Biometric authentication smart card

By integrating biometric sensors and security modules into smart cards, the problem of unauthorized credit card use has been solved, enabling a highly secure biometric authentication payment system.

CN113902080BActive Publication Date: 2026-05-15SAMSUNG ELECTRONICS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SAMSUNG ELECTRONICS CO LTD
Filing Date
2021-06-21
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing credit cards can still be used for payments by unregistered users, lacking effective biometric authentication methods, resulting in insufficient security.

Method used

Design a smart card that integrates a biometric sensor, an authentication information processing module, and a security module into a single chip. The card verifies the user's identity through fingerprint recognition, and the security module overlaps with an active shielding component to enhance security.

Benefits of technology

It achieves highly secure payment authentication based on biometrics, preventing unauthorized use and improving the security level of the payment system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113902080B_ABST
    Figure CN113902080B_ABST
Patent Text Reader

Abstract

An intelligent card is provided. The intelligent card includes a peripheral circuit configured to control a fingerprint sensing array and generate a raw image, an authentication information processing module configured to process the raw image into fingerprint information for verification, a secure module configured to determine whether the fingerprint information for verification matches registered fingerprint information to determine permission or non-permission of use of a payment request, and an active shield overlapping the secure module. The peripheral circuit, the authentication information processing module, and the secure module are integrated into one chip.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to smart cards based on biometric authentication and smart payment systems thereof. Background Technology

[0002] When a user purchases items in a store, they insert their credit card into the store's point-of-sale (POS) terminal, which reads the user's payment information from the credit card and proceeds with the payment. However, it often happens that payments are also made for items even when a non-registered person uses the credit card, leading to the development of credit cards equipped with authentication devices.

[0003] Biometrics are gaining attention as a user authentication technology due to their strong security levels and convenient usability. Recently, biometric information such as fingerprints, iris scans, and facial recognition are being used as individual units or combinations thereof for user authentication in commercial products such as smartphones and laptops. Furthermore, biometrics can be combined with electronic passport (E-Passport) systems and are used in border control systems in many countries.

[0004] As attempts to utilize biometric information as a means of authentication increase, there is also growing interest in systems that use devices such as fingerprints or iris scans to perform access control or payment authentication. In particular, systems using fingerprints are easy to use and offer little resistance to user interaction, and have therefore been relatively widely adopted. Summary of the Invention

[0005] This disclosure provides a biometric authentication-based smart card in which a biometric sensor, an authentication processing module, and a security module are implemented as a single chip.

[0006] However, the embodiments of this disclosure are not limited to those set forth herein. The above and other embodiments of this disclosure will become more apparent to those skilled in the art upon which this disclosure pertains from the following detailed description.

[0007] According to embodiments of this disclosure, a smart card includes: peripheral circuitry configured to control a fingerprint sensing array and generate an original image; an authentication information processing module configured to process the original image into fingerprint information for verification; a security module configured to determine whether the fingerprint information for verification matches registered fingerprint information to determine permission or disallowment of a payment request; and an active shielding element overlapping the security module, wherein the peripheral circuitry, the authentication information processing module, and the security module are integrated into a single chip.

[0008] According to another embodiment of this disclosure, a smart card based on biometric authentication includes a single chip, wherein the single chip includes peripheral circuitry for a biosensor, an authentication information processing module, and a security module, and wherein the security module overlaps with an active shield.

[0009] According to other embodiments of this disclosure, a smart card includes: an analog circuit configured to control a biometric sensor to generate an original image; an authentication information processing module configured to preprocess the original image and process the preprocessed original image into fingerprint information for verification; and a security module configured to compare the fingerprint information for verification with registered fingerprint information and output the authorization determination result of a payment request to a terminal, wherein the analog circuit, the authentication information processing module, and the security module are integrated into a single chip.

