Information processing device, biometric authentication system, biometric authentication method, and program
The encryption and anonymization of biometric information using a mask R and delegation template in the information processing device and biometric authentication system address privacy concerns and facilitate secure proxy authentication, improving convenience and security in biometric systems.
Patent Information
- Application Number
- JP2024067655
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-18
- Publication Date
- 2025-10-30
AI Technical Summary
Existing biometric authentication systems lack privacy protection for customer information during temporary access right transfers and are inconvenient for proxy authentication processes.
An information processing device and biometric authentication system that encrypts and anonymizes biometric authentication information using a mask R and delegation template, allowing secure proxy authentication without revealing personal information.
Ensures privacy protection and facilitates easy authority delegation using biometric information, enhancing security and convenience in proxy authentication processes.
Smart Images

Figure 2025163973000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention relates to an information processing device, a biometric authentication system, a biometric authentication method, and a program. [Background technology]
[0002] Patent Document 1 discloses a procedure management system that ensures both customer convenience and security for various procedures, while taking into account circumstances in which it is difficult for customers to use financial institutions themselves. The procedure management system includes a storage device that stores authentication information regarding customers of the financial institution and their agents, and authority information for predetermined processing regarding predetermined procedures at the financial institution.
[0003] The computing device of the procedure management system receives requests from a specified terminal for pre-registration of a specified procedure for a customer, designation of an agent to perform the specified procedure, and execution of the specified procedure by the procedure agent.The computing device of the procedure management system performs authentication processing based on the requester's authentication information and authentication information, determination processing of whether the request has authority based on the authority information of the customer or agent identified in the authentication processing, and business processing corresponding to a request for which the customer or agent is identified as having authority in the determination processing.The procedure management system requires pre-registration of rules such as consent confirmation regarding maximum amounts and execution frequency, alert notifications, and result reports.
[0004] Patent Document 2 discloses a digital asset management device capable of appropriately managing digital assets. The digital asset management device includes a registration unit, a first transmission unit, a second transmission unit, an authentication control unit, and an authorization unit. The registration unit registers agent information of an agent with member information of a member who has an account. The first transmission unit sends a confirmation message to the member if there has been no access for a set period of time set by the member. The second transmission unit sends an agent message to the agent if there is no member response. The authentication control unit controls authentication of the agent if there is a proxy response. If authentication is successful, the authorization unit grants authority over the digital assets to the agent. [Prior art documents] [Patent documents]
[0005] [Patent Document 1] International Publication No. 2016 / 194053 [Patent Document 2] International Publication No. 2023 / 062823 Summary of the Invention [Problem to be solved by the invention]
[0006] The procedure management system of Patent Document 1 lacks convenience, as it requires strict agreements regarding the details of the proxy to ensure safety when temporarily transferring access rights to an electronic wallet.
[0007] The digital asset management device of Patent Document 2 discloses customer personal information (ID, password, etc.) even if only temporarily, which makes it impossible to maintain privacy and poses the risk of future misuse.
[0008] The present invention has been made to solve the above-mentioned problems. That is, one object of the present invention is to provide an information processing device, a biometric authentication system, a biometric authentication method, and a program that can protect the privacy of a principal and realize easy authority delegation using biometric information of the principal and the agent. [Means for solving the problem]
[0009] In order to solve the above problem, an information processing device of the present invention is an information processing device including a calculation device and a storage device, wherein the storage device stores a secret information template obtained by encrypting secret information used to conceal a principal's biometric authentication information so that it can be restored using the principal's biometric authentication information, and a delegation template obtained by encrypting principal authentication information for proxy authentication delegation of the principal so that it can be restored using secret principal biometric authentication information obtained by concealing the principal's biometric authentication information using the secret information, and the calculation device is configured to provide the secret information template to a terminal used by the principal, obtain from the terminal used by the principal the encrypted secret principal biometric authentication information that is encrypted so that it can be restored using the authentication information of an agent of the principal, and provide the encrypted secret principal biometric authentication information and the delegation template to a terminal used by the agent.
[0010] The biometric authentication system of the present invention is a biometric authentication system having a plurality of terminals and a biometric template server, wherein the biometric template server holds a concealment information template obtained by encrypting concealment information used to conceal a trustor's biometric authentication information so that it can be restored using the trustor's biometric authentication information, and a delegation template obtained by encrypting trustor authentication information for proxy authentication delegation of the trustor so that it can be restored using concealed trustor biometric authentication information obtained by concealing the trustor's biometric authentication information using the concealment information, and provides the concealment information template to the terminal used by the trustor, and the terminal used by the trustor acquires the biometric authentication information from the trustor and encrypts the biometric authentication information. The method obtains the anonymized information template from a template server, restores the anonymized information from the anonymized information template using the biometric authentication information of the principal, creates the anonymized principal biometric authentication information by using the anonymization information, creates encrypted anonymized principal biometric authentication information by encrypting the anonymized principal biometric authentication information so that it can be restored using authentication information of an agent of the principal, and transmits the encrypted anonymized principal biometric authentication information directly or via the biometric template server to the terminal used by the agent, and the biometric template server provides the delegation template to the terminal used by the agent.
[0011] The biometric authentication method of the present invention is a biometric authentication method using a plurality of terminals and a biometric template server, wherein the biometric template server holds a concealment information template obtained by encrypting concealment information used to conceal a trustor's biometric authentication information so that it can be restored using the trustor's biometric authentication information, and a delegation template obtained by encrypting trustor authentication information for proxy authentication delegation of the trustor so that it can be restored using concealed trustor biometric authentication information obtained by concealing the trustor's biometric authentication information using the concealment information, and provides the concealment information template to the terminal used by the trustor, and obtains biometric authentication information from the trustor using the terminal used by the trustor, and stores the biometric template. the biometric authentication information of the principal; the biometric authentication information server obtains the anonymized information template from a biometric authentication information server, restores the anonymized information from the anonymized information template using the biometric authentication information of the principal; creates the anonymized principal biometric authentication information by using the anonymized information template to anonymize the principal biometric authentication information; creates encrypted anonymized principal biometric authentication information by encrypting the anonymized principal biometric authentication information so that it can be restored using authentication information of the principal's agent; sends the encrypted anonymized principal biometric authentication information directly or via the biometric template server to the terminal used by the agent; and provides the delegation template to the terminal used by the agent by the biometric template server.
[0012] The program of the present invention is a program that causes a computer of a terminal that acquires: an encryption information template obtained by encrypting encryption information used to conceal a principal's biometric authentication information so that it can be restored using the principal's biometric authentication information; a delegation template obtained by encrypting principal authentication information for proxy authentication delegation of the principal so that it can be restored using concealed principal biometric authentication information of the principal that has been concealed using the concealment information; and the principal's biometric authentication information, and causes the computer to execute processes of acquiring the principal's biometric authentication information, acquiring the concealment information template, restoring the concealment information from the concealment information template using the principal's biometric authentication information, creating the concealed principal biometric authentication information by concealing the principal's biometric authentication information using the concealment information, and creating the encrypted concealed principal biometric authentication information by encrypting the concealed principal biometric authentication information so that it can be restored using authentication information of a proxy of the principal. [Effects of the Invention]
[0013] According to the present invention, it is possible to protect the privacy of the principal and to easily implement authority delegation using biometric information of the principal and the agent. Note that the effects described herein are not necessarily limited to those described herein and may be any of the effects described in this disclosure. [Brief explanation of the drawings]
[0014] [Figure 1] FIG. 1 is a diagram showing an example of the configuration of a biometric authentication system according to a first embodiment of the present invention. [Figure 2] FIG. 2 is a diagram illustrating an example of the hardware configuration of a terminal. [Figure 3] FIG. 3 is a diagram illustrating an example of the hardware configuration of a computer. [Figure 4] FIG. 4 is a diagram for explaining the proxy template table. [Figure 5] FIG. 5 is a diagram for explaining the agent public key table. [Figure 6]FIG. 6 is a diagram for explaining the delegate R storage template table. [Figure 7] FIG. 7 is a diagram for explaining the delegation template table. [Figure 8] FIG. 8 is a diagram for explaining the delegation public key table. [Figure 9] FIG. 9 is a sequence diagram for explaining the operation of each terminal and server constituting the biometric authentication system. [Figure 10] FIG. 10 is a sequence diagram for explaining the operation of each terminal and server that constitute the biometric authentication system. [Figure 11] FIG. 11 is a sequence diagram for explaining the operation of each terminal and server that constitute the biometric authentication system. [Figure 12] FIG. 12 is a diagram for explaining the delegation setting screen. [Figure 13] FIG. 13 is a diagram illustrating an example of the configuration of a biometric authentication system according to the second embodiment. [Figure 14] FIG. 14 is a diagram for explaining the delegation range data table. [Figure 15] FIG. 15 is a sequence diagram for explaining the operation of each terminal and server constituting the biometric authentication system. [Figure 16] FIG. 16 is a diagram for explaining the delegation setting screen. [Figure 17] FIG. 17 is a sequence diagram for explaining the operation of each terminal and server constituting the biometric authentication system. [Figure 18] FIG. 18 is a sequence diagram for explaining the operation of each terminal and server constituting the biometric authentication system. [Figure 19] FIG. 19 is a sequence diagram for explaining the operation of each terminal and server constituting the biometric authentication system. [Figure 20] FIG. 20 is a diagram for explaining the delegation setting screen. DETAILED DESCRIPTION OF THE INVENTION
[0015] Hereinafter, each embodiment of the present invention will be described with reference to the drawings. In all the drawings of the embodiments, the same or corresponding parts may be denoted by the same reference numerals.
