[go: up one dir, main page]

CN109753779B - A network-wide unified identity authentication method and system based on biometric identification - Google Patents

A network-wide unified identity authentication method and system based on biometric identification Download PDF

Info

Publication number
CN109753779B
CN109753779B CN201910027728.6A CN201910027728A CN109753779B CN 109753779 B CN109753779 B CN 109753779B CN 201910027728 A CN201910027728 A CN 201910027728A CN 109753779 B CN109753779 B CN 109753779B
Authority
CN
China
Prior art keywords
user
trust server
identification information
information
authenticated
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
CN201910027728.6A
Other languages
Chinese (zh)
Other versions
CN109753779A (en
Inventor
蒋文保
史博轩
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Beijing Information Science and Technology University
Original Assignee
Beijing Information Science and Technology University
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Beijing Information Science and Technology University filed Critical Beijing Information Science and Technology University
Priority to CN201910027728.6A priority Critical patent/CN109753779B/en
Publication of CN109753779A publication Critical patent/CN109753779A/en
Application granted granted Critical
Publication of CN109753779B publication Critical patent/CN109753779B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Collating Specific Patterns (AREA)

Abstract

本发明提供了一种基于生物特征识别的全网统一身份认证方法及系统,其中方法包括:被认证端采集用户的生物特征,并向认证端发送认证请求;被认证端将第一采集信息发送至被认证端本地信任服务器;被认证端本地信任服务器如果查询到用户ID标识信息,则比对用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果发送至认证端;被认证端本地信任服务器如果没有查询到用户ID标识信息,则向信任锚子系统查询用户ID标识信息,信任锚子系统中的权限信任服务器将用户认证生物特征信息发送至被认证端本地信任服务器,被认证端本地信任服务器得到比对结果发送至认证端;认证端根据认证请求以及比对结果进行是否认证通过的判断。

Figure 201910027728

The present invention provides a network-wide unified identity authentication method and system based on biometric identification, wherein the method includes: an authenticated end collects a user's biometrics, and sends an authentication request to the authenticating end; the authenticated end sends the first collected information To the local trust server of the authenticated end; if the local trust server of the authenticated end queries the user ID identification information, it compares whether the biometric information of the user to be authenticated is consistent with the biometric information of the user authentication, and obtains the comparison result and sends it to the authentication end; If the authenticating end local trust server does not query the user ID identification information, it queries the trust anchor subsystem for the user ID identification information, and the authority trust server in the trust anchor subsystem sends the user authentication biometric information to the authenticated end local trust server, The local trust server of the authenticated end obtains the comparison result and sends it to the authenticating end; the authenticating end judges whether the authentication is passed according to the authentication request and the comparison result.

Figure 201910027728

Description

一种基于生物特征识别的全网统一身份认证方法及系统A network-wide unified identity authentication method and system based on biometric identification

技术领域technical field

本发明涉及通信领域,尤其涉及一种基于生物特征识别的全网统一身份认证方法及系统。The invention relates to the field of communications, in particular to a method and system for unified identity authentication of the entire network based on biometric identification.

背景技术Background technique

生物特征具有唯一性和永久性,每个人的生物特征都是相当固定的,很难发生变化等,可以把一个人同他的生物特征对应起来,通过比较生物特征特征和预先保存的生物特征特征,就可以验证其真实身份。由此可见,生物特征识别技术是目前最方便、可靠的生物特征识别技术解决方案,在大规模应用方面有着很大的潜力。从广泛的意义上来说,需要进行身份认证的系统和产品都可以应用生物特征识别装置,目前在金融、门禁、户籍等多个领域都有广泛的应用。Biometrics are unique and permanent, each person's biometrics are quite fixed and difficult to change, etc. A person can be matched with his biometrics, by comparing the biometrics with the pre-saved biometrics , you can verify its true identity. It can be seen that biometric identification technology is currently the most convenient and reliable biometric identification technology solution, and has great potential in large-scale applications. In a broad sense, biometric identification devices can be applied to systems and products that require identity authentication, and are currently widely used in many fields such as finance, access control, and household registration.

