Identity authentication system, terminal device, computer program, and identity authentication method

The personal authentication system uses dual biometric verification to ensure the user is the legitimate owner of both the portable storage medium and terminal device, enhancing security by confirming identity through biometric data comparison.

JP2025152113APending Publication Date: 2025-10-09DAI NIPPON PRINTING CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2024053857
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-03-28
Publication Date
2025-10-09

AI Technical Summary

Technical Problem

Existing systems cannot confirm whether a user operating a terminal device is the legitimate owner of both the portable storage medium and the terminal device.

Method used

A personal authentication system that includes a portable storage medium with credential authentication data and a terminal device with terminal authentication data, using biometric sensors to perform dual biometric authentication to verify the user's identity, ensuring the user is the legitimate owner of both devices.

Benefits of technology

The system effectively confirms the user's legitimacy as the owner of both the portable storage medium and the terminal device, enabling secure access to authorized services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025152113000001_ABST
    Figure 2025152113000001_ABST
Patent Text Reader

Abstract

To provide an identity authentication system and an identity authentication method configured to be capable of verifying whether a user who operates a terminal device is an owner of a portable storage medium, and verifying whether the user who operates the terminal device is an authorized owner or not.SOLUTION: In an identity authentication system, a terminal device 10 stores terminal authentication data 101 which is biometric data of an owner of the terminal device, as authentication data for use in biometric authentication of a user. Credentials 110 stored in a portable storage medium 11 store credential authentication data 111 which is biometric data of a person to be identified with the credentials 110. An identity authentication unit 100 of the terminal device 10 executes, when a user who operates the terminal device 10 is authenticated, first biometric authentication to collate the terminal authentication data 101 with biometric data acquired by a biometric authentication sensor 10b, and second biometric authentication to collate the credential authentication data 111 with the biometric data acquired by the biometric authentication sensor 10b.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present application relates to a technology for authenticating the identity of a user who operates a terminal device such as a smartphone. [Background technology]

[0002] For some time now, user credentials have been used to authenticate the identity of users who use services or systems. Credentials are data used to verify the identity of users who use services or systems, and credentials contain various data used in identity verification. For example, credentials can contain a credential ID to identify the user to whom the credential was issued, as well as authentication information (such as a password or biometric data indicating biometric characteristics).

[0003] The system disclosed in Patent Document 1 is a system that uses a user's facial image for identity authentication. In the system disclosed in Patent Document 1, a terminal device acquires personal information (equivalent to credentials) including the owner's facial image and its digital signature from a portable storage medium (IC card). In addition to this data acquired from the portable storage medium, the terminal device transmits a photographed image of the subject taken by the terminal device to a server. The server verifies the authenticity of the personal information using the digital signature and performs face authentication by comparing the facial image included in the personal information with the photographed image, and authenticates the user based on these results. [Prior art documents] [Patent documents]

[0004] [Patent Document 1] Japanese Patent Application Laid-Open No. 2015-88080 Summary of the Invention [Problem to be solved by the invention]

[0005] In the invention disclosed in Patent Document 1, a facial photograph, which serves as biometric data of the user, is stored in a portable storage medium, and the biometric data acquired from the portable storage medium is used to authenticate the identity of the user operating the terminal device. However, the above-mentioned conventional technology can confirm whether the user operating the terminal device is the owner of the portable storage medium, but cannot confirm whether the user operating the terminal device is the legitimate owner of the terminal device.

