Biological recognition login method, registration method and equipment

Through the biometric login method, the cross-verification of biometric and account features combined with device identification features is solved, and the problem of username and password leakage during vehicle login is achieved, and a safe and convenient login process is achieved.

CN120337193APending Publication Date: 2025-07-18ZHEJIANG GEELY HLDG GRP CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510407120.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-02
Publication Date
2025-07-18

Smart Images

  • Figure CN120337193A_ABST
    Figure CN120337193A_ABST
Patent Text Reader

Abstract

The invention provides a biological recognition login method, a registration method and a device, the biological recognition login method is applied to a client communicating with a target device, and comprises the following steps: obtaining user login information of a login operation of the target device as to-be-verified login information, and obtaining first character string information corresponding to the target device; wherein the login operation is triggered by a first user, the first character string information is generated through user login information of a second user for the target equipment, and the second user is a user with the login authority of the target equipment; determining equipment login verification information based on the first character string information and the to-be-verified login information; and sending the equipment login verification information to the verification end, so that the verification end determines a login feedback message of the login operation through the equipment login verification information. According to the technical scheme, the convenience and safety of vehicle machine login are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of vehicles, and in particular, to a biometric login method, a registration method, and a device. Background Art

[0002] In the technical field of vehicles, as the requirements for vehicle use safety continue to increase, it is often necessary to perform a login operation on the client corresponding to the vehicle, and the use permission of the vehicle can be obtained after successful login.

[0003] In the prior art, generally, login is performed by inputting a username, a user password, etc. However, in this login method, there are situations such as leakage and forgetting of the username and password, resulting in inconvenience and insecurity for users to log in.

[0004] Therefore, how to ensure the convenience and security of in-vehicle computer login has become a technical problem to be solved urgently. Summary of the Invention

[0005] This application provides a biometric login method, a registration method, and a device to ensure the convenience and security of in-vehicle computer login, etc.

[0006] In a first aspect, an embodiment of this application provides a biometric login method, which is applied to a client communicating with a target device. The method includes:

[0007] Obtain the user login information of the login operation of the target device as the login information to be verified, and obtain the first string information corresponding to the target device; wherein, the login operation is triggered by a first user, and the first string information is generated by a second user according to the user login information of the target device. The second user is a user with the login permission of the target device; the user login information at least includes: the biometric information of the corresponding user, the account characteristics of the corresponding user, and the device identification characteristics of the target device;

[0008] Determine the device login verification information based on the first string information and the login information to be verified;

[0009] Send the device login verification information to the verification end, so that the verification end determines the login feedback message of the login operation through the device login verification information.

[0010] In one or more embodiments, the device login verification information includes: a first ciphertext;

[0011] The determining the device login verification information based on the first string information and the login information to be verified includes:

[0012] Perform a first decryption on the first string information to obtain second string information;

[0013] Perform a second encryption on the login information to be verified using the second string information to obtain the first ciphertext.

[0014] In one or more embodiments, before the login information of the user for the login operation of the target device obtained is the login information to be verified, the method further includes:

[0015] Verify the first biometric feature of the first user who triggers the login operation;

[0016] Determine that the first biometric feature verification is successful.

[0017] In a second aspect, an embodiment of the present application provides a biometric login method applied to a verification end, and the method includes:

[0018] Receive device login verification information sent by a client communicating with a target device, where the device login verification information is determined based on first string information and login information to be verified; the login information to be verified is the user login information of the login operation of the target device, the login operation is triggered by a first user, the first string information is generated by a second user for the user login information of the target device, and the second user is a user with the login permission for the target device; the user login information at least includes: biometric information of the corresponding user, account features of the corresponding user, and device identification features of the target device;

[0019] Determine a login feedback message for the login operation based on the device login verification information.

[0020] In one or more embodiments, the device login verification information includes a first ciphertext and first string information, and the first ciphertext is obtained by performing a first encryption on the login information to be verified using the first string information;

[0021] The determining the login feedback message for the login operation based on the device login verification information includes:

[0022] Determine third string information corresponding to the first string information, where the third string information is obtained by performing a second encryption on the user login information of the target device by the second user;

[0023] Perform a third encryption on the user login information of the target device by the second user based on the third string information to generate a second ciphertext;

[0024] Generate the login feedback message for the login operation according to the first ciphertext and the second ciphertext.

[0025] In one or more embodiments, the device login verification information further includes: a first public key and a second signature of the client, where the second signature is generated based on the first ciphertext and a first private key of the client;

[0026] Before generating the login feedback message for the login operation according to the first ciphertext and the second ciphertext, it further includes:

[0027] Determine that the verification of the second signature by the first public key of the client is successful, indicating that the process of the client transmitting the device login verification information to the verification end is in a secure state.

[0028] In one or more embodiments, generating the login feedback message for the login operation according to the first ciphertext and the second ciphertext includes:

[0029] In response to the first ciphertext and the second ciphertext being consistent, generate a first feedback message as the login feedback message, where the first feedback message is used to indicate that the login operation is successful for logging in to the target device;

[0030] In response to the first ciphertext and the second ciphertext being inconsistent, generate a second feedback message as the login feedback message, where the second feedback message is used to indicate that the login operation fails for logging in to the target device.

[0031] In one or more embodiments, the third string information is string information carrying an expiration date;

[0032] Generating the login feedback message for the login operation according to the first ciphertext and the second ciphertext includes:

[0033] In response to the first ciphertext and the second ciphertext being consistent and the current timestamp being within the expiration date, generate a third feedback message as the login feedback message; the third feedback message is used to indicate that the login operation is successful for logging in to the target device;

[0034] In response to the first ciphertext and the second ciphertext being inconsistent, or the current timestamp not being within the expiration date, generate a fourth feedback message as the login feedback message, where the fourth feedback message is used to indicate that the login operation fails for logging in to the target device.

[0035] In a third aspect, an embodiment of the present application provides a biometric registration method, which is applied to a verification end, and the method includes:

[0036] In response to a registration request sent by a client communicating with the target device, obtaining user login information of a second user for the target device, the user login information including at least: biometric information of the corresponding user, account characteristics of the corresponding user, and device identification characteristics of the target device;

[0037] Generate first character string information according to user login information of the target device;

[0038] In one or more embodiments, before generating the first string information according to the user login information of the target device, the method further includes:

[0039] It is determined that the first signature is successfully verified by the first public key of the client; the first signature is generated by the first private key of the client and the user login information of the second user for the target device.

[0040] In one or more embodiments, after determining that the first signature is successfully verified by the first public key of the client, before generating the first string information according to the user login information of the target device, the method further includes:

[0041] When the account characteristics of the second user in the identity authentication service are consistent with the account characteristics in the user login information, the first signature is verified based on the first public key to verify the security of the process in which the client transmits the user login information of the second user for the target device to the verification end.

[0042] In one or more embodiments, the method further comprises:

[0043] In response to the unbinding request sent by the client, obtaining the account characteristics and the first character string information in the identity authentication service corresponding to the unbinding operation;

[0044] Based on the user login information corresponding to the first character string information, verify whether the user login information contains an account feature in the identity authentication service;

[0045] If the account feature in the identity authentication service exists, the user login information corresponding to the first string information and the first string information are deleted, and unbinding feedback information is returned.

[0046] In one or more embodiments, the user login information further includes a current timestamp; and generating the first string information according to the user login information of the target device includes:

[0047] Performing a second encryption on the user login information and the current timestamp to generate a third character string information carrying a validity period;

[0048] The third string information is subjected to third encryption by the first public key of the client to obtain the first string information, and the first public key is obtained by performing fourth encryption by the second public key of the verification end.

[0049] In one or more embodiments, the first string information is obtained by subjecting the third string information to third encryption by the first public key of the client, and the first public key is obtained by performing fourth encryption by the second public key of the verification end; the third string information is generated by the second user based on the user login information of the target device.

[0050] In one or more embodiments, the target device is a vehicle, and the biometric information includes: a feature type and a biometric feature;

[0051] The account feature includes: the account identifier of the corresponding user;

[0052] The device identifier feature includes at least one of: the vehicle identification number of the vehicle, the client type of the client, and the vehicle identifier.