在公钥密码体制下,公钥数字签名技术需依赖公钥基础设施(PKI)颁发的CA证书绑定实体身份和公钥,以保证实体公钥的真实性。以公钥证书的形式将用户公钥和用户身份进行绑定,形成了解决网络安全问题的成熟方案。但是,PKI通过引入可信第三方CA,由此带来证书的管理、存储和计算上的代价:一是证书的签发、发布、获取、验证、撤销等,流程较为复杂;二是需要在线的证书目录为用户随时提供证书下载和状态查询服务,增加了维护开销;三是如果用户通信的对象比较多,用户必须在本地存储和管理这些证书,增加了用户端使用开销;四是大规模密钥管理的问题一般是采用物理上增加CA的方法,而且各个CA的用户之间还存在交叉认证和信任管理的问题。Under the public key cryptosystem, the public key digital signature technology relies on the CA certificate issued by the public key infrastructure (PKI) to bind the entity identity and public key to ensure the authenticity of the entity public key. Binding the user's public key to the user's identity in the form of a public key certificate forms a mature solution to network security issues. However, PKI introduces a trusted third-party CA, which brings costs in the management, storage and calculation of certificates: first, the issuance, issuance, acquisition, verification, and revocation of certificates are complicated; second, online The certificate directory provides users with certificate download and status query services at any time, which increases maintenance overhead; third, if the user communicates with many objects, the user must store and manage these certificates locally, which increases the user-side usage overhead; fourth, large-scale encryption The problem of key management is generally to use the method of adding CAs physically, and there are also problems of cross-certification and trust management among the users of each CA.

发明内容SUMMARY OF THE INVENTION

本发明旨在至少克服上述缺陷之一提供一种基于生物特征识别的全网统一身份认证方法及系统。The present invention aims to overcome at least one of the above-mentioned defects and provide a method and system for unified identity authentication of the whole network based on biometric identification.

为达到上述目的,本发明的技术方案具体是这样实现的:In order to achieve the above object, the technical scheme of the present invention is specifically realized in this way:

本发明的一个方面提供了一种基于生物特征识别的全网统一身份认证方法,包括:被认证端通过生物特征采集器采集用户的生物特征,得到用户待认证生物特征信息,并向认证端发送认证请求;被认证端将第一采集信息发送至被认证端本地信任服务器,其中,第一采集信息包括用户ID标识信息、被认证端标识地址信息和用户待认证生物特征信息;被认证端本地信任服务器如果查询到用户ID标识信息,则比对用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果通过信任锚子系统发送至认证端,其中,用户认证生物特征信息为与用户ID标识信息对应的真实的用户的生物特征信息;被认证端本地信任服务器如果没有查询到用户ID标识信息,则向信任锚子系统查询用户ID标识信息,如果信任锚子系统查询到用户ID标识信息,则信任锚子系统中的权限信任服务器将用户认证生物特征信息发送至被认证端本地信任服务器,被认证端本地信任服务器比对用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端;认证端根据认证请求以及比对结果进行是否认证通过的判断。One aspect of the present invention provides a network-wide unified identity authentication method based on biometric identification. Authentication request; the authenticated terminal sends the first collection information to the local trust server of the authenticated terminal, wherein the first collection information includes user ID identification information, the identification address information of the authenticated terminal, and the biometric information of the user to be authenticated; the authenticated terminal local If the trust server finds the user ID identification information, it compares the user's biometric information to be authenticated with the user authentication biometric information, obtains the comparison result, and sends the comparison result to the authentication terminal through the trust anchor subsystem, wherein the user The authentication biometric information is the biometric information of the real user corresponding to the user ID identification information; if the authenticated local trust server does not query the user ID identification information, it will query the trust anchor subsystem for the user ID identification information, if the trust anchor When the subsystem queries the user ID identification information, the authority trust server in the trust anchor subsystem sends the user authentication biometric information to the authenticated end local trust server, and the authenticated end local trust server compares the user's biometric information to be authenticated with the user's biometric information. Verify whether the biometric information is consistent, obtain the comparison result, and send the comparison result to the authentication end; the authentication end judges whether the authentication is passed according to the authentication request and the comparison result.

其中,方法还包括:被认证端通过生物特征采集器采集用户的生物特征,得到用户认证生物特征信息;被认证端将第二采集信息发送至被认证端本地信任服务器,其中,第二采集信息包括用户ID标识信息、被认证端标识地址信息和用户认证生物特征信息;被认证端本地信任服务器将第二采集信息发送至信任锚子系统;信任锚子系统中的权限信任服务器获取第二采集信息,并存储第二采集信息。The method further includes: the authenticated end collects the biometric features of the user through a biometric collector to obtain user authentication biometric information; the authenticated end sends the second collected information to the authenticated end local trust server, wherein the second collected information Including user ID identification information, authenticated end identification address information and user authentication biometric information; the authenticated end local trust server sends the second collection information to the trust anchor subsystem; the authority trust server in the trust anchor subsystem obtains the second collection information information, and store the second collection information.

