Server, authentication system, authentication method and program
Patent Information
- Application Number
- JP2024546669
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-09-16
- Filing Date
- 2022-09-16
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2042-09-16
AI Technical Summary
In large-scale SaaS environments, ensuring high-speed processing, high security, and privacy during biometric authentication is challenging due to the risks associated with unauthorized access and data privacy issues, particularly when biometric features are leaked or mishandled.
A server system that calculates and converts the degree of similarity between encrypted biometric feature amounts using homomorphic encryption and proxy re-encryption, allowing secure and efficient authentication without decrypting the feature amounts, thus maintaining confidentiality and privacy.
This approach enables high-speed and secure biometric authentication services by keeping the feature amounts secret and avoiding the need for decrypting and re-encrypting, ensuring high security and privacy protection.
Abstract
Description
Server, authentication system, authentication method and program
[0001] The present invention relates to a server, an authentication system, an authentication method, and a program.
[0002] SaaS (Software as a Service) can be provided on an account-by-account basis as long as a terminal device and an internet connection are available, and if multiple accounts are set up, services can be provided to multiple users. This ease of use and aggregation has led to the provision of a variety of services.
[0003] As mentioned above, SaaS allows multiple users to access a server via the Internet by setting up accounts and receiving services provided by application software. In large-scale SaaS, users exist across organizations such as companies and departments. This makes ensuring security between each account a problem. In particular, to prevent unauthorized access to confidential information, it is necessary to strictly manage passwords and IDs used in account authentication.
[0004] In recent years, biometric authentication has increasingly been adopted in place of IDs and passwords to prevent unauthorized access. However, once biometric features are leaked, access to other services using the leaked biometrics becomes possible. Therefore, care must be taken when handling the so-called templates used for biometric authentication and the biometric features acquired during authentication. Furthermore, when authentication is performed using SaaS, data on the biometric authentication template and the features acquired during authentication are passed on to the service provider when registering an account, which poses security issues. Furthermore, if the features are not encrypted, service operators can identify who authenticated to which service, which raises the need to consider privacy issues.
[0005] Japanese Patent Application Laid-Open No. 2008-021295
[0006] The disclosures of the above prior art documents are incorporated herein by reference. The following analysis has been carried out by the present inventors.
[0007] The invention of Patent Document 1 discloses a program on the service provider side that enables matching processing in a member matching service between groups while keeping user identification numbers encrypted, and that enables matching processing to be carried out without the results of matching being known to third parties such as the service provider.
[0008] However, the invention of Patent Document 1 encrypts the user identification IDs in a list included in the matching query information using a common key cryptosystem, and then encrypts the list of identification IDs arranged according to priority using the public key of the service provider's server in two stages. Furthermore, the matching results are processed using processing information included in the query before being sent to a relay computer, which poses a problem in terms of processing speed when implemented in an authentication service.
[0009] In addition, because the encryption key is generated using a common key cryptosystem on the relay computer, a private key must be distributed to the user's terminal for use, which poses a security risk. In particular, if a private key is obtained illegally, the impact could be significant in situations where a large number of terminals use it, such as authentication services.
[0010] SUMMARY OF THE INVENTION It is therefore an object of the present invention to provide a server, an authentication system, an authentication method and a program that contribute to ensuring high-speed processing, high security and privacy in an authentication service.
[0011] According to a first aspect of the present invention and disclosure, there is provided a server having a storage unit that stores an encrypted first feature, an acquisition unit that acquires an encrypted second feature received by a terminal, a calculation unit that calculates a similarity based on the first feature and the second feature, and a conversion / transmission unit that converts the similarity into a format that can be decoded by another server and transmits the similarity to the other server.
