Authentication system, authentication server device, authentication method and program

The authentication system addresses spoofing risks in biometric systems by using temporary conversion keys and update information to encrypt and secure biometric data, preventing unauthorized access even if data is leaked.

JP7779387B2Active Publication Date: 2025-12-03NEC CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2024526138
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-06-09
Publication Date
2025-12-03
Estimated Expiration
2042-06-09

Smart Images

  • Figure 0007779387000001
    Figure 0007779387000001
  • Figure 0007779387000002
    Figure 0007779387000002
  • Figure 0007779387000003
    Figure 0007779387000003
Patent Text Reader

Abstract

Provided are: an authentication system that helps prevent impersonation (replay attacks) due to leakage of authentication query data in a biometric authentication system; and a corresponding authentication server device, authentication method, and program. An authentication system is provided that comprises: an authentication client device having a temporary conversion unit that receives a feature amount for receiving authentication and that converts the feature amount to authentication query data using a temporary conversion parameter; and an authentication server device having a registered feature amount data holding unit that holds registered feature amount data generated in response to reception of a feature amount for registration in a system, and a matching unit that performs matching on the basis of registered feature amount data and the authentication query data.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to an authentication system, an authentication server device, an authentication method, and a program. [Background technology]

[0002] In recent years, issues regarding biometric information registered in biometric authentication have come to light. This is because biometric authentication is personal information, and its leakage itself poses a privacy issue. Since biometric information cannot be discarded or updated even if it is leaked, if it is leaked, the security of all authentication systems that use the same biometric information will be lost.

[0003] On the other hand, standardization organizations such as ISO (International Organization for Standardization) and ITU-T (International Telecommunication Union Telecommunication Standardization Sector) also require, as standards for protecting biometric information, that even server administrators cannot obtain the original biometric information and that protected biometric information can be invalidated.

[0004] Patent Document 1 discloses a system for detecting fraudulent authentication data during matching in authentication using biometric information. In this system, enrollment data (template) to be registered in the system and authentication data to be matched are homomorphically encrypted at the time of enrollment and matching, respectively, and matching is performed while the data remains encrypted. This makes it possible to prevent the enrollment data and authentication data from being fraudulently used for authentication of other systems due to leakage of the authentication data or enrollment data due to theft or other reasons. [Prior art documents] [Patent documents]

[0005] [Patent Document 1] Japanese Patent Application Laid-Open No. 2016-118984 Summary of the Invention [Problem to be solved by the invention]

[0006] The disclosures of the above prior art documents are incorporated herein by reference. The following analysis has been carried out by the present inventors.

[0007] As in Patent Document 1, it is possible to prevent the leakage of plaintext biometric features by encrypting the enrollment data (template) and authentication data, but it is possible to spoof using the leaked enrollment data and authentication data in the system from which they were leaked. In this regard, by introducing random numbers into the enrollment data that cancel each other out between the template and the query in the calculations during matching, it is possible to make it impossible to perform matching calculations between enrollment data (templates), and it is possible to prevent spoofing by using enrollment data as authentication data.

[0008] However, if authentication data (queries) are leaked, the above countermeasures will allow spoofing because the data will be accepted as authentication unless the registration data and authentication data are re-encrypted. Since authentication data is likely to be stolen through phishing attacks, etc., countermeasures are recommended in light of the above circumstances.

[0009] An object of the present invention is to provide an authentication system, an authentication server device, an authentication method, and a program that contribute to preventing spoofing (replay attack) caused by leakage of authentication query data in a biometric authentication system. [Means for solving the problem]

[0010] According to a first aspect of the present invention and disclosure, there is provided an authentication system including: an authentication client device having a temporary conversion unit that receives features for authentication and converts the features using temporary conversion parameters to generate authentication query data; a registered feature data storage unit that stores registered feature data generated by receiving features to be registered in the system; and a matching unit that performs matching based on the registered feature data and the authentication query data.

[0011] According to a second aspect of the present invention and disclosure, there is provided an authentication server device having: a registered feature data storage unit that stores registered feature data generated by receiving features to be registered in a system; and a matching unit that performs matching based on authentication query data obtained by receiving features to be authenticated and converting the features using temporary conversion parameters, and the registered feature data.

[0012] According to a third aspect of the present invention and disclosure, there is provided an authentication method including the steps of receiving features for authentication and converting the features using temporary conversion parameters to generate authentication query data, receiving features to be registered in a system and storing the generated registered feature data, and performing matching based on the registered feature data and the authentication query data.

[0013] According to a fourth aspect of the present invention and disclosure, there is provided a program for causing a computer to execute a process of storing and retaining in a memory registered feature data that holds registered feature data generated by receiving features to be registered in a system, and matching the registered feature data with authentication query data obtained by converting the features for authentication using temporary conversion parameters. [Effects of the Invention]

[0014] According to each aspect of the present invention and disclosure, the present invention provides an authentication system, an authentication server device, an authentication method, and a program that contribute to preventing spoofing (replay attack) due to leakage of authentication query data in a biometric authentication system. [Brief explanation of the drawings]

