Biometric authentication method and device based on cloud phone, cloud phone platform and storage medium
By calling the terminal's biometric authentication hardware on the cloud phone platform and generating a virtual image and sub-key, the security of biometric authentication on the cloud phone platform and the "one device, one key" problem are solved, and the effectiveness of secure data storage and authentication is achieved.
Patent Information
- Application Number
- CN202111628730.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-28
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2041-12-28
AI Technical Summary
Cloud phone platforms cannot effectively implement biometric authentication, especially in terms of security and the "one device, one password" authentication method, and the security of user biometric data is difficult to guarantee.
By receiving requests from authentication service providers on the cloud phone platform, calling the terminal-side biometric authentication hardware, collecting and storing biometric features in the terminal's secure storage area, generating a virtual image for biometric authentication, and using a key to generate at least two levels of sub-keys for authentication, ensuring data security and a "one device, one key" mechanism.
It enables secure storage and authentication of biometric data on cloud phone platforms, prevents information leakage, meets the "one device, one password" authentication requirement, and protects user privacy and the security of authentication services.
Smart Images

Figure CN114297603B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of communication technology, in particular to a biological feature authentication method and device based on a cloud mobile phone, a cloud mobile phone platform and a storage medium. BACKGROUND
[0002] With the continuous improvement of mobile network speed, application and service cloudization has become a trend, and the cloud mobile phone is an implementation way of operating system level cloudization. The cloud mobile phone is a virtual mobile phone built on a cloud server, and the cloud mobile phone platform can install and run mobile phone application software, and users can operate the virtual mobile phone on the server through a computer or mobile phone client.
[0003] Due to the characteristics of being on the server side, the cloud mobile phone platform becomes a bottleneck for calling the hardware functions of the user side mobile phone, especially the fingerprint function related to security authentication. The cloud mobile phone platform needs to cooperate with the fingerprint hardware device on the user side to complete the authentication functions such as unlocking and payment, which is very difficult to implement. Moreover, when the cloud mobile phone platform, as an independent mobile phone system, performs some biological feature unlocking, such as fingerprint unlocking or fingerprint payment authentication operation, in order to improve security, not only the fingerprint feature matching verification is needed, but also it is necessary to determine that the operation is carried out in the current mobile phone through the network server, that is, the so-called "one machine one secret" authentication method. This method is more secure, but it cannot be applied to the existing cloud mobile phone platform. SUMMARY
[0004] The embodiments of the present application provide a biological feature authentication method and device based on a cloud mobile phone, a cloud platform server and a storage medium, to solve the technical problem that the cloud mobile phone cannot realize biological feature authentication in the prior art.
[0005] In a first aspect, the embodiments of the present application provide a biological feature authentication method based on a cloud mobile phone, comprising:
[0006] receiving a biological feature authentication service request sent by an authentication service provider;
[0007] According to the biological feature authentication service request, an authentication collection instruction is issued to the terminal to call the biological feature authentication hardware on the terminal side, and the collected biological feature is stored in the secure storage area of the terminal;
[0008] receiving a biological feature authentication virtual image sent by the terminal, the biological feature authentication virtual image comprising part of the biological feature parameters;
[0009] sending biological feature authentication service completion information to the authentication service provider, and receiving a key sent by the authentication service provider, the key corresponding to a public key allocated by the authentication service provider to the cloud mobile phone platform, and generating at least two levels of multiple sub-keys according to the key.
[0010] In a second aspect, the embodiments of the present application further provide a biometric authentication device based on a cloud mobile phone, comprising:
[0011] An authentication service request receiving module is configured to receive a biometric authentication authentication service request sent by an authentication service provider;
[0012] An issuing module is configured to issue a biometric authentication collection instruction to a terminal according to the biometric authentication authentication service request, to call a biometric authentication hardware on the terminal side, and to store the collected biometric features in a secure storage area of the terminal;
[0013] A virtual image receiving module is configured to receive a biometric authentication virtual image sent by the terminal, wherein the biometric authentication virtual image comprises partial biometric feature parameters;
[0014] A key receiving module is configured to send biometric authentication authentication service completion information to the authentication service provider, and to receive a key sent by the authentication service provider, wherein the key corresponds to a public key allocated to the cloud mobile phone platform by the authentication service provider, and at least two levels of multiple sub-keys are generated according to the key.
[0015] In a third aspect, the embodiments of the present application further provide a server, comprising:
[0016] One or more processors;
[0017] A storage device configured to store one or more programs,
[0018] When the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the biometric authentication method based on a cloud mobile phone provided by the above-mentioned embodiments.
