Security documents and methods for verifying security documents
The method links unique base material values with face information in security documents, using machine-readable codes, ensuring offline verification and resistance to tampering, addressing the limitations of existing technologies.
Patent Information
- Application Number
- JP2022090362
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-06-02
- Publication Date
- 2025-08-06
- Estimated Expiration
- 2042-06-02
AI Technical Summary
Existing security document verification technologies require analytical knowledge, are ineffective against physical attacks, and rely on online infrastructure, making them vulnerable to fraud and tampering, especially in emergencies.
A method that links unique values extracted from the security document's base material with face information, encoded as a machine-readable code, allowing offline verification using infrared or laser patterns, and optionally incorporating secure elements like holograms or RFID.
Ensures authenticity and integrity verification without specialized knowledge, resistant to physical tampering, and functional in emergencies, reducing costs by eliminating the need for online databases and secret key maintenance.
Smart Images

Figure 0007719449000001 
Figure 0007719449000002 
Figure 0007719449000003
Abstract
Description
[Technical Field]
[0001] The present invention relates to a technology for preventing fraud in security documents such as banknotes, passports, IDs, qualification certificates, and securities, and in particular to a method for detecting and verifying falsification and alteration using machine-readable codes. [Background technology]
[0002] Document fraud, such as the forgery, imitation, alteration, and falsification of security documents using digital devices such as scanners, printers, and color copiers, has become a social problem. Although it is difficult to strictly define and categorize these document frauds, generally speaking, "counterfeiting" refers to creating a counterfeit that has similar appearance and characteristics to the genuine product using materials equivalent to those of the genuine product, "imitation" refers to creating a counterfeit that only has a similar appearance to the genuine product without necessarily using materials equivalent to those of the genuine product, "alteration" refers to creating a counterfeit by replacing part or component of the genuine product with another genuine product or part of a counterfeit, and "tampering" refers to creating a counterfeit by erasing, adding to, or rewriting written information or printed designs on the face of the document (see Non-Patent Document 1).
[0003] One countermeasure against document fraud is "security printing technology." This technology field is characterized by the difficulty of producing printed documents using ordinary commercial printing methods and the possibility of verifying the uniqueness of the original document (the ability to determine authenticity). Authenticity determination includes measures against the fraudulent alteration of the name of the holder of an ID document such as a passport. Conventional techniques for countering tampering using security printing technology are primarily based on the detection of traces of tampering, and include chemical and physical measures, as described in the next section, and the use of redundancy in written information.
[0004] As a chemical countermeasure for detecting tampering, for example, Patent Document 1 discloses that solvent detection chemicals such as leuco dyes and phenolic substances are incorporated into the printing substrate or ink by means of mixing, milling, etc., and that the chemical reaction between the solvent used by the counterfeiter to erase the ink and the solvent detection chemicals is detected as a means of detecting traces of fraudulent activity.
[0005] However, because this countermeasure relies on a chemical reaction, it is not effective against physical attacks such as peeling or polishing of the printing layer (ink coating) on the surface of the document. Furthermore, because it involves observing the results of a chemical reaction, depending on the compatibility with the solvent used by the counterfeiter, a color change that is sufficiently noticeable to humans may not occur, making it difficult to detect fraud. Furthermore, contact with sweat or everyday chemicals during use can frequently cause unexpected reactions, resulting in false reactions. Furthermore, the degree of color change due to reaction with the solvent is generally very slight, making it difficult for the average user, who is not an expert in authenticity determination with analytical knowledge, to determine whether the document is genuine or not.
[0006] Physical countermeasures for detecting tampering include protecting the information on the face of a document with a fragile film or a durable laminate film. The former deters fraud by making the film easily destroyed and difficult to repair through unusual manipulations such as replacing or scratching the film layer. The latter, however, functions as a preventative measure, making destruction difficult in the first place due to the robustness of the film material. These are also widely known as typical techniques for preventing the replacement of facial photographs on documents such as card-type IDs, such as multi-layered plastics and printing the facial photograph on a color-developing layer embedded within the substrate rather than on its surface.
[0007] However, even with this countermeasure technology, there are known fraudulent attack methods, such as etching the film layer with a focused ion beam, cutting the surface in micron units with a milling machine, and peeling it off. It is also conceivable that the substrate could be replaced by peeling off the entire card surface layer, not just the photograph portion. However, these countermeasure methods are mainly limited to cards and the like that use plastic as the printing substrate, and are not effective for security documents that use thin paper substrates.
[0008] As another countermeasure for detecting falsification, for example, Patent Document 2 discloses a technology that utilizes cross-referencing due to the redundancy of written information on the face of a document. A specific example is a method of printing the name "Printing Taro" printed in the name field on the face of a document using minute characters in a background pattern or the like that forms the background of the name field. This mechanism allows a document authenticator to detect fraudulent falsification by cross-referencing the consistency between the name printed in the name field and the name in minute characters (character height of about 400 microns) in the background pattern.
[0009] However, while this method may function effectively if it is verified by a security printing expert who is familiar with the security specifications on the face of the document or the issuer of the security document, it does not function effectively for ordinary users who do not have the special knowledge to distinguish between authenticity and counterfeiting. Furthermore, if it is assumed that a counterfeiter has the same "knowledge" of the document's face specifications as an expert or the document issuer, it is likely that the counterfeiter will even replicate the redundancy ("Printing Taro" in tiny characters), so it is not a sufficient countermeasure.
