An offline identity authentication and key agreement method comprising biometric features

By combining biometrics and near-field communication technology, the difficulties in managing physical car keys and offline communication issues in shared vehicles are solved, enabling secure and reliable user authentication and key negotiation. This ensures that vehicles can still be used normally even if the smart terminal is lost, thus improving the security and convenience of using shared vehicles.

CN120050077BActive Publication Date: 2026-05-29SHANDONG UNIV OF SCI & TECH

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHANDONG UNIV OF SCI & TECH
Filing Date
2025-02-18
Publication Date
2026-05-29

AI Technical Summary

Technical Problem

During the use of shared vehicles, physical car keys are difficult to manage, user identity authentication methods in traditional car rental processes are easily stolen, multi-party communication lacks encryption protection, communication is difficult in offline environments, existing solutions are inadequate for car use after the smart terminal is lost, and communication is impossible when the network signal is poor.

Method used

An offline identity authentication and key negotiation method incorporating biometrics is adopted, involving the user's smart terminal device, the authentication server, and the vehicle. The uniqueness of biometrics is used to achieve identity authentication, and near-field communication technology is used to complete the vehicle use process in an offline environment. If the smart terminal is lost, the key is re-verified and obtained through the server.

Benefits of technology

It achieves secure and reliable user authentication in offline environments, prevents identity information theft, ensures continued vehicle use even after the smart terminal is lost, improves user experience and security, and prevents replay attacks, spoofing attacks, man-in-the-middle attacks, and key manipulation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050077B_ABST
    Figure CN120050077B_ABST
Patent Text Reader

Abstract

The application discloses an offline identity authentication and key negotiation method containing biological characteristics, and belongs to the technical field of shared resource network security. The method is completed by three parties of a user intelligent terminal device, an authentication server and a vehicle-mounted device, and contains user registration / vehicle initialization stage, user login / vehicle selection stage, user offline identity authentication and vehicle use stage, user vehicle return stage and user intelligent terminal loss and vehicle use stage. The main purpose of the application is to solve the problem that shared vehicles are scattered in different geographical spaces during use, leading to difficult management of physical vehicle keys. The core idea is to use the user's intelligent terminal as a key substitute for the shared vehicle, and through the introduction of biological characteristics, time stamps, random numbers and the like, the effects of preventing theft of the intelligent terminal attack, preventing replay attack, resisting key manipulation and the like can be achieved, so that the user experience and security are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology for shared resources, and specifically to an offline identity authentication and key negotiation method incorporating biometrics. Background Technology

[0002] With the rapid development of the sharing economy, the sharing model has provided a convenient and economical solution for travel by optimizing resource allocation—car-sharing services have rapidly become popular worldwide. However, during the use of shared vehicles, the scattered distribution of vehicles across a wide geographical area makes physical car key management difficult.

[0003] Traditional car rental typically requires users to register and log in to a platform, select a vehicle, wait for platform confirmation, unlock the vehicle using a key provided by the platform, and return it to a designated location. However, the traditional car rental process has the following problems: user authentication relies on accounts and passwords, which may lead to account theft; there is a lack of sufficient encryption in multi-party communication, posing a risk of leakage of user information; and communication is difficult in offline environments.

[0004] Current solutions attempt to provide smart cards and vehicle-to-everything (V2X) technology, which are convenient to some extent, but they are not perfect in terms of the user's continued use of the vehicle after the smart card or other smart terminal is lost. At the same time, they do not consider the problem of vehicle use in harsh environments where the user cannot communicate directly with the server due to poor network signal or other issues. Summary of the Invention

[0005] To address the aforementioned technical problems, this invention proposes an offline identity authentication and key negotiation method incorporating biometric features. This method primarily solves the problem of difficulties in managing physical vehicle keys caused by vehicles being scattered across different geographical locations during shared vehicle usage.

