective personal identifiers of those natural persons, the identity database associating with each personal identifier of a natural person a link value,

[0051] - automated means configured to:

[0052] * compare a secret received from a natural person to the secrets in the database of secrets and, a corresponding secret of the natural person being identified, to generate a link value from the secret of the natural person and from a code, preferably from a hash function associated with a dedicated key,

[0053] * compare the received link value to link values ​​in a database of identities or to link values ​​from a buffer database separate from the secrets database and the identity database;

[0054] * obtain a verification value associated with a link value in the database identity data or, the link value being a first link value of a chain of link values ​​in which each other link value is obtained from the previous link value, obtaining a verification value associated with a link value of the chain in the identity database or in a buffer database separate from the secrets database and the identity database,

[0055] * obtaining, from the identity database, a personal identifier associated, in the identity database, to the link value or to a link value in the link value chain,

[0056] * obtain a value to verify from the received secret, the received code and the identifier personal obtained, preferably also from a hash function associated with a dedicated key,

[0057] * compare the generated value to be verified with the obtained verification value, and when the generated value to be verified is identical to the obtained verification value, indicate that the personal identifier obtained corresponds to the secret received from the natural person.

[0058] Advantageously, the system comprises:

[0059] - at least one buffer database, distinct from the secrets database and the database of identities, including link values,

[0060] - automated means configured to:

[0061] *receive the link value, code and secret,

[0062] *comparing the received link value to the link values ​​in the buffer database, and, when it identifies a matching link value, to generate a next link value in the chain of link values ​​from the link value,

[0063] * transmit the following link value, code and secret.

[0064] According to the invention, there is also provided a data processing system comprising a processor configured to implement the steps of the identification method described above or of the registration method described above.

[0065] Also provided according to the invention is a computer program comprising instructions which, when the program is executed by a computer, cause the latter to implement the steps of the identification method described above or of the registration method described above.

[0066] Also provided according to the invention is a computer-readable recording medium comprising instructions which, when executed by a computer, cause the latter to implement the steps of the identification method described above or of the registration method described above.

[0067] The invention also relates to a method for identifying a natural person, implemented by computer and comprising the following steps:

[0068] - obtaining a code;

[0069] - obtaining a secret from the natural person;

[0070] - comparison of the secret of the natural person with secrets of a database of secrets;

[0071] - when a secret corresponding to the secret of the natural person in the database secret data is identified, generation of a link value from the secret and from the code, preferably from a hash function associated with a dedicated key;

[0072] - comparison of the generated link value to link values ​​of a database identity data separate from the secrets database;

[0073] - obtaining a verification value associated with the link value in the database identity data;

[0074] - obtaining, from the identity database, an associated personal identifier, in the identity database, to the link value,

[0075] - generation of a value to be verified from the received secret, the received code and the personal identifier obtained, preferably also from a hash function associated with a dedicated key;

[0076] - comparison of the generated value to be verified with the obtained verification value,

[0077] - when the generated value to be verified is identical to the obtained verification value, provision of the personal identifier obtained.

[0078] The invention also relates to a method for identifying a natural person, implemented by computer and comprising the following steps:

[0079] - obtaining a code;

[0080] - obtaining a secret from the natural person;

[0081] - comparison of the secret of the natural person with secrets of a database of secrets;

[0082] - when a secret corresponding to the secret of the natural person in the database secret data is identified, generation of a link value from the secret and from the code, preferably also from a hash function associated with a dedicated key;

[0083] - comparison of the generated link value to link values ​​of a database separate buffer data from the secrets database,

[0084] - the link value being a first value of a chain of link values ​​in in which each other link value is obtained from the previous link value, obtaining a verification value associated with a link value of the chain in an identity database separate from the secret database and the buffer database,

[0085] - obtaining, from the identity database, an associated personal identifier, in the identity database, to the chain link value,

[0086] - generation of a value to be verified from the received secret, the received code and the personal identifier obtained, preferably also from a hash function associated with a dedicated key;

[0087] - comparison of the generated value to be verified with the obtained verification value,

[0088] - when the generated value to be verified is identical to the obtained verification value, provision of the personal identifier obtained.

[0089] The invention also relates to a method for identifying a natural person, implemented by computer and comprising the following steps:

[0090] - obtaining a code;

[0091] - obtaining a secret from the natural person;

[0092] - comparison of the secret of the natural person with secrets of a database of secrets;

[0093] - when a secret corresponding to the secret of the natural person in the database secret data is identified, generation of a link value from the secret and from the code, preferably from a hash function associated with a dedicated key;

[0094] - comparing generated link value to link values ​​to link values of a buffer database separate from the secrets database;

[0095] - the link value being a first link value of a chain of link values in which each further link value is obtained from the previous link value, obtaining a check value associated with a link value of the chain in the buffer database or in a separate buffer database,

[0096] - obtaining, from the identity database, an associated personal identifier, in the identity database, to a link value of the link value chain,

[0097] - generation of a value to be verified from the received secret, the received code and the personal identifier obtained, preferably also from a hash function associated with a dedicated key;

[0098] - comparison of the generated value to be verified with the obtained verification value,

[0099] - when the generated value to be verified is identical to the obtained verification value, provision of the personal identifier obtained.

