Personal authentication applications and business applications incorporating them

By converting biometric image data into biometric hash data for secure authentication, the challenge of user reluctance and impersonation risks is addressed, ensuring high security and privacy in identity authentication systems.

JP2026044211APending Publication Date: 2026-03-12株式会社OCI
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-08-29
Publication Date
2026-03-12

AI Technical Summary

Technical Problem

Biometric image data used for personal authentication is highly private and users are reluctant to entrust it to server or cloud systems, while impersonation risks necessitate high security measures.

Method used

Convert biometric image data into biometric hash data using spatial frequency conversion and hash functions, storing and using the hash data instead of the original image data, ensuring high security and privacy by making it irreversible to reverse-calculate back to the original sequence.

Benefits of technology

Provides secure identity authentication with high privacy protection by using biometric hash data, preventing storage of sensitive biometric information on networks and enhancing security against impersonation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026044211000001_ABST
    Figure 2026044211000001_ABST
Patent Text Reader

Abstract

To provide an identity authentication application that uses biometric image data to authenticate an individual while achieving both security and personal information protection. [Solution] In the user terminal 1, the identity authentication application 100 includes a biometric image data acquisition module 110 that acquires the user's image data or an image data portion extracted from a specific region of the image data as biometric image data, a biometric image spatial frequency conversion data generation module 120 that converts the biometric image data into the spatial frequency domain using a spatial frequency conversion tool 121 to obtain biometric image spatial frequency conversion data, a biometric image sequence data extraction module 130 that obtains the numerical value of the number of occurrences for each frequency from the obtained biometric image spatial frequency conversion data as biometric image sequence data, and a biometric hash data generation module 140 that uses the obtained biometric image sequence data as input data and converts it into a hash value using a hash function tool 141 to obtain biometric hash data.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an identity authentication application that runs on a computer system, and as an example, relates to an identity authentication application that ensures that an individual logs in and starts use properly, and that the individual finishes use and logs out properly. There are identity authentication applications that run on computer systems that run when logging in online and those that run when logging in offline, but those that run when logging in online in particular are sometimes called eKYC applications (electronic Know Your Customer Applications). The business application to which the user logs in using the personal authentication application according to the present invention is not limited, and the present invention can be applied to business applications for a variety of purposes. For example, the present invention can be applied to a business application in which the user logs in at the start of use, authenticates the user, and then closes the application after authenticating the user when the user finishes using the application. [Background technology]

[0002] In computer systems, various applications are running, and various security measures are also being implemented. The meaning of security measures is broad, but for example, measures that require the input of various code information, such as a password, when accessing and opening an application system to authenticate the person who is authorized to access the application files used by the application and ensure that only that person can use the application files, are widely adopted. There are various types of personal authentication applications in the prior art. Depending on the security level, some simply require users to enter a password from a keyboard, some require users to enter ID information from an IC card they carry along with the password, and some require users to enter biometric image data such as a face image, fingerprint image, vein pattern image, palm image, iris image, or voice data to authenticate the user.

[0003] In particular, personal authentication applications that use biometric image data are difficult to impersonate and have a high level of security. After completing personal authentication using biometric image data, users can log in to business applications, input various data, view data, and operate applications.

[0004] Figure 14 is a diagram briefly explaining the operation of starting a general application, opening an application file, and then exiting and closing it. This is an example, and is a typical operation of opening and closing an application file. When a user selects the icon of the application 10 that they wish to use with a pointing device such as a mouse and launches it by double-clicking or other operation, a password entry column pops up to confirm usage authority, as shown in the upper part of Figure 14. It is common for users to be required to enter a password before starting to use the application 10. Note that some applications 10 require the entry of ID information from an IC card or biometric image data in addition to a password.

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2006-277193 DISCLOSURE OF THE INVENTION [Problem to be solved by the invention]

[0006] Here, in the prior art, personal authentication applications using biometric image data are highly secure and technically worthy of praise. However, from the user's perspective, the biometric image data that serves as the correct data for matching must be registered and stored in the server system or cloud system of the operator of the identity authentication application they wish to use. However, biometric image data is highly private as personal information, and it is highly likely that users will feel uneasy or reluctant to entrust their biometric image data to an operator's server system or cloud system.

[0007] The business applications that are expected to be used are diverse, including consultations at medical institutions, payments for shopping, payments for various services, use of services at financial institutions, entry and exit to buildings, home healthcare (acquisition of lifestyle information and health data within the home), mail order use, and logistics use (delivery and receipt), and it is expected that users will feel uneasy or reluctant to entrust their own biometric image data to the operator's server system or cloud system. Legal measures to protect personal information are also being established.

[0008] On the other hand, if someone impersonates you and falsely enters data or uses services when using various business applications, it could have an impact on your life and property, so it is necessary to raise the security level to prevent impersonation.

[0009] Therefore, the present invention aims to provide an "identity authentication application" and a "business application incorporating an identity authentication application" that achieve both security and personal information protection, by using biometric image data that is difficult to impersonate when using business application files, while eliminating the anxiety that users may feel about entrusting their own biometric image data to an operational system. [Means for solving the problem]

[0010] In order to achieve the above object, the personal authentication application of the present invention is an personal authentication application that can be used on a computer system, and includes: a biometric image data acquisition module that acquires image data of a user or an image data portion extracted from a specific region of the image data as biometric image data; a biometric image spatial frequency conversion data generation module that includes a spatial frequency conversion tool and converts the biometric image data acquired by the biometric image data acquisition module into the spatial frequency domain using the spatial frequency conversion tool to obtain biometric image spatial frequency conversion data; a biometric image sequence data extraction module that obtains the numerical value of the number of occurrences for each frequency as biometric image sequence data from the obtained biometric image spatial frequency conversion data; and a biometric hash data generation module that includes a hash function tool and converts the biometric image sequence data obtained by the sequence data extraction module into a hash value as input data to obtain biometric hash data.

[0011] With the above configuration, the identity authentication application of the present invention does not store or use the user's biometric image data acquired by the "biometric image data acquisition module" as image data on a server on a network, but converts the user's biometric image data into biometric hash data, and then stores and uses the biometric hash data. The nature of hash function tools makes it virtually irreversible to reverse-calculate the sequence obtained through the hash function tool back to the original sequence. In other words, the "biometric hash data," which is the final calculation result of the identity authentication application of the present invention, is data unique to the user, enabling a high level of identity authentication while ensuring a high level of privacy security for personal information by preventing the user's "biometric information, such as a facial image," from being stored or used on the network.