[0053] Fourthly, an embodiment of the present application provides a biometric login device, which is applied to a client communicating with a target device. The device includes:

[0054] An acquisition module, configured to acquire the user login information of the login operation of the target device as the to-be-verified login information, and acquire the first string information corresponding to the target device; wherein, the login operation is triggered by a first user, and the first string information is generated by a second user based on the user login information of the target device, and the second user is a user with the login permission of the target device; the user login information at least includes: the biometric information of the corresponding user, the account feature of the corresponding user, and the device identifier feature of the target device;

[0055] A processing module, configured to determine device login verification information based on the first string information and the to-be-verified login information;

[0056] A sending module, configured to send the device login verification information to a verification end, so that the verification end determines a login feedback message of the login operation through the device login verification information.

[0057] In one or more embodiments, the device login verification information includes: a first ciphertext;

[0058] The processing module is specifically configured to:

[0059] Perform first decryption on the first string information to obtain second string information;

[0060] The second encryption is performed on the to-be-verified login information through the second string information to obtain the first ciphertext.

[0061] In one or more embodiments, before the user login information of the login operation of the target device is obtained as the to-be-verified login information, the processing module is further configured to:

[0062] Verify the first biometric feature of the first user who triggers the login operation;

[0063] Determine that the verification of the first biometric feature is successful.

[0064] In a fifth aspect, an embodiment of the present application provides a biometric login device applied to a verification end. The device includes:

[0065] An acquisition module, configured to receive device login verification information sent by a client communicating with a target device. The device login verification information is determined based on a first string information and to-be-verified login information. The to-be-verified login information is the user login information of the login operation of the target device, and the login operation is triggered by a first user. The first string information is generated by a second user for the user login information of the target device, and the second user is a user with the login permission of the target device. The user login information at least includes: biometric information of the corresponding user, account features of the corresponding user, and device identification features of the target device;

[0066] A processing module, configured to determine a login feedback message of the login operation through the device login verification information.

[0067] In one or more embodiments, the device login verification information includes a first ciphertext and a first string information. The first ciphertext is obtained by performing a first encryption on the to-be-verified login information through the first string information;

[0068] The processing module is specifically configured to:

[0069] Determine a third string information corresponding to the first string information. The third string information is obtained by performing a second encryption on the user login information of the target device by the second user;

[0070] Perform a third encryption on the user login information of the target device by the second user based on the third string information to generate a second ciphertext;

[0071] Generate a login feedback message of the login operation according to the first ciphertext and the second ciphertext.

[0072] In one or more embodiments, the device login verification information further includes: a first public key and a second signature of the client, where the second signature is generated based on the first ciphertext and a first private key of the client;

[0073] Before generating the login feedback message for the login operation according to the first ciphertext and the second ciphertext, the processing module is configured to:

[0074] Determine that the verification of the second signature by the first public key of the client is successful, indicating that the process of the client transmitting the device login verification information to the verification end is in a secure state.

[0075] In one or more embodiments, the processing module generates the login feedback message for the login operation according to the first ciphertext and the second ciphertext, and specifically is configured to:

[0076] In response to the first ciphertext and the second ciphertext being consistent, generate a first feedback message as the login feedback message, where the first feedback message is used to indicate that the login operation is successful for logging in to the target device;

[0077] In response to the first ciphertext and the second ciphertext being inconsistent, generate a second feedback message as the login feedback message, where the second feedback message is used to indicate that the login operation fails for logging in to the target device.

[0078] In one or more embodiments, the third string information is string information carrying an expiration date;

[0079] The processing module generates the login feedback message for the login operation according to the first ciphertext and the second ciphertext, and specifically is configured to:

[0080] In response to the first ciphertext and the second ciphertext being consistent and the current timestamp being within the expiration date, generate a third feedback message as the login feedback message; the third feedback message is used to indicate that the login operation is successful for logging in to the target device;

[0081] In response to the first ciphertext and the second ciphertext being inconsistent, or the current timestamp not being within the expiration date, generate a fourth feedback message as the login feedback message, where the fourth feedback message is used to indicate that the login operation fails for logging in to the target device.

[0082] In a sixth aspect, an embodiment of the present application provides a biometric registration device applied to a verification end, and the device includes:

[0083] an acquisition module, configured to acquire user login information of a second user for the target device in response to a registration request sent by a client communicating with the target device, wherein the user login information includes at least: biometric information of the corresponding user, account characteristics of the corresponding user, and device identification characteristics of the target device;

[0084] A processing module, configured to generate first character string information according to user login information of the target device;

[0085] In one or more embodiments, before generating the first string information according to the user login information of the target device, the processing module is further used to:

[0086] It is determined that the first signature is successfully verified by the first public key of the client; the first signature is generated by the first private key of the client and the user login information of the second user for the target device.

[0087] In one or more embodiments, after determining that the first signature is successfully verified by the first public key of the client, before generating the first string information according to the user login information of the target device, the processing module is further used to:

[0088] When the account characteristics of the second user in the identity authentication service are consistent with the account characteristics in the user login information, the first signature is verified based on the first public key to verify the security of the process in which the client transmits the user login information of the second user for the target device to the verification end.

[0089] In one or more embodiments, the processing module is further configured to:

[0090] In response to the unbinding request sent by the client, obtaining the account characteristics and the first character string information in the identity authentication service corresponding to the unbinding operation;

[0091] Based on the user login information corresponding to the first character string information, verify whether the user login information contains an account feature in the identity authentication service;

[0092] If the account feature in the identity authentication service exists, the user login information corresponding to the first string information and the first string information are deleted, and unbinding feedback information is returned.

[0093] In one or more embodiments, the user login information further includes a current timestamp; the processing module generates the first string information according to the user login information of the target device, specifically for:

[0094] Perform a second encryption using the user login information and the current timestamp to generate a third string information carrying an expiration date;

[0095] Perform a third encryption on the third string information using the first public key of the client to obtain the first string information, where the first public key is obtained by performing a fourth encryption using the second public key of the verification end.

[0096] In one or more embodiments, the first string information is obtained by performing a third encryption on the third string information using the first public key of the client, where the first public key is obtained by performing a fourth encryption using the second public key of the verification end; the third string information is generated by the second user based on the user login information for the target device.

[0097] In one or more embodiments, the target device is a vehicle, and the biometric information includes: a feature type and a biometric;

[0098] The account feature includes: the account identifier of the corresponding user;

[0099] The device identifier feature includes at least one of: the vehicle identification number of the vehicle, the client type of the client, and the vehicle identifier.

[0100] In a seventh aspect, an embodiment of the present application provides an electronic device, including: a processor, and a memory communicatively connected to the processor;

[0101] The memory stores computer-executable instructions;

[0102] The processor executes the computer-executable instructions stored in the memory to implement the method as described in the first, second, and third aspects or any one of the ways above.

[0103] In an eighth aspect, an embodiment of the present application provides a computer-readable storage medium, where computer-executable instructions are stored in the computer-readable storage medium, and when the computer-executable instructions are executed by a processor, they are used to implement the method as described in the first, second, and third aspects or any one of the ways above

[0104] In a ninth aspect, an embodiment of the present application provides a computer program, the computer program product includes a computer program, the computer program is stored in a computer-readable storage medium, and at least one processor can read the computer program from the computer-readable storage medium, and when the at least one processor executes the computer program, it can implement the method as described in the first, second, and third aspects or any one of the ways above.

[0105] The biometric login method, registration method, and device provided by the embodiments of the present application. In the biometric login method, on the one hand, the biometric information of the corresponding user for logging in to the target device, the account characteristics of the corresponding user, and the device identification characteristics of the target device are used as the user login information of the target device. That is, by combining the user's biometric characteristics, the user's account characteristics, and the identification characteristics of the target device as the verification information for the login permission of the user to log in to the target device, the richness of the verification information for user login is improved. Compared with the technology that only verifies permissions based on account characteristics, the security of permission verification is significantly improved. On the other hand, after the first user triggers the login operation of the target device through the client, the client takes the user login information of the first user as the login information to be verified. Then, it obtains the first string information generated based on the user login information of the second user who has the login permission for the target device as the auxiliary information for verifying the login permission of the login information to be verified. Thus, the client generates the device login verification information based on the matching situation between the first string information and the login information to be verified and sends it to the verification end, so that the verification end determines the login feedback message of the login operation through the device login verification information. That is, the verification end judges whether the first user is the second user who has the login permission for the target device (i.e., verifies whether the first user has the login permission for the target device) based on the login verification information and generates the login feedback message. In this technical solution, the first string information is generated based on the user login information of the second user who has the login permission for the target device. Using the first string information as the auxiliary information for verifying the login information to be verified provides an additional security layer for login verification, ensuring that only users with the login permission for the target device can generate valid device login verification information. In addition, when the verification end determines the login feedback message of the login operation through the device login verification information, it can provide the login feedback to the user in a timely and fast manner. BRIEF DESCRIPTION OF THE DRAWINGS

[0106] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present application and used together with the specification to explain the principles of the present application.

