WO2001009847A1 - Procede, dispositif et systeme permettant une identification biometrique - Google Patents
Procede, dispositif et systeme permettant une identification biometrique Download PDFInfo
- Publication number
- WO2001009847A1 WO2001009847A1 PCT/EP2000/007124 EP0007124W WO0109847A1 WO 2001009847 A1 WO2001009847 A1 WO 2001009847A1 EP 0007124 W EP0007124 W EP 0007124W WO 0109847 A1 WO0109847 A1 WO 0109847A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- data
- authentication
- biometric
- stored
- biometric data
- Prior art date
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/32—User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
-
- G—PHYSICS
- G07—CHECKING-DEVICES
- G07C—TIME OR ATTENDANCE REGISTERS; REGISTERING OR INDICATING THE WORKING OF MACHINES; GENERATING RANDOM NUMBERS; VOTING OR LOTTERY APPARATUS; ARRANGEMENTS, SYSTEMS OR APPARATUS FOR CHECKING NOT PROVIDED FOR ELSEWHERE
- G07C9/00—Individual registration on entry or exit
- G07C9/30—Individual registration on entry or exit not involving the use of a pass
- G07C9/32—Individual registration on entry or exit not involving the use of a pass in combination with an identity check
- G07C9/37—Individual registration on entry or exit not involving the use of a pass in combination with an identity check using biometric data, e.g. fingerprints, iris scans or voice recognition
Definitions
- the invention relates to a method, as well as a device and a system for biometric authentication, in particular for securing the biological authentication against replay attacks.
- An authentication procedure is used when a person requests access to secure facilities. For example, authentication is carried out regularly by means of a PIN comparison if a card user inserts a chip card - for example a credit card - into an automated teller machine (terminal) or if a person requests entry to secure premises. For this purpose, a stored PIN is checked for identity with the PIN specified by the card user or the person requesting entry.
- a biometric feature of the person is used as an identification feature instead of a PIN.
- the biometric feature can be a fingerprint, for example, but in the context of the present invention is also intended to include a personal signature.
- a disadvantage of such authentication methods is that authentication can be attacked if the biometric data that has been stored as reference data or that has led to authentication is intercepted by unauthorized third parties in order to use it again later for unauthorized authentication , This type of attack is known as a replay attack.
- the object of the present invention is therefore to secure biometric authentication methods against replay attacks. This object is achieved by the features of the independent claims. Advantageous refinements of the invention are specified in subclaims.
- the invention makes use of the fact that the biometric features are generally common, that in contrast to the PIN they are not 100% reproducible, which is why authorization is already given when the biometric feature presented by the person matches the stored reference data exceeds a predetermined threshold.
- a predetermined threshold value in particular not 100% and preferably not more than 99%.
- a replay attack can in fact be assumed and, according to the invention, the authentication is consequently refused.
- a comparison circuit is provided which generates a message and, for example, outputs an error message when a comparison of the reference data with the newly recorded biometric data of a person results in a match lying above this (second) threshold value. If the error message is output, it can also be provided to automatically block further operation.
- the (second) visual value of 99% or 100% relevant to the invention is stored either in a terminal or on a separate data carrier, in particular a chip card, together with the reference data.
- the recorded biometric data which have led to an authentication and possibly also the recorded biometric data which did not lead to the authentication because they were below the first threshold value are collected and stored as data records ⁇ verden. These data records are preferably stored in a stack memory or shift register. During each authentication process, it is then checked whether the biometric data of the presented biometric feature are identical to one of the stored data records or if more than 99% match. A replay attack can then be assumed and authentication is refused by the authentication system.
- hash values of the same are stored.
- a hash function is applied to the comparison data record, which generates a relatively short hash value.
- Hash functions are known per se, a hash function being a unique, compressive mapping to a word of fixed length.
- the hash function is processed in several rounds on a block-by-block partition of the output data. The result depends on the entire input. It is not possible to calculate the output data from the hash value. It is complexity theory difficult to change the input data in such a way that the hash value remains the same.
- the hash value is recalculated.
- the probability that two biometric data sets produce the same hash value is low, so that a replay attack must be assumed if they match.