[0019] In a fourth aspect, the embodiments of the present application further provide a storage medium containing computer executable instructions, which, when executed by a computer processor, are used to perform the biometric authentication method based on a cloud mobile phone provided by the above-mentioned embodiments.
[0020] The biological feature authentication method, device, cloud platform server and storage medium based on the cloud mobile phone provided by the embodiment of the application, by receiving the biological feature authentication service request sent by the authentication service provider, calling the biological feature collection hardware device in the terminal to collect the biological feature of the user, and storing the collected biological feature information in the secure storage area of the terminal. The terminal can generate a biological feature authentication virtual image according to the collected biological feature information, and the biological feature authentication image only has part of the trusted biological feature information. The security problem caused by the leakage of the biological privacy information of the user can be prevented. The biological feature authentication service completion information is sent to the authentication service provider. The authentication service provider distributes the public key of the cloud mobile phone platform using the root key of itself according to the authentication service completion information sent by the cloud mobile phone, and sends the key to the cloud mobile phone platform. The cloud mobile phone platform can generate at least two levels of multiple sub-keys according to the key. The purpose of transmitting the corresponding authentication data in the authentication service using the corresponding key in the later stage is achieved. Not only the security of the biological feature data of the user is effectively ensured, but also the corresponding "one machine one key" mechanism can be realized in the cloud mobile phone, which meets the corresponding requirements of the authentication service provider. BRIEF DESCRIPTION OF DRAWINGS
[0021] Other features, objects, and advantages of the application will become more apparent from the following detailed description of non-limiting embodiments when read in conjunction with the accompanying drawings:
[0022] Figure 1 is a flowchart of the biological feature authentication method based on the cloud mobile phone provided by the embodiment one of the application;
[0023] Figure 2 is a flowchart of the biological feature authentication method based on the cloud mobile phone provided by the embodiment two of the application;
[0024] Figure 3 is a flowchart of the biological feature authentication method based on the cloud mobile phone provided by the embodiment three of the application;
[0025] Figure 4 is a structural diagram of the biological feature authentication device based on the cloud mobile phone provided by the embodiment four of the application;
[0026] Figure 5 is a structural diagram of the cloud mobile phone platform provided by the embodiment five of the application. DETAILED DESCRIPTION
[0027] The application will be further described in conjunction with the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the application, but not to limit the application. In addition, it should be noted that, for the convenience of description, only the parts related to the application are shown in the drawings, not all the structures.
[0028] Embodiment one
[0029] Figure 1 is a flowchart of a biological feature authentication method based on a cloud mobile phone provided by an embodiment of the present application. The embodiment can be applied to the case of implementing biological feature authentication by using a cloud mobile phone platform. The method can be executed by a biological feature authentication device based on a cloud mobile phone and can be integrated into a cloud mobile phone platform server. The method specifically includes the following steps:
[0030] S110, receiving a biological feature authentication certification service request sent by an authentication service provider.
[0031] How to accurately identify the identity of a person and protect information security has become a key social problem that must be solved. Traditional identity authentication is increasingly difficult to meet the needs of society due to its easy forgery and loss. The most convenient and secure solution is undoubtedly biological recognition technology. It is not only simple and fast, but also safe, reliable and accurate for identity identification. At the same time, it is easier to integrate with computers and security, monitoring and management systems to achieve automated management. Biological feature recognition (BIOMETRICS) technology refers to the use of computers to identify the identity of individuals by using physiological characteristics (fingerprint, iris, face, DNA, etc.) or behavioral characteristics (gait, keystroke habits, etc.) inherent to the human body. Since the biological features of each person are unique and stable over a certain period of time, they are not easy to be forged and counterfeited. Therefore, biological recognition technology is safe, reliable and accurate for identity identification. Based on the above advantages, some APPs with high information security usually use biological features for authentication. When a user uses a cloud mobile phone platform, an authentication service provider will send a biological feature authentication certification service request to achieve the purpose of biological feature identity identification.
[0032] S120, according to the biological feature authentication certification service request, issuing an authentication collection instruction to the terminal to call the biological feature authentication hardware on the terminal side and storing the collected biological features in the secure storage area of the terminal.