[0107] Figure 1 Schematic flowchart of the biometric registration method provided by the embodiments of the present application Figure 1 ;

[0108] Figure 2 Schematic flowchart of the biometric registration method provided by the embodiments of the present application Figure 2 ;

[0109] Figure 3 Schematic flowchart of the biometric registration method provided by the embodiments of the present application Figure 3 ;

[0110] Figure 4 Flow schematic of the biometric registration method provided by an embodiment of the present application Figure 4 ;

[0111] Figure 5 Flow schematic of the biometric login method provided by an embodiment of the present application Figure 1 ;

[0112] Figure 6 Flow schematic of the biometric login method provided by an embodiment of the present application Figure 2 ;

[0113] Figure 7 Flow schematic of the biometric login method provided by an embodiment of the present application Figure 3 ;

[0114] Figure 8 Structural schematic of the biometric login device provided by an embodiment of the present application Figure 1 ;

[0115] Figure 9 Structural schematic of the biometric login device provided by an embodiment of the present application Figure 2 ;

[0116] Figure 10 Structural schematic diagram of the biometric registration device provided by an embodiment of the present application;

[0117] Figure 11 Structural schematic diagram of the electronic device provided by an embodiment of the present application.

[0118] Through the above-mentioned drawings, specific embodiments of the present application have been shown, and there will be more detailed descriptions hereinafter. These drawings and textual descriptions are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. Detailed implementation manners

[0119] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all the implementation manners consistent with the present application. On the contrary, they are merely examples of the devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0120] Before introducing the embodiments of the present application, first, the application background of the embodiments of the present application will be explained:

[0121] In the field of vehicle technology, as the requirements for vehicle use safety continue to increase, it is often necessary for users to perform a login operation on the corresponding client of the vehicle. After successful login, the user can obtain the vehicle use permission.

[0122] In the prior art, login is generally performed by entering a username, user password, etc. However, in this login method, there are situations such as leakage and forgetting of the username and password, resulting in inconvenience and insecurity for users to log in.

[0123] In the existing related implementations, the biometric identification method has gradually replaced the user password login method. However, although the biometric identification method does not require complicated password verification, it poses higher requirements for the security of the login process. Therefore, how to safely implement convenient and secure biometric registration and login has become a technical problem to be solved urgently.

[0124] In view of the technical problems existing in the prior art, the inventor of this application has the following idea. In the biometric registration stage, based on the user login information of the registered user of the target device, a first string information that can be used for subsequent verification can be generated at the verification end, stored in the verification end, and sent to the client when a user requests to log in to the target device through the client, so that the client can verify the login permission of the user requesting to log in through the first string information; thus, in the biometric login stage, the client can obtain the user login information of the user requesting to log in to the target device. If the user login information of the login operation passes the preliminary verification on the client, the device login verification information is determined based on the first string information and the user login information of the login operation, and then the login verification information is sent to the verification end, so that the verification end can determine whether to allow the target device to be logged in and / or accessed through this login operation according to the device login verification information, thereby solving problems such as data leakage and low convenience in the login method of accounts. By using the user's biometric characteristics, account characteristics, and device characteristics of the target device as user login information, and combining the user login information of the registered user of the target device, cross-verification operations between the client and the verification end, etc., to verify the permission of the login operation of the target device, it avoids the security risks brought by data leakage or account password theft during the login process, and significantly improves the login security of the target device.

[0125] It should be understood that in the embodiments of the present application, the target device in the embodiments of the present application can be any terminal device or service device with communication capabilities. For example, the target device can include, but is not limited to, smart home appliances (such as, but not limited to, audio, TV, washing machine, or kitchen utensils, etc.), transportation means (such as, but not limited to, airplanes, high-speed rails, trains, ships, vehicles, buses, trucks, motorcycles, bicycles, or drones, etc.), and other devices (such as, but not limited to, robots, cups, or smart stationery); for the verification end, it can be any one or a combination of multiple devices such as an independent physical server, a server cluster, the cloud, a blockchain, an Internet of Things platform, a vehicle networking platform, a terminal device with the capabilities related to the verification end in the embodiments of the present application, etc.; for the client, it can be a device that communicates with the target device, not limited to the control device of the target device. For example, the target device can be, but is not limited to, any device such as a bracelet, a mobile phone, a vehicle head unit system, a computer, or a tablet, etc. Specifically, the client can also be an application program deployed on the target device or communicating with the target device on a related device. For example, the client can be, but is not limited to, an application software (Application, APP), a small program embedded in other clients, or HyperText Markup Language 5th generation (HTML5, H5), etc.

[0126] As an embodiment, when the target device is a vehicle, the client can be any end such as a vehicle head unit system, in-vehicle software, or an APP deployed on other terminals that can communicate with the vehicle (such as a vehicle control APP deployed on a mobile phone or a Bluetooth key that communicates with the vehicle); the verification end can be an independent server that communicates with the client, a server cluster (such as any of the cloud, blockchain end, service end of the vehicle head unit system, distributed system, Internet of Things device, or vehicle networking device, etc.); for ease of understanding, the following content will be described by taking the target device as a vehicle, the client as the vehicle control APP on a mobile phone, and the verification end as the cloud that communicates with the vehicle control APP as an example.

[0127] Next, the technical solutions of the present application will be described in detail through specific embodiments. It should be noted that the following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.

[0128] Specifically, embodiments in aspects such as biometric registration and biometric login will be described:

[0129] 1. Embodiment of the biometric registration method:

[0130] Figure 1 Flow diagram of the biometric registration method provided in the embodiments of the present application Figure 1 As shown in Figure 1 the figure, this method is applied to the verification end and can include the following steps:

[0131] Step 11: In response to a registration request sent by a client communicating with a target device, obtain the user login information of a second user for the target device.

[0132] It should be noted that the user login information in the embodiments of the present application refers to relevant information used to verify whether a user has the login permission and / or access permission for the target device.

[0133] In this step, when biometric registration of the target device is required, the client can send a registration request of the second user to the verification end, and the request carries the user login information of the second user for the target device; wherein, the second user can be the registration user for biometric identification; the first user in the following embodiments is the verification user for biometric identification.

[0134] In the embodiments of the present application, the representation method of the user login information is not limited, and those skilled in the art can set it based on actual needs; for example, in a possible implementation, the user login information can be represented in the form of a string, such as a json string, and the json string can be a string encrypted by base64 on the client side.

[0135] As an embodiment, the user login information in the embodiments of the present application at least includes: any one or any combination of feature items such as the biometric information of the corresponding user, the account characteristics of the corresponding user, and the device identification characteristics of the target device; in the embodiments of the present application, the feature items included in the foregoing user login information can be set based on the device type of the target device, and the specific content of each feature item can also be set based on the device type of the target device.

[0136] As an embodiment, the biometric information can be information related to the user's biometric signs or physiological characteristics; the biometric information can include, but is not limited to, one or more information items. For example, the biometric information can include two information items: the biometric type (also known as the "authentication type") and the user's biometric information; the biometric type in the biometric information can include, but is not limited to, any one or combination of fingerprint, voice / voiceprint, face recognition / face verification, gesture, palm vein, etc., and the user's biometric information in the biometric information can include, but is not limited to, any one or any combination of biometric information such as fingerprint, voice, face, gesture, palm vein, etc. collected for the user.

[0137] As an embodiment, the account characteristics can be the characteristic information used to identify the user's account. For example, the account characteristics can include, but are not limited to, any one or any combination of account name, account ID, account nickname, account description information, etc.

[0138] As an example, the device identification feature may be relevant information used to identify the target device and / or the client communicating with the target device. For example, the device identification feature may, but is not limited to, be device identification information used to identify the target device, or it may also be client identification information used to identify the client communicating with the target device. The device identification feature may also be a combined information of the aforementioned device identification information and client identification information. The aforementioned device identification information may, but is not limited to, include the unique device identification information of the target device (such as, but not limited to, a device ID that can uniquely identify the target device, a string and / or random number that can uniquely identify the target device; when the target device is a vehicle, the unique device identification may, but is not limited to, include any one or any combination of the vehicle license plate, vehicle identification number, engine number, electronic representation, etc.), the device type of the target device, the device name of the target device, etc. The client identification information may, but is not limited to, include any one or any combination of the client type (i.e., the type of the client), the client name (i.e., the name of the client), the client ID, etc.

