Personal biological characteristic information protection method based on trusted system
By using digital authentication and computing technologies based on trusted systems, point-to-point authorization processing of personal biometric information is achieved, solving the problem of unauthorized collection and use, improving information security and traceability, and reducing the risk of theft and counterfeiting.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-14
- Publication Date
- 2026-04-14
AI Technical Summary
Existing technologies cannot effectively prevent the unauthorized collection, processing, and use of personal biometric information, resulting in a high risk of information theft and impersonation.
A personal biometric information protection method based on a trusted system is adopted. Through digital authentication and trusted computing technologies, point-to-point authorization processing between personal biometric information and processing devices is realized. A trusted execution environment is used for identity verification and information comparison to ensure the legality of information collection, processing and use.
It increases the cost of theft and counterfeiting of personal biometric information, reduces the risk of unauthorized collection, processing and use, and enables credible labeling and traceability of information processing.
Smart Images

Figure CN121864313A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of data security technology, specifically relating to a method for protecting personal biometric information based on a trusted system. Background Technology
[0002] The identification and judgment of inherent physiological characteristics (such as fingerprints, facial images, and irises) and behavioral features (such as handwriting, voice, and gait) are crucial for identifying individuals and are an important component of personal information. The identification of these features can be divided into direct sensory recognition in everyday life and technology-assisted recognition in identity verification. Regardless of the context, when these features are stolen, imitated, or misidentified, they will negatively impact or cause losses to the individuals involved. With advancements in information technology and the expansion of AI applications, the accuracy of technology-assisted identification of these features is continuously improving. Simultaneously, the development of generative artificial intelligence has made it cheaper and more successful to imitate these features, as exemplified by fake images such as "head-swapped" videos and "face-swapped" pictures, and the use of fake images to impersonate individuals for identity verification.
[0003] Currently, protection against the theft and impersonation of personal biometric information mainly relies on post-protection measures through legislation and other management mechanisms. This involves safeguarding rights after personal biometric information has been stolen or impersonated, covering all stages of the process, including collection, storage, processing, use, transmission, provision, disclosure, and deletion. Technical protection typically involves encrypting the storage and transmission of personal biometric information carriers (such as images containing fingerprints, videos containing facial images, and audio containing voiceprints) to ensure the security and integrity of the stored and transmitted information. However, these methods cannot provide sufficient preventative protection, primarily due to the following issues:
[0004] Unauthorized collection of personal biometric information cannot be prevented. Carriers containing personal biometric information can be collected through information technology such as images, videos, and audio files. Currently, any imaging or audio-visual device can collect anyone's personal biometric information, such as collecting facial information by recording videos through mobile devices.
[0005] Unauthorized processing of personal biometric information cannot be prevented. Carriers containing personal biometric information can be stored in information formats such as images, videos, and audio files. Currently, any image, audio, or video editing device can process these files. For example, a computer device can be used to edit a video containing facial information to replace the original facial information with that of another person.
[0006] Unauthorized use of personal biometric information cannot be prevented. Carriers containing personal biometric information can be stored in digital formats such as images, videos, and audio files. Currently, any image, audio, or video playback device can use these files, such as displaying images containing fingerprint information on a mobile device. Summary of the Invention
[0007] To address the aforementioned problems, this invention is proposed to provide a method for protecting personal biometric information based on a trusted system. This method enables point-to-point authorized processing between personal biometric information and processing devices, prevents unauthorized collection, processing, and use of personal biometric information, achieves trusted labeling of personal biometric information owners and effective traceability of information processing entities, increases the cost of theft and counterfeiting of personal biometric information, and effectively reduces the risk of theft and counterfeiting.
[0008] To achieve the objectives of this invention, the technical solution adopted is a method for protecting personal biometric information based on a trusted system. The trusted system includes a personal biometric information owner terminal system and a personal biometric information processor terminal system. Both the owner terminal system and the processor terminal system include information processing components, network communication components, input / output components, storage components, and functional components. The method for protecting personal biometric information includes:
[0009] The pre-application process for digital authentication involves the owner and processor of personal biometric information applying for digital authentication from a CA (Certificate Authority) and obtaining public and private key pairs, which are used to verify their own identity during the use and processing of personal biometric information.
