process implemented by a processing unit having access to a biometric database
Associating biometric data with disjoint random sets and generating condition-specific responses in biometric databases enhances security by thwarting attackers' attempts to determine database contents, ensuring passenger information remains secure.
Patent Information
- Application Number
- FR2023008427
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-08-03
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2043-08-03
AI Technical Summary
Existing biometric databases are vulnerable to query attacks where attackers can determine if an individual is a passenger by submitting biometric data and analyzing responses, compromising security.
Implement a method where biometric data is associated with disjoint sets of random numbers, generating responses containing random numbers that satisfy specific conditions, making it difficult for attackers to deduce database contents.
Enhances the robustness of biometric databases against query attacks by providing unpredictable responses, thereby protecting the integrity of passenger information.
Smart Images

Figure 00000018_0000 
Figure 00000019_0000
Abstract
Description
Title of the invention: method implemented by a processing unit having access to a biometric database FIELD OF THE INVENTION
[0001] The present invention relates to a method implemented by a processing unit having access to a biometric database. STATE OF THE ART
[0002] To secure the boarding of passengers on board an aircraft, one solution envisaged is to create a database of passengers before boarding. Such a database is for example created from biometric data. The identity of passengers can be checked before boarding by querying such a database.
[0003] Such a query generally consists of transmitting a query asking whether a biometric data item is referenced in the database. The query is processed by a processing unit having access to the contents of the database. In response to the query, the unit generates a response which indicates whether or not the biometric data item is referenced in the database.
[0004] However, an attacker could attempt to guess whether an individual is a passenger or not on a flight, by submitting biometric data of the individual to the processing unit and generating a query in the format expected by the processing unit. By multiplying queries on a large number of biometric data relating to different individuals, and by analyzing the content of the responses provided by the processing unit, the attacker could even arrive at the conclusion that an individual will board a given flight. Statement of the invention
[0005] One aim of the invention is to make a biometric database more robust to query attacks, so that it is more difficult for an attacker to determine whether or not an individual is referenced in such a database.
[0006] This aim is achieved by a method implemented by a processing unit, comprising steps of: • receiving a first biometric data item and a query asking whether the first biometric data item is referenced in a database, the database comprising reference biometric data items associated with respective random sets which are disjoint, each random set comprising a plurality of random sets, • search for a second biometric data which corresponds to the first biometric data among the reference biometric data, • generation of a response to the request, the response containing a random number satisfying the following conditions: • when the second biometric data is found during the search, the random number is an element of the set of random numbers associated with the second biometric data, • when the second biometric data is not found during the search, the random number does not belong to any of the random number sets associated with the reference biometric data, • the random number is different from a previous random number contained in a previous response to a previous query asking whether a previous biometric data item is referenced in the biometric database, both when the previous random number is an element of one of the sets of random numbers and when the previous random number does not belong to any of the sets of random numbers.
[0007] The proposed method may also comprise the following optional features, taken alone or in combination whenever technically possible.
[0008] Preferably, the method comprises the following steps implemented for any reference biometric data, during an enrollment of the reference biometric data in the database: • generation of data representative of the set of hazards associated with the reference biometric data, • storage, in the database, of the generated data.
[0009] Preferably, for any reference biometric data, the data representative of the set of random values associated with the reference biometric data is constituted by the set of random values associated with the reference biometric data.
[0010] Preferably, the method comprises the following step carried out for any reference biometric data following the enrollment of the reference biometric data: • ordering the transmission to a control system of the data representative of the set of random events associated with the reference biometric data.
[0011] Preferably, when the second biometric data is not found during the search, the random number included in the response is generated by the processing unit after the search step.
[0012] There is also provided an identity control method implemented by a control system communicating with a processing unit configured to implement the aforementioned method, the identity control method comprising the following steps: • for any reference biometric data, reception of data representative of the set of random variables associated with the reference biometric data, following enrollment of the reference biometric data in the database, and storage of the data representative of the set of random variables associated with the reference biometric data in a memory, • transmission to the processing unit of the request asking whether the first biometric data is referenced in a database, • receipt of the response to the request, • verification of the existence in the memory of data representative of a set of random events which includes the random event contained in the response.
[0013] Preferably: the reference biometric data relates to reference individuals having a right of access to a secure area, and the first biometric data relates to an individual wishing to access the secure area.
