Information processing apparatus, verification method, and program

The biometric authentication system addresses the challenges of information leakage and forgery by dividing registration information and distributing similarity calculations between a client and server, resulting in enhanced security and reduced computational costs.

JP7697547B2Active Publication Date: 2025-06-24NEC CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024007191
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2024-01-22
Publication Date
2025-06-24
Estimated Expiration
2040-05-29

AI Technical Summary

Technical Problem

Existing biometric authentication systems face challenges in preventing leakage and forgery of registration information, especially when templates are stored on clients, and in reducing the calculation cost for collating registration information.

Method used

A collation system that includes a client terminal and a server device, where the client terminal divides registration information into first and second information, performs an initial similarity calculation, and transmits the result to the server. The server then performs a secondary similarity calculation using the second information and transmits the result back to the client for a final similarity calculation.

Benefits of technology

This approach effectively prevents information leakage and forgery while reducing the computational cost by distributing the similarity calculation across both the client and server, thus enhancing security and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007697547000008
    Figure 0007697547000008
  • Figure 0007697547000009
    Figure 0007697547000009
  • Figure 0007697547000010
    Figure 0007697547000010
Patent Text Reader

Abstract

To provide an information processing device, a verification method, and a program that prevent leaks of registered information and spoofing, and reduce the cost of calculation to verify the verification information of an authenticated person against the registered information of registrants.SOLUTION: In a verification system 10, a client divides registered information into first information and second information and provides the second information to a server, executes a first step of calculating similarity between registered information and verification information on the basis of the verification information inputted for verification against the registered information and the first information, and transmits the calculation result of the first step to the server. The server executes a second step of similarity calculation on the basis of the calculation result of the first step received from the client and the second information, and transmits the calculation result of the second step to the client. The client executes a third step of similarity calculation on the basis of the calculation result of the second step received from the server and the first information, and calculates similarity between the registered information and the verification information.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to an information processing apparatus, a collation method, and a program.

Background Art

[0002] As an example of authentication, there is biometric authentication. "Biometric authentication" is a personal authentication method for confirming whether a registrant and an authenticator match by collating biometric information of the registrant with biometric information of the authenticator.

[0003] Also, "biometric information" is data extracted from some characteristics of an individual related to the body or behavior, or data generated by converting the extracted data. This data is sometimes referred to as a feature amount.

[0004] Also, a "template" is data that is pre-stored for biometric authentication and includes data generated from biometric information of a registrant (hereinafter referred to as registration information).

[0005] When performing biometric authentication in a client-server system, there are a mode of storing a template in a client terminal and a mode of storing a template in a server device. Hereinafter, a client terminal is also referred to as a client or a terminal. Also, a server device is also simply referred to as a server.

[0006] As an example of a mode of saving a template in a client, FIDO (Fast IDentity Online) can be cited. In FIDO, a template is saved in the client in advance. Then, when biometric information of the user (the person to be authenticated) currently using the client is input into the client, the client determines whether the person to be authenticated corresponds to the person to be registered based on the input biometric information and the template. And when the client determines that the person to be authenticated corresponds to the person to be registered, the server determines whether the signature key (private key) that the client has and the verification key (public key) that the server has are paired keys based on the signature generated by the client with the signature key. That is, in FIDO, when biometric authentication is successful in the client and verification of the client's signature is successful in the server, finally, it is determined that the authentication of the user (the person to be authenticated) has been successful.

[0007] Also, in FIDO, data including information obtained by encrypting biometric information of the person to be registered is saved in the client in advance as a template. And a key for decrypting the encrypted information is also saved in the client. When biometric information of the person to be authenticated is input into the client, the client decrypts the ciphertext of the biometric information included in the template using the key, and determines whether the person to be authenticated corresponds to the person to be registered using the decrypted biometric information and the input biometric information.

[0008] Also, there may be a case where encrypted biometric information is saved in the IC (Integrated Circuit) chip of a cash card.

[0009] Here, in the "Act on the Protection of Personal Information" (hereinafter referred to as the Personal Information Protection Act) in Japan, the objects protected as personal information will be explained. In the Japanese Personal Information Protection Act, biometric information, which is information capable of identifying an individual, is defined as personal information. Furthermore, in the Personal Information Protection Act, personal information managed in an electronic database or a paper database is defined as an object of protection by the Personal Information Protection Act.

[0010] In the mode of saving the template on the server, it can be said that the templates of individual users who use individual clients are saved as a database in a common server. Therefore, the templates saved on the server are subject to protection by the Personal Information Protection Law.

[0011] The administrator of the server is required to protect the server so that the templates do not leak. That is, the security cost is incurred as much as the server is protected.

[0012] On the other hand, in the mode of saving the template on the client, the client saves the templates of one or a small number of users who use the client. Therefore, it cannot be said that the templates are saved as a database. Therefore, the templates saved on the client may not be subject to protection by the Personal Information Protection Law.

[0013] Patent Documents 1 to 3 disclose that in a biometric authentication system, a homomorphic encryption that enables operations while biometric information and the like are encrypted is used.

Prior Art Documents

Patent Documents

[0014]

Patent Document 1

Patent Document 2

Patent Document 3

Summary of the Invention

Problems to be Solved by the Invention

[0015] Even when saving the template to the client, it is preferable to prevent leakage of the user's registration information from the client. Further, prevention of forgery by a third party and reduction of the calculation cost for collating the registration information of the person to be registered and the collation information of the person to be authenticated are required.

[0016] Therefore, an object of the present invention is to provide an information processing apparatus, a collation method, and a program capable of preventing leakage and forgery of registration information and reducing the calculation cost for collating the registration information of the person to be registered and the collation information of the person to be authenticated.

