Deprecated: The each() function is deprecated. This message will be suppressed on further calls in /home/zhenxiangba/zhenxiangba.com/public_html/phproxy-improved-master/index.php on line 456
KR20070042898A - Computer readable recording medium and automatic cash transaction system containing biometric authentication method, biometric control program - Google Patents
[go: Go Back, main page]

KR20070042898A - Computer readable recording medium and automatic cash transaction system containing biometric authentication method, biometric control program - Google Patents

Computer readable recording medium and automatic cash transaction system containing biometric authentication method, biometric control program Download PDF

Info

Publication number
KR20070042898A
KR20070042898A KR1020060101720A KR20060101720A KR20070042898A KR 20070042898 A KR20070042898 A KR 20070042898A KR 1020060101720 A KR1020060101720 A KR 1020060101720A KR 20060101720 A KR20060101720 A KR 20060101720A KR 20070042898 A KR20070042898 A KR 20070042898A
Authority
KR
South Korea
Prior art keywords
authentication
information
biometric
card
data
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
KR1020060101720A
Other languages
Korean (ko)
Other versions
KR100848926B1 (en
Inventor
요시마사 이마이
다이스케 사가와
아키라 야마구치
Original Assignee
히타치 오므론 터미널 솔루션즈 가부시키가이샤
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 히타치 오므론 터미널 솔루션즈 가부시키가이샤 filed Critical 히타치 오므론 터미널 솔루션즈 가부시키가이샤
Publication of KR20070042898A publication Critical patent/KR20070042898A/en
Application granted granted Critical
Publication of KR100848926B1 publication Critical patent/KR100848926B1/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/32User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/33User authentication using certificates
    • G06F21/335User authentication using certificates for accessing specific resources, e.g. using Kerberos tickets
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F19/00Complete banking systems; Coded card-freed arrangements adapted for dispensing or receiving monies or the like and posting such transactions to existing accounts, e.g. automatic teller machines
    • G07F19/20Automatic teller machines [ATMs]
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F7/00Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus
    • G07F7/08Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means
    • G07F7/10Mechanisms actuated by objects other than coins to free or to actuate vending, hiring, coin or paper currency dispensing or refunding apparatus by coded identity card or credit card or other personal identification means together with a coded signal, e.g. in the form of personal identification information, like personal identification number [PIN] or biometric data

Landscapes

  • Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Business, Economics & Management (AREA)
  • Accounting & Taxation (AREA)
  • Finance (AREA)
  • Financial Or Insurance-Related Operations Such As Payment And Settlement (AREA)
  • Collating Specific Patterns (AREA)
  • Control Of Vending Devices And Auxiliary Devices For Vending Devices (AREA)

Abstract

본 발명은 IC카드내 인증 시스템에 관한 것으로서, 생체인증제어방법은 생체정보로부터 구해지는 전처리 데이터를 휴대전자 장치로부터 수신하고, 상기 전처리 데이터를 생체 인증기구부에 송신하고, 상기 생체인증 기구부에 의해 취득된 생체정보와 상기 전처리 데이터를 조합하여 작성하는 인증 데이터를 상기 생체인증 기구부로부터 수신하고, 수신한 상기 인증데이터를 상기 휴대전자장치에 송신하고, 상기 휴대전자장치내에 미리 격납되어 있는 등록 데이터와 상기 인증데이터를 상기 휴대전자장치내에서 조합시키도록 동작시키는 기술을 제공한다.BACKGROUND OF THE INVENTION 1. Field of the Invention The present invention relates to an authentication system in an IC card, wherein a biometric authentication method receives preprocessing data obtained from biometric information from a portable electronic device, transmits the preprocessing data to a biometric authentication mechanism, and acquires the biometric authentication mechanism. Received from the bioauthentication mechanism unit to receive authentication data created by combining the generated biometric information and the preprocessing data, and transmits the received authentication data to the portable electronic device, and the registration data previously stored in the portable electronic device; A technique is provided to operate to combine authentication data within the portable electronic device.

Description

생체인증 제어방법, 생체인증제어 프로그램이 수록된 컴퓨터가 읽을 수 있는 기록매체 및 현금자동거래장치{BIOMETRICS CONTROL METHOD, A COMPUTER READABLE MEDIUM HAVING STORED THEREON BIOMETRICS CONTROL PROGRAM}Computer-readable recording medium and automatic cash transaction system containing biometric control method, biometric control program {BIOMETRICS CONTROL METHOD, A COMPUTER READABLE MEDIUM HAVING STORED THEREON BIOMETRICS CONTROL PROGRAM}

도 1은 생체 정보 등록 처리 시스템의 개요도의 예이다.1 is an example of a schematic diagram of a biometric information registration processing system.

도 2는 생체 정보 등록 처리 시스템의 블럭도의 예이다. 2 is an example of a block diagram of a biometric information registration processing system.

도 3은 생체 정보 등록 처리의 설명도이다.3 is an explanatory diagram of a biometric information registration process.

도 4는 생체 정보 등록 처리의 플로차트의 예이다. 4 is an example of a flowchart of biometric information registration processing.

도 5는 생체 인증 처리 시스템의 개요도의 예이다.5 is an example of a schematic diagram of a biometric authentication processing system.

도 6은 생체 인증 처리 시스템의 블럭도의 예이다. 6 is an example of a block diagram of a biometric authentication processing system.

도 7은 인증 제어 소프트웨어의 구성도의 예이다.7 is an example of configuration diagram of authentication control software.

도 8은 생체 인증 처리의 설명도이다.8 is an explanatory diagram of a biometric authentication process.

도 9는 IC카드내 인증 방식을 이용한 생체 인증 처리를 포함한 거래의 플로차트의 예이다. 9 is an example of a flowchart of a transaction including biometric authentication processing using an IC card authentication method.

도 10은 인증 거래 개시 처리의 플로차트의 예이다.10 is an example of a flowchart of authentication transaction initiation processing.

도 11은 생체 인증 처리의 플로차트의 예이다.11 is an example of a flowchart of biometric authentication processing.

도 12는 인증 거래 종료 처리의 플로차트의 예이다.12 is an example of a flowchart of the authentication transaction termination process.

본 발명은, 현금 자동예금지불장치(ATM)등으로 사용되는 생체 인증 시스템에 관한다.The present invention relates to a biometric authentication system used in ATMs and the like.

종래, 현금 자동예금지불장치(ATM)등으로 행해져 온 생체 인증 시스템에는 이하와 같은 것이 있다.Conventionally, the following biometric authentication systems have been performed by ATMs or the like.

특허 문헌 1(일본국 특개2000-215294호 공보)에는 생체 식별 정보 내장형 IC카드 및 그 본인 인증 방법이 기재되어 있다. 이 기술은 IC카드를 이용한 본인 인증 방법에 있어서, IC카드로 생체 식별 내정보를 내장해 이 생체 식별 정보와 본인 고유의 생체 정보 식별 정보를 IC카드내의 생체 식별 조합 처리부에서 처리해 본인 인증을 실시하는 것이다.Patent document 1 (Japanese Patent Laid-Open No. 2000-215294) describes a biometric identification embedded IC card and its identity authentication method. This technology uses a smart card to authenticate the user by embedding the biometric identification information into the IC card and processing the biometric information and the biometric information unique to the user in the biometric identification processing unit in the IC card for authentication. will be.

특허 문헌 2(일본국 특개2005-115800호 공보)에는 생체 정보를 이용한 개인 인증 방법이 기재되어 있다. 이 기술은 이용자로부터 취득한 생체 정보를 분할하고 한쪽을 전자 카드로, 다른쪽을 데이터베이스에 각각 격납하고, 인증때 전자 카드 이용자로부터 생체 정보를 취득해 상기 전자 카드로부터 다른 한쪽의 생체 정보를 독출하고, 그 후, 이 한쪽의 생체 정보와 관련하는 다른쪽의 생체 정보가 상기 데이터베이스에 존재하는지 아닌지를 검색해 존재할 때는 그러한 생체 정보를 결합해 먼저 취득한 전자 카드 이용자의 생체 정보와 비교하고 인증 판정을 실시하는 것이다.Patent document 2 (Japanese Patent Laid-Open No. 2005-115800) describes a personal authentication method using biometric information. This technique divides the biometric information obtained from the user, stores one on the electronic card and the other on the database, obtains biometric information from the electronic card user at the time of authentication, and reads the other biometric information from the electronic card. After that, if the other biometric information related to this biometric information exists in the database or not, the biometric information is combined and compared with the biometric information of the electronic card user, which is obtained first, and the authentication is performed. .

특허 문헌 3(일본국 특개평10-312459호 공보)에는 휴대 전자 장치 및 생체 정보를 이용한 개인 인증 방법이 기재되어 있다. 이 기술은 사전에 IC카드 등의 휴대 전자 장치에 등록 데이터(생체 정보의 특징량)를 기억해 두어, IC카드내에서 인증시에 얻는 특징 데이터(생체 정보의 특징량)와 등록 데이터를 조합하는 것으로 인증을 실시하는 것이다.Patent document 3 (Japanese Patent Laid-Open No. 10-312459) describes a personal authentication method using a portable electronic device and biometric information. This technique stores registration data (characteristic amount of biometric information) in a portable electronic device such as an IC card in advance, and combines registration data and characteristic data (characteristic amount of biometric information) obtained at the time of authentication in the IC card. It is to perform authentication.

특허 문헌 1에서는 생체 정보를 기억한 IC카드내에서 생체 인증하고 있지만, IC카드내에 생체 정보를 그대로 기억하고 있으므로 IC카드의 도난·분실에 의해 생체 정보가 누설 할 가능성이 있다.In Patent Literature 1, biometric authentication is performed in an IC card that stores biometric information. However, since biometric information is stored in the IC card as it is, biometric information may leak due to theft or loss of the IC card.

특허 문헌 2에서는 생체 정보를 전자 카드와 데이터베이스의 2개로 나누어 기억(등록)하고, 인증시에 그들 2개를 결합하고 있지만 데이터베이스에 많은 이용자의 데이터를 기억해 관리를 철저히 할 필요도 있어 처리가 번잡하다.In Patent Literature 2, biometric information is divided (stored) into two of an electronic card and a database, and the two are combined at the time of authentication, but there is a necessity to thoroughly manage and store data of many users in the database. .

특허 문헌 3에서는 생체 정보로부터 생체 특징량을 추출해 등록 데이터로서 기억한 IC카드내에서 인증시에 새롭게 얻은 생체 특징량과 등록 데이터를 조합을 이용해 생체 인증하고 있지만 생체 특징량을 휴대 전자 장치(IC카드)와 데이터 처리 장치(IC카드 터미널)의 사이에 전송하고 있으므로 이 전송 과정에서 개인정보인 생체 특징량이 누설 할 가능성이 있다.In Patent Document 3, the biometric feature is extracted from the biometric information and is biometrically authenticated using a combination of biometric feature and registration data newly acquired at the time of authentication in the IC card stored as registration data. ) And the data processing device (IC card terminal), there is a possibility that the biometric feature, which is personal information, is leaked during this transmission process.

본 발명은, IC카드를 이용한 생체 인증 시스템 및 그 방법에 있어서 생체 정보의 높은 은닉성을 실현하는 것을 목적으로 한다.An object of the present invention is to realize a high concealment of biometric information in a biometric authentication system and method using an IC card.

상기 과제의 해결을 위해 생체 인증 처리를 휴대 전자 장치(IC카드) 내의 인증 프로그램으로 실시하는 IC카드내 인증 방식을 실시한다. 본 발명의 생체 인증 제어 방법은 생체 정보로부터 구해지는 전처리 데이터를 휴대 전자 장치로부터 수신해 상기 전처리 데이터를 생체 인증 기구부에 송신하고, 상기 생체 인증 기구부에 의해 취득된 생체 정보와 상기 전처리 데이터를 조합해 작성하는 인증 데이터를 상기 생체 인증 기구부로부터 수신해 수신한 상기 인증 데이터를 상기 휴대 전자 장치에 송신하고 상기 휴대 전자 장치내에 미리 격납되고 있는 등록 데이터와 상기 인증 데이터를 상기 휴대 전자 장치내에서 조합시키도록 동작시키는 것이다.In order to solve the above problems, an IC card authentication method is implemented in which a biometric authentication process is performed by an authentication program in a portable electronic device (IC card). The biometric authentication control method of the present invention receives preprocessing data obtained from biometric information from a portable electronic device, transmits the preprocessing data to a biometric authentication mechanism, and combines the biometric information obtained by the biometric authentication mechanism with the preprocessing data. Receive the authentication data to be created from the biometric authentication mechanism unit, and transmit the received authentication data to the portable electronic device, and combine registration data previously stored in the portable electronic device with the authentication data in the portable electronic device. It works.

본 발명은 IC카드, 인증 장치에 대해서 데이터의 전송, 인증 처리 지시를 나타내기 위해서 인증 제어 소프트웨어를 채용한 것에 의해 보안이 높은 생체 인증 방식을 제공할 수 있다. 또한 인증 제어 소프트웨어를 구성하는 인증 제어 어플리케이션과 인증 제어 미들웨어를 다른 복수의 인증 방식으로 대응 가능한 것으로 하여 작성함으로써, 복수의 인증으로 단말에 복수의 생체에 대한 인증 장치가 탑재되어 있는 경우에 복수의 인증 장치의 여러 가지로 대응한 제어가 가능하게 된다.The present invention can provide a highly secure biometric authentication method by employing authentication control software to indicate data transfer and authentication processing instructions to an IC card and an authentication device. In addition, the authentication control application constituting the authentication control software and the authentication control middleware are created by making it possible to cope with a plurality of different authentication methods, so that a plurality of authentications are provided when the terminal is equipped with a plurality of biometric authentication devices. Corresponding control of various devices is possible.

이하, 본 발명을 이용한 실시의 한 형태에 대해서 설명한다. EMBODIMENT OF THE INVENTION Hereinafter, one Embodiment using this invention is described.

[실시예 1]Example 1

본 실시 형태에서는 금융기관의 영업점에 있어서 오퍼레이터(창구 담당자)와 이용자 사이에서 이용자가 소유하는 휴대 전자 장치, 특히, IC카드 이용자의 생체 정보(예, 지정맥)를 등록하는 생체 정보 등록 처리와 금융기관, 편의점 등에 설치되어 주로 현금에 대해 거래를 자동적으로 거래하는 현금 자동 거래 장치, 현금 자동예금지불기(ATM)를 사용해 이용자의 생체 정보를 사용해 인증하는 생체 인증 처 리, 의 크고 2개로 나누어 설명한다. 도 1~4에서 생체 정보 등록 처리를 설명한다 도1~4로 생체 인증 처리를 설명한다.In the present embodiment, the biometric information registration processing and the financial information for registering the biometric information (for example, finger vein) of the portable electronic device owned by the user, in particular, the IC card user, between the operator (window manager) and the user at a branch of a financial institution. Installed in institutions, convenience stores, etc., mainly divided into two types: automatic cash transaction system that automatically trades transactions for cash, and biometric authentication process that authenticates users' biometric information using ATM (ATM). do. 1-4, the biometric information registration process will be described. FIG. 1-4 illustrate the biometric authentication process.

먼저, 생체 정보의 등록 처리와 인증 처리의 개요를 간단하게 설명한다. First, the outline | summary of the registration process and authentication process of biometric information is demonstrated easily.

생체 정보 등록 처리에서는 이용자의 지정맥으로부터 특징량을 추출해 전처리 데이터로 생성함과 동시에, 등록 데이터도 생성해 IC카드로 등록한다. 이 처리의 과정에서 사용되는 창구 단말은 IC카드 장치 부착 생체 정보 등록 장치와 접속되고 있고 등록용의 생체 정보(전처리 데이터, 등록 데이터)가 암호화되어, 창구 단말을 경유하지 않고 생체 정보 등록 장치로부터 IC카드로 직접 전송, 기입이 실행된다.In the biometric information registration process, the feature amount is extracted from the finger vein of the user and generated as preprocessing data, and at the same time, the registration data is also generated and registered with the IC card. The window terminal used in the process of this process is connected to a biometric information registration device with an IC card device, and the biometric information (preprocessing data, registration data) for registration is encrypted so that the IC can be accessed from the biometric information registration device without passing through the window terminal. Direct transfer and writing to the card is performed.

한편, 생체 인증 처리에서는 이용자의 지정맥으로부터의 특징량과 IC카드로 등록된 전처리 데이터, 등록 데이터를 특유의 인증, 조합 기술에 근거해 그 처리를 실행한다. 이 처리의 과정에서는 ATM을 중심으로 하고 ATM에 접속된 생체 인증 기구부에 의해 새롭게 취득한 생체 정보와 IC카드로부터 독출한 전처리 데이터에 의해 인증 데이터를 생성하고 이것을 IC카드로 전송 해 IC카드내에서 인증 처리를 실시한다.On the other hand, in the biometric authentication process, the processing is performed based on the characteristic amount from the finger vein of the user, the preprocessing data registered with the IC card, and the registration data based on the unique authentication and combination technology. In this process, authentication data is generated from biometric information newly acquired by a biometric authentication mechanism connected to the ATM and preprocessed data read from the IC card, transferred to the IC card, and authenticated in the IC card. Is carried out.

본 발명의 설명에 있어서 생체 정보의 등록 처리는 영업점 시스템을 사용하고 인증 처리는 ATM을 사용하는 모양으로 설명하지만, 영업점 시스템에 있어서도 인증 처리를 ATM에 있어서도 등록 처리를 실시하는 모양도 좋다. 단, 생체 정보의 등록 처리는 본인인 것을 확실히 함에 있어서도 오퍼레이터가 입회하는 영업점 시스템에 있어서 실행하는 것이 바람직하다. 또, 생체 정보를 등록해 두는 매체로서 IC카드를 예로 들지만 이것에 한하지 않고 휴대전화나 RFID(Radio-Frequency-Identification) 태그 등, 휴대 가능한 전자 매체(휴대 전자 장치)로서도 좋지만, 현재, 이용자에게 가장 보급되어 있는 현금카드에 IC칩을 탑재한 IC카드가 바람직하고 시스템의 변경을 억제할 수가 있다.In the description of the present invention, the biometric information registration process uses a branch office system and the authentication process uses an ATM. However, the authentication process may also be performed in the ATM system or in the ATM system. However, it is preferable to perform the registration processing of the biometric information in the branch office system in which the operator is present, even in ensuring that the user is the person. Although the IC card is an example of a medium for registering biometric information, the present invention may be used as a portable electronic medium (portable electronic device) such as a mobile phone or an RFID (Radio-Frequency-Identification) tag. An IC card having an IC chip mounted on the most prevalent cash card is preferable, and changes in the system can be suppressed.

