Information processing system and information processing method

A distributed biometric template system with multiple server verification processes ensures secure key recovery, preventing unauthorized access and enhancing privacy by making it difficult for others to obtain biometric information.

JP2026059310APending Publication Date: 2026-04-07HITACHI LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-26
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing biometric cryptography systems, such as described in Japanese Patent Application Publication No. 2023-125727, may allow unauthorized access to biometric templates and secret keys, compromising user privacy.

Method used

A distributed biometric template system where key recovery terminals receive input from multiple servers using proof information generated from key recovery biometric information, with each server determining template transmission based on verification processes, ensuring only authorized users can recover secret keys.

Benefits of technology

The system significantly enhances privacy by making it difficult for anyone other than the registered user to obtain information related to their biometric information, thereby securing the biometric templates and secret keys.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026059310000001_ABST
    Figure 2026059310000001_ABST
Patent Text Reader

Abstract

This system aims to create a system where it is difficult for anyone other than the registered user to obtain information about the registered biometric data. [Solution] The server set stores a distributed registration information set, which includes a distributed template set generated from registration biometric information. The key recovery terminal generates proof information using key recovery input information and sends it to the server set. The server set determines whether to send the key recovery distributed template set, determined from the distributed template set, to the key recovery terminal based on the distributed registration information set and the proof information. If the key recovery terminal successfully receives the key recovery distributed template set, it recovers the private key using the key recovery distributed template set and the key recovery input information.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an information processing system and an information processing method. [Background technology]

[0002] Biometric cryptography is a method that uses variable biometric information to recover a stable secret key. The recovered secret key is used in various cryptographic processes such as encryption, decryption, signature generation, and authentication.

[0003] A system based on biometric encryption generates a template using biometric information obtained from the user during the registration process and saves the template. Then, in the key recovery process, the system generates a secret key using biometric information obtained again from the user for key recovery and the saved template. The biometric encryption method is designed so that a secret key with a fixed value is recovered when the fluctuations between the biometric information for registration and the biometric information for key recovery are sufficiently small, and the value of the secret key is difficult to guess from the template alone.

[0004] From a privacy perspective, it is desirable that it be difficult for anyone other than the registered user to obtain information about their biometric data. To achieve this, it is necessary that it be difficult for anyone other than the user to obtain the template. This is because, although it is generally difficult to reconstruct the registered biometric data from the template, the template contains information related to the registered biometric data.

[0005] As a method to increase the difficulty of obtaining the template by someone other than the owner, a system that makes it difficult for someone other than the owner to download the template to a key recovery terminal is disclosed in Japanese Patent Application Publication No. 2023-125727 (Patent Document 1).

[0006] This publication states that "the key recovery terminal sends a message to the first server requesting the transmission of a template generated based on the user's registration biometric information, along with the user's first verification matching information. The first server holds the user's first registration matching information and the template. If the first verification process based on the first verification matching information and the first registration matching information is successful, the first server sends the template to the key recovery terminal. The key recovery terminal retrieves the user's key recovery biometric information and recovers the private key based on the template and the key recovery biometric information. If the first server fails the first verification process, it refuses to send the template to the key recovery terminal." (See summary). [Prior art documents] [Patent Documents]

[0007] [Patent Document 1] Japanese Patent Publication No. 2023-125727 [Overview of the Initiative] [Problems that the invention aims to solve]

[0008] In the technology described in Patent Document 1, for example, a server administrator may refer to a template stored on the server and obtain information regarding registration biometric information from the template. Therefore, one aspect of the present invention realizes a system in which it is difficult for anyone other than the target user of registration biometric information to obtain information regarding registration biometric information. [Means for solving the problem]

[0009] To solve the above problems, one aspect of the present invention adopts the following configuration. An information processing system comprising a key recovery terminal and a first to nth server (n is an integer of 2 or more), wherein the kth server (k is any integer of 1 or more and less than or equal to n) holds the kth registration information, which includes the kth distributed template included in a distributed template set generated based on registration biometric information, the key recovery terminal receives input of key recovery input information including key recovery biometric information, generates m pieces of proof information (m is a predetermined integer of 1 or more and less than or equal to n) using the key recovery input information, and the m pieces of proof information are respectively distributed to the a1th server to the a1st server and a2th server, which are m servers among the first to nth servers. m Server (a1 to a m Each value of is a distinct integer between 1 and n, and the k server sends it, and the k server determines whether to send the k-th key recovery distributed template included in the key recovery distributed template set determined from the distributed template set to the key recovery terminal based on a predetermined k rule, and if the key recovery terminal successfully receives the key recovery distributed template set, it recovers the secret key by performing a secret key recovery process using the key recovery distributed template set and the key recovery biometric information, and the a i The rule (where i is any integer between 1 and m) is the received proof information and the a i This rule involves performing a verification process using the registration information, determining whether transmission is permitted if the verification process is successful, and determining whether transmission is not permitted if the verification process fails. [Effects of the Invention]

[0010] According to one aspect of the present invention, a system can be realized in which it is difficult for anyone other than the target user of the registered biometric information to obtain information related to the registered biometric information.

[0011] Other issues, configurations, and effects not mentioned above will be clarified by the following description of the embodiments. [Brief explanation of the drawing]

[0012] [Figure 1] It is a block diagram showing a functional configuration example of a key generation system in Example 1. [Figure 2] It is a block diagram showing a hardware configuration example of a computer constituting each entity included in the key generation system in Example 1. [Figure 3] It is a sequence diagram showing an example of registration processing in Example 1. [Figure 4] It is a sequence diagram showing an example of key restoration processing in Example 1. [Figure 5] It is a block diagram showing a functional configuration example of the key generation system 10 in Example 2. [Figure 6] It is a sequence diagram showing an example of registration processing in Example 2. [Figure 7] It is a sequence diagram showing an example of key restoration processing in Example 2.

Mode for Carrying Out the Invention

[0013] Hereinafter, embodiments of the present invention will be described in detail based on the drawings. Note that it should be noted that this embodiment is merely an example for realizing the present invention and does not limit the technical scope of the present invention.

Examples

[0014] In Example 1, a key generation system via a network will be described. The system stores registration information generated using the user's biometric information, and in the key restoration process, the key restoration terminal restores a secret key with a fixed value based on the biometric information obtained again from a legitimate user. The restored secret key can be used for any cryptographic processing such as encryption, decryption, authentication, and generation of electronic signatures for any data.

[0015] Figure 1 is a block diagram showing an example of the functional configuration of a key generation system. The key generation system 10 includes, for example, a registration terminal 100, a first server 200, a second server 300, and a key recovery terminal 400. The registration terminal 100, the first server 200, the second server 300, and the key recovery terminal 400 are interconnected via a network 900.

[0016] However, not all of these devices necessarily need to be able to communicate with each other; for example, it is sufficient if the entities that communicate in each of the processes described later can communicate with each other. Also, the network 900 may be wired or wireless. The internet and local networks within an organization are examples of the network 900. Furthermore, if multiple devices in the key generation system 10 are contained within a single physical device, the network within that device may also be considered part of the network 900.

[0017] The registration terminal 100 includes, for example, a communication unit 101, a secret information acquisition unit 102 for generating verification information, a verification information generation unit 103, a biometric information acquisition unit 104, and a distributed template generation unit 105, all of which are functional units.

[0018] The first server 200 includes, for example, a communication unit 201, an information registration unit 202, and a first transmission permission determination unit 203, all of which are functional units. The first server 200 also includes, for example, a first registered information storage unit 220, which is an area for storing data.

[0019] The second server 300 includes, for example, a communication unit 301, an information registration unit 302, and a second transmission permission / failure determination unit 303, all of which are functional units. The second server 300 also includes, for example, a second registered information storage unit 320, which is an area for storing data.

[0020] The key recovery terminal 400 includes, for example, a communication unit 401, a secret information acquisition unit 402 for generating certification information, a certification information generation unit 403, a biometric information acquisition unit 404, a key recovery unit 405, and a cryptographic processing execution unit 406, all of which are functional units.

[0021] Figure 2 is a block diagram showing an example of the hardware configuration of the computers that make up each entity (registration terminal 100, first server 200, second server 300, and key recovery terminal 400) included in the key generation system 10. Computer 10000 has, for example, a CPU (Central Processing Unit) 10001, memory 10002, auxiliary storage device 10003, input device 10004, output device 10005, communication device 10006, and reading device 10007.