[0012] According to a second aspect of the present invention and disclosure, there is provided an authentication system including a server having a storage unit that stores an encrypted first feature, an acquisition unit that is received by a terminal and acquires an encrypted second feature, a calculation unit that calculates a similarity based on the first feature and the second feature, and a conversion / transmission unit that converts the similarity into a format that can be decoded by another server and transmits the similarity to the other server, wherein the acquisition unit acquires a user ID that identifies a user in association with the first feature, the calculation unit calculates the similarity based on the first feature and the second feature, each of which is encrypted, and the conversion / transmission unit transmits the similarity to the other server in association with the user ID, and the other server that decrypts the similarity and acquires a user ID based on the similarity and a predetermined criterion.
[0013] According to a third aspect of the present invention and disclosure, there is provided an authentication method including the steps of: a step of a computer storing an encrypted first feature; a step of the computer acquiring an encrypted second feature accepted by a terminal; a step of the computer calculating a similarity based on the first feature and the second feature; and a step of the computer converting the similarity into a format that can be decoded by another server and transmitting the similarity to the other server.
[0014] According to a fourth aspect of the present invention and disclosure, there is provided a program for causing a computer to execute the following processes: storing an encrypted first feature; acquiring an encrypted second feature accepted by a terminal; calculating a similarity based on the first feature and the second feature; and converting the similarity into a format that can be decoded by another server and transmitting the similarity to the other server.
[0015] According to each aspect of the present invention and disclosure, the present invention provides a server, an authentication system, an authentication method, and a program that contribute to ensuring high-speed processing, high security, and privacy in authentication services.
[0016] FIG. 1 is a block diagram showing an example of a server configuration according to an embodiment. FIG. 2 is a schematic diagram showing an overview of server processing according to a first embodiment. FIG. 3 is a block diagram showing an example of a server configuration according to the first embodiment. FIG. 4 is a flowchart showing server operation (key generation and storage of registered feature amounts) according to the first embodiment. FIG. 5 is a flowchart showing server operation (matching processing) according to the first embodiment. FIG. 6 is a schematic diagram showing a hardware configuration of a server according to the first embodiment. FIG. 7 is a block diagram showing an example of a server configuration according to a second embodiment. FIG. 8 is a sequence diagram showing an example of server operation (key generation) according to the second embodiment. FIG. 9 is a sequence diagram showing an example of server operation (feature registration) according to the second embodiment. FIG. 10 is a sequence diagram showing an example of server operation (matching) according to the second embodiment. FIG. 11 is a sequence diagram showing another example of server operation (key generation) according to the second embodiment. FIG. 12 is a sequence diagram showing another example of server operation (matching) according to the second embodiment.
[0017] [Overview of Processing of One Embodiment] First, an overview of processing of one embodiment will be described. Note that the drawing reference symbols attached to this overview are attached to each element for convenience as an example to facilitate understanding, and the description of this overview is not intended to be limiting in any way. Furthermore, the connection lines between blocks in each figure include both bidirectional and unidirectional. Unidirectional arrows are used to schematically indicate the flow of the main signal (data) and do not exclude bidirectionality. Furthermore, although not explicitly shown in the circuit diagrams, block diagrams, internal configuration diagrams, connection diagrams, etc. shown in this disclosure, input ports and output ports exist at the input and output ends of each connection line. The same applies to input / output interfaces.
[0018] [Configuration of an embodiment] Next, the configuration of a server according to an embodiment will be described with reference to the drawings. Fig. 1 is a block diagram showing an example of the configuration of a server according to an embodiment. As shown in this diagram, a server 10 according to an embodiment includes a storage unit 11, an acquisition unit 12, a calculation unit 13, and a conversion / transmission unit 14.
[0019] The storage unit 11 stores the encrypted first feature. The acquisition unit 12 acquires the encrypted second feature received from the terminal. The calculation unit 13 calculates a similarity based on the first feature and the second feature. The conversion / transmission unit 14 converts the similarity into a format that can be decoded by another server and transmits it to the other server.