도 1은 금융기관의 영업점내에 있어서 오퍼레이터가 사용하는 영업점 시스템 가운데 특히 생체 정보의 등록에 관계하는 생체 정보 등록 처리 시스템을 추출한 개요도이다. 이 생체 정보 등록 시스템은, 생체 정보독취장치 (102)를 구비한 생체 정보 등록 장치 (101)과 이 생체 정보 등록 장치 (101)을 제어하는 등록용 단말장치 (104)를 접속해 구성한다. 이 시스템은 금융기관의 오퍼레이터(창구 담당자)가 등록용 단말장치 (104)를 조작해 IC카드 (105)에 이용자의 생체 정보를 등록하는 것이다. 구체적으로는 조작부 (107)을 창구 담당자가 조작해 표시부 (106)에 표시하는 여러 가지의 메뉴로부터 선택하고 생체 정보의 등록 외 금융기관에 있어서의 여러가지 거래를 가능하게 하는 것이다.1 is a schematic diagram extracting a biometric information registration processing system relating to the registration of biometric information among branch office systems used by an operator in a branch of a financial institution. This biometric information registration system connects and comprises the biometric information registration device 101 including the biometric information reading device 102 and the registration terminal device 104 that controls the biometric information registration device 101. In this system, an operator (window manager) of a financial institution operates the terminal device 104 for registration to register the user's biometric information on the IC card 105. Specifically, the operation unit 107 is selected from various menus displayed by the person in charge at the counter and displayed on the display unit 106 to enable various transactions in a financial institution other than registration of biometric information.

창구 담당자는 IC카드 (105)를 생체 정보 등록 장치 (101)의 한구성인 IC카드 장치 (103)에 삽입해 IC카드 (105)를 기입 가능한 상태로 한다. 한편, 이용자는 이용자 스스로의 손가락을 도시하는 형상을 따라 생체 정보 독취 장치 (102)에 둔다. 창구 담당자의 조작에 의해 생체 정보 독취 장치 (102)는 근적외선을 놓여진 손가락에 투과하고 카메라에 의해 손가락의 정맥 패턴을 촬영해 그 화상을 얻는다. 이 화상으로부터 생체 특징량을 추출해 추출한 생체 특징량에 후술하는 처리를 더해 IC카드 장치 (103)에 의해 IC카드 (105)에 기록, 기입의 처리를 실행한다. 또한 생체 특징량은 손가락의 정맥 데이터(정맥 패턴)로부터 얻은 개인을 특정할 수 있는 데이터이다.The person in charge of the window inserts the IC card 105 into the IC card device 103, which is one component of the biometric information registration device 101, so that the IC card 105 can be written therein. On the other hand, the user places it in the biometric information reading apparatus 102 along the shape which shows the user's own finger. The bioinformation reading device 102 penetrates the finger placed near the infrared ray by operation of the person in charge of the window, photographs the vein pattern of the finger by the camera, and obtains the image. The biometric feature amount is extracted from this image, and the processing described later is added to the extracted biometric feature amount, and the IC card device 103 executes recording and writing processing on the IC card 105. In addition, the bio-characteristic quantity is data which can identify an individual obtained from the vein data (vein pattern) of a finger.

IC카드 장치 (103)은 상술한 바와 같이 IC카드 (105)에 정보를 기입하는 기능을 가지고 있는 외에, IC카드 (105)에 기억되고 있는 정보를 독취하는 기능도 가지고 있다. 즉 독취 또는 쓰기 기능을 가지고 있지만, 이하에서는 IC카드 (105)내에 생체 정보를 기입하는 예에서 설명한다.The IC card device 103 has a function of writing information on the IC card 105 as described above, and also has a function of reading information stored in the IC card 105. That is, although it has a read or write function, it demonstrates in the example which writes biometric information in the IC card 105 below.

도 2는 도 1로 설명한 생체 정보 등록 처리 시스템의 하나의 실시예의 구성을 나타내는 블럭도를 나타낸다.2 is a block diagram showing the configuration of one embodiment of the biometric information registration processing system described with reference to FIG.

생체 정보 등록 장치 (101)은 생체 정보 등록 장치 (101) 전체를 제어하는 CPU(201), 여러가지 정보를 기억하는 주기억부 (202), 생체 정보를 독취하는 생체 정보 독취 장치 (102), IC카드 (105)에 생체 정보를 기입하는 IC카드 장치 (103), 및 등록용 단말장치 (104)와 접속하는 통신부 (215)에 의해 구성된다.The biometric information registration device 101 includes a CPU 201 for controlling the entire biometric information registration device 101, a main memory 202 for storing various kinds of information, a biometric information reading device 102 for reading biometric information, and an IC card. An IC card device 103 for writing biometric information into the 105 and a communication unit 215 for connecting with the registration terminal device 104 are provided.

주기억부 (202)는 각종 프로그램을 기억하는 ROM (203)과 주로 데이터를 기억하고, 기억한 데이터의 개서가 가능한 RAM (204)로 나눌 수 있다. 여기에서는, ROM (203), RAM (204)에 의한 주기억부(단지, 기억부라고도 말한다,202)로서 설명하지만, 각각 하드 디스크, 여러 가지의 반도체 메모리에 의한 구성도 좋다. ROM (203)은 생체 정보의 등록 처리를 위한 등록 처리 프로그램 (205), 인증시에 이용하는 등록 데이터를 작성하기 위한 등록 데이터 작성 프로그램 (206), 생체 정보 독취 장치 (102)를 제어하기 위한 생체 정보 독취 장치 제어 프로그램 (207), IC카드 (105)에 정보의 기입 처리를 위한 IC카드 장치 제어 프로그램 (208) 및 통신부 (215)를 제어하기 위한 통신 제어 프로그램 (209)를 구비하고 있다.The main memory unit 202 can be divided into a ROM 203 for storing various programs and a RAM 204 for storing mainly data and rewriting the stored data. Here, the main memory unit (also referred to as a storage unit, 202) by the ROM 203 and the RAM 204 will be described. However, a hard disk and various semiconductor memories may be used. The ROM 203 includes a registration processing program 205 for registration processing of biometric information, a registration data creation program 206 for creating registration data for use in authentication, and biometric information for controlling the biometric information reading device 102. A read device control program 207, an IC card device control program 208 for writing information on the IC card 105, and a communication control program 209 for controlling the communication unit 215 are provided.

생체 정보 독취 장치 (102)는 생체 화상(지정맥 패턴)을 취득하고 CCD 카메라등으로 구성되는 화상 센서(화상 취득부, 210), 화상 센서 (210)의 화상 취득 가능 영역에 손가락이 놓여있는지 아닌지를 검지하는 생체 유무 검지용 조명 LED (211), 생체 화상(지정맥 패턴) 취득시에 손가락에 대해 근적외선을 조사하는 생체 취득용 조명 LED(생체 조사부, 212)를 구비하고 있다. IC카드 장치 (103)은 IC카드 (105)에 정보를 기입하는 IC카드 기입부 (213), IC카드 (105)와 접속하기 위한 접점 단자 (214)를 구비하고 있다.The biometric information reading device 102 acquires a biometric image (arrhythmic pattern), and whether or not a finger is placed in the image acquisition region of the image sensor (image acquisition unit 210) and the image sensor 210 constituted by a CCD camera or the like. It is provided with the presence detection LED (211) for detecting the presence of a living body, and the illumination LED (bio irradiation part, 212) for biological acquisition which irradiates near-infrared rays with respect to a finger at the time of acquisition of a living body image (a finger vein pattern). The IC card apparatus 103 includes an IC card writing unit 213 for writing information into the IC card 105 and a contact terminal 214 for connecting with the IC card 105.

IC카드 (105)는 IC카드 (105) 전체를 제어하는 CPU (221), 생체 정보에 관련하는 데이터나 금융거래와 관련되는 프로그램등을 기억하는 기억부 (222), 생체 정보 등록 장치 (101)과 접속하기 위한 접점 단자 (223)을 구비하고 있다. 또한 IC카드 장치 (103)과 IC카드 (105)를 접점 단자에 의한 접촉식에 한정하지 않고, 비접촉식에서도 구성할 수 있다.The IC card 105 includes a CPU 221 for controlling the entire IC card 105, a storage unit 222 for storing data related to biometric information, programs related to financial transactions, and the like, and a biometric information registration device 101. And a contact terminal 223 for connecting with each other. In addition, the IC card device 103 and the IC card 105 can be constituted not only by the contact type by the contact terminal but also by the non-contact type.

등록용 단말장치 (104)는 등록용 단말장치 (104) 전체를 제어하는 CPU (231), 데이터나 프로그램을 기억하는 주기억부 (232), CRT나 액정 디스플레이등으로 구성되어 조작 안내를 표시하는 표시부 (106), 창구 담당자의 입력 조작을 접수하는 키보드, 마우스등으로 구성된 조작부 (107), 생체 정보 등록 장치 (101)과 생체 등록용 단말장치 (104)와 접속하는 통신부 (235)에 의해 구성된다. 그리고, 주기억부 (232)는 생체 정보 등록 장치 (101)을 제어하기 위한 생체 정보 등록 장치 제어 프로그램 (233) 외, 창구에서 거래되는 여러 가지의 금융거래용의 프로그램을 격납 하고 있다.The registration terminal device 104 includes a CPU 231 for controlling the entire registration terminal device 104, a main memory part 232 for storing data or programs, a display part for displaying an operation guide, and the like for a CRT or a liquid crystal display. And a communication unit 235 connected to the biometric information registration device 101 and the biometric registration terminal device 104. . In addition to the biometric information registration device control program 233 for controlling the biometric information registration device 101, the main memory 232 stores various financial transaction programs traded at the window.

도 3에 의해 생체 정보 등록 처리로 IC카드 (105)에 등록하는 등록 데이터의 작성 과정에 대해서 설명한다. 단, 작성 과정에 있어서의 알고리즘등의 개시는 보안상, 즉, 정보 누설등에 의한 위조를 방지하는 관계로부터 그 설명을 생략 한다. 생체 정보의 인증 처리에서도 동일하다.3, the creation process of the registration data registered in the IC card 105 by the biometric information registration process will be described. However, the description of the algorithm and the like in the production process is omitted for security reasons, i.e., preventing forgery due to information leakage. The same applies to the authentication processing of the biometric information.

먼저 화상 센서 (210)에 의해 구해진 생체 화상(지정맥 패턴)에 근거하고 어느 알고리즘을 이용해 그 특징을 나타내는 생체 특징량을 추출한다(스텝 301). 그리고 이 생체 특징량으로부터 또한 어떤 알고리즘을 이용해 전처리 데이터를 작성한다. 또 생체 특징량과 전처리 데이터를 조합해 등록 데이터를 작성한다(스텝 302).First, based on the biometric image (arrhythmic pattern) obtained by the image sensor 210, a biometric feature amount representing the feature is extracted using a certain algorithm (step 301). From this biometric feature, a certain algorithm is also used to create preprocessing data. In addition, registration data are created by combining the biometric feature and the preprocessing data (step 302).

여기서, 전처리 데이터라는 것은 등록 데이터를 작성하기 위해서 이용되는 암호키라고 하는 해석 할 수 있다. 또, 등록 데이터는 상술 및 도로부터 확실히 알 수 있는 바와 같이 생체 특징량으로부터 직접 작성하는 것이 불가능한 데이터이다. 또, 전처리 데이터와 등록 데이터는 이용자 자신의 특징을 명확하게 나타내는 생체 특징량으로부터 작성한 데이터이지만 이 작성 과정에서는 불가역변환 처리에 의한 알고리즘을 이용된다. 따라서, 역변환에 의한 작성 처리로서 등록 데이터로부터 생체 특징량 또는 전처리 데이터를 작성하는 것, 전처리 데이터와 등록 데이터의 2개의 데이터로부터 생체 특징량을 작성할 수 없다. 또한 전처리 데이터는 이용자 개인을 특정할 수 없는 부분을 발출하여 작성한 정보로 등록 데이터는 개인을 특정할 수 있는 부분을 발출하여 작성한 정보인 상태가 바람직하다. 또, 전처리 데이터, 등록 데이터 모두 카드 보유자 밖에 얻을 수 없는 특유한 정보이다.Here, the preprocessing data can be interpreted as an encryption key used to create registration data. In addition, the registration data is data which cannot be created directly from the biological feature amounts as can be clearly seen from the above and the drawings. In addition, although the preprocessing data and the registration data are data created from a biometric feature amount that clearly shows the user's own characteristics, an algorithm by irreversible conversion processing is used in this preparation process. Therefore, it is not possible to create the biometric feature amount or the preprocessing data from the registration data as the creation process by the inverse transformation, and create the biometric feature amount from the two data of the preprocessing data and the registration data. It is preferable that the preprocessing data is information created by extracting a portion that cannot identify a user individual, and the registration data is information created by extracting a portion that can identify an individual. In addition, both preprocessing data and registration data are unique information that can be obtained only by the card holder.

마지막으로 작성한 전처리 데이터와 등록 데이터를 IC카드 (105)에 기억한다(스텝 303). IC카드 (105)에 기억된 이들의 데이터는 암호화된 상태로 기억되고 또한 상술한 바와 같이 역변환에 의한 작성 처리가 불가능한 상태로 기억되고 있다. 따라서, 만일 전처리 데이터, 등록 데이터가 악의의 사람에 의해 독출되고 한편 양데이터가 해독되었다고 해도 생체 특징량을 생성하는 것은 불가능하다. 이와 같이, 데이터의 암호화, 역변환이 불가능한 데이터 생성화라고 하는 이중의 보안화에 의해 IC카드내의 데이터가 지켜질 수 있는 것도 특징의 하나이다.Finally, the preprocessed data and registration data created are stored in the IC card 105 (step 303). These data stored in the IC card 105 are stored in an encrypted state and, as described above, are stored in a state in which creation processing by inverse conversion is impossible. Therefore, even if the preprocessing data and registration data are read by the malicious person and both data are decoded, it is impossible to generate the biometric characteristic amount. Thus, one of the features is that the data in the IC card can be protected by the double security, such as data generation, which cannot encrypt or reverse data.

상기의 데이터 작성 알고리즘을 이하, 수식에서 나타낸다. The above data creation algorithm is shown in the following formula.

생체 특징량을 x로 하면 전처리 데이터 (y)는 어느 함수 (f, 알고리즘에 상당)을 이용해 「y=(f, x)」라고 하여 나타낼 수 있다.If the biometric feature amount is x, the preprocessing data (y) can be represented as "y = (f, x)" using any function (f, equivalent to an algorithm).

등록 데이터 (z)는 생체 특징량 (x)와 전처리 데이터 (y)의 조합에 의해 작성되므로, 어느 함수 (g)를 이용해 「x+y+z=g(x, y)」라고 나타낼 수 있다.Since the registration data (z) is created by the combination of the biometric feature (x) and the preprocessing data (y), it can be expressed as "x + y + z = g (x, y)" using any function (g). .

그리고, 이 작성 과정은 불가역적인 것으로 z=g(x, y)+x, z=g(x, y)+y, z=g(x, y)+x+y와 같이 등록 데이터로부터 생체 특징량이나 전처리 데이터를 복원할 수 없다.In addition, this preparation process is irreversible, and biometric features are derived from registration data such as z = g (x, y) + x, z = g (x, y) + y, z = g (x, y) + x + y. Quantity or preprocessing data cannot be restored.

도 4는 생체 정보 등록 장치 (101)의 CPU(201)가 또는 CPU(201)로부터의 지시에 근거해 각 기구, 각부(프로그램도 포함한다)가 실행하는 생체 정보의 등록 처리의 플로차트예이다.4 is an example of a flowchart of registration processing of biometric information executed by the CPU 201 of the biometric information registration device 101 or by each mechanism or each part (including a program) based on an instruction from the CPU 201.

IC카드 장치 (103)에는 IC카드 (105)가 삽입되고 있고 IC카드 접속 상태(IC 카드 (105)로의 데이터의 기입이 가능한 상태로 되어 있다. IC카드 접속을 성립시킴에는, IC카드 (105)의 접점 단자 (223)에 IC카드 장치 (103)의 접점 단자 (214)를 접촉시킬 필요가 있다. 이하에서는, 창구 담당자가 등록용 단말장치 (104)를 조작해 이용자의 생체 정보를 IC카드 (105)내에 등록하는 과정을 설명함과 동시에 그 조작에 근거하는 각 기구등이 실행하는 처리, 제어에 대해서 설명한다. 또, 도 2로 설명한 통신 제어 프로그램 (209)는 특히 생체 정보 등록 장치 (101)과 생체 등록용 단말장치 (104)의 사이에 데이터의 송수신을 제어하는 것이지만 이하에서는 생략해 설명한다.The IC card 105 is inserted into the IC card device 103, and the IC card connection state (the data can be written into the IC card 105) is enabled. In order to establish the IC card connection, the IC card 105 is established. It is necessary to bring the contact terminal 214 of the IC card device 103 into contact with the contact terminal 223 of the IC card device 103. In the following, the person in charge of the window operates the terminal device 104 for registration to display the biometric information of the user. A description will be given of the process of registration in 105, and a description will be given of the processing and control performed by each mechanism based on the operation, etc. The communication control program 209 described in Fig. 2 is particularly a biometric information registration device 101. ), But the transmission and reception of data between the biometric terminal device 104 is omitted.

등록용 단말장치 (104)는 표시부 (106)에 메뉴 화면(등록, 인증, 변경, 종료등의 처리의 선택을 안내하는 화면)을 표시해 창구 담당자의 입력 조작을 조작부 (107)에 의해 접수한다. 표시된 거래 항목중에서 등록 처리가 조작부 (107)에 의해 선택되면 등록용 단말장치 (104)의 CPU (231)은 등록 처리 프로그램 (205), 생체 정보 등록 장치 제어 프로그램 (233)을 실행하고 생체 정보 등록 장치 (101)에 등록 처리 개시가 지시를 내린다.The registration terminal device 104 displays a menu screen (a screen for guiding the selection of processing such as registration, authentication, change, termination, etc.) on the display unit 106, and the operation unit 107 receives the input operation of the counter staff. If the registration process is selected by the operation unit 107 among the displayed transaction items, the CPU 231 of the registration terminal device 104 executes the registration processing program 205 and the biometric information registration device control program 233 to register the biometric information. The registration processing start instructs the device 101.