[0022] CPU10001 is an example of a processor and executes the program stored in memory10002. While CPU10001 and GPU (Graphics Processing Unit) are examples of processors, other semiconductor devices that perform the specified processing may also be used.

[0023] Memory 10002 includes non-volatile memory elements such as ROM (Read Only Memory) and volatile memory elements such as RAM (Random Access Memory). ROM stores immutable programs (e.g., BIOS (Basic Input / Output System)). RAM is a high-speed, volatile memory element such as DRAM (Dynamic Random Access Memory) and temporarily stores programs executed by CPU 10001 and data used during program execution.

[0024] The auxiliary storage device 10003 is a high-capacity, non-volatile storage device such as a magnetic storage device (HDD (Hard Disk Drive)) or flash memory (SSD (Solid State Drive)), and stores the program executed by the CPU 10001 and the data used when the program is executed. That is, the program is read from the auxiliary storage device 10003, loaded into memory 10002, and executed by the CPU 10001. In this embodiment and in other embodiments described later, memory 10002 and / or auxiliary storage device 10003 may be referred to as a storage hierarchy or storage resources.

[0025] The input device 10004 is a device that receives input from the operator, such as a keyboard or mouse. The input device 10004 may also include a biometric information acquisition device that acquires the user's biometric information, such as a camera that captures the user's facial image and a scanner that acquires the user's fingerprints or finger vein patterns. The output device 10005 is a device that outputs the program execution results in a format that the operator can see, such as a display device or printer.

[0026] The communication device 10006 is a network interface device that controls communication with other devices according to a predetermined protocol. The communication device 10006 may also include a serial interface such as USB (Universal Serial Bus).

[0027] Some or all of the program executed by CPU 10001 may be provided to computer 10000 via a network from an external computer equipped with a non-temporary storage medium such as removable media (CD-ROM, flash memory, etc.) or non-temporary storage device, and stored in non-volatile auxiliary storage device 10003, which is also a non-temporary storage medium. The reading device 10007 is an interface device for reading data from such removable media.

[0028] Each entity included in the key generation system 10 is a computer system that operates on a single physical computer 10000, or on multiple logically or physically configured computers 10000, and may operate in separate threads on the same computer, or on a virtual computer built on multiple physical computer resources.

[0029] The CPU 10001 of each computer 10000 that constitutes each entity included in the key generation system 10 includes the functional units of that entity as shown in Figure 1. For example, the CPU 10001 of the computer 10000 that constitutes the registration terminal 100 functions as a communication unit 101 by operating according to a communication program loaded into the computer 10000's memory 10002, and functions as a secret information acquisition unit 102 for generating verification information by operating according to a secret information acquisition program for generating verification information loaded into the memory 10002. The relationship between programs and functional units is similar for the other functional units of the registration terminal 100. The relationship between programs and functional units is also similar for the functional units of the first server 200, the second server 300, and the key recovery terminal 400, respectively.

[0030] Furthermore, some or all of the functions of the functional units of each entity included in the key generation system 10 may be implemented by dedicated circuits such as ASICs (Application Specific Integrated Circuits) or FPGAs (Field-Programmable Gate Arrays).

[0031] The auxiliary storage device 10003 of the computer 10000 that constitutes each entity included in the key generation system 10 provides a storage area for realizing each storage unit of the entity shown in Figure 1. Note that some or all of the information stored in each storage unit of the entity shown in Figure 1 may be stored in the memory 10002 of the computer 10000 that constitutes the entity, or in an external database connected to the entity.

[0032] In this embodiment, the information used by the key generation system 10 is independent of the data structure and can be represented in any data structure. For example, a data structure appropriately selected from a table, list, database, or queue can store the information.

[0033] Figure 3 is a sequence diagram showing an example of the registration process. In step S1101, the secret information acquisition unit 102 for generating verification information acquires secret information for generating verification information from the user. For example, if a password specified by the user is used as the secret information for generating verification information, the secret information acquisition unit 102 accepts the password input from the user via the input device 10004. Also, if the user's biometric information is used as the secret information for generating verification information, the secret information acquisition unit 102 accepts the biometric information input from the user via the input device 10004.

[0034] In step S1102, the verification information generation unit 103 generates first verification information and second verification information using the acquired secret information for generating verification information, and the communication unit 101 transmits the first verification information to the first server 200 and the second verification information to the second server 300. An example of the generation process for the first and second verification information will be described later.

[0035] In step S1103, the biometric information acquisition unit 104 acquires biometric information for registration from the user via the input device 10004. As biometric information for registration, biometric information acquired from one or more arbitrary parts such as the face, fingerprints, palm prints, and finger veins can be used.

[0036] In step S1104, the distributed template generation unit 105 generates a first distributed template and a second distributed template using the registration biometric information acquired in step S1103, and the communication unit 101 sends the first distributed template to the first server 200 and the second distributed template to the second server 300. An example of the generation process for the first and second distributed templates will be described later.

[0037] In step S1201, the information registration unit 202 of the first server 200 registers the first registration information, which includes the transmitted first verification information and the first distributed template, in the first registration information storage unit 220. The information registration unit 202 may also perform data processing such as encryption on the first registration information before registering it in the first registration information storage unit 220. In that case, the corresponding data processing such as decryption should be performed when the first registration information is used.

[0038] In step S1301, the information registration unit 302 of the second server 300 stores the second registration information, which includes the transmitted second verification information and second distributed template, into the second registration information storage unit 320. Similar to the first registration information, data processing may also be performed on the second registration information.

[0039] Figure 4 is a sequence diagram showing an example of the key recovery process. In step S2401, the secret information acquisition unit 402 for generating certification information acquires the secret information for generating certification information corresponding to the secret information for generating verification information from the user via the input device 10004.

[0040] Examples of secret information used for generating certification information include the following: If the secret information used for generating verification information is knowledge information such as a password, an example of the secret information used for generating verification information would be knowledge information such as a password with the same value. Also, if the secret information used for generating verification information is a private key, the secret information used for generating certification information would be a private key with the same value. Furthermore, if the secret information used for generating verification information is biometric information, an example of the secret information used for generating certification information would be biometric information obtained from the same body part as the secret information used for generating verification information.

[0041] Furthermore, it is assumed that the user who enters the biometric information for registration will manage the confidential information used to generate the certification information in a way that makes it difficult for anyone other than themselves to use it. This can be achieved, for example, as follows.

[0042] If the confidential information used to generate authentication information is knowledge information, it becomes difficult for anyone other than the person concerned to use it by not disclosing that knowledge information to anyone other than the person concerned. If the confidential information used to generate authentication information is a private key, it becomes difficult for anyone other than the person concerned to use it by not allowing others to use the IC (Integrated Circuit) card or electronic device, etc., on which the private key is stored. To make it difficult for others to use it, it is advisable to equip the device with an authentication function that uses knowledge information or biometric information. If the confidential information used to generate authentication information is the user's biometric information, it becomes difficult for anyone other than the person concerned to use it.

[0043] In step S2402, the certification information generation unit 403 generates first certification information and second certification information using the secret information for certification information generation obtained in step S2401, and the communication unit 401 transmits the first certification information to the first server 200 and the second certification information to the second server 300. Specific examples of the generation process for the first and second certification information will be described later.

[0044] In step S2201, the first transmission eligibility determination unit 203 determines whether the first distributed template included in the first registration information stored in the first registration information storage unit 220 can be transmitted, based on a predetermined first rule.

[0045] As an example of the first rule, the first transmission permission determination unit 203 performs a predetermined first verification process using the transmitted first certification information and the first verification information included in the first registration information stored in the first registration information storage unit 220. If the verification result is "verification successful", it determines "transmission permitted", and if the verification result is "verification failed", it determines "transmission denied".

[0046] When the first transmission permission determination unit 203 determines that transmission is permitted, the communication unit 201 transmits the first distributed template included in the first registration information to the key recovery terminal 400. When the first transmission permission determination unit 203 determines that transmission is not permitted, the communication unit 201 refuses to transmit the first distributed template to the key recovery terminal 400. As a specific example, the communication unit 201 sends a notification to the key recovery terminal 400 indicating that transmission is refused. Alternatively, the communication unit 201 may transmit a dummy first distributed template (for example, a randomly generated first distributed template) to the key recovery terminal 400.

