A face recognition system, method and terminal device based on security chip
By using a security chip in the face recognition system to authenticate and encrypt data between terminal devices, the security risks of data transmission between terminal devices are solved, the security and reliability of face recognition are improved, and key updates and device restarts and activations are supported.
Patent Information
- Application Number
- CN202211249472.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-12
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2042-10-12
AI Technical Summary
In the existing facial recognition technology, there are security risks in data transmission between terminal devices, and there is a lack of remedial solutions after the key is leaked, resulting in the facial feature data being easily illegally acquired and tampered with.
The camera, host and backend server system based on security chips is adopted to authenticate each other through camera information, and data is encrypted and decrypted using pre-stored keys to ensure the security of data transmission and support key updates and device restart activation.
It improves the security and reliability of facial recognition, prevents facial feature data from being illegally acquired and tampered with, ensures data security, and supports equipment maintenance and key updates.
Smart Images

Figure CN115941246B_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of face recognition technology, and in particular relates to a face recognition system, method and terminal device based on a security chip. Background Art
[0002] The human face, as the most common biometric feature, can be used as a basis for identity verification. However, facial biometrics are highly visible, and in the era of big data, collecting facial data is becoming increasingly easy. Attacks such as 2D images, videos, and head models are common security issues in facial recognition. To address these security issues, existing technologies primarily capture facial images using a camera on a terminal device, perform liveness detection on the terminal device, and then transmit the image to a backend recognition server for facial recognition.
[0003] However, during the face recognition process, this method allows for arbitrary binding and data transmission between different devices, and there is no remedial plan after the key is leaked, posing a major security risk. Summary of the Invention
[0004] The embodiments of the present application provide a face recognition system, method and terminal device based on a security chip, which can solve the above problems.
[0005] In the first aspect, an embodiment of the present application provides a face recognition system based on a security chip, including a camera, a host and a background server; the camera is provided with a first security chip, the host is provided with a second security chip, and the background server is provided with a third security chip; the first security chip, the second security chip and the third security chip are all pre-stored with camera information, and the camera, the host and the background server authenticate each other through the camera information; the camera is used to collect a target image according to the host's instructions after successful mutual authentication, and generate facial information based on the target image; the background server is used to obtain facial information through the host, and perform face recognition based on the facial information to obtain a face recognition result corresponding to the target image.
[0006] Furthermore, the camera is used to encrypt or decrypt data for communication and interaction with the host through the camera key pair, host public key and server public key pair pre-stored in the first security chip; the host is used to encrypt or decrypt data for communication and interaction with the camera and the background server through the host key pair, camera public key and server public key pair pre-stored in the second security chip; the background server is used to encrypt or decrypt data for communication and interaction with the host through the server key pair, host public key and camera public key pair pre-stored in the third security chip.
[0007] In the second aspect, an embodiment of the present application provides a face recognition method based on a security chip, which is applied to the face recognition system based on a security chip provided in the first aspect. The method includes: the camera, the host and the background server mutually authenticate each other through camera information; after the mutual authentication is successful, the camera collects the target image according to the instructions of the host and generates facial information based on the target image; the background server obtains the facial information through the host, and performs face recognition based on the facial information to obtain the face recognition result corresponding to the target image.
[0008] In a third aspect, an embodiment of the present application provides a terminal device, including: a camera and a host; the camera and the host are the camera and the host included in the system in the first aspect.
