A privacy protection based biometric identification method, device and equipment
By performing privacy protection processing on biometric data within a trusted execution environment on terminal devices, the vulnerability of biometric data to attacks is solved. This achieves a more reliable and secure technical solution for biometrics from the underlying layer of the terminal device to all ends, ensuring the security of user privacy and identity authentication.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
- Filing Date
- 2021-05-27
- Publication Date
- 2026-04-14
AI Technical Summary
Existing biometric technologies obtain data directly from the API layer of the network architecture system on terminal devices, making biometric data vulnerable to attacks, resulting in privacy data leaks and unreliable identity authentication.
A Trusted Execution Environment (TEE) is used to protect the privacy of biometric data. By using trusted biometric applications in the TEE of terminal devices, privacy processing rules are implemented to ensure the security of data during transmission and processing, and trustworthiness is verified on the server side.
It improves the security and trustworthiness of biometric data, reduces the probability of data being attacked or intercepted, ensures that user privacy data is not leaked, and enhances the credibility of identity authentication.
Smart Images

Figure CN115690921B_ABST
Abstract
Description
[0001] This application is a divisional application of Chinese patent application filed on May 27, 2021, with application number 202110583000.9 and title "A Biometric Identification Method, Apparatus and Device Based on Privacy Protection". Technical Field
[0002] This specification relates to the field of computer technology, and in particular to a privacy-preserving biometric method, apparatus, and device. Background Technology
[0003] With the development of mobile internet and driven by policies promoting simplified procedures and online business transactions, more and more services are moving online. This online service requires users to verify their identity to ensure they are the rightful recipients of the service. Against this backdrop, biometric identification and authentication are becoming increasingly widespread, with a growing number of application scenarios.
[0004] Currently, biometric identification or authentication mechanisms used on terminal devices directly obtain biometric data from the API layer of the network architecture system corresponding to the terminal device. This approach is susceptible to attacks and interception of biometric data, leading to the leakage of user privacy and rendering user authentication unreliable. Therefore, a more reliable and secure technical solution is needed to achieve biometric identification from the terminal device's underlying layer to all other endpoints. Summary of the Invention
[0005] The purpose of the embodiments in this specification is to provide a technical solution that enables more reliable and secure biometric identification from the bottom layer of the terminal device to each end.
[0006] To achieve the above technical solution, the embodiments in this specification are implemented as follows:
[0007] This specification provides a privacy-preserving biometric identification method applied to a terminal device equipped with a trusted execution environment. The method includes: upon receiving a biometric identification request, collecting user biometric data for biometric processing based on a biometric identification component; transmitting the user biometric data from the biometric identification component to the trusted execution environment of the terminal device via a trusted biometric application for performing biometric processing; wherein the trusted execution environment is configured with privacy processing rules for privacy protection of the user biometric data provided by the trusted biometric application; performing privacy protection processing on the user biometric data in the trusted execution environment using the privacy processing rules to obtain processed user biometric data; retrieving the processed user biometric data from the trusted execution environment based on the trusted biometric application, and providing the processed user biometric data to a server, so that the server can perform trustworthiness verification on the processed user biometric data, and perform biometric processing based on the processed user biometric data after successful verification.
[0008] This specification provides an embodiment of a privacy-preserving biometric identification method. The method includes: receiving processed user biometric data sent by a terminal device, which has undergone privacy protection processing according to privacy processing rules set in the executable environment of the terminal device. Based on preset privacy verification rules, the processed user biometric data is subjected to a credibility verification to obtain a corresponding verification result. If the verification result is successful, biometric processing is performed based on the processed user biometric data, and the biometric processing result is sent to the terminal device.
[0009] This specification provides an embodiment of a privacy-preserving biometric device. The device includes a trusted execution environment (TEA) and comprises: a data acquisition module, which, upon receiving a biometric request, acquires user biometric data for biometric processing based on a biometric component; a data transmission module, which transmits the user biometric data from the biometric component to the TEA via a trusted biometric application on the device for performing biometric processing; wherein the TEA is configured with privacy processing rules for privacy protection of the user biometric data provided by the trusted biometric application; a privacy protection processing module, which performs privacy protection processing on the user biometric data in the TEA using the privacy processing rules to obtain processed user biometric data; and a data processing module, which retrieves the processed user biometric data from the TEA based on the trusted biometric application and provides the processed user biometric data to a server, allowing the server to verify the trustworthiness of the processed user biometric data and, upon successful verification, performs biometric processing based on the processed user biometric data.
[0010] This specification provides an embodiment of a privacy-preserving biometric device, comprising: a data receiving module, which receives processed user biometric data sent by a terminal device after privacy processing according to privacy rules set in the executable environment of the terminal device; a privacy verification module, which performs a credibility verification on the processed user biometric data based on preset privacy verification rules, and obtains a corresponding verification result; and a biometric identification module, which, if the verification result is successful, performs biometric processing based on the processed user biometric data and sends the biometric processing result to the terminal device.
[0011] This specification provides an embodiment of a privacy-preserving biometric device. The device includes a trusted execution environment (TEA), comprising: a processor; and a memory configured to store computer-executable instructions. When executed, the processor, upon receiving a biometric request, collects user biometric data for biometric processing based on a biometric component. The user biometric data is transmitted from the biometric component to the TEA via a trusted biometric application on the device. The TEA is configured with privacy processing rules to perform privacy protection processing on the user biometric data provided by the trusted biometric application. In the TEA, the user biometric data is processed using the privacy processing rules to obtain processed user biometric data. The trusted biometric application retrieves the processed user biometric data from the TEA and provides it to a server. The server verifies the trustworthiness of the processed user biometric data and, upon successful verification, performs biometric processing based on the processed user biometric data.
[0012] This specification provides an embodiment of a privacy-preserving biometric device, comprising: a processor; and a memory configured to store computer-executable instructions, wherein the executable instructions, when executed, cause the processor to: receive processed user biometric data sent by a terminal device, obtained after privacy processing according to privacy rules set in the executable environment of the terminal device; perform a credibility verification on the processed user biometric data based on preset privacy verification rules, and obtain a corresponding verification result; if the verification result is successful, perform biometric processing based on the processed user biometric data, and send the biometric processing result to the terminal device.
[0013] This specification also provides a storage medium for storing computer-executable instructions. When executed, these instructions implement the following process: Upon receiving a biometric request, user biometric data for biometric processing is collected based on a biometric component. The user biometric data is transmitted from the biometric component to a trusted execution environment (TEA) on the terminal device via a trusted biometric application for performing biometric processing. The TEA is configured with privacy processing rules to protect the user biometric data provided by the trusted biometric application. In the TEA, the user biometric data is processed using the privacy processing rules to obtain processed user biometric data. The trusted biometric application retrieves the processed user biometric data from the TEA and provides it to a server. The server verifies the trustworthiness of the processed user biometric data and, upon successful verification, performs biometric processing based on the processed user biometric data.
[0014] This specification also provides a storage medium for storing computer-executable instructions. When executed, these instructions implement the following process: receiving processed user biometric data sent by a terminal device, obtained after privacy protection processing according to privacy rules set in the executable environment of the terminal device; performing a credibility verification on the processed user biometric data based on preset privacy verification rules to obtain a corresponding verification result; if the verification result is successful, performing biometric processing based on the processed user biometric data and sending the biometric processing result to the terminal device. Attached Figure Description
[0015] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0016] Figure 1A This is an embodiment of a privacy-preserving biometric identification method described in this specification;
[0017] Figure 1B This is a schematic diagram of a privacy-preserving biometric identification process described in this specification;
[0018] Figure 2This is a schematic diagram of another privacy-preserving biometric process described in this specification;
[0019] Figure 3A This is another embodiment of a privacy-preserving biometric method described in this specification;
[0020] Figure 3B This is a schematic diagram of yet another privacy-preserving biometric process described in this specification;
[0021] Figure 4 This is yet another embodiment of a privacy-preserving biometric method described in this specification;
[0022] Figure 5 This is yet another embodiment of a privacy-preserving biometric method described in this specification;
[0023] Figure 6 This is an embodiment of a privacy-preserving biometric device described in this specification;
[0024] Figure 7 This is another embodiment of a privacy-preserving biometric device described in this specification;
[0025] Figure 8 This is an example of a privacy-preserving biometric device described in this specification. Detailed Implementation
[0026] This specification provides a privacy-preserving biometric identification method, apparatus, and device through its embodiments.
[0027] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this specification.
[0028] Example 1
[0029] like Figure 1A and Figure 1BAs shown in the embodiments of this specification, a privacy-preserving biometric identification method is provided. The execution subject of this method can be a terminal device, such as a mobile phone, tablet computer, or personal computer (PC). This terminal device can be used in various services including biometric processing. The terminal device can be equipped with a trusted execution environment (TEE), which can be implemented using specified hardware devices and programs written in a predetermined programming language (i.e., hardware + software implementation) or programs written in a predetermined programming language (i.e., software implementation), depending on the specific circumstances. This trusted execution environment can be a secure operating environment for data processing. The method specifically includes the following steps:
[0030] In step S102, upon receiving a biometric request, user biometric data for biometric processing is collected based on the biometric component.
