Biological information processing method, device and system
By obtaining failure information in the biometric process and determining the terminal risk level, and carrying out standard detection and authentication processing, the problem of low biometric security in the prior art is solved, and effective protection against hacker attacks is achieved.
Patent Information
- Application Number
- CN202210174313.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-24
- Publication Date
- 2025-09-02
- Estimated Expiration
- 2042-02-24
AI Technical Summary
The existing biometric verification technology lacks effective control over the number of biometric failures, resulting in low security and easy to be hacked.
By obtaining biometric failure information in the trigger biometric identification process, determining the risk level based on the terminal information, and performing standard detection and authentication processing when the risk level is safe, the number of errors in front-end action biopsy errors and back-end authentication failures is uniformly controlled.
It improves the security of biometric technology, effectively prevents hackers from attempting multiple attacks, and enhances the security of the account system.
Smart Images

Figure CN114547576B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of artificial intelligence, and in particular to a biological information processing method, device and system. Background Art
[0002] Currently, multiple apps offer biometric authentication, such as facial recognition, voiceprint, fingerprint, and iris recognition. These authentication methods are subject to the risk of tampering and counterfeiting. For example, a customer's facial information can be easily stolen, and then a video simulation attack can be conducted using technical means to break into a customer's facial recognition authentication. Many apps don't control the number of failed biometric authentication attempts, simply reporting an error message when the back-end comparison fails. This makes it easy for hackers to exploit the situation. For example, a hacker could record a customer's video to perform a facial recognition attack, but the angle or lighting of the video might be insufficient, making the motion biopsy difficult to pass. However, without a control over the number of failed attempts, hackers can arbitrarily adjust the angle and lighting to pass the motion biopsy. Similarly, the back-end can attempt to break through the attack after multiple attempts.
[0003] In other words, current biometric verification does not have biometric failure measures, which leads to the low security of biometric technology. Summary of the Invention
[0004] In view of this, the present invention provides a biological information processing method, device and system to solve at least one of the above-mentioned problems.
[0005] According to a first aspect of the present invention, there is provided a biological information processing method, the method comprising:
[0006] In response to triggering a biometric identification process, obtaining biometric identification failure information of the current user within a predetermined time;
[0007] When the biometric recognition failure information does not reach a threshold, determining the risk level of the terminal based on the current user terminal information;
[0008] When the risk level of the terminal is in a safe state, obtaining the biometric information of the current user and performing a standard detection operation on the biometric information;
[0009] After the standard detection operation of the biometric information is successful, the biometric information is sent to the server for authentication processing, and the authentication processing result is returned to the current user terminal.
[0010] Preferably, the method further comprises:
[0011] Weight information is set in advance for the standard detection operation results and authentication processing results of the biometric information.
[0012] Furthermore, the method further comprises:
[0013] The biometric recognition failure information is updated according to the risk level of the terminal, the standard detection operation result of the biometric information and its weight information, and the authentication processing result and its weight information.
[0014] Specifically, the current user terminal information includes the following risk information: terminal debugging mode, application information installed on the terminal, and system file directory information.
[0015] The above-mentioned determination of the terminal risk level based on the current user terminal information includes:
[0016] Pre-set risk levels for risk information in user terminal information;
[0017] The risk level of the terminal is determined based on the risk information obtained in the current user terminal information and its corresponding risk level.
[0018] Specifically, the biometric information includes: facial information, voiceprint information and iris information. The standard detection operation for the biometric information includes:
[0019] A live motion detection operation is performed on the user based on at least one of the biological information.
[0020] Furthermore, the method further comprises:
[0021] When the biometric recognition failure information reaches a threshold, a standard detection operation and / or authentication process corresponding to the threshold is performed on the biometric information based on a predetermined rule.
[0022] According to a second aspect of the present invention, there is provided a biological information processing apparatus, the apparatus comprising:
[0023] a failure information acquisition unit, configured to acquire biometric recognition failure information of the current user within a predetermined time in response to triggering the biometric recognition process;
[0024] a terminal risk level determination unit, configured to determine a risk level of the terminal based on current user terminal information when the biometric recognition failure information does not reach a threshold;
[0025] a standard detection operation unit, configured to obtain the biometric information of the current user and perform a standard detection operation on the biometric information when the risk level of the terminal is in a safe state;
[0026] The authentication processing unit is used to send the biometric information to the server for authentication processing after the standard detection operation of the biometric information is successful, and return the authentication processing result to the current user terminal.
