WO2022166198A1 - 基于生物特征id链的验证方法及其验证系统、用户终端 - Google Patents

基于生物特征id链的验证方法及其验证系统、用户终端 Download PDF

Info

Publication number
WO2022166198A1
WO2022166198A1 PCT/CN2021/117470 CN2021117470W WO2022166198A1 WO 2022166198 A1 WO2022166198 A1 WO 2022166198A1 CN 2021117470 W CN2021117470 W CN 2021117470W WO 2022166198 A1 WO2022166198 A1 WO 2022166198A1
Authority
WO
WIPO (PCT)
Prior art keywords
biometric
feature
template
chain
user
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2021/117470
Other languages
English (en)
French (fr)
Inventor
陈成钱
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Unionpay Co Ltd
Original Assignee
China Unionpay Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Unionpay Co Ltd filed Critical China Unionpay Co Ltd
Priority to JP2022576855A priority Critical patent/JP7489494B2/ja
Priority to US18/257,281 priority patent/US12093360B2/en
Publication of WO2022166198A1 publication Critical patent/WO2022166198A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/32User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06VIMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
    • G06V40/00Recognition of biometric, human-related or animal-related patterns in image or video data
    • G06V40/10Human or animal bodies, e.g. vehicle occupants or pedestrians; Body parts, e.g. hands
    • G06V40/12Fingerprints or palmprints
    • G06V40/1365Matching; Classification
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
    • H04L9/0825Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using asymmetric-key encryption or public key infrastructure [PKI], e.g. key signature or public key certificates

