Secure digital enrollment with smart card

JP2023033220A5Pending Publication Date: 2025-08-21IDEMIA FRANCE SAS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2022133961
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2021-08-26
Filing Date
2022-08-25
Publication Date
2025-08-21

AI Technical Summary

Technical Problem

Smart cards with fingerprint sensors face challenges in secure digital enrollment due to limited user interface resources, making it difficult to authenticate users reliably and securely during the enrollment phase.

Method used

A processing method on smart cards using a fingerprint sensor to acquire a sequence of object prints, compare it with pre-recorded reference data, and perform authentication before the digital enrollment phase, allowing secure digital registration without requiring additional user interface devices.

Benefits of technology

Enables secure digital enrollment on smart cards with limited user interfaces by authenticating users using fingerprint sensors, reducing security risks and simplifying the enrollment process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

To provide a method which allows a secure digital enrollment with a smart card including a fingerprint sensor, a computer program, and a smart card.SOLUTION: A smart card CD1 includes a fingerprint sensor 8. The fingerprint sensor acquires a sequence SQ1 of object prints PT1 from objects detected over time, compares the sequence of object prints with reference data DREF1 defining a reference sequence SQ0 of object prints according to at least two different print types TY1, TY2, and determines that an authentication phase is successful if the sequence of object prints coincides with the reference data. During a digital enrollment phase, the smart card generates, from enrollment fingerprint PT2, digital enrollment data DREF2 and records the digital enrollment data.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to authentication by fingerprint, and more particularly to securing digital enrollment on a smart card to enable subsequent digital authentication of the user. [Background technology]

[0002] Many improvements have been developed in recent years with regard to smart cards. One of them consists in equipping smart cards with a fingerprint sensor in order to authenticate the user and, in particular, to secure the transactions carried out by means of the smart card. Thus, depending on the result of the fingerprint verification carried out by the fingerprint sensor, such a smart card can accept or reject a transaction, which makes it possible to limit the risk of fraudulent use of the card.

[0003] To enable digital authentication of a user, smart cards that embed a fingerprint sensor typically store in memory reference digital data that are used to check the validity of the fingerprints obtained during the authentication phase. Each user authentication phase is therefore based on these reference digital data, which the smart card must access in order to determine whether the user being authenticated is an authorized user. To do so, the smart card must perform an enrollment phase before the authentication phase, during which it records a fingerprint template as reference digital data.

[0004] This registration phase is particularly sensitive from a security point of view, insofar as it determines which users are subsequently authorized to use the smart card. This registration phase should be secured to ensure that the reference digital data is captured and recorded in good condition, so that only legitimate users can be successfully authenticated by the smart card.

[0005] A known method consists in configuring a smart card to authenticate the cardholder during a registration phase from a dedicated secret PIN code provided for authentication purposes by the card's issuer. However, using such a secret code poses technical difficulties insofar as smart cards have traditionally included very limited resources, in particular with regard to interface means between the user and the smart card. Typically, smart cards do not have a user interface or at least include very limited user interface means, in particular with regard to input means for entering user commands into the card.

[0006] Furthermore, according to certain techniques, the holder of a smart card enters a secret code using a specific application executed by a terminal cooperating with the card in order to authenticate himself during the registration phase. However, the use of such a terminal also presents technical difficulties insofar as the terminal must be secure and suitable for such an authentication phase. In particular, this terminal must include a user interface that is particularly suitable for allowing the cardholder to securely enter the secret code in the terminal's user interface. The use of such a terminal makes the registration phase more complicated, represents a security risk, and causes problems when such a terminal is not available.

[0007] Therefore, there is a need for a solution that allows for secure digital enrollment on smart cards that include fingerprint sensors, including when the smart card has limited means for a user interface, as is typically the case. Summary of the Invention [Means for solving the problem]

[0008] To that end, the invention relates to a processing method implemented by a smart card including a fingerprint sensor, said method comprising: a1) obtaining a sequence of object prints from an object detected over time by a fingerprint sensor; a2) comparing the acquired sequence of object prints with pre-recorded reference data in a smart card, said reference data defining reference sequences of object prints according to at least two different print types; and a3) determining that the authentication phase is successful if the sequence of object prints matches the reference data; a) an authentication phase, b1) generating digital enrollment data from at least one fingerprint, called an enrollment fingerprint; and b2) recording the digital registration data to enable subsequent digital authentication from said digital registration data; b) a digital registration stage; Includes:

[0009] According to a particular embodiment, the method comprises the steps of: - recording reference data in the memory of the smart card; Includes:

[0010] According to one particular embodiment, the reference sequence to be followed during the acquisition phase includes at least two print groups acquired sequentially over time, each print group including at least one object print acquired simultaneously by the fingerprint sensor.

[0011] According to a particular embodiment, the method comprises, during the registration phase b), b0) acquiring a sequence of object prints; a1) independently acquiring at least one fingerprint by a fingerprint sensor as an enrollment fingerprint; Includes:

[0012] According to a particular embodiment, the at least one aforementioned enrolment fingerprint from which the digital enrolment data is generated in b1) is a fingerprint obtained in a1) from among the sequence of object prints.

[0013] According to a particular embodiment, recording b2) is performed before determining a3), and the digital registration stage comprises: b3) erasing the digital enrollment data in response to determining in a3) that the authentication step failed. b2) further includes recording the following.

[0014] According to a particular embodiment, the enrollment stage b) is triggered in response to a determination in a3) that the authentication stage was successful.

[0015] According to a particular embodiment, an object print of a first print type is placed in time between two object prints of another print type according to a reference sequence.

[0016] According to a particular embodiment, each object detected by the fingerprint sensor in a1) is a finger or a tool.

[0017] According to a particular embodiment, the authentication step - analyzing each object print of the sequence of object prints obtained in a1) to determine whether said object print contains feature points; - identifying each object print of the acquired sequence of object prints as a tool print corresponding to a first print type or as a fingerprint corresponding to at least one other print type depending on whether said object print includes minutiae. Including, During comparison a2), the acquired sequence of object prints comprising prints of the first and said at least one other print type is compared with a reference sequence comprising prints of the first and said at least one other print type.

[0018] According to a particular embodiment, the authentication step determining a series of values ​​representing the acquired sequence of object prints, wherein each object print identified as a fingerprint is represented in the series of values ​​by an occurrence of a first value and each object print identified as a tool print is represented in the series of values ​​by an occurrence of a second value different from the first value; Including, During the comparison a2), a series of values ​​representative of the acquired sequence of object prints is compared with reference data defining a sequence of values ​​comprising first and second values ​​as a reference sequence.

[0019] According to a particular embodiment, the acquired sequence of object prints comprises a fingerprint, and the authentication step is -analyzing each fingerprint of the sequence of object prints acquired in a1) to identify feature points within the fingerprints of said acquired sequence of object prints; comparing fingerprints of said sequences of object prints obtained from the identified minutiae, thereby identifying at least two different fingerprint types corresponding to at least two different fingers; Including, During the comparison a2), the obtained sequence of object prints comprising said at least two different fingerprint types is compared with a reference sequence comprising fingerprints corresponding to at least two different fingers.

[0020] According to a particular embodiment, the authentication step - identifying an individual fingerprint of the acquired sequence of object prints for each of said at least two different fingerprint types as a print template if said fingerprint corresponds to a first detected finger in the acquired sequence of object prints; Including, Each print template is compared to other fingerprints in the sequence of object prints, thereby identifying each of said other fingerprints as one of said at least two different fingerprint types.

[0021] According to a particular embodiment, the authentication step - identifying at least a first fingerprint and a second fingerprint in the sequence of object prints as print templates of said at least two different fingerprint types depending on the respective positions of said at least first and second fingerprints in said acquired sequence of object prints in a1). Including, The first and second fingerprints serve as print templates to be compared with other fingerprints in the sequence of object prints, thereby identifying each of the other fingerprints as one of the at least two different fingerprint types corresponding to at least two different fingers.

[0022] According to a particular embodiment, the method comprises: c1) acquiring at least one new fingerprint by a fingerprint sensor; c2) authenticating said at least one new fingerprint by comparing it with the digital enrolment data; a) a second authentication stage after authentication stage a), including

[0023] In certain embodiments, the various steps of the processing method of the present invention are determined by computer program instructions.

[0024] Consequently, the invention also relates to a computer program on an information medium (or recording medium), which program can be implemented in a device such as a smart card or more generally in a computer, and which comprises instructions adapted to the implementation of the steps of the processing methods defined above and described in the particular embodiments below.

[0025] Thus, the methods of the present invention may be implemented by a non-volatile memory that stores computer program instructions and by a processor that executes those instructions.

[0026] This program may use any programming language and may be in the form of source code, object code, or an intermediate code between source code and object code, such as a partially compiled form, or any other desired form.

[0027] The invention also relates to an information medium (or storage medium) readable by a computer, more particularly by a smart card (notably by a processor of the smart card) and containing instructions for the computer program as described above.