[0012] The personal authentication application of the present invention has a registration phase and an authentication phase. The registration phase is carried out as follows: When the user inputs the biometric image data at the time of registration, the biometric image spatial frequency conversion data generation module executes a registration time conversion data generation process that converts the spatial frequency conversion data obtained from the biometric image data using the spatial frequency conversion tool into biometric image spatial frequency conversion data for registration, the biometric image sequence data extraction module executes a registration biometric image sequence data extraction process that extracts the numerical value of the number of occurrences for each frequency from the biometric image spatial frequency conversion data for registration as the biometric image sequence data, and the biometric hash data generation module executes a registration biometric hash data generation process that converts the biometric image sequence data obtained at the time of registration into a hash value to generate registration biometric hash data, and a registration biometric hash data transmission process that transmits the generated registration biometric hash data to a database in a storage device of the user terminal or a server on a cloud. That is, in the personal authentication application, the biometric hash data generated in the registration phase is generated as "registration biometric hash data." This registered "registered biometric hash data" is also data unique to the user and serves as the original data that enables a high level of personal authentication. In the registration phase, the registration biometric hash data storage processing module stores the registration biometric hash data generated for each user at the time of registration in a storage device of the user terminal or in a database of a server on the cloud.

[0013] The authentication phase is carried out as follows: When the user inputs the biometric image data during identity authentication, the biometric image spatial frequency conversion data generation module executes a conversion data generation process during identity authentication to convert the spatial frequency conversion data obtained from the biometric image data using the spatial frequency conversion tool into biometric image spatial frequency conversion data for identity authentication, the biometric image sequence data extraction module executes a biometric image sequence data extraction process during identity authentication to extract the numerical value of the number of occurrences for each frequency from the biometric image spatial frequency conversion data for identity authentication as the biometric image sequence data for identity authentication, and the biometric hash data generation module executes an authentication biometric hash data generation process to convert the biometric image sequence data for identity authentication into a hash value to generate authentication biometric hash data. That is, in the personal authentication application, the biometric hash data generated in the authentication phase is used as "authentication biometric hash data." This "authentication biometric hash data" is also unique to the user and serves as the original data that enables a high level of identity authentication.

[0014] In the matching process of the authentication phase, the authentication matching processing module receives the authentication biometric hash data generated during the authentication from the user, and performs a matching process with the registered biometric hash data stored in the storage device of the user terminal or in the database of a server on the cloud, thereby executing the authentication process. If this matching process is successful, the person is authenticated as the person in question, and if the matching process is unsuccessful, the person is not authenticated as the person in question. With the above configuration, the matching process can be performed correctly, and the determination results of whether the person matches the person and whether the person does not match with another person can be obtained correctly.

[0015] Next, in order to improve the authentication accuracy in the personal authentication application, it is preferable to take the following measures.

[0016] The first technique is to organize the data by scattering and discretizing the frequencies and their occurrence counts. In the biometric image sequence data extraction module, it is preferable that the frequencies for which the number of occurrences is counted in the extraction process of the biometric image sequence data and the count results of the number of occurrences for each frequency are compiled into spatial frequency transformation values ​​that are scatter data.

[0017] Here, if the number of frequency occurrences is counted too precisely and even small numerical differences are captured and matching is performed, the matching accuracy rate may be too low even for the true person. Therefore, it is preferable to summarize the number of frequency occurrences as discrete numerical values ​​as spatial frequency conversion values. With the above configuration, it is possible to prevent the occurrence of a problem in which the matching accuracy rate drops too much even if the person is the real person.

[0018] The third innovation is to use multiple biometric images to input. Here, the biometric images to input are taken from the same body part. In other words, if it is a face image of the user, multiple face images are used. Therefore, the registration biometric hash data is generated using a plurality of image data as the biometric image data for registration input by the user at the time of registration. The authentication biometric hash data is generated using a plurality of image data as the biometric image data for personal authentication input by the user during the personal authentication. In this way, by using a plurality of biometric images, the matching process results tend to be stable.

[0019] The fourth innovation is to extract, as a specific frequency band, a frequency band that is likely to appear with a high degree of coincidence when processing the origins of multiple biometric images when multiple biometric images are used, and perform matching. In other words, in the data processing of each of the multiple biometric images in the biometric image sequence data extraction module, it is preferable to select a specific frequency band in which the number of occurrences counted for each of the scattered frequencies is the same discrete value, obtain the discrete value of the number of occurrences in the specific frequency band as the biometric image sequence data, and have the biometric hash data generation module generate the biometric hash data from the biometric image sequence data corresponding to the specific frequency band. With the above configuration, it is possible to extract only frequency bands in which the image quality is likely to be stable from the target biometric image and perform matching processing, which makes the matching processing results more likely to be stable.

[0020] The fifth innovation is to utilize check data in addition to biometric hash data to reduce false positives. In other words, it is preferable that the biometric hash data generation module outputs, in addition to the generated biometric hash data for the specific frequency band, the absolute values ​​of the upper and lower limits of the specific frequency band and the absolute value of the number of occurrences of the specific frequency band as check data. With the above configuration, in addition to the matching results using biometric hash data, separate checking data can also be utilized, which may be useful in checking for so-called false positives (cases where a match is made with a different person, or a case where a match is not made with the person in question).

[0021] Furthermore, variations in the configuration of the present invention will be described. The tool that can be used as the spatial frequency transformation tool is not limited to one. For example, a Fourier transform tool, a wavelet transform tool, etc. Any other tool that can be used as the spatial frequency transformation tool can be adopted.

[0022] Next, available biometric image data may include a face image, a palm image, a vein image, a fingerprint image, an iris image, a voice data image, or a combination thereof. Note that for each biometric image data, an image area to be used may be set. For example, a facial image may be a partial image of the face, such as the forehead, eyes, and nose. Also, a vein image may be the first to third joints of a specific finger, such as the index or middle finger, a fingerprint image may be a 2 cm square in the center of the pad of a specific finger, such as the index or middle finger, or audio data may be audio information in which specific words are pronounced.

[0023] Next, in order to increase the security level of the personal authentication application of the present invention, multiple types of hash function tools are prepared, allowing the administrator to use them appropriately depending on the time and situation. There are a variety of hash function tools available, such as SHA-256, RIPEMD-160, BLAKE, CRC32, and CRC64. Having these available and allowing operators to choose which to use depending on the time and situation could be useful in improving security.

[0024] In the above configuration, since it is not known in advance which sequence transformation hash function tool module will be selected in the usage phase, it is preferable to obtain conversion results for all hash function tools that can be selected at the time of use in the registration phase. Note that there is no need to ask the registrant to input biometric image data multiple times; based on the biometric image data input once, in the registration phase, it is sufficient to switch and convert the hash function tools that can be selected at the time of use, obtain registration biometric hashes for all patterns, and register them as registration hash data for each user.

