IP Library Granted Patent US 9,984,220
Granted Patent B2
US 9,984,220 · App. 14/924,452 · Granted May 29, 2018

Method of authenticating a user holding a biometric certificate

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,984,220
App. No.
14/924,452
Granted
May 29, 2018
Kind
B2
Abstract

The present invention concerns a method of generating a biometric certificate of a user performed by a data processing device of a certifying authority, comprising a step of generating (E 4 ) a certificate for said user comprising data related to the identity of the user and truncated authentication data of said user generated using a method of generating a biometric authentication datum, comprising steps of: acquiring (E 1 ) first biometric data of said user; generating (E 2 ) a first a proof of knowledge of said first biometric data from the first acquired biometric data and from a pseudo-random function; generating (E 3 ) a first truncated authentication datum by applying a truncation function to said first generated proof of knowledge.

Claims (56)

1. A method of generating a biometric certificate of a user performed by a data processing device of a certifying authority, comprising:

acquiring biometric data of said user;

generating a proof of knowledge of said acquired biometric data from the acquired biometric data and a pseudo-random function;

generating a truncated authentication datum by applying a truncation function to said generated proof of knowledge;

generating a certificate for said user comprising data related to an identity of the user and the truncated authentication datum so that the certificate provides a proof of the user's identity and allows authenticating the user with a reduced rate of error while not allowing identification of the user,

wherein said method further comprises, for at least one error to be processed among a determined set of tolerable errors:

generating derived biometric data by adding said error to the acquired biometric data,

generating derived proofs of knowledge from the generated derived biometric data and from said pseudo-random function, and

generating derived truncated authentication data by applying said truncation function to said first generated derived proofs of knowledge.

2. The method of generating a biometric certificate according to claim 1 , wherein the data processing device of the certifying authority holds a secret encryption key, and wherein generating the certificate for said user comprises encrypting the truncated authentication data of said user.

3. The method according to claim 1 , wherein generating a proof of knowledge of biometric data comprises generating a hash of the biometric data performed by applying a hash function to the biometric data.

4. The method according to claim 3 , wherein the proof of knowledge is generated using said hash function and a secret hash key stored solely by the certifying authority.

5. The method according to claim 1 , wherein generating a proof of knowledge of biometric data comprises calculating a modular exponentiation of a uniformly distributed value obtained from the biometric data and from said pseudo-random function.

6. The method according to claim 5 , wherein generating a proof of knowledge of biometric data further comprises steps of:

acquiring a derivation parameter h verifying the formula: h=g^r where r is a random number, g a generator of a group of prime order p, and g and p being public data;

calculating the proof of knowledge using the formula: h^X or hash(h^X) with X being a value obtained from said biometric data and from said pseudo-random function, and hash being a hashing function.

7. The method according to claim 1 , wherein the truncation function applies truncation over n bits, n being a function of the probability of occurrence of the tolerable errors.

8. The method of generating a biometric certificate according to claim 1 , further including:

acquiring a truncated authentication datum or a derived truncated authentication datum stored in the certificate;

comparing the acquired truncated authentication datum or the derived truncated authentication datum with said generated truncated authentication datum,

said method further comprising:

for at least one tolerable error to be tested among a determined set of tolerable errors, generating derived biometric data by adding said error to the acquired biometric data;

for each error to be tested, generating a derived proof of knowledge from the generated derived biometric data and from said pseudo-random function, and a step of generating derived truncated authentication datum by applying said truncation function to said generated derived proof of knowledge;

acquiring a second truncated authentication datum or a derived truncated authentication datum obtained from said certificate;

comparing the second truncated authentication datum or the derived truncated authentication datum with the generated derived truncated authentication data.

9. A method of authenticating a user holding a biometric certificate generated comprising:

acquiring biometric data of said user to be authenticated;

generating a proof of knowledge of said acquired biometric data from the acquired biometric data and a pseudo-random function;

generating a truncated authentication datum by applying a truncation function to said generated proof of knowledge;

acquiring a truncated authentication datum or a derived truncated authentication datum stored in the certificate;

comparing the acquired truncated authentication datum or the derived truncated authentication datum with said generated truncated authentication datum,

said method further comprising:

for at least one tolerable error to be tested among a determined set of tolerable errors, generating derived biometric data by adding said error to the acquired biometric data;

for each error to be tested, generating a derived proof of knowledge from the generated derived biometric data and from said pseudo-random function, and a step of generating derived truncated authentication datum by applying said truncation function to said generated derived proof of knowledge;

acquiring a second truncated authentication datum or a derived truncated authentication datum obtained from said certificate;

comparing the second truncated authentication datum or the derived truncated authentication datum with the generated derived truncated authentication data.