등록 처리 개시가 지시를 받은 생체 정보 등록 장치 (101)의 CPU(201)은 등록 처리 프로그램 (205)를 실행하고 시스템 전체적으로 등록 처리를 실시한다.The CPU 201 of the biometric information registration device 101 which has been instructed to start registration processing executes the registration processing program 205 and performs registration processing as a whole of the system.

등록용 단말장치 (104)의 표시부 (106)에 생체 정보 등록 장치 (101)에 IC카드 (105)를 삽입 하도록 안내가 표시된다. IC카드 (105)가 IC카드 장치 (103)에 삽입되면(스텝 401), IC카드 (105)의 접점 단자 (223)과 IC카드 장치 (103)의 접점 단자 (214)를 접촉시켜 생체 정보 등록 장치 (101)과 IC카드 (105)의 접속을 실시 한다(스텝 402). 이 때 삽입한 IC카드 (105)의 기억부 (222)에 있어서의 생체 정보에 관련하는 프로그램의 유무를 판단하고(스텝 403), 프로그램이 없는 경우(데이터를 등록할 수 없는 카드의 경우)는 IC카드 (105)를 반환한다(스텝 411). 한편, 삽입한 IC카드 (105)의 기억부 (222)에 생체 정보에 관련하는 프로그램이 있는 경우(데이터를 등록할 수 있는 카드의 경우)는, 표시부 (106)에 등록하는 손가락을 생체 정보 독취 장치 (102)에 두도록 안내가 표시된다. 그것에 따라 이용자는 등록하는 손가락을 생체 정보 독취 장치 (102)에 둔다. 생체 정보 등록 장치 (101)의 CPU(201)은 생체 정보 독취 장치 제어 프로그램 (207)을 실행하고 생체 정보 독취장치 (102)에 생체 정보 독취 개시가 지시를 내린다. 생체 정보 독취 장치 (102)는 화상 센서 (210)의 화상 취득 가능 영역에 물체(손가락)이 놓여지면 생체 유무 검지용 조명 LED (211)에 의해 물체(손가락)의 진입을 검지해(스텝 404), 물체(손가락)이 생체인지 아닌지를 조사한다(스텝 405). 삽입된 물체(손가락)이 생체가 아닌 경우는 IC카드 (105)에 어떤 정보도 기입하는 경우 없이 IC카드 (105)를 반환한다(스텝 411). 삽입된 물체(손가락)이 생체인 경우는, 생체 취득용 조명 LED (212)에 의해 물체(손가락)에 근적외선을 조사해 화상 센서 (210)로 생체 화상(지정맥 패턴)을 취득해 RAM (204)에 기억한다(스텝 406). 다음에, 생체 화상(지정맥 패턴)로부터 생체 특징량을 추출한다(스텝 407). 그리고, 등록 데이터 작성 프로그램 (206)을 실행하는 것으로 도 3과 같이 생체 특징량으로부터 전처리 데이터를 작성한 후(스텝 408), 생체 특징량과 전처리 데이터로부터 등록 데이터를 작성한다(스텝 409). 이어서, IC카드 장치 제어 프로그램 (208)을 실행하여 작성한 RAM (204) 내의 전처리 데이터와 인증 데이터를 IC카드 기입부 (213), 또 IC카드 (105)내의 CPU (221)에 의해 IC카드 (105)의 기억부 (222)에 기억하고 생체 정보 등록이 완료하고(스텝 410), IC카드 (105)를 반환한다(스텝 411).A guide is displayed on the display unit 106 of the registration terminal device 104 so as to insert the IC card 105 into the biometric information registration device 101. When the IC card 105 is inserted into the IC card apparatus 103 (step 401), the contact terminal 223 of the IC card 105 and the contact terminal 214 of the IC card apparatus 103 are brought into contact with each other to register biometric information. The device 101 and the IC card 105 are connected (step 402). At this time, it is determined whether there is a program related to the biometric information in the storage unit 222 of the inserted IC card 105 (step 403), and if there is no program (in the case of a card for which data cannot be registered) The IC card 105 is returned (step 411). On the other hand, when there is a program related to the biometric information in the storage unit 222 of the inserted IC card 105 (in the case of a card capable of registering data), the finger that registers the finger on the display unit 106 is read out. Instructions are displayed for placement on the device 102. As a result, the user places a finger to register on the biometric information reading device 102. The CPU 201 of the biometric information registration device 101 executes the biometric information reading device control program 207 and instructs the biometric information reading device 102 to start biometric information reading. When the object (finger) is placed in the image acquisition area of the image sensor 210, the biometric information reading device 102 detects the entry of the object (finger) by the presence or absence detection illumination LED 211 (step 404). It is checked whether or not the object (finger) is a living body (step 405). If the inserted object (finger) is not a living body, the IC card 105 is returned without writing any information into the IC card 105 (step 411). When the inserted object (finger) is a living body, the near-infrared ray is irradiated to the object (finger) by the biometric illumination LED 212 to acquire a biometric image (a finger vein pattern) with the image sensor 210, and the RAM 204 (Step 406). Next, the biological feature amount is extracted from the biological image (final vein pattern) (step 407). Then, by executing the registration data creation program 206, preprocessing data is created from the biometric characteristic amount as shown in FIG. 3 (step 408), and then registration data is created from the biometric characteristic amount and the preprocessing data (step 409). Subsequently, the IC card 105 is stored by the IC card writing unit 213 and the CPU 221 in the IC card 105 by using the IC card writing unit 213 and the IC card 105 to preprocess data and authentication data in the RAM 204 created by executing the IC card device control program 208. Is stored in the storage unit 222, and biometric information registration is completed (step 410), and the IC card 105 is returned (step 411).

이상, 각 CPU(201, 221,231)이나 기억부에 기억된 각 프로그램의 처리, 제어를 기본으로 생체 정보의 등록 처리, 제어에 대해서 설명했지만 각 프로그램은 등록 처리로 이행하는 당초의 단계에서 이미 기동되고 있어도 좋고 또 이들의 하드 및 소프트에 의한 구성을 제어부로서 파악해 상술의 각종 제어, 처리는 이 제어부의 기능, 수단인 것은 말할 필요도 없다. 또, 다음에 설명하는 생체 정보의 인증 처리에 대해서도 동일하다.In the above, the registration processing and control of the biometric information have been described based on the processing and control of each program stored in each of the CPUs 201, 221, 231 and the storage unit, but each program has already been started in the initial stage of transition to the registration processing. Needless to say, these hard and soft configurations can be grasped as the control unit, and it is needless to say that the various controls and processes described above are functions and means of the control unit. The same applies to the authentication processing for biometric information described below.

생체 정보의 인증 처리를 실행하는 것에 있어 상술한 등록 처리에 의해 등록된 정보, 즉, IC카드 (105)에 기억, 등록, 기입된 전처리 데이터와 등록 데이터를 사용해 인증 처리를 실시하는 것을 전제로 해서 설명한다.In performing the authentication processing of the biometric information, on the premise that the authentication processing is performed using the information registered by the above-described registration processing, that is, preprocessing data and registration data stored, registered, and written in the IC card 105. Explain.

도 5는 생체 인증 처리 시스템의 개요도이다. 생체 인증 시스템은 생체 정보를 독취하는 기능과 IC카드 (105)의 정보에 대한 독취(또는 기입) 기능을 구비한 현금 자동 거래 또는 예금지불장치(ATM, 501)과 금융상품에 관계하는 거래에 필요한 정보를 기억하는 서버 (502)를 접속해 구성한다. ATM (501)은 입금, 지불, 입금 등 이용자가 원하는 다양한 거래를 자동적으로 실행하는 장치이고, 이용자는 카드/명세표 기구부 (504)에 IC카드 (105)를 삽입하고 조작부 (503)에 의해 원하는 거래나 금액 등을 입력하고, 생체 인증 기구 (508)에 의해 인증이 성공하는 것으로 거래를 실시하는 것이 가능해진다. 특히, 현금거래에서는 지폐 입출금 기구부 (506) 에 의한 지폐의 입금 또는 출금, 동전 입출금 기구부 (507)에 의한 동전의 입금 또는 출금이 실행되고 ATM (501)은 이용자가 원하는 현금의 교환을 실시한다. 또, 이용자가 통장 기입을 원할 때에는, 통장 기구부 (505)에서 통장에 거래 내용을 기입, 인자할 수가 있다.5 is a schematic diagram of a biometric authentication processing system. The biometric authentication system is required for a transaction related to a cash automatic transaction or a deposit payment device (ATM) 501 having a function of reading biometric information and a reading (or writing) of the information of the IC card 105 and a financial product. A server 502 that stores information is connected and configured. The ATM 501 is a device that automatically executes various transactions desired by the user, such as deposit, payment, and deposit, and the user inserts the IC card 105 into the card / specification tag mechanism 504 and the desired transaction by the operation unit 503. The amount of money or the like is inputted, and the biometric authentication mechanism 508 enables the transaction to be successful. In particular, in the cash transaction, the deposit or withdrawal of the bill by the banknote deposit and withdrawal mechanism part 506, the deposit or withdrawal of the coin by the coin withdrawal mechanism 507 is performed, and the ATM 501 exchanges cash desired by the user. In addition, when a user wants to fill out a bankbook, the account book mechanism unit 505 can fill in and print the transaction contents in the bankbook.

도 6은 생체 인증 처리 시스템의 하나의 실시예의 구성을 나타내는 블럭도이다. ATM (501)은 ATM 전체를 제어하는 CPU (601), 거래 항목의 화면 표시나 키 입력 검지, 구체적으로는 이용자의 조작이나 손가락으로 눌려진 키 입력을 접수하는 터치 패널등으로 구성된 조작부 (503), 카드의 삽입 및 배출 동작, 카드의 자기 스트라이프 또는 IC카드 (105)로의 리드/라이트 동작, 카드 엠보스 부분의 이미지의 독취나 거래한 내용을 명세표에 인자해 장치내로부터 배출하는 기능을 가지는 카드/명세표 기구부 (504), 이용자의 통장의 삽입/배출 동작, 자기 스트라이프의 리드/라이트 동작, 통장으로의 인자부에 의한 인자기능 등을 가지는 통장 기구부 (505)를 가진다.6 is a block diagram showing the configuration of one embodiment of a biometric authentication processing system. The ATM 501 is an operation unit 503 composed of a CPU 601 for controlling the entire ATM, a screen display of a transaction item or a key input detection, specifically a touch panel for accepting a user's operation or a key pressed by a finger, and the like. Cards having a function of inserting and ejecting a card, magnetic stripe of the card or read / write operation to the IC card 105, reading or trading the image of the card embossed portion in the specification table and ejecting from the device. The specification table mechanism part 504, the bankbook mechanism part 505 which has the user's insertion / ejection operation | movement of a bankbook, the read / write operation of a magnetic stripe, the printing function by the printing part to a bankbook, etc. are provided.

또한 지폐의 감별이나 반송, 수납 기능 등을 갖고, 지폐의 입금 또는 출금 처리를 실시하는 지폐 입출금 기구부 (506), 동전의 감별이나 반송, 수납 기능 등을 갖고 동전의 입금 또는 출금 처리를 실시하는 동전 입출금 기구부 (507), 생체 정보를 취득하고 그 인증을 서포트하는 생체 인증 기구부 (508), 데이터나 프로그램을 기억하는 주기억부(단지 기억부라고도 말한다, 602) 및 서버 (502)와 접속하는 통신부 (610)에 의해 구성된다.In addition, a bill having a differentiation, conveyance, and storing function of bills, a bill acceptor withdrawal mechanism unit 506 for depositing or withdrawing bills, and a coin for depositing or withdrawing coins with discrimination, conveyance, and storing functions of coins. Deposit and withdrawal mechanism unit 507, biometric authentication mechanism unit 508 for acquiring biometric information and supporting its authentication, a main memory unit (also referred to as a storage unit 602) for storing data and programs, and a communication unit connected to server 502 ( 610.

또한 도 1, 2로 설명한 등록용 단말장치 (104)의 조작부 (107)은 창구 담당 자가 이용자의 생체 정보를 IC카드 (105)에 등록할 때에 입력 조작을 행하기 위한것으로 키보드나 마우스등으로 구성되고 있고 또, 도 5, 6의 ATM (501)의 조작부 (503)은 이용자가 ATM (501)로 거래를 실시할 때에 입력 조작하기 위한 것으로, 터치 패널등으로 구성되고 있고 이 2개는 같은 조작부에서도 구성·용도가 다른 것이다.In addition, the operation unit 107 of the terminal device 104 for registration described in Figs. 1 and 2 is configured to perform an input operation when a window manager registers a user's biometric information on the IC card 105, and is composed of a keyboard or a mouse. In addition, the operation part 503 of the ATM 501 of FIG. 5, 6 is for input operation when a user makes a transaction with the ATM 501, and is comprised from a touch panel etc., and these two are the same operation part The configuration and use are different.

카드/명세표 기구부 (504)는 IC카드 (105)의 정보를 독취하는 IC카드 독취부 (603)과 명세표에 거래 내용을 인자하는 명세표 인자부 (604) 및 IC카드 (105)와 접속하기 위한 접점 단자 (605)를 구비하고 있다.The card / specification tag mechanism 504 is a contact for connecting with the IC card reader 603 for reading the information of the IC card 105, the specification card printing portion 604 for printing the transaction contents in the specification table, and the IC card 105. The terminal 605 is provided.

생체 인증 기구부 (508)은 여러 가지의 데이터등을 기억하는 기억부 (606)과 이용자의 생체 화상(지정맥 패턴)을 취득하고 CCD 카메라등으로 구성되는 화상 센서(화상 취득부, 607)과 화상 센서 (607)의 화상 취득 가능 영역에 손가락이 놓여있는지 아닌지를 검지하는 생체 유무 검지용 조명 LED (608)와 생체 화상(지정맥 패턴) 취득시에 손가락에 대해 근적외선을 조사하는 조명 LED(생체 조사부, 609)를 구비하고 있다. 즉, 생체 인증 기구부 (508)은 도 1, 2에 나타내는 생체 정보 독취 장치 (102)와 거의 동일한 생체 정보를 취득하는 기능을 가지고 있다.The biometric authentication mechanism unit 508 acquires a memory unit 606 for storing various data and the like, and a biometric image (final vein pattern) of the user, and an image sensor (image acquisition unit 607) and an image composed of a CCD camera or the like. Illumination LED 608 for detecting the presence or absence of a finger placed in the image captureable area of the sensor 607 and illumination LED for irradiating near-infrared light on the finger at the time of acquisition of the biometric image (a finger vein pattern) (bioirradiation unit) 609 is provided. In other words, the biometric authentication mechanism unit 508 has a function of acquiring biometric information which is almost the same as the biometric information reading device 102 shown in FIGS.

주기억부(단지 기억부라고도 말한다, 602)는 하드적으로는 각종 프로그램을 기억하는 ROM (620)과 주로 데이터를 기억하고 기억한 데이터의 개서가 가능한 RAM (621)로 구성된다. 상술의 등록 처리로 설명한 바와 같이, 각각 하드 디스크나 여러 가지의 반도체 메모리에 의한 구성에서도 좋고, 또 제1, 2 기억부라고도 말한다. 또, ROM (620)는 이하에 설명하는 생체 화상의 취득, 인증등의 처리를 CPU (601)등가 지시에 따라서 실시하고 생체 인증 기구부 (508)을 제어하기 위한 인증 제어 소프트웨어 (622)를 구비하고 있다. 이 외, 도시하지 않지만 ATM (501)의 조작부 (503)로의 화면 데이터, ATM (501)에 있어서의 현금거래, 입금 거래등에 필요한 프로그램, 소프트웨어도 기억되고 있다. ATM (501)과 통신망을 개재시켜 접속된 서버 (502)는 서버 (502) 전체를 제어하는 CPU (611), 기억부 (612) 및 ATM (501)과 접속하는 통신부 (613)에 의해 구성된다.The main memory unit (also referred to simply as a storage unit) 602 is hardly constituted by a ROM 620 for storing various programs and a RAM 621 capable of rewriting data stored mainly in data. As described in the above-described registration processing, the configuration may be made of a hard disk or various semiconductor memories, respectively, and is also referred to as first and second storage units. In addition, the ROM 620 is provided with authentication control software 622 for performing the processing of acquiring, authenticating, and the like described below according to the CPU 601 equivalent instruction, and controlling the biometric authentication mechanism unit 508. have. In addition, although not shown, screen data to the operation unit 503 of the ATM 501, programs and software necessary for cash transactions and deposit transactions in the ATM 501 are also stored. The server 502 connected via the communication network with the ATM 501 is constituted by a CPU 611 that controls the entire server 502, a storage unit 612, and a communication unit 613 that connects with the ATM 501. .

도 7은 ATM (501)에 있어서의 생체 정보의 인증과 관련되는 제어, 특히, 생체 인증 기구부 (508)의 제어하기 위한 인증 제어 소프트웨어 (622)를 중심으로 한 주기억부 (602), 생체 인증 기구부 (508), 카드/명세표 기구부 (504)내의 IC카드 (105) 에 관련하는 제어 블록(소프트웨어 구성)을 도시한 것이다.Fig. 7 shows a main memory unit 602 and a biometric authentication mechanism centering on the authentication control software 622 for controlling the control of the biometric information in the ATM 501, in particular, the biometric authentication mechanism unit 508. 508, a control block (software configuration) associated with the IC card 105 in the card / specification table mechanism section 504 is shown.

인증 제어 소프트웨어 (622)는, 크고, 인증 제어 어플리케이션 (701)과 인증 제어 미들웨어 (702)로 나눌 수 있고 각각, 소프트웨어의 것을 소프트, 어플리케이션의 것을 어플리, 미들웨어의 것을 미들이라고 칭할 수가 있다. 인증 제어 어플리케이션 (701)이라는 것은, 생체 인증 기구부 (508)을 탑재하는 ATM (501)를 도입하는 금융기관 등의 개별의 기능을 가지는 프로그램이고, 그 인증의 순서나 방식, 인증시에 있어서의 화면 표시 등 금융기관 개개로 그 사양을 작성하고 또 변경된다. 특히, 본 인증 제어 어플리케이션 (701)은 인증 처리 개시 지시등을 인증 미들 (702)에 대해서 실시한다.The authentication control software 622 is large and can be divided into an authentication control application 701 and an authentication control middleware 702, and software can be referred to as software, application to middle, and application to middleware, respectively. The authentication control application 701 is a program having individual functions, such as a financial institution incorporating an ATM 501 having the biometric authentication mechanism unit 508, and the screen in the authentication procedure, method, and authentication. The specifications are prepared and changed individually by financial institutions such as indicators. In particular, the authentication control application 701 implements the authentication process start indicator light for the authentication middle 702.