[0025] Next, the business application according to the present invention uses the above-mentioned personal authentication application, and can be a business application that allows login only on the condition that the user's identity is authenticated by the personal authentication application at the time of login. As an option for the business application of the present invention, it is also preferable to configure a system in which logging out is possible only when the user has been authenticated by an identity authentication application. According to the above configuration, personal authentication can be performed when starting and ending use of a business application, improving the security level. In other words, personal authentication is performed when logging in to use the business application, which is the intended use, to ensure the security level. Furthermore, if personal authentication is also performed when logging out as an option, the security level can be further improved. [Brief explanation of the drawings]

[0026] [Figure 1] FIG. 1 is a diagram simply illustrating a configuration of an identity authentication application 100 according to a first embodiment. [Figure 2] FIG. 10 is a diagram showing a face image captured and input by user 1 in the registration phase. [Figure 3] FIG. 10 is a diagram showing a scatter diagram plotted by the biometric image spatial frequency transformation data generation module 120. [Figure 4] FIG. 4 is an enlarged view of the graph in a specific frequency band in FIG. 3. [Figure 5] This is a diagram in which parts belonging to the same grid in a graph of a specific frequency band are hatched. [Figure 6] FIG. 10 is a diagram showing a face image captured and input by user 1 in the authentication phase. [Figure 7] FIG. 10 is a diagram showing a scatter diagram plotted by the biometric image spatial frequency transformation data generation module 120. [Figure 8] FIG. 8 is an enlarged view of the graph in a specific frequency band in FIG. 7. [Figure 9] This is a diagram in which parts belonging to the same grid in a graph of a specific frequency band are hatched. [Figure 10] FIG. 10 is a diagram showing a face image captured and input by user 2 (another person) in the authentication phase. [Figure 11] FIG. 10 is a diagram showing a scatter diagram plotted by the biometric image spatial frequency conversion data generation module 120 based on an image of user 2 (another person). [Figure 12] FIG. 12 is an enlarged view of the graph in a specific frequency band in FIG. [Figure 13] This is a graph of a specific frequency band based on an image of user 2 (another person), in which parts belonging to the same grid are hatched. [Figure 14] FIG. 1 is a diagram illustrating an outline of the operation of a conventional general application. BEST MODE FOR CARRYING OUT THE INVENTION

[0027] The best mode for carrying out the present invention will be specifically described below with reference to examples, although the present invention is not limited to these examples. Example 1

[0028] As a first embodiment, an individual authentication application according to the present invention and an outline of its operation will be described below. A personal authentication application according to a first embodiment will be described. FIG. 1 is a diagram simply illustrating the configuration of an identity authentication application 100 according to the first embodiment. 1, the personal authentication application 100 is installed on a smartphone or a computer system, or is provided as an ASP in a form that can be used on a network 3. In this first embodiment, as an example, a configuration example will be described in which a user uses a smartphone 1 and a cloud system 2 is provided on the network 3. It is also possible to have a configuration in which the user uses a shared terminal installed in a government agency instead of the smartphone 1, or a configuration in which the user uses a server on the network 3 that is managed by an administrator.

[0029] In the configuration example shown in Figure 1, the personal authentication application 100 built in the smartphone 1 includes a biometric image data acquisition module 110, a biometric image spatial frequency conversion data generation module 120, a biometric image sequence data extraction module 130, a biometric hash data generation module 140, and a registered biometric hash data transmission processing module 150. In addition, in the configuration example shown in Figure 1, a server on the network 3 or a cloud system 2 has an authentication server 200, which is configured to include an authentication registration database 210, a registration processing module 220, an identity authentication matching processing module 230, and a data communication module 240.

[0030] The biometric image data acquisition module 110 is a program module that inputs biometric image data from a device that inputs the biometric image data. For example, the device may be a camera, reader, scanner, microphone, or the like, depending on the biometric image data to be acquired. In the example of FIG. 1, the user terminal 1 is equipped with a camera 111. To prevent impersonation and fraud, it is preferable to acquire the biometric image data by taking a live biometric image or the like via a device equipped or controlled by the personal authentication application 100, rather than simply accepting the biometric image data brought by the user on a USB memory stick or the like.

[0031] The biometric image data to be handled may include various types of data such as face image data, palm image data, vein image data, fingerprint image data, iris image data, and voice image data. For example, in the case of face image data, face image data captured by an imaging camera is input. For example, in the case of palm image data, palm image data scanned by a palm reader is input. For example, in the case of vein image data, vein image data scanned by a vein reader is input. For example, in the case of fingerprint image data, fingerprint image data scanned by a fingerprint reader is input. For example, in the case of iris image data, iris image data scanned by an iris reader is input. For example, in the case of audio data image, an image in which audio data of a fixed phrase input by a microphone is displayed as a frequency image is input.

[0032] Here, the biometric image data may be the entire biometric image data of the user captured by a camera 111 or the like, or it may be an image data portion of a specific image area cut out from the biometric image data of the user, which may be obtained as the biometric image data. For example, in the case of a facial image, the biometric image data acquisition module 110 can extract the so-called T-zone, such as the forehead, both eyes, and nose, as a specific image area; in the case of a vein image, it can extract the first to third joints of a specific finger, such as the index finger or middle finger, as a specific image area; in the case of a fingerprint image, it can extract a 2 cm square in the center of the pad of a specific finger, such as the index finger or middle finger, as a specific image area; and in the case of audio data, it can extract the audio data of the pronunciation of specific words as a specific data area, and acquire these specific image areas as biometric image data.

[0033] The biometric image spatial frequency conversion data generation module 120 converts the biometric image data acquired by the biometric image data acquisition module 110 into the spatial frequency domain to obtain biometric image spatial frequency conversion data. The biometric image spatial frequency conversion data generation module 120 includes a spatial frequency conversion tool 121, a frequency low-pass filter 122, a histogram processing module 123, and a scatter data creation processing module .

[0034] The spatial frequency conversion tool 121 is a program module that expands input biometric image data into a series in the frequency domain. There are various possible spatial frequency transformation tools 121. Any tool that processes a mathematical method for expanding biometric image data into a series in the frequency domain can be used, such as a Fourier transform tool or a wavelet transform tool. There are also various types of Fourier transform tools, such as a two-dimensional discrete Fourier transform and a fast Fourier transform (FFT). In this example, the spatial frequency transformation tool 121 uses a Fourier transformation tool.

