WO2017012175A1 - 身份认证方法、身份认证系统、终端和服务器 - Google Patents

身份认证方法、身份认证系统、终端和服务器 Download PDF

Info

Publication number
WO2017012175A1
WO2017012175A1 PCT/CN2015/088472 CN2015088472W WO2017012175A1 WO 2017012175 A1 WO2017012175 A1 WO 2017012175A1 CN 2015088472 W CN2015088472 W CN 2015088472W WO 2017012175 A1 WO2017012175 A1 WO 2017012175A1
Authority
WO
WIPO (PCT)
Prior art keywords
biometric
vector
information
identity authentication
biometric information
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2015/088472
Other languages
English (en)
French (fr)
Inventor
钟焰涛
傅文治
林荣辉
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Original Assignee
Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Yulong Computer Telecommunication Scientific Shenzhen Co Ltd filed Critical Yulong Computer Telecommunication Scientific Shenzhen Co Ltd
Publication of WO2017012175A1 publication Critical patent/WO2017012175A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/32User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0861Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3226Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
    • H04L9/3231Biological data, e.g. fingerprint, voice or retina

Definitions

  • the present invention relates to the field of biometrics, and in particular to an identity authentication method, an identity authentication system, a terminal, and a server.
  • biometric technology refers to the technology of using human biometrics for identity authentication.
  • biometric technologies include fingerprint recognition, face recognition, and iris recognition.
  • biometric template data is a key issue because malicious programs on mobile terminals may steal storage on mobile terminals.
  • the biometric template data makes it easy to pass biometric authentication, leading to the leakage of important information and giving users a bad experience.
  • Homomorphic encryption is a special encryption technique that allows people to perform specific algebraic operations on ciphertext and obtain the same results as the plaintext. In other words, this technology allows people to operate on encrypted data to get the right results without having to decrypt the data throughout the process.
  • the current homomorphic encryption technology cannot be directly applied to complex operations such as biometric template matching.
  • a new identity authentication method which can combine biometric technology with homomorphic encryption technology, so that the server can perform correct biometric information matching without decryption, and can effectively avoid the prior art.
  • the invention is based on the above problems, and proposes a new technical solution.
  • the server can perform correct biometric information matching without decryption, and effectively avoid the present
  • the user biometric information is stored on the terminal.
  • the problem of being easily stolen by malicious people realizes the secure storage of biometric information of users, improves the security and reliability of identity authentication based on biometric information, and improves the user experience.
  • an identity authentication method for a terminal, including: collecting first biometric information of a preset user; and at least one of the first biometric information is first
  • the attribute information is represented in a vector form, and homomorphicly encrypts the at least one first attribute information represented by a vector form according to a preset key to generate a first biometric vector; and the first biometric vector is Sending to a server for the server to store the first biometric vector as a first biometric template vector.
  • the pre-storing process of the first biometric template vector is first performed, and specifically, the first attribute information that can be used for identity authentication in the first biometric information of the collected preset user is represented by a vector form.
  • the first attribute information for identity authentication has one or more items, and each first attribute information is represented by a vector form, thereby obtaining a vector group representing the first biometric information, according to the stored preset
  • the key performs homomorphic encryption on each of the vector vectors in the vector group to obtain the first biometric vector, and then sends the first object feature vector to the server, which is stored by the server as the first biometric template vector.
  • the preset key may be randomly generated by the terminal, or may be set according to actual needs of the user, and finally stored in the terminal, and the first biometric template vector generated by homomorphic encryption is stored in the server, and used.
  • the decrypted preset key is stored in the terminal, and the server cannot know the preset key, so by using the biometric technology
  • the combination of encryption technology enables the server to perform correct biometric information matching without decryption, and can effectively avoid the problem that the user biometric information is easily maliciously stolen on the terminal in the prior art, and the user creature is realized.
  • the secure storage of feature information improves the security and reliability of identity authentication based on biometric information, thereby improving the user experience.
  • the method further includes: collecting second biometric information of the current user; and expressing at least one second attribute information of the second biometric information in a vector form, and according to the preset secret
  • the key pair performs homomorphic encryption processing on the at least one second attribute information represented by the vector form to generate a second biometric vector; and sends the second biometric vector to the server for the server to Generating a first Euclidean distance from the first biometric template vector; receiving the first Euclidean distance from the server; performing homomorphic decryption processing on the first Euclidean distance Obtaining a second Euclidean distance; according to the second Euclidean The distance determines whether the second biometric information matches the first biometric information to determine whether the identity authentication is successful.
  • the second attribute information that is available for identity authentication in the collected second biometric information of the current user is represented in a vector form, wherein the second attribute information that can be authenticated has one or more And each of the second attribute information is represented by a vector form, and a vector group representing the second biometric information is obtained, and each sub-vector in the vector group is homomorphically encrypted according to the preset key.
  • the distance of course, the first Euclidean distance is also encrypted, and the server cannot know the specific result of the first Euclidean distance.
  • the server can be prevented from abusing the user's first biometric template vector, ensuring the security of the matching result.
  • the server will calculate the first The Euclidean distance is sent to the terminal, and is homomorphically decrypted by the terminal to obtain a second Euclidean distance, thereby determining whether the second biometric information matches the first biometric information according to the second Euclidean distance to determine whether Whether the identity authentication is successful, that is, the preset key used for the homomorphic decryption is stored in the terminal, and the server cannot know the preset key, thereby further ensuring the security and reliability of the identity authentication.
  • the server can perform correct biometric information matching without decryption, and can effectively avoid the prior art that the user biometric information is easily maliciously stored on the terminal.
  • the problem of stealing realizes the secure storage of user biometric information, improves the security and reliability of identity authentication based on biometric information, and improves the user experience.
  • determining whether the second biometric information matches the first biometric information according to the second Euclidean distance, to determine whether the identity authentication is successful specifically, determining: Whether the second Euclidean distance is less than or equal to the preset distance; and when it is determined that the second Euclidean distance is less than or equal to the preset distance, the second biometric information is successfully matched with the first biometric information, The identity authentication succeeds; when it is determined that the second Euclidean distance is greater than the preset distance, the second biometric information is mismatched with the first biometric information. If it fails, the identity authentication fails.
  • whether the second biometric information matches the first biometric information is determined by the second Euclidean distance, and the second Euclidean distance and the preset distance are determined to determine whether the matching is
  • the second Euclidean distance is determined to be less than or equal to the preset distance
  • the second biometric information is successfully matched with the first biometric information, indicating that the user identity authentication is successful, otherwise, the identity authentication fails, and thus, effective
  • the problem that the first biometric template vector is easily maliciously stolen on the terminal is avoided in the prior art, and the security and reliability of the biometric information based identity authentication are improved, thereby improving the user experience.
  • the preset distance can be calculated according to the actual application scenario.
  • the first biometric information and the second biometric information include at least one of the following or a combination thereof: fingerprint image information, iris image information, and face image information.
  • the first biometric information and the second biometric information include at least but not limited to one or a combination of the following: fingerprint image information, iris image information, and face image information, that is, the solution may be based on different creatures.
  • the feature information is implemented, so that the server can perform correct biometric information matching without decrypting, and can effectively avoid the problem that the first biometric template vector is easily maliciously stolen on the terminal in the prior art, thereby improving
  • the security and reliability effects of identity authentication based on biometric information further improve the applicability of identity authentication.
  • an identity authentication system for a terminal, comprising: an acquisition module, configured to collect first biometric information of a preset user; and an encryption module, configured to use the first biometric feature
  • the at least one first attribute information of the information is represented in a vector form, and the at least one first attribute information represented by the vector form is homomorphicly encrypted according to the preset key to generate the first biometric vector; a sending module, configured to send the first biometric vector to a server, for the server to store the first biometric vector as a first biometric template vector.
  • the pre-storing process of the first biometric template vector is first performed, and specifically, the first attribute information that can be used for identity authentication in the first biometric information of the collected preset user is represented by a vector form.
  • the first attribute information for identity authentication has one or more items, and each of the first attribute information is represented by a vector form, thereby obtaining a representation of the first biometric
  • the vector group of the information is homomorphically encrypted according to the stored preset key, and the first biometric vector is obtained, and then the first object feature vector is sent to the server, and the server
  • the first biometric template vector is stored as a first biometric template vector.
  • the preset key may be randomly generated by the terminal, or may be set according to actual needs of the user, and finally stored in the terminal, and is first generated by homomorphic encryption.
  • the biometric template vector is stored in the server, and the preset key used for decryption is stored in the terminal, and the server cannot know the preset key.
  • the server is enabled.
  • the correct biometric information matching can be performed without decryption, and the problem that the user biometric information is easily maliciously stolen in the prior art can be effectively avoided, and the safe storage of the biometric information of the user is realized and improved.
  • the security and reliability of identity authentication based on biometric information enhances the user experience.
  • the collecting module is further configured to collect second biometric information of the current user;
  • the encryption module is further configured to use at least one second attribute information of the second biometric information a vector form representation, and performing homomorphic encryption processing on the at least one second attribute information represented by a vector form according to the preset key to generate a second biometric vector;
  • the first sending module is further used to Transmitting the second biometric vector to the server for the server to generate a first Euclidean distance from the first biometric template vector according to the second biometric vector;
  • the identity authentication system further
  • the first receiving module is configured to receive the first Euclidean distance from the server, and the decrypting module is configured to perform homomorphic decryption processing on the first Euclidean distance to obtain a second Euclidean distance; And determining, according to the second Euclidean distance, whether the second biometric information matches the first biometric information to determine whether the identity authentication is successful.
  • the second attribute information that is available for identity authentication in the collected second biometric information of the current user is represented in a vector form, wherein the second attribute information that can be authenticated has one or more And each of the second attribute information is represented by a vector form, and a vector group representing the second biometric information is obtained, and each sub-vector in the vector group is homomorphically encrypted according to the preset key.
  • the server will calculate the first The Euclidean distance is sent to the terminal, and is homomorphically decrypted by the terminal to obtain a second Euclidean distance, thereby determining whether the second biometric information matches the first biometric information according to the second Euclidean distance to determine whether Whether the identity authentication is successful, that is, the preset key used for the homomorphic decryption is stored in the terminal, and the server cannot know the preset key, thereby further ensuring the security and reliability of the identity authentication.
  • the server can perform correct biometric information matching without decryption, and can effectively avoid the prior art that the user biometric information is easily maliciously stored on the terminal.
  • the problem of stealing realizes the secure storage of user biometric information, improves the security and reliability of identity authentication based on biometric information, and improves the user experience.
  • the determining module is specifically configured to determine whether the second Euclidean distance is less than or equal to a preset distance; and when determining that the second Euclidean distance is less than or equal to the preset distance
  • the identity authentication is successful; when it is determined that the second Euclidean distance is greater than the preset distance, the second biometric information is If the first biometric information fails to be matched, the identity authentication fails.
  • whether the second biometric information matches the first biometric information is determined by the second Euclidean distance, and determining whether the second Euclidean distance and the preset distance are matched, specifically, When it is determined that the second Euclidean distance is less than or equal to the preset distance, the second biometric information is successfully matched with the first biometric information, indicating that the user identity authentication is successful, otherwise, the identity authentication fails, thus effectively avoiding the existing In the technology, the first biometric template vector is stored on the terminal and is easily maliciously stolen, thereby improving the security and reliability of the biometric information based identity authentication, thereby improving the user experience.
  • the preset distance can be calculated according to the actual application scenario.
  • the first biometric information and the second biometric information include at least one of the following or a combination thereof: fingerprint image information, iris image information, and face image information.
  • the first biometric information and the second biometric information include at least but not limited to one or a combination of the following: fingerprint image information, iris image information, and face image information, that is, the solution may be based on different creatures.
  • the feature information is implemented, so that the server can perform correct biometric information matching without decrypting, and can effectively avoid the problem that the first biometric template vector is easily maliciously stolen on the terminal in the prior art, thereby improving
  • the security and reliability effects of identity authentication based on biometric information further improve the applicability of identity authentication.
  • an identity authentication method for a server, comprising: receiving a third biometric vector from a terminal; storing the third biometric vector as the second biometric template vector The third biometric vector is obtained by the terminal performing homomorphic encryption processing on the at least one third attribute information of the collected third biometric information of the preset user.
  • the process of storing the second biometric template vector is first performed, specifically, by storing the received third biometric vector from the terminal as the second biometric template vector, so as to smoothly carry out the subsequent matching step.
  • the third biometric vector is obtained by the terminal performing homomorphic encryption processing on each third attribute information for identity authentication of the third biometric information of the preset preset user, that is, It is a vector obtained by encryption processing, and the server cannot know the specific content. Therefore, the server avoids the abuse of the biometric information of the user, further improves the security and reliability of the identity authentication based on the biometric information, thereby improving the user experience.