[0006] The technical solution adopted in this invention is:

[0007] An offline identity authentication and key negotiation method incorporating biometrics, involving the user's smart terminal device, an authentication server, and a vehicle, includes the following steps:

[0008] (1) User registration / vehicle initialization phase;

[0009] User's smart terminal device U provides its own real identity ID. U and password PW U Register at authentication server S and imprint the user's biometric features B at the blur extractor of the user's smart terminal device. U The authentication server S uses email or SMS to uniquely verify the user's identity and then saves the user's information, including the user's biometric features B. UAnd generate a key K shared with the user's smart terminal device U. U The user's smart terminal device U and the authentication server S jointly store the key K. U At the same time, vehicle V also registers and generates a vehicle ID at the authentication server S. V The key K shared with the authentication server S V Vehicle V and authentication server S jointly store key K V ;

[0010] (2) User login / vehicle selection stage;

[0011] User's smart terminal device U inputs identity ID' U and password PW' U And imprint the user's biometric B at the blur extractor of the user's smart terminal device. U ', using shared key K U After encrypting the identity information, a login request is sent to the authentication server S. The authentication server S uses the shared key K. U After decryption, verify the user's identity. If valid, generate a session key K. U,S Send the information to the user's smart terminal device U; if the user's smart terminal device U is authenticated by the authentication server S, then the user's smart terminal device U begins selecting a vehicle and obtains the vehicle ID. V Authentication server S generates session key K. U,V The authentication server S sends the information to vehicle V and first uses the shared key K. V The encryption contains all the information the user needs for the ride, i.e., the ride ticket, and then uses the shared key K. U After encrypting this vehicle rental ticket, it is sent to the user's smart terminal device U;

[0012] (3) User offline identity authentication vehicle use stage;

[0013] After receiving the encrypted vehicle booking ticket in step (2), the user's smart terminal device U is set to only accept the shared key K by inputting the correct user biometric features. U Decryption, thus obtaining the shared key K V The user's smart terminal device U then presents this encrypted ride-hailing ticket to the vehicle V, which uses the shared key K. V After decryption, the information is obtained and verified. If the verification is successful, vehicle V is unlocked. During this process, the user's smart terminal device U and vehicle V use near-field communication.

[0014] (4) User returns the vehicle;

[0015] User's smart terminal device U submits a vehicle return request to authentication server S. Authentication server S verifies the identity ID of user's smart terminal device U.U and password PW' U Then, the user's biometric B is imprinted on the blur extractor of the user's smart terminal device. U After successful verification, the authentication server S destroys the session key K. U,S and K U,V .

[0016] Preferably, the above-mentioned offline identity authentication and key negotiation method incorporating biometrics further includes the following steps:

[0017] (5) Continued vehicle use after the user's smart terminal device is lost;

[0018] If the smart terminal device is lost during the user's vehicle use, the user needs to verify their identity ID on a new smart terminal device. U And submit a verification request to authentication server S, which retrieves the already registered ID from the database. U Then, the user's identity is uniquely verified using an email address or SMS message, and the password PW generated during user registration is used. U Encryption key K previously shared with user's smart terminal device U U The encrypted information is sent to the new user's smart terminal device, which then enters the password PW'. U Decryption yields the shared key K U After successfully verifying the user's biometrics, the authentication server S retrieves the previously generated vehicle rental ticket from the database using the shared key K. U The ticket is then encrypted and resent to the new user's smart terminal device so that the new user's smart terminal device can continue to use the vehicle using this ticket.

[0019] The principles and beneficial technical effects of this invention are as follows:

[0020] This invention proposes an offline identity authentication and key negotiation method incorporating biometrics. This method utilizes smart terminal devices (such as mobile phones and smartwatches) as car key carriers to realize the entire user car usage process. Considering the issue of re-using a car after a lost smart terminal, it leverages the uniqueness and forgery resistance of user biometrics for identity authentication. It stipulates that a usage ticket is only issued after the user inputs the correct biometrics, preventing identity theft and ensuring security after replacing the smart terminal. Simultaneously, near-field communication (NFC) technology is used to implement the user car usage process to solve the offline authentication problem, avoiding inconvenience to users. Key negotiation technology encrypts each call and basic user information, improving both user experience and security.

