Face recognition system, method and terminal device based on security chip

CN115880747BActive Publication Date: 2026-09-11SHENZHEN ORBBEC CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211247594.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-12
Publication Date
2026-09-11
Estimated Expiration
2042-10-12

AI Technical Summary

Technical Problem

[0003]但是,这种方法在人脸识别的过程中,不同设备之间可以任意进行绑定和数据传输,存在较大的安全隐患,并且,活体检测在终端设备上进行,耗费大量的算力,消耗的成本过高

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115880747B_ABST
    Figure CN115880747B_ABST
Patent Text Reader

Abstract

The application is suitable for the field of computer technology, and provides a face recognition system, method and terminal device based on a security chip, a camera and a host computer communicate and interact, and based on the host computer information and camera information pre-stored by a first security chip and the host computer information and camera information pre-stored by a second security chip, a first authentication result is obtained; the camera and a background server communicate and interact through the host computer, and based on the camera information pre-stored by the first security chip and the camera information pre-stored by the background server, a second authentication result is obtained; when the first authentication result and the second authentication result are both successful, the camera collects a target image; through information interaction among the camera, the host computer and the background server, a face recognition result corresponding to the target image is obtained. After the authentication is successful, the face recognition is performed between the camera and the host computer and between the camera and the background server, and the security and reliability of the face recognition are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of facial recognition technology, and in particular relates to a facial recognition system, method and terminal device based on a security chip. Background Technology

[0002] As the most common biometric feature, the face serves as the basis for identity verification. However, facial biometrics are easily exposed, and in the era of big data, collecting facial data has become increasingly easy. Two-dimensional image attacks, video attacks, and head-model attacks are common security issues in facial recognition. To address facial recognition attacks, current technologies primarily involve capturing facial images via a camera on a terminal device, performing liveness detection on the terminal device, and then transmitting the image to a backend recognition server for facial recognition.

[0003] However, this method allows for arbitrary binding and data transmission between different devices during facial recognition, posing significant security risks. Furthermore, liveness detection is performed on the terminal device, consuming substantial computing power and incurring excessive costs. Summary of the Invention

[0004] This application provides a face recognition system, method, and terminal device based on a security chip, which can solve the above-mentioned problems.

[0005] In a first aspect, embodiments of this application provide a face recognition system based on a security chip, including a camera, a host, and a backend server; the camera includes a first security chip, and the data pre-stored in the first security chip includes host information and camera information; the host includes a second security chip, and the data pre-stored in the second security chip includes host information and camera information; the data pre-stored in the backend server includes camera information; the camera communicates and interacts with the host, and compares the host information and camera information pre-stored in the first security chip with the host information and camera information pre-stored in the second security chip to obtain a first authentication result; the camera communicates and interacts with the backend server through the host, and compares the camera information pre-stored in the first security chip with the camera information pre-stored in the backend server to obtain a second authentication result; when both the first authentication result and the second authentication result are successful, the camera captures a target image; through information interaction between the camera, the host, and the backend server, a face recognition result corresponding to the target image is obtained.

[0006] Secondly, embodiments of this application provide a face recognition method based on a security chip. The method is applied to a face recognition system based on a security chip, the system including a camera, a host, and a backend server. The camera includes a first security chip, and the data pre-stored in the first security chip includes host information and camera information. The host includes a second security chip, and the data pre-stored in the second security chip includes host information and camera information. The data pre-stored in the backend server includes camera information. The camera communicates with the host and compares the data based on the host information and camera information pre-stored in the first security chip with the data pre-stored in the second security chip to obtain a first authentication result. The camera communicates with the backend server through the host and compares the data based on the camera information pre-stored in the first security chip with the data pre-stored in the backend server to obtain a second authentication result. When both the first and second authentication results are successful, the camera captures a target image. Through information exchange between the camera, the host, and the backend server, a face recognition result corresponding to the target image is obtained.

[0007] Thirdly, embodiments of this application provide a terminal device, including: a camera and a host; the camera and host are the same as those included in the system of the first aspect.

[0008] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program that, when executed by a processor, implements the method described in the second aspect above.

