Secure access adapter apparatus based on biometric recognition
By introducing a biometric-based secure access adapter device into the USB hub, the problem that existing USB hubs cannot effectively prevent unauthorized access is solved, and high security and convenient device access control is achieved.
Patent Information
- Application Number
- PCT/CN2024/106411
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-15
- Filing Date
- 2024-07-19
- Publication Date
- 2025-06-19
AI Technical Summary
Existing USB hubs lack effective security protection and cannot effectively prevent unauthorized access to USB devices that store sensitive data.
A secure access transfer device based on biometrics is adopted to obtain user information and generate access rights through the biometric device. The access control lock controls the transmission of access instructions based on user rights, independent of the original hardware and software, and avoids encryption operations.
It realizes high security access control for storage devices, improves the security and transparency of the device, avoids modification and encryption operations of the original device, and improves the convenience and versatility of the device.
Smart Images

Figure CN2024106411_19062025_PF_FP_ABST
Abstract
Description
A secure access switching device based on biometric identification Technical Field
[0001] The present invention relates to the field of access control, and in particular to a safe access switching device based on biometric identification. Background Art
[0002] With the advancement of technology, USB devices have become an indispensable part of our daily lives. However, security issues are becoming increasingly prominent. Preventing unauthorized access to USB devices that store sensitive data is a critical issue. Most USB hubs currently on the market lack security features, or have weak security features, failing to effectively prevent computers from accessing sensitive data stored on USB devices.
[0003] Although there are some methods on the market that can be used to prevent computers from arbitrarily accessing sensitive data in USB devices, such as the built-in permission management module in the NFTS system and technical solutions such as CN204613946U, the former requires changes to the original USB device level, while the latter controls access through encryption, which adds inconvenience to access control itself.
[0004] Summary of the Invention
[0005] To solve the above technical problems, the present invention provides a secure access switching device based on biometric identification. The specific technical solution is as follows:
[0006] A biometric-based secure access switching device, comprising:
[0007] A first transfer interface, connected to the instruction issuing device, for receiving an access instruction from the instruction issuing device;
[0008] A second transfer interface, connected to an instruction receiving device, for sending the access instruction to the instruction receiving device;
[0009] A biometric identification device for obtaining biometric identification information and generating corresponding user access rights;
[0010] An access control lock is used to control the transmission of the access instruction between the first transfer interface and the second transfer interface according to the user access rights.
[0011] Access control is achieved through a switching device that is independent of the original hardware and software and through biometric identification. On the one hand, there is no need to modify the original equipment, and on the other hand, there is no need for encryption, thereby improving the convenience of device use.
[0012] Preferably, the access control lock is further used to monitor whether the first transfer interface receives the access instruction;
[0013] The first adapter is further configured to issue a biometric recognition instruction to the instruction issuing device;
[0014] When the access control lock detects that the first adapter receives the access instruction from the instruction issuing device, it sends the biometric instruction to the instruction issuing device through the first adapter, waits for the user access rights, and determines whether to allow the access instruction to be transmitted to the second adapter based on the user access rights.
[0015] By authorizing access at the time, on the one hand, the security of the storage device is improved, and on the other hand, reminders can be used to clearly inform users about file access status, thereby improving transparency.
[0016] Preferably, the biometric recognition device is a fingerprint recognition device, specifically comprising:
[0017] Permission storage device, used to store user fingerprint information;
[0018] The fingerprint collection sensor is used to collect fingerprint images; the fingerprint recognition module is used to compare the fingerprint image with the user fingerprint template to determine the corresponding user access rights.
[0019] By using fingerprint recognition, on the one hand, the size of the biometric device can be compressed, and on the other hand, the accuracy of biometric recognition can be effectively improved without the need for additional computing resources.
[0020] Further preferably, the biometric identification device further comprises a repeated fingerprint detection device for detecting repeated fingerprints. The biometric identification device further comprises a false fingerprint detection device for detecting repeated false fingerprints.
[0021] Some mechanisms to prevent brute force attacks on fingerprint detection devices are adopted, such as detecting duplicate fingerprints, detecting fake fingerprints, etc., so as to prevent brute force attacks on fingerprint detection devices and increase security.
[0022] More preferably, the method further comprises: an external registration device for writing the biometric information and the corresponding user access rights into the biometric device.