[0015] [Figure 1] FIG. 1 is a schematic diagram illustrating an overview of processing in an authentication system according to an embodiment. [Figure 2] 1 is a block diagram illustrating an example of a configuration of an authentication system according to an embodiment. [Figure 3] FIG. 10 is a schematic diagram illustrating an overview of another process of the authentication system according to an embodiment. [Figure 4] FIG. 2 is a schematic diagram showing an overview of the processing of the authentication system according to the first embodiment. [Figure 5] FIG. 10 is a schematic diagram showing an overview of another process of the authentication system according to the first embodiment. [Figure 6] 1 is a block diagram showing an example of the configuration of an authentication system according to a first embodiment. [Figure 7] 4 is a flowchart showing the operation of the authentication system according to the first embodiment. [Figure 8] 1 is a schematic diagram showing a hardware configuration of an authentication system according to a first embodiment. [Figure 9] FIG. 10 is a schematic diagram illustrating an overview of the processing of an authentication system according to a second embodiment. [Figure 10] FIG. 10 is a schematic diagram illustrating an overview of another process of the authentication system according to the second embodiment. [Figure 11] FIG. 10 is a block diagram showing an example of the configuration of an authentication system according to a second embodiment. [Figure 12] FIG. 10 is a diagram showing the flow of operations of the authentication system according to the second embodiment. [Figure 13] FIG. 10 is a diagram showing another operational flow of the authentication system according to the second embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0016] [Processing Overview of One Embodiment] First, an overview of the processing of one embodiment will be described. Note that the reference numerals in the drawings attached to each element in this overview are provided for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, the connection lines between blocks in each figure include both bidirectional and unidirectional lines. Unidirectional arrows are used to schematically indicate the flow of the main signal (data) and do not exclude bidirectionality. Furthermore, although not explicitly shown, input and output ports exist at the input and output ends of each connection line in the circuit diagrams, block diagrams, internal configuration diagrams, connection diagrams, and the like shown in this disclosure. The same applies to input and output interfaces.

[0017] 1 is a schematic diagram showing an overview of the processing of an authentication system according to an embodiment. As shown in this diagram, at the time of enrollment, biometric information is accepted by an enrollment client, and a feature x is extracted. This is then registered as enrollment data T in a registered feature database.

[0018] During authentication, the authentication client receives the biometric information to be authenticated and extracts the feature value y. Next, the temporary conversion key K s is generated. K s may be generated by the authentication server or by a separate server that generates keys. s The transformation F is applied to the matching data T' after transformation F is given by ks (y) is sent to the authentication server.

[0019] Here, it is assumed that the transformation F uses a method such as homomorphic encryption, which allows matching (calculation of similarity) while the data remains encrypted, but which has the property that matching fails if the key is different.

[0020] The authentication server compares the registered data with the matching data. s Since all registered features to be matched are transformed by Fks Applying x to F ks Update to (x) and perform matching.

[0021] In this way, by generating a temporary conversion key during authentication and converting (encrypting) the verification data, the verification data converted with a different key is sent to the authentication server each time a key is generated. This means that even if the verification data is leaked due to theft or other reasons, a different conversion key is generated to convert the verification data. Because the converted key is different, even if the leaked verification data is sent to the authentication server again, verification is impossible, and authentication fails.

[0022] [Configuration of one embodiment] Next, the configuration of an authentication system according to an embodiment will be described with reference to the drawings. FIG. 2 is a block diagram showing an example of the configuration of an authentication system according to an embodiment. As shown in this diagram, the authentication system according to an embodiment includes an authentication client device 10 and an authentication server device 11. The authentication client device 10 has a temporary conversion unit 12. The authentication server device 11 has a registered feature data storage unit 13 and a matching unit 14.

[0023] Although not shown, the authentication server device 11 may have a temporary conversion parameter generation unit that generates a temporary conversion key. The temporary conversion parameter generation unit may be included in a device different from the authentication client device 10 and the authentication server device 11.

[0024] The temporary conversion unit 12 receives the feature amount for authentication in the authentication client device 10, and converts the feature amount using the temporary conversion parameters to generate authentication query data.

[0025] The "authentication query data" is data to be compared with registered features. In this embodiment, this refers to data sent from the authentication client device 10 to the authentication server device 11 to be compared with registered features stored in the registered feature data storage unit 13 by the matching unit 14 of the authentication server device 11.

[0026] The registered feature data holding unit 13 holds registered feature data generated in the authentication server device 11 upon receiving features to be registered in the system.

[0027] The matching unit 14 performs matching based on the registered feature data and the authentication query data. In an authentication system according to an embodiment, the matching unit 14 matches the authentication query data with data converted based on the registered feature data.

[0028] [Another Processing Overview of an Embodiment] 3 is a schematic diagram showing an overview of another process of the authentication system according to an embodiment. As shown in this figure, the temporary conversion key K s is generated, and the feature data y to be authenticated is ks The conversion is performed by the following. The result of the conversion is the matching data T' = F ks (y) is sent to the authentication server, and before verification, the authentication server uses the temporary conversion key K s By performing the inverse transformation using ks Calculate y from (y) and compare it with the registered feature x.

[0029] Here, "inverse transformation" means, for example, transforming feature data y into F ks Convert it to F ks (y), the conversion key K s Using F ks It refers to obtaining y from (y).

[0030] That is, the matching unit 14 of the authentication server device 11 performs inverse conversion based on the authentication query data, and matches the resulting data y with the registered feature amount data x. ks It is necessary to use a conversion method that allows for inverse conversion.

[0031] In the process shown in the overview of the other process above, the conversion of features executed on the authentication server device 11 side for matching only needs to be executed once for the matching data T', and therefore, processing can be performed faster than the form in which all registered features to be matched are converted as shown in the overview of the one embodiment above.

