User Equipment and Method for Protecting Confidential Data

By using a user device's image sensor to generate a compressed fingerprint for encrypting and decrypting private keys, the method addresses vulnerabilities in existing key protection solutions, enhancing security and flexibility while eliminating the need for dedicated hardware.

JP7683153B2Active Publication Date: 2025-05-27POLITECNICO DI TORINO +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2020090056
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-05-27
Filing Date
2020-05-22
Publication Date
2025-05-27
Estimated Expiration
2040-05-22

AI Technical Summary

Technical Problem

Existing solutions for protecting private keys in user devices are vulnerable to various attacks, including theft of dedicated hardware, plaintext storage vulnerabilities, and flexibility limitations in Trusted Execution Environments.

Method used

A method that utilizes an image sensor in user devices to capture images, generate a sensor fingerprint, and encode it using a random projection algorithm to create a compressed fingerprint, which is then used to encrypt and decrypt confidential data.

Benefits of technology

This approach significantly enhances the security of authentication systems by making it difficult for attackers to steal identification information, allows for flexible key protection throughout a device's life cycle, and avoids the need for dedicated hardware.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007683153000023
    Figure 0007683153000023
  • Figure 0007683153000024
    Figure 0007683153000024
  • Figure 0007683153000025
    Figure 0007683153000025
Patent Text Reader

Abstract

To provide a way to protect confidential data.SOLUTION: A device includes an image sensor and processing means for capturing multiple images by the image sensor, generating a sensor fingerprint based on the multiple images, encoding at least part of the sensor fingerprint using a random projection algorithm to generate a compressed fingerprint, and encrypting and / or decrypting confidential data using the compressed fingerprint as a key.SELECTED DRAWING: Figure 5
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to user devices such as smartphones, tablets, personal computers, laptops, etc. and methods for protecting confidential data, and more particularly to the encryption / decryption of secret encryption keys.

[0002] As is known, the latest electronic authentication systems are based on asymmetric encryption technology. The use of these technologies requires that each user / device be assigned a pair of keys, i.e., (pseudo) randomly generated sequences called "public key" and "private key". The private key is a (non-shared) secret that enables the authentication of the user / device. This must be protected by the user / device and must never be publicly shared. On the other hand, the public key is information that the user can disclose and must disclose in order for the operation of a system based on this type of encryption to be possible. For example, if user A wants to send an encrypted message to user B, user A must hold B's public key, and he / she encrypts the message with the public key and sends the message to user B. User B is the only entity that holds his / her private key and is the only entity that can decrypt the message. In fact, the decryption of a message encrypted with B's public key can only be performed with user B's private key.

[0003] Another example where asymmetric encryption technology is used for authentication is the so-called "digital signature" that enables user A to verify user B's identification information. In this scenario, user A sends a message called a challenge to user B. Then, user B signs the challenge using his / her private key and sends the signed message to user A. User A, who holds user B's public key, can verify the identification information by verifying the integrity of user B's signature and the public key of the message.

[0004] To protect the private key, there are different state-of-the-art solutions such as storage on dedicated removable hardware (e.g., USB tokens, smart cards, hardware wallets for cryptocurrencies, etc.), storage on non-volatile memory that runs applications accessible to such keys in a "Trusted Execution Environment" (either in plain text or encrypted), storage on dedicated cryptographic chips included in smartphones and cloud storage (also known as Secure Element).

[0005] However, each of these systems listed here has problems and / or vulnerabilities. In fact, storage on dedicated external hardware has the drawback that the user has to keep all the necessary hardware with them (tokens to access services, signing tokens, smart cards, smart card readers, etc.). Furthermore, the dedicated hardware may not be general-purpose, i.e., it may only allow specific operations or only keys pre-installed at the manufacturing stage. Additionally, this may have interface connection problems. In fact, it is very often impossible to connect a USB token to a smartphone.

[0006] On the other hand, plain text storage in the local memory of the device is vulnerable to any malicious user who holds the access credentials to the device.

[0007] Encrypted storage on non-volatile local memory is vulnerable to any malicious user who holds the access credentials to the device and can (offline) generate a copy of the memory and decrypt the memory content.

[0008] Executing an application that can access such keys in a virtualized area of a device's processor and RAM, i.e., the Trusted Execution Environment, which is accessible only to what is explicitly done and not to all of the system's applications, results in lower flexibility in application generation. This is because higher security corresponds to reducing the possibility of third-party applications and increasing the memory and computing power requirements for virtual environment formation. Furthermore, since the Trusted Execution Environment can be (maliciously) changed to provide appropriate privileges based on software implementation, it provides more "attack surfaces".