Means for Solving the Problems

[0017] A collation system according to an aspect of the present invention includes a client terminal and a server device. In the client terminal, a secret sharing processing unit that divides registration information into first information and second information and provides the second information to the server device, and in the client terminal, a first similarity calculation unit that executes a first step of calculating the similarity between the registration information and the collation information based on the collation information input for collation with the registration information and the first information, a first transmission unit that transmits the calculation result of the first step to the server device in the client terminal, a second similarity calculation unit that executes a second step of calculating the similarity in the server device based on the calculation result of the first step received from the client terminal and the second information, a second transmission unit that transmits the calculation result of the second step to the client terminal in the server device, and a third similarity calculation unit that executes a third step of calculating the similarity and calculates the similarity between the registration information and the collation information based on the calculation result of the second step received from the server device and the first information in the client terminal.

[0018] A client terminal according to an aspect of the present invention includes a secret sharing processing unit that divides registration information into first information and second information, stores the first information, and provides the second information to a server device; a first similarity calculation unit that executes a first step of calculating a similarity between the registration information and collation information input for collation with the registration information, based on the collation information and the first information; a transmission unit that transmits the calculation result of the first step to the server device; and a third similarity calculation unit that executes a third step of the similarity calculation, based on the calculation result of the first step received from the server device, the calculation result of the second step of the similarity calculation based on the second information among the first information and the second information divided from the registration information, and the first information, and calculates the similarity between the registration information and the collation information.

[0019] A server device according to an aspect of the present invention includes a second similarity calculation unit that receives, from a client terminal, a calculation result of a first step of calculating a similarity between first information divided from registration information and collation information input for collation with the registration information, and executes a second step of the similarity calculation, based on the calculation result of the first step and the second information among the first information and the second information divided from the registration information; and a transmission unit that transmits the calculation result of the second step to the client terminal for the client terminal to execute a third step of the similarity calculation based on the calculation result of the second step and the first information.

[0020] The verification method according to one aspect of the present invention is a verification method in a verification system including a client terminal and a server device. The client terminal divides registration information into first information and second information, provides the second information to the server device, and based on the verification information input for verification with the registration information and the first information, the client terminal executes a first step of calculating the similarity between the registration information and the verification information. The client terminal transmits the calculation result of the first step to the server device. The server device executes a second step of calculating the similarity based on the calculation result of the first step received from the client terminal and the second information. The server device transmits the calculation result of the second step to the client terminal. The client terminal executes a third step of calculating the similarity based on the calculation result of the second step received from the server device and the first information, and calculates the similarity between the registration information and the verification information.

[0021] A program for a client terminal according to one aspect of the present invention causes a computer to execute a secret sharing process of dividing registration information into first information and second information, storing the first information, and providing the second information to a server device, a first similarity calculation process of executing a first step of calculating the similarity between the registration information and the verification information based on the verification information input for verification with the registration information and the first information, a transmission process of transmitting the calculation result of the first step to the server device, a third similarity calculation process of executing a third step of calculating the similarity based on the calculation result of the first step received from the server device and the second information and the first information, and calculating the similarity between the registration information and the verification information.

[0022] A program for a server device according to an aspect of the present invention receives, from a client terminal, a calculation result of a first step of calculating a similarity between first information divided from registration information and collation information input for collation with the registration information, and based on the calculation result of the first step and the second information among the first information and the second information divided from the registration information, executes a second similarity calculation process for executing the second step of the similarity calculation, and transmits the calculation result of the second step to the client terminal for the client terminal to execute the third step of the similarity calculation based on the calculation result of the second step and the first information. The computer is caused to execute the transmission process.

Effect of the Invention

[0023] According to the present invention, it is possible to prevent leakage and forgery of registration information and reduce the calculation cost for collating the registration information of the person to be registered and the collation information of the person to be authenticated.

Brief Description of the Drawings

[0024]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Embodiments for Carrying Out the Invention

[0025] Hereinafter, each embodiment of the present invention will be described with reference to the drawings. In the present specification and the drawings, for elements that can be similarly described, duplicate description may be omitted by assigning the same reference numerals. Further, in the following description, the case where the collation system of the present invention is applied to biometric authentication will be described as an example. However, the collation system of the present invention may be applied to authentication other than biometric authentication. Also, the client 100 and the client 800 described later are client terminals, and the server 200 and the server 900 described later are server devices.

[0026] The description will be made in the following order. 1. First Embodiment 1.1. System Configuration 1.2. Registration Phase 1.3. Authentication Phase 1.4. Specific Example 1 1.5. Specific Example 2 1.6. Hardware Configuration 1.7. Explanation of Effects 2. Second Embodiment 2.1. System Configuration 2.2. Registration Phase 2.3. Authentication Phase 2.4. Explanation of Effects 3. Other Embodiments 4. Supplementary Note

[0027] <<1. First Embodiment>> <1.1. System Configuration> FIG. 1 is a block diagram showing a configuration example of the collation system according to the first embodiment. The collation system 10 shown in FIG. 1 includes a client 100 and a server 200. In FIG. 1, one client 100 is shown, but there may be a plurality of clients 100. The client 100 and the server 200 can communicate via a communication network.

[0028] In the matching system 10 of this embodiment, a challenge-response method is introduced to prevent impersonation. Specifically, the server 200 sends a different challenge to the client 100 each time for authentication, and the client 100 calculates a response corresponding to the challenge, so that the value of the response is changed for each authentication.