其中,被认证端本地信任服务器将第二采集信息发送至信任锚子系统;信任锚子系统中的权限信任服务器获取第二采集信息,并存储第二采集信息包括:被认证端本地信任服务器根据用户ID标识信息比对信任锚子系统中的被认证端本地信任服务器连接的权限信任服务器的地址是否为与用户ID标识信息对应的权限信任服务器;如果是,则被认证端本地信任服务器将第二采集信息发送至被认证端本地信任服务器连接的权限信任服务器;被认证端本地信任服务器连接的权限信任服务器获取第二采集信息,并存储第二采集信息。Wherein, the local trust server of the authenticated end sends the second collection information to the trust anchor subsystem; the authority trust server in the trust anchor subsystem obtains the second collection information, and stores the second collection information, including: the local trust server of the authenticated end according to Check whether the address of the authority trust server connected to the local trust server of the authenticated end in the trust anchor subsystem is compared with the user ID identification information is the authority trust server corresponding to the user ID identification information; if so, the local trust server of the authenticated end will The second collection information is sent to the authority trust server connected to the local trust server of the authenticating end; the authority trust server connected to the local trust server of the authenticating end acquires the second collection information, and stores the second collection information.

其中,被认证端本地信任服务器将第二采集信息发送至信任锚子系统;信任锚子系统中的权限信任服务器获取第二采集信息,并存储第二采集信息包括:被认证端本地信任服务器根据用户ID标识信息比对信任锚子系统中的被认证端本地信任服务器连接的权限信任服务器的地址是否为与用户ID标识信息对应的权限信任服务器;如果不是,被认证端则比对权限信任服务器连接的顶级信任服务器的地址是否为与用户ID标识信息对应的顶级信任服务器;如果不是,则向与顶级权限服务器连接的根信任服务器进行访问,根信任服务器根据用户ID标识信息找到与用户ID标识信息对应的顶级信任服务器,并从与用户ID标识信息对应的顶级信任服务器进行访问,找到与用户ID标识信息对应的权限信任服务器,将第二采集信息发送至与用户ID标识信息对应的权限信任服务器;与用户ID标识信息对应的权限信任服务器获取第二采集信息,并存储第二采集信息。Wherein, the local trust server of the authenticated end sends the second collection information to the trust anchor subsystem; the authority trust server in the trust anchor subsystem obtains the second collection information, and stores the second collection information, including: the local trust server of the authenticated end according to User ID identification information is compared to the authority trust server in the trust anchor subsystem to which the local trust server of the authenticated end is connected, whether the address of the authority trust server is the authority trust server corresponding to the user ID identification information; if not, the authenticated end compares the authority trust server Whether the address of the connected top-level trust server is the top-level trust server corresponding to the user ID identification information; if not, access the root trust server connected to the top-level authority server, and the root trust server finds the user ID identification information according to the user ID identification information. The top-level trust server corresponding to the information, and access from the top-level trust server corresponding to the user ID identification information, find the authority trust server corresponding to the user ID identification information, and send the second collection information to the authority trust corresponding to the user ID identification information. server; the authority trust server corresponding to the user ID identification information obtains the second collection information, and stores the second collection information.