  • the method further includes: receiving a fourth biometric vector from the terminal, wherein the fourth biometric vector is the fourth biometric information of the current user acquired by the terminal Obtaining a third Euclidean distance according to the fourth biometric template vector and the second biometric template vector; and transmitting the third Euclidean distance to the terminal And determining, by the terminal, whether the fourth biometric information matches the third biometric information according to the third Euclidean distance; and the third biometric information and the fourth biometric information are at least One or a combination of the following is included: fingerprint image information, iris image information, and face image information.
  • the third Euclidean distance calculated according to the fourth biometric vector and the second biometric template vector is sent to the terminal, so that the terminal can perform homomorphic decryption on the terminal. And determining whether the identity authentication is successful, wherein the fourth biometric vector is obtained by the terminal performing homomorphic encryption processing on each fourth attribute information of the fourth biometric information of the current user that is available for identity authentication, that is, It is a vector obtained by encryption processing, and the server cannot know its specific content.
  • the server can perform correct biometric information matching without decryption, and can effectively avoid
  • the user biometric information is stored on the terminal and is easily maliciously stolen, thereby realizing the secure storage of the biometric information of the user, avoiding the abuse of the biometric information of the user by the server, and further improving the identity based on the biometric information.
  • the security and reliability of authentication enhances the user experience.
  • the third biometric information and the fourth biometric information include at least but not limited to one of the following or a combination thereof: fingerprint image information, iris image information, and face image information, that is, the solution may be implemented based on different biometric information, So that the server can perform correct biometric information matching without decryption, and can effectively avoid the problem that the second biometric template vector is easily maliciously stolen on the terminal in the prior art, thereby improving the biometric information based.
  • the effectiveness of identity authentication and reliability further enhances the applicability of identity authentication.
  • an identity authentication system for a server, comprising: a second receiving module, configured to receive a third biometric vector from the terminal; and a storage module, configured to use the third biometric
  • the feature vector is stored as the second biometric template vector, wherein the third biometric vector is homomorphic to the terminal for at least one third attribute information of the collected third biometric information of the preset user. Encrypted processing.
  • the process of storing the second biometric template vector is first performed, specifically, by storing the received third biometric vector from the terminal as the second biometric template vector, so as to smoothly carry out the subsequent matching step.
  • the third biometric vector is obtained by the terminal performing homomorphic encryption processing on each third attribute information for identity authentication of the third biometric information of the preset preset user, that is, It is a vector obtained by encryption processing, and the server cannot know the specific content. Therefore, the server avoids the abuse of the biometric information of the user, further improves the security and reliability of the identity authentication based on the biometric information, thereby improving the user experience.
  • the second receiving module is further configured to receive a fourth biometric vector from the terminal, where the fourth biometric vector is the terminal pair acquisition
  • the at least one fourth attribute information of the fourth biometric information of the current user is obtained by homomorphic encryption processing
  • the identity authentication system further includes: the processing module is further configured to: according to the fourth biometric vector and the second The biometric template vector obtains a third Euclidean distance; and the identity authentication system further includes: a second sending module, configured to send the third Euclidean distance to the terminal, for the terminal to be according to the Determining whether the fourth biometric information matches the third biometric information; and the third biometric information and the fourth biometric information include at least one of the following or a combination thereof: a fingerprint image Information, iris image information, and face image information.
  • the third Euclidean distance calculated according to the fourth biometric vector and the second biometric template vector is sent to the terminal, so that the terminal performs homomorphic decryption to determine whether the identity authentication is successful.
  • the fourth biometric vector is obtained by the terminal performing homomorphic encryption processing on each fourth attribute information of the fourth biometric information of the current user that is available for identity authentication, that is, a vector obtained by encryption processing.
  • the server cannot know the specific content. Thus, by combining the biometric technology with the homomorphic encryption technology, the server can perform correct biometric information matching without decryption, and can effectively avoid the user in the prior art.
  • the biometric information is stored on the terminal and is easily stolen by malicious people, which realizes the safe storage of the biometric information of the user, avoids the abuse of the biometric information of the user by the server, and further improves the security and reliability of the identity authentication based on the biometric information. , which enhances the user experience.
  • the third biometric information and the fourth biometric information include at least but not limited to one of the following or a combination thereof: fingerprint image information, iris image information, and face image information, that is, the solution may be implemented based on different biometric information, So that the server can perform correct biometric information matching without decryption, and can effectively avoid the problem that the second biometric template vector is easily maliciously stolen on the terminal in the prior art, thereby improving the biometric information based.
  • the effectiveness of identity authentication and reliability further enhances the applicability of identity authentication.
  • a terminal comprising: the identity authentication system for a terminal according to any one of the preceding claims, All the beneficial effects of the identity authentication system for the terminal are not described herein.
  • a server comprising: the identity authentication system for a server according to any one of the preceding claims, and thus having the above technical party All the beneficial effects of the identity authentication system for the server described in any of the above are not described herein.
  • the biometric identification technology can be combined with the homomorphic encryption technology, so that the server can perform correct biometric information matching without decryption, and can effectively avoid the biometric information of the user in the prior art.
  • the problem that the terminal is easily maliciously stolen on the terminal realizes the secure storage of the biometric information of the user, improves the security and reliability of the identity authentication based on the biometric information, thereby improving the user experience.
  • FIG. 1 is a flow chart showing an identity authentication method according to an embodiment of the present invention
  • FIG. 2 shows a block diagram of an identity authentication system in accordance with one embodiment of the present invention
  • FIG. 3 is a flow chart showing an identity authentication method according to another embodiment of the present invention.
  • FIG. 4 shows a block diagram of an identity authentication system in accordance with another embodiment of the present invention.
  • Figure 5 shows a block diagram of a terminal in accordance with one embodiment of the present invention.
  • Figure 6 shows a block diagram of a server in accordance with one embodiment of the present invention.
  • FIG. 7 is a flow chart showing an identity authentication method according to still another embodiment of the present invention.
  • FIG. 8 is a flow chart showing a biometric information registration method according to an embodiment of the present invention.
  • FIG. 1 shows a flow chart of an identity authentication method according to an embodiment of the present invention.
  • an identity authentication method is used for a terminal, including: Step 102: Collecting first biometric information of a preset user; Step 104: at least one of the first biometric information
  • the item first attribute information is represented in a vector form, and performs homomorphic encryption processing on the at least one first attribute information represented by a vector form according to a preset key to generate a first biometric vector;
  • the first biometric vector is sent to the server for the server to store the first biometric vector as a first biometric template vector.
  • the pre-storing process of the first biometric template vector is first performed, and specifically, the first attribute information that can be used for identity authentication in the first biometric information of the collected preset user is represented by a vector form.
  • the first attribute information for identity authentication has one or more items, and each first attribute information is represented by a vector form, thereby obtaining a vector group representing the first biometric information, according to the stored preset
  • the key performs homomorphic encryption on each of the vector vectors in the vector group to obtain the first biometric vector, and then sends the first object feature vector to the server, which is stored by the server as the first biometric template vector.
  • the preset key may be randomly generated by the terminal, or may be set according to actual needs of the user, and finally stored in the terminal, and the first biometric template vector generated by homomorphic encryption is stored in the server, and used.
  • the decrypted preset key is stored in the terminal, and the server cannot know the preset key, so by using the biometric technology
  • the combination of encryption technology enables the server to perform correct biometric information matching without decryption, and can effectively avoid the problem that the user biometric information is easily maliciously stolen on the terminal in the prior art, and the user creature is realized.
  • the secure storage of feature information improves the security and reliability of identity authentication based on biometric information, thereby improving the user experience.
  • the method further includes: collecting second biometric information of the current user; and expressing at least one second attribute information of the second biometric information in a vector form, and according to the preset secret
  • the key pair performs homomorphic encryption processing on the at least one second attribute information represented by the vector form to generate a second biometric vector; and sends the second biometric vector to the server for the server to Generating a first Euclidean distance from the first biometric template vector; receiving the first Euclidean distance from the server; performing homomorphic decryption processing on the first Euclidean distance Obtaining a second Euclidean distance; determining, according to the second Euclidean distance, whether the second biometric information matches the first biometric information to determine whether the identity authentication is successful.
  • the second attribute information that is available for identity authentication in the collected second biometric information of the current user is represented in a vector form, wherein the second attribute information that can be authenticated has one or more And each of the second attribute information is represented by a vector form, and a vector group representing the second biometric information is obtained, and each sub-vector in the vector group is homomorphically encrypted according to the preset key.
  • the distance of course, the first Euclidean distance is also encrypted, and the server cannot know the specific result of the first Euclidean distance.
  • the server can be prevented from abusing the user's first biometric template vector, ensuring the security of the matching result.
  • the server will calculate the first The Euclidean distance is sent to the terminal, and is homomorphically decrypted by the terminal to obtain a second Euclidean distance, thereby determining whether the second biometric information matches the first biometric information according to the second Euclidean distance to determine whether Whether the identity authentication is successful, that is, the preset key used for the homomorphic decryption is stored in the terminal, and the server cannot know the preset key, thereby further ensuring the security and reliability of the identity authentication.
  • the server can perform correct biometric information matching without decryption, and can effectively avoid the prior art that the user biometric information is easily maliciously stored on the terminal.
  • the problem of stealing realizes the secure storage of user biometric information, improves the security and reliability of identity authentication based on biometric information, and improves the user experience.
  • determining whether the second biometric information matches the first biometric information according to the second Euclidean distance, to determine whether the identity authentication is successful specifically, determining: Whether the second Euclidean distance is less than or equal to the preset distance; and when it is determined that the second Euclidean distance is less than or equal to the preset distance, the second biometric information is successfully matched with the first biometric information, The identity authentication succeeds; when it is determined that the second Euclidean distance is greater than the preset distance, the second biometric information fails to match the first biometric information, and the identity authentication fails.
  • the second biometric information matches the first biometric information Determined by the second Euclidean distance, by determining the second Euclidean distance and the preset distance, whether it is matched, specifically, when determining that the second Euclidean distance is less than or equal to the preset distance, the second If the biometric information is successfully matched with the first biometric information, it indicates that the user identity authentication is successful, otherwise, the identity authentication fails, so that the prior art is convenient to store the first biometric template vector on the terminal.
  • the problem of being maliciously stolen improves the security and reliability of identity authentication based on biometric information, thereby improving the user experience.
  • the preset distance can be calculated according to the actual application scenario.
  • the first biometric information and the second biometric information include at least one of the following or a combination thereof: fingerprint image information, iris image information, and face image information.
  • the first biometric information and the second biometric information include at least but not limited to one or a combination of the following: fingerprint image information, iris image information, and face image information, that is, the solution may be based on different creatures.
  • the feature information is implemented, so that the server can perform correct biometric information matching without decrypting, and can effectively avoid the problem that the first biometric template vector is easily maliciously stolen on the terminal in the prior art, thereby improving
  • the security and reliability effects of identity authentication based on biometric information further improve the applicability of identity authentication.
  • FIG. 2 shows a block diagram of an identity authentication system in accordance with one embodiment of the present invention.
  • the identity authentication system 200 of an embodiment of the present invention is used for a terminal, and includes: an acquisition module 202, configured to collect first biometric information of a preset user; and an encryption module 204, configured to: The at least one first attribute information of the first biometric information is represented in a vector form, and the at least one first attribute information represented by the vector form is homomorphically encrypted according to the preset key to generate the first creature. And a first sending module 206, configured to send the first biometric vector to a server, where the server stores the first biometric vector as a first biometric template vector.
  • the pre-storing process of the first biometric template vector is first performed, and specifically, the first attribute information that can be used for identity authentication in the first biometric information of the collected preset user is represented by a vector form.
  • the first attribute information for identity authentication has one or more items, and each first attribute information is represented by a vector form, thereby obtaining a vector group representing the first biometric information, according to the stored preset
  • the key is the same for each of the vector vectors in the vector group
  • the first bio-feature vector is obtained, and then the first object feature vector is sent to the server, which is stored by the server as the first bio-feature template vector, wherein the preset key may be randomly generated by the terminal, It may be set according to actual needs of the user, and finally stored in the terminal, that is, the first biometric template vector generated by homomorphic encryption is stored in the server, and the preset key used for decryption is stored in the terminal, then the server This preset key cannot be known.
  • the server can perform correct biometric information matching without decryption, and can effectively avoid the user in the prior art.
  • the biometric information is stored on the terminal and is easily maliciously stolen.
  • the secure storage of the biometric information of the user is realized, and the security and reliability of the identity authentication based on the biometric information are improved, thereby improving the user experience.
  • the collecting module 202 is further configured to collect second biometric information of the current user; the encryption module 204 is further configured to use at least one second attribute of the second biometric information.
  • the information is represented in a vector form, and performs homomorphic encryption processing on the at least one second attribute information in a vector form according to the preset key to generate a second biometric vector; the first sending module 206 Also for transmitting the second biometric vector to the server for the server to generate a first Euclidean distance from the first biometric template vector according to the second biometric vector; and the identity
