WO2017031849A1 - 一种指纹认证方法、连接设备和终端设备 - Google Patents

一种指纹认证方法、连接设备和终端设备 Download PDF

Info

Publication number
WO2017031849A1
WO2017031849A1 PCT/CN2015/095782 CN2015095782W WO2017031849A1 WO 2017031849 A1 WO2017031849 A1 WO 2017031849A1 CN 2015095782 W CN2015095782 W CN 2015095782W WO 2017031849 A1 WO2017031849 A1 WO 2017031849A1
Authority
WO
WIPO (PCT)
Prior art keywords
fingerprint data
terminal device
time
original fingerprint
encrypted
Prior art date
Application number
PCT/CN2015/095782
Other languages
English (en)
French (fr)
Inventor
樊立
柴玉东
Original Assignee
宇龙计算机通信科技(深圳)有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 宇龙计算机通信科技(深圳)有限公司 filed Critical 宇龙计算机通信科技(深圳)有限公司
Publication of WO2017031849A1 publication Critical patent/WO2017031849A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0876Network architectures or network communication protocols for network security for authentication of entities based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2463/00Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
    • H04L2463/121Timestamp

Definitions

  • the present invention relates to the field of fingerprint authentication technologies, and in particular, to a fingerprint authentication method, a connection device, and a terminal device.
  • fingerprint authentication technology is widely used in the field of security authentication technology for terminal devices due to its uniqueness, lifetime invariance and convenience.
  • the fingerprint data of the legal user needs to be stored in the security zone of the terminal device in advance.
  • the terminal device calls the fingerprint data stored in the security domain.
  • the fingerprint data of the currently received user is compared. When the comparison is successful, it is determined that the current user is a legitimate user, and the fingerprint authentication is completed.
  • the inventor of the present invention has studied the fingerprint authentication method in the prior art and found that since the terminal device stores the fingerprint data of the legitimate user in the security domain of the terminal device in advance, for example, when the terminal device is lost, the illegal user A malicious program that illegally creates system-level access rights to the terminal device, attacks the terminal device system kernel, steals fingerprint data in the security domain of the terminal device, and then completes fingerprint authentication of the terminal device according to the stolen fingerprint data. The safety of the equipment is greatly reduced.
  • the present invention provides a fingerprint authentication method, a connection device, and a terminal device, so as to solve the problem that the fingerprint authentication method in the prior art has low security and causes the security of the terminal device to be reduced.
  • the technical solutions are as follows:
  • the present invention provides a fingerprint authentication method, which is applied to a connection device.
  • the connection device establishes a communication connection with the terminal device, and the connection device includes a plurality of storage partitions, each of the storage partitions respectively storing the encrypted partial fingerprint data, and the method includes:
  • the method further includes: after the all the decrypted partial fingerprint data is processed to obtain the original fingerprint data, and the sending the original fingerprint data to the terminal device, the method further includes:
  • the sending the original fingerprint data to the terminal device includes:
  • the encrypted original fingerprint data and the time parameter used in the encryption are transmitted to the terminal device.
  • the encrypting the original fingerprint data comprises:
  • the current time is a time parameter used in the encrypting
  • the method further includes: splitting the original fingerprint data into a plurality of partial fingerprint data;
  • the method for encrypting the partial fingerprint data includes:
  • the time encryption algorithm is invoked, and the second time stamp is added to the plurality of partial fingerprint data in turn, and the second time stamp is calculated by the current save time.
  • the present invention provides a fingerprint authentication method, which is applied to a terminal device, and the terminal device establishes a communication connection with a connection device, where the connection device includes a plurality of storage partitions, and each of the storage partitions respectively The encrypted partial fingerprint data is stored, and the method includes:
  • the connecting device sends the authentication request information to the connecting device, so that the connecting device obtains the encrypted partial fingerprint data from the storage partition according to the authentication request information, and obtains all the acquired fingerprints.
  • the fingerprint data of the secret portion is decrypted, and then all the decrypted partial fingerprint data are processed to obtain the original fingerprint data;
  • the receiving the original fingerprint data sent by the connection device specifically includes: receiving the encrypted original fingerprint data sent by the connection device and utilizing the encryption Time parameters to arrive; the method further includes:
  • the decrypting the encrypted original fingerprint data according to the time parameter used in the encryption to obtain the original fingerprint data specifically includes:
  • the first timestamp is calculated by the current time.
  • the present invention provides a connection device, the connection device establishes a communication connection with a terminal device, the connection device includes a plurality of storage partitions, and each of the storage partitions respectively stores an encrypted portion Fingerprint data, the connecting device includes:
  • a first receiving unit configured to receive authentication request information sent by the terminal device
  • a first acquiring unit configured to obtain, according to the authentication request information, the encrypted partial fingerprint data from the storage partition
  • a decryption processing unit configured to decrypt all the encrypted partial fingerprint data acquired by the first acquiring unit, and process all the decrypted partial fingerprint data to obtain original fingerprint data
  • a first sending unit configured to send the original fingerprint data to the terminal device.
  • the method further comprises:
  • a first encryption unit configured to encrypt the original fingerprint data
  • the first sending unit is specifically configured to send the encrypted original fingerprint data and a time parameter used in the encryption to the terminal device.
  • the first encryption unit comprises:
  • Obtaining a subunit configured to acquire a current time of the connected device; the current time is a time parameter used in the encrypting;
  • an encryption subunit configured to invoke a time encryption algorithm, adding a first timestamp to the original fingerprint data, where the first timestamp is calculated by the current time.
  • the method further comprises:
  • a fingerprint data splitting unit configured to split the original fingerprint data into a plurality of partial fingerprint data after the connecting device receives the original fingerprint data for the first time
  • a second encryption unit configured to invoke a time encryption algorithm according to a current save time of the plurality of partial fingerprint data, and sequentially add a second timestamp to the plurality of partial fingerprint data, where the second timestamp is The current save time is calculated.
  • the present invention provides a terminal device, the terminal device establishing a communication connection with a connection device, the connection device comprising a plurality of storage partitions, each of the storage partitions respectively storing an encrypted portion Fingerprint data, the terminal device includes:
  • a second sending unit configured to send the authentication request information to the connecting device, so that the connecting device obtains the encrypted partial fingerprint data from the storage partition according to the authentication request information, and obtains the obtained All the encrypted partial fingerprint data is decrypted, and then all the decrypted partial fingerprint data are processed to obtain the original fingerprint data;
  • a second receiving unit configured to receive original fingerprint data sent by the connecting device
  • a comparison unit configured to compare the original fingerprint data with fingerprint data currently input by a user
  • a determining unit configured to determine that the user is a legitimate user when the comparing unit is successfully aligned.
  • the second receiving unit is specifically configured to receive the encrypted original fingerprint data sent by the connecting device and the time parameter used in the encryption;
  • the terminal device further includes:
  • a decryption unit configured to decrypt the encrypted original fingerprint data according to the time parameter used in the encryption to obtain original fingerprint data.
  • the decrypting unit is configured to: according to the time parameter used in the encryption, invoke a time encryption algorithm, and remove the first timestamp in the encrypted original fingerprint data to obtain original fingerprint data;
  • the first timestamp is calculated by the current time.
  • the connection device includes a plurality of storage partitions, and each storage partition separately stores the encrypted partial fingerprint data
  • the method includes: the mobile device sends the authentication request information to Connecting the device, the connection device obtains the encrypted partial fingerprint data from the storage partition according to the authentication request information, and decrypts all the obtained partial fingerprint data, and then decrypts all the decrypted partial fingerprint data.
  • the processing is performed to obtain the original fingerprint data, and finally the original fingerprint data is sent to the terminal device, so that the terminal device completes the subsequent fingerprint authentication process according to the original fingerprint data.
  • the fingerprint data of the legal user is split and separately encrypted, and the encrypted partial fingerprint data is separately stored in each storage partition in the connected device.
  • the device may obtain the encrypted partial fingerprint data from each storage partition according to the authentication request information sent by the terminal device, and then obtain the original fingerprint data to complete the subsequent authentication.
  • the present invention does not store the fingerprint data of the legal user in the terminal device. Then, even if the terminal device is lost, the illegal user attacks the terminal device system kernel, and the fingerprint data of the legal user cannot be obtained.
  • the present invention ensures the security of the terminal device.
  • FIG. 1 is a flow chart of a fingerprint authentication method provided by the present invention
  • FIG. 2 is a schematic structural diagram of a time stamp in the present invention.
  • FIG. 3 is another schematic structural diagram of a time stamp in the present invention.