[0009] In an embodiment of the present application, a security chip-based facial recognition system includes a camera, a host, and a backend server. The camera includes a first security chip, and the data pre-stored in the first security chip includes camera information. The host includes a second security chip, and the data pre-stored in the second security chip includes camera information. The data pre-stored in the backend server includes camera information. The camera, host, and backend server mutually authenticate, restart, activate, or update keys using the camera information. When mutual authentication between the camera, host, and backend server is successful, the camera captures a target image. Through information exchange between the camera, host, and backend server, a facial recognition result corresponding to the target image is obtained. During facial recognition, mutual authentication is performed between the camera and host, and between the camera and backend server. Facial recognition is performed only after successful authentication, greatly improving the security and reliability of facial recognition and preventing facial feature data from being illegally obtained or tampered with. In addition, the system can perform key updates to further ensure data security. When removal is detected, the device can be restarted and activated, ensuring security while facilitating device maintenance. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments or descriptions of the prior art. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0011] Figure 1 This is a schematic diagram of a face recognition system based on a security chip provided in the first embodiment of the present application;
[0012] Figure 2 is a schematic diagram of a terminal device provided in the second embodiment of the present application;
[0013] Figure 3This is a signaling diagram for mutual authentication between the camera, host, and backend server provided in an embodiment of the present application;
[0014] Figure 4 This is a signaling diagram for information exchange between the camera, host, and backend server provided in an embodiment of the present application to obtain a face recognition result corresponding to a target image;
[0015] Figure 5 This is a signaling diagram for restarting and activating the camera, host, and backend server through camera information provided by an embodiment of the present application;
[0016] Figure 6 This is a signaling diagram of the camera, host and background server provided in the embodiment of the present application for detecting key updates through camera information. DETAILED DESCRIPTION
[0017] In the following description, specific details such as specific system structures and techniques are provided for purposes of illustration rather than limitation to facilitate a thorough understanding of the embodiments of the present application. However, it will be apparent to those skilled in the art that the present application may be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid obscuring the description of the present application with unnecessary detail.
[0018] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, integers, steps, operations, elements and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or collections thereof.
[0019] It will also be understood that the term "and / or" used in this specification and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.
[0020] As used in this specification and the appended claims, the term "if" can be interpreted as "when" or "upon" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "upon determination" or "in response to determining" or "upon detection of [described condition or event]" or "in response to detecting [described condition or event]," depending on the context.
[0021] In addition, in the description of the present application specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0022] References to "one embodiment" or "some embodiments" in this specification mean that a particular feature, structure, or characteristic described in conjunction with that embodiment is included in one or more embodiments of the present application. Thus, phrases such as "in one embodiment," "in some embodiments," "in other embodiments," and "in other embodiments" appearing in various places in this specification do not necessarily refer to the same embodiment, but rather mean "one or more but not all embodiments," unless otherwise specifically emphasized. The terms "including," "comprising," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.
[0023] See Figure 1 , Figure 1 FIG1 is a schematic diagram of a face recognition system based on a security chip according to a first embodiment of the present application. In this embodiment, a face recognition system based on a security chip 10 comprises a camera 101 , a host 102 and a backend server 103 .
[0024] A security chip can be considered a trusted platform module that independently performs key generation, encryption, and decryption. It contains an independent processor and storage unit for storing keys and signature data, and provides encryption and security authentication services. With encryption using a security chip, the keys are stored in hardware, making it impossible to decrypt stolen data, thus protecting data security.
[0025] In this embodiment, the camera can be a camera module consisting of a depth camera and an RGB camera. The camera and the host are located in the terminal device, and the host is in communication with the backend server. It is understood that the camera communicates with the host via a wired connection; the host is connected to the Internet via a wireless gateway to communicate with the backend server.
[0026] Camera 101 includes a first security chip. The data pre-stored in the first security chip includes camera information. Storing this information in the first security chip ensures security. The camera information pre-stored in the first security chip uniquely identifies the camera and can be a camera serial code, which is unique for each camera. Furthermore, the camera can have a tamper-evident feature. If the camera is disassembled, i.e., its back cover is removed, the biopsy key information in the first security chip becomes invalid, rendering the camera inoperable.
[0027] The host 102 includes a second security chip, and the data pre-stored in the second security chip includes camera information, wherein the camera information pre-stored in the second security chip is the identity information of the camera that can be matched with the host.
[0028] The data pre-stored in the backend server 103 includes camera information. The camera information pre-stored in the backend server is the identity information of the camera that the backend server can match.
[0029] The camera 101, the host 102, and the backend server 103 perform mutual authentication through camera information; the camera 101 is used to capture a target image according to the instructions of the host 102 after successful mutual authentication, and to generate facial information based on the target image; the backend server 103 is used to obtain facial information through the host 102, and perform face recognition based on the facial information to obtain a face recognition result corresponding to the target image.