인증 제어 미들 (702)라는 것은 금융기관이 다르고, 생체 정보가 달라도 인증 처리에 필요한 공통 기능을 가지는 프로그램이고, 생체 인증 기구부 (508)을 제 어하는 생체 인증 기구부 제어 프로그램 (703), IC카드 (105)로부터 카드와 데이터의 교환, IC카드 (105)내의 프로그램의 실행을 제어하는 IC카드 제어 프로그램 (704)라고 하는 생체 정보의 인증과 관련되는 각종 프로그램의 제어, 처리를 맡는 프로그램이다.The authentication control middle 702 is a program having a common function necessary for authentication processing even if the financial institutions are different and the biometric information is different, and the biometric authentication mechanism control unit 703 that controls the biometric authentication mechanism unit 508, the IC card ( 105 is a program that controls and processes various programs related to authentication of biometric information called an IC card control program 704 that controls the exchange of data with a card and execution of a program in the IC card 105.

또, 인증 제어 미들 (702)에 의해 실행되어 구해지는 데이터는 RAM (621)에 일시적으로 기억된다. RAM (621)은, 생체 인증 기구부 (508)과 IC카드 (105)의 사이의 데이터를 교환하기 위한 버퍼 영역인 인증 결과 데이터 버퍼 (705), 인증 데이터 버퍼 (706), 전처리 데이터 버퍼 (707)이라고 하는 각 데이터 버퍼를 가진다. 이들의 데이터는 하드적으로는 RAM (621)에 기억되지만 소프트적으로 인증 제어 소프, 특히 인증 제어 미들 (702)에 기억된다고도 말할 수 있다.The data executed by the authentication control middle 702 and obtained are temporarily stored in the RAM 621. The RAM 621 includes an authentication result data buffer 705, an authentication data buffer 706, and a preprocessing data buffer 707 which are buffer areas for exchanging data between the biometric authentication mechanism unit 508 and the IC card 105. It has each data buffer called. These data may be hardly stored in the RAM 621, but softly stored in the authentication control soap, in particular, the authentication control middle 702.

또 인증 제어 미들 (702)는 인증 제어 어플리케이션 (701)로부터의 지시에 의해 드라이버(도시하지 않는다)를 경유해 카드/명세표 기구부 (504)나 생체 인증 기구부 (508)을 동작시킨다. 그리고, 위에서 설명한 바와 같이 이들의 각부위는 ATM (501)의 CPU (601)에 의해 그 처리가 제어된다. 또한 드라이버로는 컴퓨터 주변기기·장치(디바이스)를 이용하기 위한 제어용 소프트웨어 있다.The authentication control middle 702 operates the card / specification tag mechanism 504 or the biometric authentication mechanism 508 via a driver (not shown) by an instruction from the authentication control application 701. As described above, the processing of these parts is controlled by the CPU 601 of the ATM 501. As a driver, there is control software for using a computer peripheral device (device).

인증 제어 소프트 (622)에서 제어되는 생체 인증 기구부 (508)의 기억부 (606)은 인증 데이터를 작성하기 위한 인증 데이터 작성 프로그램 (709), 인증 결과 데이터로부터 인증의 성공 여부를 판정하기 위한 인증 결과 판정 프로그램 (710)을 가진다. 또 카드/명세표 기구부 (504)는 인증 처리를 실시하기 위한 인증 프로그램 (711)을 가진다.The storage unit 606 of the biometric authentication mechanism unit 508 controlled by the authentication control software 622 includes an authentication data creation program 709 for creating authentication data and an authentication result for determining whether the authentication succeeds from the authentication result data. Has a decision program 710. The card / specification tag mechanism 504 also has an authentication program 711 for performing authentication processing.

도 8에 의해 생체 인증 처리에 있어서의 인증의 구성, 데이터의 교환에 대해서 설명한다. 후술의 도 11의 생체 인증 플로우의 설명의 보완으로서도 이용한다. 이하의 동작의 주체는 인증 제어 어플리케이션 (701)로부터 실행 명령을 받은 인증 제어 미들 (702)이지만, 인증 제어 어플리케이션 (701)과 인증 제어 미들 (702)가 공동하여 실시하는 것으로부터 인증 제어 소프트 (622)에 의해 동작한다고도 말할 수 있다. 또, 수신, 송신을 각각 입력, 출력이라고도 말할 수 있다.8, the structure of authentication and data exchange in a biometric authentication process are demonstrated. It is also used as a supplement to the description of the biometric authentication flow of FIG. 11 described later. The subject of the following operation is the authentication control middle 702 which has received an execution command from the authentication control application 701, but the authentication control software 622 from the joint control performed by the authentication control application 701 and the authentication control middle 702. It can also be said to work by). In addition, reception and transmission can also be called input and output, respectively.

ATM (501)의 거래에 있어서 생체 정보의 인증이 실행되면, IC카드 (105)에 미리 기억되고 있는 전처리 데이터, 등록 데이터 가운데 전처리 데이터가 인증 제어 미들 (702)에 송신된다. 인증 제어 미들 (702)는 IC카드 (105)로부터 전처리 데이터를 수신하고 RAM (621,인증 제어 소프트 (622), 인증 제어 미들 (702)를 포함한다)의 전처리 데이터 버퍼 (707)에 일시 기억하고 나서, 생체 인증 기구부 (508)에 송신한다(스텝 801). 한편, 생체 인증 기구부 (508)은 인증 제어 소프트 (622)로부터 전처리 데이터를 수신하고 그 후 또는 병행하여 이용자의 생체 정보를 취득하고 생체 정보로부터 생체 특징량을 추출한다. 그리고, 수신한 전처리 데이터로 취득, 추출한 생체 특징량을 조합해 인증 데이터를 작성한다(스텝 802).When authentication of the biometric information is executed in the transaction of the ATM 501, the preprocessing data among the preprocessing data and registration data previously stored in the IC card 105 is transmitted to the authentication control middle 702. The authentication control middle 702 receives the preprocessing data from the IC card 105 and temporarily stores it in the preprocessing data buffer 707 of the RAM 621 (including the authentication control software 622 and the authentication control middle 702). Then, it transmits to the biometric authentication mechanism part 508 (step 801). On the other hand, the biometric authentication mechanism unit 508 receives the preprocessing data from the authentication control software 622, and subsequently or in parallel, acquires the user's biometric information and extracts the biometric feature amount from the biometric information. Then, authentication data is created by combining the biometric feature values acquired and extracted from the received preprocessed data (step 802).

이와 같이, 생체 정보의 인증 처리에 있어서, 전처리 데이터는 인증 데이터를 작성하기 위한 암호키로서의 기능도 가지고 있다. 또, 이 인증 데이터를 만일 취득할 수 있다고 해도, 이 데이터로부터 생체 특징량을 직접 작성할 수 없다. 인증 데이터는 생체 특징량로부터 작성한 데이터이지만 이 작성 과정에서는 불가역변환 처리에 의한 알고리즘을 이용하고 있는 것으로부터 반대로 인증 데이터로부터 생체 특징량을 작성할 수 없고, 또한, 전처리 데이터와 인증 데이터의 2개의 데이터로부터 생체 특징량을 작성할 수 없다.In this way, in the authentication processing of the biometric information, the preprocessed data also has a function as an encryption key for creating authentication data. Moreover, even if this authentication data can be acquired, a biometric characteristic amount cannot be created directly from this data. The authentication data is data created from the biometric characteristic amount, but in this preparation process, the biometric characteristic amount cannot be created from the authentication data on the contrary to using the algorithm by the irreversible conversion process, and from the two data of the preprocessing data and the authentication data, Biometric features cannot be created.

전처리 데이터는 개인을 특정할 수 없는 부분을 발출하여 작성한 정보로 인증 데이터는 개인을 특정할 수 있는 부분을 발출하여 작성한 정보이다.The preprocessing data is information created by retrieving a portion that cannot specify an individual, and the authentication data is information created by retrieving a portion that can specify an individual.

여기서, 상기의 데이터 작성 알고리즘을 생체 정보 등록시와 동일하게 수식에서 나타낸다. Here, the data creation algorithm described above is expressed by a mathematical formula as in the case of biometric information registration.

생체 인증 기구부 (508)에 의해 인증시에 얻는 정보, 즉, 새롭게 얻은 생체 특징량을 x'로 한다. 그리고 전처리 데이터 (y)는 등록시와 다르지 않기 때문에, 「y=(f, x)」이다.The information obtained at the time of authentication by the biometric authentication mechanism unit 508, that is, the newly obtained biometric feature amount is assumed to be x '. And since the preprocessing data (y) is not different from the time of registration, it is "y = (f, x)".

인증 데이터 (z')는 생체 특징량 (x')와 전처리 데이터 (y)의 조합에 의해 작성되므로, 어느 함수 (g)를 이용해 「x'+y+z'=g(x', y)」라고 나타낼 수 있다. 그리고, 이 작성 과정은 불가역과정이므로, /+x', z'+y, z'+x'+y와 같이 등록 데이터로부터 생체특징량이나 전처리 데이터를 복원할 수 없다.Since the authentication data (z ') is created by the combination of the biometric feature (x') and the preprocessing data (y), using either function (g), "x '+ y + z' = g (x ', y) ”. And since this preparation process is an irreversible process, it is not possible to restore the biofeature amount or preprocessing data from the registration data such as / + x ', z' + y, z '+ x' + y.

S802의 인증 데이터 작성 후, 생체 인증 기구부 (508)로 작성한 인증 데이터를 인증 제어 소프트 (622)가 지시, 제어에 의해 인증 데이터 버퍼 (706)에 일시 기억하고 나서 IC카드 (105)에 송신한다(스텝 803). IC카드 (105)는 인증 데이터를 수신하고 IC카드 (105)에 기억해 둔 등록 데이터와 인증 데이터를 어떤 알고리즘에 의해 조합해(생체 인증 처리라고도 말한다), 인증 결과 데이터를 작성한다(스텝 804). 또한 작성한 인증 결과 데이터를 인증 제어 미들 (702)에 송신한다. 인증 제어 미들 (702)는 IC카드 (105)로부터 인증 결과 데이터를 수신하고 인증 제어 소프 트 (622)의 인증 결과 데이터 버퍼 (705)에 일시 기억하고나서 생체 인증 기구부 (508)에 송신한다. 그리고, 생체 인증 기구부 (508)은 생체인증 기구부 (508)내에서 인증 결과 데이터의 판정(분석)을 행하고(스텝 805), 인증 결과 데이터와 인증 성공 부위·인증 실패 원인을 인증 제어 미들 (702)에 통지하며(스텝 806), 생체 인증 처리는 종료한다.After creation of the authentication data in S802, the authentication data generated by the biometric authentication mechanism unit 508 is temporarily stored in the authentication data buffer 706 by the instruction and control, and then transmitted to the IC card 105 ( Step 803). The IC card 105 receives the authentication data and combines the registration data and the authentication data stored in the IC card 105 by some algorithm (also referred to as biometric authentication processing) to create authentication result data (step 804). Furthermore, the created authentication result data is transmitted to the authentication control middle 702. The authentication control middle 702 receives the authentication result data from the IC card 105, temporarily stores it in the authentication result data buffer 705 of the authentication control software 622, and transmits it to the biometric authentication mechanism unit 508. Then, the biometric authentication mechanism unit 508 performs determination (analysis) of the authentication result data in the biometric authentication mechanism unit 508 (step 805), and the authentication control middle 702 determines the authentication result data and the authentication success site and the cause of the authentication failure. (Step 806), the biometric authentication process ends.

이와 같이, 생체 인증 처리에서는 이용자의 생체 정보 그것에 가장 가까운 생체 특징량은 IC카드 (105)내에 기억하고 있지 않고, 또 생체 인증 기구부 (508)에 의해 생체 특징량을 취득, 추출하지만 생체 인증 기구부에서 밖으로는 나오지 않는 특징을 가지고 있다.In this way, in the biometric authentication process, the biometric feature amount closest to the user's biometric information is not stored in the IC card 105, and the biometric feature amount is obtained and extracted by the biometric authentication mechanism unit 508. It has a feature that does not come out.

또, 인증 제어 소프트 (622)를 개재시키고, 또 그 제어의 기본으로 IC카드 (105)와 생체 인증 기구부 (508)의 사이에 교환하는 데이터는 전처리 데이터, 인증 데이터, 인증 결과 데이터의 3개이지만, 상술한 바와 같이 이들의 데이터를 무엇으로 조합해도 생체 특징량을 작성할 수 없는 특징도 가지고 있다.Incidentally, the data exchanged between the IC card 105 and the biometric authentication mechanism unit 508 via the authentication control software 622 as the basis of the control is three pieces of preprocessing data, authentication data, and authentication result data. As described above, even if these data are combined in any way, there is a feature that a biometric feature cannot be created.

또, 생체 정보와 관련되는 각 데이터의 작성 등 생체 인증 처리에 있어서, IC카드 (105), 생체 인증 기구부 (508)이 각각 분담해 인증 결과를 구하는 특징을 가지고 있다. 그 때문에, IC카드 또는 생체 인증 기구부가 분실되어 또 그 내부를 해독했다고 해도 생체 인증 처리를 실행할 수가 없게 정리되어 있다. 즉, 인증시에 생체 인증 기구부 (508)로 취득한 생체 특징량으로부터 새롭게 전처리 데이터를 작성하고 일전에 처리 데이터와 생체 특징량으로부터 인증 데이터를 작성하는 것도 이론상 가능하지만, 본 실시 형태에서는 그와 같이 하지 않고 IC카드 (105)에 기억 해 둔 전처리 데이터와 생체 특징량에 의해 인증 데이터를 작성하므로, 보안이 높게 유지되고 있다.In addition, in the biometric authentication process such as the preparation of each data related to the biometric information, the IC card 105 and the biometric authentication mechanism unit 508 each share a feature of obtaining an authentication result. Therefore, even if the IC card or the biometric authentication mechanism is lost and the inside thereof is decrypted, the biometric authentication cannot be executed. That is, it is also theoretically possible to create new preprocessing data from the biometric feature amount acquired by the biometric authentication mechanism unit 508 at the time of authentication, and to create authentication data from the processed data and biometric feature amounts earlier, but in the present embodiment, it is not so. Instead, authentication data is generated from the preprocessing data and biometric features stored in the IC card 105, so that the security is kept high.

또, 인증 제어 미들 (702)는 전처리 데이터를 생체 인증 기구부 (508)내에 기억하고 인증 데이터가 작성되고 나서 삭제하는 것이 좋고 인증이 필요한 때에, 수시로, 전처리 데이터 버퍼 (707)로부터 생체 인증 기구부 (508)에 송신하는 편이 바람직하다. 즉, ATM (501)에 의한 거래가 끝날 때까지 인증 제어 소프트 (622)내의 전처리 데이터 버퍼 (707)에 전처리 데이터를 기억해 두는 것이다. 이렇게 하는 것으로, 전처리 데이터를 IC카드 (105)로부터 송신하는 것보다도 인증 제어 소프트 (622)내의 전처리 데이터 버퍼 (707)로부터 송신하는 것이 빠른 처리가 가능하다는 효과가 있다.In addition, the authentication control middle 702 stores the preprocessed data in the biometric authentication mechanism unit 508 and deletes it after the authentication data has been created. When authentication is necessary, the biometric authentication mechanism unit 508 is frequently used from the preprocessing data buffer 707. It is preferable to transmit to That is, the preprocessing data is stored in the preprocessing data buffer 707 in the authentication control software 622 until the transaction by the ATM 501 is completed. By doing this, there is an effect that the faster processing is possible from the preprocessing data buffer 707 in the authentication control software 622 than the preprocessing data is transmitted from the IC card 105.

9~12를 이용해 현금 자동 거래 장치, 현금 자동예금지불장치(ATM, 501)로 IC카드 (105)를 사용해 IC카드내 인증 방식에 의한 생체 인증 처리를 포함한 지불 거래를 실시할 때의 처리를 설명한다. Using 9 to 12, we will explain the processing when performing a payment transaction including a biometric authentication process using the IC card 105 using an IC card 105 with an ATM or a cash advance payment device (ATM, 501). do.

도 9는 ATM (501)의 CPU (601), 인증 제어 소프트 (622)등 (제어부)이 실행하고 특히 IC카드내 인증 방식을 이용한 생체 인증 처리에 의한 ATM상에서의 거래를 나타내는 플로차트예이다.Fig. 9 is an example of a flowchart showing a transaction on an ATM executed by a CPU 601, an authentication control software 622, and the like (control unit) of an ATM 501, and particularly by a biometric authentication process using an IC card authentication method.

생체 인증 처리를 실시하기 전에 거래 선택이나 암호인증 번호 입력, 카드 삽입 등 ATM (501)에서의 거래를 실행하기 위해서 필요한 처리를 실시한다. 조작부 (503)에 입금, 지불, 잔고 조회, 입금 등의 거래 선택 안내를 ROM (620)에서 독취하여 표시하고 이용자로부터 거래의 선택을 접수한다(스텝 901). 생체 인증이 필요 한 거래, 예를 들면 지불 거래등이 선택되었을 경우는 조작부 (503)에 IC카드를 삽입하는 취지의 안내를 표시해 IC카드 (105)의 삽입을 재촉한다. 이용자에 의해 카드/명세표 기구부 (504)에 IC카드 (105)가 삽입되면 그것을 검지 해(스텝 902), 카드/명세표 기구부 (504)의 IC카드 독취부 (603)에서 IC카드 (105)로부터 계좌 번호를 독출한다. 또한 IC카드 (105)는 자기 스트라이프를 구비한 것도 좋고 그 때는 생체 정보 이외의, 계좌 번호등의 데이터를 IC카드 (105)의 자기 스트라이프로부터 독취하는 것도 가능하다.Before performing the biometric authentication processing, processing necessary for executing a transaction in the ATM 501, such as transaction selection, input of a cryptographic authentication number, and insertion of a card, is performed. The transaction selection guide, such as deposit, payment, balance inquiry, and deposit, is read and displayed on the operation unit 503 at the ROM 620 to accept the transaction selection from the user (step 901). When a transaction requiring biometric authentication, for example, a payment transaction, is selected, a guide for inserting the IC card is displayed on the operation unit 503 to prompt the insertion of the IC card 105. When the IC card 105 is inserted into the card / specification tag mechanism 504 by the user, it is detected (step 902) and the account is entered from the IC card 105 in the IC card reading portion 603 of the card / specification tag mechanism 504. Read the number. In addition, the IC card 105 may be provided with a magnetic stripe, and data such as an account number other than the biometric information may be read from the magnetic stripe of the IC card 105 at that time.

