HK1237149B - Identity recognition, service processing and biological feature information processing method and device - Google Patents
Identity recognition, service processing and biological feature information processing method and device Download PDFInfo
- Publication number
- HK1237149B HK1237149B HK17110830.4A HK17110830A HK1237149B HK 1237149 B HK1237149 B HK 1237149B HK 17110830 A HK17110830 A HK 17110830A HK 1237149 B HK1237149 B HK 1237149B
- Authority
- HK
- Hong Kong
- Prior art keywords
- user
- biometric information
- identification information
- information
- biometric
- Prior art date
Links
Description
技术领域Technical Field
本申请涉及网络信息安全领域,尤其涉及一种身份识别、业务处理以及生物特征信息的处理方法和设备。The present application relates to the field of network information security, and in particular to a method and device for identity recognition, business processing, and processing of biometric information.
背景技术Background Art
生物识别技术是将生物技术与信息技术相结合,利用人类生物特征信息进行身份识别和认证的一种新型识别技术。人类生物特征信息包括DNA信息、指纹信息、人脸信息、虹膜信息等,由于生物特征信息具备唯一性和不可复制等特点,使得基于生物特征信息的生物识别技术具有安全性、保密性、方便性等优点。Biometrics is a new type of identification technology that combines biotechnology with information technology, utilizing human biological characteristics for identification and authentication. Human biological characteristics include DNA, fingerprints, facial features, and iris data. Because biometric information is unique and cannot be replicated, biometrics based on biometric information offer advantages such as security, confidentiality, and convenience.
随着人们对生物识别技术研究的不断深入,在对用户身份进行识别和认证的业务场景中,生物识别技术被广泛应用。例如,在智能终端设备或穿戴式设备等终端设备上配备生物特征信息传感器,通过生物特征信息传感器采集到的生物特征信息对用户身份进行识别和认证。As research into biometrics continues to deepen, it's being widely applied in business scenarios for user identification and authentication. For example, biometric sensors can be installed on devices like smart terminals and wearables to identify and authenticate users using the biometric information they collect.
以智能终端设备为例,当用户通过智能终端设备上安装的应用程序发起支付业务时,首先,智能终端设备通过生物特征信息传感器采集用户的生物特征信息(比如指纹信息),其次,智能终端设备将采集到的用户的生物特征信息携带的支付请求发送至服务器,由服务器根据接收到的用户的生物特征信息对用户身份进行验证,并在验证通过时,响应智能终端设备发送的支付请求。Taking smart terminal devices as an example, when a user initiates a payment transaction through an application installed on the smart terminal device, first, the smart terminal device collects the user's biometric information (such as fingerprint information) through the biometric information sensor. Secondly, the smart terminal device sends the payment request carried by the collected user's biometric information to the server. The server verifies the user's identity based on the received user's biometric information, and responds to the payment request sent by the smart terminal device when the verification is successful.
然而,在现有利用生物识别技术对用户身份进行认证的过程中至少存在以下问题:However, there are at least the following problems in the existing process of authenticating user identities using biometric technology:
由于用户的生物特征信息由终端设备采集,并通过网络发送给服务器,由服务器通过对生物特征信息进行识别和验证,也就是说,假设终端设备发送给服务器的是一个非法的生物特征信息,这不仅增加了服务器的识别难度,而且也无法保证后续业务执行的安全性,进而影响了生物特征识别技术的安全性。Since the user's biometric information is collected by the terminal device and sent to the server through the network, the server identifies and verifies the biometric information. In other words, if the terminal device sends illegal biometric information to the server, this not only increases the difficulty of identification for the server, but also cannot guarantee the security of subsequent business execution, thereby affecting the security of biometric recognition technology.
发明内容Summary of the Invention
有鉴于此,本申请实施例提供了一种身份识别、业务处理以及生物特征信息的处理方法和设备,用于解决现有技术中存在的生物识别技术中安全性比较低的问题。In view of this, the embodiments of the present application provide a method and device for identity recognition, business processing, and processing of biometric information, which are used to solve the problem of relatively low security in biometric recognition technology in the prior art.
本申请提供了一种身份识别方法,包括:This application provides an identity identification method, including:
终端设备接收用户发送的业务处理请求,其中,所述业务处理请求中包含用户的标识信息以及所述用户的生物特征信息;The terminal device receives a service processing request sent by a user, wherein the service processing request includes user identification information and biometric information of the user;
所述终端设备根据所述业务处理请求中包含的用户的标识信息,从生物特征信息库中查找所述用户的标识信息对应的生物特征信息,其中,所述生物特征信息库中包含用户的标识信息以及所述用户的标识信息对应的生物特征信息;The terminal device searches, based on the user identification information included in the service processing request, for biometric information corresponding to the user identification information from a biometric information database, wherein the biometric information database includes the user identification information and the biometric information corresponding to the user identification information;
所述终端设备判断接收到的所述业务处理请求中包含的所述用户的生物特征信息与查找到的所述用户的标识信息对应的生物特征信息是否一致,并根据判断结果识别所述用户的身份是否合法。The terminal device determines whether the biometric information of the user included in the received service processing request is consistent with the biometric information corresponding to the found identification information of the user, and identifies whether the identity of the user is legal based on the determination result.
本申请提供了一种业务处理方法,包括:This application provides a business processing method, including:
服务器接收终端设备发送的业务处理请求,其中,所述业务处理请求中包含用户的生物特征信息对应的属性值和所述用户的标识信息;The server receives a service processing request sent by the terminal device, wherein the service processing request includes an attribute value corresponding to the user's biometric information and the identification information of the user;
所述服务器根据接收到的业务处理请求中包含的所述用户的标识信息,从生物识别数据库中查找所述用户的标识信息对应的生物特征信息的属性值,其中,所述生物识别数据库中包含所述用户的标识信息以及所述用户的标识信息对应的生物特征信息属性值;The server searches, based on the identification information of the user included in the received service processing request, a biometric database for an attribute value of the biometric information corresponding to the identification information of the user, wherein the biometric database includes the identification information of the user and the attribute value of the biometric information corresponding to the identification information of the user;
所述服务器在确定接收到的所述业务处理请求中包含的用户的生物特征信息对应的属性值与查找到的所述用户的标识信息对应的生物特征信息的属性值相同时,响应所述业务处理请求。The server responds to the service processing request when determining that the attribute value corresponding to the user's biometric information contained in the received service processing request is the same as the attribute value of the biometric information corresponding to the found identification information of the user.
本申请提供了一种生物特征信息的处理方法,包括:This application provides a method for processing biometric information, including:
终端设备接收用户发送的所述用户的标识信息以及所述用户的生物特征信息;The terminal device receives the user's identification information and the user's biometric information sent by the user;
所述终端设备根据所述用户的生物特征信息,利用预设算法,计算得到所述用户的生物特征信息的属性值;The terminal device calculates the attribute value of the user's biometric information using a preset algorithm based on the user's biometric information;
所述终端设备建立所述用户的标识信息、所述用户的生物特征信息以及所述用户的生物特征信息的属性值之间的对应关系,并将所述对应关系存储在所述生物特征信息库中。The terminal device establishes a correspondence between the user's identification information, the user's biometric information, and an attribute value of the user's biometric information, and stores the correspondence in the biometric information database.
本申请提供了一种生物特征信息的处理方法,包括:This application provides a method for processing biometric information, including:
所述服务器接收所述终端设备发送的用户信息,其中,所述用户信息是所述终端设备得到所述用户的生物特征信息的属性值时对所述用户的标识信息和所述用户的生物特征信息的属性值进行加密后发送的,所述用户信息中包含所述用户的标识信息和所述用户的生物特征信息的属性值;The server receives user information sent by the terminal device, wherein the user information is encrypted and sent by the terminal device after obtaining the attribute value of the user's biometric information by encrypting the user's identification information and the attribute value of the user's biometric information, and the user information includes the user's identification information and the attribute value of the user's biometric information;
所述服务器通过解密操作得到所述用户信息中包含的所述用户的生物特征信息的属性值和所述用户的标识信息;The server obtains the attribute value of the user's biometric information and the user's identification information contained in the user information through a decryption operation;
所述服务器建立所述用户的标识信息与所述用户的生物特征信息的属性值之间的对应关系,并将所述对应关系存储在所述生物识别数据库中。The server establishes a correspondence between the identification information of the user and the attribute value of the user's biometric information, and stores the correspondence in the biometric recognition database.
本申请提供了一种身份识别设备,包括:This application provides an identity recognition device, including:
接收单元,用于接收用户发送的业务处理请求,其中,所述业务处理请求中包含用户的标识信息以及所述用户的生物特征信息;a receiving unit, configured to receive a service processing request sent by a user, wherein the service processing request includes user identification information and biometric information of the user;
查找单元,用于根据所述业务处理请求中包含的用户的标识信息,从生物特征信息库中查找所述用户的标识信息对应的生物特征信息,其中,所述生物特征信息库中包含用户的标识信息以及所述用户的标识信息对应的生物特征信息;a search unit, configured to search, based on the user identification information included in the service processing request, for biometric information corresponding to the user identification information from a biometric information database, wherein the biometric information database includes the user identification information and the biometric information corresponding to the user identification information;
识别单元,用于判断所述接收单元接收到的所述业务处理请求中包含的所述用户的生物特征信息与所述查找单元查找到的所述用户的标识信息对应的生物特征信息是否一致,并根据判断结果识别所述用户的身份是否合法。The identification unit is used to determine whether the biometric information of the user contained in the business processing request received by the receiving unit is consistent with the biometric information corresponding to the identification information of the user found by the search unit, and to identify whether the identity of the user is legal based on the judgment result.
本申请提供了一种业务处理设备,包括:This application provides a service processing device, including:
接收单元,用于接收终端设备发送的业务处理请求,其中,所述业务处理请求中包含用户的生物特征信息对应的属性值和所述用户的标识信息;a receiving unit, configured to receive a service processing request sent by a terminal device, wherein the service processing request includes an attribute value corresponding to the user's biometric information and identification information of the user;
查找单元,用于根据所述接收单元接收到的业务处理请求中包含的所述用户的标识信息,从生物识别数据库中查找所述用户的标识信息对应的生物特征信息的属性值,其中,所述生物识别数据库中包含所述用户的标识信息以及所述用户的标识信息对应的生物特征信息的属性值;a search unit configured to search, based on the identification information of the user included in the service processing request received by the receiving unit, for an attribute value of the biometric information corresponding to the identification information of the user from a biometric database, wherein the biometric database includes the identification information of the user and the attribute value of the biometric information corresponding to the identification information of the user;
响应单元,用于确定接收到的所述业务处理请求中包含的用户的生物特征信息对应的属性值与查找到的所述用户的标识信息对应的生物特征信息的属性值相同时,响应所述业务处理请求。The responding unit is configured to respond to the service processing request when it is determined that the attribute value corresponding to the user's biometric information contained in the received service processing request is the same as the attribute value of the biometric information corresponding to the found user identification information.
本申请提供了一种生物特征信息的处理设备,包括:This application provides a biometric information processing device, including:
接收单元,用于接收用户发送的所述用户的标识信息以及所述用户的生物特征信息;a receiving unit, configured to receive identification information of the user and biometric information of the user sent by the user;
计算单元,用于根据所述用户的生物特征信息,利用预设算法,计算得到所述用户的生物特征信息的属性值;a calculation unit, configured to calculate an attribute value of the user's biometric information using a preset algorithm based on the user's biometric information;
存储单元,用于建立所述用户的标识信息、所述用户的生物特征信息以及所述用户的生物特征信息的属性值之间的对应关系,并将所述对应关系存储在所述生物特征信息库中。The storage unit is used to establish a correspondence between the identification information of the user, the biometric information of the user, and the attribute value of the biometric information of the user, and store the correspondence in the biometric information database.