[0020] According to one embodiment, in biometric authentication, the server can calculate the similarity between a first feature serving as a template and a second feature serving as authentication query information acquired from a terminal for attempting authentication, and convert the similarity into a format that can be decrypted by another server. In other words, the calculated similarity can be converted using a key that can be decrypted by another server. For example, by converting the calculated similarity into a feature encrypted using a key that can be decrypted using a private key present on a server that provides a service, which is another server, the authentication process can be performed without additional encryption, while keeping the first and second features confidential.
[0021] Specific embodiments will be described in more detail below with reference to the drawings. Note that the same components in each embodiment are denoted by the same reference numerals, and the description thereof will be omitted.
[0022] [First Embodiment] Fig. 2 is a schematic diagram showing an overview of server processing according to the first embodiment. As shown in this diagram, there is a server 10 that performs authentication processing, a server 21 that provides service A, and a server 22 that provides service B. The server 10 provides an authentication service as SaaS. Pre-registered features for authentication are encrypted and stored in the server 10. Note that Fig. 2 shows an example in which two services, A and B, exist for one authentication SaaS, but the number of services is not limited to two.
[0023] A user 23 who is about to use service A inputs biometric information into terminal 24. For example, in the case of facial authentication, the user points his or her face at a camera and inputs an image into the terminal. Features of the input image are extracted and encrypted by the terminal. The encrypted features are sent as an authentication query together with the service ID "A" to server 10, which is the authentication server.
[0024] The server 10 calculates the similarity with the registered feature. The calculation is performed between the registered feature and the feature of the authentication query, but both are homomorphically encrypted, so the calculation can be performed while they are still encrypted. The calculated encrypted similarity D 1 is encrypted with the authentication service key. Here, the proxy re-encryption method is used to convert the authentication service key to the service A key. The converted Enc(D 1 ) is sent to the server 21 of service A and decrypted on the server 21.
[0025] Decrypted D 1 is determined on the server 21 to see if it is within a predetermined range of values, i.e., within the acceptable range. If it is within the acceptable range, an OK message is sent to the terminal 24, and service A is permitted. If it is outside the acceptable range, an NG message is sent, and the authentication process ends.
[0026] The user 25 who is going to use service B also performs the same process. The difference is that the service ID "B" is sent to the server 10 as an authentication query, and the encrypted similarity score Enc(D 2 ) is sent to the server 22.
[0027] In this way, by calculating the similarity between the registered feature and the feature of the authentication query while keeping it encrypted, it is possible to perform the authentication process in a confidential state within the service provider server 10. Furthermore, by directly converting the calculated encrypted similarity key into the key of each service, it is possible to eliminate the need for processing such as decrypting once and then re-encrypting with the key of each service, thereby enabling high-speed processing.
[0028] [Configuration of the First Embodiment] Next, the configuration of the server 10 according to the first embodiment will be described with reference to the drawings. Fig. 3 is a block diagram showing an example of the configuration of the server 10 according to the present embodiment. As shown in this diagram, the server 10 according to the first embodiment includes a storage unit 11, an acquisition unit 12, a calculation unit 13, a conversion transmission unit 14, a key generation unit 15, and a conversion key acquisition unit 16.
[0029] The storage unit 11 stores the encrypted first feature. Various methods can be used for "encryption." The server of this embodiment uses a public key encryption method, but a common key encryption method may also be used. However, since a private key needs to be distributed, which can cause security issues, it is desirable to use a public key encryption method. The "first feature" is a so-called reference template for biometric information, and there are at least as many templates as there are pre-registered users.
[0030] The storage unit 11 may store a user ID (for each service) that identifies a user in association with the encrypted first feature amount.
[0031] The acquisition unit 12 acquires the encrypted second feature that is accepted by the terminal. The second feature is included in an authentication query used to attempt authentication. The second feature must be encrypted with at least the same key as that used for the first feature. The terminal acquires biometric information, and extracts the feature based on the biometric information. The extracted feature is encrypted and sent to the server 10. The server 10 receives the feature and sends it to the calculation unit 13 in the encrypted state.