다음에 암호인증 번호를 입력하는 취지의 안내를 조작부 (503)에 표시한다. 이용자에 의해 조작부 (503)에 암호인증 번호가 입력되면 그것을 검지해(스텝 903), 독출한 계좌 번호와 입력된 암호인증 번호를 통신부 (610, 613)을 개재시켜 서버 (502)에 송신한다. 한편, 서버 (502)의 CPU (611)은 입력된 비밀번호를 통신부 (610, 613)을 개재시켜 수신하고 입력된 암호인증 번호와 사전에 기억부 (612)에 등록해 둔 계좌 번호에 대응하는 비밀번호의 조합을 실시하고 그 조합 결과를 ATM (501)에 통신부 (610, 613)을 개재시켜 송신한다. ATM (501)은 통신부 (610, 613)을 개재시켜 조합 결과를 수신하고 암호인증 번호가 맞는지를 체크하고(스텝 904), 입력된 암호인증 번호가 올바르지 않은 경우는, 암호인증 번호의 입력 회수를 카운트 한다(스텝 905). 이 때의 비밀번호의 입력 회수가 규정 회수 이내이면 이용자에 대해서 암호인증 번호의 재입력을 재촉한다. 비밀번호의 입력 회수가 규정 회수를 넘으면 거래를 중지한다(스텝 906).Next, a guide for inputting a password authentication number is displayed on the operation unit 503. If a password authentication number is input to the operation unit 503 by the user, it is detected (step 903), and the read account number and the input password authentication number are transmitted to the server 502 via the communication units 610 and 613. On the other hand, the CPU 611 of the server 502 receives the input password via the communication units 610 and 613, and the password corresponding to the input password authentication number and the account number previously registered in the storage unit 612. Are combined and the combined result is transmitted to the ATM 501 via the communication units 610 and 613. The ATM 501 receives the combination result via the communication units 610 and 613, checks whether the password authentication number is correct (step 904), and if the input password authentication number is not correct, the number of times of inputting the password authentication number is determined. It counts (step 905). If the number of times the password is input at this time is within the prescribed number, the user is urged to re-enter the password authentication number. If the number of times the password is input exceeds the prescribed number of times, the transaction is stopped (step 906).

S904에 있어서, 입력된 암호인증 번호가 올바른 경우는, 삽입된 IC카드 (105)가 생체 인증 대상 카드인지 아닌지를 판단한다(스텝 907). 이 때의 생체 인증 대상 카드라는 것은 생체 인증을 실시하기 위해서 필요한 정보나 프로그램을 가지는 카드이다.In S904, when the inputted password authentication number is correct, it is determined whether the inserted IC card 105 is a biometric authentication target card (step 907). The biometric authentication target card at this time is a card having information or a program necessary for performing biometric authentication.

그리고, 삽입된 IC카드 (105)가 생체 인증 대상 카드가 아닌 경우는 생체 인증 처리를 실시하지 않고, 계속하여 지불등의 거래를 실행한다(스텝 915). 삽입된 IC카드 (105)가 생체 인증 대상 카드인 경우 생체 인증 처리의 사전 준비로서 인증 거래 개시 처리를 실시한다(스텝 908). 인증 거래 개시 처리에 대해서는 후술의 도 10을 이용해 상세하게 설명한다.When the inserted IC card 105 is not the biometric authentication target card, the biometric authentication process is not performed and the transaction such as payment is subsequently executed (step 915). When the inserted IC card 105 is a biometric authentication target card, an authentication transaction start process is performed as a preliminary preparation of the biometric authentication process (step 908). The authentication transaction start processing will be described in detail with reference to FIG. 10 described later.

인증 거래 개시 처리가 종료하면 ATM (501)의 CPU (601)은 인증 제어 소프트 (622)를 RAM (621)로 구성하여 전개한다. 다음에 ATM (501)의 CPU (601)은 인증 제어 어플리케이션 (701)을 실행한다. 그것을 받아 인증 제어 어플리케이션 (701)은 인증 제어 미들 (702)에 대해 등록 정보 취득 지시를 내린다. 등록 정보 취득 지시를 받은 인증 제어 미들 (702)는 IC카드 제어 프로그램 (704)를 실행하고 인증 제어 어플리케이션 (701)로부터 지시받은 처리에 필요한 정보(등록자 정보)를 IC카드 (105)로부터 취득한다(스텝 909). 처리에 필요한 정보에는 계좌 번호, 지점번호, 과목 등의 거래 정보나 이용자 이름, 운전 면허증이나 보험증 등의 본인 확인이 가능한 증명서의 유무라고 하는 이용자 정보 등이 포함된다. 또, 이 때 인증 제어 미들 (702)는 인증 제어 어플리케이션 (701)로 취득을 지시받은 정보의 그 밖에, IC카드 (105)에 미리 등록되어 있던 전처리 데이터를 취득하고 전처리 데이터 버퍼 (707)에 격납 한다. 이것은 인증 제어 어플리케이션 (701)이 지정하고 있는 정보와 함께 전처리 데이터도 취득하는 것으로 IC카드 (105)에 액세스하는 회수를 줄여, 처리 시간을 향상하기 위함이다. 이 데이터는 인증 제어 미들 (702)에 송신되어 전처리 데이터 버퍼 (707)에 격납된다. 이와 같이 ATM (501)의 CPU (501)가 주체가 되어 인증 제어 소프트 (622)내의 각종 프로그램을 실행해 각각의 처리를 실시하지만, 이하에서는 설명을 간략화하기 위해서 이 과정을 생략하고 인증 제어 미들 (702)를 주체로서 설명한다. 또, 상술해 온 것처럼 이들을 모아 제어부(수단)에 의한 제어, 처리라고도 말한다.When the authentication transaction start processing ends, the CPU 601 of the ATM 501 configures the authentication control software 622 into the RAM 621 and expands. Next, the CPU 601 of the ATM 501 executes the authentication control application 701. Upon receiving it, the authentication control application 701 issues a registration information acquisition instruction to the authentication control middle 702. The authentication control middle 702 having received the registration information acquisition instruction executes the IC card control program 704 and acquires information (registrant information) necessary for the processing instructed from the authentication control application 701 from the IC card 105 ( Step 909). Information necessary for processing includes transaction information such as account number, branch number, subject, and user information such as user name, presence or absence of a certificate capable of verifying identity such as driver's license or insurance card. At this time, the authentication control middle 702 acquires the preprocessing data previously registered in the IC card 105 of the information instructed to be acquired by the authentication control application 701 and stores it in the preprocessing data buffer 707. do. This is to obtain the preprocessing data together with the information specified by the authentication control application 701, thereby reducing the number of times of access to the IC card 105 and improving the processing time. This data is transmitted to the authentication control middle 702 and stored in the preprocessing data buffer 707. In this way, the CPU 501 of the ATM 501 is mainly a subject, and executes various programs in the authentication control software 622 to perform respective processes. However, in order to simplify the description, the following steps are omitted to simplify the explanation. 702) will be described as the subject. Moreover, as mentioned above, these are also called control and a process by a control part (means).

IC카드 (105)로부터 등록 정보를 취득 후 인증 제어 미들 (702)는 생체 인증 기구부 제어 프로그램 (703)을 실행해 생체 인증 처리를 실시한다(스텝 910). 즉, 전처리 데이터 버퍼 (707)에 격납된 전처리 데이터를 생체 인증 기구부 (508)에 송신하는 것과 동시에 생체 인증 기구부 (508)에 생체 정보 취득을 지시한다. 이 생체 인증 처리에 대해서는 도 8을 이용해 설명했지만, 후술의 도 11에 있어서도 상세하게 설명한다.After obtaining the registration information from the IC card 105, the authentication control middle 702 executes the biometric authentication mechanism unit control program 703 to perform the biometric authentication process (step 910). That is, the preprocessing data stored in the preprocessing data buffer 707 is transmitted to the biometric authentication mechanism unit 508, and the biometric authentication mechanism unit 508 is instructed to acquire the biometric information. Although this biometric authentication process was demonstrated using FIG. 8, it demonstrates in detail also in FIG. 11 mentioned later.

다음에 생체 인증의 성공 여부를 체크해(스텝 911), 여기서 생체 인증이 실패였던 경우는, 생체 인증의 실시 회수를 카운트 한다(스텝 912). 이 때의 생체 인증의 실시 회수가 규정 회수 이내이면 RAM (621) 또는 프로그램에 기억, 격납 하고 있던 전처리 데이터를 생체 인증 기구부 (508)에 재송신하고 이용자에 대해 생체 인증의 재실시를 재촉한다. 생체 인증의 실시 회수가 규정 회수를 넘으면, 거래를 중지한다(스텝 913). 또한 이 때, RAM (621)에 기억된 전처리 데이터등은 보안을 높이기 위해 삭제한다. 그리고 S911에 있어서, 생체 인증이 성공한 경우는, 생체 인증 처리의 사후 처리로서 인증 거래 종료 처리를 실시한다(스텝 914). 이 인증 거래 종료 처리에 대해서는 후술의 도 12를 이용해 상세하게 설명한다.Next, it is checked whether or not the biometric authentication succeeds (step 911). If the biometric authentication fails here, the number of times of biometric authentication is performed is counted (step 912). If the number of times of biometric authentication at this time is within the specified number of times, preprocessing data stored and stored in the RAM 621 or the program is resent to the biometric authentication mechanism unit 508 to prompt the user to perform biometric authentication again. If the number of times of biometric authentication exceeds the prescribed number of times, the transaction is aborted (step 913). At this time, the preprocessed data and the like stored in the RAM 621 are deleted to increase security. In S911, when the biometric authentication succeeds, the authentication transaction end process is performed as a post-process of the biometric authentication process (step 914). This authentication transaction termination process will be described in detail with reference to FIG. 12 described later.

인증 거래 종료 처리가 종료하면 이용자가 원하는 거래, 즉 S901로 거래 선택된 거래를 실행한다(스텝 915). 구체적으로는 이용자가 원하는 거래가 지불 거래라면 조작부 (503)에 의해 지불금액의 입력을 접수한다. 이용자에 의해 지불금액 입력을 하면 입력된 금액 및 금액이 올바른지 아닌지의 확인 키 누름을 재촉하는 메세지를 조작부 (503)에 표시한다. 조작부 (503)의 확인 키가 눌러지면 서버 (502)와 거래 데이터의 교신을 실시한다. 교신 후, ATM (501)의 CPU (601)은 요구된 금액분의 지폐, 동전을 지폐 입출금 기구부 (506), 동전 입출금 기구부 (507)로부터 각각 배출하고 카드/명세표 기구부 (504)의 명세표 인자부 (604)에 거래 데이터의 인자를 실시하게 한다. 그리고, 카드/명세표 기구부 (504)로부터 IC카드 (105)를 반환함과 동시에 거래 데이터를 명세표에 인자·송출하고 거래가 종료한다(스텝 916).When the authentication transaction end processing ends, the user desires a transaction, that is, a transaction selected by S901 (step 915). Specifically, if the transaction desired by the user is a payment transaction, the operation unit 503 receives the input of the payment amount. When the user inputs the payment amount, a message is displayed on the operation unit 503 to prompt the user to press the confirmation key to confirm whether the input amount and the amount are correct. When the confirmation key of the operation unit 503 is pressed, the server 502 communicates with the transaction data. After the communication, the CPU 601 of the ATM 501 discharges the bills and coins for the required amount of money from the banknote deposit and withdrawal mechanism 506 and the coin withdrawal mechanism 507 respectively, and the specification sheet printing portion of the card / specification tag mechanism 504 604 is made to print transaction data. Then, the IC card 105 is returned from the card / specification tag mechanism 504, the transaction data is printed and sent to the specification table, and the transaction ends (step 916).

또, 이용자가 원하는 거래가 잔고 조회라면 서버 (502)와 거래 데이터의 교신을 실시하고 교신 후, 조작부 (503)에 예금 또는 차입 잔고를 표시한다. 표시 후이용자에 대해 거래를 종료하고 싶은지, 계속해 다른 거래를 실시하고 싶은지의 안내를 실시한다. 거래를 종료하고 싶은 경우에는 카드/명세표 기구부 (504)로부터 IC카드 (105)를 반환함과 동시에 이용자의 요망에 따라 거래 데이터를 명세표에 인자·송출하여 거래가 종료한다(스텝 916). 이용자가 다른 거래 실시를 원하는 경우에는 이하의 처리를 실시한다.If the transaction desired by the user is the balance inquiry, the server 502 communicates with the transaction data, and after communication, the deposit or borrowing balance is displayed on the operation unit 503. After indication We guide whether we want to end transaction or continue other transactions for user. When the transaction is to be terminated, the IC card 105 is returned from the card / description table mechanism unit 504, and the transaction data is printed and sent to the specification table according to the user's request, and the transaction ends (step 916). If the user wants to conduct another transaction, the following processing is performed.

잔고 조회 후에 이어 상술의 지불 거래 등의 생체 인증이 필요한 거래를 희망한 경우, 다시 생체 인증을 실시하고 생체 인증이 성공한 경우에만 거래를 실행한다. 생체 인증을 거래 마다 실시함으로써, 이용자가 잔고 조회에서 예금·차입 잔고를 확인했지만 IC카드 (105)를 받지 않고 ATM로부터 나온 경우, 제3자에 의해 거래를 행해져 버리는 방면도 생각할 수 있으므로, 그러한 위험을 배제하고 보안의 높은 ATM 시스템을 실현할 수가 있다.If a transaction requiring biometric authentication such as the payment transaction described above is desired after the balance inquiry, the biometric authentication is performed again, and the transaction is executed only when the biometric authentication is successful. By performing biometric authentication for each transaction, if the user confirms the deposit and borrowing balance in the balance inquiry but exits the ATM without receiving the IC card 105, it is conceivable that the transaction may be performed by a third party. It is possible to realize a high security ATM system without the need for this.

또한 이 플로우에서는 비밀번호 입력의 뒤에 생체 인증을 실시하고 있지만, 이 차례를 반대로 하고 생체 인증 실시의 뒤에 비밀번호를 입력시켜도 좋다. 암호인증 번호 입력을 먼저 실시하는 경우에는, 일반적인 거래와 동일하게 이용자는 카드 삽입 후 최초의 거래 선택 후 곧바로 암호인증 번호를 입력하므로 그 후에 생체 인증을 실시해도 조작 플로우가 현상태에 가까운 장치를 취급하기 쉽다고 하는 이점이 있다. 한편, 암호인증 번호에 의한 인증보다 생체 인증을 먼저 실시하는 경우에는 만약 본인 이외가 생체 인증을 실시해 생체 인증이 실패가 되어 거래를 거부 할 경우에, 암호인증 번호 입력을 경과하지 않고 거래를 종료하므로 쓸모없는 암호인증 번호 조합을 위한 서버의 통신을 하지 않아도 되어 서버로의 부담을 경감할 수 있다고 하는 이점이 있다.In this flow, the biometric authentication is performed after the password input. However, the order may be reversed and the password may be input after the biometric authentication. When the password authentication number is entered first, the user enters the password verification number immediately after the initial transaction selection after inserting the card as in a normal transaction. There is an advantage that it is easy. On the other hand, if the biometric authentication is performed before the authentication by the password authentication number, if the non-owner performs the biometric authentication and the biometric authentication fails and the transaction is rejected, the transaction is terminated without entering the password authentication number. There is an advantage in that the burden on the server can be reduced by not having to communicate with the server for useless password authentication number combinations.

도 10에 의해 도 9의 S908에 있어서의 인증 거래 개시 처리에 대해서 설명한다. 인증 제어 어플리케이션 (701)로부터 인증 거래 개시 지시를 받은 인증 제어 미들 (702)는, IC카드 제어 프로그램 (704)를 실행하고 IC카드 (105)의 접속을 실시한다(스텝 1001). 이것은 전술한 것처럼 IC카드 (105)로부터의 데이터의 독취를 가능한 상태로 하는 것이다. 단, IC카드 (105)에는 생체 정보에 관한 데이터가 없고, IC카드내 인증에 대응하고 있지 않는 IC카드의 경우는 예를 들면 상술의 암호인증 번호에 의한 인증 처리만으로도 ATM에서의 원하는 거래를 할 수 있도록 하는 것이 바람직하고, 도 9의 S902 등의 카드 삽입과 거의 같은 타이밍으로 IC카드 제어 프로그램 (704)를 인증 제어 미들 (702)이외의 ATM 소프트웨어에 의해 실행하고 적어도 S908의 처리전에 IC카드 (105)의 접속을 완료하게 하는 편이 좋다.10, the authentication transaction start process in S908 of FIG. 9 is demonstrated. The authentication control middle 702 which has received an authentication transaction start instruction from the authentication control application 701 executes the IC card control program 704 and connects the IC card 105 (step 1001). This makes reading of data from the IC card 105 possible. However, the IC card 105 does not have biometric information data, and in the case of an IC card that does not support authentication in the IC card, a desired transaction can be performed at the ATM only by the authentication process using the above-mentioned encryption authentication number, for example. Preferably, the IC card control program 704 is executed by ATM software other than the authentication control middle 702 at about the same timing as the card insertion of S902 or the like in FIG. 9, and at least before the processing of S908. It is better to complete the connection of 105).

또, 카드/명세표 기구부 (504)에 삽입되고 있는 IC카드 (105)에는 도 1의 생체 정보 등록 장치 (101)에 의해 미리 이용자 고유의 등록 데이터 및 전처리 데이터가 등록되어 있고 IC카드 (105)내에서 인증을 행하기 위한 인증 프로그램 (711)이 탑재, 기억되고 있다. 이 인증 프로그램 (711)은 IC카드 (105)에 사전에, 또 개서 불가능한 형식으로 기입된 어플리케이션이고, IC카드로 사전 등록된 등록 데이터와 ATM의 제어부에 의해 구해진 인증 데이터를 특정의 알고리즘에 따라서 매칭, 조합을 실시하는 프로그램이다.In addition, in the IC card 105 inserted into the card / specification tag mechanism 504, user-specific registration data and preprocessing data are registered in advance by the biometric information registration device 101 shown in FIG. The authentication program 711 for performing authentication is loaded and stored. This authentication program 711 is an application written in advance in a non-rewritable form on the IC card 105, and matches registration data pre-registered with the IC card with authentication data obtained by the ATM control unit according to a specific algorithm. , A program that performs a combination.