[0023] Further preferably, the access control lock further comprises a self-locking module, configured to enter a self-locking state when the biometric recognition device fails to match the corresponding user access rights for multiple times;
[0024] In the self-locking state, the access control lock controls the transmission of all the access instructions between the first transfer interface and the second transfer interface until the external registration device rewrites the user fingerprint information and the corresponding user access rights into the permission memory.
[0025] In this technical solution, by setting the self-locking mode, the risk of brute force cracking can be effectively reduced, thereby improving the security of the device and reducing the risk of data leakage.
[0026] Further preferably, the biometric information is a fingerprint, and the external registration device specifically includes:
[0027] Fingerprint image acquisition device, used to obtain the user's fingerprint image;
[0028] Fingerprint feature extraction means, configured to extract features from the user fingerprint image to form the user fingerprint template, and store the template in the permission memory;
[0029] The fingerprint feature verification module is used to obtain the user fingerprint image and compare it with the corresponding user fingerprint template to verify the correctness of the user fingerprint template.
[0030] Preferably, the first adapter interface and / or the second adapter interface is selected from one of USB, Type-C, and SATA.
[0031] By using common universal interfaces, there is no need to change the original device interfaces, thereby improving the versatility of the device.
[0032] Preferably, there are multiple first adapters and / or multiple second adapters.
[0033] The present invention includes at least one of the following technical effects:
[0034] (1) Access control is achieved through a switching device that is independent of the original hardware and software, using biometric identification. This allows the original device to remain unchanged and encryption is not required, thereby improving the convenience of device use.
[0035] (2) By authorizing access at the time of access, the security of the storage device is improved on the one hand, and on the other hand, the user can be clearly informed of the file access status through reminders, thereby improving transparency;
[0036] (3) By using fingerprint recognition, the size of the biometric device can be compressed, and the accuracy of biometric recognition can be effectively improved without requiring additional computing resources;
[0037] (4) Adopting some mechanisms to prevent brute force attacks on fingerprint detection devices, such as detecting duplicate fingerprints, detecting fake fingerprints, etc., thereby preventing brute force attacks on fingerprint detection devices and increasing security;
[0038] (5) By setting the self-locking mode, the risk of brute force cracking can be effectively reduced, thereby improving the security of the device and reducing the risk of data leakage;
[0039] (6) By using common universal interfaces, there is no need to change the original device interfaces, thereby improving the versatility of the equipment. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0041] FIG1 is a schematic structural diagram of a biometric-based secure access switching device according to the present invention;
[0042] FIG2 is a schematic diagram of the structure of a biometric identification device of a biometric identification-based secure access switching device according to the present invention;
[0043] FIG3 is a schematic structural diagram of an external registration device of a biometric-based secure access switching device according to the present invention.
[0044] First adapter 10
[0045] Second adapter 20
[0046] Biometric identification device 30; authorization memory 31; fingerprint collection sensor 32; fingerprint identification module 33; duplicate fingerprint detection device 34; fake fingerprint detection device 35
[0047] Access control lock 40;
[0048] External registration device 50; fingerprint image acquisition device 51; fingerprint feature extraction device 52; fingerprint feature verification module 53. DETAILED DESCRIPTION
[0049] In the following description, specific details such as specific system structures and technologies are provided for illustration rather than limitation to facilitate a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application may be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid obstructing the description of the present application with unnecessary details.
[0050] It will be understood that when used in this specification and the appended claims, the term "comprising" indicates the presence of the described features, integers, steps, operations, elements and / or components, but does not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or collections.
[0051] To simplify the drawings, only the parts relevant to the present invention are schematically depicted in each figure; they do not represent the actual structure of the product. Furthermore, to simplify the drawings and facilitate understanding, in some figures, only one component with the same structure or function is schematically depicted or labeled. As used herein, "one" refers not only to "only one" but also to "more than one."
[0052] It should be further understood that the term "and / or" used in this specification and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.
[0053] In addition, in the description of the present application, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.
[0054] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the specific embodiments of the present invention will be described below with reference to the accompanying drawings. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings and other embodiments can be obtained based on these drawings without inventive work.
[0055] Example 1:
[0056] As shown in FIG1 , this embodiment provides a biometric-based secure access switching device, including:
[0057] The first transfer interface 10 is connected to the instruction issuing device and is used to receive the access instruction of the instruction issuing device;
[0058] The second transfer interface 20 is connected to the instruction receiving device and is used to send the access instruction to the instruction receiving device;
[0059] Biometric identification device 30, used to obtain biometric identification information and generate corresponding user access rights;
[0060] The access control lock 40 is used to control the transmission of the access instruction between the first transfer interface 10 and the second transfer interface 20 according to the user access rights.