[0030] In one embodiment, the data pre-stored in the first security chip also includes a first key group; the data pre-stored in the second security chip also includes a second key group; and the data pre-stored in the third security chip also includes a third key group. The camera is configured to encrypt or decrypt data communicated with the host using the first key group pre-stored in the first security chip. The first key group includes a detection key, a camera key pair, a host public key, and a server public key. The host is configured to encrypt or decrypt data communicated with the camera and a backend server using the second key group pre-stored in the second security chip. The second key group includes a host key pair, a camera public key, and a server public key. The backend server is configured to encrypt or decrypt data communicated with the host using the third key group pre-stored in the third security chip. The third key group includes a detection key, a server key pair, a host public key, and a camera public key. The encryption method of the key group makes data transmission between the camera 101, the host 102, and the backend server 103 more secure.
[0031] In this embodiment, the camera includes a removal detection unit that monitors whether the camera's hardware structure has been moved. If the camera detects movement, it updates its removal status to "removed" and sets the detection key's usage status to invalid. Furthermore, the detection key can be retrieved via a third security chip on the backend server, encrypted with the camera's public key, and then forwarded to the camera via the host.
[0032] Figure 2 This is a schematic diagram of a terminal device provided in the second embodiment of the present application. Figure 2 As shown, the terminal device 20 of this embodiment includes: a camera 101 and a host 102. The terminal device 20 may include, but is not limited to: access control devices, door lock devices, facial payment devices, and other devices that support facial identity verification. It should be noted that the information interaction and execution process between the above-mentioned devices / units are based on the same concept as the embodiment of the method of this application. Their specific functions and technical effects can be found in the first and second embodiments, and will not be repeated here.
[0033] The third embodiment of the present application provides a security chip-based face recognition method, which is applied to the security chip-based face recognition system provided by the first embodiment or the terminal device provided by the second embodiment. The method includes: the camera, the host, and the backend server mutually authenticate each other through camera information; after successful mutual authentication, the camera captures the target image according to the host's instructions and generates facial information based on the target image; the backend server obtains the facial information through the host and performs face recognition based on the facial information to obtain a face recognition result corresponding to the target image. The camera also monitors whether the hardware structure has been moved. When the hardware structure is detected to have been moved, the disassembly status information is updated to disassembled. If the host queries the camera status and finds that the camera's disassembly status information is disassembled, reactivation is initiated.
[0034] In the first, second or third embodiment of the present application, the camera 101, the host 102 and the backend server 103 perform mutual authentication, restart activation or update the key through the camera information.
[0035] In one implementation, the camera, host, and backend server authenticate each other using camera information. Specifically, when performing face recognition, authentication must first be performed between the camera, host, and backend server to determine whether the camera, host, and backend server have permission to transmit data to ensure data security. When the host detects an authentication instruction, it sends the authentication instruction to the camera; when the camera receives the detection instruction, it sends the camera information pre-stored in the first security chip to the host; the host obtains the camera information pre-stored in the first security chip, compares the camera information pre-stored in the first security chip with the camera information pre-stored in the second security chip, and obtains a first authentication result; when the first authentication result is successful, the host sends the camera information pre-stored in the first security chip to the background server; the background server compares the camera information pre-stored in the first security chip with the camera information pre-stored in the third security chip to obtain a second authentication result; the server sends the camera information pre-stored in the first security chip and the authentication result to the host; the host receives the camera information pre-stored in the first security chip and the second authentication result, and sends the camera information pre-stored in the first security chip and the second authentication result to the camera; the camera receives the camera information pre-stored in the first security chip and the second authentication result; when the camera information pre-stored in the first security chip is consistent with the information pre-stored in the camera, and the second authentication result is passed, it is determined that the camera, the host and the background server have successfully authenticated each other.
