Method for comparing anonymized data, devices and corresponding program

The method addresses the challenge of securely and anonymously sharing sensitive data by processing digital element signatures through a network of entities, ensuring anonymity and preventing database reconstruction, thereby enhancing data security and privacy.

FR3157591A1Pending Publication Date: 2025-06-27THALES SA
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
FR2023015300
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-26
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

Existing technologies face challenges in securely and anonymously sharing sensitive data between entities, particularly in preventing the reconstruction of databases from anonymized data, which is crucial for preventing fraud and ensuring data privacy.

Method used

A method for processing a signature of a digital element, involving receiving a request, broadcasting a signature of the digital element, receiving responses from comparing the signature with local signatures, aggregating responses, and transmitting the aggregated data, while ensuring anonymity through techniques like hash matrices and binary hashing.

Benefits of technology

This method allows for anonymous sharing of sensitive data, preventing the reconstruction of databases and ensuring the anonymity of both requesting and responding entities, thus enhancing data security and privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for comparing anonymized data, devices and corresponding program The present invention relates to a method for processing a signature of a digital element comprising: - a step of receiving (E10) a request (RQ) relating to said digital element (DRSig), from a requesting electronic device (DEr1); - a step of broadcasting (E20), to responding electronic devices (DEr2, DEr3, DEr4), a signature of said digital element (DRSig); - a step of receiving (E30), from the responding devices, responses (RT) resulting from a comparison between the signature and at least one signature of digital elements (DRSig); - a step of aggregating (E40) all the responses (RT) in an aggregated data structure (StRTa); - a step of transmitting (E50) the aggregated data structure to said requesting device (DEr1). Figure for the abstract: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for comparing anonymized data, devices and corresponding program

[0001] The invention relates to the protection of sensitive data. The invention relates more particularly to the protection of sensitive data in a context of exchange, between potentially competing parties, of such data.

[0002] The digitalization of the economy is leading to the almost systematic implementation of dematerialized procedures for all everyday procedures. Physical interaction between two protagonists is gradually being replaced by digital interaction. The protagonists can still continue to meet or exchange, but these meetings and exchanges are mainly carried out via digital platforms. For example, opening a bank account no longer requires going to a branch and physically meeting an advisor.

[0003] These new business practices are leading to an increase in fraud, particularly identity fraud. Freed from the constraints of physical meetings, fraudsters have the option of using fake digital documents. In the banking sector in particular, we are seeing a rise in bank account fraud, despite existing preventive analysis tools. Three cases of electronic fraud alone account for 80% of fraud (fraudulent transfers to IB ANs, falsified identity, falsified documents justifying income).

[0004] The prevention of these frauds faces significant technological and regulatory problems. Ideally, to avoid problems related to replication fraud, it would be interesting for stakeholders (i.e. banking establishments in this case) to be able to exchange digital elements relating to fraudsters in order to create a shared database. In the banking sector, for example, the problems of replication fraud could be resolved through the sharing of certain data related to recognized frauds: IB AN (simple case), image-type documents - identity documents and certain customer documents (e.g. account statements). Indeed, the same photo, that of the fraudster, can for example be found on falsified identity cards and used to open several accounts in different names.Similarly, sharing falsified account statements, which are used by fraudsters to justify the allocation of advantageous payment instruments (overdraft, withdrawal capacity, etc.), could be a solution.

[0005] This type of sharing, however, is difficult to implement for several reasons: for example, regulatory constraints require that each bank retains its data (no centralized database can be created) and that only perfectly anonymized data, which cannot be traced back to the original data, can be exchanged. Furthermore, the security of such sharing should be perfectly ensured, which also poses significant technical problems.

[0006] On such a platform, it is also a matter of gaining the trust of partners by guaranteeing the anonymity of the banks issuing requests (to find out whether another bank has already identified a given photo as associated with a proven fraud attempt) as well as that of the banks responding to these requests.

[0007] The situation that has just been described in the case of the banking sector is also transposable in the field of security or cooperation between states participating in the same federation. Indeed, allied entities may have the need to share sensitive data, for example to identify a particular threat (e.g. terrorist, military) while ensuring that this exchange does not unduly disclose data or information that a state would not wish to share. This is for example the case when sharing data from telephone tapping, with the aim of identifying a particular person. Such a situation of data exchange needs can be found in other civil contexts.