[0139] In a possible implementation, when the device type of the target device is a mobile phone, the user login information may be set to include the biometric information of the corresponding user, the account characteristics of the corresponding user, and the device identification feature of the target device. Set the biometric information to be a face, set the account characteristic to be the user's mobile phone number, and set the device identification feature to be the device ID set for the mobile phone, etc.

[0140] For ease of understanding, the following uses a vehicle as a specific example of the target device to illustrate each feature item of the aforementioned user login information:

[0141] In this example, the target device is a vehicle, and the user login information may be set to include the biometric information of the corresponding user, the account characteristics of the corresponding user, and the device identification feature of the target device.

[0142] Furthermore, the biometric information may be set to include two information items: the biometric type and the user's biometric information. Then, the biometric information may be set to any one or any combination of "facial recognition (biometric type) + the face collected for the user (user's biometric information)", "fingerprint (biometric type) + the fingerprint collected for the user (user's biometric information)", or "voiceprint (biometric type) + the voice collected for the user (user's biometric information)" as the biometric information of the user in the user login information.

[0143] The account characteristic may be set to the user's account ID or account name.

[0144] The device identification features that can be set include the device identification information of the vehicle and the client identification information of the client communicating with the vehicle. Further, the vehicle ID and vehicle identification number of the vehicle are set as the device identification information of the vehicle, and the client type of the client is set as the aforementioned client identification. The client type can include, but is not limited to, any one or more of the in-vehicle head unit (IHU), smartphone (mobile), smartwatch / bracelet (watch), etc.

[0145] It should be noted that in the embodiments of the present application, the specific expression forms and data processing methods of the user login information, each feature item included in the user login information, and each information item included in each feature item are not overly limited, and those skilled in the art can set them according to actual needs. For example, in the process of the client in the embodiments of the present application processing the user login information, each feature item in the user login information can be converted into digital information, and the corresponding digital information can be assembled into a specific format string according to a preset data structure to express the user login information. For the convenience of understanding, several expression forms of the user login information are given here:

[0146] As an embodiment, the client can express the user login information with the string "biometric information_account feature_device identification feature" obtained by splicing the biometric information, account feature, and device identification feature. For example, when the target device is a vehicle, the biometric information is the biometric type and user biometric information, the account feature is the user's account ID, the device identification feature is the device identification information of the vehicle and the client identification information, the device identification information of the vehicle is the vehicle ID and vehicle identification number of the vehicle, and the client identification information is the client type, the user login information can be expressed as, but is not limited to, "biometric type ++ user biometric information_account ID_vehicle ID + vehicle identification number + client type".

[0147] As an embodiment, when the client converts each feature item included in the user login information into a json string in the FDI form through digital information technology and uses this json string to express the user login information. Specifically, when the target device is a vehicle, the biometric information is the biometric type and user biometric information, the account feature is the user's account ID, the device identification feature is the device identification information of the vehicle and the client identification information, the device identification information of the vehicle is the vehicle ID and vehicle identification number of the vehicle, and the client identification information is the client type, the json string can be, but is not limited to, in the following form:

[0148] {

[0149] "certificationType":"biometric type";

[0150] "certificationId": "User biological information";

[0151] "deviceType": "Client type";

[0152] "uid": "Account ID";

[0153] "deviceId": "Vehicle ID";

[0154] "vin": "Vehicle identification number";

[0155] }

[0156] Step 12: Generate the first string information based on the user login information of the target device.

[0157] In this step, the first string information is an encrypted value generated by the verification end based on the user login information of the target device, such as the K value.

[0158] Further, send the first string to the client and store it.

[0159] Optionally, before this step 12, it can also be executed: Determine that the verification of the first signature by the first public key of the client is successful; The first signature is generated by the first private key of the client and the second user for the user login information of the target device.

[0160] In this implementation, the client can generate RSA public and private keys, denoted as the first public key and the first private key. Sign the user login information of the target device with the first private key to generate the first signature. When transmitting the user login information of the target device to the verification end, also transmit the first signature to the verification end, so as to verify the first signature at the verification end. After successful verification, execute step 12.

[0161] In a possible implementation, sign md5(FDI) with the first private key to generate the first signature.

[0162] Optionally, before determining that the verification of the first signature by the first public key of the client is successful, it can also be executed: When the account characteristics of the second user in the identity verification service are consistent with the account characteristics in the user login information, verify the first signature based on the first public key to check the security of the process of the client transmitting the user login information of the second user to the verification end.

[0163] In this implementation, when the verification end receives the user login information of the target device and information such as the first signature, in order to enhance the security of data transmission, the account feature (e.g., the first user identifier) can be extracted from the authentication service (English: token), and the account feature (e.g., the second user identifier) can also be extracted from the user login information; and when the first user identifier and the second user identifier are consistent, the operation of verifying the first signature is performed.

[0164] When performing signature verification, the first signature can be verified based on the first public key.

[0165] Optionally, a possible implementation of step 12 is as follows:

[0166] Step 1: Perform second encryption on the user login information and the current timestamp to generate a third string information carrying an expiration date;

[0167] In this implementation, the current timestamp can be the time when the client performs biometric registration operations, or the time when the verification end performs the second encryption operation;

[0168] Furthermore, based on the current timestamp and the preset effective duration, the expiration date of this biometric registration is determined. For example, if the current timestamp is 01-11 and the effective duration is 30 days, the expiration date is until 02-10; then, the user login information is subjected to second encryption, and this second encryption can be a symmetric encryption algorithm to obtain a symmetric encryption key M value with an expiration date, that is, the third string information.

[0169] For example, M = (FDI + random number).

[0170] Step 2: Perform third encryption on the third string information through the first public key of the client to obtain the first string information;

[0171] Among them, the first public key is obtained by performing fourth encryption on the second public key of the verification end.

[0172] In this implementation, in order to ensure the security of the first public key of the client during transmission to the verification end, the first public key can be pre-encrypted in the client using the public key of the verification end (i.e., the second public key), and at the verification end, the first public key can be retrieved based on the private key of the verification end (i.e., the second private key), so as to perform third encryption on the third string information using the first public key to generate the K value, that is, the first string information.

[0173] For example, K = first public key (M).

[0174] Among them, both the fourth encryption and the third encryption can be implemented based on any encryption algorithm.

[0175] That is, the first string information in the embodiment of the present application is obtained by performing the third encryption on the third string information through the first public key of the client; the first public key is obtained by performing the fourth encryption on the second public key of the verification end; and the third string information is generated by the user login information of the second user for the target device.

[0176] Furthermore, the first character string information, the third character string information, and user login information of the target device are stored.

[0177] The biometric registration method provided in the embodiment of the present application is applied to the verification end, and obtains the user login information of the second user for the target device by responding to the registration request sent by the client communicating with the target device, and the user login information at least includes: the biometric information of the corresponding user, the account characteristics of the corresponding user, and the device identification characteristics of the target device; and generates the first string information according to the user login information of the target device. In this technical solution, the user identity is verified by using information such as biometric information, account characteristics, and device identification characteristics, which improves the richness of the user login verification information to increase the security of the login process, and generates the first string information based on the registered user, which provides further security guarantees for subsequent client verification, so as to realize the secure registration of biometrics.

[0178] Based on the above embodiments, Figure 2 Schematic diagram of the biometric registration method provided in the embodiment of the present application Figure 2 ,like Figure 2 As shown, the method is applied to the verification end and may also include the following steps:

[0179] Step 21: In response to the unbinding request sent by the client, obtain the account characteristics and first character string information in the identity authentication service corresponding to the unbinding operation;

[0180] In this step, when the user no longer needs biometric identification, an unbinding operation can be performed on the client, and an unbinding request can be generated, which carries the account characteristics and the first string information in the identity authentication service, and the unbinding request is sent to the verification end.

[0181] In a possible implementation, the vehicle computer carries the token and the K value to access the release interface reserved by the verification end.

[0182] Step 22: based on the user login information corresponding to the first character string information, verify whether the user login information contains an account feature in the identity authentication service;

[0183] In this step, the corresponding user login information can be obtained on the verification end based on the first character string information. When obtained, it is determined from the user login information whether there is an account feature that is consistent with the account feature in the identity authentication service.

[0184] In a possible implementation, check whether there is a second user identifier in the user login information that is consistent with the account characteristics (the above-mentioned first user identifier) in the identity authentication service. If they are consistent, it indicates its existence; if not, it indicates its non-existence.