[0006] Therefore, the present application aims to enable confirmation as to whether a user operating a terminal device is the owner of a portable storage medium, and further to enable confirmation as to whether a user operating a terminal device is the legitimate owner of the terminal device. [Means for solving the problem]

[0007] A first invention that solves the above-mentioned problem relates to a system. The personal authentication system according to the first invention is composed of at least a portable storage medium and a terminal device. The portable storage medium according to the first invention includes a first memory that stores a credential including credential authentication data, which is biometric data of a user who owns the portable storage medium. The terminal device according to the first invention includes a second memory that stores terminal authentication data, which is biometric data of the user who owns the terminal device, a biometric authentication sensor that acquires biometric data, and an authentication unit that performs first biometric authentication by comparing the biometric data acquired by the biometric authentication sensor with the terminal authentication data read from the second memory, and second biometric authentication by comparing the biometric data acquired by the biometric authentication sensor with the credential authentication data included in the credential read from the portable storage medium. In the first invention, it is preferable that the credentials stored in the portable storage medium include a credential ID used to identify the credentials, and when the first biometric authentication and the second biometric authentication are each successful, the personal authentication unit of the terminal device accesses a specified service server using the credential ID included in the credentials read from the portable storage medium.

[0008] The second invention relates to a terminal device, and the third invention relates to a computer program. The second invention is a terminal device constituting the personal authentication system described in the first invention. The third invention is a computer program that causes a processor to function as a personal authentication unit provided in the terminal device constituting the personal authentication system described in the first invention.

[0009] The fourth invention relates to a method. The fourth invention is an identity authentication method comprising: a step (a) of reading, from a portable storage medium carried by a user operating the terminal device, a credential including credential authentication data that is biometric data of the user who owns the portable storage medium; a step (b) of the terminal device acquiring biometric data of the user operating the terminal device using a biometric authentication sensor that acquires biometric data; a step (c) of the terminal device performing first biometric authentication by comparing the biometric data acquired by the biometric authentication sensor in step (b) with terminal authentication data that is biometric data of the user who owns the terminal device, using biometric data registered in the terminal device; and a step (d) of the terminal device performing second biometric authentication by comparing the biometric data acquired by the biometric authentication sensor in step (b) with the credential authentication data included in the credential read from the portable storage medium. In the personal authentication method of the fourth invention, it is preferable that the credentials stored in the portable storage medium include a credential ID used to identify the credentials, and the method further includes a step e of accessing a predetermined service server using the credential ID included in the credentials read from the portable storage medium when the terminal device succeeds in the first biometric authentication performed in step c and the second biometric authentication performed in step d. [Effects of the Invention]

[0010] The invention disclosed in this application can confirm whether the user operating the terminal device is the owner of the portable storage medium, and further whether the user operating the terminal device is the legitimate owner of the terminal device. [Brief explanation of the drawings]

[0011] [Figure 1] FIG. 1 is a diagram illustrating the configuration of an identity authentication system. [Figure 2] Block diagram of the personal authentication system. [Figure 3] FIG. 2 is a diagram illustrating the operation of the personal authentication system. DETAILED DESCRIPTION OF THE INVENTION

[0012] Hereinafter, embodiments of the invention disclosed in the present application will be described. The embodiments described here are intended to facilitate understanding of the invention disclosed in the present application. The invention disclosed in the present application is not limited to the embodiments. Furthermore, unless otherwise specified, the drawings are schematic diagrams drawn to facilitate understanding of the invention disclosed in the present application.

[0013] Fig. 1 is a diagram illustrating the configuration of an identity authentication system 1 according to an embodiment. Fig. 2 is a block diagram of the identity authentication system 1. Fig. 3 is a diagram illustrating the operation of the identity authentication system 1 according to an embodiment.

[0014] Fig. 1 illustrates the configuration of an identity authentication system 1 according to an embodiment. As illustrated in Fig. 1, the identity authentication system 1 according to an embodiment includes a terminal device 10 having a function for authenticating the identity of a user 2 using biometric data, and a portable storage medium 11 that stores a credential 110. Fig. 1 also illustrates a service server 3 operated by an institution that issued the credential 110.