[0033] Since the cloud phone platform is a virtual phone running in the cloud, it can install and run the application software of the phone, but it does not have the ability to use the terminal side hardware. For example: it cannot use the terminal's camera, GPS and other hardware. Therefore, when receiving the authentication service request, the terminal can be instructed to collect the authentication through the network. That is, the corresponding hardware in the terminal is regarded as part of the cloud phone. Through the terminal executable instruction, the terminal side biometric authentication hardware is called. When the terminal receives the authentication collection instruction, it can use various hardware provided by the terminal, such as fingerprint collection device, image collection device, etc., to collect fingerprints, iris, lip membrane and portrait biometrics. At the same time, in order to ensure the safety and effectiveness of the collected biometric features, the collected biometric features are not uploaded to the cloud phone platform, but are kept in the local secure storage area of the terminal. In addition, the terminal's computing power can also be used to generate a biometric authentication virtual image. Specifically, the cloud phone platform can issue corresponding algorithms and set a reserved parameter interface. The terminal forms corresponding parameters according to its own characteristics, such as local IMEI number, or current time or first registration time, etc. to generate a biometric authentication virtual image. The secure storage area can be formed after isolating all SoC hardware and software resources. Using hardware logic can ensure that ordinary area components cannot access secure area resources, thereby building a strong boundary between the two areas. The design of placing sensitive resources in the secure area and reliably running software in the secure processor core can ensure that assets can resist a large number of potential attacks, including those that are usually difficult to protect (for example, using keyboard or touch screen to input password).
[0034] S130, receiving the biometric authentication virtual image sent by the terminal, the biometric authentication virtual image including part of the biometric feature parameters.
[0035] In this embodiment, the collected biometric information usually exists in the form of an image. Although the complete biometric authentication virtual image is saved in the secure storage area of the terminal for security considerations. But the cloud phone platform is convenient for biometric verification of the terminal which does not store biometric information in the later stage. Therefore, the terminal will send the biometric authentication virtual image to the cloud phone platform. The biometric authentication virtual image includes part of the biometric feature parameters. In order to facilitate the effective verification of the input biometric information by the terminal when the user replaces the terminal.
[0036] S140, sending biometric authentication service completion information to the authentication service provider, and receiving the key sent by the authentication service provider, the key corresponding to the public key allocated by the authentication service provider to the cloud phone platform, and generating at least two levels of multiple sub-keys according to the key.
[0037] After receiving the biometric authentication virtual image sent by the terminal, it can be determined that the biometric collection of the calling terminal has been completed. Therefore, the biometric authentication service completion information is sent to the authentication service. The authentication server is equipped with a TPM. Each TPM uniquely corresponds to a root key, which is the source of this key system. Therefore, the security of the root key is the foundation and guarantee of the security of the key system. Once the root key is leaked, it will cause significant losses to the user. The root key can be used to assign a corresponding public key to each terminal. Correspondingly, the corresponding public key is also assigned to the mobile cloud platform. The corresponding secret key is then obtained based on the public key. The secret key is sent to the mobile cloud platform to transmit the corresponding biometric verification results.
[0038] The biggest difference between the cloud phone platform and other terminals is that it does not include the actual hardware structure, such as the biometric collection device. This means that the biometric collection device of the terminal accessed by the cloud phone platform may be completely different each time. Therefore, after receiving the secret key, the cloud phone platform can use the subkey generator to generate multiple secondary subkeys, which are used to match each terminal accessed.
[0039] This embodiment, upon receiving a biometric authentication service request from an authentication service provider, invokes the biometric collection hardware in the terminal to collect the user's biometrics and stores the collected biometric information in the terminal's secure storage area. Based on the collected biometric information, the terminal generates a biometric authentication virtual image containing only partially authentic biometric information. This prevents security issues caused by the leakage of the user's private biometric information. The terminal then sends a biometric authentication service completion message to the authentication service provider. Based on the authentication service completion message sent by the cloud phone, the authentication service provider uses its own root key to pseudo-assign a public key to the cloud phone platform and sends the key to the cloud phone platform. The cloud phone platform generates multiple subkeys at least two levels based on the key. This allows the corresponding keys to be used later in the authentication service to transmit the corresponding authentication data. This not only effectively ensures the security of the user's biometric data, but also implements a "one device, one secret" mechanism on the cloud phone, meeting the requirements of the authentication service provider.
[0040] Example 2
[0041] Figure 2A flowchart of the cloud phone-based biometric authentication method provided in Embodiment Two of the present application is shown. Embodiment Two is optimized based on the above-mentioned Embodiment One. In Embodiment Two, the method can further include the following steps: receiving a biometric authentication service request sent by an authentication service provider; sending a biometric authentication service request and a first sub-key to the terminal; receiving a biometric authentication result, which is generated by the terminal using the first sub-key according to a comparison result between the biometric feature in the secure storage area and the information collected by the biometric authentication hardware; and sending the biometric authentication result to the authentication service provider so that the authentication service provider determines whether to authorize based on the encrypted data.