[0032] The calculation unit 13 calculates the similarity based on the first feature amount and the second feature amount. Generally, the distance between the first feature amount vector and the second feature amount vector is used as the similarity. For example, various similarity measures can be used, such as Euclidean distance, Hamming distance, cosine similarity, and the square of Euclidean distance.
[0033] In this embodiment, in order to match the feature amounts while keeping them encrypted, homomorphic encryption and homomorphic operations are used as an example. For example, an encryption method called Somewhat homomorphic encryption provides homomorphism with respect to an arbitrary number of additions and a finite number of multiplications (plaintext m 1 , m 2 The ciphertext Enc(m 1 ), Enc(m 2 ), the plaintext m 1 , m 2 Binary operation m 1 ○m 2 The ciphertext Enc(m 1 ○m2 ) into plaintext m 1 , m 2 This refers to the property that the data can be calculated without decryption. Here, "○" represents a binary operation, such as addition "+" or multiplication "×".) and therefore can be applied to similarity calculations, which are the matching means in the calculation unit 13.
[0034] The conversion / transmission unit 14 converts the similarity into a format that can be decrypted by other servers and transmits it to the other servers. In the above, the first feature amount and the second feature amount are encrypted using a key generated by the server 10, which is the authentication server. This is converted into a key that can be decrypted by the server providing each service, and transmitted to the server of each service.
[0035] In the server of this embodiment, key conversion is performed using, as an example, proxy re-encryption technology. Proxy re-encryption is a technology that can convert ciphertext of one key into ciphertext of a second key without obtaining plaintext information. Here, it is used to convert the public key of the server 10 to a public key generated by a server that provides each service without decryption. Here, there are two types of public key cryptography key pairs as follows: (public key 1, private key 1) = (pk 1 , sk 1 ), (public key 2, private key 2) = (pk 2 , sk 2 ) to execute the proxy re-encryption, a re-encryption key is generated. If the re-encryption key is ReKey, the re-encryption key generation process rk=ReKeyGen() is expressed as ReKeyGen(pk 2 , sk 1 ) = rk 1→2 Here, pk 2 is the public key of the ciphertext to be converted, sk 1 is the secret key of the original ciphertext.
[0036] The key generation unit 15 generates a pair of a private key and a public key. The generated public key is distributed to each terminal that receives the service. The first feature is encrypted with the public key generated when the template is registered, and the second feature is encrypted with the public key generated when the template is authenticated.
[0037] The conversion key acquisition unit 16 acquires a conversion key from the private key generated by the key generation unit and the key acquired from another server. For example, the conversion key is generated from the private key generated by the server 10 and the public key of each service that is another server. This conversion key is generated, for example, by using the private key of the server 10 as sk 1 , the public key of each service is pk 2 Then, as described above, ReKeyGen(pk 2 , sk 1 ) = rk 1→2 The generated conversion key rk 1→2 is sent to the conversion and transmission unit 14.
[0038] In addition to the proxy re-encryption technique in which the re-encryption key can be converted in one direction as described above, there is also a technique in which the re-encryption key can be converted in two directions. 1 , sk 2 ) = rk 1←→2 As shown above, both the destination and source private keys are required. In the server of this embodiment, it becomes necessary to deliver the user's private key from another server to the server 10, which raises security issues, so it is desirable to adopt the one-way conversion model described above. If the feature amount of the plain text before encryption is M, the conversion key processing is as follows: ReEnc(rk 1→2 , Enc(pk 1 ,M))=Enc(pk 2 , M).
[0039] The server 10 may acquire a user ID for identifying a user, such as a user ID of a service provided by another server, in association with the second feature amount in the acquisition unit 12. The conversion / transmission unit 14 may transmit the calculated similarity to another server in association with the user ID.
[0040] 4 and 5 are flowcharts for explaining an example of the operation of the server 10 of this embodiment. The authentication service is mainly divided into three processing flows: key generation, storage of registered feature amounts, and matching. Fig. 4 explains an example of the operation of key generation and storage of registered feature amounts, and Fig. 5 explains an example of the operation during matching.
