WO2017152819A1 - 一种授权认证方法、装置和系统 - Google Patents
一种授权认证方法、装置和系统 Download PDFInfo
- Publication number
- WO2017152819A1 WO2017152819A1 PCT/CN2017/075745 CN2017075745W WO2017152819A1 WO 2017152819 A1 WO2017152819 A1 WO 2017152819A1 CN 2017075745 W CN2017075745 W CN 2017075745W WO 2017152819 A1 WO2017152819 A1 WO 2017152819A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- authentication
- biometric
- digital
- biometric information
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0861—Network architectures or network communication protocols for network security for authentication of entities using biometrical features, e.g. fingerprint, retina-scan
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/32—User authentication using biometric data, e.g. fingerprints, iris scans or voiceprints
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/31—User authentication
- G06F21/34—User authentication involving the use of external additional devices, e.g. dongles or smart cards
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/30—Authentication, i.e. establishing the identity or authorisation of security principals
- G06F21/45—Structures or tools for the administration of authentication
- G06F21/46—Structures or tools for the administration of authentication by designing passwords or checking the strength of passwords
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06V—IMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
- G06V40/00—Recognition of biometric, human-related or animal-related patterns in image or video data
- G06V40/10—Human or animal bodies, e.g. vehicle occupants or pedestrians; Body parts, e.g. hands
- G06V40/12—Fingerprints or palmprints
- G06V40/1365—Matching; Classification
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06V—IMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
- G06V40/00—Recognition of biometric, human-related or animal-related patterns in image or video data
- G06V40/70—Multimodal biometrics, e.g. combining information from different biometric modalities
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04B—TRANSMISSION
- H04B13/00—Transmission systems characterised by the medium used for transmission, not provided for in groups H04B3/00 - H04B11/00
- H04B13/005—Transmission systems in which the medium consists of the human body
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0853—Network architectures or network communication protocols for network security for authentication of entities using an additional device, e.g. smartcard, SIM or a different communication terminal
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/107—Network architectures or network communication protocols for network security for controlling access to devices or network resources wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/08—Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
- H04L9/0816—Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
- H04L9/0819—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
- H04L9/0825—Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using asymmetric-key encryption or public key infrastructure [PKI], e.g. key signature or public key certificates
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3226—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
- H04L9/3228—One-time or temporary data, i.e. information which is sent for every authentication or authorization, e.g. one-time-password, one-time-token or one-time-key
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3226—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using a predetermined code, e.g. password, passphrase or PIN
- H04L9/3231—Biological data, e.g. fingerprint, voice or retina
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3236—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions
- H04L9/3239—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions involving non-keyed hash functions, e.g. modification detection codes [MDCs], MD5, SHA or RIPEMD
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3236—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions
- H04L9/3242—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials using cryptographic hash functions involving keyed hash functions, e.g. message authentication codes [MACs], CBC-MAC or HMAC
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3247—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06V—IMAGE OR VIDEO RECOGNITION OR UNDERSTANDING
- G06V40/00—Recognition of biometric, human-related or animal-related patterns in image or video data
- G06V40/10—Human or animal bodies, e.g. vehicle occupants or pedestrians; Body parts, e.g. hands
- G06V40/14—Vascular patterns
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/80—Wireless
- H04L2209/805—Lightweight hardware, e.g. radio-frequency identification [RFID] or sensor
Definitions
- the present invention relates to the field of electronic technologies, and in particular, to an authorization authentication method, apparatus, and system.
- the electronic device When the user uses the electronic device to obtain authorization for certain specific places (eg, office areas, confidential areas, etc.), website login, personal items (cars, safes, etc.), dangerous goods, etc., the electronic devices are installed in these places, individuals The electronic system on the item or dangerous item establishes a communication connection, and then sends the stored key to the electronic system, which authenticates the key. It can be seen that in this prior art authorization mode, other people can use other people's electronic devices to obtain authorization, thereby performing illegal operations, resulting in loss of property, information, and the like of the user.
- the present invention is directed to solving one of the above problems.
- the main object of the present invention is to provide an authorization authentication method.
- Another object of the present invention is to provide an authorization authentication apparatus.
- An aspect of the present invention provides an authorization authentication method, including: after a biological limb enters a preset range of a first device, the first device establishes a communication connection with the second device through the biological limb; the first device Receiving, by the communication connection, the to-be-authorized information transmitted by the second device, where the to-be-authorized information includes: digital authentication information; the first time of the preset period of the biological limb entering the first device, the first The device collects biometric information of the biological limb; the first device acquires an authentication result of the digital authentication information and the biometric information authentication, and if the digital authentication information and the biometric information authentication are authenticated As a result, if the authentication is passed, the first device performs an authorization operation.
- the biometric information includes: fingerprint information and/or vein information; and the collecting, by the first device, biometric information of the biological limb includes: in a case where the biological limb is in contact with the first device, A device collects the biometric information of a contact portion of the biological limb with the first device.
- the first device acquires an authentication result package for authenticating the digital authentication information and the biometric information.
- the first device authenticates the digital authentication information and the biometric information to obtain the authentication result.
- the obtaining, by the first device, the authentication result of the digital authentication information and the biometric information includes: sending, by the first device, the biometric information and the digital authentication information to a background; the first device Receiving the authentication result sent by the background, wherein: the authentication result is an authentication result obtained by the background to authenticate the digital authentication information and the biometric information.
- the to-be-authorized information further includes: identification information; the authenticating the digital authentication information and the biometric information comprises: authenticating the digital authentication information and the biometric information according to the identification information.
- the authenticating the digital authentication information and the biometric information according to the identifier information includes: acquiring an authentication factor and biometric verification information corresponding to the identifier information, and using the authentication factor to the digital authentication information Performing digital authentication and detecting a matching rate of the biometrics verification information and the biometrics information, wherein the authenticating the authentication pass includes: digitally authenticating the digital authentication information by using the authentication factor When the matching rate between the biometric information and the biometrics verification information is greater than a preset value, the authentication result is the authentication pass.
- the digitally authenticating the digital authentication information by using the authentication factor and detecting the matching rate of the biometric verification information and the biometric information includes:
- the digital authentication information includes electronic signature information obtained by using a private key
- the authentication factor includes a public key for verifying the electronic signature information
- the digital authentication information is used by the authentication factor.