  • the authentication system 200 further includes: a first receiving module 208, configured to receive the first Euclidean distance from the server; and a decryption module 210, configured to perform a homomorphic decryption process on the first Euclidean distance to obtain a second An Euclidean distance; a determining module 212, configured to determine, according to the second Euclidean distance, whether the second biometric information matches the first biometric information to determine an
  • the second attribute information that is available for identity authentication in the collected second biometric information of the current user is represented in a vector form, wherein the second attribute information that can be authenticated has one or more And each of the second attribute information is represented by a vector form, and a vector group representing the second biometric information is obtained, and each sub-vector in the vector group is homomorphically encrypted according to the preset key.
  • the distance of course, the first Euclidean distance is also encrypted, and the server cannot know the specific result of the first Euclidean distance.
  • the server can be prevented from abusing the user's first biometric template vector, ensuring the security of the matching result.
  • the server will calculate the first The Euclidean distance is sent to the terminal, and is homomorphically decrypted by the terminal to obtain a second Euclidean distance, thereby determining whether the second biometric information matches the first biometric information according to the second Euclidean distance to determine whether Whether the identity authentication is successful, that is, the preset key used for the homomorphic decryption is stored in the terminal, and the server cannot know the preset key, thereby further ensuring the security and reliability of the identity authentication.
  • the server can perform correct biometric information matching without decryption, and can effectively avoid the prior art that the user biometric information is easily maliciously stored on the terminal.
  • the problem of stealing realizes the secure storage of user biometric information, improves the security and reliability of identity authentication based on biometric information, and improves the user experience.
  • the determining module 212 is specifically configured to determine whether the second Euclidean distance is less than or equal to a preset distance; and when determining that the second Euclidean distance is less than or equal to the preset When the distance is that the second biometric information is successfully matched with the first biometric information, the identity authentication is successful; when the second Euclidean distance is determined to be greater than the preset distance, the second biometric information is If the matching with the first biometric information fails, the identity authentication fails.
  • whether the second biometric information matches the first biometric information is determined by the second Euclidean distance, and determining whether the second Euclidean distance and the preset distance are matched, specifically, When it is determined that the second Euclidean distance is less than or equal to the preset distance, the second biometric information is successfully matched with the first biometric information, indicating that the user identity authentication is successful, otherwise, the identity authentication fails, thus effectively avoiding the existing In the technology, the first biometric template vector is stored on the terminal and is easily maliciously stolen, thereby improving the security and reliability of the biometric information based identity authentication, thereby improving the user experience.
  • the preset distance can be calculated according to the actual application scenario.
  • the first biometric information and the second biometric information include at least one of the following or a combination thereof: fingerprint image information, iris image information, and face image information.
  • the first biometric information and the second biometric information include at least but not limited to one or a combination of the following: fingerprint image information, iris image information, and face image information, that is, the solution may be based on different creatures.
  • the feature information is implemented, so that the server can perform correct biometric information matching without decrypting, and can effectively avoid the problem that the first biometric template vector is easily maliciously stolen on the terminal in the prior art, thereby improving
  • the security and reliability effects of identity authentication based on biometric information further improve the applicability of identity authentication.
  • FIG. 3 is a flow chart showing an identity authentication method according to another embodiment of the present invention.
  • an identity authentication method is used for a server, including: step 302, receiving a third biometric vector from a terminal; and step 304, storing the third biometric vector as The second biometric template vector, wherein the third biometric vector is obtained by the terminal performing homomorphic encryption processing on at least one third attribute information of the collected third biometric information of the preset user. .
  • the process of storing the second biometric template vector is first performed, specifically, by storing the received third biometric vector from the terminal as the second biometric template vector, so as to smoothly carry out the subsequent matching step.
  • the third biometric vector is obtained by the terminal performing homomorphic encryption processing on each third attribute information for identity authentication of the third biometric information of the preset preset user, that is, It is a vector obtained by encryption processing, and the server cannot know the specific content. Therefore, the server avoids the abuse of the biometric information of the user, further improves the security and reliability of the identity authentication based on the biometric information, thereby improving the user experience.
  • the method further includes: receiving a fourth biometric vector from the terminal, wherein the fourth biometric vector is the fourth biometric information of the current user acquired by the terminal Obtaining a third Euclidean distance according to the fourth biometric template vector and the second biometric template vector; and transmitting the third Euclidean distance to the terminal And determining, by the terminal, whether the fourth biometric information matches the third biometric information according to the third Euclidean distance; and the third biometric information and the fourth biometric information are at least One or a combination of the following is included: fingerprint image information, iris image information, and face image information.
  • the third Euclidean distance calculated according to the fourth biometric vector and the second biometric template vector is sent to the terminal, so that the terminal performs homomorphic decryption to determine whether the identity authentication is successful.
  • the fourth biometric vector is obtained by the terminal performing homomorphic encryption processing on each fourth attribute information of the fourth biometric information of the current user that is available for identity authentication, that is, a vector obtained by encryption processing.
  • the server cannot know the specific content. Thus, by combining the biometric technology with the homomorphic encryption technology, the server can perform correct biometric information matching without decryption, and can effectively avoid the user in the prior art.
  • the biometric information is stored on the terminal and is easily stolen by malicious people, which realizes the safe storage of the biometric information of the user, avoids the abuse of the biometric information of the user by the server, and further improves the security and reliability of the identity authentication based on the biometric information. , which enhances the user experience.
  • the third biometric information and the fourth biometric information include at least but not limited to one of the following or a combination thereof: fingerprint image information, iris image information, and face image information, that is, the solution may be implemented based on different biometric information, So that the server can perform correct biometric information matching without decryption, and can effectively avoid the problem that the second biometric template vector is easily maliciously stolen on the terminal in the prior art, thereby improving the biometric information based.
  • the effectiveness of identity authentication and reliability further enhances the applicability of identity authentication.
  • FIG. 4 shows a block diagram of an identity authentication system in accordance with another embodiment of the present invention.
  • the identity authentication system 400 of another embodiment of the present invention is used for a server, including: a second receiving module 402, configured to receive a third biometric vector from a terminal; and a storage module 404, configured to The third biometric vector is stored as the second biometric template vector, wherein the third biometric vector is at least one third of the third biometric information of the collected preset user by the terminal.
  • the attribute information is obtained by homomorphic encryption processing.
  • the second receiving module 402 is further configured to receive a fourth biometric vector from the terminal, where the fourth biometric vector is the collected current user of the terminal pair.
  • the at least one fourth attribute information of the fourth biometric information is obtained by homomorphic encryption processing; and the identity authentication system further includes: a processing module 406, configured to use the fourth biometric vector and the second biometric
  • the template vector obtains a third Euclidean distance;
  • a second sending module 408 is configured to send the third Euclidean distance to the terminal, for the terminal to determine the fourth creature according to the third Euclidean distance Whether the feature information matches the third biometric information; and the third biometric information and the fourth biometric information include at least one of the following or a combination thereof: fingerprint image information, iris image information, and face image information .
  • the third Euclidean distance calculated according to the fourth biometric vector and the second biometric template vector is sent to the terminal, so that the terminal performs homomorphic decryption to determine whether the identity authentication is successful.
  • the fourth biometric vector is obtained by the terminal performing homomorphic encryption processing on each fourth attribute information of the fourth biometric information of the current user that is available for identity authentication, that is, a vector obtained by encryption processing.
  • the server cannot know the specific content. Thus, by combining the biometric technology with the homomorphic encryption technology, the server can perform correct biometric information matching without decryption, and can effectively avoid the user in the prior art.
  • the biometric information is stored on the terminal and is easily stolen by malicious people, which realizes the safe storage of the biometric information of the user, avoids the abuse of the biometric information of the user by the server, and further improves the security and reliability of the identity authentication based on the biometric information. , which enhances the user experience.
  • the third biometric information and the fourth biometric information include at least but not limited to one of the following or a combination thereof: fingerprint image information, iris image information, and face image information, that is, the solution may be implemented based on different biometric information, So that the server can perform correct biometric information matching without decryption, and can effectively avoid the problem that the second biometric template vector is easily maliciously stolen on the terminal in the prior art, thereby improving the biometric information based.
  • the effectiveness of identity authentication and reliability further enhances the applicability of identity authentication.
  • Figure 5 shows a block diagram of a terminal in accordance with one embodiment of the present invention.
  • the terminal 500 of an embodiment of the present invention includes: the identity authentication system 200 for the terminal 500 according to any one of the foregoing technical solutions, and thus has All the beneficial effects of the identity authentication system 200 for the terminal 500 described in any one of the technical solutions are not described herein again.
  • Figure 6 shows a block diagram of a server in accordance with one embodiment of the present invention.
  • the server 600 of an embodiment of the present invention includes the identity authentication system 400 for the server 600 according to any one of the foregoing technical solutions, and thus has any of the foregoing technical solutions. All the beneficial effects of the identity authentication system 400 for the server 600 described in the section are not described herein again.
  • FIG. 7 is a flow chart showing an identity authentication method according to still another embodiment of the present invention.
  • FIG. 8 is a flow chart showing a biometric information registration method according to an embodiment of the present invention.
  • the biometric template (ie, the first biometric template vector) is represented as a vector, and each component of the vector is homomorphically encrypted, and at least one second of the second biometric information is second.
  • the attribute information is represented in a vector form, and the at least one second attribute information represented by the vector form is homomorphically encrypted according to the preset key to generate a second biometric vector; the two vectors (ie, the second biometric vector)
  • the similarity between the first biometric template vector and the first biometric template vector is determined by the Euclidean distance of the two vectors. When the distance between the two is less than a certain threshold (ie, the preset distance), the matching is considered successful, otherwise the matching fails.
  • the mobile end decrypts the Euclidean distance between the two unencrypted vectors (ie, The second Euclidean distance) determines whether the user is authenticated successfully.
  • Enc k represents that a homomorphic encryption operation is performed with k as a key
  • Dec k represents a homomorphic decryption operation with k as a key
  • the program includes two processes: biometric registration and upload process, and identity authentication process.
  • the identity authentication method in still another embodiment of the present invention specifically includes:
  • Step 702 The mobile phone collects a biometric image of the user (ie, second biometric information).
  • Step 704 processing the biometric image, extracting the vector form to represent different features, and forming a biometric vector group, such as (t' 1 , t' 2 , ..., t' n ).
  • At least one second attribute information of the second biometric information is represented in a vector form, and the at least one second attribute information represented by the vector form is homomorphicly encrypted according to the preset key to generate the second biometric vector.
  • Step 708 uploading (e' 1 , e' 2 , . . . , e' n ) (ie, the second biometric vector) to the cloud server.
  • the cloud server reads the stored encrypted biometric template (e 1 , e 2 , . . . , e n ).
  • Step 712 the cloud server calculates the Euclidean distance of the input biometric and the registered biometric template as That is, the server generates a first Euclidean distance from the first biometric vector according to the second biometric vector.
  • the cloud server transmits the Euclidean distance (ie, the first Euclidean distance) to the mobile phone.
  • step 716 the mobile phone decrypts the Euclidean distance (ie, the first Euclidean distance) result to obtain a second Euclidean distance.
  • Step 718 The mobile phone determines whether the user authentication is successful according to the value of the dist (ie, the second Euclidean distance). If the dist is greater than or equal to a certain threshold h, the authentication succeeds, otherwise the authentication fails.
  • the value of the dist ie, the second Euclidean distance
  • the biometric information registration method of an embodiment of the present invention includes:
  • Step 802 The mobile phone collects biometric features of the current user (ie, first biometric information), where the biometric data may be fingerprints, irises, faces, etc., and images of fingerprints, irises, faces, and the like are collected.
  • biometric features of the current user ie, first biometric information
  • the biometric data may be fingerprints, irises, faces, etc.
  • Step 804 Processing the biometric image, extracting feature data (ie, first attribute information) that can be identified, and representing different feature data in a vector form to form a vector group, such as (t 1 , t 2 ,... ..., t n ).
  • feature data ie, first attribute information
  • a set of keys ie, preset keys
  • Step 808 Upload (e 1 , e 2 , . . . , e n ) (ie, the first biometric vector) to the cloud server, for the server to store the first biometric vector as the second biometric template vector.
  • step 810 the mobile phone stores the key set (k 1 , k 2 , . . . , k n ).
  • the biometric template is not stored locally in the mobile phone, and there is no risk of leakage in the local area;
  • biometric template stored in the cloud is encrypted and will not leak
  • the mobile phone collects the biometric data of the user, forms a vector, encrypts and sends it to the cloud server (ie, the server), and with the help of the cloud server, the mobile phone calculates the collected biometric data and the registered biometric template (ie, the second biometric The Euclidean distance between the feature vector and the first biometric template vector), and based on the result, judge whether the authentication is successful.
  • the cloud server ie, the server
  • the mobile phone calculates the collected biometric data and the registered biometric template (ie, the second biometric The Euclidean distance between the feature vector and the first biometric template vector), and based on the result, judge whether the authentication is successful.
  • the server can perform correct biometric information matching without decryption, and can effectively avoid the prior art. Because the user biometric information is stored on the terminal and is easily maliciously stolen, the user's biometric information is safely stored, and the security and reliability of the biometric information based identity authentication is improved, thereby improving the user experience.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Health & Medical Sciences (AREA)
  • Computing Systems (AREA)
  • General Health & Medical Sciences (AREA)
  • Biomedical Technology (AREA)
  • Theoretical Computer Science (AREA)
  • Life Sciences & Earth Sciences (AREA)
  • Biodiversity & Conservation Biology (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Collating Specific Patterns (AREA)