[0042] Accordingly, the cloud phone-based biometric authentication method provided in the present embodiment specifically includes the following steps:
[0043] S210, receiving a biometric authentication service request sent by an authentication service provider.
[0044] S220, sending an authentication collection instruction to the terminal according to the biometric authentication service request to invoke the biometric authentication hardware on the terminal side and store the collected biometric feature in the secure storage area of the terminal.
[0045] S230, receiving a biometric authentication virtual image sent by the terminal, the biometric authentication virtual image including part of the biometric feature parameters.
[0046] S240, sending biometric authentication service completion information to the authentication service provider and receiving a key sent by the authentication service provider, the key corresponding to a public key allocated by the authentication service provider to the cloud phone platform, and generating a plurality of sub-keys of at least two levels according to the key.
[0047] S250, receiving a biometric authentication service request sent by an authentication service provider.
[0048] After the authentication is completed, when the biometric authentication needs to be invoked during the execution of an application program, for example, when logging in to WeChat or verifying payment, the authentication service provider corresponding to the application program sends an authentication service request to the cloud phone platform. The cloud phone platform receives the biometric authentication service request sent by the authentication service provider.
[0049] S260, sending a biometric authentication service request and a first sub-key to the current corresponding terminal.
[0050] Based on the biometric authentication service request, a biometric authentication service request is sent to the current corresponding terminal to complete the biometric authentication service using the biometric feature collection device of the terminal, and a first sub-key is sent to the terminal. The current corresponding terminal is the terminal corresponding to the user currently logged in to the cloud phone platform. The first sub-key is one of the secret keys generated above, and the first sub-key only corresponds to the current terminal.
[0051] S270, receiving a biometric authentication result, which is generated by the current corresponding terminal according to the comparison result of the biometric feature in the secure storage area and the information collected by the biometric authentication hardware using the first sub-key.
[0052] In this embodiment, the current corresponding terminal is the terminal corresponding to the user currently logged in to the cloud phone platform. When the current corresponding terminal and the terminal of the aforementioned biometric authentication service are the same terminal, since the current corresponding terminal has the corresponding biometric feature information in the secure storage area, the biometric feature information collected at this time can be compared with the corresponding biometric feature information in the secure storage area, and a corresponding comparison result can be generated. The comparison result is encrypted using the first sub-key, and the encrypted data is sent to the cloud phone platform as the biometric authentication result.
[0053] S280, sending the biometric authentication result to the authentication service provider to determine whether to authorize according to the encrypted data.
[0054] Correspondingly, the cloud phone platform receives the biometric authentication result, which can be directly sent to the authentication service provider to determine whether to authorize according to the biometric authentication result. Complete the corresponding login or payment.
[0055] The embodiment adds the following steps: receiving a biometric authentication service request sent by an authentication service provider; sending the biometric authentication service request and a first sub-key to the terminal; receiving a biometric authentication result, which is generated by the terminal according to a comparison result of the biometric feature in the secure storage area and information collected by the biometric authentication hardware using the first sub-key; and sending the biometric authentication result to the authentication service provider, so that the authentication service provider determines whether to authorize according to the encrypted data. When the terminal carrier corresponding to the cloud phone platform is authenticated by the authentication service, the input biometric feature collected by the terminal is called, and the input biometric feature is compared and verified with the biometric feature information stored in the secure storage area of the terminal. The verification result is encrypted by the first sub-key sent by the cloud phone platform and uniquely matched with the current terminal, and then sent to the authentication service provider, thereby fully meeting the biometric authentication requirement of “one machine one encryption”. The biometric authentication in the cloud phone platform is realized. At the same time, the user's private biometric feature information will not be transmitted through the network, thereby ensuring the security of the user's private biometric feature information.
[0056] Embodiment three
[0057] Figure 3 The flowchart of the biometric authentication method based on the cloud phone provided in the third embodiment of the application is shown. The embodiment is optimized based on the above-mentioned embodiments. In the embodiment, the biometric authentication result is specifically optimized as follows: receiving biometric authentication information; sending the biometric authentication virtual image and a second sub-key to the terminal; and receiving a biometric authentication result, which includes information generated by the terminal according to a comparison result of the biometric authentication virtual image and information collected by the biometric authentication hardware and part of the feature information using the second sub-key, wherein the second sub-key is generated according to the terminal and uniquely corresponds to the terminal.