[0010] The authorization process for processing personal biometric information involves the personal biometric information processor submitting an application to the personal biometric information owner. After the owner grants authorization, the processor obtains the right to use specific devices to process specific types of personal biometric information of the owner.
[0011] Preferably, the processor terminal system can provide a trusted execution environment based on trusted computing technology, and has functions such as signature key, secure input / output, memory shielding, and encapsulated storage.
[0012] Optionally, the personal biometric information processor terminal system meets the requirements of the national standard GB / T 29829-2022 Information Security Technology Trusted Computing Cryptographic Support Platform Function and Interface Specification.
[0013] Preferably, the pre-authorization process for processing personal biometric information includes the following steps:
[0014] S1: The personal biometric information processor obtains the owner's personal biometric information communication channels and prepares to apply for authorization data A;
[0015] S2: The trusted system obtains data A by encrypting data A using the owner's public key. E Then use the processor's private key to process data A. E The data is encrypted using AES and then sent to the owner.
[0016] S3: Owner receives data A ES Then, the trusted system uses the processor's public key to decrypt and obtain data AE, and then uses the owner's private key to decrypt and obtain data A.
[0017] S4: The owner prepares authorized data B, and the trusted system uses the processor's public key to encrypt data B to obtain data B. E Then use the owner's private key to access data B. E Encrypting data B ES And send it to the processor;
[0018] S5: The processor receives data B ES Then, the trusted system uses the owner's public key to decrypt and obtain data BE, and then uses the processor's private key to decrypt and obtain data B.
[0019] Preferably, the personal biometric information protection method includes a personal biometric information collection process, a processing process, and a usage process. Before collecting, processing, and using the personal biometric information, it is compared with the authorized biometric information standard data stored in a trusted system. If it is consistent with the authorized biometric information standard data, the next step is performed; if it is inconsistent, technical ambiguity is applied to render the personal biometric information invalid for personal biometric identification.
[0020] Preferably, the personal biometric information collection process includes the following steps:
[0021] Trusted systems perform personal biometric detection on information temporarily captured but not stored by the capture component;
[0022] The detected personal biometric information is compared with the standard data of authorized biometric information stored in the trusted system to determine whether the information has been authorized for collection.
[0023] If the collection is authorized, the temporarily captured content will be displayed normally. If it is not authorized, the corresponding area in the temporarily captured content will be blurred technically, so that the personal biometric information loses its personal biometric identification effect.
[0024] The trusted system stores temporarily captured information that is normally displayed and technically blurred, and adds annotations such as authorized owner information, collector information, collection device information, and collection time information.
[0025] Preferably, the personal biometric information processing procedure includes the following steps:
[0026] The processing component pre-processes the content it intends to process by performing personal biometric detection. The detected personal biometric information is then compared with the authorized biometric information standard data stored in the trusted system to determine whether the information is authorized for processing. If authorized, the processing component performs the processing; if not authorized, the processing component is prohibited from processing.
[0027] When the processing component stores the processing results, the trusted system performs personal biometric detection on the content to be stored in advance. The detected personal biometric information is compared with the standard data of authorized biometric information stored in the trusted system to determine whether the information is authorized. If it is authorized, no processing is performed. If it is not authorized, the corresponding area in the content to be stored is technically blurred, so that the personal biometric information loses its personal biometric identification effect.
[0028] The data is stored after processing, including information on the authorized owner, collector, collection device, and collection time.
[0029] Preferably, the process of using the personal biometric information includes the following steps:
[0030] When a trusted system uses personal biometric information, the playback component performs personal biometric detection on the content of the playback file and compares the detected personal biometric information with the standard data of authorized biometric information stored in the trusted system to determine whether the information is authorized for use.
[0031] If authorized, the content will be displayed normally, along with additional information, including but not limited to the basic information of the owner of the authorized personal biometric information, the basic information of the collector / processor, the information of the equipment used for collection / processing, the information of the tools used for collection / processing, and the processing time. If not authorized, the corresponding areas in the content will be technically blurred to render the personal biometric information invalid for identification purposes before being displayed.
[0032] Preferably, the communication channels include SMS, MMS, and APP software;
[0033] Preferably, the requested authorized data A includes the basic information of the personal biometric information processor, the processing device information, the basic information of the personal biometric information owner, the type of information to be processed, the reason for processing the information, and the authorized time limit;
[0034] Authorized data B includes, but is not limited to, the authorized object, the type of authorized information, the authorization period, the basic information of the authorization, and standard data of the authorized biometric information.
