Biometric binding method
By establishing a nexus between a user's biometric features and their identity through a binding video, the method ensures secure access by verifying the correlation of biometric features with reference information, thus preventing fraudulent use of another person's fingerprints.
Patent Information
- Authority / Receiving Office
- GB · GB
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-09-13
- Publication Date
- 2026-03-18
AI Technical Summary
Biometric security systems are vulnerable to unauthorized access when fraudulent use of another person's fingerprints is attempted, compromising the integrity of conditional access systems.
A method is introduced to create a nexus between a user's biometric features and their identity by capturing a binding video that includes both face and biometric features, verifying their correlation with reference information, and generating a digital signature that associates these features with identification information.
This approach enhances security by ensuring that only the rightful user's biometric features are used for access, reducing the risk of fraudulent access attempts and improving the reliability of conditional access systems.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Field of Invention The present invention relates to biometric security, and particularly to binding of a user’s 5 biometric features with their legal identity. The present invention concerns a technique of generating a digital signature, comprising one or more images of biometric features in combination with identification information for the user, which can be used as a credential for a conditional access system. The binding technique includes verification that biometric features presented by a subject are in fact those of the same person who has io previously enrolled their biometric features for use of the conditional access system. Technical Background Conditional access systems are widely used to regulate access to particular services or functions, such that access is provided only to authorized users based on credentials 15 which they supply. The security of such conditional access systems is strongly dependent on the nature of the credentials, in terms of how easily they can be obtained or reproduced by others. As such, credentials having uniqueness and complexity are preferable, as they are difficult to predict and copy. 20 An example of an effective credential is a user’s fingerprint, with each fingerprint being unique to a user, and a set of prints for each finger and thumb thus enabling a rich set of identifying information to be derived. Further, fingerprints represent relatively complex patterns of contours and curvatures, simulation of which is inherently difficult without reproduction of the original fingerprints. For this reason, biometric authorisation systems, 25 in which fingerprints are used to control access, are widely used for a number of applications, such as unlocking a mobile phone, or unlocking a door or gateway, or providing an electronic travel authority or visa. A weakness in such a biometric security system arises if an unauthorised user takes 30 unfair advantage of the authorisation of a different user’s fingerprints. For example, an unauthorised user may present the fingerprints of a companion, whether willingly or otherwise, to a conditional access system in order to deceive the system into granting access to a particular service or function. A stored image of another’s user’s fingerprints may be fraudulently obtained and input to the conditional access system. Fingerprints 35 may be captured from particular surfaces, and transferred to an impressionable medium for synthetic reproduction. In extreme cases, an authorised user may be forced to provide their fingerprints under duress. In the example of using biometric information to obtain an electronic travel authority, a 5 process of biometric self-enrolment can be performed, in which a user registers their own fingerprints. Biometric self-enrolment can be achieved using, for example, imaging software on a mobile phone, rather than visiting a physical facility, such as a kiosk, for a set of fingerprints to be taken. A problem can therefore arise if a user does not ‘self-enrol’, but deliberately enrols the fingerprints of another person as their own, in order to io take advantage of the other person’s likelihood of being granted an electronic travel authority. A further problem can arise if a user enrols the fingerprints of another person, as well as presenting the identity of the other person - here, a match between the fingerprints and the identity of the other person may lead to the grant of the electronic travel authority, despite the fact that neither is associated with the requesting user. 15 Embodiments of the present invention aim to address this problem using a technique described herein as ‘biometric binding’, in which a nexus is created between biometric features of a user and their identity. The aim is to provide a means of verifying whether the biometric features of a user are in fact the biometric features of that particular user, 20 and not the biometric features of another authorised user attempting to use them as a credential to access a particular service or function. Having verified a user’s biometric features in this manner, a digital signature can be output which contains biometric features in association with identification information for the user, to be used as trusted authentication information by a conditional access system. 25 Summary of Invention According to a first aspect of the present invention, there is provided a method for generating a digital signature, comprising: capturing a binding video of a subject; extracting one or more images from the binding video, wherein each extracted image 30 contains one or more biometric features of the subject; wherein capturing the binding video comprises capturing the face of the subject in combination with one or more biometric features of the subject in the same scene of at least a portion of the binding video; the method further comprising: receiving identification information, and obtaining reference information for biometric features of a user identified by the identification 35 information; for each extracted image, comparing the one or more biometric features with the reference information for the corresponding one or more biometric features; responsive to determining that the face of the subject correlates with a facial image contained in the identification information, and determining that biometric features of each of the extracted images correlate with respective reference information for the 5 corresponding biometric features; verifying the identity of the subject as that of the user identified by the identification information; and generating and outputting a digital signature for the subject having the verified identity, comprising the one or more images of the biometric features in combination with the identification information. io In this manner, a nexus is created between the biometric features of the subject, their face, and their identity. Using this, it can be verified that the subject’s biometric features are in fact the biometric features that belong to a person having the identity of the subject, and not biometric features of another person having a different identity. An electronic travel authority can therefore be granted to the subject, for example, using the knowledge 15 that the subject’s biometric features have been verified. In embodiments, the biometric features comprise at least one or more fingerprints of the subject. In this manner, a set of as many as ten unique fingerprints may by combined to increase the confidence of a verification process, and to improve the security of the 20 biometric security technique in which underpins the embodiments. In embodiments, capturing the binding video is performed with a single camera device. In this manner, security can be improved by removing the opportunity for a user to fraudulently combine two independent video streams, which would otherwise weaken 25 the nexus between the biometric features of the subject, their face, and their identity. In embodiments, the identification information further comprises one or more of a name, a date of birth, a passport number, a location, a user device identity, and an authentication code. This diversity of potential sources of identification renders the 30 claimed technique suitable for a variety of different applications, in which either a subject’s legal identity, or a virtual identity such as subject ID, are preferred means of identifying the subject. In embodiments, capturing the binding video is performed using a camera-equipped 35 wearable device, arranged to capture a reflection of the face and the biometric features of the subject. In this manner, the binding video can be captured without assistance, and the user has good control of the framing of the binding video by facing in the same direction as the camera-equipped device. 