  • FIG. 4 is a schematic structural diagram of another time stamp in the present invention.
  • FIG. 5 is another flowchart of a fingerprint authentication method according to the present invention.
  • FIG. 6 is still another flowchart of a fingerprint authentication method provided by the present invention.
  • FIG. 7 is still another flowchart of a fingerprint authentication method provided by the present invention.
  • FIG. 8 is a schematic structural diagram of a connection device according to the present invention.
  • FIG. 9 is a schematic structural diagram of a terminal device according to the present invention.
  • FIG. 1 is a flowchart of a method for fingerprint authentication provided by the present invention.
  • the method is specifically applied to a connection device.
  • the connection device in the present invention has established a communication connection with a terminal device, and the connection device includes multiple Storage partitions, each of which stores encrypted partial fingerprint data, the method comprising:
  • Step 101 Receive authentication request information sent by the terminal device.
  • the present invention in order to ensure the legitimacy of the terminal device, preferably further includes, in step 101, receiving the authentication request information sent by the terminal device, before receiving the authentication request information sent by the terminal device, in step 101, receiving the identity authentication information sent by the terminal device. . After the connection device passes the identity authentication of the terminal device according to the identity authentication information, step 101 is performed to receive the authentication request information sent by the terminal device.
  • Step 102 Acquire encrypted partial fingerprint data from the storage partition according to the authentication request information.
  • the present invention pre-stores fingerprint data of a legitimate user in a connected device, and the connected device includes a plurality of storage partitions.
  • the connected device receives the fingerprint data of the legal user for the first time, the connected device automatically splits the fingerprint data of the legitimate user to generate multiple partial fingerprint data, and encrypts the partial fingerprint data separately.
  • the connection device includes a plurality of storage partitions, and the connection device automatically splits the fingerprint data of the legal user into a plurality of partial fingerprint data, and the different partial fingerprint data are respectively stored in different storage partitions.
  • N is a positive integer
  • the connected device sequentially encrypts the N partial fingerprint data. .
  • the method for encrypting the N partial fingerprint data in the present invention may include: calling a time encryption algorithm according to a current save time of the plurality of partial fingerprint data, and sequentially adding a second time stamp to the plurality of partial fingerprint data, where the The second timestamp is calculated from the current save time.
  • the connection device first acquires the current save time of the N partial fingerprint data, for example, the current save time is 7:59:36, and the present invention selects to add a byte of 8 bits in the data header of the partial fingerprint data.
  • the second timestamp is 01011001, and the 01011001 is added to the data header of each partial fingerprint data.
  • the present invention may also select a second timestamp of two bytes of a 16-bit length in the header of the partial fingerprint data, the two-byte length of the 16-bit length representing the minute hand time and the second hand time.
  • the upper 4 bits of the first byte are binary data of the octet time of the minute hand
  • the lower 4 bits are the binary data of the minute hand
  • the upper 4 bits of the second byte are the binary data of the tens of digits of the second hand, the lower 4 bits.
  • Binary data for the second hand time as shown in Figure 3.
  • the second time stamp is 0101100100110110, which adds 0101100100110110 to the data header of each partial fingerprint data.
  • the present invention may also select a second timestamp of three bytes of a 24-bit bit length in the data header of the partial fingerprint data, or a second timestamp of a plurality of bytes of other bit lengths, and the implementation method thereof The same as the above, the inventors will not repeat them here.
  • the upper 4 bits and the lower 4 bits of the first byte can be used to represent the minute hand.
  • the upper 4 bits and the lower 4 bits of the second byte can be used to represent the second hand time
  • the upper 4 bits of the third byte can be different for the minute data of the minute hand and the binary data of the ten digits of the second hand time.
  • the lower 4 bits are the result of the difference between the binary data of the minute hand and the binary data of the second hand time, as shown in FIG. 4 .
  • the binary data 0101 of the minute hand time is different from the binary data 0011 of the second hand time or the high 4 bits of the third byte is 0110, and the binary data 1001 of the minute hand and the second hand time bit are Binary data 0110 is different or the lower 4 bits of the third byte are 1111.
  • the second time stamp is 010110010011011001101111, which adds 010110010011011001101111 to the data header of each partial fingerprint data.
  • the implementation manner of storing the fingerprint data of the legal user in the connection device in advance may include: the connection device receives the fingerprint data sent by the terminal device for the first time, and the fingerprint data is stored as the fingerprint data of the legal user by default, or the user Directly input through the fingerprint identification device of the connected device Fingerprint data, by default, the fingerprint data input by the user is the fingerprint data of the legitimate user, and then stored.
  • the connection device when the connection device receives the authentication request information sent by the terminal device, the connection device obtains the encrypted partial fingerprint data from different storage partitions according to the authentication request information.
  • Step 103 Decrypt all the acquired partial fingerprint data, and process all the decrypted partial fingerprint data to obtain original fingerprint data.
  • the connecting device adopts a decryption method opposite to the encryption method, calculates the second timestamp in the data header of each partial fingerprint data and removes it from the data header of each partial fingerprint data, and the remaining data portion is original. Part of the fingerprint data, and then all the decrypted partial fingerprint data obtained are linked and integrated, and finally the original fingerprint data is obtained.
  • Step 104 Send the original fingerprint data to the terminal device.
  • the mobile device sends the authentication request information to the connection device, and the connection device obtains the encrypted partial fingerprint data from the storage partition according to the authentication request information, and obtains all the encrypted partial fingerprints obtained.
  • the data is decrypted, and then all the decrypted partial fingerprint data is processed to obtain the original fingerprint data, and finally the original fingerprint data is sent to the terminal device, so that the terminal device completes the subsequent fingerprint authentication process according to the original fingerprint data.
  • the fingerprint data of the legal user is split and separately encrypted, and the encrypted partial fingerprint data is separately stored in each storage partition in the connected device, and the terminal device needs to be current.
  • the connected device may obtain the encrypted partial fingerprint data from each storage partition according to the authentication request information sent by the terminal device, and then obtain the original fingerprint data and send the original fingerprint data to the terminal device to complete the subsequent authentication.
  • the invention does not store the fingerprint data of the legal user in the terminal device. Therefore, even if the terminal device is lost, the illegal user attacks the kernel of the terminal device system, and the fingerprint data of the legal user cannot be obtained.
  • the present invention ensures the security of the terminal device.
  • the present invention further provides a fingerprint authentication method for the data transmission between the connection device and the terminal device. As shown in FIG. 5, the method includes:
  • Step 201 Receive authentication request information sent by the terminal device.
  • Step 202 Obtain an encrypted part from the storage partition according to the authentication request information. Fingerprint data.
  • Step 203 Decrypt all the acquired partial fingerprint data, and process all the decrypted partial fingerprint data to obtain original fingerprint data.
  • step 201 to step 203 in this embodiment is the same as the implementation method of step 101 to step 103 in the foregoing embodiment, and the inventors will not repeat them here.
  • Step 204 Encrypt the original fingerprint data.
  • the connection device obtains the original fingerprint data
  • the original fingerprint data is not directly transmitted to the terminal device, but the original fingerprint data is encrypted again.
  • the method for encrypting original fingerprint data by the present invention includes:
  • Step 2041 Acquire a current time of the connected device.
  • the current time is a time parameter used in the encryption.
  • Step 2042 Call a time encryption algorithm to add a first timestamp to the original fingerprint data, where the first timestamp is calculated by the current time.
  • the connection device first acquires the current time of the connected device system, for example, the current time is 7:59:36, and then uses the current time to invoke the time encryption algorithm, calculates the first timestamp, and the first time.
  • the stamp is added to the header of the original fingerprint data.
  • the original fingerprint data is encrypted in the same encryption manner as the partial fingerprint data is encrypted.
  • the current time is 7:59:36.
  • the present invention selects a first timestamp of one byte of an 8-bit bit length added to the data header of the original fingerprint data, the byte of the 8-bit bit length.
  • the minute hand time indicated, the upper 4 bits of the byte are the binary data of the tens of digits of the minute hand, and the lower 4 bits of the byte are the binary data of the minute hand of the minute hand, as shown in FIG. 2 .
  • the first timestamp is 01011001, and the first timestamp 01011001 is added to the data header of the original fingerprint data.
  • the present invention selects a first time stamp of two bytes of a 16-bit length in the header of the original fingerprint data, the two-byte length of the 16-bit length representing the minute hand time and the second hand time.
  • the upper 4 bits of the first byte are binary data of the octet time of the minute hand
  • the lower 4 bits are the binary data of the minute hand
  • the upper 4 bits of the second byte are the binary data of the tens of digits of the second hand, the lower 4 bits.