[0010] The technical problems to be solved by this disclosure are not limited to those mentioned above, and other technical problems not mentioned will be clearly understood by those skilled in the art from the following description. Attached Figure Description

[0011] The above and other embodiments and features of this disclosure will become more apparent from the detailed description of the embodiments with reference to the accompanying drawings, in which:

[0012] Figure 1 This illustration shows a smart card payment system based on biometric authentication according to some example embodiments of the present disclosure;

[0013] Figure 2 This is a schematic diagram illustrating a biometric-based smart card according to some example embodiments of the present disclosure;

[0014] Figure 3 This is a schematic diagram illustrating a biometric authentication integrated chip according to some example embodiments of the present disclosure;

[0015] Figure 4 This is a schematic diagram illustrating a biometric identification module according to some example embodiments of the present disclosure;

[0016] Figure 5 and Figure 6 This is a schematic diagram illustrating a security module according to some example embodiments of the present disclosure;

[0017] Figure 7 This is a schematic diagram illustrating an authentication information processing module according to some example embodiments of the present disclosure;

[0018] Figure 8 This is a more detailed diagram illustrating the interface between the security module and the authentication information processing module according to some example embodiments of this disclosure; and

[0019] Figure 9 This is a flowchart describing a method of operating a smart card according to some example embodiments of the present disclosure. Detailed Implementation

[0020] In the following text, reference will be made to Figures 1 to 9 This disclosure describes smart cards according to some example embodiments.

[0021] Figure 1 This invention illustrates a biometric-based smart card payment system according to some example embodiments of the present disclosure.

[0022] Reference Figure 1 According to some example embodiments, the payment system may include a biometric smart card (also referred to as a "smart card") 1000, a payment terminal 2000, and a payment server 3000.

[0023] Smart card 1000 refers to a card (e.g., a credit card element) in the form of a semiconductor chip with various functions inserted into and / or disposed on a plastic card. According to some example embodiments, smart card 1000 can be implemented in a contact manner, whereby the integrated chip 100 in smart card 100 comes into contact with payment terminal 2000, or in a contactless manner, whereby data can be exchanged at a distance from the integrated chip 100.

[0024] According to some example embodiments, when payment request information including deposit information is output from online / offline payment terminal 2000 to biometric authentication smart card 1000, biometric authentication smart card 1000 outputs payment method information corresponding to the payment request information. (Refer to...) Figures 2 to 6 Detailed description of the Biometric Authentication Smart Card 1000.

[0025] According to some example embodiments, the payment terminal 2000 may be a device for storing deposit information such as the type, quantity, and price of products sold online / offline and managing sales information for each product. According to one example embodiment, the payment terminal 2000 may be a point-of-sale (POS) terminal in a store in an offline scenario; according to another example embodiment, it may be an online shopping mall system in an online scenario; and according to yet another example embodiment, it may be a terminal device capable of accessing smart cards to read payment-related information and communicating with a payment server.

[0026] The payment terminal 2000 may be a device installed in an offline retail store and capable of reading product information from barcodes or similar materials attached to each product for sale using a reader. According to some example embodiments, the product information may include information about the product type, product code, sales price, etc.

[0027] Payment terminal 2000 may send sales-related information to payment server 3000. According to some example embodiments, the sales-related information may include at least one of the following: sales price information, the identifier (ID) of payment terminal 2000, the time when payment terminal 2000 reads the product's sales price information, the type of work to be processed by payment terminal 2000, domain information of the management server of payment terminal 2000, and / or deposit account information of the holder of payment terminal 2000. As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items. When preceding a list of elements, expressions such as "at least one" modify the entire list of elements, without modifying any individual element of that list.

[0028] In addition, the payment terminal 2000 can send payment information read from the smart card 1000 to the payment server 3000. The payment information may include payment level information and / or payment method information of the user registered in the smart card 1000.

[0029] According to some example embodiments, payment method information may include payment account information and / or payment card information. According to some example embodiments, payment account information is information related to a user's bank account and may include at least one of a bank account number, account password, and security-related authentication number. According to some example embodiments, payment card information may include at least one of the following: the card company for payment, card number, and / or card password.

[0030] In addition, the payment terminal 2000 can check whether the user of the smart card 1000 is a registered user based on the biometric authentication information in the payment information read from the smart card 1000, and when the user of the smart card 1000 is a registered user, it can send the payment level information of the user corresponding to the user index to the payment server 3000.

[0031] The payment server 3000 can determine whether to authorize payment based on sales-related information and / or payment information received from the payment terminal 2000, and can send the authorization determination result to the payment terminal 2000.

[0032] According to some example embodiments, the payment server 3000 may determine whether to permit payment of the amount corresponding to the sales-related information based on payment information (i.e., payment method information and / or payment level information).

[0033] For example, if the payment information is payment account information, payment server 3000 could be the payment server of a financial institution (bank, etc.) where the user has already opened a financial account. Similarly, if the payment information is payment card information, payment server 3000 could be the payment server of a financial institution where the user has already opened a payment card.

