Security authentication method, device and system

By synchronously collecting authentication information between the master and auxiliary devices, and using timestamp information, environmental voiceprints, and biometrics for two-factor authentication, the problem of easy leakage of authentication keys is solved, and highly secure and reliable authentication results are achieved.

CN122339705APending Publication Date: 2026-07-03SHENZHEN JIARUNXIN COMM TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHENZHEN JIARUNXIN COMM TECH CO LTD
Filing Date
2026-04-21
Publication Date
2026-07-03

Smart Images

  • Figure CN122339705A_ABST
    Figure CN122339705A_ABST
Patent Text Reader

Abstract

The application discloses a security authentication method, device and system, relates to the technical field of security management, and realizes comparison in the time sequence level by collecting synchronization authentication information of a main device and an auxiliary device, comparing collected timestamp information, so that even if an attacker obtains historical authentication data of a user, the timestamp of the historical data cannot satisfy a moment synchronization condition, and a replay attack path is blocked. When identity authentication and time sequence authentication are simultaneously satisfied, an authentication request is passed, so that the authentication request is ensured to come from a legal user and be initiated at a real physical time, and the credibility of an authentication result is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of security management technology, and in particular to security authentication methods, equipment and systems. Background Technology

[0002] With the widespread adoption of mobile payments, remote work, and privacy data protection, the security of user identity authentication has become a crucial aspect of ensuring information asset security. Currently, traditional digital passwords, gesture passwords, or biometric authentication based on fingerprints, faces, irises, and other biometric features are widely used.

[0003] Biometric authentication, digital password authentication, or gesture authentication methods can meet people's needs in normal daily life. However, in some specific scenarios (such as remote work, large-amount payments, etc.), these authentication keys based on static features can be easily obtained by users, making files or assets insecure. Summary of the Invention

[0004] The main purpose of this application is to provide a secure authentication method, device and system, which aims to solve the technical problem that existing authentication keys are easily leaked, resulting in low security.

[0005] To achieve the above objectives, this application proposes a security authentication method, which is used in the main device of a security authentication system. The security authentication system further includes an auxiliary device; the main device and the auxiliary device are communicatively connected. The method includes: When an authentication request is detected, a synchronization collection start time is sent to the auxiliary device so that the auxiliary device can collect authentication information at the synchronization collection start time and obtain the second authentication information. At the synchronous acquisition start time, authentication information is collected to obtain first authentication information and the master device timestamp information of the authentication information collection; and, the second authentication information and the auxiliary device timestamp information returned by the auxiliary device are received. Based on the first authentication information and the second authentication information, a pre-registration template is matched to obtain the identity authentication result; and, Timing verification is performed based on the timestamp information of the master device and the timestamp information of the auxiliary device to obtain the timing authentication result. When both the identity authentication result and the timing authentication result are passed, the authentication result of the authentication request is determined to be passed.

[0006] In one embodiment, the step of performing timing verification based on the master device timestamp information and the auxiliary device timestamp information to obtain a timing authentication result includes: The time difference between the main device and the auxiliary device during authentication information collection is determined based on the timestamp information of the main device and the timestamp information of the auxiliary device. Timing verification is performed based on the acquisition time difference to obtain the timing authentication result.

[0007] In one embodiment, the step of performing time-series verification based on the acquisition time difference to obtain a time-series authentication result includes: When the acquisition time difference is greater than a preset time difference threshold, the timing authentication result is determined to be unsuccessful; or, When the time difference of the data collection is not greater than the preset time difference threshold, the timing authentication result is determined to be passed.

[0008] In one embodiment, the first authentication information includes at least: first environmental voiceprint information; the second authentication information includes at least: second environmental voiceprint information and biometric information; The step of performing pre-registration template matching based on the first authentication information and the second authentication information to obtain the identity authentication result includes: Cross-correlation calculation is performed based on the first environmental acoustic print information and the second environmental acoustic print information to obtain the cross-correlation value; When the cross-correlation value is greater than a preset threshold, an environmental spatial orientation feature vector is determined based on the first environmental soundprint information and the second environmental soundprint information. Physiological features are extracted based on the biometric information to obtain the identity authentication feature vector; Based on the environmental spatial orientation feature vector and the identity authentication feature vector, feature fusion is performed to obtain a fused feature vector; Based on the fused feature vector, pre-registration template matching is performed to obtain the identity authentication result.

[0009] In one embodiment, the step of performing pre-registration template matching based on the fused feature vector to obtain the identity authentication result includes: The fused feature vector is matched against a pre-registration template in the pre-registration template library. When a target pre-registration template is matched, the identity authentication result is determined to be successful. If no matching target pre-registration template can be found, the identity authentication result is determined to be unsuccessful.

[0010] In one embodiment, the step of performing pre-registration template matching on the fused feature vector in the pre-registration template library, and determining the identity authentication result as passed when a target pre-registration template is matched, includes: Determine the identity features and fluctuation features of the fused feature vector; In the pre-registration template library, the identity feature and the fluctuation feature are matched with pre-registration templates respectively. When both the identity feature and the fluctuation feature match the target pre-registration template, the identity authentication result is determined to be passed.