[0008] To date, to respond to these situations, the existing solution consists, for each entity of a group, in individually interrogating all the other entities by transmitting the digital element, which does not guarantee the anonymity of the requesting entity and the responding entity: in fact, the requesting entity and the responding entity directly exchange digital elements, which implies that each of the entities knows exactly who is interrogating and who is responding and for which digital element.

[0009] There is therefore a need for a technical solution which allows, for a group composed of entities, a requesting entity to obtain confirmation or denial of the presence of sensitive data (for example data relating to identity) in a database of one or more other responding entities, without it being possible for these entities (requesting, responding), to reconstruct all or part of the database of another entity of the group. It is therefore necessary to resolve a technical problem of anonymous sharing of data between several entities belonging to a group of entities. Additionally, it is necessary to prevent the reconstruction, by an entity of the group, of a database from the anonymous data transmitted by the other entities.

[0010] The invention then relates to a method for processing a signature of a digital element, a method implemented by an electronic processing device which is connected to a communications network to which a group of electronic devices is also connected, said method comprising:

[0011] - a step of receiving a request, from an electronic device applicant, said request relating to said digital element;

[0012] - a broadcasting step, to a plurality of electronic devices respondents connected to the communications network, of a signature of said digital element;

[0013] - a step of receiving, from the responding electronic devices, responses resulting from a comparison between the signature of said digital element and at least one signature of digital elements in the possession of said at least one responding electronic device;

[0014] - a step of aggregating all the responses within a structure of aggregated response data;

[0015] - a step of transmitting the aggregated response data structure to said requesting electronic device.

[0016] Depending on particular implementations, the method comprises one or more of the following characteristics:

[0017] - said signature of said digital element is in the form of a string of characters;

[0018] - it further comprises a step of preparing said signature of said element digital including:

[0019] - a step of extracting characteristics from said digital element, delivering a characteristic vector;

[0020] - a step of multiplying said characteristic vector by a hash matrix predetermined, delivering a hashed characteristic vector;

[0021] - a step of binary hashing of said hashed characteristic vector delivering a binary characteristic vector, this binary characteristic vector constituting said signature of said digital element.

[0022] - the step of extracting characteristics from said digital element comprises:

[0023] - a plurality of steps of modifying said digital element, each step delivering a modified digital element;

[0024] - a step of extracting characteristics from each of the elements modified digital, delivering a set of modified characteristic vectors;

[0025] - a step of calculating a global characteristic vector by aggregating each of the modified feature vectors.

[0026] - the comparison between the signature of said digital element and said at least a signature of digital elements of said at least one responding electronic device comprises a step of calculating a distance between the signature of said digital element and said at least one digital element signature in possession of said at least one responding electronic device;

[0027] - the calculated distance is a Hamming distance;

[0028] - the comparison between the signature of said digital element and said at least one signing digital elements of said at least one responding electronic device is implemented using a private set intersection type protocol;

[0029] - said digital element belongs to the group comprising: a digital image, a video, a sound clip and a text;

[0030] The invention further relates to an electronic device for processing a signature of a digital element, the electronic processing device comprising:

[0031] - means for receiving a request, from an electronic device applicant, said request relating to said digital element;

[0032] - means of broadcasting, to a plurality of electronic devices respondents connected to the communications network, of a signature of said digital element;

[0033] - means of reception, coming from at least one electronic device respondent, of at least one response resulting from a comparison between the signature of said digital element and at least one signature of digital elements in the possession of said at least one responding electronic device;

[0034] - means for aggregating all the responses within a structure of aggregated response data;

[0035] - means for transmitting the aggregated response data structure to said requesting electronic device.

[0036] Finally, it relates to a computer program comprising software instructions which, when executed by a programmable electronic device, implement a processing method as defined above.