[0016] In the following description, various types of information may be described using expressions such as "table," but the various types of information may also be expressed using other data structures. When describing identification information, expressions such as "identification number," "name," and "ID" are used, but these are interchangeable and other expressions may also be used. Processing may be described using a functional block as the subject, but the subject of the processing may be a CPU or device instead of a functional block.
[0017] The processing performed by executing the program may be performed by a computing unit (computing device), which may include a dedicated circuit for performing specific processing. Here, the dedicated circuit may be, for example, a Field Programmable Gate Array (FPGA), an Application Specific Integrated Circuit (ASIC), or a Complex Programmable Logic Device (CPLD).
[0018] A program may be installed on a computer from a program source. The program source may be, for example, a program distribution server or a computer-readable storage medium. When the program source is a program distribution server, the program distribution server may include a processor and storage resources for storing the program to be distributed, and the processor of the program distribution server may distribute the program to be distributed to other computers. In addition, in each embodiment, two or more programs may be realized as one program, or one program may be realized as two or more programs.
[0019] <<First Embodiment>> A biometric authentication system according to a first embodiment of the present invention will now be described. FIG. 1 is a diagram showing an example of the configuration of the biometric authentication system according to the first embodiment of the present invention. As shown in FIG. 1, the biometric authentication system according to the first embodiment includes an agent registration terminal 110, an agent registration terminal 120, an agent terminal 130, an agent terminal 140, a biometric template server 150, and a service provider terminal 160. Note that a system including the agent registration terminal 110, the agent registration terminal 120, the agent terminal 130, the agent terminal 140, and the biometric template server 150 may also be referred to as a biometric authentication system.
[0020] The principal registration terminal 110, the agent registration terminal 120, the principal terminal 130, the agent terminal 140, the biometric template server 150, and the service provider terminal 160 are configured to be able to send and receive information to and from each other (be able to communicate) via a network. The network may be a local network or the Internet.
[0021] The delegator registration terminal 110 includes a biometric information acquisition function unit 111, a mask R generation function unit 112, an R restoration template creation function unit 113, and a delegation template creation function unit 114. Details of the biometric information acquisition function unit 111, the mask R generation function unit 112, the R restoration template creation function unit 113, and the delegation template creation function unit 114 will be described later. The delegator registration terminal 110 may be a fixed terminal or a portable terminal.
[0022] The agent registration terminal 120 includes a biometric information acquisition function unit 121 and an agent template creation function unit 122. Details of the biometric information acquisition function unit 121 and the agent template creation function unit 122 will be described later. The agent registration terminal 120 may be a fixed terminal or a portable terminal.
[0023] The delegator terminal 130 includes a biometric information acquisition function unit 131, a mask R restoration function unit 132, and a delegation biometric information encryption function unit 133. Details of the biometric information acquisition function unit 131, the mask R restoration function unit 132, and the delegation biometric information encryption function unit 133 will be described later. The delegator terminal 130 may be a fixed terminal or a portable terminal.
[0024] The agent terminal 140 includes a biometric information acquisition function unit 141, a delegation biometric information restoration function unit 142, and a proxy authentication function unit 143. Details of the biometric information acquisition function unit 141, the delegation biometric information restoration function unit 142, and the proxy authentication function unit 143 will be described later. The agent terminal 140 may be a fixed terminal or a portable terminal.
[0025] The biometric template server 150 includes a delegater registration function unit 151, an agent registration function unit 152, a delegation function unit 153, and a service authentication request function unit 154. Details of the delegater registration function unit 151, the agent registration function unit 152, the delegation function unit 153, and the service authentication request function unit 154 will be described later.
[0026] The biometric template server 150 holds, as databases, a proxy template table 155, a proxy public key table 156, a delegator R storage template table 157, a delegation template table 158, and a delegation public key table 159. Details of the proxy template table 155, the proxy public key table 156, the delegator R storage template table 157, the delegation template table 158, and the delegation public key table 159 will be described later.
[0027] The service provider terminal 160 includes an authentication request function unit 161 and a signature verification function unit 162. Details of the authentication request function unit 161 and the signature verification function unit 162 will be described later.
[0028] 2 is a diagram showing an example of the hardware configuration of a terminal 2000 applied to each of the principal registration terminal 110, the agent registration terminal 120, the principal terminal 130, and the agent terminal 140. As shown in Fig. 2, the terminal 2000 includes a biometric information acquisition device 2010, a display 2020, and an information processing device 2030. These are configured to be able to communicate information with each other via a bus (not shown).
[0029] The biometric information acquisition device 2010 is a device for acquiring biometric information of a specific part (e.g., face, palm print, iris, fingerprint, etc.) used for biometric authentication of a person. The biometric information acquisition device 2010 is, for example, a camera, a sensor, etc. There may be one or more biometric information acquisition devices 2010.
[0030] The display 2020 is a display device capable of displaying images. In this example, the display 2020 is a touch panel display that functions as both a display device and an input device (operation device). Note that the terminal 2000 may also include an input device (operation device) separate from the display device.
[0031] 3 is a diagram showing an example of the hardware configuration of a calculator 3000 applied to an information processing device 2030 included in a terminal 2000. The calculator 3000 may be referred to as a "computer." The calculator 3000 includes a CPU 3001, a ROM 3002, a RAM 3003, a non-volatile storage device 3004 that can read and write data, a network interface 3005, and an input / output interface 3006. These are connected to each other via a bus 3007 so as to be able to communicate with each other.
[0032] The CPU 3001 is a computing device that loads various programs (not shown) stored in the ROM 3002 and / or storage device 3004 into the RAM 3003 and executes the programs loaded into the RAM 3003, thereby realizing various functions.
[0033] As described above, the various programs executed by the CPU 3001 are loaded into the RAM 3003, and data used when the CPU 3001 executes the various programs is temporarily stored in the RAM 3003. The ROM 3002 and / or the storage device 3004 are non-volatile storage media, and the ROM 3002 and / or the storage device 3004 store various programs.
[0034] The network interface 3005 is an interface for connecting the computer 3000 to a network. The input / output interface 3006 is an interface for connecting the computer 3000 to an operation device and a display (display device) capable of displaying images.
[0035] Note that a hardware device configured with a field programmable gate array (FPGA) or the like may be used in part or in whole of the computer 3000 instead of the computer 3000. Such a hardware device may also be referred to as a "computing device."
[0036] The memory device 3004 of the information processing device 2030 of the terminal 2000 applied to the agent registration terminal 110 stores (memorizes, holds) the following programs: a biometric information acquisition function unit 111, a mask R generation function unit 112, an R restoration template creation function unit 113, and an agent template creation function unit 114.
[0037] The biometric information acquisition function unit 111 uses biometric authentication technology to acquire the biometric information of the authorized person using the biometric information acquisition device 2010. The biometric information acquisition function unit 111 in this example is configured to acquire the biometric information of the authorized person for performing face authentication, iris authentication, palm print authentication, and fingerprint authentication as biometric authentication. Note that the biometric information may be information based on biometric information such as features extracted from the biometric information. The biometric information or information based on the biometric information may be referred to as "biometric authentication information" or "template."