[0031] The biometric request can include various types, such as facial recognition, fingerprint recognition, iris recognition, etc., which can be set according to actual conditions. This specification does not limit this. The biometric component can also include various types. Different biometric data requires different biometric components. For example, if the biometric data to be collected is the user's facial data, the biometric component used can be a camera component. Similarly, if the biometric data to be collected is the user's fingerprint data, the biometric component used can be a fingerprint acquisition component, etc., which can be set according to actual conditions. This specification does not limit this. User biometric data can include various types, such as the user's facial data, fingerprint data, or iris data, which can be set according to actual conditions.
[0032] In practice, with the development of mobile internet and driven by policies such as simplifying procedures and conducting business online, more and more services are going online. This online service requires users to verify their identity to ensure they are the rightful recipients. Against this backdrop, biometrics and authentication are becoming increasingly widespread, with more and more application scenarios. However, current biometric mechanisms used on terminal devices directly obtain biometric data from the API layer of the network architecture system. This approach is susceptible to attacks and interception of biometric data, leading to the leakage of user privacy and making user authentication unreliable. Therefore, a technical solution is needed to achieve more reliable and secure biometrics from the terminal device's underlying layer to all other endpoints. This specification provides an optional technical solution, which may include the following:
[0033] A user's terminal device can have an application installed to perform a specific service (such as a payment service or a personal information inquiry service). This application can have entry points for requesting different services (implemented through hyperlinks or buttons). Furthermore, the terminal device can also have one or more different biometric mechanisms (such as facial recognition or fingerprint recognition) to authenticate the user's identity. When a user needs to request a service, they can launch the application. The application can then retrieve relevant data from the corresponding server and display it to the user. The user can find the entry point for the requested service on the application's page. This entry point triggers the application to retrieve the relevant data from the server. The terminal device can display this data, and after the user provides the corresponding request information based on this data, the terminal device can generate a service request. If user authentication is required during the service execution, a biometric mechanism can be activated. A biometric request is then generated. Upon receiving this request, the terminal device can activate its biometric component, which collects the user's biometric data for biometric processing.
[0034] For example, the application can include a transfer service entry point, accessible via a transfer button. When a user needs to transfer funds, they can click this button, and the terminal device will access the corresponding transfer page. On this page, the user can enter the amount to be transferred and the recipient's information (such as account number). After entering the information, the user can click the confirmation button on the transfer page. The terminal device will then generate a transfer request based on the user's input. Simultaneously, since the transfer process requires user authentication, the terminal device can also generate a biometric request (or biometric command). The terminal device can be equipped with a facial recognition mechanism. Upon receiving a biometric request, the terminal device can activate the facial recognition mechanism, which in turn activates the camera component within the terminal device. This camera component collects the user's facial data for biometric processing.
[0035] In step S104, the user's biometric data is transmitted from the biometric component to the trusted execution environment of the terminal device through a trusted biometric application on the terminal device for performing biometric processing; wherein, the trusted execution environment is configured with privacy processing rules for privacy protection processing of the user's biometric data provided by the trusted biometric application.
[0036] The Trusted Execution Environment (TEE) can be a secure data processing environment isolated from other environments. This means that processing performed within the TEE, and the data generated during processing, cannot be accessed by other execution environments or applications outside the TEE. A TEE can be implemented by creating a small operating system that can run independently in a trusted zone (such as TrustZone). The TEE can provide services directly through system calls (such as direct processing by the TrustZone kernel). Terminal devices can include Rich Execution Environments (REEs) and TEEs. REEs can run the operating system installed on the terminal device, such as Android, iOS, Windows, and Linux. REEs can provide all the functions of the terminal device to upper-layer applications, such as camera and touch functionality. However, REEs present many security vulnerabilities. For example, the operating system can obtain all the data of an application, but it is difficult to verify whether the operating system or the application has been tampered with. If tampered with, user information will be at significant security risk. Therefore, a TEE within the terminal device is needed to address these vulnerabilities. A Trusted Execution Environment (TEE) has its own execution space, meaning that an operating system also exists within it. TEE offers a higher level of security than Rich Execution Environments (REEs). The software and hardware resources of the terminal devices accessed by a TEE are separate from those of a REE. However, a TEE can directly access information from a REE, while a REE cannot access information from a TEE. TEEs can perform authentication and other processing through provided interfaces, thereby ensuring that user information (such as payment information and user privacy information) is not tampered with, passwords are not hijacked, and fingerprint or facial data is not stolen.
[0037] Trusted biometric applications can be pre-defined applications capable of performing biometric processing, such as financial payment applications, instant messaging applications, or pre-developed applications. These applications can be installed on the terminal device, pre-embedded code in the terminal device's hardware, or run as a plugin in the background of the terminal device's operating system. The specific configuration depends on the actual situation. Privacy processing rules are rules that protect the privacy of user biometric data. These rules can be set in various ways, such as based on pre-defined anti-tampering rules for user biometric data, user identity, or the business category corresponding to the user's biometric data. The specific configuration depends on the actual situation. Furthermore, privacy processing rules can be pre-configured in the trusted execution environment (TEX) of the terminal device. To ensure the security of these rules, they can be encrypted. Specifically, authorized rule-makers can define the content of the privacy processing rules, which can then be encrypted or signed using specified encryption or signing methods to form encrypted rules. This encrypted rule is then transmitted to the TEX of the terminal device through a designated secure data transmission channel, thus ensuring its security and preventing tampering. Within the TEX, the encrypted privacy processing rules can be decrypted or verified. Once it is confirmed that the rules have not been tampered with (e.g., verification is successful, decryption is possible, and the decrypted rules meet preset conditions), they can be stored in the TEX.
[0038] In implementation, to ensure the security of user biometric data during transmission and prevent arbitrary applications in the trusted execution environment from accessing it, a trusted biometric application can be set up to perform biometric processing. This trusted biometric application provides temporary protection for the user's biometric data. For example, it can prevent unauthorized applications from accessing the user's biometric data, or it can perform pre-processing on the user's biometric data to obtain processed biometric data, thus providing data protection. After the biometric component collects the user's biometric data, the terminal device can launch the trusted biometric application to perform biometric processing. The trusted biometric application can be pre-configured with a secure interface, and correspondingly, a secure interface can also be configured in the trusted execution environment of the terminal device. Through this secure interface, a secure data transmission channel can be established between the trusted biometric application and the trusted execution environment. The trusted biometric application can extract the user's biometric data from the biometric component and transmit it to the trusted execution environment of the terminal device through the aforementioned secure interface and data transmission channel. By setting up the trusted biometric application, secure interface, and data transmission channel, the security of the user's biometric data during transmission can be guaranteed.
[0039] It should be noted that there can be various types of trusted biometric applications. The corresponding trusted biometric applications can be set according to the business type or business identifier corresponding to the user's biometric data, or according to the data type of the user's biometric data. In practical applications, how to set up trusted biometric applications can be set according to the actual situation. This specification does not limit this in the embodiments.
[0040] In step S106, in a trusted execution environment, the user's biometric data is processed for privacy protection according to privacy processing rules to obtain the processed user biometric data.
[0041] In implementation, to ensure that user biometric data is not leaked during processing, privacy protection processing can be performed on the user biometric data within a trusted execution environment (TEA). Specific privacy protection processes can include various methods, and the following are some optional approaches: Privacy processing rules for user biometric data can be pre-defined. After the user biometric data is transmitted to the TEA of the terminal device, it can be placed within the TEA. Within the TEA, the terminal device can analyze the user biometric data, for example, determining the corresponding business category, and then obtaining the appropriate privacy processing rules based on the determined business category and other relevant information. In a trusted execution environment, user biometric data can be processed for privacy protection using acquired privacy rules. This privacy protection can take various forms. For example, an encrypted tag can be pre-set in the user biometric data, containing a pre-recorded checksum (such as a hash value). Furthermore, the processed user biometric data can be obtained by encrypting the entire biometric data or by encrypting only a portion of it. Because this processing is performed within a trusted execution environment, it is not known to other execution environments or applications on the terminal device. Therefore, the privacy-protected user biometric data within the execution environment will not be accessed by any software program or hardware device outside the trusted execution environment, thus ensuring the accuracy and security of the user biometric data (it will not be tampered with or leaked). In practical applications, privacy protection methods for user biometric data are not limited to those described above; many other feasible methods can also be used, which will not be elaborated upon here.
[0042] The above-described privacy protection processing of user biometric data is only one feasible method. In practical applications, other methods can also be used to protect user biometric data. Different processing methods can be used to protect user biometric data according to different privacy processing rules. Moreover, the specific process of privacy protection processing of user biometric data can be different depending on the privacy processing rules. The specific process can be set according to the actual situation, and the embodiments in this specification do not limit this.
[0043] In step S108, the processed user biometric data is obtained from the trusted execution environment based on the biometric trusted application, and the processed user biometric data is provided to the server so that the server can perform trust verification on the processed user biometric data, and perform biometric processing based on the processed user biometric data after the verification is passed.
[0044] In practice, by performing privacy protection processing on user biometric data in a trusted execution environment, the processed user biometric data can be obtained. This triggers a trusted biometric application, which then retrieves the processed user biometric data from the trusted execution environment and provides it to the server. Thus, the processes of obtaining user biometric data, performing privacy protection processing on user biometric data, and providing the processed user biometric data to the server are all completed within a trusted execution environment or a trusted biometric application. This not only achieves privacy protection processing of user biometric data but also ensures the security of user biometric data during processing on the terminal device.
