EP1208540A1 - Procede, dispositif et systeme permettant une identification biometrique - Google Patents
Procede, dispositif et systeme permettant une identification biometriqueInfo
- Publication number
- EP1208540A1 EP1208540A1 EP00956278A EP00956278A EP1208540A1 EP 1208540 A1 EP1208540 A1 EP 1208540A1 EP 00956278 A EP00956278 A EP 00956278A EP 00956278 A EP00956278 A EP 00956278A EP 1208540 A1 EP1208540 A1 EP 1208540A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- data
- authentication
- biometric
- stored
- biometric data
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/32—User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07C—TIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
- G07C9/00—Individual registration on entry or exit
- G07C9/30—Individual registration on entry or exit not involving the use of a pass
- G07C9/32—Individual registration on entry or exit not involving the use of a pass in combination with an identity check
- G07C9/37—Individual registration on entry or exit not involving the use of a pass in combination with an identity check using biometric data, e.g. fingerprints, iris scans or voice recognition
Definitions
- the invention relates to a method, as well as a device and a system for biometric authentication, in particular for securing the biological authentication against replay attacks.
- An authentication procedure is used when a person requests access to secure facilities. For example, authentication is carried out regularly by means of a PIN comparison if a card user inserts a chip card - for example a credit card - into an automated teller machine (terminal) or if a person requests entry to secure premises. For this purpose, a stored PIN is checked for identity with the PIN specified by the card user or the person requesting entry.
- a biometric feature of the person is used as an identification feature instead of a PIN.
- the biometric feature can be a fingerprint, for example, but in the context of the present invention is also intended to include a personal signature.
- a disadvantage of such authentication methods is that authentication can be attacked if the biometric data that has been stored as reference data or that has led to authentication is intercepted by unauthorized third parties in order to use it again later for unauthorized authentication , This type of attack is known as a replay attack.
- the object of the present invention is therefore to secure biometric authentication methods against replay attacks. This object is achieved by the features of the independent claims. Advantageous refinements of the invention are specified in subclaims.
- the invention makes use of the fact that the biometric features are generally common, that in contrast to the PIN they are not 100% reproducible, which is why authorization is already given when the biometric feature presented by the person matches the stored reference data exceeds a predetermined threshold.
- a predetermined threshold value in particular not 100% and preferably not more than 99%.
- a replay attack can in fact be assumed and, according to the invention, the authentication is consequently refused.
- a comparison circuit is provided which generates a message and, for example, outputs an error message when a comparison of the reference data with the newly recorded biometric data of a person results in a match lying above this (second) threshold value. If the error message is output, it can also be provided to automatically block further operation.
- the (second) visual value of 99% or 100% relevant to the invention is stored either in a terminal or on a separate data carrier, in particular a chip card, together with the reference data.
- the recorded biometric data which have led to an authentication and possibly also the recorded biometric data which did not lead to the authentication because they were below the first threshold value are collected and stored as data records ⁇ verden. These data records are preferably stored in a stack memory or shift register. During each authentication process, it is then checked whether the biometric data of the presented biometric feature are identical to one of the stored data records or if more than 99% match. A replay attack can then be assumed and authentication is refused by the authentication system.
- hash values of the same are stored.
- a hash function is applied to the comparison data record, which generates a relatively short hash value.
- Hash functions are known per se, a hash function being a unique, compressive mapping to a word of fixed length.
- the hash function is processed in several rounds on a block-by-block partition of the output data. The result depends on the entire input. It is not possible to calculate the output data from the hash value. It is complexity theory difficult to change the input data in such a way that the hash value remains the same.
- the hash value is recalculated.
- the probability that two biometric data sets produce the same hash value is low, so that a replay attack must be assumed if they match.
Landscapes
- Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Human Computer Interaction (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- General Engineering & Computer Science (AREA)
- Collating Specific Patterns (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
Abstract
La présente invention concerne un procédé, un dispositif et un système permettant une identification biométrique qui protège contre un piratage par réexécution. Lors de l'identification biométrique, une caractéristique biométrique présentée par une personne, une empreinte digitale ou sa signature personnelle par exemple, est présentée, puis est comparée à des données de référence préalablement enregistrées. L'objectif de cette invention est d'éviter que les données biométriques soient récupérées, puis réutilisées pour une identification non autorisée. Afin d'atteindre cet objectif, une identification avec 100 % et même seulement 99 % de coïncidence des données de la caractéristique biométrique présentée avec les données de référence est refusée. Etant donné que les caractéristiques biométriques ne peuvent en général pas être reproduites à 100 %, si le dispositif détecte une coïncidence à 100 %, cela signifie qu'il peut s'agir d'un piratage par réexécution. Dans un mode de réalisation de cette invention, les caractéristiques biométriques présentées sont collectées et enregistrées, puis, dans des processus d'identification subséquents, sont prises en compte lors de l'examen concernant le piratage par réexécution.