[0021] Specifically, the method of the present invention also has the following advantages:

[0022] This invention enables identity authentication for user smart terminal devices, authentication servers, and vehicles (or in-vehicle devices); each message transmission is accompanied by a timestamp T. n Transmitted together, each time the subject receives a message, it first checks the timestamp T. n The validity of the authentication mechanism is ensured, and the process only continues if the authentication is confirmed. Therefore, this invention prevents replay attacks. In this invention, the user first applies for a vehicle from the server. After verifying the user's identity, the server returns a vehicle usage voucher (vehicle usage ticket). This voucher is encrypted and protected by a shared key between the server and the vehicle. The user cannot see any specific information in the voucher. After receiving this encrypted voucher, the user only needs to present it to the selected vehicle. The vehicle uses the shared key to decrypt the voucher, obtains the specific information it contains, and verifies it to unlock the vehicle and enable usage. If the user's smart terminal device is lost and needs to be replaced, the user only needs to apply to the server. After successful authentication, the server will resend the voucher stored in the database to the user to facilitate continued vehicle usage. Therefore, this invention prevents attacks that steal smart terminals. Due to the existence of the authentication mechanism, this method can prevent spoofing attacks, because attackers must obtain all the user's secret information to pass the verification. It can also prevent man-in-the-middle attacks, as each login verification process requires multiple message transmissions, all of which are encrypted and protected, ensuring secure transmission. By using random numbers in conjunction with other secret information for calculation, communication security is not affected, and it can resist attacks that temporarily leak secrets. The components of the session key in this method come from different parties, and authentication is carried out during transmission. Therefore, no party can independently calculate the session key, thus effectively resisting key manipulation. Attached Figure Description

[0023] Figure 1 This is a schematic diagram of the overall process of an offline identity authentication and key negotiation method incorporating biometrics according to the present invention. Detailed Implementation

[0024] During the use of shared vehicles, the scattered distribution of vehicles across a wide geographical area makes physical key management difficult. Meanwhile, users' smart terminals, such as smartphones and smartwatches, are becoming increasingly common. The starting point for this invention is to explore how to combine cryptography, network security protocols, and biometric extraction and authentication technologies to use smart terminals as a substitute for shared vehicle keys, thereby significantly reducing the difficulties of managing physical keys while ensuring security.

[0025] Based on this, the present invention proposes an offline identity authentication and key negotiation method incorporating biometrics, in which the user's smart terminal device, the authentication server, and the vehicle (in-vehicle device) participate in identity authentication and key exchange. The method includes stages such as user registration / vehicle initialization, user login / vehicle selection, offline identity authentication for vehicle use, user return of the vehicle, and continued vehicle use after the user's smart terminal is lost. The user's smart terminal device and the in-vehicle device first register with the authentication server. The authentication server generates a shared key and exchanges and saves them separately. The smart terminal device must be equipped with a biometric fuzzy extractor (such as a fingerprint scanner or facial recognition camera) and a near-field communication (NFC) module, and the vehicle must be equipped with an NFC receiver. Before using the vehicle, the user's smart terminal device must log in to the authentication server, negotiate with the authentication server to generate and exchange a session key for this communication, and then the communication between the smart terminal device and the authentication server is encrypted using the exchanged session key. The user-selected vehicle negotiates with the authentication server to generate and exchange a session key for this communication, and then the communication between the vehicle and the authentication server is encrypted using the exchanged session key. During the rental period, users communicate with the vehicle using near-field communication. Users simply present a rental ticket encrypted with a shared key, which the vehicle then decrypts, completing the rental without server intervention. Returning the vehicle simply involves destroying the session key and invalidating the rental ticket. If a user's smart device is lost, a password generated during registration is required to retrieve the shared key and its encrypted rental ticket, ensuring continued vehicle use.

[0026] Given that the authentication server, as the main management entity, has relatively weak performance, the authentication key exchange process typically uses only lightweight operations such as XOR and hash operations for registration and authentication of user smart terminal devices and vehicle-mounted devices. The authentication server, as the central node for key negotiation and exchange, undertakes most of the computational tasks related to key negotiation, generation, and verification, while smart terminal devices and vehicle-mounted devices also perform a smaller number of computational tasks.

[0027] The present invention will be further described below with reference to the accompanying drawings and specific embodiments:

[0028] like Figure 1 As shown, an offline identity authentication and key negotiation method incorporating biometrics is presented. This method involves three entities: the user's smart terminal device, the authentication server, and the vehicle. The method includes the following steps:

[0029] Step 1: User registration / vehicle initialization phase;

[0030] Users provide their own identity ID U and password PW U Register at authentication server S and imprint biometric B at the fuzzy extractor of the terminal device.U The authentication server S uniquely verifies the user's identity using an email address or SMS message and then saves the user's relevant information, including the user's biometric features B. U And generate a key K shared with the user's smart terminal device U. U The user's smart terminal device U and the authentication server S jointly store the key K. U This ensures the security of subsequent information transmission. Simultaneously, vehicle V also registers and generates an ID with the authentication server S. V The shared key K with the authentication server S V Vehicle V and authentication server S jointly store the shared key K. V .