[0045] After receiving the processed user biometric data, the server can perform a reliability check. For example, it can calculate a checksum (such as a hash value) corresponding to the user biometric data and compare it with the checksum of the record in the tag. If the two checksums are the same, the verification result of the user biometric data can be determined to be reliable, that is, the user biometric data can be determined to have not been tampered with. At this time, biometric processing can be performed based on the processed user biometric data. If the two checksums are different, the verification result of the user biometric data can be determined to be unreliable. In addition, if the user biometric data does not contain an encrypted tag, the verification result of the user biometric data can also be determined to be unreliable.
[0046] This specification provides a privacy-preserving biometric identification method. When a terminal device receives a biometric identification request, it collects user biometric data for biometric processing using a biometric identification component. A trusted biometric application on the terminal device transmits the user biometric data from the biometric component to a trusted execution environment (TEX). In the TEX, privacy processing rules are applied to the user biometric data provided by the trusted biometric application to protect its privacy, resulting in processed user biometric data. The trusted biometric application then retrieves the processed user biometric data from the TEX and provides it to a server. The server verifies the trustworthiness of the processed user biometric data. If the verification is successful, biometric processing is performed based on the processed user biometric data. This achieves a trusted biometric identification scheme combining server-side and user-side capabilities, reducing the probability of biometric data being attacked or intercepted, preventing the leakage of user privacy data, and improving the trustworthiness of user authentication. Ultimately, this makes biometric identification from the terminal device's underlying layer to all other ends more reliable and secure.
[0047] Example 2
[0048] like Figure 2 As shown in the embodiments of this specification, a privacy-preserving biometric identification method is provided. The execution subject of this method can be a terminal device, such as a mobile phone, tablet computer, or personal computer (PC). This terminal device can be used in various services including biometric processing. The terminal device can be equipped with a trusted execution environment (TEE), which can be implemented using specified hardware devices and a program written in a predetermined programming language (i.e., hardware + software implementation) or a program written in a predetermined programming language (i.e., software implementation), depending on the specific circumstances. This trusted execution environment can be a secure operating environment for data processing. The method specifically includes the following steps:
[0049] In step S202, upon receiving a biometric request, user biometric data for biometric processing is collected based on the biometric component.
[0050] In step S204, the user's biometric data is transmitted in encrypted form to the trusted execution environment of the terminal device through the trusted biometric application; wherein, the trusted execution environment is configured with privacy processing rules to protect the user's biometric data provided by the trusted biometric application.
[0051] The privacy processing rules are set based on one or more of the following: information about the biometric components and trusted execution environment used to collect user biometric data; business rules corresponding to user biometric data; anti-tampering rules for user biometric data; and timeliness conditions for user biometric data. The anti-tampering rules for user biometric data can determine whether the user biometric data has been tampered with, for example, by determining whether the user biometric data contains specific or designated information, such as whether the user biometric data contains designated signature information and / or watermark information, and whether the designated signature information and / or watermark information is complete. Alternatively, the user biometric data can be calculated using a specified algorithm, and the calculation result can be used to determine whether the user biometric data has been tampered with. For example, the hash value of the user biometric data can be calculated, and the calculated hash value can be used to further determine whether the user biometric data has been tampered with. Specific rules can also be set according to actual circumstances. The business rules corresponding to user biometric data can be configured by associating privacy processing rules with the corresponding business. Different privacy processing rules can be set based on the different businesses associated with the user biometric data. For example, if the business associated with the user biometric data is electronic transaction, the privacy processing rules could verify whether the business type belongs to electronic transactions. If it is determined that the business type does not belong to electronic transactions (such as insurance or logistics), the user biometric data cannot be transmitted to the trusted execution environment. In practical applications, this is not the only possible implementation method; multiple implementation methods can be included, depending on the actual situation. This specification does not limit this aspect. The timeliness conditions for user biometric data can be set by defining timeliness conditions for its use. If the user biometric data is transmitted within the specified time, it is considered valid; otherwise, it is considered invalid. In practical applications, privacy processing rules can be set directly through the timeliness conditions of user biometric data, or the timeliness conditions can be combined with other rules to set privacy processing rules. Information related to the biometric components and trusted execution environment used to collect user biometric data may include information about the biometric components used to collect user biometric data and information about the trusted execution environment. Specifically, this may include identifiers of the biometric components (such as name, model, etc.) and identifiers of the trusted execution environment.
[0052] It should be noted that privacy processing rules can be set based on the above-mentioned multiple methods. In practical applications, in addition to setting privacy processing rules in the above ways, they can also be set in various other ways. Specifically, privacy processing rules can be flexibly set based on user needs, the business needs corresponding to user biometric data, etc.
[0053] In implementation, to ensure the security of user biometric data during data transmission, the user biometric data can be encrypted. The encryption algorithms used can include various methods, such as symmetric or asymmetric encryption algorithms. Trusted biometric applications can employ these symmetric or asymmetric encryption algorithms to encrypt the user biometric data, resulting in encrypted user biometric data (which is now ciphertext). Then, the trusted biometric application can transmit the encrypted user biometric data to the trusted execution environment of the terminal device through appropriate interfaces and data transmission channels, thereby ensuring the security of the user biometric data during transmission.
[0054] In practical applications, the processing of step S204 above can be varied. The following is an optional processing method, which may include the following: obtaining user biometric data from the biometric component through the trusted program corresponding to the biometric trusted application on the terminal device for performing biometric processing, and transmitting the user biometric data to the trusted execution environment of the terminal device through the trusted program corresponding to the biometric trusted application.
[0055] In this context, the trusted application corresponding to biometric trusted applications can be an application built upon a trusted program within the trusted execution environment (TEA) of the terminal device. The TEA also provides a secure execution environment for authorized secure applications (or trusted programs, i.e., TrustApps, TAs), while protecting the confidentiality, integrity, and access permissions of the trusted program's resources and data. Cryptographic techniques ensure isolation between different trusted programs, preventing any single trusted program from arbitrarily reading or manipulating the data of other trusted programs. Therefore, in addition to the independence between the TEA and the rich execution environment (REA) within the terminal device, each trusted program within the TEA also requires authorization and runs independently. Furthermore, trusted programs undergo integrity verification before execution to ensure they have not been tampered with. Trusted programs can interact directly with peripherals such as touchscreens, cameras, and fingerprint sensors without requiring interfaces from the terminal device's REA, thus ensuring data security. Trusted applications can include client programs and trusted end programs. The client program can be a trusted program corresponding to the biometric trusted application, and the trusted end program can be a corresponding trusted program in the trusted execution environment. The trusted program corresponding to the biometric trusted application can trigger the execution of the corresponding trusted program in the trusted execution environment, thereby enabling secure data transfer between the trusted program corresponding to the biometric trusted application and the corresponding trusted program in the trusted execution environment.
[0056] In implementation, user biometric data can be obtained through trusted programs corresponding to trusted biometric applications, thereby further ensuring the security of user biometric data. Furthermore, the trusted program corresponding to the trusted biometric application can trigger the execution of a corresponding trusted program in the trusted execution environment. Then, a secure data transmission channel is established between the trusted program corresponding to the trusted biometric application and the corresponding trusted program in the trusted execution environment. Through this established data transmission channel, the trusted program corresponding to the trusted biometric application can transmit user biometric data to the corresponding trusted program in the trusted execution environment of the terminal device, thus ensuring that the user biometric data securely reaches the trusted execution environment of the terminal device.
[0057] In step S206, in a trusted execution environment, the user's biometric data is processed for privacy protection according to privacy processing rules to obtain the processed user biometric data.
[0058] In step S208, the processed user biometric data is transmitted to a preset biometric software development kit (SDK) through a trusted biometric application.
[0059] The biometric SDK can be a software development kit built by the developers of the aforementioned applications to protect user privacy during the biometric identification process. This biometric SDK can act as a trusted program and may include one or more different processing mechanisms. For example, to facilitate subsequent authentication of user biometric data, mechanisms can be set up to directly retrieve user biometric data from the biometric component, along with related information about the biometric component and the trusted execution environment. Specific details can be configured according to actual needs. The biometric SDK can process user biometric data through these mechanisms to achieve privacy protection and authentication of the user's biometric data.
[0060] In step S210, the biometric SDK is used to send the processed user biometric data to the server through a preset biometric interface. The biometric SDK is used to obtain user biometric data and send it to the server through the biometric interface so that the server can perform a credibility verification on the processed user biometric data. After the verification is passed, biometric processing is performed based on the processed user biometric data.
[0061] The biometric interface can be a unified interface pre-set in the terminal device for transmitting data related to the user's biometric data. In practical applications, since user biometric data can include multiple types, the biometric interface can be set according to different types of user biometric data. For example, a biometric interface can be set for facial recognition, a biometric interface can be set for fingerprint recognition, and a biometric interface can be set for iris recognition. Alternatively, a unified biometric interface can be set for multiple different types of user biometric data. For example, the same biometric interface can be set for facial recognition and fingerprint recognition. The specific settings can be determined according to the actual situation.
[0062] In step S212, an update request for privacy processing rules in the trusted execution environment of the terminal device is received. The update request includes rule data to be updated, and the rule data to be updated is encrypted.