[0014] Further provided is a computer program product comprising program code instructions for executing the steps of any of the aforementioned methods, when this program is executed by a processing unit.
[0015] There is further provided a computer-readable memory storing computer-executable instructions for carrying out the steps of any of these methods.
[0016] Also provided is a biometric data management system comprising: • A communication interface configured for: • receive a first biometric data, and a query asking whether the biometric data is referenced in a database, the database comprising reference biometric data associated with respective random sets which are disjoint, each random set comprising a plurality of randoms, • issue a response to the request, • a processing unit configured to: • search for a second biometric data item that corresponds to the first biometric data item among the reference biometric data items, • generate the response to the query, the response containing a random number, in which the random number satisfies the following conditions: • when the second biometric data is found during the search, the random number is an element of the set of random numbers associated with the second biometric data, • when the second biometric data is not found during the search, the random number does not belong to any of the random number sets associated with the reference biometric data, • the random number is different from a previous random number contained in a previous response to a previous query asking whether a previous biometric data item is referenced in the database, both when the previous random number is part of one of the sets of random numbers and when the previous random number does not belong to any of the sets of random numbers associated with the reference biometric data.
[0017] A system is also proposed comprising: • A management system that complies with the above definition, and • A control device comprising: • A communication interface configured for: • for any reference biometric data contained in the database, receive data representative of the set of random events associated with the reference biometric data, following enrollment of the reference biometric data in the database, • send the request to the management system, • receive the response to the request, • A memory for storing the representative data received by the communication interface, • A processing unit configured to check the existence in the memory of data representing a set of random values which includes the random value contained in the response. DESCRIPTION OF FIGURES
[0018] Other characteristics, aims and advantages of the invention will emerge from the following description, which is purely illustrative and non-limiting, and which must be read in conjunction with the appended drawings in which:
[0019] [Fig.l] schematically illustrates a system according to one embodiment of the invention.
[0020] [Fig. 2] is a flowchart of steps of a method according to one embodiment of the invention.
[0021] Throughout the figures, similar elements bear identical references. DETAILED DESCRIPTION OF THE INVENTION
[0022] With reference to [Fig.l], a system comprises a control device 1 and a biometric data management system 2.
[0023] The control device 1 has the function, among other things, of controlling the identity of individuals.
[0024] The control device 1 comprises a data processing unit 10, a communication interface 12 for communicating with the management system 2, and a memory 14.
[0025] The data processing unit 10 is configured to implement certain steps of an identity control method which will be described later. For example, the data processing unit 10 comprises at least one processor configured to execute the code instructions of a program so as to implement these steps.
[0026] The communication interface 12 is for example of the wireless radio type, and uses any communication protocol (Wi-Fi, Bluetooth, etc.). Alternatively, the communication interface is wired (for example Ethernet).
[0027] The memory 14 is suitable for storing data. It is of any type (Flash, EEPROM, hard disk, SSD, etc.).
[0028] The memory 14 comprises an identity database DBI. As will be seen later, this identity database is intended to contain information relating to the identity of individuals in association with sets of random events.
[0029] The control device 1 further comprises a biometric data acquisition unit 16. The acquisition unit 16 may comprise a camera configured to acquire images showing the face of an individual, and to extract biometric data from such images. Alternatively, the acquisition unit 16 comprises a fingerprint sensor and / or an iris sensor.
[0030] In one embodiment, the control device 1 further comprises a gate 18 that can be closed to prevent an individual from accessing a secure area, and opened to allow such access. The data processing unit 10 is in particular configured to control the opening and closing of the gate 18.
[0031] For example, the control device 1 is located in an airport, and the secure area is a boarding area; in this particular application, the individuals wishing to access the boarding area are the passengers of a flight, whose identity is to be checked before boarding.
[0032] Furthermore, the management system 2 comprises a request processing unit 20, a communication interface 22 for communicating with the control device 1, and a memory 24.
[0033] The information provided above about the data processing unit 10 and the communication interface 12 is also applicable to the unit of processing 20 and to the communication interface 22.
[0034] The memory 24 stores a biometric database DBB. The database DBB contains reference biometric data relating to previously enrolled individuals. Preferably, the reference biometric data are not in clear text in the database, but are instead protected in confidentiality, i.e. are in an encrypted form, using an encryption method known from the state of the art.
[0035] No information on the identity of enrolled individuals is stored in the DBB biometric database (name, first name, date of birth, place of birth, address, etc.), apart from reference biometric data.