[0035] Fourier series expansion is a well-established mathematical technique widely used in image engineering, including image recognition and image analysis. It is a mathematical engine that converts the structure of biometric image data into the frequency domain and expands it into polynomials. The expansion result of the spatial frequency conversion tool 121 is that the image data is expanded for each frequency, and the frequency components and their numbers are obtained.

[0036] In this configuration example, the biometric image spatial frequency conversion data generation module 120 is equipped with a frequency low-pass filter 122, and performs frequency low-pass processing on the spatial frequency conversion data obtained using the spatial frequency conversion tool 121, leaving only data below a predetermined frequency using the frequency low-pass filter 122 and cutting out data above the predetermined frequency. By cutting the high frequency components of the spatial frequency conversion data of the biometric image while leaving the low frequency components, the characteristic elements of the biometric image are not lost and the data volume is reduced, which is an advantage.

[0037] Next, in this example, the biometric image spatial frequency conversion data generation module 120 includes a histogramming processing module 123, which converts the biometric image spatial frequency conversion data into a histogram. A histogram is obtained by aggregating and organizing data by dividing it into classes (bins), which are intervals that are relatively prime to each other. In this configuration example, the bin width applied by the histogramming processing module 123 is not limited, but as an example, the spatial frequency on the horizontal axis can be set to 3500. By this histogramming processing, the number of occurrences of data obtained by Fourier transform that correspond to the spatial frequency of the set bin width is counted as belonging to the bin. In the example described below, an example of histogram processing is given in which histogram bins are set in the spatial frequency range of 0.00467 to 0.0060 after frequency low-pass processing, with the bin width set to 0.000467, and the number of occurrences belonging to each bin is counted.

[0038] Next, the biometric image spatial frequency conversion data generation module 120 includes a scatter data creation processing module 124. The scatter data creation processing module 124 plots a scatter diagram with the spatial frequency bins set by the histogram processing module 123 on the horizontal axis and the data of the number of occurrences counted for each bin on the vertical axis. In this example, the biometric image spatial frequency conversion data generation module 120 performs conversion using a spatial frequency conversion tool 121, followed by low-pass processing using a frequency low-pass filter 122, histogramming processing using a histogramming processing module 123, and counting the number of occurrences of scattered spatial frequencies using a scattered data creation processing module, and uses the result as biometric image spatial frequency conversion data.

[0039] In the example described below, the results of the above histogram processing (the number of occurrences was counted by setting histogram bins with a bin width of 0.000467 in the spatial frequency range of 0.00467 to 0.0060 after frequency low-pass processing) are plotted as a scatter plot. Because the number of occurrences is large, it is also possible to count them on a logarithmic axis. In the example described below, plot results are obtained in the range of log0.1 to log4.0.

[0040] The biometric image sequence data extraction module 130 obtains the numerical value of the number of occurrences for each frequency from the biometric image space-frequency converted data obtained by the biometric image space-frequency converted data generation module 120 as biometric image sequence data. The biometric image sequence data extraction module 130 includes a three-dimensional object determination processing module 131 , a specific frequency band determination processing module 132 , and a gridding processing module 133 . Assuming that the biometric image data acquisition module 110 acquires multiple biometric images, namely biometric image data 1 and biometric image data 2, in this example, through the biometric image spatial frequency conversion data generation process in the biometric image spatial frequency conversion data generation module 120 described above, a scatter plot plotting the spatial frequency and number of occurrences for each image and scatter data lines connecting the scatter data are obtained.

[0041] The biometric image sequence data extraction module 130 includes a three-dimensional object determination processing module 131. The three-dimensional object determination processing module 131 compares the scatter data derived from biometric image data 1 with the scatter data derived from biometric image data 2, and if the count values ​​of the number of occurrences are the same across the entire frequency range, it can be determined that the biometric image data 1 and the biometric image data 2 were originally the exact same biometric image data. In other words, it can be determined that the captured image was of a simple two-dimensional object, captured by pointing the camera at a separately prepared photograph. On the other hand, if the count values ​​of the number of occurrences are different across many frequency ranges, it can be determined that the biometric image data 1 and the biometric image data 2 were images obtained by capturing a three-dimensional object live. In this way, by acquiring multiple biometric images of a user and analyzing them using the three-dimensional object determination processing module 131, it is possible to determine whether the biometric images were acquired by naturally photographing the user or whether an attempt is being made to commit some kind of fraudulent act by impersonating the user using the photograph.

[0042] The specific frequency band determination processing module 132 compares the scatter data line 1 derived from the biometric image data 1 and the scatter data line 2 derived from the biometric image data 2, which are plotted with the horizontal axis being frequency and the vertical axis being the number of occurrences, extracts the frequency band in which the two are close to each other, and determines that frequency band as the specific frequency band. In other words, the module finds a frequency band that can be expected to consistently appear close to each other in multiple biometric images of the user, and determines that frequency band as the specific frequency band. To determine a specific frequency band, it is sufficient to select a location where the difference in values ​​between the peaks and valleys in the scatter plot is small, noting that the peaks and valleys in the scatter plot correspond to the number of occurrences per frequency in the scatter data. It is preferable to identify the closest frequency band not only for two consecutive peaks and valleys in the scatter data of multiple biological images, but also for three or more consecutive peaks and valleys. This is because three or more consecutive peaks and valleys are easier to evaluate as a stable frequency bandwidth than one or two consecutive peaks and valleys.

[0043] By determining the specific frequency band by this specific frequency band determination processing module 132, the biometric image sequence data extraction module 130 does not need to extract biometric image sequence data across the entire frequency range, and can target only the number of occurrences of frequencies in the specific frequency band that can be expected to appear stably and consistently in multiple biometric images each time. Extracting biometric image sequence data by narrowing it down to this specific frequency band can improve the matching accuracy of personal authentication compared to matching across the entire frequency range.

[0044] The gridding processing module 133 performs gridding of the spatial frequency value on the horizontal axis and the number of occurrences, which is the frequency on the vertical axis, into discretized widths. The gridding referred to here means that the spatial frequency on the horizontal axis is divided into predetermined units by setting bins, while the vertical axis is the counted value of the number of occurrences. Because the number of occurrences is large, capturing the numerical value itself could result in a large impact on the biometric hash generation process and matching process described below. Therefore, the frequency of the number of occurrences on the vertical axis is also devised to be divided into certain widths. As a result, grids are set on both the horizontal and vertical axes, each divided into predetermined intervals. In this way, the gridding processing module 133 sets a grid in the space where the scatter data lines are drawn. Note that the actual processing is performed by a computer, performing numerical calculations to determine which grid the scatter points belong to.