本申请提供了一种生物特征信息的处理设备,包括:This application provides a biometric information processing device, including:
接收单元,用于接收所述终端设备发送的用户信息,其中,所述用户信息是所述终端设备得到所述用户的生物特征信息的属性值时对所述用户的标识信息和所述用户的生物特征信息的属性值进行加密后发送的,所述用户信息中包含所述用户的标识信息和所述用户的生物特征信息的属性值;a receiving unit, configured to receive user information sent by the terminal device, wherein the user information is encrypted after the terminal device obtains the attribute value of the user's biometric information by encrypting the user's identification information and the attribute value of the user's biometric information, and the user information includes the user's identification information and the attribute value of the user's biometric information;
解密单元,用于通过解密操作得到所述用户信息中包含的所述用户的生物特征信息的属性值和所述用户的标识信息;a decryption unit, configured to obtain, through a decryption operation, an attribute value of the user's biometric information and the user's identification information contained in the user information;
存储单元,用于建立所述用户的标识信息与所述用户的生物特征信息的属性值之间的对应关系,并将所述对应关系存储在所述生物识别数据库中。The storage unit is used to establish a correspondence between the identification information of the user and the attribute value of the biometric information of the user, and store the correspondence in the biometric recognition database.
本申请有益效果如下:The beneficial effects of this application are as follows:
本申请实施例提供了一种身份识别、业务处理以及生物特征信息的处理方法和设备,终端设备接收用户发送的业务处理请求,所述业务处理请求中包含用户的标识信息以及所述用户的生物特征信息;所述终端设备根据所述业务处理请求中包含的用户的标识信息,从生物特征信息库中查找所述用户的标识信息对应的生物特征信息,所述生物特征信息库中包含用户的标识信息以及所述用户的标识信息对应的生物特征信息;所述终端设备判断接收到的所述业务处理请求中包含的所述用户的生物特征信息与查找到的所述用户的标识信息对应的生物特征信息是否一致,并根据判断结果识别所述用户的身份是否合法。这样,终端设备在接收到用户发送的业务处理请求时,根据用户的生物特征信息对用户的身份进行识别,增强生物识别技术的安全性,同时为后续启动服务器对用户的身份进行识别奠定基础,此外,也避免用户的生物特征信息通过通信网络发送至服务器的过程中容易被非法窃取的风险,有效保证用户的生物特征信息的安全性。The embodiment of the present application provides a method and device for identity identification, business processing, and biometric information processing. A terminal device receives a business processing request sent by a user, wherein the business processing request includes the user's identification information and the user's biometric information. The terminal device searches for biometric information corresponding to the user's identification information from a biometric information database based on the user's identification information included in the business processing request. The biometric information database includes the user's identification information and the biometric information corresponding to the user's identification information. The terminal device determines whether the user's biometric information included in the received business processing request is consistent with the biometric information corresponding to the user's identification information found, and determines whether the user's identity is legitimate based on the judgment result. In this way, when the terminal device receives the business processing request sent by the user, the user's identity is identified based on the user's biometric information, thereby enhancing the security of biometric identification technology and laying the foundation for subsequent server authentication of the user. In addition, the terminal device avoids the risk of the user's biometric information being easily stolen during transmission to the server via the communication network, effectively ensuring the security of the user's biometric information.
附图说明BRIEF DESCRIPTION OF THE DRAWINGS
为了更清楚地说明本申请实施例中的技术方案,下面将对实施例描述中所需要使用的附图作简要介绍,显而易见地,下面描述中的附图仅仅是本申请的一部分实施例,对于本领域的普通技术人员来讲,在不付出创造性劳动性的前提下,还可以根据这些附图获得其他的附图。In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following is a brief introduction to the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only part of the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
图1为本申请实施例提供的一种身份识别方法流程示意图;FIG1 is a flow chart of an identity recognition method provided in an embodiment of the present application;
图2为本申请实施例提供的一种业务处理方法流程示意图;FIG2 is a flow chart of a business processing method provided in an embodiment of the present application;
图3为本申请实施例提供的一种生物特征信息的处理方法流程示意图;FIG3 is a flow chart of a method for processing biometric information provided in an embodiment of the present application;
图4为本申请实施例提供的一种生物特征信息的处理方法流程示意图;FIG4 is a flow chart of a method for processing biometric information provided in an embodiment of the present application;
图5为本申请实施例提供的一种身份识别设备结构示意图;FIG5 is a schematic diagram of the structure of an identity recognition device provided in an embodiment of the present application;
图6为本申请实施例提供的一种业务处理设备结构示意图;FIG6 is a schematic diagram of the structure of a service processing device provided in an embodiment of the present application;
图7为本申请实施例提供的一种生物特征信息的处理设备结构示意图;FIG7 is a schematic diagram of the structure of a biometric information processing device provided in an embodiment of the present application;
图8为本申请实施例提供的一种生物特征信息的处理设备结构示意图;FIG8 is a schematic diagram of the structure of a biometric information processing device provided in an embodiment of the present application;
图9为本申请实施例提供的一种身份识别系统的结构示意图。FIG9 is a schematic structural diagram of an identity recognition system provided in an embodiment of the present application.
具体实施方式DETAILED DESCRIPTION
随着人们对生物识别技术研究的不断深入,在需要对用户身份进行识别和认证的业务场景中,生物识别技术被广泛应用,随着科学技术的飞速发展,现有的终端设备已经配备了生物特征信息传感器,以便于用户在使用终端设备进行业务操作时,终端设备通过生物特征信息传感器采集用户的生物特征信息,并利用生物识别技术对用户的身份进行识别和认证。As people's research on biometric technology continues to deepen, biometric technology has been widely used in business scenarios where user identity identification and authentication are required. With the rapid development of science and technology, existing terminal devices have been equipped with biometric information sensors so that when users use terminal devices to perform business operations, the terminal devices collect the user's biometric information through the biometric information sensors and use biometric technology to identify and authenticate the user's identity.
为了实现提高生物特征信息的安全性的目的,本申请实施例中提供了一种身份识别、业务处理以及生物特征信息的处理方法和设备,终端设备接收用户发送的业务处理请求,所述业务处理请求中包含用户的标识信息以及所述用户的生物特征信息;所述终端设备根据所述业务处理请求中包含的用户的标识信息,从生物特征信息库中查找所述用户的标识信息对应的生物特征信息,所述生物特征信息库中包含用户的标识信息以及所述用户的标识信息对应的生物特征信息;所述终端设备判断接收到的所述业务处理请求中包含的所述用户的生物特征信息与查找到的所述用户的标识信息对应的生物特征信息是否一致,并根据判断结果识别所述用户的身份是否合法。In order to achieve the purpose of improving the security of biometric information, an embodiment of the present application provides a method and device for identity identification, business processing, and biometric information processing, wherein a terminal device receives a business processing request sent by a user, and the business processing request contains the user's identification information and the user's biometric information; the terminal device searches for the biometric information corresponding to the user's identification information from a biometric information database based on the user's identification information contained in the business processing request, and the biometric information database contains the user's identification information and the biometric information corresponding to the user's identification information; the terminal device determines whether the user's biometric information contained in the received business processing request is consistent with the biometric information corresponding to the found user's identification information, and identifies whether the user's identity is legal based on the judgment result.
这样,终端设备在接收到用户发送的业务处理请求时,根据用户的生物特征信息对用户的身份进行识别,增强生物识别技术的安全性,同时为后续启动服务器对用户的身份进行识别奠定基础,此外,也避免用户的生物特征信息通过通信网络发送至服务器的过程中容易被非法窃取的风险,有效保证用户的生物特征信息的安全性。In this way, when the terminal device receives a business processing request sent by the user, it identifies the user's identity based on the user's biometric information, thereby enhancing the security of the biometric technology and laying the foundation for the subsequent startup of the server to identify the user's identity. In addition, it also avoids the risk of the user's biometric information being easily illegally stolen during the process of being sent to the server through the communication network, effectively ensuring the security of the user's biometric information.
本申请实施例中所述的终端设备是指具有生物特征信息传感器的终端设备,用户在进行业务操作时,终端设备通过生物特征信息传感器采集用户的生物特征信息,其中,所述终端设备包括但不限于智能手机、电脑等终端设备。The terminal device described in the embodiments of the present application refers to a terminal device with a biometric information sensor. When a user performs business operations, the terminal device collects the user's biometric information through the biometric information sensor. The terminal device includes but is not limited to smartphones, computers and other terminal devices.
在本申请实施例中,用户的生物特征信息包括但不限于用户的DNA(英文全称:Deoxyribonucleic acid;中文名称:脱氧核糖核酸)信息、用户的指纹信息、用户的虹膜信息、用户的人脸信息、用户的视网膜信息、用户的掌形信息、用户的静脉信息、用户的耳型信息等,这里不做具体限定。In the embodiment of the present application, the user's biometric information includes but is not limited to the user's DNA (English full name: Deoxyribonucleic acid; Chinese name: deoxyribonucleic acid) information, the user's fingerprint information, the user's iris information, the user's face information, the user's retinal information, the user's palm shape information, the user's vein information, the user's ear shape information, etc., which are not specifically limited here.
下面结合说明书附图对本申请各个实施例作进一步地详细描述。显然,所描述的实施例仅是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其它实施例,都属于本申请保护的范围。The following is a further detailed description of various embodiments of the present application in conjunction with the accompanying drawings. Obviously, the described embodiments are only a portion of the embodiments of the present application, and not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present application without inventive effort are also within the scope of protection of this application.
图1为本申请实施例提供的一种身份识别方法流程示意图,所述方法如下所述。本申请实施例的执行主体可以是终端设备。Figure 1 is a flow chart of an identity recognition method provided by an embodiment of the present application, and the method is described as follows. The execution subject of the embodiment of the present application may be a terminal device.
步骤101:终端设备接收用户发送的业务处理请求。Step 101: The terminal device receives a service processing request sent by a user.
其中,所述业务处理请求中包含用户的标识信息以及所述用户的生物特征信息。The service processing request includes the user's identification information and the user's biometric information.
在步骤101中,用户使用终端设备进行业务操作时,为了保证用户信息的安全性,终端设备会提示用户输入验证信息。用户输入验证信息的方式可以包含用户直接输入验证码,也可以包含用户通过生物特征传感器输入用户的生物特征信息等,在本申请实施例中仅针对采集用户的生物特征信息进行描述。In step 101, when a user uses a terminal device to perform a service operation, the terminal device prompts the user to enter verification information to ensure the security of user information. The user can enter verification information by directly entering a verification code or by using a biometric sensor to enter the user's biometric information. In this embodiment of the application, only the collection of the user's biometric information is described.
具体地,终端设备通过生物特征信息传感器采集用户的生物特征信息视为用户输入的验证信息。Specifically, the terminal device collects the user's biometric information through the biometric information sensor and regards it as verification information input by the user.
例如:终端设备通过所述终端设备上的指纹信息传感器采集用户的指纹信息;或者终端设备通过所述终端设备上的人脸信息传感器采集用户的人脸信息;或者终端设备通过所述终端设备上的掌形信息传感器采集用户的掌形信息。For example: the terminal device collects the user's fingerprint information through the fingerprint information sensor on the terminal device; or the terminal device collects the user's face information through the face information sensor on the terminal device; or the terminal device collects the user's palm shape information through the palm shape information sensor on the terminal device.
在用户输入生物特征信息之后,触发用户向终端设备发送业务处理请求。终端设备接收所述用户发送的业务处理请求,其中,业务处理请求中包含所述用户的标识信息以及所述用户的生物特征信息。这样所述终端设备根据接收到的用户的生物特征信息,对用户的身份进行识别和认证。After the user enters their biometric information, the user is triggered to send a service request to the terminal device. The terminal device receives the service request, which includes the user's identification information and biometric information. The terminal device then identifies and authenticates the user based on the received biometric information.
下面以支付业务为例进行说明。在支付业务场景中,用户通过终端设备上的支付软件发起支付业务时,终端设备上的支付软件将提示用户输入支付验证信息,这里的支付验证信息限于用户的生物特征信息,那么此时,终端设备通过生物特征信息传感器采集用户的生物特征信息,以完成用户的生物特征信息的输入。在所述用户输入支付验证信息后,触发用户向终端设备发起支付业务处理请求,这里的所述支付业务处理请求中包含所述用户的标识信息以及所述用户的生物特征信息。The following uses payment services as an example. In a payment service scenario, when a user initiates a payment service through the payment software on a terminal device, the terminal device's payment software prompts the user to enter payment verification information. This payment verification information is limited to the user's biometric information. At this point, the terminal device collects the user's biometric information through a biometric information sensor to complete the user's biometric information input. After the user enters the payment verification information, the user is triggered to initiate a payment service processing request to the terminal device. This payment service processing request includes the user's identification information and the user's biometric information.
