Authentication system and authentication method
The authentication system uses a graph structure with secret sharing techniques to efficiently and securely authenticate individuals by reducing comparison nodes and enhancing security through distributed data storage.
Patent Information
- Application Number
- JP2023190385
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-07
- Publication Date
- 2025-05-19
- Estimated Expiration
- 2043-11-07
AI Technical Summary
Existing authentication systems face challenges in efficiently and securely authenticating individuals using biometric information, particularly in preventing data leakage and maintaining security in large-scale graph structures.
The proposed authentication system employs a graph structure with nodes representing individuals, where vector data generated from biometric information is divided into shares and stored across multiple servers using secret sharing techniques. This approach reduces the number of nodes to compare and enhances security by requiring data from multiple servers to restore the graph structure.
The system achieves efficient authentication by reducing comparison nodes and maintains high security by ensuring that even if data leaks from some servers, the graph structure cannot be restored without data from multiple servers.
Smart Images

Figure 2025077880000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to an authentication system and an authentication method.
Background Art
[0002] Patent Document 1 describes a technique for acquiring a face image of a user and authenticating the user using information on feature points included in the face image. [Prior Art Document] [Patent Document] [Patent Document 1] Japanese Patent Application Laid-Open No. 2021-170205
Summary of the Invention
Means for Solving the Problems
[0003] According to an embodiment of the present invention, an authentication system is provided. The authentication system may include a first server and a plurality of second servers. Each of the plurality of second servers includes a plurality of nodes corresponding to a plurality of people, and each of the plurality of nodes includes the plurality of nodes including vector data generated from biometric information of the corresponding person, and similar nodes are connected by links. For each of the plurality of nodes in the graph structure, one of the plurality of vector shares generated from the vector data and one of the plurality of link shares generated from link destination data indicating a link destination node may be stored. Each of the plurality of second servers may include a share storage unit that stores the vector share and the link share. Each of the plurality of second servers may include a share reception unit that receives one of the plurality of vector shares generated from the biometric information of the person to be authenticated. Each of the plurality of second servers may include an operation execution unit that executes an operation using the vector share received by the share reception unit and the vector share stored in the share storage unit. Each of the plurality of second servers may include a transmission unit that transmits the operation result by the operation execution unit and the link share to the first server. The first server may include a reception unit that receives the operation result and the link share from each of the plurality of second servers. The first server may include a determination unit that determines an authentication result of the person to be authenticated using the plurality of operation results received by the reception unit and the plurality of link shares.
[0004] In the authentication system, the share storage unit may store, for each of the plurality of nodes included in the graph structure, node identification data capable of identifying the node, one of the plurality of vector shares generated from the vector data included in the node, and one of the plurality of link shares generated from the link destination data included in the node.
[0005] In any of the authentication systems, the vector data may be generated by the plurality of vector shares generated from the vector data, and the linked destination data may be generated by the plurality of link shares generated from the linked destination data.
[0006] In any of the authentication systems, the first server may include a notification unit that transmits node identification data indicating any one of the plurality of nodes to the plurality of second servers. The receiving unit may receive, from each of the plurality of second servers, the calculation result and the link share corresponding to the node indicated by the node identification data transmitted by the node identification data transmitting unit. The determination unit may calculate the distance between the vector data corresponding to the node indicated by the node identification data and the vector data of the person to be authenticated based on the plurality of calculation results received by the receiving unit. When the calculated distance is shorter than a predetermined distance, it may be determined that the person to be authenticated is the person corresponding to the node indicated by the node identification data. When the distance between the vector data corresponding to the node indicated by the node identification data and the vector data of the person to be authenticated is longer than the predetermined distance, the first server may include a link generation unit that generates the linked destination data from the plurality of link shares received by the receiving unit. The notification unit may transmit node identification data indicating the linked destination node indicated by the linked destination data generated by the link generation unit to the plurality of second servers.
[0007] In any of the authentication systems described above, each of the plurality of second servers may store, for each of the plurality of nodes included in the first layer of the graph structure having a hierarchical structure including at least a first layer including all of the plurality of nodes and a second layer including some of the plurality of nodes, one of the plurality of vector shares generated from the vector data and one of the plurality of link shares generated from link destination data indicating a link destination node. The second layer of the graph structure may be made public, and the determination unit may further use the second layer to determine an authentication result of the person to be authenticated.
[0008] According to an embodiment of the present invention, an authentication method executed by a first server and a plurality of second servers is provided. In the authentication method, each of the plurality of second servers includes a plurality of nodes corresponding to a plurality of persons, each of which includes the plurality of nodes including vector data generated from the biometric information of the corresponding person, and similar nodes are connected by links. For each of the plurality of nodes in the graph structure, a storage stage may be provided in which one of a plurality of vector shares generated from the vector data and one of a plurality of link shares generated from link destination data indicating a link destination node are stored in a share storage unit. The authentication method may include a share reception stage in which each of the plurality of second servers receives one of a plurality of vector shares generated from vector data generated from the biometric information of a person to be authenticated. The authentication method may include an operation execution stage in which each of the plurality of second servers executes an operation using the vector share received in the share reception stage and the vector share stored in the share storage unit. The authentication method may include a transmission stage in which each of the plurality of second servers transmits the operation result obtained in the operation execution stage and the link share to the first server. The authentication method may include a reception stage in which the first server receives the operation result and the link share from each of the plurality of second servers. The authentication method may include a determination stage in which the first server determines an authentication result of the person to be authenticated using the plurality of operation results received in the reception stage and the plurality of link shares.
[0009] Note that the above summary of the invention does not list all the necessary features of the present invention. Also, sub-combinations of these feature groups can also be inventions.