  • Binary data for the second hand time as shown in Figure 3.
  • the first timestamp is 0101100100110110
  • the first timestamp 0101100100110110 is added to the original fingerprint data.
  • the data header In the data header.
  • the present invention selects a first timestamp of three bytes of a 24-bit length in the data header of the original fingerprint data, and the upper 4 bits and the lower 4 bits of the first byte can be used to indicate the minute hand time.
  • the upper 4 bits and lower 4 bits of the second byte can be used to indicate the second hand time, and the upper 4 bits of the third byte can be different from the binary data of the ten digits of the minute hand and the binary data of the ten digits of the second hand.
  • the lower 4 bits are the result of the difference between the binary data of the minute hand and the binary data of the second hand time, as shown in FIG. 4 .
  • the binary data 0101 of the minute hand time is different from the binary data 0011 of the second hand time or the high 4 bits of the third byte is 0110, and the binary data 1001 of the minute hand and the second hand time bit are The binary data 0110 is different or the lower 4 bits of the third byte are 1111.
  • the first time stamp is 010110010011011001101111, and the first time stamp 010110010011011001101111 is added to the data header of the original fingerprint data.
  • Step 205 Send the encrypted original fingerprint data and the time parameter used in the encryption to the terminal device.
  • the connection device After the connection device encrypts the original fingerprint data, the encrypted original fingerprint data and the time parameter used in the encryption are sent to the terminal device together with the current time 7:59:36 in the foregoing embodiment, so that the terminal device The encrypted original fingerprint data is decrypted by using the time parameter used in encryption to obtain the original fingerprint data.
  • the connecting device does not directly send the original fingerprint data to the terminal device, but encrypts the original fingerprint data and sends the original fingerprint data to the terminal device, thereby further ensuring the security of the fingerprint data transmission.
  • the present invention further provides a fingerprint authentication method, where the method is applied to a terminal device, and the terminal device establishes a communication connection with a connection device, where the connection device includes multiple storage partitions, each of which is The storage partitions respectively store the encrypted partial fingerprint data.
  • the method is as shown in FIG. 6 , and specifically includes:
  • Step 301 Send authentication request information to the connection device, so that the connection device obtains the encrypted partial fingerprint data from the storage partition according to the authentication request information, and obtains all the encrypted portions obtained.
  • the fingerprint data is decrypted, and then all the decrypted partial fingerprint data is processed to obtain the original fingerprint data.
  • the terminal device when the user operates the terminal device to implement functions such as boot unlocking, mobile payment, etc., and the user needs to input fingerprint data, the terminal device automatically searches for a connected device within a certain range around the device, and establishes and connects the device with the connected device. connection.
  • connection device in the present invention may be in a standby state for receiving data information in real time, and when the terminal device needs to find and establish a communication connection with the connected device, actively initiate a wireless network connection request to the connected device found within a certain range. . After the connected device completes the identity authentication of the terminal device, a network communication connection with the terminal device is established. At this time, the terminal device is transmitting the authentication request information to the connected device.
  • Step 302 Receive original fingerprint data sent by the connection device.
  • Step 303 Compare the original fingerprint data with fingerprint data currently input by the user. When the comparison is successful, step 304 is performed, otherwise step 305 is performed.
  • the terminal device After the terminal device receives the original fingerprint data returned by the connected device, it compares with the fingerprint data input by the current user.
  • Step 304 Determine that the user is a legitimate user.
  • the terminal device When the comparison is successful, it indicates that the current user is a legitimate user, and the terminal device completes the authentication of the user identity, and allows the user to perform subsequent operations.
  • Step 305 Determine that the user is an illegal user.
  • the terminal device also receives the time parameter used by the connection device for encryption.
  • the present invention further includes, at step 306, step 306, decrypting the encrypted original fingerprint data according to the time parameter used in the encryption to obtain original fingerprint data.
  • the terminal device invokes a time encryption algorithm according to the time parameter used in the encryption, such as the current time 7:59:36 in the foregoing embodiment, and the first time in the encrypted original fingerprint data.
  • the stamp is removed to obtain the original fingerprint data.
  • the first timestamp is calculated by the current time.
  • the terminal device when the terminal device needs to authenticate the fingerprint data input by the current user, the terminal device actively initiates a network communication connection to a connected device in a certain range around the terminal device, and then connects from the connection device.
  • the original fingerprint data of the legal user is pre-stored, and the original fingerprint data is compared with the fingerprint data input by the current user.
  • the comparison is successful, the current user is determined to be a legitimate user, and the user is allowed to continue the subsequent operations. Therefore, even if the user loses the terminal device and the illegal user attacks the terminal device system kernel, the fingerprint data of the legal user cannot be obtained, and the present invention ensures the security of the terminal device.
  • connection device in the present invention may be a wearable device on a user, such as a watch, a wristband, smart glasses, or the like.
  • the terminal device can be a mobile phone, a tablet computer, or the like.
  • the present invention further provides a connection device.
  • the connection device establishes a communication connection with a terminal device, where the connection device includes multiple storage partitions, each of which The storage partitions respectively store the encrypted partial fingerprint data, and the connection device specifically includes: a first receiving unit 10, a first obtaining unit 20, a decryption processing unit 30, and a first sending unit 40. among them,
  • the first receiving unit 10 is configured to receive authentication request information sent by the terminal device
  • the first obtaining unit 20 is configured to obtain, according to the authentication request information, the encrypted partial fingerprint data from the storage partition;
  • the decryption processing unit 30 is configured to decrypt all the encrypted partial fingerprint data acquired by the first acquiring unit 10, and process all the decrypted partial fingerprint data to obtain original fingerprint data;
  • the first sending unit 40 is configured to send the original fingerprint data to the terminal device.
  • the present invention further includes:
  • the first encryption unit 50 is configured to encrypt the original fingerprint data.
  • the first sending unit 40 is specifically configured to send the encrypted original fingerprint data and the time parameter used in the encryption to the terminal device.
  • the first encryption unit 50 specifically includes:
  • the obtaining sub-unit 51 is configured to acquire a current time of the connected device, where the current time is a time parameter used in the encrypting;
  • An encryption subunit 52 configured to invoke a time encryption algorithm, adding a first to the original fingerprint data a timestamp, the first timestamp being calculated from the current time.
  • the present invention further includes:
  • the fingerprint data splitting unit 60 is configured to split the original fingerprint data into a plurality of partial fingerprint data after the connecting device receives the original fingerprint data for the first time;
  • a second encryption unit 70 configured to invoke a time encryption algorithm according to a current save time of the plurality of partial fingerprint data, and sequentially add a second timestamp to the plurality of partial fingerprint data, where the second timestamp is The current save time is calculated.
  • the present invention further provides a terminal device.
  • the terminal device establishes a communication connection with a connection device, where the connection device includes multiple storage partitions, each of which includes a plurality of storage partitions.
  • the storage partitions respectively store the encrypted partial fingerprint data
  • the terminal device specifically includes: a second sending unit 100, a second receiving unit 200, a comparing unit 300, and a determining unit 400. among them,
  • the second sending unit 100 is configured to send the authentication request information to the connecting device, so that the connecting device obtains the encrypted partial fingerprint data from the storage partition according to the authentication request information, and acquires All the encrypted partial fingerprint data are decrypted, and then all the decrypted partial fingerprint data are processed to obtain the original fingerprint data;
  • the second receiving unit 200 is configured to receive original fingerprint data sent by the connecting device.
  • the determining unit 400 is configured to determine that the user is a legitimate user when the comparing unit is successfully aligned.
  • the second receiving unit 200 is specifically configured to receive the encrypted original fingerprint data sent by the connecting device and use the encrypted original fingerprint data.
  • a time parameter the terminal device further includes:
  • the decryption unit 500 is specifically configured to: according to the time parameter used in the encryption, invoke a time encryption algorithm, and remove the first timestamp in the encrypted original fingerprint data to obtain the original Starting fingerprint data; the first timestamp is calculated from the current time.
  • a fingerprint authentication method, a connection device, and a terminal device provided by the present invention are described in detail.
  • the principles and implementation manners of the present invention are described in the following. The description of the above embodiments is only used to help understanding. The method of the present invention and its core idea; at the same time, for those skilled in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and the scope of application. It is understood to be a limitation of the invention.