[0011] In addition, to achieve the above objectives, this application also proposes a security authentication device, which is the main device of a security authentication system. The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor. The computer program is configured to implement the steps of the security authentication method for the main device as described above.

[0012] Furthermore, to achieve the above objectives, this application also proposes a security authentication method for use in an auxiliary device of a security authentication system, wherein the security authentication system further includes a main device; and the auxiliary device is communicatively connected to the main device. The method includes: When the master device detects an authentication request, it sends a synchronization acquisition start time to the auxiliary device. Upon receiving the synchronization collection start time sent by the master device, authentication information is collected at the synchronization collection start time to obtain second authentication information and timestamp information of the auxiliary device for authentication information collection. The second authentication information and the auxiliary device timestamp information are sent to the main device, so that the main device performs pre-registration template matching based on the first authentication information and the second authentication information to obtain an identity authentication result; and performs time-series verification based on the main device timestamp information and the auxiliary device timestamp information to obtain a time-series authentication result; when both the identity authentication result and the time-series authentication result are passed, the authentication result of the authentication request is determined to be passed.

[0013] In addition, to achieve the above objectives, this application also proposes a security authentication device, which is the main device of a security authentication system. The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor. The computer program is configured to implement the steps of the security authentication method for auxiliary devices as described above.

[0014] In addition, to achieve the above objectives, this application also proposes a storage medium, which is a computer-readable storage medium, on which a computer program is stored, and which, when executed by a processor, implements the steps of the security authentication method described above.

[0015] In addition, to achieve the above objectives, this application also provides a security authentication system, which includes a security authentication device as a main device and a security authentication device as an auxiliary device as described above.

[0016] One or more technical solutions proposed in this application have at least the following technical effects: This application achieves authentication by sending a synchronization start time to the auxiliary device upon detecting an authentication request, enabling the auxiliary device to collect authentication information at the synchronization start time to obtain second authentication information; collecting authentication information at the synchronization start time to obtain first authentication information and the master device timestamp information for authentication information collection; receiving the second authentication information and the auxiliary device timestamp information returned by the auxiliary device; performing pre-registration template matching based on the first and second authentication information to obtain an identity authentication result; and performing time-series verification based on the master device timestamp information and the auxiliary device timestamp information to obtain a time-series authentication result; determining that the authentication result of the authentication request is passed when both the identity authentication result and the time-series authentication result are passed. Because synchronous authentication information collection is performed on the master device and the auxiliary device, and the collected timestamp information is compared, a time-series comparison is achieved. This prevents attackers from obtaining the user's historical authentication data and ensuring that the historical data timestamps meet the instantaneous synchronization condition, thus blocking replay attack paths and avoiding threats caused by key leakage. The authentication request is only approved when both identity authentication and time-series authentication are satisfied, ensuring that the authentication request comes from a legitimate user and is initiated at a real physical moment, thus improving the credibility of the authentication result. Attached Figure Description

[0017] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0018] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0019] Figure 1 This is a flowchart illustrating an embodiment of the security authentication method of this application. Figure 2 This is a flowchart illustrating Embodiment 2 of the security authentication method of this application; Figure 3 This is a schematic diagram of a timing scenario provided for Embodiment 2 of the security authentication method of this application; Figure 4This is a flowchart illustrating Embodiment 3 of the security authentication method of this application; Figure 5 This is a schematic diagram of the module structure of the security authentication device according to an embodiment of this application; Figure 6 This is a schematic diagram of the device structure of the hardware operating environment involved in the security authentication method in the embodiments of this application.

[0020] The purpose, features, and advantages of this application will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0021] It should be understood that the specific embodiments described herein are merely illustrative of the technical solutions of this application and are not intended to limit this application.

[0022] To better understand the technical solution of this application, a detailed description will be provided below in conjunction with the accompanying drawings and specific implementation methods.

[0023] The main solution of this application embodiment is as follows: When an authentication request is detected, a synchronization collection start time is sent to the auxiliary device so that the auxiliary device can collect authentication information at the synchronization collection start time to obtain second authentication information; authentication information is collected at the synchronization collection start time to obtain first authentication information and the master device timestamp information of the authentication information collection; and the second authentication information and the auxiliary device timestamp information returned by the auxiliary device are received; pre-registration template matching is performed based on the first authentication information and the second authentication information to obtain an identity authentication result; and timing verification is performed based on the master device timestamp information and the auxiliary device timestamp information to obtain a timing authentication result; when both the identity authentication result and the timing authentication result are passed, the authentication result of the authentication request is determined to be passed.

[0024] This application provides a solution that improves authentication security by binding authentication information collected by different devices at the same instant into a single authentication credential, requiring two-factor authentication across different devices during authentication. Furthermore, by incorporating time-series authentication, it ensures instantaneous synchronization between different factors, fundamentally preventing replay attacks.

[0025] In one embodiment of this application, a security authentication system is proposed, which may include at least two security authentication devices that have established a communication connection. One of them can be used as a master device for security authentication, which can be used to perform security authentication management; the other can be used as an auxiliary device for security authentication, which can be used to assist the master device in performing security authentication management.

[0026] In some embodiments of this application, the main device may be a tablet computer, a computer, or a mobile phone, etc., and this application does not limit this.