5 In embodiments, verifying the identity of the subject comprises determining a binding score representing the likelihood that the biometric features of the subject correspond to those of the user identified by the identification information. In this manner, it is possible to determine whether there is a strong or a weak correlation between the captured biometric images and those derived from the reference information, and an appropriate io correlation requirement can be selected for particular circumstance. In embodiments, the method further comprises providing a capture interface outputting information to guide the subject to pose such that the biometric features are captured in the binding video according to a predetermined video capture sequence. In this manner, 15 the process of capturing biometric features is made efficient as the subject can pose in a manner to optimise the capturing of specific biometric features at specific stages of the video capture, and facilitating comparison with a reference. In embodiments, the method further comprises using a machine-learning algorithm to 20 train the capture interface, wherein the machine-learning algorithm is trained on information for guiding a subject, and the binding score obtained from verifying the identity of the subject using the captured biometric features, to optimize the information for guiding the subject. In this manner, the accessibility of the process to users is maximised, as interpretations of instructions from the capture interface, and behaviours 25 in response, may vary widely from user to user. In embodiments, if the binding score is below a verification threshold, the method comprises outputting further information via the capture interface to guide the subject to adjust their pose, and performing further capture of a binding video of the subject 30 containing one or more biometric features which do not correlate with respective reference information. This further facilitates a process of determining whether a captured biometric feature is in fact the biometric feature that was expected, so that errors in the capture process can be found. In embodiments, the method further comprises determining one or more additional parameters relating to: the number of people in the captured binding video; whether an individual person remains in a scene of the binding video for the duration of the binding video; and the variation in the dimension of a physical characteristic of a person identified 5 in the binding video; the method further comprising modifying the binding score in dependence on the determined one or more additional parameters. In this manner, it is possible to confirm continuity and authenticity of the binding video by identifying constants within the binding video that would not be present if fraudulent activity were present in the capture process. 10 In embodiments, the reference information comprises one or more models of biometric features of the user identified by the identification information, and comparing a biometric feature with the reference information comprises determining whether the biometric feature conforms to a model of the biometric feature defined by the reference information. 15 In this way, it is not necessary to perform a comparison of two images, which may be high-resolution detailed files, and which may further include image artefacts such as blurring or aberration that may compromise the matching process. The effects of such image artefacts could be compensated for by the models. 20 In embodiments, the method further comprises biometrically enrolling the subject, comprising: obtaining one or more enrolment images of the subject, wherein each enrolment image contains one or more biometric features of the subject; generating a model of each of the one or more biometric features of the subject from each enrolment image as the reference information; receiving enrolment information for the subject; and 25 storing a mapping between the reference information and the enrolment information; wherein the step of obtaining reference information comprises obtaining the reference information mapped to enrolment information matching the received identification information. 30 In embodiments, the method further comprises capturing an enrolment video, and extracting the one or more enrolment images from the enrolment video. In this manner, the enrolment and biometric phases can be performed using the same or similar video capture routines as each other. In embodiments, the method further comprises destroying enrolment images for which a model of each of the one or more biometric features in the enrolment images is generated. In this manner, privacy is ensured as it is not necessary to store user data in the form of biometric images such as fingerprints. Instead, a model of such fingerprints 5 could be stored instead, which is sufficient to enable recognition of another image matching that fingerprint, but which does not enable the fingerprint to be reproduced. In embodiments, the method further comprises providing the digital signature to a conditional access system requiring biometric authentication of a user using the digital io signature as the condition of access. The verification technique can thus be integrated with a process to be protected using biometric security, such as the process of applying for an electronic travel authority. According to a second aspect of the present invention, there is provided a computer 15 program which, when executed by one or more processors, is arranged to perform the method of the first aspect. According to a third aspect of the present invention, there is provided a computer system comprising one or more processors arranged to perform the method of the first aspect, 20 the computer system further comprising: a user interface for instructing a subject to provide the identification information and to pose for the binding video; a camera for capturing the binding video; a communication interface for communicating with a database storing the reference information; and an output interface for outputting the digital signature of the subject. 25 In embodiments, the output interface is configured to communicate electronically with a digital wallet of a mobile device using RFID or NFC. In this manner, the digital signature can be received securely over a short-range communication system, for future use. 30 Brief Description of Drawings Embodiments of the present invention will be described by way of example only, with reference to the accompanying drawings, of which: Figure 1 shows a schematic representation of a method of generating a digital signature according to a first embodiment of the present invention; Figure 2 illustrates a sequence of capturing the binding video, as performed via a capture interface according to embodiments of the present invention; and Figure 3 illustrates the architecture of a digital signature generation process according to a second embodiment of the present invention. 