Multi-biometric authentication or identification process.

The method generates synthetic biometric data using a generative model and unique identifiers to authenticate or identify individuals, addressing privacy and security issues in biometric systems by eliminating the need for centralized databases and enhancing security through linked biometric traits.

FR3153436B1Active Publication Date: 2025-10-10WORLDLINE SA(FR)
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2023010014
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-09-21
Publication Date
2025-10-10
Estimated Expiration
2043-09-21

AI Technical Summary

Technical Problem

Biometric authentication systems face challenges with centralized databases that compromise privacy and security, and decentralized methods like QR codes are vulnerable to loss and provide insufficient security.

Method used

A method using a generative model to create synthetic biometric data from a first biometric trait, combined with a unique identifier, for authentication or identification, without storing actual biometric data, utilizing a learned CNN-type neural network to reconstruct the second biometric trait.

Benefits of technology

Enhances privacy by avoiding data storage, reduces regulatory constraints, and improves security through multi-factor authentication, making it suitable for large user volumes with reduced calculation and access times.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000022_0000
    Figure 00000022_0000
  • Figure 00000023_0000
    Figure 00000023_0000
  • Figure 00000024_0000
    Figure 00000024_0000
Patent Text Reader

Abstract

The present invention relates to a method for authenticating or identifying an individual, the method comprising the implementation of steps of: Obtaining a first candidate biometric data item acquired on a first biometric trait of the individual and a second candidate biometric data item acquired on a second biometric trait of the individual, different from the first biometric trait; Constructing, by applying a generative model to the first candidate biometric data item and to at least one unique reference identifier, a synthetic biometric data item corresponding to the second biometric trait; said unique reference identifier not being a biometric data item, and being stored on data storage means (12, 22a); Authenticating or identifying said individual on the basis of a comparison of the second candidate biometric data item and the synthetic biometric data item. Figure for abstract: Fig. 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Multi-biometric authentication or identification method. [0001 ] GENERAL TECHNICAL FIELD

[0002] The present invention relates to the field of biometric recognition, in particular based on voice and face. More specifically, it relates to a method for authenticating or identifying an individual on the basis of a first candidate biometric data and a second candidate biometric data, acquired on two different biometric traits of said individual.

[0003] STATE OF THE ART

[0004] Biometric authentication / identification is the automatic recognition of a person using distinctive features, i.e., automatically measurable, robust and distinctive physical (biological) characteristics or personal behavioral traits that can be used to verify (in the case of authentication) or determine (in the case of identification) the identity of an individual. Biometric technologies improve security and convenience of use.

[0005] Several biometric information has been used such as fingerprints, face, iris, voice, etc.

[0006] The problem is that managing biometric databases is complex and costly. In fact, the usual techniques require storing so-called reference biometric data (from authorized individuals called enrolled) in databases in order to compare them with fresh biometric data called candidates, acquired directly from individuals seeking to identify / authenticate themselves. All these biometric data remain personal data, the handling of which involves considerations of confidentiality and respect for privacy and is strictly regulated, in particular in accordance with the GDPR.

[0007] A technique called "Zero Biometry database" has therefore been proposed in which the reference biometric data (in particular faces of individuals) are encoded and only stored on terminals (smartphones) of individuals, with a view to representing them by dynamic QR codes. To authenticate, an individual displays his QR code on his terminal and presents it to a terminal, which decodes it to reconstruct a reference biometric template that can be compared with a candidate biometric data acquired by the terminal (photo of the face).

[0008] Such a method avoids any need for centralized biometric databases but poses other problems: - The mobile terminal is essential (but it can be lost, broken down

[0009]

[0010]

[0011]

[0012]

[0013]

