Background technology
Fingerprint recognition because of the numerous natural advantage of fingerprint recognition, is affecting daily life in field of biological recognition more and more, and fingerprint identification technology is also developing in depth.To Embedded fingerprint identification technology, fingerprint algorithm till now combines with safety chip, all emphasizes to carry out the security identification problem by the biological characteristic fingerprint from the fingerprint technique of application.
Information security is the problem that present and following computer industry is paid close attention to the most, realizes that by hardware it is the trend of technical development that information security is come the alternative software implementations information security.
Safety chip is the hottest theme of information security field in recent years, for example the most representative TPM safety chip, formulate standard, promote the credible platform module that develops by TPM (Trusted platform module) international organization, realize the thorough safety of computing machine by hardware.TPM (credible platform module, Trusted Platform Module), it is can improve at present the security of PC in the world, can improve the best technique of its ease for use again.TPM is actually a small-sized SOC (system on a chip) that contains crypto-operation parts and memory unit, fundamentally solves the safety problem of bottom hardware facility.The safety chip dominant ideas are based on trusted and calculate theory, based on to different bottoms authentications such as user identity, applied environment, network environment, prevent that thoroughly malice from stealing information and virus infraction.
It is similar to be used for the safety chip architecture that the safety chip of this patent and credible platform module TPM use.
Safety chip is a SOC (System-on-Chip) chip, the inner integrated modules such as microprocessor, RAM, ROM, volatile memory and nonvolatile memory, cryptographic algorithm coprocessor, random number generator that contain; Angle from software has chip core, compares inside with the chips such as DSP that do not have function of safety protection usually and has multiple encryption algorithms engine and safeguard procedures, can contain following encryption and safety function module usually:
Key management (key generation, key storage, key updating etc.);
Signature and authentication (RSA, ECC public key algorithms such as (p territories));
Tailor-made algorithm and high data rate encryption and decryption (DES/3DES algorithm and various special purpose system algorithm);
The safety detection protection module;
Safety chip system and supporting application software are mainly used in functions such as finishing computer platform authenticating user identification, digital signature, digital copyright management, reliability certification.Be used for the authentication of alternate user name and password with safety chip, the security that improves identity identifying and authenticating greatly, but there is potential safety hazard in safety chip external reference safety chip still by the mode of password and cryptographic algorithm.
By adopting biological identification technology to replace the pin mode of access security chip, can thoroughly stop the potential safety hazard that safety chip carries out authentication, realize the double strong factor authentication; And make full use of the advantage of biological characteristic, improved security and convenience greatly, realize end user's real name authentication simultaneously.
Safety chip based on fingerprint authenticates at present, be subjected to the restriction of chip Development Technology, biological identification technology, can be implemented in prestore identification of fingerprint sign indicating number and realize the comparison of fingerprint at chip internal of chip internal, and the operation of other fingerprint, outside auxiliary chipset is arranged or have upper strata operating system and application to finish such as fingerprint collecting, fingerprint processing, realize the safety identification authentication of higher level like this, but had certain potential safety hazard.
The utility model content
The purpose of this utility model is to have overcome above-mentioned shortcoming of the prior art, a kind of identity identifying and authenticating technology with fingerprint biological identification technology and safety chip seamless combination is provided, stop the possibility of illegal authenticated use and invasive system, can strengthen computer operating system and basic platform safety simultaneously to application layer.
Realize the safe, efficient authentication of each aspect of safety chip authentication, stop all potential safety hazards of safety chip, can combine by the secret of fingerprint identification technology and safety chip built-in various cryptographic algorithm, crypto engine and safety detection and realize.The fingerprint identification technology part is stored in the identification of fingerprint sign indicating number that prestores in the safety chip, and fingerprint collecting, fingerprint are handled and fingerprint comparison is all finished in safety chip inside, thereby realizes the double strong factor authentication.Simultaneously, board design is small and exquisite, strengthens ease for use, reaches more extensive market range of application.