[0029] Even if an attacker eavesdrops on the value of the response, the eavesdropped response value is no longer usable in the next authentication, and the attacker cannot generate a response corresponding to another challenge, so impersonation such as a replay attack is prevented. Hereinafter, each component of the matching system 10 of this embodiment will be described.

[0030] As shown in FIG. 1, the client 100 includes a registration information input unit 110, a distributed processing unit 120, a storage unit 130, a random number generation unit 140, a matching information input unit 150, a commitment generation unit 160, a commitment transmission unit 165, a response generation unit 170, a response transmission unit 175, and an output unit 180.

[0031] The registration information input unit 110 receives the input of registration information. In this embodiment, biometric information of the person to be registered is input to the registration information input unit 110 as the registration information.

[0032] In this embodiment, a case will be described as an example where the registration information and the matching information (information input for matching with the registration information) described later are represented as vectors in a common dimension as features.

[0033] The registration information input unit 110 may be any input device according to the registration information. For example, when biometric information extracted from a fingerprint is used as the registration information, the registration information input unit 110 may be an input device that reads the fingerprint, extracts a vector serving as the registration information from the fingerprint, and receives the vector as an input. Further, the registration information input unit 110 may be an input device to which the vector serving as the registration information is directly input.

[0034] In addition, in the present embodiment, the biological information may be extracted from an iris, a retina, a face, blood vessels (veins), a palm print, a voice print, or a combination thereof, in addition to fingerprints. The biological information may be extracted from other information that can identify a living body, other than the examples described above.

[0035] Let the vector corresponding to the biometric information (registration information) of the registrant input to the registration information input unit 110 be denoted as x.

[0036] The dispersion processing unit 120 secretly disperses the biometric information x of the registrant input to the registration information input unit 110. For secret dispersion, for example, 2-out-of-2 linear secret dispersion may be used. Specifically, the dispersion processing unit 120 divides the biometric information x and inputs a part of the information (that is, the first information) as a template into the storage unit 130. In addition, the dispersion processing unit 120 provides another part of the information (that is, the second information) divided from the biometric information x to the server 200 as a verification key. These pieces of information are encrypted and concealed.

[0037] Let the information input for verification with the registration information be denoted as verification information. The verification information input unit 150 receives the input of the verification information. In the present embodiment, the biometric information of the person to be authenticated is input to the verification information input unit 150 as the verification information. As described above, the registration information and the verification information are represented as vectors in the same dimension as the feature amount.

[0038] The verification information input unit 150 may be any input device according to the verification information. For example, when the biometric information extracted from a fingerprint is used as the verification information, the verification information input unit 150 may be an input device that reads the fingerprint, extracts a vector serving as the verification information from the fingerprint, and receives the vector as an input. In addition, the verification information input unit 150 may be an input device to which a vector serving as the verification information is directly input. Further, the registration information input unit 110 and the verification information input unit 150 may be a common input device.

[0039] Let the vector corresponding to the biometric information (verification information) of the person to be authenticated input to the verification information input unit 150 be denoted as y.

[0040] The random number generation unit 140 generates a random number R. The random number generation unit 140 inputs the generated random number R into the storage unit 130.

[0041] The commitment generation unit 160 generates a commitment using the random number R stored in the storage unit 130, a part of the template, and the biometric information y of the person to be authenticated. The commitment transmission unit 165 executes a transmission process for transmitting the generated commitment to the server 200.

[0042] The response generation unit 170 generates a response using the challenge received from the server 200, another part of the template, and the biometric information y of the person to be authenticated. Among the information used for response generation, the encrypted information can be used without being decrypted by the response generation unit 170. The response transmission unit 175 executes a transmission process for transmitting the generated response to the server 200.

[0043] The output unit 180 receives the determination result for the response from the server 200 and outputs the determination result. The determination result indicates an authentication result as to whether or not the person to be registered and the person to be authenticated match.

[0044] The dispersion processing unit 120, the commitment generation unit 160, the commitment transmission unit 165, the response generation unit 170, the response transmission unit 175, and the output unit 180 are realized by, for example, the CPU (Central Processing Unit) of a computer that operates according to a program for a client terminal, and the communication interface of that computer. For example, the CPU reads a program for a client terminal from a program recording medium such as a program storage device of the computer, and according to that program, using the communication interface, it may operate as the dispersion processing unit 120, the random number generation unit 140, the commitment generation unit 160, the commitment transmission unit 165, the response generation unit 170, the response transmission unit 175, and the output unit 180. Also, the random number generation unit 140 is realized by, for example, the CPU of a computer that operates according to a program for a client terminal. For example, the CPU reads a program for a client terminal from the program recording medium as described above, and according to that program, it may operate as the random number generation unit 140.

[0045] The storage unit 130 is realized by, for example, a storage device provided in a computer.

[0046] Also, as shown in FIG. 1, the server 200 includes a storage unit 210, a random number generation unit 220, a challenge generation unit 230, a challenge transmission unit 235, and a determination unit 240.

[0047] The storage unit 210 receives a part of the biometric information x of the registrant received from the client 100, and stores a part of the received biometric information x as a verification key. Also, the storage unit 210 can store the random number r1 and the range information used in the determination process, which will be described later.

[0048] The random number generation unit 220 generates a random number r1. The random number generation unit 220 inputs the generated random number r1 to the storage unit 210. The random number r1 is used for generating a challenge to be transmitted to the client 100, as will be described later.

[0049] The challenge generation unit 230 generates a challenge using the commitment received from the client 100 and a part of the biometric information x stored in the storage unit 210 as a verification key. The challenge transmission unit 235 executes a transmission process of transmitting the generated challenge to the client 100.