[0009] In this embodiment, the face recognition system based on a security chip includes a camera, a host, and a backend server. The camera communicates with the host and compares the host and camera information pre-stored in the first security chip with the host and camera information pre-stored in the second security chip to obtain a first authentication result. The camera communicates with the backend server through the host and compares the camera information pre-stored in the first security chip with the camera information pre-stored in the backend server to obtain a second authentication result. When both the first and second authentication results are successful, the camera captures a target image. Through information exchange between the camera, the host, and the backend server, a face recognition result corresponding to the target image is obtained. During face recognition, mutual authentication is performed between the camera and the host, and between the camera and the backend server. Face recognition is performed only after successful authentication, which greatly improves the security and reliability of face recognition and prevents facial feature data from being illegally obtained or tampered with. Attached Figure Description

[0010] To more clearly illustrate the technical solutions in the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0011] Figure 1 This is a schematic diagram of a face recognition system based on a security chip provided in the first embodiment of this application; Figure 2 This is a schematic diagram of the terminal device provided in the second embodiment of this application; Figure 3 This is a signaling diagram of the camera and host performing authentication according to an embodiment of this application; Figure 4 This is a signaling diagram of the camera authenticating with the backend server provided in an embodiment of this application; Figure 5 This is a signaling diagram showing the information exchange between the camera, host, and backend server provided in this application embodiment to obtain the face recognition result corresponding to the target image; Figure 6 This is a schematic flowchart of a face recognition method based on a security chip provided in the third embodiment of this application. Detailed Implementation

[0012] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.

[0013] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.

[0014] It should also be understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0015] As used in this application specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrase "if determined" or "if detected [the described condition or event]" may be interpreted, depending on the context, as meaning "once determined," "in response to determination," "once detected [the described condition or event]," or "in response to detection [the described condition or event]."

[0016] Furthermore, in the description of this application and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0017] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0018] The camera 101 includes a first security chip. The first security chip stores host information and camera information, ensuring security. The host information stored in the first security chip is the identity information of the host that can be matched with the camera. The camera information stored in the first security chip is a unique identifier for the camera, which can be a camera serial number; each camera serial number is unique. Furthermore, the camera has an anti-tamper function. When the camera is removed (i.e., the back cover is opened), the liveness detection key information in the first security chip becomes invalid, and the camera becomes unusable.

[0019] The host 102 includes a second security chip, which stores host information and camera information. The host information stored in the second security chip is a unique identifier for the host, which can be a host serial number; each host serial number is unique. The camera information stored in the second security chip is the identity information of the camera that can be matched with the host.

[0020] The data pre-stored on the backend server 103 includes camera information, which is the identity information of the cameras that the backend server can match.

[0021] In one embodiment, the data pre-stored in the first security chip of camera 101 may further include a camera key pair and a server public key, wherein the camera key pair includes a camera private key and a camera public key. The data pre-stored in the backend server may further include a server key pair and a camera public key, wherein the backend server key pair includes a server private key and a server public key. The camera uses the camera key pair and server public key pre-stored in the first security chip to encrypt or decrypt data used for communication with the backend server; the backend server uses the pre-stored server key pair and camera public key to encrypt or decrypt data used for communication with the camera. This encryption method of the key pair makes data transmission between camera 101 and backend server 103 more secure.

[0022] Figure 2 This is a schematic diagram of the terminal device provided in the second embodiment of this application. Figure 2 As shown, the terminal device 20 in this embodiment includes a camera 101 and a host 102. The terminal device 20 may include, but is not limited to, devices that support facial recognition for identity verification, such as access control devices, door lock devices, and facial payment devices. It should be noted that the information interaction and execution processes between the above-mentioned devices / units are based on the same concept as the method embodiments of this application. Their specific functions and technical effects can be found in the first and second embodiments, and will not be repeated here.

[0023] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps described in the various method embodiments above.

[0024] In the first or second embodiment of this application, when performing face recognition, it is necessary to authenticate the camera 101 and the host 102, that is, to determine whether the camera 101 and the host 102 have the authority to transmit data. The camera 101 and the host 102 communicate and interact, and compare the host information and camera information pre-stored in the first security chip with the host information and camera information pre-stored in the second security chip to obtain the first authentication result.

[0025] When the first authentication result is successful, authentication is passed, and camera 101 and host 102 have the permission to transmit data. The purpose of mutual authentication between camera 101 and host 102 is to bind the camera and host one-to-one. After binding, the camera can only be used on that host, and vice versa. This way, once the camera is installed on the host, it cannot be used on other hosts, ensuring that facial data cannot be illegally collected. When the first authentication result is unsuccessful, authentication fails, and the host cannot send any other commands.