[0185] Step 23: If there are account characteristics in the identity authentication service, delete the user login information corresponding to the first string information and the first string information, and return an unbinding feedback message.

[0186] In this step, if there are the account characteristics in the identity authentication service in the above-mentioned user login information, delete the first string information corresponding to the reserved user login information and the user login information, and return an unbinding feedback message to inform the client that the unbinding is completed.

[0187] In addition, if there are no such account characteristics in the above-mentioned user login information, an error will be reported to the client.

[0188] The biometric registration method provided by the embodiments of the present application is applied to the verification end. By responding to the unbinding request sent by the client, obtain the account characteristics and the first string information in the identity authentication service corresponding to the unbinding operation; based on the user login information corresponding to the first string information, verify whether there are account characteristics in the identity authentication service in the user login information; if there are account characteristics in the identity authentication service, delete the user login information corresponding to the first string information and the first string information, and return an unbinding feedback message. In this technical solution, the verification end obtains the account characteristics sent by the client and the first string information generated during registration, determines the corresponding user login information during registration from the verification end, and deletes them accordingly to achieve fast biometric unbinding.

[0189] Figure 3 It is a flowchart of the biometric registration method provided by the embodiments of the present application Figure 3 , as Figure 3 shown, the method may include the following steps, taking the above embodiments as examples:

[0190] Client:

[0191] Step 1: Generate a biometric code (FDI, that is, the user login information of the second user for the target device);

[0192] Among them, the biometric code of the second user includes: biometric information (authentication type, such as fingerprint type / voiceprint type / face type; and authentication identifier, such as fingerprint / voiceprint / face serial number), account characteristics (device type, such as car machine / mobile phone / watch; and user account and other identifiers), and device identification characteristics of the target device (such as vehicle identification number);

[0193] Step 2: Generate RSA public key and private key (i.e., first public key and first private key);

[0194] Step 3: Use the first private key to sign md5 (i.e., FDI + current timestamp) to generate sign (i.e., the first signature);

[0195] Step 4: Report the first signature, biometric identification code, and first public key (the public key of the vehicle computer encrypted by the second public key of the verification end);

[0196] Verification end (Authentication Center):

[0197] Step 5: parse the account ID from the token (i.e., the identity verification service) and compare it with the account ID in the biometric code. If the comparison is inconsistent, execute step 6; if the comparison is inconsistent, report an error to the client;

[0198] Step 6: Use the second private key in the cloud to wash out the first public key;

[0199] Step 7: Use the first public key to verify the first signature. If the verification is successful, execute step 8. If the verification is successful, report an error to the client.

[0200] Step 8: Generate a symmetric encryption key M value with a validity period (i.e., the third string information), M = (FDI + random number);

[0201] Step 9: Use the first public key to encrypt the secret key M value to generate a K value (i.e., the first string information), where K = public key (M);

[0202] Step 10: Store relevant information and return the validity period and K value to the client.

[0203] Figure 4 Schematic diagram of the biometric registration method provided in the embodiment of the present application Figure 4 ,like Figure 4 As shown, the method may include the following steps, which are examples of the above embodiment:

[0204] Client:

[0205] Step 1: Access the release interface with token and K value (i.e. the third string information);

[0206] Verification end (Authentication Center):

[0207] Step 2: Determine the user information based on the K value and verify whether the user information is consistent; if it is inconsistent, an error will be reported;

[0208] Step 3: After verification, release the authentication and return the release result to the client.

[0209] The registration methods of biometric identification provided in the above-mentioned Embodiment 3 and Embodiment 4 have the same implementation principles and technical effects as those in the above-mentioned embodiments, and will not be elaborated here.

[0210] II. Embodiments of the login method of biometric identification (the following parts are similar to those in the above registration method and will not be elaborated):

[0211] Based on the above embodiments, Figure 5 is a schematic flowchart of the login method of biometric identification provided in the embodiments of the present application Figure 1 as Figure 5 shown. This method is described by an interactive illustration and may include the following steps:

[0212] Step 51, the client obtains the user login information of the login operation of the target device as the login information to be verified, and obtains the first string information corresponding to the target device;

[0213] Among them, the login operation is triggered by a first user, and the first string information is generated by a second user based on the user login information of the target device. The second user is a user with the login permission for the target device; the user login information at least includes: the biometric information of the corresponding user, the account characteristics of the corresponding user, and the device identification characteristics of the target device.

[0214] In this step, when the first user needs to use the target device, the client obtains the user login information of the login operation of the target device and uses the user login information of this login operation as the login information to be verified.

[0215] In a possible implementation, when the first user logs in, the client obtains the biometric information of the first user, the account characteristics of the first user, and the device identification characteristics of the target device, generates the user login information of the login operation, and records it as the login information to be verified, that is, FDI1.

[0216] Furthermore, the first string information corresponding to the target device reserved in the client can be determined.

[0217] It should be understood that in the client, at least one second user can be registered, that is, there is first string information corresponding to different second users. At this time, based on the user login information of the login operation, the second user consistent with the first user can be determined, and the first string information corresponding to the second user is used as the first string information corresponding to the target device.

[0218] Optionally, before executing step 51, it is also possible to execute: verifying the first biometric feature of the first user who triggers the login operation; determining that the first biometric feature verification is successful.

[0219] In this implementation, during the login operation of the client, to improve the security and efficiency of verification, the first biometric feature of the first user triggering the login operation can be verified first. For example, if the biometric feature of the second user (parsed from the user login information of the second user) is saved during registration, it can be determined whether the biometric feature of the second user is consistent with the first biometric feature of the first user. When they are consistent, it is determined that the first biometric feature verification is successful, and the client reminds the user that the preliminary verification has passed in the form of an image or audio.

[0220] Correspondingly, when there is no consistency between the biometric feature of the second user and the first biometric feature of the first user, it is determined that the first biometric feature verification fails, and an error is reported, and the client reminds the user that the verification fails in the form of an image or audio.

[0221] Step 52: The client determines the device login verification information based on the first string information and the login information to be verified;

[0222] In this step, after obtaining the first string information, the client uses the first string information to encrypt the login information to be verified to determine the device login verification information.

[0223] Among them, the device login verification information is the verification information received by the verification end for verifying whether the biometric recognition is legal.

[0224] Optionally, the device login verification information includes: the first ciphertext; then a possible implementation of step 52 can be:

[0225] Step 1: Perform the first decryption on the first string information to obtain the second string information;

[0226] In this implementation, after obtaining the first string information, the client uses the first private key of the client to parse the string information from the first string information (such as the K value), denoted as the second string information, that is, the M1 value.

[0227] For example, M1 = the first private key (K).

[0228] Step 2: Perform the second encryption on the login information to be verified through the second string information to obtain the first ciphertext.

[0229] In this implementation, based on the second string information, the login information to be verified is encrypted for the second time to generate the first ciphertext, that is, F, to ensure that the data is not tampered with during the transmission process.

[0230] Among them, the second encryption can be implemented based on any encryption algorithm.

[0231] Step 53: The client sends the device login verification information to the verification end;

[0232] Step 54: The verification end determines the login feedback message for the login operation based on the device login verification information.

[0233] In this step, after receiving the device login verification information, the verification end performs biometric verification based on the device login verification information to obtain the login feedback message.

[0234] Furthermore, the login feedback message is returned to the client.

[0235] In a possible implementation, the login feedback message is the login result for the login operation of the target device, which may include indicating that the login operation for the target device is successful or failed; when successful, the login token of the target device is synchronously sent to the client.