[0063] In implementation, privacy processing rules can include various different contents. In practical applications, a model for privacy protection processing of user biometric data can be set up in a trusted execution environment, depending on the actual situation. This model can be obtained through a complex program written in a predetermined programming language, or through a simpler algorithm; this specification does not limit this. Furthermore, to prevent unrelated users or organizations from updating the privacy processing rules, information about users or organizations with update permissions (such as the user or organization that initially set up the privacy processing rule, or the user or organization that created the privacy processing rule, or a pre-designated user or organization) can be set for the privacy processing rules. That is, only users or organizations with update permissions can update the privacy processing rules. When it is necessary to update a privacy processing rule in the trusted execution environment, the user can input the identifier of the privacy processing rule to be modified and the rule data to be updated through the biometric trusted application on their terminal device. After input, the terminal device can obtain the input identifier of the privacy processing rule to be updated and the rule data to be updated, and can generate an update request, thereby allowing the terminal device to obtain the update request for the privacy processing rule.
[0064] It should be noted that the rule data to be updated may be the model or algorithm in the privacy processing rule, or the business type to which the privacy processing rule applies. The specific data can be set according to the actual situation, and the embodiments in this specification do not limit this.
[0065] In step S214, the rule data to be updated is transmitted to the trusted execution environment of the terminal device through a biometric trusted application.
[0066] In step S216, in a trusted execution environment, the rule data to be updated is decrypted, and the privacy processing rules are updated based on the decrypted rule data to be updated.
[0067] In implementation, after receiving an update request for a privacy processing rule, the terminal device can obtain the identifier of the privacy processing rule contained in the update request and locate the corresponding privacy processing rule in the trusted execution environment using this identifier. It can also obtain information about users or organizations with the authority to update the privacy processing rule. From this information, it can check whether the user or organization that initiated the update request is included. If so, it can be determined that the initiating user or organization has the authority to update the privacy processing rule. In this case, the terminal device can update the privacy processing rule in the trusted execution environment based on the update request to obtain the updated privacy processing rule. If not, it can be determined that the initiating user or organization does not have the authority to update the privacy processing rule. In this case, the terminal device can send an update failure notification message to the initiating user or organization.
[0068] It should be noted that the process of updating the privacy processing rules in steps S212 to S216 can be performed after steps S202 to S210. In practical applications, the process of steps S212 to S216 can also be performed before steps S202 to S210. This specification does not limit this.
[0069] This specification provides a privacy-preserving biometric identification method. When a terminal device receives a biometric identification request, it collects user biometric data for biometric processing using a biometric identification component. A trusted biometric application on the terminal device transmits the user biometric data from the biometric component to a trusted execution environment (TEX). In the TEX, privacy processing rules are applied to the user biometric data provided by the trusted biometric application to protect its privacy, resulting in processed user biometric data. The trusted biometric application then retrieves the processed user biometric data from the TEX and provides it to a server. The server verifies the trustworthiness of the processed user biometric data. If the verification is successful, biometric processing is performed based on the processed user biometric data. This achieves a trusted biometric identification scheme combining server-side and user-side capabilities, reducing the probability of biometric data being attacked or intercepted, preventing the leakage of user privacy data, and improving the trustworthiness of user authentication. Ultimately, this makes biometric identification from the terminal device's underlying layer to all other ends more reliable and secure.
[0070] Example 3
[0071] like Figure 3A and Figure 3B As shown in the embodiments of this specification, a privacy-preserving biometric identification method is provided. The execution entity of this method can be a server, which can be a single server or a server cluster composed of multiple different servers. The server can be used in various services that include biometric processing. Specifically, the method may include the following steps:
[0072] In step S302, the user biometric data is received from the terminal device after being processed by privacy processing rules set in the executable environment of the terminal device.
[0073] The relevant processing of step S302 above can be found in the relevant content of Embodiment 1 and Embodiment 2 above, and will not be repeated here.
[0074] In step S304, the processed user biometric data is verified for credibility based on preset privacy verification rules, and the corresponding verification results are obtained.
[0075] The privacy verification rules can be rules that verify the trustworthiness of user biometric data. These rules can be set in various ways, specifically according to the privacy processing rules described above. Furthermore, the privacy verification rules are pre-configured in the server's trusted execution environment. To ensure their security, they can be stored in encrypted form on the server.
[0076] In implementation, the processed user biometric data can be analyzed to determine information such as the business category corresponding to the processed user biometric data, and to obtain relevant privacy verification rules. The obtained privacy verification rules can be used to verify the credibility of the processed user biometric data. This credibility verification can take various forms. For example, an encrypted tag can be pre-set in the processed user biometric data, and this tag can pre-record a verification value (such as a hash value) of the user biometric data. Based on the obtained privacy verification rules, the tag can be decrypted to obtain its original content, and the original data corresponding to the processed user biometric data can also be decrypted to obtain the user biometric data. Then, the verification value (such as a hash value) corresponding to the user biometric data can be calculated, and the calculated verification value can be compared with the verification value recorded in the tag. Based on the comparison result, the corresponding verification result can be determined. Additionally, the tag's validity can be set (in this case, it is also necessary to verify whether the tag is within a set validity period before determining the corresponding verification result), which can be set according to the actual situation.
[0077] The above-described process for verifying the credibility of processed user biometric data is only one feasible method. In practical applications, other methods can also be used to verify the credibility of processed user biometric data. Different methods can be used to verify the credibility of processed user biometric data according to different privacy verification rules. Moreover, the specific processing procedure for verifying the credibility of processed user biometric data can be different depending on the privacy verification rules. The specific procedure can be set according to the actual situation, and the embodiments in this specification do not limit this.
[0078] In step S306, if the above verification result is successful, biometric processing is performed based on the processed user biometric data, and the biometric processing result is sent to the terminal device.
[0079] In practice, if the above verification result is successful, it indicates that the processed user biometric data is reliable and has not been tampered with. At this time, the server can perform biometric processing on the processed user biometric data according to the biometric processing mechanism to obtain the user identity information corresponding to the user biometric data, thereby obtaining the biometric processing result. Then, the biometric processing result can be sent to the terminal device. After receiving the biometric processing result, the terminal device can display it to the user and continue subsequent processing.
[0080] If the above verification result is that the verification fails, it indicates that the processed user biometric data is unreliable and may have been tampered with. In this case, the server can generate a biometric processing result indicating that the biometric processing has failed, and then send the biometric processing result to the terminal device.
[0081] This specification provides a privacy-preserving biometric identification method. When a terminal device receives a biometric identification request, it collects user biometric data for biometric processing using a biometric identification component. A trusted biometric application on the terminal device transmits the user biometric data from the biometric component to a trusted execution environment (TEX). In the TEX, privacy processing rules are applied to the user biometric data provided by the trusted biometric application to protect its privacy, resulting in processed user biometric data. The trusted biometric application then retrieves the processed user biometric data from the TEX and provides it to a server. The server verifies the trustworthiness of the processed user biometric data. If the verification is successful, biometric processing is performed based on the processed user biometric data. This achieves a trusted biometric identification scheme combining server-side and user-side capabilities, reducing the probability of biometric data being attacked or intercepted, preventing the leakage of user privacy data, and improving the trustworthiness of user authentication. Ultimately, this makes biometric identification from the terminal device's underlying layer to all other ends more reliable and secure.
[0082] Example 4
[0083] like Figure 4 As shown in the embodiments of this specification, a privacy-preserving biometric identification method is provided. The execution entity of this method can be a server, which can be a single server or a server cluster composed of multiple different servers. The server can be used in various services that include biometric processing. Specifically, the method may include the following steps:
[0084] In step S402, the user biometric data is received from the terminal device after being processed for privacy protection by the privacy processing rules set in the executable environment of the terminal device.
[0085] In step S404, based on preset privacy verification rules, one or more of the following data are obtained: user biometric data, information about the biometric components and trusted execution environment used to collect user biometric data.
[0086] In implementation, privacy verification rules can include various types. One optional privacy verification rule is provided below, which can specifically include: The privacy verification rule can include rules for directly obtaining user biometric data from biometric components, and obtaining relevant information about the biometric components used to collect the user biometric data and the trusted execution environment. Additionally, it can include log data recording whether the user biometric data undergoes privacy protection processing within the trusted execution environment, as well as relevant information about the various components and applications through which the user biometric data flows during transmission. Based on this, the server can analyze the privacy verification rules and perform corresponding processing or obtain corresponding information according to the rule content information recorded in the privacy verification rules. For example, it can trigger the terminal device to directly obtain user biometric data from the biometric components and send it to the server, and trigger the terminal device to obtain relevant information about the biometric components used to collect the user biometric data and the trusted execution environment, and send it to the server. Furthermore, it can also trigger the terminal device to obtain log data recording whether the user biometric data undergoes privacy protection processing within the trusted execution environment, as well as relevant information about the various components and applications through which the user biometric data flows during transmission, and send it to the server.
[0087] In step S406, the credibility of the processed user biometric data is verified based on the acquired data to obtain the corresponding verification result.