[0047] In step S2301, the second transmission eligibility determination unit 303 determines whether the second distributed template included in the second registration information stored in the second registration information storage unit 320 can be transmitted, based on a predetermined second rule.

[0048] As an example of the second rule, the second transmission permission determination unit 303 performs a predetermined second verification process using the transmitted second certification information and the second verification information contained in the second registration information stored in the second registration information storage unit 320. If the verification result is "verification successful", it determines "transmission permitted", and if the verification result is "verification failed", it determines "transmission denied".

[0049] When the second transmission permission determination unit 303 determines that transmission is permitted, the communication unit 301 transmits the second distributed template included in the second registration information to the key recovery terminal 400. When the second transmission permission determination unit 303 determines that transmission is not permitted, the communication unit 301 refuses to transmit the second distributed template to the key recovery terminal 400. A specific example of the process when the communication unit 301 refuses to transmit the second distributed template to the key recovery terminal 400 is the same as the process when the communication unit 201 refuses to transmit the first distributed template.

[0050] In step S2403, the biometric information acquisition unit 404 acquires key recovery biometric information from the user via the input device 10004. The biometric information acquisition unit 404 only needs to acquire the key recovery biometric information from the same location as the registration biometric information.

[0051] In step S2404, the key recovery unit 405 recovers the private key using the key recovery biometric information obtained in step S2404 and the first and second distributed templates transmitted in steps S2202 and S2302. The system is designed so that the correct private key is recovered in step S2404 if the registration biometric information and the key recovery biometric information are sufficiently similar. A specific example of the private key recovery process will be described later.

[0052] In step S2405, the cryptographic processing execution unit 406 uses the secret key recovered in step S2404 to perform arbitrary cryptographic processing on arbitrary data, such as encryption, decryption, authentication, and digital signature generation.

[0053] [Specific examples of verification information generation, proof information generation, and verification] Specific examples of the verification information generation process in step S1102, the proof information generation process in step S2402, and the first verification process and the second verification process in the first transmission eligibility determination process in step S2201 and the second transmission eligibility determination process in S2301 will be explained.

[0054] Hereinafter, among the confidential information for generating verification information, the data used for generating the first verification information will also be referred to as the confidential information for generating the first verification information, and the data used for generating the second verification information will also be referred to as the confidential information for generating the second verification information. The confidential information for generating the first verification information and the confidential information for generating the second verification information may be the same data or different data. Similarly, the first verification information and the second verification information may be the same data or different data.

[0055] Hereinafter, among the secret information for generating proof information, the data used for generating the first proof information will also be referred to as the secret information for generating the first proof information, and the data used for generating the second proof information will also be referred to as the secret information for generating the second proof information. The secret information for generating the first proof information and the secret information for generating the second proof information may be the same data or different data. Similarly, the first proof information and the second proof information may be the same data or different data.

[0056] Specific examples of combinations of the first verification information generation process, the first proof information generation process, and the first verification process are described below. In this description of the specific examples, the term "first" is omitted. Note that similar specific examples can be used for combinations of the second verification information generation process, the second proof information generation process, and the second verification process. The combination of the second verification information generation process, the second proof information generation process, and the second verification process may be the same as or different from the combination of the first verification information generation process, the first proof information generation process, and the first verification process.

[0057] Let's explain the first specific example. Passwords, secret strings and word sequences, and secret keys stored on IC cards or similar devices held by the user—any secret information with a fixed value—are all examples of secret information for generating certification information. Furthermore, secret information that fluctuates can also be used as secret information for generating certification information if it can be correctly converted into fixed secret information with a high probability (for example, a probability of a predetermined value or higher) through error correction processing or similar methods.

[0058] The verification information generation unit 103 generates verification information in the verification information generation process by applying an arbitrary function to the secret information for verification information generation, such as the hash value of the secret information for verification information generation. Secret information having the same value as the secret information for verification information generation is an example of secret information for proof information generation. The proof information generation unit 403 generates proof information in the proof information generation process by applying the function used in the verification information generation process to the secret information for proof information generation. The first transmission eligibility determination unit 203 determines the verification result as "verification successful" in the verification process, for example, when the values ​​of the verification information and the proof information match, and determines the verification result as "verification failed" otherwise.

[0059] Let's explain the second specific example. The same type of secret information as in the first example is an example of secret information for generating certification information. In the verification information generation process, the verification information generation unit 103 generates a digital signature key pair (i.e., a signing key and verification key pair) from the secret information for generating certification information, and determines the verification key as the verification information. Note that at this time, the verification information generation unit 103 does not have to generate a signing key, or it may determine the secret information itself as the signing key.

[0060] Confidential information having the same value as the confidential information for generating verification information is an example of confidential information for generating proof information. In the proof information generation process, the proof information generation unit 403 generates a digital signature scheme key pair (i.e., a signing key and a verification key pair) from the confidential information for generating proof information, generates a digital signature for the message using the signing key, and determines the generated digital signature as proof information. Note that the proof information generation unit 403 does not need to generate a verification key at this time. Also, random numbers and date / time information generated by the first server 200 are all examples of the message in question.

[0061] The first transmission eligibility determination unit 203, in the verification process, for example, verifies the relationship between the digital signature and the message using a verification key, and determines the verification result as "verification successful" if the verification is successful, and as "verification failed" otherwise. In order to generate and verify the digital signature, the key recovery terminal 400 and the first server 200 share the target message (for example, one sends it to the other).

[0062] Let's explain the third specific example. Biometric information obtained from the user is an example of confidential information for generating verification information. The biometric information may be the same as or different from the registration biometric information obtained in step S1103. If registration biometric information is used as confidential information for generating verification information, the process of obtaining confidential information for generating verification information in step S1101 may be omitted. In the verification information generation process, the verification information generation unit 103 determines the feature quantities obtained by performing a feature extraction process on the biometric information used as confidential information for generating verification information as verification information.

[0063] Biometric information generated from the user is an example of secret information used for generating certification information. Biometric information is obtained from the same location as secret information used for generating verification information. If key recovery biometric information is used as secret information for generating certification information, the process of obtaining secret information for generating certification information in step S2401 may be omitted.

[0064] The certification information generation unit 403 determines the certification information to be a feature quantity obtained by performing a feature extraction process on biometric information, for example, as secret information for certification information generation, during the certification information generation process. The first transmission eligibility determination unit 203 compares the verification information with the certification information during the verification process and determines the verification result to be "verification successful" if the similarity is greater than or equal to a predetermined value (or the difference is less than or equal to a predetermined value), and determines the verification result to be "verification failed" otherwise.

[0065] In this third specific example, the features extracted during the verification information generation process are not kept secret from the server. To keep the features extracted during the verification information generation process secret from the server, for example, Example 2 described later can be used.

[0066] [Specific examples of biometric encryption processing] The specific examples of distributed template generation and key recovery described later will utilize biometric cryptography. A specific example of biometric cryptography processing will be explained below.

[0067] To perform the registration process, registration features y are extracted from registration biometric information x. In the registration process, a template T is generated based on y using a predetermined algorithm Gen, by T=Gen(y). To perform the key recovery process, key recovery features y' are extracted from key recovery biometric information. In the key recovery process, a secret key K' is recovered based on y' and T using a predetermined algorithm Rep, by K'=Rep(T,y').

[0068] The biometric cryptography scheme is designed so that when the registration biometric information x and the key recovery biometric information x' are sufficiently close, specifically when the registration feature quantity y extracted from the registration biometric information x and the key recovery feature quantity y' extracted from the key recovery biometric information x' are sufficiently close (for example, when the distance is below a predetermined threshold), a secret key with a fixed value can be recovered, and it is difficult to guess this fixed value from T alone.

[0069] This section explains specific examples of Gen in the registration process and Rep in the key recovery process of a biometric cryptography scheme. Let Y be the space to which the feature quantities belong, and Q be a subspace of Y. EC is a mapping from Y to Q and represents the error correction process.

[0070] As concrete examples of Y, Q, and EC, Y is a d-dimensional real space, Q is a lattice (i.e., Q is a set defined as Q = {B*z: z is a d-dimensional column vector whose components are integers} using a given d x d real square matrix B, where B*z is the matrix product of matrix B and vector z), and EC is the nearest neighbor lattice point solution process. Another concrete example of Y, Q, and EC is a vector whose elements are elements of a finite field, Q is an error correction code, and EC is the decoding process of the error correction code.