[0036] Authentication is successful when the camera, host, and backend server successfully authenticate each other. The purpose of mutual authentication between the camera and host is to bind the camera and host one to one. Once bound, the camera can only be used on that host, and vice versa. This prevents the illegal collection of facial data by removing the camera from the host and then placing it on another host. This ensures that facial data cannot be illegally collected. The purpose of authentication between the host and backend server is to ensure that only authenticated hosts can transmit data to the backend server. If the first authentication result is a failure, the host will not send any further commands to the backend server during this process, but will notify the camera of the authentication failure. If the second authentication result is a failure, the camera is aware of the authentication failure and can send a notification to the host. After authentication fails, the camera cannot respond to control commands from the host, and the host will no longer send commands to the camera.
[0037] Specifically, if Figure 3 As shown, Figure 3 This is a signaling diagram for mutual authentication between the camera, host, and backend server. When the host detects an authentication command, it sends it to the camera. When the camera receives the detection command, it generates a random string, packages the generated random string with pre-stored camera information, and encrypts it to obtain camera matching information. The host receives the camera matching information, decrypts it, and obtains the random string generated by the camera and the pre-stored camera information. The host compares the camera information pre-stored in the first security chip with the camera information pre-stored in the second security chip to obtain a first authentication result. If the first authentication result is successful, the host packages the random string with the camera information pre-stored in the first security chip and encrypts it to obtain host matching information. The host matching information is sent to the backend server. The backend server decrypts the host matching information to obtain the random string and the pre-stored camera information. The backend server compares the camera information pre-stored in the first security chip with the pre-stored camera information in the third security chip to obtain a second authentication result. The backend server encrypts the second authentication result, the random string, and the pre-stored camera information to obtain server matching information. The backend server sends the server matching information to the host, which then sends it to the camera. The camera decrypts the server matching information to obtain the second authentication result, a random string, and camera information. If the camera information pre-stored in the first security chip matches the information pre-stored in the camera, and the second authentication result is passed, the camera, host, and backend server are deemed to have successfully authenticated each other.
[0038] In one possible implementation, in order to further ensure the security of data transmission, when the camera, host and background server perform authentication, each data transmission can be encrypted or decrypted using the first key group, the second key group or the third key group.
[0039] Specifically, when the camera receives a detection instruction, it generates a random string and encrypts the generated random string and the camera information pre-stored in the first security chip using the host public key and signs with the camera private key to obtain first matching information; after receiving the first matching information, the host decrypts the first matching information using the host private key and verifies the signature using the camera public key to obtain the random string generated by the camera and the camera information sent by the camera; the host compares the camera information in the first matching information with the camera information pre-stored in the second security chip to obtain a first authentication result; when the first authentication result is successful, the host encrypts the camera information and the random string in the first matching information using the server public key and signs with the host private key to obtain second matching information;
[0040] After receiving the second matching information, the backend server decrypts the second matching information using the server private key and verifies the signature using the host public key to obtain a random string generated by the camera and the camera information sent by the camera; the backend server compares the camera information in the second matching information with the camera information pre-stored on the backend server to obtain a second authentication result; the camera information and random string in the second matching result, as well as the second authentication result, are encrypted using the host public key and signed with the server private key to obtain third matching information;
[0041] After receiving the third matching information, the host uses the host private key to decrypt the third matching information and uses the server public key to verify the signature. After obtaining the information in the third matching information, it uses the camera public key to encrypt it and signs it with the host private key to obtain fourth matching information.
[0042] After receiving the fourth matching information, the camera decrypts it using the camera's private key and verifies the signature using the host's public key, obtaining the camera information, random string, and second authentication result contained in the fourth matching information. The camera then compares the camera information and random string contained in the fourth matching information with the camera information and the initially generated random string stored in the first security chip. If the comparison fails, authentication fails, and the camera will be unable to function properly. If the comparison succeeds, the camera will then verify that the second authentication result is successful. The camera generates the random string to ensure that the data has not been tampered with during the final camera check. The order in which the camera information and random string are compared or the authentication result is not specified.
[0043] When the mutual authentication among the camera, the host and the backend server is successful, the camera collects the target image; and through information interaction among the camera, the host and the backend server, a face recognition result corresponding to the target image is obtained.
[0044] Specifically, in one embodiment, when the mutual authentication between the camera, the host and the backend server is successful, the camera receives the face scanning command from the host and collects the target image; the camera performs face detection on the target image to obtain a face area image; the host obtains the face area image and sends the face area image to the backend server; the backend server obtains the face area image and performs face recognition comparison on the face area image to obtain a face recognition result.