[0026] In one possible implementation, the camera acquires host information pre-stored in the second security chip and compares the host information pre-stored in the second security chip with the host information pre-stored in the first security chip to obtain a first matching result; the host acquires camera information pre-stored in the first security chip and compares the camera information pre-stored in the first security chip with the camera information pre-stored in the second security chip to obtain a second matching result; and a first authentication result is obtained based on the first matching result and the second matching result.

[0027] Specifically, such as Figure 3 As shown, Figure 3 Signaling diagram for authenticating the camera and host. To enhance the security of information transmission between the camera and the host, the host 102 encrypts the host information pre-stored in the second security chip to obtain host matching information, and sends the host matching information to the camera. The camera receives the host matching information and decrypts it to obtain the host information pre-stored in the second security chip. The camera compares the host information pre-stored in the second security chip with the host information pre-stored in the first security chip to obtain a first matching result, and sends the first matching result to the host. The host receives the first matching result, and when the first matching result indicates a successful match, the host generates a random string and sends the random string to the camera. The camera receives the random string and encrypts the camera information pre-stored in the first security chip according to the random string to obtain first camera matching information, and sends the first camera matching information to the host. The host receives the first camera matching information, decrypts it to obtain the camera information pre-stored in the first security chip. The host compares the camera information pre-stored in the first security chip with the camera information pre-stored in the second security chip to obtain a second matching result. When the second matching result indicates a successful match, the host determines that the first authentication result is successful and sends the first authentication result to the camera.

[0028] The purpose of mutual authentication between camera 101 and host 102 is to bind camera 101 and host 102 one-to-one. After binding, the camera can only be used on this host, and vice versa. Once the camera is installed on the host, it cannot be used if it is removed and installed on another host, ensuring that facial data cannot be illegally collected. Before binding the camera and host one-to-one, key pre-setting is required. The camera information (camera serial code) is written into the host's security chip, and the host information (host serial code) is also written into the camera's security chip. To make the authentication process more secure, each command is encrypted, and random characters and other methods are used to ensure that each command is not re-entrant.

[0029] In a specific embodiment, after activating the face recognition system provided in the first embodiment or the terminal device provided in the second embodiment, camera 101 generates an RSA key in the first security chip and encrypts the RSA public key using an agreed AES key before sending it to host 102. The RSA key generation operation generates a different key each time it is called, ensuring that the data of the first instruction is not re-entrant. After the first security chip generates the RSA key, camera 101 encrypts the RSA public key using a preset AES key and then transmits it to host 102. Host 102 decrypts the information sent by camera 101 using the AES key to obtain the decrypted RSA public key, and then uses the decrypted RSA public key to encrypt the host information stored in the second security chip to obtain host matching information. Camera 101 receives host matching information and decrypts it to obtain host information pre-stored in the second security chip. Camera 101 compares the host information pre-stored in the second security chip with the host information pre-stored in the first security chip to obtain a first matching result, and sends the first matching result to the host. Host 102 receives the first matching result. When the first matching result is a successful match, host 102 generates a random string as a new AES key, encrypts the AES key using the RAS key, and sends it to camera 101. Camera 101 decrypts the new AES key and uses it to encrypt the camera information pre-stored in the first security chip to obtain the first camera matching information. Host 102 uses the new AES key to decrypt the first camera matching information, obtains the camera information pre-stored in the first security chip, and compares it with the camera information pre-stored in the second security chip to obtain a second matching result. When the second matching result is a successful match, host 102 determines that the first authentication result is successful and sends the first authentication result to camera 101. When the second matching result is a failed match, host 102 no longer sends instructions to camera 101.

[0030] In one possible implementation, camera 101 communicates with backend server 103 via a host, comparing the camera information pre-stored in the first security chip with the camera information pre-stored in the backend server to obtain a second authentication result. In this embodiment, authentication of camera 101 and backend server 103 determines whether they have the necessary permissions to transmit data, ensuring data security. The camera can only be used normally when the second authentication result is successful.

[0031] In one possible implementation, the backend server 103 obtains the camera information pre-stored in the first security chip through the host 102, compares the camera information pre-stored in the first security chip with the camera information pre-stored in the backend server, and obtains a third matching result; and obtains a second authentication result based on the third matching result.