Abstract

本发明提出了一种身份认证方法、一种身份认证系统、一种终端和一种服务器,身份认证方法包括:采集预设用户的第一生物特征信息;将所述第一生物特征信息的至少一项第一属性信息以向量形式表示,并根据预设密钥对以向量形式表示的所述至少一项第一属性信息进行同态加密处理,以生成第一生物特征向量;将所述第一生物特征向量发送至服务器,以供所述服务器将所述第一生物特征向量存储为第一生物特征模板向量。该技术方案,实现了用户生物特征信息的安全储存与高效认证。

Description

身份认证方法、身份认证系统、终端和服务器 技术领域
本发明涉及生物识别技术领域,具体而言,涉及一种身份认证方法、一种身份认证系统、一种终端和一种服务器。
背景技术
目前,生物识别技术是指利用人体生物特征进行身份认证的技术,常见的生物识别技术包括指纹识别、人脸识别、虹膜识别等。
在移动终端(比如手机)上集成生物识别技术能够有效保护移动终端上的信息的安全,其中,生物特征模板数据的存储是个关键的问题,因为移动终端上的恶意程序可能会窃取移动终端上存储的生物特征模板数据,从而轻易通过生物识别认证,导致重要信息的泄漏,给用户带来不好的体验。
同态加密是一种特殊的加密技术,它允许人们对密文进行特定的代数运算,且得到的运算结果与对明文进行同样的运算的结果一样。换言之,这项技术令人们可以在加密的数据中进行操作,得出正确的结果,而在整个处理过程中无需对数据进行解密。但是目前的同态加密技术还无法直接应用在生物特征模板匹配这样的复杂运算上。
因此,需要一种新的身份认证方法,可以将生物识别技术与同态加密技术相结合,使服务器不需要解密就能进行正确的生物特征信息匹配,并可以有效的避免现有技术中因将用户生物特征信息存储在终端以及服务器上易被恶意窃取的问题,提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。
发明内容
本发明正是基于上述问题,提出了一种新的技术方案,通过将生物识别技术与同态加密技术相结合,使服务器不需要解密就能进行正确的生物特征信息匹配,并有效的避免现有技术中因将用户生物特征信息存储在终端上 易被恶意窃取的问题,实现了用户生物特征信息的安全储存,提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。
有鉴于此,本发明的第一方面,提出了一种身份认证方法,用于终端,包括:采集预设用户的第一生物特征信息;将所述第一生物特征信息的至少一项第一属性信息以向量形式表示,并根据预设密钥对以向量形式表示的所述至少一项第一属性信息进行同态加密处理,以生成第一生物特征向量;将所述第一生物特征向量发送至服务器,以供所述服务器将所述第一生物特征向量存储为第一生物特征模板向量。
在该技术方案中,首先进行第一生物特征模板向量的预存储过程,具体地,通过将采集到的预设用户的第一生物特征信息中可供身份认证的第一属性信息以向量形式表示,其中,可供身份认证的第一属性信息有一项或多项,而用向量形式表示每一项第一属性信息,即可得到一个表示第一生物特征信息的向量组,根据存储的预设密钥对该向量组中的每一个分向量进行同态加密,即可得到第一生物特征向量,然后将第一物特征向量发送至服务器,由服务器将其存储为第一生物特征模板向量,其中,预设密钥可以是终端随机产生的,也可以是根据用户实际需要设定的,最终存储在终端中,即将经过同态加密生成的第一生物特征模板向量存储在服务器中,而用于解密的预设密钥存储在终端中,则服务器无法获知此预设密钥,如此,通过将生物识别技术与同态加密技术相结合,使服务器不需要解密就能进行正确的生物特征信息匹配,并可以有效的避免现有技术中因将用户生物特征信息存储在终端上易被恶意窃取的问题,实现了用户生物特征信息的安全储存,提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。
在上述技术方案中,优选地,还包括:采集当前用户的第二生物特征信息;将所述第二生物特征信息的至少一项第二属性信息以向量形式表示,并根据所述预设密钥对以向量形式表示的所述至少一项第二属性信息进行同态加密处理,以生成第二生物特征向量;将所述第二生物特征向量发送至所述服务器,以供所述服务器根据所述第二生物特征向量与所述第一生物特征模板向量生成第一欧氏距离;接收来自所述服务器的所述第一欧氏距离;对所述第一欧氏距离进行同态解密处理得到第二欧氏距离;根据所述第二欧氏 距离确定所述第二生物特征信息与所述第一生物特征信息是否匹配,以确定身份认证是否成功。
在该技术方案中,通过将采集到的当前用户的第二生物特征信息中可供身份认证的第二属性信息以向量形式表示,其中,可供身份认证的第二属性信息有一项或多项,而用向量形式表示每一项第二属性信息,即可得到一个表示第二生物特征信息的向量组,根据预设密钥对该向量组中的每一个分向量进行同态加密,即可得到第二生物特征向量,然后将第二生物特征向量发送至服务器,以供服务器在不解密的情况下,计算得出第二生物特征向量与其预存储的第一生物特征模板向量的第一欧氏距离,当然,第一欧氏距离也是加密的,服务器也无法获知第一欧氏距离的具体结果,如此,可以防止服务器滥用用户的第一生物特征模板向量,确保了匹配结果的安全性。
另外,通过将第一生物特征模板向量存储在服务器中,与现有技术相比,避免了因将第一生物特征模板向量存储在终端上易被恶意窃取的问题,服务器将计算得到的第一欧氏距离发送至终端,通过终端对其进行同态解密得到第二欧氏距离,进而即可根据第二欧氏距离确定第二生物特征信息与所述第一生物特征信息是否匹配,以确定身份认证是否成功,即用于同态解密的预设密钥存储在终端中,服务器无法获知此预设密钥,进一步确保了身份认证的安全性和可靠性。
通过将生物识别技术与同态加密技术相结合,使服务器不需要解密就能进行正确的生物特征信息匹配,并可以有效的避免现有技术中因将用户生物特征信息存储在终端上易被恶意窃取的问题,实现了用户生物特征信息的安全储存,提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。
在上述技术方案中,优选地,根据所述第二欧氏距离确定所述第二生物特征信息与所述第一生物特征信息是否匹配,以确定身份认证是否成功,具体包括:判断所述第二欧氏距离是否小于或等于预设距离;以及当判定所述第二欧氏距离小于或等于所述预设距离时,所述第二生物特征信息与所述第一生物特征信息匹配成功,则身份认证成功;当判定所述第二欧氏距离大于所述预设距离时,所述第二生物特征信息与所述第一生物特征信息匹配失 败,则身份认证失败。
在该技术方案中,第二生物特征信息与所述第一生物特征信息是否匹配由第二欧氏距离决定,通过判断第二欧氏距离与预设距离的大小即可确定其是否匹配,具体地,当判定第二欧氏距离小于或等于预设距离时,第二生物特征信息与所述第一生物特征信息匹配成功,则表明用户身份认证成功,否则,身份认证失败,如此,有效的避免了现有技术中因将第一生物特征模板向量存储在终端上易被恶意窃取的问题,提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。其中,预设距离可以根据实际应用场景需要测算出来。
在上述技术方案中,优选地,所述第一生物特征信息和所述第二生物特征信息至少包括以下之一或其组合:指纹图像信息、虹膜图像信息和人脸图像信息。
在该技术方案中,第一生物特征信息和第二生物特征信息至少包含但不限于以下之一或其组合:指纹图像信息、虹膜图像信息和人脸图像信息,即本方案可以基于不同的生物特征信息实现,以使服务器不需要解密就能进行正确的生物特征信息匹配,并可以有效的避免现有技术中因将第一生物特征模板向量存储在终端上易被恶意窃取的问题,进而提高基于生物特征信息的身份认证的安全性和可靠性的效果,进一步提高了身份认证的适用性。
根据本发明的第二方面,提出了一种身份认证系统,用于终端,包括:采集模块,用于采集预设用户的第一生物特征信息;加密模块,用于将所述第一生物特征信息的至少一项第一属性信息以向量形式表示,并根据预设密钥对以向量形式表示的所述至少一项第一属性信息进行同态加密处理,以生成第一生物特征向量;第一发送模块,用于将所述第一生物特征向量发送至服务器,以供所述服务器将所述第一生物特征向量存储为第一生物特征模板向量。
在该技术方案中,首先进行第一生物特征模板向量的预存储过程,具体地,通过将采集到的预设用户的第一生物特征信息中可供身份认证的第一属性信息以向量形式表示,其中,可供身份认证的第一属性信息有一项或多项,而用向量形式表示每一项第一属性信息,即可得到一个表示第一生物特 征信息的向量组,根据存储的预设密钥对该向量组中的每一个分向量进行同态加密,即可得到第一生物特征向量,然后将第一物特征向量发送至服务器,由服务器将其存储为第一生物特征模板向量,其中,预设密钥可以是终端随机产生的,也可以是根据用户实际需要设定的,最终存储在终端中,即将经过同态加密生成的第一生物特征模板向量存储在服务器中,而用于解密的预设密钥存储在终端中,则服务器无法获知此预设密钥,如此,通过将生物识别技术与同态加密技术相结合,使服务器不需要解密就能进行正确的生物特征信息匹配,并可以有效的避免现有技术中因将用户生物特征信息存储在终端上易被恶意窃取的问题,实现了用户生物特征信息的安全储存,提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。
在上述技术方案中,优选地,所述采集模块还用于采集当前用户的第二生物特征信息;所述加密模块还用于将所述第二生物特征信息的至少一项第二属性信息以向量形式表示,并根据所述预设密钥对以向量形式表示的所述至少一项第二属性信息进行同态加密处理,以生成第二生物特征向量;所述第一发送模块还用于将所述第二生物特征向量发送至所述服务器,以供所述服务器根据所述第二生物特征向量与所述第一生物特征模板向量生成第一欧氏距离;以及所述身份认证系统还包括:第一接收模块,用于接收来自所述服务器的所述第一欧氏距离;解密模块,用于对所述第一欧氏距离进行同态解密处理得到第二欧氏距离;判断模块,用于根据所述第二欧氏距离确定所述第二生物特征信息与所述第一生物特征信息是否匹配,以确定身份认证是否成功。
在该技术方案中,通过将采集到的当前用户的第二生物特征信息中可供身份认证的第二属性信息以向量形式表示,其中,可供身份认证的第二属性信息有一项或多项,而用向量形式表示每一项第二属性信息,即可得到一个表示第二生物特征信息的向量组,根据预设密钥对该向量组中的每一个分向量进行同态加密,即可得到第二生物特征向量,然后将第二生物特征向量发送至服务器,以供服务器在不解密的情况下,计算得出第二生物特征向量与其预存储的第一生物特征模板向量的第一欧氏距离,当然,第一欧氏距离也是加密的,服务器也无法获知第一欧氏距离的具体结果,如此,可以防止 服务器滥用用户的第一生物特征模板向量,确保了匹配结果的安全性。