[0028] The information medium may be any entity or device capable of storing a program. For example, the medium may include storage means such as a rewritable non-volatile memory or ROM, for example a CD ROM or a microelectronic circuit ROM, as well as magnetic recording means, for example a floppy disk or a hard drive.

[0029] On the other hand, the information medium may be a propagating medium such as an electrical or optical signal which can be conveyed via electrical or optical cable, by radio or by other means. The program according to the invention can in particular be downloaded from a network of the Internet type.

[0030] Alternatively, the information carrier may be an integrated circuit in which the program is embedded, the circuit being adapted to perform or be used in performing the method.

[0031] The invention also relates to a device, in particular a smart card, capable of implementing the processing method defined herein. a fingerprint sensor; an authentication module, Obtaining a sequence of object prints from an object detected over time by a fingerprint sensor; comparing the acquired sequence of object prints with pre-recorded reference data in a smart card, said reference data defining reference sequences of at least two different print types; and If the sequence of object prints matches the reference data, the authentication phase is considered successful. an authentication module configured to: a registration module, generating digital enrollment data from at least one fingerprint, referred to as an enrollment fingerprint; and Recording digital registration data to enable subsequent digital authentication from said digital registration data a registration module configured to: The present invention provides a smart card including:

[0032] It should be noted that the various embodiments and associated advantages mentioned above (and described below) with respect to the processing method of the present invention apply analogously to the device (and in particular the smart card) of the present invention.

[0033] For each step of the processing method, the device (notably the smart card) of the present invention may include a corresponding module configured to perform the aforementioned step.

[0034] According to one embodiment, the present invention is implemented by software and / or hardware components, and in this regard, the term "module" as used herein may correspond to a software component, a hardware component, or a combination of a hardware component and a software component.

[0035] A software component corresponds to one or several computer programs, one or several subprograms of a program, or more generally any element of a program or software, capable of implementing a function or a set of functions as described below with respect to the modules concerned. Such software components are executable by a data processor of a physical entity (smart card, terminal, server, gateway, router, etc.) and have access to the hardware resources of this physical entity (memory, storage media, communication buses, electronic input / output cards, user interfaces, etc.).

[0036] Similarly, a hardware component corresponds to any element of a hardware assembly capable of implementing a function or set of functions according to what is described herein with respect to the associated module. The hardware component may be a programmable hardware component or a hardware component with an integrated processor for executing software.

[0037] Other characteristics and advantages of the invention will become apparent from the description that follows, with reference to the accompanying drawings, which show exemplary embodiments without any limitation, in which: FIG. [Brief explanation of the drawings]

[0038] [Figure 1] 1 illustrates a schematic representation of a smart card according to an embodiment of the present invention; [Figure 2] 1 illustrates a schematic representation of a smart card cooperating with a peripheral device in accordance with at least one embodiment of the present invention; [Figure 3]1 illustrates a schematic representation of modules implemented by a smart card according to certain embodiments of the present invention. [Figure 4A] 10 is a schematic representation of a reference sequence to be followed to authenticate a user, according to certain embodiments; [Figure 4B] 10 is a schematic representation of a reference sequence to be followed to authenticate a user, according to certain embodiments; [Figure 5] 1 illustrates, in diagrammatic form, the steps of a processing method according to one embodiment of the present invention; [Figure 6] 1 illustrates, in diagrammatic form, the steps of a processing method according to one embodiment of the present invention; [Figure 7] 1 illustrates, in diagrammatic form, the steps of a processing method according to one embodiment of the present invention; DETAILED DESCRIPTION OF THE INVENTION

[0039] As indicated above, it is advisable to secure the digital registration phase implemented by the smart card in order to avoid any fraudulent use of the card, for which purpose the present invention provides for the performance of a user authentication, inter alia, prior to the user's digital registration phase (or at least prior to the completion of this digital registration phase), using a device such as a smart card.

[0040] However, as indicated above, smart cards inherently have relatively limited resources, especially with regard to possible user interface means that allow a user to interact with the card. In this specification, a "user interface" means any means that allows a user to interact with a device, such as a smart card. A user interface may in particular include input interface means (keyboard, actuators, buttons, microphone, etc.) that are arranged to allow a user to input commands into the device, and / or output interface means (display screen, indicator lights, loudspeaker, etc.) that are arranged to allow the device to output (return, return, etc.) information to the user.

[0041] In particular, smart cards generally contain few or no input interface means, which implies significant technical constraints and therefore poses problems for reliably and securely authenticating the user of the smart card. The present invention therefore proposes, according to various embodiments, to use a fingerprint sensor provided on the smart card (or more generally on the device) to authenticate the user before the digital enrolment phase (or at least before the completion of this digital enrolment phase).

[0042] However, using a digital sensor to authenticate a user with a smart card, and that before the digital registration phase of that user (or at least before the completion of this digital registration phase), presents technical difficulties, unless the smart card originally has reference fingerprints in its memory to check whether one or several fingerprints captured by the smart card's fingerprint sensor are valid.

[0043] The invention therefore proposes to solve these technical difficulties by comparing a sequence of object prints acquired over time by a fingerprint sensor, notably before a digital enrolment phase (or at least before the completion of this digital enrolment phase), with reference data accessible by the smart card, these reference data being for example pre-recorded in the card. More specifically, the invention provides according to some embodiments a processing method implemented by a smart card comprising notably a fingerprint sensor, which method comprises an authentication phase from the sequence of object prints acquired by the card's fingerprint sensor, which authentication phase comprises comparing this acquired sequence with reference data, and then triggering a digital enrolment phase upon detecting that the authentication phase has been successfully passed.

[0044] As described below, the fingerprint sensor of the smart card of the present invention can be used to acquire fingerprints of various objects, be they fingers (or any other anatomical site) or tools. Such a sensor may thus enable acquisition of various kinds of object prints, including fingerprints and tool prints (prints produced by any tool other than a finger).

[0045] While smart cards normally do not have in their memory a reference fingerprint of a legitimate user before the actual execution of the digital enrolment phase (the aim of which is essentially to obtain one or several reference prints), the smart card of the present invention recognizes the sequence of several object prints detected over time by the fingerprint sensor and compares this obtained sequence with a reference sequence in a way that determines whether the authentication phase will succeed or fail, and can do so before the digital enrolment phase (or at least before the completion of this enrolment phase). The use of the fingerprint sequence makes it possible to authenticate a user by the fingerprint sensor of the smart card even if the digital enrolment phase has not yet taken place.

[0046] Other aspects and advantages of the present invention will become apparent from the exemplary embodiments described below with reference to the above-mentioned drawings.

[0047] In the embodiments described below, the invention is implemented by a smart card, such as a bank or payment card, access badge, ID card, voting card, etc. However, the invention is broadly applicable to devices other than smart cards that are capable of processing transactions (e.g., payment transactions) by cooperating with an external terminal.

[0048] It should also be noted that the notion of transaction is understood in this specification in a broad sense and includes, for example, in the banking field, various banking transactions, in particular payment transactions, transfer transactions, etc. The present invention applies in particular, but not exclusively, to payment cards intended for carrying out banking transactions. It will be understood that other types of transactions or operations are conceivable within the framework of the present invention, such as electronic voting, transactions for accessing confidential data, transactions for gaining physical or logical access, etc.

[0049] Unless otherwise specified, elements common to or similar to several drawings will bear the same reference symbols and have the same or similar characteristics, and therefore, for the sake of brevity, those common elements will generally not be described again.

[0050] Unless otherwise specified, terms such as "first," "second," etc. are used herein as an arbitrary convention to identify and distinguish between various elements (keys, devices, etc.) implemented in the embodiments described below.

[0051] 1 represents the structure of a smart card CD1 according to a particular embodiment of the invention. In this example, the smart card CD1 includes a fingerprint sensor 8 and is configured to authenticate the user UR by means of the sensor 8 prior to the digital registration of the user UR on the card (or at least prior to the completion of this digital registration of the user UR on the card).

[0052] The smart card CD1 can for example be a bank card or payment card, for example a card of the EMV (Europay Mastercard Visa) type, although other protocols are also possible.

[0053] In this example, smart card CD1 is arranged to cooperate with peripheral device DV1, although other examples are possible in which no such peripheral device is involved.

[0054] More specifically, in this example the smart card CD1 comprises a processor 2, a volatile memory 4 (RAM), a non-volatile memory 6, a rewritable non-volatile memory MR1, a fingerprint sensor 8 and possibly a communication interface INT1.

[0055] For example, it is conceivable that the smart card does not include any user interface (or at least no user interface means on the input surface) apart from the fingerprint sensor 8. However, variants are also possible in which the smart card CD1 further includes a user interface in addition to the fingerprint sensor 8, for example including at least one of one or several indicator lights, a screen, one or several buttons, etc.

[0056] It is also assumed in this example that smart card CD1 has no internal power supply, and in this example, smart card CD1 is configured to be electrically powered by peripheral device DV1 when the two are coupled (as described below).

[0057] The memory 6 is a rewritable non-volatile memory or read-only memory (ROM), which is readable by the smart card CD1 and constitutes a recording medium (or information medium) according to a particular embodiment on which a computer program PG1 according to a particular embodiment is recorded. As will be described in more detail below, this computer program PG1 comprises instructions for carrying out the steps of a processing method according to a particular embodiment.