- Performing the authentication includes: performing verification of the electronic signature information by using the public key; and/or the digital authentication information includes a MAC value calculated by using a symmetric key, where the authentication factor includes calculating a symmetry of the MAC value.
- Decrypting the digital authentication information by using the authentication factor includes: calculating a MAC check value by using the symmetric key, verifying the MAC value and a MAC check value; and/or the digital authentication
- the information includes a dynamic password generated by using a seed key, the authentication factor including the seed key for verifying the dynamic password, and the authenticating the digital authentication information by using the authentication factor comprises: using the seed secret The key verifies the dynamic password.
- an authorization authentication apparatus comprising: a connection unit, configured to establish a communication connection with the identity recognition device by the biological limb after the biological limb enters a preset range of the authorization authentication device; Receiving, by the communication connection, the to-be-authorized information transmitted by the identity identification device, where the to-be-authorized information includes: digital authentication information; and an acquisition unit, in a duration of a preset range of the biological limb entering the authorized authentication device a biometric information for collecting the biological limb; an execution unit, configured to acquire an authentication result of the digital authentication information and the biometric information authentication, if the digital authentication information and the biometric information are authenticated The result of the certification is recognition If the certificate passes, the authorization operation is performed.
- the biometric information includes: fingerprint information and/or vein information; the collecting unit is configured to collect the biological limb and the authorized authentication if the biological limb is in contact with the authorized authentication device The biometric information of the contact portion of the device.
- the executing unit is specifically configured to perform authentication on the digital authentication information and the biometric information to obtain the authentication result.
- the executing unit is specifically configured to send the biometric information and the digital authentication information to the background, and receive the authentication result sent by the background, where: the authentication result is the background to the The digital authentication information and the biometric information are authenticated and the obtained authentication result.
- the to-be-authorized information further includes: identification information; the authenticating the digital authentication information and the biometric information comprises: authenticating the digital authentication information and the biometric information according to the identification information.
- the authenticating the digital authentication information and the biometric information according to the identifier information includes: acquiring an authentication factor and biometric verification information corresponding to the identifier information, and using the authentication factor to the digital authentication information Performing digital authentication and detecting a matching rate of the biometrics verification information and the biometrics information, wherein the authenticating the authentication pass includes: digitally authenticating the digital authentication information by using the authentication factor When the matching rate between the biometric information and the biometrics verification information is greater than a preset value, the authentication result is the authentication pass.
- the digitally authenticating the digital authentication information by using the authentication factor and detecting the matching rate of the biometric verification information and the biometric information comprises: authenticating the digital authentication information by using the authentication factor. And determining, when the digital authentication information is authenticated, whether a matching rate of the biometric information and the biometric verification information is greater than a preset value; or determining a matching between the biometric information and the biometric verification information Whether the rate is greater than a preset value, and when it is determined that the matching rate of the biometric information and the biometrics verification information is greater than a preset value, the digital authentication information is authenticated by using the authentication factor.
- the digital authentication information includes electronic signature information obtained by using a private key
- the authentication factor includes a public key for verifying the electronic signature information
- the digital authentication information is used by the authentication factor.
- Performing the authentication includes: performing verification of the electronic signature information by using the public key; and/or the digital authentication information includes a MAC value calculated by using a symmetric key, where the authentication factor includes calculating a symmetry of the MAC value.
- Decrypting the digital authentication information by using the authentication factor includes: calculating a MAC check value by using the symmetric key, verifying the MAC value and a MAC check value; and/or the digital authentication
- the information includes a dynamic password generated by using a seed key, the authentication factor including the seed key for verifying the dynamic password, and the authenticating the digital authentication information by using the authentication factor comprises: using the seed secret The key verifies the dynamic password.
- Still another aspect of the present invention provides an authorization authentication system, comprising: an identity recognition device and the authorization authentication device according to claims 9-16; the identity recognition device configured to authenticate the authorization through the communication connection The device sends the to-be-authorized information.
- system further includes: a background, configured to receive the biometric information and the digital authentication information sent by the authorization authentication device, and perform authentication on the digital authentication information and the biometric information to obtain an authentication result. And transmitting the authentication result to the authorized authentication device.
- a background configured to receive the biometric information and the digital authentication information sent by the authorization authentication device, and perform authentication on the digital authentication information and the biometric information to obtain an authentication result. And transmitting the authentication result to the authorized authentication device.
- the present invention provides an authorization authentication method, device and system, by which the digital authentication information of the electronic device such as a wristwatch and the biometric information of the human body can be verified and ensured.
- the authorization authentication method of the present invention the verification of the digital authentication information and the verification of the biometric information of the human body are completed in one continuous operation, once Separating twice will lead to unsuccessful verification, which will prevent others from using electronic devices such as watches to pretend to be authorized by the user to ensure the safety of information and property.
- the present invention can effectively prevent illegal molecules from using other people's electronic devices and biometric information to pass authorization by using the living body as a transmission conductor.
- various digital authentication key information that the user needs to use may be stored in an electronic device carried by the wristwatch or the like, and the electronic device automatically sends the digital authentication information to the authentication end, and the user only needs to The biometric information can be collected to complete the authorized operation, which is convenient, fast and safe.
- FIG. 1 is a flowchart of an authorization authentication method according to Embodiment 1 of the present invention.
- FIG. 2 is a schematic structural diagram of an authorization authentication apparatus according to Embodiment 1 of the present invention.
- FIG. 3 is a schematic structural diagram of an authorization authentication system according to Embodiment 1 of the present invention.
- a biological limb is used for communication, that is, a biological limb is used to incorporate both devices of communication into the body area network.
- the so-called Body Area Network (BAN) is a network element that is centered on the human body and is related to the human body (including personal terminals, distributed on the human body, on the clothes, and within a certain distance of the human body, such as within 3 to 5 meters. Even a communication network composed of sensors, networking devices, etc. inside the human body, therefore, only when the network element related to the human body enters the preset range of the communication device, the human body communication connection of the body area network can be established.
- the present invention provides an authorization authentication method, as shown in FIG. 1, including:
- Step S101 after the biological limb enters the preset range of the first device, the first device passes the biological limb and the second device A communication connection is established.