[0035] The beneficial effects of this invention are as follows:
[0036] This invention aims to deeply integrate trusted computing, digital authentication, and biometric identification technologies. When processing (i.e., collecting / processing / using, hereinafter the same) carriers containing personal biometric information, trusted computing technology provides a trusted execution environment, stores authorization and related data based on digital authentication technology, and uses biometric identification technology to compare and determine whether the biometric information contained in the carrier is authorized for processing. If authorized, processing is permitted, and the information owner and processor's information is appended; if unauthorized, the information is technically obfuscated to render it unidentifiable. This method enables point-to-point authorized processing between personal biometric information and processing devices, preventing unauthorized collection, processing, and use of personal biometric information. It also enables trusted labeling of personal biometric information owners and effective traceability of information processing entities, thereby increasing the cost of theft and counterfeiting of personal biometric information and reducing the risk of such theft and counterfeiting. Attached Figure Description
[0037] The above and other objects, features and advantages of the present invention will become more apparent from the accompanying drawings, in which like reference numerals generally denote like parts.
[0038] Figure 1 A schematic diagram of the composition structure of a trusted system according to an embodiment of the present invention is shown.
[0039] Figure 2 A flowchart of the digital authentication application pre-process according to an embodiment of the present invention is shown.
[0040] Figure 3 A diagram illustrating the key configuration of a personal biometric information owner processor according to an embodiment of the present invention is shown.
[0041] Figure 4 A flowchart illustrating the authorization pre-processing of personal biometric information processing according to an embodiment of the present invention is shown.
[0042] Figure 5 A flowchart illustrating the personal biometric information collection process according to an embodiment of the present invention is shown.
[0043] Figure 6 A flowchart illustrating the personal biometric information processing procedure according to an embodiment of the present invention is shown.
[0044] Figure 7 A flowchart illustrating the process of using personal biometric information according to an embodiment of the present invention is shown. Detailed Implementation
[0045] While preferred embodiments of the invention are shown in the accompanying drawings, it should be understood that the invention can be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that the invention will be more thorough and complete, and will fully convey the scope of the invention to those skilled in the art.
[0046] A method for protecting personal biometric information based on a trusted system, wherein the trusted system includes a personal biometric information owner terminal system and a personal biometric information processor terminal system, such as... Figure 1 As shown, the owner terminal system and the processor terminal system include information processing components, network communication components, input / output components, storage components, and functional components;
[0047] Specifically, the personal biometric information processor terminal system can provide a trusted execution environment based on trusted computing technology, and has functions such as signature key, secure input and output, memory shielding, and encapsulated storage.
[0048] The main functional components of the personal biometric information owner terminal system include "authorization acceptance", "biometric standard data generation", and "authorized records";
[0049] Preferably, the processor terminal system meets the requirements of the national standard GB / T 29829-2022 Information Security Technology Trusted Computing Cryptographic Support Platform Function and Interface Specification.
[0050] The main functional components of the personal biometric information processor terminal system include "information carrier personal biometric information inspection", "authorization application", "authorization record", "authorized data secure storage", "biometric information comparison", "information carrier information owner and processor labeling", and "video, image and audio partial blurring" and other functions.
[0051] Methods for protecting personal biometric information include the pre-application process for digital authentication and the pre-authorization process for processing personal biometric information;
[0052] The pre-application process for digital authentication involves the owner of personal biometric information and the processor of personal biometric information applying for digital authentication from a CA (Certificate Authority) and obtaining public and private key pairs, which are used to verify their own identity during the use and processing of personal biometric information.
[0053] The authorization process for processing personal biometric information involves the personal biometric information processor submitting an application to the owner. After authorization from the owner, the personal biometric information processor gains the right to use specific devices to process specific types of the owner's personal biometric information.
[0054] See the pre-application process for digital certification. Figure 2The owner and processor of personal biometric information each apply for digital authentication from a Certificate Authority (CA) and obtain public-private key pairs, which are used to verify their identity during the use and processing of personal biometric data. The personal biometric processor can be an organization or an individual. After authentication, both the owner and processor obtain public-private key pairs for an asymmetric encryption algorithm. The private key is kept by the owner and processor and stored on a specific medium (such as a USB key), while the public key is made public by the CA (such as a digital certificate).