[0014] battery, with a damaged screen, etc.), so it is not a "purely" biometric method. - A QR code stores in practice a small amount of information compared to a full face image, so security is lower. The present invention improves the situation. PRESENTATION OF THE INVENTION The present invention therefore relates, according to a first aspect, to a method for authenticating or identifying an individual, the method being characterized in that it comprises the implementation by data processing means of a terminal and / or a first server of steps of: a. Obtaining a first candidate biometric data acquired on a first biometric trait of the individual and a second candidate biometric data acquired on a second biometric trait of the individual, different from the first biometric trait; b. Construction, by applying a generative model to the first candidate biometric data and to at least one unique reference identifier, of a synthetic biometric data corresponding to the second biometric trait; said unique reference identifier not being a biometric data, and being stored on data storage means of the terminal and / or the first server; c. Authentication or identification of said individual based on a comparison of the second candidate biometric data and the synthetic biometric data. According to advantageous and non-limiting characteristics: There are a plurality of unique reference identifiers each associated with a reference individual, a synthetic biometric data is generated in step (b) for each unique reference identifier, and the second candidate biometric data is compared in step (c) to each synthetic biometric data. Said unique reference identifier is an encoding of a second reference biometric data item also corresponding to the second biometric trait, associated with said unique reference identifier; said second reference biometric data item not being stored by the data storage means of the terminal and / or the first server. The method comprises a prior enrollment of data for authentication or identification of a reference individual, said enrollment comprising the implementation by the data processing means of the first server of steps of: A. Obtaining a second reference biometric data acquired on a second biometric trait of the reference individual; B. Generation of a unique reference identifier by applying an encoding model to the second reference biometric data; C. Storage on data storage means (22a) of the first server (2a) of said unique reference identifier but not of the second reference biometric data.

[0015] The generative model is a learned model, the method comprising a prior step (aO) of learning, by data processing means of a second server, the parameters of at least the generative model, from a base of pairs of a first and a second biometric learning data.

[0016] Step (aO) comprises, for each of a plurality of pairs of a first and a second biometric learning data of said base: - The generation of a unique learning identifier (associated with the pair) by applying the encoding model to the second learning biometric data, - the attempt to reconstruct the second training biometric data by applying the generative model to the first training biometric data and to said unique training identifier.

[0017] Step (aO) comprises, for each of a plurality of pairs of a first and a second pair of a first learning biometric data and a second learning biometric data of said base: - The generation of • a first unique learning identifier by applying the encoding model to the second learning biometric data of the first pair, and • a second unique learning identifier by applying the encoding model to the second learning biometric data of the second pair; - the attempt to build • a first synthetic data by applying the generative model to the first training biometric data of the first pair and to said second unique training identifier, and • a second synthetic data item by applying the generative model to the first training biometric data item of the second pair and to said first unique training identifier,

[0018] such that neither the first synthetic biometric nor the second synthetic data item coincides with the second biometric data item of the first pair and / or with the second biometric data item of the second pair

[0019] Said generative model is a CNN-type neural network, in particular an auto-encoder.

[0020] Step (a) comprises the acquisition of the first candidate biometric data on the first biometric trait of the individual by first biometric acquisition means of the terminal and of the second candidate biometric data on the second biometric trait of the individual by second biometric acquisition means of the terminal, and their transmission to the first server; steps (b) and (c) being implemented by the data processing means of the first server.

[0021] The first biometric trait is the voice, and the second biometric trait is the face.

[0022] According to a second aspect, the invention relates to equipment for authenticating or identifying an individual, comprising data processing means and data storage means storing at least one unique reference identifier, characterized in that it comprises data processing means configured to - Obtaining a first candidate biometric data acquired on a first biometric trait of the individual and a second candidate biometric data acquired on a second biometric trait of the individual, different from the first biometric trait; - Construct, by applying a generative model to the first candidate biometric data and to said at least one unique reference identifier, a synthetic biometric data corresponding to the second biometric trait; - Authenticate or identify said individual based on a comparison of the second candidate biometric data and the synthetic biometric data.

[0023] According to advantageous and non-limiting characteristics:

[0024] The equipment is furthermore for enrolling data for authentication or identi identification of a reference individual.

[0025] The data processing means being further configured to: - Obtain a second reference biometric data acquired on a second biometric trait of the reference individual; - Generate a unique reference identifier by applying an encoding model to the second reference biometric data; - Store on the data storage means said unique reference identifier but not the second reference biometric data.

[0026] According to a third aspect, a set of a terminal, the first server according to the second aspect and possibly a second server for learning the generative model is proposed.