[0010] Another countermeasure besides security printing is the use of information security technology. Information security technology goes beyond the physical media of printing ink and substrate to implement security mechanisms for the information itself, so to speak, attached to the document surface. For example, Patent Document 3 aims to provide a printing device and print verification device for electronic approval information that protects the entire printed page as an approved document, does not require a special printing device, and can detect tampering of the entire document after the approval seal is applied by the approver. To achieve this, the printing device for electronic approval information is characterized by comprising: public information generation means for generating public information from the approver's confidential information; registration means for registering the public information in a database in advance; approval information generation means for generating approval information using the confidential information from the electronic information; approval information conversion means for converting the approval information generated by the approval information generation means into a print format; and approval information printing means for printing the approval information converted by the approval information conversion means. This means also includes a search means for retrieving public information from the database.
[0011] Furthermore, in the example of Patent Document 3, digital signature information using a public key cryptosystem is used as the authentication seal information, and therefore the use of an online public key authentication infrastructure is assumed. However, there are concerns about ensuring effectiveness in emergencies such as power outages and authentication infrastructure malfunctions during natural disasters. Furthermore, the security of public key cryptosystems relies on mathematical one-wayness, whereby a public key can be easily derived from a private key, but the reverse is extremely difficult. Therefore, absolute secrecy and maintenance of the private key is required, which incurs significant costs. [Prior art documents] [Patent documents]
[0012] [Patent Document 1] Japanese Patent Application Publication No. 182496 / 1983 [Patent Document 2] Patent No. 4635160 [Patent Document 3] Patent No. 2875450 [Non-patent literature]
[0013] [Non-Patent Document 1] ID Card Security Handbook, National Printing Bureau, February 2019 [Non-patent document 2] Yamakoshi et al., Individuality evaluation for paper based artifact-metrics using transmitted light image, Proceedings Volume 6819, Security, Forensics, Steganography, and Watermarking of Multimedia Contents X; 68190H (2008) [Non-patent document 3] Yamakoshi et al., An artifact-metrics which utilizes laser speckle patterns for plastic ID card surface, Proceedings Volume 7618, Emerging Liquid Crystal Technologies V; 76180B (2010) Summary of the Invention [Problem to be solved by the invention]
[0014] To summarize the technologies described in Patent Documents 1 and 2, in verifying the uniqueness of security documents, identifying traces of tampering or detecting whether or not tampering has occurred requires analytical and appraisal knowledge or a thorough knowledge of the security specifications on the document surface, making it difficult for ordinary users to determine whether fraud has occurred.
[0015] Next, let's consider the issues surrounding copies made from original security documents. Various certificates, such as resident registration certificates, passports, and driver's licenses, issued by public institutions are often used for various purposes. Because copies made from original documents change their base material from perforated special paper, plastic cards, or booklets to general-purpose copy paper, it is easy to determine whether the copy is not the original. Furthermore, depending on the performance of the copying equipment, the number of reproduced colors and resolution may be significantly reduced. Copies made under such circumstances do not function as described in Patent Documents 1 and 2, making it impossible to detect whether the information has been tampered with. As a result, fraudulent activities such as copying altered original documents and copies of altered copies are common in certificate management. These are attempts to camouflage evidence of tampering through the copying process. Therefore, in addition to a means of verifying the originality (uniqueness) of submitted security documents, a means of verifying the integrity (freedom of errors or missing information) of copies of said documents is required.
[0016] Although the technology described in Patent Document 3 can detect whether copies have been tampered with, it presupposes the operation of an online authentication infrastructure and database, and therefore does not function at all in emergencies such as power outages. Furthermore, while IC cards and USB memory sticks are assumed to be used as storage media for private keys, the same applies when these storage media fail to read data. Furthermore, it is conceivable that attackers (those attempting document fraud) may intentionally cause these malfunctions in order to circumvent the above-mentioned legitimate authentication methods.
[0017] Furthermore, the technology in Patent Document 3 cannot guarantee the authenticity of the document on which the desired certification information is printed. Although there is a trend toward partial digitalization of security documents such as banknotes, passports, stamps, driver's licenses, and various certificates and qualifications, the authenticity of the document itself and a means of verifying this are still required, and various technologies are available for this purpose. Furthermore, no effective technology has been developed to combat "forgery," one form of document fraud. For example, intaglio printing, perforation, holograms, etc. are implemented in banknotes, facial photographs in various qualifications, and IC chips in passports as carriers of the document's authenticity (characteristics that ensure its authenticity or authenticity). However, measures are needed to prevent the creation of counterfeits by replacing parts or components of these genuine items with parts of other genuine items or counterfeits.
[0018] The present invention aims to solve the above-mentioned problems and to provide a security document and a verification method thereof that can verify the authenticity and integrity of the original security document and the integrity of its copies, without requiring analytical and appraisal knowledge, familiarity with security design specifications, an infrastructure for querying public information, or the concealment and maintenance of confidential information. [Means for solving the problem]
[0019] The security document according to the present invention is characterized in that when a unique value extracted from the base material of the security document by any method is linked with the information written on the face of the security document to form security document information, a summary value of the security document information is calculated, encoded in the form of a machine-readable code on the face of the security document, and printed.