[0036] Each reference biometric data item is associated, in the DBB database, with a set of random values specific to the reference biometric data item. Each set of random values comprises a plurality of random values. In the present disclosure, a random value designates a randomly generated data item or one dependent on a randomly generated data item.
[0037] The sets of random variables are all disjoint. By disjoint, we mean that the sets of random variables have no element (random) in common. In other words, a random variable constituting an element of a given set of random variables does not belong to any of the other sets of random variables.
[0038] The aforementioned association between reference biometric data and random sets is to be taken in the broad sense, and does not necessarily imply that the random sets are stored as such in the biometric database DBB.
[0039] Indeed, the DBB database can contain data representative of sets of random numbers, a data representative of a set of random numbers can certainly be constituted by the random numbers of the set in question, but not necessarily. Each reference biometric data is thus stored, in the DBB database, in association with a data representative of a set of random numbers specific to the biometric data.
[0040] Ultimately, if the DBB database contains N reference biometric data, then it also contains data representative of N sets of random events respectively associated with the reference biometric data.
[0041] The query processing unit 20 is configured to process queries emanating from a transmitter, in particular from the control device 1, these queries aiming to know whether or not a biometric data item is referenced in the biometric database DBB. The processing unit 20 is configured to respond to a query of this type with a response. Preferably, this response is itself protected in confidentiality. In other words, the response is preferably an encrypted one, which must still be decrypted to know whether the biometric data item provided with the initial query was well referenced in the biometric database.
[0042] With reference to [Fig.2], a method using the system described above comprises two phases: an enrollment phase and a control phase.
[0043] By convention, the steps implemented by the control device 1 are collectively called method 100, and the steps implemented by the management system are collectively called method 200.
[0044] During the enrollment phase, individuals acquire a right.
[0045] In the following, an application will be detailed in which this right is a right to access the secure area described above. We therefore consider the application where the control device 1 has the function of conditioning physical access to the secure area for individuals. For the purposes of illustration, it will be assumed that this secure area is a boarding area in an airport, and that the user wishes to purchase a ticket for a flight.
[0046] It is initially assumed that the biometric database DBB is empty.
[0047] A user provides the control device 1 with information about his identity (surname, first name, etc.), and provides the management device 2 with biometric data D which relates to this user during the enrollment phase. For example, the user transmits this data via a terminal that he owns, for example a smartphone, a tablet or a personal computer. The biometric data D is for example acquired by a sensor of the user's terminal.
[0048] In a step 202, the management device 2 receives the biometric data D relating to the individual, and an enrollment request RE of the biometric data D. This enrollment request RE may or may not be relayed by the control device 1.
[0049] The request processing unit 20 processes the enrollment request RE as follows.
[0050] In a step 204, the processing unit 20 generates a data item A representative of a set of random numbers. The set of random numbers comprises a plurality of random numbers of different values {Al, ..., Ai, ..., AM}.
[0051] In a first embodiment of step 204, the data A representative of the set of random numbers can be the set of random numbers itself, i.e. the M random numbers Al, ..., Ai, ..., AM directly.
[0052] In a second embodiment of step 204, the data A representative of the set of random numbers comprises at least one data item from which the set of random numbers can be reconstituted by a reconstruction processing known to the processing unit 20.
[0053] In a step 206, the processing unit 20 commands the addition, in the biometric database DBB, of the biometric data D received in association with the data A representative of the set of random values {Al, ..., Ai, ..., AM] generated in step 204. The biometric data D received then becomes a reference biometric data, enrolled.
[0054] In a step 207, the management system 2 sends to the control device 1 the data A representative of the set of random events associated with the biometric data D, in response to the request for enrollment of the biometric data D.
[0055] Thus, in the first embodiment, the management system transmits as data A the set formed by the M random values Al, ..., Ai, ..., AM generated for the biometric data D.
[0056] In the second embodiment, the M random values are not sent to the control device 1, but the control device 1 is capable of reconstituting the set of random values {Al, ..., Ai, ..., AM] as needed using the same reconstruction processing as that used by the management system 2. The second embodiment has the advantage of requiring less storage resources and bandwidth than the first embodiment. Indeed, the volume of data representative of the set of random values is smaller.
[0057] In a step 102, the control device 1 receives the data A.