[0058] The rewritable non-volatile memory MR1 (for example of the Flash type) can store, inter alia, first reference data DREF1 and second reference data DREF2. As will be described below, the first reference data DREF1 are pre-recorded in the smart card CD1 and are used by the smart card CD1 during an authentication phase preceding (or parallel to or concomitant with) the digital enrolment phase in order to authenticate the user UR from the sequence of object prints PT acquired by the fingerprint sensor 8. These first reference data DREF1 can define, for example, reference sequences of at least two different prints, denoted TY1 and TY2 (FIG. 1). The second reference data DREF2 are digital enrolment data that can be generated by the smart card CD1 during an enrolment phase after the above-mentioned authentication phase. The nature and use of the reference data DREF1 and DREF2 will become clearer in more detail in the following examples.

[0059] The fingerprint sensor 8 is configured to acquire (capture) fingerprints, more generally object prints PT. These may in particular be object prints PT1 acquired during an authentication phase prior to (or parallel to or concomitant with) a digital enrolment phase, or object prints PT2 acquired during a digital enrolment phase after said authentication phase. As will be described below, the fingerprint sensor 8 may in particular be used to acquire a sequence SQ1 of object prints PT1 during an authentication phase prior to (or parallel to or concomitant with) a digital enrolment phase.

[0060] Various objects can be presented in contact with or in proximity to the sensor 8 to enable the sensor 8 to acquire corresponding prints. As already indicated, the nature of the considered object may vary depending on the case. Essentially, the fingerprint sensor 8 is configured to acquire at least a fingerprint resulting from a finger. According to some exemplary embodiments, the fingerprint sensor 8 may further be configured to acquire object prints other than fingerprints, in particular tool prints resulting from tools other than fingers (or other than anatomical sites). The fingerprint sensor 8 may be configured to acquire prints (called tool prints) of one or several tools of various types, such as, for example, a spoon, a stylus, or any other suitable tool that can be manipulated by the user UR to interact with the fingerprint sensor 8.

[0061] The fingerprint sensor 8 may be configured to determine whether an acquired object print PT1 constitutes a fingerprint or a tool print, depending inter alia on whether it identifies minutiae in said print. According to one particular example, the presence of minutiae in a print indicates that it is a fingerprint, whereas the absence of minutiae indicates that it is a tool print.

[0062] In this specification, feature points are specific elements (local singularities, irregularities, etc.) that characterize the finger surface, e.g., nipple line properties (terminations, bifurcations, islands, etc.). The nature and number of feature points considered for a given finger may vary from case to case.

[0063] In general, fingerprint sensor 8 may be configured to acquire, for example, at least two different types of object prints (denoted TY1 and TY2). Each of these types TY1 and TY2 may correspond, for example, to any fingerprint (i.e., a fingerprint characterizing any finger), a given fingerprint (characterized by predefined minutiae of a given finger), a print of any tool other than a finger (without minutiae characterizing the surface of the finger), a print of a specific tool (exhibiting predefined characteristics), etc. Exemplary implementations illustrating various print types detectable by fingerprint sensor 8 and that may be used during processing methods are described below.

[0064] The manner in which the fingerprint sensor 8 performs the acquisition of an object print from a corresponding object may vary depending on the technology used by the considered sensor. Thus, the specificity of the sensor 8 used may vary depending on the implementation choice of the skilled person. The fingerprint sensor 8 may be, among others, a capacitive sensor, an optical sensor, a thermal sensor, etc., or more generally, any sensor capable of acquiring an object print, including a fingerprint.

[0065] If fingerprint sensor 8 is configured to acquire a tool print from a tool (other than a finger), the nature of this tool may vary depending on the sensor technology. In particular, sensor 8 may be configured to acquire a tool print provided by a conductive tool or possibly a non-conductive tool, as the case may be.

[0066] As will be described later, fingerprint sensor 8 may in some cases be configured to simultaneously acquire multiple object prints PT. To do so, a user may simultaneously present several objects (fingers and / or tools) within the detection field of sensor 8 (in contact with or in close proximity to sensor 8), each of which will cause multiple prints to be acquired.

[0067] In this example, the processor 2 uses the volatile memory 4 to perform various operations of the smart card CD1 and various functions necessary for the operation of the smart card CD1, including executing the computer program PG1 during implementation of the processing method of the present invention.

[0068] The smart card CD1 may be configured to perform a given function by cooperating with an external terminal (not shown) to perform a transaction, such as a banking transaction (such as a payment transaction) or any other type of transaction. The smart card CD1 may be an EMV smart card configured, inter alia, to perform EMV transactions.

[0069] According to one particular example shown in Figure 2, the peripheral device DV1 to which the smart card CD1 can be coupled is a case into which the card CD1 can be inserted or engaged. However, other forms of the peripheral device DV1 are possible. In this example, the case DV1 includes an internal power source AL1 adapted to power the smart card CD1 when the two elements are coupled. Thus, although in this example coupling is by contact, other implementations are possible, such as a contactless coupling, so that power is supplied from the peripheral device DV1 to the smart card CD1 in a contactless manner (for example by electrostatic induction).

[0070] Optionally, peripheral device DV1 may also include a user interface 20 for guiding a user during the execution of the processing method by smart card CD1. This user interface 20 may be relatively limited and may for example include one or several indicator lights, although other implementations are also possible in which peripheral device DV1 does not have such a user interface 20.

[0071] As shown in Figure 2, smart card CD1, powered by peripheral device DV1 (by power supply AL1), is arranged to acquire object prints PT by means of its fingerprint sensor 8. As already indicated, the nature of the object whose print is acquired may vary depending on the case. In this example, sensor 8 makes it possible to capture fingerprints PT corresponding to fingers FG (for example prints corresponding to at least two different fingers, denoted FG1 and FG2), and possibly object prints PT corresponding to one or several tools, such as tool TL1 (a spoon in this example).

[0072] However, a variant is possible in which smart card CD1 includes an internal power supply, allowing smart card CD1 to be self-powered, so that it is not necessary to use peripheral device DV1.

[0073] It will be understood that certain elements typically present in a smart card have been intentionally omitted because they are not necessary for understanding the present invention. Furthermore, it is important to note that smart card CD1 constitutes only one non-limiting exemplary embodiment of the present invention. Those skilled in the art will understand that certain elements of smart card CD1 are described herein merely to facilitate understanding of the present invention, and that modifications without those elements are possible.

[0074] FIG. 3 illustrates the modules implemented by the processor 2 when the processor 2 executes the computer program PG1, namely the following modules: a first authentication module MD2, a registration module MD8, and optionally a second authentication module MD14, according to a particular embodiment.

[0075] More specifically, the first authentication module MD2 is configured to perform an authentication phase, which may be triggered before or in parallel with the enrollment phase, as described below. To do so, in this example the first authentication module MD2 may include a first acquisition module MD4 and a first processing module MD6.

[0076] The first acquisition module MD4 is configured to acquire a sequence SQ1 of object prints PT1 from an object detected over time by the fingerprint sensor 8 of the smart card CD1. The notion of a sequence of object prints will be explained in more detail later.

[0077] The first processing module MD6 is configured to compare the sequence SQ1 of the object print PT1 acquired by the first acquisition module MD4 with reference data DREF1 pre-recorded in the smart card CD1. As already indicated, these reference data DREF1 may define reference sequences SQ0 of reference prints of at least two different print types, denoted for example TY1, TY2. The first processing module MD6 is further configured to determine that the authentication phase is successful if the sequence SQ1 of the object print PT1 matches (or matches) the reference data DREF1.

[0078] The enrolment module MD8 is further configured to perform a digital enrolment step, possibly after the authentication step performed by the first authentication module MD2 or possibly in parallel (concomitant with) said authentication step, in order to do so the enrolment module MD8 in this example may also include a second processing module MD12 and possibly a second acquisition module MD10.

[0079] The second processing module MD12 is configured to generate digital enrolment data DREF2 from the at least one enrolment fingerprint PT2, ie data that serves as a template for the fingerprints of users authorized to use the smart card CD1.

[0080] By definition, a fingerprint within the meaning of this specification corresponds to the print of a finger (rather than a tool) that is or has to be detected by the fingerprint sensor 8 .

[0081] The second processing module MD12 may further be adapted to record the digital enrolment data DREF2, for example in the memory MR1 of the smart card CD1, in order to enable subsequent digital authentication by means of the smart card CD1 from the digital enrolment data DREF2.

[0082] As will be described below, the enrolment fingerprint PT2 used by the second processing module MD12 to generate the digital enrolment data DREF2 may comprise at least one fingerprint obtained by the enrolment module MD8 independently of the authentication phase performed by the first authentication module MD2. To do so, the enrolment module MD8 may further comprise the above-mentioned second acquisition module MD10, which is configured to obtain the at least one fingerprint PT2 as enrolment fingerprint by using the fingerprint sensor 8.