In order to realize above-mentioned purpose, embedded single secure chip biological fingerprint recognition system of the present utility model is as follows:
A kind of embedded single secure chip biological fingerprint recognition system, comprise the safety chip and the electric power management circuit that are carried on circuit board and the circuit board, has build-in function unit and embedded chip operating system in the described safety chip, its principal feature is, the fingerprint sensor that described system also comprises on the circuit board being carried, the fingerprint comparison module that safety chip is built-in, finger print acquisition module, Fingerprint Processing Module and nonvolatile memory, the output terminal of described fingerprint sensor is connected with the input end of finger print acquisition module, the output terminal of finger print acquisition module is connected with the input end of described Fingerprint Processing Module, the output terminal of Fingerprint Processing Module is connected with the input end of described fingerprint comparison module, and described fingerprint comparison module is connected with described nonvolatile memory.
There are microprocessor and microprocessor management control module, volatibility and nonvolatile memory, various cryptographic algorithm and safety detection unit in described safety chip inside.
Described system also comprises input/output interface module.
Described IO interface can be USB (universal serial bus) socket USB, blue tooth interface Blue Tooth, safe digital interface SDIO (Security Digital IO) or compact flash card CF (Compact Flash).
Described system also comprises the companion chip group.
Described companion chip group comprises random access memory and latch (Latch).
Described nonvolatile memory is flash memory Flash, EEPROM (Electrically Erasable Programmable Read Only Memo) EEPROM, Erarable Programmable Read only Memory EPROM, programmable read only memory PROM or other the magnetic that can continue retention data under powering-off state, electric storage medium.
Described fingerprint sensor is flush-mounted on the circuit board or the package casing surface of single secure chip, and described fingerprint sensor is that optical fingerprint sensor, semiconductor fingerprint sensor, ultrasound wave fingerprint sensor or other can obtain fingerprint image data by induction; And suitable be flush-mounted on the circuit board or the package casing of single secure chip on fingerprint sensor.
Adopted the embedded single secure chip biological fingerprint recognition system of this utility model, owing on circuit board, formed a whole set of fingerprint bio-identification automotive engine system based on safety chip, this fingerprint bio-identification automotive engine system can receive other any system hardware layer, operating system and basic platform layer, the authentication request of Secure Application layer, and authentication result returned, thereby realized safe fingerprint biological identification, user and information integrity and private ownership have been guaranteed, guaranteed system hardware, the OS kernel, the integrality of service and application program, can be applied to the finger print safety authentication of starting shooting, fields such as operation system fingerprint safety identification authentication and the authentication of application layer finger print safety, not only operational efficiency is higher, and system stability is stronger, the scope of application is comparatively extensive, for further developing of safety identification of computer technology established solid foundation.
Embodiment
In order to further specify the utility model is to reach technology, method and the functional effect that predetermined purpose is adopted, see also following about detailed description of the present utility model and accompanying drawing, believe the purpose of this utility model, feature and characteristics, when obtaining deeply and concrete understanding, yet appended diagram is only for reference and explanation usefulness, and the utility model is limited.
Usually, in the square framework of safety chip, one microprocessor and microprocessor management control module, volatile storage (RAM etc.), non-volatile memories (Non-Volatile Storage), key management (key generation, key storage, key updating etc.), signature and authentication (RSA, ECC public key algorithms such as (p territories)), tailor-made algorithm and high data rate encryption and decryption (DES/3DES algorithm and various special purpose system algorithm), security protection, management and interface module or the like are arranged in the Generally Recognized as safe chip, thereby constituted the complete safe chip.
Safety chip forms the security of system authentication system by safety chip kernel and built-in functional module.In authentication, have the memory block in the safety chip, can Store Credentials, utilize the certificate and the various cryptographic algorithm that are stored in the sheet to finish safety certification usually.
The further ins and outs of the safety chip that uses about this patent, 03138380.7) and the patent documentation of " safety chip " (number of patent application: 200510056168.5) can please refer to referring to the similar TPM safety chip of architecture patent: the patent documentation of " a kind of safety chip and based on the information security treatment facility and the method for this chip " (number of patent application:.
See also shown in Figure 2, functional module framework figure for embedded single secure chip biological fingerprint recognition system of the present utility model, wherein this embedded single secure chip biological fingerprint recognition system comprises safety chip and the electric power management circuit that is carried on circuit board and the circuit board, and finger print acquisition module wherein, Fingerprint Processing Module, fingerprint comparison module and nonvolatile memory all are built in the described safety chip, this finger print acquisition module, Fingerprint Processing Module and fingerprint comparison module have formed the fingerprint bio-identification engine in the safety chip jointly, and between finger print acquisition module and the Fingerprint Processing Module, all be connected between Fingerprint Processing Module and the fingerprint comparison module, described fingerprint comparison module is connected with nonvolatile memory.