[0032] In one possible implementation, encryption can be performed during data transmission to ensure security. The camera generates a random string and packages it with camera information pre-stored in the first security chip to obtain second camera matching information. The host obtains the second camera matching information and forwards it to the backend server. The backend server obtains the second camera matching information, along with the random string and the camera information pre-stored in the first security chip. The backend server compares the camera information pre-stored in the first security chip with the camera information pre-stored in the backend server to obtain a third matching result. The backend server packages the random string and the third matching result to obtain server matching information. The host obtains the server matching information and forwards it to the camera. The camera obtains a second authentication result based on the server matching information.

[0033] Specifically, such as Figure 4 As shown, Figure 4 Signaling diagram for authenticating the camera with the backend server. Camera 101 generates a random string, packages and encrypts the random string and the camera information pre-stored in the first security chip to obtain second camera matching information, and sends the second camera matching information to the host; host 102 receives the second camera matching information and sends it to the backend server; backend server 103 receives the second camera matching information and decrypts it to obtain a random string and the camera information pre-stored in the first security chip; the backend server compares the camera information pre-stored in the first security chip with the camera information pre-stored in the backend server to obtain a third matching result; it encrypts the third matching result, the random string, and the camera information pre-stored in the first security chip to obtain server matching information, and sends the server matching information to the host; the host receives the server matching information and sends it to the camera; the camera receives the server matching information, decrypts it to obtain the third matching result, the random string, and the camera information pre-stored in the first security chip; when the third matching result is a successful match, and the random string and the camera information pre-stored in the first security chip match the information stored in the camera, the camera determines that the second authentication result is successful, and the camera responds normally to the host's instructions. When the third matching result fails, authentication fails and camera 101 cannot be used; when the random string, the camera information pre-stored in the first security chip, and the information stored in the camera do not match, authentication fails and camera 101 cannot be used.

[0034] In one specific embodiment, after receiving an instruction requiring authentication with the backend server 103, camera 101 encrypts the camera information and random string pre-stored in the first security chip using a preset server public key, signs it with the camera's private key, and sends it to the backend server 103 via host 102. The backend server 103 decrypts the data using its private key and verifies the signature with the camera's public key, obtaining the camera information and random string pre-stored in the first security chip. It then compares this data with the camera information stored on the backend server. After the comparison, the authentication result and random string are encrypted using the camera's public key, signed with the server's private key, and sent to camera 101 via host 102. Camera 101 decrypts the data using its private key and verifies the signature with the server's public key to obtain the authentication result and random string, and then determines whether the authentication was successful. Only after successful authentication can the camera be used normally.

[0035] In one possible implementation, to further ensure the security of data transmission, when the camera authenticates with the backend server, each time data is transmitted, it can be encrypted or decrypted using the camera key pair and server public key pre-stored in the first security chip, and the server key pair and camera public key pre-stored in the backend server.

[0036] Specifically, camera 101 generates a random string and encrypts it along with camera information pre-stored in the first security chip using the server's public key, resulting in encrypted second camera matching information. The backend server receives this encrypted second camera matching information and decrypts it using its private key. The backend server can then encrypt and sign the third matching result, the random string, and the camera information pre-stored in the first security chip using the camera's public key, resulting in encrypted server matching information. The camera receives this encrypted server matching information, verifies the signature, and decrypts it using the server's private key, obtaining the third matching result, the random string, and the camera information pre-stored in the first security chip. When both the first and second authentication results are successful, the camera captures the target image. Through information exchange between the camera, the host, and the backend server, the face recognition result corresponding to the target image is obtained. The target image may include a target depth image, a target infrared image, and a target color image.

[0037] In one possible implementation, when both the first authentication result and the second authentication result are successful, the camera 101 receives the face recognition instruction from the host 102 and captures the target image; the camera 101 performs face detection on the target image to obtain a face region image; the host 102 acquires the face region image and sends the face region image to the backend server; the backend server acquires the face region image and performs face recognition comparison on the face region image to obtain the face recognition result.

[0038] In one possible implementation, liveness detection in this system is performed by camera 101. After obtaining the liveness detection result, camera 101 sends it to the backend server 103, which performs face recognition on the image to obtain the face recognition result. When both the first authentication result and the second authentication result are successful, camera 101 receives the face-scanning command from host 102 and captures the target image; camera 101 performs face detection on the target image to obtain a face region image; camera 101 performs liveness detection on the target image to obtain a liveness detection result; host 102 acquires the face region image and the liveness detection result, and sends the face region image to the backend server when the liveness detection result is successful; the backend server acquires the face region image and performs face recognition comparison on the face region image to obtain the face recognition result. In this system, liveness detection is performed by the camera, which greatly reduces the burden on the backend server, reduces the consumption of computing power on the backend server, and lowers costs.