[0034] In this specification, a normal user is a user registered and stored in the payment server 3000, and may refer to a user who has a payment account with an amount greater than or equal to the amount of the requested payment and / or a payment card with the amount of the requested payment within the available limits.

[0035] Once the cardholder is determined to be a legitimate user, the payment server 3000 can check the sales price information and the payment terminal 2000's ID from the sales-related information, compare the sales-related information with the payment information, and determine whether payment is permitted. This will be described in detail below.

[0036] Figure 2 This is a schematic diagram illustrating a biometric-based smart card according to some example embodiments of the present disclosure, and Figure 3 This is a schematic diagram illustrating a biometric authentication integrated chip according to some example embodiments of the present disclosure.

[0037] Reference Figure 2 and Figure 3 The biometric authentication smart card 1000 may include an antenna 10 and an integrated chip 100. The integrated chip 100 may include a biometric recognition module 200, an authentication information processing module 300, and a security module 400.

[0038] As used herein, the term "module" is intended to include an electronic structure comprising software, hardware, or a combination of hardware and software. The functionality of a module can be implemented by computer program instructions executed by one or more computer circuits. These computer program instructions can be provided to processor circuits of general-purpose computer circuits, special-purpose computer circuits, and / or other programmable data processing circuits to generate a machine, such that the instructions, executed via the processor of a computer and / or other programmable data processing device, transform and control transistors, values ​​stored in memory locations, and other hardware components within such circuits to implement the module's function / operation, thereby creating means (functions) and / or structures for implementing the module's function / operation. In some embodiments, the term "module" may be synonymous with "circuit".

[0039] The biometric identification module 200 can be a device for enhancing the security of the smart card 1000. The biometric identification module 200 can determine whether the fingerprint information of the actual owner of the smart card 1000 (i.e., a previously registered user) matches the fingerprint information of the card user. When the fingerprints match, the biometric identification module 200 can unlock the security module 400 embedded in the smart card 1000 for a predetermined time by authenticating that the card user is the actual owner of the card. The biometric identification module 200 can proactively reduce and / or prevent unauthorized use of the smart card 1000 by automatically closing the lock after the predetermined time.

[0040] According to some example embodiments, the biometric identification module 200 may be a sensor (e.g., a biometric sensor) configured to sense fingerprints or other types of biometric information, and may be a sensor configured to sense fingerprints by, for example, capacitive methods, piezoelectric methods, etc. The biometric identification module 200 may be a swipe-type sensor in which a finger swipes across the sensor and thus senses a fingerprint, and / or an area-type sensor in which a finger touches the sensor for a predetermined time and thus senses a fingerprint.

[0041] According to some example embodiments, the security module 400 may be an integrated circuit configured to record and / or store card identification information of the smart card 1000. The security module 400 may send the recorded card identification information to the payment terminal 2000 in a contact or contactless manner, thereby performing electronic payment.

[0042] According to some example embodiments, the security module 400 can temporarily record card identification information and modify or delete the recorded card identification information. The security module 400 can record the card identification information on one of multiple payment method information entries. Here, card identification information corresponds to payment method information and includes information required for electronic payment, such as card number information, card expiration date information, and card security information.

[0043] Security module 400 complies with high security requirements of Evaluation Assurance Level (EAL) 5 or higher. To meet these security requirements, internal components and data processed within security module 400 can be encrypted using a random key. For example, security module 400 can encrypt the fingerprint information of the actual owner of the memory card (a previously registered user) and / or prevent the fingerprint information from being exposed externally.

[0044] When it is necessary to verify the fingerprint information extracted from the biometric identification module 200 due to the use of smart card 1000, security module 400 can receive the registered fingerprint information from authentication information processing module 300 and determine whether to allow the use of smart card 1000 based on the matching result.

[0045] According to some example embodiments, the authentication information processing module 300 can process a raw image of a fingerprint received from the biometric identification module 200 to generate a fingerprint template. The raw image may include feature points of the fingerprint, i.e., minutiae, which may be detailed feature points such as the ends of ridges or bifurcations found in the fingerprint image. The authentication information processing module 300 can obtain template information corresponding to the fingerprint image, i.e., fingerprint information for verification, by detecting the minutiae. In some embodiments, the authentication information processing module 300 may include a microcontroller unit (MCU).