[0038] The mask R generation function unit 112 randomly generates a mask R (random mask R) for masking the biometric information of the trustor. The mask R is information for masking the biometric information, and in this example, the mask R is a random number. The "mask R" may be referred to as anonymization information. The biometric information of the trustor may be anonymized by encryption or the like. In this case, the information used for encryption may also be referred to as "anonymization information."
[0039] The R restoration template creation function unit 113 creates a client R storage template by encrypting the client biometric information and the mask R using an existing encryption technology so that the mask R can be restored using the client biometric information. The client R storage template is sometimes referred to as a "confidential information template."
[0040] The delegation template creation function unit 114 generates a delegation private key and a delegation public key, which are delegater authentication information, using existing encryption technology, generates information in which the delegater biometric information is masked with a mask R (hereinafter, this may be referred to as "masked R delegater biometric information" or "anonymized delegater biometric information (anonymized delegater biometric authentication information)"), and creates a delegation template by encrypting the masked R delegater biometric information and the delegation private key using existing encryption technology so that the delegation private key can be restored using the masked R delegater biometric information. Note that the delegation template creation function unit 114 can easily create a new delegation template simply by changing the mask R.
[0041] The storage device 3004 of the information processing device 2030 of the terminal 2000 applied to the agent registration terminal 120 includes, as programs, a biometric information acquisition function unit 121 and an agent's template creation function unit 122.
[0042] The biometric information acquisition function unit 121 uses biometric authentication technology to acquire biometric information of the agent (hereinafter referred to as "agent biometric information") from the biometric information acquisition device 2010. The biometric information acquisition function unit 111 in this example is capable of acquiring biometric information of the agent for performing face authentication, iris authentication, palm print authentication, and fingerprint authentication as biometric authentication.
[0043] The proxy template creation function unit 122 generates a proxy private key and a proxy public key, which are authentication information for the proxy, using existing encryption technology, and creates a proxy template by encrypting the proxy's biometric information and the proxy private key using existing encryption technology so that the proxy private key can be restored from the proxy biometric information. Although it is not possible to restore the biometric information from the proxy template, it is possible to restore the proxy private key.
[0044] The memory device 3004 of the information processing device 2030 of the terminal 2000 applied to the delegator terminal 130 stores (memorizes, holds) a biometric information acquisition function unit 131, a mask R restoration function unit 132, and a delegation biometric information encryption function unit 133 as programs.
[0045] The biometric information acquisition function unit 131 is the same as the biometric information acquisition function unit 131 of the delegater registration terminal 110 described above. The mask R restoration function unit 132 restores the mask R from the delegater R storage template using the delegater biometric information. The delegation biometric information encryption function unit 133 generates mask R delegater biometric information by masking the delegater biometric information with mask R, and then encrypts the mask R delegater biometric information using the agent public key with existing encryption technology so that the mask R delegater biometric information can be restored with the agent private key, thereby generating encrypted mask R delegater biometric information. Note that the encrypted mask R delegater biometric information is sometimes referred to as "encrypted concealed delegater biometric authentication information."
[0046] The storage device 3004 of the information processing device 2030 of the terminal 2000 applied to the agent terminal 140 stores (memorizes, holds) a biometric information acquisition function unit 141, a delegation biometric information recovery function unit 142, and a proxy authentication function unit 143 as programs.
[0047] The biometric information acquisition function unit 141 is the same as the biometric information acquisition function unit 121 of the agent registration terminal 120 described above. The delegation biometric information restoration function unit 142 restores the agent private key from the agent template using the agent biometric information, and restores the mask R agent biometric information from the encrypted mask R agent biometric information using the agent private key. The proxy authentication function unit 143 restores the delegation private key from the delegation template using the mask R agent biometric information, and performs proxy authentication using the delegation private key.
[0048] The computer 3000 shown in FIG. 3 is applied to the biometric template server 150 in FIG. 1. The computer 3000 is sometimes referred to as an "information processing device." The CPU 3001 of the biometric template server 150 executes programs stored in the ROM 3002 and / or storage device 3004 to realize various functions of the biometric template server 150. The biometric template server 150 may be composed of multiple computers 3000, and is not limited to physical computers 3000, but may also be virtual computers 3000. The computers 3000 may be computing resources and storage resources provided by a cloud, and the functions provided by the biometric template server 150 may be provided by the cloud.
[0049] The storage device 3004 of the computer 3000 applied to the biometric template server 150 stores (memorizes, holds) as programs a delegater registration function unit 151, an agent registration function unit 152, a delegation function unit 153, and a service authentication request function unit 154. The storage device 3004 of the computer 3000 applied to the biometric template server 150 stores (memorizes, holds) as databases a delegate template table 155, an agent public key table 156, a delegater R storage template table 157, a delegation template table 158, and a delegation public key table 159.
[0050] The delegator registration function unit 151 acquires the delegator R storage template from the delegator registration terminal 110 and stores the delegator R storage template in the delegator R storage template table 157. The delegator registration function unit 151 acquires the delegation template from the delegator registration terminal 110 and stores the delegation template in the delegation template table 158.
[0051] The delegator registration function unit 151 acquires the delegation public key from the delegator registration terminal 110 and stores the delegation public key in the delegation public key table 159 .
[0052] Proxy registration function unit 152 acquires a proxy template from proxy registration terminal 120 and stores the proxy template in proxy template table 155. Proxy registration function unit 152 acquires a proxy public key from proxy registration terminal 120 and stores the proxy public key in proxy public key table 156.
[0053] The delegation function unit 153 performs processing when a delegator delegates proxy authentication to a proxy. The service authentication request function unit 154 performs processing when the proxy terminal 140 requests authentication from the service provider terminal 160.
[0054] FIG. 4 is a diagram illustrating proxy template table 155. As shown in FIG. 4, proxy template table 155 includes a proxy ID 401 and an encrypted template 402 as columns for storing information (values). In proxy template table 155, information corresponding to each column for managing proxy templates is associated with each other and stored as row-by-row information (records). Specifically, an identification number for identifying the proxy is stored in proxy ID 401. An proxy template is stored in encrypted template 402.
[0055] Fig. 5 is a diagram illustrating the agent public key table 156. As shown in Fig. 5, the agent public key table 156 includes an agent ID 501 and a public key 502 as columns for storing information (values). In the agent public key table 156, information corresponding to each column for managing the agent public key is associated with each other and stored as row-based information (records). Specifically, the agent ID 501 stores an identification number for identifying the agent. The public key stores an agent private key.
[0056] FIG. 6 is a diagram illustrating the delegator R storage template table 157. As shown in FIG. 6, the delegator R storage template table 157 includes a delegator ID 601 and an encrypted template 602 as columns for storing information (values). In the delegator R storage template table 157, information corresponding to each column for managing the delegator R storage template is associated with each other and stored as row-based information (records). Specifically, the delegator ID 601 stores an identification number for identifying the delegator. The encrypted template 602 stores the delegator R storage template.
[0057] FIG. 7 is a diagram illustrating the delegation template table 158. As shown in FIG. 7, the delegation template table 158 includes a delegator ID 701 and an encrypted template 702 as columns for storing information (values). In the delegation template table 158, information corresponding to each column for managing the delegation template is associated with each other and stored as row-based information (records). Specifically, the delegator ID 701 stores an identification number for identifying the delegator. The encrypted template 702 stores the delegation template.
[0058] Fig. 8 is a diagram illustrating the delegation public key table 159. As shown in Fig. 8, the delegation public key table 159 includes a delegator ID 801 and a public key 802 as columns for storing information (values). In the delegation public key table 159, information corresponding to each column for managing the delegation public key is associated with each other and stored as row-based information (records). Specifically, the delegator ID 801 stores an identification number for identifying the delegator. The public key 802 stores the delegation public key.
[0059] The computer 3000 shown in Fig. 3 is applied to the service provider terminal 160 in Fig. 1. The CPU 3001 of the service provider terminal 160 executes programs stored in the ROM 3002 and / or the storage device 3004 to realize various functions of the service provider terminal 160. The service provider terminal 160 may be configured with multiple computers 3000, and is not limited to physical computers 3000, but may also be virtual computers 3000. The computers 3000 may be computing resources and storage resources provided by the cloud, and the functions provided by the service provider terminal 160 may be provided by the cloud.
[0060] The storage device 3004 of the computer 3000 applied to the service provider terminal 160 includes, as programs, an authentication request function unit 161 and a signature verification function unit 162. The authentication request function unit 161 requests authentication from the terminal receiving the service in order to receive the service provided by the service provider terminal 160. The signature verification function unit 162 verifies the signature and determines whether the authentication is successful.