[0236] The biometric login method provided by the embodiment of the present application is applied to a client and a verification end that communicate with a target device, and includes: the client obtains the user login information of the login operation of the target device as the login information to be verified, and obtains the first string information corresponding to the target device; wherein, the login operation is triggered by a first user, and the first string information is generated by a second user according to the user login information of the target device, and the second user is a user with the login permission of the target device; the user login information at least includes: the biometric information of the corresponding user, the account characteristics of the corresponding user, and the device identification characteristics of the target device; based on the first string information and the login information to be verified, the device login verification information is determined; the device login verification information is sent to the verification end, so that the verification end determines the login feedback message of the login operation through the device login verification information. In this method, on the one hand, the biometric information, account characteristics, device identification characteristics and other information are used to verify the user identity, which improves the richness of the verification information for user login. Compared with the technology that only verifies the permissions based on the account characteristics, the security of the permission verification is significantly improved; on the other hand, after the first user triggers the login operation of the target device through the client, the client takes the user login information of the first user as the login information to be verified, and then obtains the first string information generated by the second user with the login permission of the target device according to the user login information of the target device as the auxiliary information for verifying the permissions of the login information to be verified. Therefore, the client generates the device login verification information based on the matching situation of the first string information and the login information to be verified and sends it to the verification end, so that the verification end determines the login feedback message of the login operation through the device login verification information, that is, the verification end determines whether the first user is the second user with the login permission of the target device (that is, verifies whether the first user has the login permission of the target device) through the login verification information and generates the login feedback message. In this technical solution, the first string information is generated based on the user login information of the second user with the login permission of the target device, and the first string information is used as the auxiliary information for verifying the login information to be verified, providing an additional security layer for the login verification to ensure that only users with the login permission of the target device can generate valid device login verification information; in addition, when the verification end determines the login feedback message of the login operation through the device login verification information, it can provide the login feedback to the user in a timely and fast manner.

[0237] On the basis of the above embodiment, Figure 6 is the flow schematic of the biometric login method provided by the embodiment of the present application Figure 2 As Figure 6 shown, this method is applied to the verification end, and the above step 54 may include the following steps:

[0238] Among them, the device login verification information includes: a first ciphertext and a first string of information, and the first ciphertext is obtained by performing a first encryption on the login information to be verified using the first string of information.

[0239] Step 61: Determine the third string of information corresponding to the first string of information;

[0240] Among them, the third string of information is obtained by performing a second encryption on the user login information of the second user for the target device;

[0241] In this step, during the registration stage of biometric identification, the first string of information, the third string of information corresponding to the first string of information, and the user login information for the target device are pre-stored; at this time, after obtaining the first string of information, the corresponding third string of information can be found.

[0242] In addition, if the corresponding third string of information cannot be found based on the first string of information, an error will be reported to the client.

[0243] Step 62: Perform a third encryption on the user login information of the second user for the target device based on the third string of information to generate a second ciphertext;

[0244] In this step, a third encryption is performed on the corresponding user login information of the second user for the target device based on the third string of information to generate a second ciphertext, that is, F1.

[0245] Step 63: Generate a login feedback message for the login operation according to the first ciphertext and the second ciphertext.

[0246] In this step, the first ciphertext transmitted by the client is compared with the second ciphertext generated by the verification end to determine whether the user login information in the device login verification information is consistent with the user login information of the second user for the target device, so as to generate a login feedback message for the login operation.

[0247] Optionally, the device login verification information further includes: the first public key of the client and the second signature, and the second signature is generated based on the first ciphertext and the first private key of the client; correspondingly, before step 63, it is also possible to execute: determine that the verification of the second signature by the first public key of the client is successful, to indicate that the process of the client transmitting the device login verification information to the verification end is in a secure state.

[0248] In this implementation, the second signature is the first private key (MD5(F + M)), and then the second signature is verified using the first public key of the client. After the verification is successful, step 63 is executed.

[0249] Optionally, step 63 can have the following possible implementations:

[0250] The first type: in response to the first ciphertext and the second ciphertext being consistent, generate a first feedback message as a login feedback message, and the first feedback message is used to indicate that the login operation has successfully logged in to the target device;

[0251] In this implementation, when it is determined that the first ciphertext and the second ciphertext are consistent, it is considered that the biometric verification has passed, and a first feedback message is generated as the login feedback message and returned to the client.

[0252] In a possible implementation, the first feedback message may carry a login token of the target device, and after the client receives the login token, the target device is allowed to be used.

[0253] The second type: in response to the first ciphertext and the second ciphertext being inconsistent, generate a second feedback message as a login feedback message, and the second feedback message is used to indicate that the login operation has failed to log in to the target device.

[0254] In this implementation, when it is determined that the first ciphertext and the second ciphertext are inconsistent, it is considered that the biometric verification has failed, and a second feedback message is generated as the login feedback message and returned to the client.

[0255] In a possible implementation, the second feedback message records information such as a login error, and the target device is not allowed to be used; and it may also record information such as the reason for the error.

[0256] Optionally, if the third string information is string information carrying an expiration date, step 63 may also have the following possible implementation:

[0257] The first type: in response to the first ciphertext and the second ciphertext being consistent and the current timestamp being within the expiration date, generate a third feedback message as a login feedback message; the third feedback message is used to indicate that the login operation has successfully logged in to the target device;

[0258] In this implementation, when the first ciphertext and the second ciphertext are consistent and the current timestamp is within the expiration date, it is considered that the biometric verification has passed, and a third feedback message is generated as the login feedback message and returned to the client.

[0259] In a possible implementation, the third feedback message may carry a login token of the target device, and after the client receives the login token, the target device is allowed to be used.

[0260] Wherein, the current timestamp in this embodiment may be the time when the client performs the biometric login operation, or the time when the verification end determines the first ciphertext and the second ciphertext.

[0261] The second type: in response to the first ciphertext and the second ciphertext being inconsistent, or the current timestamp not being within the valid period, generate a fourth feedback message as a login feedback message, where the fourth feedback message is used to indicate that the login operation fails for the target device.

[0262] In this implementation, when it is determined that the first ciphertext and the second ciphertext are inconsistent, or the current timestamp is not within the valid period, it is considered that the biometric verification fails, and a fourth feedback message is generated as a login feedback message and returned to the client.

[0263] In a possible implementation, the fourth feedback message records information such as a login error, and the target device is not allowed to be used; and it can also record information such as the error reason (if it is not within the valid period, the error reason is login expiration).

[0264] The biometric login method provided by the embodiments of the present application determines the third string information corresponding to the first string information; wherein, the third string information is obtained by the second user performing second encryption on the user login information for the target device; based on the third string information, perform third encryption on the user login information of the second user for the target device to generate a second ciphertext; generate a login feedback message for the login operation according to the first ciphertext and the second ciphertext. In this technical solution, the user login information of the second user for the target device is encrypted multiple times, significantly enhancing the data security. By generating a login feedback message according to the first ciphertext and the second ciphertext, the integrity and consistency of the data can be effectively verified, ensuring that the login information is not tampered with during transmission and processing, so as to generate a more accurate login feedback message to ensure the security of biometric login.

[0265] Figure 7 It is a flowchart of the biometric login method provided by the embodiments of the present application Figure 3 , such as Figure 7 shown, this method may include the following steps, which are examples of the above embodiments:

[0266] Client:

[0267] Step 1: Verify the biometric code FDI1 (i.e., the device login verification information) to obtain the corresponding first string information (such as K in at least one K);

[0268] Among them, the biometric code FDI1 of the first user includes: biometric information (authentication type, such as fingerprint type / voiceprint type / face type; and authentication identifier, such as fingerprint / voiceprint / face serial number), account characteristics (device type, such as car machine / mobile phone / watch; and user account and other identifiers), device identification characteristics of the target device (such as vehicle identification number);

[0269] Step 2: Use the first private key to decrypt the M1 value (the second string information) from K (the first string information), M1 = private key(K);

[0270] Step 3: Use the symmetric encryption of the M1 value to encrypt FDI1 to generate the ciphertext F (the first ciphertext);

[0271] Step 4: Use the first private key to sign F and M1 to generate the signature sign (the second signature), that is, MD5(F + M1));

[0272] Step 5: Report the second signature, K, and F to the verification end;

[0273] Verification end (certification center):

[0274] Step 6: Find the M value (the third string information) according to the K value, and determine whether it is legal (that is, whether M2 exists). If it is expired (determined based on the current timestamp and the validity period), directly report an error;

[0275] Step 7: Use the M value and FDI in the database to generate the ciphertext F1 (the second ciphertext);

[0276] Step 8: Use the first public key of the in-vehicle unit to verify the second signature, compare device information, etc. If they do not match, report an error;

[0277] Step 9: Return the login token to the client, and the in-vehicle unit logs in successfully.

[0278] The biometric login method provided in the embodiment of the present application has the same implementation principle and technical effect as the above embodiment, which will not be elaborated here.

[0279] The following is the device embodiment of the present application, which can be used to execute the method embodiment of the present application. For the details not disclosed in the device embodiment of the present application, please refer to the method embodiment of the present application.