Definitions

  • the present invention relates to computer technology, in particular to a verification method based on a biometric ID chain, a verification system based on a biometric ID chain, and a user terminal.
  • the user terminal obtains the fingerprint ID, and sends the fingerprint ID together with the user ID to the identity authentication background to complete the registration.
  • the user terminal sends the obtained fingerprint ID and user ID to the identity authentication background, and the identity authentication background matches the fingerprint ID and user ID saved in the identity authentication background, and the matching is consistent. , the authentication succeeds, and if the matches are inconsistent, the authentication fails.
  • This method of matching by obtaining the fingerprint ID of the user terminal can solve the problem of specifying fingerprint verification, but the user terminal generates the fingerprint ID randomly for each entry, that is, for the same user terminal, each entry
  • the generated fingerprint IDs are all different, which causes the following problem: after the user registers the specified finger in the identity authentication registration stage, the fingerprint of the user terminal is subsequently deleted on the user terminal, and then the user terminal is re-deleted. After re-entering the user terminal with the same finger, it is no longer possible to use the same finger to complete the identity authentication, which will affect the whole process of the identity authentication process, resulting in the problem that the fingerprint of the identity authentication cannot be cancelled, and the identity authentication background will continue to accumulate User fingerprints bind garbage data.
  • the present invention aims to propose a biometric ID chain-based verification method and a biometric ID chain-based verification system that can solve the problem that the same biometrics cannot be used after deletion and re-entry.
  • the verification method based on the biometric ID chain of one aspect of the present invention is characterized in that, comprising:
  • the user terminal obtains the biometric feature to be verified
  • the user terminal compares the biometric feature to be verified with the biometric template in the old biometric template area and compares the biometric feature to be verified with the biometric template in the current biometric template area. Yes, to match at least two biometric IDs;
  • the user terminal generates a biometric ID chain based on the at least two biometric IDs
  • the sending step the user terminal sends the user ID, the device ID and the biometric ID chain to the background;
  • the background performs identity verification based on the received user ID, device ID, the biometric ID chain and the pre-stored binding relationship.
  • the binding relationship between the first biometric ID and the user ID and the device ID is pre-stored in the background, and the background verifies whether the first biometric ID stored in the binding relationship contains In the biometric ID chain, if there is, the authentication is successful.
  • the obtaining step further includes:
  • the user terminal acquires the first biometric feature, generates a corresponding biometric feature template and a first biometric feature ID based on the first biometric feature, and stores the biometric feature template and the first biometric feature ID of the first biometric feature into the current biometric feature.
  • the template area sends the first biometric ID, user ID, and device ID of the first biometric to the background;
  • Pre-storing step receiving the first biometric ID, user ID, device ID of the first biometric in the background, establishing and storing the binding relationship between the first biometric ID and the user ID, device ID;
  • the user terminal obtains an instruction to delete the first biometric feature, deletes the biometric template and the first biometric ID of the first biometric feature from the current biometric template area and stores it in the old biometric template area.
  • the deleting step and before the acquiring step it further includes:
  • the user terminal acquires the second biometric feature, generates a corresponding biometric template and a second biometric ID based on the second biometric, and stores the biometric template and the second biometric ID of the second biometric to the current biometric A template region, wherein the second biometric is the same as the first biometric.
  • the first biometric ID in the binding relationship is updated to a second biometric ID.
  • the public key is sent to the background together with the first biometric ID, user ID, and device ID of the first biometric,
  • the background receives the first biometric ID, user ID, device ID, and public key of the first biometric, and establishes and stores the relationship between the first biometric ID, the user ID, the device ID, and the public key. binding relationship.
  • the first biometric feature and the second biometric feature are any one of the following: fingerprint, iris, human face, finger vein, palm vein and palm print.
  • the verification method based on the biometric ID chain of one aspect of the present invention is characterized in that, comprising:
  • the obtaining step is to obtain the biometric feature to be verified
  • the comparison step is to compare the biometric feature to be verified with the biometric template in the old biometric template area and compare the biometric feature to be verified with the biometric template in the current biometric template area, to match at least two biometric IDs;
  • the ID chain generation step is to generate a biometric ID chain based on the at least two biometric IDs; and the sending step is to send the user ID, the device ID and the biometric ID chain to the background for authentication.
  • the identity verification includes: storing the binding relationship between the first biometric ID and the user ID and the device ID in the background,
  • the background verifies whether the first biometric ID stored in the binding relationship is included in the biometric ID chain, and if so, the authentication is successful.
  • the obtaining step further includes:
  • the authentication and registration step is to obtain the first biometric feature, generate the corresponding biometric feature template and the first biometric ID based on the first biometric feature, and store the biometric template and the first biometric ID of the first biometric feature in the current biometric template area. , send the first biometric ID, user ID, device ID of the first biometric to the background to establish the binding relationship between the first biometric ID and user ID, device ID; And delete step, obtain and delete the first biological The indication of the feature, the biometric template of the first biometric and the first biometric ID are deleted from the current biometric template area and stored in the old biometric template area.
  • the deleting step and before the acquiring step it further includes:
  • Re-entry step obtain the second biometric feature, generate the corresponding biometric template and the second biometric ID based on the second biometric, and store the biometric template and the second biometric ID of the second biometric in the current biometric template area , wherein the second biometric feature is the same as the first biometric feature.
  • the first biometric ID in the binding relationship is updated to a second biometric ID.
  • the public key is sent to the background together with the first biometric ID, user ID, and device ID of the first biometric.
  • the current biometric template area is to store the corresponding biometric template and the first biometric ID based on the first biometric when the first biometric is obtained, and delete the first biometric after obtaining the first biometric.
  • the biometric template of the first biometric and the first biometric ID are deleted from the current biometric template area, and on the other hand, the current biometric template area is obtained under the situation of the second biometric, storing the corresponding biometric template and the second biometric ID generated based on the second biometric,
  • the old biometric template area is to store the biometric template and the first biometric ID of the first biometric deleted from the current biometric template area when an instruction to delete the first biometric is obtained.
  • the first biometric feature and the second biometric feature are any one of the following: fingerprint, iris, human face, finger vein, palm vein and palm print.
  • the verification system based on the biometric ID chain of one aspect of the present invention is characterized in that it includes a background and a user terminal,
  • the user terminal includes:
  • the biological feature module is used to collect the first biological feature and the second biological feature, and respectively generate a biological feature template corresponding to the first biological feature and a first biological feature ID, and a biological feature template corresponding to the second biological feature and a second biological feature.
  • a biometric ID and for collecting the biometrics to be verified, on the other hand, for matching to at least two biometric IDs based on the biometrics to be verified and generating a biometric ID chain based on the at least two biometric IDs, wherein, the first biometric ID of the first biometric and the second biometric ID of the second biometric are randomly generated respectively; and
  • an identity verification module for performing data interaction with the background and calling the biometric module to achieve identity verification
  • a storage module for receiving the first biometric ID, user ID, and device ID sent by the user terminal, and establishing and storing the binding relationship between the first biometric ID, user ID, and device ID;
  • a verification module configured to perform identity verification based on the biometric ID chain, user ID and device ID received from the user terminal, and the binding relationship stored in the storage module.
  • the authentication module is configured to send the first biometric ID, user ID, device ID to the background and to send the user ID, device ID and biometric ID chain to the background.
  • the user terminal further includes:
  • the identity authentication module is used to generate the public key and use the public key to sign the data.
  • the identity verification module is configured to send the first biometric ID, public key, user ID, device ID to the background and to send the user ID, device ID and biometric ID chain to the background.
  • the biometric module includes:
  • the acquisition module is used to collect the first biological feature and generate the biological feature template and the first biological feature ID corresponding to the first biological feature, and collect the second biological feature and generate the biological feature template and the second biological feature corresponding to the second biological feature Feature ID, and used to collect the biometrics to be verified;
  • the current biometric template area is used to store the biometric template and biometric ID of the first biometric or the second biometric collected by the acquisition module;
  • Delete module for deleting the biometric template and biometric ID of the biometric stored in the current biometric module area according to the deletion instruction
  • the old biometric template area is used to store the biometric template and biometric ID of the biometric deleted by the deletion module;
  • a comparison module for comparing the biometric feature to be verified with the biometric template in the old biometric template area and comparing the biometric feature to be verified with the biometric template in the current biometric template area Yes, each matched to at least two biometric IDs;
  • a chain generation module for generating biometric ID chains based on at least two biometric IDs.
  • the verification module when the verification module receives the biometric ID chain, user ID and device ID from the user terminal, it verifies whether the first biometric ID stored in the binding relationship is included in the In the biometric ID chain, if there is, the authentication is successful.
  • the verification module updates the first biometric ID in the binding relationship stored in the storage module to a second biometric ID.
  • the first biometric feature and the second biometric feature are any one of the following: fingerprint, iris, human face, finger vein, palm vein and palm print.
  • the biometric module is used to collect the first biometric feature and the second biometric feature and generate a biometric template and a first biometric ID corresponding to the first biometric, a biometric template and a second biometric corresponding to the second biometric Feature ID, and for collecting the biometric feature to be verified, on the other hand, for matching to at least two biometric IDs based on the biometric feature to be verified and generating a feature ID chain based on the two biometric IDs, wherein the A first biometric ID for the first biometric and a second biometric ID for the second object feature are randomly generated; and
  • the identity verification module is used to send the first biometric ID, user ID, and device ID to the background to establish a binding relationship between the first biometric ID, the user ID, and the device ID.
  • device ID and biometric ID chain are sent to the background to implement authentication based on the binding relationship and the biometric ID chain.
  • the biometric module includes:
  • the acquisition module is used to collect the first biological feature and generate the biological feature template and the first biological feature ID corresponding to the first biological feature, and collect the second biological feature and generate the biological feature template and the second biological feature corresponding to the second biological feature Feature ID, and used to collect the biometrics to be verified;
  • the current biometric template area is used to store the biometric template and biometric ID of the first biometric or the second biometric collected by the acquisition module;
  • Delete module for deleting the biometric template and biometric ID of the biometric stored in the current biometric module area according to the deletion instruction
  • the old biometric template area is used to store the biometric template and biometric ID of the biometric deleted by the deletion module;
  • a comparison module is used to compare the biometric feature to be verified with the biometric template in the old biometric template area and compare the biometric feature to be verified with the biometric template in the current biometric template area , to match at least two biometric IDs;
  • a chain generation module for generating a chain of biometric IDs according to the two biometric IDs.
  • an identity authentication module configured to generate a public key and use the public key to sign the data.
  • the computer-readable medium of one aspect of the present invention stores a computer program thereon, and is characterized in that, when the computer program is executed by a processor, the authentication method based on the biometric ID chain is implemented.
  • a computer device includes a storage module, a processor, and a computer program stored on the storage module and executable on the processor, characterized in that, when the processor executes the computer program, the based Verification method for biometric ID chain.
  • FIG. 1 is a schematic flowchart of a verification method based on a biometric ID chain according to an aspect of the present invention.