[0061] With the development of science and technology, USB devices have become an indispensable part of our daily lives. However, the security issues of USB devices are becoming increasingly prominent, especially for USB devices that store sensitive data. How to prevent unauthorized access has become an important issue. Most of the USB hubs currently on the market do not have security protection functions, or the security protection functions are weak, and cannot effectively prevent computers from arbitrarily accessing sensitive data in USB devices. Although there are some methods on the market that can be used to prevent computers from arbitrarily accessing sensitive data in USB devices, such as the built-in permission management module in the NFTS system, and technical solutions such as CN204613946U, the former requires changes at the original USB device level, while the latter controls access through encryption, which adds inconvenience to the access control itself.
[0062] Therefore, in this embodiment, the control of instructions between two independent devices is applied. For example, when a computer accesses a file stored on another computer through an adapter, it connects to the first adapter 10 and then sends an access instruction through the first adapter 10. The biometric identification device 30 controls the opening and closing of the access control lock 40 based on the user's biometric information and the user access rights stored in the device, thereby controlling the transmission of instructions between the first adapter 10 and the second adapter 20. When the corresponding user has the corresponding user access rights, the access instruction is allowed to be transmitted from the first adapter 10 to the second adapter 20. If the corresponding user does not have the corresponding access rights, the access instruction is not allowed. At the same time, during specific use, a physical interface can be either the first adapter 10 or the second adapter 20. The status and function of the first adapter 10 and the second adapter 20 can also be converted to each other. During specific use, it can be set according to actual conditions. This embodiment only describes the functions. In terms of the selection of physical devices, the access control lock 40 can be directly implemented using the access control functions of the file system including NFTS, and the above functions such as read and write access control can be realized by using the relevant modules of the above file system on the access control lock 40 itself.
[0063] In this embodiment, access control is achieved through a switching device that is independent of the original hardware and software and through biometric identification. On the one hand, the original device does not need to be modified, and on the other hand, encryption is not required, thereby improving the convenience of device use.
[0064] In a preferred embodiment, the first adapter interface 10 and / or the second adapter interface 20 is selected from one of USB, Type-C, and SATA; and the number of the first adapter interface 10 and / or the second adapter interface 20 is multiple.
[0065] In actual use, the adapter can be set to a universal interface such as USB, Type-C, SATA, etc., making it compatible with most types of devices. It can be used to modify existing devices. For example, installing the adapter on an existing computer can prevent unauthorized external devices from reading and writing. At the same time, it can also be installed on existing mobile storage media such as USB flash drives, forcing unauthorized computers to be unable to access mobile storage media such as USB flash drives.
[0066] By using common universal interfaces, there is no need to change the original device interfaces, which improves the versatility of the device while maintaining the original functions.
[0067] In a preferred embodiment, the access control lock 40 is also used to monitor whether the first adapter 10 receives the access instruction; the first adapter 10 is also used to issue a biometric instruction to the instruction issuing device; when the access control lock 40 monitors that the first adapter 10 receives the access instruction of the instruction issuing device, it issues the biometric instruction to the instruction issuing device through the first adapter 10, waits for the user access rights, and determines whether to allow the access instruction to be transmitted to the second adapter 20 based on the user access rights.
[0068] In the specific process, the general process is as follows:
[0069] The access instruction of the instruction issuing device is received through the first adapter 10; when the access control lock 40 detects that the first adapter 10 has received the access instruction of the instruction issuing device, the biometric instruction is sent to the instruction issuing device through the first adapter 10; the instruction issuing device sends a biometric reminder to the user to remind the user to use the biometric device 30 to input biometric information, which can be fingerprint, iris, or face recognition, etc.; the access control lock 40 determines whether to allow the access instruction to be transmitted to the second adapter 20 based on the user access rights; when allowed, the second adapter 20 sends the access instruction received by the first adapter 10 to the instruction receiving device. If not allowed, the information of denying access is sent to the instruction issuing device through the first adapter.
[0070] At the same time, according to actual needs, when the device establishes a connection with the instruction receiving device and the sending device, a biometric reminder can be sent to the instruction sending device, allowing the user to enter the corresponding user identification information when using it, so that the user can obtain permission before accessing the file without the need for authentication when using it, thereby improving its efficiency.