另外,通过将第一生物特征模板向量存储在服务器中,与现有技术相比,避免了因将第一生物特征模板向量存储在终端上易被恶意窃取的问题,服务器将计算得到的第一欧氏距离发送至终端,通过终端对其进行同态解密得到第二欧氏距离,进而即可根据第二欧氏距离确定第二生物特征信息与所述第一生物特征信息是否匹配,以确定身份认证是否成功,即用于同态解密的预设密钥存储在终端中,服务器无法获知此预设密钥,进一步确保了身份认证的安全性和可靠性。
通过将生物识别技术与同态加密技术相结合,使服务器不需要解密就能进行正确的生物特征信息匹配,并可以有效的避免现有技术中因将用户生物特征信息存储在终端上易被恶意窃取的问题,实现了用户生物特征信息的安全储存,提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。
在上述技术方案中,优选地,所述判断模块具体用于判断所述第二欧氏距离是否小于或等于预设距离;以及当判定所述第二欧氏距离小于或等于所述预设距离时,所述第二生物特征信息与所述第一生物特征信息匹配成功,则身份认证成功;当判定所述第二欧氏距离大于所述预设距离时,所述第二生物特征信息与所述第一生物特征信息匹配失败,则身份认证失败。
在该技术方案中,第二生物特征信息与第一生物特征信息是否匹配由第二欧氏距离决定,通过判断第二欧氏距离与预设距离的大小即可确定其是否匹配,具体地,当判定第二欧氏距离小于或等于预设距离时,第二生物特征信息与第一生物特征信息匹配成功,则表明用户身份认证成功,否则,身份认证失败,如此,有效的避免了现有技术中因将第一生物特征模板向量存储在终端上易被恶意窃取的问题,提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。其中,预设距离可以根据实际应用场景需要测算出来。
在上述技术方案中,优选地,所述第一生物特征信息和所述第二生物特征信息至少包括以下之一或其组合:指纹图像信息、虹膜图像信息和人脸图像信息。
在该技术方案中,第一生物特征信息和第二生物特征信息至少包含但不限于以下之一或其组合:指纹图像信息、虹膜图像信息和人脸图像信息,即本方案可以基于不同的生物特征信息实现,以使服务器不需要解密就能进行正确的生物特征信息匹配,并可以有效的避免现有技术中因将第一生物特征模板向量存储在终端上易被恶意窃取的问题,进而提高基于生物特征信息的身份认证的安全性和可靠性的效果,进一步提高了身份认证的适用性。
根据本发明的第三方面,提出了一种身份认证方法,用于服务器,包括:接收来自终端的第三生物特征向量;将所述第三生物特征向量存储为所述第二生物特征模板向量,其中,所述第三生物特征向量为所述终端对采集到的预设用户的第三生物特征信息的至少一项第三属性信息进行同态加密处理得到的。
在该技术方案中,首先进行第二生物特征模板向量存储的过程,具体地,通过将接收到的来自终端的第三生物特征向量存储为第二生物特征模板向量,以为后续匹配步骤的顺利进行提供必要的前提保障,其中,第三生物特征向量是终端对采集到的预设用户的第三生物特征信息的可供身份认证的每一项第三属性信息进行同态加密处理得到的,即是经加密处理得到的向量,服务器同样无法获知其具体内容,如此,避免了服务器滥用用户的生物特征信息,进一步提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。
在上述技术方案中,优选地,还包括:接收来自所述终端的第四生物特征向量,其中,所述第四生物特征向量为所述终端对采集到的当前用户的第四生物特征信息的至少一项第四属性信息进行同态加密处理得到的;根据所述第四生物特征向量与第二生物特征模板向量得到第三欧氏距离;将所述第三欧氏距离发送至所述终端,以供所述终端根据所述第三欧氏距离确定所述第四生物特征信息与所述第三生物特征信息是否匹配;以及所述第三生物特征信息和所述第四生物特征信息至少包括以下之一或其组合:指纹图像信息、虹膜图像信息和人脸图像信息。
在该技术方案中,通过将根据第四生物特征向量与第二生物特征模板向量计算得到的第三欧氏距离发送至终端,以供终端对其进行同态解密,进 而确定身份认证是否成功,其中,第四生物特征向量是终端对采集到的当前用户的第四生物特征信息的可供身份认证的每一项第四属性信息进行同态加密处理得到的,即是经加密处理得到的向量,服务器无法获知其具体内容,如此,通过将生物识别技术与同态加密技术相结合,使服务器不需要解密就能进行正确的生物特征信息匹配,并可以有效的避免现有技术中因将用户生物特征信息存储在终端上易被恶意窃取的问题,实现了用户生物特征信息的安全储存,避免了服务器滥用用户的生物特征信息,进一步提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。
另外,第三生物特征信息和第四生物特征信息至少包含但不限于以下之一或其组合:指纹图像信息、虹膜图像信息和人脸图像信息,即本方案可以基于不同的生物特征信息实现,以使服务器不需要解密就能进行正确的生物特征信息匹配并可以有效的避免现有技术中因将第二生物特征模板向量存储在终端上易被恶意窃取的问题,进而提高基于生物特征信息的身份认证的安全性和可靠性的效果,进一步提高了身份认证的适用性。
根据本发明的第四方面,提出了一种身份认证系统,用于服务器,包括:第二接收模块,用于接收来自终端的第三生物特征向量;存储模块,用于将所述第三生物特征向量存储为所述第二生物特征模板向量,其中,所述第三生物特征向量为所述终端对采集到的预设用户的第三生物特征信息的至少一项第三属性信息进行同态加密处理得到的。
在该技术方案中,首先进行第二生物特征模板向量存储的过程,具体地,通过将接收到的来自终端的第三生物特征向量存储为第二生物特征模板向量,以为后续匹配步骤的顺利进行提供必要的前提保障,其中,第三生物特征向量是终端对采集到的预设用户的第三生物特征信息的可供身份认证的每一项第三属性信息进行同态加密处理得到的,即是经加密处理得到的向量,服务器同样无法获知其具体内容,如此,避免了服务器滥用用户的生物特征信息,进一步提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。
在上述技术方案中,优选地,所述第二接收模块还用于接收来自所述终端的第四生物特征向量,其中,所述第四生物特征向量为所述终端对采集 到的当前用户的第四生物特征信息的至少一项第四属性信息进行同态加密处理得到的;所述身份认证系统还包括:处理模块还用于根据所述第四生物特征向量与第二生物特征模板向量得到第三欧氏距离;以及所述身份认证系统还包括:第二发送模块,用于将所述第三欧氏距离发送至所述终端,以供所述终端根据所述第三欧氏距离确定所述第四生物特征信息与所述第三生物特征信息是否匹配;以及所述第三生物特征信息和所述第四生物特征信息至少包括以下之一或其组合:指纹图像信息、虹膜图像信息和人脸图像信息。
在该技术方案中,通过将根据第四生物特征向量与第二生物特征模板向量计算得到的第三欧氏距离发送至终端,以供终端对其进行同态解密,进而确定身份认证是否成功,其中,第四生物特征向量是终端对采集到的当前用户的第四生物特征信息的可供身份认证的每一项第四属性信息进行同态加密处理得到的,即是经加密处理得到的向量,服务器无法获知其具体内容,如此,通过将生物识别技术与同态加密技术相结合,使服务器不需要解密就能进行正确的生物特征信息匹配,并可以有效的避免现有技术中因将用户生物特征信息存储在终端上易被恶意窃取的问题,实现了用户生物特征信息的安全储存,避免了服务器滥用用户的生物特征信息,进一步提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。
另外,第三生物特征信息和第四生物特征信息至少包含但不限于以下之一或其组合:指纹图像信息、虹膜图像信息和人脸图像信息,即本方案可以基于不同的生物特征信息实现,以使服务器不需要解密就能进行正确的生物特征信息匹配并可以有效的避免现有技术中因将第二生物特征模板向量存储在终端上易被恶意窃取的问题,进而提高基于生物特征信息的身份认证的安全性和可靠性的效果,进一步提高了身份认证的适用性。
根据本发明的第五方面,提出了一种终端,包括:如上述技术方案中任一项所述的用于终端的所述的身份认证系统,因此具有上述技术方案中任一项所述的用于终端的所述的身份认证系统的所有有益效果,这里不再赘述。
根据本发明的第六方面,提出了一种服务器,包括:如上述技术方案中任一项所述的用于服务器的所述的身份认证系统,因此具有上述技术方 案中任一项所述的用于服务器的所述的身份认证系统的所有有益效果,这里不再赘述。
通过本发明的技术方案,可以将生物识别技术与同态加密技术相结合,使服务器不需要解密就能进行正确的生物特征信息匹配,并可以有效的避免现有技术中因将用户生物特征信息存储在终端上易被恶意窃取的问题,实现了用户生物特征信息的安全储存,提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。
附图说明
图1示出了根据本发明的一个实施例的身份认证方法的流程示意图;
图2示出了根据本发明的一个实施例的身份认证系统的框图;
图3示出了根据本发明的另一个实施例的身份认证方法的流程示意图;
图4示出了根据本发明的另一个实施例的身份认证系统的框图;
图5示出了根据本发明的一个实施例的终端的框图;
图6示出了根据本发明的一个实施例的服务器的框图;
图7示出了根据本发明的又一个实施例的身份认证方法的流程示意图;
图8示出了根据本发明的一个实施例的生物特征信息注册方法的流程示意图。
具体实施方式
为了可以更清楚地理解本发明的上述目的、特征和优点,下面结合附图和具体实施方式对本发明进行进一步的详细描述。需要说明的是,在不冲突的情况下,本申请的实施例及实施例中的特征可以相互组合。
在下面的描述中阐述了很多具体细节以便于充分理解本发明,但是,本发明还可以采用其他不同于在此描述的其他方式来实施,因此,本发明的保护范围并不受下面公开的具体实施例的限制。
图1示出了根据本发明的一个实施例的身份认证方法的流程示意图。
如图1所示,本发明的一个实施例的身份认证方法,用于终端,包括:步骤102,采集预设用户的第一生物特征信息;步骤104将所述第一生物特征信息的至少一项第一属性信息以向量形式表示,并根据预设密钥对以向量形式表示的所述至少一项第一属性信息进行同态加密处理,以生成第一生物特征向量;步骤106将所述第一生物特征向量发送至服务器,以供所述服务器将所述第一生物特征向量存储为第一生物特征模板向量。