[0041] 4, first, a pair of a private key and a public key is generated in the server 10 (step S101). Of the generated keys, the public key is distributed to each terminal (step S102). Then, the server 10 acquires the private key and the public key (or private key) generated by another server, which is the server for each service, and generates and acquires a conversion key (step S103). Next, each terminal acquires the encrypted first feature (step S104). The acquired first feature is stored in a storage area of the server 10 (step S105).
[0042] 5, the server 10 first acquires the second feature from the terminal (step S201). Next, the similarity is calculated based on the first feature and the second feature (step S202). Next, the similarity is converted into a format that can be decoded by other servers. After the conversion is complete, the encrypted similarity is transmitted to other servers, which are servers for the respective services (step S204).
[0043] [Hardware Configuration] The server 10 of this embodiment can be executed by an information processing device (computer) and has the configuration shown in Fig. 6. The server 10 includes a CPU (Central Processing Unit) 301, a memory 302, an input / output interface 303, and a NIC (Network Interface Card) 304 as a communication means, which are interconnected by an internal bus 305.
[0044] However, the configuration shown in Fig. 6 is not intended to limit the hardware configuration of the server. The server 10 may include hardware not shown, and may not include the input / output interface 303 as necessary. Furthermore, the number of CPUs and other components included in these devices is not intended to be limited to the example shown in Fig. 6; for example, the server 10 may include multiple CPUs.
[0045] The memory 302 is a RAM (Random Access Memory), a ROM (Read Only Memory), or an auxiliary storage device (such as a hard disk).
[0046] The input / output interface 303 is a means for interfacing with a display device and an input device (not shown). The display device is, for example, a liquid crystal display. The input device is, for example, a camera or sensor that receives biometric information, and a device that receives user operations such as a keyboard or mouse.
[0047] The functions of the server 10 are realized by a group of programs (processing modules) stored in the memory 302, such as a storage program, an acquisition program, a calculation program, a conversion transmission program, a key generation program, and a conversion key acquisition program, as well as a group of data, such as parameters, used by each program. The processing modules are realized, for example, by the CPU 301 executing each program stored in the memory 302. The programs can be downloaded via a network or updated using a storage medium that stores the programs. Furthermore, the processing modules may be realized by semiconductor chips. That is, it is sufficient to have some means for executing the functions performed by the processing modules using some kind of hardware and / or software.
[0048] [Hardware Operation: Key Generation] In the server 10, a key generation program is called from the memory 302 and executed by the CPU 301. This program generates a pair of a public key and a private key of the server 10 that provides the authentication SaaS and stores it in the memory 302. Also, on the server 10, a reversion key acquisition program is called from the memory 302 and executed by the CPU 301. This program receives the public key (or private key) of each server that provides the service from that server via the NIC 304, and generates a reversion key by using this together with the private key of the server 10. The generated reversion key is temporarily stored in the memory 302.
[0049] [When Registering First Feature Amount] In the server 10, the stored program is called from the memory 302 and is executed by the CPU 301. The program receives the encrypted first feature amount, which is the feature amount of the authentication query, from the user terminal via the NIC 304 and stores the encrypted first feature amount in the memory 302.
[0050] [During matching] When key generation and registration of the encrypted first feature are completed, the acquisition program is called from the memory 302 in the server 10 and is executed by the CPU 301. The program receives the second feature of the biometric information acquired at the user terminal via the NIC 304 while it remains encrypted. Next, the calculation program is called from the memory 302 in the server 10 and is executed by the CPU 301. The program calculates the similarity between the first feature stored in the memory 302 and the acquired second feature without decrypting them, while keeping both features encrypted.
[0051] Next, the conversion / transmission program is called from memory 302 and executed by CPU 301. This program reads the conversion key temporarily stored in memory 302 and the calculated similarity, and converts the public key of server 10 that encrypts the calculated similarity into a public key generated by the server of each service. The converted encrypted similarity is transmitted by this program to the other servers, which are the servers of each service, via NIC 304.