步骤102:所述终端设备根据所述业务处理请求中包含的用户的标识信息,从生物特征信息库中查找所述用户的标识信息对应的生物特征信息。Step 102: The terminal device searches for biometric information corresponding to the user identification information from a biometric information database based on the user identification information included in the service processing request.
其中,所述生物特征信息库中包含用户的标识信息以及所述用户的标识信息对应的生物特征信息。The biometric information database includes user identification information and biometric information corresponding to the user identification information.
在步骤102中,所述终端设备在接收到用户发送的业务处理请求时,确定所述业务处理请求中包含的所述用户的标识信息和所述用户的生物特征信息,并在生物特征信息库中,利用用户的标识信息查找与所述用户的标识信息对应的生物特征信息,以便于所述终端设备根据查找到的用户的标识信息对应的生物特征信息对用户的身份进行识别。In step 102, when the terminal device receives a business processing request sent by the user, it determines the user's identification information and the user's biometric information contained in the business processing request, and uses the user's identification information to search for biometric information corresponding to the user's identification information in the biometric information database, so that the terminal device can identify the user's identity based on the biometric information corresponding to the found user's identification information.
由于生物特征信息库中预先存储了用户的标识信息以及该用户的生物特征信息,这样终端设备在需要对用户的身份进行识别时,可以利用用户的标识信息在生物特征信息库中查找与该用户的标识信息对应的生物特征信息。Since the biometric information database pre-stores the user's identification information and the user's biometric information, when the terminal device needs to identify the user's identity, it can use the user's identification information to search the biometric information database for the biometric information corresponding to the user's identification information.
具体地,所述终端设备通过以下方式将所述用户的生物特征信息存储至所述生物特征信息库中:Specifically, the terminal device stores the user's biometric information in the biometric information database in the following manner:
第一步:所述终端设备接收所述用户发送的注册请求,并获取所述注册请求中包含的所述用户的生物特征信息和所述用户的标识信息。Step 1: The terminal device receives a registration request sent by the user, and obtains the user's biometric information and the user's identification information contained in the registration request.
用户在使用终端设备上的应用软件之前,需要在该应用软件上进行注册操作,即发送注册请求,一般注册请求中包含所述用户的标识信息和所述用户的生物特征信息,终端设备在接收到用户发送的注册请求时,能够从注册请求中获取用户的标识信息和用户的生物特征信息,并将用户的标识信息和所述用户的生物特征信息发送至应用软件对应的服务器,以完成用户在该应用软件中的注册。Before using the application software on the terminal device, the user needs to register on the application software, that is, send a registration request. Generally, the registration request contains the user's identification information and the user's biometric information. When the terminal device receives the registration request sent by the user, it can obtain the user's identification information and the user's biometric information from the registration request, and send the user's identification information and the user's biometric information to the server corresponding to the application software to complete the user's registration in the application software.
例如:用户需要使用终端设备上的支付应用软件,那么用户需要在该支付应用软件中进行注册,在支付应用软件的注册页面,用户输入标识信息和生物特征信息等注册信息,并发起注册请求。此时,终端设备接收该注册请求,并从注册请求中获取用户的标识信息以及用户的生物特征信息。此外,终端设备将用户的标识信息和所述用户的生物特征信息等注册信息进行加密处理后发送至支付应用软件的服务器,以完成用户在支付应用软件中的注册。For example, if a user wants to use a payment application on a terminal device, they must register with the payment application. On the payment application's registration page, the user enters registration information, including identification and biometric information, and initiates a registration request. The terminal device then receives the registration request and obtains the user's identification and biometric information from the request. Furthermore, the terminal device encrypts the user's identification and biometric information and sends it to the payment application's server, completing the user's registration with the payment application.
第二步:所述终端设备建立所述用户的标识信息与所述用户的生物特征信息之间的对应关系,并将所述对应关系存储在所述生物特征信息库中。Step 2: The terminal device establishes a correspondence between the user's identification information and the user's biometric information, and stores the correspondence in the biometric information database.
终端设备在获取到用户的标识信息和用户的生物与特征信息后,建立用户的标识信息和用户的生物特征信息之间的对应关系,并将用户的标识信息和用户的生物特征信息之间的对应关系存储在终端设备的生物特征信息库中,以便于终端设备根据用户的标识信息在所述生物特征信息库中查找与用户的标识信息对应的生物特征信息。After obtaining the user's identification information and the user's biological and characteristic information, the terminal device establishes a correspondence between the user's identification information and the user's biometric information, and stores the correspondence between the user's identification information and the user's biometric information in the terminal device's biometric information database, so that the terminal device can search for biometric information corresponding to the user's identification information in the biometric information database based on the user's identification information.
可选地,所述方法还包括:Optionally, the method further includes:
所述终端设备在获取到所述注册请求中包含的所述用户的生物特征信息时,利用预设算法,计算得到所述用户的生物特征信息的属性值。When the terminal device obtains the biometric information of the user included in the registration request, it calculates the attribute value of the biometric information of the user using a preset algorithm.
具体地,所述终端设备在获取到用户的注册信息中包含的用户的生物特征信息后,所述终端根据预设算法,根据用户的生物特征信息计算得到用户的生物特征信息的属性值,例如,所述终端设备利用Rijndael算法(密钥生成算法)计算得到用户的生物特征信息的属性值;所述终端设备利用Hash函数(散列函数)算法计算得到用户的生物特征信息的属性值;所述终端设备还可以利用其他计算机算法计算得到用户的生物特征信息的属性值,本申请实施例对所述终端设备采用的算法不作具体限定。Specifically, after the terminal device obtains the user's biometric information contained in the user's registration information, the terminal calculates the attribute value of the user's biometric information based on the user's biometric information according to a preset algorithm. For example, the terminal device uses the Rijndael algorithm (key generation algorithm) to calculate the attribute value of the user's biometric information; the terminal device uses the Hash function (hash function) algorithm to calculate the attribute value of the user's biometric information; the terminal device can also use other computer algorithms to calculate the attribute value of the user's biometric information. The embodiment of the present application does not specifically limit the algorithm adopted by the terminal device.
所述终端设备在计算得到所述用户的生物特征信息的属性值后,建立所述用户的标识信息、所述用户的生物特征信息以及所述用户的生物特征信息的属性值之间的对应关系。After calculating and obtaining the attribute value of the user's biometric information, the terminal device establishes a correspondence between the user's identification information, the user's biometric information, and the attribute value of the user's biometric information.
所述终端设备将所述用户的标识信息、所述用户的生物特征信息以及所述用户的生物特征信息的属性值之间的对应关系存储在所述生物特征信息库中。这样,在所述生物特征信息库中,所述终端设备可以根据所述用户的标识信息和上述对应关系,查找到与所述用户的标识信息对应的所述用户的生物特征信息和/或所述用户的标识信息对应的所述用户的生物特征信息的属性值。The terminal device stores the correspondence between the user's identification information, the user's biometric information, and the attribute value of the user's biometric information in the biometric information database. Thus, in the biometric information database, the terminal device can search for the user's biometric information corresponding to the user's identification information and/or the attribute value of the user's biometric information corresponding to the user's identification information based on the user's identification information and the correspondence.
可选地,终端设备可以对所述生物特征信息库中存储的用户的生物特征信息进行更新。Optionally, the terminal device may update the user's biometric information stored in the biometric information database.
具体地,所述终端设备中的所述生物特征信息库中存储的生物特征信息可以包含使用所述终端设备的所有用户的生物特征信息,也就是说,所述终端设备将接收到的所述用户发送的注册请求中包含的生物特征信息存储在所述生物特征信息库中之前,所述终端设备查询所述生物特征信息库中是否存储所述用户的标识信息对应的生物特征信息,若根据查询结果确定所述生物特征信息库中已经存储所述用户的生物特征信息,那么所述终端设备将接收到的所述用户发送的注册请求中包含的生物特征信息存储在所述生物特征信息库中,以更新在所述生物特征信息库中已经存储的所述用户的生物特征信息。Specifically, the biometric information stored in the biometric information database in the terminal device may include the biometric information of all users who use the terminal device. That is, before the terminal device stores the biometric information contained in the registration request sent by the user in the biometric information database, the terminal device queries whether the biometric information corresponding to the user's identification information is stored in the biometric information database. If it is determined according to the query result that the biometric information of the user has been stored in the biometric information database, then the terminal device stores the biometric information contained in the registration request sent by the user in the biometric information database to update the biometric information of the user already stored in the biometric information database.
需要说明的是,所述终端设备在更新所述生物特征信息库中已存储的所述用户的生物特征信息之前,提示用户输入用于验证用户身份的验证信息,比如,用户的验证邮箱、用户密码、用户预先存储在生物特征信息库中的生物特征信息等,所述终端设备在根据用户输入的验证信息验证用户的合法身份后,将接收到的所述用户的生物特征信息更新已存储的所述用户的生物特征信息,并将接收到的所述用户的标识信息、所述用户的生物特征信息以及所述用户的生物特征信息对应的属性值存储在所述生物特征信息库中。It should be noted that before updating the biometric information of the user stored in the biometric information database, the terminal device prompts the user to enter verification information for verifying the user's identity, such as the user's verification email, user password, and the user's biometric information pre-stored in the biometric information database. After verifying the user's legal identity based on the verification information entered by the user, the terminal device updates the stored biometric information of the user with the received biometric information of the user, and stores the received identification information of the user, the biometric information of the user, and the attribute values corresponding to the biometric information of the user in the biometric information database.
所述终端设备在查询到所述生物特征信息库中没有存储与所述用户的标识信息对应的用户的生物特征信息,将接收到的所述用户的注册请求中包含的所述用户的标识信息、所述用户的生物特征信息以及所述用户的生物特征信息对应的属性值存储在所述生物特征信息库中,也就是说,在所述生物特征信息库中增加存储所述用户的生物特征信息、所述用户的标识信息以及所述用户的生物特征信息的属性值。When the terminal device finds that the biometric information of the user corresponding to the identification information of the user is not stored in the biometric information database, the terminal device stores the identification information of the user, the biometric information of the user, and the attribute value corresponding to the biometric information of the user contained in the received registration request of the user in the biometric information database. That is, the terminal device adds the biometric information of the user, the identification information of the user, and the attribute value of the biometric information of the user to the biometric information database.
通过所述终端设备对所述生物特征信息库中的生物特征信息进行更新,一旦所述用户的生物特征信息被损坏或者丢失后,使得所述生物特征信息库及时将所述用户的新的生物特征信息更新原有的所述用户的生物特征信息,保证所述生物特征信息库中的生物特征信息的有效性,同时也能够保证所述终端设备根据所述用户发送的业务处理请求中包含的用户的标识信息,在所述生物特征信息库中查找所述用户的标识信息对应的所述用户的生物特征信息。The biometric information in the biometric information database is updated through the terminal device. Once the user's biometric information is damaged or lost, the biometric information database can promptly update the original biometric information of the user with the new biometric information of the user, thereby ensuring the validity of the biometric information in the biometric information database. At the same time, it can also ensure that the terminal device searches the biometric information database for the user's biometric information corresponding to the user's identification information based on the user's identification information contained in the business processing request sent by the user.
步骤103:所述终端设备判断接收到的所述业务处理请求中包含的所述用户的生物特征信息与查找到的所述用户的标识信息对应的生物特征信息是否一致,并根据判断结果识别所述用户的身份是否合法。Step 103: The terminal device determines whether the biometric information of the user included in the received service processing request is consistent with the biometric information corresponding to the found identification information of the user, and identifies whether the identity of the user is legal based on the determination result.