[0071] In the former specific examples of Y, Q, and EC, Y may be a region consisting of a part of a d-dimensional real space instead of a d-dimensional real space. In that case, operations on Y (for example, addition and subtraction of elements, and multiplication of elements by a matrix) should be modified so that the result of the operation becomes an element of Y. For example, consider the case where A is a predetermined positive integer and Y = {V is a d-dimensional real vector: each component of B^{-1}*V is greater than or equal to 0 and less than A}. In this case, the following are examples of operations on Y.

[0072] First, let V be the result of performing an operation on each element of Y, treating them as d-dimensional real vectors. Let E = B^(-1)*V, and let the components of E be (E_1,...,E_d). For each E_i (where i is any integer from 1 to d), let E'_i be the remainder when E_i is divided by A. Let E' be the vector whose components are (E'_1,...,E'_d), and let V' := B*E' be the result of the operation on Y. In this way, even if V is not an element of Y, V' will be an element of Y.

[0073] An example of Gen in the registration process is as follows: The algorithm Gen selects an element q of Q. The selection of q may be random or depend on y. Then, Gen defines the template T by T = y + q.

[0074] An example of Rep in key recovery processing is as follows: The key recovery algorithm Rep recovers q' by q'=EC(T-y'). In this case, since q'=EC(q+y-y'), q'=q when y and y' are sufficiently close. Then, Rep determines K' by K'=f_1(q') using a predetermined function f_1 (where "_" indicates an index). Since q'=q when y and y' are sufficiently close, the recovered secret key K' is equal to the fixed value f_1(q).

[0075] The secret key K' may be determined using y in place of or in addition to q'. When q'=q, y can be reconstructed using Tq. Therefore, if the secret key K' is determined by a predetermined function f_2 as K'=f_2(q',T-q'), then when y and y' are sufficiently close, the secret key K' becomes a fixed value f_2(q,y).

[0076] In the registration process, the Gen algorithm may output a fixed value as the secret key K in addition to T. Furthermore, the above registration and key recovery processes are merely examples, and any biometric encryption method such as Fuzzy Extractor, Fuzzy Commitment, or Fuzzy Vault may be used.

[0077] [Specific examples of distributed template generation and key recovery] This section describes specific examples of the distributed template generation process in step S1104 and the key recovery process in step S2404. In the following description, the first distributed template is represented as T_1, the second distributed template as T_2, and the recovered secret key as K'. Gen and Rep are the template generation algorithm and key recovery algorithm for the biometric cryptography scheme, respectively. In each specific example, the distributed template generation process extracts registration features y from registration biometric information x, and the key recovery process extracts key recovery features y' from key recovery biometric information x'.

[0078] Let's explain the first specific example. In the distributed template generation process, the distributed template generation unit 105 generates a template T using T=Gen(y). Then, the distributed template generation unit 105 generates a random number p and generates a distributed template using T_1=T+p and T_2=p. This random number p should be a random number that follows a predetermined distribution in the space to which the template belongs (for example, a uniform random number). It is preferable to use a random number p that is sufficiently random. Alternatively, a pseudorandom number may be used. In the key recovery process, the key recovery unit 405 recovers T from T_1 and T_2 using T=T_1-T_2, and then recovers K' using K'=Rep(T,y').

[0079] In this first specific example, even if either T_1 or T_2 is obtained, the information about T cannot be obtained. Therefore, neither the first server 200 nor the second server 300 can obtain the information about T, and thus the information about y used to generate T cannot be obtained.

[0080] Let's explain the second specific example. In the distributed template generation process, the distributed template generation unit 105 generates a transformation parameter p and generates a post-transformation registration feature c from y using a predetermined transformation function F, given by c=F(p,y). F(p,y)=p+y and F(p,y)=p*y are both examples of F. When F(p,y)=p+y is used as F, p is, for example, a random number (e.g., a uniform random number) that follows a predetermined distribution in the space to which the feature belongs. When F(p,y)=p*y is used as F, p is, for example, a random square matrix. Then, the distributed template generation unit 105 generates a distributed template using T_1=Gen(c) and T_2=p.

[0081] In the key recovery process, the key recovery unit 405 generates a transformed key recovery feature c' from y' using c'=F(T_2,y'), and recovers K' using Rep(T_1,c').

[0082] In this second specific example, T_1 is generated using the post-transformation registration feature v. If the transformation function F is designed in such a way that it is difficult to obtain information about y from c without knowing p, as in the example of F above, then it becomes difficult to obtain information about y from T_1. Also, it becomes impossible to obtain information about y from T_2.

[0083] [Main effects of this embodiment] This embodiment has the effect of making it difficult for anyone other than the registered individual to obtain information about the registration biometric information x. Furthermore, using specific examples of distributed template generation and key recovery, it becomes difficult for anyone other than the registered individual to obtain not only the registration biometric information x, but also information about the registration feature y.

[0084] In this embodiment, it is assumed that the user who entered the registration biometric information x manages the confidential information for generating certification information in a way that makes it difficult for anyone other than the user to use it. In this case, even if someone other than the user operates the key recovery terminal 400, it is difficult for them to enter the correct confidential information for generating certification information, and therefore it is difficult for them to obtain either the distributed template T_1 or T_2. Thus, even if someone other than the user operates the key recovery terminal 400, it is difficult for them to obtain information about the registration feature quantity y.

[0085] On the other hand, even if the administrator of the first server 200 knows T_1, it is difficult to obtain the registration feature y from T_1. Similarly, even if the administrator of the second server 300 knows T_2, it is difficult to obtain the registration feature y from T_2. Therefore, it is difficult for anyone other than the user themselves to obtain information about the registration feature y.

[0086] Furthermore, in this embodiment, it is difficult for the administrator of the first server 200, the administrator of the second server 300, and the key recovery terminal 400, which does not input the correct secret information for generating certification information, to obtain information about template T. Therefore, it becomes more difficult to guess the fixed value of the secret key recovered in the key recovery process.

[0087] [Example of changes to the process] In the verification information generation process of step S1102, it is not necessary to generate either the first verification information or the second verification information. As an example, let's explain the case where the second verification information is not generated. In this case, it is not necessary to obtain the second verification information in the registration process, nor is it necessary to store the second registration information. In the key recovery process, it is not necessary to obtain the second certification information, nor is it necessary to generate the second certification information.

[0088] Furthermore, an example of the second rule for determining whether the second transmission is permitted or not is as follows. The first example of the second rule is that the second transmission permission determination unit 303, which receives the determined first transmission permission from the first server 200, determines the second transmission permission to be "transmitted" if the first transmission permission is "transmitted," and determines the second transmission permission to be "transmitted" if the first transmission permission is "transmitted." Even when this rule is used, it is difficult for anyone other than the user themselves to receive the second distributed template even if they operate the key recovery terminal 400.

[0089] The second example of Rule 2 is a rule that states that when the second server 300 receives a request to send the second distributed template to the key recovery terminal 400, the second transmission permission determination unit 303 always determines the second transmission permission to be "transmission permitted". This request is made, for example, by the key recovery terminal 400 or the first server 200. When this rule is used, it is possible for someone other than the user to receive the second distributed template by operating the key recovery terminal 400, but it is difficult to receive the first distributed template, making it difficult for anyone other than the user to obtain the template information.

[0090] Furthermore, at least one of the first transmission eligibility and the second transmission eligibility may be determined by communication between the first server 200 and the second server 300. For example, during the communication, the first server 200 may send to the second server 300 information generated from at least one of the first verification information and the first proof information. Also, multi-party computation or the like may be used to determine at least one of the first transmission eligibility and the second transmission eligibility.

[0091] Furthermore, in the specific example of distributed template generation, a distributed template is generated based on template T after the template T is generated, but the template generation process and the distributed template generation process do not necessarily have to be separate. For example, if Y is the space to which the features belong, Q is a subspace of Y, and EC (the mapping from Y to Q) represents the error correction process, then in a method in which the distributed template generation unit 105 generates elements q of Q and random numbers p on Y, and then defines T_1=y+(q+p) and T_2=p based on the registration feature y, the template T=y+q itself is not generated during the process, but the same distributed template as in the specific example of distributed template generation is generated.