[0032] According to one embodiment of the authentication system, as described above, even if the biometric information to be authenticated is leaked during the authentication process, it is possible to prevent impersonation from passing the authentication of the system from which the information was leaked by generating a new temporary conversion key.

[0033] Specific embodiments will be described in more detail below with reference to the drawings. Note that the same components in each embodiment are denoted by the same reference numerals, and the description thereof will be omitted.

[0034] [First embodiment] In the authentication system according to the embodiment, when features are registered in the system, the registered feature data is sent to the authentication server in plain text. Therefore, if the registered feature data (template) is leaked, there is a possibility that the features may be reused in other biometric authentication systems.

[0035] In the authentication system of this embodiment, at the time of registration, the registration client can convert (encrypt) the feature to be registered using the conversion key K. As a result, the feature to be registered at the time of registration is not sent in plain text from the registration client to the authentication server and stored in the registered feature database, but is stored in a converted (encrypted) state.

[0036] [Overview of the processing of the first embodiment] 4 is a schematic diagram showing an overview of the processing of the authentication system according to the first embodiment. As shown in this figure, a conversion key K is generated in advance, and the feature x acquired at the time of registration is converted using K to obtain F. k (x) and then register it in the registered feature database of the authentication server device.s Each time a temporary conversion key K is generated, s Update information Δ(K,K s ) is generated. For this generation process, a method of generating a re-encryption key for proxy re-encryption, for example, can be adopted. When matching, the registered feature is used as input to create updated registered feature using the generated update information, and matching is performed. That is, K s Every time a feature is generated, all registered features are updated with the generated update information. k (x) F ks (x) and verify it. The authentication client updates the temporary conversion key K s The matching data T' = F ks (y) is sent to the authentication server for verification.

[0037] [Outline of another process of the first embodiment] 5 is a schematic diagram showing an overview of another process of the authentication system according to the first embodiment. In another form of the authentication system according to the present embodiment, the authentication server s Update information Δ(K s ,K), the verification data T' = F sent from the authentication client ks Update the feature of (y) and F k It is possible to perform matching processing as (y).

[0038] [Configuration of the first embodiment] Next, the configuration of the authentication system according to the first embodiment will be described with reference to the drawings. FIG. 6 is a block diagram showing an example of the configuration of the authentication system according to this embodiment. As shown in this diagram, the authentication system according to this embodiment includes an authentication client device 10 and an authentication server device 11. The authentication client device 10 has a temporary conversion unit 12. The authentication server device 11 has a registered feature data storage unit 13, a matching unit 14, and a first (second) update information generation unit 15 (16).

[0039] The temporary conversion unit 12 in the authentication client device 10 receives features for authentication and converts the features using temporary conversion parameters to generate authentication query data. The "features for authentication" are vector data extracted and digitized from video captured by a device such as a camera by performing predetermined image processing. The "temporary conversion parameters" are parameters (encryption keys) used to perform a predetermined conversion F (encryption) on the features for authentication. In principle, it is desirable to generate new temporary conversion parameters when an authentication request is made by the authentication client. However, temporary conversion parameters do not necessarily have to be generated for each authentication request; they may be generated at any time, for example, when an external attack is suspected.

[0040] Furthermore, the "temporary conversion parameter" may be generated by a device different from the authentication client device 10 and the authentication server device 11, for example, a random number used to generate a password or a seed may be generated by a hardware device such as one used to generate one-time passwords, and then sent to the authentication client device 10, etc.

[0041] The registered feature data storage unit 13 receives features to be registered in the system and stores the generated registered feature data. "Features to be registered in the system" refers to information that serves as a template used during authentication. In the authentication system of this embodiment, as shown in FIGS. 4 and 5, the authentication server and the registration client use a common key K (predetermined transformation parameters) to convert the features to be registered in the system into converted registered feature data. This converted registered feature data is sent to the authentication server and stored in the registered feature database. This common key K is generated at least once when the authentication system operates, and when K is updated, all registered features stored in the authentication server must be overwritten.

[0042] 4 and 5, the conversion process is performed at the registration client, and the converted registered feature data is sent to the authentication server. Although the above conversion process may be performed at the authentication server, it is preferable to perform the conversion at the registration client side, since the plaintext feature data will be transmitted over the communication path.

[0043] The first update information generating unit 15 generates first update information for updating data converted with predetermined conversion parameters to data converted with the temporary conversion parameters. s Whenever is generated, A temporary conversion key K consisting of temporary conversion parameters is generated from the conversion key K consisting of predetermined conversion parameters. s Update information Δ(K,K s )

[0044] Here, the second update information generating unit 16 generates second update information for updating the data converted with the temporary conversion parameters to data converted with predetermined conversion parameters, in contrast to the first update information generating unit 15. At the time of authentication, a temporary conversion key K s Each time a temporary transformation key K is generated, s to the conversion key K consisting of predetermined conversion parameters. s ,K).

[0045] The matching unit 14 performs matching based on the registered feature data and the authentication query data. In the case of a configuration including a first update information generation unit 15 (FIG. 4), update information Δ(K,K s ) to F k (x) to F ks (x) and update it to T´=F ks Match with (y).

[0046] In the case of a configuration having the second update information generating unit 16 (FIG. 5), the update information Δ(K s ,K) and T´=F ks (y) to F k (y) and then update the registered feature data F kMatch with (x).