在步骤103中,终端设备在接收到用户的业务处理请求后,终端设备根据所述业务处理请求中包含的用户的标识信息,可以在所述生物特征信息库中确定所述用户的标识信息对应的生物特征信息,所述终端设备根据查找到的生物特征信息对用户的身份进行识别。In step 103, after receiving the user's business processing request, the terminal device can determine the biometric information corresponding to the user's identification information in the biometric information database based on the user's identification information contained in the business processing request, and the terminal device identifies the user's identity based on the found biometric information.
具体地,由于所述生物特征信息库中存储了用户的标识信息、用户的生物特征信息以及用户的生物特征信息的属性值之间的对应关系或者存储了用户的标识信息与所述用户的生物特征信息之间的对应关系,因此,所述终端设备可以根据所述用户的标识信息以及所述对应关系,在所述生物特征信息库中查找到所述用户的标识信息对应的生物特征信息。Specifically, since the biometric information database stores the correspondence between the user's identification information, the user's biometric information and the attribute value of the user's biometric information, or stores the correspondence between the user's identification information and the user's biometric information, the terminal device can search for the biometric information corresponding to the user's identification information in the biometric information database based on the user's identification information and the correspondence.
那么,所述终端设备判断接收到的所述用户的生物特征信息与查找到的所述用户的标识信息对应的生物特征信息是否一致,并根据判断结果识别所述用户的身份是否合法,包括:Then, the terminal device determines whether the received biometric information of the user is consistent with the biometric information corresponding to the found identification information of the user, and identifies whether the identity of the user is legal based on the determination result, including:
假设生物特征信息库中存储了用户的标识信息与所述用户的生物特征信息之间的对应关系,那么终端设备根据用户的标识信息从生物特征信息库中查找到与用户的标识信息对应的用户的生物特征信息,此时,所述终端设备在确定接收到的所述业务处理请求中包含的所述用户的生物特征信息与查找到的所述用户的标识信息对应的生物特征信息一致时,说明执行业务操作的用户和之前注册的用户是同一个人,识别所述用户的身份合法;Assuming that the biometric information database stores the correspondence between the user's identification information and the user's biometric information, the terminal device searches the biometric information database for the user's biometric information corresponding to the user's identification information based on the user's identification information. At this time, when the terminal device determines that the user's biometric information included in the received service processing request is consistent with the biometric information corresponding to the searched user's identification information, it indicates that the user performing the service operation is the same person as the previously registered user, and the identification of the user's identity is legal;
所述终端设备在确定接收到的所述业务处理请求中包含的所述用户的生物特征信息与查找到的所述用户的标识信息对应的生物特征信息不一致时,说明执行业务操作的用户和之前注册的用户不是同一个人,识别所述用户的身份非法。When the terminal device determines that the biometric information of the user contained in the received business processing request is inconsistent with the biometric information corresponding to the found identification information of the user, it means that the user performing the business operation and the previously registered user are not the same person, and the identification of the user's identity is illegal.
假设生物特征信息库中存储了用户的标识信息、用户的生物特征信息以及用户的生物特征信息对应的属性值之间的对应关系,那么终端设备根据用户的标识信息从生物特征信息库中查找到与用户的标识信息对应的用户的生物特征信息的属性值,此时,终端设备利用预设算法计算得到接收到的所述用户的生物特征信息的属性值,此时,所述终端设备在确定接收到的所述业务处理请求中包含的所述用户的生物特征信息的属性值与查找到的所述用户的标识信息对应的生物特征信息的属性值一致时,识别所述用户的身份合法;Assuming that a biometric information database stores a correspondence between the user's identification information, the user's biometric information, and the attribute value corresponding to the user's biometric information, the terminal device searches the biometric information database for the attribute value of the user's biometric information corresponding to the user's identification information based on the user's identification information. At this time, the terminal device calculates the attribute value of the received user's biometric information using a preset algorithm. At this time, when the terminal device determines that the attribute value of the user's biometric information contained in the received service processing request is consistent with the attribute value of the biometric information corresponding to the found user's identification information, it recognizes that the user's identity is legitimate.
所述终端设备在确定接收到的所述业务处理请求中包含的所述用户的生物特征信息的属性值与查找到的所述用户的标识信息对应的生物特征信息的属性值不一致时,识别所述用户的身份非法。When the terminal device determines that the attribute value of the user's biometric information included in the received service processing request is inconsistent with the attribute value of the biometric information corresponding to the found identification information of the user, the terminal device identifies that the identity of the user is illegal.
可选地,所述方法还包括:Optionally, the method further includes:
所述终端设备在识别所述用户的身份合法时,将所述属性值以及所述用户的标识信息携带在业务处理请求中发送至服务器。When the terminal device recognizes that the identity of the user is legitimate, it sends the attribute value and the identification information of the user to the server in a service processing request.
需要说明的是,在本申请实施例中,所述终端设备可以通过查找的方式确定所述用户的标识信息对应的生物特征信息的属性值,也可以通过利用预设的算法对所述用户的生物特征信息进行计算的方式确定所述用户的标识信息对应的生物特征信息的属性值,这里不做具体限定。It should be noted that in the embodiment of the present application, the terminal device can determine the attribute value of the biometric information corresponding to the user's identification information by searching, or it can determine the attribute value of the biometric information corresponding to the user's identification information by calculating the user's biometric information using a preset algorithm. No specific limitation is made here.
需要说明的是,所述终端设备在识别所述用户的身份合法后,向服务器发送业务处理请求,这里的业务处理请求和步骤101中所述用户发送的业务处理请求所代表的业务相同,但包含的内容不相同,这里的业务处理请求包含所述用户的标识信息、所述用户的生物特征信息以及所述用户的生物特征信息的属性值,步骤101中用户发送的业务处理请求包含所述用户的标识信息以及所述用户的生物特征信息。It should be noted that after the terminal device recognizes that the identity of the user is legitimate, it sends a business processing request to the server. The business processing request here is the same as the business represented by the business processing request sent by the user in step 101, but the content included is different. The business processing request here includes the user's identification information, the user's biometric information and the attribute value of the user's biometric information. The business processing request sent by the user in step 101 includes the user's identification information and the user's biometric information.
可选地,为了保证所述用户的生物特征信息的属性值在传输至服务器的过程中的安全性,所述终端设备将所述用户的生物特征信息的属性值和所述用户的标识信息执行加密操作,并将加密后的生物特征信息的属性值以及所述用户的标识信息发送至服务器。Optionally, in order to ensure the security of the attribute values of the user's biometric information during transmission to the server, the terminal device performs an encryption operation on the attribute values of the user's biometric information and the user's identification information, and sends the encrypted attribute values of the biometric information and the user's identification information to the server.
具体地,所述终端设备将所述用户的标识信息和确定的所述用户的生物特征信息对应的属性值进行加密,得到加密结果;Specifically, the terminal device encrypts the user identification information and the attribute value corresponding to the determined biometric information of the user to obtain an encryption result;
所述终端设备将携带所述加密结果的所述业务处理请求发送至服务器。The terminal device sends the service processing request carrying the encryption result to the server.
需要说明的是,所述终端设备和所述服务器通过协商之后分别得到各自的私钥和公钥,所述终端设备和所述服务器的私钥是保密的,所述终端设备和所述服务器的公钥是公开的,且所述终端设备/所述服务器的公钥和私钥是成对匹配的。It should be noted that the terminal device and the server obtain their respective private keys and public keys through negotiation. The private keys of the terminal device and the server are confidential, and the public keys of the terminal device and the server are public, and the public keys and private keys of the terminal device/the server are matched in pairs.
所述终端设备向所述服务器发送所述用户的生物特征信息的属性值和所述用户的标识信息时,利用所述服务器的公钥对发送的所述用户的生物特征信息的属性值和所述用户的标识信息进行加密,得到加密结果,并将加密结果发送至所述服务器。所述服务器利用自己的私钥对接收到的加密结果进行解密,由于所述服务器的私钥是保密的,因此,所述终端设备发送的加密结果只有所述服务器可以解密得到,保证所述终端设备发送的用户的生物特征信息的属性值的安全性。When the terminal device sends the attribute values of the user's biometric information and the user's identification information to the server, it encrypts the sent attribute values of the user's biometric information and the user's identification information using the server's public key to obtain an encrypted result, and sends the encrypted result to the server. The server decrypts the received encrypted result using its own private key. Because the server's private key is kept confidential, only the server can decrypt the encrypted result sent by the terminal device, thereby ensuring the security of the attribute values of the user's biometric information sent by the terminal device.
为了进一步保证用户的生物特征信息的属性值的安全性,所述终端设备在利用所述服务器的公钥对发送的加密结果进行加密后,所述终端设备还可以利用自己的私钥对发送的用户的生物特征信息的属性值进行第二次加密。这样,当所述服务器接收到加密结果后,首先利用所述终端设备的公钥对接收到的加密结果进行解密,如果所述服务器解密成功,说明所述服务器接收到的加密结果是由所述终端设备发送的,即所述终端设备发送的用户的生物特征信息的属性值在传递的过程中没有被篡改,然后所述服务器利用自己的私钥对加密结果进行解密,得到所述终端设备发送的用户的生物特征信息的属性值以及用户的标识信息。To further ensure the security of the attribute values of the user's biometric information, after the terminal device encrypts the sent encryption result using the server's public key, the terminal device can also use its own private key to encrypt the sent attribute values of the user's biometric information a second time. In this way, when the server receives the encrypted result, it first decrypts the received encryption result using the terminal device's public key. If the server decrypts successfully, it indicates that the encrypted result received by the server was sent by the terminal device, that is, the attribute values of the user's biometric information sent by the terminal device have not been tampered with during the transmission process. The server then decrypts the encrypted result using its own private key to obtain the attribute values of the user's biometric information and user identification information sent by the terminal device.
在本申请实施例中,所述终端设备将所述用户的标识信息对应的生物特征信息的属性值和所述用户的标识信息进行加密后,发送至所述服务器,不仅保证所述用户的标识信息对应的生物特征信息的属性值在传递过程中的安全性,并且,相比于现有技术中所述终端设备直接将用户的生物特征信息发送至所述服务器,本申请实施例中的所述终端设备将与用户的标识信息对应的生物特征信息的属性值发送至所述服务器,避免用户生物特征信息在传输过程中容易被他人获取的风险,提高用户的生物特征信息的安全性。In an embodiment of the present application, the terminal device encrypts the attribute value of the biometric information corresponding to the user's identification information and the user's identification information, and sends it to the server, which not only ensures the security of the attribute value of the biometric information corresponding to the user's identification information during the transmission process, but also, compared with the prior art in which the terminal device directly sends the user's biometric information to the server, the terminal device in the embodiment of the present application sends the attribute value of the biometric information corresponding to the user's identification information to the server, avoiding the risk of the user's biometric information being easily obtained by others during the transmission process, thereby improving the security of the user's biometric information.
可选地,所述终端设备在识别所述用户的身份非法时,向所述用户返回身份识别结果,拒绝响应所述用户的业务处理请求,并提示用户身份识别没有通过,例如,所述终端设备提示所述用户重新登录、所述终端设备显示告警信息并提示所述用户身份非法、所述终端设备直接返回所述用户的业务操作界面等,这里对所述终端设备向所述用户放回的身份识别结果的内容和形式不做具体限定。Optionally, when the terminal device identifies that the identity of the user is illegal, it returns the identity identification result to the user, refuses to respond to the user's business processing request, and prompts the user that the identity identification failed. For example, the terminal device prompts the user to log in again, the terminal device displays an alarm message and prompts that the user's identity is illegal, the terminal device directly returns to the user's business operation interface, etc. There is no specific limitation on the content and form of the identity identification result returned by the terminal device to the user.
通过本申请实施例所述的方案,终端设备在接收到用户发送的业务处理请求时,根据用户的生物特征信息对用户的身份进行识别,增强生物识别技术的安全性,同时为后续启动服务器对用户的身份进行识别奠定基础,此外,也避免用户的生物特征信息通过通信网络发送至服务器的过程中容易被非法窃取的风险,有效保证用户的生物特征信息的安全性。Through the solution described in the embodiment of the present application, when the terminal device receives a business processing request sent by the user, it identifies the user's identity based on the user's biometric information, thereby enhancing the security of the biometric technology and laying the foundation for the subsequent startup of the server to identify the user's identity. In addition, it also avoids the risk of the user's biometric information being easily illegally stolen during the process of being sent to the server through the communication network, effectively ensuring the security of the user's biometric information.