- the first device is provided with a biometric collection function and is capable of communicating with the second device through the biological limb.
- the first device can be used to manage the access or use rights of the place (office area, secret area), website login, personal items (cars, safes, etc.), dangerous goods, etc., and the first device can also be used to execute transactions.
- it can be an access control card reader, a smart car lock, a safe lock, a dangerous goods manager, a computer with a biometric function, an ATM machine, and a POS machine.
- the second device is placed outside the living body (including the human body, the animal body, etc.) (wearing in the living body or carried around the living body) or implanted in the living body, for example, the second device may be a wearable device (smart watch, smart glasses, etc.) , smart phones, sensor devices implanted in the body, etc.
- the second device and the biological limb are in a communicable range (for example, worn on the wrist or the neck)
- the second device establishes a human body communication channel with the living body, and the biological limb can be equivalent to the extended antenna of the second device, when the detecting party detects When the limb is biological, it is equivalent to detecting the second device.
- the first device When the first device communicates by using the human body channel, it has a preset communication range. When the biological limb carrying the second device enters its communication range, the first device can detect the biological limb, and the second device passes the biological device. The first device can also be detected by the extended limb antenna.
- the above first device and second device may also support other wired or wireless communication methods.
- the first device and the second device establish a body area network (BAN) through the biological limb, and establish a living communication channel by using the biological limb, thereby realizing the first device and the second device to be transmitted through the biological limb.
- the data between the devices enables communication using the living body.
- the first device establishes a communication connection with the second device through the biological limb, and can be implemented in a wired manner and a wireless manner, and specifically, at least in one of two ways:
- the first device and the second device are each provided with an electrode, and the first device is in contact with a biological limb implanted in the human body or a second device worn on the human body (for example, a user wearing the wristwatch contacts the POS device with a finger
- the electrodes of the two sides are connected to form a passage in the human body, and the passage in the human body can be a simple line method or a current coupling method, thereby realizing wired communication.
- the first device needs to be in contact with the biological limb wearing the second device, and transmits signals by level change or waveguide, thereby completing communication.
- both the first device and the second device can detect whether the surrounding electric field transmits changes. If the communication partner enters the range allowed by the human body communication, the field strength change can be detected, and a communication connection is established with the other party. .
- the second device may be detected by the first device in real time, and the communication may be initiated after the second device is detected.
- the second device may also actively detect the first device, thereby actively initiating communication.
- the human body is used as a transmission medium of an electrical signal to realize information interaction between the body surface, the body, and the device around the human body (3 to 5 meters).
- traditional wireless communication technologies such as Bluetooth, WIFI, radio frequency and infrared
- the signal is transmitted through the human body during human communication, so electromagnetic noise has little influence on it, and has low power consumption, high confidentiality and lower human damage. advantage.
- the redundant connection problem of the wired communication method can be eliminated.
- Step S102 The first device receives the to-be-authorized information transmitted by the second device by using the communication connection, where the information to be authorized includes: Digital authentication information.
- the second device may be configured to send the to-be-authorized information to be transmitted to the first device, or may be sent by the second device to the first device after receiving the to-be-authorized information sent by the to-be-authorized information generating device.
- the to-be-authorized information includes information for performing digital authentication.
- the digital authentication information may be electronic signature information obtained by using a private key signature (when the electronic signature information is generated by the to-be-authorized information generating device,
- the to-be-authorized information generating device may be an electronic signature device, a USBkey, or the like;
- the digital authentication information may be a MAC value calculated using a symmetric key (when the MAC value is generated by the to-be-authorized information generating device, the authorization is to be authorized at this time)
- the information generating device may be a device such as a cipher machine;
- the digital authentication information may be a dynamic password generated by the seed key (when the dynamic password is generated by the to-be-authorized information generating device, the information to be authorized may be OTP, etc.) Device).
- the to-be-authorized information may further include information representing the second device (such as product serial number, etc.), identity information of the holder, user account, and the like.
- the second device may send the to-be-authorized information by means of a broadcast, or may send the to-be-authorized information to the second device after receiving the authorization request information of the first device.
- Step S103 The first device collects biometric information of the biological limb during the duration of the preset range of the biological limb entering the first device.
- the biometric information includes fingerprint information, iris information, face information, and Information such as vein information.
- the first device is provided with a module for collecting biometric information, for example, a fingerprint collection module, configured to collect when a finger of the human body enters a preset communication range of the first device and contacts the fingerprint collection module of the first device.
- the fingerprint of the finger is configured to collect the vein information in the wrist when the wrist of the human body enters the preset communication range of the first device and contacts the vein collection module, for example, iris collection a module, configured to collect iris information of the human eye when the human eye enters the preset communication range of the first device and is located in the iris collection area, and, for example, a face recognition module, configured to enter the first face When the device is within the preset communication range and is located in the face collection area, the face information of the face is collected.
- the vein collection module for example, iris collection a module, configured to collect iris information of the human eye when the human eye enters the preset communication range of the first device and is located in the iris collection area
- a face recognition module configured to enter the first face
- the first device collecting biometric information of the biological limb includes: in case the biological limb is in contact with the first device, the first device Biometric information of the contact site of the biological limb with the first device is collected.
- the first device needs to contact the biological limb of the user to collect corresponding biometric information, and the user actively contacts the first device to collect fingerprint or vein information, thereby avoiding
- the mis-communication caused by the inadvertent passage of other users in crowded situations ensures the uniqueness and security of the communication, and at the same time expresses the user's true intention and true identity.
- the action of the first device collecting the biometric information of the biological limb may be completed during the continuous process of establishing communication between the first device and the second device, or may be completed before the communication is established between the first device and the second device. As long as the biometric information and the authorized communication for collecting the biological limb are ensured to be completed in one continuous operation, the consistency of the transmitted authorization information and the biometric information is ensured.
- step 103 there is no sequence in the execution of step 103 and step 101 and step 102, and step 103 can be performed. Executing before step 101 after step 101 may also be performed simultaneously with step 102, and may also be performed after step 102.