[0061] <Summary> An overview of the present invention will be described. The biometric authentication system uses biometric information of the principal and the agent to easily realize delegation of proxy authentication and proxy authentication by the agent. Proxy authentication means that the agent is authenticated (authentication is successful) on behalf of the principal.
[0062] Before delegating proxy authentication, the delegate registers the delegation template, the delegate R storage template, and the delegation public key in the biometric template server 150 using the delegate registration terminal 110.
[0063] Before being delegated proxy authentication, the proxy registers a proxy template and a proxy public key in the biometric template server 150 using the proxy registration terminal 120. This enables the biometric authentication system to delegate proxy authentication from the proxy to the proxy using the proxy's biometric information, and to perform proxy authentication using the proxy's biometric information. Note that if there are multiple proxies who have registered proxy templates and proxy public keys, the proxy can select from the multiple proxies to delegate. Simply registering the proxy template and proxy public key does not determine who the proxy will be.
[0064] When a principal delegates proxy authentication to an agent, the principal designates the agent (e.g., agent B) and has the principal's biometric information read into the principal terminal 130. The principal terminal 130 acquires the principal R storage template from the biometric template server 150, restores the mask R from the principal R storage template using the principal's biometric information, and generates the mask R principal biometric information using the restored mask R and the principal's biometric information. In this way, the principal terminal 130 protects the principal's biometric information.
[0065] Furthermore, the delegater terminal 130 acquires the delegater public key of the designated delegate B, and uses the delegater public key of the delegater B to encrypt the Mask R delegater biometric information so that the Mask R delegater biometric information can be restored using the delegater private key. The encrypted Mask R delegater biometric information is then transmitted to the delegater terminal 140 via the biometric template server 150. This completes the delegation of proxy authentication from the delegater to the delegater B.
[0066] Thereafter, agent B can use his / her biometric information to perform proxy authentication (i.e., agent B can use his / her biometric information to be authenticated (authentication successful) to receive services from the service provider terminal 160 on behalf of the principal).
[0067] When agent B receives authentication (proxy authentication) to receive a service from the service provider terminal 160, he or she has the agent terminal 140 read the agent B's biometric information. The agent terminal 140 obtains the encrypted mask R delegater biometric information and the agent template from the biometric template server 150. The service provider terminal 160 also obtains the delegater's delegation public key, which is required for authentication, from the biometric template server 150.
[0068] The agent terminal 140 restores the agent private key from the agent template using the biometric information of agent B, and restores the mask R delegater biometric information from the encrypted mask R delegater biometric information using the agent private key.
[0069] The agent terminal 140 obtains the delegation template from the biometric template server 150 and restores the delegation private key from the delegation template using the Mask R delegator biometric information. The agent terminal 140 can use the delegation private key to receive authentication (authentication permission) for the service provided by the service provider terminal 160.
[0070] <Activation> The operation of the biometric authentication system will now be described in detail. Fig. 9 is a sequence diagram illustrating the operation of the delegater registration terminal 110 and the biometric template server 150 when the delegater registration terminal 110 registers the delegation template and the delegater R-storage template in the biometric template server 150.
[0071] Step 901: When the delegater registration terminal 110 is operated by the delegater, the delegater registration terminal 110 transmits to the biometric template server 150 a command to call the delegater registration function.
[0072] Step 902: Upon receiving the command, the biometric template server 150 transmits to the delegater registration terminal 110 an instruction to start processing to be performed on the delegater registration terminal 110 side.
[0073] Step 903: The delegate registration terminal 110 generates a random mask R (random number).
[0074] Step 904: The delegater registration terminal 110 acquires the delegater's biometric information (delegator's biometric information).
[0075] Step 905: The delegater registration terminal 110 creates a delegater R storage template by encrypting the delegater biometric information and the mask R so that the mask R can be restored from the delegater biometric information. The delegater registration terminal 110 transmits the delegater R storage template to the biometric template server 150.
[0076] Step 906: The biometric template server 150 receives the delegater R storage template from the delegater registration terminal 110 and stores it in the delegater R storage template table 157.
[0077] Step 907: The delegator registration terminal 110 generates a delegation private key and a delegation public key.
[0078] Step 908: The delegator registration terminal 110 creates mask R delegator biometric information by masking the delegator biometric information with mask R. The delegator registration terminal 110 creates a delegation template by encrypting the mask R delegator biometric information and the delegation private key so that the delegation private key can be restored using the mask R delegator biometric information. The delegator registration terminal 110 sends the delegation template to the biometric template server 150. The delegator registration terminal 110 sends the delegation public key to the biometric template server 150.
[0079] Step 909: The delegator registration terminal 110 receives the delegation template and the delegation public key from the delegator registration terminal 110, associates the delegation template with the delegator ID and registers it in the delegation template table 158, and associates the delegation public key with the delegator ID and registers it in the delegation public key table 159. From the viewpoint of information protection, it is preferable to discard (delete) the delegation template, delegation private key, and delegation public key from the delegator registration terminal 110 after registration.
[0080] FIG. 10 is a sequence diagram for explaining the operations of the agent registration terminal 120 and the biometric template server 150 when the agent registration terminal 120 registers an agent template and an agent public key in the biometric template server 150.
[0081] Step 1001: When the agent operates the agent registration terminal 120, the agent registration terminal 120 transmits to the biometric template server 150 a command to call up the agent registration function.
[0082] Step 1002: Upon receiving the command, the biometric template server 150 transmits to the agent registration terminal 120 an instruction to start processing to be performed on the agent registration terminal 120 side.
[0083] Step 1003: The agent registration terminal 120 acquires the biometric information of the agent (agent biometric information).
[0084] Step 1004: The agent registration terminal 120 generates an agent private key and an agent public key.
[0085] Step 1005: The agent registration terminal 120 creates a template for the agent by encrypting the agent biometric information and the agent private key so that the agent private key can be restored from the agent's biometric information. The agent registration terminal 120 sends the agent template to the biometric template server 150 and sends the agent public key to the biometric template server 150.
[0086] Step 1006: The biometric template server 150 receives the proxy template and proxy public key from the proxy registration terminal 120, associates the proxy template with the proxy identification ID and registers it in the proxy template table 155, and associates the proxy public key with the proxy identification ID and registers it in the proxy public key table 156. From the perspective of information protection, it is preferable to discard (delete) the proxy template, proxy private key, and proxy public key from the proxy registration terminal 120 after registration.
[0087] FIG. 11 is a sequence diagram for explaining the operations of the principal terminal 130, the agent terminal 140, the biometric template server 150, and the service provider terminal 160 when delegating proxy authentication from the principal to the agent and performing proxy authentication by the agent in the biometric authentication system.
[0088] Step 1101: The delegator (delegator A) operates the delegator terminal 130. The delegator terminal 130 transmits a command to the biometric template server 150 to call the delegation function of the biometric template server 150 based on the operation of the delegator.
[0089] Step 1102: Upon receiving the command, the biometric template server 150 transmits to the delegate terminal 130 an instruction to start processing to be performed on the delegate terminal 130 side.
[0090] Step 1103: The delegate terminal 130 acquires the delegate A's delegate R stored template from the biometric template server 150.
[0091] Step 1104: The delegate terminal 130 acquires the delegate A's biometric information.
[0092] Step 1105: The delegate terminal 130 restores the random mask R from the delegate R storage template of the delegate A acquired in step 1103, using the delegate A's biometric information.
[0093] Step 1106: The delegate terminal 130 creates masked R delegate biometric information by masking the biometric information of the delegate A with the mask R. This protects the biometric information of the delegate A, which is important as personal information.
[0094] Step 1107: The delegate terminal 130 obtains the delegate B's delegate public key from the biometric template server 150.
[0095] Step 1108: The delegate terminal 130 uses the delegate B's delegate public key and the delegate mask R biometric information to generate encrypted delegate mask R biometric information so that the delegate mask R biometric information can be restored with the delegate private key.
[0096] Step 1109: The delegator terminal 130 transmits the encrypted mask R delegator biometric information to the biometric template server 150. The delegator terminal 130 protects the mask R delegator biometric information by transmitting encrypted information so that the mask R delegator biometric information cannot be restored by anyone other than the agent of the delegatee.
[0097] Step 1110: The biometric template server 150 transmits the encrypted mask R delegater biometric information to the proxy terminal 140, and instructs the proxy terminal 140 to start processing on the proxy terminal 140 side.