[0092] Similarly, in key recovery processing, it is not necessary to clearly separate the recovery of the template T from the key recovery processing using the template T. For example, in the distributed template generation example described above (where the distributed template generation unit 105 generates elements q of Q and random numbers p on Y, and then determines T_1=y+(q+p) and T_2=p based on the registration feature y), the key may be recovered using the key recovery feature y' by K'=EC(T_1-(T_2+y')).

[0093] Furthermore, the information that the user inputs to the key recovery terminal 400 during the key recovery process (referred to as key recovery input information) includes the secret information for generating certification information and the biometric information for key recovery. However, either the secret information for generating certification information or the biometric information for key recovery may be input first, or they may be input simultaneously. Also, if the secret information for generating certification information and the biometric information for key recovery match, or if one contains the other, the overlapping portion only needs to be input once.

[0094] Furthermore, during the registration process and key recovery process, the registration terminal 100 and the key recovery terminal 400 may accept input of information for identifying a user (for example, at least one of the following: user ID, name, and date of birth), and processing may be performed on the identified user (or narrowed-down candidate user). [Examples]

[0095] Example 2 describes a key generation system 10 via a network. The key generation system 10 in Example 2 uses the user's biometric information as confidential information for generating verification information and confidential information for generating proof information, and by appropriately converting and storing the biometric information used as confidential information for generating verification information, it becomes even more difficult for anyone other than the user to obtain the biometric information. Hereafter, explanations of points similar to those in Example 1 may be omitted as appropriate.

[0096] Figure 5 is a block diagram showing an example of the functional configuration of the key generation system 10 in Embodiment 2. The registration terminal 100 in this embodiment differs from the registration terminal 100 in Embodiment 1 in that, for example, instead of the secret information acquisition unit 102 for generating verification information and the verification information generation unit 103, it includes a temporary first verification information generation unit 106 and a temporary first distributed template generation unit 107, both of which are functional units.

[0097] The first server 200 of this embodiment differs from the first server 200 of Embodiment 1 in that it further includes, for example, a first verification information generation unit 204, a first distributed template generation unit 205, and a first key recovery distributed template generation unit 206, all of which are functional units.

[0098] The second server 300 of this embodiment differs from the second server 300 of Embodiment 1 in that it further includes, for example, a second verification information generation unit 304, a verification information concealment information generation unit 305, a second distributed template generation unit 306, a template concealment information generation unit 307, a certification information concealment information generation unit 308, a second key recovery distributed template generation unit 309, and a first key recovery distributed template generation information generation unit 310, all of which are functional units.

[0099] The key recovery terminal 400 of this embodiment differs from the key recovery terminal 400 of Embodiment 1 in that, for example, it includes a functional unit, the first certification information generation unit 407, instead of the secret information acquisition unit 402 and the certification information generation unit 403 for generating certification information.

[0100] Figure 6 is a sequence diagram showing an example of the registration process in Embodiment 2. In step S3301, the second verification information generation unit 304 generates second verification information. In step S3302, the verification information concealment information generation unit 305 generates first verification information concealment information and second verification information concealment information using the second verification information generated in step S3301, and the communication unit 301 transmits the first verification information concealment information to the first server 200 and the second verification information concealment information to the registration terminal 100.

[0101] In step S3101, the biometric information acquisition unit 104 acquires biometric information for verification information generation and biometric information for registration from the user. In this embodiment, biometric information is used as confidential information for verification information generation, and hereafter this biometric information will also be referred to as biometric information for verification information generation. The biometric information for verification information generation and the biometric information for registration may be biometric information of the same modality, or one modality may include the other modality. In these cases, the biometric information for verification information generation and the biometric information for registration can be acquired simultaneously.

[0102] In step S3102, the temporary first verification information generation unit 106 generates temporary first verification information using the biometric information for verification information generation acquired in step S3101 and the second information for concealing verification information transmitted in step S3202, and the communication unit 101 transmits the generated temporary first verification information to the first server 200. In step S3201, the first verification information generation unit 204 generates first verification information using the first information for concealing verification information transmitted in step S3202 and the temporary first verification information transmitted in step S3102.

[0103] In step S3303, the second distributed template generation unit 306 generates the second distributed template. In step S3304, the template concealment information generation unit 307 generates the first template concealment information and the second template concealment information using the second distributed template generated in step S3303, and the communication unit 301 transmits the first template concealment information to the first server 200 and the second template concealment information to the registration terminal 100.

[0104] In step S3103, the temporary first distributed template generation unit 107 generates a temporary first distributed template using the registration biometric information acquired in step S3101 and the second template concealment information transmitted in step S3304, and the communication unit 101 transmits the generated temporary first distributed template to the first server 200.

[0105] In step S3202, the first distributed template generation unit 205 generates a first distributed template using the temporary first distributed template transmitted in step S3304 and the first template concealment information transmitted in step S3304.

[0106] In step S3203, the information registration unit 202 registers first registration information, which includes the first verification information generated in step S3201 and the first distributed template generated in step S3202, in the first registration information storage unit 220. In step S3305, the information registration unit 302 registers second registration information, which includes the second verification information generated in step S3301 and the second distributed template generated in step S3303, in the second registration information storage unit 320.

[0107] Figure 7 is a sequence diagram showing an example of the key recovery process in Embodiment 2. In step S4301, the certification information concealment information generation unit 308 generates the first certification information concealment information and the second certification information concealment information using the second verification information contained in the second registration information stored in the second registration information storage unit 320, and the communication unit 301 transmits the first certification information concealment information to the first server 200 and the second certification information concealment information to the key recovery terminal 400.

[0108] In step S4401, the biometric information acquisition unit 404 acquires biometric information as secret information for generating certification information (biometric information for generating certification information) and biometric information for key recovery from the user via the input device 10004. In step S4402, the first certification information generation unit 407 generates first certification information using the biometric information for generating certification information acquired in step S4401 and the second information for concealing certification information transmitted in step S4301, and the communication unit 401 transmits the first certification information to the first server 200.

[0109] In step S4201, the first transmission permission determination unit 203 determines whether to transmit based on a predetermined first rule. As an example of the first rule, the first transmission permission determination unit 203 performs a first verification process using the first information for concealing certification information transmitted in step S4301, the first certification information transmitted in step S4402, and the first verification information included in the first registration information stored in the first registration information storage unit 220. If the verification result is "verification successful", it determines "transmission permitted", and if the verification result is "verification failed", it determines "transmission denied".

[0110] In step S4302, the second transmission eligibility determination unit 303 determines the second transmission eligibility based on a predetermined second rule. As an example of the second rule, the second server 300 receives the first transmission eligibility determined in step S4201 from the first server 200, and the second transmission eligibility determination unit 303 determines the second transmission eligibility to be "transmittable" if the first transmission eligibility is "transmittable," and determines the second transmission eligibility to be "transmitted" if the first transmission eligibility is "not transmittable." As another example of the second rule, the second transmission eligibility determination unit 303 always determines the second transmission eligibility to be "transmittable."

[0111] In step S4303, if the second transmission permission is "transmission permitted", the second key recovery distributed template generation unit 309 generates a second key recovery distributed template, and the communication unit 301 transmits the second key recovery distributed template to the key recovery terminal 400. If the second transmission permission is "transmission denied", the second key recovery distributed template generation unit 309 refuses to transmit the second key recovery distributed template.

[0112] In step S4304, the first key recovery distributed template generation information generation unit 310 generates the first key recovery distributed template generation information using the second key recovery distributed template, and the communication unit 201 transmits the first key recovery distributed template generation information to the first server 200. If the second transmission permission status is "transmission denied", the first key recovery distributed template generation information generation unit 310 may refuse to transmit the first key recovery distributed template generation information.

[0113] In step S4202, if the first transmission permission is "transmission permitted", the first key recovery distributed template generation unit 206 generates the first key recovery distributed template using the first key recovery distributed template generation information transmitted in step S4304 and the first distributed template included in the first registration information stored in the first registration information storage unit 220, and transmits it to the key recovery terminal 400. If the first transmission permission is "transmission denied", the first key recovery distributed template generation unit 206 refuses to transmit the first key recovery distributed template.

