CN101127599B - An identity and right authentication method and system and a biological processing unit - Google Patents

An identity and right authentication method and system and a biological processing unit Download PDF

Info

Publication number
CN101127599B
CN101127599B CN2006101098799A CN200610109879A CN101127599B CN 101127599 B CN101127599 B CN 101127599B CN 2006101098799 A CN2006101098799 A CN 2006101098799A CN 200610109879 A CN200610109879 A CN 200610109879A CN 101127599 B CN101127599 B CN 101127599B
Authority
CN
China
Prior art keywords
authentication
biological
user
identity
certificate
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Expired - Fee Related
Application number
CN2006101098799A
Other languages
Chinese (zh)
Other versions
CN101127599A (en
Inventor
刘宏伟
刘淑玲
位继伟
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to CN2006101098799A priority Critical patent/CN101127599B/en
Priority to JP2009524890A priority patent/JP2010501103A/en
Priority to EP07800922.2A priority patent/EP2053777B1/en
Priority to KR1020097005360A priority patent/KR20090041436A/en
Priority to PCT/CN2007/070446 priority patent/WO2008022585A1/en
Publication of CN101127599A publication Critical patent/CN101127599A/en
Priority to US12/388,315 priority patent/US20090271635A1/en
Application granted granted Critical
Publication of CN101127599B publication Critical patent/CN101127599B/en
Expired - Fee Related legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

The utility model discloses an identity and right authentication method and system as well as a biological treatment unit for enhancing the flexibility of the authentication process; wherein, the method comprises the following steps: associating the right authentication with the identity authentication; acquiring the security level of rights; making inquiries on the security level of identities corresponding to the security level of rights according to the correspondence between the security level of rights and the identities; determining the authentication parameters according to the identity security level; checking the customer biological templates with the checking parameters and generating checking results. The utility model also provides a corresponding system and a biological treatment unit. The utility model has the advantage of effectively improving the flexibility of the authentication process.