[0039] Specifically, such as Figure 5 As shown, Figure 5 The signaling diagram facilitates information exchange between the camera, host, and backend server to obtain the face recognition result corresponding to the target image. Face recognition is initiated when both the first and second authentication results are successful. The backend server 103 generates a random string and sends it to the host 102. The host 102 adds the random string to the face recognition command, generates the face recognition command, and sends it to the camera 101. When the camera 101 receives the face recognition command, it acquires the target image, which may include a target depth image, a target infrared image, and a target color image as needed. The camera 101 performs face detection and liveness detection on the acquired target depth image, target infrared image, and target color image according to a preset face detection algorithm and liveness detection algorithm, obtaining a face region image and a liveness detection result. The system performs a liveness detection process: Camera 101 packages and encrypts the face region image and the liveness detection result to obtain liveness information, and sends this information to host 102; host 102 receives the liveness information, decrypts it, and obtains the face region image and the liveness detection result; if the liveness detection result is successful, the host sends the face region image to the backend server 103; the backend server 103 receives the face region image, performs face recognition on it, obtains the face recognition result, and sends the result to the host; the host receives the face recognition result and selects the next instruction based on it. If the liveness detection result fails, the host determines the reason for the failure based on the result and prompts the user.

[0040] To further ensure data transmission security, the camera generates a liveness signature before sending out the obtained face region image and liveness test result. The camera encrypts the face region image, the liveness signature, and the liveness test result, packages them, and then encrypts them again to obtain liveness information, which is then sent to the host. The secondary encryption key (SK) is a symmetric key (AES or SM4), which is randomly generated during host initialization and encrypted before being sent to the camera. The host receives the liveness information and decrypts it using the secondary encryption key (SK) to obtain the encrypted face region image, liveness signature, and liveness test result. If the liveness test result is successful, the host sends the encrypted face region image and liveness signature to the backend server. The backend server receives the encrypted face region image and liveness signature, decrypts the image, and then verifies the liveness signature. After successful verification, it performs face recognition on the face region image, obtains the face recognition result, and sends the face recognition result to the host. The host receives the face recognition result and selects the next instruction based on the face recognition result.

[0041] In one possible implementation, to further ensure the security of data transmission, when the camera 101, host 102 and backend server 103 exchange information to obtain the face recognition result corresponding to the target image, each time data is transmitted, it can be signed, encrypted or decrypted using a preset liveness detection key and session key.

[0042] Specifically, the camera can sign the liveness detection result using a liveness detection key, and then encrypt the signed liveness detection result and the face region image using a session key to obtain encrypted liveness information. The host receives the liveness information and decrypts it using the session key to obtain the face region image and the signed liveness detection result. The host can verify the liveness detection result. After successful verification, if the liveness detection result is successful, the host can encrypt the face region image using a face key and send the encrypted face region image to the backend server. The backend server receives the encrypted face region image, decrypts it, performs face recognition on the face region image, obtains the face recognition result, and sends the face recognition result to the host. The host receives the face recognition result and selects the next instruction based on the face recognition result.

[0043] In one possible implementation, to further ensure the security of data transmission, when the camera, host, and backend server exchange information to obtain the face recognition result corresponding to the target image, each time data is transmitted, it can be encrypted or decrypted using the face encryption key and the liveness detection key.

[0044] Specifically, the camera can sign the live detection information using a live detection key, encrypt the face region image using a face encryption key, and then perform a second encryption using a random symmetric key (SK) to obtain encrypted liveness information. The host receives the encrypted liveness information and decrypts it using the symmetric key (SK) to obtain the encrypted face region image, signed liveness information, and liveness result. When the liveness result is successful, the host sends the encrypted face region image and liveness signature information to the backend server. The backend server receives the encrypted face region image, decrypts it, and verifies the liveness information. After successful verification, it performs face recognition on the face region image to obtain the face recognition result, which is then sent to the host. The host receives the face recognition result and selects the next instruction based on it.

[0045] In this embodiment, the random string can be used as the key initialization vector during encryption. A session key is pre-stored in the camera, which is used to protect data transmission between the camera and the backend server. The session key uses either AES or SM4 algorithms, and each camera's session key is unique.