[0037] Other characteristics and advantages of the invention will emerge from the description given below, for information purposes only and in no way limiting, with reference to the appended figures, among which: - [Fig.l] illustrates a system comprising electronic devices and a processing server for implementing the method of processing the signature of digital elements. - [Fig.2] illustrates the software or hardware components of an electronic device; - [Fig.3] illustrates the physical architecture of an electronic device and the processing server; - [Fig.4] is a diagram of the complete installation illustrating the flows during the process of processing signatures of digital elements within the processing server; - [Fig.5] illustrates the different stages of implementation of the interrogation of electronic devices in the system of [Fig.l]. Detailed description

[0038] In relation to [Fig.l], 2 and 3, the architecture of a system capable of implementing the method which is the subject of the present disclosure is presented, as well as the architecture of the electronic devices making up this system. Such a system comprises a processing server SrvT connected to a plurality of electronic devices DErl, DEr2, DEr3, DEr4, etc. via a communication network Ntwk.

[0039] The processing server SrvT comprises: means for receiving a request, from a requesting electronic device (within the group comprising the plurality of electronic devices), the request comprising a signature of a digital element; means for broadcasting, to the responding electronic devices, belonging to the group, connected to the communication network, the signature of the digital element; means for receiving, from the responding electronic devices, responses resulting from a comparison between the signature of the digital element and a signature of digital elements of the responding electronic device; means for aggregating all of the responses within an aggregated response data structure; means for transmitting the aggregated response data structure to said requesting electronic device.

[0040] These means are essentially implemented in the form of a component (hardware or software depending on the implementation circumstances), called the DtShrPrx intermediation component which acts as an intermediary between each device and the rest of the devices in the group. It makes it possible to receive requests from the different devices, to retransmit them to the other devices in the group (thus ensuring the anonymity of the requesters), to aggregate the responses provided by the different devices in the group (without identifying these different responding devices) and to return the aggregated response to the requester (thus ensuring the anonymity of the respondents). This component makes it possible to guarantee the anonymity of the devices in the group in the context of sharing sensitive data within a group.

[0041] In addition, the electronic devices of the Derl, Der2, etc. group comprise DtHsh signature generation means for generating, from a digital element, a signature in the form of a character string; the generated signature is a representation of characteristics (the signified) of the digital element provided as input (image, video, sound, text) which has been constructed in such a way that two similar data have close final signatures and thus robustness against variations in form. They also include means for transmitting requests DtRqst, to the processing server SrvT, these requests comprising one or more signatures from the generation means; these means can be implemented in the form of a REST type service. They also include means for constructing DtbsHsh a database of own signatures, which anonymized data comes from data in the possession of the electronic device itself (this is its own data, for example identity data of its customers, or other data relating to critical information of the entity). They also include means for comparison DtChck, between a signature received, from the processing server and one or more signatures present within the anonymized database.

[0042] These means are essentially implemented in the same way by the electronic devices of the group to achieve the exchange of data / responses. This is particularly the case of the means for generating DtHsh signatures and the means for comparing DtChck signatures received so that the signatures can actually be correctly compared, according to a predetermined comparison protocol.

[0043] Optionally, the processing server SrvT may also comprise means for preparing the signature of a digital element provided by a device of the group when this device does not have means for generating this signature for example. The processing server SrvT may also comprise means for comparing the signature of a digital element and one or more signatures of digital elements of the responding electronic devices, for example by using a private set intersection type protocol between the processing server and each of the electronic devices of the group.

[0044] Optionally, each electronic device of the group has its own architecture within which it has anonymized the data that it wishes to make available according to a process of its own. In this situation, each member entity of the group has freedom of action in terms of anonymizing the data and storing it. Consequently, the processing server SrvT has the information (in the form of an anonymization configuration) necessary to provide, for each electronic device of the group, the signature (which is an anonymized form of the question asked) that is appropriate for its interrogation. In other words, the processing server receives, from the requesting electronic device, a request comprising data representative of a question (i.e. a digital element). For each responding electronic device that it queries, the processing server applies a process anonymization of this digital element, which is a function of the anonymization specificities of the responding electronic device, and transmits a signature according to the specificities of each responding electronic device. This example of implementation involves more complex processing at the processing server level but it has the advantage of allowing the inclusion, within the group, of electronic devices which do not necessarily all share the same anonymization requirements.