图2为本申请实施例提供的一种业务处理方法流程示意图,所述方法如下所述。本申请实施例的执行主体可以是服务器。Figure 2 is a flow chart of a service processing method provided by an embodiment of the present application, and the method is described as follows. The execution subject of the embodiment of the present application may be a server.
步骤201:服务器接收终端设备发送的业务处理请求。Step 201: The server receives a service processing request sent by a terminal device.
其中,所述业务处理请求中包含用户的生物特征信息对应的属性值和所述用户的标识信息。The service processing request includes the attribute value corresponding to the user's biometric information and the user's identification information.
在步骤201中,所述服务器接收所述终端设备发送的业务处理请求,业务处理请求中携带所述用户的标识信息和所述用户的标识信息对应的生物特征信息的属性值加密后的加密结果。In step 201, the server receives a service processing request sent by the terminal device, where the service processing request carries the user's identification information and an encrypted result of an attribute value of biometric information corresponding to the user's identification information.
所述服务器接收到所述终端设备发送的业务处理请求后,所述服务器对业务处理请求中包含的加密的所述用户的生物特征信息的属性值和所述用户的标识信息进行解密操作,并通过解密操作得到所述业务处理请求中包含的所述用户的生物特征信息的属性值和所述用户的标识信息。After the server receives the business processing request sent by the terminal device, the server decrypts the attribute values of the encrypted user's biometric information and the user's identification information contained in the business processing request, and obtains the attribute values of the user's biometric information and the user's identification information contained in the business processing request through the decryption operation.
所述服务器通过本申请提供的第一个实施例中的解密方法对所述加密后的所述用户的生物特征信息的属性值和所述用户的标识信息进行解密,这里不再重复描述。The server decrypts the encrypted attribute values of the user's biometric information and the user's identification information through the decryption method in the first embodiment provided in this application, which will not be repeated here.
所述服务器对加密结果进行解密后,得到所述终端设备发送的业务处理请求中包含的所述用户的的生物特征信息的属性值和所述用户的标识信息。After decrypting the encryption result, the server obtains the attribute value of the user's biometric information and the user's identification information contained in the service processing request sent by the terminal device.
步骤202:所述服务器根据接收到的业务处理请求中包含的所述用户的标识信息,从生物识别数据库中查找所述用户的标识信息对应的生物特征信息的属性值。Step 202: The server searches a biometric database for an attribute value of the biometric feature information corresponding to the user's identification information based on the user's identification information included in the received service processing request.
其中,所述生物识别数据库中包含所述用户的标识信息以及所述用户的标识信息对应的生物特征信息的属性值。The biometric database contains the identification information of the user and the attribute value of the biometric information corresponding to the identification information of the user.
在步骤202中,所述服务器在接收到所述终端设备发送的业务处理请求时,确定所述业务处理请求中包含的所述用户的标识信息和所述用户的生物特征信息的属性值,并在生物识别数据库中,利用用户的标识信息查找与所述用户的标识信息对应的生物特征信息的属性值,以便于所述服务器根据查找到的用户的标识信息对应的生物特征信息的属性值对用户的身份进行验证。In step 202, when the server receives the business processing request sent by the terminal device, it determines the user's identification information and the attribute value of the user's biometric information contained in the business processing request, and uses the user's identification information to search for the attribute value of the biometric information corresponding to the user's identification information in the biometric database, so that the server can verify the user's identity based on the attribute value of the biometric information corresponding to the user's identification information found.
由于生物识别数据库中预先存储了用户的标识信息以及该用户的生物特征信息的属性值,这样服务器在需要对用户的身份进行验证时,可以利用用户的标识信息在生物识别数据库中查找与该用户的标识信息对应的生物特征信息的属性值。Since the biometric database pre-stores the user's identification information and the attribute values of the user's biometric information, when the server needs to verify the user's identity, it can use the user's identification information to search the biometric database for the attribute values of the biometric information corresponding to the user's identification information.
具体地,所述服务器通过以下方式将所述用户的标识信息对应的生物特征信息的属性值存储至所述生物识别数据库中:Specifically, the server stores the attribute value of the biometric information corresponding to the identification information of the user in the biometric recognition database in the following manner:
第一步:所述服务器接收所述终端设备发送的用户信息。Step 1: The server receives the user information sent by the terminal device.
其中,所述用户信息是所述终端设备将用户发送的注册请求中包含的所述用户的标识信息和所述用户的生物特征信息的属性值进行加密后发送的,所述用户信息中包含所述用户的标识信息和所述用户的生物特征信息的属性值。Among them, the user information is sent by the terminal device after encrypting the user's identification information and the attribute values of the user's biometric information contained in the registration request sent by the user, and the user information contains the user's identification information and the attribute values of the user's biometric information.
由于终端设备在接收到用户发送的注册请求时,获取了注册请求中包含的所述用户的标识信息和所述用户的生物特征信息,并根据所述用户的生物特征信息确定所述用户的生物特征信息的属性值,进而通过对所述用户的生物特征信息的属性值和所述用户的标识信息进行加密,并将加密后的所述用户的生物特征信息的属性值和所述用户的标识信息发送至所述服务器,使得所述服务器接收到所述终端设备发送的加密后的所述用户的标识信息和所述用户的生物特征信息的属性值。When the terminal device receives the registration request sent by the user, it obtains the identification information and biometric information of the user contained in the registration request, and determines the attribute value of the user's biometric information based on the biometric information of the user, and then encrypts the attribute value of the user's biometric information and the identification information of the user, and sends the encrypted attribute value of the user's biometric information and the identification information of the user to the server, so that the server receives the encrypted identification information and biometric information of the user sent by the terminal device.
第二步:所述服务器通过解密操作得到所述用户信息中包含的所述用户的生物特征信息的属性值和所述用户的标识信息。Step 2: The server obtains the attribute value of the user's biometric information and the user's identification information contained in the user information through a decryption operation.
所述服务器利用所述终端设备的公钥对加密后的所述用户信息进行解密,验证业务处理请求是否是所述终端设备发送的,验证通过后,所述服务器确定携带所述加密结果的注册处理请求在传递的过程中没有被篡改,所述服务器利用自己的公钥对加密进行第二次解密,所述服务器得到所述用户的生物特征信息的属性值和所述用户的标识信息。The server uses the public key of the terminal device to decrypt the encrypted user information and verify whether the business processing request is sent by the terminal device. After the verification is passed, the server determines that the registration processing request carrying the encryption result has not been tampered with during the transmission process. The server uses its own public key to decrypt the encryption for the second time, and the server obtains the attribute value of the user's biometric information and the user's identification information.
第三步:所述服务器建立所述用户的标识信息与所述用户的生物特征信息的属性值之间的对应关系,并将所述对应关系存储在所述生物识别数据库中。Step 3: The server establishes a correspondence between the user's identification information and the attribute value of the user's biometric information, and stores the correspondence in the biometric recognition database.
所述服务器在得到所述用户的生物特征信息的属性值以及所述用户的标识信息后,建立所述用户的标识信息以及所述用户的生物特征信息的属性值之间的对应关系,并将所述用户的标识信息以及所述用户的生物特征信息的属性值之间的对应关系存储在所述服务器中的所述生物识别数据库中。After obtaining the attribute value of the user's biometric information and the user's identification information, the server establishes a correspondence between the user's identification information and the attribute value of the user's biometric information, and stores the correspondence between the user's identification information and the attribute value of the user's biometric information in the biometric recognition database in the server.
这样,在所述生物识别数据库中,所述服务器可以根据所述用户的标识信息和上述对应关系,查找到与所述用户的标识信息对应的所述用户的生物特征信息的属性值。In this way, in the biometric database, the server can find the attribute value of the user's biometric information corresponding to the user's identification information based on the user's identification information and the above-mentioned correspondence.
可选地,服务器在接收到终端设备发送的用户的标识信息和所述用户的生物特征信息的属性值时,首先,确定生物识别数据库中是否已存储与所述用户的标识信息对应的用户的生物特征信息的属性值;其次,在确定已存储与所述用户的标识信息对应的用户的生物特征信息的属性值时,可以利用接收到的用户的生物特征信息的属性值更新已存储的用户的生物特征信息的属性值;在确定未存储与所述用户的标识信息对应的用户的生物特征信息的属性值时,可以将接收到的用户的生物特征信息的属性值存储至生物识别数据库中,以便于后续对用户的身份进行识别。Optionally, when the server receives the user's identification information and the attribute value of the user's biometric information sent by the terminal device, it first determines whether the attribute value of the user's biometric information corresponding to the user's identification information has been stored in the biometric database; secondly, when it is determined that the attribute value of the user's biometric information corresponding to the user's identification information has been stored, it can use the received attribute value of the user's biometric information to update the stored attribute value of the user's biometric information; when it is determined that the attribute value of the user's biometric information corresponding to the user's identification information has not been stored, it can store the received attribute value of the user's biometric information in the biometric database to facilitate subsequent identification of the user's identity.
步骤203:所述服务器在确定接收到的所述业务处理请求中包含的用户的生物特征信息对应的属性值与查找到的所述用户的标识信息对应的生物特征信息的属性值相同时,响应所述业务处理请求。Step 203: When the server determines that the attribute value corresponding to the user's biometric information contained in the received service processing request is the same as the attribute value of the biometric information corresponding to the found user identification information, the server responds to the service processing request.
具体地,由于所述生物识别数据库中存储了用户的标识信息与用户的生物特征信息属性值之间的对应关系,因此,所述服务器可以根据所述用户的标识信息以及所述对应关系,在所述生物识别数据库中查找到所述用户的标识信息对应的生物特征信息的属性值。Specifically, since the biometric database stores the correspondence between the user's identification information and the user's biometric information attribute value, the server can search the biometric database for the attribute value of the biometric information corresponding to the user's identification information based on the user's identification information and the correspondence.
那么,所述服务器在所述生物识别数据库中查找到所述用户的标识信息对应的所述用户的生物特征信息的属性值后,所述服务器将接收到的所述用户的生物特征信息的属性值与查找到的所述用户的标识信息对应的生物特征信息的属性值进行对比,包括:Then, after the server finds the attribute value of the user's biometric information corresponding to the user's identification information in the biometric database, the server compares the received attribute value of the user's biometric information with the attribute value of the biometric information corresponding to the found user's identification information, including:
所述服务器确定接收到的所述用户的生物特征信息的属性值与查找到的所述用户的生物特征信息的属性值相同,说明执行业务操作的用户和之前注册的用户是同一个人,所述服务器对验证所述用户的身份合法,所述服务器响应接收到的所述终端设备发送的业务处理请求;The server determines that the attribute value of the received biometric information of the user is the same as the attribute value of the found biometric information of the user, indicating that the user performing the service operation and the previously registered user are the same person. The server verifies the legitimacy of the user's identity and responds to the service processing request sent by the terminal device.
所述服务器确定接收到的所述用户的生物特征信息的属性值与查找到的所述用户的生物特征信息的属性值不相同,说明执行业务操作的用户和之前注册的用户不是同一个人,所述服务器验证所述用户的身份非法,所述服务器拒绝响应接收到的所述终端设备发送的业务处理请求。The server determines that the attribute value of the received biometric information of the user is different from the attribute value of the biometric information of the user found, indicating that the user performing the business operation and the previously registered user are not the same person. The server verifies that the identity of the user is illegal, and the server refuses to respond to the business processing request sent by the terminal device.
可选地,所述服务器验证所述用户的身份非法后,提示所述终端设备所述用户的身份非法,并返回告警信息,告警业务处理请求处理失败,这里对所述服务器返回告警信息的内容和形式不作具体限定。Optionally, after the server verifies that the identity of the user is illegal, it prompts the terminal device that the identity of the user is illegal and returns an alarm message, indicating that the service processing request has failed. The content and form of the alarm message returned by the server are not specifically limited here.