[0027] In some embodiments of this application, the auxiliary device may be a smart bracelet, a smartwatch, or a mobile phone, etc., and this application does not limit it.

[0028] In another embodiment of this application, a security authentication method is proposed, which can be used in a master device of a security authentication system. For example... Figure 1 As shown, Figure 1 This is a flowchart illustrating the first embodiment of the security authentication method of this application.

[0029] Reference Figure 1 The security authentication method in this application includes the following steps: Step S10: When an authentication request is detected, a synchronization collection start time is sent to the auxiliary device so that the auxiliary device can collect authentication information at the synchronization collection start time to obtain the second authentication information; Step S20: At the start time of the synchronous acquisition, authentication information is acquired to obtain first authentication information and the master device timestamp information of the authentication information acquisition; and the second authentication information and the auxiliary device timestamp information returned by the auxiliary device are received.

[0030] It should be noted that a security authentication request can be generated when a user requires security authentication. When the master device detects the security authentication request, it can determine the synchronization start time for data collection and transmit this synchronization start time to the auxiliary device.

[0031] It should be explained that the synchronous acquisition start time can be a parameter used to constrain the master device and auxiliary device to acquire data at the same time. When the synchronous acquisition start time is reached, the master device and auxiliary device can begin acquiring authentication information.

[0032] It should be noted that the first authentication information mentioned above refers to the authentication information collected by the master device, and the second authentication information mentioned above refers to the authentication information collected by the slave device. In this embodiment of the application, the collection dimensions of the first authentication information and the second authentication information can be the same or different.

[0033] For example, the first authentication information may be information related to the authentication environment, such as location information, spatial orientation information, etc.; the second authentication information may be information related to the authentication identity, such as electrocardiogram information, pulse information, fingerprint information, etc., and the embodiments of this application do not limit this.

[0034] For example, the first authentication information can be information related to the authentication environment; the second authentication information can be information related to the authentication environment and the authentication identity.

[0035] It should be noted that, in this embodiment of the application, the main device and auxiliary device can simultaneously record the collection timestamp to obtain the corresponding main device timestamp information and auxiliary device timestamp information when collecting authentication information. This timestamp information can be used for timing verification. If there are network fluctuations, network attacks, or other situations that cause a large difference in timestamp values, authentication will be rejected, thereby improving authentication security.

[0036] In its specific implementation, the master device in this embodiment can send a synchronization collection start time to the auxiliary device when it detects an authentication request. Upon reaching the synchronization collection start time, the master device and the auxiliary device can synchronously begin collecting authentication information to obtain first authentication information, the corresponding master device timestamp information, second device information, and the corresponding auxiliary device timestamp information. Because two-factor authentication is performed by collecting different authentication information from both ends, the security risks associated with using any single factor are avoided.

[0037] Step S30: Perform pre-registration template matching based on the first authentication information and the second authentication information to obtain the identity authentication result; and perform time-series verification based on the timestamp information of the main device and the timestamp information of the auxiliary device to obtain the time-series authentication result. Step S40: When both the identity authentication result and the timing authentication result are passed, determine that the authentication result of the authentication request is passed.

[0038] It should be noted that this embodiment may include a pre-registration template library, which may contain at least several identity templates (pre-registration templates). Upon obtaining the first authentication information and the second authentication information, these can be merged to obtain the identity information corresponding to the current user. By matching this identity information with the pre-registration templates in the pre-registration template library, if a matching pre-registration template is found, the identity authentication result is considered successful; otherwise, the identity authentication result is considered unsuccessful.

[0039] In some embodiments of this application, the step of performing timing verification based on the timestamp information of the master device and the timestamp information of the auxiliary device to obtain a timing authentication result includes: determining the acquisition time difference between the master device and the auxiliary device when collecting authentication information based on the timestamp information of the master device and the timestamp information of the auxiliary device; and performing timing verification based on the acquisition time difference to obtain a timing authentication result.

[0040] It is understood that the aforementioned collection time difference is the absolute value of the time difference between the timestamp information of the master device and the timestamp information of the auxiliary device. When the collection time difference is greater than a preset time difference threshold, it indicates that the authentication information of the master device and the slave device (i.e., the authentication factors of two different devices) are separated in time. In this case, the timing authentication result is set as failing, avoiding potential losses caused by replay attacks, remote hijacking, device asynchrony, etc., and improving authentication security. When the collection time difference is not greater than the preset time difference threshold, it indicates that the two authentication factors are collected at the same physical moment, and the master device and the auxiliary device are working normally together. Specifically, the step of performing timing verification based on the collection time difference to obtain the timing authentication result includes: determining the timing authentication result as failing when the collection time difference is greater than the preset time difference threshold; or, determining the timing authentication result as passing when the collection time difference is not greater than the preset time difference threshold.

[0041] It should be understood that if both the identity authentication result and the timing authentication result are passed, it can be concluded that the authentication request was genuinely sent by the user, and therefore the authentication request can be passed.