[0027] According to a third aspect of the present invention, a biometric information processing system is provided, which includes the above-mentioned biometric information processing device, a biometric information standard detection device and a biometric information authentication server, wherein the biometric information standard detection device is used to perform standard detection operations on the acquired biometric information of the current user, and the biometric information authentication server is used to perform authentication processing on the biometric information.
[0028] According to a fourth aspect of the present invention, an electronic device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above method when executing the program.
[0029] According to a fifth aspect of the present invention, there is provided a computer-readable storage medium having a computer program stored thereon, which implements the steps of the above method when executed by a processor.
[0030] It can be seen from the above technical solution that, when the biometric identification process is triggered, the biometric identification failure information of the current user within a predetermined time is obtained. When the biometric identification failure information does not reach the threshold, the risk level of the terminal is determined according to the current user terminal information. Only when the risk level of the terminal is in a safe state, the biometric information of the current user is obtained, and a standard detection operation is performed on the biometric information. After the standard detection operation of the biometric information is successful, the biometric information is sent to the server for authentication processing. Compared with the existing technology, this technical solution uniformly controls the number of front-end action biopsy errors and the number of back-end authentication comparison failures, controls the risk of multiple attempts by hackers, and improves the security of biometric technology. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0032] Figure 1 is a flow chart of a biological information processing method according to an embodiment of the present invention;
[0033] Figure 2 is a schematic diagram of a biological information processing flow according to an embodiment of the present invention;
[0034] Figure 3 is a structural block diagram of a biological information processing system according to an embodiment of the present invention;
[0035] Figure 4is a structural block diagram of a biological information processing apparatus 1 according to an embodiment of the present invention;
[0036] Figure 5 FIG. 6 is a schematic block diagram of a system structure of an electronic device 600 according to an embodiment of the present invention. DETAILED DESCRIPTION
[0037] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0038] Because current biometric verification does not include a biometric failure response, the security of biometric technology is relatively low. Therefore, an embodiment of the present invention provides a biometric information processing solution that uniformly manages the number of front-end biopsy errors and back-end authentication comparison failures, thereby improving the security of biometric technology.
[0039] It should be noted that the acquisition, storage, use, and processing of data in the technical solution of this application are in compliance with the relevant provisions of national laws and regulations. The following is a detailed description of the embodiments of the present invention in conjunction with the accompanying drawings.
[0040] Figure 1 is a flow chart of a biological information processing method according to an embodiment of the present invention. Figure 1 As shown, the method includes:
[0041] Step 101: In response to triggering the biometric identification process, obtain the biometric identification failure information of the current user within a predetermined time. The biometric identification failure information here can be determined by the risk level of the terminal, the standard detection operation of the biometric information, and the authentication processing result in the following steps 102-104.
[0042] Step 102: When the biometric recognition failure information does not reach a threshold (the threshold may be determined based on actual operations), the risk level of the terminal is determined based on the current user terminal information.
[0043] Preferably, the current user terminal information includes the following risk information: terminal debugging mode, terminal installed application information, and system file directory information.
[0044] In actual operation, the risk level can be set in advance for the risk information in the user terminal information; and then the risk level of the terminal is determined based on the risk information in the current user terminal information obtained and its corresponding risk level.
[0045] Step 103: When the risk level of the terminal is in a safe state, the biometric information of the current user is obtained, and a standard detection operation is performed on the biometric information.
[0046] The biometric information here may include: facial information, voiceprint information, iris information, etc.
[0047] Standard biometric detection includes performing liveness detection based on at least one of the biometric information. For example, performing a corresponding action for facial recognition or reading out text or numbers as instructed for voiceprint authentication. If liveness detection fails, the number of errors is accumulated and added to the biometric failure information.