[0083] According to one particular example, the second authentication module MD14 is further configured to perform digital authentication of the user by comparing at least one fingerprint acquired by the fingerprint sensor 8 (after the authentication phase performed by the first authentication module MD2) with digital enrollment data DREF2, which in this example can be referenced by the smart card CD1 in the memory MR1 of the smart card CD1.

[0084] As indicated above, the smart card CD1 is configured to authenticate a user UR (FIG. 1) before (or possibly in parallel with) the execution of a digital registration phase for said user UR from the sequence SQ1 of the object print PT1 acquired by the fingerprint sensor 8. For this authentication phase to pass successfully, this sequence SQ1 must match a reference sequence SQ0 defined by reference data DREF1 pre-recorded in the smart card CD1.

[0085] Generally, the reference sequence SQ0 defined by the reference data DREF1 consists of a plurality of object fingerprints PT1 created over time according to a predetermined order, with a respective print type (i.e., TY1 or TY2 in the following example) assigned to each of the object prints of the reference sequence SQ0. In other words, according to the reference data DREF1, each object print of the reference sequence SQ0 is of a respective print type. This implies that not all object prints PT1 constituting the reference sequence SQ0 are acquired simultaneously, but rather that this sequence includes at least two object prints PT1 acquired one after the other over time in a predetermined order.

[0086] The nature of the reference sequence SQ0 that the user UR needs to execute against the fingerprint sensor 8 to authenticate himself may vary depending on the case, and some exemplary implementations are described below: In particular, the types of object prints PT1 (especially the nature of those types and the number of different types) or the organization of the object prints PT1 over time within the reference sequence SQ0 may vary depending on the desired implementation.

[0087] 4A shows a specific example of a reference sequence SQ0 that must be followed by a sequence SQ1 of object fingerprints PT1 performed by a user UR during a period PR1 during the authentication phase prior to the enrollment phase (or at least prior to the completion of this enrollment phase). This sequence SQ0 includes object prints PT1 of two different print types TY1 and TY2. Here, for example, let us assume that the first print type TY1 corresponds to an arbitrary fingerprint FG (corresponding to an arbitrary finger), while the second print type TY2 corresponds to an arbitrary tool TL1 (without minutiae characterizing the object's surface). By way of example, this reference sequence SQ0 is composed of object prints PT1 of the following types over time: TY1-TY2-TY1-TY1-TY2-TY1. In this example, the object prints PT1 must be detected one after the other during the period PR1. To successfully authenticate himself, the user UR must therefore present, for example, an arbitrary finger, then a tool without minutiae, then an arbitrary finger twice in succession, then a tool without minutiae, and then an arbitrary finger again.

[0088] At the stage of the authentication phase before the digital registration phase (or at least before the completion of the digital registration phase), the smart card CD1 does not have a template of the cardholder's fingerprint in its memory, but it is able to recognize whether the object print PT1 corresponds to a finger (first type TY1) or a tool (second type TY2), for example, depending on whether minutiae are detected in each print acquired.

[0089] In some embodiments, the reference sequence SQ0 followed during the authentication phase prior to (or parallel to) the enrolment phase includes at least two print groups GP acquired sequentially over a period PR1, each print group GP including at least one object print PT1 acquired simultaneously by the fingerprint sensor 8.

[0090] 4B shows a reference sequence SQ0 according to a specific example that must be followed by a sequence SQ1 of object prints PT1 executed by a user UR during a period PR1 during an authentication phase prior to the enrollment phase (or at least prior to the completion of this enrollment phase), this sequence SQ0 comprising object prints PT1 of two different print types TY1 and TY2. In this example, it is assumed that the first print type TY1 corresponds to a fingerprint corresponding to a first arbitrary finger (i.e., a fingerprint characterized by a first minutiae of the first arbitrary finger), and the second print type T2 corresponds to a fingerprint corresponding to a second arbitrary finger different from the first finger (i.e., a fingerprint characterized by a second minutiae of the second arbitrary finger). In this case, the use of a tool TL1 is not necessary to enable the user UR to authenticate himself / herself by means of the fingerprint sensor 8, although variants are possible in which the reference sequence SQ0 comprises at least two different print types (called the first print type and the second print type) and at least one tool print of a third print type.

[0091] As will be described in more detail later, the reference sequence SQ0 shown in FIG. 4B does not define which specific fingers (or which feature points) must be detected to authenticate the user UR, but more generally defines a given transition of fingerprint types corresponding to several distinct fingers, possibly any of which fingers, as long as the transition of print types defined by the reference sequence SQ0 is followed.

[0092] Continuing with the example of FIG. 4B , the reference sequence SQ0 followed during an authentication phase preceding (or parallel to or concomitant with) the enrollment phase may include print groups GP sequentially acquired by fingerprint sensor 8 during period PR1, with each print group GP including a fingerprint with print types among TY1 and TY2, or two prints with print types TY1 and TY2 detected simultaneously. Alternatively, group GP may include three or more fingerprints acquired simultaneously by fingerprint sensor 8. To do so, fingerprint sensor 8 may be configured to allow two fingerprints (or more) to be captured simultaneously by placing two (or more) fingers side-by-side on fingerprint sensor 8 (or within its detection area).

[0093] 4B is composed of the following types of object prints PT1 over time: TY1-TY2-[TY1,TY2]-TY1-[TY1,TY2]-TY2, where the reference to [TY1,TY2] indicates that the fingerprint sensor 8 simultaneously captures a first object print PT1 of a first type TY1 and a second object print PT1 of a second type TY2. Thus, to successfully authenticate himself, the user UR must present, for example, a first arbitrary finger FG1, then a second arbitrary finger FG2 (different from the first finger), then the first finger FG1 and the second finger FG2 simultaneously, then the first finger FG1, then again the first finger FG1 and the second finger FG2 simultaneously, then the second finger FG2.

[0094] As already indicated, at the stage of the authentication phase preceding (or parallel to or concomitant with) the digital enrolment phase, the smart card CD1 does not have in memory a template of the cardholder's fingerprint, but can be configured to recognise whether each object print PT1 acquired as part of the sequence SQ1 is a fingerprint or a tool print, for example depending on the presence or absence of minutiae in the print, or to recognise that several acquired fingerprints PT1 correspond to the same finger (depending on the minutiae characterising those prints). The smart card is therefore able to detect transitions between print types defined by the sequence SQ1 of object prints PT1.

[0095] Thus, a user UR of smart card CD1 (Fig. 1) can make various combinations of object prints (with one or several fingers and / or with one or several tools) according to the sequence SQ1 of prints over time in order to authenticate himself with smart card CD1, without smart card CD1 having in its memory at this stage a template of the cardholder's fingerprint. Now, an exemplary embodiment of the inventive processing method is described below, which, by using the fingerprint sensor 8, allows smart card CD1 to authenticate user UR before his digital registration (or at least before the completion of his finger registration).

[0096] An embodiment of the present invention is described below with reference to Figure 5. More specifically, the smart card CD1 described above with reference to Figures 1 to 4 implements the processing method of the invention according to a particular example by executing a program PG1.

[0097] Let us assume that the user UR wants to personalize the smart card CD1 by digitally registering it in order to store in it one or several fingerprint templates that will serve as reference data for later authenticating the user UR. To do so, in this example the smart card CD1 is coupled to a peripheral device DV1, which thereby powers the smart card CD1, although other examples are possible in which there is no such peripheral device DV1.

[0098] The smart card CD1 is first considered to be in an initial state, in which the card contains reference data DREF1 in its memory but has not yet undergone the registration phase of the user UR. In other words, the smart card CD1 does not have in its memory a template of the fingerprint of the user UR. The smart card CD1 therefore executes a processing method according to a particular example in order to securely register at least one fingerprint of the user UR.

[0099] 5, during an authentication stage S2 (before the digital registration stage S10 or at least upon completion of this digital registration stage S10), the smart card CD1 verifies the authenticity of the user UR from the object print PT1 acquired by the user UR's fingerprint sensor 8. To do so, the authentication stage S2 comprises steps S4, S6 and S8 described below.

[0100] During the acquisition step S4, the smart card CD1 acquires a sequence SQ1 of object prints PT1 from the object detected over time by the fingerprint sensor 8. By way of example, it is considered that the acquisition S4 of the sequence SQ1 takes place over a period PR1, which may vary depending on the case and may be suitable to those skilled in the art.

[0101] As already mentioned, the type of object print PT1 obtained at S4 in the sequence SQ1 can vary depending on the case and may depend, among other things, on the nature of the object used to generate each print. The user UR can, among other things, present objects (one or several fingers and / or one or several tools) one after the other or in groups of two or more successively in the detection field of the fingerprint sensor 8. To do so, it is assumed by way of example that the user UR places each object in contact with the fingerprint sensor 8, although variants are also possible in which object prints are obtained without the need for contact of the object with the sensor 8.