[0009] As described above, the storage of dedicated cryptographic chips has the drawback of not being very flexible for dedicated external hardware. On the other hand, updatable versions of such cryptographic chips are vulnerable. In fact, these internal data are written to writable memory, which further enables the formation of clones (as possible in the Trusted Execution Environment).

[0010] Cloud storage of data requires an internet connection and that the server where the key is maintained is secure (at a reliable security level since the device where the storage is physically realized is not under the direct control of the user who holds the key).

[0011] It is clear how these vulnerabilities can enable a third party to steal so-called electronic identification information and enable them to commit their intended crimes such as transferring money from the user's bank account to other accounts, sending emails from the user's account to all other addresses present in the user's address book, minimizing the effect of anti-spam filters, sending the stolen identification information to others, etc.

[0012] The present invention proposes a solution to these and other problems by providing a method for protecting confidential data according to the appended claims.

[0013] The present invention further provides a user device for protecting confidential data according to the appended claims.

[0014] The underlying concept of the present invention is to configure a user device to capture a plurality of images by an image sensor provided in the device, generate a sensor fingerprint based on the plurality of images, and generate a compressed fingerprint by encoding at least a part of the sensor fingerprint using an algorithm of random projection, and use the compressed fingerprint as a key to encrypt and / or decrypt confidential data.

[0015] In this way, it is possible to improve the security of the authentication system. In fact, stealing the identification information by stealing the secret key encrypted using the compressed fingerprint as a key is particularly complicated (even if it is not impossible). This is because in order to decrypt the encrypted secret key, it is determined that it is necessary to have access to the user terminal with sufficient access rights to utilize the image sensor of the user device, so it is necessary to hold the fingerprint of the image sensor.

[0016] Furthermore, if a third party (attacker) somehow illegally generates the fingerprint of the image sensor (for example, directly from the user terminal or from the Internet by imaging the photo taken by the sensor), it is further possible to return the authentication system to a secure state by using a new seed to generate a new compressed fingerprint by the algorithm of random projection and encrypting a new secret key using the new compressed fingerprint as a key.

[0017] By securely storing the key in the user device, the device already owned by the user can be advantageously utilized, and it should also be emphasized that this avoids the purchase and management costs of dedicated hardware. Furthermore, this technical solution is very flexible. The cryptographic key can be protected at any time during the device's life cycle. For example, since it is possible to make the keys already held by the user difficult to decrypt, they can be used generically in an already operating authentication system. In fact, such a solution can be used as an additional security level, and the key can be made available only when the fingerprint of the camera sensor is available.

[0018] Further advantageous features of the present invention are the subject of the appended claims.

[0019] These features and further advantages of the present invention will become clearer from the description of its embodiments shown in the accompanying drawings, which are provided by way of non-limiting example only.

Brief Description of the Drawings

[0020]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Modes for Carrying Out the Invention

[0021] The description of "Embodiment" in this specification is intended to indicate that a specific configuration, structure, or feature is provided in at least one embodiment of the present invention. Therefore, the terms "in an embodiment" and similar terms present in different parts of this specification do not necessarily all refer to the same embodiment. Furthermore, a specific configuration, structure, or feature can be combined in any appropriate manner in one or more embodiments. The descriptions used below are for convenience only and do not limit the scope of protection or the scope of embodiments.

[0022] Referring to FIG. 1, here, for example, in a typical usage scenario, an authentication system S that operates according to the WebAuthn standard (recommended by the FIDO Alliance) will be described. Such an authentication system S includes the following parts. - A user device 1 according to the present invention, such as a smartphone, tablet, etc. - An application server 2 configured to provide at least one service that requires authentication of the user device 1, that is, the user device 1 is associated with a specific account in the registration stage (more specifically, described later in this specification), and a secret and / or personal service is associated (for example, access to a current account of an individual or company in a social networking service such as Facebook (registered trademark), access to an individual or company profile), and it is necessary to confirm that it is the same as the user device (for example, services such as social networks, email, transactions, home banking, e-commerce, online banking, cryptocurrency exchanges, etc.).

[0023] The user device 1 and the application server 2 perform signal communication with each other via a data network, preferably a public data network (such as the Internet).