[0048] Step 104: After the standard detection operation of the biometric information is successful, the biometric information is sent to the server for authentication processing, and the authentication processing result is returned to the current user terminal.
[0049] When the biometric recognition process is triggered, the biometric recognition failure information of the current user within a predetermined time is obtained. When the biometric recognition failure information does not reach a threshold, the risk level of the terminal is determined based on the current user terminal information. Only when the risk level of the terminal is in a safe state, the biometric information of the current user is obtained, and a standard detection operation is performed on the biometric information. After the standard detection operation of the biometric information is successful, the biometric information is sent to the server for authentication processing. Compared with the existing technology, the embodiment of the present invention uniformly controls the number of front-end action biopsy errors and the number of back-end authentication comparison failure errors, controls the risk of multiple attempts by hackers, and improves the security of biometric technology.
[0050] In actual operation, weight information can be set in advance for the standard detection operation results and authentication processing results of the biometric information; then the biometric failure information is updated according to the risk level of the terminal, the standard detection operation results of the biometric information and its weight information, and the authentication processing results and its weight information.
[0051] When the number of biometric authentication failures reaches a threshold, a standard detection operation and / or authentication process corresponding to the threshold may be performed on the biometric information based on a predetermined rule, i.e., the difficulty of the standard detection operation and / or authentication process may be increased. For example, the number of standard detection operations may be increased.
[0052] When the number of biometric failures reaches the limit, it means that there is a possibility of multiple attempts by hackers. At this time, the biometric recognition process is terminated to avoid the risk of the customer account system being attacked.
[0053] In order to better understand the present invention, the following Figure 2The embodiment of the present invention is described in detail with reference to the flow chart shown.
[0054] exist Figure 2 The figure shows the existing process and the process of the embodiment of the present invention. Compared with the existing process, the embodiment of the present invention mainly adds the control of the number of front-end and back-end errors, and first determines whether the current number of customer errors exceeds the limit before each biometric recognition. This can improve the security of biometric recognition and effectively prevent the system from being attacked. It should be noted that the newly added steps of the embodiment of the present invention can be flexibly configured according to the scenario. For example, if a certain recognition scenario does not require front-end verification, the front-end error accumulation step can be eliminated.
[0055] See also Figure 2 As shown, the biometric identification process of the embodiment of the present invention specifically includes:
[0056] 1. Before initiating biometric authentication, the system checks whether the current customer's error count has reached the limit. If so, the transaction is rejected. If not, the system then checks the client's risk level. This involves determining, based on client information security check rules, whether the terminal (e.g., a mobile phone) contains ROM (Read-Only Memory) implants, whether it is running an emulator, and other abnormal behaviors. The security level is then incorporated into the error count calculation formula as a fixed parameter.
[0057] 2. Perform front-end liveness detection, such as performing corresponding actions in face recognition or reading corresponding text or numbers according to instructions in voiceprint authentication. If the liveness detection fails to meet the standard, the number of errors needs to be accumulated according to the weighting coefficient (i.e., weight).
[0058] 3. If the liveness detection passes, the back-end will verify the biometric information. If the comparison fails, the number of errors will be accumulated according to the weighted coefficient.
[0059] 4. Regarding the method of accumulating the number of errors, the frequency and impact of errors vary depending on the actual situation. Therefore, the embodiment of the present invention uses a multivariate linear regression model for fitting to obtain a formula for accumulating the number of errors. The specific formula is as follows:
[0060] T times =ax+by+C
[0061] Here, ax represents the control factor for the number of front-end errors. Because the number of front-end errors is high, factor a is a parameter less than 1 (i.e., the weight information of the standard detection operation result) and can be tentatively set to 0.5, meaning that a biopsy failure caused by substandard front-end actions has a smaller impact. by represents the control factor after a back-end biometric information comparison fails. Because back-end comparison results are generally more accurate, factor b (i.e., the weight information of the authentication processing result) can be tentatively set to 1, meaning that a back-end comparison failure directly accumulates as an error.