Applications Claiming Priority (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE19936094 | 1999-07-30 | ||
| DE19936094A DE19936094C1 (de) | 1999-07-30 | 1999-07-30 | Verfahren und Vorrichtung zur biometrischen Authentisierung |
| PCT/EP2000/007124 WO2001009847A1 (fr) | 1999-07-30 | 2000-07-25 | Procede, dispositif et systeme permettant une identification biometrique |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP1208540A1 true EP1208540A1 (fr) | 2002-05-29 |
Family
ID=7916749
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP00956278A Ceased EP1208540A1 (fr) | 1999-07-30 | 2000-07-25 | Procede, dispositif et systeme permettant une identification biometrique |
Country Status (4)
| Country | Link |
|---|---|
| EP (1) | EP1208540A1 (fr) |
| AU (1) | AU6828300A (fr) |
| DE (1) | DE19936094C1 (fr) |
| WO (1) | WO2001009847A1 (fr) |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR100899199B1 (ko) | 2002-11-05 | 2009-05-27 | 삼성전자주식회사 | 지문인식을 이용한 보안시스템 및 보안방법 |
| US7693313B2 (en) * | 2004-03-22 | 2010-04-06 | Raytheon Company | Personal authentication device |
| RU2294014C1 (ru) * | 2005-08-15 | 2007-02-20 | Федеральное государственное унитарное предприятие "ПЕНЗЕНСКИЙ НАУЧНО-ИССЛЕДОВАТЕЛЬСКИЙ ЭЛЕКТРОТЕХНИЧЕСКИЙ ИНСТИТУТ" (ФГУП "ПНИЭИ") | Способ оценки стойкости биометрической защиты к атакам подбора |
Family Cites Families (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US5280527A (en) * | 1992-04-14 | 1994-01-18 | Kamahira Safe Co., Inc. | Biometric token for authorizing access to a host system |
| US5870723A (en) * | 1994-11-28 | 1999-02-09 | Pare, Jr.; David Ferrin | Tokenless biometric transaction authorization method and system |
| WO1998011750A2 (fr) * | 1996-09-11 | 1998-03-19 | Yang Li | Procede d'utilisation d'empreintes digitales pour l'authentification des communications sans fil |
| DE19730170A1 (de) * | 1997-07-15 | 1999-01-21 | Rene Baltus | Vielfacherfassungs- und Vergleichsgerät für biometrische Merkmale |
-
1999
- 1999-07-30 DE DE19936094A patent/DE19936094C1/de not_active Expired - Fee Related
-
2000
- 2000-07-25 AU AU68283/00A patent/AU6828300A/en not_active Abandoned
- 2000-07-25 EP EP00956278A patent/EP1208540A1/fr not_active Ceased
- 2000-07-25 WO PCT/EP2000/007124 patent/WO2001009847A1/fr not_active Ceased
Non-Patent Citations (1)
| Title |
|---|
| See references of WO0109847A1 * |
Also Published As
| Publication number | Publication date |
|---|---|
| WO2001009847A1 (fr) | 2001-02-08 |
| DE19936094C1 (de) | 2001-04-26 |
| AU6828300A (en) | 2001-02-19 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| DE4003386C1 (fr) | ||
| DE69328454T2 (de) | Verbesserte Authentizitätsfeststellungsrückrufverfahren und Gerät | |
| DE3103514C2 (de) | Verfahren und Vorrichtung zum Sichern von Transaktionen | |
| DE69315419T2 (de) | Vorrichtung mit Zugangskontrolle für den Erhalt von Dienstleistungen | |
| EP1188151B1 (fr) | Dispositifs et procede pour l'authentification biometrique | |
| EP1326470A2 (fr) | Méthode et appareil pour l'authentification d'un souscripteur dans un réseau de communications | |
| DE69702454T2 (de) | Sicherheitsvorrichtungen und systeme | |
| DE69425717T2 (de) | Verfahren zur Anpassung an Kohle/Elektret-Mikrofoncharakteristiken der Telefonhörers für die automatische Sprecheridentitätsprüfung | |
| WO1999048056A1 (fr) | Procede et dispositif permettant de controler une caracteristique biometrique | |
| WO1998047110A1 (fr) | Procede de verification d'identite | |
| WO1998050880A1 (fr) | Procede d'adaptation par ordinateur d'un jeu de donnees de reference a l'aide d'un jeu de donnees d'entree | |
| DE102018208118A1 (de) | Verfahren und Vorrichtung zum Authentifizieren einer über einen Bus übertragenen Nachricht | |
| AT401205B (de) | System zur identifizierung eines kartenbenutzers | |
| DE102018109825A1 (de) | Wahlverfahren und Stimmabgabegerät | |
| DE60105550T2 (de) | Verfahren zum schutz gegen den diebstahl eines geheimkodes auf einer chipkarte fur mehrfachanwendungen, und chipkarten zur durchführung dieses verfahrens | |
| EP1208540A1 (fr) | Procede, dispositif et systeme permettant une identification biometrique | |
| EP1116358A1 (fr) | Procede d'authentification d'au moins un abonne lors d'un echange de donnees | |
| EP1071034A2 (fr) | Enregistrement d'empreintes digitales | |
| DE102009014919A1 (de) | Verfahren und Vorrichtung zum Authentifizieren eines Benutzers | |
| DE19841886A1 (de) | Verfahren und Vorrichtung zur Erzeugung von Paßwörtern | |
| WO2001069900A1 (fr) | Verification d'un appelant au moyen d'un procede biometrique | |
| DE69725252T2 (de) | Verfahren und Vorrichtung zur Prüfung von Sprache | |
| DE19921387C2 (de) | Anordnung und Verfahren zum Vergleich von Biometrik-Daten | |
| DE102006034241A1 (de) | Verfahren zur Ermittlung einer Berechtigung | |
| DE102014100794A1 (de) | Verfahren zumindest zum Lesen wenigstens einer Ausweisnummer von Benutzerdatenspeichern mit unterschiedlichen Datenstrukturen |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20020228 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AT BE CH CY DE DK ES FI FR GB GR IE IT LI LU MC NL PT SE |
|
| AX | Request for extension of the european patent |
Free format text: AL;LT;LV;MK;RO;SI |
|
| 17Q | First examination report despatched |
Effective date: 20030703 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION HAS BEEN REFUSED |
|
| 18R | Application refused |
Effective date: 20060421 |