[0047] [System Operation] 7 is a flowchart showing the operation of the authentication system according to the first embodiment. FIG. 7 shows a series of operations until authentication is successful during system authentication. First, a temporary conversion key K s (Step S11). Next, biometric information of the subject of authentication is received and a feature is extracted (Step S12). Next, the extracted feature is converted into a temporary conversion key K s Convert it to F ks Next, the first update information Δ(K,K s ) or the second update information Δ(K s , K) is generated (step S14). Next, all the feature quantities F k (x) (or authentication query data F ks ( y ) is updated (step S15).

[0048] Next, matching is performed (step S16). Specifically, the updated converted registered feature data F ks (x) and the authentication query data F ks The similarity is calculated by calculating the distance between the (y) and the temporary conversion key K. If the similarity is within the predetermined acceptance criteria, it is accepted (step S16: OK). s If the result does not meet the acceptance criteria, the result is not accepted (step S16: NG), and the process returns to step S12 where biometric information is received and features are extracted.

[0049] [Hardware configuration] The authentication system of this embodiment can be executed by an information processing device (computer), and is composed of an authentication client device 10 and an authentication server device 11, with the configuration shown in Fig. 8. The authentication client device 10 and the authentication server device 11 each include a CPU (Central Processing Unit) 101, a memory 102, an input / output interface 103, and a NIC (Network Interface Card) 104 as a communication means, which are interconnected by an internal bus 105.

[0050] However, the configuration shown in Fig. 8 is not intended to limit the hardware configuration of the authentication system. The authentication client device 10 and the authentication server device 11 may include hardware not shown, and may not be equipped with the input / output interface 103 as necessary. Furthermore, the number of CPUs and other components included in these devices is not intended to be limited to the example shown in Fig. 8; for example, the authentication client device 10 and the authentication server device 11 may include multiple CPUs.

[0051] The memory 102 is a RAM (Random Access Memory), a ROM (Read Only Memory), or an auxiliary storage device (such as a hard disk).

[0052] The input / output interface 103 is a means for interfacing with a display device and an input device (not shown). The display device is, for example, a liquid crystal display. The input device is, for example, a camera or sensor that receives biometric information, and a device that receives user operations such as a keyboard or mouse.

[0053] The functions of the authentication client device 10 and the authentication server device 11 are realized by a group of programs (processing modules) stored in memory 102, such as a temporary conversion program, a first (second) update information generation program, a matching program, etc., and a group of data, such as parameters, used by each program. The processing modules are realized, for example, by the CPU 101 executing each program stored in memory 102. The programs can be updated by downloading them over a network or using a storage medium storing the programs. Furthermore, the processing modules may be realized by semiconductor chips. That is, it is sufficient if there is some means for executing the functions performed by the processing modules using some kind of hardware and / or software.

[0054] [Hardware operation] When the authentication system starts operation, the temporary conversion program is called from the memory 102 in the authentication client device 10 and is put into execution by the CPU 101. The program generates and acquires the temporary conversion parameter K s The input / output interface 103 converts (encrypts) the feature extracted from the biometric information y acquired by the input / output interface 103 using the conversion key F. ks (y) is sent to the authentication server device 11 via the NIC 104 or the like.

[0055] The authentication server device 11 stores in the memory 102 the converted registered feature F converted by a predetermined conversion parameter K. k (x) is stored in the memory 102. Here, the first (second) update information generation program is called from the memory 102 and is executed on the CPU 101. This program is capable of converting data converted with keys based on two different conversion parameters by updating. The first update information generation program converts the update information Δ(K,K s ) The second update information generation program generates update information Δ(K s ,K).

[0056] Next, the matching program is called by the memory 102 and executed by the CPU 101. The program updates the transformed feature quantity using the update information Δ and performs matching. Specifically, the update information Δ(K,K s ) to convert the registered feature F k (x) and the temporary transformation parameter K s Feature F using ks (x) and update it to the same parameter K s F from the authentication client device, converted using ks (y) and F ks (x) and F ks The distance between (y) is calculated to determine the similarity. If the distance between the two is less than a predetermined value, it is accepted, and if it is greater than the predetermined value, it is rejected.

[0057] Similarly, the update information Δ(K s , K), the matching program uses this to convert the converted feature F sent from the authentication client device 10. ks (y) is calculated by F using the updated information Δ k (y), and the converted registered feature F stored in the memory 102 k Execute a match with (x). The specific process of matching has been described above, so details are omitted here.

[0058] [Effect description] As described above, the authentication system of this embodiment makes it possible to conceal the registered feature by conversion, and also eliminates the need to rewrite the registered feature database for matching even when a new temporary conversion key is generated, and enables matching by updating the registered feature (after conversion) using update information at the time of matching. Furthermore, when generating the temporary conversion key, it is not necessary to distribute the conversion key to all authentication clients, and it is sufficient to distribute it only to the authentication client and authentication server requesting authentication, which has the effect of reducing key distribution costs and improving security.

[0059] Furthermore, as described in [Outline of another process of the first embodiment], by using the update information to update the key that converts the authentication query data during matching (temporary conversion parameter → predetermined conversion parameter), data updating can be completed only once per authentication. Therefore, as described in [Configuration of the first embodiment], there is an advantageous effect that processing can be executed faster than updating all of the converted registered features with the update information.