Description

A kind of identity and purview certification method and system and a kind of biological processing unit
Technical field
The present invention relates to the data security technical field, relate in particular to a kind of identity and purview certification method and system and a kind of biological processing unit.
Background technology
Along with the network fast development, ecommerce has obtained a large amount of application, Web bank, and transaction etc. are also more general.Protect personal account information obviously to be not enough to guarantee safety of data in the conventional cipher mode, network fraud in recent years, the phenomenon of account takeover is increasing.Therefore, the personal information guarantee of the higher security arrangement of development, authentication mechanism is imperative.
The application to a certain degree that PKIX (PKI, Pubic Key Infrastructure) authentication public key system has obtained at present.Authoritative institution provides the user that public key certificate is given terminal, and certificate can disclose, and has deposited user's PKI in certificate, and other information.Taken care of by user oneself with the corresponding private key of PKI, PKI and private key are unique definite relation, can not infer private key from PKI, and the information of public key encryption can be passed through the unique deciphering of private key.This specific character of PKI can guarantee whether the verifier can provide private key to confirm whether the user is the entity of stating on the public key certificate according to the user, and then guarantee that user profile can illegally not stolen.
In the mechanism of PKI, the protection private key for user is crucial, and private key generally is that the mode with electronic information leaves some in above the hardware.If private key is lost, also lost guarantee with regard to the personal information that means the user.
Biometrics identification technology is ripe gradually in recent years, and the particular surroundings of network ID authentication, and biometrics identification technology is applied in the authentication, utilizes the characteristics such as uniqueness, stability of biological characteristic, for information security provides guarantee.
Utilize personal biological information to carry out the effective ways that authentication is a kind of resource conservation.Consider the particularity of biological information itself, and the particular surroundings of network ID authentication, a kind of safer authentication architecture formed so biological information can be combined with PKI.
The PKI system is a kind of method that authenticates personal identification, and biological characteristic is the basic method of proof personal identification, the two is combined carry out authentication and can bring into play separately advantage, remedies the other side's shortcoming.With the coupling authentication of comparing in client is example, and idiographic flow as shown in Figure 1.The authentication square tube is crossed biological attribute data template in the creature certificate that the user biological characteristic sample that will collect and user provide and is carried out matching ratio to determine the legitimacy of its identity.
At the different requirements of different user, serve the provider and authorize different rights can for different users, promptly realize by empowerment management infrastructure (PMI, Privilege Management Infrastructure).
PMI is the aggregate of parts such as Attribute certificate, attribute authority (aa), Attribute certificate storehouse, be used for realizing authority and certificate generation, management, storage, distribute and function such as cancel.
Attribute certificate (AC, Attribute Certificate) defined an authority that entity has, the binding of entity and authority is to be provided by a data structure that has been digitally signed, this data structure is called Attribute certificate, sign and issue and manage by attribute authority (aa), it comprises that one is launched mechanism and a series of special certificate extension mechanism, and concrete form as shown in Figure 2.
Authentication and purview certification all play a very important role to data safety, and a kind of identity and purview certification method are in the prior art: authentication and purview certification separating treatment, that is:
When carrying out purview certification, the user submits authorized application to; Server authenticates the user according to the authenticate ruler that presets, if by then authorizing its corresponding authority.
When carrying out authentication, similar with the purview certification process, server all is to authenticate by the authenticate ruler that presets, two kinds of independent execution of authentication.
But owing to only the user is carried out authentication or only carry out the accuracy that purview certification possibly can't improve whole authentication process.
Another kind of identity and purview certification method are in the prior art: earlier the user is carried out authentication, when authenticating user identification by after again the user is carried out purview certification.
This technical scheme has improved the strict degree of whole identifying procedure, and then has improved accuracy.But this scheme can only authenticate according to the rule that presets, and can not adjust authenticate ruler according to actual conditions in verification process, can not realize dynamic authentication, so reduced the flexibility of identity and purview certification.
Summary of the invention
The technical problem to be solved in the present invention provides a kind of identity and purview certification method and system and a kind of biological processing unit, is used for adjusting authenticate ruler according to actual conditions, improves the flexibility of verification process.
Identity provided by the invention and purview certification method comprise: carry out related to purview certification with authentication; Obtain the legal power safety rank; According to the corresponding relation of legal power safety rank and identity level of security, inquire about the identity level of security of described legal power safety rank correspondence; Determine parameters for authentication according to described identity level of security; Utilize described parameters for authentication that the user biological masterplate is carried out verification and generates check results.
Alternatively, related step being carried out in purview certification and authentication comprises: the corresponding relation of setting up legal power safety rank and identity level of security.
Alternatively, described legal power safety rank is stored in the Attribute certificate; Described corresponding relation is stored in the biological algorithm certificate.
Alternatively, further comprise before related in that purview certification and authentication are carried out: the user sends access request to application system; Application program receives after the described request, activates the authentication adapter unit; The authentication adapter unit is asked user's creature certificate and Attribute certificate to the user; The user returns creature certificate and Attribute certificate to the authentication adapter unit.