[0042] This application embodiment, upon detecting an authentication request, sends a synchronization collection start time to the auxiliary device, enabling the auxiliary device to collect authentication information at the synchronization collection start time to obtain second authentication information; collects authentication information at the synchronization collection start time to obtain first authentication information and the master device timestamp information for authentication information collection; receives the second authentication information and the auxiliary device timestamp information returned by the auxiliary device; performs pre-registration template matching based on the first and second authentication information to obtain an identity authentication result; and performs time-series verification based on the master device timestamp information and the auxiliary device timestamp information to obtain a time-series authentication result; when both the identity authentication result and the time-series authentication result are passed, the authentication result of the authentication request is determined to be passed. Because synchronous authentication information collection is performed on the master device and the auxiliary device, and the collected timestamp information is compared, a time-series comparison is achieved, preventing attackers from obtaining historical authentication data of the user and ensuring that the timestamps of the historical data meet the instantaneous synchronization condition, thus blocking replay attack paths. By only passing the authentication request when both identity authentication and time-series authentication are satisfied, it ensures that the authentication request originates from a legitimate user and is initiated at a real physical moment, improving the credibility of the authentication result.

[0043] Based on the first embodiment of this application, in the second embodiment of this application, the content that is the same as or similar to that in the first embodiment described above can be referred to the above description, and will not be repeated hereafter. Based on this, please refer to... Figure 2 , Figure 2 This is a flowchart illustrating the second embodiment of the security authentication method of this application.

[0044] like Figure 2 As shown in this embodiment, the first authentication information includes at least: first environmental voiceprint information; the second authentication information includes at least: second environmental voiceprint information and biometric information. The step of performing pre-registration template matching based on the first authentication information and the second authentication information to obtain the identity authentication result includes: Step S100: Perform cross-correlation calculation based on the first environmental soundprint information and the second environmental soundprint information to obtain the cross-correlation value; Step S200: When the cross-correlation value is greater than a preset threshold, determine the environmental spatial orientation feature vector based on the first environmental soundprint information and the second environmental soundprint information.

[0045] It is understandable that sound propagation in physical space is affected by environmental physical structures such as room size, wall material, furniture layout, and room shape, resulting in different sound characteristics. This application embodiment obtains environmental soundprint information by collecting ambient sound data through a main device. By extracting the sound location information from this environmental soundprint information, a feature reflecting the spatial orientation of the sound source is obtained, namely, an environmental spatial orientation feature vector. For example, the environmental spatial orientation feature vector is generated by using the time difference and intensity difference of the same sound signal received by different microphones on the main device.

[0046] In some embodiments of this application, the auxiliary device can also be used to collect environmental acoustic fingerprint information. By performing cross-correlation calculations on the environmental acoustic fingerprint information received by the main device and the auxiliary device, it can be determined whether the main device and the auxiliary device are in the same acoustic environment. When the main device and the auxiliary device are in the same acoustic environment, the environmental spatial orientation feature vector can be determined based on the environmental acoustic fingerprint information. Specifically, the environmental spatial orientation feature vector can be determined based solely on the first environmental acoustic fingerprint information or the second environmental acoustic fingerprint information, or it can be determined by fusing the first and second environmental acoustic fingerprint information and then determining the environmental spatial orientation feature vector based on the fused features. In this application, the specific method for determining the environmental spatial orientation feature vector is not limited, and can be selected according to the needs of actual applications.

[0047] It is understandable that the aforementioned preset threshold can be a threshold used to determine whether the main device and the auxiliary device are in the same acoustic environment based on the first and second environmental acoustic fingerprint information. When the cross-correlation value is greater than the preset threshold, it can be determined that the main device and the auxiliary device are in the same acoustic environment; otherwise, it is determined that the main device and the auxiliary device are not in the same acoustic environment.

[0048] It should be noted that the cross-correlation calculation in the embodiments of this application can be implemented based on time-domain correlation and frequency-domain correlation. Specifically, it can be implemented using Pearson correlation coefficient, deep learning, etc. The embodiments of this application do not limit this.

[0049] In some embodiments of this application, in order to obtain more accurate environmental soundprint information, this application embodiment can actively send an audio signal through a master device or a slave device, and obtain environmental soundprint information by receiving the echo signal generated by the propagation of the audio signal in the environment.

[0050] Step S300: Extract physiological features based on the biometric information to obtain the identity authentication feature vector; Step S400: Based on the environmental spatial orientation feature vector and the identity authentication feature vector, feature fusion is performed to obtain a fused feature vector; Step S500: Perform pre-registration template matching based on the fused feature vector to obtain the identity authentication result.

[0051] It should be noted that the aforementioned biometric information can be collected by biosensors on auxiliary devices, such as electrocardiogram (ECG) signals, photoplethysmography (PPG) pulse wave signals, or electromyography (EMG) signals. By preprocessing the biometric information through filtering, noise reduction, and other methods, and extracting its time-domain, frequency-domain, or nonlinear features, a physiological feature vector is formed. This physiological feature vector can be used for user identification; that is, the physiological feature vector can serve as an identity authentication feature vector for user identification.

[0052] In some embodiments of this application, in order to achieve identity authentication, the environmental spatial orientation feature vector and the identity authentication feature vector can be fused to obtain a fused feature vector. The fusion method in this application can be feature-level fusion, score-level fusion, weighted fusion, etc., and this application does not limit the specific method used.