[0024] The application server 2 may be composed of one or more servers appropriately configured to form a cluster, and is preferably configured to send at least one authentication request to the user device after the user device 1 requests access to the application server 2 to a secret and / or personal service, i.e., a service that requires authentication of the user device 1. Such an authentication request preferably includes a string (e.g., representing the time of such a request) that the user device 1 must return signed using its secret signature, whereby the application server 2 can authenticate the user device 1 using the public key associated with the secret key.

[0025] The user device 1 includes an image sensor 14 (such as an imaging sensor, a night vision sensor, etc.). Such a user device 1 may alternatively be composed of a personal computer, a laptop, or another electronic device that performs signal communication with an image sensor (such as a webcam), and is preferably provided (integrally) within the device.

[0026] The application server 2 includes several elements (i.e., control and processing means, volatile memory means, mass memory means, communication means, and input / output means) that are functionally similar to those of the user device 1, perform signal communication with each other, and are configured to execute different functions described in more detail later in this specification. Further, such an application server 2 may also be provided together with the user device 1 when a service that requires authentication of the user device 1 is directly executed by the user device 1.

[0027] Referring also to FIG. 2, the user device 1 according to the present invention (such as a smartphone, a tablet, etc.) includes the following components. - Control and processing means 11 (also referred to as processing means), such as one or more CPUs that control the operation of device 1 through the execution of appropriate instructions, preferably in a programmable manner - For example, volatile memory means 12 such as a random access memory RAM that performs signal communication with the control and processing means 11. In the volatile memory means 12, it is possible to implement the method according to the present invention and store at least instructions that can be read by the control and processing means 11 when the device 1 is in an operating state. - Mass storage means 13 that performs signal communication with the control and processing means 11 and the volatile memory means 12, preferably one or more magnetic disks (hard disks) or flash type or other types of memory - For example, an image sensor 14 such as an imaging sensor, a night vision sensor using infrared rays, etc. - Communication means 15, preferably a network interface that operates according to the 802.11 standard family (known by the name WiFi (registered trademark)), 802.16 (known by the name WiMAX (registered trademark)), IEEE803.2 (also known by the name Ethernet (registered trademark)), or an interface with a data network of types such as GSM (registered trademark) / GPRS / UMTS / LTE, TETRA, etc. that enables the device 1 to communicate with other devices via a data network. The latter will be described in more detail later in this specification. - Input / output means (I / O) 16 that can be used to connect the device 1 to peripheral devices (such as one or more interfaces that enable access to other mass storage means and thereby preferably enable copying of information from these to the mass storage means 13), or to a programming terminal configured to write instructions (that the processing means and the control means 11 must execute) to the memory means 12, 13. Such input / output means 16 can include adapters such as USB, FireWire, RS232, IEEE1284, etc. - A communication bus 17 that enables the exchange of information between the control and processing means 11, the volatile memory means 12, the mass storage means 13, the image sensor 14, the communication means 15, and the input / output means 16.

[0028] Instead of the communication bus 17, it is possible to connect the control and processing means 11, the volatile memory means 12, the mass memory means 13, the image sensor 14, the communication means 15 and the input / output means 16 to a star architecture.

[0029] Referring further to FIG. 3, a typical scenario using the method and user equipment 1 according to the present invention is described in more detail here. Here, by executing the steps of the method for registering the user equipment 1, it is then possible to authenticate the user equipment 1 in the device 1. Preferably, the registration method executed by the user equipment 1 comprises the following steps. - An image acquisition step E1 in which a plurality of images (preferably a number provided between 10 and 30, for example, a number compatible with the calculated power provided by the processing means 11) are captured in raw format (RAW) by the image sensor 14, preferably to make more distinct the defects of the image sensor 14 due to impurities in the silicon portion in which it is formed. - A registration fingerprint calculation step E2 in which a registration sensor fingerprint is generated by the processing means 11 of the user equipment 1 based on the plurality of images captured in step E1, and at least a part of the registration sensor fingerprint is encoded (compressed) by the processing means and control means of the user equipment 1 using a random projection algorithm, thereby generating a compressed fingerprint W of at least a part of the registration sensor fingerprint. For example, the processing means and control means of the user equipment 1 are configured to execute an instruction set implementing a random projection algorithm (described in more detail later in this specification). - A key, that is, a copy of the public key and the private key, is generated, the public key is transmitted to the application server 2, and the private key is encrypted using the compressed fingerprint W as a key, preferably by a symmetric encryption algorithm, thereby generating an encrypted private key (also referred to as a "sketch"), which is stored in the memory means 12, 13, a key generation step E3. A public key transmission step E4 in which the public key generated in step E3 is transmitted by the communication means 15 of the user device 1 to the application server 2 through a preferably protected channel (such as a connection like SSL).