Alternatively, described parameters for authentication comprises: contrast biological template generating algorithm parameter, matching algorithm parameter and threshold value.
Alternatively, the described step of utilizing parameters for authentication that user biological information is carried out verification and generating check results comprises: generate the contrast biological template according to contrast biological template generating algorithm parameter; Described contrast biological template and user biological masterplate are mated and obtain the coupling scoring according to the matching algorithm parameter; Whether judge described coupling scoring more than or equal to threshold value, if more than or equal to, judge that then the user passes through authentication, if less than, judge that then the user is not by authentication.
Alternatively, utilize parameters for authentication user biological information to be carried out verification and generate further comprising after the check results: check results is fed back to the user.
Identity provided by the invention and purview certification system comprise resolution unit, biological processing unit and verification unit; Described resolution unit is used to obtain the legal power safety rank, and described legal power safety rank is sent to biological processing unit; Biological processing unit is according to described legal power safety rank corresponding identity level of security of inquiry in the corresponding relation of legal power safety rank and identity level of security, determine parameters for authentication according to described identity level of security, and described parameters for authentication is sent to verification unit; The parameters for authentication that the verification unit utilization receives is carried out verification and is generated check results the user biological masterplate.
Alternatively, described system also comprises: authentication adapter unit, biomedical information acquisition unit and application system; The user sends access request to described application system, and application system activates the authentication adapter unit after receiving described request; Described authentication adapter unit be activated rear line request attribute certificate and creature certificate; Described biological collecting unit is used to gather the user biological data and sends to biological processing unit.
Biological processing unit provided by the invention comprises: associative cell, parameter generating unit, contrast masterplate generation unit and creature certificate resolution unit; Described associative cell is used to obtain the corresponding relation of legal power safety rank and identity level of security, sends to parameter generating unit according to the identity level of security of legal power safety rank inquiry correspondence and with described identity level of security; Described parameter generating unit generates corresponding parameters for authentication according to the identity level of security that receives, and described parameter is sent to contrast masterplate generation unit; Described contrast masterplate generation unit generates the contrast biological template according to described parameter; Described creature certificate resolution unit is extracted the user biological masterplate from the user biological certificate that obtains.
Above technical scheme as can be seen, the present invention has the following advantages:
At first, among the present invention, authentication combines with purview certification, authenticate accordingly according to the identity of the corresponding identity level of security of the legal power safety rank of customer requirements inquiry the user, so can in verification process, adjust the rule of authentication, the flexibility that has improved identifying procedure according to actual conditions;
Secondly, among the present invention, generate behind the contrast masterplate and user's biological template mates according to the matching algorithm of correspondence and obtains the coupling scoring, compare with corresponding threshold value again and judge whether by authentication, matching algorithm and threshold value all obtain according to actual conditions, so improved the accuracy of verification process.
Description of drawings
Fig. 1 utilizes biological template to carry out the schematic flow sheet of authentication;
Fig. 2 is the Attribute certificate schematic diagram;
Fig. 3 is a biological extend information schematic diagram in the Attribute certificate;
Fig. 4 is the inventive method overview flow chart;
Fig. 5 is the inventive method detail flowchart;
Fig. 6 is a system schematic of the present invention;
Fig. 7 is system functional model figure of the present invention;
Fig. 8 is a biological processing unit schematic diagram of the present invention;
Fig. 9 is biological processing unit functional mode figure of the present invention.
Embodiment
The invention provides a kind of identity and purview certification method and system and a kind of biological processing unit, be used for adjusting authenticate ruler, improve the flexibility of verification process according to actual conditions.
For in conjunction with biological identification, need carry out certain replenishing to the PMI system.In order to make the systematic influence minimum, we will increase the expansion item in the Attribute certificate.
The extend information of Attribute certificate mainly is that statement is used some relevant policy informations with certificate.The Attribute certificate extend information comprises that basic extend information, authority cancel extend information, root attribute authority (aa) extend information, role's extend information and authorize 5 parts such as extend information.
When the use attribute certificate carries out purview certification, at first need user identity is authenticated, consider Attribute certificate and creature certificate are associated, to guarantee the accurate corresponding relation of purview certification and personal identification.Therefore, we have added the index information of relevant creature certificate in the biology expansion the inside of Attribute certificate, as shown in Figure 3.
See also Fig. 3, wherein, creature certificate publisher and biological sequence number: identified the creature certificate with this Attribute certificate holder, promptly the Attribute certificate holder has been carried out the required creature certificate of authentication.When the holder is carried out authentication, the holder's that gathers biological attribute data is compared with the Template Information in this creature certificate, so that it is carried out authentication.But creature certificate publisher and biological sequence number are options.