[0031] Specifically, the user registration / vehicle initialization phase includes the following steps:

[0032] Step 11: To obtain services from the selected server S, users must first go through a registration process, in which they select their own identity ID. U and password PW U Then, a registration request {ID} is submitted to server S via a secure channel. U PW U}

[0033] Step 12: Server S receives a registration request {ID} from user's smart terminal device U. U PW U Afterwards, the user's identity is uniquely verified via email or SMS, and a shared key K is generated between the user's smart terminal device U and the server S. U and {ID U PW U ,K U} is stored in the database, and then {K} is sent through a secure channel. U} is sent to the user's smart terminal, and the smart terminal stores {K U}

[0034] Step 13: The user's smart terminal device U receives {K} from the server S. U Afterwards, biometric feature B is imprinted at the fuzzy extractor of the smart terminal. U And calculate (R) U ,P U ) = Gen(B U ), and V = h(ID) U ||PW U ), then {B U ,P U The server sends {B, L, V} to server S, and the server sends {B} to server S. U ,PU The values ​​of ,L,V} are stored in the database. Here, N is a random number, Gen(·) is the generation algorithm for the fuzzy extractor, and R... U It is the string output by the generation algorithm, P U It is a public help string that generates the output of the algorithm.

[0035] Step 14: Vehicle V registers with the server to generate a unique identifier (vehicle number) ID. V And establish a shared key K with server S. V Server S will use the vehicle ID. V Stored in the database, and both server S and vehicle V store K. V .

[0036] Step 2: User login / car selection stage;

[0037] User's smart terminal device U inputs identity ID' U and password PW' U Imprinting biometric feature B at the blur extractor of the terminal device. U ', using shared key K U After encrypting the identity information, a login request is sent to server S. Server S uses the shared key K. U After decryption, verify the user's identity. If valid, generate a session key K. U,S The message is sent to the user's smart terminal device U, and then both parties perform identity authentication and key exchange. If the user's smart terminal device U is authenticated by the server S, then the user's smart terminal device U begins selecting a vehicle and obtains the vehicle ID. V Server S generates session key K U,V The message is sent to vehicle V, and server S first uses the shared key K. V The encryption contains all the information the user needs for the ride, i.e., the ride ticket, and then uses the shared key K. U After encrypting this ticket, it is sent to the user's smart device terminal U. This ticket can only be used by vehicle V with the shared key K. V Decrypt.

[0038] Specifically, the user login / car selection stage includes the following steps:

[0039] Step 21: The user enters their identity ID on the smart terminal. U and password PW' U Biometric feature B is imprinted at the fuzz extractor of the smart terminal. U Because the newly entered username and password may not be correct during login, and they need to be compared with the initial username and password stored on the server, the identity ID is used. U With ID U To differentiate. (The ID') Uand using shared key K U Encrypted {PW' U B U The request to log in is sent to server S via a secure channel, and server S uses the shared key K. U Decrypt and save {PW' U B U '}, verify R U =Rep(B U ',P U ), If the verification fails, the session is terminated; otherwise, if the verification is valid, server S generates a session key K. U,S After being stored in the database, it is sent to the user's smart terminal device U, and the smart terminal saves it. U,S Rep(·) is the regeneration algorithm of the fuzzy extractor.

[0040] Step 22, User Smart Terminal Device U-Computing Select a random number r U And X, then calculate K U,S =h(ID) U ||H||A1||A2||T1) and C U =h(ID) U ||H||K U,S ||T1), the user's smart terminal will {ID U ,p,q,g,r U The server sends {ID} to server S. Server S will then send {ID} to server S. U ,p,q,g,r U The data (X, A1, NID, T1) is stored in the database, and the user's smart terminal device uses the shared key K. U For {K U,S ,H,C U After encryption, the encrypted result is sent to the server S through a secure channel. Here, T1 is the current timestamp of the user's smart terminal device U, p is a randomly generated large prime number, q is a (p-1) prime factor, and g is the q-order primitive element of the finite field GF(p).