[0046] In some embodiments, the integrated chip 100 may include additional components. For example, the integrated chip 100 may include components for transmitting / receiving radio frequency (RF) signals, a power supply VDD, input pins for one or more signals (e.g., CLK, RST, SIO), and / or one or more transmit TX or receive RX solder pads.

[0047] The peripheral circuits 220 of the biometric identification module 200, the authentication information processing module 300, and the security module 400 (see...) Figure 4 This can be implemented as a single integrated chip 100. That is, each of components 200, 300, and 400 can be integrated into a single chip. (See reference...) Figures 4 to 8 A detailed description of each of components 200, 300, and 400 in integrated chip 100.

[0048] Figure 4 This is a schematic diagram illustrating a biometric identification module according to some example embodiments of the present disclosure.

[0049] According to some example embodiments, the biometric identification module 200 may include a sensor array 210 configured to sense fingerprints (in... Figure 4 (shown as sensing array 210) and peripheral circuitry 220 configured to control and / or drive sensing array 210 and generate the sensed raw image (in) Figure 4 (The middle part is shown as peri).

[0050] In some embodiments, the sensing array 210 is or includes a biometric sensor. In some embodiments, the sensing array 210 is a unit that senses the touch of a finger and obtains a fingerprint image by scanning the fingerprint of the touching finger. The sensing array 210 can scan the fingerprint of a finger in various ways, such as capacitive methods, optical methods, pressure methods, thermal detection methods, etc. According to an example embodiment, the sensing array 210 can also perform fingerprint sensing by combining swipe methods and touch methods. For example, when registering a fingerprint, feature points of the fingerprint can be extracted after obtaining a fingerprint image using a swipe method, and when authenticating a fingerprint, feature points of the fingerprint can be extracted after obtaining a fingerprint image using a touch method, and vice versa.

[0051] The peripheral circuit 220 can perform signal processing on fingerprint image frames scanned by the sensing array 210 at a predetermined period (speed). For example, the peripheral circuit 220 may include analog circuits, noise reduction circuits, signal sensitivity amplification circuits, analog-to-digital converter circuits, digital circuits, etc., that can convert the fingerprint image into an electrical signal. The peripheral circuit 220 can be implemented separately from or integrated with the sensing array 210 in the form of an application-specific integrated circuit (ASIC). The peripheral circuit 220 can output the raw image to the authentication information processing module 300 after performing signal processing on it.

[0052] Figure 5 and Figure 6 This is a schematic diagram illustrating a security module 400 according to some example embodiments of the present disclosure.

[0053] Reference Figure 5 The security module 400 may include a secure central processing unit (CPU) 410, a cryptographic engine 420, a PKRAM 425, a non-volatile memory (NVM) 430, a memory controller 435, an external interface (I / F) 440, a system control unit 450, a modem 460, a memory 470, a mailbox 480, and an energy harvesting unit 490.

[0054] Components 410 to 490 can communicate with each other via bus 401. For example, bus 401 can be configured as an Advanced High Performance Bus (AHB) interface.

[0055] According to some example embodiments, security module 400 may include an active shield 520 that overlaps (e.g., vertically) with each of components 410 to 490, as well as side logic 511 and 512. It will be understood that "element A that overlaps vertically with element B" (or similar language) as used herein means that there is at least one vertical line intersecting both elements A and B. According to some example embodiments, active shield 520 is a unit in which signal lines extending in one direction (a first direction) are arranged parallel to each other at regular intervals in a plan view using the top metal of the layout of security module 400. As an example, active shield 520 may include a plurality of top metal lines spaced parallel to each other at 1 μm intervals. Side logic 511 and 512 may be disposed at opposite ends of active shield 520 and may extend in a second direction perpendicular to the first direction, and may be electrically connected to the signal lines of active shield 520. Side logic 511 and 512 can apply predetermined signals to active shield 520 to prevent and / or reduce detection from the outside via reverse engineering or probe.

[0056] The security CPU 410 controls all security-related operations of the security module 400. For example, the security CPU 410 can determine whether registered fingerprint information matches the fingerprint information used for verification, and determine whether to authorize the use of the requested payment based on the determination result.

[0057] Cryptographic engine 420 can encrypt and / or decrypt data to be sent to or received from outside security module 400. For example, cryptographic engine 420 can perform private key encryption / decryption operations based on Advanced Encryption Standard (AES), Data Encryption Standard (DES), Secure Hash Algorithm (SHA), etc. Cryptographic engine 420 may include a large number multiplier (e.g., TORNADO) for detecting errors in encrypting and / or decrypting data (e.g., calculating Rivest-Shamir-Adleman (RSA), Elliptic Curve Cryptography (ECC), etc.). TM ).