[0102] 4A-4B, in particular, the sequence SQ1 may include a number of different types of object prints (e.g., at least two different types). Furthermore, the sequence SQ1 may be divided into several successive acquisition steps, so that one or several object prints are acquired by the fingerprint sensor 8 in each of these acquisition steps. In the case of multiple acquisitions of prints, all prints are acquired simultaneously during the acquisition step under consideration. Thus, according to one particular example, the sequence SQ1 of object prints acquired in S4 includes at least two groups of prints acquired sequentially over time (during successive acquisition steps), each group of prints including at least one object print acquired simultaneously by the fingerprint sensor 8.

[0103] During the comparison step S6, the smart card CD1 compares the sequence SQ1 of the object print PT1 obtained in S4 with the reference data DREF1. In this example, the reference data DREF1 is pre-recorded in the smart card CD1. To do so, the method may comprise a preliminary step (not shown) before the authentication phase S2 (or at least before the comparison step S6) of recording the reference data DREF1, in this example, in the memory MR1 of the smart card CD1.

[0104] During the analysis step S8, the smart card CD1 determines that the authentication step S2 has been passed successfully if the print sequence SQ1 matches the reference sequence SQ0 defined by the reference data DREF1. In other words, the user UR is successfully authenticated if the print sequence SQ1 does not match the reference data DREF1. On the other hand, if the sequence SQ1 does not match the reference sequence SQ0, the authentication step S2 is considered to have failed.

[0105] For example, it is assumed that the reference data DREF1 defines a reference sequence SQ0 of object prints of at least two different print types TY1 and TY2. In other words, the reference sequence SQ0 forms a series of object prints that includes object prints of at least two different kinds TY1 and TY2. For simplicity, it is assumed here that the reference sequence SQ0 includes only these two different kinds TY1 and TY2, but other implementations with more than two different print types are possible.

[0106] During the authentication phase S2, the smart card CD1 does not yet have in its memory a fingerprint template to serve as reference data for authenticating the cardholder. As explained above, the reference data DREF1 defines a reference sequence SQ0 formed of a plurality of object prints PT1 created over time according to a predefined order, each of the object prints of the reference sequence SQ0 being assigned a respective print type (i.e. TY1 or TY2 in this example). Furthermore, during the comparison step S6, the smart card CD1 does not know the cardholder's real fingerprint, but verifies that the sequence SQ1 of object prints obtained in S4 follows the evolution (or changes) of the print types defined in the reference sequence SQ0.

[0107] According to one particular example, during the comparison step S6, the smart card CD1 the sequences SQ0 and SQ1 contain the same number of object prints PT1, and The object print PT1 constituting the acquired sequence SQ1 follows the transition of the print type defined by the reference sequence SQ0. Match the.

[0108] If these checks pass successfully, the smart card CD1 detects in S8 that the authentication step S2 has been successful.

[0109] 4A, the reference sequence SQ0 defines object prints with two print types TY1 and TY2, which correspond to an arbitrary fingerprint and an arbitrary tool print, respectively. In this example, the smart card CD1 verifies in S6 that the acquired sequence SQ1 includes six consecutive object prints PT1, and that these prints correspond consecutively to an arbitrary fingerprint FG, an arbitrary tool print TL1, and twice consecutively to an arbitrary fingerprint FG, an arbitrary tool print TL1, and an arbitrary fingerprint FG (FG-TL1-FG-FG-TL1-FG). To do this, the smart card CD1 can temporarily record the object prints PT1 acquired in S4 (e.g., in its RAM4) so ​​that it can determine the type of the object prints PT1 acquired in S4 and verify that these object prints PT1 follow the reference sequence SQ0. As described below, the smart card CD1 checks each acquired object print PT1 to see if it contains minutiae that characterize a fingerprint, and if so, can determine that said print constitutes a fingerprint (otherwise said print is a tool print).

[0110] For example, in the example shown in FIG. 4B, the reference sequence SQ0 defines two object prints of print types TY1 and TY2, corresponding to fingerprints corresponding to a first given finger and a second given finger different from the first finger. In this example, the smart card CD1 verifies in S6 that the acquired sequence SQ1 includes six consecutive groups of at least one fingerprint according to the reference sequence SQ0 shown in FIG. 4B. To do so, the smart card CD1 can temporarily record (e.g., in its RAM4) the object prints PT1 acquired in S4 so as to verify that the object prints PT1 acquired in S4 are fingerprints and recognize fingerprints corresponding to the same finger and therefore belonging to the same type (TY1 or TY2 in this example) within the sequence SQ1. As described below, the smart card CD1 does not have a template of the cardholder's fingerprints in its memory, but can analyze the minutiae in each acquired object print PT1 and determine from them which fingerprints correspond to the same finger and therefore belong to the same type.

[0111] In particular, smart card CD1 is able to verify that object print PT1 acquired at S4 in sequence SQ1 is in fact a fingerprint, since it detects minutiae that characterize each print. Upon detecting the characteristics of the finger minutiae, smart card CD1 determines that object print PT1 constitutes a fingerprint. As described below, smart card CD1 can further compare fingerprints PT1 in sequence SQ1 to identify prints that correspond to the same finger, and therefore the same print type (TY1 or TY2 in this example).

[0112] Continuing with reference to Figure 5, the smart card CD1 also triggers a digital enrolment step S10 comprising steps S14 and S16 described below. Variations are also possible in which the enrolment step S10 further comprises an acquisition step S12, as described below.

[0113] By way of example, we consider here that in response to determining in S8 that authentication step S2 was successful, smart card CD1 triggers a digital registration step S10. Since user UR has been successfully authenticated and is considered to be the cardholder, this registration step S10 therefore enables digital registration of holder UR to be carried out. It is therefore possible to secure the digital registration process of user UR on smart card CD1. However, as will be described later, variants are also possible in which registration step S10 is triggered before the completion of authentication step S2, and therefore before smart card CD1 determines in S8 that authentication step S2 was successful. It is therefore also possible for registration step S10 to be carried out in parallel (concomitantly) with step S2.

[0114] Thus, during the generation step S14, the smart card CD1 generates digital enrolment data DREF2 which it records (S16) from at least one fingerprint PT2, called enrolment fingerprint, thereby allowing subsequent digital authentication from these digital enrolment data PT2. Such subsequent digital authentication is only possible if the authentication result in S8 has passed successfully. As already indicated, the digital enrolment data DREF2 is recorded, for example, in the memory MR1 of the card.

[0115] As an example, it will be assumed below that smart card CD1 generates digital enrollment data DREF2 from a plurality of enrollment fingerprints PT2. As will be described below, these enrollment prints PT2 can be obtained by smart card CD1 in various ways. The digital enrollment data DREF2 can be generated, for example, by aggregating the enrollment fingerprints PT2 (or data characteristics of those prints). Various processing operations can be performed by smart card CD1 to obtain the digital enrollment data DREF2 from the enrollment fingerprints PT2.

[0116] According to a particular example, the at least one digital enrollment print PT2 from which the digital enrollment data DREF2 are generated in S14 is the fingerprint PT1 obtained in S4 from among the sequence of object prints SQ1. In other words, the smart card CD1 uses as enrollment fingerprint PT2 the at least one object print PT1 (more specifically a fingerprint) obtained in S4 during the authentication phase S2 in order to generate the digital enrollment data DREF2 in S14. Thus, insofar as the same fingerprint obtained by the fingerprint sensor 8 can be used both for authenticating the user UR during the authentication phase S2 and for enrolling the fingerprint of the user UR, the digital enrollment process can be accelerated while ensuring a good level of security.

[0117] According to a particular example, each enrollment fingerprint PT2 used in S14 to generate digital enrollment data DREF2 is a fingerprint PT1 of the sequence of object prints SQ1 obtained in S4 during the authentication phase S2. In this case, the generation S14 of the digital enrollment data DREF2 (and more generally the digital enrollment phase S10) can be triggered by the smart card CD1 before determining in S8 whether the authentication phase S2 has been successful (i.e. before the completion of the authentication phase S2). The enrollment phase S10 can therefore be performed in parallel (concomitantly) with the authentication phase S2. Advantageously, the execution of the authentication phase S2 can be made transparent to the user UR, who then does not necessarily realize that the fingerprint he presents to the fingerprint sensor 8 serves both to authenticate and to perform his digital enrollment on the card.

[0118] As indicated above, the enrollment fingerprints PT2 used during the enrollment phase S10 can be obtained at various stages of the method. According to one particular example, at least one of the enrollment fingerprints PT2 from which the digital enrollment data DREF2 are generated in S14 is a fingerprint PT2 acquired during an acquisition step S12 during the enrollment phase S10, independently of the acquisition S4 of the sequence SQ1. Thus, during the enrollment phase S10, the smart card CD1 can acquire by the fingerprint sensor 8 at least one fingerprint as enrollment fingerprint PT2, independently of the acquisition S4 of the sequence SQ1 of object prints PT1 (S12). In this way, the enrollment fingerprint PT2 obtained during acquisition S12 is used for the digital enrollment of the user UR during the enrollment phase S10, but does not play a role in authenticating this user UR during the authentication phase S2.