[0046] In one possible implementation, the system can preview the face region image on the host's application page. The camera encrypts the live face region image and sends the encrypted face region image to the host. The host receives the encrypted face region image, decrypts it to obtain the face region image, and displays the face region image on the host's display module.

[0047] In this embodiment, the face recognition system based on a security chip includes a camera, a host, and a backend server. The camera communicates with the host and compares the host and camera information pre-stored in the first security chip with the host and camera information pre-stored in the second security chip to obtain a first authentication result. The camera communicates with the backend server through the host and compares the camera information pre-stored in the first security chip with the camera information pre-stored in the backend server to obtain a second authentication result. When both the first and second authentication results are successful, the camera captures a target image. Through information exchange between the camera, the host, and the backend server, a face recognition result corresponding to the target image is obtained. During face recognition, mutual authentication is performed between the camera and the host, and between the camera and the backend server. Face recognition is performed only after successful authentication, which greatly improves the security and reliability of face recognition and prevents facial feature data from being illegally obtained or tampered with.

[0048] Please see Figure 6 , Figure 6This is a schematic flowchart illustrating a face recognition method based on a security chip according to the third embodiment of this application. The face recognition method based on a security chip in this embodiment is applied to a face recognition system based on a security chip. The system includes a camera, a host, and a backend server. The terminal device based on the security chip in this embodiment includes a camera and a host, and the host communicates with the backend server. The camera includes a first security chip, and the data pre-stored in the first security chip includes host information and camera information. The host includes a second security chip, and the data pre-stored in the second security chip includes host information and camera information. The data pre-stored in the backend server includes camera information. For details regarding the face recognition system based on the security chip, please refer to the relevant description in the first embodiment; for details regarding the terminal device based on the security chip, please refer to the relevant description in the second embodiment. Further details are omitted here.

[0049] like Figure 6 As shown, the face recognition method based on a security chip includes: S601: The camera communicates and interacts with the host, and compares the host information and camera information pre-stored in the first security chip with the host information and camera information pre-stored in the second security chip to obtain the first authentication result. S602: The camera communicates and interacts with the backend server through the host, and compares the camera information pre-stored in the first security chip with the camera information pre-stored in the backend server to obtain the second authentication result. S603: When both the first and second authentication results are successful, the camera captures the target image; through information exchange between the camera, the host, and the backend server, the face recognition result corresponding to the target image is obtained.

[0050] The face recognition method based on the security chip in the first embodiment is described in detail in the face recognition system based on the security chip. Please refer to the relevant description in the first embodiment. It will not be repeated here.

[0051] This application also provides a computer program product that, when run on a mobile terminal, enables the mobile terminal to execute the steps described in the above-described method embodiments. If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods described in this application can be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the above-described method embodiments. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include at least: any entity or device capable of carrying the computer program code to a camera / terminal device, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium. Examples include USB flash drives, portable hard drives, magnetic disks, or optical disks. In some jurisdictions, computer-readable media may not be electrical carrier signals or telecommunication signals, according to legislation and patent practice.

[0052] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0053] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0054] In the embodiments provided in this application, it should be understood that the disclosed apparatus / network devices and methods can be implemented in other ways. For example, the apparatus / network device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0055] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0056] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application, and should all be included within the protection scope of this application.

Claims

1. A face recognition system based on a security chip, characterized in that, It includes a camera, a host, and a backend server; the camera includes a first security chip, and the data pre-stored in the first security chip includes host information and camera information; the host includes a second security chip, and the data pre-stored in the second security chip includes host information and camera information; The data pre-stored on the backend server includes camera information; The camera communicates and interacts with the host, and compares the host information and camera information pre-stored in the first security chip with the host information and camera information pre-stored in the second security chip to obtain the first authentication result. The camera communicates and interacts with the backend server through the host, and compares the camera information pre-stored in the first security chip with the camera information pre-stored in the backend server to obtain a second authentication result. When both the first authentication result and the second authentication result are successful, the camera captures the target image; through information interaction between the camera, the host and the backend server, the face recognition result corresponding to the target image is obtained; The camera communicates and interacts with the host, and compares the host information and camera information pre-stored in the first security chip with the host information and camera information pre-stored in the second security chip to obtain a first authentication result, including: The camera acquires the host information pre-stored in the second security chip and compares the host information pre-stored in the second security chip with the host information pre-stored in the first security chip to obtain a first matching result; The host obtains the camera information pre-stored in the first security chip and compares the camera information pre-stored in the first security chip with the camera information pre-stored in the second security chip to obtain a second matching result; The first authentication result is obtained based on the first matching result and the second matching result.