[0058] In a step 104, the control device 1 stores in the database DBI identity data A representing the set of random events, in association with information relating to the identity of the individual to whom the biometric data D relates, which the individual has previously provided (surname, first name, address, etc.).
[0059] The preceding steps are repeated for each new user wishing to be enrolled.
[0060] At each new implementation of the generation step 204, a new data item A representative of a new set of random numbers is generated. Any new set of random numbers verifies the disjunction constraints discussed previously, that is to say that all the random numbers that it contains do not appear in any set of random numbers represented by a data item A previously generated, during a previous implementation of step 204.
[0061] At the end of the enrollment phase, N individuals have been enrolled. Consequently, N reference biometric data relating respectively to these individuals are present in the biometric database DBB, in association with N data A representative of N sets of random numbers which are all disjoint. Furthermore, the N data A representative of N sets of random numbers are also stored in the other database DBI in association with information relating to the identity of the individuals.
[0062] During a control phase subsequent to the enrollment phase, individuals avail themselves of the aforementioned right.
[0063] To do this, one of these individuals comes close to the control device 1.
[0064] In a step 106, the control device 1 acquires a biometric data item D of the individual, which is conventionally called “first biometric data item”. This step can be carried out using the biometric acquisition unit of the control device 1. Alternatively, if the reference individual is in possession of a terminal, this terminal can acquire the first biometric data item D and then transmit it to the control device 1.
[0065] In a step 108, the device sends to the management system 2 the first biometric data D and a request R asking whether the first biometric data D is referenced in the biometric database DBB.
[0066] The request processing unit 20 receives the request R in a step 208, and applies the following processing to this request R.
[0067] In a step 210, the query processing unit 20 searches, in the biometric database DBB, a reference biometric datum which corresponds to the first biometric datum targeted by the query R. By convention, a reference biometric datum D' which corresponds to the first biometric datum is called "second biometric datum".
[0068] Step 210 is known from the prior art. This step 210 may comprise the calculation of a metric representative of a distance between the biometric data D and a reference biometric data, and the comparison of this distance with a predefined threshold. If the distance is less than the threshold, then it is considered that the two compared biometric data correspond. Otherwise, it is considered that the two biometric data do not correspond, and the calculation and comparison steps are repeated for another reference biometric data contained in the biometric database DBB.
[0069] The search 210 leads to two possible results: either the second biometric data D' is found, or the second biometric data D' is not found (i.e. no reference biometric data contained in the biometric database DBB corresponds to the first biometric data D).
[0070] In a step 212, the processing unit 20 generates a response to the query, the response comprising a random number. This step 212 is carried out regardless of the result of the search 210.
[0071] The random number included in the response generated in step 212 satisfies the following conditions: a. When the second biometric data D' is found during the search, the random number is an element of the set of random numbers associated with the second biometric data. b. When the second biometric data D' is not found during the search, the random number does not belong to any of the random number sets. c. The hazard is different from a previous hazard contained in a previous response to a previous query asking whether a previous biometric data item is referenced in the reference biometric database, both when the previous random number is an element of one of the random number sets and when the previous random number does not belong to any of the random number sets.
[0072] In case a), the processing unit 20 simply selects one of the random values from the set represented by the data A associated with the data D', this data A having been generated during the enrollment phase.
[0073] Preferably, in case b), the random number is generated by the processing unit 20 following the search step 210.
[0074] Whatever the result of the search 210 (case a) or case b)), the random number included in the response is always coded on the same number of bits, preferably at least 16 bits, or even at least 32 bits. As indicated previously, it is easy to obtain a random number satisfying the non-membership condition stated in case b) when this random number is coded on a high number of bits.
[0075] In a step 214, the management system 2 transmits the response to the sender of the request, otherwise to the control device 1.
[0076] In a step 110, the control device 1 receives the response containing the random number.
[0077] In a step 112, the control device 1 checks whether the random number contained in the response is referenced in the DBI database, that is, if the random number contained in the response is part of one of the N sets of random numbers which are represented by the data A stored in the DBI database.
[0078] In the first embodiment discussed previously, the processing unit 10 simply compares the random number received in the response with a random number stored in the memory 14, and repeats this step until it finds a random number stored in the DBI database which is equal to the random number contained in the response or until all the sets of random numbers are searched.