[0119] According to one particular example, the smart card CD1 uses at least one fingerprint PT1 obtained in S4 during the authentication stage S2 as an enrolment fingerprint PT2 in order to generate in S14 the digital enrolment data DREF2, and further performs an acquisition step S12 in order to obtain at least one additional enrolment fingerprint PT2 independently of the sequence SQ1 obtained in S4. For example, to enrol a user UR, it is possible to authenticate the user UR in S2 from a given number of fingerprints and use these fingerprints (or at least some of them) plus the additional fingerprints obtained during the enrolment stage S10.

[0120] According to one particular example, all enrollment fingerprints PT2 from which digital enrollment data DREF2 are generated in S14 are fingerprints PT2 acquired during acquisition step S12 in enrollment phase S10, independently of acquisition S4 of sequence SQ1. Enrollment phase S10 can be performed in parallel with or after authentication phase S2. In particular, enrollment phase S10 can be initiated in response to a determination in S8 that authentication phase S2 has been successfully passed, as already indicated.

[0121] Once the enrollment stage S10 is complete and it is determined at S8 (FIG. 5) that the authentication stage S2 has been successfully passed, the smart card CD1 has in its memory digital enrollment data DREF2 that can be used as a print template during a subsequent authentication stage to verify the authenticity of the user UR. Thus, as shown in FIG. 5, the method can continue, for example, after the authentication stage S2 with a second authentication stage S18. During this authentication stage S18, the smart card CD1 acquires (S20) at least one new fingerprint PT3 (single or multiple, depending on the case) by means of the fingerprint sensor 8 and then performs authentication (S22) by comparing said at least one new fingerprint PT3 with the digital enrollment data DREF2 recorded at S16 during the enrollment stage S10. In particular, the smart card CD1 can determine in S22 whether said at least one new fingerprint PT3 is valid by comparing said at least one new fingerprint PT3 with the digital enrollment data DREF2. Said at least one new fingerprint PT3 is determined to be valid if it matches (or matches) the digital enrolment data DREF2. If multiple new fingerprints PT3 are obtained in S20, it can be considered that e.g. authentication S22 has passed successfully if all the new fingerprints PT3 (or at least a predetermined number of them) match the digital enrolment data DREF2, otherwise the authentication is considered to have failed.

[0122] As indicated above, variants are notably possible in which the enrollment stage S10 is not initiated in response to a determination at S8 that the authentication stage S2 has been successfully passed, but is initiated upstream of decision S8 so as to be executed in parallel with the authentication stage S2. In this case, the smart card CD1 can therefore optionally perform steps S12 and S14 to record the digital enrollment data DREF2 (all or part) before the authentication stage S2 is completed, i.e. even before the result of the authentication stage S2 is determined at S8. Furthermore, during the enrollment stage S10, the smart card CD1 can perform an erasure step (not shown) in response to a determination at S8 that the authentication stage S2 has failed. During this erasure step, the smart card CD1 erases (deletes) the digital enrollment data DREF2 previously recorded at S16 from its memory, which makes it possible to secure the digital enrollment process in case the user UR cannot be successfully authenticated.

[0123] Furthermore, according to a particular example, the reference sequence SQ0 defined by the reference data DREF1 includes multiple object prints PT1, such that at least one object print PT1 of a first print type TY1 is placed between at least two object prints PT1 of another print type TY2 over time. The reference sequence SQ0 thus defines a transition between several print types (at least two different print types), which allows the authentication of the user UR, and thus the digital registration process, to be secure. Indeed, during the digital registration phase, it may seem more ergonomic and intuitive for the user UR to present the same first finger several times and then present another second finger several times without having to reacquire the first finger (which would mean making the acquisition a "back and forth" operation between several fingers). This is explained by the fact that the goal of digital registration is not, in theory, to authenticate the user, but to acquire the user's fingerprint to subsequently serve as a print template. However, it is possible according to the invention to complicate the acquisition of fingerprints PT1 during authentication stage S2 by using a complex reference sequence SQ0 which requires a "back and forth" operation of acquisition between several different fingerprint types, which fingerprints may further serve at least in part to generate digital enrollment data DREF2 during enrollment stage S10. Thus, the digital enrollment is secure while limiting the number of fingerprints that must be acquired by the card.

[0124] Other variations of the implementation of the embodiment described above in FIG. 5 will now be described below with reference to FIGS.

[0125] According to a particular example, smart card CD1 (FIGS. 1-3) executes the processing method shown in FIG. 5, and the reference sequence SQ0 defined by reference data DREF1 is the one shown in FIG. 4A. During the authentication phase S2, smart card CD1 executes steps S30 and S32, and possibly also step S34, as described below.

[0126] More specifically, during the analysis step S30, the smart card CD1 analyzes each object print PT1 constituting the sequence SQ1 acquired in S4 to determine whether said object print PT1 contains fingerprint feature points. In particular, the smart card CD1 determines whether there are feature points characterizing the fingerprint (finger surface) in each acquired object print PT1. In a known manner, any fingerprint essentially contains feature points, i.e. characteristic points formed by a particular arrangement of nipple lines. These feature points characterize the singularities or irregularities formed by nipple lines (ends, bifurcations, islands, etc.).

[0127] During the identification (or classification) step S32, the smart card CD1 identifies each object print PT1 of the sequence SQ1 as either a tool print corresponding to a first print type or as a fingerprint corresponding to at least one other print type, depending on whether said object print PT1 contains a minutiae. By way of example, it is assumed here that the smart card CD1 classifies in S32 each object print PT1 of the sequence SQ1 obtained in S4 as either a fingerprint corresponding to a first print type TY1 or as a tool print corresponding to a second print type TY2, depending on whether said object print PT1 contains a minutiae. It is noted, however, that variants are also possible in which, in addition to the print type corresponding to the tool print, several different print types (shown for example as TY1a, TY1b, etc.) corresponding to the fingerprints of various fingers may be defined within the reference sequence SQ0.

[0128] Thus, during an identification step S32, the smart card CD1 identifies the print type of each object print PT1 of the sequence SQ1 from the result of the analysis step S30. If the object print PT1 contains a feature point representative of the surface of a finger, the smart card CD1 determines that said print is a fingerprint (of type TY1), denoted by PT1a. If there is no such feature point, the smart card CD1 determines that the considered object print PT1 is a tool print (of type TY2), denoted by PT1b, representing a tool (not a finger).

[0129] Thus, during the comparison S6 carried out within the authentication stage S2 (Figure 5), the smart card CD1 compares the sequence SQ1 containing fingerprints of the first print type and at least one other print type mentioned above (i.e. prints of types TY1 and TY2 in this example) with a reference sequence SQ0 containing prints of the first print type and at least one other print type mentioned above (i.e. prints of types TY1 and TY2 in this example).

[0130] According to a variant, the smart card CD1 further carries out a determination step S34 (FIG. 6) during the authentication phase S2, during which the card determines from the result of the identification S32 the values ​​of a series SR1 (also called classification code) representing the sequence SQ1 of object prints obtained in S4. This series SR1 values ​​comprises at least a first value V1 and a second value V2 different from the first value V1, so that each object print PT1 identified in S32 as a fingerprint PT1a is indicated by the occurrence of the first value V1 in the series of values ​​SR1, and each object print PT1 identified in S32 as a tool print PT1b is indicated by the occurrence of the second value V2 in the series of values ​​SR1. In other words, the series SR1 comprises, for each object print PT1, a value representative of the type identified for said print, the values ​​being ordered according to the order in which the object prints PT1 were obtained in S4.

[0131] As an example, V1=1 and V2=0 are chosen, but other implementations are possible. Each type of object print PT1 can therefore be coded on one bit, and the value of the series SR1 comprises consecutive bits representing each type of object print PT1 respectively according to the order in which the object prints PT1 were obtained in S4. The values ​​used to code the series SR1 as well as the number of values ​​can be adapted depending on the case, in particular depending on the number of different types of object prints given in the reference sequence SQ0.

[0132] The smart card CD1 may for example temporarily record the object prints PT1 acquired during acquisition S4 in order to perform classification S32 and generate the series SR1 (S34). Classification S32 and possibly also determination S34 may be performed dynamically when the object prints PT1 are acquired in S4, or possibly once acquisition S4 is complete.

[0133] According to this variant, the smart card CD1 then performs a comparison S6 (FIG. 5) from the values ​​of the series SR1 obtained in S34. More specifically, the smart card CD1 compares the values ​​of the series SR1 with the reference data DREF1 (S6). To do so, the reference data can define a series of values ​​including a first value V1 and a second value V2 as a reference sequence SQ0. The reference data DREF1 can form a series of reference values ​​equal to V1 or V2, for example, and this series can have the same format as that of the series SR1.

[0134] According to a particular example, it is considered that the smart card CD1 (FIGS. 1 to 3) executes the processing method shown in FIG. 5, the reference sequence SQ0 defined by the reference data DREF1 being the one shown in FIG. 4B. In the example considered here, during the authentication phase S2, the smart card CD1 executes the analysis step S40 and the comparison step S42 shown in FIG. 7.