[0053] In some embodiments of this application, a pre-registration template library can be pre-established to achieve pre-registration template matching. This pre-registration template library may include feature vectors corresponding to real users. By matching the fused feature vector with the feature vectors in the pre-registration template library, it can be determined whether a target pre-registration template exists in the pre-registration template library and passes the matching. Specifically, the step of performing pre-registration template matching based on the fused feature vector to obtain the authentication result includes: performing pre-registration template matching on the fused feature vector in the pre-registration template library; when a target pre-registration template is matched, the authentication result is determined to be passed; when no target pre-registration template is matched, the authentication result is determined to be failed.

[0054] It should be noted that, in this embodiment, the fused feature vector can be compared one by one with the pre-registered templates in the pre-registered template library to determine the similarity score between the fused feature vector and the pre-registered template. This embodiment can also set a preset similarity score threshold; when the similarity score between the fused feature vector and the pre-registered template is greater than the similarity score threshold, the pre-registered template can be used as the target pre-registered template for matching.

[0055] In some embodiments of this application, to further improve authentication security, the step of performing pre-registration template matching on the fused feature vector in the pre-registration template library, and determining the identity authentication result as passed when a target pre-registration template is matched, includes: determining the identity feature and fluctuation feature of the fused feature vector; performing pre-registration template matching on the identity feature and the fluctuation feature respectively in the pre-registration template library; and determining the identity authentication result as passed when both the identity feature and the fluctuation feature are matched with the target pre-registration template.

[0056] It should be noted that, due to the differences in anatomical structure and physiological structure among different individuals, the corresponding biometric information collected will vary. Therefore, the fused feature vector may include identity features that reflect differences in user identity.

[0057] For example, differences in the geometric position and orientation of the heart in the chest cavity, the electrical conductivity of the myocardium, and the elasticity and path of the arteries can lead to differences in the overall shape of the electrocardiogram waveform, such as the width, amplitude, and area of ​​the QRS wave, the curvature of the ST segment, and the symmetry of the T wave.

[0058] It should be noted that when the human body experiences emotions such as tension and fear, the autonomic nervous system rapidly adjusts parameters such as heart rate and rhythm. Therefore, fluctuations in biometric information can be used to determine the characteristics of these fluctuations, thereby enabling the assessment of the user's emotions. When these fluctuation characteristics are abnormal, the user may be in a situation of coercion or danger.

[0059] In some embodiments of this application, the pre-registration template library may further include several fluctuation templates as pre-registration templates. When matching identity features and fluctuation features through the pre-registration template library, if both can be matched with the target pre-registration template, the identity authentication result can be considered as passed; otherwise, the identity authentication result is considered as failed.

[0060] In this embodiment, by dually judging identity features and fluctuation features, it is ensured that the authentication request is made by the user in a secure state, further improving authentication security. If the identity features and / or fluctuation features cannot match the target pre-registration template, an alert can be issued to emergency contacts to further enhance security.

[0061] In some embodiments of this application, the overall implementation timing flow of this application can be as follows: Figure 3 As shown, Figure 3 This is a schematic diagram of the timing scenario provided for Embodiment 2 of the security authentication method of this application.

[0062] Reference Figure 3 In this application embodiment, the main device can be a mobile phone, and the auxiliary device can be a watch. The security authentication process in this application embodiment can be divided into three stages. Stage 1 is authentication triggering and synchronization preparation, Stage 2 is the agreed synchronization collection time, and Stage 3 is data transmission and processing.

[0063] It should be noted that in Phase 1, users / applications can initiate authentication requests (such as payment requests). When the main device detects an authentication request, it can generate a one-time random number N and record the current timestamp. The master device can also determine the latency. Then, synchronous data acquisition begins, and this is used to determine the start time of synchronous data acquisition. The synchronization acquisition command sent by the master device to the auxiliary device may include the current timestamp when the master device detected the authentication request. The random number N, the data collection duration t, and the synchronous data collection start time are all specified. Information such as latency. It can be a fixed delay, the specific duration of which can be selected according to the actual application, such as 50ms, 100ms, etc.

[0064] Understandably, the random number N mentioned above can be used as a binding factor for timestamps, thereby encrypting the information transmission between the master device and the auxiliary device.

[0065] In this embodiment, the communication connection between the master device and the auxiliary device can be Bluetooth Low Energy (BLE), Ultra Wide Band (UWB), or other connection methods. This communication connection allows the master device to send synchronization acquisition commands via BLE / UWB.

[0066] It should be noted that in Phase Two, the master device can synchronize data collection starting at the start time. The system continuously collects environmental soundprint information, with a collection duration of t. Similarly, the slave device can synchronize the collection start time. Biometric information collection begins at any time and lasts for a duration of t. By pre-sending the collection duration and the synchronized start time, the collection actions of the main and auxiliary devices can be strictly aligned.

[0067] It should be explained that in phase three, the auxiliary device can upload the collected biometric data (i.e., biometric information) and the auxiliary device's timestamp to the main device. These parameters can be encrypted before uploading to improve transmission security.