[0015] In the identity authentication system 1 according to the embodiment, when authenticating the identity of a user 2 operating a terminal device 10, the terminal device 10 uses biometric data of the user 2 operating the terminal device 10 to confirm whether the user 2 operating the terminal device 10 is the legitimate owner of the terminal device 10, and further performs identity authentication to confirm whether the user 2 operating the terminal device 10 is the person identified by the credential 110.

[0016] Biometric data that can be used for identity authentication include fingerprints, faces, veins, irises, voice, DNA, and habits (behavioral characteristics), but from a practical standpoint, fingerprints or faces are preferable as the biometric data used in identity authentication system 1. Fingerprint and face authentication technology has achieved extremely high accuracy thanks to advances in advanced algorithms and image processing technology. Furthermore, modern computing devices that can be used as terminal device 10, such as smartphones and personal computers, are equipped as standard with fingerprint sensors that scan fingerprint patterns and cameras that capture facial images.

[0017] First, we will explain the portable storage medium 11. The portable storage medium 11 refers to a lightweight and compact medium. For example, the portable storage medium 11 can be an IC card, a USB memory, an SD card, or the like.

[0018] As shown in Figure 2, the portable storage medium 11 includes an NVM 11b (Non-Volatile Memory), which is a memory that stores the credentials 110, a processor 11a that controls the portable storage medium 11, and an interface circuit 11c, which is a circuit for communicating with external devices.

[0019] The NVM 11b of the portable storage medium 11 is an electrically rewritable nonvolatile memory. The NVM 11b corresponds to the first memory of the present application. The processor 11a of the portable storage medium 11 is a central part of the portable storage medium 11 and is an integrated circuit that performs complex calculations and data processing. When the processor 11a of the portable storage medium 11 receives a read request for data (here, the credential 110) from an external device (here, the terminal device 10), it selects the data stored in the NVM 11b and transmits the data for which the read request was received to the external device. The portable storage medium 11 may be configured so that password verification is required to read data stored in the NVM 11b.

[0020] In the embodiment, the NVM 11b of the portable storage medium 11 stores the credential 110 of the user 2 who owns the portable storage medium 11. The credential 110 is data used to verify the identity of the user 2 to whom the credential 110 has been issued. In the embodiment, the credential 110 stored in the NVM 11b of the portable storage medium 11 includes credential authentication data 111, which is biometric data of the user 2 who owns the portable storage medium 11, i.e., the user 2 to whom the credential 110 has been issued, and a credential ID 112 used to identify the credential 110. The credential ID 112 used to identify the credential 110 is also used to identify the user 2 to whom the credential 110 has been issued.

[0021] Next, a description will be given of the terminal device 10. The terminal device 10 is a computer device. For example, a smartphone, a tablet computer, or a personal computer can be used as the terminal device 10.

[0022] The terminal device 10 includes the hardware shown in Fig. 2. The terminal device 10 also includes hardware necessary for operating as the terminal device 10, such as a power supply unit that supplies power, which is not shown in Fig. 2.

[0023] The ROM 10c (Read-Only Memory) is a non-volatile memory that cannot be electrically rewritten. The RAM 10d (Random Access Memory) is a memory that temporarily stores data when the terminal device 10 executes a computer program. The NVM 10e is a memory that the terminal device 10 permanently stores data in. The NVM 10e corresponds to the second memory according to the present application. In the terminal device 10, an SSD (Solid State Drive) is used as the NVM 10e. In the embodiment, the NVM 10e included in the terminal device 10 stores terminal authentication data 101, which is biometric data of a user 2 who owns the terminal device 10 and has been registered in advance in the terminal device 10.

[0024] The network communication module 10h is a circuit that provides a function for connecting the terminal device 10 to a network, including Wi-Fi, Bluetooth (registered trademark), mobile data communication (3G, 4G, 5G, etc.), and the like.

[0025] The display 10f is a device responsible for displaying the screen. The display 10f may be a liquid crystal display, an OLED (Organic Light Emitting Diode), or the like. The operation device 10g is a device used to operate the terminal device 10. For example, the operation device 10g may be a keyboard, a touch screen, or the like.