[0088] In implementation, based on the example of step S404 above, the server can compare the relevant information of the biometric component used to collect user biometric data with the relevant information of the biometric component corresponding to the processed user biometric data. If they are the same, the server can compare the relevant information of the acquired trusted execution environment with the relevant information of the trusted execution environment corresponding to the processed user biometric data. If they are the same, the server can analyze the acquired log data to determine whether the user biometric data has undergone privacy protection processing in the trusted execution environment. If so, the server can compare the relevant information of each component and application through which the user biometric data flows during transmission with the relevant information corresponding to the processed user biometric data. If they are the same, the server can compare the user biometric data directly obtained from the biometric component with the user biometric data corresponding to the processed user biometric data. If they are the same, the server determines that the trustworthiness verification of the processed user biometric data has passed; otherwise, the server determines that the trustworthiness verification of the processed user biometric data has failed.
[0089] In practical applications, the specific processing method of the above step S406 can be varied. In addition to the above method, it can also be processed in a variety of ways. The following provides three optional processing methods, which can specifically include the following processing methods one to three.
[0090] Method 1: Trustworthiness verification based on verifiable claims, which may specifically include the following steps A2 and A4.
[0091] A2, based on preset privacy verification rules, obtains the verifiable claims corresponding to the processed user biometric data and verifies the validity of the verifiable claims.
[0092] Verifiable statements can be normative information describing certain attributes of entities such as individuals and organizations. They enable evidence-based trust, allowing entities to verify the credibility of information regarding certain attributes of the current entity. A verifiable statement can include multiple fields and corresponding values. For example, a field might represent the business entity corresponding to the user's biometric data, with the corresponding value being organization A; another field might represent the time when the user's biometric data underwent privacy protection processing, with the corresponding value being February 1, 2021, 11:11:52, etc.
[0093] In implementation, if the privacy verification rules include rule content information for a verifiable claim corresponding to the processed user biometric data, the verifiable claim corresponding to the user biometric data can be obtained from the specified device based on the privacy verification rules. Then, the verifiable claim can be verified to determine its validity. Specifically, the verification process can include various steps, such as calculating the field values contained in the verifiable claim using a predetermined algorithm (e.g., calculating the hash value of the field values contained in the verifiable claim using a hash algorithm) to obtain the corresponding calculation result. The verifiable claim also includes the exact value (or baseline value) of the above calculation result. The obtained calculation result can be compared with the exact value in the verifiable claim. If they are the same, the verifiable claim is valid. In this case, appropriate processing can be performed based on the verifiable claim to further ensure the security of data processing; otherwise, the verifiable claim is invalid.
[0094] It should be noted that the methods for verifying the validity of a verifiable claim are not limited to those mentioned above, but may include other possible methods. The specific methods can be set according to the actual situation, and the embodiments in this specification do not limit this.
[0095] A4. If the verification result is valid, then based on the other sub-rules in the privacy verification rules (excluding the sub-rule corresponding to the verifiable claim), the processed user biometric data is verified for credibility, and the corresponding verification result is obtained.
[0096] In practical applications, there are many ways to process step A4 above. In addition to the above method, there are many other ways to process it. The following is another optional processing method, which may include the processing of steps A42 and A44.
[0097] A42, if the verification result is valid, then obtain the verification sub-rule corresponding to the holder of the verifiable claim based on the privacy verification rule.
[0098] In implementation, verification sub-rules can be set for holders of different verifiable claims, or the holders of verifiable claims can pre-set verification sub-rules. After confirming the validity of the verifiable claim, the verification sub-rules corresponding to the holder of the verifiable claim can be obtained from the specified device based on the privacy verification rules.
[0099] A44, based on the verification sub-rules corresponding to the holder of the verifiable claim, performs credibility verification on the processed user biometric data and obtains the corresponding verification results.
[0100] Method 2: Credibility verification based on verification algorithm, which may include the following steps B2 and B4.
[0101] B2 calculates the processed user biometric data based on the verification algorithm corresponding to the privacy verification rules, and obtains the corresponding calculation results.
[0102] The verification algorithm corresponding to the privacy verification rule can be of various types. For example, the verification algorithm can be a hash algorithm, or it can be a data comparison algorithm, etc. The specific algorithm can be set according to the actual situation.
[0103] B4 matches the calculated result with the baseline result in the privacy verification rules, and determines the verification result of the credibility verification of the processed user biometric data based on the matching result.
[0104] In implementation, the trusted biometric application in the terminal device can pre-obtain a baseline result and send it to the server. After receiving the calculated result of the processed user biometric data, the calculated result can be matched with the baseline result. If they match, the verification result is considered successful; otherwise, the verification result is considered unsuccessful.
[0105] Method 3: Trustworthiness verification based on digital identity information, which may specifically include the following steps C2 and C4.
[0106] C2, based on preset privacy verification rules, obtains the user's digital identity information corresponding to the processed user biometric data, and checks whether the user's digital identity information exists in the pre-stored digital identity information.
[0107] Digital identity information refers to information that identifiableally portrays a user through digitization; that is, condensing real identity information into digital code to facilitate the binding, querying, and verification of a user's real-time behavioral information. Digital identity information can include not only identity coding information such as a user's birth information, individual description, and biometrics, but also various attributes of personal behavioral information (such as transaction information or entertainment information). Digital identity information can be presented in various ways, such as through DID (Decentralized Identity).
[0108] C4, if it exists, then based on the other sub-rules in the privacy verification rules besides the sub-rule corresponding to obtaining the user's digital identity information, the processed user biometric data is verified for credibility, and the corresponding verification result is obtained.
[0109] In step S408, if the above verification result is successful, biometric processing is performed based on the processed user biometric data, and the biometric processing result is sent to the terminal device.
[0110] This specification provides a privacy-preserving biometric identification method. When a terminal device receives a biometric identification request, it collects user biometric data for biometric processing using a biometric identification component. A trusted biometric application on the terminal device transmits the user biometric data from the biometric component to a trusted execution environment (TEX). In the TEX, privacy processing rules are applied to the user biometric data provided by the trusted biometric application to protect its privacy, resulting in processed user biometric data. The trusted biometric application then retrieves the processed user biometric data from the TEX and provides it to a server. The server verifies the trustworthiness of the processed user biometric data. If the verification is successful, biometric processing is performed based on the processed user biometric data. This achieves a trusted biometric identification scheme combining server-side and user-side capabilities, reducing the probability of biometric data being attacked or intercepted, preventing the leakage of user privacy data, and improving the trustworthiness of user authentication. Ultimately, this makes biometric identification from the terminal device's underlying layer to all other ends more reliable and secure.
[0111] Example 5
[0112] This embodiment will describe in detail a privacy-preserving biometric method provided by the present invention in conjunction with a specific application scenario. The corresponding application scenario is a facial recognition application scenario, wherein the biometric request is a facial recognition request, the biometric component is a camera component, the user biometric data is user facial data, the biometric SDK is a facial recognition SDK, and the biometric processing is facial recognition processing.
[0113] like Figure 5 As shown in the embodiments of this specification, a privacy-preserving biometric identification method is provided. The execution entity of this method can be a server and a terminal device, wherein the terminal device can be a device such as a mobile phone, tablet computer, or personal computer (PC). The terminal device can be used in various services including biometric processing. The terminal device can be equipped with a trusted execution environment (TEE), which can be implemented using specified hardware devices and a program written in a predetermined programming language (i.e., it can be implemented in hardware + software form), or it can be implemented using a program written in a predetermined programming language (i.e., it can be implemented in software form), etc., depending on the actual situation. The server can be a server for a specific service (such as a transaction service or financial service) or for biometric processing. The method specifically includes the following steps:
[0114] In step S502, upon receiving a facial recognition request, the terminal device collects user facial data for facial recognition processing based on the camera component.
[0115] In step S504, the terminal device transmits the user's facial data in encrypted form to the trusted execution environment of the terminal device through a biometric trusted application; wherein, the trusted execution environment is configured with privacy processing rules for privacy protection processing of the user's facial data provided by the biometric trusted application.
[0116] In step S506, the terminal device performs privacy protection processing on the user's facial data in a trusted execution environment according to privacy processing rules, and obtains the processed user facial data.
[0117] In step S508, the terminal device transmits the processed user facial data to the preset facial recognition SDK through a biometric trusted application.
[0118] In step S510, the terminal device uses the facial recognition SDK to send the processed user facial data to the server through a preset biometric interface, and uses the facial recognition SDK to obtain user facial data and sends the user facial data to the server through the biometric interface.
[0119] In step S512, the server obtains one or more of the following data based on preset privacy verification rules: user facial data, information about the camera component used to collect the user facial data, and information about the trusted execution environment.
[0120] In step S514, the server performs a credibility verification on the processed user facial data based on the acquired data and obtains the corresponding verification result.
[0121] In step S516, if the above verification result is successful, the server performs facial recognition processing based on the processed user facial data and sends the facial recognition processing result to the terminal device.
[0122] In step S518, the terminal device receives an update request for privacy processing rules in the trusted execution environment of the terminal device. The update request includes rule data to be updated, and the rule data to be updated is encrypted.
[0123] In step S520, the terminal device transmits the rule data to be updated to the trusted execution environment of the terminal device through a biometric trusted application.
[0124] In step S522, the terminal device decrypts the rule data to be updated in a trusted execution environment and updates the privacy processing rules based on the decrypted rule data to be updated.