[0050] The determination unit 240 determines whether the value of the response received from the client 100 is within a predetermined range. The range information regarding the value of the response may be acquired from the storage unit 210.

[0051] Specifically, the determination unit 240 determines whether the collation information and the registration information correspond by determining whether the value of the response is within a predetermined range. That is, the determination unit 240 determines whether the person to be registered and the person to be authenticated match.

[0052] If the value of the response is within the predetermined range, the determination unit 240 determines that the collation information and the registration information correspond. That is, it is determined that the person to be registered and the person to be authenticated match (authentication success). Also, if the value of the response is not within the predetermined range, the determination unit 240 determines that the collation information and the registration information do not correspond. That is, it is determined that the person to be registered and the person to be authenticated do not match (authentication failure). The determination unit 240 transmits information indicating the determination result to the client 100.

[0053] When the person to be registered and the person to be authenticated match, the post-authentication process may be executed as if the authentication was successful. For example, as an example, the server 200 transmits the determination result of the determination unit 240 to the client 100, and when the client 100 receives the determination result that the person to be registered and the person to be authenticated match, the client 100 may execute the post-authentication process as if the authentication was successful. However, the device that executes the post-authentication process is not limited to the client 100, and a device other than the client 100 may execute the post-authentication process on the condition that the determination result that the person to be registered and the person to be authenticated match is obtained.

[0054] The challenge generation unit 230, the challenge transmission unit 235, and the determination unit 240 are realized by, for example, a CPU of a computer that operates according to a program for a server device and a communication interface of the computer. For example, the CPU may read a program for a server device from a program recording medium such as a program storage device of the computer and operate as the challenge generation unit 230, the challenge transmission unit 235, and the determination unit 240 using the communication interface according to the program. Further, the random number generation unit 220 is realized by, for example, a CPU of a computer that operates according to a program for a server device. For example, the CPU may read a program for a server device from the program recording medium as described above and operate as the random number generation unit 220 according to the program.

[0055] The storage unit 210 is realized by, for example, a storage device included in a computer.

[0056] Next, the processing flow in the registration phase of the biometric information x and the processing flow in the authentication phase of the biometric information y in the matching method of the present embodiment will be described.

[0057] <1.2. Registration Phase> FIG. 2 is a flowchart showing an example of the processing flow in the registration process according to the first embodiment. In such a registration process, the input biometric information is secretly shared into a template and a verification key, the template is stored in the client 100, and the verification key is stored in the server. Note that detailed descriptions of matters already described will be omitted.

[0058] First, in step S201, the registration information input unit 110 of the client 100 receives an input of the biometric information x = (x[1], x[2], ···, x[n]) of the person to be registered.

[0059] Next, in step S202, the distributed processing unit 120 performs secret distribution of the input biological information x. A part of the information (i.e., the first information) divided from the biological information x is used as a template, and another part of the information (i.e., the second information) divided from the biological information x is used as a verification key. Specifically, as will be described later in the following specific example 1, the i-th (where i = 1, ···, n) element x[i] of the biological information x is divided so as to satisfy x[i]=x1[i]+x2[i]·x3[i]. {(x1[i], x2[i])} is used as a template, and {x3[i]} is used as a verification key. The distributed processing unit 120 provides the verification key {x3[i]} to the server 200.

[0060] Next, in step S203, the storage unit 130 of the client 100 stores the template {(x1[i], x2[i])}. Also, in step S204, the storage unit 210 of the server 200 stores the verification key {x3[i]} provided from the client.

[0061] Note that the above-described registration process may be repeatedly executed.

[0062] As described above, the biological information x is distributed and registered between the client 100 and the server 200. Therefore, even if a part of the registration information leaks from either the client 100 or the server 200, it does not become information that can identify an individual by itself, so personal information is protected.

[0063] <1.3. Authentication Phase> FIG. 3 is a flowchart showing an example of the flow of the authentication process in the first embodiment. In such an authentication process, authentication of the person to be authenticated is performed using two-party secure computation between the client 100 and the server 200. For matters already described, detailed descriptions are omitted.

[0064] First, in step S301, the collation information input unit 150 of the client 100 receives an input of the biological information y of the person to be authenticated.

[0065] Next, in step S302, the commitment generation unit 160 generates a commitment using the biological information y and a part (x2[i]) of the template stored in the storage unit 210. The commitment transmission unit 165 transmits the generated commitment to the server 200.

[0066] Next, in step S303, the challenge generation unit 230 of the server 200 generates a challenge using the commitment received from the client 100 and the verification key {x3[i]} stored in the storage unit 210. The challenge transmission unit 235 transmits the generated challenge to the client 100.

[0067] Next, in step S304, the response generation unit 170 of the client 100 generates a response using the biological information y, a part (x1[i]) of the template, and the challenge received from the server 200. The response transmission unit 175 transmits the generated response to the server 200.

[0068] Next, in step S305, the determination unit 240 of the server 200 determines whether the value of the response received from the client 100 is within a predetermined range. If the value of the response is within the predetermined range, an authentication result indicating "authentication successful" is generated assuming that the registrant and the authenticated person match. On the other hand, if the value of the response is not within the predetermined range, an authentication result indicating "authentication failed" is generated assuming that the registrant and the authenticated person do not match. The determination unit 240 transmits the generated authentication result to the client 100.

[0069] In step S306, the output unit 180 of the client 100 outputs the determination result received from the server 200.

[0070] Note that the authentication result may be directly output from the server 200. Also, the above-described authentication process may be repeatedly executed.