[0058] Correspondingly, the biometric authentication method based on the cloud phone provided in the embodiment specifically includes the following steps:
[0059] S310, receiving a biometric authentication service request sent by an authentication service provider.
[0060] S320, issuing an authentication collection instruction to the terminal according to the biometric authentication service request, so as to call the biometric authentication hardware on the terminal side and store the collected biometric feature in the secure storage area of the terminal.
[0061] S330, receiving a biometric authentication virtual image sent by the terminal, wherein the biometric authentication virtual image includes part of the biometric feature parameters.
[0062] S340, sending the biometric authentication service completion information to the authentication service provider, and receiving the key sent by the authentication service provider, the key corresponding to the public key allocated by the authentication service provider to the cloud mobile platform, and generating at least two levels of multiple sub-keys according to the key.
[0063] S350, receiving the biometric authentication service request sent by the authentication service provider.
[0064] S360, sending the biometric authentication service request and the first sub-key to the current corresponding terminal.
[0065] S370, receiving the biometric authentication information, and sending the biometric authentication virtual image and the second sub-key to the terminal.
[0066] In the embodiment, the current corresponding terminal can not be the same terminal as the terminal that has performed the biometric authentication service before. There is no responsive biometric information in the secure storage area of the terminal. Therefore, the terminal cannot complete the authentication. The terminal sends the authentication failure information to the cloud mobile platform. After receiving the biometric authentication failure information, the cloud mobile platform determines that the current corresponding terminal is not the terminal that has performed the biometric authentication service, and therefore sends the biometric authentication virtual image obtained in the authentication process to the terminal, so that the terminal performs biometric authentication using the biometric authentication virtual image. Optionally, the biometric authentication virtual image includes part of the real and valid information. The biometric authentication virtual image can be divided into two types, one of which provides part of the position and image matching information. The other is to scramble and regenerate the position and image feature correspondence. In the verification, whether the provided part of the information or the corresponding position has special features can be verified.
[0067] At the same time, since the terminal is different from the original terminal, it is equivalent to another terminal, and therefore the cloud mobile platform sends the second sub-key to it, so that the sent key is uniquely matched with each terminal.
[0068] S380, receiving the biometric authentication result, the biometric authentication result including the comparison result of the biometric authentication virtual image and the information collected by the biometric authentication hardware of the terminal, and the information encrypted by the second sub-key using part of the feature information, the second sub-key being generated according to the terminal and uniquely corresponding to the terminal.
[0069] In this embodiment, the terminal can compare the collected information with the received biometric authentication virtual image. If the biometric authentication virtual image contains partial matching information, the terminal determines whether the matching degree between the collected image and the biometric authentication virtual image exceeds a matching threshold. If the matching threshold is exceeded, the match is considered successful. If the biometric authentication virtual image is shuffled and regenerated, a random portion of the image is selected to determine whether the feature exists at that location. Based on this, the authentication result is determined. The authentication result is encrypted using the second subkey and sent to the cloud phone platform.
[0070] S390: Send the biometric authentication result to an authentication service provider, so that the authentication service provider determines whether to authorize based on the encrypted data.
[0071] This embodiment optimizes the process of receiving a biometric authentication result to include: receiving information indicating that biometric authentication is unavailable; sending the biometric authentication virtual image and the second subkey to the terminal; and receiving a biometric authentication result, wherein the biometric authentication result includes a comparison result between the terminal and information collected by the biometric authentication hardware based on the biometric authentication virtual image, and information encrypted using the second subkey, wherein the second subkey is generated based on the terminal and uniquely corresponds to the terminal. When the current terminal is not a terminal performing biometric authentication services, authentication can be performed using the biometric authentication virtual image. Since the biometric authentication virtual image only contains a small portion of the user's biometric features, information leakage can be prevented during transmission, ensuring the security of the user's private data while achieving authentication.
[0072] In a preferred implementation of this embodiment, the process of sending the encrypted data to the authentication service provider can be specifically optimized to include sending the encrypted comparison result and partial feature comparison information to the authentication service provider, so that the authentication service provider can use an AI algorithm to determine whether to grant authorization based on the comparison result and partial comparison information. Since the authentication result can only be determined by comparing the biometric authentication virtual image with the collected biometric features, errors may occur. Therefore, in this embodiment, the terminal can encrypt the comparison result and partial feature information using the second subkey and send them to the cloud phone platform. The cloud phone platform forwards them to the authentication service provider, which can then construct an AI model based on the corresponding biometric features. By determining the likelihood of biometric features occurring nearby at certain locations, or the likelihood of the conspirator's image features appearing at the corresponding locations, the authentication service provider can then determine whether to grant authorization. This further improves the accuracy of authentication when no biometric features are stored. Furthermore, since only a small amount of data is transmitted, the security of user privacy data can be guaranteed.