- Step S104 The first device acquires the authentication result of the digital authentication information and the biometric information authentication. If the authentication result of the digital authentication information and the biometric information authentication is the authentication, the first device performs the authorization operation. Specifically, when the first device can authenticate the digital authentication information and the biometric information by using the pre-stored information, the digital authentication information and the biometric information can also be sent to the background connected thereto, and the digital authentication information and the creature are utilized by the background. Feature information is authenticated. When the result of the authentication pass is obtained, the first device performs a corresponding authorization operation, such as authorizing login to the website, authorizing opening of the access control, authorizing the opening of certain devices (cars, guns, etc.).
- a corresponding authorization operation such as authorizing login to the website, authorizing opening of the access control, authorizing the opening of certain devices (cars, guns, etc.).
- the first device acquiring the authentication result of the digital authentication information and the biometric information authentication may be completed by, but not limited to, the following manner:
- the first device authenticates the digital authentication information and the biometric information, and obtains the authentication result.
- the first device may store a key related to digital authentication and biometrics and other information, and have a function module for authenticating the digital authentication information and the biometric information, and may complete the entire authentication process by itself, thereby improving The efficiency of the authorization, and because the first device can complete the authorization independently, the security of the authorization is guaranteed.
- the first device is a device such as an access card reader or a safe lock
- the authentication function is completed by the access card reader, the safe lock, etc., so that the user holding the valid authorization information can be quickly, safely and conveniently. Turn these devices on easily.
- the second device sends the biometric information and the digital authentication information to the background.
- the first device receives the authentication result sent by the background, where: the authentication result is the background authentication of the digital authentication information and the biometric information, and the obtained authentication result.
- the first device may only complete the collection of the biometric information and the communication with the second device, and the authentication process is completed by the background, and the background has a faster computing speed, and the complex operation can be completed quickly.
- the separation of the acquisition part and the authentication part can also ensure the security of the system.
- the digital authentication information of the electronic device such as a wristwatch and the biometric information of the human body can be verified, and the correlation and uniformity of the verified digital authentication information and the biometric information are ensured, and the authorization in the present invention is authorized.
- the verification of the digital authentication information and the verification of the biometric information of the human body are completed in one continuous operation, and once separated, the verification is unsuccessful, thereby preventing others from using the electronic devices such as watches to impersonate. Users are authorized to ensure the security of information and property.
- the present invention can effectively prevent illegal molecules from using other people's electronic devices and biometric information to pass authorization by using the living body as a transmission conductor.
- various digital authentication key information that the user needs to use may be stored in an electronic device carried by the wristwatch or the like, and the electronic device automatically sends the digital authentication information to the authentication end, and the user only needs to The biometric information can be collected to complete the authorized operation, which is convenient, fast and safe.
- the to-be-authorized information further includes: identification information; and the digital authentication information and the biometric information authentication comprise: authenticating the digital authentication information and the biometric information according to the identification information.
- the to-be-authorized information further includes identifier information for indicating that the key information for authenticating the digital authentication information and the biometric information is obtained.
- the identification information can be a serial number, Name, index number, etc.
- the digital authentication information and the biometric information are authenticated according to the identification information, including: obtaining an authentication factor and biometric verification information corresponding to the identification information, and performing digital authentication and detection on the digital authentication information by using an authentication factor.
- the certification result is certified.
- the authentication factor corresponding to the digital authentication information and the biometric verification information corresponding to the biometric information may be indexed or quickly searched according to the identification information, for example, when the digital authentication information is an electronic signature information, the identification information
- the indication may be to find a corresponding public key for verifying the signature, and the public key may be directly stored or stored in a digital certificate, and the identification information may identify the number of the public key or the number of the digital certificate, thereby causing the device to be verified.
- the corresponding public key can be quickly found from the database; when the acquired biometric information is fingerprint information, the identification information may be the number of the fingerprint information or the number of the user holding the fingerprint information, so that the identification information can be quickly Accurately obtain corresponding authentication factors and biometric verification information.
- the digital authentication information may be authenticated first, or the biometric information may be authenticated first, or at the same time, only when the authentication results for both are When passing, it is determined that the authentication result is the certification pass.
- the verification method of the biometric information is mainly to determine the matching rate, and the collected biometric information is compared with the biometric verification information.
- the matching rate is greater than a certain value, the verification is passed.
- setting a high matching rate can ensure the authenticity of the results, but the high matching rate often causes the real user to be mistaken as the wrong user or the recognition fails, thereby deny authorization, resulting in inconvenient operation of the user.
- a specific threshold eg, 99%, 90%, etc.
- the feature information is the same biometric information, and the biometric authentication information is authenticated.
- the specific threshold is a matching rate indicating that the two biometric information are the same biometric information.
- the specific threshold in the prior art is usually set high, and the problem that the authentication fails due to the unidentifiable by the legitimate user is likely to occur.
- the preset value is smaller than the specific threshold in the prior art, and the matching rate between the biometric verification information and the biometric information is detected to be greater than a preset value.
- the final authentication result is determined by combining the results of digitally authenticating the information to be authenticated by using the digital authentication factor.
- the digital authentication of the digital authentication information by using the authentication factor and the detection of the matching rate of the biometric verification information and the biometric information include: authenticating the digital authentication information by using the authentication factor, and authenticating the digital authentication information When passing, determining whether the matching rate of the biometric information and the biometric verification information is greater than a preset Whether the matching rate of the biometric information and the biometric verification information is greater than a preset value, and when the matching rate of the biometric information and the biometric verification information is greater than a preset value, the authentication factor is used to authenticate the digital authentication information. .
- the digital authentication information is first authenticated, and the digital authentication guarantee by the strong authentication function can be used to reduce the probability that the real and legitimate users are recognized and failed.
- the digital authentication fails, the biometric information is not required to be verified, which simplifies the process.
- the biometric authentication information is first authenticated, the biometric information can be verified to identify the counterfeiter, so that no further follow-up is needed.
- the digital certification process simplifies the process.
- the authentication of the digital authentication information may include, but is not limited to, one or several of the following:
- the digital authentication information includes electronic signature information obtained by using a private key signature
- the authentication factor includes a public key for verifying the electronic signature information
- the authentication of the digital authentication information by using the authentication factor includes: using the public key to the electronic signature information
- the digital authentication in this mode is electronic signature authentication
- the electronic signature information generation manner may use a private key to sign a preset value (such as a random number, etc.), obtain a signature value, and set a signature value and a preset. The value is used as electronic signature information.