[0045] These means are essentially implemented in the form of components, hardware or software, depending on the operational implementation conditions within the electronic devices DErl, DEr2, DEr3, DEr4, etc. or possibly within the processing server SrvT. The components are as follows (the references have been retained): - DtHsh signature generation component, allowing any device, for each data that it wishes to share with the group (to check if other devices have already observed it in the past), to generate a signature in the form of a character string (for example in the form of a Hash) whose length is variable depending on the operational implementation conditions.

[0046] The generated signature is characteristic of the data (of the signified) and robust to variations in the form (the signifier) ​​so as to ultimately allow two similar data to have close signatures.

[0047] Two data are considered similar if they are identical in substance but not necessarily in form, e.g. two audio signals corresponding to the pronunciation of the same sentence by two different people, two images representing the same person but who may be dressed, styled differently, etc.

[0048] Thus, the signature makes it possible to prevent the digital element from being exposed in clear text. The signature includes characteristics of the digital element but it does not make it possible to reconstruct this digital element, thus implying an anonymization of the digital element.

[0049] The signature generation method is naturally dependent on the nature of the input data. An example of generation adapted to the processing of image data, and presented below, is based on the use of a deep neural network to extract a vector of characteristics of an image (vector of floating point numbers). This vector is then converted into a binary vector via a “locality-sensitive hashing (LSH)” mechanism, which is directly convertible into a character string representing the hash / signature of the image. This mechanism is directly transposable for video, text or audio data by adapting the architecture of the neural network as well as the data used to learn the weights of this architecture.

[0050] To address the challenge of signature tolerance to variations in form, the signature generation method incorporates a step called “Data Augmentation” which consists of generating multiple variations in the form of the data to be anonymized. To each of the variations thus generated, the mechanism for constructing a signature / hash is applied. The construction of the final signature of the data to be anonymized is then constructed by aggregating the signatures of the different variations of the original data. The average was used in our implementations as an aggregation operator.

[0051] This component plays an important role in ensuring the anonymity of the content of the requests exchanged within the group. The addition of the “Data Augmentation” step in the signature generation process is an essential new feature introduced by our invention. It allows, in fact, by playing on the transformations applied to the original data, to modulate the robustness to the variations in form that one wishes to implement according to the signature comparison mechanism that is put in place (via the DtChck component, this directly influencing the anonymization requirements that one can impose on the solution). - DtRqst query component: component allowing an electronic device to transmit, to the group, via the SrvT processing server, a request to verify the existence of data. This is, for example, a component in the form of a Web service (REST) ​​which allows the data that is the subject of the request to be transmitted to the group after having anonymized it via the DtHsh component. - Anonymized database management component DtbsHsh that allows any device to build an anonymized database from the sensitive data it wishes to share with the group. It uses the DtHsh component to anonymize each of the data in the database and ensures the persistence of this anonymized data. An example of a sensitive database in a banking context could be, for example, image data representing identity documents that have already been identified in the past, by the organization managing the electronic device, as having been involved in one or more frauds. - DtChck signature comparison component allowing each device to perform the comparison between the object of a verification request issued by one of the devices in the group with the internal anonymized database of this device, previously constructed via the component DtbsHsh. This comparison allows you to know whether the data being requested exists or not in the device's sensitive database.

[0052] In relation to [Fig. 3], the general architecture of an electronic device for processing signature data DEr and / or a processing server SrvT implemented within the system previously presented is described. For example, the electronic device for processing signature data and / or the processing server comprises a memory 31 comprising for example a buffer memory, a general processing processor 32, equipped for example with a microprocessor, and controlled by a computer program 33, and / or a secure memory 34, a secure processing processor 35, controlled by a computer program 36, these processors implement in particular the methods of processing, transmission, aggregation of responses, generation and storage in a database of the signatures of digital elements, possibly in the form of cryptographic processing, using the components previously described.

[0053] At initialization, the code instructions of the computer program 36 are for example loaded into a memory before being executed by the secure processing processor 35. The processing processor 35 receives as input at least one digital element and / or a signature from a digital element. The secure processing processor 35 implements the steps of the method for processing digital element signature data, to obtain a data structure in which a signature is present, according to the instructions of the computer program 36 to obtain a set of signature comparison results that can be aggregated within a response data structure.For this purpose, the electronic signature data processing device comprises, in addition to the memory 34, communication means, such as network communication modules 37 and data transmission circuits between the various components of the electronic data processing device. These means may be general means or dedicated means. For example, the means for extracting characteristics, via a neural network, may be in the form of a dedicated calculation unit designed for the implementation of artificial intelligence processing. Implementation process.