S1001에서 카드/명세표 기구부 (504)와 IC카드 (105)의 접속이 성공하면 인증제어 미들 (702)는 IC카드 (105)에 등록되어 있는 서포트 인증 방식(또는 서포트 인증 정보)을 취득한다(스텝 1002). 서포트 인증 방식이라는 것은 미리 IC카드 (105)에 등록되어 있는 것으로 인증 데이터나 생체 특징량 등의 정보를 어느 제어 순서로 인증 처리를 실시할 수 있을지를 한번에 결정할 수 있는 정보이다. 예를 들면, 지정맥 인증에서는 생체 인증 기구부 (508)내에 있어서 인증(조합)하는 장치내 인증 처리와 IC카드 (105)내에 있어서 인증하는 IC카드내 인증 처리를 서포트하고 있고 IC카드 (105)로부터 서포트 인증 방식을 취득하는 것으로 인증 제어 순서를 변환 1개의 인증 제어 프로그램으로 2개의 인증 방식을 가능하게 하고 있다.If the card / specification tag mechanism 504 and the IC card 105 are successfully connected in S1001, the authentication control middle 702 acquires the support authentication method (or support authentication information) registered in the IC card 105 (step). 1002). The support authentication method is registered in advance in the IC card 105, and it is information that can be determined at one time in which control order to perform authentication processing, such as authentication data and biometric feature amounts, in which control sequence. For example, in the finger vein authentication, the in-device authentication processing to authenticate (combine) in the biometric authentication mechanism unit 508 and the IC card authentication processing to authenticate in the IC card 105 are supported. Acquiring the support authentication method The authentication control procedure is changed. Two authentication methods are enabled with one authentication control program.

이 서포트 인증 방식 취득과 같은 IC카드 등에 등록된 인증 방식, 인증 제어Authentication method and authentication control registered in IC card or the like as the support authentication method acquisition

순서를 한번에 결정하는 정보를 이용해 인증 제어의 순서나 방식을 바꾸는 방법은, ATM등의 생체 인증 장치 탑재 단말에 복수의 인증 장치(예를 들면 손가락, 손바닥이라고 하는 정맥 인증 장치나 눈의 홍채 인증 장치등)가 탑재되어 있는 경우에도, 인증 제어 프로그램의 제어 방식을 바꾸는 것으로 복수의 생체 인증 장치의 제어에 대응할 수 있게 된다.The method of changing the order and method of authentication control by using the information which determines the order at once is a plurality of authentication devices (for example, a vein authentication device such as a finger and a palm and an iris authentication device of the eye) to a terminal equipped with biometric authentication devices such as ATM. Etc.), it is possible to cope with control of a plurality of biometric authentication devices by changing the control method of the authentication control program.

다음에, 스텝 1002로 구한 인증 방식이, IC카드내 인증인지 아닌지를 판단해(스텝 1003), IC카드내 인증이 아닌 경우는 거래 처리를 실시하지 않고 IC카드 (105)를 반환한다(스텝 916). 한편, IC카드내 인증 방식인 경우는 ATM (501)과 IC카드 (105)의 사이의 상호 인증을 실시하고 인증 거래 개시 처리는 종료한다(스텝 1004). 상호 인증이라는 것은 생체 인증 기구부 (508)에 있는 인증 데이터 작성 프로그램 (709)나, IC카드 (105)에 탑재된 인증 프로그램 (711)등이 부정한 프로그램에 고쳐져 있지 않은지, ATM (501)과 IC카드 (105)로 상호의 프로그램의 정당성을 확인하기 위한 처리이다.Next, it is judged whether or not the authentication method obtained in step 1002 is authentication in the IC card (step 1003), and if it is not authentication in the IC card, the IC card 105 is returned without performing transaction processing (step 916). ). On the other hand, in the case of the IC card authentication method, mutual authentication is performed between the ATM 501 and the IC card 105, and the authentication transaction start process ends (step 1004). The mutual authentication means that the authentication data creation program 709 in the biometric authentication mechanism unit 508 or the authentication program 711 mounted on the IC card 105 is not corrected by an illegal program, or the ATM 501 and the IC card. (105) is a process for confirming the validity of the mutual program.

도 11에 의해 도 9의 S908의 생체 인증 처리에 대해서 설명한다. 도 8로 설명한 것처럼, 이 생체 인증 처리는 최종적으로는 미리 IC카드 (105)내에 기록해 둔 등록 데이터와 생체 인증 처리시에 새롭게 작성한 인증 데이터의 인증(조합)을 실시하고 그 조합 결과를 구하는 처리이고, 인증 자신의 개체와 관련되는 처리는 IC 카드 (105)내에서 실시하는 것을 특징으로 한다.The biometric authentication process of S908 of FIG. 9 will be described with reference to FIG. 11. As described with reference to Fig. 8, this biometric authentication process is a process of finally authenticating (combining) the registration data recorded in the IC card 105 in advance and the authentication data newly created during the biometric authentication process and obtaining the combination result. In this case, the processing associated with the individual of the authentication itself is performed in the IC card 105.

도 9의 S909에 있어서 IC카드 (105)보다 데이터를 수신하지만 그것과 동시에 이 생체 인증시에는 IC카드 (105)로부터 미리 기억하고 있던 전처리 데이터를 인증 제어 미들 (702)에 송신한다. 인증 제어 미들 (702)는 IC카드 (105)에 기억하고 있던 전처리 데이터를 수신하고 전처리 데이터 버퍼 (707)에 격납한다. 또한 전처리 데이터 버퍼 (707)에 격납되 경우의 전처리 데이터를 생체 인증 기구부 (508)에 송신한다(스텝 1101). 생체 인증 기구부 (508)은 전처리 데이터를 수신하면 다음에 또 병행처리로서 이용자의 생체 정보를 독출한다.In S909 of FIG. 9, data is received from the IC card 105, but at the same time, pre-processed data stored in advance from the IC card 105 is transmitted to the authentication control middle 702 at the time of this biometric authentication. The authentication control middle 702 receives the preprocessing data stored in the IC card 105 and stores it in the preprocessing data buffer 707. Further, the preprocessing data when stored in the preprocessing data buffer 707 is transmitted to the biometric authentication mechanism unit 508 (step 1101). Upon receipt of the preprocessing data, the biometric authentication mechanism unit 508 reads out the biometric information of the user as a parallel process again.

도 11의 스텝 1102~스텝 1105의 처리는 도 4의 스텝 404~스텝 407과 대략 동일한 처리를 실행해 생체 특징량을 구한다. 화상 센서 (607)의 화상 취득 가능 영역에 손가락이 놓여지면 생체 유무 검지용 조명 LED (608)에 의해 물체(손가락)이 놓여진 것을 검지해(스텝 1102), 물체(손가락)이 생체인지 아닌지를 조사한다(스텝 1103). 삽입된 물체(손가락)이 생체가 아닌 경우는, 생체 인증이 실패가 된다(스텝 1104). 삽입된 물체(손가락)이 생체인 경우는, 생체 취득용 조명 LED (609)에 의해 생체에 근적외선을 조사하고 화상 센서 (607)로 생체 화상(지정맥 패턴)을 취득하고 기억부 (606)에 기억 한다(스텝 1105).The processing in steps 1102 to 1105 in FIG. 11 executes substantially the same processing as in steps 404 to 407 in FIG. 4 to obtain a biometric feature amount. When the finger is placed in the image acquisition area of the image sensor 607, the illumination LED 608 for detecting the presence or absence of the object detects that the object (finger) is placed (step 1102), and examines whether the object (finger) is a living body. (Step 1103). If the inserted object (finger) is not a living body, biometric authentication fails (step 1104). When the inserted object (finger) is a living body, the near-infrared ray is irradiated to the living body by the living body LED 609, and the living body image (a finger vein pattern) is acquired by the image sensor 607, and stored in the storage unit 606. Remember (step 1105).

다음에, 생체 화상(지정맥 패턴)로부터 특징적인 데이터를 나타내는 생체 특징량을 추출한다(스텝 1106). 그리고, 인증 제어 미들 (702)의 지시로 인증 데이터 작성 프로그램 (709)를 실행하는 것으로, 도 8에서 설명한 인증 데이터를 작성한다(스텝 1107). 그리고 작성된 인증 데이터를 인증 제어 미들 (702)에 송신하고 인 증 데이터 버퍼 (706)에 격납 한다.Next, a biometric feature amount representing characteristic data is extracted from the biometric image (a finger vein pattern) (step 1106). Then, by executing the authentication data creation program 709 under the instruction of the authentication control middle 702, the authentication data described with reference to FIG. 8 is created (step 1107). The created authentication data is transmitted to the authentication control middle 702 and stored in the authentication data buffer 706.

인증 제어 미들 (702)는 IC카드 제어 프로그램 (704)를 실행하고 인증 데이터 버퍼 (706)에 격납한 인증 데이터를 IC카드 (105)에 송신하는 것과 동시에 IC카드 (105)내의 인증 프로그램 (711)에 생체 인증 지시를 내린다(스텝 1108). 한편, IC카드 (105)는 카드내에 기억된 인증 프로그램 (711)을 실행하고 IC카드 (105)에 미리 등록된 등록 데이터와 상술의 인증 제어 미들 (702)의 인증 데이터 버퍼 (706)에 격납된 인증 데이터를 조합해 생체 인증 처리를 실시하고 인증 결과 데이터를 작성한다.The authentication control middle 702 executes the IC card control program 704 and transmits the authentication data stored in the authentication data buffer 706 to the IC card 105 and at the same time the authentication program 711 in the IC card 105. The biometric authentication instruction is given (step 1108). On the other hand, the IC card 105 executes the authentication program 711 stored in the card and is stored in the registration data registered in advance in the IC card 105 and in the authentication data buffer 706 of the authentication control middle 702 described above. The authentication data is combined to perform biometric authentication, and the authentication result data is created.

그리고, IC카드 (105)는 인증 결과 데이터를 인증 제어 미들 (702)에 송신하고 인증 제어 미들 (702)는 인증 제어 미들 (702)내(하드로서는 RAM내)의 인증 결과 데이터 버퍼 (705)에 격납 한다. 이와 같이 인증 제어 미들 (702)가 실시하는 생체 인증 기구부 (508)과 IC카드 (105) 사이의 데이터의 송수신 제어에서는 생체 화상(지정맥 패턴)으로부터 취득한 생체 특징량은 생체 인증 기구부 (508)의 외부에 나오는 경우가 없고, 또 IC카드 (105)에 등록되어 있는 인증 데이터도 외부에 나오는 경우가 없다. 따라서 개인정보가 장치의 외부에 누설하는 것을 방지하는 것이 가능하므로 개인정보의 은닉성이 지켜 보안이 향상한다.Then, the IC card 105 transmits the authentication result data to the authentication control middle 702, and the authentication control middle 702 is sent to the authentication result data buffer 705 in the authentication control middle 702 (hard in RAM). To be stored. In this way, in the transmission and reception control of the data between the biometric authentication mechanism unit 508 and the IC card 105 performed by the authentication control middle 702, the biometric feature amount obtained from the biometric image (the finger vein pattern) is determined by the biometric authentication mechanism unit 508. It does not appear outside, and the authentication data registered in the IC card 105 also does not appear outside. Therefore, since personal information can be prevented from leaking to the outside of the device, the confidentiality of personal information can be kept, thereby improving security.

인증 제어 미들 (702)는 생체 인증 기구부 제어 프로그램 (703)을 실행해 인증 결과 데이터 버퍼 (705)에 격납된 인증 결과 데이터를 생체 인증 기구부 (508)헤 송신함과 동시에 인증 결과 판정 프로그램 (710)에 인증 결과 판정 지시를 내린다. 다음에 인증 결과 판정 프로그램 (710)을 실행해 IC카드 (105)내에서 실시한 인증의 결과인 인증 결과 데이터 버퍼 (705)에 격납된 인증 결과 데이터로부터 생체 인증이 성공인가 실패인지를 판단한다. 여기서 출력으로서 생체 인증 기구부 (508)은 인증이 성공한 경우는 생체의 어느 부위에서 인증이 성공했는지를 인증 제어 미들 (702)에 통지한다(스텝 1109). 예를 들면 생체 인증의 부위가 지정맥이나, 지문등이라면 어느 손가락(예, 오른손, 중지 등)으로 인증이 성공했는지, 손바닥의 정맥이면 오른손, 왼손인지 눈의 홍채이면, 오른쪽눈, 왼쪽눈의 어느쪽에서 인증이 성공했는지가 인증 제어 미들 (702)에 통지되게 된다.The authentication control middle 702 executes the biometric authentication mechanism unit control program 703 to transmit the authentication result data stored in the authentication result data buffer 705 to the biometric authentication mechanism unit 508 and at the same time the authentication result determination program 710. Instruct the authentication result judgment to be sent. Next, the authentication result determination program 710 is executed to determine whether the biometric authentication succeeds or fails from the authentication result data stored in the authentication result data buffer 705 that is the result of the authentication performed in the IC card 105. In this case, as an output, the biometric authentication mechanism unit 508 notifies the authentication control middle 702 at which part of the living body the authentication succeeds when the authentication succeeds (step 1109). For example, if the site of biometric authentication is finger vein or fingerprint, which finger (e.g. right hand, middle finger, etc.) is successful, if the palm vein is the right hand, the left hand or the iris of the eye, the right eye, the left eye The authentication control middle 702 is notified which side the authentication was successful.

인증 결과가 실패한 경우는 인증 결과 판정 프로그램 (710)으로 IC카드내 인증에 실패한 원인을 판단해 인증 제어 미들 (702)에 통지한다. 원인으로서 예를 들면 손가락의 놓는 방법이 나빴던지, 등록되어 있던 다른 손가락을 놓아 버렸는지, 등의 정보를 부수시켜 인증 제어 미들 (702)에 통지하고 그것에 기초를 두어 인증 제어 어플리케이션 (701)에 의해 조작부 (503)에 그 원인을 표시하는 것이 바람직하고, 이것에 의해 조작성이 좋은 장치를 제공할 수 있다. 이와 같이, 생체 인증 기구부 (508)이 인증 결과를 판별하는 예에서 설명했지만, IC카드내의 인증 프로그램 (711), 또는 인증 결과 데이터를 취득한 인증 제어 미들 (702)에서도 인증 처리의 성공 여부나 인증 성공 부위, 인증 실패 원인 등의 인증 결과의 판별을 할 수 있는 형태에서도 좋다.If the authentication result fails, the authentication result determination program 710 determines the cause of the failure in the IC card, and notifies the authentication control middle 702. For example, the authentication control middle 702 informs the authentication control middle 702 by attaching information such as whether a finger is released in a bad manner or that another registered finger is released. It is preferable to display the cause on the operation unit 503, whereby a device having good operability can be provided. As described above in the example in which the biometric authentication mechanism unit 508 determines the authentication result, the authentication program 711 in the IC card or the authentication control middle 702 in which the authentication result data has been acquired has succeeded or failed the authentication process. Also in the form which can discriminate authentication result, such as a site | part and the cause of authentication failure, it is good.

인증 제어 미들 (702)는 등록 데이터와 인증 데이터의 매칭, 조합 결과인 판정 결과 데이터를 인증 제어 어플리케이션 (701)에 송신한다. 인증 제어 어플리케이션 (701)은 판정 결과 데이터가 인증 실패이면, ATM (501)의 조작부 (503)에 인 증 재개시화면을 내는 등 하고 이용자에게 재차, 인증을 실시시키도록 한다. 이 때, 인증 제어 미들 (702)는 IC카드 (105)의 등록 정보 취득 처리로 취득한 전처리 데이터를 전처리 데이터 버퍼 (707)로 유지하는 것이 바람직하고, IC카드 (105)의 등록 정보 취득 처리를 생략할 수가 있으므로, 인증 처리 시간이 향상한다. 이것은 잔고 조회로부터 지불거래라고 하는 바와 같은 1회의 내점으로 연속한 본인 확인이 필요한 거래를 실시하기 위해 여러 차례의 인증 처리를 실행하는 경우에도 동일하게 IC카드 (105)로부터 취득한 전처리 데이터를 전처리 데이터 버퍼 (707)로부터 삭제하지 않는 것으로, IC카드 (105)의 등록 정보 취득 처리를 생략하고 연속 거래에서의 인증 처리를 실행하는 것이 가능하다.The authentication control middle 702 transmits the determination result data, which is a result of matching and combination of registration data and authentication data, to the authentication control application 701. If the determination result data is authentication failure, the authentication control application 701 displays the authentication restart screen on the operation unit 503 of the ATM 501 and causes the user to authenticate again. At this time, the authentication control middle 702 preferably holds the preprocessing data acquired by the registration information acquisition process of the IC card 105 in the preprocessing data buffer 707, and omits the registration information acquisition process of the IC card 105. This can improve the authentication processing time. This is similar to the preprocessing data buffer obtained from the IC card 105 even when a plurality of authentication processes are executed to execute a transaction requiring continuous identity verification from a balance inquiry to a visit, such as a payment transaction. By not deleting from 707, it is possible to omit the registration information acquisition process of the IC card 105 and to execute the authentication process in the continuous transaction.

도 12에 의해 도 9의 S914에 나타내는 인증 거래 종료 처리에 대해서 설명한다. The authentication transaction end process shown in S914 of FIG. 9 is demonstrated by FIG.

인증 제어 어플리케이션 (701)은 판정 결과 데이터가 인증 성공이면, 인증 제어 미들 (702)에 대해서 인증 거래 종료 지시를 내린다. 인증 제어 미들 (702)는 IC카드 제어 프로그램 (704)를 실행하고 IC카드 (105)의 절단 처리를 실행한다. IC카드 (105)의 절단으로는 IC카드 (105)에 액세스 할 수가 없게 되는 상태이다. IC카드 (105)의 절단 후 인증 제어 미들 (702)로부터의 지시로 생체 인증 장치 제어 프로그램 (703)은, 생체 인증 기구부 (508)에 있는 생체 특징량 등, 생체 인증에 사용한 개인정보나 그것을 바탕으로 작성된 인증과 관계되는 정보를 모두 기억부로부터 삭제한다.The authentication control application 701 issues an authentication transaction termination instruction to the authentication control middle 702 if the determination result data is authentication success. The authentication control middle 702 executes the IC card control program 704 and executes the cutting process of the IC card 105. By cutting off the IC card 105, the IC card 105 cannot be accessed. The biometric authentication device control program 703, based on the instruction from the authentication control middle 702 after the cutting of the IC card 105, uses the personal information used for biometric authentication, such as the biometric feature in the biometric authentication mechanism unit 508, and the same. Delete all information related to the authentication created from the storage unit.