- the electronic signature authentication ensures that the digital authentication passes the user's real authorization and has the function of preventing the user from reversing and refusing the executed operation.
- the digital authentication information includes a MAC value calculated by using a symmetric key
- the authentication factor includes a symmetric key for calculating a MAC value
- the authentication of the digital authentication information by using the authentication factor includes: calculating a MAC check value by using a symmetric key, and verifying MAC value and MAC check value; specifically, in this mode, the digital authentication uses the symmetric key to encrypt the information, and the authenticator decrypts the information by using the symmetric key, for example, using a symmetric algorithm (for example, MAC calculation) to utilize the symmetric
- the key encrypts the preset value to obtain a ciphertext value (for example, a MAC value), and uses the ciphertext value and the preset value as the ciphertext information, thereby ensuring the security of the data transmission and improving the security of the communication.
- the identity of the user is verified by a symmetric key pre-stored by both parties.
- the digital authentication information includes a dynamic password generated by using a seed key
- the authentication factor includes a seed key for verifying the dynamic password
- the authentication of the digital authentication information by using the authentication factor includes: verifying the dynamic password by using the seed key.
- the method uses a dynamic password to verify the identity, and can generate a dynamic password based on time or based on the challenge value, and the dynamic password can be used to verify the real identity of the user and ensure the security of the authorization.
- This embodiment also provides an authorization authentication device 20, as shown in FIG.
- the authorization authentication device 20 is a device corresponding to the authorization authentication method, and the authorization authentication device 20 is equivalent to the first device in the authorization authentication method, and the identity recognition device 30 is equivalent to the second device in the authorization authentication method.
- the authorization authentication device 20 includes:
- the connecting unit 201 is configured to establish a communication connection with the identity recognition device 30 through the biological limb after the biological limb enters the preset range of the authorization authentication device 20;
- the receiving unit 202 is configured to receive the to-be-authorized information transmitted by the identity identification device 30 by using a communication connection, where the to-be-authorized information includes: digital authentication information;
- the collecting unit 203 is configured to collect biometric information of the biological limb during the duration of the preset range of the biological limb entering the authorized authentication device 20;
- the executing unit 204 is configured to obtain an authentication result of the digital authentication information and the biometric information authentication. If the authentication result of the digital authentication information and the biometric information authentication is the authentication pass, the authorization operation is performed.
- the biometric information includes: fingerprint information and/or vein information;
- the collecting unit 203 is configured to collect biometric information of the contact portion of the biological limb and the authorized authentication device 20 in the case where the biological limb is in contact with the authorized authentication device 20.
- the execution result obtained by the execution unit 204 for the digital authentication information and the biometric information authentication may be completed by, but not limited to, the following two methods:
- the first execution unit 204 is configured to perform authentication on the digital authentication information and the biometric information to obtain an authentication result.
- the second execution unit 204 is configured to send the biometric information and the digital authentication information to the background 40, and receive the authentication result sent by the background, where the authentication result is the background 40 authenticating the digital authentication information and the biometric information. Certification results.
- the to-be-authorized information further includes: identification information; and the digital authentication information and the biometric information authentication comprise: authenticating the digital authentication information and the biometric information according to the identification information.
- the digital authentication information and the biometric information are authenticated according to the identification information, including: obtaining an authentication factor and biometric verification information corresponding to the identification information, and performing digital authentication and detection on the digital authentication information by using an authentication factor.
- the certification result is certified.
- the verification method of the biometric information is mainly to determine the matching rate, and the collected biometric information is compared with the biometric verification information.
- the matching rate is greater than a certain value, the verification is passed.
- setting a high matching rate can ensure the authenticity of the results, but the high matching rate often causes the real user to be mistaken as the wrong user or the recognition fails, thereby deny authorization, resulting in inconvenient operation of the user.
- a specific threshold eg, 99%, 90%, etc.
- the feature information is the same biometric information, and the biometric authentication information is authenticated.
- the specific threshold is a matching rate indicating that the two biometric information are the same biometric information.
- the specific threshold in the prior art is usually set high, and the problem that the authentication fails due to the unidentifiable by the legitimate user is likely to occur.
- the preset value is smaller than the specific threshold in the prior art, and the matching rate between the biometric verification information and the biometric information is detected to be greater than a preset value.
- the final authentication result is determined by combining the results of digitally authenticating the information to be authenticated by using the digital authentication factor.
- the strong authentication function of digital authentication can set the matching rate of biometric authentication to be lower than the biometric authentication matching rate of the general device, thereby reducing the fact that the user carrying the real biometric is misjudged as the wrong user or the recognition fails. Probability.
- the digital authentication of the digital authentication information by using the authentication factor and the detection of the matching rate of the biometric verification information and the biometric information include:
- the authentication information is used to authenticate the digital authentication information, and when the digital authentication information is authenticated, it is determined whether the matching rate between the biometric information and the biometric verification information is greater than a preset value; or
- the digital authentication information is authenticated by using the authentication factor.
- authenticating the digital authentication information may be accomplished by, but not limited to, the following:
- the digital authentication information includes electronic signature information obtained by using a private key signature, the authentication factor includes a public key for verifying the electronic signature information, and the authentication of the digital authentication information by using the authentication factor includes: using the public key to the electronic signature information Conduct a check; and/or
- the digital authentication information includes a MAC value calculated by using a symmetric key
- the authentication factor includes a symmetric key for calculating a MAC value
- the authentication of the digital authentication information by using the authentication factor includes: calculating a MAC check value by using a symmetric key, and verifying MAC value and MAC check value;
- the digital authentication information includes a dynamic password generated by using a seed key
- the authentication factor includes a seed key for verifying the dynamic password
- the authentication of the digital authentication information by using the authentication factor includes: verifying the dynamic password by using the seed key.
- the embodiment further provides an authorization authentication system, as shown in FIG. 3, the authorization authentication system includes the foregoing identity recognition device 30 and the aforementioned authorization authentication device 20;
- the identity identifying device 30 is configured to send the to-be-authorized information to the authorization authentication device 20 through the communication connection.
- the authorization authentication system further includes: a background 40, configured to receive biometric information and digital authentication information sent by the authorization authentication device 20, and authenticate the digital authentication information and the biometric information to obtain an authentication result.