[0030] Referring further to FIG. 4, a method for authenticating the user device 1 at the application server 2 is described herein. The authentication method preferably executed by the user device 1 comprises the following steps. - An image acquisition step V1 in which at least one image (preferably the number of images is compatible with the calculation power provided by the processing means 11 and, for example, a number of images provided between 5 and 10) is preferably captured in raw format (RAW) by the image sensor 14 for the same reasons as already described above. - Based on the plurality of images captured in step V1, in a similar or same manner as step E2 described above, an authentication sensor fingerprint is generated by the processing means 11 of the user device 1, thereby generating a compressed fingerprint W of at least a part of the authentication sensor fingerprint, an authentication fingerprint calculation step V2. - By the processing means 11, the encrypted secret key (also referred to as a "sketch") is read by the memory means 12, 13 and is decrypted using the compressed fingerprint W as a key by a symmetric encryption algorithm preferably the same as or consistent with that used in step E3, thereby restoring the secret key, that is, obtaining a plaintext copy of the secret key, a secret key restoration step V3. - An authentication request (i.e., a message also referred to as a "challenge") is received by the application server 2, and the processing means 11 performs the following steps, generating an electronic signature based on the authentication request that executes a digital signature algorithm that uses the secret key as a key (such as DSA, ECDSA, etc., i.e., an asymmetric encryption algorithm), and transmitting the electronic signature to the application server 2 by the communication means 15, and performing a signature step V4.

[0031] When the system S is in an operating state, the elements 1, 2, and 3 of the system preferably perform the following steps. - The user device generates a key pair, i.e., a public key and a private key, registers the public key with the application server 2 that transmits the public key to it and stores the private key in the memory means 12, 13. - The user device 1 accesses the public service provided by the application server 2 (e.g., accesses the "landing page" of the service provided by the server 2), and transmits the user information that requires access to at least one service that requires authentication of the user device 1. - Based on the user information received from the user device, the application server 2 generates an authentication request ("challenge") (e.g., generates a message including at least the user information), and transmits the authentication request to the device 1. - The user device 1 performs the following sub-steps (after executing the method according to the present invention described later) generating an electronic signature based on the authentication request that executes a digital signature algorithm using the private key as a key (e.g., DSA, ECDSA, etc., i.e., like an asymmetric encryption algorithm), and transmitting the electronic signature to the application server 2. - The application server 2 verifies the authenticity of the electronic signature received from the user device 1 that executes a digital signature verification algorithm using the public key as a key (e.g., DSA, ECDSA, etc., i.e., like an asymmetric encryption algorithm).

[0032] Referring further to FIG. 5, the method according to the present invention is described herein. This is executed in the registration and authentication methods described above. Specifically, the method is generalized as a method for protecting secret data (e.g., one or more private keys), and the following steps - An image acquisition step P1 in which a plurality of images are captured by the image sensor 14, and - The sensor fingerprint is generated by the processing means 11 in the fingerprint calculation stage P2 based on a plurality of images captured in the image acquisition stage P1. - In the compression stage P3, at least a part of the sensor fingerprint is encoded by the processing means 11 using a random projection algorithm to generate a compressed fingerprint W. - In the processing stage P4, the confidential data is encrypted and / or decrypted using the compressed fingerprint W as a key. It is provided with. In this way, it is possible to improve the security of the authentication system.

[0033] In each of the image imaging stages E1, P1, and V1, before the image sensor 14 executes at least one imaging of an image, the processing means 11 executes a set of command sets for generating a set of sensor control signals configured to configure the image sensor 14 to capture an image. As a result, the image captured by the sensor can extract a higher-quality sensor fingerprint, that is, a sensor fingerprint less affected by noise. In this way, the repeatability of the extraction process is improved.

[0034] The sensor control signal encodes imaging data that defines the imaging parameter as the focal length, the sensor sensitivity (also known as ISO sensitivity), and the exposure time.

[0035] The processing means may be configured to determine a focal length that allows the image sensor 14 to capture an out-of-focus image of the surrounding environment in one of the image imaging stages E1, P1, and V1. More specifically, the processing means preferably performs the following steps - Generating an estimated focal length that enables the image sensor 14 to capture a sharp image of the surrounding environment, that is, to be captured by correctly setting the focal length (for example, executing a focal length estimation algorithm according to the state of the art using a stream of low-resolution images captured by the image sensor 14). - Selecting a focal length different from the estimated focal length. may be configured to execute.