[0100] The invention also provides a system for identifying a natural person, comprising:

[0101] - a database of secrets comprising secrets of natural persons,

[0102] - an identity database comprising respective personal identifiers of these natural persons, the identity database associating a link value with each personal identifier of a natural person,

[0103] - a secret server configured to compare a secret received from a person physical to the secrets in the secrets database and, when it identifies a matching secret of the natural person, to generate a link value from the secret of the natural person and from a code, preferably from a hash function associated with a dedicated key,

[0104] the secret server also being configured to transmit the link value, the code and the secret to an identity server or a buffer server,

[0105] - an identity server configured to compare the received link value to values of links from the identity database,

[0106] the identity server also being configured to obtain a verification value associated with a link value in the identity database, or to obtain a verification value transmitted by the buffer server or by another buffer server,

[0107] the identity server also being configured to obtain, from the identity database, a personal identifier associated, in the identity database, with the link value or, the link value being a first link value of a chain of link values ​​in which each value is obtained from the previous link value, associated with a link value of the chain transmitted by the buffer server or by a following buffer server,

[0108] the identity server also being configured to obtain a value to be verified from the secret received, the code received and the personal identifier obtained, preferably also from a hash function associated with a dedicated key,

[0109] the identity server also being configured to compare the generated value to be verified with the obtained verification value, and when the generated value to be verified is identical to the obtained verification value, to indicate that the personal identifier obtained corresponds to the secret received from the natural person. Brief description of the figures

[0110] The invention will be better understood on reading the following description given solely by way of example and with reference to the appended drawings in which:

[0111] [Fig-1] is a diagram of a biometric identification system according to a first embodiment of the invention;

[0112] [Fig.2] is a flowchart of a method of registering a natural person in the identification system of [Fig.l];

[0113] [Fig.3] is a flowchart of a method for biometric identification of a natural person by the identification system of [Fig.l], according to a first mode of implementation;

[0114] [Fig.4] is a diagram of a biometric identification system according to a second embodiment of the invention;

[0115] [Fig.5] is a flowchart of a method of registering a natural person in the identification system of [Fig.4];

[0116] [Fig.6] is a flowchart of a method for biometric identification of a natural person by the identification system of [Fig.4];

[0117] [Fig.7] is a diagram of a biometric identification system according to a third embodiment of the invention;

[0118] [Fig.8] is a flowchart of a method of registering a natural person in the identification system of [Fig.7];

[0119] [Fig.9] is a flowchart of a method of biometric identification of a natural person by the identification system of [Fig.7],

[0120] [Fig. 10] is a diagram of a biometric identification system according to a fourth embodiment of the invention;

[0121] [Fig. 11] is a flowchart of a method of registering a natural person in the identification system of [Fig. 10];

[0122] [Fig. 12] is a flowchart of a method of biometric identification of a natural person by the identification system of [Fig.10]. Detailed description

[0123] By “database” we mean any organized collection of structured information, stored electronically in a computer system in a secure manner.

[0124] The term "server" will be used to designate any program dedicated to a series of computer tasks which will be specified, and which have access to a strictly identified database. In the invention described below, each server is associated with a database. We will speak of a "server-base" pair.

[0125] A server can store data in its database, access this data, and perform calculations based on this data. A server can also receive external data and not store it, and perform calculations based on this external data. A server can finally transmit data or calculation results.

[0126] Two servers described as distinct from each other cannot operate on each other's databases. They can, however, transmit data to each other.

[0127] Each server-database pair is implemented on its own computing device. This device is equipped with conventional computing components for storing the database and operating the server. Each device is physically isolated from other computing devices.

[0128] Alternatively, a single computing device may have several servers. However, it is necessary to separate these servers described as distinct on the software level.

[0129] [Fig.l] shows a first embodiment of a biometric identification system 2 according to the invention.

[0130] This system comprises a database 4 called “biometric database” comprising biometric fingerprints T of natural persons.

[0131] The system 2 also comprises a database 6 called the “identity database” comprising respective personal identifiers ID of these natural persons, the identity database associating with each personal identifier of a natural person a value called the “link value” LIDbase. In other words, in a table illustrating the identity database, each identifier ID corresponds to an alphanumeric value called the “link value” LIDbase and which will be described below. It will be compared to LID link values ​​calculated during the identification method described below. The identity database also associates with each of these pairs of values ​​a “verification value” CIbase which will be described below. In other words, the table of this database comprises triplets “personal identifier ID - link value LIDbase - verification value CI base

[0132] The system 2 also comprises a server 8, called a “biometric server”, configured to execute some of the steps of the methods described below. This server is associated with the biometric database.

[0133] The system 2 also comprises a server 10, called an “identity server”, configured to execute some of the steps of the methods described below. This server is associated with the identity database. It is distinct from the biometric server.

[0134] The servers described implement the computer programs 12 and 15 comprising instructions which, when the programs are executed by a computer, cause the latter to implement the steps of the methods described below.