[0027] According to a fourth and a fifth aspect, the invention relates to a computer program product comprising code instructions for executing a method according to the first aspect of authentication or identification of an individual; and a storage means readable by computer equipment on which is recorded a computer program product comprising code instructions for executing a method according to the first aspect of authentication or identification of an individual. PRESENTATION OF FIGURES

[0028] Other characteristics and advantages of the present invention will appear on reading the following description of a preferred embodiment. This description will be given with reference to the appended drawings in which:

[0029] [Fig.l] [Fig.l] is a diagram of a system for implementing the method according to the invention;

[0030] [Fig.2] [Fig.2] is a flowchart representing the steps of an embodiment of the method according to the invention;

[0031] [Fig.3a] [Fig.3a] illustrates the arrangement of neural networks used in operation in a preferred embodiment of the method according to the invention;

[0032] [Fig.3b] [Fig.3b] illustrates the arrangement of neural networks used during learning in a preferred embodiment of the method according to the invention. DETAILED DESCRIPTION

[0033] Architecture

[0034] The present invention relates to a method for authenticating or identifying an individual, i.e. for determining or verifying the identity of the individual presenting himself in front of a terminal 1, in a system such as represented in [Fig.l], for example for the implementation of a transaction by said individual, but also for access control, guaranteed geolocation, etc.

[0035] The said individual whose identity is sought to be verified is considered a “candidate”, as opposed to “reference” individuals whose identity is known.

[0036] The terminal 1 comprises data processing means 11 such as a processor, and where appropriate data storage means 12 (a memory), interface means 13 (a screen). This is typically a smartphone-type mobile terminal, but alternatively the terminal 1 can be a tablet, a personal computer, but also fixed equipment such as an access control terminal, or any other equipment owned and controlled by an entity with whom the authentication / identification must be carried out.

[0037] Furthermore, and as will be seen, the terminal 1 advantageously comprises first and second biometric acquisition means 14, 15, i.e. means res respectively acquiring a first biometric data item on a first biometric trait of the individual and a second biometric data item on a second biometric trait of the individual, different from the first biometric trait.

[0038] Biometric features may, for example, be the shape of the individual's face, the individual's voice, one or more fingerprints, the shape of an ear, a hand (or any other part of the body) or one or more irises of the individual. It may also be the structure of the venous network of one or more fingers or one or both hands, etc. We also speak of "modalities" to designate various biometrics.

[0039] According to a preferred embodiment which will be described later, the first biometric trait is the voice of the individual (and the first biometric data is then a sound signal of speech from said individual) and the second biometric trait is the shape of the face of the individual (and the second biometric data is then a photo of this face), but it could be the reverse or any other combination of two different biometrics.

[0040] In the above embodiment, the first and second biometric acquisition means 14, 15 are in particular a microphone 14 and a camera 15, but in the case of other biometrics it could be a fingerprint scanner, an oculometer, etc. Note that these means 14, 15 are generally integrated into the terminal 1, but it could also be a peripheral connected to the rest of the terminal 1, for example that of a webcam or a headset connected (wired or not) to a smartphone-type terminal 1. The assembly then constitutes the terminal 1.

[0041] In all cases, the biometric data acquisition means 14, 15 advantageously comprise a data processing capacity (which can be transferred to the means 11) adapted to extract the biometric data from “raw” data representative of the biometric trait, according to a possible processing of the image of the biometric trait which depends on the nature of the biometric trait. Various sound or image processing methods for extracting biometric data are known to those skilled in the art. By way of non-limiting example, the extraction of the biometric data may comprise a breakdown of a sound signal and the isolation of a fragment corresponding to speech. As a variant, it may comprise an extraction of particular points (fingerprint minutiae) or of a shape / aspect of the face in the case of an image of the individual's face, etc. Alternatively or in addition, a convolutional neural network may be used.It is also possible that there is no such processing and that the biometric data is directly the raw data (iris image for example).

[0042] We will not return to this aspect in detail, and we will assume that we can obtain for an individual that we seek to identify / authenticate (i.e. the candidate individual) a first candidate biometric data acquired on a first biometric trait of the individual and a second candidate biometric data acquired on a second biometric trait of the individual, different from the first biometric trait, for any desired pair of biometric traits. To reformulate, each individual is associated with a pair of a first biometric data and a second biometric data, corresponding to different biometric traits.

[0043] Note that by analogy with the first and second candidate biometric data, we can speak of first and second reference data, i.e. “expected” biometric data corresponding to the same first and second biometric traits but for reference individuals, known and authorized. If the candidate individual is indeed the or one of the reference individual(s) (case respectively of authentication and identification), the first candidate biometric data must coincide with the first reference biometric data associated with said reference individual and the second candidate biometric data coincides with the second reference biometric data associated with said reference individual.