[0020] The method for verifying a security document according to the present invention is characterized in that when a unique value extracted from the base material of the security document to be verified is linked to the information written on the face of the security document to obtain the security document information of the document to be verified, a summary value calculated from the security document information is compared and verified with the decoded result of the machine-readable code on the security document to be verified.
[0021] When the substrate of the security document is a translucent material such as thin paper or plastic, the characteristic value extracted from the substrate is a value extracted from an infrared transmission light pattern obtained when infrared light is irradiated onto the substrate.
[0022] The method for verifying a security document is characterized in that, when the base material of the security document to be verified is a translucent material such as thin paper or plastic, the eigenvalue extracted from the base material is a value extracted from an infrared transmitted light pattern obtained when infrared light is irradiated onto the base material.
[0023] When the substrate of the security document is an opaque material such as that used in ID cards, the characteristic value extracted from the substrate is a value extracted from a speckle pattern generated when laser light is irradiated onto the substrate.
[0024] The method for verifying a security document is characterized in that, when the base material of the security document to be verified is an opaque material such as that used in ID cards, the eigenvalue extracted from the base material is a value extracted from a speckle pattern generated when laser light is irradiated onto the base material.
[0025] The security document according to the present invention is characterized in that when information read from a security background pattern pre-printed on the base material of the security document is linked with information printed on the face of the security document to form security document information, a summary value of the security document information is calculated, encoded in the form of a machine-readable code on the face of the security document, and printed.
[0026] The security document information is a security document described in item number
[0025] that is information that combines at least the information read from the security watermark pattern, the information written on the face of the card, and any information shared in advance between the issuer and the verifier.
[0027] The method for verifying a security document according to the present invention is characterized in that when the information read out from the security tint pattern pre-printed on the base material of the security document to be verified is linked with the information written on the face of the security document to obtain the security document information of the document to be verified, a summary value calculated from the security document information is compared and verified with the decoded result of the machine-readable code on the security document to be verified.
[0028] A method for verifying a security document described in item number
[0027] , in which the security document information is information that is at least a combination of information read from the security watermark pattern, information written on the face of the card, and any information shared in advance between the issuer and the verifier.
[0029] The information read from the security background pattern described in item number
[0027] is typically invisible to the naked eye and is characterized as dynamic and / or static information that is visualized using wavelength ranges such as infrared and / or ultraviolet.
[0030] The method for verifying security documents described in item number
[0028] is characterized by dynamic and / or static information that is normally invisible to the naked eye and is visualized by wavelength ranges such as infrared and / or ultraviolet.
[0031] The information read from the security background pattern described in item number
[0027] is typically difficult to read with the naked eye alone, and is characterized as being dynamic and / or static information that can be made readable by using a magnifying glass, an optical filter, changing the observation angle, observing with transmitted light, or copying using a copy machine.
[0032] The security document information described in item number
[0025] is information that at least combines information read from a security watermark pattern including obfuscated information, information written on the face of the card, and any information shared in advance between the issuer and the verifier.
[0033] The method for verifying security documents described in item number
[0027] is characterized by the fact that the information is dynamic and / or static, and is usually difficult to read with the naked eye alone, but is made readable by using a magnifying glass, an optical filter, changing the observation angle, observing with transmitted light, or copying using a copy machine.
[0034] A method for verifying a security document described in item number
[0027] , in which the security document information described in item number
[0025] is information that combines at least information read from a security watermark pattern including obfuscated information, information written on the face of the card, and arbitrary information shared in advance between the issuer and the verifier.
[0035] The information printed on the face of the security document is characterized by including unique ID information of at least one secure element such as a hologram or RFID mounted in any form, such as attached to or embedded in the base material of the security document.
[0036] The machine-readable code is printed so as to overlap at least one secure element such as the hologram or RFID. [Effects of the Invention]
[0037] In the present invention, as explained in detail in Non-Patent Document 2, even if an attacker were to obtain an infrared transmission light image illegally, the attacker would not be able to reconstruct each of the minute cellulose fibers that make up the paper substrate, and so the infrared transmission light image taken from the substrate can serve as a basis for verifying the uniqueness of the paper substrate. Furthermore, even if an attacker tampers with part of the information written on the face of the document, the attacker would not be able to calculate the authentic summary value, and the verifier would be able to reject the document as a fake.
[0038] In the present invention, as explained in detail in Non-Patent Document 3, the speckle pattern collected from the substrate is a physical one-way function, so that even if an attacker were to obtain a speckle pattern image illegally, the speckle pattern lacks phase information from the laser light source, making it impossible to reconstruct the corresponding microstructure of the substrate surface. Therefore, it can serve as a basis for verifying the uniqueness of the substrate. Furthermore, even if an attacker tampers with part of the information written on the face of the document, the attacker will not be able to calculate the authentic summary value, allowing the verifier to reject the document as a fake.
[0039] In the present invention, even when information in a security pattern that is normally invisible to the naked eye is used as part of the security document information, it is difficult for an attacker to infer the necessary information from the security pattern that covers almost the entire surface of the document, and therefore the attacker cannot calculate the authentic digest value, allowing the verifier to reject the document as a fake.
[0040] In the present invention, when information in a security tint pattern that is generally obscured is used as part of the security document information, the obscured information of the security document can be read from a copy made by a copier, and therefore, by comparing and verifying a digest value calculated from the security document information including the obscured information on the copy with the decoded result of the machine-readable code on the copy, it is possible to detect falsification of the information written on the copy.