[0054] As explained previously, an object of the disclosure is to allow an electronic device belonging to a group (for example a group of banks, insurance companies, states or even smartphones, computers, etc.) to have a response (positive, negative, probabilistic, etc.) to the request representing the presence of sensitive data in a database of another electronic device of the group, while not allowing the requesting device, not not only to know which devices responded to the request, but also which devices responded positively to it. Conversely, the anonymity of the requester is guaranteed.

[0055] In the case of a bank, for example, the request to know if an identity data item is present in a database of a (competing) bank must not allow the electronic device of the requesting bank to determine which electronic devices of the other banks have provided the information, nor the nature of the information provided.

[0056] To solve this technical problem, the disclosure sets out the following method. This method is described in relation to Figures 4 and 5. [Fig.4] sets out the method as implemented within a processing server SrvT: - a step E10 of receiving a request RQ, from a requesting electronic device DErl connected to the communication network Ntwk, said request RQ relating to the digital element DRSig (either the request includes the digital element, or the request includes the signature of the digital element; if the request includes the digital element, the server performs a transformation of the digital element into a signature, as explained above); - a broadcasting step E20, to a plurality of responding electronic devices DEr2, DEr3, DEr4, connected to the communication network, of a signature of said digital element DRSig (when using the PSI protocol, a multitude of requests with pieces of the signature of said digital element DRSig is broadcast); - a reception step E30, from the responding electronic devices DEr2, DEr3, DEr4, of the responses RT resulting from a comparison between the signature of said digital element DRSig and at least one signature of digital elements DRSigs in the possession of the responding electronic devices; - an aggregation step E40 of all the RT responses within an aggregated response data structure StRTa; - a transmission step E50 of the aggregated response data structure to said requesting electronic device.

[0057] By implementing this method, it is thus possible to anonymize both the transmission of interrogation requests and the transmission of responses. In other words, by means of this method, the requesting device is not able to know which responding devices provide it with the expected responses, while the responding devices are not able to know which requesting device queried them. Only the processing server SrvT, which performs the intermediation, is able to know this information. The process is thus, at least in part, implemented within a processing server independent of the group's devices. Furthermore, as indicated previously, the signatures that are transmitted to the responding electronic devices are also anonymized. More specifically, the responding electronic device does not receive clear data, but a signature (corresponding to the anonymized digital element). Several examples of anonymization of digital elements are presented below. Given the fact that this received signature is anonymous, the responding electronic device is not able to discover (easily) to which digital element this data corresponds.For example, if we assume that the query concerns the knowledge of a face, the data transmitted to the responding electronic device is not a digital file of the face itself, but a representation of this face. This representation is a signature of the face, which serves as a formulated question: is this face known to one or more responding electronic devices? For example, if we assume that the query concerns the knowledge of a voice, the data transmitted to the responding electronic device is not a voice file, but a representation of the speaker's voice. This representation is a voice signature of the speaker which serves as a formulated question.

[0058] In an exemplary embodiment, each electronic device of the group DErl, DEr2, DEr3, DEr4 has a similar component architecture making it possible, on the one hand, to respond to requests formulated by the processing server SrvT and, on the other hand, to formulate questions to the processing server SrvT.

[0059] An example of implementation within the system is illustrated in [Fig.5] which describes the steps of the querying method within a group comprising a plurality of electronic devices in relation to the system of [Fig.l]. In this implementation, an application, marked NnShrG in [Fig.5], is deployed on each device of the group. The DtShrPrx component is deployed on a remote infrastructure (the processing server SrvT). The NnShrG applications are identical for the different electronic devices of the group. They offer an interface which makes it possible to control the aforementioned components (with the exception of the DtShrPrx which is independent and ensures the interconnection between the electronic devices).