[0041] Step 23: When server S receives the message at time T2, it verifies that |T2-T1|≤ΔT, where ΔT is the effective time delay in message transmission. If the verification fails, server S terminates the session. Otherwise, server S uses the shared key K. U Decryption yields {K U,S ,H,C U}, then calculate and obtain Server S stores {A3, ID}U} and use ID U Retrieve from the database and verify C. U =? h(ID) U (||H||A1||A3||T1). If verification fails, the session terminates. Otherwise, the user's smart terminal device U authenticates through server S, and server S returns the authentication result to the user's smart terminal device U.

[0042] Step 24: When the user's smart terminal device U receives the message at time T3, it verifies that |T3-T2|≤ΔT. If the time delay in message transmission is invalid, the session is terminated. Otherwise, the user's smart terminal device U will select the vehicle ID. V and {ID U {ID} is sent to server S via a secure channel, and server S stores {ID}. V Server S generates a random number r. S ,calculate And generate session key K U,V =h(ID) U ||ID V ||H||A4||A3||T3||T1) and C S =h(ID) U ||H||K U,V ||T3), then server S uses the shared key K V Encrypted ticket information {K U,V C S After A4}, use the shared key K. U Encrypt the ticket, then combine the encrypted information with {ID} V ,r S Together with T3, the ticket for the specified vehicle is sent to the user's smart terminal device U.

[0043] Step 3: User offline identity verification for vehicle use;

[0044] After receiving the information from step 2, user smart terminal device U is required to use the shared key K only if the correct biometric features are entered. U Decryption yields the shared key K. V The encrypted ride ticket is then presented by the user's smart terminal device U to the vehicle V, which uses the shared key K. V After decryption, the information is obtained and verified. If the verification is successful, vehicle V is unlocked, and the user can use vehicle V. During this process, the user's smart terminal device U and vehicle V use near-field communication, without the need for server S to participate.

[0045] By introducing biometrics into the offline authentication process, security risks such as vehicle theft caused by the loss of smart terminals can be addressed.

[0046] Specifically, the offline identity verification process for vehicle use includes the following steps:

[0047] Step 31: After receiving the information from step 24 at time T4, the user's smart terminal verifies |T4-T3|≤ΔT. If the time delay in message transmission is invalid, the session is terminated. Otherwise, proceed to the following steps. Here, it is stipulated that the user's smart terminal device U can only use the shared key K after inputting the correct biometric features. U Decrypt the information to obtain the shared key K. V The encrypted vehicle rental ticket. The ticket is then shown to vehicle V, along with the {ID} U ,H,X,r S {p,g,A2,T1,T3} is sent to vehicle V, and vehicle V saves {ID}. U ,H,X,r S ,p,g,A2,T1,T3}, and use the shared key K V Decrypt the bill and calculate Session key K U,V =h(ID) U ||ID V (||H||A2||A5||T3||T1), verify C S =? h(ID) U ||ID V If the verification fails (||H||A2||A5||T3||T1), the session will be terminated; otherwise, if the verification succeeds, the vehicle will be unlocked, meaning the user can use the vehicle.

[0048] Step 4: User returns the vehicle;

[0049] User's smart terminal device U submits a vehicle return request to server S, and server S confirms the identity ID entered by user's smart terminal device U. U and password PW' U Then, users are required to imprint their biometric B at the fuzzy extractor on their smart devices. U After successful verification, server S destroys session key K. U,S and K U,V .

[0050] Specifically, the user's vehicle return process includes the following steps:

[0051] Step 41: The user's smart terminal device U confirms its identity ID. U and password PW' U Then, send {ID' to server S through a secure channel. U ,PW'U} to submit a request to return the vehicle.

[0052] Step 42: After receiving the return request from the user's smart terminal device U, the server S verifies {ID' U ,PW' U After successful verification, the user is required to imprint their biometric B at the fuzzy extractor on the smart terminal. U ', Server S received B U Post-validation R U =Rep(B U ',P U And calculate If the verification fails, the session terminates; otherwise, if the verification succeeds, proceed to step 43.