Entity title: the title that has identified one or more Attribute certificate holder, if have only this in the expansion of the creature certificate of Attribute certificate sign, the creature certificate that then any principal name is included in the entity title can be used for verifying this Attribute certificate holder's identity.Promptly, can be used for verifying holder's identity as long as the principal name of creature certificate is included in the entity title.The holder is as long as use above any one creature certificate by authentication, and it is legal just to think.But, if creature certificate publisher and biological sequence item and this and when depositing are as the criterion with the creature certificate of creature certificate publisher and biological sequence correspondence.
Object summary info: the i.e. summary of the sequence number of Attribute certificate holder's creature certificate, the term of validity, main body and unique identification thereof, publisher and unique identification thereof, template style sign, biometric templates, extend information etc.Be used for directly verifying Attribute certificate holder identity.When the holder is carried out authentication, at first the creature certificate content with the holder makes an abstract, compare with the object summary info in the biological expansion of Attribute certificate, if identical then illustrate that the creature certificate of this Attribute certificate correspondence is exactly the creature certificate that the holder provides, further carry out authentication then.
Biological expansion the inside comprises in creature certificate publisher and biological sequence number, entity title, the object summary info at least, to guarantee that Attribute certificate can find its corresponding creature certificate.
On the other hand, carry out authentication if comprised biological template in the PKI public key certificate that the Attribute certificate holder provides, then the corresponding relation of Attribute certificate and biological template can directly be realized by this PKI certificate of Attribute certificate index, this index do not realize by the expansion index, but in the Attribute certificate holder's definition direct index this PKI certificate realize.
See also Fig. 4, the inventive method overall procedure is:
401, carry out related to purview certification with authentication;
402, obtain the legal power safety rank;
403, the corresponding identity level of security of inquiry;
Wherein, according to the corresponding relation of legal power safety rank and identity level of security, inquire about the identity level of security of described legal power safety rank correspondence.
404, determine parameters for authentication;
Wherein, determine parameters for authentication according to the identity level of security that inquires.
405, verification;
Wherein, utilize the parameters for authentication of determining that the user biological masterplate is carried out verification.
406, generate check results.
See also Fig. 5, the inventive method detailed process is:
501, set up corresponding relation;
Wherein, set up the corresponding relation between legal power safety rank and the identity level of security, and corresponding relation is stored in the biological algorithm certificate, be understandable that this corresponding relation can be stored in other positions equally.
Wherein, present embodiment realizes being understandable that related to purview certification and authentication by setting up legal power safety rank and the corresponding relation between the identity level of security, can realize the related of purview certification and authentication equally in other way.
502, the user sends access request to application system;
Wherein, the resource of user applies access application system.
503, activate the authentication adapter unit;
Wherein, application system receives after the access request of user's transmission, activates the authentication adapter unit, requires the authentication adapter unit to ask creature certificate and Attribute certificate to the user.
504, obtain creature certificate and Attribute certificate;
Wherein, the authentication adapter unit rear line that is activated is initiated the request of creature certificate and Attribute certificate, and the user sends to the authentication adapter unit with creature certificate and Attribute certificate.
505, obtain the legal power safety rank;
Wherein, resolution unit is resolved the Attribute certificate that the authentication adapter unit sends, and obtains legal power safety rank wherein.
506, the corresponding identity level of security of inquiry;
Wherein, biological processing unit is according to legal power safety rank corresponding identity level of security of inquiry in the corresponding relation of the legal power safety rank of having set up and identity level of security.
507, determine parameters for authentication;
Wherein, biological processing unit is determined parameters for authentication according to the identity level of security that inquires, and comprises contrast biological template generating algorithm parameter, matching algorithm parameter and threshold value.
508, generate the contrast biological template;
Wherein, biological processing unit generates corresponding contrast biological template according to contrast biological template generating algorithm parameter.
509, obtain the user biological masterplate;
Wherein, biological processing unit extracts the user biological masterplate from user's creature certificate, is understandable that, the execution sequence that this step is unfixing can be carried out when acquiring creature certificate equally, only need carry out getting final product between mating.
510, coupling contrast biological template and user biological masterplate;
Wherein, verification unit will contrast biological template and the user biological masterplate mates, and draws the coupling scoring, and the present invention does not limit the mode of coupling.
511, whether judge the coupling scoring more than or equal to threshold value, if, then turn to step 512, if not, then turn to step 513;
Wherein, threshold value is in the parameters for authentication, is obtained by identity level of security correspondence.
512, judge that the user is by authentication;
513, judge that the user is not by authentication;
514, feed back to the user.
Wherein, with final authentication result notification user.
In the present embodiment, when application system is received user's access request, at first activate the authentication adapter unit, the authentication adapter unit is asked creature certificate and Attribute certificate to the user; Receive back resolution unit checking and resolve Attribute certificate, obtain legal power safety rank and access rights; The authentication adapter unit activates biological processing unit, resolves the biological algorithm certificate that is positioned at the checking end, obtains the identity level of security, determines biological treatment parameter and threshold value according to the identity level of security, and generates the contrast biological template; Biological processing unit is resolved the user biological certificate, obtains the user biological masterplate, contrast biological template and the comparison of user biological masterplate, obtains the coupling score value; Verification unit is made last judgement according to threshold value; After authentication was passed through, the authentication adapter unit returned to application system to authority, and application system is instead given the user requested resource result.