[0060] It is assumed, of course, that upstream, a signature database has been created for each electronic device, using (sensitive) digital elements that each of these electronic devices wishes to share: the digital elements are selected, then for each of them, the DtbsHsh component makes an anonymization request to the DtHsh component. The DtHsh component generates a signature for each transmitted digital element and returns it to the component DtbsHsh. The DtbsHsh component stores signatures in the component's own signature database.

[0061] In this exemplary embodiment, the query mechanism within the group is broken down as follows: 1. an electronic device DErl receives a selection, from the NnShrG application, of a digital element to be verified and requests the DtRqst component to transmit a verification request to the group; 2. the DtRqst component requests from the DtHsh component the generation of a signature allowing the anonymization of the digital element to be verified; 3. the DtHsh component generates a signature and returns it to the DtRqst component; 4. the DtRqst component transmits the verification request to the SrvT processing server (implementing the DtShrPrx component) by attaching to its message only the signature of the digital element to be verified, i.e. without attaching the digital element itself; 5. the DtShrPrx component of the processing server broadcasts the request to the DtChck components of the different electronic devices of the Der2, Der3, Der4 group; 6. for each electronic device, the DtChck component retrieves the internal signature database generated by the DtbsHsh component and compares the signature to be verified with the different signatures in its database. Signature verification can be carried out indirectly. At the end of this step, the result of the verification is provided to the DtShrPrx component (true, false, real probabilistic value); 7. DtShrPrx component aggregates responses from different devices electronic devices of the group and transmits the aggregated result to the DtRqst component of the electronic device that issued the request; 8. the result of the query is uploaded to the dedicated NnShrG application. Determining a degree of anonymization

[0062] An important feature of the disclosure is to agree, for the group of devices, on a level (degree) of anonymization of the digital elements to be compared. Three solutions are possible, based on the components presented previously, so as to be able to adjust this level of anonymization according to operational constraints. These three solutions are presented in an increasing order of guarantee of the anonymization of the shared digital elements. For Each of these solutions only details the specificities in relation to the components previously described.

[0063] Distance between robust signatures transmitted in clear on the network

[0064] Within the DtChck component, a distance calculation between the signature (a hash) of the digital query element and the signature of each of the digital elements in the signature database is performed. A Hamming distance between the bit vectors of two signatures is used, for example. In this situation, the DtShrPrx transmits the signature of the digital query element in clear text to the responding electronic devices. A threshold on the distances is applied to determine whether there is a match with one of the signatures in the internal database. If this is the case, a positive response, for example binary (“yes, this sensitive data has already been seen”), is returned. A probabilistic response can also be transmitted. The choice of the threshold is made so as to limit false positives.

[0065] This solution is the one that provides maximum robustness in the face of variations in the form of the digital elements to be verified within the group. Conversely, it is the one with the lowest level of guarantee of anonymization of the digital elements. Indeed, the clear transmission of the signature induces a risk of reverse engineering of the solution which could make it possible to go back to the source data by a device which could manage to listen to the network communications between the DtShrPrx and the devices of the group. However, it should be noted that the introduction of the “Data Augmentation” step with construction of a signature by aggregation of individual signatures reduces this risk (see below).

[0066] This solution also presents another risk on the anonymization guarantee insofar as the DtChck component, carrying out alone the comparisons between clear signatures, has the possibility of determining which data has been shared as soon as there is an identified (positive) matching with one of the data of its own internal base: in other words, the component knows for which digital element it is being queried when there is a matching.

[0067] Distance between robust, modified signatures transmitted in clear text on the network

[0068] Within the DtHsh component, a mechanism for modifying the generated signatures is added in post-processing (to further anonymize these signatures). This mechanism consists of introducing random modifications into the bit vector corresponding to a signature. The signature transmitted to the other devices in the group is therefore not exactly the generated signature, but a randomly modified signature.

[0069] Within the DtChck component, in a similar manner to what was implemented for the first solution, a distance calculation between the signature of the digital query element and the signature of each of the digital elements of the internal database is carried out. However, since the signatures to be compared are modified, the distance calculation is adjusted accordingly. The calculated distances are thus higher due to the modifications introduced in the original signature. To do this, for each signature in the internal database with which to compare the query signature, a distance is calculated (e.g. Hamming) between the final / aggregated query signature and the signature of each of the transformations applied to the internal digital elements of the database. This gives a distribution of distances. An anomaly detection algorithm (e.g. "isolation forest" type) is then applied to see if the distribution of distances associated with one of the signatures in the internal database is statistically different from the others, with a lower average distance than the others. If this is the case, we consider that there is indeed an observed match (with a given probability).