[0280] Figure 8 The structural schematic diagram of the biometric login device provided in the embodiment of the present application Figure 1 As Figure 8 shown, the device is applied to a client that communicates with a target device, and includes:

[0281] An obtaining module 81, configured to obtain the user login information of the login operation of the target device as the to-be-verified login information, and obtain the first string information corresponding to the target device; wherein, the login operation is triggered by a first user, and the first string information is generated by a second user for the user login information of the target device, and the second user is a user with the login permission of the target device; the user login information at least includes: the biometric information of the corresponding user, the account characteristics of the corresponding user, and the device identification characteristics of the target device;

[0282] A processing module 82, configured to determine device login verification information based on the first string information and the login information to be verified.

[0283] A sending module 83, configured to send the device login verification information to the verification end, so that the verification end determines the login feedback message of the login operation through the device login verification information.

[0284] In one or more embodiments, the device login verification information includes: a first ciphertext;

[0285] The processing module 82 is specifically configured to:

[0286] Perform a first decryption on the first string information to obtain second string information;

[0287] Perform a second encryption on the login information to be verified through the second string information to obtain the first ciphertext.

[0288] In one or more embodiments, before obtaining the user login information of the login operation of the target device as the login information to be verified, the processing module 82 is further configured to:

[0289] Verify the first biometric feature of the first user who triggers the login operation;

[0290] Determine that the first biometric feature verification is successful.

[0291] The biometric login device provided by the embodiments of the present application can be used to execute the biometric login method in any of the above embodiments applied to the client communicating with the target device. The implementation principles and technical effects are similar and will not be elaborated here.

[0292] Figure 9 The structural schematic of the biometric login device provided by the embodiments of the present application Figure 2 . As Figure 9 shown, the device is applied to the verification end and includes:

[0293] An acquisition module 91, configured to receive the device login verification information sent by the client communicating with the target device. The device login verification information is determined based on the first string information and the login information to be verified. The login information to be verified is the user login information of the login operation of the target device, and the login operation is triggered by the first user. The first string information is generated by the second user for the user login information of the target device, and the second user is a user with the login permission of the target device. The user login information at least includes: the biometric feature information of the corresponding user, the account feature of the corresponding user, and the device identification feature of the target device;

[0294] A processing module 92, configured to determine the login feedback message of the login operation through the device login verification information.

[0295] In one or more embodiments, the device login verification information includes a first ciphertext and a first string information, and the first ciphertext is obtained by performing a first encryption on the to-be-verified login information using the first string information;

[0296] The processing module 92 is specifically configured to:

[0297] Determine a third string information corresponding to the first string information, where the third string information is obtained by performing a second encryption on the user login information of the second user for the target device;

[0298] Perform a third encryption on the user login information of the second user for the target device based on the third string information to generate a second ciphertext;

[0299] Generate a login feedback message for the login operation according to the first ciphertext and the second ciphertext.

[0300] In one or more embodiments, the device login verification information further includes: a first public key of the client and a second signature, and the second signature is generated based on the first ciphertext and the first private key of the client;

[0301] Before generating a login feedback message for the login operation according to the first ciphertext and the second ciphertext, the processing module 92 is configured to:

[0302] Determine that the verification of the second signature by the first public key of the client is successful, so as to indicate that the process of the client transmitting the device login verification information to the verification end is in a secure state.

[0303] In one or more embodiments, the processing module 92 generates a login feedback message for the login operation according to the first ciphertext and the second ciphertext, and is specifically configured to:

[0304] In response to the first ciphertext and the second ciphertext being consistent, generate a first feedback message as the login feedback message, and the first feedback message is used to indicate that the login operation is successful for logging in to the target device;

[0305] In response to the first ciphertext and the second ciphertext being inconsistent, generate a second feedback message as the login feedback message, and the second feedback message is used to indicate that the login operation fails for logging in to the target device.

[0306] In one or more embodiments, the third string information is a string information carrying an expiration date;

[0307] The processing module 92 generates a login feedback message for the login operation according to the first ciphertext and the second ciphertext, and is specifically configured to:

[0308] In response to the first ciphertext and the second ciphertext being consistent and the current timestamp being within the expiration date, generate a third feedback message as the login feedback message; the third feedback message is used to indicate that the login operation is successful for logging in to the target device;

[0309] In response to the first ciphertext and the second ciphertext being inconsistent, or the current timestamp being not within the validity period, a fourth feedback message is generated as a login feedback message, and the fourth feedback message is used to indicate that the login operation has failed for the target device.

[0310] The biometric login device provided in the embodiment of the present application can be used to execute the biometric login method in any of the above-mentioned embodiments applied to the client. Its implementation principle and technical effects are similar and will not be repeated here.

[0311] Figure 10 This is a schematic diagram of the structure of the biometric registration device provided in the embodiment of the present application. Figure 10 As shown, the device is applied to a verification end, and includes:

[0312] The acquisition module 101 is used to obtain user login information of the second user for the target device in response to a registration request sent by a client communicating with the target device, where the user login information at least includes: biometric information of the corresponding user, account characteristics of the corresponding user, and device identification characteristics of the target device;

[0313] The processing module 102 is used to generate first character string information according to the user login information of the target device;

[0314] In one or more embodiments, before generating the first string information according to the user login information of the target device, the processing module 102 is further configured to:

[0315] It is determined that the first signature is successfully verified by the first public key of the client; the first signature is generated by the first private key of the client and the user login information of the second user for the target device.

[0316] In one or more embodiments, after determining that the first signature is successfully verified by the first public key of the client, before generating the first string information according to the user login information of the target device, the processing module 102 is further used to:

[0317] When the account characteristics of the second user in the identity authentication service are consistent with the account characteristics in the user login information, the first signature is verified based on the first public key to verify the security of the process in which the client transmits the user login information of the second user for the target device to the verification end.

[0318] In one or more embodiments, the processing module 102 is further configured to:

[0319] In response to the unbinding request sent by the client, obtaining account characteristics and first character string information in the identity authentication service corresponding to the unbinding operation;

[0320] Based on the user login information corresponding to the first string information, verify whether there is an account feature in the identity verification service in the user login information;

[0321] If there is an account feature in the identity verification service, delete the user login information corresponding to the first string information and the first string information, and return an unbinding feedback message.

[0322] In one or more embodiments, the user login information further includes a current timestamp; the processing module 102 generates the first string information according to the user login information of the target device, specifically for:

[0323] Perform second encryption through the user login information and the current timestamp to generate a third string information carrying an expiration date;

[0324] Perform third encryption on the third string information through the first public key of the client to obtain the first string information, and the first public key is obtained by performing fourth encryption through the second public key of the verification end.

[0325] In addition, in one or more embodiments of any of the above devices, the first string information is obtained by performing third encryption on the third string information through the first public key of the client, and the first public key is obtained by performing fourth encryption through the second public key of the verification end; the third string information is generated by the second user for the user login information of the target device.

[0326] In one or more embodiments, the target device is a vehicle, and the biometric information includes: a feature type and a biometric;

[0327] The account feature includes: the account identifier of the corresponding user;

[0328] The device identifier feature includes at least one of the vehicle identification number of the vehicle, the client type of the client, and the vehicle identifier.

[0329] The biometric registration device provided by the embodiments of the present application can be used to execute the biometric registration method in any of the above embodiments applied to the verification end, and its implementation principle and technical effect are similar, and will not be elaborated here.

[0330] It should be noted that it should be understood that the division of each module of the above device is only a division of logical functions. In actual implementation, it can be fully or partially integrated into a physical entity, or physically separated. And these modules can all be implemented in the form of software called by a processing element; they can also all be implemented in the form of hardware; some modules can also be implemented in the form of software called by a processing element, and some modules can be implemented in the form of hardware. In addition, all or part of these modules can be integrated together or can be independently implemented. The processing element mentioned here can be an integrated circuit with signal processing capabilities. In the implementation process, each step of the above method or each of the above modules can be completed by the integrated logic circuit in the processor element or the instruction in the form of software.

[0331] Figure 11 FIG. is a schematic structural diagram of an electronic device provided by an embodiment of the present application. As Figure 11 shown, the electronic device can be the corresponding device of the verification end or the client described above.

[0332] It may include: a processor 111, a memory 112, and computer program instructions stored on the memory 112 and executable on the processor 111. When the processor 111 executes the computer program instructions, the method provided in any one of the foregoing embodiments is implemented.

[0333] Optionally, the above-mentioned various components of the electronic device can be connected through a system bus.

[0334] The memory 112 can be a separate storage unit or a storage unit integrated in the processor 111. The number of processors 111 is one or more.