Brief Description of the Drawings
[0010]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Modes for Carrying Out the Invention
[0011] When performing one-to-many authentication, graph search is effective. For example, a graph structure including a plurality of nodes corresponding to a plurality of people, each node including vector information generated from biometric information of the corresponding person, and similar nodes being connected by links is used. By doing so, the number of nodes to be compared with the person to be authenticated and the vector information can be appropriately reduced, and efficient authentication can be performed. Such a graph structure includes information of a large number of people and also includes information on the relationships between a large number of people. Therefore, it can be said that the need to prevent the leakage of the graph structure is very high. In the authentication system 10 according to the present embodiment, the graph structure is divided and stored in a plurality of servers by a secret sharing technique. According to the secret sharing technique, even if data leaks from some servers, the graph structure cannot be restored, so an attacker has to obtain data from a plurality of servers, resulting in increased security.
[0012] Hereinafter, the present invention will be described through embodiments of the invention. However, the following embodiments do not limit the invention according to the claims. Also, not all combinations of features described in the embodiments are essential for the solution means of the invention.
[0013] FIG. 1 schematically shows an example of the authentication system 10. The authentication system 10 may be a biometric authentication system using secret sharing.
[0014] The authentication system 10 includes a main server 100 and a plurality of sub-servers 200. The main server 100 may be an example of a first server. The sub-server 200 may be an example of a second server.
[0015] The authentication system 10 may further include a registration client 300. The authentication system 10 may further include a registration server 400. The authentication system 10 may further include an authentication client 500.
[0016] The main server 100, the sub-server 200, the registered client 300, the registration server 400, and the authentication client 500 may communicate via the network 20. The network 20 may include the Internet. The network 20 may include a LAN (Local Area Network). The network 20 may include a mobile communication network. The mobile communication network may conform to any of the communication methods such as the 5G (5th Generation) communication method, the LTE (Long Term Evolution) communication method, the 3G (3rd Generation) communication method, and the communication methods after the 6G (6th Generation) communication method.
[0017] The main server 100 may be wired-connected to the network 20. The main server 100 may be wirelessly connected to the network 20. The main server 100 may be connected to the network 20 via a wireless base station. The main server 100 may be connected to the network 20 via a Wi-Fi (registered trademark) access point. The main server 100 may be composed of a so-called server device. The main server 100 may be a server implemented on any device.
[0018] The sub-server 200 may be wired-connected to the network 20. The sub-server 200 may be wirelessly connected to the network 20. The sub-server 200 may be connected to the network 20 via a wireless base station. The sub-server 200 may be connected to the network 20 via a Wi-Fi access point. The sub-server 200 may be composed of a so-called server device. The sub-server 200 may be a server implemented on any device.
[0019] The registered client 300 may be wired-connected to the network 20. The registered client 300 may also be wirelessly connected to the network 20. The registered client 300 may be connected to the network 20 via a wireless base station. The registered client 300 may be connected to the network 20 via a Wi-Fi access point. The registered client 300 may be any device. For example, the registered client 300 may be a smartphone, a tablet terminal, a PC (Personal Computer), a dedicated registration terminal, a server device, etc.
[0020] The registration server 400 may be wired-connected to the network 20. The registration server 400 may also be wirelessly connected to the network 20. The registration server 400 may be connected to the network 20 via a wireless base station. The registration server 400 may be connected to the network 20 via a Wi-Fi access point. The registration server 400 may be constituted by a so-called server device. The registration server 400 may also be a server implemented on any device.
[0021] The authentication client 500 may be wired-connected to the network 20. The authentication client 500 may also be wirelessly connected to the network 20. The authentication client 500 may be connected to the network 20 via a wireless base station. The authentication client 500 may be connected to the network 20 via a Wi-Fi access point. The authentication client 500 may be any device. For example, the authentication client 500 may be a smartphone, a tablet terminal, a PC, a dedicated authentication terminal, a server device, etc.
[0022] The registered client 300 acquires the biometric information of the person 70 to be registered by a sensor. The registered client 300 may transmit the acquired biometric information to the registration server 400. The registered client 300 may generate multi-dimensional vector data representing the characteristics of the acquired biometric information and transmit the generated vector data to the registration server 400.
[0023] When the registration server 400 receives biometric information from the registration client 300, it generates and stores vector data from the biometric information. When the registration server 400 receives vector data from the registration client 300, it stores the vector data.
[0024] The registration server 400 generates a graph structure for authenticating a plurality of persons 70 using the vector data of the plurality of persons 70. The registration server 400 may include a plurality of nodes corresponding to the plurality of persons 70, each of which includes a plurality of nodes including the vector data of the corresponding person, and generate a graph structure in which the plurality of nodes are connected by links. Nodes connected by links in the graph structure may be nodes with similar vector data. The registration server 400 may generate such a graph structure using a known method.
[0025] For each of the plurality of nodes in the generated graph structure, the registration server 400 generates a plurality of vector shares from the vector data included in the node, and generates a plurality of link shares from the link destination data indicating the link destination node. For each of the plurality of nodes, the registration server 400 transmits each of the plurality of vector shares and the plurality of link shares to each of the plurality of sub-servers 200.
[0026] Each of the plurality of sub-servers 200 stores the received vector shares and link shares. Which vector shares and link shares are stored in which sub-server 200 may be managed by the registration server 400 and the main server 100.
[0027] The authentication client 500 acquires the biometric information of the person 80 to be authenticated by a sensor, and transmits information used for authenticating the person 80 to the authentication system 10. For example, the authentication client 500 generates vector data from the biometric information of the person 80, generates a plurality of vector shares from the vector data, and transmits them to each of the plurality of sub-servers 200.
[0028] The authentication system 10 performs biometric authentication using a graph structure and secret sharing.