其中,被认证端本地信任服务器如果没有查询到用户ID标识信息,则向信任锚子系统查询用户ID标识信息,如果信任锚子系统查询到用户ID标识信息,则信任锚子系统中的权限信任服务器将用户认证生物特征信息发送至被认证端本地信任服务器,被认证端本地信任服务器比对用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端包括:被认证端本地信任服务器如果没有查询到用户ID标识信息,则向信任锚子系统中的与认证端本地信任服务器连接的权限信任服务器查询用户ID标识信息,如果在权限信任服务器上查询到用户ID标识信息,则由与权限信任服务器连接的与用户ID标识信息对应的本地信任服务器对比用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端;如果在权限信任服务器上没有查询到用户ID标识信息,则向与权限信任服务器连接的顶级信任服务器查询用户ID标识信息,如果在顶级信任服务器下的权限信任服务器上查询到用户ID标识信息,则由与顶级信任服务器下的权限信任服务器连接的存有用户ID标识信息的本地信任服务器对比用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端;如果在顶级信任服务器下的权限信任服务器上没有查询到用户ID标识信息,则向与顶级信任服务器连接的根信任服务器查询用户ID标识信息,如果根信任服务器下的权限信任服务器上存有用户ID标识信息,则通过根信任服务器向与根信任服务器连接的存储有用户ID标识信息的顶级信任服务器向存储有用户ID标识信息的权限信任服务器进行查询,在存储有用户ID标识信息的权限信任服务器查询到用户认证生物特征信息时,由与存储有用户ID标识信息的权限信任服务器连接的本地信任服务器对比用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端。Among them, if the local trust server of the authenticated end does not query the user ID identification information, it queries the trust anchor subsystem for the user ID identification information. If the trust anchor subsystem queries the user ID identification information, the authority trusts in the trust anchor subsystem The server sends the user authentication biometric information to the local trust server of the authenticated side, and the local trust server of the authenticated side compares the biometric information of the user to be authenticated with the user authentication biometric information, obtains the comparison result, and sends the comparison result to The authenticating end includes: if the local trust server of the authenticated end does not query the user ID identification information, it will query the user ID identification information from the authority trust server connected with the authenticating end local trust server in the trust anchor subsystem. When the user ID identification information is queried, the local trust server connected to the authority trust server and corresponding to the user ID identification information compares whether the biometric information of the user to be authenticated is consistent with the biometric information for authentication of the user, and obtains the comparison result. Send it to the authentication terminal; if the user ID identification information is not queried on the authority trust server, query the user ID identification information from the top-level trust server connected to the authority trust server. If the user ID information is queried on the authority trust server under the top-level trust server ID identification information, then the local trust server connected with the authority trust server under the top-level trust server and storing the user ID identification information compares whether the biometric information of the user to be authenticated is consistent with the biometric information for user authentication, and obtains the comparison result. The result is sent to the authentication terminal; if the user ID identification information is not queried on the authority trust server under the top-level trust server, the user ID identification information is queried from the root trust server connected to the top-level trust server. The user ID identification information is stored on the trust server, and the root trust server is used to query the top-level trust server that stores the user ID identification information connected to the root trust server to the authority trust server that stores the user ID identification information. When the authority trust server of the ID identification information queries the user authentication biometric information, the local trust server connected to the authority trust server storing the user ID identification information compares whether the user biometric information to be authenticated is consistent with the user authentication biometric information, and obtains The comparison result is sent to the authentication terminal.

其中,被认证端本地信任服务器如果没有查询到用户ID标识信息,则向信任锚子系统查询用户ID标识信息,如果信任锚子系统查询到用户ID标识信息,则信任锚子系统中的权限信任服务器将用户认证生物特征信息发送至被认证端本地信任服务器,被认证端本地信任服务器比对用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端包括:被认证端本地信任服务器如果没有查询到用户ID标识信息,则通过迭代查询,向被认证端本地信任服务器上级的根信任服务器请求查询用户ID标识信息,如果在根信任服务器上查询到用户ID标识信息,则返回用户ID标识信息所属的顶级信任服务器的地址,被认证端本地信任服务器向用户ID标识信息所属的顶级信任服务器请求查询用户ID标识信息,如果在顶级信任服务器上查询到用户ID标识信息,则返回用户ID标识信息所属的权限信任服务器的地址,被认证端本地信任服务器向用户ID标识信息所属的权限信任服务器请求查询用户ID标识信息,如果在权限信任服务器上查询到用户ID标识信息,则返回给被认证端本地信任服务器与用户ID标识信息对应的用户认证生物特征信息,被认证端本地信任服务器对比用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端。Among them, if the local trust server of the authenticated end does not query the user ID identification information, it queries the trust anchor subsystem for the user ID identification information. If the trust anchor subsystem queries the user ID identification information, the authority trusts in the trust anchor subsystem The server sends the user authentication biometric information to the local trust server of the authenticated side, and the local trust server of the authenticated side compares the biometric information of the user to be authenticated with the user authentication biometric information, obtains the comparison result, and sends the comparison result to The authenticating end includes: if the local trust server of the authenticated end does not query the user ID identification information, it will make an iterative query to request the upper-level root trust server of the authenticated end local trust server to query the user ID identification information. To the user ID identification information, the address of the top-level trust server to which the user ID identification information belongs is returned, and the local trust server of the authenticated end requests the top-level trust server to which the user ID identification information belongs to query the user ID identification information. If the top-level trust server is queried To the user ID identification information, the address of the authority trust server to which the user ID identification information belongs is returned, and the local trust server of the authenticated end requests the authority trust server to which the user ID identification information belongs to query the user ID identification information. to the user ID identification information, then return to the authenticated end local trust server and the user authentication biometric information corresponding to the user ID identification information, and the authenticated end local trust server compares the user to be authenticated. The comparison result is obtained, and the comparison result is sent to the authentication terminal.