[0125] This specification provides a privacy-preserving biometric identification method. When a terminal device receives a biometric identification request, it collects user biometric data for biometric processing using a biometric identification component. A trusted biometric application on the terminal device transmits the user biometric data from the biometric component to a trusted execution environment (TEX). In the TEX, privacy processing rules are applied to the user biometric data provided by the trusted biometric application to protect its privacy, resulting in processed user biometric data. The trusted biometric application then retrieves the processed user biometric data from the TEX and provides it to a server. The server verifies the trustworthiness of the processed user biometric data. If the verification is successful, biometric processing is performed based on the processed user biometric data. This achieves a trusted biometric identification scheme combining server-side and user-side capabilities, reducing the probability of biometric data being attacked or intercepted, preventing the leakage of user privacy data, and improving the trustworthiness of user authentication. Ultimately, this makes biometric identification from the terminal device's underlying layer to all other ends more reliable and secure.
[0126] Example 6
[0127] The above describes a privacy-preserving biometric method provided in the embodiments of this specification. Based on the same idea, the embodiments of this specification also provide a privacy-preserving biometric device, which is equipped with a trusted execution environment, such as... Figure 6 As shown.
[0128] The privacy-preserving biometric device includes: a data acquisition module 601, a data transmission module 602, a privacy-preserving processing module 603, and a data processing module 604, wherein:
[0129] Data acquisition module 601, upon receiving a biometric request, collects user biometric data for biometric processing based on the biometric component;
[0130] The data transmission module 602 transmits the user's biometric data from the biometric component to the trusted execution environment of the device through a trusted biometric application on the device for performing biometric processing; wherein, the trusted execution environment is configured with privacy processing rules for privacy protection processing of the user's biometric data provided by the trusted biometric application;
[0131] The privacy protection processing module 603 performs privacy protection processing on the user biometric data according to the privacy processing rules in the trusted execution environment to obtain processed user biometric data.
[0132] The data processing module 604 obtains the processed user biometric data from the trusted execution environment based on the biometric trusted application, and provides the processed user biometric data to the server so that the server can perform trust verification on the processed user biometric data, and perform biometric processing based on the processed user biometric data after the verification is passed.
[0133] In this embodiment of the specification, the data processing module 604 includes:
[0134] The data transmission unit transmits the processed user biometric data to a preset biometric software development kit (SDK) through the biometric trusted application.
[0135] The data sending unit uses the biometric SDK to send the processed user biometric data to the server through a preset biometric interface, and uses the biometric SDK to obtain the user biometric data and sends the user biometric data to the server through the biometric interface.
[0136] In the embodiments described in this specification, the biometric request is a facial recognition request, the biometric component is a camera component, and the user biometric data is user facial data.
[0137] In this embodiment of the specification, the data transmission module 602 transmits the user's biometric data in encrypted form to the trusted execution environment of the device through the trusted biometric application.
[0138] In the embodiments described in this specification, the device further includes:
[0139] The update request module receives an update request for the privacy processing rules in the trusted execution environment of the device. The update request includes rule data to be updated, and the rule data to be updated is encrypted.
[0140] The update data transmission module transmits the rule data to be updated to the trusted execution environment of the device through the biometric trusted application.
[0141] The update module decrypts the rule data to be updated in the trusted execution environment and updates the privacy processing rules based on the decrypted rule data.
[0142] In the embodiments described in this specification, the privacy processing rules are set based on one or more of the following:
[0143] Information related to the biometric component and the trusted execution environment used to collect the user's biometric data;
[0144] The business rules corresponding to the user's biometric data;
[0145] The anti-tampering rules for the user's biometric data; and...
[0146] The timeliness condition of the user's biometric data.
[0147] This specification provides a privacy-preserving biometric identification device. Upon receiving a biometric request, a terminal device collects user biometric data for biometric processing using a biometric component. A trusted biometric application on the terminal device transmits the user biometric data from the biometric component to a trusted execution environment (TEA). In the TEA, privacy processing rules are applied to the user biometric data provided by the trusted biometric application to protect its privacy, resulting in processed user biometric data. The trusted biometric application then retrieves the processed user biometric data from the TEA and provides it to a server. The server verifies the trustworthiness of the processed user biometric data. If the verification is successful, biometric processing is performed based on the processed user biometric data. This achieves a trusted biometric identification scheme combining server-side and user-side capabilities, reducing the probability of biometric data being attacked or intercepted, preventing the leakage of user privacy data, and improving the trustworthiness of user authentication. Ultimately, this makes biometric identification from the terminal device's underlying layer to all other ends more reliable and secure.
[0148] Example 7
[0149] Following the same line of thought, embodiments of this specification also provide a privacy-preserving biometric device, such as... Figure 7 As shown.
[0150] The privacy-preserving biometric device includes: a data receiving module 701, a privacy verification module 702, and a biometric identification module 703, wherein:
[0151] The data receiving module 701 receives user biometric data sent by the terminal device after privacy protection processing by privacy processing rules set in the executable environment of the terminal device.
[0152] The privacy verification module 702 performs a credibility verification on the processed user biometric data based on preset privacy verification rules, and obtains the corresponding verification results.
[0153] If the verification result is successful, the biometric module 703 performs biometric processing based on the processed user biometric data and sends the biometric processing result to the terminal device.
[0154] In this embodiment of the specification, the privacy verification module 702 includes:
[0155] The data acquisition unit, based on preset privacy verification rules, acquires one or more of the following data: the user's biometric data, information related to the biometric component used to collect the user's biometric data, and the trusted execution environment;
[0156] The first privacy verification unit performs a credibility verification on the processed user biometric data based on the acquired data, and obtains the corresponding verification result.
[0157] In this embodiment of the specification, the privacy verification module 702 includes:
[0158] The verification unit, based on preset privacy verification rules, obtains the verifiable claim corresponding to the processed user biometric data and verifies the validity of the verifiable claim.
[0159] If the verification result is valid, the second privacy verification unit performs a credibility verification on the processed user biometric data based on the other sub-rules in the privacy verification rules, excluding the sub-rule corresponding to the verifiable declaration, and obtains the corresponding verification result.
[0160] In this embodiment of the specification, if the verification result is valid, the second privacy verification unit obtains the verification sub-rule corresponding to the holder of the verifiable claim based on the privacy verification rule; and performs a credibility verification on the processed user biometric data based on the verification sub-rule corresponding to the holder of the verifiable claim to obtain the corresponding verification result.
[0161] In this embodiment of the specification, the privacy verification module 702 includes:
[0162] The calculation unit performs calculations on the processed user biometric data based on the verification algorithm corresponding to the privacy verification rule, and obtains the corresponding calculation results.
[0163] The third privacy verification unit matches the obtained calculation result with the benchmark result in the privacy verification rule, and determines the verification result of the credibility verification of the processed user biometric data based on the matching result.
[0164] This specification provides a privacy-preserving biometric identification device. Upon receiving a biometric request, a terminal device collects user biometric data for biometric processing using a biometric component. A trusted biometric application on the terminal device transmits the user biometric data from the biometric component to a trusted execution environment (TEA). In the TEA, privacy processing rules are applied to the user biometric data provided by the trusted biometric application to protect its privacy, resulting in processed user biometric data. The trusted biometric application then retrieves the processed user biometric data from the TEA and provides it to a server. The server verifies the trustworthiness of the processed user biometric data. If the verification is successful, biometric processing is performed based on the processed user biometric data. This achieves a trusted biometric identification scheme combining server-side and user-side capabilities, reducing the probability of biometric data being attacked or intercepted, preventing the leakage of user privacy data, and improving the trustworthiness of user authentication. Ultimately, this makes biometric identification from the terminal device's underlying layer to all other ends more reliable and secure.
[0165] Example 8
[0166] The above are examples of privacy-preserving biometric devices provided in this specification. Based on the same concept, this specification also provides a privacy-preserving biometric device, such as... Figure 8 As shown.
[0167] The privacy-protected biometric device can be the terminal device or server provided in the above embodiments.
[0168] Privacy-preserving biometric devices can vary significantly in configuration and performance. They may include one or more processors 801 and memory 802, with memory 802 storing one or more applications or data. Memory 802 can be temporary or persistent storage. Applications stored in memory 802 may include one or more modules (not shown), each module including a series of computer-executable instructions for the privacy-preserving biometric device. Furthermore, processor 801 may be configured to communicate with memory 802, executing the series of computer-executable instructions in memory 802 on the privacy-preserving biometric device. Privacy-preserving biometric devices may also include one or more power supplies 803, one or more wired or wireless network interfaces 804, one or more input / output interfaces 805, and one or more keyboards 806.
[0169] Specifically, in this embodiment, the privacy-preserving biometric device includes a memory and one or more programs, wherein one or more programs are stored in the memory, and one or more programs may include one or more modules, and each module may include a series of computer-executable instructions for the privacy-preserving biometric device, and is configured to be executed by one or more processors. The one or more programs include computer-executable instructions for performing the following:
[0170] Upon receiving a biometric request, user biometric data is collected using the biometric component for biometric processing.
[0171] The user's biometric data is transmitted from the biometric component to the trusted execution environment of the terminal device through a trusted biometric application on the terminal device for performing biometric processing; wherein, the trusted execution environment is configured with privacy processing rules to perform privacy protection processing on the user's biometric data provided by the trusted biometric application;
[0172] In the trusted execution environment, the user biometric data is subjected to privacy protection processing through the privacy processing rules to obtain processed user biometric data.