[0029] Figure 2 schematically shows an example of the graph structure 600. The graph structure 600 includes a plurality of nodes 610 corresponding to a plurality of persons 70. Each of the plurality of nodes 610 corresponds to one of the plurality of persons 70. In the graph structure 600, the nodes 610 are connected to each other by links 620. Each of the plurality of nodes 610 includes vector data generated from the biometric information of the corresponding person 70 and link destination data indicating the link destination node.
[0030] Figure 3 is an explanatory diagram for explaining a general authentication process using the graph structure 600. In the general authentication process, a node 610 whose distance from the authentication target vector data 630 generated from the biometric information of the person 80 to be authenticated is shorter than a predetermined threshold is searched within the graph structure 600. The main body of the authentication process, for example, calculates the distance between the vector data included in the start node 640 and the authentication target vector data 630 with any one of the plurality of nodes 610 as the start node 640 and compares it with the threshold. When the calculated distance is shorter than the threshold, the main body of the authentication process determines that the person 80 to be authenticated is the person 70 corresponding to the start node 640 and determines that the authentication is successful.
[0031] When the calculated distance is longer than the threshold, the authentication processing entity identifies the node 610 that is the link destination of the start node 640, calculates the distance between the vector data included in the link destination node 610 and the authentication target vector data 630, and compares it with the threshold. If there is a node 610 where the calculated distance is shorter than the threshold, the authentication processing entity determines that the person 80 to be authenticated is the person 70 corresponding to the node 610 and succeeds in authentication. If there is no node 610 where the calculated distance is shorter than the threshold, the authentication processing entity identifies the node 610 with the shortest calculated distance among the link destination nodes 610 and identifies the link destination node 610 of the identified node 610. The authentication processing entity continues the process until it finds a node 610 where the calculated distance is shorter than the threshold or identifies a node 610 that includes the vector data with the shortest distance from the authentication target vector data 630 among the plurality of nodes 610. When a node 610 where the calculated distance is shorter than the threshold is found, authentication is successful. If the node 610 with the shortest distance from the authentication target vector data 630 is identified but the distance between the authentication target vector data 630 and the vector data is longer than the threshold, authentication fails.
[0032] The authentication system 10 according to this embodiment realizes the search using such a graph structure 600 by using secret sharing. For example, when the number of shares is 3, one vector data is divided into three vector shares, one link destination data is divided into three link shares, and three pairs of vector shares and link shares are distributed and managed by three sub-servers 200.
[0033] FIG. 4 is an explanatory diagram for explaining the data included in the node 610, the vector share, and the link share when the number of shares is 3. Here, node A whose link destinations are node B, node C, and node D will be described as an example.
[0034] Node A includes vector data 612 representing the characteristics of the biometric information of the person 70 corresponding to node A and link destination data 622 indicating link destinations node B, node C, and node D.
[0035] The registration server 400 generates three vector shares 614 from the vector data 612. When the three vector shares 614 are complete, the vector data 612 can be restored.
[0036] The registration server 400 generates three link shares 624 from the linked data 622. When the three link shares 624 are complete, the linked data 622 can be restored. The registration server 400, for example, uses the value obtained by subtracting the first hash value and the second hash value from the linked data 622, the first hash value, and the second hash value as the three link shares 624. The method for generating the link shares 624 is not limited to this.
[0037] The registration server 400 sends pairs of the three vector shares 614 and the link shares 624 to each of the three sub - servers 200, and causes each of the three sub - servers 200 to store the pairs of the vector shares 614 and the link shares 624 in association with node identification data that can identify node A.
[0038] FIG. 5 schematically shows an example of the processing flow in the authentication system 10.
[0039] The registration server 400 includes a generation unit 402 and a conversion unit 404. The generation unit 402 generates a graph structure 600 using the vector data of a plurality of persons 70. The registration server 400 may acquire the graph structure 600 generated by another device.
[0040] For each of the plurality of nodes 610 in the graph structure 600, the conversion unit 404 generates a plurality of vector shares 614 from the vector data 612 and generates a plurality of link shares 624 from the link destination data 622. For each of the plurality of nodes 610, the conversion unit 404 transmits the node identification data and each pair of the plurality of vector shares 614 and link shares 624 to each of the plurality of sub-servers 200. The conversion unit 404 may transmit the node identification data and each pair of the plurality of vector shares 614 and link shares 624 to each of the plurality of sub-servers 200 after encrypting using an arbitrary encryption method. The transmission destination of each pair of the plurality of vector shares 614 and link shares 624 may be shared with the main server 100.
[0041] The authentication client 500 includes a sensor unit 502 and a conversion unit 504. The sensor unit 502 acquires the biometric information 82 of the person 80 to be authenticated and generates vector data 84 from the biometric information 82. The conversion unit 504 generates a plurality of vector shares 86 from the vector data 84 and transmits each of the plurality of vector shares 86 to each of the plurality of sub-servers 200. The conversion unit 504 may transmit each of the plurality of vector shares 86 to each of the plurality of sub-servers 200 after encrypting using an arbitrary encryption method. The transmission destination of the plurality of vector shares 86 is specified in advance by the registration client 300 or the main server 100.
[0042] Each of the plurality of sub-servers 200 executes an operation on the vector share 86 received from the authentication client 500 and any one of the plurality of vector shares 614 stored therein. Each of the plurality of sub-servers 200 may execute an operation on the vector share 86 and the vector share 614 corresponding to the node 610 corresponding to the start node. Which of the plurality of nodes 610 is used as the start node may be specified by the registration server 400, may be determined among the plurality of sub-servers 200, or may be specified by the main server 100.