在该技术方案中,首先进行第一生物特征模板向量的预存储过程,具体地,通过将采集到的预设用户的第一生物特征信息中可供身份认证的第一属性信息以向量形式表示,其中,可供身份认证的第一属性信息有一项或多项,而用向量形式表示每一项第一属性信息,即可得到一个表示第一生物特征信息的向量组,根据存储的预设密钥对该向量组中的每一个分向量进行同态加密,即可得到第一生物特征向量,然后将第一物特征向量发送至服务器,由服务器将其存储为第一生物特征模板向量,其中,预设密钥可以是终端随机产生的,也可以是根据用户实际需要设定的,最终存储在终端中,即将经过同态加密生成的第一生物特征模板向量存储在服务器中,而用于解密的预设密钥存储在终端中,则服务器无法获知此预设密钥,如此,通过将生物识别技术与同态加密技术相结合,使服务器不需要解密就能进行正确的生物特征信息匹配,并可以有效的避免现有技术中因将用户生物特征信息存储在终端上易被恶意窃取的问题,实现了用户生物特征信息的安全储存,提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。
在上述技术方案中,优选地,还包括:采集当前用户的第二生物特征信息;将所述第二生物特征信息的至少一项第二属性信息以向量形式表示,并根据所述预设密钥对以向量形式表示的所述至少一项第二属性信息进行同态加密处理,以生成第二生物特征向量;将所述第二生物特征向量发送至所述服务器,以供所述服务器根据所述第二生物特征向量与所述第一生物特征模板向量生成第一欧氏距离;接收来自所述服务器的所述第一欧氏距离;对所述第一欧氏距离进行同态解密处理得到第二欧氏距离;根据所述第二欧氏距离确定所述第二生物特征信息与所述第一生物特征信息是否匹配,以确定身份认证是否成功。
在该技术方案中,通过将采集到的当前用户的第二生物特征信息中可供身份认证的第二属性信息以向量形式表示,其中,可供身份认证的第二属性信息有一项或多项,而用向量形式表示每一项第二属性信息,即可得到一个表示第二生物特征信息的向量组,根据预设密钥对该向量组中的每一个分向量进行同态加密,即可得到第二生物特征向量,然后将第二生物特征向量发送至服务器,以供服务器在不解密的情况下,计算得出第二生物特征向量与其预存储的第一生物特征模板向量的第一欧氏距离,当然,第一欧氏距离也是加密的,服务器也无法获知第一欧氏距离的具体结果,如此,可以防止服务器滥用用户的第一生物特征模板向量,确保了匹配结果的安全性。
另外,通过将第一生物特征模板向量存储在服务器中,与现有技术相比,避免了因将第一生物特征模板向量存储在终端上易被恶意窃取的问题,服务器将计算得到的第一欧氏距离发送至终端,通过终端对其进行同态解密得到第二欧氏距离,进而即可根据第二欧氏距离确定第二生物特征信息与所述第一生物特征信息是否匹配,以确定身份认证是否成功,即用于同态解密的预设密钥存储在终端中,服务器无法获知此预设密钥,进一步确保了身份认证的安全性和可靠性。
通过将生物识别技术与同态加密技术相结合,使服务器不需要解密就能进行正确的生物特征信息匹配,并可以有效的避免现有技术中因将用户生物特征信息存储在终端上易被恶意窃取的问题,实现了用户生物特征信息的安全储存,提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。
在上述技术方案中,优选地,根据所述第二欧氏距离确定所述第二生物特征信息与所述第一生物特征信息是否匹配,以确定身份认证是否成功,具体包括:判断所述第二欧氏距离是否小于或等于预设距离;以及当判定所述第二欧氏距离小于或等于所述预设距离时,所述第二生物特征信息与所述第一生物特征信息匹配成功,则身份认证成功;当判定所述第二欧氏距离大于所述预设距离时,所述第二生物特征信息与所述第一生物特征信息匹配失败,则身份认证失败。
在该技术方案中,第二生物特征信息与所述第一生物特征信息是否匹配 由第二欧氏距离决定,通过判断第二欧氏距离与预设距离的大小即可确定其是否匹配,具体地,当判定第二欧氏距离小于或等于预设距离时,所述第二生物特征信息与所述第一生物特征信息匹配成功,则表明用户身份认证成功,否则,身份认证失败,如此,有效的避免了现有技术中因将第一生物特征模板向量存储在终端上易被恶意窃取的问题,提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。其中,预设距离可以根据实际应用场景需要测算出来。
在上述技术方案中,优选地,所述第一生物特征信息和所述第二生物特征信息至少包括以下之一或其组合:指纹图像信息、虹膜图像信息和人脸图像信息。
在该技术方案中,第一生物特征信息和第二生物特征信息至少包含但不限于以下之一或其组合:指纹图像信息、虹膜图像信息和人脸图像信息,即本方案可以基于不同的生物特征信息实现,以使服务器不需要解密就能进行正确的生物特征信息匹配,并可以有效的避免现有技术中因将第一生物特征模板向量存储在终端上易被恶意窃取的问题,进而提高基于生物特征信息的身份认证的安全性和可靠性的效果,进一步提高了身份认证的适用性。
图2示出了根据本发明的一个实施例的身份认证系统的框图。
如图2所示,本发明的一个实施例的身份认证系统200,用于终端,包括:采集模块202,用于采集预设用户的第一生物特征信息;加密模块204,用于将所述第一生物特征信息的至少一项第一属性信息以向量形式表示,并根据预设密钥对以向量形式表示的所述至少一项第一属性信息进行同态加密处理,以生成第一生物特征向量;第一发送模块206,用于将所述第一生物特征向量发送至服务器,以供所述服务器将所述第一生物特征向量存储为第一生物特征模板向量。
在该技术方案中,首先进行第一生物特征模板向量的预存储过程,具体地,通过将采集到的预设用户的第一生物特征信息中可供身份认证的第一属性信息以向量形式表示,其中,可供身份认证的第一属性信息有一项或多项,而用向量形式表示每一项第一属性信息,即可得到一个表示第一生物特征信息的向量组,根据存储的预设密钥对该向量组中的每一个分向量进行同 态加密,即可得到第一生物特征向量,然后将第一物特征向量发送至服务器,由服务器将其存储为第一生物特征模板向量,其中,预设密钥可以是终端随机产生的,也可以是根据用户实际需要设定的,最终存储在终端中,即将经过同态加密生成的第一生物特征模板向量存储在服务器中,而用于解密的预设密钥存储在终端中,则服务器无法获知此预设密钥,如此,通过将生物识别技术与同态加密技术相结合,使服务器不需要解密就能进行正确的生物特征信息匹配,并可以有效的避免现有技术中因将用户生物特征信息存储在终端上易被恶意窃取的问题,实现了用户生物特征信息的安全储存,提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。
在上述技术方案中,优选地,所述采集模块202还用于采集当前用户的第二生物特征信息;所述加密模块204还用于将所述第二生物特征信息的至少一项第二属性信息以向量形式表示,并根据所述预设密钥对以向量形式表示的所述至少一项第二属性信息进行同态加密处理,以生成第二生物特征向量;所述第一发送模块206还用于将所述第二生物特征向量发送至所述服务器,以供所述服务器根据所述第二生物特征向量与所述第一生物特征模板向量生成第一欧氏距离;以及所述身份认证系统200还包括:第一接收模块208,用于接收来自所述服务器的所述第一欧氏距离;解密模块210,用于对所述第一欧氏距离进行同态解密处理得到第二欧氏距离;判断模块212,用于根据所述第二欧氏距离确定所述第二生物特征信息与所述第一生物特征信息是否匹配,以确定身份认证是否成功。
在该技术方案中,通过将采集到的当前用户的第二生物特征信息中可供身份认证的第二属性信息以向量形式表示,其中,可供身份认证的第二属性信息有一项或多项,而用向量形式表示每一项第二属性信息,即可得到一个表示第二生物特征信息的向量组,根据预设密钥对该向量组中的每一个分向量进行同态加密,即可得到第二生物特征向量,然后将第二生物特征向量发送至服务器,以供服务器在不解密的情况下,计算得出第二生物特征向量与其预存储的第一生物特征模板向量的第一欧氏距离,当然,第一欧氏距离也是加密的,服务器也无法获知第一欧氏距离的具体结果,如此,可以防止服务器滥用用户的第一生物特征模板向量,确保了匹配结果的安全性。
另外,通过将第一生物特征模板向量存储在服务器中,与现有技术相比,避免了因将第一生物特征模板向量存储在终端上易被恶意窃取的问题,服务器将计算得到的第一欧氏距离发送至终端,通过终端对其进行同态解密得到第二欧氏距离,进而即可根据第二欧氏距离确定第二生物特征信息与所述第一生物特征信息是否匹配,以确定身份认证是否成功,即用于同态解密的预设密钥存储在终端中,服务器无法获知此预设密钥,进一步确保了身份认证的安全性和可靠性。
通过将生物识别技术与同态加密技术相结合,使服务器不需要解密就能进行正确的生物特征信息匹配,并可以有效的避免现有技术中因将用户生物特征信息存储在终端上易被恶意窃取的问题,实现了用户生物特征信息的安全储存,提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。
在上述技术方案中,优选地,所述判断模块212具体用于判断所述第二欧氏距离是否小于或等于预设距离;以及当判定所述第二欧氏距离小于或等于所述预设距离时,所述第二生物特征信息与所述第一生物特征信息匹配成功,则身份认证成功;当判定所述第二欧氏距离大于所述预设距离时,所述第二生物特征信息与所述第一生物特征信息匹配失败,则身份认证失败。
在该技术方案中,第二生物特征信息与第一生物特征信息是否匹配由第二欧氏距离决定,通过判断第二欧氏距离与预设距离的大小即可确定其是否匹配,具体地,当判定第二欧氏距离小于或等于预设距离时,第二生物特征信息与第一生物特征信息匹配成功,则表明用户身份认证成功,否则,身份认证失败,如此,有效的避免了现有技术中因将第一生物特征模板向量存储在终端上易被恶意窃取的问题,提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。其中,预设距离可以根据实际应用场景需要测算出来。
在上述技术方案中,优选地,所述第一生物特征信息和所述第二生物特征信息至少包括以下之一或其组合:指纹图像信息、虹膜图像信息和人脸图像信息。
在该技术方案中,第一生物特征信息和第二生物特征信息至少包含但不限于以下之一或其组合:指纹图像信息、虹膜图像信息和人脸图像信息,即本方案可以基于不同的生物特征信息实现,以使服务器不需要解密就能进行正确的生物特征信息匹配,并可以有效的避免现有技术中因将第一生物特征模板向量存储在终端上易被恶意窃取的问题,进而提高基于生物特征信息的身份认证的安全性和可靠性的效果,进一步提高了身份认证的适用性。
图3示出了根据本发明的另一个实施例的身份认证方法的流程示意图。
如图3所示,本发明的另一个实施例的身份认证方法,用于服务器,包括:步骤302,接收来自终端的第三生物特征向量;步骤304,将所述第三生物特征向量存储为所述第二生物特征模板向量,其中,所述第三生物特征向量为所述终端对采集到的预设用户的第三生物特征信息的至少一项第三属性信息进行同态加密处理得到的。