[0053] Step 43: Server S Destroys K U,S K U,V At the same time, the server S destroys the vehicle usage ticket that the user's smart terminal device U presented to the vehicle V during the usage period.

[0054] Step 5: Continued vehicle use after the user's smart terminal is lost;

[0055] If a user's smart terminal device is lost during vehicle use, the user needs to verify their identity ID on a new smart terminal device. U And submit a verification request to server S, server S retrieves the already registered ID from the database. U Then, the user's identity is uniquely verified using an email address or mobile SMS, and the password PW generated during user registration is used. U Encryption of the key K previously shared with the user's smart terminal U U The encrypted information is sent to the user's smart terminal device U. The user's smart terminal device U then enters the password PW'. U Decryption yields the shared key K U After server S successfully verifies the biometric characteristics of user's smart terminal device U, it retrieves the previously generated vehicle rental ticket from the database using the shared key K. U The encrypted ticket is then resent to the user's smart terminal device U, allowing the user's smart terminal device U to continue using the vehicle with this ticket. In other words, this invention allows users to change their smart terminal while renting the same vehicle.

[0056] Specifically, the continued vehicle use phase after a user's smart terminal device is lost includes the following steps:

[0057] Step 51: If the user's smart terminal is lost during vehicle use, the user needs to enter their identity ID on a new smart terminal. U And submit the ID to server S through a secure channel. UTo make a verification request, server S retrieves the already registered ID from the database. U Then, the system verifies the user's identity using the email address or SMS message used during registration, and uses the password PW generated during user registration. U Encryption key K previously shared with user's smart terminal device U U Simultaneously using shared key K U Encrypt the current timestamp {T5}, then PW U The encrypted information is sent to the user's smart terminal device U.

[0058] Step 52: After receiving the information from the server S at time T6, the user's smart terminal device U first enters the password PW'. U Decryption is performed to obtain the shared key K. U And {T5}, verify |T6-T5|≤ΔT. If the time delay in message transmission is invalid, terminate the session. Otherwise, the user imprints biometric feature B at the fuzzy extractor of the smart terminal. U ', then use the shared key K U Encryption B U 'After ID U B is sent together to server S, and server S saves it. U And verify R U =Rep(B U ',P U ), If the verification fails, the session terminates; otherwise, if the verification succeeds, server S will store the ticket in the database using the shared key K. U After encryption, the ticket is resent to the user's smart terminal device U, meaning the user's smart terminal device U can then present the ticket to the vehicle V again so that the user can continue to use the vehicle V.

[0059] The symbols used in the above steps and their explanations are summarized below:

[0060] U represents the user's smart terminal device; S represents the authentication server; V represents the vehicle; ID U This indicates the user's real identity; PW U B represents the user's password; U User's biometric characteristics; ID V Indicates the vehicle's actual serial number; K U K represents the shared key between U and S; V K represents the shared key between V and S; U,S K represents the session key between U and S. U,V This represents the session key between U and V; The symbol represents the XOR operation; || represents the concatenation operator; mod represents the modulo operation; h(·) represents the one-way hash function; A1~A5 represent the intermediate parameters generated during key negotiation; Gen represents the generation process of fuzzy extraction; Rep represents the recovery process of fuzzy extraction; R U To generate the string output by the algorithm; P U To generate a public help string for the algorithm's output; T n Represents the nth timestamp; ΔT represents T. n With T n-1 The time difference between them; p represents a large prime number; q represents a (p-1) prime factor; g represents the q-order primitive of the finite field GF(p).

[0061] For any parts not mentioned above, existing technologies can be adopted or referenced.

[0062] The embodiments described above are merely preferred embodiments of the present invention and are not intended to limit the scope of the present invention. Various modifications and improvements made by those skilled in the art to the technical solutions of the present invention without departing from the spirit of the present invention, such as replacing shared vehicles with other shared resources with access control, should also fall within the protection scope defined by the claims of the present invention.