[0041] This series of verification methods does not require online database queries and can be completed offline, ensuring their effectiveness in emergencies. Furthermore, it is cost-effective because it does not require the confidentiality and maintenance of secret information equivalent to the private key of an information security system that uses public key cryptography. [Brief explanation of the drawings]
[0042] [Figure 1] Schematic diagram of the security document according to the present invention [Figure 2]Verification flow of security document in the present invention [Figure 3] Schematic diagram of a card-type security document according to the present invention [Figure 4] Schematic diagram of a security document having a security tint pattern containing invisible information according to the present invention. [Figure 5] Verification flow of security document having security background pattern according to the present invention [Figure 6] Schematic diagram of a security document having a security background pattern including obfuscated information according to the present invention. [Figure 7] Schematic diagram of a copy of a security document having a security background pattern containing obfuscated information according to the present invention. [Figure 8] 1 is a schematic diagram of a security document having a security background pattern including invisible information according to a first embodiment; [Figure 9] Schematic diagram of a security document having a security background pattern including obfuscation information in Example 2. [Figure 10] Schematic diagram of a copy of a security document having a security background pattern including obfuscated information in Example 2. [Figure 11] Infrared transmitted light image of recycled paper in this invention [Figure 12] Infrared transmitted light intensity profile in the present invention [Figure 13] Speckle pattern on the card surface in the present invention [Figure 14] Schematic diagram of a speckle pattern photographing device according to the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0043] (Embodiment 1) FIG. 1 shows a schematic diagram of a security document (1) according to the present invention. The security document (1) comprises a substrate (2), a substrate-specific value reading area (3), information printed on the surface (4), and a machine-readable code (5). The substrate (2) is not limited to a paper substrate such as a sheet, and may take any form, such as a booklet, plastic card, or label-type sticker, as long as it is possible to measure the amount of transmitted light when irradiated with light of any wavelength. The substrate-specific value reading area (3) is shown merely as a schematic representation and may represent part or all of the printed surface shown in FIG. 1. Examples of substrate-specific values include the degree of entanglement of cellulose fibers constituting the paper, the light emission distribution of special luminescent fibers mixed in during the papermaking process, the perforation pattern, and the vibration characteristics of the paper. In any case, the substrate-specific value represents a feature that can uniquely identify the individuality of the paper substrate. It is determined based on factors such as whether the feature covers the desired number of individual identifications, whether it has a wide distinguishable feature space, the cost of collecting and measuring the feature, and the appropriateness of the data size. In this embodiment, an example is described in which an infrared transmission light pattern captured by an infrared flatbed scanner, which has excellent resistance to folds, wrinkles, and dirt on the substrate, is used. The document information (4) can include any information to be protected, such as the document title, document holder, issuer, and certified information, as well as facial photograph information, not limited to text information. The detailed specifications of the machine-readable code (5) are determined taking into consideration the information volume and error correction rate of the calculated summary value. The summary value stores the result of a summary calculation of a data string that concatenates the substrate-specific value collected by the infrared flatbed scanner when the document is issued with the document-specific information (4). Here, concatenation refers to combining multiple data strings that are treated separately into a single data string. In general mathematical notation, it is expressed as (substrate-specific value ||document information). The summary value, also known as a hash value, is a one-way function. Any of several types of hash functions, such as SHA and MD5, may be used.
[0044] The information stored in the machine-readable code (5) is not necessarily limited to a summary value, but may be encrypted data obtained by encrypting the information on the card (4) using a common key encryption method such as Advanced Encryption Standard (hereinafter referred to as AES) or Triple Data Encryption Standard (hereinafter referred to as 3DES) with the substrate-specific value as the key. In this case, the integrity of the information on the card (4) can be verified by comparing the encrypted data with the plain text obtained by decrypting the encrypted data using the substrate-specific value.
[0045] In this embodiment, no security tint pattern is included, but if a security tint pattern is included, an infrared transmission light pattern obtained by superimposing the base material (2) and the security tint pattern may be collected and utilized. Since minute positional deviations that occur during base material transport by a printing device cannot be controlled artificially, the minute positional deviations can be used as base material-specific values.
[0046] FIG. 2 shows the verification flow for a security document (1) according to the present invention. First, the substrate characteristic value of the document to be verified is input (S1). In principle, it is desirable to use the same method and equipment as those used to collect and measure the substrate characteristic value when issuing the security document (1) as described in
[0043] . In this embodiment, the same flatbed scanner with an infrared light source was used when issuing the document. Next, the face information (4) is input (S2). This is done using commercially available automatic input technology such as OCR or manual input. Next, the substrate characteristic value and the input face information (4) are concatenated (S3), and a summary value of the data string is calculated (S4). Next, the read result (S5) of the machine-readable code (5) printed on the security document (1) to be verified is compared with the summary value (S6). If they are identical, the document is deemed authentic; if they are not identical, a determination is made that the document is a counterfeit, and the comparison and verification process is terminated.
[0047] As shown in Figure 2, if the document to be verified is a copy made by a copier, or if the raw materials of the substrate (2) are significantly different from those of the original security document (1), and the substrate characteristic value cannot be read (S1), a determination that the document is a fake can be output and the comparison verification process can be completed.