[0052] The transmitted encrypted similarity after conversion is decrypted on the other server using its own private key, and the other server executes a process to determine whether it is within the acceptable range.
[0053] [Description of Effects] According to the server 10 of this embodiment, when a biometric authentication service is provided as SaaS, the authentication process can be performed while keeping the information confidential from the SaaS provider, thereby enabling high-level security and privacy protection. Furthermore, by using a conversion key to convert the key that encrypts the encrypted similarity, high-speed authentication can be achieved.
[0054] [Second embodiment] The authentication system of this embodiment is based on the authentication server of the first embodiment, and further decrypts the similarity encrypted by another server and determines whether it is within the acceptable range, thereby enabling authentication for services being provided by the other server.
[0055] [Configuration of Second Embodiment] Figure 7 is a block diagram showing the configuration of an authentication system according to a second embodiment. As shown in this figure, the server of this embodiment includes a group of other servers 20 and a server 10. In this configuration, there are multiple other servers 20, and one server 10 is responsible for authenticating multiple services. The configuration of the server 10 is the same as above, and includes a storage unit 11, an acquisition unit 12, a calculation unit 13, a conversion and transmission unit 14, a key generation unit 15, and a conversion key acquisition unit 16. At least one of the multiple group of other servers 20 is assigned to each service (services A to X).
[0056] The configuration of the server 10 has been explained above, so a detailed description will be omitted. The other server group 20 acquires the encrypted similarity from the server 10 and decrypts it. If the decrypted similarity is within a predetermined acceptance range, a message indicating authentication OK is sent to the terminal. On the other hand, if the similarity is outside the predetermined acceptance range, a message indicating authentication NG is sent to the terminal.
[0057] Furthermore, when the server 10 stores the user IDs of service users in association with the first feature in the storage unit, the other server group 20 may acquire one user ID based on the similarity and a predetermined criterion. For example, a process may be executed to acquire the user ID associated with the feature with the highest similarity. The acquired user ID may be used as a login ID for a service running on the other server 20.
[0058] Furthermore, the other server group 20 may be configured to acquire payment information including the user ID based on the authentication result, transmit the payment information to the payment server, and receive payment result information from the payment server.
[0059] [System Operation] Figures 8 to 10 are sequence diagrams showing an example of the operation of the server according to the second embodiment. Figure 8 shows an example of the operation when generating a key, and Figure 9 shows an example of the operation when registering a first feature. Figure 10 shows an example of the operation when comparing a second feature with a first feature.
[0060] [System Operation: Key Generation] Referring to FIG. 8, at the start of system operation, the server 10 and another server 20 corresponding to service A exchange a pair of a public key and a private key (pk A , sk A ), (pk S , sk S ) are generated (steps S401 and S402). Next, the other server 20 sends the public key pk A (or sk A ) is sent to the server 10. S and the received public key pk A Using the conversion key rk S→A The generated public key pk of the server 10 is generated (step S403). S is sent to the user terminal 1. If no more services are added, i.e., if the number of other servers 20 does not increase, the secret key sk S may be deleted (step S404).
[0061] [Template Registration] Referring to FIG. 9, the public key of the server 10 is sent to the user terminal 1 of the service A (shown again). The user terminal 1 of the service A receives the biometric feature x 1 Obtain the obtained x 1 is encrypted with the public key of the server 10 (step S405). The encrypted data is sent to the server 10 as the first feature. At this time, the user ID of user 1 may be associated with the data and sent. This operation is repeated the number of times equal to the number of users.