Abstract

本发明提供一种指纹认证方法、连接设备和终端设备。方法包括:接收终端设备发送的鉴权请求信息;依据所述鉴权请求信息,从所述存储分区中获取加密后的部分指纹数据;将获取到的所有加密后的部分指纹数据进行解密,并将所有解密后的部分指纹数据进行处理得到原始指纹数据;将所述原始指纹数据发送至终端设备。本发明预先将合法用户的指纹数据进行拆分并加密,进而将加密后的部分指纹数据分别存储在连接设备中的各个存储分区,由于本发明并没有将合法用户的指纹数据存储在终端设备中,那么即使终端设备丢失,非法用户攻击终端设备系统内核,也无法获取到合法用户的指纹数据,本发明保证了终端设备的安全性。

Description

一种指纹认证方法、连接设备和终端设备
本申请要求于2015年8月25日提交中国专利局、申请号为201510526460.2、发明名称为“一种指纹认证方法、连接设备和终端设备”的中国专利申请的优先权,其全部内容引用在本申请中。
技术领域
本发明涉及指纹认证技术领域,更具体地说,涉及一种指纹认证方法、连接设备和终端设备。
背景技术
随着对终端设备安全性要求的逐渐提升,指纹认证技术凭借其唯一性、终身不变性、方便性等特点被广泛应用于终端设备的安全认证技术领域中。
现有技术中的终端设备在实现指纹认证时,需要预先将合法用户的指纹数据存储在终端设备的安全域(trustzone)中,在具体认证时,终端设备通过调用安全域中存储的指纹数据,与当前接收到的用户输入的指纹数据进行比对,当比对成功时,确定当前用户为合法用户,完成指纹认证。
然而本发明的发明人对现有技术中的指纹认证方法进行研究后发现,由于终端设备是将合法用户的指纹数据预先存储在终端设备的安全域中,那么例如当终端设备丢失时,非法用户捡到该终端设备并非法创建系统级访问权限的恶意程序,攻击终端设备系统内核,盗取终端设备安全域中的指纹数据后,便可依据盗取的指纹数据完成终端设备的指纹认证,终端设备的安全性大大降低。
因此,如何提高终端设备安全性成为当前急需解决的一个技术问题。
发明内容
有鉴于此,本发明提供一种指纹认证方法、连接设备和终端设备,以解决现有技术中的指纹认证方法安全性低,导致终端设备安全性降低的问题。技术方案如下:
基于本发明的一方面,本发明提供一种指纹认证方法,应用于连接设备, 所述连接设备与终端设备建立通信连接,所述连接设备包括多个存储分区,每个所述存储分区分别存储有加密后的部分指纹数据,所述方法包括:
接收所述终端设备发送的鉴权请求信息;
依据所述鉴权请求信息,从所述存储分区中获取加密后的部分指纹数据;
将获取到的所有加密后的部分指纹数据进行解密,并将所有解密后的部分指纹数据进行处理得到原始指纹数据;
将所述原始指纹数据发送至所述终端设备。
优选地,所述将所有解密后的部分指纹数据进行处理得到原始指纹数据后,且所述将所述原始指纹数据发送至所述终端设备前,所述方法还包括:
对所述原始指纹数据进行加密;
所述将所述原始指纹数据发送至所述终端设备,具体包括:
将加密后的原始指纹数据和加密时利用到的时间参数发送至所述终端设备。
优选地,所述对所述原始指纹数据进行加密包括:
获取所述连接设备的当前时间;所述当前时间为所述加密时利用到的时间参数;
调用时间加密算法,为所述原始指纹数据添加第一时间戳,所述第一时间戳由所述当前时间计算得到。
优选地,当所述连接设备首次接收到所述原始指纹数据时,所述方法还包括:将所述原始指纹数据拆分成多个部分指纹数据;
所述部分指纹数据的加密方法包括:
依据对所述多个部分指纹数据的当前保存时间,调用时间加密算法,依次为所述多个部分指纹数据添加第二时间戳,所述第二时间戳由所述当前保存时间计算得到。
基于本发明的另一方面,本发明提供一种指纹认证方法,应用于终端设备,所述终端设备与连接设备建立通信连接,所述连接设备包括多个存储分区,每个所述存储分区分别存储有加密后的部分指纹数据,所述方法包括:
发送鉴权请求信息至所述连接设备,以使得所述连接设备依据所述鉴权请求信息,从所述存储分区中获取加密后的部分指纹数据,并将获取到的所有加 密后的部分指纹数据进行解密,进而将所有解密后的部分指纹数据进行处理得到原始指纹数据;
接收所述连接设备发送的原始指纹数据;
将所述原始指纹数据与用户当前输入的指纹数据进行比对;
当比对成功时,确定所述用户为合法用户。
优选地,当所述原始指纹数据为加密后的原始指纹数据时,所述接收所述连接设备发送的原始指纹数据具体包括:接收所述连接设备发送的加密后的原始指纹数据和加密时利用到的时间参数;所述方法还包括:
依据所述加密时利用到的时间参数,对所述加密后的原始指纹数据进行解密,以获得原始指纹数据。
优选地,所述依据所述加密时利用到的时间参数,对所述加密后的原始指纹数据进行解密,以获得原始指纹数据具体包括:
依据所述加密时利用到的时间参数,调用时间加密算法,将所述加密后的原始指纹数据中的第一时间戳去除,获得原始指纹数据;
其中所述第一时间戳由所述当前时间计算得到。
基于本发明的再一方面,本发明提供一种连接设备,所述连接设备与终端设备建立通信连接,所述连接设备包括多个存储分区,每个所述存储分区分别存储有加密后的部分指纹数据,所述连接设备包括:
第一接收单元,用于接收所述终端设备发送的鉴权请求信息;
第一获取单元,用于依据所述鉴权请求信息,从所述存储分区中获取加密后的部分指纹数据;
解密处理单元,用于将所述第一获取单元获取到的所有加密后的部分指纹数据进行解密,并将所有解密后的部分指纹数据进行处理得到原始指纹数据;
第一发送单元,用于将所述原始指纹数据发送至所述终端设备。
优选地,还包括:
第一加密单元,用于对所述原始指纹数据进行加密;
所述第一发送单元具体用于,将加密后的原始指纹数据和加密时利用到的时间参数发送至所述终端设备。
优选地,所述第一加密单元包括:
获取子单元,用于获取所述连接设备的当前时间;所述当前时间为所述加密时利用到的时间参数;
加密子单元,用于调用时间加密算法,为所述原始指纹数据添加第一时间戳,所述第一时间戳由所述当前时间计算得到。
优选地,还包括:
指纹数据拆分单元,用于在所述连接设备首次接收到所述原始指纹数据后,将所述原始指纹数据拆分成多个部分指纹数据;
第二加密单元,用于依据对所述多个部分指纹数据的当前保存时间,调用时间加密算法,依次为所述多个部分指纹数据添加第二时间戳,所述第二时间戳由所述当前保存时间计算得到。
基于本发明的再一方面,本发明提供一种终端设备,所述终端设备与连接设备建立通信连接,所述连接设备包括多个存储分区,每个所述存储分区分别存储有加密后的部分指纹数据,所述终端设备包括:
第二发送单元,用于发送鉴权请求信息至所述连接设备,以使得所述连接设备依据所述鉴权请求信息,从所述存储分区中获取加密后的部分指纹数据,并将获取到的所有加密后的部分指纹数据进行解密,进而将所有解密后的部分指纹数据进行处理得到原始指纹数据;
第二接收单元,用于接收所述连接设备发送的原始指纹数据;
比对单元,用于将所述原始指纹数据与用户当前输入的指纹数据进行比对;
确定单元,用于当所述比对单元比对成功时,确定所述用户为合法用户。
优选地,当所述原始指纹数据为加密后的原始指纹数据时,所述第二接收单元具体用于,接收所述连接设备发送的加密后的原始指纹数据和加密时利用到的时间参数;所述终端设备还包括:
解密单元,用于依据所述加密时利用到的时间参数,对所述加密后的原始指纹数据进行解密,以获得原始指纹数据。
优选地,所述解密单元具体用于,依据所述加密时利用到的时间参数,调用时间加密算法,将所述加密后的原始指纹数据中的第一时间戳去除,获得原始指纹数据;
其中所述第一时间戳由所述当前时间计算得到。
应用本发明上述技术方案,本发明提供的指纹认证方法中,连接设备包括多个存储分区,且每个存储分区分别存储有加密后的部分指纹数据,方法包括:移动设备发送鉴权请求信息至连接设备,连接设备依据该鉴权请求信息,从所述存储分区中获取加密后的部分指纹数据,并将获取到的所有加密后的部分指纹数据进行解密,进而将所有解密后的部分指纹数据进行处理得到原始指纹数据,最后将原始指纹数据发送至终端设备,以使得终端设备依据原始指纹数据完成后续指纹认证过程。本发明预先将合法用户的指纹数据进行拆分并分别加密,进而将加密后的部分指纹数据分别存储在连接设备中的各个存储分区,当终端设备需要对当前用户的合法性进行认证时,连接设备可以依据终端设备发送的鉴权请求信息从各个存储分区中获得加密的部分指纹数据进行解密,进而得到原始指纹数据完成后续认证,由于本发明并没有将合法用户的指纹数据存储在终端设备中,那么即使终端设备丢失,非法用户攻击终端设备系统内核,也无法获取到合法用户的指纹数据,本发明保证了终端设备的安全性。
附图说明