[0026] The biometric authentication sensor 10b is a device that acquires biometric data. The specific form of the biometric authentication sensor 10b is determined by the biometric characteristics of the biometric data used for personal authentication. When a fingerprint is used as the biometric data, the biometric authentication sensor 10b becomes a fingerprint sensor that scans the fingerprint pattern. When a face is used as the biometric data, the biometric authentication sensor 10b becomes a camera that captures a face image.

[0027] The reader device 10i is a device for communicating with the portable storage medium 11. The reader device 10i does not need to be built into the terminal device 10. The reader device 10i may be connected to the terminal device 10 via a general-purpose interface such as a USB (Universal Serial Bus). Naturally, the specific form of the reader device 10i is determined by the form of the portable storage medium 11. For example, when a contactless IC card is used for the portable storage medium 11, the reader device 10i becomes a contactless IC card reader.

[0028] The processor 10a is a central part of the terminal device 10 and is an integrated circuit that performs complex calculations and data processing. A computer program that causes the processor 10a to function as the personal authentication unit according to the present application is stored in the ROM 10c or NVM 10e of the terminal device 10. By executing this computer program, the processor 10a functions as the personal authentication unit 100 according to the present application.

[0029] Fig. 3 explains the operation of the personal authentication system 1. The explanation of Fig. 3 also includes an explanation of the personal authentication method according to the present application.

[0030] When authenticating the identity of a user 2 who operates the terminal device 10, the identity authentication unit 100 included in the terminal device 10 first uses the reader device 10i to execute a process of reading the credential 110 from the portable storage medium 11 carried by the user 2 who operates the terminal device 10 (step S1). In this process, the identity authentication unit 100 included in the terminal device 10 displays on the display 10f an instruction to connect the portable storage medium 11 to the reader device 10i, and then transmits a read request for the credential 110 to the portable storage medium 11 connected to the reader device 10i, and reads the credential 110 from the portable storage medium 11.

[0031] Next, the personal authentication unit 100 included in the terminal device 10 uses the biometric authentication sensor 10b to execute a process to acquire biometric data of the user 2 operating the terminal device 10 (step S2). In this process, the personal authentication unit 100 included in the terminal device 10 displays on the display 10f an instruction to have the biometric authentication sensor 10b read the biometric data, and then acquires from the biometric authentication sensor 10b the biometric data scanned by the biometric authentication sensor 10b.

[0032] Next, the personal authentication unit 100 included in the terminal device 10 executes first biometric authentication by comparing the biometric data acquired by the biometric authentication sensor 10b with the terminal authentication data 101 registered in the NVM 10e of the terminal device 10 to confirm whether the user 2 operating the terminal device 10 is the owner of the terminal device 10 (step S3). If the first biometric authentication is successful, that is, if the biometric data acquired by the biometric authentication sensor 10b and the biometric data registered in the NVM 10e of the terminal device 10 are considered to be the same, the personal authentication unit 100 included in the terminal device 10 proceeds to the next step S4. Note that, although not shown in FIG. 3, if the first biometric authentication fails, the terminal device 10 aborts subsequent processing.

[0033] Next, the personal authentication unit 100 included in the terminal device 10 performs second biometric authentication by comparing the biometric data acquired by the biometric sensor 10b in step S3 with the credential authentication data 111 included in the credential 110 to confirm whether the user 2 operating the terminal device 10 is the person identified by the credential 110 (step S4). Next, if the second biometric authentication is successful, that is, if the credential authentication data 111 acquired by the biometric sensor 10b and the credential authentication data 111 included in the credential 110 read from the portable storage medium 11 are considered to be the same, the personal authentication unit 100 included in the terminal device 10 proceeds to the next step S5. Note that, although not shown in FIG. 3, if the second biometric authentication fails, the terminal device 10 aborts subsequent processing.