5 Detailed Description Figure 1 shows a schematic representation of a method of generating a digital signature according to a first embodiment of the present invention. The method is executed by a binding engine 10, which outputs the digital signature 16. The binding engine receives io information relating to biometric features 11 of a subject, captured via a capture interface 12. The binding engine also receives identification information 13 from the subject, and obtains reference information 14 which corresponds to the ID information 13 of the subject. The correspondence between the ID information 13 and the reference information 14 is illustrated in Figure 1 using a dotted line. 15 The binding engine 10 operates to verify whether the subject’s information relating to biometric features 11 relates to the identification information 13 of the subject. On successful verification, a digital signature 16 is output which confirms this verification in association with the subject’s identification and biometric information, which can be used 20 a credential to be used as a condition of access to a system, function or service. In embodiments, the system, function or service comprises an electronic travel authority. In this manner, it can be ensured that access to the system, function or service is restricted to users who have provided information relating to their own biometric features 25 11, rather than enlisting biometric features of another. It the verification returns a negative result because it cannot be verified that a user’s biometric features are their own, such a user will not be granted access to the system, function or service via a digital signature 16. 30 In embodiments, the biometric features 11 include at least the fingerprints of the subject. As described above, fingerprint information enables ten unique prints, corresponding to the eight fingers and two thumbs of the subject, to be used as the basis of accessing a system function or service protected via a biometric security scheme. The biometric features may additionally, or alternatively, comprise definitions of the contours of the 35 subject’s ears, the palms of their hands, and so on - any suitable biometric features which enable unique identification of a user may be used instead of, or in addition to the fingerprint information. The capture interface 12 captures one or more images of the biometric features 11, which 5 are fed into the binding engine 10. In embodiments, the capture interface 12 is physically integrated with the binding engine 10, as part of a camera-enabled device such as a mobile phone. In other embodiments, an image-capture element of the capture interface 12 may be a separate entity from the binding engine 10, such as a standalone camera, or a camera-equipped wearable device such as a wristwatch or glasses. io In embodiments, the one or more images of the biometric features 11 are extracted, by the binding engine 10, from a binding video captured via the capture interface 12. The binding video comprises a sequence of video segments of the subject in each of which one or more biometric features 11 of the subject are positioned within the frame of an 15 image-capture device. In the disclosure of the present embodiment, the biometric features 11 are referred to as fingerprints, by way of example. The binding video is divided into its constituent segments by the binding engine 10, and one or more images of a predetermined number of the subject’s fingerprints are extracted 20 from the segments, and stored by the binding engine 10 in association with a label for the fingerprint (e.g. ‘left thumb’, ‘right index finger’ and so on). Having obtained images of the subject’s fingerprints in this manner, the binding engine 10 operates to determine whether fingerprints are in fact those of the subject, and not 25 those of somebody else. This verification operation is achieved by establishing a nexus between the images of the fingerprints and the identity of the subject, which is referred to herein as a biometric binding process. The nexus is established by comparing the fingerprint images with those derived from reference information 14 which is associated with the subject. The reference information 14 may comprise a set of reference images 30 for the fingerprints, recorded in a previous capture process, but in other embodiments, the reference information comprises one or more reference models, to which verified fingerprints would conform, and to which unverified fingerprints would not conform. The models are such that the fingerprints themselves cannot be recreated from the models, and, as such, a subject’s data privacy concerns are addressed by avoiding the need to 35 store enrolled images of their fingerprints. The binding engine 10 may alternatively, or additionally, operate to determine whether the palms or other biometric features are those of the subject, and the biometric binding process may apply to such biometric features accordingly. 5 The reference information 14 is stored in a database which is accessible to the binding engine 10. The database may store reference information 14 for a plurality of different subjects subscribing to the verification process and having enrolled for access to whichever system requires the digital signature 16 as a condition of access. As such, the binding engine 10 is instructed to access reference information 14 for a specific subject io using identification information 13 provided by the subject as an input to the binding engine 10. The relationship between the reference information 14 and the identification of the subject 13 is assumed by the binding engine 10 to be valid, so that the verification process that takes place is a verification of whether the fingerprints which are presented to the binding engine 10 via the capture interface 12 are the fingerprints of the same 15 subject as the subject of the reference information 14, and not the fingerprints of another subject. The identification information 13 may be presented in a variety of different forms. In embodiments, the identification information 13 comprises one or more of a name, a date 20 of birth, a passport number, a location, a user device identity, and a unique authentication code issued to the subject when subscribing to the verification process. The identification information which is provided is used to derive the legal identity of the subject, as defined on a legal document such as a government-issued passport. In the case of providing a passport number, the subject’s identity can be accessed from a passport database 25 hosted by, for example, a government system. In the case of providing a virtual identity such as a user device identity, for example a subscriber identity module (SIM) card number of a mobile device, the binding engine 10 accesses a database of a consenting network provider storing a mapping between SIM 30 card numbers and their registered owners, identified by name, nationality and date of birth, for example. From this, information can be obtained for use in interrogate a passport database to obtain passport information for the user associated with the SIM card. It will be appreciated that a variety of techniques will enable a legal identity to be obtained. Passports are required to contain images of the faces of their subjects. As such, the legal identification of a subject enables a corresponding facial image of that subject to be obtained, and such a facial image is obtained by the binding engine 10. In Figure 1, the facial image is to be understood as part of what is illustrated as the ID information 13 5 input to the binding engine 10, although in practice, identification information such as a passport number, and a facial image, may be provided to the binding engine 10 in discrete steps. The facial image enables a further reference, or biometric anchor, against which the io identity of the subject presenting themselves to the binding