为了更清楚地说明本发明实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据提供的附图获得其他的附图。
图1为本发明提供的一种指纹认证方法的一种流程图;
图2为本发明中时间戳的结构示意图;
图3为本发明中时间戳的另一结构示意图;
图4为本发明中时间戳的再一结构示意图;
图5为本发明提供的一种指纹认证方法的另一种流程图;
图6为本发明提供的一种指纹认证方法的再一种流程图;
图7为本发明提供的一种指纹认证方法的再一种流程图;
图8为本发明提供的一种连接设备的结构示意图;
图9为本发明提供的一种终端设备的结构示意图。
具体实施方式
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。
请参阅图1,其示出了本发明提供的一种指纹认证方法的流程图,该方法具体应用于连接设备,本发明中的连接设备与终端设备已建立通信连接,所述连接设备包括多个存储分区,每个所述存储分区分别存储有加密后的部分指纹数据,所述方法包括:
步骤101,接收所述终端设备发送的鉴权请求信息。
在本发明中,连接设备为了保证终端设备的合法性,本发明较优的在步骤101接收所述终端设备发送的鉴权请求信息之前,还可以包括步骤100,接收终端设备发送的身份认证信息。当连接设备依据该身份认证信息对终端设备的身份认证通过后,再执行步骤101接收终端设备发送的鉴权请求信息。
步骤102,依据所述鉴权请求信息,从所述存储分区中获取加密后的部分指纹数据。
本发明预先将合法用户的指纹数据存储在连接设备中,所述连接设备包括多个存储分区。当连接设备第一次接收到合法用户的指纹数据时,连接设备会自动将合法用户的指纹数据进行拆分生成多个部分指纹数据,并对多个部分指纹数据分别加密。其中较优的,本发明中连接设备包括多少个存储分区,连接设备便自动将合法用户的指纹数据拆分成多少个部分指纹数据,其不同的部分指纹数据分别存储在不同的存储分区中。在本发明中,连接设备在将合法用户的指纹数据(后续称之为原始指纹数据)拆分成N个部分指纹数据后,N为正整数,连接设备依次对该N个部分指纹数据进行加密。
本发明中对于N个部分指纹数据的加密方法可以包括:依据对多个部分指纹数据的当前保存时间,调用时间加密算法,依次为所述多个部分指纹数据添加第二时间戳,所述第二时间戳由所述当前保存时间计算得到。
具体地,连接设备首先获取该N个部分指纹数据的当前保存时间,例如当前保存时间为7:59:36,且本发明选取在部分指纹数据的数据头中添加8比特位长度的一个字节的第二时间戳,该8比特位长度的字节表示的分针时间,其字节的高4位为分针时间十位的二进制数据,字节的低4位为分针时间个位的二进制数据,具体如图2所示。那么该第二时间戳即为01011001,将该01011001添加到各个部分指纹数据的数据头中。
当然,本发明还可以选取在部分指纹数据的数据头中添加16比特位长度的两个字节的第二时间戳,该16比特位长度的两个字节表示的分针时间和秒针时间。其第一字节的高4位为分针时间十位的二进制数据,低4位为分针时间个位的二进制数据,第二字节的高4位为秒针时间十位的二进制数据,低4位为秒针时间个位的二进制数据,具体如图3所示。那么此时,该第二时间戳即为0101100100110110,该将0101100100110110添加到各个部分指纹数据的数据头中。
当然,本发明还可以选取在部分指纹数据的数据头中添加24比特位长度的三个字节的第二时间戳,或者其他比特位长度的多个字节的第二时间戳,其实现方法同上述相同,发明人在此不在赘述。
此外,对于本发明选取在部分指纹数据的数据头中添加24比特位长度的三个字节的第二时间戳来说,其第一字节的高4位和低4位可以用于表示分针时间,第二字节的高4位和低4位可以用于表示秒针时间,而其第三字节的高4位可以为分针时间十位的二进制数据与秒针时间十位的二进制数据相异或的结果,低4位为分针时间个位的二进制数据与秒针时间个位的二进制数据相异或的结果,具体如图4所示。那么此时,分针时间十位的二进制数据0101与秒针时间十位的二进制数据0011相异或得到第三字节的高4位为0110,分针时间个位的二进制数据1001与秒针时间个位的二进制数据0110相异或得到第三字节的低4位为1111,此时该第二时间戳即为010110010011011001101111,该将010110010011011001101111添加到各个部分指纹数据的数据头中。
对于本发明预先将合法用户的指纹数据存储在连接设备中的实现方式可以包括:连接设备第一次接收终端设备发送的指纹数据,默认该指纹数据为合法用户的指纹数据进行存储,或,用户直接通过连接设备的指纹识别装置输入 指纹数据,连接设备默认该用户输入的指纹数据为合法用户的指纹数据,进而进行存储。
具体在本发明中,当连接设备接收到终端设备发送的鉴权请求信息时,连接设备依据该鉴权请求信息从不同的存储分区中获取加密后的部分指纹数据。
步骤103,将获取到的所有加密后的部分指纹数据进行解密,并将所有解密后的部分指纹数据进行处理得到原始指纹数据。
连接设备采用与加密方法相逆的解密方法,将各个部分指纹数据的数据头中的第二时间戳计算出来并将其从各个部分指纹数据的数据头中去除,剩下的数据部分即为原始的部分指纹数据,进而将获得的所有解密后的部分指纹数据进行链接、整合,最终得到原始指纹数据。
步骤104,将所述原始指纹数据发送至所述终端设备。
在本发明中,移动设备发送鉴权请求信息至连接设备,连接设备依据该鉴权请求信息,从所述存储分区中获取加密后的部分指纹数据,并将获取到的所有加密后的部分指纹数据进行解密,进而将所有解密后的部分指纹数据进行处理得到原始指纹数据,最后将原始指纹数据发送至终端设备,以使得终端设备依据原始指纹数据完成后续指纹认证过程。
因此应用本发明的上述技术方案,本发明预先将合法用户的指纹数据进行拆分并分别加密,进而将加密后的部分指纹数据分别存储在连接设备中的各个存储分区,当终端设备需要对当前用户的合法性进行认证时,连接设备可以依据终端设备发送的鉴权请求信息从各个存储分区中获得加密的部分指纹数据进行解密,进而得到原始指纹数据发送至终端设备,以完成后续认证,由于本发明并没有将合法用户的指纹数据存储在终端设备中,那么即使终端设备丢失,非法用户攻击终端设备系统内核,也无法获取到合法用户的指纹数据,本发明保证了终端设备的安全性。
在上述实施例的基础上,本发明为进一步保证连接设备与终端设备间数据传输的安全性,本发明还提供一种指纹认证方法,如图5所示,包括:
步骤201,接收所述终端设备发送的鉴权请求信息。
步骤202,依据所述鉴权请求信息,从所述存储分区中获取加密后的部分 指纹数据。
步骤203,将获取到的所有加密后的部分指纹数据进行解密,并将所有解密后的部分指纹数据进行处理得到原始指纹数据。
本实施例中步骤201-步骤203的实现方法同前述实施例中步骤101-步骤103的实现方法相同,发明人在此不再赘述。
步骤204,对所述原始指纹数据进行加密。
在本发明中,当连接设备获得原始指纹数据后,并不是直接将原始指纹数据发送至终端设备,而是再次对原始指纹数据进行加密。
具体地,本发明对原始指纹数据进行加密的方法包括:
步骤2041,获取所述连接设备的当前时间。所述当前时间为所述加密时利用到的时间参数。
步骤2042,调用时间加密算法,为所述原始指纹数据添加第一时间戳,所述第一时间戳由所述当前时间计算得到。
具体在本发明中,连接设备首先获取连接设备系统的当前时间,例如当前时间为7:59:36,进而利用该当前时间调用时间加密算法,计算第一时间戳,并将所述第一时间戳添加到原始指纹数据的数据头中。
本发明中对原始指纹数据进行加密的方式可以采用同对部分指纹数据进行加密的相同加密方式。例如以当前时间为7:59:36继续为例来说,本发明选取在原始指纹数据的数据头中添加8比特位长度的一个字节的第一时间戳,该8比特位长度的字节表示的分针时间,其字节的高4位为分针时间十位的二进制数据,字节的低4位为分针时间个位的二进制数据,具体如图2所示。那么该第一时间戳即为01011001,将该第一时间戳01011001添加到原始指纹数据的数据头中。
亦或者,本发明选取在原始指纹数据的数据头中添加16比特位长度的两个字节的第一时间戳,该16比特位长度的两个字节表示的分针时间和秒针时间。其第一字节的高4位为分针时间十位的二进制数据,低4位为分针时间个位的二进制数据,第二字节的高4位为秒针时间十位的二进制数据,低4位为秒针时间个位的二进制数据,具体如图3所示。那么此时,该第一时间戳即为0101100100110110,该将第一时间戳0101100100110110添加到原始指纹数据的 数据头中。