- the authentication result is sent to the authorization authentication device 20.
- Embodiments of the present invention provide a computer program that, when run on a processor, performs the above-described authorization authentication method.
- modules in the devices of the embodiments can be adaptively changed and placed in one or more devices different from the embodiment.
- the modules or units or components of the embodiments may be combined into one module or unit or component, and further they may be divided into a plurality of sub-modules or sub-units or sub-components.
- all combinations of the features disclosed in the specification, as well as any methods or devices disclosed herein may be employed in any combination, unless otherwise It is expressly stated that each feature disclosed in this specification can be replaced by an alternative feature that provides the same, equivalent or similar purpose.
- the various component embodiments of the present invention may be implemented in hardware, or in a software module running on one or more processors, or in a combination thereof.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Theoretical Computer Science (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- General Physics & Mathematics (AREA)
- Physics & Mathematics (AREA)
- Software Systems (AREA)
- Computing Systems (AREA)
- General Health & Medical Sciences (AREA)
- Biomedical Technology (AREA)
- Health & Medical Sciences (AREA)
- Power Engineering (AREA)
- Biodiversity & Conservation Biology (AREA)
- Life Sciences & Earth Sciences (AREA)
- Human Computer Interaction (AREA)
- Multimedia (AREA)
- Collating Specific Patterns (AREA)
- Measurement Of The Respiration, Hearing Ability, Form, And Blood Characteristics Of Living Organisms (AREA)
Abstract
Description
Claims (17)
- 一种授权认证方法,其特征在于,包括:在生物肢体进入第一设备的预设范围后,所述第一设备通过所述生物肢体与第二设备建立通信连接;所述第一设备通过所述通信连接接收所述第二设备传输的待授权信息,所述待授权信息包括:数字认证信息;在所述生物肢体进入第一设备的预设范围的持续时间内,所述第一设备采集所述生物肢体的生物特征信息;所述第一设备获取对所述数字认证信息以及所述生物特征信息认证的认证结果,如果对所述数字认证信息以及所述生物特征信息认证的认证结果为认证通过,则所述第一设备执行授权操作。
- 根据权利要求1所述的方法,其特征在于,所述生物特征信息包括:指纹信息和/或静脉信息;所述第一设备采集所述生物肢体的生物特征信息包括:在所述生物肢体与所述第一设备接触的情况下,第一设备采集所述生物肢体与所述第一设备的接触部位的所述生物特征信息。
- 根据权利要求1或2所述的方法,其特征在于,所述第一设备获取对所述数字认证信息以及所述生物特征信息认证的认证结果包括:所述第一设备对所述数字认证信息以及所述生物特征信息进行认证,获得所述认证结果。
- 根据权利要求1或2所述的方法,其特征在于,所述第一设备获取对所述数字认证信息以及所述生物特征信息的认证结果包括:所述第一设备向后台发送所述生物特征信息以及所述数字认证信息;所述第一设备接收所述后台发送的所述认证结果,其中:所述认证结果为所述后台对所述数字认证信息以及所述生物特征信息进行认证,获得的认证结果。
- 根据权利要求3或4所述的方法,其特征在于,所述待授权信息还包括:标识信息;所述对所述数字认证信息以及所述生物特征信息认证包括:根据所述标识信息对所述数字认证信息以及所述生物特征信息进行认证。
- 根据权利要求5所述的方法,其特征在于,根据所述标识信息对所述数字认证信息以及所述生物特征信息进行认证包括:获取所述标识信息对应的认证因子和生物特征验证信息,并利用所述认证因子对所述数字认证信息进行数字认证以及检测所述生物特征验证信息与所述生物特征信息的匹配率,其中,所述认证结果为认证通过包括:在利用所述认证因子对所述数字认证信息进行数字认证通过且所述生物特征信息与所述生物特征验证信息的匹配率大于预设值时,所述认证结果为认证通过。
- 根据权利要求6所述的方法,其特征在于,所述预设值小于特定门限值,其中,所述特定门限值为指示两个生物特征信息为同一个生物特征信息的匹配率。
- 一种授权认证装置,其特征在于,包括:连接单元,在生物肢体进入授权认证装置的预设范围后,用于通过所述生物肢体与身份识别装置建立通信连接;接收单元,用于通过所述通信连接接收所述身份识别装置传输的待授权信息,所述待授权信息包括:数字认证信息;采集单元,在所述生物肢体进入授权认证装置的预设范围的持续时间内,用于采集所述生物肢体的生物特征信息;执行单元,用于获取对所述数字认证信息以及所述生物特征信息认证的认证结果,如果对所述数字认证信息以及所述生物特征信息认证的认证结果为认证通过,则执行授权操作。
- 根据权利要求8所述的装置,其特征在于,所述生物特征信息包括:指纹信息和/或静脉信息;所述采集单元,在所述生物肢体与所述授权认证装置接触的情况下,用于采集所述生物肢体与所述授权认证装置的接触部位的所述生物特征信息。
- 根据权利要求8或9所述的装置,其特征在于,所述执行单元,具体用于对所述数字认证信息以及所述生物特征信息进行认证,获得所述认证结果。
- 根据权利要求8或9所述的装置,其特征在于,所述执行单元,具体用于向后台发送所述生物特征信息以及所述数字认证信息,并接收所述后台发送的所述认证结果,其中:所述认证结果为所述后台对所述数字认证信息以及所述生物特征信息进行认证,获得的认证结果。
- 根据权利要求10或11所述的装置,其特征在于,所述待授权信息还包括:标识信息;所述对所述数字认证信息以及所述生物特征信息认证包括:根据所述标识信息对所述数字认证信息以及所述生物特征信息进行认证。
- 根据权利要求12所述的装置,其特征在于,根据所述标识信息对所述数字认证信息以及所述生物特征信息进行认证包括:获取所述标识信息对应的认证因子和生物特征验证信息,并利用所述认证因子对所述数字认证信息进行数字认证以及检测所述生物特征验证信息与所述生物特征信息的匹配率,其中,所述认证结果为认证通过包括:在利用所述认证因子对所述数字认证信息进行数字认证通过且所述生物特征信息与所述生物特征验证信息的匹配率大于预设值时,所述认证结果为认证通过。
- 根据权利要求13所述的装置,其特征在于,所述预设值小于特定门限值,其中,所述特定门限值为指示两个生物特征信息为同一个生物特征信息的匹配率。
- 一种授权认证系统,其特征在于,包括:身份识别装置以及如权利要求8-14所述的授权认证装置;所述身份识别装置,用于通过所述通信连接向所述授权认证装置发送所述待授权信息。
- 根据权利要求15所述的系统,其特征在于,所述系统还包括:后台,用于接收所述授权认证装置发送的所述生物特征信息以及所述数字认证信息,对所述数字认证信息以及所述生物特征信息进行认证,获得认证结果,并将所述认证结果发送至所述授权认证装置。
- 一种计算机程序,当其在处理器上运行时,执行如权利要求1-7中任一项所述的授权认证方法。