[0073] Example 4
[0074] Figure 4 is a structural schematic diagram of a cloud phone-based biometric authentication device provided by Embodiment Four of the present application, as shown in the figure, the device comprises: Figure 4
[0075] An authentication service request receiving module 410 is configured to receive a biometric authentication authentication service request sent by an authentication service provider;
[0076] An issuing module 420 is configured to issue a biometric authentication collection instruction to a terminal according to the biometric authentication authentication service request, so as to call a biometric authentication hardware on the terminal side, and store the collected biometric features in a secure storage area of the terminal;
[0077] A virtual image receiving module 430 is configured to receive a biometric authentication virtual image sent by the terminal, wherein the biometric authentication virtual image comprises part of the biometric feature parameters;
[0078] A key receiving module 440 is configured to send biometric authentication authentication service completion information to the authentication service provider, and receive a key sent by the authentication service provider, wherein the key corresponds to a public key allocated by the authentication service provider to the cloud phone platform, and at least two levels of multiple sub-keys are generated according to the key.
[0079] The cloud phone-based biometric authentication device provided by the embodiment, by receiving a biometric authentication authentication service request sent by an authentication service provider, calling a biometric feature collection hardware device in a terminal to collect biometric features of a user, and storing the collected biometric feature information in a secure storage area of the terminal, the terminal can generate a biometric authentication virtual image according to the collected biometric feature information, and the biometric authentication image only has part of the trusted biometric feature information. It can prevent security problems caused by leakage of the user's biometric privacy information. And send biometric authentication authentication service completion information to the authentication service provider. The authentication service provider generates a public key for the cloud phone platform using its own root key according to the authentication authentication service completion information sent by the cloud phone, and sends the key to the cloud phone platform. The cloud phone platform can generate at least two levels of multiple sub-keys according to the key. The purpose of transmitting corresponding authentication data in the authentication service using the corresponding key in the later stage is achieved. Not only does it effectively ensure the security of the user's biometric feature data, but also it can implement the corresponding "one machine one key" mechanism in the cloud phone, which meets the corresponding requirements of the authentication service provider.
[0080] On the basis of the above-mentioned embodiments, the device further comprises:
[0081] An authentication service request receiving module is configured to receive a biometric authentication service request sent by an authentication service provider;
[0082] The authentication service request sending module is configured to send a biometric authentication service request and a first sub-key to a current corresponding terminal.
[0083] The biometric authentication result receiving module is configured to receive a biometric authentication result, which is encrypted by the first sub-key according to a comparison result of the biometric feature in the secure storage area and information collected by the biometric authentication hardware.
[0084] The biometric authentication result sending module is configured to send the biometric authentication result to an authentication service provider, so that the authentication service provider determines whether to authorize according to the encrypted data.
[0085] On the basis of the above embodiments, the biometric authentication result receiving module comprises:
[0086] The biometric authentication result receiving module comprises:
[0087] The biometric authentication virtual image sending unit is configured to send the biometric authentication virtual image and a second sub-key to a terminal.
[0088] The biometric authentication result receiving unit is configured to receive a biometric authentication result, which comprises information encrypted by the second sub-key according to a comparison result of the biometric authentication virtual image and information collected by the biometric authentication hardware and partial feature information, the second sub-key is generated according to the terminal and uniquely corresponds to the terminal.
[0089] On the basis of the above embodiments, the biometric authentication result sending module comprises:
[0090] The partial feature comparison information sending unit is configured to send the encrypted comparison result and partial feature comparison information to the authentication service provider, so that the authentication service provider determines whether to authorize according to the comparison result and partial comparison information using an AI algorithm.
[0091] On the basis of the above embodiments, the biometric authentication virtual image comprises:
[0092] The image generated by randomly selecting a point in the biometric image and corresponding image features is taken as the biometric authentication virtual image.
[0093] On the basis of the above embodiments, the biometric authentication virtual image comprises:
[0094] The image generated by randomly combining a point in the biometric image and corresponding image features is taken as the biometric authentication image.