[0044] These reference data are however not necessary for the implementation of the present method, and especially do not need to be stored by any of the equipment involved. As we will see, we may just briefly need the second reference biometric data of an individual to carry out their enrollment, but this data can be processed on the fly and in practice never stored. The first reference data does not even need to be acquired.

[0045] Thus, in the absence of any storage of personal data there is no risk of leakage (and therefore no possible privacy problem), and no more regulatory constraints such as those of the GDPR to respect.

[0046] The present method is implemented by the terminal 1 and / or a first server 2a which can be the same as the terminal 1, or remote and connected by a network 10 such as the internet network. Advantageously, there is a second server 2b (which is a learning device as will be seen), typically remote (i.e. in the network 10), but which could be the same as the first server 2a. The first server 2a can for example be the authentication server of a banking entity.

[0047] Each server 2a, 2b also has data processing means 21a, 21b (typically a processor) and data storage means 22a, 22b (a memory, for example a hard disk). As will be seen, the data processing means 21b of the second server 2b (but also those of the first server 2a) can store at least one learning database, in practice pairs of a first and a second learning biometric data, i.e. of the same individual, which are preferably public data (and not reference biometric data) to continue to avoid any privacy problem.

[0048] Method

[0049] The present method relates to a biometric authentication or identification process based on two biometric traits, capable of verifying the identity of an individual without having to store reference biometric data for either of the two traits.

[0050] With reference to [Fig. 2], the present method begins with a step (a) of obtaining a first candidate biometric data item corresponding to the first biometric trait of the individual and a second candidate biometric data item corresponding to the second biometric trait of the individual, different from the first biometric trait. More precisely, step (a) comprises either directly acquiring the two candidate biometric data items by the means 14, 15 of the terminal 1, or receiving said data (where appropriate encrypted) by the server 2a from the terminal 1.

[0051] When the first biometric trait is the voice, the first candidate biometric data is, as typically explained, a sound signal of speech of said individual. By "sound signal of speech of said individual", we mean the audio recording of the "speaker" individual, i.e. pronouncing a sentence (predetermined or not), the sentence spoken being designated speech. It will be noted that we are not limited here to any speaker recognition technique, so that said speech is either: - A specific predetermined sentence; - An expected sentence, that is to say that for example terminal 1 displays the sentence to be pronounced, in challenge / response mode; - Any sentence; - Etc.

[0052] When the second biometric feature is the shape of the face, the second candidate biometric data is an image of the face or data derived therefrom (for example the position of characteristic points of the face)

[0053] In a step (b), the data processing means 11 or 21a construct, by applying a generative model to the first candidate biometric data and to at least one unique reference identifier, a synthetic biometric data item also corresponding to the second biometric trait of the individual. The unique identifier, or code, is a biometric data item, and typically an alphanumeric data item. It may be a QR code as in the prior art. As we will see, it is in particular an encoding of a second reference biometric data item, also corresponding to the second biometric trait.

[0054] Note that in the case of a plurality of unique reference identifiers, step (b) may comprise the construction of several synthetic data, i.e. one for each unique reference identifier (case of an identification).

[0055] In other words, each reference individual is associated with a unique reference identifier (which therefore represents an expected identity), the latter being in practice a representation of said second reference biometric data, but not disclosing anything about the reference individual.

[0056] As explained, preferably only the unique reference identifier is stored on the data storage means 12, 22a of the terminal 1 and / or the first server 2a (and / or possible second server 2b), and not the reference biometric data.

[0057] This method cleverly uses work that has shown that the different biometrics of an individual are "linked", and that it is possible, from a first biometric data item corresponding to the first biometric trait of the individual, to predict the second biometric data item corresponding to the second biometric trait of the same individual. To reformulate, it is possible to generate a synthetic biometric data item (in that it is artificial) corresponding to said second biometric trait (that is to say, it is for example a face image if the second biometric trait is the shape of the face) which turns out to coincide with the second biometric data item, i.e. to be sufficiently similar and for example to represent the same face in a recognizable manner.

[0058] For example, the document SpeechZFace: Leaming the Face Behind a Voice, Tae-Hyun Oh, Tali Dekel, Changil Kim, Inbar Mosseri, William T. Freeman, Michael Ru-binstein, Wojciech Matusik, IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2019, presents an auto-encoder type model, comprising a first encoder block and a second decoder block.