[0062] The constant parameter C represents the client's risk factor (i.e., the terminal risk level). Basic checks can be performed on the local device based on the client's security verification procedure when the app is launched. Specific checks include:
[0063] (1) Whether the terminal debugging mode is turned on;
[0064] (2) Whether it is rooted / jailbroken;
[0065] (3) Whether files are implanted in the ROM storage space;
[0066] (4) Whether there are any Trojan files pre-installed by certain black market apps in the system file directory (some black market apps may still leave traces of Trojan files after being uninstalled, for example, some apps in the Android system);
[0067] (5) Whether certain black market apps are installed (for example, apps that can remotely control the machine, start internal timed threads to send network requests, etc.).
[0068] The risk levels of the above factors gradually increase:
[0069] a. If only (1) is hit, the constant C can be set to 0.5;
[0070] b. If (2) is hit, the constant C can be set to 1;
[0071] c. If (3) is hit, the constant C can be set to 1.5;
[0072] d. If (4) or (5) above is hit, the constant C is set to 2.
[0073] In actual operation, if the device hits several of the above rules, the corresponding risk factor values need to be accumulated.
[0074] In one example, the cumulative formula for the number of errors in a face recognition scenario can be:
[0075] T times =0.5x 前端活检失败次数 +y后端对比人脸失败次数 +C 客户端风险因子
[0076] If the client performs two substandard actions on the front end, causing the biopsy to fail, and the back-end facial information comparison also fails, and the current client risk factor parameter is 2, then the cumulative number of errors for this facial recognition failure is 4. If the maximum number of consecutive facial recognition failures on the same day is 10, and the number of errors accumulated this time is 4, it is very likely an attack on the system account. In this case, the authentication difficulty can be increased, which can greatly improve account security.
[0077] It should be noted that the above-mentioned formula for accumulating the number of errors can be determined by fitting according to different biometric authentication scenarios and existing data, and the present invention does not impose any limitation on this.
[0078] When checking the customer's current cumulative number of errors before performing biometric authentication, different authentication methods can be used based on the current cumulative number to further enhance authentication security, that is, to increase the authentication difficulty. Assuming that the current maximum cumulative number of errors is 10, and the customer has accumulated 5 errors before this authentication, it means that the customer's system may have been attacked or brute-force cracked, and it is necessary to increase the difficulty of biometric authentication. Specific methods for increasing the difficulty include:
[0079] (1) Increase the number of liveness detection authentications. If this is face recognition, the number of collected actions can be increased from the preset 2 actions to 4; if this is voiceprint authentication, the number of read-out numbers can be increased from the preset 2 groups to 4 groups. The same applies to other authentication methods.
[0080] (2) Raising the back-end matching threshold. In practice, the matching degree of biometric authentication cannot currently reach 100% technically. Therefore, a matching threshold of 99% or higher is generally considered successful. In an embodiment of the present invention, the difficulty can be increased by raising the matching threshold to 99.5%.
[0081] (3) A combination of multi-dimensional authentication methods. Currently, biometric authentication methods include face authentication, voiceprint authentication, iris authentication, etc. If the cumulative number of errors in the current customer account has almost reached the upper limit (for example, 9 times), it is necessary to consider using two or more authentication methods for combined authentication, which can improve the security of the account.
[0082] In actual operation, you can also strengthen authentication through SMS verification or card password verification to further reduce the risk of account hacking.
[0083] From the above description, it can be seen that the embodiment of the present invention is based on the unified management technology of the number of front-end and back-end errors, which can effectively improve the security and reliability of biometric technology and prevent malicious attacks on customer accounts.
[0084] Based on similar inventive concepts, an embodiment of the present invention further provides a biological information processing system, such as Figure 3 As shown, the system includes: a biometric information processing device 1, a biometric information standard detection device 2 and a biometric information authentication server 3, wherein the biometric information processing device 1 can preferably be used to implement the process of the above-mentioned biometric information processing method, the biometric information standard detection device 2 can be used to perform standard detection operations on the acquired user biometric information, and the biometric information authentication server 3 can be used to perform authentication processing on the biometric information.