[0135] The system 2 contains a computer-readable recording medium 13 comprising instructions which, when executed by a computer, cause the latter to implement the steps of the methods described below, in particular by the biometric server 8. This medium thus contains the program 15. The system 2 also contains a computer-readable recording medium 14 comprising instructions which, when executed by a computer, cause the latter to implement the steps of the methods described below, in particular by the identity server 10. This medium thus contains the program 12.

[0136] The system 2 also comprises an apparatus for providing a biometric fingerprint, not illustrated. This apparatus is configured to obtain biometric data from a natural person and to provide a biometric fingerprint. The biometric data may be voice, iris, a fingerprint or any other biometric data allowing the natural person to be reliably identified. The apparatus is configured to output a corresponding biometric fingerprint, in particular in the form of an alphanumeric value, which may be stored. It is with this apparatus that the natural person interacts directly. The operation of this apparatus does not concern the subject of the application and will not be described in detail. It is a conventional apparatus.

[0137] Alternatively, it may be considered that system 2 does not include this device, since any conventional device capable of providing a biometric fingerprint is compatible with the system.

[0138] This system 2, in particular the databases 4 and 6, is shared by several merchants. Among all the natural persons registered in the system 2, some are registered with a single merchant, others with several merchants. The biometric database 4 and respectively the identity database 6 include the biometric fingerprints T and respectively the personal identifiers ID associated with the LIDbase link values ​​of all these natural persons, whether they are registered with one or more merchants.

[0139] This system 2 corresponds to a data processing system comprising processors for implementing the steps of the methods described below.

[0140] We will now describe, with reference to [Fig.2], a method 100 for registering a natural person in the identification system. The natural person wishes to register with a single merchant and create, for the moment, a single profile.

[0141] In step 101, the natural person requests to carry out an identification with the biometric fingerprint supply device.

[0142] In step 102, the natural person presents his attribute - his eye, his voice, or his fingers depending on the device or the natural person's choice - to the device.

[0143] In step 103, the device generates a biometric fingerprint E of the person physical, made from its attribute.

[0144] In step 104, the user selects the merchant with whom she wishes to be registered, from among the merchants sharing this system.

[0145] In step 105, the device obtains a code C.

[0146] In a first variant, this code C is provided to him by the natural person who wishes to register, when defining the password of this natural person. This code C is then a hashed version, generated via a conventional hash function, of this password. This code C is then specific to the natural person, or even, if he wishes to register different profiles of his person, to a profile of this natural person.

[0147] In a second variant, this code is obtained by the device when choosing the merchant from among the merchants sharing this system. In this alternative, a code C specific to a merchant is defined beforehand. This code C can even then be public.

[0148] In step 106, the device sends this biometric fingerprint E and this code C to the biometric server.

[0149] In step 107, the biometric server receives this biometric fingerprint E and this code C.

[0150] In step 108, the biometric server compares the biometric fingerprint E of the natural person to biometric fingerprints in the biometric database. It should be noted that the biometric server does not search for a fingerprint in the database that necessarily corresponds 100% to the fingerprint E. Indeed, for the same attribute of the natural person, the device can generate two slightly different biometric fingerprints (differences in pixels of an image, in a few bits of a sequence of bytes, etc.). The server therefore searches for the corresponding fingerprint, if it is in the biometric database, according to a method that is not part of the subject of the invention.

[0151] In step 109, when no biometric fingerprint in the biometric database corresponds to the biometric fingerprint E of the natural person, the biometric server stores in the biometric database a biometric fingerprint T corresponding to E. T and E are identical.

[0152] Alternatively, T is not identical but is derived from E. The biometric server can retrieve T from E in a conventional manner, T is for example more detailed or completed with respect to E.

[0153] In a second variant, it is the capture device which generates T on the basis of E and transmits T to the biometric server.

[0154] We will speak in the following of biometric print T whatever its form with respect to the original print E.

[0155] In step 110, the biometric server generates a LIDbase link value specific to the natural person, based on the following formula: LIDbase = MACKb(fb(T), C), where MACKb is a MAC function parameterized by a key Kb known only to the biometric server, Fb is a conventional hash function applied here to the fingerprint T, forming a hashed version of the fingerprint T. In other words, the LIDbase link value is generated from the biometric fingerprint of the natural person and the code, also from the hash function MACKb associated with a dedicated key Kb. The so-called “MAC” functions, for “message authentication code”, are functions used to authenticate the origin of a message and certify the nature of this message. They use a private key, here the key Kb known only to the biometric server.

[0156] In step 111, the biometric server stores, in the biometric database, the biometric fingerprint T of the natural person, without storing either the link value LIDbase or the code C.

[0157] In step 112, the biometric server transmits, to the identity server, the code C, the hashed value of the fingerprint Fb(T) and the LIDbase link value, accompanied by a registration request.

[0158] In step 113, the identity server receives this code, this Fb(T) value and the LIDbase link value.

[0159] In step 114, the identity server verifies that the identity database does not contain a LIDbase link value already identical to that received.