[0070] This solution is less robust than the first to variations in form, but the introduction of modifications in the signatures makes it possible to reduce the exposure to the risk of reverse-engineering of these signatures, which nevertheless remain transmitted in clear text on the network. Experimental results indicate that it is possible to introduce up to 12.5% ​​of random modifications to the signature without significantly affecting the matching performance. On the other hand, the risk facing malicious group devices is still present since each device can know what data has been transmitted as soon as a matching is observed.

[0071] Exact matching of robust signatures via a cryptographic exchange protocol

[0072] Within the DtChck component, the verification of the matching between the signature of the request and the signatures of the digital elements of the internal database to which the DtChck component has access is not carried out directly by DtChck. A cryptographic data exchange, using a PSI type protocol (from the English for "Private Set Intersection") is set up between the DtShrPrx component and the DtChck component of each device in the group to carry out this verification. With this protocol, the signature of the request is not transmitted in clear text by the DtShrPrx component. This protocol, which makes it possible not to transmit the signature in clear text, thus offers an additional level of anonymization guarantee compared to the two solutions described previously. On the one hand, it is not possible, for a requesting electronic device, to perform reverse engineering of data, since the signature will never be transmitted in clear text.On the other hand, since the verification is not carried out at the DtChck component level, it has no way of knowing which element of the database led to a match with the query.

[0073] In return, the use of this protocol implies that two signatures are exactly the same for there to be a pairing. It is not possible to carry out a distance calculation. Ultimately this results in less tolerance for shape variations between the digital elements that we are trying to match. Example of anonymization of image data

[0074] This section exemplifies obtaining an anonymous signature of image data. The specific case to which this example relates is the following: one of the members of the group receives, from a prospect, identity data comprising an image. This identity data must be verified to estimate the probability of a possible fraud attempt. The method that is the subject of the disclosure is implemented to obtain, from the other members of the group, data representing knowledge of past fraud in connection with this identity, on the basis of the image. This image is therefore converted into a signature according to the example described here.

[0075] Essentially, two methods can be implemented.

[0076] The first method consists of a signature extraction based on a neural network. In this situation, the image available to the requesting electronic device is normalized (preprocessed) and a feature extraction based on a neural network (for example a CNN convolutional neural network) is implemented. This extraction delivers a characteristic vector of the preprocessed image (which comprises a plurality of real values). The size of this characteristic vector is adapted to the needs (for example 128 values). This characteristic vector is then multiplied by a hash matrix, the size of which is also adapted to the needs. This matrix also comprises a plurality of real values, adapted to the extracted characteristics. A hashed characteristic vector is thus obtained. This vector again comprises a plurality of real values.The hashed feature vector then undergoes binary hashing (only values ​​greater than 0 are retained) to obtain a binary feature vector. This binary feature vector constitutes the signature which is used for comparison with the signatures available to other electronic devices in the group.

[0077] The second method consists of carrying out a plurality of data augmentation phases, based on the image initially provided to support the identity of the prospect. The method comprises a first phase during which a characteristic vector of the initial image is provided to a characteristic extraction algorithm (in the implementation example, the “vggface2” algorithm is used because we are only interested in the faces present on the identity documents). At the end of this first phase, a first characteristic vector of given size (for example 512 values) is obtained. Then the method comprises a plurality of augmentation phases. Each augmentation phase comprises: - A step of applying, to the initial image, a random transformation available from among a plurality of transformations (for example a rotation, a horizontal or vertical tilt, color modification, transition to gray level, Gaussian blur) delivering a modified image; - A step of applying, on the modified image, the feature extraction algorithm, delivering a characteristic vector of the modified image.