[0085] Figure 4 is a structural block diagram of the biological information processing device 1, such as Figure 4 As shown, the biometric information processing device 1 includes: a failure information acquisition unit 11, a terminal risk level determination unit 12, a standard detection operation unit 13 and an authentication processing unit 14, wherein:
[0086] The failure information acquisition unit 11 is configured to acquire the biometric recognition failure information of the current user within a predetermined time in response to triggering the biometric recognition process.
[0087] The terminal risk level determination unit 12 is configured to determine the risk level of the terminal according to the current user terminal information when the biometric recognition failure information does not reach a threshold.
[0088] Specifically, the current user terminal information includes the following risk information: terminal debugging mode, terminal installed application information, and system file directory information.
[0089] The terminal risk level determination unit 12 may set a risk level for the risk information in the user terminal information in advance; and then determine the risk level of the terminal according to the risk information in the acquired current user terminal information and its corresponding risk level.
[0090] The standard detection operation unit 13 is configured to obtain the biometric information of the current user and perform a standard detection operation on the biometric information when the risk level of the terminal is in a safe state.
[0091] In actual operation, the biometric information may include: face information, voiceprint information, iris information, etc. The standard detection operation unit 13 may perform a motion liveness detection operation on the user based on at least one of the biometric information.
[0092] The authentication processing unit 14 is configured to send the biometric information to a server for authentication processing after the standard detection operation of the biometric information is successful, and return the authentication processing result to the current user terminal.
[0093] When the biometric identification process is triggered, the failure information acquisition unit 11 obtains the biometric identification failure information of the current user within a predetermined time. When the biometric identification failure information does not reach the threshold, the terminal risk level determination unit 12 determines the risk level of the terminal based on the current user terminal information. Only when the risk level of the terminal is in a safe state, the standard detection operation unit 13 obtains the biometric information of the current user and performs a standard detection operation on the biometric information. After the standard detection operation of the biometric information is successful, the authentication processing unit 14 sends the biometric information to the server for authentication processing. Compared with the existing technology, the embodiment of the present invention uniformly controls the number of front-end action biopsy errors and the number of back-end authentication comparison failures, controls the risk of multiple attempts by hackers, and improves the security of biometric technology.
[0094] In actual operation, the above-mentioned device 1 may further include: a weight setting unit and a biometric recognition failure information updating unit, wherein:
[0095] The weight setting unit is used to set weight information for the standard detection operation result and the authentication processing result of the biometric information in advance.
[0096] The biometric recognition failure information updating unit is configured to update the biometric recognition failure information according to the risk level of the terminal, the standard detection operation result of the biometric information and its weight information, and the authentication processing result and its weight information.
[0097] Preferably, the above-mentioned device 1 may further include: an execution difficulty increasing unit, configured to perform a standard detection operation and / or authentication process corresponding to a threshold value on the biometric information based on a predetermined rule when the biometric recognition failure information reaches the threshold value.
[0098] The specific execution process of each of the above units can be found in the description of the above method embodiment, which will not be repeated here.
[0099] In actual operation, the above-mentioned units can be provided in combination or individually, and the present invention is not limited thereto.
[0100] This embodiment further provides an electronic device, which may be a desktop computer, a tablet computer, a mobile terminal, etc., but this embodiment is not limited thereto. In this embodiment, the electronic device may be implemented with reference to the above-mentioned method embodiment and the embodiment of the bioinformation processing device / system, the contents of which are incorporated herein, and any repetitions are omitted.
[0101] Figure 5 FIG. 6 is a schematic block diagram of a system structure of an electronic device 600 according to an embodiment of the present invention. Figure 5As shown, the electronic device 600 may include a central processor 100 and a memory 140; the memory 140 is coupled to the central processor 100. It should be noted that this figure is exemplary; other types of structures may be used to supplement or replace this structure to implement telecommunication functions or other functions.
[0102] In one embodiment, the bioinformation processing function may be integrated into the central processing unit 100. The central processing unit 100 may be configured to perform the following control:
[0103] In response to triggering a biometric identification process, obtaining biometric identification failure information of the current user within a predetermined time;
[0104] When the biometric recognition failure information does not reach a threshold, determining the risk level of the terminal based on the current user terminal information;
[0105] When the risk level of the terminal is in a safe state, obtaining the biometric information of the current user and performing a standard detection operation on the biometric information;
[0106] After the standard detection operation of the biometric information is successful, the biometric information is sent to the server for authentication processing, and the authentication processing result is returned to the current user terminal.