[0095] In the above embodiments, the biometric feature comprises:
[0096] Fingerprint, iris, and lip print.
[0097] The cloud mobile phone based biometric authentication device provided by the embodiments of the present application can execute the cloud mobile phone based biometric authentication method provided by any of the embodiments of the present application, and has the function modules and beneficial effects corresponding to the execution method.
[0098] Embodiment five
[0099] Figure 5 A structural schematic diagram of a cloud mobile phone platform provided for the embodiment five of the present application. Figure 5 A block diagram of an exemplary cloud mobile phone platform 12 suitable for implementing embodiments of the present application is shown. Figure 5 The shown cloud mobile phone platform 12 is merely an example, and should not bring any limitation to the function and use range of the embodiments of the present application.
[0100] As Figure 5 shown, the cloud mobile phone platform 12 is in the form of a general computing device. The components of the cloud mobile phone platform 12 can include, but are not limited to, one or more processors or processing units 16, a system memory 28, and a bus 18 that couples various system components including the system memory 28 and the processing unit 16.
[0101] The bus 18 represents one or more of any of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration bus, a processor or local bus using any of a variety of bus architectures. By way of example, these architectures include Industry Standard Architecture (ISA) bus, Micro Channel Architecture (MAC) bus, Enhanced ISA bus, Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI) bus.
[0102] The cloud mobile phone platform 12 typically includes a variety of computer system readable media. These media can be any available media that is accessible by the cloud mobile phone platform 12 and includes both volatile and non-volatile media, removable and non-removable media.
[0103] The system memory 28 can include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. The cloud mobile phone platform 12 can further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, a storage system 34 can be provided for reading from and writing to non-removable, non-volatile magnetic media (e.g., a "hard drive"). Figure 5 Not shown, is an example, a magnetic hard disk drive for reading from and writing to non-removable, non-volatile magnetic media (e.g., a "hard drive"). Although not specifically shown, such computer system readable media can also include, by way of example, a solid state device such as a flash memory or other memory device, or a magnetic disk that can be read from or written to a removable, non-volatile media. Figure 5A disk drive, a floppy disk drive, a CD-ROM drive, a DVD-ROM drive, or other removable media drive, a flash memory card drive (such as a compact flash drive), and a tape drive, a tape drive, a tape backup device, or any other storage device, which can be provided, can be included in the computing device 10, can be provided, and coupled to bus 18, by any means as will be readily apparent to those of skill in the art. A user can enter commands and information into the computing device 10, through input device(s) 12, such as a keyboard and pointing device, commonly utilized
[0104] Program / utility 40 having a set (at least one) of program modules 42 can be stored in memory 28 by way of example, and not limitation, as well as an operating system, one or more application programs, other program modules, and program data, each or some combination thereof, can include implementation of the network environment in each or some combination of these examples. Program modules 42 generally carry out the functions and / or methodologies of embodiments of the application as described herein.
[0105] Cloud phone platform 12 can also be communicatively coupled to one or more external devices 14, such as a keyboard, a pointing device, a display 24, etc.; can further be communicatively coupled to one or more devices that enable a user to interact with cloud phone platform 12; and / or one or more devices that enable cloud phone platform 12 to communicate with one or more other computing devices. Such communication can be via input / output (I / O) interface(s) 22. Similarly, such communication can be via network adaptor 20 to one or more networks, such as a local area network (LAN), a wide area network (WAN), and / or the Internet, as examples. Network adaptor 20 can be any type of adapter to enable coupling to a networked environment, such as an Ethernet adapter, a modem, etc. As will be appreciated by one of ordinary skill in the art having the benefit of this disclosure, one or more other input / output devices 14 can be used with computing device 10, such as a printer, a scanner, a pen input device, a microphone, a camera, a video camera, etc.
[0106] Processing unit(s) 16 can execute instructions stored in system memory 28 to perform various functions as described herein, such as implementing cloud phone based biometric authentication methods.
[0107] Embodiment Six
[0108] Embodiment Six of the present application also provides a storage medium containing computer executable instructions, which when executed by a computer processor, perform a cloud phone based biometric authentication method as provided by the above embodiments.
[0109] The computer storage medium of the embodiment of the present invention may adopt any combination of one or more computer-readable media. The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or component, or any combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, device or device.