图3为本申请实施例提供的一种生物特征信息的处理方法流程示意图,所述方法如下所述。本申请实施例的执行主体可以是终端设备。FIG3 is a flow chart of a method for processing biometric information provided by an embodiment of the present application, and the method is described as follows. The execution subject of the embodiment of the present application may be a terminal device.
步骤301:终端设备接收用户发送的所述用户的标识信息以及所述用户的生物特征信息。Step 301: The terminal device receives the user's identification information and the user's biometric information sent by the user.
在步骤301中,用户发送的用户的标识信息和用户的生物特征信息可以是用户在注册应用软件时发送的,也可以是用户在执行其他操作时发送的,这里不做具体限定。In step 301, the user identification information and the user biometric information sent by the user may be sent by the user when registering the application software, or may be sent by the user when performing other operations, which are not specifically limited here.
终端设备接收用户发送的用户的标识信息和用户的生物特征信息,以便于终端设备对用户的生物特征信息进行处理。The terminal device receives the user's identification information and the user's biometric information sent by the user, so that the terminal device processes the user's biometric information.
步骤302:所述终端设备根据所述用户的生物特征信息,利用预设算法,计算得到所述用户的生物特征信息的属性值。Step 302: The terminal device calculates the attribute value of the user's biometric information using a preset algorithm based on the user's biometric information.
所述终端设备根据所述用户的生物特征信息,利用本申请提供的第一个实施例中的预设算法,计算得到所述用户的生物特征信息的属性值,这里不再重复描述。The terminal device calculates the attribute value of the user's biometric information based on the user's biometric information using the preset algorithm in the first embodiment provided in this application, which will not be repeated here.
可选地,所述终端设备得到所述用户的生物特征信息的属性值后,将所述用户的标识信息以及所述用户的生物特征信息的属性值进行加密,得到加密结果,并将所述终端设备将所述加密结果发送至所述服务器。Optionally, after obtaining the attribute value of the user's biometric information, the terminal device encrypts the user's identification information and the attribute value of the user's biometric information to obtain an encryption result, and the terminal device sends the encryption result to the server.
本申请实施例中的所述终端设备使用本申请提供的第一个实施例中的加密方法对用户的生物特征信息的属性值和用户的标识信息进行加密,这里不再重复描述。The terminal device in the embodiment of the present application uses the encryption method in the first embodiment provided in the present application to encrypt the attribute values of the user's biometric information and the user's identification information, which will not be repeated here.
步骤303:所述终端设备建立所述用户的标识信息、所述用户的生物特征信息以及所述用户的生物特征信息的属性值之间的对应关系,并将所述对应关系存储在所述生物特征信息库中。Step 303: The terminal device establishes a correspondence between the user's identification information, the user's biometric information, and the attribute value of the user's biometric information, and stores the correspondence in the biometric information database.
在步骤303中所述终端设备将用户的标识信息、所述用户的生物特征信息以及所述用户的生物特征信息的属性值之间的对应关系存储在所述生物特征信息库中之前,所述终端设备在所述生物特征信息库中查询是否存在所述用户的生物特征信息,若所述生物特征信息库中可能已经存储所述用户的生物特征信息,那么所述终端设备将接收到的用户发送的生物特征信息存储在所述生物特征信息库中,以更新在所述生物特征信息库中已经存储的所述用户的生物特征信息。In step 303, before the terminal device stores the correspondence between the user's identification information, the user's biometric information and the attribute value of the user's biometric information in the biometric information database, the terminal device queries whether the user's biometric information exists in the biometric information database. If the user's biometric information may have been stored in the biometric information database, the terminal device stores the biometric information sent by the user in the biometric information database to update the user's biometric information already stored in the biometric information database.
具体地,所述终端设备向所述生物特征信息库发送查询请求,其中,所述查询请求中包含所述用户的标识信息;Specifically, the terminal device sends a query request to the biometric information database, wherein the query request includes the identification information of the user;
所述终端设备接收所述生物特征信息库返回的查询结果;The terminal device receives the query result returned by the biometric information database;
所述终端设备根据查询结果确定在所述生物特征信息库中已存储与所述用户的标识信息对应的用户的生物特征信息,利用接收到的所述用户的生物特征信息更新所述生物特征信息库中已存储与所述用户的标识信息对应的用户的生物特征信息。The terminal device determines, based on the query result, that the biometric information of the user corresponding to the identification information of the user has been stored in the biometric information database, and uses the received biometric information of the user to update the biometric information of the user corresponding to the identification information of the user stored in the biometric information database.
这里的生物特征信息库的更新方式与本申请提供的第一个实施例中的生物特征信息库的更新方式相同,不再重复描述。The updating method of the biometric information database here is the same as the updating method of the biometric information database in the first embodiment provided in this application, and will not be described again.
所述终端设备在确定所述生物特征信息库中没有存储所述用户的生物特征信息,那么所述终端设备确定接收到的所述生物特征信息的属性值,并在所述生物特征信息库增加存储所述用户的生物特征信息、所述用户的标识信息以及所述用户的生物特征信息的属性值之间的对应关系。When the terminal device determines that the biometric information of the user is not stored in the biometric information database, the terminal device determines the attribute value of the received biometric information and adds a correspondence between the biometric information of the user, the identification information of the user and the attribute value of the biometric information of the user to the biometric information database.
图4为本申请实施例提供的一种生物特征信息的处理方法流程示意图,所述方法如下所述。FIG4 is a flow chart of a method for processing biometric information provided in an embodiment of the present application, and the method is described as follows.
步骤401:所述服务器接收所述终端设备发送的用户信息。Step 401: The server receives user information sent by the terminal device.
其中,所述用户信息是所述终端设备得到所述用户的生物特征信息的属性值时对所述用户的标识信息和所述用户的生物特征信息的属性值进行加密后发送的,所述用户信息中包含所述用户的标识信息和所述用户的生物特征信息的属性值。Among them, the user information is sent after the terminal device encrypts the user's identification information and the attribute value of the user's biometric information when obtaining the attribute value of the user's biometric information. The user information contains the user's identification information and the attribute value of the user's biometric information.
步骤402:所述服务器通过解密操作得到所述用户信息中包含的所述用户的生物特征信息的属性值和所述用户的标识信息。Step 402: The server obtains the attribute value of the user's biometric information and the user's identification information contained in the user information through a decryption operation.
所述服务器通过本申请提供的第一个实施例中的解密方法对所述加密后的所述用户的生物特征信息的属性值和所述用户的标识信息进行解密,这里不再重复描述。The server decrypts the encrypted attribute values of the user's biometric information and the user's identification information through the decryption method in the first embodiment provided in this application, which will not be repeated here.
所述服务器对所述用户信息解密后,得到所述用户信息中包含的所述用户的生物特征信息的属性值和所述用户的标识信息。After decrypting the user information, the server obtains the attribute value of the user's biometric information and the user's identification information contained in the user information.
步骤403:所述服务器建立所述用户的标识信息与所述用户的生物特征信息的属性值之间的对应关系,并将所述对应关系存储在所述生物识别数据库中。Step 403: The server establishes a correspondence between the user's identification information and the attribute value of the user's biometric information, and stores the correspondence in the biometric recognition database.
所述服务器在得到所述用户的生物特征信息的属性值以及所述用户的标识信息后,建立所述用户的标识信息以及所述用户的生物特征信息的属性值之间的对应关系,并将所述用户的标识信息以及所述用户的生物特征信息的属性值对应存储在所述服务器中的所述生物识别数据库中。After obtaining the attribute value of the user's biometric information and the user's identification information, the server establishes a correspondence between the user's identification information and the attribute value of the user's biometric information, and stores the user's identification information and the attribute value of the user's biometric information in the biometric recognition database in the server.
可选地,所述服务器还可以对所述生物识别数据库中存储的用户的生物特征信息进行更新,更新的具体实现方式与图2中步骤202中所使用的方式相同,这里不再赘述。Optionally, the server may also update the biometric information of the user stored in the biometric database. The specific implementation method of the update is the same as that used in step 202 in Figure 2 and will not be repeated here.
图5为本申请实施例提供的一种身份识别设备结构示意图。所述身份识别设备包括:接收单元51、查找单元52、识别单元53、发送单元54、建立单元55、计算单元56和返回单元57,其中:Figure 5 is a schematic diagram of the structure of an identity recognition device provided by an embodiment of the present application. The identity recognition device includes: a receiving unit 51, a search unit 52, an identification unit 53, a sending unit 54, an establishment unit 55, a calculation unit 56 and a return unit 57, wherein:
接收单元51,用于接收用户发送的业务处理请求,其中,所述业务处理请求中包含用户的标识信息以及所述用户的生物特征信息;A receiving unit 51 is configured to receive a service processing request sent by a user, wherein the service processing request includes user identification information and biometric information of the user;
查找单元52,用于根据所述业务处理请求中包含的用户的标识信息,从生物特征信息库中查找所述用户的标识信息对应的生物特征信息,其中,所述生物特征信息库中包含用户的标识信息以及所述用户的标识信息对应的生物特征信息;a search unit 52 configured to search, based on the user identification information included in the service processing request, for biometric information corresponding to the user identification information from a biometric information database, wherein the biometric information database includes the user identification information and the biometric information corresponding to the user identification information;
识别单元53,用于判断所述接收单元51接收到的所述业务处理请求中包含的所述用户的生物特征信息与所述查找单元查找到的所述用户的标识信息对应的生物特征信息是否一致,并根据判断结果识别所述用户的身份是否合法。The identification unit 53 is used to determine whether the biometric information of the user contained in the business processing request received by the receiving unit 51 is consistent with the biometric information corresponding to the identification information of the user found by the search unit, and to identify whether the identity of the user is legal based on the judgment result.
可选地,所述身份识别设备还包括:发送单元54,其中:Optionally, the identity recognition device further includes a sending unit 54, wherein:
所述发送单元54,用于在识别所述用户的身份合法时,确定所述用户的生物特征信息的属性值,并将所述属性值以及所述用户的标识信息携带在业务处理请求中发送至服务器。The sending unit 54 is configured to determine the attribute value of the user's biometric information when the user's identity is recognized to be legitimate, and send the attribute value and the user's identification information to the server in a service processing request.
具体地,所述发送单元54将所述属性值以及所述用户的标识信息携带在业务处理请求中发送至服务器,包括:Specifically, the sending unit 54 carries the attribute value and the user's identification information in the service processing request and sends it to the server, including:
将所述用户的标识信息和所述属性值进行加密,得到加密结果;Encrypting the user's identification information and the attribute value to obtain an encryption result;
将携带所述加密结果的业务处理请求发送至服务器。Sending a service processing request carrying the encryption result to the server.
可选地,所述身份识别设备还包括:建立单元55,其中:Optionally, the identity recognition device further includes: an establishing unit 55, wherein:
所述接收单元51,还用于接收所述用户发送的注册请求,并获取所述注册请求中包含的所述用户的生物特征信息和所述用户的标识信息;The receiving unit 51 is further configured to receive a registration request sent by the user and obtain the user's biometric information and the user's identification information contained in the registration request;
所述建立单元55,用于建立所述用户的标识信息与所述用户的生物特征信息之间的对应关系,并将所述对应关系存储在所述生物特征信息库中。The establishing unit 55 is configured to establish a correspondence between the user's identification information and the user's biometric information, and store the correspondence in the biometric information database.
可选地,诉述身份识别设备还包括:计算单元56,其中:Optionally, the identity recognition device further comprises: a computing unit 56, wherein:
所述计算单元56,用于在获取到所述注册请求中包含的所述用户的生物特征信息时,利用预设算法,计算得到所述用户的生物特征信息的属性值;The calculation unit 56 is configured to calculate the attribute value of the user's biometric information by using a preset algorithm when obtaining the user's biometric information included in the registration request;
所述建立单元55建立所述用户的标识信息与所述用户的生物特征信息之间的对应关系,包括:The establishing unit 55 establishes a correspondence between the user's identification information and the user's biometric information, including:
建立所述用户的标识信息、所述用户的生物特征信息以及所述用户的生物特征信息的属性值之间的对应关系。A correspondence between the user's identification information, the user's biometric information, and the attribute value of the user's biometric information is established.