亦或者,本发明选取在原始指纹数据的数据头中添加24比特位长度的三个字节的第一时间戳,其第一字节的高4位和低4位可以用于表示分针时间,第二字节的高4位和低4位可以用于表示秒针时间,而其第三字节的高4位可以为分针时间十位的二进制数据与秒针时间十位的二进制数据相异或的结果,低4位为分针时间个位的二进制数据与秒针时间个位的二进制数据相异或的结果,具体如图4所示。那么此时,分针时间十位的二进制数据0101与秒针时间十位的二进制数据0011相异或得到第三字节的高4位为0110,分针时间个位的二进制数据1001与秒针时间个位的二进制数据0110相异或得到第三字节的低4位为1111,此时该第一时间戳即为010110010011011001101111,该将第一时间戳010110010011011001101111添加到原始指纹数据的数据头中。
步骤205,将加密后的原始指纹数据和加密时利用到的时间参数发送至所述终端设备。
连接设备在完成对原始指纹数据的加密后,将加密后的原始指纹数据和加密时用到的时间参数,如前述实施例中当前时间7:59:36一同发送至终端设备,以使得终端设备利用加密时用到的时间参数对加密后的原始指纹数据进行解密,以获得原始指纹数据。
在本实施例中,连接设备并不是直接将原始指纹数据发送至终端设备,而是将原始指纹数据加密后发送至终端设备,进一步保证了指纹数据传输的安全性。
在上述实施例的基础上,本发明还提供一种指纹认证方法,该方法应用于终端设备,所述终端设备与连接设备建立通信连接,所述连接设备包括多个存储分区,每个所述存储分区分别存储有加密后的部分指纹数据,所述方法如图6所示,具体包括:
步骤301,发送鉴权请求信息至连接设备,以使得所述连接设备依据所述鉴权请求信息,从所述存储分区中获取加密后的部分指纹数据,并将获取到的所有加密后的部分指纹数据进行解密,进而将所有解密后的部分指纹数据进行处理得到原始指纹数据。
在本发明中,当用户操作终端设备实现例如开机解屏锁、手机支付等功能,而需要用户输入指纹数据时,终端设备会自动寻找其周围一定范围内的连接设备,并建立与连接设备的连接。
具体地,本发明中的连接设备可以处于实时接收数据信息的待机状态,终端设备需要寻找并建立与连接设备间的通信连接时,主动向在一定范围内寻找到的连接设备发起无线网络连接请求。当连接设备完成对终端设备的身份认证后,建立与终端设备的网络通信连接。此时,终端设备在发送鉴权请求信息至连接设备。
步骤302,接收所述连接设备发送的原始指纹数据。
步骤303,将所述原始指纹数据与用户当前输入的指纹数据进行比对。当比对成功时,执行步骤304,否则执行步骤305。
当终端设备接收到连接设备返回的原始指纹数据后,与当前用户输入的指纹数据进行比对。
步骤304,确定所述用户为合法用户。
当比对成功时,表明当前用户为合法用户,终端设备完成对用户身份的认证,允许用户执行后续操作。
步骤305,确定所述用户为非法用户。
当比对不成功时,表明当前用户为非法用户,终端设备直接拒绝本次操作。
当然在本实施例中,如果步骤302接收到的原始指纹数据为加密后的原始指纹数据时,如图7所示,同时终端设备还会接收到连接设备发送的加密时利用到的时间参数,此时,本发明在步骤302与步骤303之间还包括:步骤306,依据所述加密时利用到的时间参数,对所述加密后的原始指纹数据进行解密,以获得原始指纹数据。
具体地,终端设备会依据所述加密时利用到的时间参数,如上述实施例中的当前时间7:59:36,调用时间加密算法,将所述加密后的原始指纹数据中的第一时间戳去除,获得原始指纹数据。其中所述第一时间戳由所述当前时间计算得到。
因此在本实施例中,当终端设备需要对当前用户输入的指纹数据进行认证时,会主动向其周围一定范围内的连接设备发起网络通信连接,进而从连接设 备中获取预先存储的合法用户的原始指纹数据,将该原始指纹数据与当前用户输入的指纹数据进行比对,当比对成功时,确定当前用户为合法用户,允许用户继续执行后续操作。因此即使用户丢失了终端设备,非法用户攻击终端设备系统内核,也无法获取到合法用户的指纹数据,本发明保证了终端设备的安全性。
在本发明上述实施例中,本发明中的连接设备可以为用户身上的穿戴设备,例如手表、手环、智能眼镜等。终端设备可以为手机、平板电脑等。
基于前文本发明提供的一种指纹认证方法,本发明还提供一种连接设备,如图8所示,该连接设备与终端设备建立通信连接,所述连接设备包括多个存储分区,每个所述存储分区分别存储有加密后的部分指纹数据,所述连接设备具体包括:第一接收单元10、第一获取单元20、解密处理单元30和第一发送单元40。其中,
第一接收单元10,用于接收所述终端设备发送的鉴权请求信息;
第一获取单元20,用于依据所述鉴权请求信息,从所述存储分区中获取加密后的部分指纹数据;
解密处理单元30,用于将所述第一获取单元10获取到的所有加密后的部分指纹数据进行解密,并将所有解密后的部分指纹数据进行处理得到原始指纹数据;
第一发送单元40,用于将所述原始指纹数据发送至所述终端设备。
其中较优的,本发明还包括:
第一加密单元50,用于对所述原始指纹数据进行加密;
所述第一发送单元40具体用于,将加密后的原始指纹数据和加密时利用到的时间参数发送至所述终端设备。
其中,所述第一加密单元50具体包括:
获取子单元51,用于获取所述连接设备的当前时间;所述当前时间为所述加密时利用到的时间参数;
加密子单元52,用于调用时间加密算法,为所述原始指纹数据添加第一 时间戳,所述第一时间戳由所述当前时间计算得到。
其中较优的,本发明还包括:
指纹数据拆分单元60,用于在所述连接设备首次接收到所述原始指纹数据后,将所述原始指纹数据拆分成多个部分指纹数据;
第二加密单元70,用于依据对所述多个部分指纹数据的当前保存时间,调用时间加密算法,依次为所述多个部分指纹数据添加第二时间戳,所述第二时间戳由所述当前保存时间计算得到。
基于前文本发明提供的一种指纹认证方法,本发明还提供一种终端设备,如图9所示,所述终端设备与连接设备建立通信连接,所述连接设备包括多个存储分区,每个所述存储分区分别存储有加密后的部分指纹数据,所述终端设备具体包括:第二发送单元100、第二接收单元200、比对单元300和确定单元400。其中,
第二发送单元100,用于发送鉴权请求信息至所述连接设备,以使得所述连接设备依据所述鉴权请求信息,从所述存储分区中获取加密后的部分指纹数据,并将获取到的所有加密后的部分指纹数据进行解密,进而将所有解密后的部分指纹数据进行处理得到原始指纹数据;
第二接收单元200,用于接收所述连接设备发送的原始指纹数据;
比对单元300,用于将所述原始指纹数据与用户当前输入的指纹数据进行比对;
确定单元400,用于当所述比对单元比对成功时,确定所述用户为合法用户。
其中较优的,当所述原始指纹数据为加密后的原始指纹数据时,所述第二接收单元200具体用于,接收所述连接设备发送的加密后的原始指纹数据和加密时利用到的时间参数;所述终端设备还包括:
解密单元500,用于依据所述加密时利用到的时间参数,对所述加密后的原始指纹数据进行解密,以获得原始指纹数据。
其中所述解密单元500具体用于,依据所述加密时利用到的时间参数,调用时间加密算法,将所述加密后的原始指纹数据中的第一时间戳去除,获得原 始指纹数据;所述第一时间戳由所述当前时间计算得到。
需要说明的是,本说明书中的各个实施例均采用递进的方式描述,每个实施例重点说明的都是与其他实施例的不同之处,各个实施例之间相同相似的部分互相参见即可。对于装置类实施例而言,由于其与方法实施例基本相似,所以描述的比较简单,相关之处参见方法实施例的部分说明即可。
最后,还需要说明的是,在本文中,诸如第一和第二等之类的关系术语仅仅用来将一个实体或者操作与另一个实体或操作区分开来,而不一定要求或者暗示这些实体或操作之间存在任何这种实际的关系或者顺序。而且,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者设备不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者设备所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括所述要素的过程、方法、物品或者设备中还存在另外的相同要素。
以上对本发明所提供的一种指纹认证方法、连接设备和终端设备进行了详细介绍,本文中应用了具体个例对本发明的原理及实施方式进行了阐述,以上实施例的说明只是用于帮助理解本发明的方法及其核心思想;同时,对于本领域的一般技术人员,依据本发明的思想,在具体实施方式及应用范围上均会有改变之处,综上所述,本说明书内容不应理解为对本发明的限制。