[0036] These steps may be implemented in the user device 1 that configures itself such that when the focal length estimation algorithm indicates that the environment requires the use of an infinite focal length (e.g., when the image sensor 14 frames a landscape), it selects an imaging mode known as "macro" (focal length less than 1 meter), and when the focal length estimation algorithm indicates that the environment requires the use of a focal length less than 1 meter (e.g., when the image sensor 14 frames a detail of an object), it selects an imaging mode known as "landscape" (infinite focal length).

[0037] This reduces the high frequencies (i.e., the entropy of the image) present in the image due to the surrounding environment, so that only the high frequencies generated by the physical defects of the sensor 14 are maintained in the image, thereby improving the repeatability of the sensor fingerprint extraction process.

[0038] Thus, the integration of the method according to the present invention in existing user devices is simplified, the reduction of high frequencies due to the surrounding environment reduces the computational load, the required number of extractions of the fingerprint is reduced, and the security level of the system S is improved.

[0039] As a combination or alternative to the above, the processing means 11 may be configured to determine the exposure time and / or the sensor sensitivity so as to capture an image without a saturation zone in one of the image capture steps E1, P1, and V1. In this way, the quality of the extracted fingerprint is improved, i.e., the repeatability of the extraction process is improved, and advantageously, the required number of extractions is reduced, thereby improving the security level of the system S.

[0040] An approach that can be taken to generate an image capable of extracting a good-quality sensor fingerprint is to reduce the sensor sensitivity as much as possible and increase the exposure time until a very bright and unsaturated image is obtained. For example, the processing means 11 performs the following steps - Selecting a sensitivity value corresponding to the minimum value that the sensor 14 can take and setting such a value as a shooting parameter; - Based on the ambient environment of the image sensor 14, determining an estimated sensitivity value and an estimated exposure time value using a well-known algorithm in the state of the art, preferably, for example, a 3A algorithm (auto exposure, autofocus, automatic white balance), in order to obtain a sufficiently exposed image; - Determining the exposure time based on the selected sensor sensitivity, the estimated sensitivity value, and the estimated exposure time value; - Setting the exposure time as a shooting parameter of the image sensor 14; It is possible to configure it to execute.

[0041] The determination of the exposure time may be performed, for example, by multiplying the estimated exposure time value by a correction factor and multiplying by the ratio between the minimum sensitivity value that can be taken and the estimated sensitivity value.

[0042] However, if executing the foregoing steps results in an exposure time higher than the threshold (for example, because the ambient environment of the image sensor 14 is dark), the processing means 11 may execute such steps again, but may be configured to select a higher sensitivity value as the shooting parameter than the previous one.

[0043] Instead of or in combination with increasing the sensitivity value, the processing means 11 may be configured to increase the number of images to be captured (for example, from 5 to 10), thereby increasing the amount of information available for extracting the sensor fingerprint.

[0044] In processing stage P4, the encryption and / or decryption operation of the confidential data may preferably be performed by executing an exclusive bit-by-bit OR operation (bitwise XOR) between the compressed fingerprint W and at least the column consisting of the confidential data.

[0045] In compression stage P3, the sensor fingerprint calculated in fingerprint calculation stage P2 is compressed using the random projection (RP) technique. In other words, in each stage P3, the processing means and control means of the user device 1 are configured to execute an instruction set implementing a compression algorithm that utilizes the random projection technique.

[0046] This algorithm provides a stage of compressing the registered and authenticated sensor fingerprint with very little or ideally no loss of information. More specifically, the random projection technique is a powerful but not overly complex dimensionality reduction method, based on the concept of projecting the original n-dimensional data onto an m-dimensional subspace where m < n using a random matrix

Number

Number

Number

Number

[0047] The main property that supports RP technology is the Johnson-Lindenstrauss lemma (which is considered an inseparable part of this specification) regarding the low-distortion embedding of points from a high-dimensional to a low-dimensional Euclidean space. The lemma establishes that a small set of points in a high-dimensional space can be embedded into a much lower-dimensional space while (almost) maintaining the distances between the points.

[0048] According to such a premise, the user device 1 may be configured to calculate each compressed version of the calculated sensor fingerprint by multiplying it by a random projection, that is, by multiplying (matrix multiplication) between a compression matrix and a matrix representing the sensor fingerprint (or vice versa). Here, the compression matrix has a smaller number of rows (or columns) than the matrix representing the sensor fingerprint.