Priority Applications (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US16/083,469 US10785218B2 (en) | 2016-03-07 | 2017-03-06 | Authorization authentication method, device and system |
| JP2018546887A JP2019512786A (ja) | 2016-03-07 | 2017-03-06 | 権限付与認証方法、権限付与装置及び権限付与システム |
| EP17762505.0A EP3429157A4 (en) | 2016-03-07 | 2017-03-06 | AUTHORIZATION AUTHENTICATION METHOD, DEVICE AND SYSTEM |
Applications Claiming Priority (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201610127334.4 | 2016-03-07 | ||
| CN201610127235.6 | 2016-03-07 | ||
| CN201610127334.4A CN105939336A (zh) | 2016-03-07 | 2016-03-07 | 一种身份认证方法及系统 |
| CN201610127235.6A CN105991654A (zh) | 2016-03-07 | 2016-03-07 | 一种授权认证方法、装置和系统 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2017152819A1 true WO2017152819A1 (zh) | 2017-09-14 |
Family
ID=59788979
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2017/075745 Ceased WO2017152819A1 (zh) | 2016-03-07 | 2017-03-06 | 一种授权认证方法、装置和系统 |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US10785218B2 (zh) |
| EP (1) | EP3429157A4 (zh) |
| JP (1) | JP2019512786A (zh) |
| WO (1) | WO2017152819A1 (zh) |
Families Citing this family (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| JP2019102902A (ja) * | 2017-11-30 | 2019-06-24 | ルネサスエレクトロニクス株式会社 | 通信システム |
| DE102019108095A1 (de) * | 2019-03-28 | 2020-10-01 | Infineon Technologies Ag | Ausführen einer kryptografischen Operation |
| US11194897B2 (en) * | 2019-04-10 | 2021-12-07 | Mastercard International Incorporated | System and methods for generating and authenticating dynamic usernames replication |
| CN113642050B (zh) * | 2021-10-13 | 2022-02-08 | 联芸科技(杭州)有限公司 | 自配置加密硬盘及其配置方法、系统及系统的启动方法 |
| CN118503946A (zh) * | 2024-01-30 | 2024-08-16 | 中国银联股份有限公司 | 一种基于可信计算的生物特征验证方法及其系统 |
Citations (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103237030A (zh) * | 2013-04-25 | 2013-08-07 | 深圳市中兴移动通信有限公司 | 基于生物识别的用户认证方法及系统 |
| CN104202744A (zh) * | 2014-08-14 | 2014-12-10 | 腾讯科技(深圳)有限公司 | 一种智能终端的操作认证方法、终端及系统 |
| CN104767760A (zh) * | 2015-04-23 | 2015-07-08 | 王晓军 | 具有指静脉身份认证的智能指环及用其控制终端的方法 |
| CN105245341A (zh) * | 2015-09-07 | 2016-01-13 | 天地融科技股份有限公司 | 远程身份认证方法和系统以及远程开户方法和系统 |
| CN105939336A (zh) * | 2016-03-07 | 2016-09-14 | 李明 | 一种身份认证方法及系统 |
| CN105989495A (zh) * | 2016-03-07 | 2016-10-05 | 李明 | 一种支付方法及系统 |
| CN105991654A (zh) * | 2016-03-07 | 2016-10-05 | 李明 | 一种授权认证方法、装置和系统 |
| CN105991652A (zh) * | 2016-03-07 | 2016-10-05 | 李明 | 一种身份认证方法及系统 |
| CN105991653A (zh) * | 2016-03-07 | 2016-10-05 | 李明 | 一种身份认证方法及装置 |
Family Cites Families (21)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101061521B (zh) * | 2004-11-16 | 2010-11-24 | 皇家飞利浦电子股份有限公司 | 识别系统和操作该系统的方法 |
| JP2006268614A (ja) * | 2005-03-25 | 2006-10-05 | Sony Corp | 情報処理システム、情報処理装置および方法、プログラム、並びに記録媒体 |
| CN101213559B (zh) * | 2005-08-05 | 2012-02-29 | 夏普株式会社 | 通信装置和通信系统 |
| JP2010049490A (ja) * | 2008-08-21 | 2010-03-04 | Panasonic Electric Works Co Ltd | 認証システム |
| JP2011076593A (ja) * | 2009-09-03 | 2011-04-14 | Seiko Instruments Inc | 情報表示システム、管理装置、情報表示装置および電子棚札端末 |
| JP2011123729A (ja) * | 2009-12-11 | 2011-06-23 | Hitachi Omron Terminal Solutions Corp | 認証システム、人体通信端末装置、およびホスト装置 |
| JP2012039370A (ja) * | 2010-08-06 | 2012-02-23 | Sony Corp | 通信システム並びに通信装置 |
| US20130006859A1 (en) * | 2011-06-29 | 2013-01-03 | Hyundai Motor Company | Payment system and method using human body communication |
| US8994827B2 (en) * | 2012-11-20 | 2015-03-31 | Samsung Electronics Co., Ltd | Wearable electronic device |
| KR20140119324A (ko) * | 2013-03-28 | 2014-10-10 | 인텔렉추얼디스커버리 주식회사 | 의료 정보 모니터링 시스템 및 방법 |
| JP2015055952A (ja) * | 2013-09-11 | 2015-03-23 | 大日本印刷株式会社 | 決済システム、決済方法、認証サーバ、認証方法、及び、プログラム |
| EP3078135B1 (en) * | 2013-12-05 | 2019-12-11 | Sony Corporation | Pairing consumer electronic devices using a cross-body communications protocol |
| US9510197B2 (en) * | 2014-06-12 | 2016-11-29 | Sony Mobile Communications Inc. | Electronic equipment and method of authenticating a user |
| US10588005B2 (en) * | 2014-09-26 | 2020-03-10 | Mcafee, Llc | Fuzzy fingerprinting of communicating wearables |