[0045] In another embodiment, liveness detection in this system is performed by a camera. After the camera obtains the liveness detection result, it sends it to the backend server, which performs facial recognition on the image to obtain the facial recognition result. When mutual authentication between the camera, host, and backend server is successful, the camera receives the host's face scan command and captures the target image; the camera performs facial detection on the target image to obtain a facial area image; the camera performs liveness detection on the target image to obtain a biopsy result; the host obtains the facial area image and the biopsy result, and if the biopsy result is successful, it sends the facial area image to the backend server; the backend server obtains the facial area image and performs facial recognition comparison on the facial area image to obtain the facial recognition result. Liveness detection in this system is performed by the camera, which greatly reduces the burden on the backend server, reduces the computing power consumption of the backend server, and reduces costs.
[0046] Specifically, if Figure 4 As shown, Figure 4A signaling diagram for information exchange between the camera, host, and background server to obtain the face recognition result corresponding to the target image. When both the first authentication result and the second authentication result are successful, the background server generates a random string and sends the random string to the host; the host adds the random string to the face-scanning instruction, generates a face-scanning instruction, and sends the face-scanning instruction to the camera; when the camera receives the face-scanning instruction, the camera collects the target image; the camera performs liveness detection processing on the target depth image, target infrared image, and target color image according to the preset biopsy algorithm to obtain the face area image, biopsy signature information, and biopsy results; the camera encrypts the face area image, biopsy signature information, and biopsy results, packages them, and encrypts them twice to obtain liveness information, and sends the liveness information to the host; the secondary encryption key (SK) is a symmetric key (AES (or SM4), the key is randomly generated by the host during initialization and encrypted and sent to the camera; the host receives the liveness information and uses the secondary encryption key (SK) to decrypt the liveness information to obtain the encrypted facial area image, biopsy signature information, and biopsy result; when the biopsy result is successful, the host sends the encrypted facial area image and biopsy signature information to the backend server; the backend server receives the encrypted facial area image and biopsy signature information, first decrypts the image, and then verifies the biopsy signature information; after the signature verification is successful, the face recognition is performed on the face area image to obtain the face recognition result, and the face recognition result is sent to the host; the host receives the face recognition result and selects the next instruction based on the face recognition result. If the biopsy result is a failure, the host determines the reason for the biopsy failure based on the biopsy result and prompts the user.
[0047] In one possible implementation, in order to further ensure the security of data transmission, information is exchanged between the camera, the host and the background server. When the face recognition result corresponding to the target image is obtained, each time data is transmitted, it can be encrypted or decrypted using the face encryption key and the biopsy key.
[0048] Specifically, the camera can sign the biopsy information based on the biopsy key, encrypt the face area image based on the face encryption key, and then re-encrypt the signed biopsy information, encrypted face area image, and biopsy result based on a random symmetric key (SK) to obtain encrypted liveness information. The host receives the encrypted liveness information and decrypts it based on the symmetric key (SK) to obtain the encrypted face area image, signed biopsy information, and biopsy result. When the biopsy result is successful, the host sends the encrypted face area image and biopsy signature information to the backend server. The backend server receives the encrypted face area image, decrypts it, and verifies the signature of the biopsy information. After the signature verification is passed, it performs face recognition on the face area image to obtain the face recognition result, and sends the face recognition result to the host. The host receives the face recognition result and selects the next instruction based on the face recognition result.
[0049] The random string in this embodiment can be used as the initialization vector for the key during encryption. The camera pre-stores a biopsy key and a face encryption key, which are used to protect data transmission between the camera and the backend server. The biopsy key and face encryption key use the AES or SM4 algorithm, and each camera has a unique session key.
[0050] In one possible implementation, the system can preview the face area image in the host APP, the camera encrypts the face area image, and sends the encrypted face area image to the host; the host receives the encrypted face area image, decrypts the encrypted face area image, obtains the face area image, and displays the face area image.