10. The authentication method according to claim 9 , wherein the data processing device of the certifying authority holds a secret encryption key, the certificate generating step for said user comprises an encryption step of the truncated authentication data of said user, and wherein acquiring the first truncated authentication datum comprises decrypting using the encryption key the first acquired encrypted truncated authentication datum.

11. A computer program product comprising program code instructions, stored on a non-transitory computer readable medium, to perform a method of generating a biometric certificate of a user by:

acquiring biometric data of said user;

generating a proof of knowledge of said acquired biometric data from the acquired biometric data and a pseudo-random function;

generating a truncated authentication datum by applying a truncation function to said generated proof of knowledge;

generating a certificate for said user comprising data related to an identity of the user and the truncated authentication datum so that the certificate provides a proof of the user's identity and allows authenticating the user with a reduced rate of error while not allowing identification of the user,

wherein said method further comprises, for at least one error to be processed among a determined set of tolerable errors:

generating derived biometric data by adding said error to the acquired biometric data,

generating derived proofs of knowledge from the generated derived biometric data and from said pseudo-random function, and

generating derived truncated authentication data by applying said truncation function to said first generated derived proofs of knowledge.

12. A certification server comprising:

a processor and a memory storing instructions which when executed by the processor perform configured to perform a method of generating a biometric certificate of a user by:

acquiring biometric data of said user;

generating a proof of knowledge of said acquired biometric data from the acquired biometric data and a pseudo-random function;

generating a truncated authentication datum by applying a truncation function to said generated proof of knowledge;

generating a certificate for said user comprising data related to an identity of the user and the truncated authentication datum so that the certificate provides a proof of the user's identity and allows authenticating the user with a reduced rate of error while not allowing identification of the user,

wherein said method further comprises, for at least one error to be processed among a determined set of tolerable errors:

generating derived biometric data by adding said error to the acquired biometric data,

generating derived proofs of knowledge from the generated derived biometric data and from said pseudo-random function, and

generating derived truncated authentication data by applying said truncation function to said first generated derived proofs of knowledge.

Assignments (12)
CORRECTIVE ASSIGNMENT TO CORRECT THE PATENT NUMBER REPLACING 10158873 WITH 10185873 PREVIOUSLY RECORDED ON REEL 71930 FRAME 625. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT . Recorded Apr 1, 2026
From: IDEMIA IDENTITY & SECURITY FRANCE
To: IDEMIA PUBLIC SECURITY FRANCE
Reel/Frame 075530/0067 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 14, 2025
From: IDEMIA IDENTITY & SECURITY FRANCE
To: IDEMIA PUBLIC SECURITY FRANCE
Reel/Frame 071930/0625 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE ERRONEOUSLY NAME PROPERTIES/APPLICATION NUMBERS PREVIOUSLY RECORDED AT REEL: 055108 FRAME: 0009. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 066365/0151 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE REMOVE PROPERTY NUMBER 15001534 PREVIOUSLY RECORDED AT REEL: 055314 FRAME: 0930. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 066629/0638 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY NAMED PROPERTIES 14/366,087 AND 15/001,534 PREVIOUSLY RECORDED ON REEL 048039 FRAME 0605. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Jan 17, 2024
From: MORPHO
To: SAFRAN IDENTITY & SECURITY
Reel/Frame 066343/0143 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ERRONEOUSLY NAMED PROPERTIES 14/366,087 AND 15/001,534 PREVIOUSLY RECORDED ON REEL 047529 FRAME 0948. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Jan 17, 2024
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY
Reel/Frame 066343/0232 →
CORRECTIVE ASSIGNMENT TO CORRECT THE APPLICATION NUMBER PREVIOUSLY RECORDED AT REEL: 055108 FRAME: 0009. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Feb 17, 2021
From: SAFRAN IDENTITY AND SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 055314/0930 →
CORRECTIVE ASSIGNMENT TO CORRECT THE THE RECEIVING PARTY DATA PREVIOUSLY RECORDED ON REEL 047529 FRAME 0948. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Oct 29, 2020
From: SAFRAN IDENTITY AND SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 055108/0009 →
CORRECTIVE ASSIGNMENT TO CORRECT THE CORRECT THE ASSIGNEE NAME PREVIOUSLY RECORDED AT REEL: 047529 FRAME: 0949. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded May 1, 2020
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY FRANCE
Reel/Frame 052551/0082 →
CHANGE OF NAME Recorded Jan 9, 2019
From: MORPHO
To: SAFRAN IDENTITY & SECURITY
Reel/Frame 048039/0605 →
CHANGE OF NAME Recorded Aug 30, 2018
From: SAFRAN IDENTITY & SECURITY
To: IDEMIA IDENTITY & SECURITY
Reel/Frame 047529/0948 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2016
From: CIPIERE, OLIVIER; CHABANNE, HERVE; BRINGER, JULIEN; HUGEL, RODOLPHE
To: MORPHO
Reel/Frame 040191/0165 →