[0043] Each of the plurality of sub - servers 200 executes a part of the operation for calculating the distance between the vector data 612 included in the node 610 corresponding to the start node and the vector data 84. As a specific example, each of the plurality of sub - servers 200 executes a part of the operation for calculating the Euclidean distance between the vector data 612 included in the node 610 corresponding to the start node and the vector data 84. Each of the plurality of sub - servers 200 transmits the operation result 250 and the link share 624 corresponding to the node 610 corresponding to the start node to the main server 100.
[0044] The main server 100 calculates the distance between the vector data 612 included in the node 610 corresponding to the start node and the vector data 84 by using the operation results 250 received from each of the plurality of sub - servers 200. For example, the main server 100 may calculate the distance between the vector data 612 included in the node 610 corresponding to the start node and the vector data 84 by adding the plurality of operation results 250 received from the plurality of sub - servers 200.
[0045] When the calculated distance is shorter than a predetermined threshold value, the main server 100 generates a determination result 150 indicating that the person 80 to be authenticated is the person 70 corresponding to the node 610 corresponding to the start node and the authentication is successful.
[0046] When the calculated distance is longer than the threshold value, the main server 100 generates link - destination data 622 by using the plurality of link shares 624 received from the plurality of sub - servers 200. The main server 100 notifies the plurality of sub - servers 200 of the node 610 of the link destination indicated by the generated link - destination data 622. The main server 100 may transmit the node identification data of the node 610 of the link destination indicated by the link - destination data 622 to the plurality of sub - servers 200.
[0047] When there is one linked node 610 indicated by the linked data 622, each of the plurality of sub-servers 200 executes an operation on the vector share 86 received from the authentication client 500 and the vector share 614 corresponding to the linked node 610 among the plurality of stored vector shares 614. Each of the plurality of sub-servers 200 transmits the operation result 250 and the link share 624 corresponding to the linked node to the main server 100. The main server 100 calculates the distance between the vector data 612 included in the linked node 610 and the vector data 84 using the operation results 250 received from each of the plurality of sub-servers 200. When the calculated distance is shorter than a predetermined threshold value, the main server 100 generates a determination result 150 indicating that the person 80 to be authenticated is the person 70 corresponding to the linked node 610 and the authentication is successful. When the calculated distance is longer than the threshold value, the main server 100 generates the linked data 622 using the plurality of link shares 624 received from the plurality of sub-servers 200. The main server 100 notifies the plurality of sub-servers 200 of the linked node 610 indicated by the generated linked data 622.
[0048] When there are a plurality of destination nodes 610 indicated by the destination data 622, each of the plurality of sub-servers 200 executes an operation on the vector share 86 received from the authentication client 500 and each of the vector shares 614 corresponding to the plurality of destination nodes 610. Each of the plurality of sub-servers 200 transmits, for each of the plurality of destination nodes 610, the operation result 250 and the link share 624 corresponding to the destination node 610 to the main server 100. The main server 100 calculates, for each of the plurality of destination nodes 610, the distance between the vector data 612 included in the destination node 610 and the vector data 84 using the operation results 250 received from each of the plurality of sub-servers 200. When there is a destination node 610 among the plurality of destination nodes 610 whose calculated distance is shorter than a predetermined threshold, the main server 100 generates a determination result 150 indicating that the person 80 is the person 70 corresponding to the node 610 and the authentication is successful. When any of the calculated distances is longer than the threshold, the main server 100 generates the destination data 622 from the plurality of link shares 624 corresponding to the node 610 with the shortest distance. The main server 100 notifies the plurality of sub-servers 200 of the destination node 610 indicated by the generated destination data 622.
[0049] By repeating such processing, the authentication system 10 performs the authentication process for the person 80.
[0050] FIG. 6 schematically shows an example of the functional configuration of the sub-server 200. The sub-server 200 includes a share acquisition unit 202, a share storage unit 204, a share reception unit 206, an operation execution unit 208, and a transmission unit 210.
[0051] The share acquisition unit 202 acquires, for each of the plurality of nodes 610 in the graph structure 600, node identification data, one of the plurality of vector shares 614 generated from the vector data 612, and one of the plurality of link shares 624 generated from the link destination data 622. The share acquisition unit 202 may receive, from the registration server 400, for each of the plurality of nodes 610, the node identification data, one of the plurality of vector shares 614, and one of the plurality of link shares 624.
[0052] The share storage unit 204 stores the node identification data, the vector share 614, and the link share 624 acquired by the share acquisition unit 202. The share storage unit 204 stores, for each of the plurality of nodes 610 in the graph structure 600, the node identification data, the vector share 614, and the link share 624. Each of the share storage units 204 of the plurality of sub-servers 200 stores, for each of the plurality of nodes 610 included in the graph structure 600, the node identification data, each of the plurality of vector shares 614 generated from the vector data 612, and each of the plurality of link shares 624 generated from the link destination data 622.
[0053] The share reception unit 206 receives one of the plurality of vector shares 86 generated from the vector data 84 generated from the biometric information 82 of the person 80 to be authenticated. The share reception unit 206 may receive the vector share 86 from the authentication client 500.
[0054] The calculation execution unit 208 executes a calculation using the vector share 86 received by the share reception unit 206 and the vector share 614 stored in the share storage unit 204. The calculation execution unit 208 executes a part of the calculation for calculating the distance between the vector data 612 corresponding to the node 610 corresponding to the vector share 86 and the vector data 84. The calculation execution unit 208 may calculate the distance between the vector share 86 and the vector share 614. The calculation execution unit 208 may calculate the Euclidean distance between the vector share 86 and the vector share 614.
[0055] When the calculation execution unit 208 executes the authentication process for the person 80 to be authenticated, first, it may execute a calculation using the vector share 614 corresponding to the node 610 corresponding to the start node among the plurality of nodes 610 included in the graph structure 600 and the vector share 86. For example, it executes a calculation using the vector share 614 corresponding to the node 610 specified by the registration server 400 or the main server 100 and the vector share 86.