User right and legal power safety rank have been deposited in the Attribute certificate; Deposited user's biological template in the user biological certificate; Deposit the corresponding relation between authority level of security and the identity level of security in the biological algorithm certificate, the correspondence position in corresponding relation has different contrast biological template generating algorithm parameter, matching algorithm parameter and threshold value.
See also Fig. 6, system of the present invention comprises: application system 601, authentication adapter unit 602, resolution unit 603, biomedical information acquisition unit 604, biological processing unit 605 and verification unit 606.Wherein the user sends access request to application system 601, and application system 601 activates authentication adapter unit 602 after receiving described request; Authentication adapter unit 602 is activated and sends to resolution unit 603 and biological processing unit 605 after rear line request attribute certificate and the creature certificate; Resolution unit 603 is used for the dependency certificate and obtains the legal power safety rank, and the legal power safety rank is sent to biological processing unit 605; Biological processing unit 605 is according to legal power safety rank corresponding identity level of security of inquiry in the corresponding relation of legal power safety rank and identity level of security, determine parameters for authentication according to the identity level of security, and generate the contrast biological template according to the user biological information that biomedical information acquisition unit 604 sends, and will contrast biological template, user biological masterplate in the user biological certificate and the matching algorithm parameter in the parameters for authentication and threshold value send to verification unit 606; Verification unit 606 is mated the user biological masterplate according to the data utilization contrast biological template that receives, and check results is sent to authentication adapter unit 602.
See also Fig. 7, systemic-function flow process of the present invention is:
701, the user visits to the application system request;
702, application system activates the authentication adapter unit;
703, the authentication adapter unit is asked user's creature certificate and Attribute certificate to the user;
704, the user returns creature certificate and the Attribute certificate of oneself;
705, the authentication adapter unit activates resolution unit;
706, the authentication adapter unit activates biological processing unit;
707, resolution unit authentication certificate validity, and parse authority and legal power safety rank, simultaneously the legal power safety rank is passed to biological processing unit;
708, biological processing unit biological treatment asks to import corresponding user biological information to the user then, and after the biomedical information acquisition elements capture user biological information, corresponding software module sends it to biological processing unit;
709, biological processing unit is handled biological information and is generated the contrast biological template, and the biological template in the creature certificate is sent to verification unit with the contrast biological template mates scoring;
710, verification unit is judged according to threshold value, makes acceptance (Y)/refusal (N), and the result is sent to the authentication adapter unit;
711, the authentication adapter unit obtains (visit) authority that parses in the dependency certificate, and it is passed to application system;
712, application system is according to the request of (visit) authority process user, and result is sent to the user.
See also Fig. 8, biological processing unit 605 of the present invention comprises: associative cell 801, parameter generating unit 802, contrast masterplate generation unit 803 and creature certificate resolution unit 804; Associative cell 801 is used to obtain the corresponding relation of legal power safety rank and identity level of security, sends to parameter generating unit 802 according to the identity level of security of legal power safety rank inquiry correspondence and with the identity level of security; Parameter generating unit 802 generates corresponding parameters for authentication according to the identity level of security that receives, and parameters for authentication is sent to contrast masterplate generation unit 803; Contrast masterplate generation unit 803 generates the contrast biological template according to parameters for authentication; Creature certificate resolution unit 804 is extracted the user biological masterplate from the user biological certificate that obtains.
See also Fig. 9, biological processing unit functional sequence of the present invention is:
901, obtain the legal power safety rank;
902, associative cell obtains the corresponding relation between legal power safety rank and the identity level of security, the identity level of security of search access right level of security correspondence, and the identity level of security sent to parameter generating unit;
903, the creature certificate resolution unit is resolved the user biological certificate, obtains the user biological masterplate;
904, parameter generating unit generates corresponding parameters for authentication according to the identity level of security that receives, and comprises contrast biological template generating algorithm parameter, threshold value and matching algorithm parameter;
905, respectively contrast biological template generating algorithm parameter is sent to contrast masterplate generation unit, threshold value and matching algorithm parameter are sent to verification unit;
906, ask to import corresponding user biological information to the user, after the biomedical information acquisition elements capture user biological information, corresponding software module sends it to contrast masterplate generation unit;
907, contrast masterplate generation unit will be through the biological characteristic processing, and final the generation contrast biological template, and sends it to verification unit;
908, verification unit is mated biological template, and judges according to threshold value, makes acceptance (Y)/refusal (N), and the result is sent to the authentication adapter unit.
More than a kind of identity provided by the present invention and purview certification method and system and a kind of biological processing unit are described in detail, used specific case herein principle of the present invention and execution mode are set forth, the explanation of above embodiment just is used for helping to understand method of the present invention and core concept thereof; Simultaneously, for one of ordinary skill in the art, according to thought of the present invention, the part that all can change in specific embodiments and applications, in sum, this description should not be construed as limitation of the present invention.