[0071] As described above, the authentication process of the biometric information y of the person to be authenticated is performed between the client 100 and the server 200 based on the challenge-response method. Note that the calculation of the similarity between the biometric information x of the person to be registered and the biometric information y of the person to be authenticated, which is performed in the challenge-response method, is carried out using secret calculation utilizing homomorphic encryption. The calculation of the similarity will be described in the following specific examples.

[0072] Hereinafter, specific examples of the present embodiment will be described. In the following description, it is assumed that the biometric information x of the person to be registered and the biometric information y of the person to be authenticated are common n-dimensional vectors. Also, the similarity between the biometric information x and the biometric information y is calculated by the inner product of the biometric information x and the biometric information y.

[0073] <1.4. Specific Example 1> FIG. 4 is an explanatory diagram showing a specific example of the registration process in the present embodiment.

[0074] First, for each i = 1, ···, n, the distributed processing unit 120 of the client 100 obtains x1[i], x2[i], and x3[i] that satisfy x[i]=x1[i]+x2[i]·x3[i] for the i-th element x[i] of the input biometric information x of the person to be registered.

[0075] Next, the distributed processing unit 120 stores {(x1[i], x2[i])} in the storage unit 130 as a template and provides {x3[i]} to the server 200 as a verification key.

[0076] FIG. 5 is an explanatory diagram showing a specific example of the authentication process in the present embodiment.

[0077] First, the random number generation unit 140 of the client 100 randomly selects a random number R∈Ζp. Z represents the set of all integers.

[0078] Next, the commitment generation unit 160 generates a commitment com = {R·x2[i]·y[i]}. The commitment transmission unit 165 transmits the generated commitment com to the server 200.

[0079] Next, the challenge generation unit 230 of the server 200 calculates the value sum = Σcom[i]·x3[i]. Also, the random number generation unit 220 randomly selects a random number r1 ∈ Zp. Next, the challenge generation unit 230 generates challenges chal1 and chal2 represented by the following formula (1).

[0080]

Number

[0081] As shown in formula (1), the group operation is performed in a form independent of the dimension number of the vector.

[0082] The challenge transmission unit 235 transmits the generated challenge to the client 100. Note that the above value sum is encrypted with the homomorphic encryption.

[0083] Next, the response generation unit 170 of the client 100 calculates the value sum1 = Σx1[i]·y[i]. Further, the response generation unit 170 uses the calculated value sum1 to generate responses resp1 and resp2 represented by the following formula (2).

[0084]

Number

[0085] As shown in formula (2), the group operation is performed in a form independent of the dimension number of the vector.

[0086] The response transmission unit 175 transmits the generated response to the server 200. Note that the responses resp1 and resp2 are ciphertexts of the inner product.

[0087] Next, the determination unit 240 of the server 200 determines whether the value represented by the following (3) is included in a predetermined range Dec range according to the response.

[0088] [Mathematics]

[0089] If it is included in the specified range Dec range, it is determined that the registered person and the authenticated person correspond. On the other hand, if it is not included in the specified range Dec range, it is determined that the registered person and the authenticated person do not correspond. The determination unit 240 transmits the determination result to the client 100.

[0090] Note that the inner product x·y for calculating the similarity between the biometric information x and the biometric information y can be calculated by the following formula (4).

[0091] [Mathematics]

[0092] In formula (4), x1·y is calculated by the client 100. Therefore, the information about x1 is not provided to the server 200. Also, x2x3·y is calculated using secure multi-party computation between the client 100 and the server 200. Since x2 and x3 are multiplicative secret shares of x2·x3, at the server 200, the calculation result of x2·y can be multiplied by x3 using secure multi-party computation.

[0093] To add x1·y while keeping the calculation result of x2x3·y secret, homomorphic encryption is used. Therefore, since the number of encryption operations does not depend on the dimension of the vector, the number of group operations in the authentication process also does not depend on the dimension. Thus, an increase in the number of group operations due to an increase in the dimension of the vector can be suppressed, and the computational cost can be reduced.

[0094] <1.5. Specific Example 2> Next, a specific example different from the above specific example 1 will be described. In this specific example 2, in the authentication process, the point of dividing the biometric information y of the person to be authenticated is different from that in the above specific example 1. Also, the processes related to commitment, challenge, and response are each performed on the divided part of the biometric information y. Since the registration process is the same as that in the above specific example 1, the description thereof will be omitted.

[0095] FIG. 6 is an explanatory diagram showing another specific example of the authentication process in the present embodiment.

[0096] First, for each i = 1, ···, n, the matching information input unit 150 of the client 100 obtains y1[i] and y2[i] that satisfy y[i] = y1[i] + y2[i] for the i-th element y[i] of the input biometric information y of the person to be authenticated.

[0097] Next, the random number generation unit 140 randomly selects two random numbers R1, R2 ∈ Ζp.

[0098] Next, the commitment generation unit 160 generates a commitment com1 = {R1·x2[i]·y1[i]} for y1[i] and a commitment com2 = {R2·x2[i]·y2[i]} for y2[i]. The commitment transmission unit 165 transmits the generated commitments com1, com2 to the server 200.

[0099] Next, the challenge generation unit 230 of the server 200 calculates values sum1 = Σcom1·x3[i] and sum2 = Σcom2·x3[i] for each of the two commitments. Also, the random number generation unit 220 randomly selects a random number r1 ∈ Zp. Next, the challenge generation unit 230 generates challenges (c11, c12), (c21, c22) represented by the following formula (5).

[0100]

Equation

[0101] As shown in Equation (5), the group operation is performed in a form independent of the dimension number of the vector.

[0102] The challenge transmission unit 235 transmits the generated challenge to the client 100.