[0045] Then, the sequence data extraction module 130 extracts a grid through which both of them commonly pass across multiple biometric images in the scatter data of a specific frequency band drawn in the gridded space by the gridding processing module 133. In other words, the sequence data extracted by the sequence data extraction module 130 is the sequence data assigned to the grid through which both of them commonly pass.

[0046] The biometric image sequence data extraction module 130 preferably also extracts check data. Here, the check data is the absolute values ​​of the upper and lower limits of a specific frequency band and the absolute value of the number of occurrences of the specific frequency band. Note that this check data is not converted into a hash value by the hash function tool 141, but is sent as an absolute value to the authentication server 200 of the cloud system 2 and used for authentication.

[0047] The biometric hash data generation module 140 is equipped with a hash function tool 141, and uses the biometric image sequence data obtained by the sequence data extraction module 130 as input data, converts it into a hash value using the hash function tool 141, and uses the obtained data as biometric hash data. The hash value converted by the biometric hash data generation module 140 becomes an "enrollment biometric hash" in the enrollment phase, and becomes an "authentication biometric hash" in the personal authentication phase. When check data is sent from the number sequence data extraction module 130, the biometric hash data generation module 140 does not convert the check data into a hash value using the hash function tool 141, but passes it directly to the registered biometric hash data transmission processing module 150. By using check data as an auxiliary, it is possible to match numerical values, and even if the hash data converted into biometric hash data happens to be the same, it is thought that misrecognition can be reduced by comparing the numerical values ​​of this check data.

[0048] There are currently various hash function tools 141 available, including SHA-256, SHA-512, MD5, and RIPEMD-160. SHA-256 and RIPEMD-160 are also used in blockchains. Generally, hash function tools have the property that "forward calculations are easy but reverse calculations are difficult." However, by using the hash function tool 141 in the personal authentication application 100 of the present invention, this property of "one-way calculations are easy but reverse calculations are difficult" is also achieved, making it difficult to reconstruct the original biometric image data from the biometric hash output by the personal authentication application 100, thereby significantly increasing the level of privacy protection and security for personal information protection. Furthermore, while hash function tools generally have the property that even slight differences in input data will result in conversion into an entirely different hash value, the personal authentication application 100 of the present invention can expect differences in biometric image data even between twins by using the hash function tool 141. In other words, even if someone is merely disguised, the biometric hashes obtained by the biometric hash data generation module 140 will be completely different, significantly increasing the security level.

[0049] If the numerical value of the frequency occurrence is used instead of using a grid that discretizes the frequency occurrence, differences may occur even for the same person, and the biometric hash value converted by the biometric hash data generation module 140 may be completely different each time. Therefore, by gridding the biometric image sequence data extracted by the biometric image sequence data extraction module 130 of the present invention as described above, the numerical value of the frequency occurrence is grouped by section, thereby maintaining a reasonable level of authentication accuracy.

[0050] The registered biometric hash data transmission processing module 150 transmits the registered biometric hash data generated by the biometric hash data generation module 140 to a storage device of a user terminal 1 such as a smartphone or a shared terminal or to a cloud system 2 on the network 3. It is preferable that the registered biometric hash data transmission processing module 150 also transmits check data.

[0051] The above is a description of the components of the personal authentication application 100. Next, the components of the authentication server 200 of the cloud system 2 will be described. As shown in FIG. 1, the authentication server 200 includes an authentication registration database 210, a registration processing module 220, an identity authentication matching processing module 230, and a data communication module 240.

[0052] The authentication registration database 210 may be any device that stores data, such as a hard disk or a large-scale memory device, but is not limited thereto. The registration processing module 220 records, registers, and manages the registered biometric hash data sent from the personal authentication application 100 in the storage device of a user terminal 1 such as a smartphone or shared terminal, or in the authentication registration database 210 of a server in the cloud system 2 on the network 3.

[0053] The personal authentication matching processing module 230 compares the registered biometric hash data generated by the personal authentication application 100 at the time of registration and registered in the authentication registration database 210 by the registration processing module 220 with the personal authentication biometric hash data generated by the personal authentication application 100 at the time of personal authentication and obtained via the data communication module 240, performs matching processing, and executes the personal authentication processing. If the frequency band is limited to a specific frequency band, the registration biometric hash data generated within the range of the specific frequency band is compared with the personal authentication biometric hash data, and a matching process is performed.

[0054] Here, when a specific frequency band is determined and personal authentication processing is performed, the personal authentication matching processing module 230 can also check matching processing with check data in order to improve the accuracy of personal authentication. The check data is the absolute values ​​of the upper and lower limits of a specific frequency band and the absolute value of the number of occurrences of the specific frequency band. This check data is not converted into a hash value by the hash function tool 141, so it is possible to match the numerical values. Even if the converted hash data happens to be the same as the biometric hash data, comparing the numerical values ​​of this check data is thought to reduce misrecognition. Conversely, even if the biometric hash data is different due to subtle differences in the biometric image sequence data generated from the biometric image of the person, comparing the numerical values ​​of the check data is thought to reduce misrecognition.

[0055] The data communication module 240 executes data communication processing on the network 3, and data can be exchanged with the personal authentication application 100 via this data communication module 240. The above is a description of each component of the example configuration of the personal authentication application 100 and the authentication server 200 of the cloud system 2 shown in FIG.

[0056] Next, using specific user images, we will explain the registration phase of biometric hash data using a registered biometric image in the authentication application 100 and the authentication server 200 of the cloud system 2, and the authentication phase of biometric hash data using an authentication biometric image.

[0057] [Process flow and example of the biometric hash data registration phase] The process flow and example of the biometric hash data registration phase will be explained. The registrant inputs biometric image data using the biometric image data acquisition module 110 (registrant biometric image data input step). In this example, when a user registers, he or she takes and inputs multiple (two) facial images as biometric image data for registration, and the user takes live facial images via a camera, which is a device 111 controlled by the biometric image data acquisition module 110.

[0058] Figure 2 shows examples of facial images taken and entered by user 1 during the registration phase. (a) is facial image 1 of user 1, and Figure 2(b) is facial image 2 of user 1. At first glance, there appear to be few differences, but these are consecutive photographs, and the facial posture and facial expression are almost identical. This is because consecutive photographs are a prerequisite for practical use, and this example is appropriate for demonstration purposes.

[0059] Next, the biometric image spatial frequency conversion data generation module 120 executes a biometric image spatial frequency conversion process for each of the two sets of face image data, which are the biometric images acquired in Fig. 2. In this processing example, frequency low-pass processing, histogram processing, and scatter data creation processing are further executed. 3 shows the results of processing by the biometric image spatial frequency conversion data generation module 120, plotted as a scatter plot with the horizontal axis representing spatial frequencies grouped into bins and the vertical axis representing the number of occurrences of the frequency components. The vertical axis is a logarithmic scale.