[0060] [Overview of the processing of the second embodiment] As described in the above embodiment, by using the update information Δ of the conversion key (conversion parameter), the temporary conversion key K s 3 and 4, a predetermined conversion key (conversion parameter) K and the registered feature data converted by the conversion key are both stored in the same authentication server, and there remains a concern that if the authentication server is attacked, the registered feature data may be decrypted by K and plaintext features may be leaked.

[0061] In this embodiment, an authentication system is provided that has the same effects as the above-described embodiments, but does not use K, which is a predetermined conversion parameter, in the authentication server.

[0062] 9 is a schematic diagram showing an overview of the processing of the authentication system according to the second embodiment. As shown in this diagram, a predetermined conversion key K is first delivered to a registration client at the time of registration, and the feature x to be registered in the system is converted to the converted registered feature data F k The result is stored as (x) in the registered feature database of the authentication server.

[0063] During authentication, a temporary conversion key K s is generated and sent to the authentication client device, the conversion key K and the temporary conversion key K s and the combined transformation key K s During authentication, the authentication client device generates a synthetic transformation key Ks Convert with K and use T´=F as authentication query (matching) data {ks·k} (y)=F ks (F k (y)) is sent to the authentication server as an authentication query. The authentication server then sends the temporary conversion key K s and obtain the registered transformed feature data F k (x) to K s Reconvert with F ks (F k (x)) and authentication query T´=F ks (F k (y)) and match it.

[0064] [Outline of another process of the second embodiment] 10 is a schematic diagram showing an outline of another process of the authentication system according to the second embodiment. As shown in this figure, in the process of FIG. 9, the converted registered feature data is reconverted and compared with the synthetically converted authentication query (matching) data. In the outline of the other process, the synthetic transformation key K s ·Features T´=F transformed by K {ks·k} (y)=F ks (F k By utilizing the property that (y)) is reversible, the converted authentication query (matching) data is converted into F k (y) is obtained, and the registered feature F k Match with (x).

[0065] [Configuration of the second embodiment] Next, the configuration of an authentication system according to a second embodiment will be described with reference to the drawings. FIG. 11 is a block diagram showing an example of the configuration of an authentication system according to this embodiment. As shown in this diagram, the authentication system according to this embodiment includes an authentication client device 10 and an authentication server device 11. The authentication client device 10 has a temporary conversion unit 12 and a composite conversion parameter generation unit 17. The authentication server device 11 has a registered feature data storage unit 13 and a matching unit 14. A feature of this embodiment is that the authentication client device 10 further includes the composite conversion parameter generation unit 17.

[0066] The composite transformation parameter generating unit 17 performs a transformation using a predetermined parameter (K) and a transformation using the temporary transformation parameter (K s The generated composite transformation parameters are sent to the temporary transformation unit 12.

[0067] In this embodiment, the temporary conversion unit 12 receives the composite conversion parameters from the composite conversion parameter generation unit 17, converts the feature amount for authentication, and generates the composite converted authentication query data.

[0068] In this embodiment, the matching unit 14 in the authentication server device 11 converts the converted registered feature data again using temporary conversion parameters, and performs matching with the synthesized and converted authentication query data.

[0069] [Another configuration of the second embodiment] In this embodiment, in another configuration of the second embodiment corresponding to [Outline of another process of the second embodiment], based on the configuration of the second embodiment, the matching unit 14 inversely transforms the synthesized transformed authentication query data using temporary transformation parameters, and performs matching with the transformed registered feature data.

[0070] [System Operation] FIG. 12 is a diagram showing the flow of operation of the authentication system according to the second embodiment. In particular, this diagram shows the flow of authentication during the authentication system of this embodiment. As shown in this diagram, first, in the registration stage, a predetermined transformation parameter K is delivered to the authentication client device. In addition, in the authentication server device, a post-transformation registered feature F, which is a registered feature transformed by the predetermined transformation parameter K, is delivered to the authentication client device. k (x) is stored.

[0071] When an authentication request is made from the authentication client device, a temporary conversion parameter K s is generated and delivered to the authentication client device and the authentication server device. smay be generated by the authentication server device or by an independent temporary conversion parameter generating device. Next, in the authentication client device, the composite conversion parameter K s On the other hand, in the authentication server device, a temporary transformation parameter K s Using this, the converted registered feature F k (x) to K s The reconversion is performed using the following formula, and the registered feature value F ks (F k Calculate (x).

[0072] The authentication client device receives the biometric information and extracts the authentication feature y. Then, the synthesis transformation parameter K s ·K is used to perform the conversion process, and F {ks·k} (y)=F ks (F k This is sent as an authentication query (matching data) to the authentication server device, where matching processing is performed.

[0073] [Another system behavior] 13 is a diagram showing another operational flow of the authentication system according to the second embodiment. The difference from the above is that after an authentication query (matching data) is sent from the authentication client device, the authentication server device converts a temporary conversion parameter K s After the inverse transformation (F ks (F k (y)) → F k (y)) is the feature F k (y) is obtained, and the converted registered feature F k A matching process with (x) is performed.

[0074] [Effect description] In the authentication system of this embodiment, a temporary conversion parameter K is calculated for the feature to be authenticated in the authentication client device. sBy performing temporary conversion using a composite conversion parameter of the predetermined conversion parameter K, the authentication server device does not need to process the predetermined conversion parameter K. The conversion parameter K and the converted registered feature data F are stored in memory. k (x) will no longer be stored, and the authentication server device will be attacked and both K and F k (x) and (x) are stolen, resulting in F k (x) is decrypted, reducing the risk of the plaintext feature x being leaked.