[0335] It should be understood that the processor 111 can be a central processing unit (CPU), or can also be other general-purpose processors 111, digital signal processors 111 (DSPs), application specific integrated circuits (ASICs), etc. The general-purpose processor 111 can be a microprocessor 111 or the processor 111 can also be any conventional processor 111, etc. The steps of the method disclosed in combination with the present application can be directly embodied as being executed and completed by the hardware processor 111, or can be executed and completed by a combination of the hardware and software modules in the processor 111.

[0336] The system bus can be a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The system bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity in illustration, only a thick line is used in the figure to represent it, but it does not mean that there is only one bus or one type of bus. The memory 112 may include a Random Access Memory (RAM), and may also include a Non-Volatile Memory (NVM), such as at least one disk memory 112.

[0337] All or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The aforementioned program can be stored in a readable memory 112. When this program is executed, it performs the steps including the above method embodiments; and the aforementioned memory 112 (storage medium) includes: Read-Only Memory (ROM), RAM, flash memory 112, hard disk, solid-state drive, magnetic tape, floppy disk, optical disc, and any combination thereof.

[0338] The electronic device provided in the embodiments of the present application can be used to execute the method provided in any of the above method embodiments. The implementation principle and technical effects are similar and will not be elaborated here.

[0339] The embodiments of the present application provide a computer-readable storage medium. Computer instructions are stored in the computer-readable storage medium. When the computer instructions run on a computer, the computer is enabled to execute the above method.

[0340] For the above computer-readable storage medium, the above-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory, Electrically Erasable Programmable Read-Only Memory, Erasable Programmable Read-Only Memory, Programmable Read-Only Memory, Read-Only Memory, magnetic memory, flash memory, disk, or optical disc. The readable storage medium can be any available medium accessible by a general-purpose or special-purpose computer.

[0341] Optionally, a readable storage medium is coupled to the processor so that the processor can read information from and write information to the readable storage medium. Of course, the readable storage medium can also be an integral part of the processor. The processor and the readable storage medium can be located in an Application Specific Integrated Circuits (ASIC). Of course, the processor and the readable storage medium can also exist as discrete components in the device.

[0342] An embodiment of the present application further provides a computer program product. The computer program product includes a computer program stored in a computer-readable storage medium. At least one processor can read the computer program from the computer-readable storage medium, and when the at least one processor executes the computer program, the above method can be implemented.

[0343] It should be understood that the present disclosure is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present disclosure is only limited by the appended claims.

Claims

1. A biometric login method, characterized in that, A client applied to communicate with a target device, the method comprising: Obtaining user login information of a login operation of the target device as login information to be verified, and obtaining first string information corresponding to the target device; wherein, the login operation is triggered by a first user, and the first string information is generated by a second user based on the user login information of the target device, and the second user is a user with the login permission of the target device; the user login information at least includes: biometric information of the corresponding user, account characteristics of the corresponding user, and device identification characteristics of the target device; Determining device login verification information based on the first string information and the login information to be verified; Sending the device login verification information to a verification end, so that the verification end determines a login feedback message of the login operation through the device login verification information.

2. The method according to claim 1, wherein The device login verification information includes: a first ciphertext; The determining device login verification information based on the first string information and the login information to be verified includes: Performing first decryption on the first string information to obtain second string information; Performing second encryption on the login information to be verified through the second string information to obtain the first ciphertext.

3. The method according to claim 1 or 2, characterized in that, Before obtaining user login information of a login operation of the target device as login information to be verified, the method further includes: Verifying a first biometric of the first user who triggers the login operation; Determining that the first biometric verification is successful.

4. A biometric login method, characterized in that, A verification end, the method comprising: Receiving device login verification information sent by a client communicating with a target device, the device login verification information being determined based on first string information and login information to be verified; the login information to be verified is user login information of a login operation of the target device, the login operation is triggered by a first user, and the first string information is generated by a second user based on the user login information of the target device, and the second user is a user with the login permission of the target device; the user login information at least includes: biometric information of the corresponding user, account characteristics of the corresponding user, and device identification characteristics of the target device; Determining a login feedback message of the login operation through the device login verification information.

5. The method according to claim 4, wherein The device login verification information includes: a first ciphertext and first string information, the first ciphertext being obtained by performing first encryption on the login information to be verified through the first string information; The determining a login feedback message of the login operation through the device login verification information includes: Determining third string information corresponding to the first string information, the third string information being obtained by performing second encryption on the user login information of the target device by the second user; Performing third encryption on the user login information of the target device by the second user based on the third string information to generate a second ciphertext; Generating a login feedback message of the login operation according to the first ciphertext and the second ciphertext.

6. The method according to claim 5, wherein The device login verification information further includes: the first public key and the second signature of the client, where the second signature is generated based on the first ciphertext and the first private key of the client; before generating the login feedback message for the login operation according to the first ciphertext and the second ciphertext, it further includes: determining that the verification of the second signature by the first public key of the client is successful, to indicate that the process of the client transmitting the device login verification information to the verification end is in a secure state; and / or Generating the login feedback message for the login operation according to the first ciphertext and the second ciphertext includes: in response to the first ciphertext and the second ciphertext being consistent, generating a first feedback message as the login feedback message, where the first feedback message is used to indicate that the login operation is successful for logging in to the target device; in response to the first ciphertext and the second ciphertext being inconsistent, generating a second feedback message as the login feedback message, where the second feedback message is used to indicate that the login operation fails for logging in to the target device; and / or The third string information is string information carrying an expiration date; generating the login feedback message for the login operation according to the first ciphertext and the second ciphertext includes: in response to the first ciphertext and the second ciphertext being consistent and the current timestamp being within the expiration date, generating a third feedback message as the login feedback message; the third feedback message is used to indicate that the login operation is successful for logging in to the target device; in response to the first ciphertext and the second ciphertext being inconsistent, or the current timestamp not being within the expiration date, generating a fourth feedback message as the login feedback message, where the fourth feedback message is used to indicate that the login operation fails for logging in to the target device.

7. A biometric registration method, characterized in that, Applied to the verification end, the method includes: In response to a registration request sent by a client communicating with a target device, obtaining the user login information of the second user for the target device, where the user login information at least includes: the biometric information of the corresponding user, the account characteristics of the corresponding user, and the device identification characteristics of the target device; Generating a first string information according to the user login information of the target device.

8. The method according to claim 7, wherein Before generating the first string information according to the user login information of the target device, the method further includes: Determining that the verification of the first signature by the first public key of the client is successful; the first signature is generated by the first private key of the client and the user login information of the second user for the target device.

9. The method according to claim 8, wherein After determining that the verification of the first signature by the first public key of the client is successful and before generating the first string information according to the user login information of the target device, the method further includes: When the account characteristics of the second user in the identity verification service are consistent with the account characteristics in the user login information, verifying the first signature based on the first public key to check the security of the process of the client transmitting the user login information of the second user for the target device to the verification end.

10. The method according to claim 7, wherein The method further includes: In response to the unbinding request sent by the client, obtain the account features in the identity authentication service corresponding to the unbinding operation and the first string information; Based on the user login information corresponding to the first string information, verify whether the account features in the identity authentication service exist in the user login information; If the account features in the identity authentication service exist, delete the user login information corresponding to the first string information and the first string information, and return unbinding feedback information.

11. The method according to claim 7, characterized in that, The user login information further includes a current timestamp; The generation of the first string information according to the user login information of the target device includes: Perform second encryption through the user login information and the current timestamp to generate a third string information with an expiration date; Perform third encryption on the third string information through the first public key of the client to obtain the first string information, and the first public key is obtained by performing fourth encryption through the second public key of the verification end.

12. The method according to claim 1-3 or 4-6 or 7-11, characterized in that, The first string information is obtained by performing third encryption on the third string information through the first public key of the client, and the first public key is obtained by performing fourth encryption through the second public key of the verification end; The third string information is generated by the second user for the user login information of the target device; and / or The target device is a vehicle, and the biometric information includes: a feature type and a biometric; the account feature includes: an account identifier of the corresponding user; the device identifier feature includes: at least one of the vehicle identification number of the vehicle, the client type of the client, and the vehicle identifier.

13. An electronic device, characterized in that, Includes: A memory, a processor; The memory stores computer execution instructions; The processor executes the computer execution instructions stored in the memory, so that the processor executes the method according to any one of claims 1-12.

14. A computer-readable storage medium, characterized in that, Computer execution instructions are stored in the computer-readable storage medium, and when the computer execution instructions are executed by a processor, they are used to implement the method according to any one of claims 1-12.