[0060] 3, when the graphs derived from the two facial images 1 and 2 of user 1 are checked, it can be seen that the two graphs are very similar, but there are differences between them. The three-dimensional object determination processing module 131 of the biometric image sequence data extraction module 130 determines that the subject has changed subtly during the shooting time of the continuous photographs, resulting in slight changes in the posture angle and expression of the face, and therefore determines that the images are of a three-dimensional face.

[0061] The specific frequency band determination processing module 132 compares the plot results of the scatter data line derived from facial image data 1 of user 1, which is drawn with frequency on the horizontal axis and the number of occurrences on the vertical axis, with the scatter data line derived from facial image data 2, and extracts the frequency band where the two are close to each other with three or more consecutive peaks and valleys, and determines that frequency band as the specific frequency band. In reality, the specific frequency band is determined by the specific frequency band determination processing module 132 through numerical calculations performed by computer processing, but in the visualized Figure 3, it can be seen that the plot results for three consecutive points in the frequency band from 0.004787 to 0.005907 are within a very close range on both graphs. In this example, the frequency band from 0.004787 to 0.005533 is determined as the specific frequency band.

[0062] FIG. 4 is an enlarged view of the graph in a specific frequency band in FIG. Next, the biometric image sequence data extraction module 130 uses the gridding processing module 133 to grid the space plotted as a scatter plot with the horizontal axis representing the spatial frequency grouped into bins and the vertical axis representing the number of occurrences of that frequency component. In reality, this is performed by computer processing using numerical calculations by the biometric image sequence data extraction module 130. In the visualized image in Figure 4, because it is enlarged, it can be seen that there is a difference in the number of occurrences of both, but it can also be seen that they belong to the same set grid.

[0063] 5 is a graph of a specific frequency band in which hatching is applied to portions that belong to the same frequency bin on the horizontal axis and to grids with the same number of occurrences on the vertical axis. In practice, the biometric image sequence data extraction module 130 extracts those that pass through the grids with the same number of occurrences through numerical calculations in computer processing. The hatched areas in the visualized Figure 5 are represented as squares, and if the set of discrete frequency values ​​and discrete occurrence count values ​​assigned to these 10 squares is extracted as biometric image sequence data, it becomes (0.004787:0.6625), (0.004880:0.6625), (0.004973:0.6625), (0.005067:0.5500), etc. In other words, the biometric image sequence data is a sequence consisting of 20 numerical values ​​of 10 grids: "0.0047870.66250.0048800.66250.0049730.66250.0050670.5500...". Furthermore, if the lower and upper limits of the range of the specific frequency band and its occurrence count are extracted as check data, the four numerical values ​​of 0.004600, 0.005533, 0.4375, and 0.6625 become the check data.

[0064] Next, the biometric hash data generation module 140 uses the hash function tool 141 to calculate a hash value from the biometric image sequence data of the sequence of 20 numbers, thereby generating enrollment biometric hash data. In this example, if SHA256 is used as the hash function, the biometric hash data obtained will be "a4133c5fa2bcd0083b00884ac26b5399985e5013eb035b5d8fd173f32ca1a2e5···".

[0065] The registration processing module 220 of the authentication server 200 records and registers the registration biometric hash data sent from the personal authentication application 100 in the authentication registration database 210 of the server in the cloud system 2 on the network 3 . The above is the flow of the biometric hash data registration process in the registration phase.

[0066] [Process flow and example of the biometric hash data authentication phase] Next, the processing flow and example of the biometric hash data authentication phase will be described. The user to be authenticated inputs biometric image data using the biometric image data acquisition module 110 (authenticator biometric image data input step). Here, similarly, the user takes and inputs multiple (two) facial images as biometric image data for authentication during authentication. The user takes live facial images via a camera, which is a device 111 controlled by the biometric image data acquisition module 110. 6A and 6B show examples of facial images captured and input by user 1 in the authentication phase. FIG. 6A shows facial image 1 of user 1, and FIG. 6B shows facial image 2 of user 1.

[0067] Next, the biometric image spatial frequency conversion process is executed by the biometric image spatial frequency conversion data generation module 120 for each of the two sets of face image data, which are the biometric images acquired in Fig. 6. In this processing example, frequency low-pass processing, histogram processing, and scatter data creation processing are also executed. 7 shows the results of processing by the biometric image spatial frequency conversion data generation module 120, plotted as a scatter plot with the horizontal axis representing spatial frequencies grouped into bins and the vertical axis representing the number of occurrences of the frequency components. The vertical axis is a logarithmic scale. Here, since there is a difference between the two based on the biometric image spatial frequency conversion results shown in FIG. 7, the three-dimensional object determination processing module 131 determines that the multiple images input at the time of authentication are images of a three-dimensional face.

[0068] The specific frequency band determination processing module 132 compares the plot results of the scatter data line derived from facial image data 1 of user 1, which is plotted with frequency on the horizontal axis and number of occurrences on the vertical axis, with the scatter data line derived from facial image data 2, extracts the frequency band where the two are close to each other at three or more consecutive peaks and valleys, and determines that frequency band as the specific frequency band. In the visualized Figure 7, it can be seen that the plot results for three consecutive points in the frequency band from 0.004787 to 0.005533 are very close to each other. In this example, the frequency band from 0.004787 to 0.005533 is determined as the specific frequency band.

[0069] FIG. 8 is an enlarged view of the graph in a specific frequency band in FIG. The gridding processing module 133 grids the space plotted as a scatter diagram in which the horizontal axis represents spatial frequencies grouped into bins and the vertical axis represents the number of occurrences of the frequency components. In reality, this is performed by computer processing using numerical calculations by the biometric image sequence data extraction module 130. In the visualized image in Figure 8, because it is enlarged, it can be seen that there is a difference in the number of occurrences of both, but it can also be seen that they belong to the same set grid.

[0070] FIG. 9 is a graph of a specific frequency band in which hatching is applied to portions that belong to the same frequency bin on the horizontal axis and to grids with the same number of occurrences on the vertical axis. The hatched areas in the visualized Figure 9 are represented as squares, and if the set of discrete frequency values ​​and discrete occurrence count values ​​assigned to these 20 squares is extracted as biometric image sequence data, it becomes (0.004787:0.6625), (0.004880:0.6625), (0.004973:0.6625), (0.005067:0.5500), etc. In other words, the biometric image sequence data is a sequence consisting of 20 numerical values ​​of 10 grids: "0.0047870.66250.0048800.66250.0049730.66250.0050670.5500...". Furthermore, if the lower and upper limits of the range of the specific frequency band and its occurrence count are extracted as check data, the four numerical values ​​of 0.004600, 0.005533, 0.4375, and 0.6625 become the check data.