[0110] A computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0111] Program code embodied on a computer readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0112] Computer program code for performing the operations of the present invention may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0113] Note that the above merely describes preferred embodiments of the present application and the principles of the technology applied. Those skilled in the art will understand that the present application is not limited to the specific embodiments described herein, and that various obvious changes, modifications and substitutions can be made without departing from the scope of the present application. Therefore, although the present application has been described in detail through the above embodiments, the present application is not limited to the above embodiments, and can include more other equivalent embodiments without departing from the concept of the present application, and the scope of the present application is determined by the scope of the claims.
Claims
1. A biometric authentication method based on cloud mobile phone, characterized in that: include: Receive biometric authentication service requests sent by authentication service providers; According to the biometric authentication service request, an authentication collection instruction is issued to the terminal to call the biometric authentication hardware on the terminal side and store the collected biometrics in a secure storage area of the terminal; Receiving a biometric authentication virtual image sent by a terminal, wherein the biometric authentication virtual image includes part of the biometric parameters; Sending biometric authentication service completion information to the authentication service provider, and receiving a key sent by the authentication service provider, wherein the key corresponds to a public key assigned by the authentication service provider to the cloud phone platform, and generating multiple subkeys of at least two levels based on the key; Receive biometric authentication service requests sent by authentication service providers; Sending a biometric authentication service request and the first subkey to the current corresponding terminal; Receiving a biometric authentication result, the biometric authentication result being generated by the current corresponding terminal by encrypting using the first subkey based on a comparison result of the biometric in the secure storage area with information collected by the biometric authentication hardware; The biometric authentication result is sent to an authentication service provider, so that the authentication service provider determines whether to authorize based on the encrypted data.
2. The method according to claim 1, characterized in that Receiving a biometric authentication result includes: The biometric feature cannot be used to authenticate the information received; Sending the biometric authentication virtual image and the second subkey to the terminal; Receive a biometric authentication result, where the biometric authentication result includes a comparison result between the terminal and information collected by the biometric authentication hardware based on the biometric authentication virtual image and information generated by encrypting part of the feature information using a second subkey, where the second subkey is generated based on the terminal and uniquely corresponds to the terminal.
3. The method according to claim 2, characterized in that The sending of the biometric authentication result to the authentication service provider includes: The encrypted comparison result and part of the feature comparison information are sent to the authentication service provider, so that the authentication service provider uses the AI algorithm to determine whether to authorize based on the comparison result and part of the comparison information.
4. The method according to claim 1, wherein The biometric authentication virtual image includes: The image features corresponding to randomly selected points in the biometric image are used to generate an image as a virtual image for biometric authentication.
5. The method according to claim 2, characterized in that The biometric authentication virtual image includes: The image generated by randomly combining the midpoints of the biometric image and the corresponding image features is used as the biometric authentication image.
6. The method according to claim 4 or 5, characterized in that The biometric features include: One of fingerprint, iris and lip print.
7. A biometric authentication device based on a cloud phone, characterized in that: include: Authentication service request receiving module, used to receive biometric authentication service requests sent by authentication service providers; an issuing module, configured to issue a biometric authentication collection instruction to the terminal according to the biometric authentication service request, so as to invoke the biometric authentication hardware on the terminal side and store the collected biometrics in a secure storage area of the terminal; A virtual image receiving module, configured to receive a biometric authentication virtual image sent by a terminal, wherein the biometric authentication virtual image includes some biometric parameters; A key receiving module, configured to send biometric authentication service completion information to the authentication service provider, receive a key sent by the authentication service provider, wherein the key corresponds to a public key assigned by the authentication service provider to the cloud phone platform, and generate multiple subkeys of at least two levels based on the key; An authentication service request receiving module is used to receive a biometric authentication service request sent by an authentication service provider; An authentication service request sending module, configured to send a biometric authentication service request and a first subkey to the current corresponding terminal; A biometric authentication result receiving module, configured to receive a biometric authentication result, the biometric authentication result being generated by the current corresponding terminal by encrypting the biometric information in the secure storage area with the information collected by the biometric authentication hardware using the first subkey; The biometric authentication result sending module is used to send the biometric authentication result to the authentication service provider, so that the authentication service provider can determine whether to authorize based on the encrypted data.
8. A cloud phone platform, characterized in that: The cloud phone platform includes: one or more processors; a storage device for storing one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the cloud phone-based biometric authentication method as described in any one of claims 1-6.
9. A storage medium comprising computer-executable instructions, wherein the computer-executable instructions, when executed by a computer processor, are used to execute the biometric authentication method based on a cloud phone as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Service processing method, system and device based on cloud mobile phone, equipment and medium
CN113691602A
Biometric characteristic-based security authentication method, device and electronic equipment
WO2017197974A1