[0075] [Third embodiment] In the authentication systems of the first and second embodiments, if the authentication query and the corresponding temporary conversion key are leaked at the same time, spoofing can be performed by using both pieces of information. For example, if the authentication query T'=F ks (y) and temporary conversion key K s If the temporary conversion key K is leaked, the temporary conversion key K is sent from the authentication server device in another authentication process. t In contrast, K s and K. t Update information Δ(K s ,K t ) can be calculated. Δ(K s, K t ) to get T´=F ks (y) to F kt By updating it to (y) and sending it as an authentication query, the matching process will be successful. Also, if the conversion method is easy to calculate the inverse conversion, the feature y itself can be restored from the authentication query and the temporary conversion key.

[0076] Therefore, the authentication system of this embodiment is based on the authentication systems of the first and second embodiments, and uses secret information shared in advance between the authentication client device and the authentication server device to generate a temporary conversion key K s It is possible to prevent spoofing even if the authentication query and the password are leaked at the same time.

[0077] In the configuration described above in [Overview of the processing of the first embodiment], the authentication client device receives a temporary conversion key K s and a separate temporary conversion key Ku and generate an authentication query T´=F ku (y) is sent to the authentication server device. u and generate Δ(K,K u ) and calculate the registered feature F k (x) to K u F converted by ku Update to (x) and verify. K s and T´=F ku Since (y) has a different conversion key, it cannot be used for impersonation even if both are leaked at the same time.

[0078] In the configuration described above in [Outline of another process in the first embodiment], the update information Δ(K u ,K), and the matching query F ku (y) to Δ(K u ,K) and F k Update to (y) and verify.

[0079] In the configuration described above in [Overview of the processing of the second embodiment], the authentication client device receives a temporary conversion key K s and another temporary conversion key K from the shared secret information. u and generate an authentication query T´=F ku (F k (y)) is sent to the authentication server device. u and generate the registered feature F k (x) to K u F retransformed with ku (F k Update to (x) and verify. K s and T´=F ku (F k Since (y)) has a different conversion key, even if both are leaked at the same time, they cannot be used for impersonation.

[0080] In the configuration described above in [Outline of another process in the second embodiment], the authentication server device ku (F k (y)) to K u Inverse transformation is performed with F k Update to (y) and verify.

[0081] In the above embodiment, the shared secret information may be other than the temporary conversion key, such as the cancelable conversion key K used at the time of registration, or a "master parameter" previously shared between the authentication client and the authentication server. u Regarding the method of generating F, the shared secret is a given conversion key K. ku (*)=F k (F ks (*)) u The shared secret is the master parameter param, and the input random number seed for the key generation process (K s ||param) is given, the output is K u One possible method is to

[0082] [Fourth embodiment] The authentication system in the first embodiment requires the authentication server to always store a predetermined re-key K, which poses a security concern. The authentication system in this embodiment can prevent spoofing attacks that use the authentication query while storing only a portion of the predetermined re-key K (for example, only the latter half) on the authentication server.

[0083] The authentication system of the fourth embodiment is configured such that the authentication server device has a challenge generation unit (not shown) that generates a challenge and transmits it to the authentication client device, and a verification unit (not shown) that receives a response and performs verification using temporary conversion parameters, and the authentication client device has a temporary conversion unit that further converts the challenge using the temporary conversion parameters and transmits the converted response to the verification unit of the authentication server device, and the verification unit of the authentication server device performs verification using part of the predetermined conversion parameters.

[0084] The operation of the authentication system of this embodiment is as follows: first, the authentication server generates a random number sequence to be used when temporarily converting the authentication query and sends it to the authentication client as a challenge. Meanwhile, the authentication server device uses a portion of a predetermined conversion key K (for example, only the latter half) to convert the sent random number sequence and stores it as check data. When the authentication query is received, in addition to the normal matching process, it checks whether the value of the check data portion matches, and if there is a mismatch at even one point, the authentication is rejected.

[0085] In the authentication system of this embodiment, the authentication server device only needs to store a portion of the predetermined converted key K, which can reduce security concerns such as leakage due to attacks.