[0107] From the above description, it can be seen that the electronic device provided in the embodiment of the present application obtains the biometric failure information of the current user within a predetermined time when the biometric identification process is triggered. When the biometric failure information does not reach the threshold, the risk level of the terminal is determined according to the current user terminal information. Only when the risk level of the terminal is in a safe state, the current user's biometric information is obtained, and a standard detection operation is performed on the biometric information. After the standard detection operation of the biometric information is successful, the biometric information is sent to the server for authentication processing. Compared with the existing technology, the embodiment of the present invention uniformly controls the number of front-end action biopsy errors and the number of back-end authentication comparison failures, controls the risk of multiple attempts by hackers, and improves the security of biometric technology.
[0108] In another embodiment, the bioinformation processing device / system can be configured separately from the central processing unit 100. For example, the bioinformation processing device / system can be configured as a chip connected to the central processing unit 100, and the bioinformation processing function is realized under the control of the central processing unit.
[0109] like Figure 5 As shown, the electronic device 600 may further include: a communication module 110, an input unit 120, an audio processing unit 130, a display 160, and a power supply 170. It is worth noting that the electronic device 600 does not necessarily have to include Figure 5In addition, the electronic device 600 may also include all components shown in Figure 5 For components not shown, reference may be made to the prior art.
[0110] like Figure 5 As shown, the central processing unit 100 is sometimes also referred to as a controller or an operation control unit, and may include a microprocessor or other processor device and / or logic device. The central processing unit 100 receives inputs and controls the operations of various components of the electronic device 600 .
[0111] Memory 140 may be, for example, one or more of a cache, flash memory, hard drive, removable media, volatile memory, non-volatile memory, or other suitable devices. It may store the aforementioned failure-related information and may also store programs that execute the relevant information. The CPU 100 may execute the programs stored in memory 140 to implement information storage or processing.
[0112] The input unit 120 provides input to the CPU 100. The input unit 120 may be, for example, a keypad or touch input device. The power supply 170 is used to provide power to the electronic device 600. The display 160 is used to display objects such as images and text. The display may be, for example, an LCD display, but is not limited thereto.
[0113] The memory 140 may be a solid-state memory, such as a read-only memory (ROM), a random access memory (RAM), or a SIM card. Alternatively, it may be a memory that retains information even when power is off, can be selectively erased, and is provided with more data. Examples of such memory are sometimes referred to as EPROMs. The memory 140 may also be some other type of device. The memory 140 includes a buffer memory 141 (sometimes referred to as a buffer). The memory 140 may include an application / function storage unit 142 for storing application programs and function programs or processes for executing the operations of the electronic device 600 via the central processing unit 100.
[0114] The memory 140 may also include a data storage unit 143 for storing data, such as contacts, digital data, pictures, sounds, and / or any other data used by the electronic device. The driver storage unit 144 of the memory 140 may include various driver programs for communication functions of the electronic device and / or for executing other functions of the electronic device (such as messaging applications, address book applications, etc.).
[0115] The communication module 110 is a transmitter / receiver 110 that transmits and receives signals via an antenna 111. The communication module (transmitter / receiver) 110 is coupled to the central processor 100 to provide input signals and receive output signals, which may be the same as in a conventional mobile communication terminal.
[0116] Based on different communication technologies, multiple communication modules 110 may be provided in the same electronic device, such as a cellular network module, a Bluetooth module, and / or a wireless local area network module. The communication module (transmitter / receiver) 110 is also coupled to a speaker 131 and a microphone 132 via an audio processor 130 to provide audio output via the speaker 131 and receive audio input from the microphone 132, thereby implementing common telecommunication functions. The audio processor 130 may include any suitable buffer, decoder, amplifier, etc. Furthermore, the audio processor 130 is also coupled to the central processing unit 100, enabling local recording via the microphone 132 and playback of stored audio via the speaker 131.