engine 10 can be assessed. Specifically, the face of the presenting subject is imaged via the capture interface 12, and compared with the facial image of the identification information 13. In order to establish the nexus between a subject’s fingerprints and their identity, what is required is the establishment of a nexus between the subject’s fingerprints, their identify and their 15 facial image, which is achieved by ensuring that the subject’s fingerprints, and the face of the subject, are captured in combination in the binding video. Specifically, the binding video captures one or more scenes in which the one or more fingerprints of the subject and their face exist together. In this manner, it can be verified that the fingerprints belong to a subject having the face which matches a facial image associated with the legal 20 identity of the subject, and for which a set of reference information 14 is stored which correlates with the fingerprints. In embodiments, to enhance the reliability of the binding video, it is ensured that the binding video is a body image, or even a full body image, in which a physical connection 25 via arms, torso and neck, from the user’s fingerprints to their face, can be observed. In this manner, it is ensured that there are not two different subjects on the binding video, one presenting their face, and the other presenting their fingerprints, such that the verification of the subject’s fingerprints can be established. 30 Figure 2 illustrates an example of a sequence of capturing the binding video, as performed via the capture interface 12, according to embodiments. In a first stage, 21, an applicant 27 for an electronic travel authority is to be the subject of a binding video. The applicant 27 is accompanied by an assistant 28 in the illustrated sequence, who is tasked with using an application on a mobile phone 25 as the capture interface 12. The mobile phone 25 has a camera with a field of view 26 corresponding to the scenes to be captured in the binding video. In the first stage 21, the assistant 28 captures a video of a flat plain wall 29, without the 5 subject 27, so that a constant and unobtrusive reference background for the binding video can be identified for all subsequent scenes. The subject 22 then walks into view for the second stage 22. In the second stage 22, the assistant 28 holds the camera still, or uses a tripod, and io directs the subject 27 to stand in a position so that a full body height video can be captured within the field of view 26. The subject 27 is directed by the assistant 28 to raise their hands to approximately face height. In this manner, an image of the face and their fingerprints, in relatively close proximity to their face, can be determined. Further, images of the palms of the subject’s hands can also be extracted. 15 In the third stage 23, the assistant 28 directs the subject 27 to turn around 360° on the spot, while maintaining their hands in the raised position of the second stage 22. In this manner, a range of angles and lighting conditions can be applied to the scene containing the subject’s fingerprints, while it is also possible to capture features on the side of the 20 user’s face, such as their ears. In the fourth stage 24, the assistant 28 directs the subject 27 to hold both arms straight out in front, at approximately shoulder height and width, with palms facing forwards to the assistant 28, so that the face of the subject 27 remains visible to the camera. The 25 assistant 28 may capture a sequence of images at this point, containing close-ups of the palm and fingers on one hand of the subject 27, either by the assistant physically moving towards the subject 27, or using an optical or digital zoom on the camera. The phone 25 is tilted so that the thumb on the same hand is captured. The camera pans back to the face of the subject 27, and the capture process is complete. In alternative embodiments, 30 the second hand of the subject 27 is similarly imaged before the capture process is complete. The captured video is uploaded to the binding engine 10 for processing. Images of the fingerprints, in combination with the face of the subject 27, are extracted from the binding 35 video. This is done using fingerprint imaging software as known on the art. In alternative embodiments, the fingerprint imaging software is executed by an application on the mobile device 24, so that both capture and image extraction can be performed at the same device, and the extracted images are then uploaded to the binding engine 10. 5 Variations of the sequence illustrated in Figure 2 fall within the scope of the present invention. For example, stage 23 may be performed prior to stage 22, or may not be performed at all. Additional steps such as raising hands to the ceiling may assist in demonstrating liveness of the hands and the absence of foreign objects (for example, artificial reproductions of hands or fingerprints) being held by the subject. io In embodiments, to be described below, the sequence of capturing the binding video may be optimized using a machine-learning process. It is advantageous, in embodiments, for the capture sequence to be such that one or 15 more images can be extracted from the binding video in a predetermined order corresponding to a predetermined sequence of fingerprints. In this manner, the imaging software knows to look for a print for a particular finger at a particular time, which can simply the imaging process and also simply the identification of any image capture errors which are such that a print corresponding to a specific finger is not obtained, rather than 20 needing to test for prints of multiple fingers in each image extraction process. Although the sequence of Figure 2 is performed using an assistant 28 to guide the position of the subject 27, in alternative embodiments, where an assistant is not available 28, the subject 27 may take instructions from a user interface on a capture device such 25 as a mobile phone, in order to guide their position and posture for the binding video. The user interface may be part of what is illustrated in Figure 1 as the capture interface 12, and represent part of an application running on the capture device which can output spoken instructions, display text or images, or a combination of both. In embodiments, this capture application can assess whether the subject’s pose is correct, and whether 30 the subject 27 has responded to the guidance which was issued, and can output further guidance in response. The guidance can be controlled via an artificial intelligence system which is learns how a user responds to particular instructions, and trains its prompts accordingly. Another example of a self-capture mode is one in which the subject is using a wearable camera-equipped device such as a watch, and is capturing a reflection of their biometric features in a mirror. In such embodiments, a user interface may be provided on a device such as a mobile phone, providing spoken and / or visual instructions and guidance, and 5 the user positions their watch and biometric features accordingly. In stage 22 of Figure 2, it is shown that the user’s arms are in a W-position, with bent elbows. The purpose of this is to take advantage of identification principles similar to those of the Bertillon system of identification, in which dimensions of physical io characteristics can reliably provide useful information in identifying a subject. Physical characteristics include head length, head breadth, the length of the middle finger, and, in particular, the length from the elbow to the extremity of the middle finger, or the length from the elbow to the wrist. By imaging the arms in the position in shown in Figure 2, the length from the elbow to the wrist can be identified in order to confirm that this remains 15 constant through the binding video, suggesting that the subject is present throughout the binding video and has not been substituted for another user, or a binding video fraudulently captured. Other postures may enable the identification or extraction of other characteristic features, and measurement of their dimensions. 