[0056] The transmission unit 210 transmits the calculation result 250 by the calculation execution unit 208 and the link share 624 to the main server 100. The transmission unit 210 transmits the calculation result 250 by the calculation execution unit 208 and the link share 624 corresponding to the vector share 614 on which the calculation execution unit 208 performed the calculation to the main server 100.
[0057] FIG. 7 schematically shows an example of the functional configuration of the main server 100. The main server 100 includes a correspondence management unit 102, a reception unit 104, a determination unit 106, a link generation unit 108, a notification unit 110, and an authentication result output unit 112. Note that it is not always essential for the main server 100 to include all of these.
[0058] The correspondence management unit 102 manages, for each of the plurality of nodes 610 included in the graph structure 600, the correspondence regarding which of the plurality of vector shares 614 generated from the vector data 612 and which of the plurality of link shares 624 generated from the link destination data 622 are stored in which of the plurality of sub-servers 200. For example, when the dispersion number is 3, the correspondence management unit 102 stores, for each of the plurality of nodes 610, the correspondence indicating the sub-server 200 that stores the first vector share 614 and link share 624, the sub-server 200 that stores the second vector share 614 and link share 624, and the sub-server 200 that stores the third vector share 614 and link share 624.
[0059] The receiving unit 104 receives the calculation results 250 and the link shares 624 from each of the plurality of sub-servers 200. The receiving unit 104 receives the calculation results 250 and the link shares 624 transmitted by the respective transmitting units 210 of the plurality of sub-servers 200.
[0060] The determination unit 106 determines the authentication result of the person 80 to be authenticated using the plurality of calculation results 250 received by the receiving unit 104 and the plurality of link shares 624. The determination unit 106 calculates the distance between the vector data 612 and the vector data 84 from the plurality of calculation results received by the receiving unit 104. For example, the receiving unit 104 may calculate the distance between the vector data 612 and the vector data 84 by adding the plurality of calculation results. When the calculated distance is shorter than a predetermined threshold value, the determination unit 106 generates a determination result 150 indicating that the person 80 is the person 70 corresponding to the node 610 and the authentication is successful.
[0061] When the calculated distance is longer than the threshold value, the link generation unit 108 generates link destination data 622 using the plurality of link shares 624 received by the receiving unit 104.
[0062] The notification unit 110 notifies the plurality of sub-servers 200 of the link destination node 610 indicated by the link destination data 622 generated by the link generation unit 108. The notification unit 110 may transmit the node identification data of the link destination node 610 indicated by the link destination data 622 to the plurality of sub-servers 200.
[0063] When a plurality of sub-servers 200 execute a part of the operation for calculating the distance between the vector data 612 corresponding to the node 610 corresponding to the start node and the vector data 84, the determination unit 106 uses the plurality of operation results 250 to calculate the distance between the vector data 612 corresponding to the node 610 corresponding to the start node and the vector data 84. When the calculated distance is shorter than a predetermined threshold value, the determination unit 106 generates a determination result 150 indicating that the person 80 to be authenticated is the person 70 corresponding to the node 610 corresponding to the start node and the authentication is successful. When the calculated distance is longer than the threshold value, the link generation unit 108 generates link destination data 622 using the plurality of link shares 624 received by the reception unit 104. Then, the notification unit 110 transmits the node identification data of the link destination node 610 indicated by the link destination data 622 generated by the link generation unit 108 to the plurality of sub-servers 200.
[0064] When the sub-server 200 receives the node identification data, the operation execution unit 208 executes an operation using the vector share 614 corresponding to the node 610 indicated by the node identification data and the vector share 86 among the plurality of vector shares 614 stored in the share storage unit 204. When receiving a plurality of node identification data, the operation execution unit 208 executes an operation using the corresponding vector share 614 and the vector share 86 for each of the plurality of nodes 610 indicated by the plurality of node identification data. The transmission unit 210 transmits the operation result 250 by the operation execution unit 208 and the link share 624 corresponding to the node 610 indicated by the node identification data to the main server 100.
[0065] When the reception unit 104 receives the operation result 250 and the link share 624 transmitted by the transmission unit 210, the determination unit 106 executes a determination.
[0066] When there is one linked node 610, the determination unit 106 calculates the distance between the vector data 612 included in the linked node 610 and the vector data 84 by using the calculation results 250 received from each of the plurality of sub-servers 200. When the calculated distance is shorter than a predetermined threshold, the determination unit 106 generates a determination result 150 indicating that the person 80 to be authenticated is the person 70 corresponding to the linked node 610 and the authentication is successful. When the calculated distance is longer than the threshold, the link generation unit 108 generates link destination data 622 by using the plurality of link shares 624 received from the plurality of sub-servers 200. Then, the notification unit 110 notifies the plurality of sub-servers 200 of the linked node 610 indicated by the link destination data 622 generated by the link generation unit 108.
[0067] When there are a plurality of linked nodes 610, the determination unit 106 calculates the distance between the vector data 612 included in the linked node 610 and the vector data 84 for each of the plurality of linked nodes 610 by using the calculation results 250 received from each of the plurality of sub-servers 200. When there is a node 610 among the plurality of linked nodes 610 for which the calculated distance is shorter than a predetermined threshold, the determination unit 106 generates a determination result 150 indicating that the person 80 is the person 70 corresponding to the node 610 and the authentication is successful. When any of the calculated distances is longer than the threshold, the link generation unit 108 generates link destination data 622 from the plurality of link shares 624 corresponding to the node 610 with the shortest distance. Then, the notification unit 110 notifies the plurality of sub-servers 200 of the linked node 610 indicated by the link destination data 622 generated by the link generation unit 108.