Claims (9)

1. identity and purview certification method is characterized in that, comprising:
Receive the access request that the user sends;
Ask user's creature certificate and Attribute certificate to the user according to described access request;
Obtain creature certificate and Attribute certificate that the user sends;
Resolve described Attribute certificate, obtain the legal power safety rank;
According to the legal power safety rank of prior association and the corresponding relation of identity level of security, inquire about the identity level of security of described legal power safety rank correspondence;
Determine parameters for authentication according to described identity level of security;
Utilize parameters for authentication that the user biological masterplate is carried out verification and generates check results.
2. identity according to claim 1 and purview certification method is characterized in that, related step is carried out in purview certification and authentication comprise:
Set up the corresponding relation of legal power safety rank and identity level of security.
3. identity according to claim 2 and purview certification method is characterized in that, described legal power safety rank is stored in the Attribute certificate; Described corresponding relation is stored in the biological algorithm certificate.
4. identity according to claim 1 and purview certification method is characterized in that, described parameters for authentication comprises: contrast biological template generating algorithm parameter, matching algorithm parameter and threshold value.
5. identity according to claim 4 and purview certification method is characterized in that, the described step of utilizing parameters for authentication that the user biological masterplate is carried out verification and generating check results comprises:
Generate the contrast biological template according to contrast biological template generating algorithm parameter;
Described contrast biological template and user biological masterplate are mated and obtain the coupling scoring according to the matching algorithm parameter;
Whether judge described coupling scoring more than or equal to threshold value, if more than or equal to, judge that then the user passes through authentication, if less than, judge that then the user is not by authentication.
6. identity according to claim 1 and purview certification method is characterized in that, utilize parameters for authentication that the user biological masterplate is carried out verification and generate check results further to comprise afterwards:
Check results is fed back to the user.
7. identity and purview certification system is characterized in that, comprise resolution unit, biological processing unit, verification unit, authentication adapter unit and application system;
Described application system is used to receive user's request visit, and activates described authentication adapter unit;
Described authentication adapter unit be activated rear line request user's creature certificate and Attribute certificate;
Described resolution unit is used to resolve described Attribute certificate, obtains the legal power safety rank, and described legal power safety rank is sent to biological processing unit;
Biological processing unit is according to described legal power safety rank corresponding identity level of security of inquiry in the corresponding relation of legal power safety rank and identity level of security, determine parameters for authentication according to described identity level of security, and described parameters for authentication is sent to verification unit;
The parameters for authentication that the verification unit utilization receives is carried out verification and is generated check results the user biological masterplate.
8. identity according to claim 7 and purview certification system is characterized in that, described system also comprises:
Biological collecting unit is used to gather the user biological data and sends to biological processing unit.
9. a biological processing unit is characterized in that, comprising: associative cell, parameter generating unit, contrast masterplate generation unit and creature certificate resolution unit; Described associative cell is used to obtain the corresponding relation of legal power safety rank and identity level of security, sends to parameter generating unit according to the identity level of security of legal power safety rank inquiry correspondence and with described identity level of security; Described parameter generating unit generates corresponding parameters for authentication according to the identity level of security that receives, and described parameter is sent to contrast masterplate generation unit; Described contrast masterplate generation unit generates the contrast biological template according to described parameter; Described creature certificate resolution unit is extracted the user biological masterplate from the user biological certificate that obtains.
CN2006101098799A 2006-08-18 2006-08-18 An identity and right authentication method and system and a biological processing unit Expired - Fee Related CN101127599B (en)