Claims (14)

  1. 一种指纹认证方法,应用于连接设备,其特征在于,所述连接设备与终端设备建立通信连接,所述连接设备包括多个存储分区,每个所述存储分区分别存储有加密后的部分指纹数据,所述方法包括:
    接收所述终端设备发送的鉴权请求信息;
    依据所述鉴权请求信息,从所述存储分区中获取加密后的部分指纹数据;
    将获取到的所有加密后的部分指纹数据进行解密,并将所有解密后的部分指纹数据进行处理得到原始指纹数据;
    将所述原始指纹数据发送至所述终端设备。
  2. 根据权利要求1所述的方法,其特征在于,所述将所有解密后的部分指纹数据进行处理得到原始指纹数据后,且所述将所述原始指纹数据发送至所述终端设备前,所述方法还包括:
    对所述原始指纹数据进行加密;
    所述将所述原始指纹数据发送至所述终端设备,具体包括:
    将加密后的原始指纹数据和加密时利用到的时间参数发送至所述终端设备。
  3. 根据权利要求2所述的方法,其特征在于,所述对所述原始指纹数据进行加密包括:
    获取所述连接设备的当前时间;所述当前时间为所述加密时利用到的时间参数;
    调用时间加密算法,为所述原始指纹数据添加第一时间戳,所述第一时间戳由所述当前时间计算得到。
  4. 根据权利要求1-3任一项所述的方法,其特征在于,当所述连接设备首次接收到所述原始指纹数据时,所述方法还包括:将所述原始指纹数据拆分成多个部分指纹数据;
    所述部分指纹数据的加密方法包括:
    依据对所述多个部分指纹数据的当前保存时间,调用时间加密算法,依次为所述多个部分指纹数据添加第二时间戳,所述第二时间戳由所述当前保存时间计算得到。
  5. 一种指纹认证方法,应用于终端设备,其特征在于,所述终端设备与连接设备建立通信连接,所述连接设备包括多个存储分区,每个所述存储分区分别存储有加密后的部分指纹数据,所述方法包括:
    发送鉴权请求信息至所述连接设备,以使得所述连接设备依据所述鉴权请求信息,从所述存储分区中获取加密后的部分指纹数据,并将获取到的所有加密后的部分指纹数据进行解密,进而将所有解密后的部分指纹数据进行处理得到原始指纹数据;
    接收所述连接设备发送的原始指纹数据;
    将所述原始指纹数据与用户当前输入的指纹数据进行比对;
    当比对成功时,确定所述用户为合法用户。
  6. 根据权利要求5所述的方法,其特征在于,当所述原始指纹数据为加密后的原始指纹数据时,所述接收所述连接设备发送的原始指纹数据具体包括:接收所述连接设备发送的加密后的原始指纹数据和加密时利用到的时间参数;所述方法还包括:
    依据所述加密时利用到的时间参数,对所述加密后的原始指纹数据进行解密,以获得原始指纹数据。
  7. 根据权利要求6所述的方法,其特征在于,所述依据所述加密时利用到的时间参数,对所述加密后的原始指纹数据进行解密,以获得原始指纹数据具体包括:
    依据所述加密时利用到的时间参数,调用时间加密算法,将所述加密后的原始指纹数据中的第一时间戳去除,获得原始指纹数据;
    其中所述第一时间戳由所述当前时间计算得到。
  8. 一种连接设备,其特征在于,所述连接设备与终端设备建立通信连接,所述连接设备包括多个存储分区,每个所述存储分区分别存储有加密后的部分指纹数据,所述连接设备包括:
    第一接收单元,用于接收所述终端设备发送的鉴权请求信息;
    第一获取单元,用于依据所述鉴权请求信息,从所述存储分区中获取加密后的部分指纹数据;
    解密处理单元,用于将所述第一获取单元获取到的所有加密后的部分指纹 数据进行解密,并将所有解密后的部分指纹数据进行处理得到原始指纹数据;
    第一发送单元,用于将所述原始指纹数据发送至所述终端设备。
  9. 根据权利要求8所述的连接设备,其特征在于,还包括:
    第一加密单元,用于对所述原始指纹数据进行加密;
    所述第一发送单元具体用于,将加密后的原始指纹数据和加密时利用到的时间参数发送至所述终端设备。
  10. 根据权利要求9所述的连接设备,其特征在于,所述第一加密单元包括:
    获取子单元,用于获取所述连接设备的当前时间;所述当前时间为所述加密时利用到的时间参数;
    加密子单元,用于调用时间加密算法,为所述原始指纹数据添加第一时间戳,所述第一时间戳由所述当前时间计算得到。
  11. 根据权利要求8-10任一项所述的连接设备,其特征在于,还包括:
    指纹数据拆分单元,用于在所述连接设备首次接收到所述原始指纹数据后,将所述原始指纹数据拆分成多个部分指纹数据;
    第二加密单元,用于依据对所述多个部分指纹数据的当前保存时间,调用时间加密算法,依次为所述多个部分指纹数据添加第二时间戳,所述第二时间戳由所述当前保存时间计算得到。
  12. 一种终端设备,其特征在于,所述终端设备与连接设备建立通信连接,所述连接设备包括多个存储分区,每个所述存储分区分别存储有加密后的部分指纹数据,所述终端设备包括:
    第二发送单元,用于发送鉴权请求信息至所述连接设备,以使得所述连接设备依据所述鉴权请求信息,从所述存储分区中获取加密后的部分指纹数据,并将获取到的所有加密后的部分指纹数据进行解密,进而将所有解密后的部分指纹数据进行处理得到原始指纹数据;
    第二接收单元,用于接收所述连接设备发送的原始指纹数据;
    比对单元,用于将所述原始指纹数据与用户当前输入的指纹数据进行比对;
    确定单元,用于当所述比对单元比对成功时,确定所述用户为合法用户。
  13. 根据权利要求12所述的终端设备,其特征在于,当所述原始指纹数据为加密后的原始指纹数据时,所述第二接收单元具体用于,接收所述连接设备发送的加密后的原始指纹数据和加密时利用到的时间参数;所述终端设备还包括:
    解密单元,用于依据所述加密时利用到的时间参数,对所述加密后的原始指纹数据进行解密,以获得原始指纹数据。
  14. 根据权利要求13所述的终端设备,其特征在于,所述解密单元具体用于,依据所述加密时利用到的时间参数,调用时间加密算法,将所述加密后的原始指纹数据中的第一时间戳去除,获得原始指纹数据;
    其中所述第一时间戳由所述当前时间计算得到。
PCT/CN2015/095782 2015-08-25 2015-11-27 一种指纹认证方法、连接设备和终端设备 WO2017031849A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510526460.2A CN105208005B (zh) 2015-08-25 2015-08-25 一种指纹认证方法、连接设备和终端设备
CN201510526460.2 2015-08-25

