Specific embodiment
For the ease of understanding the present invention, the present invention is described more fully below with reference to relevant drawings.In attached drawing
Give the preferred embodiment of the present invention.But the present invention can realize in many different forms, however it is not limited to herein
Described embodiment.On the contrary, the purpose for providing these embodiments is to make the understanding to the disclosure more saturating
It is thorough comprehensive.
Unless otherwise defined, all of technologies and scientific terms used here by the article is with belonging to technical field of the invention
The normally understood meaning of technical staff is identical.Used term is intended merely to describe specific reality in the description of the invention
Apply the purpose of example, it is not intended that in the limitation present invention.Term as used herein " or/and " include one or more relevant institutes
The arbitrary and all combination of list of items.
The access control method based on biometric feature and system of the present invention is related to smart card and certification end.Smart card
It can be with storage device sequence number, biometric feature;Smart card can be with information such as storing initial key, authentication keys;
Smart card can also carry out biological characteristic validation;Smart card can also carry out random number and user name according to authentication key
Encryption.Expense control key management system is installed on certification end.The equipment sequence of all smart cards is stored on the server of certification end
Row number and corresponding access control right.It can also store user's corresponding with equipment Serial Number on the server of certification end
Username and password.Certification end can gather and receive the biometric feature of human body.Certification end can also receive user's typing
User name and password.
As shown in Figure 1, the access control method based on biometric feature of one embodiment of the present invention, including step
Suddenly:
S140:The biometric feature of human body is received, and the biometric feature of the human body is sent to intelligence and is sticked into
Row biological characteristic validation.
Certification end gathers the biometric feature of human body, and receives the biometric feature, but is not stored in certification end
The biometric feature, but the biometric feature is sent to smart card.In this way, avoid the life in certification end leakage user
Object identification feature.Smart card is preserved by user oneself, and biological characteristic validation carries out within a smart card, therefore need not be in certification end
It is transmitted in preservation or grid, ensure that the security of the biometric feature of user.The biological characteristic validation tool
Body is to be compared the biometric feature received with the biometric feature stored within a smart card by the smart card
Verification.
In one of the embodiments, biometric feature is fingerprint.It is to be appreciated that it is hand, the shape of face, rainbow
The features such as film, retina, pulse, auricle.
S145:Receive the biological characteristic validation result that smart card is sent.
If biological characteristic validation result is by performing step S190.If biological characteristic validation result for not by,
Show biological characteristic validation failure, return continues to execute step S140.
S190:Authorize corresponding access control right.
In the present embodiment, according to the equipment Serial Number of smart card and biological characteristic validation as a result, authorizing and equipment sequence
Number corresponding access control right.
The above-mentioned access control method based on biometric feature, receives the biometric feature of human body, and by the people
The biometric feature of body is sent to smart card and carries out biological characteristic validation;Receive the biological characteristic validation knot that smart card is sent
Fruit;If biological characteristic validation is by authorizing corresponding access control right.Since the biometric feature of reception is sent to intelligence
Can card carry out biological characteristic validation, therefore, there is no need to preserve in certification end or grid in transmit biometric feature, can be with
Ensure the security of the biometric feature of user to a certain extent.
For enhance access control security, avoid to be certified people carry out personal injury, such as organ cutting, cause by
Donor is non-, and subjective agreement is licensed and is authorized for situation about accessing.In one of the embodiments, as shown in Fig. 2,
After step S140 or S145, step S190 includes step S170 and S180.
S170:Receive the username and password of typing.
In one of the embodiments, only biological characteristic validation result be by when, the user name of typing could be received
And password.Since if biological characteristic validation result is not by the way that need not carry out subsequent authentication can directly judge do not have
Any access rights do not allow to access, so, it is possible to reduce the unnecessary burden of system.
In another embodiment, if the biological characteristic validation result is by performing step S180.
S180:Authentication is carried out according to the equipment Serial Number of the username and password of reception and the smart card.
Whether corresponded to according to the equipment Serial Number of the user name of reception and the smart card and whether username and password is accurate
Really and correspond to carry out authentication.
In the present embodiment, if the step of authentication, i.e., the result of step S180 is by just authorizing corresponding access
Control authority performs former step S190;If the result of the step of authentication is by not showing that authentication fails, returning
It returns and continues to execute step S170 or S140.
In biological characteristic validation result to pass through and then carrying out authentication, make access control only by being based on smart card
Biological characteristic validation single factor test determine, be promoted to by the biological characteristic validation based on smart card and knowledge based memory user
The dual factors of the authentication of name and password determine.In this way, the security of access control can be enhanced, can be emitted to avoid smart card
With or the security risk stolen of password.
Please continue to refer to Fig. 2, to further enhance the security of access control, in one of the embodiments, if described
Biological characteristic validation result is by the way that after step S145, step is further included before step S180:
S150:Random number is generated, the random number is sent to the smart card, and receives the smart card and recognized using identity
The ciphering sequence that card key generates after the random number and user name are encrypted.