[0051] In one embodiment, the camera, host, and backend server are reactivated based on camera information. In this embodiment, the camera and host are connected via USB. The camera monitors whether the camera's housing has been removed, not whether the connection between the camera and host has been severed. Upon detecting camera removal, the camera, host, and backend server must reestablish communication to prevent the camera from being replaced.
[0052] Specifically, if Figure 5 As shown, Figure 5 This diagram illustrates the signaling process for restarting and reactivating the camera, host, and backend server using camera information. When the camera detects that the camera housing has been removed, it updates the removal status information to "removed," generates a random string, and sets the detection key usage status to "invalid." The removal status information, random string, and camera information stored in the first security chip are then sent to the host.
[0053] The host receives the removal status information, random string, and camera information sent by the camera. That is, after the host detects that the camera is unavailable, it can trigger the anti-tampering activation process. The host sends the removal status information, random string, and received camera information to the backend server.
[0054] The background server receives the dismantling status information, the random string and the camera information, and compares the received camera information with the camera information pre-stored in the third security chip; when the received camera information is consistent with the camera information pre-stored in the third security chip, and the dismantling status information is dismantled, the background server sets the sending status information of the camera activation instruction to a sendable state; when the sending instruction of the camera activation instruction is detected, the background server sends the camera activation instruction, the random string and the received camera information to the host; the host receives the camera activation instruction, the random string and the camera information, and sends the obtained camera activation instruction, the random string and the camera information to the camera; the camera receives the camera activation instruction, the random string and the camera information, and when the random string and the received camera information are consistent with the information in the camera, and the camera activation instruction is to confirm activation, the camera is restarted and the usage status of the detection key is set to available.
[0055] In one possible implementation, in order to further ensure the security of data transmission, when the camera, host and background server are restarted and activated, each time data is transmitted, it can be encrypted or decrypted using the first key group, the second key group and the third key group.
[0056] Specifically, when the camera detects that the camera housing has been removed, it updates the removal status information to "removed," generates a random string, and sets the detection key usage status to invalid. The camera encrypts the removal status information, the random string, and the camera information pre-stored in the first security chip using the host's public key, signs the encryption with the camera's private key, and then sends the encryption to the host. The host verifies the signature using the camera's public key and then decrypts the encryption using the host's private key to obtain the removal status information, the random string, and the camera information pre-stored in the first security chip. The host can then encrypt the removal status information, the random string, and the camera information pre-stored in the first security chip using the server's public key, sign the encryption with the host's private key, and send the encryption to the backend server. The backend server decrypts the encryption using the server's private key and verifies the signature using the host's public key to obtain the removal status information, the random string, and the camera information pre-stored in the first security chip.
[0057] When a camera activation command is detected, the backend server encrypts the command, a random string, and the camera information stored in the third security chip using the host's public key, signs it with the server's private key, and sends it to the host. The host decrypts the command using its private key and verifies the signature using the server's public key, obtaining the command, random string, and camera information stored in the third security chip. The host then decrypts the command, random string, and camera information using the camera's public key, signs them with the host's private key, and sends them to the camera. The camera decrypts the command using its private key and verifies the signature using the host's public key, obtaining the command, random string, and camera information.
[0058] In one embodiment, the camera, host, and backend server use camera information to update keys. This further ensures key security and triggers a key update when a key leak is detected, ensuring data security. The detection key can include a biopsy key and a face encryption key. The biopsy key is used to encrypt the biopsy result, while the face encryption key is used to encrypt the facial region image. These two keys can be updated simultaneously or separately.
[0059] like Figure 6 As shown, Figure 6 Signaling diagram for the camera, host, and backend server to detect key updates through camera information.
[0060] In one embodiment, the detection key includes a biopsy key, and a specific method for updating the biopsy key is as follows.
[0061] The host sends a detection key update instruction to the camera; after the camera receives the detection key update instruction, it sends the camera information pre-stored in the first security chip to the host; the host receives the camera information sent by the camera and forwards it to the background server; the background server receives the camera information and compares the received camera information with the camera information pre-stored in the background server to obtain an update verification result; when the update verification result is a successful match, the command to update the detection key is triggered to obtain a new detection key; the background server sends the new detection key, the received camera information and the random character string to the host.