[0086] Some or all of the above-described embodiments can also be described as in the following supplementary notes. However, the following supplementary notes are merely examples of the present invention, and the present invention is not limited to such cases. [Appendix 1] This is the same as the authentication system related to the first aspect mentioned above. [Appendix 2] Preferably, the authentication system according to appendix 1, wherein the matching unit of the authentication server device transforms the registered feature data using temporary transformation parameters and performs matching. [Appendix 3] Preferably, the authentication system according to appendix 1, wherein the verification unit of the authentication server device performs verification by inversely transforming the authentication query data using the temporary transformation parameter. [Appendix 4] Preferably, the authentication system according to appendix 1, wherein the registered feature data storage unit of the authentication server device, when registering a feature to be registered in the system, stores converted registered feature data obtained by converting the feature using predetermined conversion parameters and registering the feature, and the matching unit matches the converted registered feature data with the authentication query data. [Appendix 5] Preferably, the authentication system of appendix 4, wherein the authentication server device further includes a first update information generation unit that generates first update information for updating data converted using predetermined conversion parameters to data converted using temporary conversion parameters, and the matching unit updates the converted registered feature data using the first update information and performs matching with the authentication query data. [Appendix 6] Preferably, the authentication system of Appendix 4, wherein the authentication server device further has a second update information generation unit that generates second update information for updating data converted using temporary conversion parameters to data converted using predetermined conversion parameters, and the matching unit updates the authentication query data using the second update information and performs matching with the converted registered feature data. [Appendix 7] Preferably, the authentication system according to Supplementary Note 4, wherein the authentication client device has a composite transformation parameter generation unit that generates composite transformation parameters for performing a transformation that combines a transformation using predetermined parameters and a transformation using temporary transformation parameters, the temporary transformation unit converts features for authentication using the composite transformation parameters to generate composite-transformed authentication query data, and the authentication server device has a matching unit that converts the converted registered feature data again using the temporary transformation parameters and performs matching with the composite-transformed authentication query data. [Appendix 8] Preferably, the authentication system according to appendix 4, wherein the authentication client device has a composite transformation parameter generation unit that generates composite transformation parameters for performing a transformation that combines a transformation using predetermined parameters and a transformation using temporary transformation parameters, the temporary transformation unit transforms features for authentication using the composite transformation parameters to generate composite-transformed authentication query data, and the authentication server device has a matching unit that inversely transforms the composite-transformed authentication query data using the temporary transformation parameters and performs matching with the converted registered feature data. [Appendix 9] Preferably, the authentication system of any one of appendices 5 to 8, wherein the authentication client device has a first secret information temporary conversion parameter generation unit that generates a secret information temporary conversion parameter using secret information shared with the authentication server device and the temporary conversion parameter, and the temporary conversion unit converts the feature for authentication using the secret information temporary conversion parameter instead of the temporary conversion parameter to generate authentication query data after temporary conversion of secret information, and the authentication server device has a second secret information temporary conversion parameter generation unit that generates a secret information temporary conversion parameter using the secret information shared with the authentication client device and the temporary conversion parameter. [Appendix 10] Preferably, in the authentication system of Supplementary Note 9, the matching unit of the authentication server device converts the converted registered feature data using the secret information temporary conversion parameter, and performs matching with the secret information temporarily converted authentication query data. [Appendix 11] Preferably, in the authentication system of Supplementary Note 9, the matching unit of the authentication server device converts the authentication query data after temporary secret information conversion using the temporary secret information conversion parameter, and performs matching with the registered feature amount data. [Appendix 12] Preferably, the authentication server device has a challenge generation unit that generates a challenge and sends it to the authentication client device, and a verification unit that receives a response and verifies it using temporary conversion parameters, and the authentication client device has a temporary conversion unit that further converts the challenge using the temporary conversion parameters and sends it as a response to the verification unit of the authentication server device, in an authentication system as described in Appendix 5 or 6. [Appendix 13] 13. The authentication system of claim 12, wherein the authentication server device has a verification unit that performs verification using a portion of the predetermined conversion parameters. [Appendix 14] This is the same as the authentication server device according to the second aspect described above. [Appendix 15] This is the same as the authentication method relating to the third aspect described above. [Appendix 16] This is the same as the program related to the fourth perspective mentioned above.

[0087] The disclosures of the above-cited patent documents and other documents are incorporated herein by reference. Modifications and adjustments of the embodiments are possible within the scope of the entire disclosure of the present invention (including the claims), and further based on the basic technical concepts thereof. Furthermore, various combinations and selections (including partial deletions) of various disclosed elements (including each element of each claim, each embodiment, each element of each embodiment, each element of each drawing, etc.) are possible within the scope of the entire disclosure of the present invention. In other words, the present invention naturally includes various modifications and alterations that would be possible by a person skilled in the art in accordance with the entire disclosure and technical concepts, including the claims. In particular, with regard to the numerical ranges set forth herein, any numerical value or subrange included within the range should be construed as specifically set forth, even if not otherwise specified. [Explanation of symbols]

[0088] 10: Authentication client device 11: Authentication server device 12: Temporary conversion section 13: Registered feature data storage unit 14: Matching section 15:First update information generation section 16:Second update information generation section 17: Synthesis transformation parameter generation unit 101: CPU 102: Memory 103: Input / output interface 104:NIC 105: Internal bus

Claims

1. a temporary conversion unit that receives a feature for authentication, converts the feature using a temporary conversion parameter to generate authentication query data, and converts a challenge transmitted from the authentication server device using the temporary conversion parameter to generate a response, and transmits the response to a verification unit of the authentication server device; an authentication client device having a registered feature data storage unit that stores converted registered feature data obtained by converting registered feature data generated by receiving features to be registered in the system using predetermined conversion parameters; a first update information generation unit that generates first update information for updating the data converted using the predetermined conversion parameters to the data converted using the temporary conversion parameters; a challenge generation unit that generates the challenge and transmits it to the authentication client device; a verification unit that receives the response and performs verification using the temporary conversion parameter; a matching unit that updates the converted registered feature data using the first update information and performs matching with the authentication query data; an authentication server device having Authentication system including.