[0160] In step 115, if no LIDbase link value already exists in the identity database, the identity server generates a personal identifier ID for the natural person. This personal identifier ID is any alphanumeric value, which must be unique. It is random and therefore does not rely on previously received or calculated values.

[0161] This identifier corresponds to the identity of the natural person. This ID identifier is associated, in a database not concerned by the invention, with one or more personal data of the natural person, such as his name, his address, his location, or his interests. This identifier can therefore be used by the merchant for purposes, such as the construction of a customer history, reduction proposals, which do not concern the object of this invention.

[0162] In step 116, the identity server generates a verification value CIbase from the following formula: CIbase = MACKi (Fb(T), C, ID), where MACKi is a MAC function parameterized by a dedicated key Ki and known only to the identity server. In other words, the value CIbase is determined from the hashed value of the received fingerprint Fb(T), i.e. indirectly from the biometric fingerprint E, the received code C and the generated personal identifier ID, also from the MACKi hash function associated with a dedicated key Ki.

[0163] In step 117, the identity server stores, in the identity database, the personal identifier ID of the natural person associated with the link value LIDbase and associated with the verification value CIbase-

[0164] The natural person is now registered with the merchant in the identification system.

[0165] We will now describe with reference to [Fig.3] a method 200 for identifying the natural person, implemented within the identification system 2. The natural person wishes to be identified by the merchant with whom he or she is registered.

[0166] In step 201, the natural person presents his attribute (the one with which he was previously registered) to the device for providing a biometric fingerprint.

[0167] In step 202, the device generates a biometric fingerprint E from this attribute.

[0168] In step 203, the device obtains a code C. This is a hashed value of a word of password provided by the user.

[0169] Alternatively, the code corresponds to the merchant with whom the user wishes to identify himself and which he selects from among the available merchants, on a screen of the device.

[0170] In step 204 the device transmits the code C and the fingerprint E to the biometric server 8.

[0171] In step 205, the biometric server 8 obtains the biometric fingerprint E of the natural person and the code C.

[0172] In step 206, the biometric server 8 compares the biometric fingerprint E of the natural person with biometric fingerprints T of the biometric database 4. The objective is to identify the closest fingerprint T among all the fingerprints T of the database 4. As mentioned above with reference to the registration method, the fingerprint T which corresponds to the fingerprint E is not necessarily totally identical to the latter. , and the manner in which the result is obtained is not the subject of this invention. This verification may also result in the absence of a fingerprint T corresponding to the received fingerprint E.

[0173] In step 207, when the biometric server 8 identifies a biometric fingerprint T corresponding to the biometric fingerprint E of the natural person in the biometric database 4, the biometric server 8 generates a link value LID according to the formula LID = MACKb(fb(T), C), i.e. from the hashed value of the biometric fingerprint T and from the code C, also from the hash function MACKb associated with the dedicated key Kb.

[0174] Using Fb(T) and not Fb(E) makes it possible to ensure the correct functioning of the method, since, as mentioned above, a generated footprint E can be le management of the corresponding footprint T although they relate to the same physical attribute.

[0175] In step 208, the biometric server 8 transmits to the identity server 10 the link value LID, the code C and the hashed value Fb(T) of the biometric fingerprint T.

[0176] In step 209, the identity server 10 receives the link value LID, the code C and the hashed value Fb(T).

[0177] In step 210, the identity server 10 compares the received LID link value with the LIDbase link values ​​of the identity database 6.

[0178] In step 211, if it finds a LIDbase link value in the database 6 corresponding to the received LID link value, the identity server 10 obtains the CIbase verification value associated with the LIDbase link value in the identity database 6. Conversely, if it does not find any corresponding LIDbase value in the database, the method stops: the natural person is not identified.

[0179] In case of success, in step 212 the identity server 10 obtains, from the identity database 6, the personal identifier ID associated, in the identity database, with the link value LIDbase as well as with the verification value CIbase.

[0180] In step 213, the identity server 10 generates a value to be verified CI from the following formula: CI = MACKi(fb(T), C, ID), that is to say from the hashed value of the biometric fingerprint T, the received code C and the personal identifier obtained ID, also from the hash function MACKi associated with the dedicated key Ki.

[0181] In step 214, the identity server 10 compares the generated CI value to be verified with the obtained CIbase verification value.

[0182] In step 215, when the generated value to be verified CI is identical to the obtained verification value CIbase, this means that the personal identifier ID obtained corresponds to the biometric fingerprint T and therefore to the biometric fingerprint E of the natural person. As a reminder, this verification value CIbase was obtained, in step 212, from the identity database where it is stored and associated with the link value LIDbase. From then on, the identity server provides the merchant with the personal identifier obtained. The natural person is therefore identified to his merchant.