  • FIG. 2 is a structural block diagram of a verification system based on a biometric ID chain according to an aspect of the present invention.
  • FIG. 3 shows a schematic flowchart of an embodiment of a verification method based on a fingerprint ID chain.
  • FIG. 4 is a block diagram showing the structure of an embodiment of the authentication system based on the fingerprint ID chain.
  • Words such as “have” and “include” indicate that in addition to having units (modules) and steps that are directly and explicitly stated in the description and claims, the technical solutions of the present invention do not exclude any units (modules) and steps that are not directly or explicitly stated. The situation of other units (modules) and steps of the representation.
  • the idea of the present invention is to obtain the historical biometric ID information of the same biometric feature on the same user terminal, and during identity authentication, by uploading the biometric ID chain to the background, the background will query and determine whether the user is currently based on the biometric ID.
  • the biometrics belonging to it belong to the same biometrics as the biometrics in the previous identity authentication registration stage, so as to determine the matching relationship to complete the identity verification.
  • FIG. 1 is a schematic flowchart of a verification method based on a biometric ID chain according to an aspect of the present invention.
  • the verification method based on the biometric ID chain of one aspect of the present invention mainly includes the following steps:
  • Authentication and registration step S100 During registration, the user terminal obtains the first biometric feature, generates a corresponding first biometric feature template and a first biometric ID based on the first biometric feature, and puts the first biometric template and the first biometric ID into the system. Enter the current biometric template area, and the user terminal sends the first biometric ID, user ID, and device ID to the background;
  • Pre-storing step S200 the background receives the first biometric ID, the user ID, and the device ID from the user terminal, and establishes and stores the binding relationship between the first biometric ID, the user ID, and the device ID;
  • Deleting step S300 the user terminal obtains an instruction to delete the first biometric feature, and deletes the biometric module and the first biometric ID of the first biometric feature from the current biometric template area and stores them in the old biometric template area;
  • Re-entry step S400 the user terminal acquires the second biometric feature, generates a corresponding biometric template and a second biometric ID based on the second biometric, and stores the biometric template and the second biometric ID of the second biometric in the current biometric Feature template area, wherein the second biometric feature is the same as the first biometric feature, such as the fingerprint of the same finger;
  • Obtaining step S500 the user terminal obtains the biometric feature to be verified
  • Comparison step S600 the user terminal compares the biometric feature to be verified with the biometric template in the old biometric template area and compares the biometric feature to be verified with the biometric template in the current biometric template area. Align to match at least two biometric IDs;
  • ID chain generation step S700 the user terminal generates a biometric ID chain based on the at least two biometric IDs
  • Sending step S800 the user terminal sends the user ID, the device ID and the biometric ID chain to the background;
  • Verification step S900 the background performs identity verification based on the received user ID, device ID, the biometric ID chain and the pre-stored binding relationship.
  • the background verifies whether the first biometric ID stored in the binding relationship is included in the biometric ID chain, and if so, the identity verification is successful. Moreover, in the verification step 200, when the identity verification is successful, the first biometric ID in the binding relationship is updated to a second biometric ID.
  • the public key is sent to the background together with the first biometric ID, user ID, and device ID of the first biometric.
  • FIG. 2 is a structural block diagram of a verification system based on a biometric ID chain according to an aspect of the present invention.
  • a verification system based on a biometric ID chain includes a user terminal 100 and a background 200 .
  • User terminal 100 includes:
  • the biometric module 110 is configured to collect the first biometric feature and the second biometric feature, and respectively generate a biometric template and a first biometric ID corresponding to the first biometric, a biometric template and a first biometric ID corresponding to the second biometric.
  • Two biometric IDs, and for collecting the biometrics to be verified, on the other hand, for matching at least two biometric IDs based on the biometric template of the biometrics to be verified and based on the at least two biometric IDs Generate an item feature ID chain, wherein the first biometric ID of the first biometric and the second biometric ID of the second item feature are randomly generated respectively; and
  • an identity authentication module 120 used to generate a public key and use the public key to sign data
  • the identity verification module 130 is used to perform data interaction with the background 200 and call the biometric module 110 and the identity verification module 120 to realize identity verification,
  • the biometric module 110 includes:
  • the acquisition module 111 is used to collect the first biometrics and generate a biometric template and a first biometric ID corresponding to the first biometrics, and collect the second biometrics and generate a biometric template and a second biometrics corresponding to the second biometrics. Biometric ID, and used to collect the biometrics to be verified;
  • the current biometric template area 112 is used to store the biometric template and biometric ID of the first biometric or the second biometric collected by the acquisition module 111;
  • the deletion module 113 is used to delete the biometric template and the biometric ID of the biometric stored in the current biometric module area 112 according to the deletion instruction;
  • the old biometric template area 114 is used to store the biometric template and biometric ID of the biometric deleted by the deletion module 113;
  • the comparison module 115 is used to respectively obtain at least two biometric IDs by matching the biometrics to be verified with the biometric templates in the old biometric template area and the biometric templates in the current biometric template area. ;as well as
  • the chain generation module 116 is configured to generate a chain of biometric IDs according to the at least two biometric IDs.
  • the identity verification module 130 is used for sending the first biometric ID, user ID and device ID to the background 200 and for sending the user ID, device ID and biometric ID chain to the background 200 .
  • the authentication module 130 is used for sending the first biometric ID, public key, user ID, device ID to the background and for sending the user ID, device ID and biometric ID chain to the background 200 .
  • the background 200 includes:
  • the storage module 210 is used to receive the first biometric ID and the user ID and the device ID sent by the user terminal, and establish and store the binding relationship between the first biometric ID and the user ID and the device ID; and the verification module 220 , for performing authentication based on the biometric ID chain, user ID and device ID received from the user terminal, and the binding relationship stored in the storage module.
  • the verification module 220 verifies whether the first biometric ID stored in the binding relationship is included in the biometric ID chain In, if present, the authentication is successful. Preferably, when the identity verification is successful, the verification module 220 updates the first biometric ID in the above-mentioned binding relationship stored in the storage module 210 to the second biometric ID.
  • fingerprints irises, faces, finger veins, palm veins, and palm prints can be used as biometric features.
  • a fingerprint is used as an example to describe the specific implementation manner.
  • FIG. 3 shows a schematic flowchart of an embodiment of a verification method based on a fingerprint ID chain.
  • the verification method based on the fingerprint ID chain of this embodiment mainly includes an authentication registration phase and an identity verification phase (wherein the identity verification phase describes the situation where the user's same finger fingerprint is deleted and then entered).
  • the authentication registration stage mainly includes:
  • S1 The user starts the identity authentication registration, the user clicks the identity authentication registration, enters the user ID, and enters the fingerprint;
  • S2 the user terminal generates an old fingerprint template and an old fingerprint ID (corresponding to "the first biometric template and the first biometric ID” in the claims) according to the entered fingerprint, and puts it into the current fingerprint template area;
  • S3 The user terminal generates a public and private key
  • S4 The user terminal signs the public key, device ID, user ID, and old fingerprint ID data and sends it to the background;
  • S5 The background uses the received public key to verify the signature, and saves the binding relationship between the device ID, user ID, public key, and old fingerprint ID.
  • the authentication phase consists of:
  • S6 The user clicks on the user terminal to delete the fingerprint (ie, sends an instruction to delete the fingerprint);
  • S7 The user terminal puts the old fingerprint template and the old fingerprint ID of the deleted old fingerprint into the old fingerprint template area;
  • S9 the user terminal generates a new fingerprint template and a new fingerprint ID (corresponding to "the second biometric template and the second biometric ID" in the claims) for the entered new fingerprint and puts it into the current fingerprint template area;
  • S11 The user terminal obtains a new fingerprint ID by matching the fingerprint to be verified in the current fingerprint template area;
  • S12 The user terminal obtains the old fingerprint ID by matching the fingerprint to be verified in the old fingerprint template area;
  • S13 The user terminal forms a fingerprint ID chain with the new fingerprint ID and the old fingerprint ID;
  • S14 The user terminal signs the fingerprint ID chain, device ID, user ID and user private key and sends it to the background;
  • S16 The background queries whether the fingerprint ID in the binding relationship exists in the received fingerprint ID chain, and if the judgment result is that it exists, the verification succeeds, otherwise the verification fails.
  • FIG. 4 is a block diagram showing the structure of an embodiment of the authentication system based on the fingerprint ID chain.
  • the authentication system based on the fingerprint ID chain of this embodiment includes: a user terminal 500 and a background 600 .
  • the user terminal 500 includes:
  • the fingerprint authentication module 510 is used to collect new and old fingerprints and generate new and old fingerprint templates and new and old fingerprint IDs corresponding to the new and old fingerprints, and generate a fingerprint ID chain based on the old fingerprint IDs and the new fingerprint IDs; and identity authentication A module 520 for generating public and private keys and encrypting new and old fingerprint IDs and fingerprint ID chains using the public key; and
  • the identity verification module 530 is used for data interaction with the background and invoking the fingerprint authentication module 510 and the identity authentication module 520 .
  • the background 600 includes:
  • the storage module 610 is used to establish and store the binding relationship between the old fingerprint ID and the user ID and the device ID;
  • the verification module 620 is configured to perform identity verification based on the fingerprint ID chain, user ID and device ID received from the user terminal, and the binding relationship stored in the storage module 610 .
  • the identity authentication module 530 may be set in the REE environment, and the fingerprint authentication module 510 and the identity authentication module 520 may be set in the TEE environment.
  • the verification module 620 verifies whether the old biometric ID stored in the binding relationship is included in the biometric ID chain in the case of receiving the biometric ID chain, user ID and device ID from the user terminal 400, and if so, the identity verification success.
  • the verification module 620 updates the old first biometric ID in the above-mentioned binding relationship stored in the storage module 210 to a new biometric ID.
  • the fingerprint authentication module 510 includes:
  • the collection module 511 is used to collect old fingerprints and generate fingerprint templates and old fingerprint IDs corresponding to the old fingerprints and collect new fingerprints and generate new fingerprint templates and new fingerprint IDs corresponding to the new fingerprints, and to collect fingerprints to be verified;
  • the current fingerprint template area 512 is used to store the fingerprint template and fingerprint ID of the old or new fingerprint collected by the collection module collection 111;
  • the deletion module 513 is used to delete the fingerprint template and the fingerprint ID of the fingerprint stored in the current fingerprint module area 112 according to the deletion instruction;
  • the old fingerprint template area 514 is used to store the fingerprint template and the fingerprint ID of the fingerprint deleted by the deletion module 113; the comparison module 515 is used to compare the fingerprint to be verified with the fingerprint template in the old fingerprint template area and the current fingerprint template respectively.
  • the fingerprint templates in the fingerprint template area are matched to obtain at least two fingerprint IDs respectively; and a chain generation module 516 is configured to generate a fingerprint ID chain according to the at least two fingerprint IDs.
  • the verification method based on the biometric ID chain and the verification system based on the biometric ID chain of the present invention propose the technical concept of forming the biometric ID chain, and propose a technology for performing identity verification by using the biometric ID chain based on the same biometrics idea.
  • a biometric ID chain containing the biometric history of the unified user terminal is generated, and in the authentication registration stage and the identity verification stage, by adding the biometric ID
  • the chain sends the background, and the background matches the device ID, user ID and biometric ID chain, which can solve the problem that the user's biometrics on the same user terminal cannot be used after deletion and re-entry.
  • a computer device comprising: a memory; a processor; and a computer program stored on the memory and executable on the processor, wherein the execution of the computer program causes the processor to execute the computer program when The verification method based on the biometric ID chain described above is implemented.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Physics & Mathematics (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Human Computer Interaction (AREA)
  • Multimedia (AREA)
  • Collating Specific Patterns (AREA)