[0079] In the second embodiment, the processing unit 10 applies the reconstruction processing to reconstruct a set of random numbers, before comparing the received random number with the random numbers of the reconstructed set. These steps are repeated until a random number stored in the DBI database is found which is equal to a reconstructed random number or until all the sets of random numbers have been reconstructed and scanned.
[0080] If, during the verification 112, the control device 1 finds that the random number received in the response is referenced in the identity database DBI, then it is considered that the individual to whom the first biometric data D relates does indeed have the right that he wishes to exercise (in this case, to access the secure area). The processing unit 10 then automatically commands the opening of the gate 18, so as to allow the individual to access the secure area.
[0081] If during the verification 112 the control device 1 notes on the contrary that the random number received is not referenced in the DBI identity database, then there is a presumption that the individual to whom the first biometric data relates does not have the right that he wishes to exercise (in this case, to access the secure area). The processing unit 10 then does not automatically command the opening of the gate 18, thus preventing the individual from accessing the secure area. In this second case, a manual check of the identity of the individual may possibly be carried out as a supplement, by asking the user to provide an identity document (identity card, passport or other), and checking whether the database contains identity information corresponding to the information recorded in the identity document (surname, first name, etc.).
[0082] The preceding steps are repeated each time a new individual avails himself of the aforementioned right.
[0083] Attacker attempts to access the database
[0084] Let us now suppose that an attacker seeks to obtain information on the content of the biometric database DBB, by interrogating the management system 2 by successive requests, and by analyzing the corresponding responses returned by the management system 2. It is assumed that the attacker has succeeded in obtaining biometric data relating to individuals, and knows the format of the requests that the processing unit 20 is intended to process.
[0085] Using a terminal, the attacker sends to the management system 2 a biometric data item and a request asking whether the biometric data item is referenced in the database, in the format expected by the management system 2, and repeats this step several times, as in step 108 implemented by the control device 1.
[0086] The management system 2 processes each request in accordance with the steps 210, 212, 214 described previously. The attacker, who sends the requests, therefore receives a succession of responses.
[0087] This sequence of responses does not provide the attacker with any useful information.
[0088] First, each response that the attacker receives contains a random variable, both in the case where the biometric data tested by the attacker is actually present in the DBB database (condition a) and in the opposite case (condition b).
[0089] Second, all the responses that the attacker receives successively contain, by construction, different random values (condition c). Indeed, at each new request, the processing unit “draws” from a set of random values a random value that has not already been used previously and returned in response to a previous request. It is noted that the random value can be drawn from a set of random values that has been associated with a reference biometric data item (if, by chance, the attacker has managed to get hold of a biometric data item relating to an individual enrolled in the biometric database DBB) or not (when the biometric data item submitted by the attacker refers to an individual who is not referenced in the DBI biometric database). From the attacker's point of view, the behavior of the management system is similar in both cases.
[0090] This principle in no way prevents the control device 1 from subsequently carrying out the identity control phase discussed previously (steps 110, 112, 114). If by chance the management system 2 has been led to respond to requests from an attacker between the enrollment phase and the control phase, the management system 2 will still provide the control device 1 with a random number satisfying the conditions a), b), c), the only difference potentially residing in the value of the random number returned.
[0091] For example, the control device 1 will receive the random number A1 associated with an enrolled individual as a response to step 110, in the case where no intercalary attack has been carried out. On the other hand, if two intercalary attacks are carried out with two biometric data which turn out to relate to an enrolled individual, the attacker will receive the random numbers A1, A2 as responses, and the control device 1 will receive at step 110 the random number A3 as a response to a request based on a biometric data item of the same individual. Of course, this example assumes that the index i associated with a biometric data item is incremented, but the interval of integers of length M can be traversed by other logic (in particular by decrementation).
[0092] A situation that may occur is that in which the processing unit 20 is interrogated such a large number of times (for example by an attacker) that the set of random numbers {Al, ..., Ai, ..., AM] associated with one of the reference biometric data is entirely "consumed". In this case, two policies can be implemented.
[0093] According to a first policy, the processing unit 20 again implements steps 204, 206, 207, so as to transmit to the control device 1 a new data item A' associated with the biometric data item concerned (the control device 1 also repeats steps 102, 104).