[0183] Thanks to the code C specific to each identity, for the same biometric fingerprint E, the same person can register several of their profiles, by associating each of these profiles with their respective code C. Having several profiles makes it possible to have several personal identifiers and therefore to choose which personal data to provide. For example, for a main profile corresponding to a first code C and for which the personal identifier is associated, with merchants, with an age, an address, a name, the person can also have a secondary profile, corresponding to a second code C, for which a second personal identifier is associated only with the age, or with a different postal address with other merchants. This allows the user to make available to the merchants he chooses the personal data he wishes. The management of profiles of the same user therefore becomes possible. Rather than restarting the registration process from scratch, to create a second profile the user can derive his secondary profile from a main profile, by presenting his biometric attribute to the device to identify himself and indicating, after validation of the identification, that he wishes to create a second profile corresponding to the same fingerprint.

[0184] Conversely, for the same personal identifier, the user can associate another biometric fingerprint with another code. The same natural person can therefore have several biometric fingerprints for the same identifier and several identifiers for the same biometric fingerprint.

[0185] It follows from this profile management that this process allows the revocation of an identity from a single merchant without revoking it from the others. Indeed, it is possible to destroy a profile corresponding to a code, while retaining, for the same natural person, the profiles associated with other codes.

[0186] It also follows from this profile management that this process improves the respect of users' personal data. Indeed, by using different codes from each other for the same natural person, it is not necessary to have a filtering table to associate a natural person with different service providers, it is enough to create a profile for each merchant by associating a specific code with it. Each merchant only has access to the personal data associated with personal identifiers, and nothing else.

[0187] Alternatively, the code could be publicly known, and associated with a particular merchant. It then makes it possible to differentiate between merchants sharing the system.

[0188] It results from the processes 100 and 200, carried out for several natural persons and with several merchants, that the identification system 2 then comprises:

[0189] - a biometric database 4 comprising biometric fingerprints T of natural persons,

[0190] - an identity database 6 comprising personal identifiers ID respective of these natural persons, the identity database associating with each personal identifier ID of a natural person a LIDbase link value,

[0191] - a biometric server 8 configured to compare a received biometric fingerprint E of a natural person to the fingerprints T of the biometric database and, when it identifies a biometric fingerprint T corresponding to the natural person, to generate a link value LID from the biometric fingerprint T of the natural person and from a code C, from a MAC hash function associated with a dedicated key Kb,

[0192] the biometric server 8 also being configured to transmit the link value LID, the C code and the fingerprint, in this case a hashed value of the Fb(T) fingerprint, to an identity server,

[0193] - an identity server 10 configured to compare the received LID link value to LIDbase link values ​​from the identity database,

[0194] the identity server 10 also being configured to obtain a CIbase verification value associated with a LIDbase link value in the identity database 6,

[0195] the identity server 10 also being configured to obtain, from the identity database 6, a personal identifier ID associated, in the identity database, with the LIDbase link value,

[0196] the identity server 10 also being configured to obtain a value to be verified CI from the received fingerprint Fb(T), the received code C and the obtained personal identifier ID, also resulting from a MAC hash function associated with a dedicated key Ki,

[0197] the identity server 10 also being configured to compare the generated value to be verified CI with the obtained verification value CIbase, and when the generated value to be verified is identical to the obtained verification value, to indicate that the personal identifier ID obtained corresponds to the secret received from the natural person.

[0198] With reference to [Fig.4], the identification system 16 illustrated differs from the identification system of [Fig.l] by the presence of a buffer database 18, distinct from the biometric database 20 and the identity database 22. This database is managed by a buffer server 24 distinct from the biometric server 26 and the identity server 28. The buffer server therefore implements a computer program of its own, itself recorded on a recording medium.

[0199] By "buffer database" is meant the function of a database allowing, by the data that it stores, to make the link between values ​​stored on the one hand in the biometric database and on the other hand in the identity database. It is thus not possible to find the personal identifier of the natural person, located in the identity database, from the biometric fingerprint of this person, located in the biometric database, without going through a corresponding data located in the buffer database. In this system, the link value LIDbase is not unique, it is a first link value, called LIDlbase. It is stored in the buffer database 18. The identity database 22 does not store this first link value but a second link value LID2base, obtained from the first link value.

[0200] The registration method 300 illustrated in [Fig.5] and implemented on this system 16 differs from the registration method 200 in that the link value, here the first link value LIDlbase, is stored in the buffer database 18 only, and in that a second link value LID2base is generated and stored in the database of identities 22 only, in association with the verification value CIbase and the personal identifier ID. This LID2base value is obtained in accordance with the following described calculations: a so-called "first history value" Histl is generated in accordance with the following formula: Histi = Ui (LIDi, Hist0) where Ui is a one-way function parameterized by a key specific to the buffer server 24, and where Hist0 is any default value known to the biometric server 26. These values ​​are not stored by any of the databases. Then the LID2base value is generated in accordance with the following formula: LID2base = MACKt(fb(T), C, Histl) where Kt is a key specific to the buffer server. It is stored in the identity database 22.

[0201] We will now, with reference to [Fig.6], describe the method 400 for identifying a natural person implemented within this identification system 16.

[0202] Steps 401 to 407 are identical to steps 201 to 207 of method 200.

[0203] In step 408, the biometric server 26 transmits the LID link value, herein called LID1, the code C and the hashed value Fb(T) of the biometric fingerprint T, not to the identity server as in the method 200, but to the buffer server 24. In addition, it generates and transmits to the buffer server a value called “first history value” Histl, which it determines in accordance with the following formula: Histl = Ui(LIDi, Hist0).