[0068] It should be noted that once the main device obtains environmental voiceprint information and biometric information, it can extract features from this information to obtain environmental spatial orientation feature vectors and identity authentication feature vectors. By fusing the environmental spatial orientation feature vectors and identity authentication feature vectors, it is possible to achieve matching decisions by integrating environmental voiceprint features and biometric features.

[0069] This application embodiment calculates the cross-correlation value based on the first and second environmental voiceprint information. When the cross-correlation value is greater than a preset threshold, an environmental spatial orientation feature vector is determined based on the first and second environmental voiceprint information. Physiological features are extracted based on biometric information to obtain an identity authentication feature vector. Feature fusion is performed on the environmental spatial orientation feature vector and the identity authentication feature vector to obtain a fused feature vector. Pre-registration template matching is performed based on the fused feature vector to obtain the identity authentication result. Since deep binding of the two factors is achieved by acquiring two-factor authentication information composed of environmental voiceprints and physiological features and performing vector fusion, authentication security is improved. By utilizing multiple devices that users typically carry as separate sensors to collaboratively collect signals from different dimensions, the difficulty for attackers to simultaneously forge all signals is increased.

[0070] Based on the first and / or second embodiments of this application, in the third embodiment of this application, the content that is the same as or similar to the first and / or second embodiments described above can be referred to the above description and will not be repeated hereafter. Based on this, please refer to... Figure 4 , Figure 4 This is a flowchart illustrating the third embodiment of the security authentication method of this application.

[0071] like Figure 4 As shown in the embodiment of this application, before the step of performing pre-registration template matching based on the first authentication information and the second authentication information to obtain the identity authentication result, the method further includes: Step S01: When in a whitelisted environment, send an audio signal; Step S02: Receive the echo signal corresponding to the audio signal in the whitelist environment; Step S03: Generate the spatial orientation feature vector template of the whitelist environment based on the echo signal; Step S04: Obtain the user's identity feature vector template, and fuse the spatial orientation feature vector template and the identity feature vector template to obtain a pre-registration template.

[0072] It should be noted that the aforementioned whitelist environment is the same as the security environment, which can be set according to actual applications and the corresponding spatial orientation feature vector template can be collected, such as the user's home, company, or other places. This application embodiment does not impose any restrictions on this.

[0073] It should be understood that during the propagation of audio signals in a whitelisted environment, they may encounter obstacles and be reflected or scattered back, allowing the main device to receive the corresponding echo signal. This echo signal can then be used to determine the spatial orientation feature vector corresponding to the whitelisted environment.

[0074] It is understood that the aforementioned identity feature vector template can be a template constructed based on the physiological feature information uploaded by the user. For example, fingerprint features, electrocardiogram features, etc., recorded when generating the verification key, are not limited in this embodiment. By fusing the identity feature vector template and the spatial orientation feature vector template, a pre-registration template can be obtained.

[0075] This application embodiment transmits an audio signal while in a whitelisted environment; receives the echo signal corresponding to the audio signal in the whitelisted environment; generates a spatial orientation feature vector template for the whitelisted environment based on the echo signal; obtains the user's identity feature vector template; and fuses the spatial orientation feature vector template and the identity feature vector template to obtain a pre-registration template. Because a stable environmental spatial feature vector template is generated by actively transmitting audio and receiving echoes in a secure whitelisted environment, and then fused with the user's identity feature vector template, a two-factor joint binding pre-registration template is formed, providing a highly secure, highly reliable, and seamless comparison benchmark for subsequent two-factor authentication.

[0076] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the security authentication method of this application. Any simple modifications based on this technical concept are within the protection scope of this application.

[0077] This application also provides a security authentication device, please refer to... Figure 5 , Figure 5 This is a schematic diagram of the module structure of a security authentication device according to an embodiment of this application. The security authentication device includes: The request management module 10 is used to send a synchronization collection start time to the auxiliary device when an authentication request is detected, so that the auxiliary device can collect authentication information at the synchronization collection start time and obtain second authentication information. Data acquisition module 20 is used to acquire authentication information at the synchronous acquisition start time to obtain first authentication information and the master device timestamp information of the authentication information acquisition; and to receive second authentication information and auxiliary device timestamp information returned by the auxiliary device. The preliminary authentication module 30 is used to perform pre-registration template matching based on the first authentication information and the second authentication information to obtain an identity authentication result; and to perform time-series verification based on the timestamp information of the main device and the timestamp information of the auxiliary device to obtain a time-series authentication result. The secondary authentication module 40 is used to determine that the authentication result of the authentication request is passed when both the identity authentication result and the time-series authentication result are passed.

[0078] The security authentication device provided in this application, employing the security authentication method described in the above embodiments, can solve the technical problem that existing authentication keys are easily leaked, leading to low security. Compared with the prior art, the beneficial effects of the security authentication device provided in this application are the same as those of the security authentication method provided in the above embodiments, and other technical features in the security authentication device are the same as those disclosed in the methods of the above embodiments, and will not be repeated here.