[0048] (Embodiment 2) FIG. 3 shows a schematic diagram of a card-type security document (6) according to the present invention. The card-type security document (6) is composed of a card substrate (7), a card substrate unique value reading area (8), card face information (9), a card face machine-readable code (10), and a facial photograph (11). The card substrate (7) may be made of any opaque material, such as plastic or paper (cotton fiber), but it is assumed that the surface reflected light can be measured when irradiated with laser light. The card substrate unique value reading area (8) is shown merely as a schematic representation and may be part or all of the printed face shown in FIG. 3. It may also overlap with the area bearing the facial photograph (11) and the card face machine-readable code (10). An example of a substrate unique value is a minute uneven shape on the substrate surface that is difficult to detect. In the case of plastic substrates, the surface microstructures of the rolling rolls and molds used in manufacturing processes such as rolling and injection molding have subtle individual differences that cannot be artificially controlled. Therefore, the surface of manufactured plastic substrates also has subtle individual differences between individual units and product lots. These differences in the microstructure of individual surfaces, which exceed the control limit, are used to identify the substrate. While any method for measuring the microstructure can be used, such as a magnified photograph of the substrate surface using reflected light or a light-dark image of the substrate surface captured with a precision scanner, this embodiment describes an example using a speckle pattern obtained by irradiating a substrate surface with a laser. Speckles are dotted light-dark patterns that occur when coherent light, such as a laser, is irradiated onto a diffuse surface such as paper, plastic, or metal. They occur when light scattered at each point on the diffuse surface interferes with each other in an irregular phase relationship corresponding to the microscopic irregularities on the surface of the card substrate (7). Because this speckle pattern is unique to each individual card-type security document (6), it can be used to uniquely identify the document. The information written on the card (9) can include any information to be protected, such as the document title, document holder, issuer, and certified items, as well as facial photograph information (11), which is not limited to text information. The detailed specifications of the machine-readable code (10) on the card are determined in the same manner as in
[0043] .The summary value recorded in the card face machine readable code (10) stores the result of summarizing the data string that combines the card substrate unique value and the card face information (9).
[0049] The information stored in the machine-readable code (10) is not necessarily limited to the digest value, but may be encrypted data obtained by encrypting the card information (9) using a common key encryption method such as AES or 3DES, using the value of the information in the card substrate unique value reading area (8) (the card substrate unique value) as a key. In this case, the integrity of the card information (9) can be verified by comparing it with the plain text obtained by decrypting it using the information in the card substrate unique value reading area (8) (used as a key).
[0050] The basic configuration of the verification flow (Fig. 5) for a card-type security document (6) according to the present invention is the same as that shown in Fig. 2. In this embodiment of the present invention, a general-purpose diode laser is irradiated onto the surface of the card substrate (7) to read the card substrate characteristic value, and the resulting speckle pattern is captured by a general-purpose CMOS camera (S1). Next, the card face information (9) is input (S2) using commercially available automatic input technology such as OCR or by manual input, the card substrate characteristic value is linked to the input card face information (9) (S3), and a summary value of the data string is calculated (S4). Next, the card face machine-readable code (10) printed on the card-type security document (6) to be verified is read (S5), and the result is compared with the summary value (S6). If they are identical, the document is deemed authentic; if they are not identical, a determination is made that the document is counterfeit, and the comparison and verification process is terminated.
[0051] In addition, if the document to be verified is a crude duplicate card, or if the characteristics of the raw materials of the card substrate (7) are significantly different from those of the original card-type security document (6), and the substrate characteristic value cannot be read (S1), a determination that the document is a fake can be output and the comparison verification process can be terminated.
[0052] (Embodiment 3) FIG. 4 shows a schematic diagram of a security document (12) with a security background pattern containing invisible information according to a third embodiment. The security document (12) with a security background pattern is composed of a substrate (13), a security background pattern (14) containing invisible information, printed information (17), and a machine-readable code (18). Details of the substrate (13), printed information (17), and machine-readable code (18) are the same as those described in
[0043] . The circular window (16) shown in the enlarged partial view simulates an image printed in UV-luminescent ink that is camouflaged in the security background pattern (14) containing invisible information and visualized by a UV light source (19). More specifically, the camouflaged image in UV-luminescent ink is the word "Secure" (15). The image visualized by the UV light source (19) does not necessarily have to be human-readable information; it may be a machine-readable code (18). In this embodiment, an example of invisible information has been described using an image printed with UV luminescent ink, but the present invention is not limited to this and may be any of a small image of at most 10 microns square, ink in a wavelength range other than ultraviolet light that is not sensitive to the naked eye, transparent ink, a low-brightness image on a highly white substrate (13), the use of glossy / non-glossy ink, and application by processing the substrate (13) such as embossed printing without ink.Various embodiments are conceivable for the method of applying invisible information, but it is generally assumed that the information is not visible to the naked eye and cannot be reproduced by copying with a copy machine.
[0053] The information stored in the machine-readable code (18) is not necessarily limited to a digest value, but may be encrypted data obtained by encrypting the information (17) written on the card using a common key encryption method such as AES or 3DES with the character string "Secure" (15) as the key. In this case, the integrity of the information (17) written on the card can be verified by comparing it with the plain text obtained by decrypting it using the character string "Secure" (15) (used as the key).
[0054] When the invisible information is reproduced in a visible form by copying using a copy machine, the function of detecting tampering with the information written on the face of the card (17) in the copy made by the copy machine described above is realized.
[0055] Figure 5 shows the verification flow of a security document (12) having a security tint pattern in this embodiment. The only difference from the verification flow shown in Figure 2 is the reading (S7) of invisible information from the security tint pattern (14) containing invisible information, and the processes other than (S7) are the same.