[0117] An embodiment of the present invention further provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the steps of the above-mentioned biological information processing method are implemented.
[0118] In summary, the embodiments of the present invention improve the security of biometric technology by establishing a unified management mechanism for the number of front-end and back-end errors, and effectively avoid the risk of attacks on the customer account system.
[0119] Preferred embodiments of the present invention have been described above with reference to the accompanying drawings. Many features and advantages of these embodiments are apparent from this detailed description, and thus the appended claims are intended to cover all such features and advantages of these embodiments that fall within their true spirit and scope. Furthermore, since numerous modifications and changes will readily occur to those skilled in the art, the embodiments of the present invention are not intended to be limited to the precise construction and operation illustrated and described, but are intended to cover all suitable modifications and equivalents that fall within the scope thereof.
[0120] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0121] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0122] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0123] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0124] Specific embodiments are used in the present invention to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core ideas. At the same time, for those skilled in the art, according to the ideas of the present invention, there may be changes in the specific implementation methods and application scopes. In summary, the contents of this specification should not be understood as limiting the present invention.
Claims
1. A biological information processing method, characterized in that: The method comprises: In response to triggering a biometric identification process, obtaining biometric identification failure information of the current user within a predetermined time; When the biometric recognition failure information does not reach a threshold, determining the risk level of the terminal based on the current user terminal information; When the risk level of the terminal is in a safe state, obtaining the biometric information of the current user and performing a standard detection operation on the biometric information; After the standard detection operation of the biometric information is successful, the biometric information is sent to the server for authentication processing, and the authentication processing result is returned to the current user terminal; The biometric identification failure information is determined by the risk level of the terminal, the standard detection operation of the biometric information and the authentication processing result.
2. The method according to claim 1, characterized in that The method further comprises: Weight information is set in advance for the standard detection operation results and authentication processing results of the biometric information.
3. The method according to claim 2, characterized in that The method further comprises: The biometric recognition failure information is updated according to the risk level of the terminal, the standard detection operation result of the biometric information and its weight information, and the authentication processing result and its weight information.
4. The method according to claim 1, wherein The current user terminal information includes the following risk information: terminal debugging mode, terminal installed application information, and system file directory information.
5. The method according to claim 4, characterized in that Determining the terminal's risk level based on current user terminal information includes: Pre-set risk levels for risk information in user terminal information; The risk level of the terminal is determined based on the risk information obtained in the current user terminal information and its corresponding risk level.
6. The method according to claim 1, characterized in that The biometric information includes: facial information, voiceprint information and iris information. The standard detection operation for the biometric information includes: A live motion detection operation is performed on the user based on at least one of the biological information.
7. The method according to claim 1, characterized in that The method further comprises: When the biometric recognition failure information reaches a threshold, a standard detection operation and / or authentication process corresponding to the threshold is performed on the biometric information based on a predetermined rule.
8. A biological information processing device, characterized in that: The device comprises: a failure information acquisition unit, configured to acquire biometric recognition failure information of the current user within a predetermined time in response to triggering the biometric recognition process; a terminal risk level determination unit, configured to determine a risk level of the terminal based on current user terminal information when the biometric recognition failure information does not reach a threshold; a standard detection operation unit, configured to obtain the biometric information of the current user and perform a standard detection operation on the biometric information when the risk level of the terminal is in a safe state; an authentication processing unit, configured to send the biometric information to a server for authentication processing after a standard detection operation of the biometric information is successful, and return an authentication processing result to the current user terminal; The biometric identification failure information is determined by the risk level of the terminal, the standard detection operation of the biometric information and the authentication processing result.
9. A biological information processing system, characterized in that: The system includes a biometric information processing device, a biometric information standard detection device and a biometric information authentication server as described in claim 8, wherein the biometric information standard detection device is used to perform a standard detection operation on the acquired biometric information of the current user, and the biometric information authentication server is used to perform authentication processing on the biometric information.
10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the steps of the method according to any one of claims 1 to 7 are implemented.
11. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Biological recognition-based user authentication method and system
CN103237030A
Living body detection method, device, system and storage medium
CN108875688A