[0068] The authentication system 10 continues the process until it discovers a node 610 whose calculated distance is shorter than the threshold value, or until it identifies a node 610 that includes the vector data 612 with the shortest distance from the vector data 84 among the multiple nodes 610. When the determination unit 106 discovers a node 610 whose calculated distance is shorter than the threshold value, it determines that the authentication is successful. If it identifies a node 610 with the shortest distance from the vector data 84, but the distance between the vector data 84 and the vector data 612 is longer than the threshold value, it determines that the authentication has failed.
[0069] The authentication result output unit 112 outputs the determination result 150 by the determination unit 106. For example, the authentication result output unit 112 causes the display provided in the main server 100 to display the determination result 150. For example, the authentication result output unit 112 transmits the determination result 150 to another device via the network 20. For example, the authentication result output unit 112 transmits the determination result 150 to the authentication client 500 via the network 20.
[0070] FIG. 8 is an explanatory diagram for explaining an example of the calculation of vector data in the authentication system 10. Here, any element vector x of the d-dimensional vector i is assumed to be secretly distributed and stored in a plurality of sub-servers 200 as represented by the following Mathematical Formula 1. Also, the vector data 84 of the person 80 to be authenticated is distributed and provided to a plurality of sub-servers 200 as represented by the following Mathematical Formula 2. S represents the dispersion number.
[0071]
Equation
[0072]
Equation
[0073] In this case, the Euclidean distance between the vector data 612 of the registered person 70 and the vector data 84 of the person 80 to be authenticated can be represented by the mathematical formula shown in FIG. 8.
[0074] Each of the plurality of sub-servers 200 executes each of the plurality of partial operations 230 in FIG. 8. The main server 100 receives the operation result 250 of the partial operation 230 from each of the plurality of sub-servers 200, and for the plurality of operation results 250, as shown in FIG. 8, calculates the root of the value obtained by adding the values obtained by squaring the values obtained by adding the plurality of operation results 250 for 1 to d dimensions, thereby calculating the Euclidean distance between the vector data 612 and the vector data 84.
[0075] FIG. 9 schematically shows an example of the graph structure 600 in the case of having a hierarchical structure. The graph structure 600 may have a hierarchical structure as shown in FIG. 9.
[0076] In the example shown in FIG. 9, the layer 650 includes all of the plurality of nodes 610. The layer 650 may be an example of the first layer. The layer 652 includes a plurality of nodes 610 that are a part of the plurality of nodes 610 included in the layer 650. The layer 654 includes a plurality of nodes 610 that are a part of the plurality of nodes 610 included in the layer 652. The graph structure 600 may include four or more layers. The layer 652 may be an example of the second layer. The layer 654 may be an example of the second layer.
[0077] Each of the plurality of sub-servers 200 stores, for each of the plurality of nodes 610 included in the layer 650 in the graph structure 600, one of the plurality of vector shares 614 generated from the vector data 612 and one of the plurality of link shares 624 generated from the link destination data 622 indicating the link destination node. Each of the plurality of sub-servers 200 does not have to store these data for the layer 652 and the layer 654. The layer 654 may be made public. The layer 652 may be made public.
[0078] In addition to layer 650, the determination unit 106 may further use layer 652, or further use layer 652 and layer 654 to determine the authentication result of the person 80 to be authenticated. For example, the determination unit 106 searches layer 654 based on the vector data 84 generated from the biometric information 82 of the person 80 to be authenticated, and identifies the node 610 with the shortest distance from the vector data 84. The determination unit 106 may perform the search in layer 654 by executing the general authentication process described in FIG. 3. The determination unit 106 identifies the node 610 in layer 652 corresponding to the node 610 identified in layer 654.
[0079] In layer 652, the determination unit 106 uses the identified node 610 as the start node to identify the node 610 with the shortest distance from the vector data 84. The determination unit 106 may perform the search in layer 654 by executing the general authentication process described in FIG. 3. The determination unit 106 identifies the node 610 in layer 650 corresponding to the node 610 identified in layer 652.
[0080] In layer 650, the determination unit 106 uses the identified node 610 as the start node and performs the determination process by the method described in FIG. 5.
[0081] In this way, in the upper layer of the hierarchical structure of the graph structure 600, general authentication processing is performed without using secret sharing, and in the lower layer, authentication using secret sharing is performed, so that the secrecy of the important part of the graph structure 600 can be maintained while accelerating the processing.
[0082] FIG. 10 schematically shows an example of the hardware configuration of a computer 1200 that functions as the main server 100, the sub-server 200, the registered client 300, the registration server 400, or the authentication client 500. Programs installed on the computer 1200 cause the computer 1200 to function as one or more "parts" of the device according to the present embodiment, or cause the computer 1200 to execute operations associated with the device according to the present embodiment or the one or more "parts", and / or cause the computer 1200 to execute the process according to the present embodiment or stages of the process. Such programs may be executed by the CPU 1212 to cause the computer 1200 to execute certain operations associated with some or all of the blocks of the flowcharts and block diagrams described herein.
[0083] The computer 1200 according to the present embodiment includes a CPU 1212, a RAM 1214, and a graphic controller 1216, which are interconnected by a host controller 1210. The computer 1200 also includes input / output units such as a communication interface 1222, a storage device 1224, a DVD drive, and an IC card drive, which are connected to the host controller 1210 via an input / output controller 1220. The DVD drive may be a DVD-ROM drive, a DVD-RAM drive, or the like. The storage device 1224 may be a hard disk drive, a solid state drive, or the like. The computer 1200 also includes legacy input / output units such as a ROM 1230 and a keyboard, which are connected to the input / output controller 1220 via an input / output chip 1240.