[0049] The result of the product may be quantized, that is, represented by a finite number of bits, in order to obtain a more compact representation of the compressed version of the sensor fingerprint. For example, the binary version of the compressed sensor fingerprint may be obtained by the following formula.

Number

[0050] In other words, in the compression stage P3, at least a part of the sensor fingerprint is encoded using a random projection algorithm, thereby generating an encoded sensor fingerprint. After that, the encoded sensor fingerprint is quantized by the processing means 11 to generate a compressed fingerprint W.

[0051] By doing so, by storing and processing less data, specifically, without requiring Device 1 to perform the decoding of high-sensitivity data, it is possible to generate a compressed version of the (registered or authenticated) sensor fingerprint without degrading the security characteristics of the authentication system S. Thus, reducing the spatial complexity enables the use of limited resources of the user device 1, whereby such an authentication system S can be used in a large number of user terminals. This makes it possible to generate an authentication system S that uses user terminals that are not necessarily of the latest generation, thereby improving the global security level.

[0052] Instead of or in combination with the above, the security of the system is based on the use of a pseudo-random number generator initialized by a seed that is kept secret on the user's device, so it can be further improved by a method for generating a random projection.

[0053] More specifically, the method according to the present invention may further comprise a random generation step in which a random bit sequence is generated by a processing means. In the compression step P3, the random projection algorithm generates a set of random projections, preferably a matrix of the BCCB (Block circulant with circulant blocks) type, based on the random bit sequence. Thereby, in the processing step P4, when the confidential data is encrypted, a compressed fingerprint generated with a new random bit sequence (seed) can be advantageously used.

[0054] The random bit sequence is preferably stored in the memory means 12, 13 so that it can be reused later if necessary to decrypt the confidential data. For this purpose, the method according to the invention may further comprise a random sequence reading step. The random bit sequence stored in the memory means 12, 13 is read by the processing means 11, and in the compression stage P3, the processing means 11 generates a set of random projections based on the random bit sequence, whereby in the processing stage P4, if the confidential data is decrypted, it is possible to reconstruct the compressed fingerprint previously used (for the encryption of the confidential data).

[0055] In this way, it is possible to improve the security of the authentication system and manage the situation where an attacker somehow illegally generates the fingerprint of the image sensor. In fact, by generating a new random bit sequence and using it for the encryption of a new secret key (and repeating the registration procedure), it is possible to return the authentication system S to a secure state.

[0056] It should be emphasized that the fingerprint calculated in stage P2 and used by the user equipment 1 for registration in the application server 2 is (very likely) different from that used for authentication. In fact, since the sensor fingerprint is actually a measurement of the characteristics of the sensor, it is difficult for two separate fingerprints determined at different times to be the same, and since they are affected by noise as occurs with any other measurement, it should also be emphasized that in fact, the fingerprint generated in stage P2 depends on the amount of light reaching the image sensor 14 when the image is captured in the image acquisition stage P1.

[0057] To avoid this noise from degrading the operation of the authentication system S (due to obvious security issues), the processing means 11 may be configured to execute a set of instructions implementing a polar encoding / decoding algorithm (such as those described in, for example, "Achieving the secrecy capacity of wiretap channels using polar codes" by Mahdavifar et al., IEEE Transactions on Information Theory, vol. 57, no. 10, pp. 6428 - 6443, Oct 2011) in processing stage P4.

[0058] Specifically, when it is necessary to encrypt the confidential data in processing stage P4, the column of confidential data is encoded by the processing means 11 using polar encoding to obtain a column of encoded confidential data. The encoded confidential data is encrypted using the compressed fingerprint W as the key. On the other hand, in processing stage P4, when it is necessary to decrypt the confidential data, the confidential data is decrypted to obtain the encoded confidential data. The encoded confidential data is decoded using polar encoding.

[0059] Polar encoding / decoding exists between the pre - encryption version of the confidential data and the post - decryption version of the confidential data, and can correct errors (errors) resulting from errors that may exist between the compressed sensor fingerprint used for encrypting the confidential data and the compressed sensor fingerprint used for decrypting the confidential data within a testable probability range. This makes it substantially impossible to authenticate other user devices having different image sensors or to use generally available images captured by the same sensor and compressed by an information - loss method (irreversible) such as JPEG or other formats, while it is possible to authenticate user device 1 with a probability exceeding 80% using a small number of images (even just one). Thus, it is possible to improve the security of the authentication system S.