Landscapes
- Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Human Computer Interaction (AREA)
- Computer Hardware Design (AREA)
- Software Systems (AREA)
- General Engineering & Computer Science (AREA)
- Collating Specific Patterns (AREA)
- Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
Abstract
Priority Applications (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
EP00956278A EP1208540A1 (fr) | 1999-07-30 | 2000-07-25 | Procede, dispositif et systeme permettant une identification biometrique |
AU68283/00A AU6828300A (en) | 1999-07-30 | 2000-07-25 | Method, device and system for biometric authentication |
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
DE19936094A DE19936094C1 (de) | 1999-07-30 | 1999-07-30 | Verfahren und Vorrichtung zur biometrischen Authentisierung |
DE19936094.4 | 1999-07-30 |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2001009847A1 true WO2001009847A1 (fr) | 2001-02-08 |
Family
ID=7916749
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/EP2000/007124 WO2001009847A1 (fr) | 1999-07-30 | 2000-07-25 | Procede, dispositif et systeme permettant une identification biometrique |
Country Status (4)
Country | Link |
---|---|
EP (1) | EP1208540A1 (fr) |
AU (1) | AU6828300A (fr) |
DE (1) | DE19936094C1 (fr) |
WO (1) | WO2001009847A1 (fr) |
Cited By (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
EP1418486A3 (fr) * | 2002-11-05 | 2005-01-05 | Samsung Electronics Co., Ltd. | Appareil d'authentification à base d'empreinte digitale |
WO2005096214A1 (fr) * | 2004-03-22 | 2005-10-13 | Raytheon Company | Dispositif d'authentification personnelle |
RU2294014C1 (ru) * | 2005-08-15 | 2007-02-20 | Федеральное государственное унитарное предприятие "ПЕНЗЕНСКИЙ НАУЧНО-ИССЛЕДОВАТЕЛЬСКИЙ ЭЛЕКТРОТЕХНИЧЕСКИЙ ИНСТИТУТ" (ФГУП "ПНИЭИ") | Способ оценки стойкости биометрической защиты к атакам подбора |
Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US5280527A (en) * | 1992-04-14 | 1994-01-18 | Kamahira Safe Co., Inc. | Biometric token for authorizing access to a host system |
WO1998011750A2 (fr) * | 1996-09-11 | 1998-03-19 | Yang Li | Procede d'utilisation d'empreintes digitales pour l'authentification des communications sans fil |
US5870723A (en) * | 1994-11-28 | 1999-02-09 | Pare, Jr.; David Ferrin | Tokenless biometric transaction authorization method and system |
Family Cites Families (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
DE19730170A1 (de) * | 1997-07-15 | 1999-01-21 | Rene Baltus | Vielfacherfassungs- und Vergleichsgerät für biometrische Merkmale |
-
1999
- 1999-07-30 DE DE19936094A patent/DE19936094C1/de not_active Expired - Fee Related
-
2000
- 2000-07-25 EP EP00956278A patent/EP1208540A1/fr not_active Ceased
- 2000-07-25 WO PCT/EP2000/007124 patent/WO2001009847A1/fr not_active Application Discontinuation
- 2000-07-25 AU AU68283/00A patent/AU6828300A/en not_active Abandoned
Patent Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US5280527A (en) * | 1992-04-14 | 1994-01-18 | Kamahira Safe Co., Inc. | Biometric token for authorizing access to a host system |
US5870723A (en) * | 1994-11-28 | 1999-02-09 | Pare, Jr.; David Ferrin | Tokenless biometric transaction authorization method and system |
WO1998011750A2 (fr) * | 1996-09-11 | 1998-03-19 | Yang Li | Procede d'utilisation d'empreintes digitales pour l'authentification des communications sans fil |
Cited By (5)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
EP1418486A3 (fr) * | 2002-11-05 | 2005-01-05 | Samsung Electronics Co., Ltd. | Appareil d'authentification à base d'empreinte digitale |
US7382904B2 (en) | 2002-11-05 | 2008-06-03 | Samsung Electronics Co., Ltd. | Security system and security method using fingerprints |
WO2005096214A1 (fr) * | 2004-03-22 | 2005-10-13 | Raytheon Company | Dispositif d'authentification personnelle |
US7693313B2 (en) | 2004-03-22 | 2010-04-06 | Raytheon Company | Personal authentication device |