Authentication key is that certification end is generated using the equipment Serial Number of smart card as dispersion factor, and in smart card point
When issuing user and carrying out personal settings, smart card is sent to, therefore, the authentication key of each smart card not phase
Together.User name can be to be stored in together with equipment Serial Number in smart card;Or by certification end receive retransmit to
Smart card.
S160:The ciphering sequence is decrypted in use certificate key, and judges the random number and use after decryption
Whether name in an account book is consistent with the random number of generation and the user name of storage.
Authentication key for when being verified, the server of certification end using the equipment Serial Number of smart card as disperse because
Sub and generation the estimated key identical with authentication key.
If the random number and user name after decryption are consistent with the random number and the user name of storage produced, illustrate equipment sequence
Row number, random number, user name are accurate.At this point it is possible to carry out subsequent authentication or operation, in the present embodiment, step is performed
S180。
If the random number and user name and the random number produced and the user name of storage after decryption are inconsistent, illustrate equipment
Sequence number, random number, user name at least one there are problems.At this point, display authentication failed, returns to S140 or S150.
In this way, carrying out the verification of random number, user name and key by challenge response pattern, access can be further enhanced
The security of control.Authentication key is identical with the dispersion factor that authentication key generates, and the two is theoretically identical
Key, therefore above-mentioned challenge response pattern is specially the challenge response pattern based on symmetric key.Challenge based on symmetric key
Answer-mode need not additionally increase Public Key Infrastructure in certification end, simple in structure, while verification process is simple.
Please continue to refer to Fig. 2, in one of the embodiments, before step S140, step is further included:
S130:The biometric feature of human body is received, and is stored into the smart card.
Smart card is carried by user oneself, so, it is ensured that the security of biometric feature.
Please continue to refer to Fig. 2, in one of the embodiments, before step S130, step is further included:
S110:The initial key of the smart card is received, and the initial secret key is verified.
Initial key is the key that smart card uses before personal settings are carried out, available for the true of verification smart card
It is pseudo-.If being verified, step S120 is performed;Otherwise, step S110 is continued to execute.
S120:Authentication key is generated according to the equipment Serial Number of the smart card, and it is close to send the authentication
Key is to the smart card.
After carrying out personal settings to smart card, initial key failure, subsequent operation uses the identity of personal settings
Authentication key is encrypted.In this way, the difference of different intelligent card can be increased by carrying out personal settings to smart card.
As shown in figure 3, the access control system based on biometric feature of one embodiment of the present invention, including:
Feature receives sending module 140, for receiving the biometric feature of human body, and by the bio-identification of the human body
Feature is sent to smart card and carries out biological characteristic validation.
The feature of certification end receives sending module 140 and gathers the biometric feature of human body, and receives bio-identification spy
Sign, but the biometric feature is not stored in certification end, but the biometric feature is sent to smart card.In this way, it keeps away
Exempt from the biometric feature in certification end leakage user.Smart card is preserved by user oneself, and biological characteristic validation is in smart card
Middle progress, therefore need not be transmitted in certification end preservation or grid, it ensure that the peace of the biometric feature of user
Quan Xing.The biological characteristic validation is specially with storing within a smart card by the smart card by the biometric feature received
Biometric feature carry out contrast verification.
In one of the embodiments, biometric feature is fingerprint.It is to be appreciated that it is hand, the shape of face, rainbow
The features such as film, retina, pulse, auricle.
Characteristic results receiving module 145, for receiving the biological characteristic validation result of smart card transmission.
If biological characteristic validation result is by performing access rights and authorizing module 190.If biological characteristic validation result
For not by then showing that biological characteristic validation fails, return continues to execute feature and receives sending module 140.
Access rights authorize module 190, for authorizing corresponding access control right.
In the present embodiment, according to the equipment Serial Number of smart card and biological characteristic validation as a result, authorizing and equipment sequence
Number corresponding access control right.
The above-mentioned access control system based on biometric feature, feature receive the biology that sending module 140 receives human body
Identification feature, and the biometric feature of the human body is sent to smart card and carries out biological characteristic validation;Characteristic results receive
Module 145 receives the biological characteristic validation result that smart card is sent;If the biological characteristic that the characteristic results receiving module receives
It is verified as by the way that access rights authorize module 190 and authorize corresponding access control right.Since the biometric feature of reception is sent out
It send to smart card and carries out biological characteristic validation, therefore, there is no need to transmit bio-identification spy in certification end preservation or grid
Sign can ensure the security of the biometric feature of user to a certain extent.
For enhance access control security, avoid to be certified people carry out personal injury, such as organ cutting, cause by
Donor is non-, and subjective agreement is licensed and is authorized for situation about accessing.In one of the embodiments, as shown in figure 4,
Further include user name password acceptance module 170 and authentication module 180.
User name password acceptance module 170, for receiving the username and password of typing.