[0173] The biometric trusted application obtains the processed user biometric data from the trusted execution environment and provides the processed user biometric data to the server so that the server can verify the trustworthiness of the processed user biometric data and perform biometric processing based on the processed user biometric data after the verification is passed.
[0174] Furthermore, specifically in this embodiment, the privacy-preserving biometric device includes a memory and one or more programs, wherein one or more programs are stored in the memory, and one or more programs may include one or more modules, and each module may include a series of computer-executable instructions for the privacy-preserving biometric device, and is configured to be executed by one or more processors. The one or more programs include computer-executable instructions for performing the following:
[0175] The user biometric data received from the terminal device is processed for privacy protection by privacy processing rules set in the executable environment of the terminal device;
[0176] Based on preset privacy verification rules, the processed user biometric data is verified for credibility, and the corresponding verification results are obtained.
[0177] If the verification result is successful, then biometric processing is performed based on the processed user biometric data, and the biometric processing result is sent to the terminal device.
[0178] This specification provides a privacy-preserving biometric device. Upon receiving a biometric request, the terminal device collects user biometric data for processing using a biometric component. A trusted biometric application on the terminal device transmits the user biometric data from the biometric component to a trusted execution environment. In the trusted execution environment, privacy processing rules are applied to the user biometric data provided by the trusted biometric application to protect its privacy. The resulting processed user biometric data is then retrieved from the trusted execution environment by the trusted biometric application and provided to a server. The server verifies the trustworthiness of the processed user biometric data. If the verification is successful, biometric processing is performed based on the processed user biometric data. This achieves a trusted biometric solution combining server-side and user-side capabilities, reducing the probability of biometric data being attacked or intercepted, preventing the leakage of user privacy data, and improving the trustworthiness of user authentication. Ultimately, this makes biometric identification from the terminal device's underlying layer to all other ends more reliable and secure.
[0179] Example 9
[0180] Furthermore, based on the above Figures 1A to 5 The method shown in this specification, along with one or more embodiments, also provides a storage medium for storing computer-executable instruction information. In one specific embodiment, the storage medium can be a USB flash drive, optical disc, hard disk, etc. When the computer-executable instruction information stored in the storage medium is executed by a processor, it can achieve the following process:
[0181] Upon receiving a biometric request, user biometric data is collected using the biometric component for biometric processing.
[0182] The user's biometric data is transmitted from the biometric component to the trusted execution environment of the terminal device through a trusted biometric application on the terminal device for performing biometric processing; wherein, the trusted execution environment is configured with privacy processing rules to perform privacy protection processing on the user's biometric data provided by the trusted biometric application;
[0183] In the trusted execution environment, the user biometric data is subjected to privacy protection processing through the privacy processing rules to obtain processed user biometric data.
[0184] The biometric trusted application obtains the processed user biometric data from the trusted execution environment and provides the processed user biometric data to the server so that the server can verify the trustworthiness of the processed user biometric data and perform biometric processing based on the processed user biometric data after the verification is passed.
[0185] In another specific embodiment, the storage medium can be a USB flash drive, optical disc, hard disk, etc., and the computer-executable instruction information stored in the storage medium can achieve the following process when executed by the processor:
[0186] The user biometric data received from the terminal device is processed for privacy protection by privacy processing rules set in the executable environment of the terminal device;
[0187] Based on preset privacy verification rules, the processed user biometric data is verified for credibility, and the corresponding verification results are obtained.
[0188] If the verification result is successful, then biometric processing is performed based on the processed user biometric data, and the biometric processing result is sent to the terminal device.
[0189] This specification provides a storage medium that, upon receiving a biometric request, allows a terminal device to collect user biometric data for biometric processing based on a biometric component. A trusted biometric application on the terminal device then transmits the user biometric data from the biometric component to a trusted execution environment (TEA). Within the TEA, privacy processing rules are applied to the user biometric data provided by the trusted biometric application to protect its privacy, resulting in processed user biometric data. The trusted biometric application then retrieves the processed user biometric data from the TEA and provides it to a server. The server verifies the trustworthiness of the processed user biometric data and, upon successful verification, performs biometric processing. This achieves a trusted biometric scheme combining server-side and user-side capabilities, reducing the probability of biometric data being attacked or intercepted, preventing the leakage of user privacy data, and improving the trustworthiness of user authentication. Ultimately, this makes biometric identification from the terminal device's underlying layer to all other endpoints more reliable and secure.
[0190] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0191] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the methodology). However, with technological advancements, many methodological improvements today can be considered direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that a methodological improvement cannot be implemented using a hardware physical module. For example, a Programmable Logic Device (PLD) (e.g., a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program a digital system themselves to "integrate" it onto a PLD, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should understand that by simply performing some logic programming on the method flow using one of these hardware description languages and programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.
[0192] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, ASICs, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.
[0193] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.
[0194] For ease of description, the above apparatus is described by dividing it into various functional units. Of course, when implementing one or more embodiments of this specification, the functions of each unit can be implemented in one or more software and / or hardware.
[0195] Those skilled in the art will understand that the embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, one or more embodiments of this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0196] The embodiments described herein are illustrated with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this specification. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable parallel device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable parallel device, create means for implementing the functions specified in one or more flowchart illustrations and / or one or more block diagrams.
[0197] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable fraud device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.
[0198] These computer program instructions may also be loaded onto a computer or other programmable device in parallel or in series, causing a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable device, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.
[0199] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0200] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0201] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0202] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0203] Those skilled in the art will understand that the embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, one or more embodiments of this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0204] One or more embodiments of this specification can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a particular task or implement a particular abstract data type. One or more embodiments of this specification can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0205] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.
[0206] The above description is merely an embodiment of this specification and is not intended to limit this specification. Various modifications and variations can be made to this specification by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of the claims of this specification.
Claims
1. A privacy-preserving biometric identification method, applied to a terminal device equipped with a trusted execution environment, the method comprising: Upon receiving a biometric request, user biometric data is collected using the biometric component for biometric processing. The user's biometric data is transmitted from the biometric component to the trusted execution environment of the terminal device through a trusted biometric application on the terminal device for performing biometric processing; wherein, the trusted execution environment is configured with privacy processing rules to perform privacy protection processing on the user's biometric data provided by the trusted biometric application; In the trusted execution environment, the user biometric data is subjected to privacy protection processing through the privacy processing rules to obtain processed user biometric data. The processed user biometric data is obtained from the trusted execution environment based on the biometric trusted application, and then transmitted to a preset biometric software development kit (SDK) through the biometric trusted application. Using the biometric SDK, the processed user biometric data is sent to a server through a preset biometric interface. The server, based on preset privacy verification rules, obtains relevant information about the biometric component and / or the trusted execution environment used to collect the user biometric data, or obtains multiple of the following: the user biometric data, relevant information about the biometric component used to collect the user biometric data, and the trusted execution environment. Based on the obtained data, the server performs a trustworthiness verification on the processed user biometric data, and after successful verification, performs biometric processing based on the processed user biometric data.
2. The method according to claim 1, further comprising: The user's biometric data is obtained using the biometric SDK and sent to the server through the biometric interface.
3. The method according to claim 1 or 2, wherein the biometric request is a facial recognition request, the biometric component is a camera component, and the user biometric data is user facial data.
4. The method according to claim 3, wherein transmitting the user's biometric data to the trusted execution environment of the terminal device via a trusted biometric application on the terminal device for performing biometric processing includes: The biometric trusted application transmits the user's biometric data in encrypted form to the trusted execution environment of the terminal device.
5. The method according to claim 4, further comprising: The device receives an update request for the privacy processing rules in the trusted execution environment of the terminal device, the update request including rule data to be updated, the rule data to be updated being encrypted; The biometric trusted application transmits the rule data to be updated to the trusted execution environment of the terminal device. In the trusted execution environment, the rule data to be updated is decrypted, and the privacy processing rules are updated based on the decrypted rule data to be updated.
6. The method according to claim 1, wherein the privacy processing rule is set based on relevant information of the biometric component and the trusted execution environment used to collect the user's biometric data, or the privacy processing rule is set based on relevant information of the biometric component and the trusted execution environment used to collect the user's biometric data, and one or more of the following: The business rules corresponding to the user's biometric data; The anti-tampering rules for the user's biometric data; and... The timeliness condition of the user's biometric data.
7. A privacy-preserving biometric identification method, the method comprising: The system receives processed user biometric data sent by a terminal device, which has undergone privacy protection processing according to privacy rules set in the trusted execution environment of the terminal device. This processed user biometric data is collected by the terminal device based on a biometric component when a biometric request is received. The data is then transmitted from the biometric component to the trusted execution environment of the terminal device via a trusted biometric application for performing biometric processing. Within the trusted execution environment, the user biometric data is protected against privacy using privacy rules set in the trusted execution environment. The trusted biometric application then retrieves the processed user biometric data from the trusted execution environment and transmits it to a preset biometric software development kit (SDK). Finally, the biometric SDK is used to send the processed user biometric data through a preset biometric interface. Based on preset privacy verification rules, obtain relevant information about the biometric component and / or the trusted execution environment used to collect the user's biometric data, or obtain multiple of the following data: the user's biometric data, relevant information about the biometric component and the trusted execution environment used to collect the user's biometric data; perform trustworthiness verification on the processed user's biometric data based on the obtained data, and obtain the corresponding verification result; If the verification result is successful, then biometric processing is performed based on the processed user biometric data, and the biometric processing result is sent to the terminal device.