Claims

1. An offline identity authentication and key negotiation method incorporating biometrics, characterized in that, This method involves the participation of three parties: the user's smart terminal device, the authentication server, and the vehicle, and includes the following steps: (1) User registration / vehicle initialization phase; User smart terminal devices Provide your real identity and password On the authentication server The user applies for registration and has their biometric features imprinted on the blur extractor of their smart terminal device. Authentication server User information, including biometrics, is saved after a unique verification of the user's identity via email or SMS. And generate with user smart terminal devices Shared key User smart terminal devices With authentication server Shared key Meanwhile, vehicles Also on the authentication server Register and generate vehicle number and authentication server Shared key ,vehicle With authentication server Shared key ; (2) User login / vehicle selection stage; User smart terminal devices Enter identity and password And imprint the user's biometric features at the blur extractor of the user's smart terminal device. Using a shared key After encrypting the identity information, send it to the authentication server. Send login request, authentication server Use shared keys After decryption, verify the user's identity. If valid, generate a session key. Send to user's smart terminal device If the user's smart terminal device Through the authentication server The user's smart terminal device is authenticated. Start selecting a car and obtain the vehicle number. Authentication server Generate session key Send to vehicle Authentication server First use the shared key The encryption contains all the information a user needs for their ride, namely the ride ticket, and then uses a shared key. The rental ticket is then encrypted and sent to the user's smart terminal device. ; (3) User offline identity authentication vehicle use stage; User smart terminal devices After receiving the encrypted vehicle rental ticket in step (2), configure the user's smart terminal device. Only users who enter the correct biometric information can use the shared key. Decryption, thus obtaining the shared key. Encrypted ride-hailing ticket, then the user's smart terminal device. Show this encrypted vehicle rental ticket to the vehicle ,vehicle Use shared keys After decryption, the information is obtained and verified. If the verification is successful, the vehicle... Unlock; during this process, the user's smart terminal device With vehicles Use near-field communication; (4) User returns the vehicle; User smart terminal devices to the authentication server Submit a car return request, authentication server Confirm user's smart terminal device identity and password Then, the user's biometric features are imprinted on the blur extractor of the user's smart terminal device. After successful verification, the authentication server Destroy session key and .

2. The offline identity authentication and key negotiation method incorporating biometrics according to claim 1, characterized in that, It also includes the following steps: (5) The stage of continuing to use the vehicle after the user's smart terminal device is lost; If the smart terminal device is lost during the user's vehicle use, the user needs to verify their identity on a new smart terminal device. and to the authentication server Submit a verification request to the authentication server. Retrieve already registered users from the database Then, the user's identity is uniquely verified using an email address or SMS message, and the password generated during user registration is used. Encryption previously associated with user smart terminal devices Shared key The encrypted information is sent to the new user's smart terminal device, which then enters the password. Decrypt to obtain the shared key Authentication server After successfully verifying the user's biometrics, the previously generated vehicle rental ticket is retrieved from the database using a shared key. The ticket is then encrypted and resent to the new user's smart terminal device so that the new user's smart terminal device can continue to use the vehicle using this ticket.

3. The offline identity authentication and key negotiation method incorporating biometrics according to claim 2, characterized in that, Step (1) specifically includes the following steps: (11) Users select their own identity and password Then, it sends a message to the authentication server via a secure channel. Submit registration request ; (12) Authentication server Received from user smart terminal device Registration request sent Then, the user's identity is uniquely verified via email or SMS, and the user's smart terminal device is generated. With authentication server Shared key and will Stored in the database, and then transmitted via a secure channel. Send to the user's smart terminal device, and store it on the user's smart terminal device. ; (13) When the user's smart terminal device receives the authentication server Sent Then, the user's biometric features are imprinted at the blur extractor of the smart terminal device. and calculate , and Then Send to the authentication server Authentication server Will Store in the database; in, It is a random number. It is the generation algorithm of the fuzz extractor. It is the string output by the generation algorithm. It is a public help string generated by the algorithm. This represents the XOR operation. Indicates a connector; Represents a hash function; (14) Vehicles On the authentication server Register and generate vehicle number and authentication server Establish a shared key Authentication server Vehicle number Stored in the database, and authenticated by the server. and vehicles All store keys .