20 Advantageously, the capture of the binding video is performed using a single camera device, in which one or more lenses and image-capture sensors are integrated in a single physical device to be positioned by a user. In this manner, one device captures the entirety of the binding video, including any peripheral movements such as the subject moving into and out of shot, which improves the integrity of the binding video. Although 25 it is technically possible to capture the binding video using multiple camera devices, positioned differently such that difference angles are captured, for example, there is an intrinsic security problem in that the relationship between the two camera devices cannot necessarily be guaranteed, unless there is correspondence between the scenes captured by the two camera devices, or unless one camera device is in the field of view 30 of the other. Once biometric images have been extracted by the binding engine 10, analysis is performed to determine whether binding is possible, such that the fingerprints of the subject correspond to their identity, as described above. The process of comparing 35 images with the reference information 14 can be performed in a number of different ways in dependence on the nature of the binding information, and in each case, the output of the comparison can be expressed as a binding score, also referred to herein as a Bhandari score, representing a likelihood that the subject’s fingerprints can be verified. The binding score is based on the correlation between the fingerprints and the reference 5 information 14. If the correlation is below a threshold, a binding score of zero may be output, representing a negative verification result. Above the threshold, variance in correlation levels may arise due to image capture errors or deficiencies, in which portions of fingerprints may be out of focus or in poor lighting, but there is sufficient imagery available for verification to be performed. 10 The binding score is primarily affected by the correlation between fingerprints and reference information 14, but additional factors may affect the binding score. The score may be affected by the number of people in the captured binding video, and whether an individual person remains in a scene of the binding video for the duration of the binding 15 video. Any variation in the measurement of indicative physical characteristics, such as an elbow to wrist measurement, can also affect the binding score. These additional factors lead to a reduction in the binding score if there is reason to doubt that the fingerprints which are presented are those of the subject to be verified. 20 For example, a person may leave the scene of a binding video for a short period to reposition a camera, before re-entering the scene - while the reason for leaving the scene temporarily is genuine in this instance, rather than a fraudulent attempt to introduce the fingerprints of another person into the binding video, the binding engine 10 identifies such an ‘out of scene’ event as suspicious, and reduced the binding score by 25 an amount or percentage. A change in the length of the forearm which is measured in the binding video may indicate that the user present in the scene has changed. A much more significant reduction in the binding score may occur in such an event, as the likelihood of the user 30 having changed is significant. The basis of the determination of the binding score can be adjusted by a user via a setting in an application executed by the binding engine 10, for example by identifying a set of fixed factors which should be taken into account. The factors which should be taken into account may be selected automatically based on a capture mode, such as a single or multiple camera capture mode, or a self or assisted capture mode. In embodiments of the present invention, the reference information 14 may be created 5 by a third party process and stored in a database accessible to the binding engine. Other embodiments include the creation of the reference information 14 during an enrolment process. In the enrolment process, the capture interface 12 guides a subject to register enrolment images of their biometric features, in a similar manner to the process of capturing a binding video, the aim being to obtain a set of images of fingerprints to be io stored in association with the identity of the user, provided to the capture interface 12. The capture interface 12 may request a user to select an operating mode, namely enrolment mode or binding mode, and images or videos captured by the capture interface 12 are processed and stored as reference information 14. 15 In embodiments, the reference information 14 obtained during the enrolment mode is a set of images, each labelled in accordance with the biometric feature(s) which it represents, such as ‘left middle finger, ‘right thumb’, or ‘four fingers of left hand’. In other embodiments, the reference information 14 obtained during enrolment mode is a model of the user’s fingerprints. The models are such that the fingerprints themselves cannot 20 be recreated from the models, but the models will serve as a reference to which biometric features obtained during from a binding video can be compared to determine whether they conform to the model. Further, such models enable the effects of image-processing deficiencies to be reduced, because rather than requiring a direct image-to-image comparison, which may fail in areas of blurring or aberration, the model can effectively 25 enable interpolation of a fingerprint in such areas to preserve the ability for a comparison to be made. Where models are generated in this manner, the original images captured by the capture interface 12 during the enrolment procedure, are deleted. In this manner, it is not 30 necessary to store biometric images for the user, and the user’s privacy can be ensured. Figure 3 illustrates the architecture 30 of a digital signature generation process according to a second embodiment. In the second embodiment, both binding and enrolment processes are illustrated. The architecture is represented in terms of both functional modules, such as software and / or hardware for executing particular functions, and information which is input to, and output from, such modules. As described above, binding and enrolment may both be performed using the same 5 application on a user device such as a mobile phone, as different operating modes. The enrolment mode 31 is illustrated as being a self-enrolment process in which a user interacts with the application, whereas the binding mode 32 is illustrated as being an assisted process, but as described above, this is simply by way of example. In alternative embodiments, the enrolment mode 31 and binding mode 32 are implemented by io separate applications. A user interface 33 on the mobile device, with which a user interacts in the enrolment mode, 31 provides speech and / or text guidance to assist the user with positioning themselves for image-capture, and to request enrolment interaction information 34. The 15 user interface 33 may provide a training video to demonstrate how they should pose for image capture. This is particularly advantageous where the enrolment is performed without human assistance, and where it is undesirable for the user to interrupt the enrolment process to seek further assistance, which could increase the exposure of the system to fraudulent activity between, for example, repeated image capture events. 