[0204] At step 409, it is therefore the buffer server 24 which receives the link value LID1, the code C and the hashed value Fb(T), but also the first history value Histl.

[0205] In step 410, the buffer server 24 compares the received LID1 link value to the LIDlbase link values ​​of the buffer database 18.

[0206] In step 411, if it finds a link value LIDlbase corresponding to the link value LID1 received in the buffer database 18, the buffer server 24 generates a next link value LID2 according to the following formula: LID2 = MACKt (fb(T), C, Histl), where Kt is a key specific to the buffer server 24, as well as a history value Hist2 according to the formula Hist2 = U2(LID2, Histi). The value LID2 therefore corresponds to a link value of a link value chain and is obtained from the previous value of the chain, LID1, while in the same way, the value Hist2 corresponds to a history value of a history value chain and is obtained from the previous value of this chain, Histl. It is necessary to have the history values ​​to determine the successive link values. However, historical values ​​are not stored.Therefore, it is necessary to go through the buffer server to have the LID2 value. This therefore improves the security of the system 16. .

[0207] In step 412, the buffer server 24 transmits to the identity server 28 the value LID2, the code C and the hashed value Fb(T), as well as the history value Hist2.

[0208] In step 413, the identity server 28 obtains the CIbase verification value associated with the LID2base link value in the identity database. Conversely, if it does not If no matching LID2base link value is found in the database, the process stops: the natural person is not identified.

[0209] In case of success, in step 414 the identity server 28 obtains, from the identity database 22, the personal identifier ID associated, in the identity database, with the link value LID2base as well as with the verification value CIbase.

[0210] The following steps are steps 213 and 215 of method 200.

[0211] The natural person is therefore identified with their merchant.

[0212] The identification system 30 illustrated in [Fig.7] is a generalization of the identification system of [Fig.4]. Thus, it does not comprise a single but n buffer databases, n ranging from 1, which corresponds to the system of [Fig.4], to any number, for example 5, 10 or 15 buffer databases. Each of these n buffer databases is associated with its respective buffer server 32 or 34. In this generalization, the identity database 36 stores, instead of the value of LID2base, the last value LIDn+lbase of a chain of link values ​​starting with the value LIDlbase. In this chain of link values, each link value is obtained from in particular the previous link value, in accordance with the calculations described below.

[0213] In the registration method 500 of [Fig.8] and implemented within this system 30, in addition to the elements already mentioned, the LIDkbase values ​​are generated for each buffer database in accordance with the formula LIDk+lbase= MACKt(fb(T), C, Histk) where Kt is a key specific to the buffer server considered, and where the history values ​​Histk are calculated in accordance with the formula Histk+1 = Uk+i(LIDk+l, Histk). These LIDkbase values ​​are stored in the respective buffer databases 38, 40. The value LIDn+1 is stored in the identity database 36. No history values ​​are stored.

[0214] In the identification method 600 of [Fig.9] and implemented within the system 30, the buffer server 32, corresponding to the kth server, k ranging from 1 to n, compares the received LIDk link value to the LIDkbase link values ​​of the buffer database 38 that it manages. If it finds in the buffer database a corresponding LIDkbase value 38 to the received link value LIDk, the buffer server 32 generates a following link value LIDk+i in accordance with the formula LIDk+i= MACKt(fb(T), C, Histk) where Kt is a key specific to the buffer server 32, as well as a history value Histk+1 in accordance with the formula Histk+i = Uk+i(LIDk+i, Histk), the function Uk+1 being parameterized with a key specific to the buffer server 32. The buffer server 32 then sends to the buffer server 34 the values ​​LIdk+1, Histk+1, the code C and the hashed value Fb(T).The server 34 repeats the operations of comparison, determination of the link values ​​and the history values, and transmission of the values, until a last buffer server n transmits the values ​​C, Fb(T), LIDn+1 and Histn+1 to the identity server 42. The identity server 42 obtains the veri value. CIbase identification associated with the link value LIDn+lbase in the identity database. The identity server 42 obtains, from the identity database 36, the personal identifier ID associated, in the identity database, with the link value LIDn+lbase as well as with the CIbase verification value. Conversely, if it does not find any corresponding LIDn+lbase value in the database, the process stops: the natural person is not identified.

[0215] This method therefore takes advantage of a chain of n+1 link values ​​LIDlbase to LIDn+lbase, a chain in which each link value is obtained from the previous one. To prevent an attacker from simply finding the last link value in the chain, each of these values ​​is also calculated from a history value and the chain of history values ​​makes it possible to force passage through each of the buffer databases. This chain of history values ​​also makes it possible to find the server where an error may have occurred.

[0216] With reference to [Fig. 10], the identification system 44 differs from the identification system 30 of [Fig. 7] in that the CIbase values ​​are not stored in the identity database, but in one of the buffer databases 46. The identity database now only stores the last link value LIDn+lbase of the chain and the associated personal identifier ID.