There are microprocessor and microprocessor management control module, volatibility and nonvolatile memory, various cryptographic algorithm and safety detection unit in described safety chip inside; Described system also comprises input/output interface module simultaneously, and this IO interface can be USB (universal serial bus) socket USB, blue tooth interface Blue Tooth, safe digital interface SDIO (Security Digital IO) or compact flash card CF (Compact Flash); And described system can also according to circumstances include the companion chip group, and this companion chip group comprises random access memory and latch (Latch).
The safety chip hardware resource of this moment can be finished fingerprint collecting, handle computing and fingerprint comparison function, its arithmetic capability CPU in the sheet that places one's entire reliance upon, and its internal memory then is the RAM that has utilized in the sheet.
Simultaneously, the nonvolatile memory of this embedded single secure chip biological fingerprint recognition system is flash memory Flash, EEPROM (Electrically Erasable Programmable Read Only Memo) EEPROM, Erarable Programmable Read only Memory EPROM, programmable read only memory PROM or other the magnetic that can continue retention data under powering-off state, electric storage medium.The detailed technology information of magnetic memory cell wherein sees also american documentation literature " Thin Film Magnetic Core Memory And Method Of Making Same ",
The patent No.: on June 30th, 5126971,1992 published.
In the middle of reality was used, embedded single chip finger print recognition system of the present utility model had multiple display form, and prevailing is exactly the very strong embedded single chip finger print KEY of versatility.This single-chip fingerprint KEY, overall appearance is small and exquisite, also littler than common USB flash disk, the hardware profile through the external mold encapsulation does not see also shown in Fig. 3 a and Fig. 3 b again, described system comprises fingerprint sensor 1, safety chip 2, latch 3, random access memory 4 and the USB (universal serial bus) socket USB module 5 of being carried on the circuit board 6, this USB (universal serial bus) socket USB module 5 has constituted input/output interface module, and this input/output interface module also can adopt serial interface module according to the occasion of concrete application; Simultaneously, described random access memory and latch have constituted memory module at random jointly.Wherein said fingerprint sensor 1 is flush-mounted on the circuit board or the package casing surface of single secure chip, described fingerprint sensor 1 can for semiconductor fingerprint sensor, ultrasound wave fingerprint sensor or other can by induction obtain fingerprint image data and suitable size is flush-mounted on the circuit board or the package casing of single secure chip on fingerprint sensor, described semiconductor fingerprint sensor is silicon capacitance fingerprint sensor, semiconductor pressure-sensitive fingerprint sensor or conductor temperature induction fingerprint sensor.Wherein the MCU among Fig. 4 is meant Micro Control Unit (micro-control unit), include simple software kernel, and this MCU uses and extends out the random access memory that Static RAM (static RAM) interface expands chip, make chip executive routine faster, and, form a high performance fingerprint KEY by the external fingerprint sensor of interface.
Above Fig. 3 and Fig. 4 are a special case in many specific embodiments.
In the middle of practical application, the utility model is to increase fingerprint biological identification engine in safety chip, and connect a fingerprint sensor, this fingerprint sensor is passed to the finger print image that collects the fingerprint biological identification engine finger print acquisition module of safety chip, the digital finger-print image that finger print acquisition module collects sends Fingerprint Processing Module to, carry out fingerprint characteristic value by Fingerprint Processing Module and extract, be encoded to fingerprint and debate the knowledge sign indicating number.
The fingerprint comparison module is debated fingerprint and is known the fingerprint that prestores in sign indicating number and the safety chip and debate to know and yard compare, and finishes authentication.
Key of the present utility model is to increase a bio-identification engine modules in safety chip, under the security context in safety chip be pre-stored in the safety chip identification of fingerprint sign indicating number and compare, realize the fingerprint comparison authentication.
In order to guarantee that system has high security, when utilizing safety chip to handle the collection of fingerprint and handling computing, the collection of fingerprint, processing and comparison work are all finished in safety chip.