[0103] Next, the response generation unit 170 of the client 100 calculates the value sum = Σx1[i]·y[i]. Further, the response generation unit 170 uses the calculated value sum to generate a response (resp1, resp2) represented by the following Equation (6).

[0104]

Equation

[0105] As shown in Equation (6), the group operation is performed in a form independent of the dimension number of the vector.

[0106] The response transmission unit 175 transmits the generated response to the server 200.

[0107] Next, the determination unit 240 of the server 200 determines whether the value represented by the following (7) is included in a predetermined range Dec range according to the response.

[0108]

Equation

[0109] If it is included in the predetermined range Dec range, it is determined that the registrant and the authenticated person correspond. On the other hand, if it is not included in the predetermined range Dec range, it is determined that the registrant and the authenticated person do not correspond. The determination unit 240 transmits the determination result to the client 100.

[0110] Thus, in this embodiment, the collation information y may be divided to perform the authentication process.

[0111] <1.6. Hardware Configuration> FIG. 7 is a schematic block diagram showing an example of the hardware configuration of a computer related to the client and server of the present embodiment. Note that the computer used as the client and the computer used as the server are separate computers.

[0112] The computer 700 includes a CPU 701, a main memory device 702, an auxiliary storage device 703, an interface 704, and a communication interface 705.

[0113] The client and server of the present embodiment are realized by the computer 700. However, as described above, the computer used as the client and the computer used as the server are separate computers.

[0114] The operation of the computer 700 that realizes the client is stored in the auxiliary storage device 703 in the form of a program for the client terminal. The CPU 701 reads out the program for the client terminal from the auxiliary storage device 703 and expands it in the main memory device 702, and executes the operation of the client described in the present embodiment according to the program for the client terminal.

[0115] The operation of the computer 700 that realizes the server is stored in the auxiliary storage device 703 in the form of a program for the server device. The CPU 701 reads out the program for the server device from the auxiliary storage device 703 and expands it in the main memory device 702, and executes the operation of the server described in the present embodiment according to the program for the server device.

[0116] The auxiliary storage device 703 is an example of a non-transitory tangible medium. Other examples of non-transitory tangible media include magnetic disks, magneto-optical disks, CD-ROMs (Compact Disk Read Only Memories), DVD-ROMs (Digital Versatile Disk Read Only Memories), semiconductor memories, etc. connected via the interface 704. Also, when a program is distributed to the computer 700 via a communication line, the receiving computer 700 may expand the program in the main storage device 702 and operate according to the program.

[0117] Also, some or all of the components of the client may be implemented by general-purpose or dedicated circuitry, processors, etc., or combinations thereof. These may be constituted by a single chip or by a plurality of chips connected via a bus. Some or all of each component may be implemented by a combination of the circuitry, etc. described above and a program. The same applies to the server. <1.7. Explanation of Effects>

[0118] According to this embodiment, since the biometric information x of the registrant is secretly shared between the client 100 and the server 200, information leakage in a state where an individual can be identified can be prevented.

[0119] Also, since the verification system 10 of this embodiment performs authentication in a challenge-response manner, the response value is changed for each authentication. That is, even if an attacker eavesdrops on the response value, the eavesdropped value can no longer be used in the next authentication, so impersonation can be prevented.

[0120] In addition, the similarity calculation between the biometric information x of the registrant and the biometric information y of the authenticator is performed by secret calculation using homomorphic encryption, and the number of encryptions is performed so as not to depend on the dimensionality of the vector. Therefore, the number of group operations with a large computational cost also does not depend on the dimensionality, and the computational cost can be reduced. That is, it is possible to shorten the calculation time required for the similarity calculation and speed up the calculation process.

[0121] Note that the predetermined range Dec range may be changed for each user or each client. Further, the predetermined range Dec range may be changed according to external factors or the like. Examples of external factors include the frequency of authentication received by the server, the frequency of suspicious access, the state of the communication network or CPU load, and the like. When the predetermined range Dec range is changed, there is a possibility that the load on the communication network or CPU is reduced.

[0122] Among the processes executed by the collation system 10, a collation system that executes a registration process may be configured. For example, a registration collation system may be configured by a client including a registration information input unit 110, a distributed processing unit 120, and a storage unit 130, and a server including a storage unit 210.

[0123] Similarly, among the processes executed by the collation system 10, a collation system that executes an authentication process may be configured. For example, a client including a random number generation unit 140, a collation information input unit 150, a commitment generation unit 160, a commitment transmission unit 165, a response generation unit 170, a response transmission unit 175, and an output unit 180, and a random number generation unit 220, a challenge generation unit 2230, a challenge transmission unit 235, and a determination unit 240. An authentication collation system may be configured by a server provided with the above.

[0124] <<2. Second Embodiment>> Next, with reference to FIG. 8, a second embodiment of the present invention will be described. The above-described first embodiment is a specific embodiment, but the second embodiment is a more generalized embodiment.

[0125] <2.1. System Configuration> FIG. 8 is a block diagram showing a configuration example of the matching system according to the second embodiment. The matching system 20 of the present embodiment includes a client 800 and a server 900. Although one client 800 is shown, there may be a plurality of clients 800. The client 800 and the server 900 can communicate with each other via a communication network.

[0126] The client 800 includes a distributed processing unit 810, a commitment generation unit 820, a commitment transmission unit 825, a response generation unit 830, and a response transmission unit 835. The server 900 includes a challenge generation unit 910 and a challenge transmission unit 915. Specific operations of each component will be described later.