[0114] In step S4403, the key recovery unit 405 recovers the secret key by performing a key recovery process using the first key recovery distributed template transmitted in step S4202, the second key recovery distributed template transmitted in step S4303, and the key recovery biometric information obtained in step S4410. In step S4404, the cryptographic processing execution unit 406 performs cryptographic processing using the secret key recovered in step S4403. An example of cryptographic processing is the same as in step S2405 of Embodiment 1.

[0115] [Specific examples of distributed template generation and key recovery] This section explains specific examples of distributed template generation and key recovery, along with specific examples of the data generated for these processes.

[0116] The following is a specific example of the data generated for distributed template generation during the registration process. The second distributed template generation unit 306 generates a random number p and defines the second distributed template T_2 by T_2=p. The template concealment information generation unit 307 generates a random number r and defines the first template concealment information I_1 by I_1=T_2-r and the second template concealment information I_2 by I_2=r. The random number r, as well as the random numbers r', r'', and u described later, may be random numbers that follow a predetermined distribution in the space to which the template belongs (e.g., uniform random numbers), similar to the random number p. In addition, the random numbers P, R, and R' may be random numbers that follow a predetermined distribution in the space to which the verification information generation feature v belongs (e.g., uniform random numbers). It is preferable that sufficiently random numbers be used for these random numbers r, r', r'', u, P, R, and R'. Pseudorandom numbers may also be used.

[0117] The temporary first distributed template generation unit 107 extracts registration feature quantities y from registration biometric information x, generates a template T using the biometric cryptographic registration process Gen by T=Gen(y), and defines the temporary first distributed template T_tmp1 by T_tmp1=T+I_2. The first distributed template generation unit 205 defines the first distributed template T_1 by T_1=T_tmp1+I_1.

[0118] A specific example of the data generated for key recovery is as follows: The second key recovery distributed template generation unit 309 generates a random number r'' and determines the second key recovery distributed template T'_2 by T'_2=r''. The first key recovery distributed template generation information generation unit 310 determines the first key recovery distributed template generation information T'_tmp1 by T'_tmp1=T_2-T'_2.

[0119] The first key recovery distributed template generation unit 206 defines the first key recovery distributed template T'_1 by T'_1 = T'_1 - T'_tmp1. The key recovery unit 405 recovers the template T by T = T'_1 - T'_2, extracts key recovery feature quantities y' from the key recovery biometric information x', and recovers the secret key K' by K' = Rep(T, y') using the biometric cryptography key recovery process Rep.

[0120] [Specific examples of verification information generation, proof information generation, and verification] This section explains specific examples of verification information generation, proof information generation, and verification. The first example is explained below. In the registration process, the second verification information generation unit 304 generates a random number P and determines the second verification information S_2 by S_2=P. The verification information concealment information generation unit 305 generates a random number R and determines the first verification information concealment information H_1 by H_1=S_2-R and the second verification information concealment information H_2 by H_2=R.

[0121] The temporary first verification information generation unit 106 extracts a feature quantity v for verification information generation from the biological information w for verification information generation, and determines the temporary first verification information S_tmp1 by S_tmp1 = v + H_2. The first verification information generation unit 204 determines the first verification information S_1 by S_1 = S_tmp1 + H_1.

[0122] In the key recovery process, the proof information concealment information generation unit 308 generates a random number R', and determines the first proof information concealment information H'_1 as H'_1=S_2-R' and the second proof information concealment information H'_2 as H'_2=R'. The first proof information generation unit 407 extracts the proof information generation feature quantity v' from the proof information generation biometric information w', and determines the first proof information S'_1 as S'_1=v'+H'_2.

[0123] The first transmission eligibility determination unit 203, as a first verification process, calculates the difference between v' and v, v'-v, using v'-v=S'_1+H'_1-S_1, and determines the verification result as "verification successful" if the magnitude of v'-v (for example, the Euclidean norm if the feature is a real-valued vector, or the Hamming weights or L1 norm if it is an integer-valued vector) is less than or equal to a predetermined threshold t, and as "verification failed" otherwise.

[0124] Let me explain the second specific example. In this second example, registration biometric information x is used as verification biometric information w, and key recovery biometric information x' is used as proof biometric information w'. Therefore, in step S3101, the biometric information acquisition unit 104 does not need to acquire verification biometric information w, and in step S4401, the biometric information acquisition unit 404 does not need to acquire proof biometric information w'.

[0125] Furthermore, h is an arbitrary linear function that takes integer values ​​(e.g., a linear hash), and g is a group generator. In addition, the Gen method described in the specific example of the biometric cryptography processing in Example 1 is used (where Y is a region consisting of a d-dimensional real space or a part thereof, Q is a lattice (i.e., Q is a set defined as Q={B*z: z is a d-dimensional column vector whose components are integers} using a predetermined d x d real square matrix B, B*z is the matrix product of matrix B and vector z), and EC is the nearest neighbor lattice point solving process). This Gen method is also used in the temporary first distributed template generation process.

[0126] In the registration process, the second verification information generation unit 304 generates a random number P and determines the second verification information S_2 by S_2=P. The verification information concealment information generation unit 305 generates a random number R and determines the first verification information concealment information H_1 by H_1=S_2-R and the second verification information concealment information H_2 by H_2=R.

[0127] The temporary first verification information generation unit 106 uses q (let's call this q q_1) generated by Gen in the temporary first distributed template generation process to determine an integer a by a = h(B^(-1)*q_1) (where "^" indicates exponentiation), and determines the temporary first verification information S_tmp1 by S_tmp1 = g^(a+H_2). The first verification information generation unit 204 determines the first verification information S_1 by S_1 = S_tmp1*g^H_1.

[0128] In the key recovery process, the certificate information concealment information generation unit 308 generates random numbers R' and r', sets H'_11=S_2-R' and H'_12=T_2-r', and defines the first certificate information concealment information H'_1 as H'_1=(H'_11,H'_12). Furthermore, the certificate information concealment information generation unit 308 sets H'_21=R' and H'_22=r', and defines the second certificate information concealment information H'_2 as H'_2=(H'_21,H'_22).

[0129] The first proof information generation unit 407 defines the first proof information S'_1 as the following pair (S'_11, S'_12). The first proof information generation unit 407 extracts the key recovery feature quantity y' from the key recovery biometric information x', determines T' by T'=Gen(y'), and defines S'_12 by S'_12=T'+H'_22. Furthermore, the first proof information generation unit 407 uses the generated q (let's call this q'_1) to determine the integer a' by a'=h(B^(-1)*q'_1), and defines S'_11 by S'_11=g^(a'+H'_21).

[0130] The first transmission eligibility determination unit 203, as the first verification process, first calculates the template difference T-T' using T-T'=T_1-S'_12-H'_12, and then calculates the estimated value D_1 of a-a' using D_1=h(B^(-1)*EC(T-T')). When y and y' are sufficiently close, specifically when EC(y-y') is a zero vector, D_1=a-a'. Therefore, the first transmission eligibility determination unit 203 determines the verification result as "verification successful" if S'_11*(g^(D_1+H'_11))=S_1 holds, and as "verification failed" otherwise.

[0131] Let me explain the third specific example. In this third example, the biometric information x for registration is used as the biometric information w for generating verification information, and the biometric information x' for key recovery is used as the biometric information w' for generating proof information. Therefore, in step S3101, the biometric information acquisition unit 104 does not need to acquire the biometric information w for generating verification information, and in step S4401, the biometric information acquisition unit 404 does not need to acquire the biometric information w' for generating proof information.

[0132] Furthermore, the generation and storage of the first and second verification information are unnecessary, and the first verification process is performed using the first and second distributed templates. Specifically, in the registration process, the processes in steps S3301, S3302, S3102, and S3201 are unnecessary. Also, the first registration information and the second registration information do not necessarily have to include the first and second verification information, respectively.

[0133] In the key recovery process, the proof information concealment information generation unit 308 generates a random number r', and determines the first proof information concealment information H'_1 by H'_1=T_2-r' and H'_2 by H'_2=r'. The first proof information generation unit 407 extracts the key recovery feature quantity y' from the key recovery biometric information x', determines T' by T'=Gen(y'), and determines S'_1 by S'_1=T'+H'_2.