Abstract

一种基于生物特征ID链的验证方法以及验证系统。该方法包括:获取待验证的生物特征;将所述待验证的生物特征与旧生物特征模板区中的生物特征模板进行比对以及将所述待验证的生物特征与当前生物特征模板区中的生物特征模板进行比对,以分别匹配到至少两个生物特征ID;基于所述至少两个生物特征ID生成生物特征ID链;以及将用户ID、设备ID以及所述生物特征ID链发送到后台以进行身份验证。该方法通过在用户终端本地重新录入生物特征时,生成一个包含统一用户终端的生物特征历史的生物特征ID链,能够解决用户在同一用户终端的生物特征在删除重新录入后无法使用的问题。

Description

基于生物特征ID链的验证方法及其验证系统、用户终端
本申请对提交于2021年2月5日并且发明名称为“基于生物特征ID链的验证方法及其验证系统、用户终端”的中国专利申请202110160183.3要求优先权,该中国专利申请的全部公开通过引用并入本文。
技术领域
本发明涉及计算机技术,具体地涉及一种基于生物特征ID链的验证方法、基于生物特征ID链的验证系统以及用户终端。
背景技术
随着指纹手机的普及,越来越多的业务功能使用到了基于指纹的身份认证功能,通过判断用户指纹来开启业务实施等。现有技术中对于指纹进行验证的方式主要是:
(1)身份认证注册阶段,用户终端获取指纹ID,并将指纹ID与用户ID一起发送给身份认证后台完成注册。
(2)身份认证验证阶段,用户终端在指纹验证通过之后,将获取的指纹ID及用户ID发给身份认证后台,身份认证后台将指纹ID和用户ID与身份认证后台保存的进行匹配,匹配一致,则身份认证成功,匹配不一致,则身份认证失败。
这样的通过获取用户终端的指纹ID来进行匹配的方式,虽然能解决指定指纹验证的问题,但是,用户终端对于每次录入的指纹ID都是随机生成,即对于同一个用户终端,每次录入的时候,产生的指纹ID都是不一样的,这样就造成了一下的问题:当用户在身份认证注册阶段注册了指定的手指之后,后续在用户终端重新删除了这个用户终端的指纹,后续再使用同样的手指重新录入到用户终端后,就无法再使用同样的手指来完成身份认证了,这将影响身份认证流程的整个流程,造成身份认证的这个指纹无法注销问题,让身份认证后台不断堆积用户指纹绑定垃圾数据。
发明内容
鉴于上述问题,本发明旨在提出一种能够解决相同的生物特征在删除并重新录入后无法使用的问题的基于生物特征ID链的验证方法以及基于生物特征ID链的验证系统。
本发明一方面的基于生物特征ID链的验证方法,其特征在于,包括:
获取步骤,用户终端获取待验证的生物特征;
比对步骤,用户终端将所述待验证的生物特征与旧生物特征模板区中的生物特征模板进行比对以及将所述待验证的生物特征与当前生物特征模板区中的生物特征模板进行比对,以匹配到至少两个生物特征ID;
ID链生成步骤,用户终端基于所述至少两个生物特征ID生成生物特征ID链;以及
发送步骤,用户终端将用户ID、设备ID以及所述生物特征ID链发送到后台;以及
验证步骤,后台基于接收到的用户ID、设备ID以及所述生物特征ID链和预先存储的绑定关系进行身份验证。
可选地,在所述验证步骤中,后台预先存储有第一生物特征ID与用户ID、设备ID之间的绑定关系,后台验证所述绑定关系中存储的第一生物特征ID是否包含在所述生物特征ID链中,若在,身份验证成功。
可选地,在所述获取步骤之前进一步包括:
认证注册步骤,用户终端获取第一生物特征,基于第一生物特征生成对应的生物特征模板和第一生物特征ID,将第一生物特征的生物特征模板和第一生物特征ID存储到当前生物特征模板区,将第一生物特征的第一生物特征ID、用户ID、设备ID发送到后台;
预先存储步骤,后台接收第一生物特征的第一生物特征ID、用户ID、设备ID,建立并存储第一生物特征ID与用户ID、设备ID之间的绑定关系;以及
删除步骤,用户终端获取删除第一生物特征的指示,将第一生物特征的生物特征模板和第一生物特征ID从当前生物特征模板区删除并存储到旧生物特征模板区。
可选地,在所述删除步骤之后以及所述获取步骤之前进一步包括:
重新录入步骤,用户终端获取第二生物特征,基于第二生物特征生成对应的生物 特征模板和第二生物特征ID,将第二生物特征的生物特征模板和第二生物特征ID存储到当前生物特征模板区,其中,所述第二生物特征与所述第一生物特征相同。
可选地,在所述验证步骤中,在身份验证成功的情况下,将所述绑定关系中的所述第一生物特征ID更新为第二生物特征ID。
可选地,在所述认证注册步骤中,将公钥与第一生物特征的第一生物特征ID、用户ID、设备ID一起发送到后台,
在所述预先存储步骤中,后台接收第一生物特征的第一生物特征ID、用户ID、设备ID以及公钥,建立并存储第一生物特征ID与用户ID、设备ID以及公钥之间的绑定关系。
可选地,所述第一生物特征和所述第二生物特征为以下任意一种:指纹、虹膜、人脸、指静脉、掌静脉以及掌纹。
本发明一方面的基于生物特征ID链的验证方法,其特征在于,包括:
获取步骤,获取待验证的生物特征;
比对步骤,将所述待验证的生物特征与旧生物特征模板区中的生物特征模板进行比对以及将所述待验证的生物特征与当前生物特征模板区中的生物特征模板进行比对,以匹配到至少两个生物特征ID;
ID链生成步骤,基于所述至少两个生物特征ID生成生物特征ID链;以及发送步骤,将用户ID、设备ID以及所述生物特征ID链发送到后台以进行身份验证。
可选地,所述身份验证包括:后台存储有第一生物特征ID与用户ID、设备ID之间的绑定关系,
后台验证所述绑定关系中存储的第一生物特征ID是否包含在所述生物特征ID链中,若在,身份验证成功。
可选地,在所述获取步骤之前进一步包括:
认证注册步骤,获取第一生物特征,基于第一生物特征生成对应的生物特征模板和第一生物特征ID,将第一生物特征的生物特征模板和第一生物特征ID存储到当前生物特征模板区,将第一生物特征的第一生物特征ID、用户ID、设备ID发送到后台以建立第一生物特征ID与用户ID、设备ID之间的绑定关系;以及删除步骤,获取删除第一生物特征的指示,将第一生物特征的生物特征模板和第 一生物特征ID从当前生物特征模板区删除并存储到旧生物特征模板区。
可选地,在所述删除步骤之后以及所述获取步骤之前进一步包括:
重新录入步骤,获取第二生物特征,基于第二生物特征生成对应的生物特征模板和第二生物特征ID,将第二生物特征的生物特征模板和第二生物特征ID存储到当前生物特征模板区,其中,所述第二生物特征与所述第一生物特征相同。
可选地,在身份验证成功的情况下,将所述绑定关系中的所述第一生物特征ID更新为第二生物特征ID。
可选地,在所述认证注册步骤中,将公钥与第一生物特征的第一生物特征ID、用户ID、设备ID一起发送到后台。
可选地,所述当前生物特征模板区为在获取第一生物特征的情况下,存储基于第一生物特征生成对应的生物特征模板和第一生物特征ID,并且在获取删除第一生物特征的指示的情况下,第一生物特征的生物特征模板和第一生物特征ID从当前生物特征模板区被删除,并且另一方面,所述当前生物特征模板区在获取第二生物特征的情况下,存储基于第二生物特征生成对应的生物特征模板和第二生物特征ID,
所述旧生物特征模板区为在获取删除第一生物特征的指示的情况下,存储从当前生物特征模板区删除的第一生物特征的生物特征模板和第一生物特征ID。
可选地,所述第一生物特征和所述第二生物特征为以下任意一种:指纹、虹膜、人脸、指静脉、掌静脉以及掌纹。
本发明的一方面的基于生物特征ID链的验证系统,其特征在于,包括后台和用户终端,
其中,所述用户终端包括:
生物特征模块,用于采集第一生物特征和第二生物特征,并且分别生成与第一生物特征对应的生物特征模板和第一生物特征ID、与第二生物特征对应的生物特征模板和第二生物特征ID,以及用于采集待验证的生物特征,另一方面,用于基于待验证的生物特征匹配到至少两个生物特征ID并基于所述至少两个生物特征ID生成物特征ID链,其中,所述第一生物特征的第一生物特征ID和第二物特征的第二生物特征ID分别随机生成;以及
身份验证模块,用于与所述后台进行数据交互以及调用所述生物特征模块以实现 身份验证,
所述后台包括:
存储模块,用于接收所述用户终端发送的第一生物特征ID与用户ID、设备ID,建立并存储第一生物特征ID与用户ID、设备ID之间的绑定关系;以及