이것은 개인정보등이 외부에 누설하는 것을 방지하고 보안을 향상시키기 위 해서 유효한 특징이기도 하다. 생체 인증 기구 (508)내의 데이터를 클리어 한 후, 인증 제어 미들 (702)는 자신이 가지는 인증 결과 데이터 버퍼 (705), 인증 데이터 버퍼 (706), 전처리 데이터 버퍼 (707)에 격납된 정보를 삭제하고(연속 거래는 제외한다), 정보 누설을 방지하고 있다. 인증 거래 종료 처리가 종료하면 지불금액의 입력, 서버 (502)의 교신 등을 실시하고 지불 거래를 종료한다.This is also a valid feature to prevent leakage of personal information, etc. and to improve security. After clearing the data in the biometric authentication mechanism 508, the authentication control middle 702 deletes the information stored in the authentication result data buffer 705, the authentication data buffer 706, and the preprocessing data buffer 707 which it has. (Except continuous transaction) and prevent information leakage. When the authentication transaction end processing ends, the payment amount is input, the server 502 is communicated, and the payment transaction is terminated.

이상, 도 1~4를 이용해 생체 정보의 등록 처리, 도 5~12를 이용해 생체 정보의 인증 처리를 설명한 바와 같이, 예를 들면, 하드적으로는 CPU (601), 주기억부 (602)의 제어, 처리에 의해 행해지고 소프트적으로는 인증 제어 소프트 (622), 인증 제어 어플리케이션 (701), 인증 제어 미들 (702)의 제어, 처리에 의해 생체 정보의 인증이 실행된다. 따라서, 상술한 바와 같이, 이들을 모아 제어부, 제어 수단에 의한 제어, 처리 할 수가 있고, 또 각 프로그램의 기능을 LSI등의 하드적으로도 달성할 수 있다. 또 도 7의 각종 프로그램은 그 처리에 필요한 때에 처음으로 기동, 실행될 뿐만 아니라, ATM 기동시에 각 프로그램을 기동하게 하고 각 처리로 필요한 프로그램을 실행시키는편이 처리 시간은 단축할 수 있다.As described above, the registration processing of the biometric information using FIGS. 1 to 4 and the authentication processing of the biometric information using FIGS. 5 to 12 have been described. For example, the control of the CPU 601 and the main storage unit 602 is hard. The authentication of the biometric information is performed by the control and processing of the authentication control software 622, the authentication control application 701, and the authentication control middle 702. Therefore, as described above, these can be collected and controlled and processed by the control unit and the control means, and the function of each program can also be achieved in terms of LSI and the like. In addition, the various programs shown in Fig. 7 are not only started and executed for the first time when they are necessary for the processing, but also the processing time can be shortened by allowing each program to be started at the time of ATM startup and executing the necessary program in each process.

또, 도 3에 있어서 전처리 데이터를 생체 특징량으로부터 작성하고 그 작성한 전처리 데이터와 생체 특징량으로부터 인증시에 사용되는 등록 데이터를 작성하는 형태에서 설명했지만, 전처리 데이터의 작성에 관해서 생체 특징량과는 전혀 관련 없고, 또 독립하여 작성해도 괜찮다. 상술한 바와 같이, 생체 정보의 등록시에 있어서 전처리 데이터는 등록 데이터를 작성하기 위한 암호키(또는 알고리즘)의 기능을 갖고, 생체 인증시에는 인증 데이터를 작성하기 위한 암호키의 기능, 역할을 가지고 있다. 따라서, 생체 특징량으로부터 전처리 데이터를 작성하면, 즉 이용자 각각 대응한 데이터가 되어 보안이 높은 데이터 작성 알고리즘을 구성할 수 있지만, 한편, 전처리 데이터를 생체 특징량과는 독립으로 작성하면, 사전에 암호키로서의 역할인 전처리 데이터 자신을 작성해 둘 수도 있어 전체적으로 간단하고 쉬운 프로그램 구성이 되므로 수고를 줄일 수 있어 등록 인증의 처리 시간이 짧아진다.In FIG. 3, the preprocessing data is created from the biometric characteristic amount and the registration data used for authentication is created from the created preprocessing data and the biometric characteristic amount. However, the creation of the preprocessing data differs from the biometric characteristic amount. It is not relevant at all and can be written independently. As described above, the preprocessing data at the time of registration of the biometric information has the function of an encryption key (or algorithm) for creating the registration data, and at the time of biometric authentication has the function and role of the encryption key for creating the authentication data. . Therefore, if the preprocessing data is created from the biometric characteristic amount, that is, the data corresponding to each user can be constructed, a highly secure data creation algorithm can be constructed. On the other hand, if the preprocessed data is created independently of the biometric characteristic amount, the encryption is performed in advance. The preprocessing data itself, which serves as a key, can also be created, resulting in a simple and easy program configuration as a whole, thus reducing the effort and processing time of registration authentication.

또, 전처리 데이터를 생체 특징량으로부터 일단층에서 작성했지만, 몇 단계인가 밟은 다음 작성하도록 해도 괜찮다. 이것에 의하고 제3자가 전처리 데이터 작성 과정을 해석하려고 해도, 작성 과정이 복잡해서 해석하기 어렵다, 또, 해석에 시간이 걸린다고 하는 효과가 있다.In addition, although the preprocessing data was created in one layer from the biological feature amount, it may be made after several steps. By this means, even if a third party attempts to analyze the preprocessing data creation process, the creation process is complicated and difficult to interpret, and the analysis takes time.

또, 전처리 데이터, 등록 데이터, 인증 데이터(인증 실패시나 연속 거래시에 작성하는 인증 데이터를 포함한다)는 원래 이용자의 손가락 등의 생체 특징량(화상 패턴 포함한다)으로부터 작성, 생성된 정보인 것으로부터, 제1, 2,…(생체) 정보라고 할 수 있다. 즉, 이들 제 1, 2···(생체 정보)는 생체 특징량을 포함한 개념인 생체 정보로부터 구해지는 정보라고도 말할 수 있다.In addition, the preprocessing data, registration data, and authentication data (including authentication data created at the time of authentication failure or continuous transaction) are information created and generated from biometric features (including image patterns) such as the user's finger. From, first, second,... It can be called (bio) information. That is, these 1st, 2nd ... (biological information) can also be said to be information calculated | required from biological information which is a concept containing a biometric characteristic amount.

이상, 본 발명의 IC카드내 인증 방식으로는 IC카드내에 등록된 개인을 특정할 수 있는 정보와 인증 장치로 취득한 생체 정보(생체 특징량) 그 자체는 인증 장치 탑재 단말에 넣어지는 것이 없기 때문에 개인정보의 은닉성이 지켜질 수 있어 보안이 높은 생체 인증이 가능해진다.As described above, according to the authentication method in the IC card of the present invention, since the information capable of identifying the individual registered in the IC card and the biometric information (bio-feature amount) acquired by the authentication device itself are not stored in the terminal equipped with the authentication device, The confidentiality of the information can be kept, enabling secure biometric authentication.

Claims (27)

생체 인증을 제어하는 방법으로서,As a method of controlling biometric authentication, 생체 정보로부터 구해지는 제1 정보를 휴대 전자 장치로부터 수신하고, 상기 제1 정보를 생체 인증 기구부에 송신하고, 상기 생체 인증 기구부에 의해 취득된 생체 정보와 상기 제1 정보를 조합해 작성하는 제2 정보를 상기 생체 인증 기구부로부터 수신하고 수신한 상기 제2 정보를 상기 휴대 전자 장치에 송신하고, 상기 휴대 전자 장치내에 미리 격납되고 있는 등록 데이터와 상기 제2 정보를, 상기 휴대 전자 장치내에서 조합시키도록 동작시키는 것을 특징으로 하는 생체 인증 제어 방법.A second for receiving first information obtained from the biometric information from the portable electronic device, transmitting the first information to the biometric authentication mechanism, and combining the biometric information acquired by the biometric authentication mechanism and the first information to create the second information; Information is received from the biometric authentication mechanism unit and the received second information is transmitted to the portable electronic device, and registration data previously stored in the portable electronic device and the second information are combined in the portable electronic device. And biometric authentication control method. 청구항 1 기재의 생체 인증 제어 방법에 있어서,In the biometric authentication control method according to claim 1, 상기 제1 정보는 개인을 특정 불가능한 정보를, 상기 제2 정보는 개인을 특정 가능한 정보를 포함하는 것을 특징으로 하는 생체 인증 제어 방법.And wherein the first information includes information that can not specify a person and the second information includes information that can specify a person. 청구항 1 기재의 생체 인증 제어 방법에 있어서,In the biometric authentication control method according to claim 1, 상기 제2 정보는, 상기 제1 정보를 암호키로서 생체 정보를 암호화한 정보를 포함하는 것을 특징으로 하는 생체 인증 제어 방법.And wherein the second information includes information obtained by encrypting biometric information using the first information as an encryption key. 청구항 1 기재의 생체 인증 제어 방법에 있어서,In the biometric authentication control method according to claim 1, 상기 휴대 전자 장치에 기억된 서포트 인증 방식이 휴대 전자 장치내 인증 방식인지 아닌지를 판단하고 휴대 전자 장치내 인증 방식이면, 상기 등록 데이터와 상기 제2 정보를 조합시키도록 동작시키는 것을 특징으로 하는 생체 인증 제어 방법.It is determined whether or not the support authentication method stored in the portable electronic device is an authentication method in the portable electronic device, and if the authentication method is in the portable electronic device, the biometric authentication is performed to combine the registration data and the second information. Control method. 청구항 1 기재의 생체 인증 제어 방법에 있어서,In the biometric authentication control method according to claim 1, 상기 생체 인증 기구부에 놓여진 손가락이 생체인지 아닌지를 판단하고 생체이면, 상기 등록 데이터와 상기 제2 정보를 조합시키도록 동작시키는 것을 특징으로 하는 생체 인증 제어 방법.And determining whether or not the finger placed on the biometric authentication mechanism is a living body, and if so, operating the combination data and the second information to combine the registration data. 청구항 1 기재의 생체 인증 제어 방법에 있어서,In the biometric authentication control method according to claim 1, 상기 제1 정보 및 상기 제2 정보는 어떤 알고리즘을 이용해 상기 생체 정보를 기본으로 하여 작성된 정보를 포함하는 것을 특징으로 하는 생체 인증 제어 방법.And the first information and the second information include information created based on the biometric information using a certain algorithm. 청구항 1 기재의 생체 인증 제어 방법에 있어서,In the biometric authentication control method according to claim 1, 상기 제1 정보 및 상기 제2 정보는, 상기 제1 정보 및 상기 제2 정보 자체로부터 상기 생체 정보를 복원 불가능한 정보를 포함하는 것을 특징으로 하는 생체 인증 제어 방법.And wherein the first information and the second information include information that is impossible to recover the biometric information from the first information and the second information itself. 생체 인증을 제어하는 방법으로서,As a method of controlling biometric authentication, 생체 특징량으로부터 생성되는 제1 정보를 휴대 전자 장치로부터 수신함과 동시에 메모리에 기억하고, 상기 메모리에 기억한 상기 제1 정보를 생체 인증 기구부에 송신하고, 상기 생체 인증 기구부에 의해 추출된 생체 특징량과 상기 제1 정보로부터 작성하는 제2 정보를 상기 생체 인증 기구부로부터 수신하고 수신한 상기 제2 정보를 상기 휴대 전자 장치에 송신하고, 상기 휴대 전자 장치내에 미리 격납되어 있는 등록 데이터와 상기 제2 정보를 상기 휴대 전자 장치내에서 조합시키도록 동작시키고,Receiving the first information generated from the biometric characteristic amount from the portable electronic device and storing it in a memory, transmitting the first information stored in the memory to a biometric authentication mechanism, and extracting the biometric feature amount extracted by the biometric authentication mechanism. And second information created from the first information from the biometric authentication mechanism unit, and transmits the received second information to the portable electronic device, and pre-stored registration data and the second information in the portable electronic device. Is operated to combine in the portable electronic device, 또한 그 조합의 실패, 또는 이용자가 연속해 거래를 실시하는 것을 원함에 따라 다시 조합이 필요하게 되었을 때, 상기 메모리에 기억한 상기 제1 정보를 상기 생체 인증 기구부에 송신하고, 상기 생체 인증 기구부에 의해 취득된 새로운 생체 특징량과 상기 제1 정보로부터 작성하는 제3 정보를 상기 생체 인증 기구부로부터 수신함과 동시에 상기 휴대 전자 장치에 송신하고, 상기 휴대 전자 장치내에서 상기 등록 데이터와 상기 제3 정보를 재조합시키도록 동작시키는 것을 특징으로 하는 생체 인증 제어 방법.When the combination fails, or the combination is needed again as the user wants to conduct a transaction continuously, the first information stored in the memory is transmitted to the biometric authentication mechanism, and the biometric authentication mechanism is sent to the biometric authentication mechanism. The new biometric characteristic value acquired by the first information and the third information created from the first information are received from the biometric authentication mechanism unit and transmitted to the portable electronic device, and the registration data and the third information are stored in the portable electronic device. Biometric authentication control method characterized in that it is operated to recombine. 청구항 8 기재의 생체 인증 제어 방법에 있어서,In the biometric authentication control method according to claim 8, 상기 제1 정보는 개인을 특정 불가능한 정보를, 사람을 특정 가능한 정보를 포함하는 것을 특징으로 한다.The first information may include information that cannot be specified by an individual and information that can be specified by a person. 청구항 8 기재의 생체 인증 제어 방법에 있어서,In the biometric authentication control method according to claim 8, 상기 제2 정보 및 상기 제3 정보는 상기 제1 정보를 암호키로서 생체 정보를 암호화한 정보를 포함하는 것을 특징으로 하는 생체 인증 제어 방법.And the second information and the third information include information obtained by encrypting biometric information using the first information as an encryption key. 청구항 8 기재의 생체 인증 제어 방법에 있어서,In the biometric authentication control method according to claim 8, 상기 휴대 전자 장치는 IC카드를 포함하고 상기 IC카드내에서 생체 인증시키는 것을 특징으로 하는 생체 인증 제어 방법.And said portable electronic device comprises an IC card and performs biometric authentication in said IC card. 청구항 8 기재의 생체 인증 제어 방법에 있어서,In the biometric authentication control method according to claim 8, 상기 휴대 전자 장치의 접속을 한 경우에 따라서 상기 휴대 전자 장치에 미리 기억된 서포트 인증 방식이 휴대 전자 장치내 인증 방식인지 아닌지를 판단하고 휴대 전자 장치내 인증 방식이면 상기 등록 데이터와 상기 제2 정보 또는 상기 제3 정보를 조합시키도록 동작시키는 것을 특징으로 하는 생체 인증 제어 방법.In accordance with the connection of the portable electronic device, it is determined whether the support authentication method stored in the portable electronic device in advance is an authentication method in the portable electronic device, and if the authentication method is in the portable electronic device, the registration data and the second information or And operate to combine the third information. 청구항 8 기재의 생체 인증 제어 방법에 있어서,In the biometric authentication control method according to claim 8, 상기 생체 인증 기구부가 가지는 생체 유무 검지용 조명에 의해 상기 생체 인증 기구부에 놓여진 손가락이 생체인지 아닌지르 판단하고 생체이면 생체 화상을 취득하고 상기 생체 특징량을 추출하는 것을 특징으로 하는 생체 인증 제어 방법.And determining whether a finger placed on the biometric authentication mechanism is a living body by illumination of the biometric detection mechanism of the biometric authentication unit, and obtaining a biometric image and extracting the biometric feature amount if the finger is a living body. 청구항 8 기재의 생체 인증 제어 방법에 있어서,In the biometric authentication control method according to claim 8, 상기 조합의 결과가 성공으로,또한 이용자가 원하는 모든 거래가 종료하면 상기메모리에 기억한 상기 제1 정보를 소거하는 것을 특징으로 하는 생체 인증 제어 방법.And the first information stored in the memory is erased when the result of the combination is successful and all transactions desired by the user are completed. 청구항 8 기재의 생체 인증 제어 방법에 있어서,In the biometric authentication control method according to claim 8, 상기 생체 인증 기구부에 송신된 상기 제1 정보를 상기 생체 인증 기구부에 기억하고 그 후 상기 제2 정보의 작성이 끝나면 기억한 상기 제1 정보를 소거하는 것을 특징으로 하는 생체 인증 제어 방법.And storing said first information sent to said biometric authentication mechanism in said biometric authentication mechanism and deleting said stored first information after creation of said second information. 등록 데이터를 기억하는 IC카드의 각종 데이터를 독취하는 카드 기구부와 생체 정보를 취득하는 생체 인증 기구부와 메모리를 가지는 컴퓨터를,A computer having a card mechanism unit for reading various data of the IC card storing registration data, a biometric authentication mechanism unit for obtaining biometric information, and a memory, 상기 카드 기구부에 의해 독출한 상기 IC카드내의 제1 정보를 수신함과 동시에 상기 메모리에 기억하고, 상기 메모리에 기억한 상기 제1 정보를 상기 생체 인증 기구부에 송신하고, 상기 생체 인증 기구부에 의해 취득된 생체 정보와 상기 제1 정보로부터 생성하는 제2 정보를 상기 생체 인증 기구부로부터 수신하고 수신한 상기 제2 정보를 상기 IC카드로 송신하고, 상기 IC카드내에 미리 격납되고 있는 등록 데이터와 상기 제2 정보를 상기 IC카드내에서 조합시키도록 동작시키는 것을 특징으로 하는 컴퓨터가 읽을 수 있는 생체인증프로그램을 수록한 기록매체Receiving the first information in the IC card read out by the card mechanism unit and storing it in the memory, and transmitting the first information stored in the memory to the biometric authentication mechanism, and obtained by the biometric authentication mechanism. Receives the biometric information and the second information generated from the first information from the biometric authentication mechanism unit and transmits the received second information to the IC card, and the registration data and the second information previously stored in the IC card. Recording medium containing a computer-readable biometric authentication program, characterized in that it is operative to combine the data into the IC card. 현금의 거래를 자동적으로 실시하는 현금 자동 거래 장치에 있어서,In the cash automatic trading device which performs the transaction of cash automatically, IC카드의 정보를 독취하는 카드 기구부와, 상기 현금 자동 거래 장치를 이용하는 이용자의 생체 특징량을 취득하는 생체 인증 기구부와 제어부를 갖고,A card mechanism unit for reading the information of the IC card, a biometric authentication mechanism unit and a control unit for acquiring the biometric characteristic amount of the user who uses the cash automatic transaction apparatus, 상기 제어부는 상기 카드 기구부에 의해 독출한 상기 IC카드내의 전처리 데이터를 수신하고 또한 수신한 상기 전처리 데이터를 상기 생체 인증 기구부에 송신 함과 동시에 송신한 상기 전처리 데이터와 상기 생체 인증 기구부에서 취득한 상기 생체 특징량에 의해 생성된 인증 데이터를 수신하고 또한 수신한 상기 인증 데이터를 상기 카드 기구부를 개재시켜 상기 IC카드로 송신하고, 상기 IC카드에 의한 생체 정보의 인증 처리를 실행하는 것을 특징으로 하는 현금 자동 거래 장치.The control unit receives the preprocessing data in the IC card read out by the card mechanism unit, and transmits the received preprocessing data to the biometric authentication mechanism while simultaneously transmitting the preprocessed data transmitted by the biometric authentication mechanism and the biometric characteristic acquired by the biometric authentication mechanism. Receive the authentication data generated by the amount, and transmit the received authentication data to the IC card via the card mechanism unit, and perform the authentication processing of the biometric information by the IC card, characterized in that Device. 청구항 17 기재의 현금 자동 거래 장치에 있어서,In the cash automated transaction apparatus according to claim 17, 상기 생체 인증 기구부는 상기 생체 인증 기구부에 놓여진 생체에 대해서 빛을 조사하는 생체 조사부와, 상기 생체 조사부에 의해 조사된 상기 생체의 화상을 취득하는 화상 취득부를 갖고,The biometric authentication mechanism portion has a biometric irradiation portion for irradiating light onto a living body placed in the biometric authentication mechanism portion, and an image acquisition portion for obtaining an image of the living body irradiated by the biometric irradiation portion, 상기 화상 취득부에 의해 취득한 상기 생체 특징량과, 상기 IC카드로부터 상기 제어부를 개재시켜 수신한 상기 전처리 데이터로부터 혹은 알고리즘에 따라서 상기 인증 데이터를 생성하는 것을 특징으로 하는 현금 자동 거래 장치.And the authentication data generated from the biometric feature acquired by the image acquisition section and the preprocessing data received from the IC card via the control section or in accordance with an algorithm. 청구항 18 기재의 현금 자동 거래 장치에 있어서,In the cash automated transaction apparatus according to claim 18, 상기 제어부는, 생체 정보의 인증 처리를 실행하는 인증 제어 미들을 기억하고 기억한 상기 인증 제어 미들로부터 지시에 의해 상기 생체 인증 기구부에서 상 기 인증 데이터를 생성하고 생성된 상기 인증 데이터를 상기 IC카드로 송신하는 것을 특징으로 하는 현금 자동 거래 장치.The control unit generates the authentication data in the biometric authentication mechanism unit according to an instruction from the authentication control middle which stores and stores the authentication control middle for executing the authentication process of the biometric information, and sends the generated authentication data to the IC card. Cash automatic transaction apparatus characterized in that the transmission. 청구항 17 기재의 현금 자동 거래 장치에 있어서,In the cash automated transaction apparatus according to claim 17, 상기 카드 기구부는, 상기 생체 인증 기구부에서 수신한 상기 인증 데이터를 상기 IC카드로 기억시키고,The card mechanism section stores the authentication data received by the biometric authentication mechanism section as the IC card, 상기 IC카드는, 카드 보유자 특유의 정보로서 미리 기억된 등록 데이터와,The IC card includes registration data stored in advance as information unique to the card holder, 상기 기억한 인증 데이터를 인증 또는 조합 처리하는 것을 특징으로 하는 현금 자동 거래 장치.And an authentication or combination process of the stored authentication data. 청구항 20 기재의 현금 자동 거래 장치에 있어서,In the cash automatic transaction apparatus according to claim 20, 상기 제어부는, 상기 카드 기구부를 개재시켜 상기 IC카드내에서 인증 또는 조합 처리한 결과를 독출하여 상기 생체 인증 기구부에 송신하고, 상기 생체 인증 기구부에 의해 분석된 인증 결과에 근거해 생체 정보의 인증 처리를 실행하는 것을 특징으로 하는 현금 자동 거래 장치.The control unit reads out the result of authentication or combination processing in the IC card via the card mechanism unit and transmits the result to the biometric authentication mechanism unit, and authenticates the biometric information based on the authentication result analyzed by the biometric authentication mechanism unit. Cash automatic transaction device, characterized in that for executing. 청구항 21 기재의 현금 자동 거래 장치 에 있어서,In the cash automated transaction apparatus according to claim 21, 상기 제어부는, 상기 생체 인증 기구부에서 생체의 어느 부위에서 성공했는지 아닌지의 정보도 포함해 수신하고 인증 실패시의 원인을 출력하는 것을 특징으로 하는 현금 자동 거래 장치.And the control unit receives the biometric authentication mechanism unit including information on which part of the living body has succeeded, and outputs the cause of the authentication failure. 청구항 17 기재의 현금 자동 거래 장치에 있어서,In the cash automated transaction apparatus according to claim 17, 상기 카드 기구부는, 상기 IC카드의 접속을 확립함과 동시에 상기 IC카드로부터 생체 인증에 있어서의 서포트 정보를 독출하여 상기 제어부에 송신하고,The card mechanism unit establishes the connection of the IC card and at the same time reads support information in biometric authentication from the IC card and transmits it to the control unit. 상기 제어부는 수신한 상기 서포트 정보에 근거하고 IC카드내 인증 처리시는 상기 인증 처리를 계속하고 장치내 인증 처리시는 상기 카드 기구부로부터 상기 IC카드를 배출하는 것을 특징으로 하는 현금 자동 거래 장치.And the control unit continues the authentication process upon authentication processing in the IC card based on the received support information, and discharges the IC card from the card mechanism unit during the in-device authentication processing. 청구항 17 기재의 현금 자동 거래 장치에 있어서,In the cash automated transaction apparatus according to claim 17, 상기 제어부는, 상기 IC카드에 의한 인증 처리에 응답하여 이용자가 선택한 거래를 실행하고 상기 인증 처리의 결과가 실패일때 상기 IC카드에서 수신한 상기 전처리 데이터를 다시 상기 생체 인증 기구부에 송신해 다시 인증 처리를 실행하는 것을 특징으로 하는 현금 자동 거래 장치.The control unit executes a transaction selected by the user in response to the authentication process by the IC card, and when the result of the authentication process fails, transmits the preprocessing data received from the IC card to the biometric authentication mechanism again for authentication process. Cash automatic transaction device, characterized in that for executing. 청구항 17 기재의 현금 자동 거래 장치에 있어서, In the cash automated transaction apparatus according to claim 17, 지폐 입출금을 실시하는 지폐 입출금부와,Banknote deposit and withdrawal department which performs banknote deposit and withdrawal, 이용자에게 조작 내용을 표시하고 이용자로부터의 입력을 접수하는 조작부를 갖고,It has an operation unit which displays the operation contents to the user and receives the input from the user, 상기 제어부는, 상기 조작부에 의해 이용자가 원하는 지불 거래를 접수하고,상기 IC카드에 의한 인증 처리에 응답해 그 결과가 성공한 경우에, 상기 지폐 입출 금부로부터 지폐를 출금하는 것을 특징으로 하는 현금 자동 거래 장치.The control unit accepts a payment transaction desired by the user by the operation unit, and withdraws a bill from the bank note withdrawal unit when the result is successful in response to the authentication processing by the IC card. Device. 청구항 17 기재의 현금 자동 거래 장치에 있어서,In the cash automated transaction apparatus according to claim 17, 거래에 관련의 조작 내용을 표시하고 이용자로부터의 입력을 검지하는 조작부를 갖고,It has an operation unit which displays the operation contents related to the transaction and detects the input from the user, 상기 제어부는, 상기 조작부에 의해 이용자가 원하는 잔고 조회를 검지하고 상기 IC카드에 의한 인증 처리에 응답해 그 결과가 상기 조합 결과가 성공인 경우에, 상기 조작부에 예금 또는 차입 잔고를 표시하고 그 후, 상기 조작부에서 인증을 필요로 하는 거래를 접수하면 상기 IC카드에서 수신하여 기억한 상기 전처리 데이터를 상기 생체 인증 기구부에 재송신하고, 상기 생체 인증 기구부로부터 새롭게 입력된 생체 특징량과 재출력된 상기 전처리 데이터로부터 인증 데이터를 생성하는 것을 특징으로 하는 현금 자동 거래 장치.The control unit detects the balance inquiry desired by the user by the operation unit and, in response to the authentication processing by the IC card, displays the deposit or borrowed balance on the operation unit when the result of the combination is successful. And, upon receipt of a transaction requiring authentication at the operation unit, retransmits the preprocessing data received and stored at the IC card to the biometric authentication mechanism, and newly inputs biometric features and reprinted the preprocessed data from the biometric authentication mechanism. Automatic cash transaction apparatus characterized in that for generating authentication data from the data. 청구항 17 기재의 현금 자동 거래 장치에 있어서,In the cash automated transaction apparatus according to claim 17, 상기 제어부는 상기 전처리 데이터를 이용자가 선택한 거래 종료까지 일시 기억하고,The controller temporarily stores the preprocessed data until the end of the transaction selected by the user. 거래 종료에 기인해 상기 전처리 데이터를 삭제 처리하는 것을 특징으로 하는 현금 자동 거래 장치.And automatically delete the preprocessing data due to the transaction termination.
KR1020060101720A 2005-10-19 2006-10-19 Computer readable recording medium and automatic cash transaction system containing biometric authentication method, biometric control program Expired - Fee Related KR100848926B1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
JP2005303838A JP4500760B2 (en) 2005-10-19 2005-10-19 IC card authentication system
JPJP-P-2005-00303838 2005-10-19