[0058] PKRAM 425 is a memory connected to cryptographic engine 420 and can store public keys. Cryptographic engine 420 can use public and private keys to perform encryption / decryption of data.

[0059] The non-volatile memory 430 can be controlled and / or driven by the memory controller 435. The non-volatile memory 430 can store codes used for the operation of the secure CPU 410, initial data, fingerprint information of registered users, etc. Data read from and / or output from the non-volatile memory 430 may also include error correction code (ECC) bits corresponding to the stored data. The memory controller 435 can detect errors by checking the ECC bits of the read data and correct the detected errors.

[0060] External interface 440 can receive commands from a host device (e.g., payment terminal 2000) or send data processed by commands to the host device. External interface 440 may include multiple pins, such as a clock signal pin CLK, a reset signal pin RST, and / or a data pin SIO. External interface can contact and communicate with the host device according to, for example, the ISO 7816 standard.

[0061] Modem 460 can receive commands from a host device (e.g., payment terminal 2000) or send data processed by commands to the host device. Unlike external interface 440, modem 460 can communicate with the host device contactlessly according to ISO 14443 standard. Modem 460 can be connected to energy harvesting unit 490. Energy harvesting unit 490 can be connected to a radio frequency (RF) pin connected to antenna 10. Energy harvesting unit 490 can receive RF signals through antenna 10 and use the received RF signals to generate power. Modem 460 can supply the generated power to security module 400 to control and / or drive smart card 1000.

[0062] The system control unit 450 can perform system control operations, such as controlling the clock of the smart card 1000, controlling the drive reset of the smart card 1000, and / or controlling the power supply.

[0063] Memory 470 may be a working memory that stores data generated during the operation of security module 400. Memory 470 may be, for example, volatile memory, such as random access memory (RAM).

[0064] Mailbox 480 communicates with authentication information processing module 300. As used herein, the term "mailbox" refers to an electronic structure and / or circuit that can be implemented in hardware and / or software. In some embodiments, mailbox 480 facilitates the sending / receiving of messages (e.g., electronic messages). Reference will be made to... Figure 8 Provide a detailed description.

[0065] Figure 7 This is a schematic diagram illustrating an authentication information processing module according to some example embodiments of the present disclosure.

[0066] When the authentication information processing module 300 receives a command from the security module 400, the authentication information processing module 300 can activate the biometric recognition module 200 and receive the original image of the sensed fingerprint from the biometric recognition module 200. The authentication information processing module 300 can extract feature points from the original image and generate fingerprint information for verification, and send the fingerprint information for verification to the security module 400.

[0067] According to some example embodiments, the authentication information processing module 300 meets the security requirements specification regarding EAL2. In some embodiments, the authentication information processing module 300 can operate at a high frequency to extract fingerprint information from the raw image within milliseconds. In some embodiments, the authentication information processing module 300 can use a top metal wire as a signal line and / or power line. That is, with Figure 6 Unlike other modules, the authentication information processing module 300 may not include active shielding and side logic.

[0068] Reference Figure 7 According to some example embodiments, the authentication information processing module 300 may include a non-volatile memory 310, a memory controller 315, a CPU 320, an accelerator (ACC) 330, a first memory 340, a second memory 350, a serial peripheral interface (SPI) 370, and / or an advanced peripheral bus (APB) bridge 360.

[0069] Components 310 to 370 can communicate with each other via bus 301. For example, bus 301 can be configured as an AHB interface.

[0070] The non-volatile memory 310 can be controlled and / or driven by the memory controller 315. The non-volatile memory 310 can store code, initial data, etc., for CPU 320 operation. Data read from and output from the non-volatile memory 310 may also include ECC bits corresponding to the stored data. The memory controller 315 can detect errors by checking the ECC bits of the read data and correct any detected errors.

[0071] The CPU 320 controls the overall operation of the authentication information processing module 300. Furthermore, the CPU 320 can process the original image into fingerprint information, encrypt the processed fingerprint information, and / or send the encrypted fingerprint information to the security module 400 via bus 301. For example, the CPU 320 can use the AES method to encrypt the processed fingerprint information.