[0098] Step 1111: The agent terminal 140 acquires the agent template for agent B from the biometric template server 150.
[0099] Step 1112: The agent terminal 140 acquires agent B's biometric information.
[0100] Step 1113: The agent terminal 140 restores the agent private key of agent B from the agent template using the biometric information of agent B.
[0101] Step 1114: The agent terminal 140 uses the agent private key of the agent B to obtain the mask R agent biometric information from the encrypted mask R agent biometric information.
[0102] Step 1115: The proxy terminal 140 acquires the delegation template of the delegator A from the biometric template server 150.
[0103] Step 1116: The agent terminal 140 restores the delegator A's delegator private key from the delegator template using the mask R delegator biometric information.
[0104] Step 1117: The agent terminal 140 requests the service from the service provider terminal 160.
[0105] Step 1118: The service provider terminal 160 obtains the delegator A's delegator public key from the biometric template server 150.
[0106] Step 1119 : The service provider terminal 160 sends an authentication request to the agent terminal 140 .
[0107] Step 1120 : The agent terminal 140 creates a digital signature using the delegator A's delegator private key, and transmits it to the service provider terminal 160 .
[0108] Step 1121: The service provider terminal 160 verifies the signature using the delegation public key.
[0109] Step 1122: If the authentication is successful (verification is successful) as a result of the signature verification, the service provider terminal 160 provides the service to the agent terminal 140.
[0110] 12 is a diagram illustrating a delegation setting screen 1200 displayed on the delegator terminal 130 when the delegator delegates a proxy. The delegation setting screen 1200 is a GUI (Graphical User Interface) screen. The delegation setting screen 1200 includes an authentication method setting button 1201, a proxy ID input box 1202, and a delegation start button 1203.
[0111] The authentication method setting button 1201 is a button made up of an image that is operated to select an authentication method for biometric authentication. In this example, the authentication method setting button 1201 allows selection from face authentication, palm print authentication, fingerprint authentication, and iris authentication. The agent ID input box 1202 is an input box for inputting the ID (identification number) of the agent. The delegation start button 1203 is a button that is operated to start delegation.
[0112] 11, the principal selects an authentication method by operating the authentication method setting button 1201 via the operation device. The principal terminal 130 authenticates the principal using the selected authentication method. If the principal authentication is successful, the principal terminal 130 completes the authentication.
[0113] The principal designates a proxy by inputting the proxy ID into the proxy ID input box 1202 via an operating device. When the principal terminal 130 confirms the designated proxy, it completes the confirmation of the proxy.
[0114] When the delegation start button 1203 is operated after the personal authentication and confirmation of the agent are completed, the agent terminal 130 sends a command to call the delegation function to the biometric template server 150. Thereafter, the agent terminal 130 executes steps 1105 to 1109 as described above to create encrypted R-masked agent biometric information using the agent's biometric information, and transmits the encrypted R-masked agent biometric information to the agent terminal 140 used by the agent via the biometric template server 150. As described above, when the agent terminal 140 receives (acquires) the encrypted R-masked agent biometric information, it uses the agent's biometric information to restore the delegation private key from the encrypted R-masked agent biometric information, thereby becoming able to perform proxy authentication. This completes the delegation of proxy authentication to the agent using the agent's biometric information.
[0115] <Effects> As described above, the biometric authentication system according to the first embodiment of the present invention can easily perform authority delegation while protecting the biometric information of the principal, by using the biometric information of the principal and the biometric information of the agent.
[0116] <<Second embodiment>> A biometric authentication system according to a second embodiment of the present invention will now be described. The biometric authentication system according to the second embodiment differs from the biometric authentication system according to the first embodiment only in the following points.
[0117] The biometric authentication system according to the second embodiment executes delegation of proxy authentication with a delegation scope from a trustor to a proxy, and proxy authentication with a delegation scope by the proxy.
[0118] The following description will focus on this difference.
[0119] <Configuration> Fig. 13 shows an example of the configuration of a biometric authentication system according to the second embodiment. As shown in Fig. 13, in the biometric authentication system according to the second embodiment, the delegator terminal 130 has a delegation range setting function unit 134, and the biometric template server 150 has a delegation range data table 159a. The rest is the same as the example of the configuration of the biometric authentication system shown in Fig. 1.
[0120] The delegation range setting function unit 134 creates delegation range data that indicates the delegation range.
[0121] Fig. 14 is a diagram for explaining the delegation range data table 159a. As shown in Fig. 14, the delegation range data table 159a includes columns for storing information (values), such as a delegator ID 1401, delegation details 1402, number of times 1403, location 1404, and deadline 1405.
[0122] In the delegation range data table 159a, information corresponding to each column for managing the delegation range is associated with each other and stored as row-based information (records). Specifically, the delegator ID 1401 stores an identification number for identifying the delegator. The delegation content 1402 stores the content of the delegation range of proxy authentication delegated by the delegator to the proxy. The number of times 1403 stores the number of times proxy authentication can be performed by the proxy. The location 1404 stores the location where proxy authentication can be performed by the proxy. The expiration date 1405 stores the expiration date for proxy authentication by the proxy.
[0123] <Summary> When a principal A delegates proxy authentication to an agent (for example, agent B), the principal A designates agent B and has the agent A's biometric information read into the agent registration terminal 110, and also inputs the scope of delegation into the agent registration terminal 110.
[0124] The delegate registration terminal 110 creates delegated range data (data corresponding to a row (record) in the delegated range data table 159a) based on the input delegated range, sends it to the biometric template server 150, and registers the delegated range data in the delegated range data table 159a.
[0125] If the proxy authentication is successful, the service provider terminal 160 checks the delegation scope of the proxy authentication by referring to the delegation scope data in the biometric template server 150. If the proxy authentication by the proxy (the content of the service received by the proxy, the number of delegations, the place where the service is received, and the delegation period) is within the delegation range, the service provider terminal 160 provides the service within the delegation range, and if the proxy authentication by the proxy (at least one of the content of the service received by the proxy, the number of delegations, the place where the service is received, and the delegation period) is outside the delegation range (if it is not within the delegation range), the service is not provided.
[0126] As described above, the biometric authentication system can realize flexible and easy authority delegation using the biometric information of the principal and the agent, while protecting the privacy (biometric information) of the principal.
[0127] An example of use of the biometric authentication system according to the second embodiment will be described. For example, if a delegator is a parent and delegates (requests) the purchase of alcoholic beverages to a minor child acting as the proxy of the parent, by setting the scope of delegation so that purchases are limited to one at a specified store, the minor child acting as proxy will be prevented from purchasing alcoholic beverages outside the scope of delegation requested by the parent. For example, if the delegator is a person requiring care and the delegator requests an assistant who assists in the care of the delegator to purchase only necessary items, by setting the scope of delegation so that only necessary items can be purchased, the assistant acting as proxy will be prevented from purchasing items outside the scope of delegation.
[0128] <Activation> FIG. 15 is a sequence diagram for explaining the operation of the biometric authentication system when a proxy authentication is delegated from a trustor to a proxy and proxy authentication is performed by the proxy.
[0129] After the delegator terminal 130 performs the above-mentioned step 1101 and the biometric template server 150 performs the above-mentioned step 1102, the delegator terminal 130 performs the following step 1511.
[0130] Step 1511: The delegator terminal 130 creates delegation range data, transmits it to the biometric template server 150, and registers (stores) the delegation range data in the delegation range data table 159a of the biometric template server 150.
[0131] Thereafter, the delegate terminal 130 performs the above-described steps 1103 to 1109 to create the encrypted mask R delegate biometric information and transmits the encrypted mask R delegate biometric information to the biometric template server 150 .
[0132] After the biometric template server 150 performs the above-mentioned step 1110, the agent terminal 140 performs the above-mentioned steps 1111 to 1116, and sends a service request to the service provider terminal 160 in the above-mentioned step 1117. The service provider terminal 160 executes the above-mentioned step 1118. Thereafter, the service provider terminal 160 performs the following step 1521.
[0133] Step 1521: After step 1118, the service provider terminal 160 acquires the delegator A's delegation range data from the delegation template table 158 of the biometric template server 150.
[0134] Thereafter, the service provider terminal 160 performs the above-described step 1119, and the agent terminal 140 performs the above-described step 1120. The service provider terminal 160 performs the above-described step 1121, and the signature verification is successful. Thereafter, the service provider terminal 160 performs the following steps 1522 and 1523 in order.