[0084] The CPU 1212 operates according to programs stored in the ROM 1230 and the RAM 1214, thereby controlling each unit. The graphic controller 1216 acquires image data generated by the CPU 1212 in a frame buffer provided in the RAM 1214 or the like, or in itself, and causes the image data to be displayed on the display device 1218.
[0085] The communication interface 1222 communicates with other electronic devices via a network. The storage device 1224 stores programs and data used by the CPU 1212 in the computer 1200. The DVD drive reads a program or data from a DVD-ROM or the like and provides it to the storage device 1224. The IC card drive reads programs and data from an IC card and / or writes programs and data to an IC card.
[0086] The ROM 1230 stores therein a boot program or the like executed by the computer 1200 at activation, and / or a program dependent on the hardware of the computer 1200. The input / output chip 1240 may also connect various input / output units to the input / output controller 1220 via a USB port, a parallel port, a serial port, a keyboard port, a mouse port, or the like.
[0087] The program is provided by a computer-readable storage medium such as a DVD-ROM or an IC card. The program is read from the computer-readable storage medium, installed in the storage device 1224, which is also an example of a computer-readable storage medium, the RAM 1214, or the ROM 1230, and executed by the CPU 1212. The information processing described in these programs is read by the computer 1200, resulting in cooperation between the programs and the various types of hardware resources described above. The apparatus or method may be configured by realizing the operation or processing of information according to the use of the computer 1200.
[0088] For example, when communication is executed between the computer 1200 and an external device, the CPU 1212 may execute a communication program loaded into the RAM 1214 and instruct the communication interface 1222 to perform communication processing based on the processing described in the communication program. Under the control of the CPU 1212, the communication interface 1222 reads transmission data stored in a transmission buffer area provided in a recording medium such as the RAM 1214, the storage device 1224, the DVD-ROM, or the IC card, transmits the read transmission data to the network, or writes the received data received from the network to a reception buffer area or the like provided on the recording medium.
[0089] Further, the CPU 1212 may cause all or a necessary part of a file or database stored in an external recording medium such as the storage device 1224, the DVD drive (DVD-ROM), the IC card, etc. to be read into the RAM 1214 and perform various types of processing on the data on the RAM 1214. The CPU 1212 may then write back the processed data to the external recording medium.
[0090] Various types of information such as various types of programs, data, tables, and databases may be stored in the recording medium and may undergo information processing. The CPU 1212 may perform various types of processing on the data read from the RAM 1214, including various types of operations, information processing, conditional judgments, conditional branches, unconditional branches, search / replacement of information, etc. described throughout this disclosure and specified by the program instruction sequence, and write back the results to the RAM 1214. Further, the CPU 1212 may search for information in files, databases, etc. within the recording medium. For example, when a plurality of entries each having an attribute value of a first attribute associated with an attribute value of a second attribute are stored in the recording medium, the CPU 1212 searches for an entry that matches the condition in which the attribute value of the first attribute is specified among the plurality of entries, reads the attribute value of the second attribute stored in the entry, and thereby obtains the attribute value of the second attribute associated with the first attribute that satisfies a predetermined condition.
[0091] The programs or software modules described above may be stored on a computer-readable storage medium on or near computer 1200. Also, a recording medium such as a hard disk or RAM provided within a server system connected to a dedicated communication network or the Internet can be used as a computer-readable storage medium, thereby providing the program to computer 1200 via the network.
[0092] The blocks in the flowcharts and block diagrams in this embodiment may represent stages of a process in which an operation is performed or "parts" of an apparatus that has the role of performing an operation. Specific stages and "parts" may be implemented by a dedicated circuit, a programmable circuit supplied with computer-readable instructions stored on a computer-readable storage medium, and / or a processor supplied with computer-readable instructions stored on a computer-readable storage medium. The dedicated circuit may include digital and / or analog hardware circuits and may include integrated circuits (ICs) and / or discrete circuits. The programmable circuit may include, for example, a reconfigurable hardware circuit including AND, OR, exclusive OR, NAND, NOR, and other logical operations, flip-flops, registers, and memory elements, such as a field programmable gate array (FPGA) and a programmable logic array (PLA).
[0093] A computer-readable storage medium may include any tangible device that can store instructions executable by an appropriate device. As a result, a computer-readable storage medium having instructions stored therein will comprise a product that includes instructions executable to create means for performing the operations specified in a flowchart or block diagram. Examples of computer-readable storage media may include electronic storage media, magnetic storage media, optical storage media, electromagnetic storage media, semiconductor storage media, and the like. More specific examples of computer-readable storage media may include floppy (registered trademark) disks, diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), electrically erasable programmable read-only memory (EEPROM), static random access memory (SRAM), compact disc read-only memory (CD-ROM), digital versatile disc (DVD), Blu-ray (registered trademark) disc, memory stick, integrated circuit card, and the like.
[0094] Computer-readable instructions may include any combination of one or more programming languages, including assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, or source code or object code written in any combination of object-oriented programming languages such as Smalltalk (registered trademark), JAVA (registered trademark), C++, and conventional procedural programming languages such as the "C" programming language or similar programming languages.
[0095] Computer-readable instructions may be provided to a processor of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, or to a programmable circuit, locally or via a wide area network (WAN) such as a local area network (LAN), the Internet, etc., to execute the computer-readable instructions to generate means for executing the operations specified in a flowchart or block diagram. Examples of processors include computer processors, processing units, microprocessors, digital signal processors, controllers, microcontrollers, and the like.
[0096] As described above, the present invention has been described using embodiments. However, the technical scope of the present invention is not limited to the scope described in the above embodiments. It is obvious to those skilled in the art that various changes or improvements can be made to the above embodiments. It is clear from the description of the claims that forms with such changes or improvements can also be included in the technical scope of the present invention.