[0071] In this embodiment, the authorization upon access is used to improve the security of the storage device on the one hand, and on the other hand, the user can be clearly informed of the file access status through the reminder method, thereby improving transparency.
[0072] In a preferred embodiment, as shown in Figures 1, 2, and 3, the biometric recognition device 30 is a fingerprint recognition device, which specifically includes: an authority memory 31 for storing user fingerprint information; a fingerprint acquisition sensor 32 for acquiring fingerprint images; and a fingerprint recognition module 33 for comparing the fingerprint image with the user fingerprint template to determine the corresponding user access rights.
[0073] In this preferred embodiment, biometric identification is generally performed using fingerprint recognition. This approach allows the adapter to be relatively small, requiring only a flat surface the size of a fingertip to accommodate the fingerprint, thereby reducing the overall size of the device. Furthermore, because fingerprint recognition requires relatively little computing power, the user's fingerprint template can be directly stored locally on the adapter, and then the fingerprint recognition device's built-in chip performs calculations to obtain the corresponding user access rights.
[0074] This embodiment uses fingerprint recognition to reduce the size of the biometric recognition device 30 and effectively improve the accuracy of biometric recognition without requiring additional computing resources.
[0075] Further preferably, the biometric identification device 30 further comprises a repeated fingerprint detection device 34 for detecting repeated fingerprints. The biometric identification device 30 further comprises a false fingerprint detection device 35 for detecting repeated false fingerprints.
[0076] In this further preferred embodiment, some mechanisms are used to prevent brute force attacks on the fingerprint detection device, such as detecting duplicate fingerprints, detecting fake fingerprints, etc., so as to prevent brute force attacks on the fingerprint detection device and increase security.
[0077] Preferably, the system further includes: an external registration device 50 for writing the biometric information and the corresponding user access rights into the biometric recognition device 30. The biometric information is a fingerprint, and the external registration device 50 specifically includes: a fingerprint image acquisition device 51 for acquiring the user fingerprint image; a fingerprint feature extraction device 52 for performing feature extraction on the user fingerprint image to form the user fingerprint template and store it in the permission memory 31; and a fingerprint feature verification module 53 for acquiring the user fingerprint image and comparing it with the corresponding user fingerprint template to verify the correctness of the user fingerprint template.
[0078] In this embodiment, when a new user wants to use the adapter device, he needs to connect the adapter device to the computer. He can directly use the first adapter interface 10 or the second adapter interface 20 to connect to the computer, and then use the first adapter interface 10 or the second adapter interface 20 to realize communication between the computer and the biometric device 30, and then use the management software on the computer to write biometric information and corresponding user access rights to the biometric device 30.
[0079] During specific use, the user's biometric information can be fingerprints. During registration, a fingerprint collector is connected to the computer to collect the user's fingerprint. The fingerprint collector then uses a fingerprint recognition algorithm to extract features from the collected fingerprint data, extracting unique fingerprint features such as key points and lines, and then forming a unique fingerprint template. This is then written into the biometric recognition device 30. The user then compares the written user fingerprint template with the adapter or external fingerprint collector to determine whether the user's fingerprint template is correct. If it is incorrect, the corresponding template is re-entered, thereby improving the security factor of the device.
[0080] In the subsequent use process, the authorization method is similar to the entry process. The user enters the user's fingerprint image through the biometric device 30, and then the biometric device 30 compares the user's fingerprint image with the fingerprint template through the fingerprint recognition algorithm, and determines whether the corresponding user authority should be granted based on the final comparison result.
[0081] Further preferably, the access control lock 40 further includes a self-locking module for entering a self-locking state when the biometric recognition device 30 fails to match the corresponding user access rights for multiple times;
[0082] In the self-locking state, the access control lock 40 controls the transmission of all access instructions between the first transfer interface 10 and the second transfer interface 20 until the external registration device 50 rewrites the user fingerprint information and the corresponding user access rights into the permission memory 31.
[0083] In this preferred embodiment, the adapter is equipped with a function that automatically locks after a certain number of failed authentication attempts. When the set number of failed authentication attempts is reached, the adapter enters a locked state, requiring re-authorization to unlock. This requires connecting the adapter to a computer and re-writing the user's fingerprint template into the biometric recognition device 30 through the management software.
[0084] In this embodiment, by setting the self-locking mode, the risk of brute force cracking can be effectively reduced, thereby improving the security of the device and reducing the risk of data leakage.