4. The offline identity authentication and key negotiation method incorporating biometrics according to claim 3, characterized in that, Step (2) specifically includes the following steps: (21) The user enters his identity on the smart terminal device and password Biometric features are imprinted at the blur extractor of the smart terminal device. ,Will and using shared keys Encrypted Send to the authentication server via a secure channel To request login, authentication server Use shared keys Decrypt and save ,verify , If the verification fails, the session is terminated; otherwise, the verification is successful, and the authentication server... Generate session key It is then stored in the database and subsequently sent to the user's smart terminal device. User smart terminal devices save ;in, It is a regeneration algorithm for the fuzzy extractor; (22) User intelligent terminal device computing Select random number and and calculate , , , and User smart terminal devices will Send to the authentication server Authentication server Will Stored in the database, smart terminal devices use a shared key right After encryption, the encryption result is sent to the authentication server through a secure channel. ; in, It is a user smart terminal device Current timestamp It is a randomly generated large prime number. This represents the modulo operation. yes Element factor, It is a finite field of The fundamental element; (23) Authentication server In time Verify upon receiving the message. ,in This refers to the effective time delay during message transmission; if the verification fails, the authentication server... Terminate the session; otherwise, the authentication server... Use shared keys Decryption Then calculate and obtain Authentication server save Use Retrieve from the database and verify. If verification fails, the session terminates; otherwise, the user's smart terminal device... Through the authentication server Authentication, authentication server The authentication result is returned to the user's smart terminal device. ; (24) User intelligent terminal equipment In time Verify upon receiving the message. If the time delay in message transmission is invalid, the session will be terminated; otherwise, the user's smart terminal device... Select the vehicle number and Send to the authentication server via a secure channel Authentication server save And authentication server Generate random numbers ,calculate and generate session keys. and Then the authentication server Use shared keys Encrypted ticket information Then, use Encrypt the ticket, then combine the encrypted information with... Send together to the user's smart terminal device .

5. The offline identity authentication and key negotiation method incorporating biometrics according to claim 4, characterized in that, Step (3) specifically includes the following steps: (31) In time After receiving the information from step (24), the user's smart terminal device verify If the time delay in message transmission is invalid, the session is terminated; otherwise, the following steps are performed, specified here for the user's smart terminal device. Only after entering the correct biometrics can the shared key be used. Decrypt the information to obtain the shared key. The rental ticket is encrypted, and then the rental ticket is sent to the vehicle. Show, and at the same time Send to vehicle ,vehicle save and using a shared key Decrypt the bill and calculate Session key ,verify If verification fails, the session is terminated; otherwise, if verification succeeds, the vehicle is unlocked and the user can use the vehicle.

6. The offline identity authentication and key negotiation method incorporating biometrics according to claim 5, characterized in that, Step (4) specifically includes the following steps: (41) The user confirms his / her identity and password Then, it sends a message to the authentication server via a secure channel. send Submit a request to return the vehicle; (42) Upon receiving a vehicle return request submitted by a user, the authentication server verify After successful verification, the user's smart terminal device is required. Imprinting its biometric features at the fuzzy extractor Authentication server receive Post-verification And calculate If the verification fails, the session terminates; otherwise, if the verification succeeds, proceed to step (43). (43) Authentication server destroy , Simultaneously, authentication server Destroy user smart terminal devices used during vehicle rental Show to vehicle Vehicle usage receipts.

7. The offline identity authentication and key negotiation method incorporating biometrics according to claim 6, characterized in that, Step (5) specifically includes the following steps: (51) If a user’s smart terminal device is lost during vehicle use, the user needs to enter their identity on a new smart terminal device. and through a secure channel to the authentication server submit Make a verification request, authentication server Retrieve registered users from the database. Then, the system verifies the user's identity using the email address or SMS message used during registration, and uses the password generated during user registration. Encryption previously associated with user smart terminal devices Shared key Using a shared key at the same time For the current timestamp Encrypt, and then The encrypted information is sent to the user's smart terminal device. ; (52) User intelligent terminal equipment In time Received authentication server After receiving the information, first enter the password. Decrypt to obtain the shared key. and ,verify If the time delay in message transmission is invalid, the session is terminated; otherwise, biometric features are imprinted at the fuzzy extractor of the user's smart terminal device. Then use encryption After and Send together to the authentication server Authentication server Preservation of biological characteristics And verify , If the verification fails, the session terminates; otherwise, the verification succeeds, and the authentication server... The tickets stored in the database will be stored using a shared key. Resend to the user's smart terminal device after encryption User smart terminal devices Can show the vehicle rental receipt to the vehicle again? In order to continue using the vehicle .