[0062] 10, first, the service ID "SID(A)" is sent from the other server 20. The user terminal 1 receives the biometric feature y 1 Next, the public key pk sent from the server 10 is obtained. S So 1 The encrypted feature quantity y is then encrypted (step S406). 1is transmitted to the server 10 as the second feature together with the service ID: SID(A). The server 10 calculates the similarity between the first feature and the second feature (step S407). S , D(x 1 , y 1 )) is the public key pk of the server 10 S Since the server 20 is encrypted with its own private key sk S The conversion key rk S→A Next, the server 10 sends the encrypted similarity Enc(pk A , D(x 1 , y 1 )) and performs a decryption process (step S409). It is determined whether the decrypted D is within a predetermined range (step S410). Depending on the result, the other server 20 notifies the user terminal of an OK or NG message.
[0063] 11 and 12 show the operation of the system when an endpoint is used. An "endpoint" refers to a device that can receive authentication services, such as a terminal installed in a convenience store.
[0064] [Another Operation of the System: Key Generation] Referring to FIG. 11, the endpoint of service A generates a key instead of the user's terminal. The pair of public key and private key (pk α , sk α ) is generated (step S501). In addition, the other server 20 and the server 10 each generate a pair of a public key and a private key (steps S502 and S503). In the same manner as above, the conversion key rk S→A The endpoint α receives the public key pk from the server 10 (step S504). S (or sk S ) and convert the key rk α→S (Step S505). α may be deleted after the re-key is generated (step S506).
[0065] [When registering a template] When registering a template, the user's terminal can be used to transmit encrypted user biometric information as a first feature to the server 10 and store it. In this case, the operation is the same as in Fig. 9, so a description thereof will be omitted.
[0066] [During verification] Referring to FIG. 12, the endpoint α acquires biometric information of the user to be authenticated and compares it with the feature quantity y 1 and extracts its own public key pk α (Step S507). The encrypted authentication query data is sent to the server 10 together with the service ID: SID(A) and the endpoint ID: EID(α). On the server 10, the encrypted second feature Enc(pk α , y 1 ) into the conversion key rk α→S Enc(pk S , y 1 ) (step S508). Then, the similarity with the registered first feature is calculated (step S509). After that, the key is converted again to pk so that it can be decrypted with the key of another server 20. s From pk A 10, the other server 20 decodes the similarity (step S511) and determines whether it is within the acceptable range (step S512). The result of the determination is notified to the endpoint α.
[0067] [Explanation of Effects] In the authentication system of this embodiment, the first feature is encrypted by the user terminal and registered in the server 10. The second feature, which is the authentication query, is also encrypted in the same way, and the server 10 calculates the similarity while keeping it encrypted. By converting the resulting encrypted similarity key, it can be made decryptable with the key of another server 20. This makes it possible to achieve high levels of security and privacy, as well as high-speed processing, as an authentication service.
[0068] Some or all of the above-described embodiments can also be described as in the following supplementary notes. However, the following supplementary notes are merely examples of the present invention, and the present invention is not limited to such cases. [Supplementary Note 1] As in the server according to the first aspect described above. [Supplementary Note 2] Preferably, the server according to Supplementary Note 1, wherein the calculation unit calculates the similarity based on the first feature amount and the second feature amount, each of which is encrypted. [Supplementary Note 3] Preferably, the server according to Supplementary Note 1 or 2, further including: a key generation unit that generates a pair of a private key and a public key, and a reconstitution key acquisition unit that acquires a reconstitution key from the private key generated by the key generation unit and a key acquired from another server. [Supplementary Note 4] Preferably, the server according to any one of Supplements 1 to 3, wherein the storage unit stores a user ID that identifies a user in association with the first feature amount, and the conversion transmission unit transmits the similarity to another server in association with the user ID. [Supplementary Note 5] As in the authentication system according to the second aspect described above. [Supplementary Note 6] Preferably, the authentication system of Supplementary Note 5, wherein the other server decrypts the similarity and obtains the user ID associated with the highest similarity. [Supplementary Note 7] Preferably, the authentication system of Supplementary Note 5 or 6, wherein the server further comprises a key generation unit that generates a pair of a private key and a public key, and a reconstitution key acquisition unit that acquires a reconstitution key from the private key generated by the key generation unit and the key acquired from the other server. [Supplementary Note 8] Preferably, the authentication system of any one of Supplements 5 to 7, wherein the other server transmits payment information including the one user ID to the payment server and receives payment result information from the payment server. [Supplementary Note 9] As in the authentication method according to the third aspect described above. [Supplementary Note 10] As in the program according to the fourth aspect described above.