[0072] Accelerator 330 can perform complex computations during image processing of the original image. For example, accelerator 330 can feed the original image into a convolutional neural network (CNN) to perform anti-spoofing computations on the image. Accelerator 330 may include adders and / or multipliers for CNN computations.

[0073] The first memory 340 may be a working memory, and as an example, it may store intermediate or result values ​​of the accelerator 330, and / or as another example, it may store data required by the CPU 320.

[0074] The authentication information processing module 300 may also include a sensor controller (FCON) 355 and spatial frequency response (SFR) units 365 and 367.

[0075] The sensor controller 355 can enable the biometric identification module 200 and / or control the peripheral circuitry 220 to receive raw images.

[0076] SFR units 365 and 367 can be connected to APB bridge 360 ​​via bus 302. For example, bus 302 can be implemented as an APB interface. APB bridge 360 ​​can convert APB data to AHB data and / or convert AHB data to APB data.

[0077] Sensor controller 355 can control SFR unit 367 via SFR unit 365. SFR unit 367 can preprocess the raw image, enabling CPU 320 and / or accelerator 330 to process the raw image. SFR unit 367 can adjust the sharpness of the received raw image based on, for example, an SFR algorithm.

[0078] The sensor controller 355 can store data obtained by processing the raw image received from the biometric recognition module 200 through the SFR unit 367, accelerometer 330, and / or CPU 320 in a second memory 350. The second memory 350 can store data in units that can be processed by the CPU 320 and / or accelerometer 330.

[0079] The first memory 340 and the second memory 350 can be volatile memory devices, such as dynamic random access memory (DRAM) and static random access memory (SRAM).

[0080] The authentication information processing module 300 may also include a serial peripheral interface (SPI) 370. SPI 370 may be an interface for connecting to external devices and for sending SPI signals (e.g., SCLK, CS, MOSI, MISO, etc.) and / or receiving SPI signals from external devices. For example, SPI 370 may be connected to an extended external fingerprint sensor.

[0081] Figure 8 This is a diagram showing in more detail the interface between the security module and the authentication information processing module according to some example embodiments of this disclosure.

[0082] Reference Figure 5 , Figure 6 and Figure 8 The security module 400 meets security requirements greater than or equal to EAL5. The bus 401 and memories 430 and 470 in the security module 400 (see...) Figure 5 The data can be encrypted by the secure CPU 410 based on a random key. The fingerprint information of registered actual users can be encrypted and stored in non-volatile memory 430, thereby preventing exposure to the outside world.

[0083] Subsequently, when the fingerprint information used for verification needs to be authenticated, the security module 400 can determine whether the fingerprint information received via email 480 matches the registered fingerprint information stored in non-volatile memory 430, and determine whether to grant final permission.

[0084] Mailbox 480 may include a protocol changer 481, a mailbox controller 482, a memory (RAM) 483, and multiple multiplexers (MUX) MUX1, MUX2, and MUX3. In some embodiments, the multiple multiplexers (MUX) MUX1, MUX2, and MUX3 may be controlled by control signals CON1 and CON2.

[0085] The authentication information processing module 300 may also include a protocol changer 380 as an interface.

[0086] Protocol changer 380 can send the AHB signal used for communication between authentication information processing module 300 and mailbox 480 to protocol changer 481. Protocol changer 481 can activate and / or wake up multiple MUX1, MUX2, MUX3 and security CPU 410, causing security module 400 to perform authentication operations based on the received AHB signal.

[0087] The mailbox controller 482 may store usage status information and / or data size information. The mailbox controller 482 may include, for example, a status register and / or a size register, and may store usage status information in the status register and / or data size information in the size register. The usage status information may be information indicating whether the mailbox 480 is being used by the authentication information processing module 300, i.e., the communication status with the authentication information processing module 300. The data size information may be the size of the data sent to and / or received from the authentication information processing module 300.

[0088] The memory 483 may temporarily store data sent to and / or received from the authentication information processing module 300. The memory 483 may be a volatile memory, such as DRAM, SRAM, etc.

[0089] The security module 400 can check the communication status with the authentication information processing module 300 through the mailbox controller 482. When not in use, that is, when the authentication information processing module 300 does not use the mailbox 480 (i.e., the mailbox is empty), the mailbox 480 can check the size of the data to be sent, write the size information into the size register of the mailbox controller 482, store the data in the memory 483, and change the usage status information from an empty state to a send-ready state.