[0071] Next, the biometric hash data generation module 140 uses the hash function tool 141 to calculate a hash value from the biometric image sequence data of the 20-digit sequence, generating biometric authentication hash data. Here, the same hash function as during registration, SHA256, is used. The resulting biometric hash data is "a4133c5fa2bcd0083b00884ac26b5399985e5013eb035b5d8fd173f32ca1a2e5...". The authentication matching processing module 230 of the authentication server 200 compares the authentication biometric hash data sent from the authentication application 100 with the registered biometric hash data registered in the authentication registration database 210, performs matching processing, and executes authentication processing. In this example, the matching processing of the biometric hash data is successful, and the check data also matches the four numerical values ​​0.004600, 0.005533, 0.4375, and 0.6625, so the person is authenticated and the result is output and reported to the management system.

[0072] In the personal authentication application 100 of the present invention, only biometric hash data is used in both the registration phase and the authentication phase, and the biometric data itself, such as the user's facial image, is not stored anywhere, thereby maintaining a high level of personal information protection.

[0073] Next, an example will be described in which it is determined that authentication of a person cannot be performed when a person other than the person in question attempts to authenticate the person by pretending to be the person in question. The other user 2 inputs biometric image data using the biometric image data acquisition module 110 (authenticated person biometric image data input step). Here, similarly, the user takes and inputs multiple (two) facial images as biometric image data for authentication during authentication. The user takes live facial images via a camera, which is a device 111 controlled by the biometric image data acquisition module 110. Figure 10 shows examples of facial images captured and input by user 2 (other person) in the authentication phase. Figure 10(a) shows facial image 1 of user 2 (other person), and Figure 10(b) shows facial image 2 of user 2 (other person).

[0074] Next, the biometric image spatial frequency conversion data generation module 120 executes a biometric image spatial frequency conversion process for each of the two sets of face image data, which are the biometric images acquired in Fig. 10. In this processing example, frequency low-pass processing, histogram processing, and scatter data creation processing are also executed. 11 shows the results of processing the facial image of user 2 (another person) by the biometric image spatial frequency conversion data generation module 120, plotted as a scatter plot with the horizontal axis representing spatial frequency grouped into bins and the vertical axis representing the number of occurrences of that frequency component. Note that the vertical axis is a logarithmic scale.

[0075] 11, there is a difference between the two images, and so the three-dimensional object determination processing module 131 determines that the multiple images input during authentication are images of a three-dimensional face. If a photograph of the face of user 1, who is the person in question, is held up to camera 111 and input, the three-dimensional object determination processing module 131 will detect fraudulent input.

[0076] The specific frequency band determination processing module 132 compares the plot results of the scatter data line derived from facial image data 1 of user 1, which is plotted with frequency on the horizontal axis and the number of occurrences on the vertical axis, with the scatter data line derived from facial image data 2, extracts the frequency band where the two are close to each other at three or more consecutive peaks and valleys, and determines that frequency band as the specific frequency band. In the visualized Figure 11, it can be seen that the plot results for three consecutive points in the frequency band from 0.004787 to 0.005533 are very close to each other. In this example, the frequency band from 0.004787 to 0.005533 is determined as the specific frequency band.

[0077] FIG. 12 is an enlarged view of the graph in a specific frequency band in FIG. The gridding processing module 133 grids the space plotted as a scatter diagram in which the horizontal axis represents spatial frequencies grouped into bins and the vertical axis represents the number of occurrences of the frequency components. In reality, the biometric image sequence data extraction module 130 performs numerical calculations through computer processing. In the visualized image in Figure 12, because it is enlarged, it can be seen that there is a difference in the number of occurrences of both, but it can also be seen that they belong to the same set grid.

[0078] Figure 13 is a graph of a specific frequency band, in which hatching is applied to parts that belong to the same frequency bin on the horizontal axis and the same grid with the same number of occurrences on the vertical axis. The hatched parts in the visualized Figure 13 are expressed as squares, and when the sets of discrete frequency values ​​and discrete occurrence values ​​assigned to these three squares are extracted as biometric image sequence data, they become (0.004880:0.5500), (0.004973:0.5500), and (0.005067:0.5500). In other words, the sequence consisting of six numbers from the three grids, "0.0048800.55000.0049730.55000.0050670.5500," becomes the biometric image sequence data. Furthermore, if the lower and upper limits of the range of the specific frequency band and its occurrence count are extracted as check data, the four numerical values ​​of 0.004787, 0.4375, 0.005067, and 0.5500 become the check data.

[0079] Next, the biometric hash data generation module 140 uses the hash function tool 141 to calculate a hash value from the biometric image sequence data of the six-digit sequence, thereby generating biometric hash data for personal authentication. Here, SHA256 is used as the hash function. The biometric hash data “62f668c8463a310d21b6e4de64b3566960f404586f1ec0678de018f843449bbb” is obtained and sent to the authentication server 200. The authentication matching processing module 230 of the authentication server 200 compares the authentication biometric hash data sent from the authentication application 100 with the registered biometric hash data registered in the authentication registration database 210, performs matching processing, and executes authentication processing. In this case, the matching processing is not successful, and the check data also does not match the four numbers 0.004600, 0.005533, 0.4375, and 0.6625 with the four numbers 0.004787, 0.4375, 0.005067, and 0.5500, so it is determined that the person cannot be authenticated, and the result is output and reported to the management system. The above is the flow of processing when the identity authentication of a person other than the person is not successful.

[0080] Next, a brief description will be given of a business application 300 to which the personal authentication application 100 of the present invention can be applied. The business application 300 is not particularly limited, and various main business applications are envisioned. For example, there are a wide variety of applications, such as a medical consultation application at a medical institution, a payment application for mail order or in-store shopping, a payment application for various service usage, a service usage application at a financial institution, a building entry / exit application, a home healthcare application (acquiring lifestyle information and health data within a home, etc.), and a logistics application (delivery and receipt). Note that various other business applications besides those listed above can also be the main business application 300. In these business applications 300, the personal authentication application 100 of the present invention can be applied to processing procedures that require eKYC (electronic Know Your Customer). In other words, the personal authentication application 100 of the present invention can also be used as an eKYC application. [Industrial Applicability]

[0081] The present invention can be widely applied as an identity authentication application or eKYC application that runs on a computer system. It can also be widely applied to a variety of business applications. For example, it can be widely applied to business applications that require identity authentication when logging in and logging out.