20 The enrolment interaction information 34 may include confirmation of the user’s passport details, an indication of the presence of other people in the user’s vicinity, an authorisation code enabling access to the binding mode 31, consent information, and any other information derived from the user’s interaction with the interface 33 which may 25 provide enrolment context. The authorisation code may be a unique code given to the user by an entity such as a government platform for issuing an electronic travel authority for which the digital signature 40 is required. Enrolment data 35 is captured in the enrolment mode 31 which includes biometric image 30 captures, fingerprints in the present embodiment, captured in combination with the user’s face, in a capture mode similar to the process of capturing a binding video described above. In addition, identification information such as a device identifier, SIM code, device type, or location are also included in the enrolment data 35. The enrolment data 35 and the enrolment interaction information 34 are passed to an enrolment processing module 36. The enrolment processing module 36 operates to obtain a series of enrolment images, either by extracting images from an enrolment video captured in the enrolment mode 31, via the guidance of the interface 33, or by labelling 5 captured images. As is possible with the binding video, the enrolment video may be divided into a series of video segments, each of the order of a few seconds in duration, to facilitate the extraction of images for specific fingerprints which are expected to be present in the video segment in accordance with a predetermined capture sequence. io Facial images are also extracted by the enrolment processing module 36 in order to compare them with them with those extracted from a passport scanner 37 operating on the user’s passport, within which a facial image is present. In embodiments, the enrolment processing module 36 generates one or more models 15 for the fingerprints from the enrolment images, and the enrolment images are deleted after the generation of the models, in order to preserve the user’s security. Enrolment images which are processed for output by the enrolment processing module 36 are stored in a processed images storage module 38. In embodiments in which the 20 enrolment images are deleted, the enrolment images are superseded by the generated one or more models, which are stored in a storage module analogous in function and arrangement to the illustrated processed images storage module 38. The stored information represents the reference information 14 to be fed into the binding engine 10 during a binding process. 25 The passport scanner 37 represents an image processing function of a camera on either a standalone image capture device, or the camera of the device used for the application for the enrolment mode 31, and acts to extract legal document information 39 including user’s name, passport number and data of birth, and a facial image. The legal document 30 information 39 so extracted may be compared, by the enrolment processing module 36, with the enrolment interaction information 34 provided by the user and the facial images of the enrolment data 35, and the result of the determination may be appended to the processed images or fingerprint models which are output by the enrolment processing module 36, in order to verify that the user presenting to the enrolment mode is in 35 possession of their own passport. Having enrolled in this manner, the user is in a position to use the binding mode 32 at another time in the future, for the purpose of generating a digital signature 40 for accessing a particular system, service or function. In the present embodiment, the digital 5 signature is, in essence, a verification that fingerprints presented in the binding mode 32 are in fact those of a subject having previously enrolled the same fingerprints, with the identity of the subject being bound to the fingerprints. In the embodiment of Figure 3, the binding mode 32 employs the same interface 33 as io the enrolment mode 32. The interface is used to capture binding interaction information 41, which include one or more of the user’s full name, date of birth, authorisation code as used previously during the enrolment mode 31, consent, and any other supplementary information which provides binding context. 15 Additionally, binding data 42 is captured in the form of a binding video, as described with reference to Figure 1, as well as location and device ID or type. The location and device ID or type may, in alternative embodiments, be provided via interaction with the interface 33 and stored as binding interaction information 42. 20 The binding interaction information 41 and binding data 42 are provided to a binding processing module 43. The binding processing module 43 is analogous in structure and function to the binding engine 10 of Figure 1. The binding processing module 34 acts on the binding interaction information 41 and binding data 42, together with the processed images 38 and supplementary information output by the enrolment processing module 25 36, to determine binding results 44 which are used to determine whether a digital signature 40 can be output. In more detail, the binding processing module 43 receives identification information for a subject seeking a digital signature via the binding mode 32. The receipt of identification 30 information 13 is shown in Figure 1, and in Figure 3 may include binding interaction information 41. The binding processing module 43 searches for enrolments with the same identification number, in this embodiment, a passport number, in order to determine whether the subject claims to have previously enrolled. In doing so, a check of the identification information 13 may include a check of a name, date of birth, and an 35 authorisation code used in a prior enrolment. If prior enrolment has occurred, a positive result is returned, which represents completion of a pre-binding or preliminary processing stage. In response to such a positive result, the binding process begins in a manner similar to 5 that already described above with reference to Figure 1 and 2. In the present embodiment, however, the process of matching the processed images 38 with binding data is outsourced to a dedicated fingerprint matcher module 45. This is simply by way of example, and the fingerprint matcher 45 can be integrated with the binding processing module 43. By using a dedicated fingerprint matcher 45, sophisticated image processing io tools and algorithms can be employed which can be trained and updated independently of the operation of the binding processing module 43. The fingerprint matcher 45 acts to match the patterns of contours of the fingerprint in images extracted from the binding video with reference information derived from the enrolment processing module 36 as described above and input to the binding processing module 43, using, for example, the 15 correlation function of an image processing algorithm, to determine a proximity of each to the subject’s fingerprints to the enrolled records contained in the reference information 13. A binding score is generated and output to the binding results storage 44. In 20 embodiments, the binding results may further comprise identifications of perceived image-capture errors such as blurring or aberrations, or identifications as to which, if any, fingerprints have failed to be verified, in order for the interface 33 to determine whether to prompt the user to recapture portions of the binding video to update the captured images. 