验证模块,用于基于从所述用户终端接收的生物特征ID链、用户ID以及设备ID、以及所述存储模块存储的所述绑定关系进行身份验证。
可选地,所述身份验证模块用于将第一生物特征ID、用户ID、设备ID发送到后台并且用于将用户ID、设备ID和生物特征ID链发送到后台。
可选地,所述用户终端进一步包括:
身份认证模块,用于生成公钥并采用公钥对数据进行签名。
可选地,所述身份验证模块用于将第一生物特征ID、公钥、用户ID、设备ID发送到后台并且用于将用户ID、设备ID和生物特征ID链发送到后台。
可选地,所述生物特征模块包括:
采集模块,用于采集第一生物特征并生成与第一生物特征对应的生物特征模板和第一生物特征ID以及采集第二生物特征并生成与第二生物特征对应的生物特征模板和第二生物特征ID,并且用于采集待验证的生物特征;
当前生物特征模板区,用于存储所述采集模块采集的第一生物特征或第二生物特征的生物特征模板和生物特征ID;
删除模块,用于根据删除指令删除所述当前生物特征模块区存储的生物特征的生物特征模板和生物特征ID;
旧生物特征模板区,用于存储所述删除模块删除的生物特征的生物特征模板和生物特征ID;
比对模块,用于将待验证的生物特征与所述旧生物特征模板区中的生物特征模板进行比对以及将待验证的生物特征与所述当前生物特征模板区中的生物特征模板进行比对,分别匹配到至少两个生物特征ID;以及
链生成模块,用于根据至少两个生物特征ID生成生物特征ID链。
可选地,所述验证模块在从所述用户终端接收所述生物特征ID链、用户ID以及设备ID的情况下,验证所述绑定关系中存储的第一生物特征ID是否包含于所述生物特征ID链中,若在,身份验证成功。
可选地,在身份验证成功的情况下,所述验证模块将所述存储模块中存储的所述绑定关系中的所述第一生物特征ID更新为第二生物特征ID。
可选地,所述第一生物特征和所述第二生物特征为以下任意一种:指纹、虹膜、人脸、指静脉、掌静脉以及掌纹。
本发明一方面的用户终端,其特征在于,包括:
生物特征模块,用于采集第一生物特征和第二生物特征并且分别生成与第一生物特征对应的生物特征模板和第一生物特征ID、与第二生物特征对应的生物特征模板和第二生物特征ID,以及用于采集待验证的生物特征,另一方面,用于基于待验证的生物特征匹配到至少两个生物特征ID并基于两个生物特征ID生成物特征ID链,其中,所述第一生物特征的第一生物特征ID和第二物特征的第二生物特征ID随机生成;以及
身份验证模块,用于将第一生物特征ID、用户ID、设备ID发送到后台以建立第一生物特征ID与用户ID、设备ID之间的绑定关系,另一方面,用于将用户ID、设备ID和生物特征ID链发送到后台以实现基于所述绑定关系和所述生物特征ID链进行的身份验证。
可选地,所述生物特征模块包括:
采集模块,用于采集第一生物特征并生成与第一生物特征对应的生物特征模板和第一生物特征ID以及采集第二生物特征并生成与第二生物特征对应的生物特征模板和第二生物特征ID,并且用于采集待验证的生物特征;
当前生物特征模板区,用于存储所述采集模块采集的第一生物特征或第二生物特征的生物特征模板和生物特征ID;
删除模块,用于根据删除指令删除所述当前生物特征模块区存储的生物特征的生物特征模板和生物特征ID;
旧生物特征模板区,用于存储所述删除模块删除的生物特征的生物特征模板和生物特征ID;
比对模块,用于将待验证的生物特征与所述旧生物特征模板区中的生物特征模板进行比对以及将待验证的生物特征与所述当前生物特征模板区中的生物特征模板比对,以匹配到至少两个生物特征ID;以及
链生成模块,用于根据所述两个生物特征ID生成生物特征ID链。
可选地,进一步包括:身份认证模块,用于生成公钥并采用公钥对数据进行签名。
本发明一方面的计算机可读介质,其上存储有计算机程序,其特征在于,该计算机程序被处理器执行时实现所述的基于生物特征ID链的验证方法。
本发明一方面的计算机设备,包括存储模块、处理器以及存储在存储模块上并可在处理器上运行的计算机程序,其特征在于,所述处理器执行所述计算机程序时实现所述的基于生物特征ID链的验证方法。
附图说明
图1是本发明一方面的基于生物特征ID链的验证方法的流程示意图。
图2是本发明一方面的基于生物特征ID链的验证系统的结构框图。
图3表示基于指纹ID链的验证方法的一个实施方式的流程示意图。
图4表示基于指纹ID链的验证系统的一个实施方式的结构框图。
具体实施方式
下面介绍的是本发明的多个实施例中的一些,旨在提供对本发明的基本了解。并不旨在确认本发明的关键或决定性的要素或限定所要保护的范围。
出于简洁和说明性目的,本文主要参考其示范实施例来描述本发明的原理。但是,本领域技术人员将容易地认识到,相同的原理可等效地应用于所有类型的基于生物特征ID链的验证方法以及基于生物特征ID链的验证系统,并且可以在其中实施这些相同的原理,以及任何此类变化不背离本专利申请的真实精神和范围。
而且,在下文描述中,参考了附图,这些附图图示特定的示范实施例。在不背离本发明的精神和范围的前提下可以对这些实施例进行电、机械、逻辑和结构上的更改。此外,虽然本发明的特征是结合若干实施/实施例的仅其中之一来公开的,但是如针对任何给定或可识别的功能可能是期望和/或有利的,可以将此特征与其他实施/实施例的一个或多个其他特征进行组合。因此,下文描述不应视为在限制意义上的,并且本发明的范围由所附权利要求及其等效物来定义。
诸如“具备”和“包括”之类的用语表示除了具有在说明书和权利要求书中有直接和明确表述的单元(模块)和步骤以外,本发明的技术方案也不排除具有未被直接或明确表述的其它单元(模块)和步骤的情形。
本发明的构思在于,在同一用户终端上获取同一生物特征的历史生物特征ID信息,并在身份认证时,通过上送生物特征ID链给后台,后台根据生物特征ID来查询并认定是否用户当前所属的生物特征与之前身份认证注册阶段的生物特征属于同一生物特征,从而判断匹配关系,来完成身份验证。
图1是本发明一方面的基于生物特征ID链的验证方法的流程示意图。
如图1所示,本发明一方面的基于生物特征ID链的验证方法主要包括以下步骤:
认证注册步骤S100:在注册时,用户终端获取第一生物特征,基于第一生物特征生成对应的第一生物特征模板和第一生物特征ID,将第一生物特征模板和第一生物特征ID放入当前生物特征模板区,用户终端将第一生物特征ID与用户ID、设备ID发送到后台;
预先存储步骤S200:后台从用户终端接收第一生物特征ID与用户ID、设备ID,建立并存储第一生物特征ID与用户ID、设备ID之间的绑定关系;
删除步骤S300:用户终端获取删除第一生物特征的指示,将第一生物特征的生物特征模块和第一生物特征ID从当前生物特征模板区删除并存放到旧生物特征模板区;
重新录入步骤S400:用户终端获取第二生物特征,基于第二生物特征生成对应的生物特征模板和第二生物特征ID,将第二生物特征的生物特征模板和第二生物特征ID存储到当前生物特征模板区,其中,所述第二生物特征与所述第一生物特征相同,例如同一个手指的指纹;
获取步骤S500:用户终端获取待验证的生物特征;
比对步骤S600:用户终端将所述待验证的生物特征与旧生物特征模板区中的生物特征模板进行比对以及将所述待验证的生物特征与当前生物特征模板区中的生物特征模板进行比对,以匹配到至少两个生物特征ID;
ID链生成步骤S700:用户终端基于所述至少两个生物特征ID生成生物特征ID链;
发送步骤S800:用户终端将用户ID、设备ID以及所述生物特征ID链发送到后台;以及
验证步骤S900:后台基于接收到的用户ID、设备ID以及所述生物特征ID链和 预先存储的绑定关系进行身份验证。
其中,在所述验证步骤S900中,后台验证所述绑定关系中存储的第一生物特征ID是否包含在所述生物特征ID链中,若在,身份验证成功。而且,在验证步骤200中,在身份验证成功的情况下,将所述绑定关系中的所述第一生物特征ID更新为第二生物特征ID。
优选地,在所述认证注册步骤S100中,将公钥与第一生物特征的第一生物特征ID、用户ID、设备ID一起发送到后台。
图2是本发明一方面的基于生物特征ID链的验证系统的结构框图。
如图2所示,本发明一方面的基于生物特征ID链的验证系统包括用户终端100和后台200。