Publications (2)

Publication Number Publication Date
KR20070042898A true KR20070042898A (en) 2007-04-24
KR100848926B1 KR100848926B1 (en) 2008-07-29

Family

ID=38059315

Family Applications (1)

Application Number Title Priority Date Filing Date
KR1020060101720A Expired - Fee Related KR100848926B1 (en) 2005-10-19 2006-10-19 Computer readable recording medium and automatic cash transaction system containing biometric authentication method, biometric control program

Country Status (3)

Country Link
JP (1) JP4500760B2 (en)
KR (1) KR100848926B1 (en)
CN (3) CN1952985B (en)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11308495B2 (en) * 2017-12-11 2022-04-19 Feitian Technologies Co., Ltd. Financial card with function of fingerprint verification and working method therefor

Families Citing this family (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP5110983B2 (en) * 2007-06-29 2012-12-26 日立オムロンターミナルソリューションズ株式会社 Biometric authentication processing system
CN104009962B (en) * 2013-02-26 2018-01-16 中国银联股份有限公司 Equipment for safety information interaction
CN103997504B (en) * 2014-06-13 2017-11-10 谭知微 Authentication system and auth method
CN104182788A (en) * 2014-08-26 2014-12-03 黑龙江大学 RFID bank card development method based on finger vein identity recognition
JP6192082B1 (en) * 2016-04-27 2017-09-06 ブレイニー株式会社 Biometric data registration system and settlement system
JP2018018324A (en) * 2016-07-28 2018-02-01 株式会社東芝 IC card and portable electronic device
CN106888207B (en) * 2017-02-21 2020-02-21 中国联合网络通信集团有限公司 Authentication method, system and SIM card
WO2019190639A1 (en) * 2018-03-26 2019-10-03 Mastercard International Incorporated System and method for enabling receipt of electronic payments
DE112020004358T5 (en) 2019-09-12 2022-06-15 Sony Group Corporation AUTHENTICATION DEVICE, AUTHENTICATION METHOD, PROGRAM AND INFORMATION PROCESSING DEVICE
KR20220156685A (en) * 2021-05-18 2022-11-28 삼성전자주식회사 Ic card including registered biometic information and registerd pin information, and operation method thereof, and operation method of card reader communicating with the ic card

Family Cites Families (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
KR19990010554A (en) * 1997-07-18 1999-02-18 김지태 Fingerprint Card System
KR19990073820A (en) * 1998-03-03 1999-10-05 박기옥 Cash dispenser with fingerprint reader
JP3112076B2 (en) * 1998-05-21 2000-11-27 豊 保倉 User authentication system
KR20010025234A (en) * 2000-11-09 2001-04-06 김진삼 A certification method of credit of a financing card based on fingerprint and a certification system thereof
KR100397382B1 (en) * 2001-04-19 2003-09-17 주식회사 안에스티 System of smart card for fingerprinting cognition
AU2002330406A1 (en) * 2002-09-13 2004-04-30 Fujitsu Limited Biosensing instrument and method and identifying device having biosensing function

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11308495B2 (en) * 2017-12-11 2022-04-19 Feitian Technologies Co., Ltd. Financial card with function of fingerprint verification and working method therefor

Also Published As

Publication number Publication date
CN101504784A (en) 2009-08-12
CN101504785B (en) 2013-01-02
CN1952985A (en) 2007-04-25
CN101504785A (en) 2009-08-12
JP2007114911A (en) 2007-05-10
KR100848926B1 (en) 2008-07-29
CN1952985B (en) 2011-06-22
JP4500760B2 (en) 2010-07-14

Similar Documents

Publication Publication Date Title
JP4804759B2 (en) IC card updating method and IC card updating apparatus having biometric authentication function
JP4657668B2 (en) Biometric authentication method and biometric authentication device
JP7155859B2 (en) Authentication device, authentication system, and authentication method
GB2525660A (en) Methods, devices and systems for transaction initiation
CN100578558C (en) Transaction processing system
CN101334915A (en) Biometric authentication device, method and device for obtaining vein information
KR100848926B1 (en) Computer readable recording medium and automatic cash transaction system containing biometric authentication method, biometric control program
CN1855155B (en) Automatic cash transaction device
JP7171388B2 (en) Transaction terminal device and transaction control method for transaction terminal device
KR100788768B1 (en) System for automatic teller machine and automatic cash transaction device
JP4834785B2 (en) Automatic cash deposit system and apparatus
JP4117335B2 (en) IC card authentication system
JP2007164423A (en) Personal identification system and personal identification method
JP5075675B2 (en) Biometric authentication system and biometric authentication device
JP4500834B2 (en) IC card authentication system
JP4914578B2 (en) Automatic cash transaction apparatus and transaction system
JP4319154B2 (en) User authentication method and user authentication program
JP4800131B2 (en) Biometric authentication device and system, and transaction processing device
JP2006099313A (en) Transaction system
JP2007280405A (en) Individual authentication method
JP4208014B2 (en) Automatic transaction apparatus and automatic transaction system
TWM553857U (en) Automated teller machine incorporated with verification function using biometric features and barcode
JP4951297B2 (en) Identity verification device and transaction processing device
JP2008047143A (en) Automatic transaction system
JP2010079596A (en) Automated transaction machine

Legal Events

Date Code Title Description
A201 Request for examination
PA0109 Patent application

St.27 status event code: A-0-1-A10-A12-nap-PA0109

PA0201 Request for examination

St.27 status event code: A-1-2-D10-D11-exm-PA0201

PN2301 Change of applicant

St.27 status event code: A-3-3-R10-R13-asn-PN2301

St.27 status event code: A-3-3-R10-R11-asn-PN2301

PG1501 Laying open of application

St.27 status event code: A-1-1-Q10-Q12-nap-PG1501

D13-X000 Search requested

St.27 status event code: A-1-2-D10-D13-srh-X000

D14-X000 Search report completed

St.27 status event code: A-1-2-D10-D14-srh-X000

E902 Notification of reason for refusal
PE0902 Notice of grounds for rejection

St.27 status event code: A-1-2-D10-D21-exm-PE0902

P11-X000 Amendment of application requested

St.27 status event code: A-2-2-P10-P11-nap-X000

P13-X000 Application amended

St.27 status event code: A-2-2-P10-P13-nap-X000

E701 Decision to grant or registration of patent right
PE0701 Decision of registration

St.27 status event code: A-1-2-D10-D22-exm-PE0701

GRNT Written decision to grant
PR0701 Registration of establishment

St.27 status event code: A-2-4-F10-F11-exm-PR0701

PR1002 Payment of registration fee

St.27 status event code: A-2-2-U10-U11-oth-PR1002

Fee payment year number: 1

PG1601 Publication of registration

St.27 status event code: A-4-4-Q10-Q13-nap-PG1601

PR1001 Payment of annual fee

St.27 status event code: A-4-4-U10-U11-oth-PR1001

Fee payment year number: 4

PR1001 Payment of annual fee

St.27 status event code: A-4-4-U10-U11-oth-PR1001

Fee payment year number: 5

FPAY Annual fee payment

Payment date: 20130705

Year of fee payment: 6

PR1001 Payment of annual fee

St.27 status event code: A-4-4-U10-U11-oth-PR1001

Fee payment year number: 6

FPAY Annual fee payment

Payment date: 20140707

Year of fee payment: 7

PR1001 Payment of annual fee

St.27 status event code: A-4-4-U10-U11-oth-PR1001

Fee payment year number: 7

FPAY Annual fee payment

Payment date: 20150619

Year of fee payment: 8

PR1001 Payment of annual fee

St.27 status event code: A-4-4-U10-U11-oth-PR1001

Fee payment year number: 8

FPAY Annual fee payment

Payment date: 20160617

Year of fee payment: 9

PR1001 Payment of annual fee

St.27 status event code: A-4-4-U10-U11-oth-PR1001

Fee payment year number: 9

P22-X000 Classification modified

St.27 status event code: A-4-4-P10-P22-nap-X000

FPAY Annual fee payment

Payment date: 20170616

Year of fee payment: 10

PR1001 Payment of annual fee

St.27 status event code: A-4-4-U10-U11-oth-PR1001

Fee payment year number: 10

P22-X000 Classification modified

St.27 status event code: A-4-4-P10-P22-nap-X000

LAPS Lapse due to unpaid annual fee
PC1903 Unpaid annual fee

St.27 status event code: A-4-4-U10-U13-oth-PC1903

Not in force date: 20180723

Payment event data comment text: Termination Category : DEFAULT_OF_REGISTRATION_FEE

PC1903 Unpaid annual fee

St.27 status event code: N-4-6-H10-H13-oth-PC1903

Ip right cessation event data comment text: Termination Category : DEFAULT_OF_REGISTRATION_FEE

Not in force date: 20180723

PN2301 Change of applicant

St.27 status event code: A-5-5-R10-R13-asn-PN2301

St.27 status event code: A-5-5-R10-R11-asn-PN2301