[0134] The first transmission eligibility determination unit 203 calculates the template difference T-T' using T-T'=T_1-S'_1-H'_1 and uses the template difference to calculate an estimated value D_2 of the magnitude of y-y'. For example, the first transmission eligibility determination unit 203 defines D_2 as the Euclidean norm of T-T'-EC(T-T'). It can be seen that when EC(y-y') is a zero vector, D_2 is the Euclidean norm of y-y'. In the first verification process, the first transmission eligibility determination unit 203 determines the verification result as "verification successful" if D_2 is less than or equal to a predetermined threshold, and as "verification failed" otherwise.

[0135] [Main effects of this embodiment] In this embodiment, the user's biometric information is used as the secret information for generating verification information and the secret information for generating certification information, and the first registration information and the second registration information are defined such that neither the first server 200 nor the second server 300 can obtain information on the biometric information for generating verification information. Furthermore, unless the user inputs the biometric information for generating certification information into the key recovery terminal 400, it is difficult for any of the first server 200, the second server 300, and the key recovery terminal 400 to obtain information on the biometric information for generating verification information during the key recovery process.

[0136] If someone other than the individual could obtain information regarding the biometric information used for generating verification information, they could potentially impersonate the individual by generating biometric information for generating proof information based on that information. However, since it is difficult for someone other than the individual to obtain information regarding the biometric information used for generating verification information, it is difficult to successfully impersonate someone in this way (specifically, to succeed in the first verification process). This means that it is difficult for someone other than the individual to obtain information regarding the biometric information used for registration.

[0137] Thus, this embodiment makes it possible to realize a key generation system 10 in which it is difficult for anyone other than the person concerned to obtain biometric information (both registration biometric information and confidential information for generating verification information). Furthermore, since the key generation system 10 of this embodiment also uses biometric information for the confidential information for generating certification information, it has the advantage of convenience in that it does not require the storage of a physical device or the storage of knowledge for key recovery processing.

[0138] Furthermore, the method described in the specific example of distributed template generation and key recovery in this embodiment has the following effects. To explain the effects, the set of registered first distributed template T_1 and second distributed template T_2 is also called the distributed template set, and the set of first key recovery distributed template T'_1 and second key recovery distributed template T'_2, which are sent to the key recovery terminal 400 for key recovery, is also called the key recovery distributed template set.

[0139] In Example 1, it can be understood that the distributed template set for key recovery (T'_1, T'_2), defined by T'_1=T'1 and T'_2=T'2, is sent to the key recovery terminal 400. In contrast, in Example 2, the distributed template set (T'_1, T'_2) is transformed by a random number r'', and the resulting (T'_1, T'_2) is sent to the key recovery terminal 400. As a result, the values ​​of each distributed template T'1 and T'2 are not sent outside of the respective servers where they are stored, making it more difficult for the user to recover a template T that they did not intend.

[0140] Furthermore, the second and third specific examples of verification information generation, proof information generation, and verification in this embodiment have the following advantages. First, biometric information for generating verification information and biometric information for generating proof information are not required. Therefore, one type of biometric information is sufficient, improving user convenience.

[0141] Furthermore, even if a powerful attack were to occur in which data stored on multiple servers were stolen, the data that would be recovered would be template T and g^a in the second example, and only template T in the third example, thus maintaining the difficulty of recovering the registration feature y.

[0142] In other words, the second and third specific examples demonstrate that a key generation system 10 can be realized that requires only one type of biometric information, is difficult for anyone other than the person concerned to obtain information on the registration feature y unless stored data is stolen from multiple servers, and maintains the difficulty of recovering the registration feature y even in the event of a powerful attack in which stored data is stolen from multiple servers.

[0143] Furthermore, the third specific example has the following effect: In the first and second specific examples of verification information generation, proof information generation, and verification, the kth registration information E_k stored on the kth server (k=1,2) consists of the kth verification information S_k and the kth distributed template T_k. In contrast, in the third specific example, the kth registration information E_k consists only of the kth distributed template T_k, which has the advantage of storage efficiency as it does not require the storage of additional data for the verification process.

[0144] [Example of changes to the process] By adding the following processing, a verification process can be included in the second transmission eligibility determination. In the registration process, steps S3301, S3302, S3102, and S3201 (and steps S3303, S3304, S3103, and S3202 if a distributed template is used for the verification process) which are processes related to the generation of the first verification information and the second verification information are performed with the roles of the first server 200 and the second server 300 swapped. As a result, the first server 200 can obtain the second verification information, and the second server 300 can obtain the first verification information (and the second distributed template and the first distributed template, respectively, if a distributed template is used for the verification process), the first server 200 can include the second verification information in the first registration information, and the second server 300 can include the first verification information in the second registration information.

[0145] In the key recovery process, steps S4301 and S4402, which are processes related to the first certification information, are performed with the roles of the first server 200 and the second server 300 swapped. As a result, the second server 300 can obtain the first certification information, and the second transmission permission determination unit 303 can perform the verification process using the same method as the first verification process in step S4201.

[0146] Furthermore, in order to avoid difficulties in obtaining biometric information and other data, it is desirable to regenerate the random numbers required for each process when switching the roles of the first server 200 and the second server 300 and performing each process.

[0147] Furthermore, the order of processing may be changed as long as it is feasible. For example, when the second transmission permission determination in step S4302 is always "transmission permitted", steps S4303 and S4304 may be performed simultaneously with step S4301, or before step S4301.

[0148] Furthermore, in Examples 1 and 2, the key generation system 10 described an example in which it performs key recovery using a distributed template set for key recovery that is generated based on a distributed template set consisting of distributed templates stored in two servers (first server 200 and second server 300). Generalizing this, the key generation system 10 may also perform key recovery using a distributed template set for key recovery that is generated based on a distributed template set consisting of distributed templates stored in n servers (where n is an integer of 2 or more).

[0149] In this case, there may be servers that store each of the distributed templates other than the n distributed templates mentioned above. That is, the key generation system 10 may include N servers (N is an integer greater than or equal to n) (the first server 200 to the nth server), each of the N servers storing one distributed template, and the set of distributed templates consisting of the distributed templates (the first distributed template to the nth distributed template) stored in n servers (the first server 200 to the nth server) out of the N servers may be used to define the set of distributed templates for key recovery. Note that the notation "X to Y" refers to the range from X to Y, including X and Y. In other words, for example, the description "Server 1 200 to Server N" refers to N servers consisting of Server 1 200, Server 2 300, ..., Server (N-1), and Server N, and the description "Distributed template 1 to Distributed template n" refers to N distributed templates consisting of Distributed template 1, Distributed template 2, ..., Distributed template (N-1), and Template N.

[0150] For example, one possible method is to generate N distributed templates by applying an (n,N) threshold secret sharing scheme (e.g., Shamir's secret sharing scheme) to a template T generated by the registration terminal 100, and then store these templates on N servers. In this case, if there are distributed templates stored on n servers, template T can be restored.

[0151] Not limited to the (n, N) threshold secret sharing method, any secret sharing method may be applied. Depending on the secret sharing method, the number of distributed templates required for restoration is not fixed, but a process of determining a distributed template set for key restoration using a distributed template set consisting of the number of distributed templates required for restoration may be performed.

[0152] Note that when a distributed template set consisting of distributed templates (first distributed template to nth distributed template) stored in n out of N servers (N ≥ n) (first server 200 to nth server) is used to determine the distributed template set for key restoration, among the first server 200 to nth server, in m (1 ≤ m ≤ n) servers, a transmission permission decision is made by verification processing using proof information and registration information. That is, for example, among the first server 200 to nth server, to the mth a i server (i is an arbitrary integer from 1 or more and m or less, and each value of a1 to a m is a different integer from 1 or more and n or less), the a k proof information is transmitted, and the rule for the a i is that when the verification processing using the a i proof information and the a i registration information is successful, the a i transmission permission is determined to be transmissible, and when the verification processing fails, the a i transmission permission is determined to be non-transmissible. Further, among the first server 200 to nth server, in servers other than the mth a i server, according to at least one result of the a1 transmission permission decision to a m transmission permission decision, a rule for determining transmission permission (for example, a rule similar to the second rule described in Example 1 (for example, a rule that is only "transmissible" when all of the a1 transmission permission decision to a m transmission permission decisions are "transmissible") may be used, or the a1 transmission permission decision to a mA rule is defined which determines whether a transmission is permitted if a predetermined number of transmission permission decisions (the predetermined number being 1 or more and m-1 or less) or more are "transmission permitted," and determines whether a transmission is not permitted if fewer than the predetermined number of transmission permission decisions are "transmission permitted." Alternatively, among the first server 200 to the nth server, the m a i A rule may be defined on at least one server other than the server itself that always sets it to "transmittable".