[0055] like Figure 3 As shown, after being authenticated by a CA (Certificate Authority), the owner of an individual's biometric data obtains a private key M1 and a public key M2. The private key M1 is kept by the owner of the individual's biometric data and stored in a specific medium, while the public key M2 is made public by the CA. After being authenticated by a CA, the processor of an individual's biometric data obtains a private key N1 and a public key N2. The private key N1 is kept by the processor of the individual's biometric data and stored in a specific medium, while the public key N2 is made public by the CA. When one of the public and private keys is used for encryption, only the other can be used for decryption.
[0056] like Figure 4 As shown, the authorization pre-processing procedure for personal biometric information processing is as follows:
[0057] The personal biometric information processor obtains the owner's communication channels, including mobile phone text messages, MMS, social software, and other specific channels; the processor prepares data A, which includes the processor's basic information (including but not limited to name and organization), processing device information (including but not limited to device type and serial number), owner's basic information (including but not limited to the name of the personal biometric information owner), the type of information to be processed (including but not limited to fingerprints, facial images, irises, handwriting, voice, gait, etc.), the reason for processing the information, and the authorization period required; the trusted system uses the owner's public key (which can be obtained from a CA certification authority or other channels) to encrypt data A to obtain data A. E Then use the private key obtained by the processor to process data A. E Data A is obtained after encryption ES And send it to the owner;
[0058] The owner received data A ES Then, the trusted system uses the processor's public key (which can be obtained from sources such as a CA certification authority) to decrypt and obtain data A. E Then, the data A is obtained by decrypting it using the owner's private key; the information owner receives the message "XXX requests the collection / processing / use of your XXX information";
[0059] Upon receiving the application, if the owner refuses authorization, the system sends a refusal notification to the processor; if the owner chooses to grant authorization, the system prepares Data B, which includes, but is not limited to, basic authorization information such as the authorized recipient, authorization type, and authorization duration, as well as standard data of the authorized biometric information. Standard data can be generated by the system. The generation process of standard data does not store any carriers containing biometric information, such as videos, images, or audio recordings; it only stores the standard data itself.
[0060] The system adds the authorized content to the owner's "Authorized Records". The owner can view the authorized records through this list and perform operations such as canceling authorization and adjusting the authorization time limit.
[0061] The trusted system first encrypts data B using the processor's public key to obtain data B. E Then use the owner's private key to access data B. E Encrypt to obtain data B ES And send it to the processor; the processor receives data B ES Then, the trusted system uses the owner's public key to decrypt and obtain data B. E Then, the processor's private key is used to decrypt and obtain data B.
[0062] The trusted system adds the basic authorization information from data B to the "authorized record" and encrypts and stores the authorized biometric information standard data from data B using a key derived from trusted technology to ensure that the standard data can only be accessed on this device; the processor receives a notification message indicating that the authorization application was successful.
[0063] like Figure 5 As shown, the process of collecting personal biometric information is as follows:
[0064] When a trusted system collects information, it performs biometric detection on information temporarily captured but not stored by capture components (such as cameras and microphones). The detected biometric information, which has the power to identify individuals, is compared with the standard data of authorized biometric information stored in the trusted system to determine whether the information was collected authorizedly. If authorized, the temporarily captured content is displayed normally; if not authorized, the corresponding area in the temporarily captured content is blurred, rendering the biometric information ineffective for personal biometric identification.
[0065] When storing captured content, the capture component attaches data C using two methods: general data storage and data steganography. Data C includes, but is not limited to, the basic information of the authorized individual's biometric information owner (such as name), the basic information of the collector (such as name), the information of the device used for collection (such as device type, brand and model), and the collection time, etc., to complete the storage.
[0066] like Figure 6 As shown, the processing of personal biometric information is as follows:
[0067] When a trusted system processes information, it pre-detects the personal biometric features of the content to be processed by the processing components (such as image, video, and audio editing software). The detected biometric information, which has the power of identification, is compared with the authorized biometric information standard data stored in the trusted system to determine whether the information is authorized for processing. If authorized, the processing component is allowed to proceed; if unauthorized, processing is prohibited, and the system displays the message "The object being processed contains unauthorized personal biometric features; processing is prohibited."