25 If the binding score exceeds a particular threshold, successful binding of the subject’s fingerprints to their identity is determined, and a digital signature 40 is generated. The digital signature may be an authorisation token or code, to be stored in an electronic wallet of the subject’s device, for example, their mobile device, communicated, for 30 example, using a short-range communication means such as Near Field Communication (NFC), or Radio Frequency Identification (RFID). The authorisation token or code comprises a verified mapping between biometric images of the subject and their identity, such that when the subject attempts to access a system, service or function using their fingerprints, the risk of a fraudulent access attempt is significantly reduced. The 35 conditional access system can rely on the verification achieved via the binding process described herein as an indication that access can be permitted without, the risk that the subject has presented the fingerprints of another person. The binding processing module 43 communicates with a facial recognition module 46, 5 which matches a facial image extracted from the binding video with a passport image derived from the enrolment process to determine a matching correlation, which is returned as a result to the binding processing module 43. In this manner, it is possible to determine whether the face of the subject presented for biometric binding matches the face of a user already known to have the identity which the subject purports to have. The io advantages of a dedicated facial recognition module 46 are similar to the advantages of a dedicated fingerprint matcher 45, in that operation of the facial recognition module 46 can be readily optimised and configured independently of the binding process. In embodiments, the facial recognition module 46 uses presentation attack detection 15 (PAD), which detects whether the user’s face has liveness or is reproduced or spoofed by synthetic means. In this manner, an attempt to defraud the system by using, for example, a mask or textured reproduction of another person’s face (produced, for example, using additive manufacturing), rather than the face being ‘live’, can be prevented if the PAD identifies that the presented face is a reproduction. 20 Such PAD detection can on also be included, in embodiments, within the functionality of the enrolment processing module 36 and the binding processing module 43 in relation to at least the fingerprints of a person, and optionally in relation to a person’s palms, ears, or other biometric features. 25 The method of embodiments of the present invention is performed as a computerexecutable method, defined by a plurality of computer-readable instructions which are executed by at least the binding engine 10. The functional modules and capabilities described herein may be represented as discrete hardware components, such as 30 storage modules and processors, but may also be represented as functional sections of code within the overall operating algorithm for the method, such as a video segmentation algorithm. Any appropriate architecture may be employed which is suitable for executing the method of embodiments of the present invention. In embodiments in which enrolment processing is performed as well as binding, it may be possible for a separate enrolment processing module 36 and a binding processing module 43 to be employed, but these can be generalised as a single processing module (which may itself comprise a plurality of processors), such as the binding engine 10. 5 Although the capture interface 12 of Figure 1 and the interface 33 of Figure 3 are shown as standalone modules, in embodiments, these modules may also be integrated with the binding engine 10, with all capture and processing performed by a single computer system, such as a mobile device or table, which is executing a binding application. The io binding application may access ID information, reference information, passport databases, external facial image recognition modules, and automated assistant functionality, as described above. The binding application is defined by the set of computer-executable instructions. 15 In alternative embodiments, the binding engine 10 operates on a server which is external with respect to the user interface and cameras which are employed. In this manner, the user accesses a back-end binding engine through access to a binding platform or system through a front-end interface. 20 From the perspective of the user experience, the nature of the interaction between the platform and a user when binding and when enrolling can be customised and developed using a machine-learning algorithm to train the interface. The machine-learning algorithm may be trained on information for guiding a subject, and the binding score obtained from verifying the identity of the subject using the captured biometric features, to optimize the 25 information for guiding the subject. The optimization is such that the user is able to present features in a way which maximises the quality of image-capture. This is particularly advantageous for self-capture modes, in which it is more difficult for the user to determine a correct positioning, or image-capture settings and conditions, on a camera preview screen than it is for an assistant to make necessary adjustments. Additionally, 30 the length of an enrolment or binding capture process, and the length of, for example, a binding video, can be reduced if the proportion of the binding video containing sub-optimal image capture conditions is reduced. This relaxes the requirements on editing, segmenting, and clipping of the binding video to eliminate any redundant information. The user-interface may take advantage of native settings on the capture device, such as the camera modes of a mobile phone, in order to select the appropriate lens of a multilens camera device, and to use the correct filters, white balancing, exposure settings, aperture settings, and the like. 5 The user-interface may use an automated assistant to guide its interactions with the user, responding to conversational inputs or behaviours, and suggesting appropriate actions to take. In addition to improving the efficiency of the process, this also improves the accessibility of the platform by enabling a user-friendly interaction. For applications io where the purpose of the binding process is to lead to the issue of an electronic travel authority, for example, it may be envisaged that the binding technique could be used by a significant number of the population with the platform hosted on, for example, a government-owned technology platform, and by improving the user experience, it can be ensured that as many of the population as possible are able to self-enrol and perform 15 binding, with minimal assistance. Further, variation in behaviour of the population is accommodated within the models used to train the automated assistant Although references to passports are made in this disclosure, this is simply by way of example. The techniques of the present invention are compatible with national or 20 regional identification cards, driving licences, any other form of official identification means which contains a facial image for the identified user. More modern forms of identification may contain electronic chips or tags, which can be read by an electronic scanners to obtain both identification and facial image without the need of an image scanner. Such a document reader may take the place of the passport scanner 37 shown 25 in Figure 3. The binding threshold which is set, and the number of fingerprints to be imaged, the duration for which they should be imaged, together with specifications as to the specific combinations which should be included in the enrolment and binding capture sequence, 30 are variable by a user configuring the binding engine 10 or binding processing module 43 via an interface (not shown) from which settings can be adjusted in dependence on particular applications. For example, for the purpose of generating a digital signature for an electronic travel authority, a stricter set of conditions may be needed, such as a full set of fingerprints, also including images of palms of hands, as well as a high threshold 35 for the binding score. PAD may also be required. For a door access system with a lower number of expected access attempts, and lower security concern, it may be sufficient to capture only two or three fingerprints, and a tolerance for image-capture errors and capture of additional people in the binding video may be relaxed. Required capture sequences may therefore be adjusted accordingly. It will therefore be appreciated that there are many modifications to the embodiments disclosed above, which fall within the scope of the claims.