[0127] Regarding the client 800, the distributed processing unit 810, the commitment generation unit 820, the commitment transmission unit 825, the response generation unit 830, and the response transmission unit 835 are realized, for example, by a CPU (Central Processing Unit) of a computer that operates according to a program for a client terminal, and a communication interface of that computer. For example, the CPU reads a program for a client terminal from a program recording medium such as a program storage device of the computer, and operates as the commitment generation unit 820, the commitment transmission unit 825, the response generation unit 830, and the response transmission unit 835 according to the program, using the communication interface.

[0128] Regarding the server 900, the challenge generation unit 910 and the challenge transmission unit 915 are realized, for example, by a CPU of a computer that operates according to a program for a server device, and a communication interface of that computer. For example, the CPU reads a program for a server device from a program recording medium such as a program storage device of the computer, and operates as the challenge generation unit 230, the challenge transmission unit 235, and the determination unit 240 according to the program, using the communication interface.

[0129] <2.2. Registration Phase> The operation example of the registration phase of the second embodiment will be described.

[0130] The distributed processing unit 810 of the client 800 divides the registration information into first information and second information, and provides the second information to the server 900. That is, the distributed processing unit 810 functions as a secret sharing processing unit.

[0131] <2.3. Authentication Phase> The operation example of the authentication phase of the second embodiment will be described.

[0132] The commitment generation unit 820 of the client 800 executes the first step of calculating the similarity between the registration information and the verification information based on the verification information input for verification with the registration information and the first information. That is, the commitment generation unit 820 functions as a first similarity calculation unit that executes the first similarity calculation process.

[0133] The commitment transmission unit 825 transmits the calculation result of the first step to the server 900. That is, the commitment transmission unit 825 functions as a first transmission unit.

[0134] The challenge generation unit 910 of the server 900 executes the second step of calculating the similarity based on the calculation result of the first step received from the client 800 and the second information. That is, the challenge generation unit 910 functions as a second similarity calculation unit that executes the second similarity calculation process.

[0135] The challenge transmission unit 915 transmits the calculation result of the second step to the client 800. That is, the challenge transmission unit 915 functions as a second transmission unit.

[0136] The response generation unit 830 of the client 800 executes the third step of similarity calculation based on the calculation result of the second step received from the server 900 and the first information, and calculates the similarity between the registration information and the collation information. That is, the response generation unit 830 functions as a third similarity calculation unit that executes the third similarity calculation process.

[0137] - Relationship with the First Embodiment

[0138] As an example, the client 800 and the server 900 of the second embodiment are respectively the client 100 and the server 200 of the first embodiment. In this case, the description of the first embodiment can also be applied to the second embodiment.

[0139] Note that the second embodiment is not limited to this example.

[0140] <2.4. Explanation of Effects> According to the second embodiment, it is possible to prevent leakage and forgery of registration information and reduce the calculation cost for collating the registration information of the person to be registered and the collation information of the person to be authenticated.

[0141] <<3. Other Embodiments>> Note that the present invention is not limited to the above-described embodiments. It will be understood by those skilled in the art that the above-described embodiments are merely illustrative and that various modifications can be made without departing from the scope and spirit of the present invention.

[0142] For example, the steps in the processes described in this specification do not necessarily have to be executed in chronological order according to the order described in the flowchart. For example, the steps in the process may be executed in an order different from the order described as the flowchart, or may be executed in parallel. Also, some of the steps in the process may be deleted, and additional steps may be added to the process.

[0143] Also, an apparatus (for example, one or more apparatuses (or units) among a plurality of apparatuses (or units) constituting the collation system, or a module for one of the plurality of apparatuses (or units)) including the components of the collation system described in this specification may be provided. Further, a method including the processing of the above components may be provided, and a program for causing a processor to execute the processing of the above components may be provided. Also, a non-transitory computer readable medium recording the program may be provided. Of course, such an apparatus, module, method, program, and non-transitory computer readable medium are also included in the present invention.

[0144] <<4. Supplementary Note>> The above embodiments of the present invention may be described as follows in the supplementary note, but are not limited thereto.

[0145] (Supplementary Note 1) A collation system including a client terminal and a server device, in the client terminal, a secret sharing processing unit that divides registration information into first information and second information and provides the second information to the server device; in the client terminal, a first similarity calculation unit that executes a first step of calculating the similarity between the registration information and the collation information based on the collation information input for collation with the registration information and the first information; in the client terminal, a first transmission unit that transmits the calculation result of the first step to the server device; in the server device, a second similarity calculation unit that executes a second step of calculating the similarity based on the calculation result of the first step received from the client terminal and the second information; in the server device, a second transmission unit that transmits the calculation result of the second step to the client terminal; In the client terminal, based on the calculation result of the second step received from the server device and the first information, the third step of the similarity calculation is executed, and a third similarity calculation unit that calculates the similarity between the registration information and the collation information; A collation system characterized by comprising the same.

[0146] (Supplementary Note 2) The collation system according to Supplementary Note 1, wherein when the registration information is x, the first information is x1 and x2, and the second information is x3, the registration information is divided so as to satisfy x = x1 + x2·x3.

[0147] (Supplementary Note 3) The similarity calculation is the inner product of the registration information and the collation information. When the collation information is y, it is represented by x·y = (x1 + x2·x3)·y, In the first step, x2·y is calculated, In the second step, the calculation result of the first step is multiplied by x3, The collation system according to Supplementary Note 2, wherein in the third step, x1·y is added to the calculation result of the second step.

[0148] (Supplementary Note 4) The collation system according to Supplementary Note 3, wherein the collation information is divided so as to satisfy y = y1 + y2, and the first step, the second step, and the third step are executed for each of y1 and y2.