[0069] The disclosures of the above-cited patent documents and other documents are incorporated herein by reference. Modifications and adjustments of the embodiments are possible within the scope of the entire disclosure of the present invention (including the claims), and further based on the basic technical concepts thereof. Furthermore, various combinations and selections (including partial deletions) of various disclosed elements (including elements of each claim, each embodiment, each element of each embodiment, each element of each drawing, etc.) are possible within the scope of the entire disclosure of the present invention. In other words, the present invention naturally includes various modifications and alterations that would be possible by a person skilled in the art in accordance with the entire disclosure and technical concepts, including the claims. In particular, with regard to the numerical ranges described herein, any numerical value or subrange included within the range should be construed as being specifically described, even if not otherwise specified.
[0070] 10: Server 11: Storage unit 12: Acquisition unit 13: Calculation unit 14: Conversion and transmission unit 15: Key generation unit 16: Conversion key acquisition unit 20, 21, 22: Server(s) 23, 25: User 24, 26: Terminal 301: CPU 302: Memory 303: Input / output interface 304: NIC 305: Internal bus
Claims
1. A storage unit that stores an encrypted first feature amount; An acquisition unit that acquires an encrypted second feature amount received by a terminal; A calculation unit that calculates a similarity based on the first feature amount and the second feature amount; A conversion transmission unit that converts the similarity into a form that can be decrypted by another server and transmits it to the other server; A server having the above.
2. The calculation unit calculates the similarity in a state where each is encrypted based on the first feature amount and the second feature amount. The server according to Claim 1.
3. A key generation unit that generates a set of secret keys and public keys; A conversion key acquisition unit that acquires a conversion key from the secret key generated by the key generation unit and a key acquired from another server; The server according to Claim 1, further comprising the above.
4. The storage unit holds a user ID for identifying a user in association with the first feature amount; The conversion transmission unit transmits the similarity to another server in association with the user ID. The server according to any one of Claims 1 to 3.
5. A storage unit that stores an encrypted first feature amount; An acquisition unit that acquires an encrypted second feature amount received by a terminal; A calculation unit that calculates a similarity based on the first feature amount and the second feature amount; A conversion transmission unit that converts the similarity into a form that can be decrypted by another server and transmits it to the other server, having: The storage unit holds a user ID for identifying a user in association with the first feature amount; The calculation unit calculates the similarity in a state where each is encrypted based on the first feature amount and the second feature amount; The conversion transmission unit transmits the similarity to another server in association with the user ID; A server; Another server that decrypts the similarity and acquires one user ID based on the similarity and a predetermined criterion; An authentication system including the above.
6. The other server decrypts the similarity and acquires the user ID related to the highest similarity. The authentication system according to Claim 5.
7. The server has: A key generation unit that generates a set of secret keys and public keys; A conversion key acquisition unit that acquires a conversion key from the secret key generated by the key generation unit and a key acquired from another server, further comprising the above. The authentication system according to Claim 5.
8. The other server transmits settlement information including the one user ID to a settlement server and receives settlement result information from the settlement server. The authentication system according to any one of claims 5 to 7.
9. The step of a computer storing an encrypted first feature amount; The step of the computer acquiring an encrypted second feature amount received by a terminal; The step of the computer calculating a similarity based on the first feature amount and the second feature amount; The step of the computer converting the similarity into a form decodable by another server and transmitting the similarity to the other server, which is an authentication method.
10. The process of storing an encrypted first feature amount; The process of acquiring an encrypted second feature amount received by a terminal; The process of calculating a similarity based on the first feature amount and the second feature amount; The process of converting the similarity into a form decodable by another server and transmitting the similarity to the other server; A program for causing a computer to execute the above.