[0059] Each block being a CNN (Convolutional Neural Network) type neural network. The encoder block (for example a feature extraction block of a voice recognition CNN) generates a code representative of the first biometric data (voice), and the decoder block (for example a GAN, Generative Adversarial Network) generates the second biometric data (face) from said code. Indeed, it can be seen that said code is in practice also representative of the second biometric data.

[0060] The code is, as explained, not biometric data but a "feature map", which can be further compressed into the form of the unique identifier mentioned.

[0061] The present method proposes, as seen in [Fig.3a], a model for generating synthetic data which takes as input not only the first biometric data, but also the unique identifier. This adds entropy to the generative model and allows it to construct synthetic biometric data coinciding with the second biometric data of an individual only in the case where the first biometric data and the unique identifier in input are associated with the same individual, i.e. the unique identifier is indeed an encoding of the second biometric data of the same individual.

[0062] In other words, to the extent that the biometrics are linked as explained, the unique identifier "completes" the first biometric data, and the quality of the prediction of the second biometric data is greatly amplified if the two input data are associated with the same individual: for example in the case of the face, not only is the individual recognizable but in addition the image is very similar. Conversely, if it is theoretically possible to reconstruct the second biometric data from the identifier alone (this is what the prior art "Zero biometry database" proposes), this works poorly in practice. The invention thus proposes not to reconstruct the second biometric data on the basis of the identifier, but to use the identifier only to reinforce the reconstruction on the basis of the first biometric data, which is very different.It is also possible to further compress the identifier so that the reconstruction of the biometrics on its sole basis is completely impossible (To reformulate, the unique reference identifier is preferably obtained by encoding the second reference biometric data such that it is impossible to reconstruct the second reference biometric data from the unique identifier), which further improves respect for the user's privacy, insofar as the unique identifier is the only data still stored in a database, and avoids, as explained, any regulatory constraints.

[0063] In addition, the present method further improves security: if, on the contrary, the two input data of the generative model (first biometric data and unique identifier) ​​are associated with different individuals, which is an attempt at fraud, the model is disturbed and the synthetic data no longer resembles the second biometric data at all, and therefore represents, for example, the face of another individual who does not exist (a “hybrid” between the individual associated with the first biometric data and the individual associated with the second biometric data and the unique identifier), so that any authentication / identification becomes impossible.

[0064] Finally, it should be noted that the present method is particularly suitable for a large volume of users: to the extent that the database is particularly small and only stores alphanumeric data of minimal size compared to biometric data, the calculation and access times are greatly reduced.

[0065] Finally, in a step (c), the data processing means 11 or 21a authenticate / identify said individual on the basis of a comparison of the second candidate biometric data and the synthetic biometric data.

[0066] It is understood that the nature of the generation model means that the synthetic biometric data coincides with the second reference biometric data associated with said unique reference identifier (i.e. of the same reference individual) if and only if the first candidate biometric data coincides with a hypothetical first reference biometric data associated with said unique reference identifier (i.e. again from the same reference individual - we understand that in practice this first reference biometric data is theoretical, is not stored and does not even need to exist).

[0067] Thus, this technique makes it possible to use the generative model to simulate the second reference biometric data without having to store it either.

[0068] In authentication, we have a single unique identifier associated with the expected reference individual (i.e. the identity that the candidate individual claims to have), and the result of the comparison is binary.

[0069] In identification, there are a plurality of unique reference identifiers each associated with a reference individual, a synthetic biometric data item is generated in step (b) for each unique reference identifier, and the second candidate biometric data item is compared in step (c) to each synthetic biometric data item. The candidate individual is then identified as the reference individual associated with the unique reference identifier on the basis of which a synthetic biometric data item could be constructed coinciding with the second candidate biometric data item (if there is a match - otherwise the candidate individual is rejected).

[0070] In all cases, security is multi-factorial because: 1. if the voice of the candidate individual is not that of a reference individual, the synthetic data generated does not coincide with any second biometric data, and systematically represents the face of an individual who does not exist, and therefore who is neither the candidate individual nor any reference individual, hence any positive outcome is impossible at step (c), even if the candidate individual turns out to resemble one of the reference individuals by chance. 2. Even if an individual tries to impersonate a reference individual with a deepfake of his voice (spoofing), then the model will correctly reconstruct the second reference biometric data of this reference individual, but it will not coincide with the second candidate biometric data.