[0217] The registration method 700 of [Fig. 11] implemented on this system 44 is adapted in this sense, one of the buffer databases being chosen to store these CIbase values.

[0218] Concerning the identification method 800 of [Fig.12] implemented on this system 44, it differs from the method described previously in that the buffer server 46 including the CIbase values ​​transmits all the CIbase verification values ​​corresponding to the received link value LIDk to the next buffer server, these values ​​then being transmitted from buffer databases to buffer databases until the identity server 48 receives these values. The identity server 48 compares each received CIbase to the value to be verified that it generates, and deduces therefrom the correct associated personal identifier ID to be indicated.

[0219] The system and methods described in relation to biometric fingerprints can be implemented with other types of data, in particular with any data deemed secret allowing a person to be identified.

[0220] Thus, by generalizing the description of the methods described to any secret, a method for identifying a natural person is therefore provided, implemented by computer and comprising the following steps:

[0221] - obtaining a code;

[0222] - obtaining a secret from the natural person;

[0223] - comparison of the secret of the natural person with secrets of a database of secrets;

[0224] - when a secret corresponding to the secret of the natural person in the database secret data is identified, generation of a link value from the secret and from the code, preferably from a hash function associated with a dedicated key;

[0225] - comparison of the generated link value to link values ​​of a database identity data separate from the secrets database or to link values ​​from a buffer database separate from the secrets database and the identity database;

[0226] - obtaining a verification value associated with the link value in the database identity data, or, the link value being a first link value in a chain of link values ​​in which each other link value is obtained from the previous link value, obtaining a verification value associated with a link value in the chain in the identity database or in a buffer database separate from the secrets database and the identity database,

[0227] - obtaining, from the identity database, an associated personal identifier, in the identity database, to the link value or to a link value in the link value chain,

[0228] - generation of a value to be verified from the received secret, the received code and the personal identifier obtained, preferably also from a hash function associated with a dedicated key;

[0229] - comparison of the generated value to be verified with the obtained verification value,

[0230] - when the generated value to be verified is identical to the obtained verification value, provision of the personal identifier obtained. List of references

[0231] 2: identification system according to a first embodiment

[0232] 4, 20: biometric database

[0233] 6, 22, 36: identity database

[0234] 8, 26: biometric server

[0235] 10, 28, 42, 48: identity server

[0236] 12: computer program

[0237] 14: recording medium

[0238] 16: identification system according to a second embodiment

[0239] 18, 38, 40: buffer database

[0240] 24, 32, 34, 46: buffer server

[0241] 30: identification system according to a third embodiment

[0242] 44: identification system according to a fourth embodiment

[0243] 100: system registration process 2

[0244]

[0245]

[0246]

[0247]

[0248]

[0249]

[0250] 200: identification method implemented within the system 2 300: registration method in the system 16 400: identification method implemented within the system 16 500: registration method in the system 30 600: identification method implemented within the system 30 700: registration method in the system 44 800: identification method implemented within the system 44

Claims

Claims

1. Method for identifying (200, 400, 600, 800) a natural person, implemented by computer and comprising the following steps: - obtaining (203) a code (C); - obtaining (205) a secret (T) from the natural person; - comparison (206; 410) of the secret (T) of the natural person with secrets (E) of a database (4; 20) of secrets; - when a secret (E) corresponding to the secret (T) of the natural person in the database (4; 20) of secrets is identified, generation (207) of a link value (LID; LID1) from the secret (T) and from the code (C), preferably from a hash function (MAC) associated with a dedicated key (Kb); - comparison (210; 410) of the generated link value (LID) with link values ​​(LIDbase; LID2base; LIDn+lbase) of an identity database (6; 22; 36) distinct from the secrets database (4; 20) or with link values ​​(LIDkbase; LIDlbase) of a buffer database (18; 38; 40) distinct from the secrets database (4; 20) and the identity database (6; 22; 36); - obtaining (211; 413) a verification value (CIbase) associated with the link value (LIDbase) in the identity database (6; 22; 36), or, the link value being a first link value (LIDlbase) of a chain of link values ​​in which each other link value is obtained from the previous link value, obtaining a verification value (CIbase) associated with a link value (LID2base; LIDn+1 base) of the chain in the identity database or in a buffer database separate from the secrets database and the identity database, - obtaining (212; 414), from the identity database (6; 22; 36), a personal identifier (ID) associated, in the identity database, with the link value (LIDbase) or with a link value (LID2base; LIDn+lbase) of the link value chain, - generation (213) of a value to be verified (CI) from the secret (T) received, the code (C) received and the personal identifier (ID) obtained, preferably also derived from a hash function (MAC) associated with a dedicated key (Ki); - comparison (214) of the value to be verified (CI) generated with the verification value (CIbase) obtained, - when the generated value to be verified (CI) is identical to the verification value obtained (CIbase), provision (215) of the personal identifier obtained.

2. Method (200; 400; 600; 800) according to the preceding claim, in which, the method being a biometric identification method, the secret (T) relates to a biometric fingerprint of the natural person, in particular the secret is a hashed value (Fb(T)) of a biometric fingerprint of the natural person, the secret database (4; 20) is a biometric database comprising biometric fingerprints of natural persons.