[0034] If the second biometric authentication is successful, the identity authentication unit 100 included in the terminal device 10 determines that identity authentication of the user 2 operating the terminal device 10 has been successful (step S5), and the procedure in Fig. 3 ends. Note that in the embodiment, successful identity authentication of the user 2 operating the terminal device 10 means that the user 2 operating the terminal device 10 is the legitimate owner of the terminal device 10 and that the user 2 operating the terminal device 10 is the person identified by the credential 110.

[0035] As described above, the credential 110 stored in the portable storage medium 11 is data issued by an organization that operates a service server. Therefore, in the identity authentication system 1 according to the embodiment, it is desirable to configure the terminal device 10 so that, upon determining that identity authentication has been successful in step S5 of FIG. 3 , the terminal device 10 accesses a predetermined service server 3, in this case, the service server 3 operated by the organization that issued the credential 110. The address of the service server 3 operated by the organization that issued the credential 110 may be included in the credential 110, or may be registered in the identity authentication unit 100 of the terminal device 10. Note that, since the service server 3 operated by the organization that issued the credential 110 needs to identify the user 2 who has been successfully authenticated, it is desirable for the terminal device 10 to transmit the credential ID 112 included in the credential 110 to the service server 3 when accessing the service server 3 operated by the organization that issued the credential 110. [Explanation of symbols]

[0036] 1. Identity authentication system 10 Terminal Equipment 100 Personal authentication unit 101 Terminal authentication data 10b Biometric Sensors 11 Portable storage media 110 Credentials 111 Authentication data for credentials 112 Credential ID 2 users 3 Service Server

Claims

1. The system is configured at least with a portable storage medium and a terminal device, the portable storage medium includes a first memory for storing a credential including credential authentication data that is biometric data of a user who owns the portable storage medium; The terminal device includes a second memory that stores terminal authentication data, which is biometric data of a user who owns the terminal device; a biometric authentication sensor that acquires biometric data; and an identity authentication unit that executes first biometric authentication that compares the biometric data acquired by the biometric authentication sensor with the terminal authentication data read from the second memory, and second biometric authentication that compares the biometric data acquired by the biometric authentication sensor with the credential authentication data included in the credential read from the portable storage medium. A personal authentication system characterized by:

2. the credential stored in the portable storage medium includes a credential ID used to identify the credential; When the first biometric authentication and the second biometric authentication are each successful, the personal authentication unit of the terminal device accesses a predetermined service server using the credential ID included in the credential read from the portable storage medium.

2. The personal authentication system according to claim 1.

3. 3. A terminal device constituting the personal authentication system according to claim 1.

4. 3. A computer program that causes a processor to function as an identity authentication unit provided in a terminal device that constitutes the identity authentication system according to claim 1.

5. a step a) in which a terminal device reads out, from a portable storage medium held by a user who operates the terminal device, a credential including credential authentication data, which is biometric data of the user who owns the portable storage medium; a step b in which the terminal device acquires biometric data of a user operating the terminal device using a biometric authentication sensor that acquires biometric data; a step c) of performing a first biometric authentication by the terminal device, in which the biometric data acquired by the biometric authentication sensor in the step b is compared with biometric data registered in the terminal device to obtain terminal authentication data, which is biometric data of the user who owns the terminal device; a step d of performing second biometric authentication by the terminal device by comparing the biometric data acquired by the biometric authentication sensor in the step b with the credential authentication data included in the credential read from the portable storage medium; A personal authentication method comprising:

6. the credential stored in the portable storage medium includes a credential ID used to identify the credential; and a step e) of accessing a predetermined service server by using the credential ID included in the credential read from the portable storage medium when the first biometric authentication performed in the step c) and the second biometric authentication performed in the step d) are successful.

6. The method for authenticating an individual according to claim 5.

Citation Information

Patent Citations

  • Authentication system, authentication method, and program

    JP2015088080A