在该技术方案中,首先进行第二生物特征模板向量存储的过程,具体地,通过将接收到的来自终端的第三生物特征向量存储为第二生物特征模板向量,以为后续匹配步骤的顺利进行提供必要的前提保障,其中,第三生物特征向量是终端对采集到的预设用户的第三生物特征信息的可供身份认证的每一项第三属性信息进行同态加密处理得到的,即是经加密处理得到的向量,服务器同样无法获知其具体内容,如此,避免了服务器滥用用户的生物特征信息,进一步提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。
在上述技术方案中,优选地,还包括:接收来自所述终端的第四生物特征向量,其中,所述第四生物特征向量为所述终端对采集到的当前用户的第四生物特征信息的至少一项第四属性信息进行同态加密处理得到的;根据所述第四生物特征向量与第二生物特征模板向量得到第三欧氏距离;将所述第三欧氏距离发送至所述终端,以供所述终端根据所述第三欧氏距离确定所述第四生物特征信息与所述第三生物特征信息是否匹配;以及所述第三生物特征信息和所述第四生物特征信息至少包括以下之一或其组合:指纹图像信息、虹膜图像信息和人脸图像信息。
在该技术方案中,通过将根据第四生物特征向量与第二生物特征模板向量计算得到的第三欧氏距离发送至终端,以供终端对其进行同态解密,进而确定身份认证是否成功,其中,第四生物特征向量是终端对采集到的当前用户的第四生物特征信息的可供身份认证的每一项第四属性信息进行同态加密处理得到的,即是经加密处理得到的向量,服务器无法获知其具体内容,如此,通过将生物识别技术与同态加密技术相结合,使服务器不需要解密就能进行正确的生物特征信息匹配,并可以有效的避免现有技术中因将用户生物特征信息存储在终端上易被恶意窃取的问题,实现了用户生物特征信息的安全储存,避免了服务器滥用用户的生物特征信息,进一步提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。
另外,第三生物特征信息和第四生物特征信息至少包含但不限于以下之一或其组合:指纹图像信息、虹膜图像信息和人脸图像信息,即本方案可以基于不同的生物特征信息实现,以使服务器不需要解密就能进行正确的生物特征信息匹配并可以有效的避免现有技术中因将第二生物特征模板向量存储在终端上易被恶意窃取的问题,进而提高基于生物特征信息的身份认证的安全性和可靠性的效果,进一步提高了身份认证的适用性。
图4示出了根据本发明的另一个实施例的身份认证系统的框图。
如图4所示,本发明的另一个实施例的身份认证系统400,用于服务器,包括:第二接收模块402,用于接收来自终端的第三生物特征向量;存储模块404,用于将所述第三生物特征向量存储为所述第二生物特征模板向量,其中,所述第三生物特征向量为所述终端对采集到的预设用户的第三生物特征信息的至少一项第三属性信息进行同态加密处理得到的。
在该技术方案中,首先进行第二生物特征模板向量存储的过程,具体地,通过将接收到的来自终端的第三生物特征向量存储为第二生物特征模板向量,以为后续匹配步骤的顺利进行提供必要的前提保障,其中,第三生物特征向量是终端对采集到的预设用户的第三生物特征信息的可供身份认证的每一项第三属性信息进行同态加密处理得到的,即是经加密处理得到的向量,服务器同样无法获知其具体内容,如此,避免了服务器滥用用户的生物特征信息,进一步提高了基于生物特征信息的身份认证的安全性和可靠性, 从而提升了用户体验。
在上述技术方案中,优选地,所述第二接收模块402还用于接收来自所述终端的第四生物特征向量,其中,所述第四生物特征向量为所述终端对采集到的当前用户的第四生物特征信息的至少一项第四属性信息进行同态加密处理得到的;以及所述身份认证系统还包括:处理模块406,用于根据所述第四生物特征向量与第二生物特征模板向量得到第三欧氏距离;第二发送模块408,用于将所述第三欧氏距离发送至所述终端,以供所述终端根据所述第三欧氏距离确定所述第四生物特征信息与所述第三生物特征信息是否匹配;以及所述第三生物特征信息和所述第四生物特征信息至少包括以下之一或其组合:指纹图像信息、虹膜图像信息和人脸图像信息。
在该技术方案中,通过将根据第四生物特征向量与第二生物特征模板向量计算得到的第三欧氏距离发送至终端,以供终端对其进行同态解密,进而确定身份认证是否成功,其中,第四生物特征向量是终端对采集到的当前用户的第四生物特征信息的可供身份认证的每一项第四属性信息进行同态加密处理得到的,即是经加密处理得到的向量,服务器无法获知其具体内容,如此,通过将生物识别技术与同态加密技术相结合,使服务器不需要解密就能进行正确的生物特征信息匹配,并可以有效的避免现有技术中因将用户生物特征信息存储在终端上易被恶意窃取的问题,实现了用户生物特征信息的安全储存,避免了服务器滥用用户的生物特征信息,进一步提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。
另外,第三生物特征信息和第四生物特征信息至少包含但不限于以下之一或其组合:指纹图像信息、虹膜图像信息和人脸图像信息,即本方案可以基于不同的生物特征信息实现,以使服务器不需要解密就能进行正确的生物特征信息匹配并可以有效的避免现有技术中因将第二生物特征模板向量存储在终端上易被恶意窃取的问题,进而提高基于生物特征信息的身份认证的安全性和可靠性的效果,进一步提高了身份认证的适用性。
图5示出了根据本发明的一个实施例的终端的框图。
如图5所示,本发明的一个实施例的终端500,包括:如上述技术方案中任一项所述的用于终端500的所述的身份认证系统200,因此具有上 述技术方案中任一项所述的用于终端500的所述的身份认证系统200的所有有益效果,这里不再赘述。
图6示出了根据本发明的一个实施例的服务器的框图。
如图6所示,本发明的一个实施例的服务器600,包括:如上述技术方案中任一项所述的用于服务器600的所述的身份认证系统400,因此具有上述技术方案中任一项所述的用于服务器600的所述的身份认证系统400的所有有益效果,这里不再赘述。
下面结合图7和图8详细说明本发明的技术方案:
图7示出了根据本发明的又一个实施例的身份认证方法的流程示意图。
图8示出了根据本发明的一个实施例的生物特征信息注册方法的流程示意图。
在本实施例中将生物特征模板(即第一生物特征模板向量)表示为向量的形式,并对该向量的每个分量分别进行同态加密,将第二生物特征信息的至少一项第二属性信息以向量形式表示,并根据预设密钥对以向量形式表示的至少一项第二属性信息进行同态加密处理,以生成第二生物特征向量;两个向量(即第二生物特征向量与第一生物特征模版向量)之间的相似度由这两个向量的欧氏距离决定,当二者之间的距离小于某个阈值(即预设距离)时,认为匹配成功,否则匹配失败;在云端计算加密后的两个向量之间的欧氏距离(即第一欧氏距离),结果发送给手机端后,手机端解密得到未加密的两个向量之间的欧氏距离(即第二欧氏距离),从而判定用户是否认证成功。
本方案描述中Enck表示以k为密钥执行同态加密操作,Deck表示以k为密钥执行同态解密操作;
本方案包括两个流程:生物特征注册及上传过程、身份认证过程。
如图7所示,本发明的又一个实施例的身份认证方法,具体包括:
步骤702,手机采集用户的生物特征图像(即第二生物特征信息)。
步骤704,对生物特征图像进行处理,提取出向量形式表示不同的特征,形成生物特征向量组,比如(t′1,t′2,……,t′n)。
步骤706,读取手机存储的密钥组(k1,k2,……,kn),对上述特征向量中每 个分量分别进行同态加密,得到
Figure PCTCN2015088472-appb-000001
(即第二生物特征向量),其中i=1,2,……,n。
即将第二生物特征信息的至少一项第二属性信息以向量形式表示,并根据预设密钥对以向量形式表示的至少一项第二属性信息进行同态加密处理,以生成第二生物特征向量。
步骤708,将(e′1,e′2,……,e′n)(即第二生物特征向量)上传至云服务器。
步骤710,云服务器读取所存储的加密生物特征模板(e1,e2,……,en)。
步骤712,云服务器计算出输入生物特征和注册生物特征模板的欧氏距离为
Figure PCTCN2015088472-appb-000002
即服务器根据所述第二生物特征向量与第一生物特征向量生成第一欧氏距离。
步骤714,云服务器将欧氏距离(即第一欧氏距离)发送给手机。
步骤716,手机将欧氏距离(即第一欧氏距离)结果解密,得到第二欧氏距离。
步骤718,手机根据dist(即第二欧氏距离)的值判断用户认证是否成功,若dist大于或等于某个阈值h,则认证成功,否则认证失败
如图8所示,本发明的一个实施例的生物特征信息注册方法,包括:
步骤802,手机采集当前用户的生物特征(即第一生物特征信息),这里的生物特征数据可以是指纹、虹膜、人脸等,采集到的是指纹、虹膜、人脸等的图像。
步骤804,对生物特征图像进行处理,提取出可供身份识别的特征数据(即第一属性信息),并以向量形式表示不同的特征数据,形成向量组,比如(t1,t2,……,tn)。
步骤806,选定一组密钥(即预设密钥)比如:k1,k2,……,kn,对向量组(t1,t2,……,tn)中每个分量分别进行同态加密,得到
Figure PCTCN2015088472-appb-000003
(即第二生物特征向量),其中i=1,2,……,n。
步骤808,将(e1,e2,……,en)(即第一生物特征向量)上传至云服务器,以供服务器将所述第一生物特征向量存储为第二生物特征模板向量。
步骤810,手机存储密钥组(k1,k2,……,kn)。
本实施例的有益效果:
1、手机本地不存储生物特征模板,本地没有泄露风险;
2、云端存储的生物特征模板经过加密,不会泄漏;
3、使用同态加密方案,确保了经过加密的生物特征模板不需要解密就能执行用户认证。
本实施例中,手机采集用户的生物特征数据,形成向量后加密并发送到云服务器(即服务器),在云服务器帮助下,手机计算出所采集生物特征数据和注册生物特征模板(即第二生物特征向量与第一生物特征模板向量)之间的欧氏距离,并根据结果判断认证是否成功。
以上结合附图详细说明了本发明的技术方案,通过将生物识别技术与同态加密技术相结合,使服务器不需要解密就能进行正确的生物特信息征匹配,并可以有效的避免现有技术中因将用户生物特征信息存储在终端上易被恶意窃取的问题,实现了用户生物特征信息的安全储存,提高了基于生物特征信息的身份认证的安全性和可靠性,从而提升了用户体验。
以上所述仅为本发明的优选实施例而已,并不用于限制本发明,对于本领域的技术人员来说,本发明可以有各种更改和变化。凡在本发明的精神和原则之内,所作的任何修改、等同替换、改进等,均应包含在本发明的保护范围之内。