Safety chip was not stepped out in pre-deposit data of fingerprint and comparison, realized the double strong factor safety certification.Fingerprint bio-identification engine receives the authentication request of other any system hardware layers, operating system and basic platform layer, Secure Application layer in the safety chip, authentication result is returned, realize safe fingerprint biological identification, guarantee user and information integrity and private ownership, guarantee system hardware, OS kernel,
Simultaneously, this fingerprint sensor 1 can obtain the sensor of fingerprint image data by induction for optical fingerprint sensor, semiconductor fingerprint sensor, ultrasound wave fingerprint sensor or other, and described semiconductor fingerprint sensor is silicon capacitance fingerprint sensor, semiconductor pressure-sensitive fingerprint sensor or conductor temperature induction fingerprint sensor.
In the middle of reality was used, this fingerprint sensor 1 can use various types of fingerprint sensors.Mainly comprise at present the fingerprint sensor of three kinds of big classes, be respectively: optics, semiconductor, ultrasound wave fingerprint sensor.Wherein the semiconductor-type fingerprint sensor is divided into again: sensors such as silicon capacitance, semiconductor pressure-sensitive, conductor temperature induction.Along with the development of technology, the sensor of newtype can constantly be released, and fingerprint collecting can use the various sensors that obtain fingerprint image data by induction to obtain the fingerprint image information in the utility model.
Biological fingerprint recognition system of the present utility model can be applied to numerous fingerprint field of biological recognition.Security fields are divided into three of national defense safeties, information security, physical security usually; Physical security and national defense safety all are based on the information security of computer system, information security is a core problem the most in the computer system security, relate to safety problem and the information encryption and the identification of operating system, database, network, access control, identification is the breakthrough point of information security.
Convenience such as the fingerprint biological identification technology is as the most ripe identity recognizing technology and carry, one " finger " settled are widely used in:
1) national defense safety such as E-Passport, entry-exit management field;
2) the digital memory device product of PC peripheral equipment and IT increases fingerprint identification function;
3) ecommerce, E-Government provide identity authentication identification trusty;
4) the fingerprint new way of paying of purchase commodity of directly settling accounts;
5) identity authentication of digital copyright protecting identification, common and PKI architecture combined realizes copyright protection;
6) identity and the real name transaction identification of mobile phone, mobile media player (PMP).
Application technology environment: multi-purpose computer, Embedded Application environment, ATM automatic teller machine, PDA, ambulatory handheld POS machine etc., mobile phone, mobile SPMP etc.
Simultaneously, biological fingerprint recognition system of the present utility model can be applied to different computer platforms, and and platform independence.
Computer platform: Windows, linux, Unix, Solaris, Mac OS, Unisys;
Mobile platform: Windows CE, Pocket PC, Symbian, SmartPhone, Palm, Linux.
The embedded chip hardware resource is very limited usually, chip internal CPU has only tens dominant frequency usually, random access memory (RAM) has only about 8K usually, nonvolatile memory (NVM) also has only about 8K usually, to in so narrow and small hardware resource, carry out the extraction of fingerprint image characteristics value, computing, comparison, core fingerprint algorithm, embedded program design are challenged.We are optimized, improve by constantly practice, and fingerprint algorithm is realized breakthrough innovation, cooperate the chip hardware designing technique to take the lead in realizing single-chip embedded fingerprint authentication recognition technology at home.
Adopted above-mentioned embedded single secure chip biological fingerprint recognition system, owing on circuit board, formed fingerprint bio-identification automotive engine system based on safety chip, and under the security context in safety chip be pre-stored in the safety chip fingerprint and compare, the authentication of realization fingerprint comparison, and collection, processing and the comparison work of fingerprint all finished, thereby obtain higher security of system and reliability in chip; Moreover, this fingerprint bio-identification automotive engine system can receive other any system hardware layer, operating system and basic platform layer, the authentication request of Secure Application layer, and authentication result returned, thereby realized safe fingerprint biological identification, user and information integrity and private ownership have been guaranteed, guaranteed system hardware, the OS kernel, the integrality of service and application program, can be applied to the finger print safety authentication of starting shooting, fields such as operation system fingerprint safety identification authentication and the authentication of application layer finger print safety, not only operational efficiency is higher, and system stability is stronger, the scope of application is comparatively extensive, for further developing of safety identification of computer technology established solid foundation.
In this instructions, the utility model is described with reference to its certain embodiments.But, still can make various modifications and conversion obviously and not deviate from spirit and scope of the present utility model.Therefore, instructions and accompanying drawing are regarded in an illustrative, rather than a restrictive.