[0094] According to a second policy, the processing unit 20 returns a new random number not belonging to any of the sets of random numbers (as in case b), but, unlike the first policy, the processing unit 20 does not “declare” this new random number to the control device 1 via step 207. In this case, the enrolled individual to whom the reference biometric data under discussion relates will not be recognized as being enrolled during step 112. It is to cover such a situation that it is advantageous to carry out a manual check of the identity of the individual as a supplement, as indicated above.
Claims
Claims
1. Method implemented by a processing unit (20), comprising steps of: • receiving (208) a first biometric data item and a query asking whether the first biometric data item is referenced in a database (DBB), the database (DBB) comprising reference biometric data items associated with respective random sets which are disjoint, each random set comprising a plurality of random sets, • searching (210) for a second biometric data item which corresponds to the first biometric data item among the reference biometric data, • generating (212) a response to the query, the response containing a random set satisfying the following conditions: • when the second biometric data item is found during the search, the random set is an element of the random set associated with the second biometric data item, • when the second biometric data item is not found during the search,the random number does not belong to any of the sets of random numbers associated with the reference biometric data, • the random number is different from a previous random number contained in a previous response to a previous query asking whether a previous biometric data item is referenced in the biometric database (BDB), both when the previous random number is an element of one of the sets of random numbers and when the previous random number does not belong to any of the sets of random numbers.,
2. Method according to the preceding claim, comprising the following steps implemented for any reference biometric data, during an enrollment of the reference biometric data in the database (DBB): • generation of data (A) representative of the set of hazards associated with the reference biometric data, • storage, in the database (DBB), of the data generated.
3. Method according to claim 2, in which, for any reference biometric data, the data representative of the set of random values associated with the reference biometric data is constituted by the set of random values associated with the reference biometric data.
4. Method according to any one of claims 2 and 3, further comprising the following step carried out for any reference biometric data following the enrollment of the reference biometric data: • ordering the transmission to a control system (1) of the data representative of the set of random events associated with the reference biometric data.
5. Method according to any one of the preceding claims, wherein when the second biometric data is not found during the search, the random number included in the response is generated by the processing unit (20) after the search step.
6. Identity control method implemented by a control system (1) communicating with a processing unit (20) configured to implement the method according to any one of the preceding claims, the identity control method comprising the following steps: • for any reference biometric data, reception of data representative of the set of random events associated with the reference biometric data, following enrollment of the reference biometric data in the database, and storage of the data representative of the set of random events associated with the reference biometric data in a memory (14), • transmission to the processing unit (20) of the request asking whether the first biometric data is referenced in a database (DBB), • reception of the response to the request, • verification of the existence in the memory of data representing a set of random variables which includes the random variable contained in the response.
7. Identity control method according to the preceding claim, in which: • the reference biometric data relates to reference individuals having a right of access to a secure area, • the first biometric data relates to an individual wishing to access the secure area.
8. Computer program product comprising program code instructions for executing the steps of the method according to one of the preceding claims, when this program is executed by a processing unit (20).
9. Computer-readable memory (24) storing computer-executable instructions for carrying out the steps of the method according to one of the preceding claims.
10. A biometric data management system (2) comprising: • A communication interface (22) configured to: • receive a first biometric data item, and a query asking whether the biometric data item is referenced in a database (DBB), the database (DBB) comprising reference biometric data items associated with respective random sets which are disjoint, each random set comprising a plurality of random sets, • issue a response to the query, • a processing unit (20) configured to: • search for a second biometric data item which corresponds to the first biometric data item among the reference biometric data, • generate the response to the query, the response containing a random set, in which the random set satisfies the following conditions: • when the second biometric data is found during the search, the random number is an element of the set of random numbers associated with the second biometric data, • when the second biometric data is not found during the search, the random number does not belong to any of the random number sets associated with the reference biometric data, • the random number is different from a previous random number contained in a previous response to a previous query asking whether a previous biometric data item is referenced in the database (DBB), both when the previous random number is part of one of the sets of random numbers and when the previous random number does not belong to any of the sets of random numbers associated with the reference biometric data.
11. System comprising: • A management system (2) according to the preceding claim, and • A control device (1) comprising: • A communication interface (12) configured for: • for any reference biometric data contained in the database (DBB), receive data representative of the set of random events associated with the reference biometric data, following enrollment of the reference biometric data in the database, • send the request to the management system (2), • receive the response to the request, • A memory (14) for storing the representative data received by the communication interface (12), A processing unit (10) configured to verify the existence in the memory (14) of data representative of a set of random values which includes the random value contained in the response.