[0056] The verification flow for a security document (12) with a security background pattern begins by irradiating the invisible information in the security background pattern (14) with a UV light source (19) to make it visible, and then reading the visible information using any method. Next, the information written on the face of the document (17) is input (S2) using automatic input technology or manual input. Next, the visible information and the input information written on the face of the document (17) are linked (S3), and a summary value of the data string is calculated (S4). Next, the read result (S5) of the machine-readable code (18) printed on the security document (12) with the security background pattern to be verified is compared with the summary value (S6). If they are identical, the document is deemed authentic; if they are not identical, a determination is made that the document is a counterfeit, and the comparison verification process is completed.
[0057] As shown in FIG. 5, if the invisible information in the security background pattern (14) containing invisible information is not made visible by irradiation with the UV light source (19) (S7), a determination that the item is a fake is output, and the comparison and verification process can be completed.
[0058] (Fourth embodiment) FIG. 6 shows a schematic diagram of a security document (20) according to the present invention, which has a security background pattern containing obfuscated information. The security document (20) includes a base material (21), a security background pattern (22) containing obfuscated information, information printed on the face of the card (23), and a machine-readable code (24). More specifically, the security background pattern (22) containing obfuscated information includes obfuscated information (25). Obfuscated information (25) is typically information such as characters, symbols, figures, and designs that are difficult to see and read with the naked eye alone. The obfuscated information (25) in this embodiment corresponds to a copy prevention pattern character such as that described in Japanese Patent Publication No. 3268418. The copy deterrent pattern characters are suitable as an embodiment because, in the original security document, they are designed to maximize obfuscation from both security and aesthetic standpoints by making the average halftone dot ratio of the deterrent pattern area and the background pattern area equal, so that no difference in shading is perceived macroscopically. As shown in the schematic diagram of a copy (Figure 7), the copy deterrent pattern makes the "NPB" characters (26) clear and easily readable as a warning message to attackers. Here, the visibility or readability quality of the obfuscation information (25) in the copy is sufficient as long as it remains visible and is at most recognizable in the copy. Other examples of hard-to-read information (25) include various latent images in which a specific pattern becomes visible only when the viewing angle is changed, various latent images in which a specific pattern becomes visible only when a specific optical filter is superimposed, special perforations that are visible even under reflected light (allowing the reflected image to be copied), holograms (in which a specific fixed image appears in the copy), and minute characters with a height of around 400 microns.
[0059] For example, when minute characters are used as a means of providing the obfuscation information (25), the minute characters may not remain visible due to the resolution of the copy machine. In this case, it is desirable to share the obfuscation information (25) between the document issuer and the verifier in advance, or to make the obfuscation information redundant by creating a security background pattern (22) containing the obfuscation information by a means that can remain visible on other copies.
[0060] The information stored in the machine-readable code (24) is not necessarily limited to the digest value, but may be encrypted data obtained by encrypting the information on the face of the card (23) with a common key encryption method such as AES or 3DES using the value of the obfuscation information (25) as a key. In this case, the integrity of the information on the face of the card (23) can be verified by comparing it with the plain text obtained by decrypting it with the value of the obfuscation information (25) (used as a key). Similarly, verification is also possible by encryption and decryption with a common key encryption method such as AES or 3DES using the value of information previously shared between the document issuer and the verifier as a key.
[0061] FIG. 5 shows the verification flow for a copy of a security document (20) with a security background pattern containing obfuscated information according to this embodiment. The process is identical to
[0056] except that in step S7, the obfuscated information (25) is read instead of the invisible information. In step S6, the digest value and the information in the machine-readable code (24) are compared and verified. If they are identical, it is possible to determine that the information on the face of the document (23) has not been tampered with. If they are different, it is possible to determine that the information on the face of the document (23) has been tampered with. The document verification flow begins by reading the obfuscated information (25) in the security background pattern (22) containing obfuscated information using any method. Next, the information on the face of the document (23) is input (S2) using automatic input technology or manual input. Next, the obfuscated information (25) and the input information on the face of the document (23) are concatenated (S3), and a digest value for the data string is calculated (S4). Next, the result of reading (S5) the machine-readable code (24) printed on the security document (20) with a security background pattern containing the obfuscated information to be verified is compared (S6) with the digest value. If they are identical, the document is deemed to be genuine, and if they are not, the document is deemed to be counterfeit, and the comparison and verification process is completed.
[0062] 7, if the obfuscation information (25) in the security background pattern (22) containing the obfuscation information cannot be read (S7), a determination that the item is a fake or a copy can be output and the comparison verification process can be terminated. Also, if the object to be verified is a copy and the obfuscation information (25) can be read, the process can be continued and by verifying the digest value and code information (S6), if they are identical, it can be verified that there has been no tampering, and if they are different, it can be verified that the item has been tampered with. [Example]
[0063] Example 1 An embodiment of the present invention will be described using a schematic diagram (28) of a security document to which an RFID label having a unique ID is affixed. The security document in this embodiment is composed of information (29) written on the face of the card (the characters "Printing Taro" and "876543"), an RFID (30) as an example of a secure element having a unique ID, a unique RFID ID (31) (the numbers "233445" are visualized for convenience), invisible information (32) (the characters "KEY123") embedded in a security background pattern that is not visible to the naked eye, and a machine-readable code (33) printed like a tally seal with the RFID (30). The invisible information (32) used in this embodiment is very small characters with a character height of approximately 280 μm or less.