[0090] When mailbox 480 confirms the sending ready state, mailbox 480 can activate and / or wake up authentication information processing module 300, and mailbox 480 can enter standby state. Authentication information processing module 300 can read fingerprint information stored in second memory 350 and send the read fingerprint information to mailbox 480.

[0091] The mailbox 480 can store the read fingerprint information in the memory 483. The secure CPU 410 can send the fingerprint information stored in the memory 483 to the password engine 420.

[0092] Figure 9 This is a flowchart describing a method of operating a smart card according to some example embodiments of the present disclosure.

[0093] Reference Figure 9When communication with the payment terminal 2000 begins (S10), the smart card 1000 first receives payment request information from the payment terminal 2000 (S11). The security module 400 can activate and / or wake up the authentication information processing module 300 according to the payment request information and instruct the authentication information processing module 300 to sense biometric information (S12). The authentication information processing module 300 enables the biometric identification module 200 and allows the biometric identification module 200 to sense and / or scan fingerprints (S13 and S14). The biometric identification module 200 confirms whether the card user's finger is detected, and when a finger is detected, the biometric identification module 200 senses and / or scans the fingerprint (S15) and sends the original image (S16). The authentication information processing module 300 preprocesses the original image using a CPU and accelerator, and then generates fingerprint information for verification, including a template, etc. (S17). The fingerprint information used for verification is sent to the security module 400 (S18), and the security module 400 determines whether the registered fingerprint information matches the fingerprint information used for verification, and determines whether the card user is the same as the registered user (S19). When it is determined that the card user is the same as the registered user, a usage permission notification for the payment request information is sent to the payment terminal, and when it is determined that the card user is not the same as the registered user, a usage disallowance notification for the payment request information is sent to the payment terminal (S23). The usage permission / disallowance notification can also be displayed by illuminating a light-emitting diode (LED) or the like (e.g., on the smart card 1000) via an indicator controller (S20 to S22).

[0094] Although exemplary embodiments of the present disclosure have been described with reference to the accompanying drawings, those skilled in the art will understand that various modifications can be made without departing from the scope of the disclosure and without changing its essential characteristics. Therefore, the above exemplary embodiments should be understood as examples and not limitations.

Claims

1. A smart card, comprising: Peripheral circuitry, configured to control the fingerprint sensing array and generate the original image; An authentication information processing module is configured to process the original image into fingerprint information for verification. A security module is configured to determine whether the fingerprint information used for verification matches registered fingerprint information in order to determine whether the payment request is authorized or not. as well as An active shielding element that overlaps with the security module. The peripheral circuit, the authentication information processing module, and the security module are integrated into a single chip. The security module includes a mailbox located beneath the active shield and configured to communicate with the authentication information processing module. The mailbox stores usage status information and data size information. The usage status information indicates the communication status with the authentication information processing module, and the data size information is the size of the data sent to and / or received from the authentication information processing module.

2. The smart card as described in claim 1, wherein, The active shielding includes multiple signal lines that extend in a first direction in a plane parallel to the surface of the smart card and are spaced apart from each other at predetermined intervals and are parallel to each other. The security module includes a first side logic and a second side logic extending in a second direction perpendicular to the first direction in a plane parallel to the surface of the smart card. The first side logic and the second side logic intersect with the end of each of the plurality of signal lines to be electrically connected to each of the plurality of signal lines.

3. The smart card as described in claim 2, wherein, The security module also includes: A first non-volatile memory, configured to store the registered fingerprint information; and A secure central processing unit is configured to compare the fingerprint information used for verification with the registered fingerprint information, and determine whether to grant or deny use based on the comparison result. The first non-volatile memory and the secure central processing unit are located below the active shield.

4. The smart card as described in claim 2, wherein, The security module also includes: A cryptographic engine configured to encrypt and / or decrypt data sent to and / or received from outside the security module; and A first memory, configured to store encrypted and / or decrypted data, and The first memory and the cryptographic engine are located below the active shield.

5. The smart card as described in claim 1, wherein, The email address is also configured as follows: Check the size of the data to be sent and enter the send-ready state; Activate the authentication information processing module, causing the security module to enter standby mode; and The fingerprint information used for verification is received from the authentication information processing module.

6. The smart card as claimed in claim 1, wherein, The authentication information processing module includes: A second memory is configured to receive and store the original image; An accelerator configured to perform convolutional neural network computations on the original image; A third memory is configured to store intermediate and / or result values ​​calculated by the convolutional neural network; and A central processing unit is configured to process the original image into the registered fingerprint information based on the result value.