[0060] In stage P2, the (registration and authentication) sensor fingerprint is extracted by executing an instruction set that implements a regression algorithm. More specifically, the sensor output is preferably modeled as follows.

Number

[0061] Here, g γ is gamma correction (g varies for each color channel and γ is typically close to 0.45), which models the noise sources within the sensor, and q models the noise outside the sensor (e.g., quantization noise). k models the sensor fingerprint (a matrix of the dimensions of the image generated by image sensor 14) that is desired to be extracted, and i is the intensity of the light hitting the sensor. To extract k, Equation (1) may be approximated to the first term of the Taylor expansion.

Number

[0062] Here, o id =(gi) γ is the ideal output of the image sensor, and o id ·k is the pixel response non-uniformity (PRNU) of the image sensor that desires to extract the fingerprint k,

Number

[0063] It is possible to generate a noise-free version o dn by an appropriate filtering process, and assuming that such a noise-free version is available instead of the ideal output o id it can be described as. Here, q collects all the model errors.

Number

[0064] The number C≧1 of images is available,

Number

Number

Number

Number

Number

Number

[0065] From this, it is possible to say that the image from which the sensor fingerprint can be extracted best is an image with high brightness (but not saturated) and (in order to reduce

Number

Number

Number

[0066] When the image captured by the image sensor 14 is in color, the estimation must be performed separately for each color channel (red, green, blue). That is, the maximum likelihood estimate is for each channel, that is, for the red channel

Number

Number

Number

Number

[0067] However, those skilled in the art can use a regression algorithm different from those just described, provided that they do not depart from the teachings of the present invention.

[0068] In order to further improve the quality of the sensor fingerprint extracted in the fingerprint calculation stage P2, each of the images captured by the image sensor 14 may be filtered by a Wiener filter configured to remove all periodic artifacts before the sensor fingerprint is extracted (calculated). In other words, the processing means and control means of the user device 1 may execute a set of instructions to remove all periodic artifacts from the image by applying a Wiener filtering algorithm to the image captured in the image acquisition stage P1 at the start of the fingerprint calculation stage P2, before the authentication sensor fingerprint is generated. In this way, the ability of the system S to distinguish between two fingerprints obtained from two separate image sensors is improved, thereby improving the security level of the authentication system S.

[0069] In combination with or instead of the above-described matters, it is also possible to perform a selection of a portion of the fingerprint having a (horizontal and / or vertical) spatial frequency higher than a threshold value in the compression stage P3 (calculated in the fingerprint calculation stage P2).

[0070] Specifically, in the compression stage P3, the processing means and control means of the user device 1 perform the following steps - obtaining a transformed fingerprint by transforming the fingerprint calculated in the transformation region in stage P2, for example, by executing a set of instructions implementing a transformation algorithm such as a discrete cosine transform (DCT) or a 2D fast Fourier transform (2D FFT); - selecting points of the transformed fingerprint having a horizontal and / or vertical spatial frequency higher than a predetermined threshold value; - inverse-transforming the selected points of the transformed fingerprint, for example, by executing a set of instructions implementing an inverse transformation algorithm such as an inverse discrete cosine transform (DCT) or a 2D inverse fast Fourier transform (2D IFFT). configured to perform.

[0071] By doing so, a (registered and authenticated) sensor fingerprint containing only "high" frequency components is obtained. This is particularly advantageous when these frequency components are higher than the maximum frequency contained in a compressed image using a compression format (such as JPEG, etc.) that is widely used and often used to publish self-generated content on the Internet. Thus, since the frequency components of the fingerprint used by the system S to authenticate the user device 1 do not exist in the compressed image, it is impossible to generate a valid authentication sensor fingerprint starting from a set of images that are publicly available on the Internet (and also recognize the seeds used by the random projection algorithm) and are taken from the same user terminal, thereby improving the security level of the authentication system S.

[0072] In combination with or instead of the above-described matters, the user device 1 may be provided with obstructive means (such as a plug, a sliding flap, etc.). This can prevent the image sensor 14 from being irradiated when operated by the user of the user device 1, that is, it can prevent light from reaching the image sensor 14. Thereby, it becomes possible to prevent the processing means 11 from generating a valid sensor fingerprint (in step P2). In the image acquisition step P1, the absence of light enables the extraction of the fingerprint of the image sensor 14 by preventing the imaging of an image with sufficient entropy.