用户终端100包括:
生物特征模块110,用于采集第一生物特征和第二生物特征,并且分别生成与第一生物特征对应的生物特征模板和第一生物特征ID、与第二生物特征对应的生物特征模板和第二生物特征ID,以及用于采集待验证的生物特征,另一方面,用于基于集待验证的生物特征的生物特征模板匹配到至少两个生物特征ID并基于所述至少两个生物特征ID生成物特征ID链,其中,所述第一生物特征的第一生物特征ID和第二物特征的第二生物特征ID分别随机生成;以及
身份认证模块120;用于生成公钥并采用公钥对数据进行签名;
身份验证模块130,用于与后台200进行数据交互以及调用生物特征模块110以及身份认证模块120实现身份验证,
其中,生物特征模块110包括:
采集模块111,用于采集第一生物特征并生成与第一生物特征对应的生物特征模板和第一生物特征ID以及采集第二生物特征并生成与第二生物特征对应的生物特征模板和第二生物特征ID,并且用于采集待验证的生物特征;
当前生物特征模板区112,用于存储采集模块采集111采集的第一生物特征或第二生物特征的生物特征模板和生物特征ID;
删除模块113,用于根据删除指令删除当前生物特征模块区112存储的生物特征的生物特征模板和生物特征ID;
旧生物特征模板区114,用于存储删除模块113删除的生物特征的生物特征模板 和生物特征ID;
比对模块115,用于将待验证的生物特征分别与所述旧生物特征模板区中的生物特征模板以及所述当前生物特征模板区中的生物特征模板进行匹配分别获得至少两个生物特征ID;以及
链生成模块116,用于根据至少两个生物特征ID生成生物特征ID链。
其中,身份验证模块130用于将第一生物特征ID、用户ID、设备ID发送到后台200并且用于将用户ID、设备ID和生物特征ID链发送到后台200。
进一步,身份验证模块130用于将第一生物特征ID、公钥、用户ID、设备ID发送到后台并且用于将用户ID、设备ID和生物特征ID链发送到后台200。
其中,后台200包括:
存储模块210,用于接收所述用户终端发送的第一生物特征ID与用户ID、设备ID,建立并存储第一生物特征ID与用户ID、设备ID之间的绑定关系;以及验证模块220,用于基于从所述用户终端接收的生物特征ID链、用户ID以及设备ID、以及所述存储模块存储的所述绑定关系进行身份验证。
验证模块220在从所述用户终端100接收所述生物特征ID链、用户ID以及设备ID的情况下,验证所述绑定关系中存储的第一生物特征ID是否包含于所述生物特征ID链中,若在,身份验证成功。优选地,在身份验证成功的情况下,验证模块220将存储模块210中存储的上述绑定关系中的所述第一生物特征ID更新为第二生物特征ID。
这里作为生物特征可以采用指纹、虹膜、人脸、指静脉、掌静脉以及掌纹等。以下为了便于说明,以指纹为例进行具体实施方式的说明。
图3表示基于指纹ID链的验证方法的一个实施方式的流程示意图。
该实施方式的基于指纹ID链的验证方法主要包括认证注册阶段以及身份验证阶段(其中,身份验证阶段描述了用户同一手指指纹删除后再录入的情况)。
如图3所示,认证注册阶段主要包括:
S1:用户开始身份认证注册,用户点击身份认证注册,输入用户ID,录入指纹;
S2:用户终端根据录入的指纹生成旧指纹模板和旧指纹ID(对应于权利要求书中的“第一生物特征模板和第一生物特征ID”),并且放入当前指纹模板区;
S3:用户终端生成公私钥;
S4:用户终端将公钥、设备ID、用户ID、旧指纹ID数据签名后上送后台;
S5:后台用收到的公钥验签,保存设备ID、用户ID与公钥、旧指纹ID的绑定关系。
接着,身份验证阶段包括:
(1)删除指纹并重新录入指纹:
S6:用户在用户终端上点击删除指纹(即发出删除指纹的指令);
S7:用户终端将删除的旧指纹的旧指纹模板和旧指纹ID放入旧指纹模板区;
S8:用户重新在用户终端上录入相同手指的指纹;
S9:用户终端对于录入的新指纹生成新指纹模板和新指纹ID(对应于权利要求书中的“第二生物特征模板和第二生物特征ID”)并且放入当前指纹模板区;
(2)重新录入指纹后发起验证:
S10:用户输入待验证指纹;
S11:用户终端在当前指纹模板区匹配待验证指纹获得新指纹ID;
S12:用户终端在旧指纹模板区匹配待验证指纹获得旧指纹ID;
S13:用户终端将新指纹ID和旧指纹ID形成指纹ID链;
S14:用户终端将指纹ID链、设备ID、用户ID用户私钥签名后发送给后台;
S15:后台使用公钥验签;以及
S16:后台查询绑定关系中的指纹ID是否存在于接收到的指纹ID链中,若判断结果为存在则验证成功,否则验证失败。
图4表示基于指纹ID链的验证系统的一个实施方式的结构框图。
如图4所示,该实施方式的基于指纹ID链的验证系统包括:用户终端500和后台600。
其中,用户终端500包括:
指纹认证模块510,用于采集新、旧指纹并且生成与新、旧指纹对应的新、旧指纹模板和新、旧指纹ID,并且基于旧指纹ID和新指纹ID生成指纹ID链;以及身份认证模块520,用于生成公私钥以及采用公钥对新、旧指纹ID以及指纹ID链进行加密;以及
身份验证模块530,用于与后台进行数据交互以及调用指纹认证模块510和身份认证模块520。
所述后台600包括:
存储模块610,用于建立并存储旧指纹ID与用户ID、设备ID之间的绑定关系;以及
验证模块620,用于基于从所述用户终端接收的指纹ID链、用户ID以及设备ID、以及所述存储模块610存储的所述绑定关系进行身份验证。
在用户终端500中,身份验证模块530可以设置REE环境中,指纹认证模块510和身份认证模块520设置在TEE环境中。
其中,验证模块620在从用户终端400接收生物特征ID链、用户ID以及设备ID的情况下,验证绑定关系中存储的旧生物特征ID是否包含于生物特征ID链中,若在,身份验证成功。优选地,在身份验证成功的情况下,验证模块620将存储模块210中存储的上述绑定关系中的旧第一生物特征ID更新为新生物特征ID。
在本实施方式中,作为一个示例,指纹认证模块510包括:
采集模块511,用于采集旧指纹并生成与旧指纹对应的指纹模板和旧指纹ID以及采集新指纹并生成与新指纹对应的新指纹模板和新指纹ID,并且用于采集待验证的指纹;
当前指纹模板区512,用于存储采集模块采集111采集的旧指纹或新指纹的指纹模板和指纹ID;
删除模块513,用于根据删除指令删除当前指纹模块区112存储的指纹的指纹模板和指纹ID;
旧指纹模板区514,用于存储删除模块113删除的指纹的指纹模板和指纹ID;比对模块515,用于将待验证的指纹分别与所述旧指纹模板区中的指纹模板以及所述当前指纹模板区中的指纹模板进行匹配分别获得至少两个指纹ID;以及链生成模块516,用于根据至少两个指纹ID生成指纹ID链。
本发明的基于生物特征ID链的验证方法以及基于生物特征ID链的验证系统提出了构成生物特征ID链的技术构思,并且提出了利用基于同一生物特征的生物特征ID链来进行身份验证的技术构思。基于同一生物特征的生物特征ID链的能力,包含同一生物特征在同一用户终端上的历史生物特征ID,以提供给后台基于生物特征ID链查询同一用户终端的生物特征ID历史记录,从而完成指定生 物特征的匹配。
如上所述,在本发明中,通过在用户终端本地重新录入生物特征时,生成一个包含统一用户终端的生物特征历史的生物特征ID链,在认证注册阶段与身份验证阶段,通过将生物特征ID链发送后台,后台通过设备ID、用户ID与生物特征ID链进行匹配,能够解决用户在同一用户终端的生物特征在删除重新录入后无法使用的问题。
一种计算机设备,包括:存储器;处理器;以及存储在所述存储器上并可在所述处理器上运行的计算机程序,其中,该计算机程序的运行使得所述处理器执行所述计算机程序时实现上述的基于生物特征ID链的验证方法。
以上例子主要说明了本发明的基于生物特征ID链的验证方法以及基于生物特征ID链的验证系统。尽管只对其中一些本发明的具体实施方式进行了描述,但是本领域普通技术人员应当了解,本发明可以在不偏离其主旨与范围内以许多其他的形式实施。因此,所展示的例子与实施方式被视为示意性的而非限制性的,在不脱离如所附各权利要求所定义的本发明精神及范围的情况下,本发明可能涵盖各种的修改与替换。