3. Method (200; 400; 600; 800) according to any one of the preceding claims, in which the code (C) is: - relating to a password provided by the natural person, in particular the code (C) comprises a hashed value of a password provided by the natural person to the secret server; and / or - relating to an entity, such as a merchant with which the natural person makes his identification, in particular the code (C) comprises a public identification value of the entity known by the secret server.

4. Method (400; 600; 800) according to any one of the preceding claims, comprising the following steps, when the link value (LID1) is a first link value of a chain of link values ​​in which each other link value is obtained from the previous link value: - beforehand, generating (408) a first history value (Histl), of a chain of history values, from the first link value (LID1), - when a link value (LIDlbase) corresponding to the generated first link value (LID1) is identified in the buffer database (18; 38;40), generation (411) of a next link value (LID2), optionally last link value, of the link value chain, from the secret (T), the code (C) and the first history value (Histl), preferably from a hash function (MAC) associated with a dedicated key, and generation of a next history value (Hist2) from the next link value (LID2) and the first history value, preferably also from a one-way function associated with a dedicated key, - optionally, comparison of the next link value (LIDk) with;

5. link values ​​(LIDkbase) from a subsequent buffer database distinct from the buffer database, and generating a subsequent link value (LIDk+1) and a subsequent history value (Histk+1), these comparison and generation steps being repeated until a last link value of the link value chain is generated, - to obtain the associated personal identifier (ID) in the identity database, comparing the last link value of the link value chain with link values ​​from the identity database (LIDn+lbase). Method for registering (100; 300; 500; 700) a natural person in an identification system, implemented by computer and comprising the following steps: - obtaining (105) code (C); - obtaining (107) a secret (E) from the natural person; - comparison (109) of the secret (E) of the natural person with secrets (T) of a secrets database; - when no secret in the database corresponds to the secret of the natural person, generation (110) of a link value specific to the natural person, from the secret of the natural person and the code (C), preferably from a hash function associated with a dedicated key; - storage (110), in the secrets database, of the secret of the natural person, without storing either the link value or the code; - generation (116), following receipt of this code and this secret, of a personal identifier of the natural person; - generation (111) of a verification value from the received secret, the received code and the generated personal identifier, preferably also from a hash function associated with a dedicated key; - storing (118), in an identity database, the personal identifier of the natural person associated with the link value and the verification value, or, the link value being a first link value of a chain of link values ​​in which each other link value is obtained from the previous one, storing, in the identity database, the personal identifier associated with the last link value of the chain, and storing the verification value, in the identity database and associated with the personal identifier or in a buffer database, separate from the secret database and the identity database, associated with a link value of the chain.

6. System (2; 16; 30; 44) for identifying a natural person, comprising: - a database (4; 20) of secrets comprising secrets (T) of natural persons, and - an identity database (6; 22; 36) comprising respective personal identifiers (IDs) of these natural persons, the identity database associating a link value with each personal identifier of a natural person, - automated means configured to: * comparing a secret received from a natural person to secrets in the secrets database and, a corresponding secret of the natural person being identified, to generate a link value from the secret of the natural person and from a code, preferably from a hash function associated with a dedicated key, * comparing the received link value to link values ​​in an identity database or to link values ​​in a buffer database separate from the secrets database and the identity database; * obtaining a verification value associated with a link value in the identity database or, the link value being a first link value in a chain of link values ​​in which each other link value is obtained from the previous link value, obtaining a verification value associated with a link value in the chain in the identity database or in a buffer database separate from the secrets database and the identity database, *obtain, from the identity database, a personal identifier associated, in the identity database, with the link value or a link value in the link value chain, *obtain a value to be verified from the received secret, the received code and the obtained personal identifier, preferably also from a hash function associated with a dedicated key, *compare the generated verification value with the obtained verification value, and when the generated verification value is identical to the obtained verification value, indicate that the obtained personal identifier corresponds to the secret received from the natural person.

7. Identification system (6; 30; 44) according to the preceding claim, also comprising: - at least one buffer database (18; 38; 40), separate from the secrets database and the identity database, comprising link values, - automated means configured to: *receive the link value, the code and the secret, *compare the received link value with the link values ​​of the buffer database, and, when it identifies a corresponding link value, to generate a next link value of the chain of link values ​​from the link value, *transmit the next link value, the code and the secret.

8. Data processing system (2; 16; 30; 44) comprising a processor configured to implement the steps of the identification method (200; 400; 600; 800) according to any one of claims 1 to 4 or of the registration method (100; 300; 500; 700) according to claim 5.

9. A computer program (12) comprising instructions which, when the program is executed by a computer, cause the computer to implement the steps of the identification method according to any one of claims 1 to 4 or of the registration method according to claim 5.

10. A computer-readable recording medium (14) comprising instructions which, when executed by a computer, cause the computer to carry out the steps of the identification method (200; 400; 600; 800) according to any one of claims 1 to 4 or of the writing method (100; 300; 500; 700) according to claim 5.