[0073] Thus, the security of the authentication system S is improved by physically preventing an attacker from being able to generate a valid fingerprint and decrypting confidential data for (remotely) controlling the user device 1.

[0074] In the above-described modification of the present invention, a similar image sensor as in the preferred embodiment includes processing means (such as a CPU, a microcontroller, etc.) configured to execute the steps of the method according to the present invention.

[0075] Thus, embedding the method according to the present invention into an existing user device or a user device project that has already been completed is simplified (for example, by replacing or reprogramming an image sensor), so that the security of the authentication system S is improved.

[0076] Although some possible variations have been described above, it will be apparent to those skilled in the art that in actual embodiments, there are further other embodiments having different elements that can be replaced by other technically equivalent elements. Therefore, the present invention is not limited to the exemplary examples described, and various modifications, improvements, and replacements of parts and equivalent elements can be made without departing from the inventive concept defined in the following claims.

Claims

1. A method for protecting confidential data, comprising: an image acquisition stage in which a plurality of images are captured by an image sensor; a fingerprint calculation stage in which a sensor fingerprint is generated by a processing means based on the plurality of images captured in the image acquisition stage; a compression stage in which at least a part of the sensor fingerprint is encoded by the processing means using a random projection algorithm to generate a compressed fingerprint; a processing stage in which the confidential data is encrypted or decrypted by the processing means using the compressed fingerprint as a key; comprising; the confidential data includes a secret key; in the processing stage, a column of confidential data is encoded by the processing means using a first polar coding to obtain a column of encoded confidential data, and the encoded confidential data is encrypted using the compressed fingerprint as a key, or obtaining the encoded confidential data by encrypting the confidential data when the confidential data is decrypted, and the encoded confidential data is decoded using a second polar coding; Method.

2. In the processing stage, when the confidential data is encrypted, the method further comprises: a random generation stage in which a random bit sequence is generated by the processing means; in the compression stage, the random projection algorithm generates a set of random projections based on the random bit sequence; The method according to claim 1.

3. In the processing stage, when the confidential data is decrypted, the method further comprises: a random sequence reading stage in which a random bit sequence stored in a memory means is read by the processing means; in the compression stage, the processing means generates a set of random projections based on the random bit sequence; The method according to claim 1 or 2.

4. In the compression stage, at least a part of the sensor fingerprint is encoded by using a random projection algorithm to generate an encoded sensor fingerprint, and the encoded sensor fingerprint is quantized by the processing means to generate the compressed fingerprint; The method according to any one of claims 1 to 3.

5. In the compression stage, the processing means obtains a transformed fingerprint by transforming the sensor fingerprint generated within the transformation region in the fingerprint calculation stage; selects points of the transformed fingerprint having a horizontal and / or vertical spatial frequency higher than a threshold value; inverse-transforms the selected points of the transformed fingerprint; The method according to any one of claims 1 to 4, which executes

6. In the fingerprint calculation stage, before the sensor fingerprint is generated, an instruction set for removing all periodic artifacts from the plurality of images by applying a Wiener filtering algorithm to each image captured in the image acquisition stage is executed. The method according to any one of claims 1 to 5.

7. A user device for protecting confidential data, comprising: an image sensor configured to capture an image; processing means for communicating with the image sensor; The processing means captures a plurality of images by the image sensor, generates a sensor fingerprint based on the plurality of images, generates a compressed fingerprint by encoding at least a part of the sensor fingerprint using a random projection algorithm, obtains a column of encoded confidential data by encoding the confidential data using a first polar encoding with the compressed fingerprint as a key, and encrypts the column of the confidential data by encrypting the encoded confidential data with the compressed fingerprint as a key, or obtains the encoded confidential data by decrypting the confidential data with the compressed fingerprint as a key, and decrypts the encrypted confidential data using a second polar encoding; is configured as The user device, wherein the confidential data includes a secret key.

8. The user device according to claim 7, further comprising interference means configured to prevent the image sensor from being irradiated.

9. An image sensor of a user device, comprising processing means configured to execute the steps of the method according to any one of claims 1 to 6.

10. ​ A program for causing a computer to execute the steps of the method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Safety coding method based on limited-length polarization codes in Gaussian wiretap channel

    CN109194421A

  • Electronic signature system

    JP2005123883A

  • Challenge response authentication method using public key infrastructure

    JP2008167107A

  • Biometric authentication device and biometric authentication method

    JP2014071882A

  • Device and methods for authenticating a user equipment

    WO2018073681A1