IP Library Granted Patent US 10,007,773
Granted Patent B2
US 10,007,773 · App. 14/382,920 · Granted Jun 26, 2018

Method for generating public identity for authenticating an individual carrying an identification object

Inventors: Bruno Benteo (Issy les Moulineaux, FR); Philippe Bertiaux (Issy les Moulineaux, FR)
Assignee: MORPHO
G06F21/34G06F21/32G06F21/35G06F21/6227H04L9/3231H04L9/3234H04L63/0861H04W12/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,007,773
App. No.
14/382,920
Granted
Jun 26, 2018
Kind
B2
Abstract

A method for generating a public identity for authenticating an individual carrying an identification object, the method including: entering an initial biometric datum of the individual; generating a first key from the biometric datum; generating a second key derived from a datum generated by a security component of the object; generating an initial encryption key combining the first key and the second key; communicating with a server a first identity of the individual in connection with the initial encryption key; generating by the server a public identity by encrypting the first identity using the initial encryption key, the public identity being stored by the server in connection with the initial encryption key. The public identity is not significant, but is secured by a strong connection between the object and biometry of the individual.

Claims (49)

1. A method for generating a public identity for authenticating an individual carrying an identification object including at least one security component, the method comprising:

an initialization phase including:

capturing initial biometric data of the individual;

generating a first key by applying a hash function to the biometric data, wherein the first key is generated in the security component of the identification object;

generating a second key based on data generated by the security component of the object only, the second key being generated in the security component;

generating an initial encryption key combining the first key and the second key;

communicating, with a server, a first identity of the individual in association with the initial encryption key; and

generating, by the server, a public identity by encrypting the first identity using the initial encryption key, the public identity being stored on the server in association with the initial encryption key, wherein the server introduces a key derivation function for the initial encryption key before generating the public identity.

2. The method according to claim 1 , wherein the data generated by the security component of the object is an unpredictable numerical value Physical Unclonable Feature (PUF) produced by the security component of the object.

3. The method according to claim 1 , wherein the data generated by the security component of the object is a random number stored in the security component of the object after generation.

4. The method according to claim 1 , wherein the first key is obtained by applying a signature or encryption function to reference digital data derived from the biometric data.

5. The method according to claim 1 , wherein the first key is generated in a secure element of a third party and transmitted to the identification object.

6. The method according to claim 1 , wherein the initial encryption key is generated by the security component of the identification object, then transmitted to the server.

7. The method according to claim 1 , wherein the initial encryption key is generated by the server.

8. The method according to claim 1 , wherein the generating generates the first key by introducing a key derivation received from the server.

9. The method according to claim 1 , wherein the generating generates the second key by introducing a key derivation received from the server.

10. The method according to claim 1 , wherein a plurality of derived public identities is generated and stored on the server or on a plurality of servers in association with a respective derived initial encryption key.

11. The method according to claim 10 , wherein the public identity or identities are also transmitted and stored in the identification object.

12. The method according to claim 1 , further comprising:

a verification phase for verifying the identity of the individual carrying the identification object, the verification phase including the following steps:

capturing current biometric data of the individual,

generating current data by the security component of the object,

generating a current encryption key from the current biometric data and from the current data generated by the security component of the object,

comparing the current encryption key with the initial encryption key,

in response to the comparison being positive, validating the identity of the individual carrying the identification object, and

in response to the comparison being negative, refuting the identity of the individual carrying the identification object.

13. The method according to claim 12 , wherein the comparing is performed in the security component of the identification object.

14. The method according to claim 12 , wherein the comparing is performed at the server.

15. An electronic device comprising:

a security component configured to

capture initial biometric data of an individual,

generate of a first key by applying a hash function to the biometric data, wherein the first key is generated in the security component of the identification object,

generate a second key based on data generated by the security component only,

generate an initial encryption key combining the first key and the second key, and

communicate, with a server, a first identity of the individual in association with the initial encryption key, the server generating a public identity by encrypting the first identity using the initial encryption key, and storing the public identity in association with the initial encryption key;

wherein a key derivation function for the initial encryption key is introduced by the server before generation of the public identity.

16. The electronic device according to claim 15 , further comprising a device configured to capture biometric data.

17. The electronic device according to claim 15 , wherein the security component accesses a memory in which a plurality of public identities is stored.

18. A system for authenticating a holder of an identification object, the system comprising:

at least one authentication server; and

an electronic device including a security component configured to

capture initial biometric data of an individual,

generate of a first key by applying an encryption a hash function to the biometric data, wherein the first key is generated in the security component of the identification object,

generate a second key based on data generated by the security component only,

generate an initial encryption key combining the first key and the second key, and

communicate, with a server, a first identity of the individual in association with the initial encryption key,

wherein the authentication server is configured to generate a public identity by encrypting the first identity using the initial encryption key, and store the public identity in association with the initial encryption key; and

wherein a key derivation function for the initial encryption key is introduced by the authentication server before generation of the public identity.

19. The system according to claim 18 , further comprising a plurality of authentication servers each including at least one derived public identity.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY NAMED PROPERTIES 14/366,087 AND 15/001,534 PREVIOUSLY RECORDED ON REEL 048039 FRAME 0605. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Jan 17, 2024
From: MORPHO
To: SAFRAN IDENTITY & SECURITY
Reel/Frame 066343/0143 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE REMOVE PROPERTY NUMBER 15001534 PREVIOUSLY RECORDED AT REEL: 055314 FRAME: 0930. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 066629/0638 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE ERRONEOUSLY NAME PROPERTIES/APPLICATION NUMBERS PREVIOUSLY RECORDED AT REEL: 055108 FRAME: 0009. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 066365/0151 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY NAMED PROPERTIES 14/366,087 AND 15/001,534 PREVIOUSLY RECORDED ON REEL 047529 FRAME 0948. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY
Reel/Frame 066343/0232 →
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 055108 FRAME: 0009. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Feb 17, 2021
From: SAFRAN IDENTITY AND SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 055314/0930 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE RECEIVING PARTY DATA PREVIOUSLY RECORDED ON REEL 047529 FRAME 0948. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Oct 29, 2020
From: SAFRAN IDENTITY AND SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 055108/0009 →
CHANGE OF NAME Recorded Jan 9, 2019
From: MORPHO
To: SAFRAN IDENTITY & SECURITY
Reel/Frame 048039/0605 →
CHANGE OF NAME Recorded Aug 30, 2018
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY
Reel/Frame 047529/0948 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 4, 2014
From: BENTEO, BRUNO; BERTIAUX, PHILIPPE
To: MORPHO
Reel/Frame 033669/0325 →
Priority Claims (1)
FR 12 52444 · Mar 19, 2012 · national
Continuity (1)
Related Publication 20150046699A1 · Feb 12, 2015
Cited By (2)
US 12,597,014 US 12,621,294