[0062] The host receives the new detection key, camera information and random string, and sends the new detection key, camera information and random string to the camera; when the random string and the camera information pre-stored in the first security chip are consistent with the information in the camera, the detection key in the first key group is updated according to the new detection key.
[0063] In one possible implementation, to further ensure data transmission security, the camera, host, and backend server can use the first, second, and third key groups to encrypt or decrypt each data transmission during a test key update. It is important to note that in this implementation, the test key is accessible only to the camera and backend server in plain text; the host cannot access the plain text of the test key to prevent host leaks.
[0064] Specifically, when the camera receives a detection key update command, it generates a random string and encrypts the camera information and random string pre-stored in the first security chip using the host's public key. The encrypted string is signed using the camera's private key to generate camera verification information, which is then sent to the host. The host decrypts the camera verification information using the host's private key and verifies the signature using the camera's public key to obtain the camera information and random string. The host then encrypts the decrypted camera information and random string using the server's public key and signs it with the host's private key to generate update verification information, which is then sent to the backend server. The backend server receives the update verification information, decrypts it using the server's private key, and verifies the signature using the host's public key to obtain the camera information and random string. The server then compares the camera information in the update verification information with the camera information pre-stored on the backend server to obtain the update verification result. If the update verification result is a match, the backend server triggers a command to update the detection key, obtaining a new detection key. The backend server encrypts the new detection key, the camera information, and random string in the update verification information using the camera's public key, signs it using the server's private key, and sends the update information to the host. The host forwards the update information directly to the camera, ensuring that the new detection key does not exist in plaintext on the link, enhancing security. The host's second security chip only stores the host key pair, camera public key and server public key. Therefore, the update information sent by the background server is encrypted with the camera public key. The host does not have the camera private key and cannot decrypt the plaintext data in the update information.
[0065] After the camera receives the update information, it uses the camera private key to decrypt and the server public key to verify the signature. After decryption and verification, when the camera information and random string in the update information are consistent with the camera information and generated random string pre-stored in the first security chip, the detection key in the first key group is updated according to the new detection key.
[0066] In one embodiment, the detection key includes a face encryption key. The specific details of the face encryption key update can be referred to the description of the biopsy key update process above, which will not be repeated here.
[0067] In an embodiment of the present application, a security chip-based facial recognition system includes a camera, a host, and a backend server. The camera includes a first security chip, and the data pre-stored in the first security chip includes camera information. The host includes a second security chip, and the data pre-stored in the second security chip includes camera information. The data pre-stored in the backend server includes camera information. The camera, host, and backend server mutually authenticate, restart, activate, or update keys using the camera information. When mutual authentication between the camera, host, and backend server is successful, the camera captures a target image. Through information exchange between the camera, host, and backend server, a facial recognition result corresponding to the target image is obtained. During facial recognition, mutual authentication is performed between the camera and host, and between the camera and backend server. Facial recognition is performed only after successful authentication, greatly improving the security and reliability of facial recognition and preventing facial feature data from being illegally obtained or tampered with. In addition, the system can perform key updates to further ensure data security. When removal is detected, the device can be restarted and activated, ensuring security while facilitating device maintenance.
[0068] An embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented.
[0069] An embodiment of the present application provides a computer program product. When the computer program product is run on a mobile terminal, the mobile terminal can implement the steps in the above embodiments when executing the computer program product.
[0070] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the present application implements all or part of the process of the above-mentioned method embodiment by instructing the relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of each of the above-mentioned method embodiments. The computer program includes computer program code, which can be in source code form, object code form, executable file, or some intermediate form. The computer-readable medium can at least include: any entity or device capable of carrying computer program code to the camera / terminal device, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal, and software distribution medium. For example, a USB flash drive, mobile hard drive, magnetic disk, or optical disk. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electric carrier signals or telecommunication signals.
[0071] In the above embodiments, the description of each embodiment has its own focus. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant description of other embodiments.
[0072] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0073] In the embodiments provided in this application, it should be understood that the disclosed devices / network equipment and methods can be implemented in other ways. For example, the device / network equipment embodiments described above are merely illustrative. For example, the division of the modules or units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0074] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0075] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the scope of protection of the present application.
