Information processing system and information processing method

A distributed template system across multiple servers ensures only authorized users can recover the secret key, enhancing security by preventing unauthorized access to biometric data.

WO2026069907A1PCT designated stage Publication Date: 2026-04-02HITACHI LTD
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-07-02
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Existing biometric cryptography systems face challenges in ensuring that only the registered user can access their biometric data and recover the secret key, as servers or administrators may inadvertently or maliciously access sensitive biometric information.

Method used

A distributed template system is implemented across multiple servers, where each server holds a part of the biometric template, and the key recovery terminal must provide proof information to each server for successful transmission, ensuring only authorized users can recover the secret key.

Benefits of technology

This system significantly enhances security by making it extremely difficult for anyone other than the registered user to obtain or guess the secret key, even if servers or administrators try to access the biometric information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025023850_02042026_PF_FP_ABST
    Figure JP2025023850_02042026_PF_FP_ABST
Patent Text Reader

Abstract

In this information processing system, a server set distributes and stores a distributed registration information set that includes a distributed template set generated from biometric information for registration. A key restoration terminal generates certification information by using input information for key restoration, and transmits the certification information to the server set. On the basis of the distributed registration information set and the certification information, the server set determines whether the distributed template set for key restoration determined from the distributed template set can be transmitted to the key restoration terminal, and if the key restoration terminal successfully receives the distributed template set for key restoration, the key restoration terminal restores a private key by using the distributed template set for key restoration and the input information for key restoration.
Need to check novelty before this filing date? Find Prior Art

Description

Information processing system and information processing method Import by reference

[0001] This application claims priority to and incorporates the contents of Japanese Patent Application No. 2024-167299, filed on 26 September 2024, by reference thereto.

[0002] The present invention relates to an information processing system and an information processing method.

[0003] Biometric cryptography is a method that uses variable biometric information to recover a stable secret key. The recovered secret key is used in various cryptographic processes such as encryption, decryption, signature generation, and authentication.

[0004] A system based on biometric encryption generates a template using biometric information obtained from the user during the registration process and saves the template. Then, in the key recovery process, the system generates a secret key using biometric information obtained again from the user for key recovery and the saved template. The biometric encryption method is designed so that a secret key with a fixed value is recovered when the fluctuations between the biometric information for registration and the biometric information for key recovery are sufficiently small, and the value of the secret key is difficult to guess from the template alone.

[0005] From a privacy perspective, it is desirable that it be difficult for anyone other than the registered user to obtain information about their biometric data. To achieve this, it is necessary that it be difficult for anyone other than the user to obtain the template. This is because, although it is generally difficult to reconstruct the registered biometric data from the template, the template contains information related to the registered biometric data.

[0006] As a method to increase the difficulty of obtaining the template by someone other than the owner, a system that makes it difficult for someone other than the owner to download the template to a key recovery terminal is disclosed in Japanese Patent Application Publication No. 2023-125727 (Patent Document 1).

[0007] This publication states that "the key recovery terminal sends a message to the first server requesting the transmission of a template generated based on the user's registration biometric information, along with the user's first verification matching information. The first server holds the user's first registration matching information and the template. If the first verification process based on the first verification matching information and the first registration matching information is successful, the server sends the template to the key recovery terminal. The key recovery terminal obtains the user's key recovery biometric information and recovers the private key based on the template and the key recovery biometric information. If the first verification process fails, the server refuses to send the template to the key recovery terminal." (See summary).

[0008] Japanese Patent Publication No. 2023-125727

[0009] In the technology described in Patent Document 1, for example, a server administrator may refer to a template stored on the server and obtain information regarding registration biometric information from the template. Therefore, one aspect of the present invention realizes a system in which it is difficult for anyone other than the target user of registration biometric information to obtain information regarding registration biometric information.

[0010] To solve the above problems, one aspect of the present invention adopts the following configuration. An information processing system comprising a key recovery terminal and a first to nth server (n is an integer of 2 or more), wherein the kth server (k is any integer from 1 to n) holds the kth registration information, which includes the kth distributed template included in a distributed template set generated based on registration biometric information, the key recovery terminal receives input of key recovery input information including key recovery biometric information, generates m pieces of proof information (m is a predetermined integer from 1 to n) using the key recovery input information, and each of the m pieces of proof information is assigned to the a 1 Servers and a m Server (a 1 or a mEach value is sent as a distinct integer between 1 and n, and the k server determines whether to send the k-th key recovery distributed template included in the key recovery distributed template set determined from the distributed template set to the key recovery terminal based on a predetermined k-th rule, and if the key recovery terminal successfully receives the key recovery distributed template set, it recovers the secret key by performing a secret key recovery process using the key recovery distributed template set and the key recovery biometric information, and a i The rule (where i is any integer between 1 and m) is the received proof information and the a i This rule involves performing a verification process using the registration information, determining whether transmission is permitted if the verification process is successful, and determining whether transmission is not permitted if the verification process fails.

[0011] According to one aspect of the present invention, a system can be realized in which it is difficult for anyone other than the target user of the registered biometric information to obtain information related to the registered biometric information.

[0012] Other issues, configurations, and effects not mentioned above will be clarified by the following description of the embodiments.

[0013] This is a block diagram showing an example of the functional configuration of the key generation system in Example 1. This is a block diagram showing an example of the hardware configuration of the computers that constitute each entity included in the key generation system in Example 1. This is a sequence diagram showing an example of the registration process in Example 1. This is a sequence diagram showing an example of the key recovery process in Example 1. This is a block diagram showing an example of the functional configuration of the key generation system 10 in Example 2. This is a sequence diagram showing an example of the registration process in Example 2. This is a sequence diagram showing an example of the key recovery process in Example 2.

[0014] Embodiments of the present invention will be described in detail below with reference to the drawings. It should be noted that these embodiments are merely one example of how to realize the present invention and do not limit the technical scope of the present invention.

[0015] Example 1 describes a key generation system via a network. The system stores registration information generated using the user's biometric information, and in the key recovery process, a key recovery terminal recovers a private key with a fixed value based on biometric information obtained again from the legitimate user. The recovered private key can be used for any cryptographic processing, such as encryption, decryption, authentication, and digital signature generation of any data.

[0016] Figure 1 is a block diagram showing an example of the functional configuration of a key generation system. The key generation system 10 includes, for example, a registration terminal 100, a first server 200, a second server 300, and a key recovery terminal 400. The registration terminal 100, the first server 200, the second server 300, and the key recovery terminal 400 are interconnected via a network 900.

[0017] However, not all of these devices necessarily need to be able to communicate with each other; for example, it is sufficient if the entities that communicate in each of the processes described later can communicate with each other. Also, the network 900 may be wired or wireless. The internet and local networks within an organization are examples of the network 900. Furthermore, if multiple devices in the key generation system 10 are contained within a single physical device, the network within that device may also be considered part of the network 900.

[0018] The registration terminal 100 includes, for example, a communication unit 101, a secret information acquisition unit 102 for generating verification information, a verification information generation unit 103, a biometric information acquisition unit 104, and a distributed template generation unit 105, all of which are functional units.

[0019] The first server 200 includes, for example, a communication unit 201, an information registration unit 202, and a first transmission permission determination unit 203, all of which are functional units. The first server 200 also includes, for example, a first registered information storage unit 220, which is an area for storing data.

[0020] The second server 300 includes, for example, a communication unit 301, an information registration unit 302, and a second transmission permission determination unit 303, all of which are functional units. The second server 300 also includes, for example, a second registered information storage unit 320, which is an area for storing data.

[0021] The key recovery terminal 400 includes, for example, a communication unit 401, a secret information acquisition unit 402 for generating certification information, a certification information generation unit 403, a biometric information acquisition unit 404, a key recovery unit 405, and a cryptographic processing execution unit 406, all of which are functional units.

[0022] Figure 2 is a block diagram showing an example of the hardware configuration of the computers that make up each entity (registration terminal 100, first server 200, second server 300, and key recovery terminal 400) included in the key generation system 10. The computer 10000 has, for example, a CPU (Central Processing Unit) 10001, memory 10002, auxiliary storage device 10003, input device 10004, output device 10005, communication device 10006, and reading device 10007.

[0023] The CPU 10001 is an example of a processor and executes the program stored in the memory 10002. While the CPU 10001 and GPU (Graphics Processing Unit) are examples of processors, other semiconductor devices may also be used as long as they perform the required processing.

[0024] The memory 10002 includes a non-volatile memory element called ROM (Read Only Memory) and a volatile memory element called RAM (Random Access Memory). The ROM stores immutable programs (for example, the BIOS (Basic Input / Output System)). The RAM is a high-speed, volatile memory element such as DRAM (Dynamic Random Access Memory) and temporarily stores programs executed by the CPU 10001 and data used during program execution.

[0025] The auxiliary storage device 10003 is a high-capacity, non-volatile storage device such as a magnetic storage device (HDD (Hard Disk Drive)) or flash memory (SSD (Solid State Drive)), and stores the program executed by the CPU 10001 and the data used when the program is executed. That is, the program is read from the auxiliary storage device 10003, loaded into memory 10002, and executed by the CPU 10001. In this embodiment and in other embodiments described later, memory 10002 and / or auxiliary storage device 10003 may be referred to as a storage hierarchy or storage resources.

[0026] The input device 10004 is a device that receives input from the operator, such as a keyboard or mouse. The input device 10004 may also include a biometric information acquisition device that acquires the user's biometric information, such as a camera that captures the user's facial image and a scanner that acquires the user's fingerprints or finger vein patterns. The output device 10005 is a device that outputs the program execution results in a format that the operator can see, such as a display device or printer.

[0027] The communication device 10006 is a network interface device that controls communication with other devices according to a predetermined protocol. The communication device 10006 may also include a serial interface such as USB (Universal Serial Bus).

[0028] Some or all of the program executed by the CPU 10001 may be provided to the computer 10000 via a network from an external computer equipped with a non-temporary storage medium, such as removable media (CD-ROM, flash memory, etc.), or a non-temporary storage device, and stored in the non-volatile auxiliary storage device 10003, which is also a non-temporary storage medium. The reading device 10007 is an interface device for reading data from such removable media.

[0029] Each entity included in the key generation system 10 is a computer system configured on one physical computer 10000 or on a plurality of computers 10000 configured logically or physically. It may operate in separate threads on the same computer or may operate on a virtual computer constructed on a plurality of physical computer resources.

[0030] The CPU 10001 of the computer 10000 that constitutes each entity included in the key generation system 10 includes each functional unit that the entity has shown in FIG. 1. For example, the CPU 10001 of the computer 10000 that constitutes the registration terminal 100 functions as the communication unit 101 by operating according to the communication program loaded in the memory 10002 of the computer 10000, and functions as the secret information acquisition unit 102 for generating verification information by operating according to the secret information acquisition program for generating verification information loaded in the memory 10002. The relationship between the program and the functional unit is the same for other functional units that the registration terminal 100 has. Also, for the functional units that each of the first server 200, the second server 300, and the key restoration terminal 400 has, the relationship between the program and the functional unit is the same.

[0031] Note that part or all of the functions performed by the functional units that each entity included in the key generation system 10 has may be realized by a dedicated circuit such as an ASIC (Application Specific Integrated Circuit) or an FPGA (Field-Programmable Gate Array).

[0032] The auxiliary storage device 10003 of the computer 10000 that constitutes each entity included in the key generation system 10 provides a storage area for realizing each storage unit that the entity has shown in FIG. 1. Note that part or all of the information stored in each storage unit that the entity has shown in FIG. 1 may be stored in the memory 10002 of the computer 10000 that constitutes the entity, or may be stored in an external database connected to the entity.

[0033] Note that in this embodiment, the information used by the key generation system 10 may be expressed in any data structure regardless of the data structure. For example, a data structure appropriately selected from a table, a list, a database, or a queue can store the information.

[0034] FIG. 3 is a sequence diagram showing an example of the registration process. In step S1101, the verification information generation secret information acquisition unit 102 acquires the verification information generation secret information from the user. For example, when a password specified by the user is used as the verification information generation secret information, the verification information generation secret information acquisition unit 102 receives the input of the password from the user via the input device 10004. Also, when the biometric information of the user is used as the verification information generation secret information, the verification information generation secret information acquisition unit 102 receives the input of the biometric information from the user via the input device 10004.

[0035] In step S1102, the verification information generation unit 103 generates the first verification information and the second verification information using the acquired verification information generation secret information, and the communication unit 101 transmits the first verification information to the first server 200 and the second verification information to the second server 300. An example of the generation process of the first verification information and the second verification information will be described later.

[0036] In step S1103, the biometric information acquisition unit 104 acquires the registration biometric information from the user via the input device 10004. As the registration biometric information, for example, biometric information acquired from one or more arbitrary parts such as a face, a fingerprint, a palmprint, and a finger vein can be used.

[0037] In step S1104, the distributed template generation unit 105 generates the first distributed template and the second distributed template using the registration biometric information acquired in step S1103, and the communication unit 101 transmits the first distributed template to the first server 200 and the second distributed template to the second server 300. An example of the generation process of the first distributed template and the second distributed template will be described later.

[0038] In step S1201, the information registration unit 202 of the first server 200 registers the first registration information, which includes the transmitted first verification information and the first distributed template, in the first registration information storage unit 220. The information registration unit 202 may also perform data processing such as encryption on the first registration information before registering it in the first registration information storage unit 220. In that case, the corresponding data processing such as decryption should be performed when the first registration information is used.

[0039] In step S1301, the information registration unit 302 of the second server 300 stores the second registration information, which includes the transmitted second verification information and second distributed template, into the second registration information storage unit 320. Similar to the first registration information, data processing may also be performed on the second registration information.

[0040] Figure 4 is a sequence diagram showing an example of the key recovery process. In step S2401, the secret information acquisition unit 402 for generating certification information acquires secret information for generating certification information corresponding to the secret information for generating verification information from the user via the input device 10004.

[0041] Examples of secret information used for generating certification information include the following: If the secret information used for generating verification information is knowledge information such as a password, an example of the secret information used for generating verification information would be knowledge information such as a password with the same value. Also, if the secret information used for generating verification information is a private key, the secret information used for generating certification information would be a private key with the same value. Furthermore, if the secret information used for generating verification information is biometric information, an example of the secret information used for generating certification information would be biometric information obtained from the same body part as the secret information used for generating verification information.

[0042] Furthermore, it is assumed that the user who enters the biometric information for registration will manage the confidential information used to generate the certification information in a way that makes it difficult for anyone other than themselves to use it. This can be achieved, for example, as follows.

[0043] If the confidential information used to generate authentication information is knowledge information, it becomes difficult for anyone other than the person concerned to use it by not disclosing that knowledge information to anyone other than the person concerned. If the confidential information used to generate authentication information is a private key, it becomes difficult for anyone other than the person concerned to use it by not allowing others to use the IC (Integrated Circuit) card or electronic device, etc., on which the private key is stored. To make it difficult for others to use it, it is advisable to equip the device with an authentication function that uses knowledge information or biometric information. If the confidential information used to generate authentication information is the user's biometric information, it becomes difficult for anyone other than the person concerned to use it.

[0044] In step S2402, the certification information generation unit 403 generates first certification information and second certification information using the secret information for certification information generation obtained in step S2401, and the communication unit 401 transmits the first certification information to the first server 200 and the second certification information to the second server 300. Specific examples of the generation process for the first and second certification information will be described later.

[0045] In step S2201, the first transmission eligibility determination unit 203 determines whether the first distributed template included in the first registration information stored in the first registration information storage unit 220 can be transmitted, based on a predetermined first rule.

[0046] As an example of the first rule, the first transmission permission determination unit 203 performs a predetermined first verification process using the transmitted first certification information and the first verification information included in the first registration information stored in the first registration information storage unit 220. If the verification result is "verification successful", it determines "transmission permitted", and if the verification result is "verification failed", it determines "transmission denied".

[0047] When the first transmission permission determination unit 203 determines that transmission is permitted, the communication unit 201 transmits the first distributed template included in the first registration information to the key recovery terminal 400. When the first transmission permission determination unit 203 determines that transmission is not permitted, the communication unit 201 refuses to transmit the first distributed template to the key recovery terminal 400. As a specific example, the communication unit 201 sends a notification to the key recovery terminal 400 indicating that transmission is refused. Alternatively, the communication unit 201 may transmit a dummy first distributed template (for example, a randomly generated first distributed template) to the key recovery terminal 400.

[0048] In step S2301, the second transmission eligibility determination unit 303 determines whether or not to transmit the second distributed template included in the second registration information stored in the second registration information storage unit 320, based on a predetermined second rule.

[0049] As an example of the second rule, the second transmission permission determination unit 303 performs a predetermined second verification process using the transmitted second certification information and the second verification information included in the second registration information stored in the second registration information storage unit 320. If the verification result is "verification successful", it determines "transmission permitted", and if the verification result is "verification failed", it determines "transmission not permitted".

[0050] When the second transmission permission determination unit 303 determines that transmission is permitted, the communication unit 301 transmits the second distributed template included in the second registration information to the key recovery terminal 400. When the second transmission permission determination unit 303 determines that transmission is not permitted, the communication unit 301 refuses to transmit the second distributed template to the key recovery terminal 400. A specific example of the process when the communication unit 301 refuses to transmit the second distributed template to the key recovery terminal 400 is the same as the process when the communication unit 201 refuses to transmit the first distributed template.

[0051] In step S2403, the biometric information acquisition unit 404 acquires key recovery biometric information from the user via the input device 10004. The biometric information acquisition unit 404 only needs to acquire the key recovery biometric information from the same location as the registration biometric information.

[0052] In step S2404, the key recovery unit 405 recovers the private key using the key recovery biometric information obtained in step S2404 and the first and second distributed templates transmitted in steps S2202 and S2302. The system is designed so that the correct private key is recovered in step S2404 if the registration biometric information and the key recovery biometric information are sufficiently similar. A specific example of the private key recovery process will be described later.

[0053] In step S2405, the cryptographic processing execution unit 406 uses the secret key recovered in step S2404 to perform arbitrary cryptographic processing on arbitrary data, such as encryption, decryption, authentication, and digital signature generation.

[0054] [Specific Examples of Verification Information Generation, Certification Information Generation, and Verification] Specific examples of the verification information generation process in step S1102, the certification information generation process in step S2402, and the first verification process and the second verification process in the first transmission eligibility determination process in step S2201 and the second transmission eligibility determination process in S2301 will be explained.

[0055] Hereinafter, among the confidential information for generating verification information, the data used for generating the first verification information will also be referred to as the confidential information for generating the first verification information, and the data used for generating the second verification information will also be referred to as the confidential information for generating the second verification information. The confidential information for generating the first verification information and the confidential information for generating the second verification information may be the same data or different data. Similarly, the first verification information and the second verification information may be the same data or different data.

[0056] Hereinafter, among the secret information for generating proof information, the data used for generating the first proof information will also be referred to as the secret information for generating the first proof information, and the data used for generating the second proof information will also be referred to as the secret information for generating the second proof information. The secret information for generating the first proof information and the secret information for generating the second proof information may be the same data or different data. Similarly, the first proof information and the second proof information may be the same data or different data.

[0057] A specific example of a combination of the first verification information generation process, the first proof information generation process, and the first verification process will be explained. In this explanation of the specific example, the term "first" will be omitted. Note that similar specific examples can be used for the combination of the second verification information generation process, the second proof information generation process, and the second verification process. The combination of the second verification information generation process, the second proof information generation process, and the second verification process may be the same as or different from the combination of the first verification information generation process, the first proof information generation process, and the first verification process.

[0058] Let's explain the first specific example. Passwords, secret strings and word sequences, and secret keys stored on IC cards or the like held by the user, are all examples of secret information used for generating certification information. Furthermore, even secret information that fluctuates can be used as secret information for generating certification information if it can be correctly converted into fixed secret information with a high probability (for example, a probability greater than a predetermined value) through error correction processing or similar methods.

[0059] The verification information generation unit 103 generates verification information in the verification information generation process by applying an arbitrary function to the secret information for verification information generation, such as the hash value of the secret information for verification information generation. Secret information having the same value as the secret information for verification information generation is an example of secret information for proof information generation. The proof information generation unit 403 generates proof information in the proof information generation process by applying the function used in the verification information generation process to the secret information for proof information generation. The first transmission eligibility determination unit 203 determines the verification result as "verification successful" in the verification process, for example, when the values ​​of the verification information and the proof information match, and determines the verification result as "verification failed" otherwise.

[0060] Let's explain the second specific example. The same confidential information as in the first specific example is an example of confidential information for generating certification information. In the verification information generation process, the verification information generation unit 103 generates a digital signature key pair (i.e., a signature key and a verification key pair) from the confidential information for generating certification information, and determines the verification key as the verification information. Note that at this time, the verification information generation unit 103 does not have to generate a signature key, or it may determine the confidential information itself as the signature key.

[0061] Confidential information having the same value as the confidential information for generating verification information is an example of confidential information for generating proof information. In the proof information generation process, the proof information generation unit 403 generates a digital signature scheme key pair (i.e., a signing key and a verification key pair) from the confidential information for generating proof information, generates a digital signature for the message using the signing key, and determines the generated digital signature as proof information. Note that the proof information generation unit 403 does not need to generate a verification key at this time. Also, random numbers and date / time information generated by the first server 200 are all examples of the message in question.

[0062] The first transmission eligibility determination unit 203, in the verification process, for example, verifies the relationship between the digital signature and the message using a verification key, and determines the verification result as "verification successful" if the verification is successful, and as "verification failed" otherwise. In order to generate and verify the digital signature, the key recovery terminal 400 and the first server 200 share the target message (for example, one sends it to the other).

[0063] Let's explain the third specific example. Biometric information obtained from the user is an example of confidential information for generating verification information. The biometric information may be the same as or different from the registration biometric information obtained in step S1103. If registration biometric information is used as confidential information for generating verification information, the process of obtaining confidential information for generating verification information in step S1101 may be omitted. In the verification information generation process, the verification information generation unit 103 determines the feature quantities obtained by performing a feature extraction process on the biometric information used as confidential information for generating verification information as verification information.

[0064] Biometric information generated from the user is an example of secret information used for generating certification information. Biometric information is obtained from the same location as secret information used for generating verification information. If key recovery biometric information is used as secret information for generating certification information, the process of obtaining secret information for generating certification information in step S2401 may be omitted.

[0065] The certification information generation unit 403 determines the certification information to be a feature quantity obtained by performing a feature extraction process on biometric information, for example, as secret information for certification information generation, during the certification information generation process. The first transmission eligibility determination unit 203 compares the verification information with the certification information during the verification process and determines the verification result to be "verification successful" if the similarity is greater than or equal to a predetermined value (or the difference is less than or equal to a predetermined value), and determines the verification result to be "verification failed" otherwise.

[0066] In this third specific example, the features extracted during the verification information generation process are not kept secret from the server. To keep the features extracted during the verification information generation process secret from the server, for example, the second example described later can be used.

[0067] [Specific Examples of Biometric Cryptography Processing] In the specific examples of distributed template generation and key recovery described later, processing using biometric cryptography is performed. Specific examples of biometric cryptography processing are explained below.

[0068] To perform the registration process, registration features y are extracted from registration biometric information x. In the registration process, a template T is generated based on y using a predetermined algorithm Gen, with T = Gen(y). To perform the key recovery process, key recovery features y' are extracted from key recovery biometric information. In the key recovery process, a secret key K' is recovered based on y' and T using a predetermined algorithm Rep, with K' = Rep(T, y').

[0069] The biometric encryption scheme is designed such that when the registration biometric information x and the key recovery biometric information x' are sufficiently close, specifically when the registration feature quantity y extracted from the registration biometric information x and the key recovery feature quantity y' extracted from the key recovery biometric information x' are sufficiently close (for example, the distance is below a predetermined threshold), a secret key with a fixed value can be recovered, and it is difficult to guess the fixed value from T alone.

[0070] This section explains specific examples of Gen in the registration process and Rep in the key recovery process of a biometric encryption scheme. Let Y be the space to which the feature quantities belong, and Q be a subspace of Y. EC is a mapping from Y to Q and represents the error correction process.

[0071] As concrete examples of Y, Q, and EC, Y is a d-dimensional real space, Q is a lattice (i.e., Q is a set defined as Q = {B * z: z is a d-dimensional column vector whose components are integers} using a given d x d real square matrix B, where B * z is the matrix product of matrix B and vector z), and EC is the nearest neighbor lattice point solution process. Another concrete example of Y, Q, and EC is a vector whose elements are elements of a finite field, Q is an error correction code, and EC is the decoding process of the error correction code.

[0072] In the former specific examples of Y, Q, and EC, Y may be a region consisting of a part of a d-dimensional real space instead of a d-dimensional real space. In that case, operations on Y (for example, addition and subtraction of elements, and multiplication of elements by a matrix) should be modified so that the result of the operation becomes an element of Y. For example, let's consider the case where A is a predetermined positive integer and Y = {V is a d-dimensional real vector: each component of B^{-1}*V is greater than or equal to 0 and less than A}. In this case, the following are examples of operations on Y.

[0073] First, let V be the result of performing an operation on each element of Y, treating them as d-dimensional real vectors. Let E = B^(-1) * V, and let the components of E be (E_1, ..., E_d). For each E_i (where i is any integer from 1 to d), let E'_i be the remainder when E_i is divided by A. Let E' be the vector whose components are (E'_1, ..., E'_d), and let V' := B * E' be the result of the operation on Y. In this way, even if V is not an element of Y, V' will be an element of Y.

[0074] An example of Gen in the registration process is as follows: The Gen algorithm selects an element q of Q. The selection of q may be random or depend on y. Then, Gen defines the template T by T = y + q.

[0075] An example of Rep in key recovery processing is as follows: The key recovery algorithm Rep recovers q' by q' = EC(T - y'). In this case, since q' = EC(q + y - y'), when y and y' are sufficiently close, q' = q. Then, Rep determines K' by K' = f_1(q') using a predetermined function f_1 ("_" indicates an index). When y and y' are sufficiently close, q' = q, so the recovered secret key K' is equal to the fixed value f_1(q).

[0076] The secret key K' may be determined using y in place of or in addition to q'. When q' = q, y can be reconstructed using T - q. Therefore, if the secret key K' is determined by a predetermined function f_2 as K' = f_2(q', T - q'), then when y and y' are sufficiently close, the secret key K' becomes a fixed value f_2(q, y).

[0077] In the registration process, the algorithm Gen may output the fixed value K as the secret key in addition to T. Furthermore, the above registration and key recovery processes are merely examples, and any biometric encryption scheme such as Fuzzy Extractor, Fuzzy Commitment, or Fuzzy Vault may be used.

[0078] [Specific Examples of Distributed Template Generation and Key Recovery] Specific examples of the distributed template generation process in step S1104 and the key recovery process in step S2404 will be explained. In the following explanation, the first distributed template is represented by T_1, the second distributed template by T_2, and the recovered secret key by K'. Gen and Rep are the template generation algorithm and key recovery algorithm of the biometric cryptography scheme, respectively. In each specific example, the distributed template generation process extracts registration feature quantities y from registration biometric information x, and the key recovery process extracts key recovery feature quantities y' from key recovery biometric information x'.

[0079] Let's explain the first specific example. In the distributed template generation process, the distributed template generation unit 105 generates a template T by T = Gen(y). Then, the distributed template generation unit 105 generates a random number p and generates a distributed template by T_1 = T + p and T_2 = p. This random number p should be a random number that follows a predetermined distribution in the space to which the template belongs (for example, a uniform random number). It is preferable to use a random number p that is sufficiently random. Alternatively, a pseudorandom number may be used. In the key recovery process, the key recovery unit 405 recovers T from T_1 and T_2 by T = T_1 - T_2, and then recovers K' by K' = Rep(T, y').

[0080] In this first specific example, even if either T_1 or T_2 is obtained, the information about T cannot be obtained. Therefore, neither the first server 200 nor the second server 300 can obtain the information about T, and thus the information about y used to generate T cannot be obtained.

[0081] Let's explain the second specific example. In the distributed template generation process, the distributed template generation unit 105 generates a transformation parameter p and generates a post-transformation registration feature c from y using a predetermined transformation function F, given by c = F(p, y). F(p, y) = p + y and F(p, y) = p * y are both examples of F. When F(p, y) = p + y is used as F, p is, for example, a random number (e.g., a uniform random number) that follows a predetermined distribution in the space to which the feature belongs. When F(p, y) = p * y is used as F, p is, for example, a random square matrix. Then, the distributed template generation unit 105 generates a distributed template with T_1 = Gen(c) and T_2 = p.

[0082] In the key recovery process, the key recovery unit 405 generates a converted key recovery feature quantity c' from y' by c' = F(T_2, y'), and recovers K' by Rep(T_1, c').

[0083] In this second specific example, T_1 is generated using the post-transformation registration feature v. If the transformation function F is designed in such a way that it is difficult to obtain information about y from c without knowing p, as in the example of F above, then it becomes difficult to obtain information about y from T_1. Also, information about y cannot be obtained from T_2.

[0084] [Main Effects of This Embodiment] This embodiment has the effect of making it difficult for anyone other than the registered individual to obtain information about the registration biometric information x. Furthermore, by using specific examples of distributed template generation and key recovery, it becomes difficult for anyone other than the registered individual to obtain not only the registration biometric information x, but also information about the registration feature y.

[0085] In this embodiment, it is assumed that the user who inputs the registration biometric information x manages the confidential information for generating certification information in a way that makes it difficult for anyone other than the user to use it. In this case, even if someone other than the user operates the key recovery terminal 400, it is difficult for them to input the correct confidential information for generating certification information, and therefore it is difficult for them to obtain either the distributed template T_1 or T_2. Thus, even if someone other than the user operates the key recovery terminal 400, it is difficult for them to obtain information about the registration feature quantity y.

[0086] On the other hand, even if the administrator of the first server 200 knows T_1, it is difficult to obtain the registration feature y from T_1. Similarly, even if the administrator of the second server 300 knows T_2, it is difficult to obtain the registration feature y from T_2. Therefore, it is difficult for anyone other than the user themselves to obtain information regarding the registration feature y.

[0087] Furthermore, in this embodiment, it is difficult for the administrator of the first server 200, the administrator of the second server 300, and the key recovery terminal 400, which does not input the correct secret information for generating certification information, to obtain the information of template T. Therefore, it becomes even more difficult to guess the fixed value of the secret key to be recovered in the key recovery process.

[0088] [Example of process modification] In the verification information generation process of step S1102, it is not necessary to generate either the first verification information or the second verification information. As an example, the case in which the second verification information is not generated is explained. In this case, it is not necessary to obtain the second verification information in the registration process, nor is it necessary to store the second registration information. In the key recovery process, it is not necessary to obtain the second certification information, nor is it necessary to generate the second certification information.

[0089] Furthermore, an example of the second rule for determining whether to send the second data is as follows. The first example of the second rule is that the second transmission permission determination unit 303, which receives the determined first transmission permission from the first server 200, determines the second transmission permission to "send" if the first transmission permission is "transmitted," and determines the second transmission permission to "deny" if the first transmission permission is "denied." Even when this rule is used, it is difficult for anyone other than the user themselves to receive the second distributed template by operating the key recovery terminal 400.

[0090] The second example of the second rule is that when the second server 300 receives a request to send the second distributed template to the key recovery terminal 400, the second transmission permission determination unit 303 always determines the second transmission permission to be "transmission permitted". This request is made, for example, by the key recovery terminal 400 or the first server 200. When this rule is used, it is possible for someone other than the user to receive the second distributed template by operating the key recovery terminal 400, but it is difficult to receive the first distributed template, making it difficult for anyone other than the user to obtain the template information.

[0091] Furthermore, at least one of the first transmission eligibility and the second transmission eligibility may be determined by communication between the first server 200 and the second server 300. For example, during the communication, the first server 200 may send to the second server 300 information generated from at least one of the first verification information and the first proof information. Also, multi-party computation or the like may be used to determine at least one of the first transmission eligibility and the second transmission eligibility.

[0092] Furthermore, in the specific example of distributed template generation, a distributed template is generated based on a template T after the template T is generated, but the template generation process and the distributed template generation process do not necessarily have to be separate. For example, if Y is the space to which the features belong, Q is a subspace of Y, and EC (the mapping from Y to Q) represents the error correction process, then in a method in which the distributed template generation unit 105 generates elements q of Q and a random number p on Y, and then determines T_1 = y + (q + p) and T_2 = p based on the registration feature y, the template T = y + q itself is not generated during the process, but the same distributed template as in the specific example of distributed template generation is generated.

[0093] Similarly, in the key recovery process, it is not necessary to clearly separate the recovery of the template T from the key recovery process using the template T. For example, in the distributed template generation process example described above (where the distributed template generation unit 105 generates elements q of Q and a random number p on Y, and then determines T_1 = y + (q + p) and T_2 = p based on the registration feature y), the key may be recovered using the key recovery feature y' by K' = EC (T_1 - (T_2 + y')).

[0094] Furthermore, the information that the user inputs to the key recovery terminal 400 during the key recovery process (referred to as key recovery input information) includes secret information for generating certification information and biometric information for key recovery. However, either the secret information for generating certification information or the biometric information for key recovery may be input first, or they may be input simultaneously. Also, if the secret information for generating certification information and the biometric information for key recovery match, or if one contains the other, the overlapping portion only needs to be input once.

[0095] Furthermore, during the registration process and key recovery process, the registration terminal 100 and the key recovery terminal 400 may accept input of information for identifying a user (for example, at least one of the following: user ID, name, and date of birth), and processing may be performed on the identified user (or narrowed-down candidate user).

[0096] Example 2 describes a key generation system 10 via a network. The key generation system 10 of Example 2 uses the user's biometric information as confidential information for generating verification information and confidential information for generating proof information, and by appropriately converting and storing the biometric information used as confidential information for generating verification information, it becomes even more difficult for anyone other than the user to obtain the biometric information. Hereafter, explanations of points similar to those in Example 1 may be omitted as appropriate.

[0097] Figure 5 is a block diagram showing an example of the functional configuration of the key generation system 10 in Embodiment 2. The registration terminal 100 in this embodiment differs from the registration terminal 100 in Embodiment 1 in that, for example, instead of the secret information acquisition unit 102 for generating verification information and the verification information generation unit 103, it includes a temporary first verification information generation unit 106 and a temporary first distributed template generation unit 107, both of which are functional units.

[0098] The first server 200 of this embodiment differs from the first server 200 of Embodiment 1 in that it further includes, for example, a first verification information generation unit 204, a first distributed template generation unit 205, and a first key recovery distributed template generation unit 206, all of which are functional units.

[0099] The second server 300 of this embodiment differs from the second server 300 of Embodiment 1 in that it further includes, for example, a second verification information generation unit 304, a verification information concealment information generation unit 305, a second distributed template generation unit 306, a template concealment information generation unit 307, a certification information concealment information generation unit 308, a second key recovery distributed template generation unit 309, and a first key recovery distributed template generation information generation unit 310, all of which are functional units.

[0100] The key recovery terminal 400 of this embodiment differs from the key recovery terminal 400 of Embodiment 1 in that, for example, it includes a functional unit, the first certification information generation unit 407, instead of the secret information acquisition unit 402 and the certification information generation unit 403 for generating certification information.

[0101] Figure 6 is a sequence diagram showing an example of the registration process in Embodiment 2. In step S3301, the second verification information generation unit 304 generates second verification information. In step S3302, the verification information concealment information generation unit 305 generates first verification information concealment information and second verification information concealment information using the second verification information generated in step S3301, and the communication unit 301 transmits the first verification information concealment information to the first server 200 and the second verification information concealment information to the registration terminal 100.

[0102] In step S3101, the biometric information acquisition unit 104 acquires biometric information for verification information generation and biometric information for registration from the user. In this embodiment, biometric information is used as confidential information for verification information generation, and hereafter this biometric information will also be referred to as biometric information for verification information generation. The biometric information for verification information generation and the biometric information for registration may be biometric information of the same modality, or one modality may include the other modality. In these cases, the biometric information for verification information generation and the biometric information for registration can be acquired simultaneously.

[0103] In step S3102, the temporary first verification information generation unit 106 generates temporary first verification information using the biometric information for verification information generation acquired in step S3101 and the second information for concealing verification information transmitted in step S3202, and the communication unit 101 transmits the generated temporary first verification information to the first server 200. In step S3201, the first verification information generation unit 204 generates first verification information using the first information for concealing verification information transmitted in step S3202 and the temporary first verification information transmitted in step S3102.

[0104] In step S3303, the second distributed template generation unit 306 generates a second distributed template. In step S3304, the template concealment information generation unit 307 generates first template concealment information and second template concealment information using the second distributed template generated in step S3303, and the communication unit 301 transmits the first template concealment information to the first server 200 and the second template concealment information to the registration terminal 100.

[0105] In step S3103, the temporary first distributed template generation unit 107 generates a temporary first distributed template using the registration biometric information acquired in step S3101 and the second template concealment information transmitted in step S3304, and the communication unit 101 transmits the generated temporary first distributed template to the first server 200.

[0106] In step S3202, the first distributed template generation unit 205 generates a first distributed template using the temporary first distributed template transmitted in step S3304 and the first template concealment information transmitted in step S3304.

[0107] In step S3203, the information registration unit 202 registers first registration information, which includes the first verification information generated in step S3201 and the first distributed template generated in step S3202, in the first registration information storage unit 220. In step S3305, the information registration unit 302 registers second registration information, which includes the second verification information generated in step S3301 and the second distributed template generated in step S3303, in the second registration information storage unit 320.

[0108] Figure 7 is a sequence diagram showing an example of the key recovery process in Embodiment 2. In step S4301, the certification information concealment information generation unit 308 generates the first certification information concealment information and the second certification information concealment information using the second verification information contained in the second registration information stored in the second registration information storage unit 320, and the communication unit 301 transmits the first certification information concealment information to the first server 200 and the second certification information concealment information to the key recovery terminal 400.

[0109] In step S4401, the biometric information acquisition unit 404 acquires biometric information as secret information for generating certification information (biometric information for generating certification information) and biometric information for key recovery from the user via the input device 10004. In step S4402, the first certification information generation unit 407 generates first certification information using the biometric information for generating certification information acquired in step S4401 and the second information for concealing certification information transmitted in step S4301, and the communication unit 401 transmits the first certification information to the first server 200.

[0110] In step S4201, the first transmission permission determination unit 203 determines whether to transmit based on a predetermined first rule. As an example of the first rule, the first transmission permission determination unit 203 performs a first verification process using the first information for concealing certification information transmitted in step S4301, the first certification information transmitted in step S4402, and the first verification information included in the first registration information stored in the first registration information storage unit 220. If the verification result is "verification successful", it determines "transmission permitted", and if the verification result is "verification failed", it determines "transmission not permitted".

[0111] In step S4302, the second transmission eligibility determination unit 303 determines the second transmission eligibility based on a predetermined second rule. As an example of the second rule, the second server 300 receives the first transmission eligibility determined in step S4201 from the first server 200, and the second transmission eligibility determination unit 303 determines the second transmission eligibility to be "transmittable" if the first transmission eligibility is "transmittable," and determines the second transmission eligibility to be "transmitted" if the first transmission eligibility is "not transmittable." As another example of the second rule, the second transmission eligibility determination unit 303 always determines the second transmission eligibility to be "transmittable."

[0112] In step S4303, if the second transmission permission is "transmission permitted", the second key recovery distributed template generation unit 309 generates a second key recovery distributed template, and the communication unit 301 transmits the second key recovery distributed template to the key recovery terminal 400. If the second transmission permission is "transmission denied", the second key recovery distributed template generation unit 309 refuses to transmit the second key recovery distributed template.

[0113] In step S4304, the first key recovery distributed template generation information generation unit 310 generates the first key recovery distributed template generation information using the second key recovery distributed template, and the communication unit 201 transmits the first key recovery distributed template generation information to the first server 200. If the second transmission permission status is "transmission denied", the first key recovery distributed template generation information generation unit 310 may refuse to transmit the first key recovery distributed template generation information.

[0114] In step S4202, if the first transmission permission is "transmission permitted", the first key recovery distributed template generation unit 206 generates the first key recovery distributed template using the first key recovery distributed template generation information transmitted in step S4304 and the first distributed template included in the first registration information stored in the first registration information storage unit 220, and transmits it to the key recovery terminal 400. If the first transmission permission is "transmission denied", the first key recovery distributed template generation unit 206 refuses to transmit the first key recovery distributed template.

[0115] In step S4403, the key recovery unit 405 recovers the secret key by performing a key recovery process using the first key recovery distributed template transmitted in step S4202, the second key recovery distributed template transmitted in step S4303, and the key recovery biometric information obtained in step S4410. In step S4404, the cryptographic processing execution unit 406 performs cryptographic processing using the secret key recovered in step S4403. An example of cryptographic processing is the same as in step S2405 of Embodiment 1.

[0116] [Specific Examples of Distributed Template Generation and Key Recovery] Specific examples of distributed template generation and key recovery are explained, along with specific examples of the data generated for these purposes.

[0117] The following is a specific example of the data generated for distributed template generation during the registration process. The second distributed template generation unit 306 generates a random number p and determines the second distributed template T_2 by T_2 = p. The template concealment information generation unit 307 generates a random number r and determines the first template concealment information I_1 by I_1 = T_2 - r and the second template concealment information I_2 by I_2 = r. The random number r, as well as the random numbers r', r'', and u described later, may be random numbers that follow a predetermined distribution in the space to which the template belongs (for example, uniform random numbers), similar to the random number p. In addition, the random numbers P, R, and R' may be random numbers that follow a predetermined distribution in the space to which the verification information generation feature v belongs (for example, uniform random numbers). It is preferable that sufficiently random numbers be used for these random numbers r, r', r'', u, P, R, and R'. Pseudorandom numbers may also be used.

[0118] The temporary first distributed template generation unit 107 extracts registration feature quantities y from registration biometric information x, generates a template T using the biometric cryptographic registration process Gen by T = Gen(y), and defines the temporary first distributed template T_tmp1 by T_tmp1 = T + I_2. The first distributed template generation unit 205 defines the first distributed template T_1 by T_1 = T_tmp1 + I_1.

[0119] A specific example of the data generated for key recovery is as follows: The second key recovery distributed template generation unit 309 generates a random number r'' and determines the second key recovery distributed template T'_2 by T'_2 = r''. The first key recovery distributed template generation information generation unit 310 determines the first key recovery distributed template generation information T'_tmp1 by T'_tmp1 = T_2 - T'_2.

[0120] The first key recovery distributed template generation unit 206 determines the first key recovery distributed template T'_1 by T'_1 = T_1 - T'_tmp1. The key recovery unit 405 recovers the template T by T = T'_1 - T'_2, extracts the key recovery feature quantity y' from the key recovery biometric information x', and recovers the secret key K' by K' = Rep(T, y') using the biometric cryptography key recovery process Rep.

[0121] [Specific Examples of Verification Information Generation, Proof Information Generation, and Verification] Specific examples of verification information generation, proof information generation, and verification will be explained. The first specific example will be explained. In the registration process, the second verification information generation unit 304 generates a random number P and determines the second verification information S_2 by S_2 = P. The verification information concealment information generation unit 305 generates a random number R and determines the first verification information concealment information H_1 by H_1 = S_2 - R and the second verification information concealment information H_2 by H_2 = R.

[0122] The temporary first verification information generation unit 106 extracts a feature quantity v for verification information generation from the biological information w for verification information generation, and determines the temporary first verification information S_tmp1 by S_tmp1 = v + H_2. The first verification information generation unit 204 determines the first verification information S_1 by S_1 = S_tmp1 + H_1.

[0123] In the key recovery process, the certification information concealment information generation unit 308 generates a random number R', and determines the first certification information concealment information H'_1 as H'_1 = S_2 - R', and the second certification information concealment information H'_2 as H'_2 = R'. The first certification information generation unit 407 extracts the certification information generation feature quantity v' from the certification information generation biometric information w', and determines the first certification information S'_1 as S'_1 = v' + H'_2.

[0124] The first transmission eligibility determination unit 203, as a first verification process, calculates the difference between v' and v, v'-v, using the formula v'-v = S'_1 + H'_1 - S_1, and determines the verification result as "verification successful" if the magnitude of v'-v (for example, the Euclidean norm if the feature is a real-valued vector, or the Hamming weights or L1 norm if it is an integer-valued vector) is less than or equal to a predetermined threshold t, and as "verification failed" otherwise.

[0125] Let me explain the second specific example. In the second specific example, registration biometric information x is used as verification biometric information w, and key recovery biometric information x' is used as proof biometric information w'. Therefore, in step S3101, the biometric information acquisition unit 104 does not need to acquire verification biometric information w, and in step S4401, the biometric information acquisition unit 404 does not need to acquire proof biometric information w'.

[0126] Furthermore, h is an arbitrary linear function that takes integer values ​​(for example, a linear hash), and g is a group generator. In addition, the Gen described in the specific example of the biometric cryptography processing in Example 1 is used (where Y is a region consisting of a d-dimensional real space or a part thereof, Q is a lattice (i.e., Q is a set defined as Q = {B * z: z is a d-dimensional column vector whose components are integers} using a predetermined d x d real square matrix B, B * z is the matrix product of matrix B and vector z), and EC is the nearest neighbor lattice point solving process). This Gen is also assumed to be used in the temporary first distributed template generation process.

[0127] In the registration process, the second verification information generation unit 304 generates a random number P and determines the second verification information S_2 by S_2 = P. The verification information concealment information generation unit 305 generates a random number R and determines the first verification information concealment information H_1 by H_1 = S_2 - R and the second verification information concealment information H_2 by H_2 = R.

[0128] The temporary first verification information generation unit 106 uses q (let's call this q q_1) generated by Gen in the temporary first distributed template generation process to determine an integer a by a = h(B^(-1) * q_1) (where "^" indicates exponentiation), and determines the temporary first verification information S_tmp1 by S_tmp1 = g^(a + H_2). The first verification information generation unit 204 determines the first verification information S_1 by S_1 = S_tmp1 * g^H_1.

[0129] In the key recovery process, the certification information concealment information generation unit 308 generates random numbers R' and r', sets H'_11 = S_2 - R' and H'_12 = T_2 - r', and defines the first certification information concealment information H'_1 as H'_1 = (H'_11, H'_12). Furthermore, the certification information concealment information generation unit 308 sets H'_21 = R' and H'_22 = r', and defines the second certification information concealment information H'_2 as H'_2 = (H'_21, H'_22).

[0130] The first proof information generation unit 407 defines the first proof information S'_1 as the following pair (S'_11, S'_12). The first proof information generation unit 407 extracts the key recovery feature quantity y' from the key recovery biometric information x', defines T' by T' = Gen(y'), and defines S'_12 by S'_12 = T' + H'_22. Furthermore, the first proof information generation unit 407 uses the generated q (let's call this q q'_1) to define the integer a' by a' = h(B^(-1) * q'_1), and defines S'_11 by S'_11 = g^(a' + H'_21).

[0131] The first transmission eligibility determination unit 203, as a first verification process, first calculates the template difference T-T' using T-T' = T_1 - S'_12 - H'_12, and then calculates the estimated value D_1 of a-a' using D_1 = h(B^(-1) * EC(T-T')). When y and y' are sufficiently close, specifically when EC(y-y') is a zero vector, D_1 = a-a'. Therefore, the first transmission eligibility determination unit 203 determines the verification result as "verification successful" if S'_11 * (g^(D_1 + H'_11)) = S_1 holds, and as "verification failed" otherwise.

[0132] Let me explain the third specific example. In this third example, registration biometric information x is used as verification biometric information w, and key recovery biometric information x' is used as proof biometric information w'. For this reason, in step S3101, the biometric information acquisition unit 104 does not need to acquire verification biometric information w, and in step S4401, the biometric information acquisition unit 404 does not need to acquire proof biometric information w'.

[0133] Furthermore, the generation and storage of the first and second verification information are unnecessary, and the first verification process is performed using the first and second distributed templates. Specifically, in the registration process, the processes in steps S3301, S3302, S3102, and S3201 are unnecessary. Also, the first registration information and the second registration information do not necessarily have to include the first and second verification information, respectively.

[0134] In the key recovery process, the proof information concealment information generation unit 308 generates a random number r', and determines the first proof information concealment information H'_1 by H'_1 = T_2 - r' and H'_2 by H'_2 = r'. The first proof information generation unit 407 extracts the key recovery feature quantity y' from the key recovery biometric information x', determines T' by T' = Gen(y'), and determines S'_1 by S'_1 = T' + H'_2.

[0135] The first transmission eligibility determination unit 203 calculates the template difference T-T' using T-T' = T_1 - S'_1 - H'_1 and uses the template difference to calculate an estimated value D_2 of the magnitude of y-y'. For example, the first transmission eligibility determination unit 203 defines D_2 as the Euclidean norm of T-T' - EC(T-T'). It can be seen that when EC(y-y') is a zero vector, D_2 is the Euclidean norm of y-y'. In the first verification process, the first transmission eligibility determination unit 203 determines the verification result as "verification successful" if D_2 is less than or equal to a predetermined threshold, and as "verification failed" otherwise.

[0136] [Main Effects of This Embodiment] In this embodiment, the user's biometric information is used as the secret information for generating verification information and the secret information for generating certification information, and the first registration information and the second registration information are defined such that neither the first server 200 nor the second server 300 can obtain information on the biometric information for generating verification information. Furthermore, unless the user inputs the biometric information for generating certification information into the key recovery terminal 400, it is difficult for the first server 200, the second server 300, and the key recovery terminal 400 to obtain information on the biometric information for generating verification information during the key recovery process.

[0137] If someone other than the individual could obtain information regarding the biometric information used for generating verification information, they could potentially impersonate the individual by generating biometric information for generating proof information based on that information. However, since it is difficult for someone other than the individual to obtain information regarding the biometric information used for generating verification information, it is difficult to successfully impersonate someone in this way (specifically, to succeed in the first verification process). This means that it is difficult for someone other than the individual to obtain information regarding the biometric information used for registration.

[0138] Thus, this embodiment makes it possible to realize a key generation system 10 in which it is difficult for anyone other than the person concerned to obtain biometric information (both registration biometric information and confidential information for generating verification information). Furthermore, since the key generation system 10 of this embodiment also uses biometric information for the confidential information for generating certification information, it has the advantage of convenience of not requiring the storage of a physical device or the storage of knowledge for key recovery processing.

[0139] Furthermore, the method described in the specific example of distributed template generation and key recovery in this embodiment has the following effects. To explain the effects, the set of registered first distributed template T_1 and second distributed template T_2 is also called a distributed template set, and the set of first key recovery distributed template T'_1 and second key recovery distributed template T'_2, which are sent to the key recovery terminal 400 for key recovery, is also called a key recovery distributed template set.

[0140] In Example 1, it can be understood that the distributed template set for key recovery (T'_1, T'_2), defined by T'_1 = T'1 and T'_2 = T'2, is sent to the key recovery terminal 400. In contrast, in Example 2, the distributed template set (T'_1, T'2) is transformed by a random number r'' to generate (T'_1, T'_2), which is then sent to the key recovery terminal 400. As a result, the values ​​of each distributed template T'1 and T'2 are not sent outside of the respective servers where they are stored, making it more difficult for the user to recover a template T that they did not intend.

[0141] Furthermore, the second and third specific examples of verification information generation, proof information generation, and verification in this embodiment have the following advantages. First, biometric information for generating verification information and biometric information for generating proof information are not required. Therefore, one type of biometric information is sufficient, improving user convenience.

[0142] Furthermore, even if a powerful attack were to occur in which data stored on multiple servers were stolen, the data that would be recovered would be template T and g^a in the second example, and only template T in the third example, thus maintaining the difficulty of recovering the registration feature y.

[0143] In other words, the second and third specific examples demonstrate that a key generation system 10 can be realized that requires only one type of biometric information, is difficult for anyone other than the person concerned to obtain information on the registration feature quantity y unless stored data is stolen from multiple servers, and maintains the difficulty of recovering the registration feature quantity y even in the event of a powerful attack in which stored data is stolen from multiple servers.

[0144] Furthermore, the third specific example has the following effect: In the first and second specific examples of verification information generation, proof information generation, and verification, the kth registration information E_k stored on the kth server (k=1,2) consists of the kth verification information S_k and the kth distributed template T_k. In contrast, in the third specific example, the kth registration information E_k consists only of the kth distributed template T_k, which has the advantage of storage efficiency as it eliminates the need to store additional data for the verification process.

[0145] [Example of process modification] By adding the following process, a verification process can be included in the second transmission eligibility determination. In the registration process, steps S3301, S3302, S3102, and S3201 (and steps S3303, S3304, S3103, and S3202 if a distributed template is used for the verification process) which are processes related to the generation of the first verification information and the second verification information are performed with the roles of the first server 200 and the second server 300 swapped. As a result, the first server 200 can obtain the second verification information, and the second server 300 can obtain the first verification information (and the second distributed template and the first distributed template, respectively, if a distributed template is used for the verification process), the first server 200 can include the second verification information in the first registration information, and the second server 300 can include the first verification information in the second registration information.

[0146] In the key recovery process, steps S4301 and S4402, which are processes related to the first certification information, are performed with the roles of the first server 200 and the second server 300 reversed. As a result, the second server 300 can obtain the first certification information, and the second transmission permission determination unit 303 can perform the verification process using the same method as the first verification process in step S4201.

[0147] Furthermore, in order to make it difficult to obtain information such as biometric data, when the roles of the first server 200 and the second server 300 are swapped and each process is performed, it is desirable to generate the random numbers necessary for each process again.

[0148] Furthermore, the order of processing may be changed as long as it is feasible. For example, when the second transmission permission determination in step S4302 is always "transmission permitted", steps S4303 and S4304 may be performed simultaneously with step S4301, or before step S4301.

[0149] Furthermore, in Examples 1 and 2, the key generation system 10 was described as performing key recovery using a distributed template set for key recovery, which is generated based on a distributed template set consisting of distributed templates stored in two servers (first server 200 and second server 300). Generalizing this, the key generation system 10 may also perform key recovery using a distributed template set for key recovery, which is generated based on a distributed template set consisting of distributed templates stored in n servers (where n is an integer of 2 or more).

[0150] In this case, there may be servers that store each of the distributed templates other than the n distributed templates mentioned above. That is, the key generation system 10 may include N servers (N is an integer greater than or equal to n) (first server 200 to the nth server), each of the N servers storing one distributed template, and a set of distributed templates consisting of the distributed templates (first distributed template to the nth distributed template) stored in n servers (first server 200 to the nth server) out of the N servers may be used to define the key recovery distributed template set. Note that the notation "X to Y" refers to the range from X to Y, including X and Y. In other words, for example, the description "Server 1 200 to Server N" refers to N servers consisting of Server 1 200, Server 2 300, ..., Server (N-1), and Server N, and the description "Distributed template 1 to Distributed template n" refers to N distributed templates consisting of Server 1, Distributed template n, ..., Server (N-1), and Template N.

[0151] For example, one possible method is to generate N distributed templates by applying an (n,N) threshold secret sharing scheme (e.g., Shamir's secret sharing scheme) to a template T generated by a registration terminal 100, and then store these templates on N servers. In this case, if there are distributed templates stored on n servers, template T can be restored.

[0152] Not limited to the (n, N) threshold secret sharing method, any secret sharing method may be applied. Depending on the secret sharing method, the number of distributed templates required for restoration is not fixed, but a process of determining a distributed template set for key restoration using a distributed template set consisting of the number of distributed templates required for restoration may be performed.

[0153] Note that when a distributed template set consisting of distributed templates (first distributed template to nth distributed template) stored in n servers (N ≥ n) out of N servers (first server 200 to nth server) is used to determine the distributed template set for key restoration, in m servers (1 ≤ m ≤ n) out of the first server 200 to the nth server, a transmission permission determination is made by a verification process using proof information and registration information. That is, for example, among the first server 200 to the nth server, to m th a i servers (i is an arbitrary integer from 1 or more and m or less, and each value of a 1 to a m is a different integer from 1 or more and n or less), the a k proof information is transmitted to the a i server, and the rule is that when the verification process using the a i proof information and the a i registration information is successful, the a i [[ID=1第十九]]transmission permission is determined to be transmission-permissible, and when the verification process fails, the a i transmission permission is determined to be non-transmissible. Further, among the first server 200 to the nth server, in servers other than the m th a i servers, a rule for determining transmission permission according to at least one result of the a 1 transmission permission determination to the a m transmission permission determination (for example, a rule similar to the second rule described in Example 1 (for example, a rule that is "transmission-permissible" only when all of the a 1 transmission permission determination to the a m transmission permission determination are "transmission-permissible") may be used, or a rule for determining transmission permission according to at least one result of the a 1 transmission permission determination to the a mA rule is defined which determines whether a transmission is permitted if a predetermined number of transmission permission decisions (the predetermined number being 1 or more and m-1 or less) or more are "transmission permitted," and whether a transmission permission decision is not permitted if fewer than the predetermined number of transmission permission decisions are "transmission permitted." Alternatively, the rule may be defined which of the first 200 to the nth server is the mth a i A rule may be defined on at least one server other than the server itself that always sets it to "transmittable".

[0154] Furthermore, as an example of generating more than two distributed templates, a secret sharing scheme may be applied to the first and second distributed templates, respectively, using the methods described in the specific examples of distributed template generation and key recovery in Example 1 and Example 2.

[0155] Furthermore, the distributed template stored on each server may be divided into multiple data items, in which case the distributed template stored on that server can be considered as a set of those multiple data items.

[0156] Furthermore, the key generation system 10 may include entities related to the distributed template set for key recovery other than the first server 200, ..., and the nth server. The following is an example for n=2. Assume that when the registration process is completed, the first server 200 stores the first distributed template T_1 = T + p + u (where T is the template and p and u are random numbers), the second server 300 stores the second distributed template T_2 = p, and the additional server (an example of the entities described above) stores the random number u.

[0157] In the key recovery process, when the decision to allow transmission at each server is "allowed to transmit", the additional server generates a random number r, sends r to the first server 200, and sends u + r to the second server 300. The first server 200 defines the first key recovery distributed template T'_1 as T'_1 = T_1 + r, and the second server 300 defines the second key recovery distributed template T'_2 as T'_2 = T_2 + u + r. The key recovery terminal 400 can recover T from T'_1 and T'_2 using T = T'_1 - T'_2, and key recovery becomes possible from T and the key recovery biometric information.

[0158] Furthermore, some or all of the devices constituting the key generation system 10 may be a single physical device, or they may be separated by virtual machines or the like. In this case as well, if each virtual machine has a different administrator, the effect of making it difficult for anyone other than the user to obtain biometric information can be obtained.

[0159] It should be noted that the present invention is not limited to the embodiments described above, and various modifications are included. For example, the embodiments described above are described in detail to make the present invention easier to understand, and are not necessarily limited to those having all the configurations described. It is also possible to replace parts of the configuration of one embodiment with the configuration of another embodiment, and it is also possible to add configurations from other embodiments to the configuration of one embodiment. Furthermore, it is possible to add, delete, or replace parts of the configuration of each embodiment with other configurations.

[0160] Furthermore, each of the above configurations, functions, processing units, processing means, etc., may be implemented in hardware, either partially or entirely, by designing them as integrated circuits, for example. Alternatively, each of the above configurations, functions, etc., may be implemented in software by having the processor interpret and execute programs that realize each function. Information such as programs, tables, and files that realize each function can be stored in memory, a recording device such as a hard disk or SSD (Solid State Drive), or a recording medium such as an IC card, SD card, or DVD.

[0161] Furthermore, the control lines and information lines shown are those deemed necessary for explanatory purposes, and not all control lines and information lines are necessarily shown in the actual product. In reality, it is safe to assume that almost all components are interconnected.

Claims

1. An information processing system comprising a key recovery terminal and a first to nth server (where n is an integer of 2 or more), wherein the kth server (where k is any integer from 1 to n) holds the kth registration information, which includes the kth distributed template included in a distributed template set generated based on registration biometric information, the key recovery terminal receives input of key recovery input information including key recovery biometric information, generates m pieces of proof information (where m is a predetermined integer from 1 to n) using the key recovery input information, and each of the m pieces of proof information is assigned to the a 1 Server to the a m Server (a 1 or a m Each value of is sent as a distinct integer between 1 and n, and the k server determines whether to send the k-th key recovery distributed template included in the key recovery distributed template set determined from the distributed template set to the key recovery terminal based on a predetermined k-th rule, and if the key recovery terminal successfully receives the key recovery distributed template set, it recovers the secret key by performing a secret key recovery process using the key recovery distributed template set and the key recovery biometric information, and the a i The rule (where i is any integer between 1 and m) is the received proof information and the a i An information processing system that performs a verification process using registered information, and determines whether transmission is permitted if the verification result in the verification process is successful, and determines whether transmission is not permitted if the verification result is unsuccessful.

2. An information processing system according to claim 1, wherein at least one of the first to nth distributed templates is generated based on a template generated by a transformation using transformation parameters applied to registration features extracted from the registration biometric information.

3. An information processing system according to claim 1, wherein the k-key recovery distributed template is the k-distributed template.

4. An information processing system according to claim 1, wherein the distributed template for recovering the j-th key has at least one integer j of 1 or more and less than or equal to n, which has a different value from the j-th distributed template.

5. An information processing system according to claim 4, wherein at least one of the first key recovery distributed template to the nth key recovery distributed template is generated based on a random number generated for concealment.

6. An information processing system according to claim 1, wherein the key recovery input information includes biometric information for generating certification information, and the key recovery terminal generates at least one of the one or more certification information using the biometric information for generating certification information.

7. An information processing system according to claim 6, wherein at least one of the first to nth distributed templates is generated by concealing the biometric information for generating proof information using parameters.

8. An information processing system according to claim 1, wherein the key recovery terminal generates at least one of the m pieces of certification information using the key recovery biometric information.

9. An information processing system according to claim 8, wherein at least one of the verification processes includes a process for verifying the difference between an integer generated in the generation of the distributed template set and an integer generated in the generation of the proof information.

10. An information processing system according to claim 8, wherein the verification process includes a process for calculating an estimated distance between a registration feature quantity generated from the registration biometric information and a key recovery feature quantity generated from the key recovery biometric information.

11. An information processing system according to claim 10, wherein the k registration information is the k distributed template.

12. An information processing system according to claim 1, wherein the k distributed template is generated by a process that conceals a template generated from the registration biometric information using a distributed template generation random number, and the secret key recovery process includes a process that recovers the template from the key recovery distributed template set.

13. An information processing system comprising: a key recovery terminal; and a server set including a plurality of servers, wherein the server set stores a distributed registration information set including a distributed template set generated from registration biometric information in a distributed manner; the key recovery terminal receives input information for key recovery; generates one or more pieces of proof information using the key recovery input information; transmits the one or more pieces of proof information to the server set; the server set determines whether or not to transmit a distributed template set for key recovery, determined from the distributed template set, to the key recovery terminal based on the distributed registration information set and the proof information stored in a distributed manner; and if the key recovery terminal successfully receives the distributed template set for key recovery, it recovers a private key using the distributed template set for key recovery and the key recovery input information.

14. An information processing method by an information processing system, wherein the information processing system includes a key restoration terminal and first to nth servers (n is an integer of 2 or more), and the kth server (k is an arbitrary integer of 1 or more and n or less) holds kth registration information including the kth distributed template included in a distributed template set generated based on registration biometric information. The information processing method includes: the key restoration terminal receiving an input of key restoration input information including key restoration biometric information; the key restoration terminal generating m pieces (m is a predetermined integer of 1 or more and n or less) of proof information using the key restoration input information; the key restoration terminal transmitting the m pieces of proof information to m servers, i.e., the ath 1 server to the ath m server (each value of a 1 to a m is a different integer of 1 or more and n or less) among the first to nth servers; the kth server determining whether to transmit the kth key restoration distributed template included in the key restoration distributed template set determined from the distributed template set to the key restoration terminal based on a predetermined kth rule; and the key restoration terminal restoring a secret key by secret key restoration processing using the key restoration distributed template set and the key restoration biometric information when the key restoration distributed template set is successfully received. The ath i rule (i is an arbitrary integer of 1 or more and m or less) is a rule that performs verification processing using the received proof information and the ath i registration information, determines that the transmission is possible when the verification result in the verification processing is a verification success, and determines that the transmission is not possible when the verification result is a verification failure. Information processing method.

Citation Information

Patent Citations

  • Template management system and template management method

    JP2023125727A

  • Leveraging multiple devices to enhance security of biometric authentication

    US20210336792A1

  • Distributed private key recovery

    US20230050481A1

  • Method for Secure Privacy-Preserving Device-Free Biometric Signing with Multi-Party Computation and Cancelable Biometric Template

    US20240259204A1