In one of the embodiments, the biological characteristic validation result that only characteristic results receiving module 145 receives is logical
Out-of-date, user name password acceptance module 170 could receive the username and password of typing.Since if biological characteristic validation result is
Not by the way that need not carry out subsequent authentication can directly judge do not have any access rights, not allow to access, in this way, can
To reduce the unnecessary burden of system.
In another embodiment, if the biological characteristic validation result that characteristic results receiving module 145 receives is logical
It crosses, performs authentication module 180.
The authentication module 180, for the equipment sequence of the username and password according to reception and the smart card
Number carry out authentication.
Whether authentication module 180 corresponds to and uses according to the user name of reception and the equipment Serial Number of the smart card
Whether name in an account book and password are accurate and corresponding carry out authentication.
In the present embodiment, right-granting module 190 are additionally operable to receive institute before corresponding access control right is authorized
If the authentication of authentication module is stated as a result, the authentication that the authentication module 180 carries out is
By authorizing corresponding access control right;If authentication module 180 carry out the authentication for not by,
Show authentication failure, return continues to execute user name password acceptance module 170 or feature receives sending module 140.
It is to pass through and then pass through authentication in the biological characteristic validation result that characteristic results receiving module 145 receives
Module 180 carry out authentication, access control is made only to be determined by the biological characteristic validation single factor test based on smart card, be promoted to by
The dual factors of the authentication of the username and password of biological characteristic validation and knowledge based memory based on smart card determine.Such as
This, can enhance the security of access control, can be falsely used to avoid smart card or security risk that password is stolen.
Please continue to refer to Fig. 4, to further enhance the security of access control, in one of the embodiments, if feature
As a result receiving module 145 receive the biological characteristic validation result be by, further include random number generation module 150 with it is consistent
Property judgment module 160.
Random number generation module 150 for generating random number, sends the random number to the smart card, and receives institute
State the ciphering sequence generated after smart card is encrypted the random number and user name using authentication key.
Authentication key is that certification end is generated using the equipment Serial Number of smart card as dispersion factor, and in smart card point
When issuing user and carrying out personal settings, smart card is sent to, therefore, the authentication key of each smart card not phase
Together.User name can be to be stored in together with equipment Serial Number in smart card;Or by certification end receive retransmit to
Smart card.
Uniformity judgment module 160 is decrypted the ciphering sequence for use certificate key, and judges to solve
Whether the random number and user name after close are consistent with the random number of generation and the user name of storage.
Authentication key for when being verified, the server of certification end using the equipment Serial Number of smart card as disperse because
Sub and generation the estimated key identical with authentication key.
If the random number and user name after decryption are consistent with the random number and the user name of storage produced, illustrate equipment sequence
Row number, random number, user name are accurate.At this point it is possible to carry out subsequent authentication or operation.In the present embodiment, the identity is tested
Module 180 is demonstrate,proved, is additionally operable to receive the judging result of the uniformity judgment module 160 before authentication is carried out, if described
Judging result judges the random number and storage of random number and user name after decryption with generation for the uniformity judgment module 160
User name it is consistent, then carry out the authentication.
If the random number and user name and the random number produced and the user name of storage after decryption are inconsistent, illustrate equipment
Sequence number, random number, user name at least one there are problems.At this point, display authentication failed, backout feature receive sending module
140 or random number generation module 150.
In this way, carrying out the verification of random number, user name and key by challenge response pattern, access can be further enhanced
The security of control.Authentication key is identical with the dispersion factor that authentication key generates, and the two is theoretically identical
Key, therefore above-mentioned challenge response pattern is specially the challenge response pattern based on symmetric key.Challenge based on symmetric key
Answer-mode need not additionally increase Public Key Infrastructure in certification end, simple in structure, while verification process is simple.
Please continue to refer to Fig. 4, in one of the embodiments, further include:
First feature receiving module 130, for receiving the biometric feature of human body, and stores into the smart card.
Smart card is carried by user oneself, so, it is ensured that the security of biometric feature.
Please continue to refer to Fig. 4, in one of the embodiments, further include:
Initial key authentication module 110 for receiving the initial secret key of the smart card, and carries out the initial key
Verification.
Initial key is the key that smart card uses before personal settings are carried out, available for the true of verification smart card
It is pseudo-.If being verified, personal settings module 120 is performed;Otherwise, initial key authentication module 110 is continued to execute.
Personal settings module 120, for generating authentication key according to the equipment Serial Number of the smart card, concurrently
The authentication key is sent to the smart card.
After carrying out personal settings to smart card, initial key failure, subsequent operation uses the identity of personal settings
Authentication key is encrypted.In this way, the difference of different intelligent card can be increased by carrying out personal settings to smart card.
Above example only expresses the several embodiments of the present invention, and description is more specific and detailed, but can not
Therefore it is interpreted as the limitation to the scope of the claims of the present invention.It should be pointed out that for those of ordinary skill in the art,
Without departing from the inventive concept of the premise, multiple modification and improvement can also be made, these belong to the protection model of the present invention
It encloses.Therefore, the protection domain of patent of the present invention should be determined by the appended claims.