Claims (28)

  1. 一种基于生物特征ID链的验证方法,其特征在于,包括:
    获取步骤,用户终端获取待验证的生物特征;
    比对步骤,用户终端将所述待验证的生物特征与旧生物特征模板区中的生物特征模板进行比对以及将所述待验证的生物特征与当前生物特征模板区中的生物特征模板进行比对,以匹配到至少两个生物特征ID;
    ID链生成步骤,用户终端基于所述至少两个生物特征ID生成生物特征ID链;以及
    发送步骤,用户终端将用户ID、设备ID以及所述生物特征ID链发送到后台;以及
    验证步骤,后台基于接收到的用户ID、设备ID以及所述生物特征ID链和预先存储的绑定关系进行身份验证。
  2. 如权利要求8所述的基于生物特征ID链的验证方法,其特征在于,
    在所述验证步骤中,后台预先存储有第一生物特征ID与用户ID、设备ID之间的绑定关系,后台验证所述绑定关系中存储的第一生物特征ID是否包含在所述生物特征ID链中,若在,身份验证成功。
  3. 如权利要求1所述的基于生物特征ID链的验证方法,其特征在于,在所述获取步骤之前进一步包括:
    认证注册步骤,用户终端获取第一生物特征,基于第一生物特征生成对应的生物特征模板和第一生物特征ID,将第一生物特征的生物特征模板和第一生物特征ID存储到当前生物特征模板区,将第一生物特征的第一生物特征ID、用户ID、设备ID发送到后台;
    预先存储步骤,后台接收第一生物特征的第一生物特征ID、用户ID、设备ID,建立并存储第一生物特征ID与用户ID、设备ID之间的绑定关系;以及
    删除步骤,用户终端获取删除第一生物特征的指示,将第一生物特征的生物特征模板和第一生物特征ID从当前生物特征模板区删除并存储到旧生物特征模板区。
  4. 如权利要求3所述的基于生物特征ID链的验证方法,其特征在于,在所述删除步骤之后以及所述获取步骤之前进一步包括:
    重新录入步骤,用户终端获取第二生物特征,基于第二生物特征生成对应的生物特征模板和第二生物特征ID,将第二生物特征的生物特征模板和第二生物特征ID存储到当前生物特征模板区,其中,所述第二生物特征与所述第一生物特征相同。
  5. 如权利要求4所述的基于生物特征ID链的验证方法,其特征在于,
    在所述验证步骤中,在身份验证成功的情况下,将所述绑定关系中的所述第一生物特征ID更新为第二生物特征ID。
  6. 如权利要求3所述的基于生物特征ID链的验证方法,其特征在于,
    在所述认证注册步骤中,将公钥与第一生物特征的第一生物特征ID、用户ID、以及设备ID一起发送到后台,
    在所述预先存储步骤中,后台接收第一生物特征的第一生物特征ID、用户ID、设备ID以及公钥,建立并存储第一生物特征ID与用户ID、设备ID以及公钥之间的绑定关系。
  7. 如权利要求1~6任意一项所述的基于生物特征ID链的验证方法,其特征在于,
    所述第一生物特征和所述第二生物特征为以下任意一种:指纹、虹膜、人脸、指静脉、掌静脉以及掌纹。
  8. 一种基于生物特征ID链的验证方法,其特征在于,包括:
    获取步骤,获取待验证的生物特征;
    比对步骤,将所述待验证的生物特征与旧生物特征模板区中的生物特征模板进行比对以及将所述待验证的生物特征与当前生物特征模板区中的生物特征模板进行比对,以匹配到至少两个生物特征ID;
    ID链生成步骤,基于所述至少两个生物特征ID生成生物特征ID链;以及
    发送步骤,将用户ID、设备ID以及所述生物特征ID链发送到后台以进行身份验证。
  9. 如权利要求8所述的基于生物特征ID链的验证方法,其特征在于,
    所述身份验证包括:后台存储有第一生物特征ID与用户ID、设备ID之间的绑定关系,
    后台验证所述绑定关系中存储的第一生物特征ID是否包含在所述生物特征ID链中,若在,身份验证成功。
  10. 如权利要求8所述的基于生物特征ID链的验证方法,其特征在于,在所述获取步骤之前进一步包括:
    认证注册步骤,获取第一生物特征,基于第一生物特征生成对应的生物特征模板和第一生物特征ID,将第一生物特征的生物特征模板和第一生物特征ID存储到当前生物特征模板区,将第一生物特征的第一生物特征ID、用户ID以及设备ID发送到后台以建立第一生物特征ID与用户ID、设备ID之间的绑定关系;以及
    删除步骤,获取删除第一生物特征的指示,将第一生物特征的生物特征模板和第一生物特征ID从当前生物特征模板区删除并存储到旧生物特征模板区。
  11. 如权利要求10所述的基于生物特征ID链的验证方法,其特征在于,在所述删除步骤之后以及所述获取步骤之前进一步包括:
    重新录入步骤,获取第二生物特征,基于第二生物特征生成对应的生物特征模板和第二生物特征ID,将第二生物特征的生物特征模板和第二生物特征ID存储到当前生物特征模板区,其中,所述第二生物特征与所述第一生物特征相同。
  12. 如权利要求8所述的基于生物特征ID链的验证方法,其特征在于,
    在身份验证成功的情况下,将所述绑定关系中的所述第一生物特征ID更新为第二生物特征ID。
  13. 如权利要求10所述的基于生物特征ID链的验证方法,其特征在于,
    在所述认证注册步骤中,将公钥与第一生物特征的第一生物特征ID、用户ID、设备ID一起发送到后台。
  14. 如权利要求8所述的基于生物特征ID链的验证方法,其特征在于,
    所述当前生物特征模板区为在获取第一生物特征的情况下,存储基于第一生物特征生成对应的生物特征模板和第一生物特征ID,并且在获取删除第一生物特征的指示的情况下,第一生物特征的生物特征模板和第一生物特征ID从当前生物特征模板区被删除,并且另一方面,所述当前生物特征模板区在获取第二生物特征的情况下,存储基于第二生物特征生成对应的生物特征模板和第二生物特征ID,
    所述旧生物特征模板区为在获取删除第一生物特征的指示的情况下,存储从当前生物特征模板区删除的第一生物特征的生物特征模板和第一生物特征ID。
  15. 如权利要求8~14任意一项所述的基于生物特征ID链的验证方法,其特征在于,
    所述第一生物特征和所述第二生物特征为以下任意一种:指纹、虹膜、人脸、指静脉、掌静脉以及掌纹。
  16. 一种基于生物特征ID链的验证系统,其特征在于,包括后台和用户终端,
    其中,所述用户终端包括:
    生物特征模块,用于采集第一生物特征和第二生物特征,并且分别生成与第一生物特征对应的生物特征模板和第一生物特征ID、与第二生物特征对应的生物特征模板和第二生物特征ID,以及用于采集待验证的生物特征,另一方面,用于基于待验证的生物特征匹配到至少两个生物特征ID并基于所述至少两个生物特征ID生成物特征ID链,其中,所述第一生物特征的第一生物特征ID和第二物特征的第二生物特征ID分别随机生成;以及
    身份验证模块,用于与所述后台进行数据交互以及调用所述生物特征模块以实现身份验证,
    所述后台包括:
    存储模块,用于接收所述用户终端发送的第一生物特征ID与用户ID、设备ID,建立并存储第一生物特征ID与用户ID、设备ID之间的绑定关系;以及
    验证模块,用于基于从所述用户终端接收的生物特征ID链、用户ID以及设备ID、以及所述存储模块存储的所述绑定关系进行身份验证。
  17. 如权利要求16所述的基于生物特征ID链的验证系统,其特征在于,
    所述身份验证模块用于将第一生物特征ID、用户ID以及设备ID发送到后台并且用于将用户ID、设备ID以及生物特征ID链发送到后台。
  18. 如权利要求16所述的基于生物特征ID链的验证系统,其特征在于,
    所述用户终端进一步包括:
    身份认证模块,用于生成公钥并采用公钥对数据进行签名。
  19. 如权利要求18所述的基于生物特征ID链的验证系统,其特征在于,
    所述身份验证模块用于将第一生物特征ID、公钥、用户ID以及设备ID发送 到后台并且用于将用户ID、设备ID以及生物特征ID链发送到后台。
  20. 如权利要求11所述的基于生物特征ID链的验证系统,其特征在于,所述生物特征模块包括:
    采集模块,用于采集第一生物特征并生成与第一生物特征对应的生物特征模板和第一生物特征ID以及采集第二生物特征并生成与第二生物特征对应的生物特征模板和第二生物特征ID,并且用于采集待验证的生物特征;
    当前生物特征模板区,用于存储所述采集模块采集的第一生物特征或第二生物特征的生物特征模板和生物特征ID;
    删除模块,用于根据删除指令删除所述当前生物特征模块区存储的生物特征的生物特征模板和生物特征ID;
    旧生物特征模板区,用于存储所述删除模块删除的生物特征的生物特征模板和生物特征ID;
    比对模块,用于将待验证的生物特征与所述旧生物特征模板区中的生物特征模板进行比对以及将待验证的生物特征与所述当前生物特征模板区中的生物特征模板进行比对,分别匹配到至少两个生物特征ID;以及
    链生成模块,用于根据至少两个生物特征ID生成生物特征ID链。
  21. 如权利要求20所述的基于生物特征ID链的验证系统,其特征在于,
    所述验证模块在从所述用户终端接收所述生物特征ID链、用户ID以及设备ID的情况下,验证所述绑定关系中存储的第一生物特征ID是否包含于所述生物特征ID链中,若在,身份验证成功。
  22. 如权利要求21所述的基于生物特征ID链的验证系统,其特征在于,
    在身份验证成功的情况下,所述验证模块将所述存储模块中存储的所述绑定关系中的所述第一生物特征ID更新为第二生物特征ID。
  23. 如权利要求16~22任意一项所述的基于生物特征ID链的验证系统,其特征在于,
    所述第一生物特征和所述第二生物特征为以下任意一种:指纹、虹膜、人脸、指静脉、掌静脉以及掌纹。
  24. 一种用户终端,其特征在于,包括:
    生物特征模块,用于采集第一生物特征和第二生物特征并且分别生成与第一 生物特征对应的生物特征模板和第一生物特征ID、与第二生物特征对应的生物特征模板和第二生物特征ID,以及用于采集待验证的生物特征,另一方面,用于基于待验证的生物特征匹配到至少两个生物特征ID并基于两个生物特征ID生成物特征ID链,其中,所述第一生物特征的第一生物特征ID和第二物特征的第二生物特征ID随机生成;以及
    身份验证模块,用于将第一生物特征ID、用户ID以及设备ID发送到后台以建立第一生物特征ID与用户ID、设备ID之间的绑定关系,另一方面,用于将用户ID、设备ID和生物特征ID链发送到后台以实现基于所述绑定关系和所述生物特征ID链进行的身份验证。
  25. 如权利要求24所述的用户终端,其特征在于,所述生物特征模块包括:
    采集模块,用于采集第一生物特征并生成与第一生物特征对应的生物特征模板和第一生物特征ID以及采集第二生物特征并生成与第二生物特征对应的生物特征模板和第二生物特征ID,并且用于采集待验证的生物特征;
    当前生物特征模板区,用于存储所述采集模块采集的第一生物特征或第二生物特征的生物特征模板和生物特征ID;
    删除模块,用于根据删除指令删除所述当前生物特征模块区存储的生物特征的生物特征模板和生物特征ID;
    旧生物特征模板区,用于存储所述删除模块删除的生物特征的生物特征模板和生物特征ID;
    比对模块,用于将待验证的生物特征与所述旧生物特征模板区中的生物特征模板进行比对以及将待验证的生物特征与所述当前生物特征模板区中的生物特征模板比对,以匹配到至少两个生物特征ID;以及
    链生成模块,用于根据所述两个生物特征ID生成生物特征ID链。
  26. 如权利要求25所述的用户终端,其特征在于,进一步包括:
    身份认证模块,用于生成公钥并采用公钥对数据进行签名。
  27. 一种计算机可读介质,其上存储有计算机程序,其特征在于,
    该计算机程序被处理器执行时实现权利要求1~7或者8~15任意一项所述的基于生物特征ID链的验证方法。
  28. 一种计算机设备,包括:
    存储器;
    处理器;以及
    存储在所述存储器上并可在所述处理器上运行的计算机程序,
    其中,该计算机程序的运行使得所述处理器执行所述计算机程序时实现权利要求1~7或者8~15任意一项所述的基于生物特征ID链的验证方法。
PCT/CN2021/117470 2021-02-05 2021-09-09 基于生物特征id链的验证方法及其验证系统、用户终端 Ceased WO2022166198A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
JP2022576855A JP7489494B2 (ja) 2021-02-05 2021-09-09 生体特徴idチェーンに基づく検証方法及び検証システム、ユーザ端末
US18/257,281 US12093360B2 (en) 2021-02-05 2021-09-09 Verification method and verification system based on biometric feature ID chain, and user terminal