[0071] For the implementation of step (c), one can proceed in any known manner, in particular by calculating a so-called similarity score, for example from a distance calculation (between the synthetic biometric data and the second candidate biometric data), to finally compare it to a threshold. It is understood that two biometric data even coming from the same individual will never be perfectly identical, but it is considered that there is coincidence (i.e. that the data coincide) if the score exceeds said threshold (i.e. the distance is less than a minimum acceptable distance). Note that the threshold can be predetermined, or dynamic, depending on the context.

[0072] Alternatively, in particular in identification, one can use a classification model attempting to associate the second candidate biometric data with each synthetic biometric data.

[0073] For the generative model, we can use a CNN-type neural network, in particular an auto-encoder, and in particular the one proposed in the Speech2Face document mentioned above, with a feature extraction block followed by a GAN. If we want biometric traits other than voice / face, it is sufficient in particular to change the feature extraction block, taking in particular that of a network adapted to the first biometric trait: that of a VGG will for example be adapted to the face biometric trait, while that of a voice transcription network will be adapted to the face biometric trait

[0074] Learning

[0075] As explained, typically at least the generative model is a model learned on a basis of pairs of a first and a second training biometric data associated with any same individual (which is not a reference individual). Each pair can also be associated with the corresponding unique identifier, but it is recalled that it can be generated on the fly from the second biometric data, in particular by using an encoding model. Note that said learning base is preferably a public base (i.e. each pair is associated with a “public” individual, for example a celebrity, or even a volunteer individual) so as to avoid any storage of reference biometric data.

[0076] Preferably, the encoding model is either a model simultaneously learned at the same time as the generative model, or a pre-learned model, and potentially taken off the shelf, for example a feature extraction block of a neural network adapted to the first biometric trait (for example a VGG as proposed). Note that the encoding model may include a final block representing the output of the feature extraction block (typically a matrix) in the form of an alphanumeric identifier, by any known technique. For example, it may be a connected integer layer concatenating the values ​​of the boxes of the matrix.

[0077] The possible classification model of step (c) can also be learned, always on a public basis.

[0078] In this respect, the method advantageously comprises a preliminary step (aO) of learning, by data processing means 21b of a second server 2b, the parameters of at least the generative model, from said learning base (pairs of the first and second biometric learning data).

[0079] For a pair of a first and a second biometric data learning of said base (preferably a plurality, or even all), the generative model is trained to reconstruct said second biometric learning data from the first learning data and a unique identifier obtained by applying the encoding model to the second biometric learning data.

[0080] Thus, with reference to [Fig.3b], step (a0) comprises in the preferred embodiment, for each of a plurality (or even all) of pairs of a first and a second learning biometric data of said base: - The generation of a unique learning identifier (associated with the pair) by applying the encoding model to the second learning biometric data, - the attempt to reconstruct the second training biometric data by applying the generative model to the first training biometric data and to said unique training identifier. Learning aims to minimize the reconstruction error (distance between the synthetic image actually constructed by the generative model and the second training biometric data) by adjusting the parameters of the generative model. Note that this type of learning ("reconstruction of the input") is classic for autoencoders. We speak of attempted reconstruction because we know that at the beginning the synthetic biometric data will not coincide with the second biometric data, but that the distance will reduce as the parameter values ​​evolve and new pairs are tested. The encoding model can also be fine-tuned.

[0081] Note that to increase the discriminating character and prevent the generative model from being based on only one of its inputs, we can give it false examples (first and second biometric data from two different crossed pairs) by training it then not to reconstruct the second data.

[0082] Step (a0) comprises in this embodiment, for each of a plurality of pairs of a first and a second pair of a first learning biometric data and a second learning biometric data of said base (i.e. there is a first learning biometric data of a first pair, a second learning biometric data of the first pair, a first learning biometric data of a second pair different from the first pair (i.e. pairs associated with two different individuals) and a second reference biometric data of the second pair): - The generation of • a first unique learning identifier (associated with the first pair) by applying the encoding model to the second data training biometric of the first pair, and • a second unique training identifier (associated with the second pair) by applying the encoding model to the second training biometric data of the second pair; - the attempt to build • a first synthetic data by applying the generative model to the first biometric training data of the first pair and to said second unique training identifier, and / or • a second synthetic data item by applying the generative model to the first training biometric data item of the second pair and to said first unique training identifier,

[0083] such that neither the first synthetic biometric nor the second synthetic data item coincides with the second biometric data item of the first pair and / or with the second biometric data item of the second pair.