RU2294014C1 (ru) * | 2005-08-15 | 2007-02-20 | Федеральное государственное унитарное предприятие "ПЕНЗЕНСКИЙ НАУЧНО-ИССЛЕДОВАТЕЛЬСКИЙ ЭЛЕКТРОТЕХНИЧЕСКИЙ ИНСТИТУТ" (ФГУП "ПНИЭИ") | Способ оценки стойкости биометрической защиты к атакам подбора |
Also Published As
Publication number | Publication date |
---|---|
AU6828300A (en) | 2001-02-19 |
DE19936094C1 (de) | 2001-04-26 |
EP1208540A1 (fr) | 2002-05-29 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
DE4003386C1 (fr) | ||
DE69315419T2 (de) | Vorrichtung mit Zugangskontrolle für den Erhalt von Dienstleistungen | |
DE3103514C2 (de) | Verfahren und Vorrichtung zum Sichern von Transaktionen | |
DE69415053T2 (de) | Verfahren und Vorrichtung zur Kreditkartenechtheitsprüfung | |
DE69702454T2 (de) | Sicherheitsvorrichtungen und systeme | |
WO2000078078A1 (fr) | Procede et systeme pour la verification de l'authenticite d'un premier partenaire de communication dans un reseau de communication | |
EP1188151A1 (fr) | Dispositifs et procede pour l'authentification biometrique | |
WO1999048056A1 (fr) | Procede et dispositif permettant de controler une caracteristique biometrique | |
DE69425717T2 (de) | Verfahren zur Anpassung an Kohle/Elektret-Mikrofoncharakteristiken der Telefonhörers für die automatische Sprecheridentitätsprüfung | |
DE102018208118A1 (de) | Verfahren und Vorrichtung zum Authentifizieren einer über einen Bus übertragenen Nachricht | |
WO1998047110A1 (fr) | Procede de verification d'identite | |
WO1998050880A1 (fr) | Procede d'adaptation par ordinateur d'un jeu de donnees de reference a l'aide d'un jeu de donnees d'entree | |
DE102018109825A1 (de) | Wahlverfahren und Stimmabgabegerät | |
EP1208540A1 (fr) | Procede, dispositif et systeme permettant une identification biometrique | |
EP2077658A1 (fr) | Procédé de mise à disposition d'un service pour un utilisateur | |
WO2000018061A1 (fr) | Procede d'authentification d'au moins un abonne lors d'un echange de donnees | |
DE102006034241A1 (de) | Verfahren zur Ermittlung einer Berechtigung | |
WO2000051084A1 (fr) | Procede d'identification d'utilisateur | |
EP1071034A2 (fr) | Enregistrement d'empreintes digitales | |
DE102009014919A1 (de) | Verfahren und Vorrichtung zum Authentifizieren eines Benutzers | |
DE10258323A1 (de) | Verschlüsselungsverfahren | |
DE19921387C2 (de) | Anordnung und Verfahren zum Vergleich von Biometrik-Daten | |
EP1266513A1 (fr) | Verification d'un appelant au moyen d'un procede biometrique | |
DE19841886A1 (de) | Verfahren und Vorrichtung zur Erzeugung von Paßwörtern | |
DE69725252T2 (de) | Verfahren und Vorrichtung zur Prüfung von Sprache |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
AK | Designated states |
Kind code of ref document: A1 Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BY BZ CA CH CN CR CU CZ DK DM DZ EE ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NO NZ PL PT RO RU SD SE SG SI SK SL TJ TM TR TT TZ UA UG US UZ VN YU ZA ZW |
|
AL | Designated countries for regional patents |
Kind code of ref document: A1 Designated state(s): GH GM KE LS MW MZ SD SL SZ TZ UG ZW AM AZ BY KG KZ MD RU TJ TM AT BE CH CY DE DK ES FI FR GB GR IE IT LU MC NL PT SE BF BJ CF CG CI CM GA GN GW ML MR NE SN TD TG |
|
121 | Ep: the epo has been informed by wipo that ep was designated in this application | ||
DFPE | Request for preliminary examination filed prior to expiration of 19th month from priority date (pct application filed before 20040101) | ||
WWE | Wipo information: entry into national phase |
Ref document number: 2000956278 Country of ref document: EP |
|
WWP | Wipo information: published in national office |
Ref document number: 2000956278 Country of ref document: EP |
|
NENP | Non-entry into the national phase |
Ref country code: JP |
|
WWR | Wipo information: refused in national office |
Ref document number: 2000956278 Country of ref document: EP |
|
WWW | Wipo information: withdrawn in national office |
Ref document number: 2000956278 Country of ref document: EP |