Claims

1. 1. An authentication application usable on a computer system, comprising: a biometric image data acquisition module that acquires image data of a user or an image data portion obtained by cutting out a specific region of the image data as biometric image data; a biometric image spatial frequency conversion data generation module including a spatial frequency conversion tool, the biometric image data being converted into a spatial frequency domain by the spatial frequency conversion tool to obtain biometric image spatial frequency conversion data; a biometric image sequence data extraction module that obtains the number of occurrences of each frequency as biometric image sequence data from the obtained biometric image spatial frequency conversion data; An identity authentication application including a hash function tool and a biometric hash data generation module that uses the biometric image sequence data obtained by the sequence data extraction module as input data and converts it into a hash value to generate biometric hash data.

2. If the user inputs the biometric image data at the time of registration, the biometric image spatial frequency conversion data generation module executes a registration time conversion data generation process in which the spatial frequency conversion data obtained from the biometric image data using the spatial frequency conversion tool is used as biometric image spatial frequency conversion data for registration; the biometric image sequence data extraction module executes a registration biometric image sequence data extraction process to extract the numerical value of the number of occurrences for each frequency from the biometric image space-frequency conversion data for registration as the biometric image sequence data; a registration biometric hash data generation process in which the biometric hash data generation module converts the biometric image sequence data obtained at the time of registration into a hash value to generate registration biometric hash data; The personal authentication application according to claim 1, wherein a registration biometric hash data transmission process is executed to transmit the generated registration biometric hash data to a storage device of a user terminal or to a database of a cloud system on a network.

3. When the user inputs the biometric image data during identity authentication, the biometric image spatial frequency conversion data generation module executes a conversion data generation process for generating biometric image spatial frequency conversion data for personal authentication, the spatial frequency conversion data being obtained from the biometric image data using the spatial frequency conversion tool; the biometric image sequence data extraction module executes a biometric image sequence data extraction process for extracting the number of occurrences of each frequency from the biometric image space-frequency conversion data for personal authentication as the biometric image sequence data for personal authentication; the biometric hash data generation module executes an authentication biometric hash data generation process by converting the biometric image sequence data for the personal authentication into a hash value to generate authentication biometric hash data; The personal authentication application according to claim 2, characterized in that it executes an authentication biometric hash data transmission process that transmits the generated authentication biometric hash data to the storage device of the user terminal or to the database of the cloud system on the network.

4. The storage device of the user terminal or the server on the cloud, a registration processing module that stores the registration biometric hash data in a storage device of the user terminal or in the database of a server on a cloud; 4. The personal authentication application of claim 3, further comprising an authentication matching processing module that receives the authentication biometric hash data generated during the personal authentication from the user, performs a matching process with the registered biometric hash data stored in the storage device of the user terminal or in the database of a server on the cloud, and executes the personal authentication process.

5. The personal authentication application according to claim 4, characterized in that the biometric image spatial frequency conversion data generation module is provided with a frequency low-pass filter, and performs frequency low-pass processing to leave only data below a predetermined frequency of the frequency low-pass filter from the obtained spatial frequency conversion data, and cut out data exceeding the predetermined frequency.

6. The personal authentication application according to claim 5, characterized in that the frequencies to be counted in the extraction process of the biometric image sequence data by the biometric image sequence data extraction module are discretized, and the count results of the number of occurrences for each discretized frequency are also summarized as discretized discrete spatial frequency transformed values.

7. The biometric image data for registration input by the user at the time of registration is a plurality of pieces of photographed data taken consecutively, The biometric image data for personal authentication input by the user at the time of personal authentication is a plurality of consecutively captured photographed data, At the time of the registration, the registration biometric hash data is generated using the plurality of biometric image data for registration; 7. The personal authentication application according to claim 6, wherein the authentication biometric hash data is generated using a plurality of pieces of the biometric image data for personal authentication during the personal authentication.

8. In the biometric image sequence data extraction module, in processing each of the data derived from a plurality of biometric images, a specific frequency band is selected in which the number of occurrences counted for each of the discretized frequencies is the same discrete value, and the discrete value of the number of occurrences in the specific frequency band is obtained as the biometric image sequence data; The personal authentication application according to claim 7 , wherein the biometric hash data generation module generates the biometric hash data from the biometric image sequence data in the specific frequency band.

9. The personal authentication application of claim 8, characterized in that the biometric image sequence data extraction module, in processing each of the data derived from a plurality of biometric images, is further provided with a three-dimensional object determination processing module that determines that the input photographic data is a plurality of photographic data taken consecutively from a planar object if the number of occurrences counted across the entire range of the discretized frequencies is the same discrete value, and that determines that the input photographic data is a plurality of photographic data taken consecutively from a three-dimensional object if the number of occurrences counted at some frequencies is a different discrete value.

10. the biometric hash data generation module outputs, as check data, the absolute values ​​of the upper and lower limits of the specific frequency band and the absolute values ​​of the upper and lower limits of the number of occurrences of the specific frequency band in addition to the generated biometric hash data for the specific frequency band; The registration processing module in the user terminal or the server on the cloud registers the check data in addition to the biometric hash data, The personal authentication application according to claim 9, characterized in that the personal authentication matching processing module performs a matching process of the check data in addition to a matching process of the registered biometric hash data and the authentication biometric hash data, thereby performing personal authentication processing.

11. 11. The personal authentication application according to claim 1, wherein the spatial frequency transformation tool is a Fourier transform tool or a wavelet transform tool.

12. An identity authentication application described in any one of claims 1 to 10, characterized in that when the biometric image data acquisition module acquires the image data portion cut out of the specific area of ​​the image data as the biometric image data, the specific area is a facial image portion including at least the user's eyes and nose.

13. 11. The personal authentication application according to claim 1, wherein the biometric image data is any one of a face image, a palm image, a vein image, a fingerprint image, an iris image, and a voice data image, or a combination thereof.

14. the biometric hash data generation module includes a plurality of different types of hash function tools as the hash function tools, and even if the input biometric image sequence data is the same, if the hash function tools are different, the conversion result into the biometric hash data will be different; An identity authentication application as described in any one of claims 1 to 10, characterized in that the biometric hash data generation module includes a hash function tool selection processing step for selecting one of the multiple types of hash function tools to be used.

15. 11. A business application incorporating an identity authentication application according to claim 1, wherein the login is possible on the condition that the identity of the user is authenticated by the identity authentication application at the time of login.

16. The business application according to claim 15, characterized in that the logout is possible not only at the time of the login but also at the time of the logout on the condition that the user's identity has been authenticated by the identity authentication application.