[0135] More specifically, during the analysis step S40, the smart card CD1 analyzes each object print PT1 of the sequence SQ1 of object prints acquired in S4 (FIG. 5) in order to identify minutiae (or fingerprint characteristics) within the fingerprints of the sequence SQ1. As an example, let us assume that all object prints PT1 are fingerprints PT1a resulting from the corresponding fingers detected by the fingerprint sensor 8 during acquisition S4. If no fingerprint minutiae characteristics can be identified within a given object print PT1 in S40, the smart card CD1 deduces from this that it is not a fingerprint or does not have sufficient quality to continue with the method. In this case, the smart card CD1 can optionally request a new acquisition of the print under consideration or of all prints of the sequence SQ1, or even terminate the method. However, variants are also possible in which, among the object prints PT1 contained in the sequence SQ1 acquired in S4, several are fingerprints PT1a and at least one is a tool print PT1b. In this particular case, smart card CD1 detects the object prints PT1 that make up fingerprint PT1a in S40 (FIG. 7) and processes them by performing a comparison step S42 that follows on the fingerprints PT1a thus identified. Tool print PT1b, identified in sequence SQ1, can also be processed as above as belonging to the corresponding print type.

[0136] During the analysis S40, the smart card CD1 can perform any suitable processing on the fingerprints PT1a to identify the characteristic points formed by the nipple lines of the fingers. For each fingerprint PT1a, the smart card CD1 can determine a model of the characteristic points representing, for example, the fingers of the user UR.

[0137] According to one particular example, the smart card CD1 temporarily records (for example in its RAM memory 4) the object print PT1 acquired during acquisition S4 in order to be able to carry out the analysis S40.

[0138] During the comparison step S42, the smart card CD1 compares the fingerprints PT1a of the sequence SQ1 from the minutiae identified in S40 in order to identify at least two different fingerprint types (denoted TY1 and TY2) corresponding to at least two different fingers. Thus, the smart card CD1 cannot verify that the fingerprint is actually that of the user UR under consideration, but it can distinguish within the sequence SQ1 different fingerprint types PT1a corresponding to different fingers. This comparison step S42 therefore makes it possible to determine the individual print type of each fingerprint of the sequence SQ1. In this example, it is assumed that the sequence SQ1 contains fingerprints PT1a with two different print types TY1 and TY2, but other implementations with a larger number of different print types (and possibly even mixing tool prints PT1b corresponding to other print types) are possible.

[0139] As already explained, smart card CD1 does not have a reference template of the fingerprint of card user UR, since the digital enrollment phase for that user UR has not yet taken place (as already indicated, the enrollment phase S10 can optionally start before the result of authentication phase S2 is available in S8, but digital enrollment does not take place until this result is available). Smart card CD1 therefore compares the minutiae of the fingerprints PT1a of sequence SQ1 to determine which fingerprints correspond to the same finger and therefore to the same print type. To do so, smart card CD1 applies an algorithm for assessing the similarity of the fingerprints PT1a of sequence SQ1 from their minutiae, for example, in order to determine which type each of the fingerprints PT1a belongs to (i.e., TY1 or TY2 in this example).

[0140] Thus, during the following comparison step S6 (FIG. 5), a print sequence SQ1 containing two different print types TY1, TY2 (or at least these two varieties TY1, TY2) is compared with a reference sequence SQ0 defined by reference data DREF1. In this example, we consider that the reference sequence SQ0 contains prints with two different print types TY1, TY2 corresponding to two different fingers (which may be arbitrary), but other implementations are possible in which the reference sequence SQ0 contains more different print types (and possibly even mixes tool prints that fit into different print types).

[0141] According to a particular example, the smart card CD1 performs steps S44 and S46 (FIG. 7) during the comparison step S42. During the identification step S44, the smart card CD1 identifies an individual fingerprint PT1a of the sequence SQ1 as a print template for each of the at least two different fingerprint types mentioned above (i.e., in this example, the two print types TY1 and TY2) if (or when it detects) that said fingerprint corresponds to a finger detected for the first time in the sequence SQ1. By "first detected finger" it is meant that the fingerprint PT1 corresponding to the finger under consideration appears for the first time in the sequence SQ1. Thus, by way of example, it is now considered that the smart card CD1 detects in S44 in the sequence SQ1 a first fingerprint PT1a_1 (and separately a second fingerprint PT1a_2) corresponding to a first finger (and separately a second finger different from the first finger) detected for the first time in the sequence SQ1 over time. The smart card CD1 then identifies the first fingerprint PT1a_1 and the second fingerprint PT1a_2 as print templates of the first type TY1 (corresponding to the first finger) and the second type TY2 (corresponding to the second finger), respectively.

[0142] Thus, during a comparison step S46 (Fig. 7), the smart card CD1 compares each print template identified in S42 (i.e. fingerprints PT1a_1 and PT1a_2 in this example) with the other fingerprints PT1a of the sequence SQ1 obtained in S4 (Fig. 5), thereby identifying each such other fingerprint as one of said at least two different fingerprint types. The invention therefore makes it possible to reliably and efficiently distinguish between different fingerprint types corresponding to different fingers within the sequence SQ1, and this is done without the card having in its memory at this stage a template of the user's fingerprint, i.e. a fingerprint template as reference digital data.

[0143] Optionally, the two steps S44 and S46 can be performed simultaneously (in parallel) during the comparison step S42. To do so, the smart card CD1 can successively analyze each fingerprint PT1a occurring in chronological order in the sequence SQ1 acquired in S4 (FIG. 5) and compare said print with one or several print templates already identified, if necessary, during the identification step S44, to determine whether said print constitutes a template of a new fingerprint type corresponding to a new finger detected for the first time in the sequence SQ1, or whether it constitutes a fingerprint that matches a previously identified print template in the sequence SQ1. In other words, the smart card CD1 recognizes each fingerprint PT1a acquired over time, for example during the acquisition period PR1, that does not correspond to any existing fingerprint template as a print template representing a new print type. This process is performed for each fingerprint PT1a acquired in the sequence SQ1 in the order in which the fingerprints were acquired in S4. Thus, the type of each fingerprint PT1a forming the sequence SQ1 can be determined.

[0144] According to a variant, the smart card CD1 identifies in S44 (FIG. 7) at least the first fingerprint PT1a_1 and the second fingerprint PT1a_2 in the print sequence SQ1 as print templates of at least two different fingerprint types corresponding to at least two different fingers, due to their respective positions in the print sequence SQ1 obtained in S4. Thus, during the comparison step S46, the smart card CD1 compares these first fingerprint PT1a_1 and second fingerprint PT1a_2 serving as print templates with the other fingerprints PT1a of the print sequence SQ1, thereby being able to identify each of said other fingerprints PT1a as one of said at least two different fingerprint types corresponding to at least two different fingers.

[0145] Thus, by way of example, smart card CD1 may identify (S44) the first two fingerprints PT1a acquired over time in sequence SQ1, i.e., during preliminary phase PR2 of period PR1 (FIG. 4B), as fingerprint templates representing print types TY1 and TY2, respectively. The two initial fingerprints that start sequence SQ1 optionally serve as templates to which each other fingerprint PT1a in sequence SQ1 is compared (S46) to determine its type from TY1 and TY2. Smart card CD1 may, for example, evaluate (S46) the similarity of each other fingerprint in sequence SQ1 to those two initial fingerprints, and the type of each other fingerprint is that of the closest of those two initial fingerprints.

[0146] Thus, the present invention generally allows for secure digital registration on a smart card that includes a fingerprint sensor, even when the smart card includes limited means of user interface, as is typically the case. In particular, the smart card's fingerprint sensor can be used to authenticate a user even before (or even in parallel with) the execution of the user's digital registration phase, thus eliminating the need for the smart card to have a template of the user's fingerprint in memory. The user can easily and ergonomically create a specific sequence of object prints using one or several fingers and / or one or several tools. If the sequence thus obtained by the smart card matches a reference sequence pre-recorded in the card, authentication is successful. Therefore, there is no need for the smart card to cooperate with a third-party terminal, such as a smartphone, that includes an advanced user interface, which limits the security risks associated with the digital registration process.

[0147] The present invention allows leveraging the fingerprint sensor of a smart card to authenticate a user even before the user has digitally registered themselves. In particular, the present invention allows authenticating a user by using a variety of objects, including tools other than a finger or any other anatomical site. A user can securely authenticate themselves with a smart card using a spoon or another everyday object, or even by using a dedicated tool (provided, for example, by the card's issuer).

[0148] The present invention makes it possible, inter alia, to secure the use of smart cards, and in particular the transactions processed by the card. Thus, once digital registration has been successfully carried out, the smart card is able to authenticate the user during the processing of a transaction. Depending on the result of the fingerprint verification carried out by its fingerprint sensor, the smart card according to the invention can, for example, accept or reject a transaction, which makes it possible to limit the risk of fraudulent use of the card.