Claims
1. A method for generating a digital signature, comprising: capturing a binding video of a subject;5 extracting one or more images from the binding video, wherein each extractedimage contains one or more biometric features of the subject;wherein capturing the binding video comprises capturing the face of the subject in combination with one or more biometric features of the subject in the same scene of at least a portion of the binding video;io the method further comprising:receiving identification information, and obtaining reference information for biometric features of a user identified by the identification information;for each extracted image, comparing the one or more biometric features with the reference information for the corresponding one or more biometric features;15 responsive to determining that the face of the subject correlates with a facialimage contained in the identification information, and determining that biometric features of each of the extracted images correlate with respective reference information for the corresponding biometric features,verifying the identity of the subject as that of the user identified by the 20 identification information; andgenerating and outputting a digital signature for the subject having the verified identity, comprising the one or more images of the biometric features in combination with the identification information.25 2. A method according to claim 1, wherein the biometric features comprise at leastone or more fingerprints of the subject.
3. A method according to claim 1 or claim 2, wherein capturing the binding video is performed with a single camera device.
304. A method according to any one of the preceding claims, wherein capturing the binding video is performed using a camera-equipped wearable device, arranged to capture a reflection of the face and the biometric features of the subject.
5. A method according to any one of the preceding claims, wherein the identification information further comprises one or more of a name, a date of birth, a passport number, a location, a user device identity, and an authentication code.
56. A method according to any one of the preceding claims, wherein verifying the identity of the subject comprises determining a binding score representing the likelihood that the biometric features of the subject correspond to those of the user identified by the identification information.10 7. A method according to claim 6 comprising providing a capture interface outputtinginformation to guide the subject to pose such that the biometric features are captured in the binding video according to a predetermined video capture sequence.
8. A method according to claim 7, comprising using a machine-learning algorithm to 15 train the capture interface, wherein the machine-learning algorithm is trained on information for guiding a subject, and the binding score obtained from verifying the identity of the subject using the captured biometric features, to optimize the information for guiding the subject.20 9. A method according to claim 7 or claim 8, wherein if the binding score is below averification threshold, the method comprises outputting further information via the capture interface to guide the subject to adjust their pose, and performing further capture of a binding video of the subject containing one or more biometric features which do not correlate with respective reference information.2510. A method according to any one of claims 6 to 9, further comprising determining one or more additional parameters relating to:the number of people in the captured binding video;whether an individual person remains in a scene of the binding video for the 30 duration of the binding video; andvariation in the dimension of a physical characteristic of a person identified in the binding video; andmodifying the binding score in dependence on the determined one or more additional parameters.3511. A method according to any one of the preceding claims, wherein the reference information comprises one or more models of biometric features of the user identified by the identification information, and comparing a biometric feature with the reference information comprises determining whether the biometric feature conforms to a model of5 the biometric feature defined by the reference information.
12. A method according to any one of the preceding claims, further comprising biometrically enrolling the subject, comprising:obtaining one or more enrolment images of the subject, wherein each enrolment io image contains one or more biometric features of the subject;generating a model of each of the one or more biometric features of the subject from each enrolment image as the reference information;receiving enrolment information for the subject; andstoring a mapping between the reference information and the enrolment 15 information;wherein the step of obtaining reference information comprises obtaining the reference information mapped to enrolment information matching the received identification information.20 13. A method according to claim 12, comprising capturing an enrolment video, andextracting the one or more enrolment images from the enrolment video.
14. A method according to any one of claims 11 to 13 comprising destroying enrolment images for which a model of each of the one or more biometric features in the 25 enrolment images is generated.
15. A method according to any one of the preceding claims, further comprising providing the digital signature to a conditional access system requiring biometric authentication of a user using the digital signature as the condition of access.3016. A computer program which, when executed by one or more processors, is arranged to perform the method of any one of the preceding claims.
17. A computer system comprising one or more processors arranged to perform the 35 method of any one of claims 1 to 15, the computer system further comprising:IO- 2 / -a user interface for instructing a subject to provide the identification information and to pose for the binding video;a camera for capturing the binding video;a communication interface for communicating with a database storing the reference information; andan output interface for outputting the digital signature of the subject.
18. A computer system according to claim 17, wherein the output interface is configured to communicate electronically with a digital wallet of a mobile device using RFID or NFC.
Citation Information
Patent Citations
Energy providing devices and applications thereof
US20200203692A1
Method and system for verifying users
US20210192189A1
Synchronized Identity, Document, and Transaction Management
US20230134651A1
System and method for facial recognition
AU2020203692A1