[0085] The present invention has achieved the following through the above embodiments:
[0086] (1) Access control is achieved through a switching device that is independent of the original hardware and software, using biometric identification. This allows the original device to remain unchanged and encryption is not required, thereby improving the convenience of device use.
[0087] (2) By authorizing access at the time of access, the security of the storage device is improved on the one hand, and on the other hand, the user can be clearly informed of the file access status through reminders, thereby improving transparency;
[0088] (3) By using fingerprint recognition, the size of the biometric recognition device 30 can be compressed, and the accuracy of biometric recognition can be effectively improved without requiring additional computing resources;
[0089] (4) Adopting some mechanisms to prevent brute force attacks on fingerprint detection devices, such as detecting duplicate fingerprints, detecting fake fingerprints, etc., thereby preventing brute force attacks on fingerprint detection devices and increasing security;
[0090] (5) By setting the self-locking mode, the risk of brute force cracking can be effectively reduced, thereby improving the security of the device and reducing the risk of data leakage;
[0091] (6) By using common universal interfaces, there is no need to change the original device interfaces, thereby improving the versatility of the equipment.
[0092] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.
[0093] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.
Claims
1. A secure access switching device based on biometrics, characterized in that: include: A first transfer interface, connected to the instruction issuing device, for receiving an access instruction from the instruction issuing device; A second transfer interface, connected to an instruction receiving device, and used to send the access instruction to the instruction receiving device; A biometric device for obtaining biometric information and generating corresponding user access rights; An access control lock is used to control the transmission of the access instruction between the first transfer interface and the second transfer interface according to the user access rights.
2. A biometric-based secure access switching device according to claim 1, characterized in that: The access control lock is also used to monitor whether the first transfer interface receives the access instruction; The first adapter is also used to issue a biometric identification instruction to the instruction issuing device; When the access control lock monitors that the first adapter receives the access instruction from the instruction issuing device, it sends the biometric instruction to the instruction issuing device through the first adapter, waits for the user access rights, and determines whether to allow the access instruction to be transmitted to the second adapter based on the user access rights.
3. The biometric-based secure access switching device according to claim 1, characterized in that: The biometric identification device is a fingerprint identification device, specifically comprising: Permission storage device, used to store user fingerprint information; Fingerprint collection sensor, used for collecting fingerprint images; The fingerprint recognition module is used to compare the fingerprint image with the user fingerprint template to determine the corresponding user access rights.
4. A biometric-based security access switching device according to claim 3, characterized in that the biometric device also includes a duplicate fingerprint detection device for detecting duplicate fingerprints.
5. The biometric-based secure access switching device according to claim 3, characterized in that: The biometric identification device also includes a false fingerprint detection device for detecting repeated false fingerprints.
6. The biometric-based secure access switching device according to claim 1, characterized in that: Also includes: The external registration device is used to write the biometric information and the corresponding user access rights into the biometric device.
7. The biometric-based secure access switching device according to claim 6, characterized in that: The access control lock further comprises a self-locking module, which is used to enter a self-locking state when the biometric identification device fails to match the corresponding user access rights for multiple times; In the self-locking state, the access control lock controls the transmission of all the access instructions between the first transfer interface and the second transfer interface until the external registration device re-writes the user fingerprint information and the corresponding user access rights into the permission storage.
8. The biometric-based secure access switching device according to claim 6, characterized in that: The biometric information is a fingerprint, and the external registration device specifically includes: A fingerprint image acquisition device, used to obtain the user's fingerprint image; A fingerprint feature extraction device, used for extracting features from the user fingerprint image to form the user fingerprint template, and storing it in the authority storage; The fingerprint feature verification module is used to obtain the user fingerprint image and compare it with the corresponding user fingerprint template to verify the correctness of the user fingerprint template.
9. The biometric-based secure access switching device according to claim 1, characterized in that: The first adapter interface and / or the second adapter interface is selected from one of USB, Type-C, and SATA.
10. The biometric-based secure access switching device according to claim 1, characterized in that: The number of the first adapter and / or the second adapter is multiple.
Citation Information
Patent Citations
High-security radio frequency fingerprint U disk and secure implementation method
CN108985427A
External terminal protection device with user tracing function and protection system
CN111898105A
External terminal protection equipment and protection system comprising identity information verification
CN111898167A
User data protection method for secure computer
CN112905976A
Secure access switching device based on biological recognition
CN117494237A