2. The face recognition system based on a security chip as described in claim 1, characterized in that, The data pre-stored in the first security chip of the camera also includes a camera key pair and a server public key, and the data pre-stored in the backend server also includes a server key pair and a camera public key; wherein, the camera key pair includes a camera private key and the camera public key, and the backend server key pair includes a server private key and the server public key; The camera is used to encrypt or decrypt data used in communication with the backend server using the camera key pair pre-stored in the first security chip and the server public key. The backend server is used to encrypt or decrypt data that is communicated and interacted with the camera using the pre-stored server key pair and the camera's public key.

3. The face recognition system based on a security chip as described in claim 1, characterized in that, The camera communicates with the backend server through the host, and compares the camera information pre-stored in the first security chip with the camera information pre-stored in the backend server to obtain a second authentication result, including: The backend server obtains the camera information pre-stored in the first security chip through the host, and compares the camera information pre-stored in the first security chip with the camera information pre-stored in the backend server to obtain a third matching result; The second authentication result is obtained based on the third matching result.

4. The face recognition system based on a security chip as described in claim 1, characterized in that, The camera communicates with the backend server through the host, and compares the camera information pre-stored in the first security chip with the camera information pre-stored in the backend server to obtain a second authentication result, including: The camera generates a random string and packages the generated random string with the camera information pre-stored in the first security chip to obtain the second camera matching information; The host obtains the matching information of the second camera and forwards the matching information of the second camera to the backend server; The backend server obtains the matching information of the second camera, and gets the random string and the camera information pre-stored in the first security chip; The backend server compares the camera information pre-stored in the first security chip with the camera information pre-stored in the backend server to obtain a third matching result. The backend server packages the random string and the third matching result to obtain server matching information; The host obtains the server matching information and forwards the server matching information to the camera; The camera obtains the second authentication result based on the matching information from the server.

5. The face recognition system based on a security chip as described in claim 4, characterized in that, When both the first authentication result and the second authentication result are successful, the camera captures the target image; The face recognition result corresponding to the target image is obtained through information interaction between the camera, the host, and the backend server, including: When both the first authentication result and the second authentication result are successful, the camera receives the face recognition command from the host and captures the target image; The camera performs face detection on the target image to obtain a face region image; The host acquires the face region image and sends the face region image to the backend server; The backend server acquires the face region image and performs face recognition comparison on the face region image to obtain the face recognition result.

6. The face recognition system based on a security chip as described in claim 4, characterized in that, When both the first authentication result and the second authentication result are successful, the camera captures the target image; The face recognition result corresponding to the target image is obtained through information interaction between the camera, the host, and the backend server, including: When both the first authentication result and the second authentication result are successful, the camera receives the face recognition command from the host and captures the target image; The camera performs face detection on the target image to obtain a face region image; The camera performs liveness detection on the target image to obtain the liveness detection result; The host acquires the face region image and the biopsy result, and sends the face region image to the backend server when the biopsy result is successful; The backend server acquires the face region image and performs face recognition comparison on the face region image to obtain the face recognition result.

7. A face recognition method based on a security chip, characterized in that, The method is applied to the face recognition system based on a security chip as described in claim 1, the system including a camera, a host, and a backend server; the camera includes a first security chip, and the data pre-stored in the first security chip includes host information and camera information; The host includes a second security chip, and the data pre-stored in the second security chip includes host information and camera information; The data pre-stored on the backend server includes camera information; The camera communicates and interacts with the host, and compares the host information and camera information pre-stored in the first security chip with the host information and camera information pre-stored in the second security chip to obtain the first authentication result. The camera communicates and interacts with the backend server through the host, and compares the camera information pre-stored in the first security chip with the camera information pre-stored in the backend server to obtain a second authentication result. When both the first authentication result and the second authentication result are successful, the camera captures the target image; through information interaction between the camera, the host and the backend server, the face recognition result corresponding to the target image is obtained.

8. A terminal device, characterized in that, include: Camera and main unit; The camera and the host are the camera and host included in the system according to any one of claims 1-6.

9. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method as described in claim 7.

Citation Information

Patent Citations

  • Camera system-based safe encryption method and camera system

    CN108599946A