[0064] Next, we will explain what kind of document information is actually calculated as a summary value, encoded into the machine-readable code (33), and stored. The aforementioned information is a string that combines the information printed on the card (29), the RFID unique ID (31), and the invisible information (32), and is mathematically expressed as (Printing Taro 876543||233445||KEY123) = "Printing Taro 876543233445KEY123" (spaces are significant here). Next, the string is converted into a byte array using UTF-8 (character encoding format), and the summary value, consisting of a 256-bit binary string, is calculated using the summary value function "SHA256." When the digest value is converted into a string in hexadecimal notation to be machine-readable (for example, QR Code (registered trademark), or Code 128), the result is "1f5048fe0778829856b56b634946c305029d74495e3e6855ff804654634d02af." In other words, the string in hexadecimal notation is encoded and stored in the machine-readable code (33).
[0065] As a first embodiment of the present invention, a method for verifying a security document to which an RFID label having a unique ID as shown in Figure 8 is attached will be described. Here, it is assumed that the security document to be verified has been tampered with by an attacker, with the characters "Printing Taro" in the name field being changed to "Printing Hanako." The document verifier reads the invisible information (32) "KEY123" using a method previously shared with the document issuer, such as a magnifying glass with a specified magnification and light source specifications. Similarly, the document verifier reads the RFID unique ID (31) "233445" stored in the RFID tag (30) attached to the document surface using a specified RFID reader. The read information and the information (29) written on the document surface, "Printing Hanako 876543," are concatenated in the same order as when the document was created, and a digest value is calculated using SHA256 by any existing method, and converted into a hexadecimal string. The resulting string is "b7a2772e39a1f6ecf230ccad7ab9a9d2dd7c5eba348c797e14e5a8e16515e9f3." Next, the presence or absence of tampering can be verified by comparing the digest value "1f5048fe0778829856b56b634946c305029d74495e3e6855ff804654634d02af" stored in the machine-readable code (33) printed on the face of the ticket with the resulting string "b7a2772e39a1f6ecf230ccad7ab9a9d2dd7c5eba348c797e14e5a8e16515e9f3."
[0066] Even if an attacker were able to tamper with the information on the face of the card (29) as desired, they would not be able to calculate the authentic digest value because they would not be able to obtain the invisible information that can only be visualized and read using a method previously shared with the document issuer. Even if an attacker were to keep the authentic information on the face of the card (29) and only replace the RFID unique ID (31) by replacing the RFID (30), they would not be able to calculate the authentic digest value, making it possible to verify the security document. Furthermore, since the machine-readable code (33) containing the digest value is printed on the RFID (30) like a tally seal, this has a physical deterrent effect against unauthorized replacement of the RFID (30).
[0067] Example 2 A second embodiment of the present invention will be described using the schematic diagram of a security document (34) on which a security background pattern containing obfuscated information is printed, as shown in Figure 9. The security document (34) on which a security background pattern containing obfuscated information is printed in this embodiment is composed of information written on the face of the card (35) (the characters "Printing Taro" and "876543"), a machine-readable code (36), and obfuscated information "NPB" (37) in the security background pattern. Here, the obfuscated information "NPB" (37) is a so-called copy deterrent pattern disclosed in Patent Publication No. 3268418 and the like, and has the characteristic of being optically decoded and visualized by copying with a copy machine or by a line-pattern lenticular lens.
[0068] Next, we will explain what kind of document information digest value is calculated, encoded into machine-readable code (36), and stored. The aforementioned information is a string that concatenates the information written on the card (35) and the obfuscated information "NPB" (37) in the security background pattern, and is expressed as (Printing Taro 876543||NPB) = "Printing Taro 876543NPB." Next, using UTF-8, the string is converted into a byte array. The digest value function "SHA256" calculates a digest value consisting of a 256-bit binary string. This is then converted into a hexadecimal string for machine-readable encoding, resulting in "d920b22d2c86a206037ea22eafac965f90dc62f121799a9ba3f7c0d609a87886." The hexadecimal string is encoded and stored in machine-readable code (36).
[0069] As a second embodiment of the present invention, a method for verifying a copy of a security document (34) on which a security background pattern containing obfuscation information is printed is described below. The method uses a copy of the falsified document (38) shown in Figure 10 (or an equivalent copy of the falsified copy). Assume that the copy (38) to be verified has been falsified by an attacker, changing the characters "Printing Taro" in the name field to "Printing Hanako" (39). The document verifier reads the information written on the face of the document (35) and the obfuscation information "NPB" (40) revealed by copying using a copy machine, concatenates them in the same order as when the document was created, calculates a digest using SHA256 using any existing method, and converts it into a hexadecimal string. The resulting string is "bfd81286fc689897dfb42ad094e376b686a2b3318b13cd75c0484b365c54f2f1." Next, it is possible to verify whether the ticket has been tampered with by checking whether the summary value “d920b22d2c86a206037ea22eafac965f90dc62f121799a9ba3f7c0d609a87886” stored in the machine-readable code (36) printed on the ticket face is different from the obtained character string “bfd81286fc689897dfb42ad094e376b686a2b3318b13cd75c0484b365c54f2f1.”
[0070] To further enhance security, the document issuer can also calculate and use a summary value by combining not only the obfuscation information but also other pre-shared information.