[0149] (Supplementary Note 5) The collation system according to any one of Supplementary Notes 1 to 4, wherein the second step and the third step are performed by secret calculation.

[0150] (Supplementary Note 6) The collation system according to any one of Supplementary Notes 1 to 5, wherein the registration information and the collation information are common n-dimensional vectors.

[0151] (Supplementary Note 7) The collating system according to any one of Supplementary Notes 1 to 6, characterized in that the client terminal and the server device execute the similarity calculation based on a challenge-response method.

[0152] (Supplementary Note 8) The collating system according to any one of Supplementary Notes 1 to 6, characterized in that the registration information and the collating information represent feature amounts of biometric information.

[0153] (Supplementary Note 9) A secret sharing processing unit that divides registration information into first information and second information, stores the first information, and provides the second information to a server device; A first similarity calculation unit that executes a first step of similarity calculation between the registration information and the collating information based on the collating information input for collation with the registration information and the first information; A transmission unit that transmits the calculation result of the first step to the server device; A third similarity calculation unit that executes a third step of similarity calculation based on the calculation result of the first step received from the server device, the calculation result of the second step of similarity calculation based on the second information, and the first information, and calculates the similarity between the registration information and the collating information; A client terminal, characterized by comprising the above.

[0154] (Supplementary Note 10) A second similarity calculation unit that receives, from a client terminal, a calculation result of a first step of similarity calculation between first information divided from registration information and collating information input for collation with the registration information, and executes a second step of similarity calculation based on the calculation result of the first step and second information divided from the registration information; A transmission unit that transmits the calculation result of the second step to the client terminal so that the client terminal executes a third step of similarity calculation based on the calculation result of the second step and the first information; A server device, characterized by comprising the above.

[0155] (Appendix 11) A verification method in a verification system including a client terminal and a server device, wherein the client terminal divides registration information into first information and second information, and provides the second information to the server device, the client terminal executes a first step of calculating the similarity between the registration information and the verification information based on the verification information input for verification with the registration information and the first information, the client terminal transmits the calculation result of the first step to the server device, the server device executes a second step of calculating the similarity based on the calculation result of the first step received from the client terminal and the second information, the server device transmits the calculation result of the second step to the client terminal, the client terminal executes a third step of calculating the similarity based on the calculation result of the second step received from the server device and the first information, and calculates the similarity between the registration information and the verification information A verification method characterized by the above.

[0156] (Appendix 12) Secret sharing processing for dividing registration information into first information and second information, storing the first information, and providing the second information to a server device, a first similarity calculation process for executing a first step of calculating the similarity between the registration information and the verification information based on the verification information input for verification with the registration information and the first information, a transmission process for transmitting the calculation result of the first step to the server device, a third similarity calculation process for executing a third step of calculating the similarity based on the calculation result of the first step received from the server device, the calculation result of the second step of calculating the similarity based on the calculation result of the first step and the second information, and the first information, and calculating the similarity between the registration information and the verification information A program for a client terminal that causes a computer to execute.

[0157] (Appendix 13) Receiving from the client terminal the calculation result of the first step of calculating the similarity between the first information divided from the registration information and the collation information input for collation with the registration information, and based on the calculation result of the first step and the second information divided from the registration information, a second similarity calculation process for executing the second step of the similarity calculation; A transmission process of transmitting the calculation result of the second step to the client terminal so that the client terminal executes the third step of the similarity calculation based on the calculation result of the second step and the first information; A program for a server device that causes a computer to execute. Industrial applicability

[0158] The present invention is suitably applied to a collation system that performs authentication using a client and a server.

Explanation of symbols

[0159] 10 Collation system 100 Client 110 Registration information input unit 120 Dispersion processing unit 130 Storage unit 140 Random number generation unit 150 Collation information input unit 160 Commitment generation unit 165 Commitment transmission unit 170 Response generation unit 175 Response transmission unit 180 Output unit 200 Server 210 Storage unit 220 Random number generation unit 230 Challenge generation unit 235 Challenge transmission unit 240 Determination unit

Claims

1. A division processing means for dividing the registration information into first information and second information; a generating means for performing a calculation based on the matching information and the first information to generate a first result; a receiving means for receiving from a server a second result generated by performing a calculation based on the second information and the first result; a determination means for performing a calculation based on the second result and the first information and determining whether the matching information can be authenticated; An information processing device comprising:

2. The division processing means performs secret sharing processing. The information processing device according to claim 1 .

3. A verification method in a verification system including an information processing device and a server, In the information processing device, Dividing the registration information into first information and second information; performing a calculation based on the matching information and the first information to generate a first result; receiving from the server a second result generated by performing a calculation based on the second information and the first result; performing a calculation based on the second result and the first information to determine whether the matching information can be authenticated; A matching method comprising:

4. In the division, a secret sharing process is performed. The collation method according to claim 3.

5. Computers as information processing devices Dividing the registration information into first information and second information; performing a calculation based on the matching information and the first information to generate a first result; receiving, from a server, a second result generated by performing a calculation based on the second information and the first result; performing a calculation based on the second result and the first information to determine whether the matching information can be authenticated; A program that executes the following.

6. In the division, a secret sharing process is performed. The program according to claim 5.

Citation Information

Patent Citations

  • Monitoring information sharing system, collation device, monitoring device, and program

    JP2016071639A

  • Collator and register

    WO2004088591A1

  • Data processing device

    WO2011052056A1

  • Information processing system, node, authentication method and storage medium

    WO2016152130A1

  • Crypto-information creation device, crypto-information creation method, recording medium, and collation system

    WO2016203762A1