Publications (1)

Publication Number Publication Date
WO2017031849A1 true WO2017031849A1 (zh) 2017-03-02

Family

ID=54955439

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2015/095782 WO2017031849A1 (zh) 2015-08-25 2015-11-27 一种指纹认证方法、连接设备和终端设备

Country Status (2)

Country Link
CN (1) CN105208005B (zh)
WO (1) WO2017031849A1 (zh)

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110225014A (zh) * 2019-05-30 2019-09-10 上海应用技术大学 基于指纹集中下发式的物联网设备身份认证方法
US11552944B2 (en) 2017-10-11 2023-01-10 Samsung Electronics Co., Ltd. Server, method for controlling server, and terminal device

Families Citing this family (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106022055A (zh) * 2016-05-27 2016-10-12 广东欧珀移动通信有限公司 一种指纹解锁控制方法、及终端设备
CN106066953B (zh) * 2016-05-27 2019-12-27 Oppo广东移动通信有限公司 一种指纹解锁控制方法、及终端设备
CN106886699B (zh) * 2017-01-20 2020-06-19 北京安云世纪科技有限公司 一种指纹验证方法及相关设备
CN106897596B (zh) * 2017-01-20 2020-06-19 北京安云世纪科技有限公司 一种指纹验证方法及相关设备
CN107239771A (zh) * 2017-06-21 2017-10-10 北京小米移动软件有限公司 指纹校准方法及装置
CN110781472A (zh) * 2019-10-08 2020-02-11 Oppo(重庆)智能科技有限公司 指纹数据的存储和校验方法、终端及存储介质

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2348309B (en) * 1999-03-23 2002-10-09 Nec Corp Authentication executing,device portable authentication device and authentication method using biometrics identification
CN103546544A (zh) * 2013-09-30 2014-01-29 张家港市速达电子商务有限公司 一种基于云计算的数据管理系统
CN104050406A (zh) * 2014-07-03 2014-09-17 南昌欧菲生物识别技术有限公司 利用指纹组合进行鉴权的方法及终端设备

Family Cites Families (13)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101375284B (zh) * 2004-10-25 2012-02-22 安全第一公司 安全数据分析方法和系统
CN1841255B (zh) * 2005-03-30 2011-09-07 侯方勇 保护数据存储的机密性与完整性的方法和装置
CN101043326B (zh) * 2006-03-22 2011-02-09 赵兴 动态信息加密系统和方法
CN101098225B (zh) * 2006-06-29 2012-07-25 中国银联股份有限公司 安全数据传输方法及支付方法、支付终端和支付服务器
JP4388039B2 (ja) * 2006-07-07 2009-12-24 株式会社ジェーシービー ネット決済システム
JP4919744B2 (ja) * 2006-09-12 2012-04-18 富士通株式会社 生体認証装置及び生体認証方法
CN101312522A (zh) * 2007-05-22 2008-11-26 中兴通讯股份有限公司 视频点播系统
CN101330594B (zh) * 2007-06-18 2013-02-27 中兴通讯股份有限公司 对等网络视频点播媒体的存储方法及其媒体点播系统
CN101122942B (zh) * 2007-09-21 2012-02-22 飞天诚信科技股份有限公司 数据安全读取方法及其安全存储装置
CN101478541A (zh) * 2008-10-21 2009-07-08 刘洪利 一种生物特征认证方法,以及一种生物特征认证系统
CN103955528B (zh) * 2014-05-09 2015-09-23 北京华信安天信息科技有限公司 写入文件数据的方法、读取文件数据的方法以及装置
CN104318201A (zh) * 2014-09-05 2015-01-28 大唐微电子技术有限公司 一种指纹处理的方法及芯片、终端
CN104601681A (zh) * 2014-12-31 2015-05-06 乐视网信息技术(北京)股份有限公司 一种文件分片的处理方法和装置

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
GB2348309B (en) * 1999-03-23 2002-10-09 Nec Corp Authentication executing,device portable authentication device and authentication method using biometrics identification
CN103546544A (zh) * 2013-09-30 2014-01-29 张家港市速达电子商务有限公司 一种基于云计算的数据管理系统
CN104050406A (zh) * 2014-07-03 2014-09-17 南昌欧菲生物识别技术有限公司 利用指纹组合进行鉴权的方法及终端设备

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US11552944B2 (en) 2017-10-11 2023-01-10 Samsung Electronics Co., Ltd. Server, method for controlling server, and terminal device
CN110225014A (zh) * 2019-05-30 2019-09-10 上海应用技术大学 基于指纹集中下发式的物联网设备身份认证方法
CN110225014B (zh) * 2019-05-30 2021-07-16 上海应用技术大学 基于指纹集中下发式的物联网设备身份认证方法

Also Published As

Publication number Publication date
CN105208005A (zh) 2015-12-30
CN105208005B (zh) 2019-10-11

Similar Documents

Publication Publication Date Title
WO2017031849A1 (zh) 一种指纹认证方法、连接设备和终端设备
JP6571250B2 (ja) ある装置を使用して別の装置をアンロックする方法
CN109150835B (zh) 云端数据存取的方法、装置、设备及计算机可读存储介质
CN110365484B (zh) 一种设备认证的数据处理方法、装置及系统
TWI655875B (zh) Method for establishing wireless communication connection, communication master device, communication slave device, server and system
US20170063827A1 (en) Data obfuscation method and service using unique seeds
JP5739072B2 (ja) 共有エフェメラル・キー・データのセットを用いるエクスチェンジを符号化するためのシステム及び方法
CN105760764B (zh) 一种嵌入式存储设备文件的加解密方法、装置及终端
US11463435B2 (en) Identity authentication method and system based on wearable device
CN106452770B (zh) 一种数据加密方法、解密方法、装置和系统
WO2012024872A1 (zh) 移动互联网加密通讯的方法、系统及相关装置
US11424919B2 (en) Protecting usage of key store content
US11356442B2 (en) Wearable device-based identity authentication method and system
CN107707562B (zh) 一种非对称动态令牌加、解密算法的方法、装置
WO2020232854A1 (zh) 车辆解锁方法、装置、计算机设备及存储介质
US20110010544A1 (en) Process distribution system, authentication server, distribution server, and process distribution method
KR101358375B1 (ko) 스미싱 방지를 위한 문자메시지 보안 시스템 및 방법
JP2022117456A (ja) ハードウェアセキュリティモジュールを備えたメッセージ伝送システム
WO2014166193A1 (zh) 应用程序加密处理方法、装置和终端
KR101451638B1 (ko) 본인 확인 및 도용 방지 시스템 및 방법
KR101004387B1 (ko) 웹사이트 사용자 인증 시스템 및 그 방법
CN112887983A (zh) 设备身份认证方法、装置、设备及介质
WO2019153751A1 (zh) 一种终端的认证方法和装置
KR101808313B1 (ko) 데이터 암호화 방법
CN105722080B (zh) 蓝牙配对方法、主智能终端以及从智能终端

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 15902118

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 15902118

Country of ref document: EP

Kind code of ref document: A1