IP Library › Granted Patent US 8,782,758
Granted Patent B2
US 8,782,758 · App. 13/225,738 · Granted Jul 15, 2014

Biometric authentication system, biometric authentication server, method and program thereof

Inventor: Ken Kamakura (Kawasaki, JP)
Assignee: Fujitsu Limited
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,782,758
App. No.
13/225,738
Granted
Jul 15, 2014
Kind
B2
Abstract

An authentication system in which a authentication server and a plurality of clients are coupled through a network and configured to process an authentication from a user of a client, is configured to determine as a cache target user another user who is different from the user who requested the authentication; is configured to generate an identifier that indicates the cache target user; and is configured to transmit biometric data of the cache target user and the identifier to the client from which the authentication of the user was requested. A cache availability determiner can determine whether biometric data of any cache target user are available on a client.

Claims (59)

1. A biometric authentication system comprising:

a biometric authentication server computer; and

a plurality of client computers that are coupled through a network and configured to process an authentication request from a user of a client computer,

wherein the biometric authentication server computer is configured to

determine a cache target user, wherein the cache target user is another user who is different from the user who requested the authentication to the biometric authentication server computer;

generate an identifier that indicates the cache target user;

transmit biometric data of the cache target user and the identifier to the client computer of the user who requested the authentication;

determine whether biometric data of any cache target user with a corresponding identifier are available on any client computers;

measure a number of client computers that performed an authentication request to the biometric authentication server; and

determine the cache target user when the number of client computers measured by the measurement unit exceeds a certain number of client computers; and

wherein the client computer is configured to cache the biometric data of the cache target user and the identifier that are received from the biometric authentication server computer.

2. The biometric authentication system according to claim 1 ,

wherein the biometric authentication server computer is further configured to identify a group to which the user who requested the authentication belongs; and

determine as the cache target user another user who belongs to the group.

3. The biometric authentication system according to claim 1 ,

wherein the biometric authentication server computer is further configured to

provide cache availability attribute information that indicates cache availability of biometric data of the client computer; and

determine cache availability of the client computer based on the cache availability attribute information and determines the cache target user when the client computer is determined to be available for cache.

4. The biometric authentication system according to claim 1 , the biometric authentication server computer further configured to

manage a number of client computers to which biometric data of a certain user is cached; and

determine priority of a plurality of the client computers to which biometric data of the certain user is cached; and determine a client computer that performs authentication processing according to the priority among the plurality of client computers for which priority is determined when the certain user requests an authentication.

5. The biometric authentication system according to claim 1 , the biometric authentication server computer further configured to

identify a group to which a user of biometric data that is to be cached to the client computer of the user who requested the authentication belongs; and

determine a user who belongs to the group as the cache target user.

6. The biometric authentication system according to claim 1 , the biometric authentication server computer further configured to manage a final authentication time and/or date of each user; and

determine as the cache target user an other user with authentication time and/or date elapsed from a final authentication time and/or date of the other user.

7. The biometric authentication system according to claim 1 , the biometric authentication server computer further configured to

manage authentication time of each user;

calculate a time zone on which authentication requests from users are concentrated; and

determine as the cache target user, when an authentication is requested, a user for whom authentication requests are concentrated in a time zone after a certain time has elapsed from time of the authentication request.

8. The biometric authentication system according to claim 1 , the biometric authentication server computer further configured to

manage an authentication success rate for each user; and

determine as the cache target user a user with a success rate lower than a certain success rate.

9. The biometric authentication system according to claim 1 , the biometric authentication server computer further configured to manage a network distance between client computers; and

determine as the cache target user a user of a client computer which network distance from the client computer that performed the authentication request is shorter than a certain distance.

10. The biometric authentication system according to claim 1 , the biometric authentication server computer further configured to

monitor an operation state of a cache destination client computer to which biometric data is to be cached; and

determine as the cache target user a user of a cache destination client computer for an available operation state.

11. The biometric authentication system according to claim 1 , the client computer further configured to

manage cache time and/or date when biometric data is cached; and

transmit an update request to the biometric authentication server computer when a certain time elapses from the cache time and/or date;

wherein the biometric authentication server computer additionally encrypts biometric data of a user corresponding to the biometric data cached to a client computer and generates a new identifier, and transmits updated encrypted biometric data and the identifier to the client computer.

12. The biometric authentication system according to claim 1 , wherein a client computer further configured to

retain a cache usage limit that indicates a usage limit of cached biometric data;

wherein the client computer of the cache target user retains an address of a cache destination client and performs an authentication request directly to the cache destination client within a range of the cache usage limit when the cache target user performs an authentication request.

13. A authentication server computer configured to store a plurality of pieces of biometric data, that is coupled to a plurality of client computers through a network, and processes an authentication request by checking biometric data for verification collected from a user of a client against the biometric data when the user requests the authentication through a client of the computer; the authentication server computer comprising:

one or more computing machines configured to

determine a cache target user, wherein the cache target user is another user who is different from the user who requested the authentication to the authentication server computer;

generate an identifier of the cache target user;

transmit biometric data of the cache target user and the identifier to the client computer of the user that requested the authentication;

determine whether biometric data of any cache target user with a corresponding identifier are available on any of the client computers;

measure a number of client computers that performed an authentication request to the authentication server computer; and

determine the cache target user when the number of client computers measured by the measurement unit exceeds a certain number of client computers.

14. A biometric authentication method executed by an authentication server computer that includes a storage unit configured to store a plurality of pieces of biometric data, is coupled to a plurality of client computers through a network, and performs authentication request processing for a user of a client by checking biometric data for verification collected from a user against the biometric data, the method comprising:

determining by the authentication server computer a cache target user, wherein the cache target user is another user who is different from the user who performed the authentication request to the authentication server computer;

generating an identifier for the cache target user;

transmitting by the authentication server computer biometric data of the cache target user and the identifier to the client computer of the user that performed the authentication request to the authentication server computer;

measuring a number of client computers that performed an authentication request to the authentication server; and

determining the cache target user when the number of client computers measured by the measurement unit exceeds a certain number of client computers.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 6, 2011
From: KAMAKURA, KEN
To: FUJITSU LIMITED
Reel/Frame 026858/0510 →
Priority Claims (1)
JP 2010-214695 · Sep 27, 2010 · national
Continuity (1)
Related Publication 20120079579A1 · Mar 29, 2012