Claims (14)

  1. 一种身份认证方法,用于终端,其特征在于,包括:
    采集预设用户的第一生物特征信息;
    将所述第一生物特征信息的至少一项第一属性信息以向量形式表示,并根据预设密钥对以向量形式表示的所述至少一项第一属性信息进行同态加密处理,以生成第一生物特征向量;
    将所述第一生物特征向量发送至服务器,以供所述服务器将所述第一生物特征向量存储为第一生物特征模板向量。
  2. 根据权利要求1所述的身份认证方法,其特征在于,还包括:
    采集当前用户的第二生物特征信息;
    将所述第二生物特征信息的至少一项第二属性信息以向量形式表示,并根据所述预设密钥对以向量形式表示的所述至少一项第二属性信息进行同态加密处理,以生成第二生物特征向量;
    将所述第二生物特征向量发送至所述服务器,以供所述服务器根据所述第二生物特征向量与所述第一生物特征模板向量生成第一欧氏距离;
    接收来自所述服务器的所述第一欧氏距离;
    对所述第一欧氏距离进行同态解密处理得到第二欧氏距离;
    根据所述第二欧氏距离确定所述第二生物特征信息与所述第一生物特征信息是否匹配,以确定身份认证是否成功。
  3. 根据权利要求2所述的身份认证方法,其特征在于,根据所述第二欧氏距离确定所述第二生物特征信息与所述第一生物特征信息是否匹配,以确定身份认证是否成功,具体包括:
    判断所述第二欧氏距离是否小于或等于预设距离;以及
    当判定所述第二欧氏距离小于或等于所述预设距离时,所述第二生物特征信息与所述第一生物特征信息匹配成功,则身份认证成功;
    当判定所述第二欧氏距离大于所述预设距离时,所述第二生物特征信息与所述第一生物特征信息匹配失败,则身份认证失败。
  4. 根据权利要求1至3中任一项所述的身份认证方法,其特征在于,
    所述第一生物特征信息和所述第二生物特征信息至少包括以下之一或其组合:指纹图像信息、虹膜图像信息和人脸图像信息。
  5. 一种身份认证系统,用于终端,其特征在于,包括:
    采集模块,用于采集预设用户的第一生物特征信息;
    加密模块,用于将所述第一生物特征信息的至少一项第一属性信息以向量形式表示,并根据预设密钥对以向量形式表示的所述至少一项第一属性信息进行同态加密处理,以生成第一生物特征向量;
    第一发送模块,用于将所述第一生物特征向量发送至服务器,以供所述服务器将所述第一生物特征向量存储为第一生物特征模板向量。
  6. 根据权利要求5所述的身份认证系统,其特征在于,
    所述采集模块还用于采集当前用户的第二生物特征信息;
    所述加密模块还用于将所述第二生物特征信息的至少一项第二属性信息以向量形式表示,并根据所述预设密钥对以向量形式表示的所述至少一项第二属性信息进行同态加密处理,以生成第二生物特征向量;
    所述第一发送模块还用于将所述第二生物特征向量发送至所述服务器,以供所述服务器根据所述第二生物特征向量与所述第一生物特征模板向量生成第一欧氏距离;以及
    所述身份认证系统还包括:
    第一接收模块,用于接收来自所述服务器的所述第一欧氏距离;
    解密模块,用于对所述第一欧氏距离进行同态解密处理得到第二欧氏距离;
    判断模块,用于根据所述第二欧氏距离确定所述第二生物特征信息与所述第一生物特征信息是否匹配,以确定身份认证是否成功。
  7. 根据权利要求6所述的身份认证系统,其特征在于,所述判断模块具体用于判断所述第二欧氏距离是否小于或等于预设距离;以及
    当判定所述第二欧氏距离小于或等于所述预设距离时,所述第二生物特征信息与所述第一生物特征信息匹配成功,则身份认证成功;
    当判定所述第二欧氏距离大于所述预设距离时,所述第二生物特征信息与所述第一生物特征信息匹配失败,则身份认证失败。
  8. 根据权利要求5至7中任一项所述的身份认证系统,其特征在于,
    所述第一生物特征信息和所述第二生物特征信息至少包括以下之一或其组合:指纹图像信息、虹膜图像信息和人脸图像信息。
  9. 一种身份认证方法,用于服务器,其特征在于,包括:
    接收来自终端的第三生物特征向量;
    将所述第三生物特征向量存储为所述第二生物特征模板向量,其中,所述第三生物特征向量为所述终端对采集到的预设用户的第三生物特征信息的至少一项第三属性信息进行同态加密处理得到的。
  10. 根据权利要求9所述的身份认证方法,其特征在于,还包括:
    接收来自所述终端的第四生物特征向量,其中,所述第四生物特征向量为所述终端对采集到的当前用户的第四生物特征信息的至少一项第四属性信息进行同态加密处理得到的;
    根据所述第四生物特征向量与第二生物特征模板向量得到第三欧氏距离;
    将所述第三欧氏距离发送至所述终端,以供所述终端根据所述第三欧氏距离确定所述第四生物特征信息与所述第三生物特征信息是否匹配;以及
    所述第三生物特征信息和所述第四生物特征信息至少包括以下之一或其组合:指纹图像信息、虹膜图像信息和人脸图像信息。
  11. 一种身份认证系统,用于服务器,其特征在于,包括:
    第二接收模块,用于接收来自终端的第三生物特征向量;
    存储模块,用于将所述第三生物特征向量存储为所述第二生物特征模板向量,其中,所述第三生物特征向量为所述终端对采集到的预设用户的第三生物特征信息的至少一项第三属性信息进行同态加密处理得到的。
  12. 根据权利要求11所述的身份认证系统,其特征在于,所述第二接收模块还用于接收来自所述终端的第四生物特征向量,其中,所述第四生物特征向量为所述终端对采集到的当前用户的第四生物特征信息的至少一项第四属性信息进行同态加密处理得到的;以及
    所述身份认证系统还包括:
    处理模块,用于根据所述第四生物特征向量与第二生物特征模板向量得 到第三欧氏距离;
    第二发送模块,用于将所述第三欧氏距离发送至所述终端,以供所述终端根据所述第三欧氏距离确定所述第四生物特征信息与所述第三生物特征信息是否匹配;以及所述第三生物特征信息和所述第四生物特征信息至少包括以下之一或其组合:指纹图像信息、虹膜图像信息和人脸图像信息。
  13. 一种终端,其特征在于,包括如权利要求5至8任一项所述的身份认证系统。
  14. 一种服务器,其特征在于,包括如权利要求11或12所述的身份认证系统。
PCT/CN2015/088472 2015-07-23 2015-08-30 身份认证方法、身份认证系统、终端和服务器 Ceased WO2017012175A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510439665.7 2015-07-23
CN201510439665.7A CN105635099A (zh) 2015-07-23 2015-07-23 身份认证方法、身份认证系统、终端和服务器

Publications (1)

Publication Number Publication Date
WO2017012175A1 true WO2017012175A1 (zh) 2017-01-26

Family

ID=56049595

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/088472 Ceased WO2017012175A1 (zh) 2015-07-23 2015-08-30 身份认证方法、身份认证系统、终端和服务器

Country Status (2)

Country Link
CN (1) CN105635099A (zh)
WO (1) WO2017012175A1 (zh)

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN112000940A (zh) * 2020-09-11 2020-11-27 支付宝(杭州)信息技术有限公司 一种隐私保护下的用户识别方法、装置以及设备
CN112163542A (zh) * 2020-10-12 2021-01-01 桂林电子科技大学 一种基于ElGamal加密的掌纹保密认证方法
CN115842646A (zh) * 2022-09-07 2023-03-24 福建云豆网络科技有限公司 一种基于物联网的网上银行用户登录加密系统
CN117201698A (zh) * 2023-11-07 2023-12-08 北京隐算科技有限公司 一种安全高效的图像识别方法
WO2023228140A3 (en) * 2022-05-27 2024-05-16 Vaultavo Inc Digital custody
WO2024152768A1 (zh) * 2023-01-20 2024-07-25 中国银联股份有限公司 生物特征匹配方法、终端设备、服务器、系统及介质
EP3665862B1 (en) * 2017-08-10 2024-08-28 Visa International Service Association Use of biometrics and privacy preserving methods to authenticate account holders online

Families Citing this family (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2018090183A1 (zh) * 2016-11-15 2018-05-24 深圳达闼科技控股有限公司 一种身份认证的方法、终端设备、认证服务器及电子设备
US11328044B2 (en) 2017-01-19 2022-05-10 Huawei Technologies Co., Ltd. Dynamic recognition method and terminal device
CN106951865B (zh) * 2017-03-21 2020-04-07 东莞理工学院 一种基于海明距离的隐私保护生物识别方法
CN107196918B (zh) * 2017-04-27 2020-10-30 北京小米移动软件有限公司 一种匹配数据的方法和装置
CN107919965B (zh) * 2018-01-05 2020-10-09 杭州电子科技大学 一种基于同态加密的生物特征敏感信息外包身份认证方法
CN108509874A (zh) * 2018-03-16 2018-09-07 联想(北京)有限公司 一种数据处理方法及电子设备、计算机存储介质
CN108933655A (zh) * 2018-07-12 2018-12-04 江苏慧学堂系统工程有限公司 一种计算机网络身份验证系统
CN109150538B (zh) * 2018-07-16 2021-06-25 广州大学 一种指纹与声纹融合身份认证方法
CN109145829A (zh) * 2018-08-24 2019-01-04 中共中央办公厅电子科技学院 一种基于深度学习和同态加密的安全高效的人脸识别方法
CN109714148B (zh) * 2018-12-13 2022-06-10 北京九州云腾科技有限公司 对用户身份进行远程多方认证的方法
CN112084476B (zh) * 2020-09-02 2024-11-22 支付宝(杭州)信息技术有限公司 生物识别身份验证方法、客户端、服务器、设备及系统
CN115086014A (zh) * 2022-06-13 2022-09-20 中国银行股份有限公司 一种人脸对比的方法及装置

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101984576A (zh) * 2010-10-22 2011-03-09 北京工业大学 一种基于加密人脸的匿名身份认证方法和系统
CN102664885A (zh) * 2012-04-18 2012-09-12 南京邮电大学 一种基于生物特征加密和同态算法的身份认证方法
CN103731271A (zh) * 2013-12-30 2014-04-16 北京工业大学 一种基于同态加密和混沌置乱的在线人脸身份认证方法
US20140281567A1 (en) * 2013-03-15 2014-09-18 Mitsubishi Electric Research Laboratories, Inc. Method for Authenticating an Encryption of Biometric Data

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN104598835A (zh) * 2014-12-29 2015-05-06 无锡清华信息科学与技术国家实验室物联网技术中心 一种保护隐私的基于云的实数向量距离计算方法

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101984576A (zh) * 2010-10-22 2011-03-09 北京工业大学 一种基于加密人脸的匿名身份认证方法和系统
CN102664885A (zh) * 2012-04-18 2012-09-12 南京邮电大学 一种基于生物特征加密和同态算法的身份认证方法
US20140281567A1 (en) * 2013-03-15 2014-09-18 Mitsubishi Electric Research Laboratories, Inc. Method for Authenticating an Encryption of Biometric Data
CN103731271A (zh) * 2013-12-30 2014-04-16 北京工业大学 一种基于同态加密和混沌置乱的在线人脸身份认证方法

Cited By (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP3665862B1 (en) * 2017-08-10 2024-08-28 Visa International Service Association Use of biometrics and privacy preserving methods to authenticate account holders online
CN112000940A (zh) * 2020-09-11 2020-11-27 支付宝(杭州)信息技术有限公司 一种隐私保护下的用户识别方法、装置以及设备
CN112163542A (zh) * 2020-10-12 2021-01-01 桂林电子科技大学 一种基于ElGamal加密的掌纹保密认证方法
WO2023228140A3 (en) * 2022-05-27 2024-05-16 Vaultavo Inc Digital custody
CN115842646A (zh) * 2022-09-07 2023-03-24 福建云豆网络科技有限公司 一种基于物联网的网上银行用户登录加密系统
WO2024152768A1 (zh) * 2023-01-20 2024-07-25 中国银联股份有限公司 生物特征匹配方法、终端设备、服务器、系统及介质
CN117201698A (zh) * 2023-11-07 2023-12-08 北京隐算科技有限公司 一种安全高效的图像识别方法
CN117201698B (zh) * 2023-11-07 2024-01-12 北京隐算科技有限公司 一种安全高效的图像识别方法

Also Published As

Publication number Publication date
CN105635099A (zh) 2016-06-01

Similar Documents

Publication Publication Date Title
WO2017012175A1 (zh) 身份认证方法、身份认证系统、终端和服务器
CN111738238B (zh) 人脸识别方法和装置
CN106612259B (zh) 身份识别、业务处理以及生物特征信息的处理方法和设备
US9218473B2 (en) Creation and authentication of biometric information
CN112948795B (zh) 保护隐私的身份认证方法及装置
CN101420301A (zh) 人脸识别身份认证系统
CN114596639B (zh) 一种生物特征识别方法、装置、电子设备及存储介质
Rajeswari et al. Multi-fingerprint unimodel-based biometric authentication supporting cloud computing
US10963552B2 (en) Method and electronic device for authenticating a user
CN106936775A (zh) 一种基于指纹识别的认证方法及系统
EP3745289B1 (en) Apparatus and method for registering biometric information, apparatus and method for biometric authentication
CN114996727A (zh) 基于掌纹掌静脉识别的生物特征隐私加密方法及系统
CN110392030B (zh) 一种基于生物特征的身份认证、业务处理方法及系统
JP2006262333A (ja) 生体認証システム
JP7259979B2 (ja) 情報照合システム及び情報照合方法
CN113079017A (zh) 一种电子签名的指纹实名认证方法和系统
KR101808809B1 (ko) 특징 데이터 전송 방법, 특징 데이터를 이용한 사용자 인증 방법 및 시스템
CN115834088A (zh) 一种生物特征认证方法和系统
Aanjanadevi et al. A secure authenticated bio-cryptosystem using face attribute based on fuzzy extractor
CN115941183B (zh) 一种生物信息的处理方法和相关装置
CN109005158B (zh) 基于模糊保险箱的动态手势认证系统的认证方法
Neethu Revocable Session Key Generation Using Combined Fingerprint Template
KR102210620B1 (ko) 서버에의 비밀 정보 저장 방법 및 복구 방법
Athira Ram et al. Reducing Vulnerability of a Fingerprint Authentication System
Priya et al. A Survey On Network Security In Biometrics

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15898731

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15898731

Country of ref document: EP

Kind code of ref document: A1