可选地,所述身份识别设备还包括:返回单元57,其中:Optionally, the identity recognition device further includes a returning unit 57, wherein:
所述返回单元57,用于在所述识别单元53识别所述用户的身份非法时,向所述用户返回身份识别结果。The returning unit 57 is configured to return an identity recognition result to the user when the identifying unit 53 identifies that the user's identity is illegal.
需要说明的是,本申请实施例提供的身份识别设备可以通过硬件方式实现,也可以通过软件方式实现,这里不做具体限定。It should be noted that the identity recognition device provided in the embodiment of the present application can be implemented by hardware or software, and no specific limitation is made here.
图6为本申请实施例提供的一种业务处理设备结构示意图。所述业务处理设备包括:接收单元61、查找单元62、响应单元63、解密单元64和建立单元65,其中:FIG6 is a schematic diagram of the structure of a service processing device provided in an embodiment of the present application. The service processing device includes: a receiving unit 61, a search unit 62, a response unit 63, a decryption unit 64 and an establishment unit 65, wherein:
接收单元61,用于接收终端设备发送的业务处理请求,其中,所述业务处理请求中包含用户的生物特征信息对应的属性值和所述用户的标识信息;A receiving unit 61 is configured to receive a service processing request sent by a terminal device, wherein the service processing request includes an attribute value corresponding to a user's biometric information and identification information of the user;
查找单元62,用于根据所述接收单元61接收到的业务处理请求中包含的所述用户的标识信息,从生物识别数据库中查找所述用户的标识信息对应的生物特征信息的属性值,其中,所述生物识别数据库中包含所述用户的标识信息以及所述用户的标识信息对应的生物特征信息的属性值;a search unit 62 configured to search, based on the user identification information included in the service processing request received by the receiving unit 61, for an attribute value of the biometric information corresponding to the user identification information in a biometric database, wherein the biometric database includes the user identification information and the attribute value of the biometric information corresponding to the user identification information;
响应单元63,用于确定接收到的所述业务处理请求中包含的用户的生物特征信息对应的属性值与查找到的所述用户的标识信息对应的生物特征信息的属性值相同时,响应所述业务处理请求。The responding unit 63 is configured to respond to the service processing request when it is determined that the attribute value corresponding to the user's biometric information contained in the received service processing request is the same as the attribute value of the biometric information corresponding to the found user identification information.
可选地,所述业务处理设备还包括:解密单元64,其中:Optionally, the service processing device further includes a decryption unit 64, wherein:
所述解密单元64,用于在所述接收单元61接收所述终端设备发送的业务处理请求后,所述查找单元62从生物识别数据库中查找所述用户的标识信息对应的生物特征信息的属性值之前,通过解密操作得到所述业务处理请求中包含的所述用户的生物特征信息的属性值和所述用户的标识信息。The decryption unit 64 is used to obtain the attribute value of the user's biometric information and the user's identification information contained in the business processing request through a decryption operation after the receiving unit 61 receives the business processing request sent by the terminal device and before the search unit 62 searches for the attribute value of the biometric information corresponding to the user's identification information from the biometric database.
可选地,所述业务处理设备还包括:建立单元65,其中:Optionally, the service processing device further includes: an establishing unit 65, wherein:
所述接收单元61,还用于接收所述终端设备发送的用户信息,其中,所述用户信息是所述终端设备将用户发送的注册请求中包含的所述用户的标识信息和所述用户的生物特征信息的属性值进行加密后发送的,所述用户信息中包含所述用户的标识信息和所述用户的生物特征信息的属性值,所述注册请求中包含所述用户的生物特征信息和所述用户的标识信息;The receiving unit 61 is further configured to receive user information sent by the terminal device, wherein the user information is encrypted by the terminal device by encrypting the user's identification information and the attribute values of the user's biometric information contained in the registration request sent by the user, the user information including the user's identification information and the attribute values of the user's biometric information, and the registration request including the user's biometric information and the user's identification information;
所述解密单元64,还用于通过解密操作得到所述用户信息中包含的所述用户的生物特征信息的属性值和所述用户的标识信息;The decryption unit 64 is further configured to obtain the attribute value of the user's biometric information and the user's identification information contained in the user information through a decryption operation;
所述建立单元65,用于建立所述用户的标识信息与所述用户的生物特征信息的属性值之间的对应关系,并将所述对应关系存储在所述生物识别数据库中。The establishing unit 65 is configured to establish a correspondence between the user's identification information and the attribute value of the user's biometric information, and store the correspondence in the biometric recognition database.
需要说明的是,本申请实施例提供的业务处理设备可以通过硬件方式实现,也可以通过软件方式实现,这里不做具体限定。It should be noted that the business processing device provided in the embodiment of the present application can be implemented by hardware or software, and no specific limitation is made here.
图7为本申请实施例提供的一种生物特征信息的处理设备结构示意图。所述生物特征信息的处理设备包括:接收单元71、计算单元72、存储单元73、加密单元74和发送单元75,其中:Figure 7 is a schematic diagram of the structure of a biometric information processing device provided in an embodiment of the present application. The biometric information processing device includes: a receiving unit 71, a computing unit 72, a storage unit 73, an encryption unit 74, and a sending unit 75, wherein:
接收单元71,用于接收用户发送的所述用户的标识信息以及所述用户的生物特征信息;A receiving unit 71 is configured to receive identification information of the user and biometric information of the user sent by the user;
计算单元72,用于根据所述用户的生物特征信息,利用预设算法,计算得到所述用户的生物特征信息的属性值;A calculation unit 72 is configured to calculate an attribute value of the user's biometric information using a preset algorithm based on the user's biometric information;
存储单元73,用于建立所述用户的标识信息、所述用户的生物特征信息以及所述用户的生物特征信息的属性值之间的对应关系,并将所述对应关系存储在所述生物特征信息库中。The storage unit 73 is configured to establish a correspondence between the user's identification information, the user's biometric information, and the attribute value of the user's biometric information, and store the correspondence in the biometric information database.
具体地,所述生物特征信息的处理设备还包括:加密单元74和发送单元75,其中:Specifically, the biometric information processing device further includes: an encryption unit 74 and a sending unit 75, wherein:
所述加密单元74,用于在所述计算单元72计算得到所述用户的标识信息对应的生物特征信息的属性值后,将所述用户的标识信息以及所述用户的生物特征信息的属性值进行加密,得到加密结果;The encryption unit 74 is configured to encrypt the user identification information and the attribute value of the user's biometric information after the calculation unit 72 calculates the attribute value of the biometric information corresponding to the user's identification information to obtain an encryption result;
所述发送单元75,用于将所述加密结果发送至所述服务器。The sending unit 75 is configured to send the encryption result to the server.
可选地,所述存储单元73建立所述用户的标识信息、所述用户的生物特征信息以及所述用户的标识信息对应的生物特征信息的属性值之间的对应关系,并将所述对应关系存储在所述生物特征信息库中,包括:Optionally, the storage unit 73 establishes a correspondence between the user's identification information, the user's biometric information, and an attribute value of the biometric information corresponding to the user's identification information, and stores the correspondence in the biometric information database, including:
向所述生物特征信息库发送查询请求,其中,所述查询请求中包含所述用户的标识信息;Sending a query request to the biometric information database, wherein the query request includes identification information of the user;
接收所述生物特征信息库返回的查询结果;Receiving the query result returned by the biometric information database;
根据查询结果确定在所述生物特征信息库中已存储与所述用户的标识信息对应的用户的生物特征信息,利用接收到的所述用户的生物特征信息更新所述生物特征信息库中已存储与所述用户的标识信息对应的用户的生物特征信息;determining, based on the query result, that biometric information of a user corresponding to the identification information of the user is stored in the biometric information database, and updating the biometric information of the user corresponding to the identification information of the user stored in the biometric information database using the received biometric information of the user;
根据查询结果确定在所述生物特征信息库中未存储与所述用户的标识信息对应的用户的生物特征信息,建立所述用户的标识信息、所述用户的生物特征信息以及所述用户的标识信息对应的生物特征信息的属性值之间的对应关系,并将所述对应关系存储在所述生物特征信息库中。According to the query result, it is determined that the biometric information of the user corresponding to the identification information of the user is not stored in the biometric information database, a correspondence is established between the identification information of the user, the biometric information of the user, and the attribute value of the biometric information corresponding to the identification information of the user, and the correspondence is stored in the biometric information database.
需要说明的是,本申请实施例提供的生物特征信息的处理设备可以通过硬件方式实现,也可以通过软件方式实现,这里不做具体限定。It should be noted that the biometric information processing device provided in the embodiments of the present application can be implemented by hardware or software, and is not specifically limited here.
图8为本申请实施例提供的一种生物特征信息的处理设备结构示意图。所述生物特征信息的处理设备包括:接收单元81、解密单元82和存储单元83,其中:FIG8 is a schematic diagram of a biometric information processing device according to an embodiment of the present application. The biometric information processing device includes: a receiving unit 81, a decryption unit 82, and a storage unit 83, wherein:
接收单元81,用于接收所述终端设备发送的用户信息,其中,所述用户信息是所述终端设备得到所述用户的生物特征信息的属性值时对所述用户的标识信息和所述用户的生物特征信息的属性值进行加密后发送的,所述用户信息中包含所述用户的标识信息和所述用户的生物特征信息的属性值;a receiving unit 81 configured to receive user information sent by the terminal device, wherein the user information is encrypted after the terminal device obtains the attribute value of the user's biometric information by encrypting the user's identification information and the attribute value of the user's biometric information, and the user information includes the user's identification information and the attribute value of the user's biometric information;
解密单元82,用于通过解密操作得到所述用户信息中包含的所述用户的生物特征信息的属性值和所述用户的标识信息;A decryption unit 82, configured to obtain the attribute value of the user's biometric information and the user's identification information contained in the user information through a decryption operation;
存储单元83,用于建立所述用户的标识信息与所述用户的生物特征信息的属性值之间的对应关系,并将所述对应关系存储在所述生物识别数据库中。The storage unit 83 is configured to establish a correspondence between the user's identification information and the attribute value of the user's biometric information, and store the correspondence in the biometric recognition database.
需要说明的是,本申请实施例提供的生物特征信息的处理设备可以通过硬件方式实现,也可以通过软件方式实现,这里不做具体限定。It should be noted that the biometric information processing device provided in the embodiments of the present application can be implemented by hardware or software, and is not specifically limited here.
图9为本申请实施例提供的一种身份识别系统的结构示意图。所述系统包括:终端设备和服务器设备,其中,所述终端设备包含身份识别单元91、身份识别返回单元92,所述服务器设备包含:身份验证单元93和业务处理单元94。Figure 9 is a schematic diagram of the structure of an identity recognition system provided by an embodiment of the present application. The system includes: a terminal device and a server device, wherein the terminal device includes an identity recognition unit 91 and an identity recognition return unit 92, and the server device includes an identity authentication unit 93 and a service processing unit 94.
在身份识别系统中,终端设备在接收到用户发送的业务处理请求时,将发起对该用户的身份识别。In the identity recognition system, when a terminal device receives a service processing request sent by a user, it will initiate identity recognition of the user.
具体地,所述身份识别单元91,用于根据用户发送的业务处理请求识别所述用户的身份是否合法,其中,所述业务处理请求包含所述用户的标识信息和所述用户的生物特征信息;Specifically, the identity recognition unit 91 is configured to identify whether the user's identity is legitimate based on a service processing request sent by the user, wherein the service processing request includes the user's identification information and the user's biometric information;
所述身份识别返回单元92,用于在所述身份识别单元91识别所述用户的身份非法后,向所述用户返回身份识别结果。The identity recognition returning unit 92 is configured to return an identity recognition result to the user after the identity recognition unit 91 recognizes that the user's identity is illegal.