Claims
1. A face recognition system based on a security chip, characterized in that: Including camera, host and backend server; The camera is provided with a first security chip, the host is provided with a second security chip, and the background server is provided with a third security chip; The first security chip, the second security chip, and the third security chip all have camera information pre-stored therein, and the camera, the host, and the backend server perform mutual authentication through the camera information; The camera is used to capture a target image according to the host's instructions after successful mutual authentication, and generate facial information based on the target image; The backend server is used to obtain the facial information through the host, and perform face recognition based on the facial information to obtain a face recognition result corresponding to the target image.
2. The face recognition system based on a security chip according to claim 1, characterized in that: The camera is configured to encrypt or decrypt data for communication with the host using the camera key pair, the host public key, and the server public key pre-stored in the first security chip; The host is configured to encrypt or decrypt data for communication and interaction with the camera and the backend server using the host key pair, the camera public key, and the server public key pre-stored in the second security chip; The background server is used to encrypt or decrypt data communicated with the host through the server key pair, the host public key and the camera public key pre-stored in the third security chip.
3. The face recognition system based on a security chip according to claim 2, characterized in that: The backend server is configured to obtain a detection key through the third security chip, encrypt the key with the camera public key, and then forward the key to the camera through the host; The camera is used to encrypt the target image using the detection key to obtain the facial information.
4. The face recognition system based on a security chip according to claim 3, characterized in that: The camera includes a dismantling detection unit for monitoring whether the hardware structure of the camera is moved. When it is monitored that the hardware structure is moved, the camera updates the dismantling status information to dismantled and sets the usage status of the detection key to invalid.
5. The face recognition system based on a security chip according to claim 1, characterized in that: The camera communicates and interacts with the host via a wired connection; The host accesses the Internet through a wireless gateway to communicate and interact with the background server.
6. The face recognition system based on a security chip according to claim 1, characterized in that: The camera, the host, and the backend server perform mutual authentication through the camera information, including: The host obtains the camera information pre-stored in the first security chip, compares the camera information pre-stored in the first security chip with the camera information pre-stored in the second security chip, and obtains a first authentication result; when the first authentication result is successful, the host sends the camera information pre-stored in the first security chip to the backend server; The backend server compares the camera information pre-stored in the first security chip with the camera information pre-stored in the backend server to obtain a second authentication result; the backend server sends the camera information pre-stored in the first security chip and the second authentication result to the host; The host receives the camera information and the second authentication result pre-stored in the first security chip, and sends the camera information and the second authentication result pre-stored in the first security chip to the camera; The camera receives the camera information pre-stored in the first security chip and the second authentication result; when the camera information pre-stored in the first security chip is consistent with the information pre-stored in the camera, and the second authentication result is passed, it is determined that the camera, the host and the background server have successfully authenticated each other.
7. A face recognition method based on a security chip, characterized in that: The method is applied to a face recognition system based on a security chip, the system comprising a camera, a host and a backend server; The camera is provided with a first security chip, the host is provided with a second security chip, and the background server is provided with a third security chip; The first security chip, the second security chip, and the third security chip all have camera information pre-stored therein; The method comprises: The camera, the host and the backend server perform mutual authentication through the camera information; After mutual authentication is successful, the camera captures a target image according to the host's instructions and generates facial information based on the target image; The backend server obtains the facial information through the host, and performs face recognition based on the facial information to obtain a face recognition result corresponding to the target image.
8. The face recognition method based on a security chip according to claim 7, characterized in that: Also includes: The camera monitors whether the hardware structure is moved, and when it is detected that the hardware structure is moved, updates the removal state information to removed.
9. A terminal device, characterized in that: include: Camera and host; The camera and the host are the camera and host included in the system described in any one of claims 1-6.
10. The terminal device according to claim 9, wherein: The terminal device includes: one of: an access control device, a door lock device, a face payment device, and a face identity verification device.
Citation Information
Patent Citations
Door lock communication system and method based on security chips
CN108122316A
Secure face recognition device based on trusted environment and dual security chips
CN109191131A