[0097] It should be noted that the execution order of each process such as operations, procedures, steps, and stages in the devices, systems, programs, and methods shown in the claims, the specification, and the drawings is not explicitly indicated as "earlier" or "preceding" etc., and can be realized in any order unless the output of the previous process is used in the subsequent process. Regarding the operation flowcharts in the claims, the specification, and the drawings, even if explanations are made using "first," "next," etc. for convenience, it does not mean that it is essential to implement in this order.
Explanation of Reference Numerals
[0098] 10 Authentication system, 20 Network, 70 Person, 80 Person, 82 Biometric information, 84 Vector data, 86 Vector share, 100 Main server, 102 Correspondence management section, 104 Receiving section, 106 Determination section, 108 Link generation section, 110 Notification section, 112 Authentication result output section, 150 Determination result, 200 Sub-server, 202 Share acquisition section, 204 Share storage section, 206 Share receiving section, 208 Calculation execution section, 210 Transmission section, 230 Partial calculation, 250 Calculation result, 300 Registered client, 400 Registered server, 402 Generation section, 404 Conversion section, 500 Authentication client, 502 Sensor section, 504 Conversion section, 600 Graph structure, 610 Node, 612 Vector data, 614 Vector share, 620 Link, 622 Link destination data, 624 Link share, 630 Authentication target vector data, 640 Start node, 650 Layer, 652 Layer, 654 Layer, 1200 Computer, 1210 Host controller, 1212 CPU, 1214 RAM, 1216 Graphic controller, 1218 Display device, 1220 Input / output controller, 1222 Communication interface, 1224 Storage device, 1230 ROM, 1240 Input / output chip
Claims
1. 1. An authentication system, comprising: A first server; A plurality of second servers; Equipped with Each of the plurality of second servers includes a plurality of nodes corresponding to a plurality of people, each of the plurality of nodes including vector data generated from biometric information of the corresponding person, and for each of the plurality of nodes in a graph structure in which the plurality of nodes are connected by links, stores one of a plurality of vector shares generated from the vector data and one of a plurality of link shares generated from link destination data indicating a link destination node; Each of the plurality of second servers a share storage unit that stores the vector share and the link share; a share receiving unit that receives one of a plurality of vector shares generated from vector data generated from biometric information of a person to be authenticated; an operation execution unit that executes an operation using the vector share received by the share receiving unit and the vector share stored in the share storage unit; a transmission unit that transmits the calculation result by the calculation execution unit and the link share to the first server; having The first server a receiving unit that receives the calculation result and the link share from each of the second servers; a determination unit that determines an authentication result of the person to be authenticated by using the plurality of calculation results and the plurality of link shares received by the receiving unit; An authentication system comprising:
2. 2. The authentication system of claim 1, wherein the share memory unit stores, for each of the plurality of nodes included in the graph structure, node identification data capable of identifying the node, one of the plurality of vector shares generated from the vector data included in the node, and one of the plurality of link shares generated from the link destination data included in the node.
3. The vector data can be generated by the plurality of vector shares generated from the vector data, The authentication system according to claim 1 , wherein the linked data can be generated by the plurality of link shares generated from the linked data.
4. the first server has a notification unit that transmits node identification data indicating any one of the plurality of nodes to the plurality of second servers; the receiving unit receives, from each of the second servers, the calculation result and the link share corresponding to the node indicated by the node identification data transmitted by the notifying unit; 4. The authentication system according to claim 1, wherein the determination unit calculates a distance between vector data corresponding to the node indicated by the node identification data and vector data of the person to be authenticated based on the multiple calculation results received by the receiving unit, and if the calculated distance is shorter than a predetermined distance, determines that the person to be authenticated is the person corresponding to the node indicated by the node identification data.
5. The first server a link generating unit that generates the link destination data from the plurality of link shares received by the receiving unit when a distance between the vector data corresponding to the node indicated by the node identification data and the vector data of the person to be authenticated is longer than the predetermined distance; having The notification unit transmits, to the second servers, node identification data indicating a link destination node indicated by the link destination data generated by the link generation unit. The authentication system according to claim 4.
6. 2. The authentication system of claim 1, wherein each of the second servers stores, for each of the nodes included in the first layer in the graph structure having a hierarchical structure including at least a first layer including all of the nodes and a second layer including some of the nodes, one of the vector shares generated from the vector data and one of the link shares generated from link destination data indicating the linked node.
7. the second layer of the graph structure is public; The authentication system according to claim 6 , wherein the determination unit further uses the second layer to determine an authentication result of the person to be authenticated.
8. An authentication method performed by a first server and a plurality of second servers, comprising: a storage step in which each of the plurality of second servers includes a plurality of nodes corresponding to a plurality of people, each of the plurality of nodes including vector data generated from biometric information of the corresponding person, and for each of the plurality of nodes in a graph structure in which the plurality of nodes are connected by links, one of a plurality of vector shares generated from the vector data and one of a plurality of link shares generated from link destination data indicating a link destination node are stored in a share storage unit; a share receiving step in which each of the plurality of second servers receives one of a plurality of vector shares generated from vector data generated from biometric information of a person to be authenticated; a calculation execution step in which each of the second servers executes a calculation using the vector share received in the share receiving step and the vector share stored in the share storage unit; a transmission step in which each of the second servers transmits a calculation result from the calculation execution step and the link share to the first server; a receiving step of the first server receiving the calculation result and the link share from each of the second servers; a determination step in which the first server determines an authentication result of the person to be authenticated by using the plurality of calculation results and the plurality of link shares received in the receiving step; An authentication method comprising:
Citation Information
Patent Citations
Decentralized biometric identification and authentication network
US20210342432A1