| KR20160072682A (ko) * | 2014-12-15 | 2016-06-23 | 삼성전자주식회사 | 생체 정보를 이용한 인증 방법 및 이를 위한 전자 장치 |
| KR102139795B1 (ko) * | 2014-12-15 | 2020-07-31 | 삼성전자주식회사 | 생채 특징 패턴을 업데이트하는 방법 및 이를 위한 전자 장치 |
| KR101675728B1 (ko) * | 2015-01-05 | 2016-11-14 | 주식회사 슈프리마 | 정보처리기기를 이용한 사용자 인증 처리 방법 및 장치 |
| CN105447437B (zh) * | 2015-02-13 | 2017-05-03 | 比亚迪股份有限公司 | 指纹识别方法和装置 |
| US9842329B2 (en) * | 2015-02-13 | 2017-12-12 | Sony Corporation | Body area network for secure payment |
| KR20160136013A (ko) * | 2015-05-19 | 2016-11-29 | 엘지전자 주식회사 | 이동 단말기 및 그 제어 방법 |
| KR102027112B1 (ko) * | 2016-07-05 | 2019-10-01 | 주식회사 슈프리마 | 지문 인증 방법 및 장치 |
-
2017
- 2017-03-06 JP JP2018546887A patent/JP2019512786A/ja active Pending
- 2017-03-06 EP EP17762505.0A patent/EP3429157A4/en not_active Withdrawn
- 2017-03-06 US US16/083,469 patent/US10785218B2/en active Active
- 2017-03-06 WO PCT/CN2017/075745 patent/WO2017152819A1/zh not_active Ceased
Patent Citations (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103237030A (zh) * | 2013-04-25 | 2013-08-07 | 深圳市中兴移动通信有限公司 | 基于生物识别的用户认证方法及系统 |
| CN104202744A (zh) * | 2014-08-14 | 2014-12-10 | 腾讯科技(深圳)有限公司 | 一种智能终端的操作认证方法、终端及系统 |
| CN104767760A (zh) * | 2015-04-23 | 2015-07-08 | 王晓军 | 具有指静脉身份认证的智能指环及用其控制终端的方法 |
| CN105245341A (zh) * | 2015-09-07 | 2016-01-13 | 天地融科技股份有限公司 | 远程身份认证方法和系统以及远程开户方法和系统 |
| CN105939336A (zh) * | 2016-03-07 | 2016-09-14 | 李明 | 一种身份认证方法及系统 |
| CN105989495A (zh) * | 2016-03-07 | 2016-10-05 | 李明 | 一种支付方法及系统 |
| CN105991654A (zh) * | 2016-03-07 | 2016-10-05 | 李明 | 一种授权认证方法、装置和系统 |
| CN105991652A (zh) * | 2016-03-07 | 2016-10-05 | 李明 | 一种身份认证方法及系统 |
| CN105991653A (zh) * | 2016-03-07 | 2016-10-05 | 李明 | 一种身份认证方法及装置 |
Non-Patent Citations (1)
| Title |
|---|
| See also references of EP3429157A4 * |
Also Published As
| Publication number | Publication date |
|---|---|
| US10785218B2 (en) | 2020-09-22 |
| JP2019512786A (ja) | 2019-05-16 |
| US20190075103A1 (en) | 2019-03-07 |
| EP3429157A4 (en) | 2019-10-16 |
| EP3429157A1 (en) | 2019-01-16 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3428818B1 (en) | Identity authentication method and system | |
| US11012438B2 (en) | Biometric device pairing | |
| JP7467702B2 (ja) | アクセス制御のためのシステム、方法及び装置 | |
| US8955069B1 (en) | Event-based biometric authentication using mobile device | |
| US20140380445A1 (en) | Universal Authentication and Data Exchange Method, System and Service | |
| CN106612259B (zh) | 身份识别、业务处理以及生物特征信息的处理方法和设备 | |
| WO2017152818A1 (zh) | 一种支付方法及系统 | |
| US20190174304A1 (en) | Universal Authentication and Data Exchange Method, System and Service | |
| CN105939336A (zh) | 一种身份认证方法及系统 | |
| US20150026479A1 (en) | Creation and authentication of biometric information | |
| US20210105254A1 (en) | System, method and computer-accessible medium for two-factor authentication during virtual private network sessions | |
| CN105991652A (zh) | 一种身份认证方法及系统 | |
| WO2017152819A1 (zh) | 一种授权认证方法、装置和系统 | |
| US9030290B2 (en) | Vicinity-based multi-factor authentication | |
| CN105553926A (zh) | 一种认证方法、服务器以及终端 | |
| CN105991654A (zh) | 一种授权认证方法、装置和系统 | |
| CN105989488B (zh) | 一种支付方法及系统 | |
| CN105989497A (zh) | 一种支付方法及系统 | |
| CN105939195A (zh) | 一种交易方法及系统 | |
| WO2017016038A1 (zh) | 支付方法、支付装置、终端和支付系统 | |
| KR102339949B1 (ko) | 인증 정보 처리 방법 및 장치와 인증 정보 처리 방법 장치를 포함한 사용자 단말 | |
| CN105989498A (zh) | 一种支付方法及系统 | |
| CN109005158B (zh) | 基于模糊保险箱的动态手势认证系统的认证方法 | |
| WO2026092841A1 (en) | Preventing unauthorized use while charging | |
| CN120048030A (zh) | 一种智能设备控制系统、方法及相关产品 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| ENP | Entry into the national phase |
Ref document number: 2018546887 Country of ref document: JP Kind code of ref document: A |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2017762505 Country of ref document: EP |
|
| ENP | Entry into the national phase |
Ref document number: 2017762505 Country of ref document: EP Effective date: 20181008 |
|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 17762505 Country of ref document: EP Kind code of ref document: A1 |