[0079] This application embodiment also provides a security authentication method for an auxiliary device in a security authentication system, the method comprising: when the master device detects an authentication request, sending a synchronization acquisition start time to the auxiliary device; Upon receiving the synchronization collection start time sent by the master device, authentication information is collected at the synchronization collection start time to obtain second authentication information and timestamp information of the auxiliary device for authentication information collection. The second authentication information and the auxiliary device timestamp information are sent to the main device, so that the main device performs pre-registration template matching based on the first authentication information and the second authentication information to obtain an identity authentication result; and performs time-series verification based on the main device timestamp information and the auxiliary device timestamp information to obtain a time-series authentication result; when both the identity authentication result and the time-series authentication result are passed, the authentication result of the authentication request is determined to be passed.

[0080] The security authentication method for auxiliary devices in this application corresponds to the technical features of the security authentication method for main devices described above. Compared with the prior art, the beneficial effects of the security authentication method for auxiliary devices are the same as those of the security authentication method for main devices provided in the above embodiments, and other technical features correspond to the features disclosed in the above embodiments, and will not be repeated here.

[0081] This application provides a security authentication device, which can be used as a main device or an auxiliary device. The security authentication device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enables the at least one processor to perform the security authentication method of the above embodiments.

[0082] The following is for reference. Figure 6 The diagram illustrates a structural schematic suitable for implementing the security authentication device in the embodiments of this application. The security authentication device in the embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), PMPs (Portable Media Players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 6 The security authentication device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0083] like Figure 6As shown, the security authentication device may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 1002 or a program loaded from storage device 1003 into random access memory (RAM) 1004. The RAM 1004 also stores various programs and data required for the operation of the security authentication device. The processing unit 1001, ROM 1002, and RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to the I / O interface 1006: input devices 1007 including, for example, touchscreens, touchpads, keyboards, mice, image sensors, microphones, accelerometers, gyroscopes, etc.; output devices 1008 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 1003 including, for example, magnetic tapes, hard disks, etc.; and communication devices 1009. Communication device 1009 allows the security authentication device to communicate wirelessly or wiredly with other devices to exchange data. While the figure shows security authentication devices with various systems, it should be understood that implementation or possession of all the systems shown is not required. More or fewer systems may be implemented alternatively.

[0084] Specifically, according to the embodiments disclosed in this application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments disclosed in this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from storage device 1003, or installed from ROM 1002. When the computer program is executed by processing device 1001, it performs the functions defined in the methods of the embodiments disclosed in this application.

[0085] The security authentication device provided in this application, employing the security authentication method for the main device or the security authentication method for the auxiliary device described in the above embodiments, can solve the technical problem that existing authentication keys are easily leaked, leading to low security. Compared with the prior art, the beneficial effects of the security authentication device provided in this application are the same as those of the security authentication methods provided in the above embodiments, and other technical features in this security authentication device are the same as those disclosed in the methods of the previous embodiments, and will not be repeated here.

[0086] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any suitable manner in one or more embodiments or examples.

[0087] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0088] This application provides a computer-readable storage medium having at least one computer-readable program instruction (i.e., a computer program) stored thereon, the computer-readable program instruction being used to execute the security authentication method for a host device and / or as described in the above embodiments.

[0089] The computer-readable storage medium provided in this application may be, for example, a USB flash drive, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or flash memory, optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.

[0090] The aforementioned computer-readable storage medium may be included in the security authentication device; or it may exist independently and not be assembled into the security authentication device.

[0091] The aforementioned computer-readable storage medium carries one or more programs, which, when executed by a security authentication device, cause the security authentication device to: When an authentication request is detected, a synchronization collection start time is sent to the auxiliary device so that the auxiliary device can collect authentication information at the synchronization collection start time and obtain the second authentication information. At the synchronous acquisition start time, authentication information is collected to obtain first authentication information and the master device timestamp information of the authentication information collection; and, the second authentication information and the auxiliary device timestamp information returned by the auxiliary device are received. Based on the first authentication information and the second authentication information, a pre-registration template is matched to obtain the identity authentication result; and, Timing verification is performed based on the timestamp information of the master device and the timestamp information of the auxiliary device to obtain the timing authentication result. When both the identity authentication result and the timing authentication result are passed, the authentication result of the authentication request is determined to be passed.

[0092] And / or, when the master device detects an authentication request, it sends a synchronization acquisition start time to the auxiliary device; Upon receiving the synchronization collection start time sent by the master device, authentication information is collected at the synchronization collection start time to obtain second authentication information and timestamp information of the auxiliary device for authentication information collection. The second authentication information and the auxiliary device timestamp information are sent to the main device, so that the main device performs pre-registration template matching based on the first authentication information and the second authentication information to obtain an identity authentication result; and performs time-series verification based on the main device timestamp information and the auxiliary device timestamp information to obtain a time-series authentication result; when both the identity authentication result and the time-series authentication result are passed, the authentication result of the authentication request is determined to be passed.

[0093] Computer program code for performing the operations of this application can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0094] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0095] The modules described in the embodiments of this application can be implemented in software or hardware. The names of the modules do not necessarily limit the functionality of the unit itself.

[0096] The readable storage medium provided in this application is a computer-readable storage medium that stores computer-readable program instructions (i.e., a computer program) for executing the above-described security authentication method. This solves the technical problem that existing authentication keys are easily leaked, leading to low security. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in this application are the same as those of the security authentication method provided in the above embodiments, and will not be repeated here.