[0084] This time, the learning aims to maximize the reconstruction errors (distance between the synthetic images actually constructed by the generative model and the two second training biometric data) by playing on the parameters of the generative model. We note that this type of learning (discrimination of false) is classic for GANs. Again, we speak of attempted reconstruction because we know that at the beginning there is a risk of a certain number of false positives (synthetic biometric data coinciding with one of the second biometric data), but that the distance will increase as the parameter values ​​evolve and new pairs are tested. The encoding model can still be finely tuned.

[0085] Enrollment

[0086] The method advantageously comprises the prior enrollment of data for authentication or identification of a reference individual, typically implemented by the data processing means 21a of the first server 2a so that this enrollment can be controlled. As for the authentication or identification method, it can be placed entirely or partially on each of the first and second servers 2a, 2b. According to a preferred embodiment, there is truly a separation with the first server 2a having the authentication / identification functions and those of enrollment, and the second server 2b only those of learning. Note that this enrollment is independent of the learning (step (a0)) and can be implemented before or after.

[0087] Enrollment may be initiated by the individual on his terminal 1, assuming he can authenticate himself separately (e.g. by other biometric factors and / or in the presence of an authority), but not implemented on the terminal 1 for security issues.

[0088] According to a preferred embodiment represented by Figure 3, the method comprises the steps of: A. Obtaining a second reference biometric data item acquired on a second biometric trait of the reference individual (this is the equivalent of step (a) of the method according to the first aspect, it being understood that the first reference biometric data item is not required); B. Generation of a unique reference identifier by applying the encoding model to the second reference biometric data; C. Storage on data storage means 22a of the first server 2a of said unique reference identifier but not of the second reference biometric data. It is understood that the second reference biometric data could be stored briefly for the time required to implement step (B), but if necessary it would then be deleted in step (C). Preferably the unique identifier is generated on the fly.

[0089] Servers

[0090] According to a second aspect, the invention relates to the equipment for implementing the method according to the invention. In particular, the first server 2a and / or the terminal 1 have the role of authentication / identification equipment, and the first server 2a and / or the second server 2b have the role of enrollment equipment. The second server 2b is, on the other hand, the only one in charge of learning.

[0091] The authentication / identification equipment comprises data processing means 11, 21a, and data storage means 12, 22a. The terminal 1 has an interface 13 and especially biometric data acquisition means 14, 15 (for example microphone and camera).

[0092] The means 11,21a are configured to: - Obtaining a first candidate biometric data acquired on a first biometric trait of the individual and a second candidate biometric data acquired on a second biometric trait of the individual, different from the first biometric trait; - Construct, by applying a generative model to the first candidate biometric data and to said at least one unique reference identifier, a synthetic biometric data corresponding to the second biometric trait; - Authenticate or identify said individual on the basis of a comparison of the second candidate biometric data and the synthetic biometric data

[0093] The means 21a can further be configured to: Obtain a second reference biometric data acquired on a second biometric trait of the reference individual; Generate a unique reference identifier by applying the encoding model to the second reference biometric data; Store on the data storage means 22a said unique reference identifier but not the second reference biometric data.

[0094] According to a third aspect, a set of the terminal 1, the first server 2a and possibly the second server 2b is proposed. All these elements 1, 2a, 2b can be connected via a network 10.

[0095] Computer program product

[0096] According to a fourth and a fifth aspect, the invention relates to a computer program product comprising code instructions for the execution (in particular on the data processing means 11, 21a, 21b) of a method according to the first aspect of the invention for authenticating or identifying an individual, as well as storage means readable by computer equipment (a memory 12, 22a, 22b) on which this computer program product is found.

Claims

Claims

1. Method for authenticating or identifying an individual, the method being characterized in that it comprises the implementation by data processing means (11, 21a) of a terminal (1) and / or a first server (2a) of steps of: a. Obtaining a first candidate biometric data item acquired on a first biometric trait of the individual and a second candidate biometric data item acquired on a second biometric trait of the individual, different from the first biometric trait; b. Constructing, by applying a generative model to the first candidate biometric data item and to at least one unique reference identifier, a synthetic biometric data item corresponding to the second biometric trait; said unique reference identifier not being a biometric data item, and being stored on data storage means (12, 22a) of the terminal (1) and / or the first server (2a); c.Authentication or identification of said individual based on a comparison of the second candidate biometric data and the synthetic biometric data.