[0135] Step 1522: The service provider terminal 160 compares the proxy request (content of service to be received by the proxy, number of times of delegation, place of receiving the service, and deadline for delegation) with the delegation range data, and notifies the delegator terminal 130 of the comparison result.
[0136] Step 1523: If the comparison result is within the delegation range, the service provider terminal 160 provides the service to the agent terminal 140.
[0137] As described above, the biometric authentication system can delegate proxy authentication with a set delegation range to an agent using the biometric information of the agent. The biometric authentication system can perform proxy authentication within the delegation range using the biometric information of the agent. This allows the biometric authentication system to realize flexible authority delegation.
[0138] 16 is a diagram illustrating a delegation setting screen 1200 displayed on the delegator terminal 130 when the delegator delegates a proxy. As shown in Fig. 16, the delegation setting screen 1200 includes a delegation range designation box 1601 in addition to the authentication method setting button 1201, proxy ID input box 1202, and delegation start button 1203 described above.
[0139] The delegation range designation box 1601 is an input box for inputting the delegation content, number of times, location, and deadline. In step 1101 of Fig. 15, the delegator inputs the delegation content, number of times, location, and deadline into the delegation range designation box 1601 via the operation device. The delegator terminal 130 creates delegation range data based on the input delegation content, number of times, location, and deadline.
[0140] <Effects> As described above, the biometric authentication system according to the second embodiment of the present invention can realize flexible and easy authority delegation using the biometric information of the principal and the agent, while protecting the privacy of the principal.
[0141] <<Third Embodiment>> A biometric authentication system according to a third embodiment of the present invention will now be described. The biometric authentication system according to the third embodiment differs from the biometric authentication system according to the first embodiment only in the following points.
[0142] The biometric authentication system according to the third embodiment sets a delegation range and executes delegation authentication of an agent from an agent. Note that while in the second embodiment the delegation range data is registered in the biometric template server 150, in the third embodiment the delegation range data is associated with the mask R delegator biometric information, and the mask R delegator biometric information and the delegation range data are encrypted.
[0143] The following explanation will focus on these differences.
[0144] <Activation> FIG. 17 is a sequence diagram for explaining the operation when the biometric authentication system executes delegation of proxy by the agent and proxy authentication by the agent.
[0145] After the delegator terminal 130 performs the above-mentioned step 1101 and the biometric template server 150 performs the above-mentioned step 1102, the delegator terminal 130 performs the following step 1711.
[0146] Step 1711: The delegator terminal 130 creates delegation range data. Thereafter, the delegator terminal 130 performs the above-described steps 1103 to 1107 to create the mask R delegator biometric information and obtain the public key of the agent B. Thereafter, the delegator terminal 130 executes steps 1712 and 1713 described below.
[0147] Step 1712: The delegate terminal 130 uses the delegate B's delegate public key to encrypt the Mask R delegate biometric information and delegation range data so that they can be restored with the delegate private key, thereby creating encrypted Mask R delegate biometric information (with delegation range).
[0148] Step 1713: The delegater terminal 130 transmits the encrypted mask R delegater biometric information (with the delegation range) to the biometric template server 150.
[0149] Thereafter, the biometric template server 150 executes step 1714 below.
[0150] Step 1714: The biometric template server 150 transmits the encrypted mask R delegater biometric information (with the delegation range) to the proxy terminal 140, and instructs the proxy terminal 140 to start processing on its side.
[0151] Thereafter, the proxy terminal 140 sequentially executes the above-mentioned steps 1111 to 1113. Thereafter, the proxy terminal 140 executes the following step 1715.
[0152] Step 1715: The agent terminal 140 uses the agent private key to restore the encrypted mask R delegater biometric information (with delegation range) to obtain the mask R delegater biometric information and delegation range data.
[0153] Thereafter, the agent terminal 140 executes the above-mentioned steps 1115 and 1116, and then proceeds to step 1716 to transmit the delegation range data together with the service request to the service provider terminal 160. By transmitting only the delegation range data to the agent from the agent terminal 140, the overall picture of the delegation content set by the user of the biometric authentication system can be concealed from the service provider, and privacy can be protected.
[0154] Thereafter, the service provider terminal 160 performs the above-described steps 1118 and 1119 to obtain the delegator A's delegator public key and requests authentication from the agent terminal 140. Thereafter, the agent terminal 140 performs the above-described step 1120. The service provider terminal 160 performs the signature verification (verification successful) in the above-described step 1121. Thereafter, the service provider terminal 160 performs the following steps 1717 and 1718.
[0155] Step 1717: The service provider terminal 160 compares the proxy request with the delegation range data and notifies the comparison result to the delegator terminal 130. This allows the delegator to recognize that proxy authentication has been performed within the delegation range.
[0156] Step 1718: If the comparison result indicates that the service is within the delegation range, the service provider terminal 160 provides the service to the agent terminal 140.
[0157] <Effects> The biometric authentication system according to the third embodiment of the present invention can realize flexible and easy authority delegation using biometric information of the principal and the agent, while protecting the privacy of the principal.
[0158] <<Fourth Embodiment>> A biometric authentication system according to a fourth embodiment of the present invention will be described. The biometric authentication system according to the fourth embodiment differs from the biometric authentication system according to the second embodiment only in the following points.
[0159] The biometric authentication system according to the fourth embodiment issues an alert to the principal and the agent if the proxy authentication by the agent is outside the delegation range. When the number of delegations within the delegation range or the expiration date has passed, the biometric authentication system according to the fourth embodiment deletes the delegation template and invalidates the delegation.
[0160] The following explanation will focus on these differences.
[0161] <Activation> 18 and 19 are sequence diagrams for explaining the operation of the biometric authentication system when it executes delegation of proxy by an agent and proxy authentication by an agent.
[0162] The delegator terminal 130 performs the above-mentioned step 1101, and the biometric template server 150 performs the above-mentioned step 1102. Thereafter, the delegator terminal 130 performs the above-mentioned step 1511, and then performs the above-mentioned steps 1103 to 1109. As a result, the delegator terminal 130 creates the encrypted mask R delegator biometric information and transmits the encrypted mask R delegator biometric information to the biometric template server 150.
[0163] After the biometric template server 150 performs the above-mentioned step 1110, the proxy terminal 140 performs the above-mentioned steps 111 to 1116.
[0164] After step 1109, the delegator terminal 130 performs steps 1801 to 1806.
[0165] Step 1801: The delegator A operates the delegator terminal 130. The delegator terminal 130 invokes the delegation function.
[0166] Step 1802: The delegator terminal 130 generates a random mask R (random number). Note that in step 1802, a mask R different from the mask R in step 1106 is generated.
[0167] Step 1803: The delegator terminal 130 acquires the delegator biometric information. Note that the delegator terminal 130 may retain the biometric information acquired in step 1104 up to step 1803 and use the retained biometric information.
[0168] Step 1804: The delegater terminal 130 creates a delegater R storage template by encrypting the delegater biometric information and the mask R so that the mask R can be restored from the delegater biometric information. Note that the mask R used here is different from the mask R used in step 1106.
[0169] Step 1805: The delegator terminal 130 generates a delegation private key and a delegation public key.
[0170] Step 1806: The delegator terminal 130 creates mask R delegator biometric information by masking the delegator biometric information with mask R. The delegator terminal 130 creates a delegation template by encrypting the mask R delegator biometric information and the delegation private key so that the delegation private key can be restored using the mask R delegator biometric information. The delegator terminal 130 retains the created delegation template.
[0171] After performing step 1116 described above, the agent terminal 140 performs step 1117 described above in Fig. 19 to make a service request to the service provider terminal 160. The service provider terminal 160 then executes step 1118 described above. Thereafter, the service provider terminal 160 acquires the delegation range data of the delegator A by performing step 1521 described above.
[0172] Thereafter, the service provider terminal 160 performs the above-mentioned step 1119, and the agent terminal 140 performs the above-mentioned step 1120. The service provider terminal 160 performs the above-mentioned steps 1121 and 1522, and if the comparison result shows that the agent request differs from the delegation scope, it performs step 1901 described below.
[0173] Step 1901: If the comparison result indicates that the proxy request is outside the delegation range, the biometric template server 150 does not provide the service and alerts the principal and the proxy. This allows the biometric template server 150 to alert the principal and the proxy that a service request has been made outside the delegation range.
[0174] Step 1902: If the comparison result indicates that the proxy request is within the delegation range, the biometric template server 150 provides the service (step 1523) and notifies the delegator and the proxy.