[0068] When the processing component stores the processing results, the system pre-processes the content to be stored with personal biometric features. The detected biometric information, which has the power of identification, is compared with the authorized biometric information standard data stored in the trusted system to determine whether the information has been authorized for processing. If authorized, no processing is performed; if not authorized, the corresponding area in the stored content is technically blurred, rendering the personal biometric information ineffective for identification.
[0069] Information is stored using two methods: general data storage and data steganography. This data includes, but is not limited to, the owner's basic information (such as name), the processor's basic information (such as name), the equipment used in the processing (such as basic equipment information, processing software information), the tools used in the processing (such as software name), and the processing time.
[0070] like Figure 7 As shown, the process of using personal biometric information is as follows:
[0071] When a trusted system uses information, the playback component (such as a graphics card chip, sound card chip, or image, video, or audio playback software) performs personal biometric detection on the content of the file being played back. The detected biometric information, which has the power of identification, is compared with the authorized biometric information standard data stored in the trusted system to determine whether the information is authorized for use. If authorized, it is displayed normally.
[0072] Additional information can be displayed, including but not limited to the basic information of the owner (such as name), the basic information of the processor (such as name), the information of the equipment used for processing (such as basic equipment information, processing software information, etc.), the information of the tools used for processing (such as software name, etc.), and the processing time; if not authorized, the corresponding area in the content will be technically blurred to render the personal biometric information invalid for personal biometric identification before it is displayed.
[0073] The processor can view the owner's basic information and related information collection and processing information stored in the carrier using general data storage methods.
[0074] In data identity authentication scenarios, the authenticator can read the steganographic data in the images or sounds to be authenticated to obtain information that is helpful for authentication.
[0075] This invention is a method for protecting personal biometric information based on a trusted system. It primarily integrates functions such as identity verification of the owner and processor of personal biometric information, authorization of processing by the information owner to the processor, and trusted labeling of the information owner and processor with the collection, processing, and use of personal biometric information. Utilizing existing technologies such as trusted computing, digital authentication, and biometric recognition, it achieves controllable processing, ownership verification, and traceability of personal biometric information in carriers containing biometric information (such as videos, images, and audio). This prevents unauthorized collection, processing, and use of personal biometric information. Simultaneously, it enables trusted labeling of the subject of personal biometric information and effective traceability of the information processing entity, thereby increasing the cost of theft and counterfeiting of personal biometric information, reducing the risk of theft and counterfeiting, and minimizing the negative impacts and losses caused by theft and counterfeiting on individuals and other relevant parties.
[0076] The trusted system in this invention primarily functions in two ways. If other local hardware / software or remote platforms with corresponding capabilities are used, an untrusted system can be employed. First, through its cryptographic capabilities, it generates keys associated with the device's own hardware / software environment, encrypts and stores authorization-related information, and binds the authorization behavior to the device. Second, through its measurement capabilities, it ensures that the hardware / software used to process information meets relevant functional requirements and cannot bypass the checks in each process of this invention.
[0077] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. The solutions in the embodiments of the present invention can be implemented using various computer languages, such as the object-oriented programming language Java and the interpreted scripting language JavaScript.
[0078] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0079] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0080] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0081] Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including both the preferred embodiments and all changes and modifications falling within the scope of the invention.
[0082] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.
Claims
1. A method for protecting personal biometric information based on a trusted system, wherein the trusted system includes a personal biometric information owner terminal system and a personal biometric information processor terminal system, both the owner terminal system and the processor terminal system including information processing components, network communication components, input / output components, storage components, and functional components, characterized in that, The methods for protecting personal information using biometrics include: The pre-application process for digital authentication involves the owner and processor of personal biometric information applying for digital authentication from a CA (Certificate Authority) and obtaining public and private key pairs, which are used to verify their own identity during the use and processing of personal biometric information. The authorization process for processing personal biometric information involves the personal biometric information processor submitting an application to the personal biometric information owner. After the owner grants authorization, the processor obtains the right to use specific devices to process specific types of personal biometric information of the owner.
2. The method for protecting personal biometric information based on a trusted system according to claim 1, characterized in that, The processor terminal system can provide a trusted execution environment based on trusted computing technology, and has functions such as signature key, secure input / output, memory shielding, and encapsulated storage.