[0149] 5, the smart card CD1 can generate the digital enrollment data DREF2 in S14 from one or several enrollment fingerprints PT2 acquired during the acquisition step S12. Furthermore, in order to accelerate the digital enrollment process while ensuring a high level of security, the smart card CD1 can use at least one object print PT1 previously acquired in S4 during the authentication phase as a replacement for, or as a complement to, or in addition to, the enrollment fingerprint PT2 acquired in S10, said at least one print PT1 corresponding to a fingerprint. In other words, the smart card CD1 can also use one or several fingerprints PT1 acquired during the authentication phase S2 to replace or complement the enrollment fingerprint PT2 from which the digital enrollment data DREF2 are generated. Insofar as the same fingerprint can be used both to authenticate the user UR during the authentication phase S2 and to enroll this same user UR during the digital enrollment phase S10, the enrollment process is improved (accelerated and secured).

[0150] According to a particular exemplary embodiment, the reference sequence SQ0 defined by the reference data DREF1 includes tool prints of at least two different print types. In this case, the smart card CD1 can detect and analyze the tool prints TL1 included in the sequence SQ1 acquired in S4 during the authentication stage S2 (FIG. 5) in order to identify which of the at least two different print types the said tool prints belong to. To do so, the smart card CD1 can, for example, analyze characteristics specific to the tool prints in order to distinguish between the at least two different tool types. In particular, the smart card CD1 can, for example, compare the tool prints detected in the sequence SQ1 (similar to fingerprints) in order to identify an individual print template for each print type corresponding to each tool considered, and to identify the type to which each other tool print in the sequence SQ1 relates by evaluating the similarity of each other tool print to each print template.

[0151] It should be noted that a user UR who wishes to register on a smart card CD1 as described above may be informed by the issuer of the card (for example by a bank) or by any other third party provided for this purpose of the reference sequence SQ0 to be followed during the authentication phase S2. The communication of this reference sequence SQ0 may be done in any suitable way, for example by any communication medium known to those skilled in the art other than the one in which the card is received, for example by post or by SMS sent to the communication terminal of the user UR.

[0152] As will be understood by those skilled in the art, the above-described embodiments and modifications merely constitute non-limiting exemplary implementations of the present invention, and in particular, those skilled in the art can consider any adaptation or combination of the above-described embodiments and modifications to meet very specific needs in accordance with the appended claims. [Explanation of symbols]

[0153] 2 processors 4 Volatile Memory 6 Non-volatile memory 8 Fingerprint Sensor 20 User Interface AL1 Internal power supply CD1 Smart Card DREF1 First reference data DREF2 Second reference data DV1 Peripheral Devices FG finger FG1 First finger FG2 Second finger INT1 communication interface MD2 First Authentication Module MD4 first acquisition module MD6 first processing module MD8 Enrollment Module MD10 Second Acquisition Module MD12 Second Processing Module MD14 Secondary Authentication Module MR1 Rewritable Non-Volatile Memory PG1 Computer Program PR1 period PT Object Print PT1 Object Print PT1a fingerprint PT1a_1 First Fingerprint PT1a_2 Second Fingerprint PT1b Tool Print PT2 Object Print PT3 New Fingerprint S2 Authentication Stage S4 Acquisition step S6 Comparison Step S8 Analysis Step S10 Registration stage S12 Acquisition step S14 Generation step S16 Record S18 Second authentication stage S20 acquisition S22 Certification S30 Analysis Step S32 Identification Step S34 Decision Step S40 Analysis Step S42 Comparison Step S44 Identification step S46 Comparison Step SR1 series SQ0 Reference Sequence SQ1 Sequence TL1 Tools TY1 First Print Type TY2 Second print type UR User V1 First value V2 Second value

Claims

1. A processing method implemented by a smart card (CD1) including a fingerprint sensor (8), comprising: a1) obtaining (S4) a sequence (SQ1) of object prints (PT1) from an object detected over time by said fingerprint sensor (8); a2) comparing (S6) said acquired sequence (SQ1) of object prints with reference data (DREF1) pre-recorded in said smart card (CD1), said reference data (DREF1) defining a reference sequence (SQ0) of object prints according to at least two different print types (TY1, TY2); and a3) determining that the authentication step is successful if the sequence (SQ1) of the object print matches the reference data (DREF1) (S8); a) an authentication stage (S2) including: b1) generating (S14) digital enrollment data (DREF2) from at least one fingerprint (PT2), called the enrollment fingerprint; and b2) recording said digital enrolment data (DREF2) to enable subsequent digital authentication from said digital enrolment data (S16); b) a digital registration step (S10) including A method comprising:

2. The method further comprises, before the authentication step: - recording said reference data (DREF1) in the memory of said smart card (CD1); The method of claim 1 , comprising:

3. 2. The method of claim 1, wherein the reference sequence (SQ0) to be followed during the acquisition stage (S4) comprises at least two print groups (GP) acquired sequentially over time, each print group (GP) comprising at least one object print (PT1) acquired simultaneously by the fingerprint sensor (8).

4. During said registration step b), b0) said acquiring said sequence of object prints a1) independently of (S4) acquiring by said fingerprint sensor at least one fingerprint (PT2) as an enrollment fingerprint; The method of claim 1 , comprising:

5. 2. The method of claim 1, wherein at least one of the enrollment fingerprints from which the digital enrollment data is generated in b1) is a fingerprint (PT2) obtained in a1) (S4) from among the sequence (SQ1) of object prints.

6. The recording step (b2) is performed before the determining step (a3), and the digital registration step (S10) comprises: b3) erasing the digital enrollment data (DREF2) in response to the determination in a3) that the authentication step failed. The method of claim 1 , further comprising after said recording b2).

7. 2. The method of claim 1, wherein the enrollment step b) (S10) is triggered in response to the determination (S8) in a3) that the authentication step (S2) is successful.

8. 2. The method of claim 1, wherein, according to said reference sequence (SQ0), an object print of a first print type (TY1) is placed in time between two object prints of another print type (TY2).

9. The method of claim 1, wherein each object detected by the fingerprint sensor in a1) is a finger (FG) or a tool (TL1).

10. The authentication step (S2) - a1) analyzing (S30) each object print (PT1) of said sequence (SQ1) of object prints acquired in order to determine whether said object print contains feature points; - identifying (S32) each object print (PT1) of said acquired sequence (SQ1) of object prints as a tool print (TL1) corresponding to a first print type or as a fingerprint (FG) corresponding to at least one other print type, depending on whether said object print contains feature points; Including, During the comparison a2) (S6), the acquired sequence (SQ1) of object prints comprising prints of the first and the at least one other print type is compared with the reference sequence (SQ0) comprising prints of the first and the at least one other print type; 10. The method of claim 9.

11. The authentication step - determining (S34) a series (SR1) of values ​​representing said acquired sequence (SQ1) of object prints, wherein each object print identified as a fingerprint is represented in said series (SR1) of values ​​by the occurrence of a first value, and each object print identified as a tool print is represented in said series of values ​​by the occurrence of a second value different from said first value; Including, During said comparison a2) (S6), said series (SR1) of values ​​representing said acquired sequence (SQ1) of object prints is compared with said reference data (DREF1), which defines a sequence of values ​​comprising said first value and said second value as a reference sequence (SQ0); The method of claim 10.

12. The obtained sequence (SQ1) of object prints (PT1) comprises a fingerprint, and the authentication step a1) analyzing (S40) each object print (PT1) of the sequence (SQ1) of object prints acquired in (S4) to identify feature points within the fingerprint of the acquired sequence (SQ1) of object prints, - comparing (S42) said fingerprints of said sequence (SQ1) of object prints (PT1) obtained from said identified minutiae, thereby identifying at least two different fingerprint types (TY1, TY2) corresponding to at least two different fingers; Including, 2. The method of claim 1, wherein during the comparison a2) (S6), the acquired sequence (SQ1) of object prints comprising the at least two different fingerprint types (TY1, TY2) is compared with the reference sequence (SQ0) comprising fingerprints corresponding to at least two different fingers.

13. The authentication step (S2) - identifying (S44) an individual fingerprint of the acquired sequence of object prints for each of the at least two different fingerprint types (TY1, TY2) as a print template (PT1a_1, PT1a_2) if said fingerprint corresponds to a finger detected for the first time in the acquired sequence of object prints (SQ1); Including, each print template (PT1a_1, PT1a_2) is compared (S46) with other fingerprints in said sequence (SQ1) of object prints, thereby identifying each said other fingerprint as one of said at least two different fingerprint types (TY1, TY2); The method of claim 12.

14. A computer program (PG1) comprising instructions for carrying out the steps of the method according to any one of claims 1 to 13 when executed by a computer.

15. - a fingerprint sensor (8), an authentication module (MD2), - obtaining a sequence (SQ1) of object prints (PT1) from an object detected over time by said fingerprint sensor (8); Comparing said acquired sequence of object prints with reference data (DREF1) pre-recorded in a smart card, said reference data defining reference sequences (SQ0) of at least two different print types (TY1, TY2); and determining that the authentication phase is successful if said sequence (SQ1) of the object print (PT1) matches said reference data (DREF1); an authentication module (MD2) configured to: a registration module, generating digital enrolment data (DREF2) from at least one fingerprint (PT2), called enrolment fingerprint; and Recording digital enrolment data (DREF2) to enable subsequent digital authentication from said digital enrolment data a registration module configured to: A smart card (CD1) including: