EP1208540A1 - Procede, dispositif et systeme permettant une identification biometrique - Google Patents

Procede, dispositif et systeme permettant une identification biometrique

Info

Publication number
EP1208540A1
EP1208540A1 EP00956278A EP00956278A EP1208540A1 EP 1208540 A1 EP1208540 A1 EP 1208540A1 EP 00956278 A EP00956278 A EP 00956278A EP 00956278 A EP00956278 A EP 00956278A EP 1208540 A1 EP1208540 A1 EP 1208540A1
Authority
EP
European Patent Office
Prior art keywords
data
authentication
biometric
stored
biometric data
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
EP00956278A
Other languages
German (de)
English (en)
Inventor
Albert MÖDL
Elmar Stephan
Robert Müller
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Giesecke+Devrient GmbH
Original Assignee
Giesecke+Devrient GmbH
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Giesecke+Devrient GmbH filed Critical Giesecke+Devrient GmbH
Publication of EP1208540A1 publication Critical patent/EP1208540A1/fr
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/32User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07CTIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
    • G07C9/00Individual registration on entry or exit
    • G07C9/30Individual registration on entry or exit not involving the use of a pass
    • G07C9/32Individual registration on entry or exit not involving the use of a pass in combination with an identity check
    • G07C9/37Individual registration on entry or exit not involving the use of a pass in combination with an identity check using biometric data, e.g. fingerprints, iris scans or voice recognition

Definitions

  • the invention relates to a method, as well as a device and a system for biometric authentication, in particular for securing the biological authentication against replay attacks.
  • An authentication procedure is used when a person requests access to secure facilities. For example, authentication is carried out regularly by means of a PIN comparison if a card user inserts a chip card - for example a credit card - into an automated teller machine (terminal) or if a person requests entry to secure premises. For this purpose, a stored PIN is checked for identity with the PIN specified by the card user or the person requesting entry.
  • a biometric feature of the person is used as an identification feature instead of a PIN.
  • the biometric feature can be a fingerprint, for example, but in the context of the present invention is also intended to include a personal signature.
  • a disadvantage of such authentication methods is that authentication can be attacked if the biometric data that has been stored as reference data or that has led to authentication is intercepted by unauthorized third parties in order to use it again later for unauthorized authentication , This type of attack is known as a replay attack.
  • the object of the present invention is therefore to secure biometric authentication methods against replay attacks. This object is achieved by the features of the independent claims. Advantageous refinements of the invention are specified in subclaims.
  • the invention makes use of the fact that the biometric features are generally common, that in contrast to the PIN they are not 100% reproducible, which is why authorization is already given when the biometric feature presented by the person matches the stored reference data exceeds a predetermined threshold.
  • a predetermined threshold value in particular not 100% and preferably not more than 99%.
  • a replay attack can in fact be assumed and, according to the invention, the authentication is consequently refused.
  • a comparison circuit is provided which generates a message and, for example, outputs an error message when a comparison of the reference data with the newly recorded biometric data of a person results in a match lying above this (second) threshold value. If the error message is output, it can also be provided to automatically block further operation.
  • the (second) visual value of 99% or 100% relevant to the invention is stored either in a terminal or on a separate data carrier, in particular a chip card, together with the reference data.
  • the recorded biometric data which have led to an authentication and possibly also the recorded biometric data which did not lead to the authentication because they were below the first threshold value are collected and stored as data records ⁇ verden. These data records are preferably stored in a stack memory or shift register. During each authentication process, it is then checked whether the biometric data of the presented biometric feature are identical to one of the stored data records or if more than 99% match. A replay attack can then be assumed and authentication is refused by the authentication system.
  • hash values of the same are stored.
  • a hash function is applied to the comparison data record, which generates a relatively short hash value.
  • Hash functions are known per se, a hash function being a unique, compressive mapping to a word of fixed length.
  • the hash function is processed in several rounds on a block-by-block partition of the output data. The result depends on the entire input. It is not possible to calculate the output data from the hash value. It is complexity theory difficult to change the input data in such a way that the hash value remains the same.
  • the hash value is recalculated.
  • the probability that two biometric data sets produce the same hash value is low, so that a replay attack must be assumed if they match.

Landscapes

  • Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Human Computer Interaction (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Collating Specific Patterns (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)

Abstract

La présente invention concerne un procédé, un dispositif et un système permettant une identification biométrique qui protège contre un piratage par réexécution. Lors de l'identification biométrique, une caractéristique biométrique présentée par une personne, une empreinte digitale ou sa signature personnelle par exemple, est présentée, puis est comparée à des données de référence préalablement enregistrées. L'objectif de cette invention est d'éviter que les données biométriques soient récupérées, puis réutilisées pour une identification non autorisée. Afin d'atteindre cet objectif, une identification avec 100 % et même seulement 99 % de coïncidence des données de la caractéristique biométrique présentée avec les données de référence est refusée. Etant donné que les caractéristiques biométriques ne peuvent en général pas être reproduites à 100 %, si le dispositif détecte une coïncidence à 100 %, cela signifie qu'il peut s'agir d'un piratage par réexécution. Dans un mode de réalisation de cette invention, les caractéristiques biométriques présentées sont collectées et enregistrées, puis, dans des processus d'identification subséquents, sont prises en compte lors de l'examen concernant le piratage par réexécution.
EP00956278A 1999-07-30 2000-07-25 Procede, dispositif et systeme permettant une identification biometrique Ceased EP1208540A1 (fr)

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
DE19936094 1999-07-30
DE19936094A DE19936094C1 (de) 1999-07-30 1999-07-30 Verfahren und Vorrichtung zur biometrischen Authentisierung
PCT/EP2000/007124 WO2001009847A1 (fr) 1999-07-30 2000-07-25 Procede, dispositif et systeme permettant une identification biometrique

Publications (1)

Publication Number Publication Date
EP1208540A1 true EP1208540A1 (fr) 2002-05-29

Family

ID=7916749

Family Applications (1)

Application Number Title Priority Date Filing Date
EP00956278A Ceased EP1208540A1 (fr) 1999-07-30 2000-07-25 Procede, dispositif et systeme permettant une identification biometrique

Country Status (4)

Country Link
EP (1) EP1208540A1 (fr)
AU (1) AU6828300A (fr)
DE (1) DE19936094C1 (fr)
WO (1) WO2001009847A1 (fr)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR100899199B1 (ko) 2002-11-05 2009-05-27 삼성전자주식회사 지문인식을 이용한 보안시스템 및 보안방법
US7693313B2 (en) * 2004-03-22 2010-04-06 Raytheon Company Personal authentication device
RU2294014C1 (ru) * 2005-08-15 2007-02-20 Федеральное государственное унитарное предприятие "ПЕНЗЕНСКИЙ НАУЧНО-ИССЛЕДОВАТЕЛЬСКИЙ ЭЛЕКТРОТЕХНИЧЕСКИЙ ИНСТИТУТ" (ФГУП "ПНИЭИ") Способ оценки стойкости биометрической защиты к атакам подбора

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5280527A (en) * 1992-04-14 1994-01-18 Kamahira Safe Co., Inc. Biometric token for authorizing access to a host system
US5870723A (en) * 1994-11-28 1999-02-09 Pare, Jr.; David Ferrin Tokenless biometric transaction authorization method and system
WO1998011750A2 (fr) * 1996-09-11 1998-03-19 Yang Li Procede d'utilisation d'empreintes digitales pour l'authentification des communications sans fil
DE19730170A1 (de) * 1997-07-15 1999-01-21 Rene Baltus Vielfacherfassungs- und Vergleichsgerät für biometrische Merkmale

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See references of WO0109847A1 *

Also Published As

Publication number Publication date
WO2001009847A1 (fr) 2001-02-08
DE19936094C1 (de) 2001-04-26
AU6828300A (en) 2001-02-19

Similar Documents

Publication Publication Date Title
DE4003386C1 (fr)
DE69328454T2 (de) Verbesserte Authentizitätsfeststellungsrückrufverfahren und Gerät
DE3103514C2 (de) Verfahren und Vorrichtung zum Sichern von Transaktionen
DE69315419T2 (de) Vorrichtung mit Zugangskontrolle für den Erhalt von Dienstleistungen
EP1188151B1 (fr) Dispositifs et procede pour l'authentification biometrique
EP1326470A2 (fr) Méthode et appareil pour l'authentification d'un souscripteur dans un réseau de communications
DE69702454T2 (de) Sicherheitsvorrichtungen und systeme
DE69425717T2 (de) Verfahren zur Anpassung an Kohle/Elektret-Mikrofoncharakteristiken der Telefonhörers für die automatische Sprecheridentitätsprüfung
WO1999048056A1 (fr) Procede et dispositif permettant de controler une caracteristique biometrique
WO1998047110A1 (fr) Procede de verification d'identite
WO1998050880A1 (fr) Procede d'adaptation par ordinateur d'un jeu de donnees de reference a l'aide d'un jeu de donnees d'entree
DE102018208118A1 (de) Verfahren und Vorrichtung zum Authentifizieren einer über einen Bus übertragenen Nachricht
AT401205B (de) System zur identifizierung eines kartenbenutzers
DE102018109825A1 (de) Wahlverfahren und Stimmabgabegerät
DE60105550T2 (de) Verfahren zum schutz gegen den diebstahl eines geheimkodes auf einer chipkarte fur mehrfachanwendungen, und chipkarten zur durchführung dieses verfahrens
EP1208540A1 (fr) Procede, dispositif et systeme permettant une identification biometrique
EP1116358A1 (fr) Procede d'authentification d'au moins un abonne lors d'un echange de donnees
EP1071034A2 (fr) Enregistrement d'empreintes digitales
DE102009014919A1 (de) Verfahren und Vorrichtung zum Authentifizieren eines Benutzers
DE19841886A1 (de) Verfahren und Vorrichtung zur Erzeugung von Paßwörtern
WO2001069900A1 (fr) Verification d'un appelant au moyen d'un procede biometrique
DE69725252T2 (de) Verfahren und Vorrichtung zur Prüfung von Sprache
DE19921387C2 (de) Anordnung und Verfahren zum Vergleich von Biometrik-Daten
DE102006034241A1 (de) Verfahren zur Ermittlung einer Berechtigung
DE102014100794A1 (de) Verfahren zumindest zum Lesen wenigstens einer Ausweisnummer von Benutzerdatenspeichern mit unterschiedlichen Datenstrukturen

Legal Events

Date Code Title Description
PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

17P Request for examination filed

Effective date: 20020228

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AT BE CH CY DE DK ES FI FR GB GR IE IT LI LU MC NL PT SE

AX Request for extension of the european patent

Free format text: AL;LT;LV;MK;RO;SI

17Q First examination report despatched

Effective date: 20030703

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE APPLICATION HAS BEEN REFUSED

18R Application refused

Effective date: 20060421