[0153] Furthermore, as an example of generating more than two distributed templates, a secret sharing scheme may be applied to the first and second distributed templates, respectively, using the methods described in the specific examples of distributed template generation and key recovery in Examples 1 and 2.

[0154] Furthermore, the distributed template stored on each server may be divided into multiple data items, in which case the distributed template stored on that server can be considered as a set of those multiple data items.

[0155] Furthermore, the key generation system 10 may include entities related to the distributed template set for key recovery other than the first server 200, ..., and the nth server. An example for n=2 is as follows: When the registration process is completed, the first server 200 stores the first distributed template T_1=T+p+u (where T is the template and p and u are random numbers), the second server 300 stores the second distributed template T_2=p, and the additional server (an example of the entities described above) stores the random number u.

[0156] In the key recovery process, when the decision to allow transmission at each server is "allowed to transmit", the additional server generates a random number r, sends r to the first server 200, and sends u+r to the second server 300. The first server 200 defines the first key recovery distributed template T'_1 as T'_1=T_1+r, and the second server 300 defines the second key recovery distributed template T'_2 as T'_2=T_2+u+r. The key recovery terminal 400 can recover T from T'_1 and T'_2 using T=T'_1-T'_2, and can recover the key from T and the key recovery biometric information.

[0157] Furthermore, some or all of the devices constituting the key generation system 10 may be a single physical device, or they may be separated by virtual machines or the like. In this case as well, if each virtual machine has a different administrator, the effect of making it difficult for anyone other than the user to obtain biometric information can be obtained.

[0158] It should be noted that the present invention is not limited to the embodiments described above, and various modifications are included. For example, the embodiments described above are described in detail to make the present invention easier to understand, and are not necessarily limited to those having all the configurations described. It is also possible to replace parts of the configuration of one embodiment with the configuration of another embodiment, and it is also possible to add configurations from other embodiments to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace parts of the configuration of each embodiment with other configurations.

[0159] Furthermore, each of the above configurations, functions, processing units, and processing means may be implemented in hardware, either partially or entirely, by designing them as integrated circuits, for example. Alternatively, each of the above configurations and functions may be implemented in software by having the processor interpret and execute programs that implement each function. Information such as programs, tables, and files that implement each function can be stored in memory, a recording device such as a hard disk or SSD (Solid State Drive), or a recording medium such as an IC card, SD card, or DVD.

[0160] Furthermore, the control lines and information lines shown are those deemed necessary for explanatory purposes, and not all control lines and information lines are necessarily shown in the actual product. In reality, it is safe to assume that almost all components are interconnected. [Explanation of Symbols]

[0161] 10 Key generation system, 100 Registration terminal, 103 Verification information generation unit, 105 Distributed template generation unit, 200 First server, 203 First transmission permission / failure determination unit, 220 First registration information storage unit, 300 Second server, 303 Second transmission permission / failure determination unit, 320 Second registration information storage unit, 400 Key recovery terminal, 403 Certification information generation unit, 405 Key recovery unit, 10000 Computer, 10001 CPU, 10002 Memory, 10003 Auxiliary storage device, 10006 Communication device

Claims

1. An information processing system, The system includes a key recovery terminal and a first to nth server (where n is an integer of 2 or more), The kth server (where k is any integer between 1 and n) holds the kth registration information, which includes the kth distributed template included in the distributed template set generated based on the registration biometric information. The aforementioned key recovery terminal is We accept input of key recovery information, including biometric information for key recovery. Using the aforementioned key recovery input information, m pieces of proof information (where m is a predetermined integer between 1 and n) are generated. The m pieces of certification information are each assigned to m servers from the first to the nth servers. 1 Server to the a m Server (a 1 or a m Each value of (1 or greater and n or less, all distinct integers) is sent, The k server determines, based on a predetermined k rule, whether or not to transmit the k-th key recovery distributed template, which is included in the key recovery distributed template set determined from the distributed template set, to the key recovery terminal. If the key recovery terminal successfully receives the distributed template set for key recovery, it recovers the private key by performing a private key recovery process using the distributed template set for key recovery and the biometric information for key recovery. a i The rule (where i is any integer between 1 and m) is the received proof information and the a i An information processing system that performs a verification process using registered information, and determines whether transmission is permitted if the verification result in the verification process is successful, and determines whether transmission is not permitted if the verification result is unsuccessful.

2. The information processing system according to claim 1, An information processing system in which at least one of the first to the nth distributed templates is generated based on a template generated by a transformation using transformation parameters applied to registration features extracted from the registration biometric information.

3. The information processing system according to claim 1, The k-key recovery distributed template is an information processing system which is the k-key distributed template.

4. The information processing system according to claim 1, An information processing system in which there exists at least one integer j, between 1 and n, such that the distributed template for recovering the j-th key has a different value from the j-th distributed template.

5. The information processing system according to claim 4, An information processing system in which at least one of the distributed templates for recovering the first key to the nth key is generated based on random numbers generated for confidentiality.

6. The information processing system according to claim 1, The aforementioned input information for key recovery includes biometric information for generating certification information. The key recovery terminal is an information processing system that generates at least one of the one or more pieces of certification information using the biometric information for generating the certification information.

7. The information processing system according to claim 6, An information processing system in which at least one of the first to the nth distributed templates is generated by concealing the biometric information for generating the proof information using parameters.

8. The information processing system according to claim 1, The key recovery terminal is an information processing system that generates at least one of the m pieces of certification information using the key recovery biometric information.

9. The information processing system according to claim 8, An information processing system in which at least one of the verification processes includes a process for verifying the difference between an integer generated in the generation of the distributed template set and an integer generated in the generation of the proof information.

10. The information processing system according to claim 8, The verification process includes an information processing system that calculates an estimated distance between a registration feature quantity generated from the registration biometric information and a key recovery feature quantity generated from the key recovery biometric information.

11. An information processing system according to claim 10, The k registration information is an information processing system, which is the k distributed template.

12. The information processing system according to claim 1, The k-distributed template is generated by a process that conceals the template generated from the registration biometric information using a random number for distributed template generation. The aforementioned private key recovery process includes a process for recovering the template from the distributed template set for key recovery, and is an information processing system.

13. An information processing system, It comprises a key recovery terminal and a server set including multiple servers, The aforementioned server set stores a distributed registration information set, which includes a distributed template set generated from registration biometric information, in a distributed manner. The aforementioned key recovery terminal is We accept input of key recovery information. Using the aforementioned key recovery input information, one or more certificates are generated. The one or more certificate pieces mentioned above are transmitted to the server set. Based on the distributed registration information set and the certificate information, the server set determines whether or not to send the distributed template set for key recovery, which is determined from the distributed template set, to the key recovery terminal. The key recovery terminal is an information processing system that, upon successful reception of the key recovery distributed template set, recovers a private key using the key recovery distributed template set and the key recovery input information.

14. An information processing method using an information processing system, The aforementioned information processing system includes a key recovery terminal and a first to nth server (where n is an integer of 2 or more). The kth server (where k is any integer between 1 and n) holds the kth registration information, which includes the kth distributed template included in the distributed template set generated based on the registration biometric information. The aforementioned information processing method is: The aforementioned key recovery terminal accepts input of key recovery input information, including key recovery biometric information. The key recovery terminal generates m pieces of proof information (where m is a predetermined integer between 1 and n) using the key recovery input information. The key restoration terminal transmits the m pieces of proof information to the a-th 1 server to the a-th m server (where each value of a 1 to a m is an integer different from each other that is 1 or more and n or less), The k server determines, based on a predetermined k rule, whether or not to transmit the k-th key recovery distributed template, which is included in the key recovery distributed template set determined from the distributed template set, to the key recovery terminal. If the key recovery terminal successfully receives the distributed template set for key recovery, it recovers the private key by performing a private key recovery process using the distributed template set for key recovery and the biometric information for key recovery. a i The rule (where i is any integer between 1 and m) is the received proof information and the a i An information processing method that performs a verification process using registered information, determines whether transmission is permitted if the verification result in the verification process is successful, and determines whether transmission is not permitted if the verification result is unsuccessful.

Citation Information

Patent Citations

  • Template management system and template management method

    JP2023125727A