8. The method according to claim 7, wherein the step of performing a credibility verification on the processed user biometric data based on preset privacy verification rules to obtain a corresponding verification result includes: Based on preset privacy verification rules, obtain verifiable claims corresponding to the processed user biometric data, and verify the validity of the verifiable claims. If the verification result is valid, then based on the other sub-rules in the privacy verification rules besides the sub-rule corresponding to the verifiable claim, the processed user biometric data is verified for credibility, and the corresponding verification result is obtained.
9. The method according to claim 8, wherein if the verification result is valid, the processed user biometric data is subjected to credibility verification based on other sub-rules in the privacy verification rules besides the sub-rule corresponding to the verifiable claim, to obtain a corresponding verification result, including: If the verification result is valid, then the verification sub-rule corresponding to the holder of the verifiable claim is obtained based on the privacy verification rule; The credibility of the processed user biometric data is verified based on the verification sub-rules corresponding to the holder of the verifiable claim, and the corresponding verification results are obtained.
10. The method according to claim 7, wherein the step of performing a credibility verification on the processed user biometric data based on preset privacy verification rules to obtain a corresponding verification result includes: The processed user biometric data is calculated based on the verification algorithm corresponding to the privacy verification rule to obtain the corresponding calculation results. The obtained calculation result is matched with the benchmark result in the privacy verification rule, and the verification result of the credibility verification of the processed user biometric data is determined based on the matching result.
11. A privacy-preserving biometric device, wherein a trusted execution environment is provided in the device, the device comprising: The data acquisition module, upon receiving a biometric request, collects user biometric data for biometric processing based on the biometric component. The data transmission module transmits the user's biometric data from the biometric component to the trusted execution environment of the device via a trusted biometric application on the device for performing biometric processing; wherein, the trusted execution environment is configured with privacy processing rules for privacy protection processing of the user's biometric data provided by the trusted biometric application; The privacy protection processing module performs privacy protection processing on the user biometric data according to the privacy processing rules in the trusted execution environment to obtain processed user biometric data. The data processing module acquires the processed user biometric data from the trusted execution environment based on the trusted biometric application, and transmits the processed user biometric data to a preset biometric software development kit (SDK) through the trusted biometric application. Using the biometric SDK, the module sends the processed user biometric data to the server through a preset biometric interface. The server then acquires relevant information about the biometric component and / or the trusted execution environment used to collect the user biometric data, or, based on preset privacy verification rules, acquires multiple of the following data: the user biometric data, relevant information about the biometric component used to collect the user biometric data, and the trusted execution environment. Based on the acquired data, the module performs a trustworthiness verification on the processed user biometric data, and upon successful verification, performs biometric processing based on the processed user biometric data.
12. A privacy-preserving biometric device, the device comprising: The data receiving module receives processed user biometric data sent by the terminal device, which has undergone privacy protection processing according to privacy processing rules set in the trusted execution environment of the terminal device. The processed user biometric data is collected by the terminal device based on a biometric component when a biometric request is received. The user biometric data is then transmitted from the biometric component to the trusted execution environment of the terminal device via a trusted biometric application for performing biometric processing. Within the trusted execution environment, the user biometric data is processed for privacy protection according to privacy processing rules set in the trusted execution environment. The trusted biometric application then retrieves the processed user biometric data from the trusted execution environment and transmits it to a preset biometric software development kit (SDK). Finally, the biometric SDK is used to send the processed user biometric data through a preset biometric interface. The privacy verification module, based on preset privacy verification rules, obtains relevant information about the biometric component and / or the trusted execution environment used to collect the user's biometric data, or obtains multiple of the following data: the user's biometric data, relevant information about the biometric component and the trusted execution environment used to collect the user's biometric data; and performs a trustworthiness verification on the processed user's biometric data based on the obtained data to obtain the corresponding verification result. If the verification result is successful, the biometric module performs biometric processing based on the processed user biometric data and sends the biometric processing result to the terminal device.
13. A privacy-preserving biometric device, wherein the privacy-preserving biometric device is provided with a trusted execution environment, comprising: processor; as well as A memory configured to store computer-executable instructions, which, when executed, cause the processor to: Upon receiving a biometric request, user biometric data is collected using the biometric component for biometric processing. The user's biometric data is transmitted from the biometric component to the trusted execution environment of the device via a trusted biometric application on the device for performing biometric processing; wherein, the trusted execution environment is configured with privacy processing rules to perform privacy protection processing on the user's biometric data provided by the trusted biometric application; In the trusted execution environment, the user biometric data is subjected to privacy protection processing through the privacy processing rules to obtain processed user biometric data. The processed user biometric data is obtained from the trusted execution environment based on the biometric trusted application, and then transmitted to a preset biometric software development kit (SDK) through the biometric trusted application. Using the biometric SDK, the processed user biometric data is sent to a server through a preset biometric interface. The server, based on preset privacy verification rules, obtains relevant information about the biometric component and / or the trusted execution environment used to collect the user biometric data, or obtains multiple of the following: the user biometric data, relevant information about the biometric component used to collect the user biometric data, and the trusted execution environment. Based on the obtained data, the server performs a trustworthiness verification on the processed user biometric data, and after successful verification, performs biometric processing based on the processed user biometric data.
14. A storage medium for storing computer-executable instructions, which, when executed, perform the following process: Upon receiving a biometric request, user biometric data is collected using the biometric component for biometric processing. The user's biometric data is transmitted from the biometric component to the trusted execution environment of the terminal device via a trusted biometric application on the terminal device for performing biometric processing; wherein... The trusted execution environment is configured with privacy processing rules that protect the privacy of user biometric data provided by the trusted biometric application. In the trusted execution environment, the user biometric data is subjected to privacy protection processing through the privacy processing rules to obtain processed user biometric data. The processed user biometric data is obtained from the trusted execution environment based on the biometric trusted application, and then transmitted to a preset biometric software development kit (SDK) through the biometric trusted application. Using the biometric SDK, the processed user biometric data is sent to a server through a preset biometric interface. The server, based on preset privacy verification rules, obtains relevant information about the biometric component and / or the trusted execution environment used to collect the user biometric data, or obtains multiple of the following: the user biometric data, relevant information about the biometric component used to collect the user biometric data, and the trusted execution environment. Based on the obtained data, the server performs a trustworthiness verification on the processed user biometric data, and after successful verification, performs biometric processing based on the processed user biometric data.
15. A privacy-preserving biometric device, wherein the privacy-preserving biometric device is provided with a trusted execution environment, comprising: processor; as well as A memory configured to store computer-executable instructions, which, when executed, cause the processor to: The system receives processed user biometric data sent by a terminal device, which has undergone privacy protection processing according to privacy rules set in the trusted execution environment of the terminal device. This processed user biometric data is collected by the terminal device based on a biometric component when a biometric request is received. The data is then transmitted from the biometric component to the trusted execution environment of the terminal device via a trusted biometric application for performing biometric processing. Within the trusted execution environment, the user biometric data is protected against privacy using privacy rules set in the trusted execution environment. The trusted biometric application then retrieves the processed user biometric data from the trusted execution environment and transmits it to a preset biometric software development kit (SDK). Finally, the biometric SDK is used to send the processed user biometric data through a preset biometric interface. Based on preset privacy verification rules, obtain relevant information about the biometric component and / or the trusted execution environment used to collect the user's biometric data, or obtain multiple of the following data: the user's biometric data, relevant information about the biometric component and the trusted execution environment used to collect the user's biometric data; perform trustworthiness verification on the processed user's biometric data based on the obtained data, and obtain the corresponding verification result; If the verification result is successful, then biometric processing is performed based on the processed user biometric data, and the biometric processing result is sent to the terminal device.
16. A storage medium for storing computer-executable instructions, which, when executed, perform the following process: The system receives processed user biometric data sent by a terminal device, which has undergone privacy protection processing according to privacy rules set in the trusted execution environment of the terminal device. This processed user biometric data is collected by the terminal device based on a biometric component when a biometric request is received. The data is then transmitted from the biometric component to the trusted execution environment of the terminal device via a trusted biometric application for performing biometric processing. Within the trusted execution environment, the user biometric data is protected against privacy using privacy rules set in the trusted execution environment. The trusted biometric application then retrieves the processed user biometric data from the trusted execution environment and transmits it to a preset biometric software development kit (SDK). Finally, the biometric SDK is used to send the processed user biometric data through a preset biometric interface. Based on preset privacy verification rules, obtain relevant information about the biometric component and / or the trusted execution environment used to collect the user's biometric data, or obtain multiple of the following data: the user's biometric data, relevant information about the biometric component and the trusted execution environment used to collect the user's biometric data; perform trustworthiness verification on the processed user's biometric data based on the obtained data, and obtain the corresponding verification result; If the verification result is successful, then biometric processing is performed based on the processed user biometric data, and the biometric processing result is sent to the terminal device.
Citation Information
Patent Citations
Data processing method, device and equipment based on block chain
CN111680305A
Verification method, device and equipment based on verification information and private data
CN111917799A
A privacy-preserving biometric method, device, and equipment
CN113239853B