可选地,所述身份识别单元91还包括:生物特征信息采集模块911、生物特征信息计算模块912、生物特征信息识别模块913和发送模块914,其中:Optionally, the identity recognition unit 91 further includes: a biometric information collection module 911, a biometric information calculation module 912, a biometric information recognition module 913 and a sending module 914, wherein:
所述生物特征信息采集模块911,用于采集用户的生物特征信息;The biometric information collection module 911 is used to collect the user's biometric information;
所述生物特征信息计算模块912,用于根据所述生物特征信息采集模块911采集的所述用户的生物特征信息,计算得到所述用户的生物特征信息的属性值;The biometric information calculation module 912 is configured to calculate the attribute value of the user's biometric information based on the user's biometric information collected by the biometric information collection module 911;
所述生物特征信息识别模块913,用于根据所述用户的标识信息、所述生物特征信息采集模块911采集的所述用户的生物特征信息识别所述用户的身份是否合法;The biometric information recognition module 913 is used to identify whether the user's identity is legal based on the user's identification information and the user's biometric information collected by the biometric information collection module 911;
所述发送模块914,用于对所述用户的标识信息和所述用户的生物特征信息的属性值进行加密,并将加密结果发送至所述服务器设备。The sending module 914 is configured to encrypt the user's identification information and the attribute value of the user's biometric information, and send the encryption result to the server device.
具体地,所述终端设备接收用户发送的业务处理请求,所述生物特征信息采集模块911采集所述用户的生物特征信息,所述生物特征信息识别模块913根据所述用户的标识信息,从所述终端设备中的生物特征信息库中查找所述用户的标识信息对应的生物特征信息,此时,所述生物特征信息识别模块913确定接收到的所述用户的生物特征信息与查找到的所述用户的标识信息对应的生物特征信息一致时,所述生物特征信息识别模块913识别所述用户的身份合法。Specifically, the terminal device receives a business processing request sent by a user, the biometric information collection module 911 collects the biometric information of the user, and the biometric information identification module 913 searches for the biometric information corresponding to the user's identification information from the biometric information database in the terminal device based on the user's identification information. At this time, when the biometric information identification module 913 determines that the received biometric information of the user is consistent with the biometric information corresponding to the found identification information of the user, the biometric information identification module 913 identifies that the identity of the user is legal.
可选地,所述生物特征信息计算模块912根据所述用户的生物特征信息,计算得到所述生物特征信息的属性值,所述生物特征信息识别模块913从所述终端设备中的生物特征信息库中查找所述用户的标识信息对应的生物特征信息的属性值,此时,所述生物特征信息识别模块913在确定接收到所述用户的生物特征信息的属性值与查找到的所述用户的标识信息对应的生物特征信息的属性值一致时,所述生物特征信息识别模块913识别所述用户的身份合法。Optionally, the biometric information calculation module 912 calculates the attribute value of the biometric information based on the biometric information of the user, and the biometric information identification module 913 searches for the attribute value of the biometric information corresponding to the identification information of the user from the biometric information library in the terminal device. At this time, when the biometric information identification module 913 determines that the attribute value of the received biometric information of the user is consistent with the attribute value of the biometric information corresponding to the found identification information of the user, the biometric information identification module 913 identifies that the identity of the user is legal.
可选地,所述生物特征信息识别模块913识别所述用户的身份合法后,所述生物特征信息识别模块913从生物特征信息库中查找所述用户的标识信息对应的生物特征信息的属性值/所述生物特征信息计算模块912根据接收到的所述用户的生物特征信息计算所述用户的生物特征信息的属性值,所述发送模块914将所述用户的标识信息和所述用户的生物特征信息的属性值进行加密,并携带加密结果的业务处理请求发送至所述服务器设备。Optionally, after the biometric information recognition module 913 recognizes that the identity of the user is legal, the biometric information recognition module 913 searches for the attribute value of the biometric information corresponding to the user's identification information from the biometric information database/the biometric information calculation module 912 calculates the attribute value of the user's biometric information based on the received biometric information of the user, and the sending module 914 encrypts the user's identification information and the attribute value of the user's biometric information, and sends a business processing request carrying the encryption result to the server device.
在身份识别系统中,服务器设备在接收到终端设备发送的业务处理请求时,将发起对该业务处理请求者的身份识别。In the identity recognition system, when a server device receives a service processing request from a terminal device, it will initiate identity recognition of the service processing requester.
具体地,所述身份验证单元93,用于根据接收到的用户标识信息和所述用户的生物特征信息的属性值,验证所述用户的身份是否合法;Specifically, the identity authentication unit 93 is used to verify whether the identity of the user is legitimate based on the received user identification information and the attribute value of the user's biometric information;
所述业务处理单元94,用于在所述身份验证单元93验证所述用户的身份合法后,对所述用户发送的业务处理请求进行处理。The service processing unit 94 is configured to process the service processing request sent by the user after the identity verification unit 93 verifies that the user's identity is legitimate.
可选地,所述身份验证单元93还包括:接收模块931、解密模块932、生物特征信息验证模块933和身份验证返回模块934,其中:Optionally, the identity authentication unit 93 further includes: a receiving module 931, a decryption module 932, a biometric information verification module 933 and an identity authentication return module 934, wherein:
所述接收模块931,用于接收所述发送模块914发送的加密结果;The receiving module 931 is configured to receive the encryption result sent by the sending module 914;
所述解密模块932,用于对所述接收模块931接收到的加密结果进行解密,得到解密后的所述用户的标识信息和所述用户的生物特征信息的属性值;The decryption module 932 is configured to decrypt the encryption result received by the receiving module 931 to obtain the decrypted user identification information and attribute values of the user's biometric information;
所述生物特征信息验证模块933,用于根据所述用户的标识信息和所述用户的生物特征信息的属性值验证所述用户的身份是否合法;The biometric information verification module 933 is used to verify whether the user's identity is legitimate based on the user's identification information and the attribute value of the user's biometric information;
所述身份验证返回模块934,用于在所述生物特征信息验证模块933验证所述用户的身份非法后,向所述用户返回验证结果。The identity authentication return module 934 is used to return the verification result to the user after the biometric information verification module 933 verifies that the identity of the user is illegal.
具体地,所述接收模块931接收所述终端设备发送的携带加密结果的业务处理请求,所述解密模块932对所述加密结果进行解密,得到解密后的所述用户的标识信息和所述用户的生物特征信息的属性值,所述生物特征信息验证模块933根据所述用户的标识信息,从所述服务器设备中的生物识别数据库中查找所述用户的标识信息对应的所述用户的生物特征信息的属性值。Specifically, the receiving module 931 receives the business processing request carrying the encryption result sent by the terminal device, the decryption module 932 decrypts the encryption result to obtain the decrypted user identification information and the attribute value of the user's biometric information, and the biometric information verification module 933 searches for the attribute value of the user's biometric information corresponding to the user's identification information from the biometric recognition database in the server device based on the user's identification information.
此时,所述生物特征信息验证模块933确定接收到的所述用户的生物特征信息的属性值与查找到的所述用户的标识信息对应的生物特征信息的属性值一致时,所述生物特征信息验证模块933验证所述用户的身份合法。At this time, when the biometric information verification module 933 determines that the attribute value of the received biometric information of the user is consistent with the attribute value of the biometric information corresponding to the found identification information of the user, the biometric information verification module 933 verifies the legitimacy of the user's identity.
本领域的技术人员应明白,本申请的实施例可提供为方法、装置(设备)、或计算机程序产品。因此,本申请可采用完全硬件实施例、完全软件实施例、或结合软件和硬件方面的实施例的形式。而且,本申请可采用在一个或多个其中包含有计算机可用程序代码的计算机可用存储介质(包括但不限于磁盘存储器、CD-ROM、光学存储器等)上实施的计算机程序产品的形式。Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, devices (equipment), or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
本申请是参照根据本申请实施例的方法、装置(设备)和计算机程序产品的流程图和/或方框图来描述的。应理解可由计算机程序指令实现流程图和/或方框图中的每一流程和/或方框、以及流程图和/或方框图中的流程和/或方框的结合。可提供这些计算机程序指令到通用计算机、专用计算机、嵌入式处理机或其他可编程数据处理设备的处理器以产生一个机器,使得通过计算机或其他可编程数据处理设备的处理器执行的指令产生用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的装置。The present application is described with reference to the flowcharts and/or block diagrams of the methods, devices (equipment) and computer program products according to the embodiments of the present application. It should be understood that each process and/or box in the flowchart and/or block diagram, as well as the combination of the processes and/or boxes in the flowchart and/or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the function specified in one process or multiple processes in the flowchart and/or one box or multiple boxes in the block diagram.
这些计算机程序指令也可存储在能引导计算机或其他可编程数据处理设备以特定方式工作的计算机可读存储器中,使得存储在该计算机可读存储器中的指令产生包括指令装置的制造品,该指令装置实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能。These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and/or one or more boxes in the block diagram.
这些计算机程序指令也可装载到计算机或其他可编程数据处理设备上,使得在计算机或其他可编程设备上执行一系列操作步骤以产生计算机实现的处理,从而在计算机或其他可编程设备上执行的指令提供用于实现在流程图一个流程或多个流程和/或方框图一个方框或多个方框中指定的功能的步骤。These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and/or one or more boxes in the block diagram.
尽管已描述了本申请的优选实施例,但本领域内的技术人员一旦得知了基本创造性概念,则可对这些实施例作出另外的变更和修改。所以,所附权利要求意欲解释为包括优选实施例以及落入本申请范围的所有变更和修改。Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present application.
显然,本领域的技术人员可以对本申请进行各种改动和变型而不脱离本申请的范围。这样,倘若本申请的这些修改和变型属于本申请权利要求及其等同技术的范围之内,则本申请也意图包含这些改动和变型在内。Obviously, those skilled in the art may make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is intended to include these modifications and variations.
Claims (24)
Publications (3)
| Publication Number | Publication Date |
|---|---|
| HK1237149A1 HK1237149A1 (en) | 2018-04-06 |
| HK1237149A HK1237149A (en) | 2018-04-06 |
| HK1237149B true HK1237149B (en) | 2021-08-13 |
Family
ID=
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN106612259B (en) | Identity recognition, business processing and biological characteristic information processing method and equipment | |
| CN112926092B (en) | Privacy-protecting identity information storage and identity authentication method and device | |
| JP6882254B2 (en) | Safety verification methods based on biological characteristics, client terminals, and servers | |
| US9887989B2 (en) | Protecting passwords and biometrics against back-end security breaches | |
| US9485098B1 (en) | System and method of user authentication using digital signatures | |
| US20160219046A1 (en) | System and method for multi-modal biometric identity verification | |
| CN112329519B (en) | A secure online fingerprint matching method | |
| CN108134791A (en) | A kind of data center's total management system login validation method | |
| CN106612180A (en) | Method and device for realizing session identifier synchronization | |
| CN101174953A (en) | A Method of Identity Authentication Based on S/Key System | |
| WO2021190197A1 (en) | Method and apparatus for authenticating biometric payment device, computer device and storage medium | |
| KR101897715B1 (en) | System for non-password secure biometric digital signagure | |
| CN114547589A (en) | Privacy-protecting user registration and user authentication method and device | |
| CN115550002B (en) | A smart home remote control method and related device based on TEE | |
| CN112039665A (en) | A key management method and device | |
| WO2022042745A1 (en) | Key management method and apparatus | |
| CN106936775A (en) | A kind of authentication method and system based on fingerprint recognition | |
| CN114996727A (en) | Biological feature privacy encryption method and system based on palm print and palm vein recognition | |
| US20190288833A1 (en) | System and Method for Securing Private Keys Behind a Biometric Authentication Gateway | |
| KR20040082674A (en) | System and Method for Authenticating a Living Body Doubly | |
| CN113935002B (en) | A secure face authentication method and system based on honeypot technology | |
| CN119740217B (en) | A secure bio-privacy information verification system combining random storage and noise perturbation | |
| JP7632477B2 (en) | Recovery verification system, collation system, recovery verification method and program | |
| TWI736280B (en) | Identity verification method based on biometrics | |
| Mehra et al. | Remote user authentication and issues: A survey |