7. The smart card as described in claim 6, wherein, The authentication information processing module further includes a spatial frequency response unit, which is configured to preprocess the original image and store the preprocessed original image in the second memory.

8. The smart card according to claim 6, wherein, The authentication information processing module also includes a serial peripheral interface configured to connect to an external device.

9. A smart card based on biometric authentication, comprising a single chip, in, The single chip includes: Peripheral circuitry of biometric sensors; Authentication information processing module; and Security module, and The security module overlaps with the active shielding component. The security module includes a mailbox located beneath the active shield and configured to communicate with the authentication information processing module. The mailbox stores usage status information and data size information. The usage status information indicates the communication status with the authentication information processing module, and the data size information is the size of the data sent to and / or received from the authentication information processing module.

10. The smart card as claimed in claim 9, wherein, The security module includes: The active shielding includes a plurality of signal lines extending in a first direction in a plane parallel to the surface of the smart card and spaced apart from each other at predetermined intervals and parallel to each other; and First-side logic and second-side logic extend in a plane parallel to the surface of the smart card in a second direction perpendicular to the first direction, and intersect with the opposite ends of each of the plurality of signal lines to be electrically connected to each of the plurality of signal lines.

11. The smart card as claimed in claim 9, wherein, The peripheral circuitry is configured to control the biometric sensor to generate the original image. The authentication information processing module is configured to process the original image into fingerprint information for verification. The security module is configured to determine whether the registered fingerprint information matches the fingerprint information used for verification, and output permission or denial to the terminal based on the determination result.

12. The smart card as claimed in claim 11, wherein, The security module includes: A cryptographic engine configured to encrypt and / or decrypt data sent to and / or received from the security module; and The first memory is configured to store encrypted and / or decrypted data.

13. The smart card as claimed in claim 12, wherein, The email address is also configured as follows: Check the size of the data to be sent; Entering the transmission ready state; Activate the authentication information processing module, causing the security module to enter standby mode; and The fingerprint information used for verification is received from the authentication information processing module.

14. The smart card as claimed in claim 13, wherein, The cryptographic engine is also configured to encrypt the fingerprint information used for verification, and The security module is further configured to determine whether the encrypted fingerprint information used for verification matches the registered fingerprint information.

15. The smart card as claimed in claim 11, wherein, The authentication information processing module includes: A second memory is configured to receive and store the original image; An accelerator configured to perform convolutional neural network computations on the original image; A third memory is configured to store intermediate and / or result values ​​calculated by the convolutional neural network; and A central processing unit is configured to process the original image into the registered fingerprint information based on the result value.

16. The smart card as claimed in claim 9, wherein, The authentication information processing module includes a serial peripheral interface configured to connect to an external device.

17. A smart card, comprising: Analog circuitry configured to control biometric sensors to generate raw images; An authentication information processing module is configured to preprocess the original image and process the preprocessed original image into fingerprint information for verification. as well as The security module is configured to compare the fingerprint information used for verification with registered fingerprint information and output the authorization determination result of the payment request to the terminal. The analog circuit, the authentication information processing module, and the security module are integrated into a single chip. The security module includes an email address configured to communicate with the authentication information processing module. The mailbox stores usage status information and data size information. The usage status information indicates the communication status with the authentication information processing module, and the data size information is the size of the data sent to and / or received from the authentication information processing module.

18. The smart card as claimed in claim 17, wherein, The security module includes: An active shielding element comprising multiple signal lines overlapping the security module, the signal lines extending in a first direction in a plane parallel to the surface of the smart card and spaced apart from each other at predetermined intervals to be parallel to each other; and First-side logic and second-side logic extend in a plane parallel to the surface of the smart card in a second direction perpendicular to the first direction, and intersect with the opposite ends of each of the plurality of signal lines to be electrically connected to each of the plurality of signal lines.

19. The smart card as claimed in claim 17, wherein, The authentication information processing module and the security module each include a protocol changer, which is configured to send and receive Advanced High Performance Bus (AHS) signals to and from each other. The mailbox is configured to be activated based on an Advanced Performance Bus (APB) signal; the security module also includes: A cryptographic engine configured to encrypt the fingerprint information received from the mailbox for verification; and A secure central processing unit is configured to compare encrypted fingerprint information for verification with the registered fingerprint information and output a permission determination result.