Priority Applications (6)

Application Number Priority Date Filing Date Title
CN2006101098799A CN101127599B (en) 2006-08-18 2006-08-18 An identity and right authentication method and system and a biological processing unit
JP2009524890A JP2010501103A (en) 2006-08-18 2007-08-10 Method and system for authentication
EP07800922.2A EP2053777B1 (en) 2006-08-18 2007-08-10 A certification method, system, and device
KR1020097005360A KR20090041436A (en) 2006-08-18 2007-08-10 A certification method, system, and device
PCT/CN2007/070446 WO2008022585A1 (en) 2006-08-18 2007-08-10 A certification method, system, and device
US12/388,315 US20090271635A1 (en) 2006-08-18 2009-02-18 Methods and systems for authentication

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN2006101098799A CN101127599B (en) 2006-08-18 2006-08-18 An identity and right authentication method and system and a biological processing unit

Publications (2)

Publication Number Publication Date
CN101127599A CN101127599A (en) 2008-02-20
CN101127599B true CN101127599B (en) 2011-05-04

Family

ID=39095536

Family Applications (1)

Application Number Title Priority Date Filing Date
CN2006101098799A Expired - Fee Related CN101127599B (en) 2006-08-18 2006-08-18 An identity and right authentication method and system and a biological processing unit

Country Status (1)

Country Link
CN (1) CN101127599B (en)