[0078] The set of characteristic vectors obtained (the number of which varies according to the number of random transformations undergone) is then processed to obtain an averaged characteristic vector. Each value is averaged with the corresponding value of each characteristic vector of the different modified images. This averaged characteristic vector is then multiplied by a hash matrix, the size of which is also adapted to the needs. This matrix comprises a plurality of real values, adapted to the extracted characteristics. A hashed characteristic vector is thus obtained. This vector again comprises a plurality of real values. The hashed characteristic vector then undergoes binary hashing (only values ​​greater than 0 are retained) to obtain a binary characteristic vector.This binary characteristic vector constitutes the signature that is used for comparison with the signatures available to other electronic devices in the group. Compared to the first method of obtaining a signature, the second allows for "wider" signatures, because they better represent the real characteristics of the face in the image, characteristics that are more robust to variations in shape.

Claims

Claims

1. Method for processing a signature of a digital element, method implemented by an electronic processing device (SrvT) which is connected to a communication network to which a group of electronic devices (DErl, DEr2, DEr3, DEr4) is also connected, said method comprising: - a step of receiving (E10) a request (RQ), from a requesting electronic device (DErl), said request (RQ) relating to said digital element (DRSig); - a step of broadcasting (E20), to a plurality of responding electronic devices (DEr2, DEr3, DEr4) connected to the communication network, a signature of said digital element (DRSig);- a step of receiving (E30), from the responding electronic devices, responses (RT) resulting from a comparison between the signature of said digital element (DRSig) and at least one signature of digital elements (DRSig) in the possession of said at least one responding electronic device; - a step of aggregating (E40) all the responses (RT) within an aggregated response data structure (StRTa); - a step of transmitting (E50) the aggregated response data structure to said requesting electronic device (DErl).;

2. Method for processing a signature of a digital element according to claim 1, characterized in that said signature of said digital element (DRSig) is in the form of a character string.

3. Method for processing a signature of a digital element according to claim 1, characterized in that it further comprises a step of preparing said signature of said digital element (DRSig) comprising: - a step of extracting characteristics from said digital element, delivering a characteristic vector; - a step of multiplying said characteristic vector by a predetermined hash matrix, delivering a hashed characteristic vector; - a step of binary hashing of said hashed characteristic vector delivering a binary characteristic vector, this binary characteristic vector constituting said signature of said digital element (DRSig).

4. Method for processing a signature of a digital element according to claim 3, characterized in that the step of extracting characteristics from said digital element comprises: - a plurality of steps of modifying said digital element, each step delivering a modified digital element; - a step of extracting characteristics from each of the modified digital elements, delivering a set of modified characteristic vectors; - a step of calculating a global characteristic vector by aggregating each of the modified characteristic vectors.

5. Method for processing a signature of a digital element according to claim 1, characterized in that the comparison between the signature of said digital element (DRSig) and said at least one signature of digital elements (DRSigs) of said at least one responding electronic device comprises a step of calculating a distance between the signature of said digital element (DRSig) and said at least one signature of digital elements (DRSigs) in possession of said at least one responding electronic device.

6. Method for processing a signature of a digital element according to claim 4, characterized in that the calculated distance is a Hamming distance.

7. Method for processing a signature of a digital element according to claim 1, characterized in that the comparison between the signature of said digital element (DRSig) and said at least one signature of digital elements (DRSigs) of said at least one responding electronic device is implemented using a private set intersection (PSI) type protocol.

8. Method for processing a signature of a digital element according to claim 1, characterized in that said digital element belongs to the group comprising: a digital image, a video, a sound extract and a text.

9. Electronic processing device (SrvT) for a signature of a digital element, the electronic processing device comprising: - means for receiving a request, from a requesting electronic device, said request relating to said digital element; - means for broadcasting, to a plurality of responding electronic devices connected to the communication network, a signature of said digital element; - means for receiving, from at least one responding electronic device, at least one response resulting from a comparison between the signature of said digital element and at least one signature of digital elements in the possession of said at least one responding electronic device; - means for aggregating all of the responses within an aggregated response data structure;- means of transmitting the aggregated response data structure to said requesting electronic device.;

10. A computer program comprising software instructions which, when executed by a programmable electronic device, implement a processing method according to claims 1 to 8.

Citation Information

Patent Citations

  • Identity information checking method and system

    CN108229260A