3. The method for protecting personal biometric information based on a trusted system according to claim 2, characterized in that, The personal biometric information processor terminal system meets the requirements of the national standard GB / T 29829-2022 Information Security Technology Trusted Computing Cryptographic Support Platform Function and Interface Specification.
4. The method for protecting personal biometric information based on a trusted system according to claim 3, characterized in that, The pre-authorization process for processing personal biometric information includes the following steps: The personal biometric information processor obtains the owner's personal biometric information communication channels and prepares to request authorized data A; The trusted system obtains data A by encrypting data A using the owner's public key. E Then use the processor's private key to process data A. E Data A is obtained after encryption ES And send it to the owner; The owner received data A ES Then, the trusted system uses the processor's public key to decrypt and obtain data A. E Then, use the owner's private key to decrypt and obtain data A; The owner prepares authorized data B, and the trusted system obtains data B by encrypting data B using the processor's public key. E Then use the owner's private key to access data B. E Encrypting data B ES And send it to the processor; The processor receives data B ES Then, the trusted system uses the owner's public key to decrypt and obtain data B. E Then, the processor's private key is used to decrypt and obtain data B.
5. A method for protecting personal biometric information based on a trusted system according to any one of claims 1-4, characterized in that, The method for protecting personal biometric information includes a process of collecting, processing, and using personal biometric information. Before collecting, processing, and using personal biometric information, it is compared with authorized biometric information standard data stored in a trusted system. If it matches the authorized biometric information standard data, the next step is performed; if it does not match, technical ambiguity is applied to render the personal biometric information invalid for personal biometric identification.
6. A method for protecting personal biometric information based on a trusted system according to claim 5, characterized in that, The process of collecting personal biometric information includes the following steps: Trusted systems perform personal biometric detection on information temporarily captured but not stored by the capture component; The detected personal biometric information is compared with the standard data of authorized biometric information stored in the trusted system to determine whether the information has been authorized for collection. If the collection is authorized, the temporarily captured content will be displayed normally. If it is not authorized, the corresponding area in the temporarily captured content will be blurred technically, so that the personal biometric information loses its personal biometric identification effect. The trusted system stores temporarily captured information that is normally displayed and technically blurred, and adds annotations such as authorized owner information, collector information, collection device information, and collection time information.
7. A method for protecting personal biometric information based on a trusted system according to claim 6, characterized in that, The process of processing personal biometric information includes the following steps: The processing component pre-processes the content it intends to process by performing personal biometric detection. The detected personal biometric information is then compared with the authorized biometric information standard data stored in the trusted system to determine whether the information is authorized for processing. If authorized, the processing component performs the processing; if not authorized, the processing component is prohibited from processing. When the processing component stores the processing results, the trusted system performs personal biometric detection on the content to be stored in advance. The detected personal biometric information is compared with the standard data of authorized biometric information stored in the trusted system to determine whether the information is authorized. If it is authorized, no processing is performed. If it is not authorized, the corresponding area in the content to be stored is technically blurred, so that the personal biometric information loses its personal biometric identification effect. The data is stored after processing, including information on the authorized owner, collector, collection device, and collection time.
8. A method for protecting personal biometric information based on a trusted system according to claim 7, characterized in that, The process of using the personal biometric information includes the following steps: When a trusted system uses personal biometric information, the playback component performs personal biometric detection on the content of the playback file and compares the detected personal biometric information with the standard data of authorized biometric information stored in the trusted system to determine whether the information is authorized for use. If authorized, the content will be displayed normally, along with additional information, including but not limited to the basic information of the owner of the authorized personal biometric information, the basic information of the collector / processor, the information of the equipment used for collection / processing, the information of the tools used for collection / processing, and the collection / processing time. If not authorized, the corresponding areas in the content will be technically blurred to render the personal biometric information invalid for identification purposes before being displayed.
9. A method for protecting personal biometric information based on a trusted system according to claim 8, characterized in that, The communication channels include mobile phone text messages, multimedia messages, and mobile apps.
10. A method for protecting personal biometric information based on a trusted system according to claim 9, characterized in that: The requested authorized data A includes the personal biometric information processor's basic information, processing device information, personal biometric information owner's basic information, the type of information to be processed, the reason for processing the information, and the authorized time limit; Authorized data B includes, but is not limited to, the authorized object, the type of authorized information, the authorization period, the basic information of the authorization, and standard data of the authorized biometric information.