2. The method of claim 1, wherein there are a plurality of unique reference identifiers each associated with a reference individual, a synthetic biometric data item is generated in step (b) for each unique reference identifier, and the second candidate biometric data item is compared in step (c) to each synthetic biometric data item.

3. Method according to one of claims 1 and 2, in which said unique reference identifier is an encoding of a second reference biometric data item also corresponding to the second biometric trait, associated with said unique reference identifier; said second reference biometric data item not being stored by the data storage means (12, 22a) of the terminal (1) and / or of the first server (2a).

4. A method according to claim 3, comprising pre-enrollment of data for authentication or identification of a reference individual, said enrollment comprising the implementation by the data processing means (21a) of the first server (2a) of steps of: A. Obtaining a second reference biometric data item acquired on a second biometric trait of the reference individual; B. Generating a unique reference identifier by applying an encoding model to the second reference biometric data item; C. Storing on data storage means (22a) of the first server (2a) said unique reference identifier but not the second reference biometric data item.

5. Method according to one of claims 1 to 4, in which the generative model is a learned model, the method comprising a prior step (aO) of learning, by data processing means (21b) of a second server (2b), the parameters of at least the generative model, from a base of pairs of a first and a second biometric learning data.

6. Method according to one of claims 3 and 4 and claim 5 in combination, wherein step (a0) comprises, for each of a plurality of pairs of a first and a second training biometric data of said base: - The generation of a unique training identifier (associated with the pair) by applying the encoding model to the second training biometric data, - the attempt to reconstruct the second training biometric data by applying the generative model to the first training biometric data and to said unique training identifier.

7. Method according to claim 6, in which step (a0) comprises, for each of a plurality of pairs of a first and a second pair of a first biometric training data and a second biometric training data of said base: - The generation of • a first unique learning identifier by applying the encoding model to the second learning biometric data of the first pair, and • a second unique learning identifier by applying the encoding model to the second learning biometric data of the second pair; - attempting to construct • a first synthetic data by applying the generative model to the first learning biometric data of the first pair and to said second unique learning identifier, and • a second synthetic data by applying the generative model to the first learning biometric data of the second pair and to said first unique learning identifier, such that neither the first synthetic biometric nor the second synthetic data coincides with the second biometric data of the first pair and / or with the second biometric data of the second pair

8. Method according to one of claims 1 to 7, wherein said generative model is a CNN type neural network, in particular an autoencoder.

9. Method according to one of claims 1 to 8, in which step (a) comprises the acquisition of the first candidate biometric data on the first biometric trait of the individual by first biometric acquisition means (14) of the terminal (1) and of the second candidate biometric data on the second biometric trait of the individual by second biometric acquisition means (15) of the terminal (1), and their transmission to the first server (2a); steps (b) and (c) being implemented by the data processing means (21a) of the first server (2a).

10. Method according to one of claims 1 to 9, in which the first biometric trait is the voice, and the second biometric trait the face.

11. Equipment (11, 2a) for authenticating or identifying a individual, comprising data processing means (11, 21a) and data storage means (12, 22a) storing at least one unique reference identifier, characterized in that it comprises data processing means (11, 21a) configured to: - Obtaining a first candidate biometric data acquired on a first biometric trait of the individual and a second candidate biometric data acquired on a second biometric trait of the individual, different from the first biometric trait; - Construct, by applying a generative model to the first candidate biometric data and to said at least one unique reference identifier, a synthetic biometric data corresponding to the second biometric trait; - Authenticate or identify said individual based on a comparison of the second candidate biometric data and the synthetic biometric data.

12. Equipment according to claim 11, furthermore for enrolling data for authentication or identification of a reference individual, characterized in that the data processing means (21a) are further configured to: - Obtain a second reference biometric data item acquired on a second biometric trait of the reference individual; - Generate a unique reference identifier by applying an encoding model to the second reference biometric data item; - Store on the data storage means (22a) said unique reference identifier but not the second reference biometric data item.

13. Computer program product comprising code instructions for executing a method according to one of claims 1 to 10 for authenticating or identifying an individual, when said program is executed on a computer.

14. Storage medium readable by computer equipment on which is registered a computer program product comprising code instructions for executing a method according to one of claims 1 to 10 for authenticating or identifying an individual.