[0071] Example 3 Figure 11 shows a 400 x 400 (pixel) infrared transmitted light image taken from an area of approximately 25 x 25 (mm) on a thin paper substrate used for security documents, and Figure 12 shows a profile of the transmitted light amount in part of the image at 8-bit depth. The detailed conditions of the paper substrate and the equipment used to take the image are as follows: Paper brand: PPC100 (recycled paper for copiers), manufactured by Kishu Paper Co., Ltd., basis weight: 65 g / m 2Infrared scanner (flatbed type): IR4000, manufactured by iMeasure, wavelength 940 nm, resolution 400 DPI, depth 8 bits. The eigenvalues extracted from the infrared transmitted light image correspond to the invisible information in Example 1 or the hard-to-read information in Example 2, and can be used to calculate the summary value.
[0072] Example 4 Figure 13 shows an image of a speckle pattern generated when a laser is irradiated onto the surface of a card substrate used in a card-type security document, and a schematic diagram of the imaging device for capturing the speckle pattern (Figure 14). The speckle pattern imaging device consists of a general-purpose laser light source (42) (SMLX-D13, Kiko Giken, wavelength 675 nm, output 6.8 mW, irradiation size 8 x 2 mm) installed so that it irradiates the card-type security document (45) placed on a measurement stage in a perpendicular direction via two convex lenses (41), and a general-purpose CMOS camera (43) (DMK-41AF02, Imaging Source, pixel size: 4.65 μm, pixel count: 1280 x 960 pixels) installed so that it captures the image at a 30-degree angle (46) from the perpendicular direction of the card surface. The CMOS camera is equipped with a 670 nm bandpass filter (44) and other components to block ambient light. The eigenvalues extracted from the captured image of the speckle pattern correspond to the invisible information in the first embodiment or the hard-to-read information in the second embodiment, and can be used to calculate the summary value. [Explanation of symbols]
[0073] 1. Security Documents 2 Base material 3. Reading area for substrate specific values 4. Information printed on the ticket 5 Machine Readable Code 6. Card-type security documents 7 Card substrate 8. Card substrate specific value reading area 9. Card information 10. Card machine readable code 11. Photo of your face 12 Security document with security pattern containing invisible information 13 Base material 14 Security background patterns containing invisible information 15 Schematic diagram of information visualized using UV luminescent ink 16 Schematic diagram of UV irradiation area 17 Information printed on the ticket 18 Machine Readable Code 19 UV light source 20 Security document with security background pattern containing obfuscated information 21 Base material 22 Security background patterns containing obfuscated information 23 Information printed on the ticket 24 machine readable code 25 Obfuscated information 26 Schematic diagram of the copy 27 Warning message text "NPB" 28 Schematic diagram of a security document with an RFID label attached 29 Information printed on the ticket 30 RFID 31 Unique ID "233445" visualized for convenience 32 Invisible Information 33 Tally-like machine-readable code 34 Security documents printed with security patterns containing obfuscated information 35 Information printed on the ticket 36 Machine Readable Code 37 Difficult to read information "NPB" 38 Schematic diagram of a copy of the falsified document 39 Information altered to read "Printing Hanako" 40. Obfuscated information “NPB” 41 Two convex lenses 42 Laser light source 43 CMOS camera 44 Bandpass filter (670nm) 45 Card-type security documents 46 Showing an angle of 30 degrees
Claims
1. The base material has first information and face-printed information on at least a portion thereof, i) a summary value of information obtained by linking the first information and the information printed on the face of the card; ii) Encrypted data obtained by encrypting the information written on the card using the first information as a key. A security document having at least one machine-readable code encoding one of The first information is iii) A substrate characteristic value extracted from the substrate iv) Invisible Information v) Obfuscated information A security document characterized by being at least one selected from the following.
2. In the machine-readable code, second information is further linked to the first information, The second information is vi) Any information previously shared between the issuer and verifier of the security document. vii) Information formed on a hologram attached to or embedded in the substrate viii) Information recorded on an RFID attached to or contained in the base material 2. The security document according to claim 1, wherein the security document is at least one selected from the following:
3. 3. The security document according to claim 2, wherein in the case of vii) and / or viii) of claim 2, the machine-readable code is formed at a position overlapping either or both of the hologram and the RFID.
4. A verification method including detection of tampering of a security document according to any one of claims 1 to 3, comprising: a calculation means for calculating the digest value formed on the security document; decoding means for decoding the machine-readable code formed on the security document; A method for verifying a security document, comprising: comparing and collating the digest value obtained by the digest value calculation means with the information obtained by the decoding means, and performing verification including detection of tampering.
5. A verification method including detection of tampering of a security document according to any one of claims 1 to 3, comprising: A method for verifying a security document, comprising: decoding the machine-readable code; comparing and matching the information obtained by decrypting the encrypted data with the information written on the face of the document; and performing verification including detection of tampering.
Citation Information
Patent Citations
Alteration preventing paper
JP1988182496A
Device and method of determining genuineness of banknote, device and method of registering surface characteristics of banknote, system of determining genuineness of banknote, device and method of printing card, device and method of determining genuineness of card, system of determining genuineness of card, and card
JP2007213148A
Method and apparatus for authenticating products
JP2008542916A
PUF-based composite security marking for anti-counterfeiting
JP2020515099A
Electronic approval information printing device and print verification device
JP2875450B2