[0097] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the security authentication method described above.

[0098] The computer program product provided in this application can solve the technical problem that existing authentication keys are easily leaked, resulting in low security. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as those of the security authentication method provided in the above embodiments, and will not be repeated here.

[0099] The above description is only a part of the embodiments of this application and does not limit the scope of protection of this application. All equivalent structural transformations made under the technical concept of this application and using the content of this application specification and drawings, or direct / indirect applications in other related technical fields, are included in the scope of protection of this application.

Claims

1. A security authentication method characterized by, The security authentication method is used in the main device of the security authentication system, and the security authentication system further includes: auxiliary device; the main device and the auxiliary device are communicatively connected. The method includes: When an authentication request is detected, a synchronization collection start time is sent to the auxiliary device so that the auxiliary device can collect authentication information at the synchronization collection start time and obtain the second authentication information. At the synchronous acquisition start time, authentication information is collected to obtain first authentication information and the master device timestamp information of the authentication information collection; and, the second authentication information and the auxiliary device timestamp information returned by the auxiliary device are received. Based on the first authentication information and the second authentication information, a pre-registration template is matched to obtain the identity authentication result; and, Timing verification is performed based on the timestamp information of the master device and the timestamp information of the auxiliary device to obtain the timing authentication result. When both the identity authentication result and the timing authentication result are passed, the authentication result of the authentication request is determined to be passed.

2. The security authentication method of claim 1, wherein, The step of performing timing verification based on the timestamp information of the master device and the timestamp information of the auxiliary device to obtain the timing authentication result includes: The time difference between the main device and the auxiliary device during authentication information collection is determined based on the timestamp information of the main device and the timestamp information of the auxiliary device. Timing verification is performed based on the acquisition time difference to obtain the timing authentication result.

3. The security authentication method of claim 2, wherein, The step of performing time-series verification based on the acquisition time difference to obtain the time-series authentication result includes: When the acquisition time difference is greater than a preset time difference threshold, the timing authentication result is determined to be unsuccessful; or, When the time difference of the data collection is not greater than the preset time difference threshold, the timing authentication result is determined to be passed.

4. The security authentication method of claim 1, wherein, The first authentication information includes at least: first environmental voiceprint information; the second authentication information includes at least: second environmental voiceprint information and biometric information; The step of performing pre-registration template matching based on the first authentication information and the second authentication information to obtain the identity authentication result includes: Cross-correlation calculation is performed based on the first environmental acoustic print information and the second environmental acoustic print information to obtain the cross-correlation value; When the cross-correlation value is greater than a preset threshold, an environmental spatial orientation feature vector is determined based on the first environmental soundprint information and the second environmental soundprint information. Physiological features are extracted based on the biometric information to obtain the identity authentication feature vector; Based on the environmental spatial orientation feature vector and the identity authentication feature vector, feature fusion is performed to obtain a fused feature vector; Based on the fused feature vector, pre-registration template matching is performed to obtain the identity authentication result.

5. The security authentication method as described in claim 4, characterized in that, The step of performing pre-registration template matching based on the fused feature vector to obtain the identity authentication result includes: The fused feature vector is matched against a pre-registration template in the pre-registration template library. When a target pre-registration template is matched, the identity authentication result is determined to be successful. If no matching target pre-registration template can be found, the identity authentication result is determined to be unsuccessful.

6. The security authentication method as described in claim 5, characterized in that, The step of performing pre-registration template matching on the fused feature vector in the pre-registration template library, and determining the identity authentication result as passed when a target pre-registration template is matched, includes: Determine the identity features and fluctuation features of the fused feature vector; In the pre-registration template library, the identity feature and the fluctuation feature are matched with pre-registration templates respectively. When both the identity feature and the fluctuation feature match the target pre-registration template, the identity authentication result is determined to be passed.

7. A security authentication method, characterized in that, The security authentication method is used in an auxiliary device of a security authentication system, which further includes a main device; the auxiliary device is communicatively connected to the main device. The method includes: When the master device detects an authentication request, it sends a synchronization acquisition start time to the auxiliary device. Upon receiving the synchronization collection start time sent by the master device, authentication information is collected at the synchronization collection start time to obtain second authentication information and timestamp information of the auxiliary device for authentication information collection. The second authentication information and the auxiliary device timestamp information are sent to the main device, so that the main device performs pre-registration template matching based on the first authentication information and the second authentication information to obtain an identity authentication result; and performs time-series verification based on the main device timestamp information and the auxiliary device timestamp information to obtain a time-series authentication result; when both the identity authentication result and the time-series authentication result are passed, the authentication result of the authentication request is determined to be passed.

8. A security authentication device, characterized in that, The security authentication device is the main device of the security authentication system. The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor. The computer program is configured to implement the steps of the security authentication method as described in any one of claims 1 to 6.

9. A security authentication device, characterized in that, The security authentication device is an auxiliary device for the security authentication system. The device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. The computer program is configured to implement the steps of the security authentication method as described in claim 7.

10. A security authentication system, characterized in that, The security authentication system includes the security authentication device as described in claim 8 and the security authentication device as described in claim 9.