Families Citing this family (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100306821A1 (en) * 2009-05-29 2010-12-02 Google, Inc. Account-recovery technique
CN101594232B (en) * 2009-06-30 2011-12-28 飞天诚信科技股份有限公司 Authentication method for dynamic password, system and corresponding authentication device
WO2011155899A1 (en) * 2010-06-09 2011-12-15 Actatek Pte Ltd A secure access system employing biometric identification
CN103310137B (en) * 2012-03-16 2016-09-21 宇龙计算机通信科技(深圳)有限公司 A kind of method and device having secure access to terminal
CN103856331B (en) * 2012-12-07 2018-04-13 北京三星通信技术研究有限公司 A kind of signature authentication method and system
CN103152366B (en) * 2013-04-10 2015-12-23 魅族科技(中国)有限公司 Obtain the method for terminal authorization, terminal and server
KR102334209B1 (en) * 2015-06-15 2021-12-02 삼성전자주식회사 Method for authenticating user and electronic device supporting the same
US10990658B2 (en) 2016-07-11 2021-04-27 Samsung Electronics Co., Ltd. Method and apparatus for verifying user using multiple biometric verifiers
KR102547820B1 (en) * 2016-07-11 2023-06-27 삼성전자주식회사 Method and apparatus for verifying user using multiple biometric verifiers
CN108604990A (en) * 2016-12-02 2018-09-28 华为技术有限公司 The application method and device of local authorized certificate in terminal
CN108810002B (en) * 2018-06-21 2020-02-21 北京智芯微电子科技有限公司 Multi-CA application system and method of security chip
CN109842611B (en) * 2018-12-14 2023-04-18 平安科技(深圳)有限公司 Identity authentication method, identity authentication device, computer equipment and storage medium
CN112581103A (en) * 2020-12-31 2021-03-30 苏州盛德隆智能科技有限公司 Safety online conference management method

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1588853A (en) * 2004-07-13 2005-03-02 中国工商银行 Uniform identication method and system based on network
CN1592197A (en) * 2003-09-01 2005-03-09 台均实业有限公司 Method of identification between user device and local client use or remote-network service
CN1627683A (en) * 2003-12-09 2005-06-15 鸿富锦精密工业(深圳)有限公司 Unitary authentication authorization management system and method

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1592197A (en) * 2003-09-01 2005-03-09 台均实业有限公司 Method of identification between user device and local client use or remote-network service
CN1627683A (en) * 2003-12-09 2005-06-15 鸿富锦精密工业(深圳)有限公司 Unitary authentication authorization management system and method
CN1588853A (en) * 2004-07-13 2005-03-02 中国工商银行 Uniform identication method and system based on network

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
JP 特开2005-4253 A,全文.

Also Published As

Publication number Publication date
CN101127599A (en) 2008-02-20

Similar Documents

Publication Publication Date Title
CN101127599B (en) An identity and right authentication method and system and a biological processing unit
EP2053777B1 (en) A certification method, system, and device
US10554421B2 (en) Method for superseding log-in of user through PKI-based authentication by using smart contact and blockchain database, and server employing same
US8539249B2 (en) System and method for security authentication using biometric authentication technique
CN108777684B (en) Identity authentication method, system and computer readable storage medium
US10659236B2 (en) Method for superseding log-in of user through PKI-based authentication by using blockchain database of UTXO-based protocol, and server employing same
US20190333054A1 (en) System for verification of pseudonymous credentials for digital identities with managed access to personal data on trust networks
EP2214342B1 (en) Method and system for implementing authentication on information security
AU2008347346B2 (en) Method for reading attributes from an ID token
US8245292B2 (en) Multi-factor authentication using a smartcard
US20040010697A1 (en) Biometric authentication system and method
CN113743921B (en) Digital asset processing method, device, equipment and storage medium
CA2569355A1 (en) System and method for handling permits for user authentication tokens
CN101317362B (en) Information safety authentication method and system
CN101051896B (en) Certifying method and system
KR101603058B1 (en) System and method for identification with I-PIN and electric wallet
CN110647553B (en) Block chain-based power transaction contract management method and system
KR101330245B1 (en) Anonymous certificate processing system by distributed autority
KR20230004312A (en) System for authentication and identification of personal information using DID(Decentralized Identifiers) without collection of personal information and method thereof
WO2023027756A1 (en) Secure ledger registration
CN115955345A (en) Security management authentication method and device combining biological characteristics
CN111209255A (en) Method for constructing common communication timestamp chain
CN115834073A (en) Financial service information authentication system based on block chain
CN117640102A (en) Digital identity authentication and user data sharing method
CN113763165A (en) Method, device, equipment, medium and computer program product for producing general evidence

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
CF01 Termination of patent right due to non-payment of annual fee
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20110504

Termination date: 20170818