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202110160183.3 2021-02-05
CN202110160183.3A CN113297552B (zh) 2021-02-05 2021-02-05 基于生物特征id链的验证方法及其验证系统、用户终端

Publications (1)

Publication Number Publication Date
WO2022166198A1 true WO2022166198A1 (zh) 2022-08-11

Family

ID=77318918

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2021/117470 Ceased WO2022166198A1 (zh) 2021-02-05 2021-09-09 基于生物特征id链的验证方法及其验证系统、用户终端

Country Status (5)

Country Link
US (1) US12093360B2 (zh)
JP (1) JP7489494B2 (zh)
CN (1) CN113297552B (zh)
TW (1) TWI802002B (zh)
WO (1) WO2022166198A1 (zh)

Families Citing this family (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2021214970A1 (ja) * 2020-04-24 2021-10-28 日本電気株式会社 情報処理装置、システム、顔画像の更新方法及び記憶媒体
CN113297552B (zh) * 2021-02-05 2023-11-17 中国银联股份有限公司 基于生物特征id链的验证方法及其验证系统、用户终端

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100009658A1 (en) * 2008-07-08 2010-01-14 Hong Fu Jin Precision Industry (Shenzhen) Co., Ltd. Method for identity authentication by mobile terminal
CN110084019A (zh) * 2019-05-10 2019-08-02 浙江臻享网络科技有限公司 采用多生物特征信息相似度比对的身份核验算法及装置
CN111639361A (zh) * 2020-05-15 2020-09-08 中国科学院信息工程研究所 一种区块链密钥管理方法、多人共同签名方法及电子装置
CN112287320A (zh) * 2020-11-02 2021-01-29 刘高峰 一种基于生物特征的身份验证方法、装置及客户端
CN113297552A (zh) * 2021-02-05 2021-08-24 中国银联股份有限公司 基于生物特征id链的验证方法及其验证系统、用户终端

Family Cites Families (22)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP2006085268A (ja) * 2004-09-14 2006-03-30 Fuji Photo Film Co Ltd 生体認証システムおよび生体認証方法
KR100718125B1 (ko) * 2005-03-25 2007-05-15 삼성전자주식회사 생체신호와 인공신경회로망을 이용한 생체인식 장치 및방법
US7979899B2 (en) * 2008-06-02 2011-07-12 Microsoft Corporation Trusted device-specific authentication
JP5805040B2 (ja) 2012-09-25 2015-11-04 ビッグローブ株式会社 人物認証用辞書更新方法、人物認証用辞書更新装置、人物認証用辞書更新プログラム及び人物認証システム
EP3090525B1 (en) * 2013-12-31 2021-06-16 Veridium IP Limited System and method for biometric protocol standards
US12130900B2 (en) * 2014-08-28 2024-10-29 Facetec, Inc. Method and apparatus to dynamically control facial illumination
CN105068974B (zh) 2015-06-30 2019-12-24 联想(北京)有限公司 一种信息处理方法及电子设备
CN106330850B (zh) * 2015-07-02 2020-01-14 创新先进技术有限公司 一种基于生物特征的安全校验方法及客户端、服务器
CN107113315B (zh) * 2016-04-15 2020-11-13 深圳前海达闼云端智能科技有限公司 一种身份认证方法、终端及服务器
CN105959287A (zh) 2016-05-20 2016-09-21 中国银联股份有限公司 一种基于生物特征的安全认证方法及装置
JP6570480B2 (ja) 2016-06-07 2019-09-04 ヤフー株式会社 生成装置、端末装置、生成方法、生成プログラム及び認証処理システム
US10142333B1 (en) * 2016-06-21 2018-11-27 Wells Fargo Bank, N.A. Biometric reference template record
EP4273820A3 (en) * 2016-08-05 2023-12-06 Assa Abloy AB Method and system for automated physical access control system using biometric recognition coupled with tag authentication
CN106651363B (zh) 2016-12-28 2020-06-02 飞天诚信科技股份有限公司 一种硬件钱包及其持有者身份验证方法
CN107077615A (zh) * 2017-01-12 2017-08-18 厦门中控生物识别信息技术有限公司 指纹防伪方法和设备
CN108288050B (zh) * 2018-02-13 2022-03-01 北京小米移动软件有限公司 更新指纹模板的方法、装置、电子设备
US10325084B1 (en) 2018-12-11 2019-06-18 block.one Systems and methods for creating a secure digital identity
CN109992680A (zh) 2018-12-13 2019-07-09 阿里巴巴集团控股有限公司 信息处理方法、装置、电子设备及计算机可读存储介质
CN110933603B (zh) * 2019-09-04 2021-08-10 中国银联股份有限公司 基于生物特征的身份认证方法及其身份认证系统
WO2021101761A1 (en) * 2019-11-21 2021-05-27 Jumio Corporation Authentication using stored authentication image data
TWM594186U (zh) 2019-12-16 2020-04-21 臺灣網路認證股份有限公司 結合線上快速認證及公鑰基礎架構以識別身分之裝置及系統
CN111414599A (zh) * 2020-02-26 2020-07-14 北京奇艺世纪科技有限公司 身份验证方法、装置、终端、服务端以及可读存储介质

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100009658A1 (en) * 2008-07-08 2010-01-14 Hong Fu Jin Precision Industry (Shenzhen) Co., Ltd. Method for identity authentication by mobile terminal
CN110084019A (zh) * 2019-05-10 2019-08-02 浙江臻享网络科技有限公司 采用多生物特征信息相似度比对的身份核验算法及装置
CN111639361A (zh) * 2020-05-15 2020-09-08 中国科学院信息工程研究所 一种区块链密钥管理方法、多人共同签名方法及电子装置
CN112287320A (zh) * 2020-11-02 2021-01-29 刘高峰 一种基于生物特征的身份验证方法、装置及客户端
CN113297552A (zh) * 2021-02-05 2021-08-24 中国银联股份有限公司 基于生物特征id链的验证方法及其验证系统、用户终端

Also Published As

Publication number Publication date
TWI802002B (zh) 2023-05-11
US20240054199A1 (en) 2024-02-15
JP2023530119A (ja) 2023-07-13
US12093360B2 (en) 2024-09-17
CN113297552A (zh) 2021-08-24
CN113297552B (zh) 2023-11-17
JP7489494B2 (ja) 2024-05-23
TW202232349A (zh) 2022-08-16

Similar Documents

Publication Publication Date Title
US12149528B2 (en) Authenticating devices via tokens and verification computing devices
JP5218991B2 (ja) 複数種類のテンプレートを用いた生体認証システム及び生体認証方法
JP6318588B2 (ja) 生体認証装置、生体認証方法及び生体認証用コンピュータプログラム
CN107800672B (zh) 一种信息验证方法、电子设备、服务器及信息验证系统
US10282532B2 (en) Secure storage of fingerprint related elements
TWI802002B (zh) 基於生物特徵id鏈的驗證方法及其驗證系統、用戶終端
CN112580010B (zh) 一种生物特征共享方法、装置、电子设备及存储介质
WO2016188230A1 (zh) 一种解锁方法及装置
CN111478875A (zh) 一种基于区块链的生物体征混合模式认证方法与系统
CN111726365A (zh) 一种在线身份认证的方法及装置
CN109379388B (zh) 一种身份识别方法、终端及可穿戴设备
US10936706B2 (en) Biometric authentication
JP2003150557A (ja) 生体認証による情報の自動入力方法,その自動入力システムおよびその自動入力用プログラム
US20240106823A1 (en) Sharing a biometric token across platforms and devices for authentication
KR20030052194A (ko) 생체정보를 이용한 사용자 인증 시스템, 상기 시스템에서인증서를 등록하는 방법 및 사용자 인증방법
CN111475793A (zh) 访问控制、用户注册、用户登录方法、装置及设备
KR20180119040A (ko) 생체 인증 정보에 기반한 인증 방법 및 장치
HK40059223A (zh) 基於生物特徵id链的验证方法及其验证系统、用户终端
HK40059223B (zh) 基於生物特徵id链的验证方法及其验证系统、用户终端
JPH10105517A (ja) 自動個人確認処理方法
JP2002366528A (ja) 個人認証におけるセキュリティ方式
JP7342504B2 (ja) 情報処理装置、システム、プロビジョニングデータを生成する方法、およびプログラム
JP2005275527A (ja) 個人認証装置、個人認証システムおよび個人認証方法
KR20060053699A (ko) 지문 인식을 통한 이동통신 단말기의 인증 방법
WO2022237546A1 (zh) 一种可变生物特征的可脱机认证方法、设备及系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 21924196

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2022576855

Country of ref document: JP

Kind code of ref document: A

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 21924196

Country of ref document: EP

Kind code of ref document: A1