2. a temporary conversion unit that receives a feature for authentication, converts the feature using a temporary conversion parameter to generate authentication query data, and converts a challenge transmitted from the authentication server device using the temporary conversion parameter to generate a response, and transmits the response to a verification unit of the authentication server device; an authentication client device having a registered feature data storage unit that stores converted registered feature data obtained by converting registered feature data generated by receiving features to be registered in the system using predetermined conversion parameters; a second update information generation unit that generates second update information for updating the data converted using the temporary conversion parameters to the data converted using the predetermined conversion parameters; a challenge generation unit that generates the challenge and transmits it to the authentication client device; a verification unit that receives the response and performs verification using the temporary conversion parameters; a matching unit that updates the authentication query data using the second update information and performs matching with the converted registered feature data; an authentication server device having Authentication system including.

3. the authentication client device, a first secret information temporary conversion parameter generation unit that generates a secret information temporary conversion parameter using secret information shared with the authentication server device and the temporary conversion parameter, and replaces the temporary conversion parameter with the generated secret information temporary conversion parameter; and The authentication server device a second secret information temporary conversion parameter generation unit that generates the secret information temporary conversion parameter using secret information shared with the authentication client device and the temporary conversion parameter, and replaces the temporary conversion parameter with the generated secret information temporary conversion parameter; 3. The authentication system according to claim 1, further comprising:

4. In the authentication server device, a step of converting registered feature data, which is a feature to be registered in the system, using predetermined conversion parameters to generate converted registered feature data and storing the converted registered feature data in a memory; a challenge generation step in the authentication server device of generating a challenge and transmitting the challenge to the authentication client device; a temporary conversion step of extracting, in the authentication client device, an authentication feature that is a feature for receiving authentication, and converting the authentication feature using a temporary conversion parameter to generate authentication query data; a response transmission step of converting the challenge using the temporary conversion parameter in the authentication client device and transmitting the converted challenge as a response to the authentication server device; a first update information generation step in the authentication server device of generating first update information for updating the data converted using the predetermined conversion parameters to data converted using the temporary conversion parameters; a verification step in the authentication server device of receiving the response and performing verification using the temporary conversion parameter; a matching step of updating, in the authentication server device, the converted registered feature data using the first update information to generate updated registered feature data, and matching the generated updated registered feature data with the authentication query data; authentication methods, including

5. In the authentication server device, a step of converting registered feature data, which is a feature to be registered in the system, using predetermined conversion parameters to generate converted registered feature data and storing the converted registered feature data in a memory; a challenge generation step in the authentication server device of generating a challenge and transmitting the challenge to the authentication client device; a temporary conversion step of extracting, in the authentication client device, an authentication feature that is a feature for receiving authentication, and converting the authentication feature using a temporary conversion parameter to generate authentication query data; a response transmission step of converting the challenge using the temporary conversion parameter in the authentication client device and transmitting the converted challenge as a response to the authentication server device; a second update information generating step in the authentication server device of generating second update information for updating the data converted using the temporary conversion parameters to data converted using the predetermined conversion parameters; a verification step in the authentication server device of receiving the response and performing verification using the temporary conversion parameter; a matching step of updating, in the authentication server device, the authentication query data using the second update information to generate updated authentication query data, and matching the converted registered feature data with the generated updated authentication query data; authentication methods, including

6. A temporary conversion process that extracts authentication features, which are features for authentication, and converts the authentication features using temporary conversion parameters to generate authentication query data; a response transmission process for, upon receiving a challenge from the authentication server device, converting the challenge using the temporary conversion parameters and transmitting the converted challenge as a response to the authentication server device; a program for causing a computer of an authentication client device to execute the above; A process of storing converted registered feature data, which is a feature to be registered in the system, by using predetermined conversion parameters and generating the converted registered feature data in a memory; a challenge generation process for generating the challenge and transmitting it to the authentication client device; a first update information generation process for generating first update information for updating the data converted using the predetermined conversion parameters to the data converted using the temporary conversion parameters; a verification process of receiving the response from the authentication client device and performing verification using the temporary conversion parameter; a matching process of updating the converted registered feature data using the first update information to generate updated registered feature data, and matching the generated updated registered feature data with the authentication query data; and a recording medium for storing a program for causing a computer of the authentication server device to execute the above.

7. A temporary conversion process that extracts authentication features, which are features for authentication, and converts the authentication features using temporary conversion parameters to generate authentication query data; a response transmission process for, upon receiving a challenge from the authentication server device, converting the challenge using the temporary conversion parameters and transmitting the converted challenge as a response to the authentication server device; a program for causing a computer of an authentication client device to execute the above; A process of storing converted registered feature data, which is a feature to be registered in the system, by using predetermined conversion parameters and generating the converted registered feature data in a memory; a challenge generation process for generating the challenge and transmitting it to the authentication client device; a second update information generation process for generating second update information for updating the data converted using the temporary conversion parameters to the data converted using the predetermined conversion parameters; a verification process of receiving the response from the authentication client device and performing verification using the temporary conversion parameter; a matching process of updating the authentication query data using the second update information to generate updated authentication query data, and matching the converted registered feature data with the generated updated authentication query data; and a recording medium for storing a program for causing a computer of the authentication server device to execute the above.

Citation Information

Patent Citations

  • Security information distribution device and system

    JP1999015789A

  • Individual authentication system, and authentication device and individual authentication method used for the individual authentication system

    JP2006209697A

  • Biometric authentication system and method therefor

    JP2010146245A

  • Biometrics authentication system and portable terminal

    JP2011165102A

  • Information processing method, information processing program, and information processing apparatus

    JP2016118984A