[0175] Step 1903: If the number of delegations for the delegation range has run out or the delegation period for the delegation range has expired, the biometric template server 150 deletes the registered delegation template and delegator R stored template corresponding to the delegator from the delegation template table 158 and the delegator R stored template table 157, and notifies the delegator terminal 130 of this.
[0176] Step 1904: The delegator terminal 130 registers the new delegator template and the new delegator R-storage template in the delegator template table 158 and the delegator R-storage template table 157 of the biometric template server 150. In other words, in steps 1903 and 1904, the delegator terminal 130 updates the delegation template and the delegator R-storage template held by the biometric template server 150 with the new delegation template and the new delegator R-storage template. The delegator terminal 130 also updates the delegation public key registered in the delegation public key table 159 corresponding to the delegator with the new delegation public key.
[0177] When the old delegation template, old delegator R storage template, and old delegation public key are updated with the new delegation template, new delegator R storage template, and new delegation public key, the old delegation template, old delegator R storage template, old delegator public key, and old encrypted mask R delegator biometric information become unusable.
[0178] In this way, when the delegation to the agent ends (for example, when the delegation ends due to the expiration of the delegation count or the lapse of the delegation period), the biometric authentication system makes the delegator R storage template, delegation public key, delegation template, and encrypted mask R delegator biometric information used for the delegation unusable. Forcing the delegator to register a new delegator R storage template, delegation public key, and delegation template each time a delegation ends would impose a cumbersome procedure on the delegator.
[0179] Therefore, in the biometric authentication system, the delegator terminal 130 sends the encrypted mask R delegator biometric information in step 1109, and then executes steps 1801 to 1806 to create and store a new delegator R storage template, delegation public key, and delegation template. Note that a new delegator R storage template can be created simply by changing the mask R.
[0180] When the number of delegations or the delegation period for the delegated proxy authentication expires, the biometric template server 150 deletes the delegator R stored template, delegation public key, and delegation template corresponding to the delegator. After deleting the delegator R stored template, delegation public key, and delegation template, the delegator terminal 130 automatically registers the delegator R stored template, delegation public key, and delegation template in the biometric template server 150. This invalidates the delegation of the delegated proxy authentication, and the biometric authentication system becomes able to allow the delegator to execute a new proxy authentication delegation.
[0181] <Effects> As described above, the biometric authentication system according to the fourth embodiment of the present invention can realize flexible and easy authority delegation using the biometric information of the principal and the agent, while protecting the privacy (biometric information) of the principal.
[0182] <<Fifth Embodiment>> A biometric authentication system according to a fifth embodiment of the present invention will be described. The biometric authentication system according to the fifth embodiment differs from the biometric authentication system according to the first embodiment only in the following points.
[0183] In the biometric authentication system according to the fifth embodiment, the delegator can stop delegation at any timing.
[0184] The following explanation will focus on these differences.
[0185] 20 is a diagram illustrating a delegation setting screen 1200 that is displayed on the delegator terminal 130 when the delegator terminates the delegation of a proxy. As shown in Fig. 20, the delegation setting screen 1200 includes a delegation termination button 2001. The delegation termination button 2001 is a button that is operated to terminate the delegation.
[0186] When the delegator operates the delegator stop button 2001, the delegator terminal 130 performs operations to stop the delegation. Specifically, the delegator terminal 130 operates in the same manner as steps 1801 to 1806 in Fig. 18, generating a delegation private key and a delegation public key, and generating a new delegator R storage template and a new delegator template.
[0187] The delegator terminal 130 transmits the newly generated new delegator R storage template, the new delegation public key, and the delegator R storage template to the biometric template server 150.
[0188] The biometric template server 150 updates the encrypted template corresponding to the delegator in the delegator R storage template table 157 with the received new delegator R storage template. The biometric template server 150 updates the delegator public key corresponding to the delegator in the delegator public key table 159 with the received new delegation public key. The biometric template server 150 updates the encrypted template corresponding to the delegator in the delegator template table 158 with the received new delegation template.
[0189] After this, the old encrypted Mask R Delegator Biometric Information (the old Mask R Delegator Biometric Information and the old delegation private key restored from it) will no longer function effectively (will become unusable). In other words, authentication of a service request using the old delegation private key restored from the old delegation template will result in an authentication failure. It is not possible to restore the new delegation private key from the new delegation template using the old Mask R Delegator Biometric Information.
[0190] When the principal newly delegates proxy authentication to an agent, the principal terminal 130 generates new encrypted mask R delegater biometric information using the principal's biometric information and transmits it to the agent terminal 140 of the agent who delegates proxy authentication. Specifically, the principal terminal 130 uses the principal's biometric information to obtain a new mask R from the new principal R storage template and masks the delegater biometric information with the new mask R to create new mask R delegater biometric information, encrypts the new mask R delegater biometric information with the agent public key of the agent who delegates proxy authentication to create new encrypted mask R delegater biometric information, and transmits the new encrypted mask R delegater biometric information to the agent terminal 140. The agent terminal 140 can then perform proxy authentication using the received new encrypted mask R delegater biometric information.
[0191] <Effects> As described above, the biometric authentication system according to the fifth embodiment of the present invention has the same effects as those of the first embodiment. Furthermore, the biometric authentication system according to the fifth embodiment allows the delegator to easily stop the delegation of proxy authentication at any timing of their choice based on their operation.
[0192] <<Modifications>> The present invention is not limited to the above-described embodiments, and various modifications can be adopted within the scope of the present invention. Furthermore, the above-described embodiments can be combined with each other without departing from the scope of the present invention.
[0193] In each of the above embodiments, the biometric authentication system may be configured such that the principal registration terminal 110 and the principal terminal 130 are replaced with terminals having the functions of the principal registration terminal 110 and the functions of the principal terminal 130. The biometric authentication system may be configured such that the agent registration terminal 120 and the agent terminal 140 are replaced with terminals having the functions of the agent registration terminal 120 and the functions of the agent terminal 140.
[0194] In each of the above embodiments, the principal terminal 130 transmitted the encrypted R mask principal biometric information to the agent terminal 140 of the agent requesting the delegation via the biometric template server 150, but it may also be configured to transmit it directly to the agent terminal 140 of the agent requesting the delegation without going through the biometric template server 150.
[0195] The present invention can also have the following configuration.
[0196] [1] Multiple devices and a biometric template server; A biometric authentication method using The biometric template server a concealment information template obtained by encrypting concealment information used to conceal the biometric authentication information of an authorized person so that the concealment information can be restored using the biometric authentication information of the authorized person; a delegation template that encrypts the delegater authentication information for proxy authentication delegation of the delegater so that the delegater's biometric authentication information can be restored using the concealed delegater biometric authentication information that has been concealed using the concealment information; and providing the concealment information template to the terminal used by the delegater. The terminal used by the delegate acquiring biometric authentication information from the principal, acquiring the anonymized information template from the biometric template server, restoring the anonymized information from the anonymized information template using the biometric authentication information of the principal, encrypting the anonymized biometric authentication information of the principal using the anonymized information to create the anonymized principal biometric authentication information, encrypting the anonymized principal biometric authentication information so that it can be restored using authentication information of an agent of the principal, to create encrypted anonymized principal biometric authentication information, and transmitting the encrypted anonymized principal biometric authentication information to the terminal used by the agent directly or via the biometric template server; The biometric template server providing the delegation template to the terminal used by the agent; Biometric authentication methods.
[0197] [2] a concealment information template obtained by encrypting concealment information used to conceal the biometric authentication information of an authorized person so that the concealment information can be restored using the biometric authentication information of the authorized person; a delegation template in which the delegater authentication information for proxy authentication delegation of the delegater is encrypted so that it can be restored using concealed delegater biometric authentication information obtained by concealing the delegater's biometric authentication information using the concealment information; biometric information of the authorizer; A program that causes a computer of a terminal that acquires the information to execute processing, The computer, a process of acquiring biometric authentication information of the principal, acquiring the concealed information template, restoring the concealed information from the concealed information template using the biometric authentication information of the principal, concealing the biometric authentication information of the principal using the concealed information to create the concealed principal biometric authentication information, and encrypting the concealed principal biometric authentication information so that it can be restored using authentication information of an agent of the principal, thereby creating encrypted concealed principal biometric authentication information; Let it run, program. [Explanation of symbols]
[0198] 110... Delegator registration terminal, 120... Proxy registration terminal, 130... Delegator terminal, 140... Proxy terminal, 150... Biometric template server, 155... Proxy template table, 156... Proxy public key table, 157... Delegator R storage template table, 158... Delegation template table, 159... Delegation public key table, 159a... Delegation range data table, 160... Service provider terminal
Claims
1. A computing device; A storage device; An information processing device comprising: The storage device includes: a concealment information template obtained by encrypting concealment information used to conceal the biometric authentication information of an authorized person so that the concealment information can be restored using the biometric authentication information of the authorized person; a delegation template in which the delegater authentication information for proxy authentication delegation of the delegater is encrypted so that it can be restored using concealed delegater biometric authentication information obtained by concealing the delegater's biometric authentication information using the concealment information; is stored, The computing device providing the concealed information template to a terminal used by the principal, and obtaining, from the terminal used by the principal, encrypted concealed principal biometric authentication information that has been encrypted so as to be restorable using authentication information of an agent of the principal; providing the encrypted and concealed delegate biometric information and the delegation template to a terminal used by the delegate; It was configured as follows: Information processing device.
2. 2. The information processing device according to claim 1, The computing device acquiring the anonymized information template and the delegation template from the terminal used by the delegator, and storing the anonymized information template and the delegation template in the storage device; It was configured as follows: Information processing device.
3. 2. The information processing device according to claim 1, The storage device includes: a proxy template is stored, the proxy template being encrypted so that the proxy's authentication information can be restored using the proxy's biometric authentication information; The computing device providing the proxy template to the terminal used by the proxy; It was configured as follows: Information processing device.
4. 2. The information processing device according to claim 1, the storage device stores delegation range data indicating the delegation range of proxy authentication; The computing device provides the delegation scope data to a terminal that performs authentication of the service. It was configured as follows: Information processing device.
5. 5. The information processing device according to claim 4, The delegation range includes a range regarding the delegation period and the number of delegations; The computing device When either the delegation period or the number of delegations of the proxy authentication falls outside the delegation range, a new delegation template and a new concealed information template are obtained from the terminal used by the delegator, and the delegation template and the concealed information template stored in the storage device are updated with the new delegation template and the new concealed information template. It was configured as follows: Information processing device.
6. 2. The information processing device according to claim 1, The computing device when an instruction to terminate delegation is received from the terminal used by the delegator, a new delegation template and a new anonymized information template are obtained from the terminal used by the delegator, and the delegation template and the anonymized information template stored in the storage device are updated with the new delegation template and the new anonymized information template. It was configured as follows: Information processing device.
7. Multiple devices and a biometric template server; A biometric authentication system having: The biometric template server a concealment information template obtained by encrypting concealment information used to conceal the biometric authentication information of an authorized person so that the concealment information can be restored using the biometric authentication information of the authorized person; a delegation template that encrypts the delegater authentication information for proxy authentication delegation of the delegater so that the delegater's biometric authentication information can be restored using the concealed delegater biometric authentication information that has been concealed using the concealment information; and providing the concealment information template to the terminal used by the delegater. The terminal used by the delegate is acquiring biometric authentication information from the principal, acquiring the anonymized information template from the biometric template server, restoring the anonymized information from the anonymized information template using the biometric authentication information of the principal, encrypting the anonymized biometric authentication information of the principal using the anonymized information to create the anonymized principal biometric authentication information, encrypting the anonymized principal biometric authentication information so that it can be restored using authentication information of an agent of the principal, to create encrypted anonymized principal biometric authentication information, and transmitting the encrypted anonymized principal biometric authentication information to the terminal used by the agent directly or via the biometric template server; The biometric template server providing the delegation template to the terminal used by the agent; Biometric authentication system.
8. The biometric authentication system according to claim 7, The biometric template server a proxy template is stored that is encrypted so that the authentication information of the proxy of the principal can be restored using the biometric authentication information of the proxy; providing the agent template to the terminal used by the agent; The terminal used by the agent is acquiring the delegation template and the proxy template from the biometric template server, acquiring the proxy's biometric authentication information from the proxy, restoring the proxy's authentication information from the proxy template using the proxy's biometric authentication information, restoring the anonymized proxy biometric authentication information from the encrypted anonymized proxy biometric authentication information using the proxy's authentication information, and restoring the proxy authentication information from the delegation template using the anonymized proxy biometric authentication information; Biometric authentication system.
9. The biometric authentication system according to claim 7, The terminal used by the delegate is acquiring biometric authentication information from the authorized person, randomly generating the confidential information, and encrypting the confidential information so that it can be restored by biometric authentication of the authorized person, thereby creating the confidential information template, and registering the confidential information template in the biometric template server; using the anonymization information to anonymize the biometric authentication information of the principal, thereby creating the anonymized principal biometric authentication information; encrypting the principal authentication information so that it can be restored using the anonymized principal biometric authentication information, thereby creating the delegation template; and registering the delegation template in the biometric template server. Biometric authentication system.
10. The biometric authentication system according to claim 7, The biometric template server retaining delegation range data indicating the delegation range of the proxy authentication, and providing the delegation range data to the terminal that performs service authentication; Biometric authentication system.
11. The biometric authentication system according to claim 10, The delegation range includes a range regarding the delegation period and the number of delegations; The terminal used by the delegate is After transmitting the encrypted and concealed delegate biometric information to the terminal used by the agent, creating a new delegation template; The biometric template server when either the delegation period or the number of delegations of the proxy authentication falls outside the delegation range, a new delegation template and a new concealed information template are obtained from the terminal used by the delegator, and the stored delegation template and the concealed information template are updated with the new delegation template and the new concealed information template. Biometric authentication system.
12. The biometric authentication system according to claim 7, The biometric template server when an instruction to terminate delegation is received from the terminal used by the delegator, a new delegation template and a new anonymized information template are obtained from the terminal used by the delegator, and the delegation template and the anonymized information template that are held are updated with the new delegation template and the new anonymized information template. Biometric authentication system.
13. The biometric authentication system according to claim 7, The terminal used by the delegate is and creating the encrypted concealed delegater biometric authentication information by encrypting delegation range data indicating the delegation range of the proxy authentication in addition to the concealed delegater biometric authentication information so that the data can be restored using the authentication information of the proxy of the delegater. Biometric authentication system.
14. Multiple devices and a biometric template server; A biometric authentication method using The biometric template server a concealment information template obtained by encrypting concealment information used to conceal the biometric authentication information of an authorized person so that the concealment information can be restored using the biometric authentication information of the authorized person; a delegation template that encrypts the delegater authentication information for proxy authentication delegation of the delegater so that the delegater's biometric authentication information can be restored using the concealed delegater biometric authentication information that has been concealed using the concealment information; and providing the concealment information template to the terminal used by the delegater. The terminal used by the delegate acquiring biometric authentication information from the principal, acquiring the anonymized information template from the biometric template server, restoring the anonymized information from the anonymized information template using the biometric authentication information of the principal, encrypting the anonymized biometric authentication information of the principal using the anonymized information to create the anonymized principal biometric authentication information, encrypting the anonymized principal biometric authentication information so that it can be restored using authentication information of an agent of the principal, to create encrypted anonymized principal biometric authentication information, and transmitting the encrypted anonymized principal biometric authentication information to the terminal used by the agent directly or via the biometric template server; The biometric template server providing the delegation template to the terminal used by the agent; Biometric authentication methods.
15. a concealment information template obtained by encrypting concealment information used to conceal the biometric authentication information of an authorized person so that the concealment information can be restored using the biometric authentication information of the authorized person; a delegation template in which the delegater authentication information for proxy authentication delegation of the delegater is encrypted so that it can be restored using concealed delegater biometric authentication information obtained by concealing the delegater's biometric authentication information using the concealment information; biometric information of the authorizer; A program that causes a computer of a terminal that acquires the information to execute processing, The computer, a process of acquiring biometric authentication information of the principal, acquiring the concealed information template, restoring the concealed information from the concealed information template using the biometric authentication information of the principal, concealing the biometric authentication information of the principal using the concealed information to create the concealed principal biometric authentication information, and encrypting the concealed principal biometric authentication information so that it can be restored using authentication information of an agent of the principal, thereby creating encrypted concealed principal biometric authentication information; Let it run, program.
Citation Information
Patent Citations
Procedure management system and procedure management method
WO2016194053A1
Digital asset management device, digital asset management system, digital asset management method, and non-transitory computer-readable medium
WO2023062823A1