本发明另一方面提供了一种基于生物特征识别的全网统一身份认证系统,包括:被认证端、认证端以及信任锚子系统;其中:信任锚子系统至少包括被认证端本地信任服务器;被认证端,用于通过生物特征采集器采集用户的生物特征,得到用户待认证生物特征信息,并向认证端发送认证请求;被认证端,还用于将第一采集信息发送至被认证端本地信任服务器,其中,第一采集信息包括用户ID标识信息、被认证端标识地址信息和用户待认证生物特征信息;被认证端本地信任服务器,用于如果查询到用户ID标识信息,则比对用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果通过信任锚子系统发送至认证端,其中,用户认证生物特征信息为与用户ID标识信息对应的真实的用户的生物特征信息;被认证端本地信任服务器,还用于如果没有查询到用户ID标识信息,则向信任锚子系统查询用户ID标识信息,如果信任锚子系统查询到用户ID标识信息,则信任锚子系统中的权限信任服务器将用户认证生物特征信息发送至被认证端本地信任服务器,被认证端本地信任服务器比对用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端;认证端,用于根据认证请求以及比对结果进行是否认证通过的判断。Another aspect of the present invention provides a network-wide unified identity authentication system based on biometric identification, including: an authenticated end, an authenticating end, and a trust anchor subsystem; wherein: the trust anchor subsystem at least includes a local trust server of the authenticated end; The authenticated end is used to collect the biometrics of the user through the biometric collector, obtain the biometric information of the user to be authenticated, and send an authentication request to the authenticating end; the authenticated end is also used to send the first collected information to the authenticated end Local trust server, wherein the first collection information includes user ID identification information, authenticated end identification address information and user biometric information to be authenticated; the authenticated end local trust server is used to compare the user ID identification information if the user ID identification information is queried. Whether the user's biometric information to be authenticated is consistent with the user authentication biometric information, a comparison result is obtained, and the comparison result is sent to the authentication terminal through the trust anchor subsystem, wherein the user authentication biometric information is the real information corresponding to the user ID identification information. The biometric information of the user; the local trust server of the authenticated end is also used to query the user ID identification information from the trust anchor subsystem if the user ID identification information is not queried, and if the trust anchor subsystem queries the user ID identification information, Then the authority trust server in the trust anchor subsystem sends the user authentication biometric information to the authenticated end local trust server, and the authenticated end local trust server compares the user biometric information to be authenticated with the user authentication biometric information, and obtains a comparison. As for the result, the comparison result is sent to the authentication terminal; the authentication terminal is used for judging whether the authentication is passed according to the authentication request and the comparison result.

其中,信任锚子系统还包括:权限信任服务器;被认证端,还用于通过生物特征采集器采集用户的生物特征,得到用户认证生物特征信息;被认证端,还用于将第二采集信息发送至被认证端本地信任服务器,其中,第二采集信息包括用户ID标识信息、被认证端标识地址信息和用户认证生物特征信息;被认证端本地信任服务器,还用于将第二采集信息发送至信任锚子系统;信任锚子系统中的权限信任服务器,用于获取第二采集信息,并存储第二采集信息。Wherein, the trust anchor subsystem further includes: an authority trust server; the authenticated end is also used to collect the biometrics of the user through the biometric collector to obtain the user authentication biometric information; the authenticated end is also used to collect the second collected information Sent to the authenticated end local trust server, wherein the second collection information includes user ID identification information, authenticated end identification address information and user authentication biometric information; the authenticated end local trust server is also used to send the second collection information to the trust anchor subsystem; the authority trust server in the trust anchor subsystem is used to acquire the second collection information and store the second collection information.

其中,被认证端本地信任服务器,具体用于根据用户ID标识信息比对信任锚子系统中的被认证端本地信任服务器连接的权限信任服务器的地址是否为与用户ID标识信息对应的权限信任服务器;如果是,则将第二采集信息发送至被认证端本地信任服务器连接的权限信任服务器;被认证端本地信任服务器连接的权限信任服务器,具体用于获取第二采集信息,并存储第二采集信息。Wherein, the local trust server of the authenticated end is specifically used to compare whether the address of the authority trust server connected to the local trust server of the authenticated end in the trust anchor subsystem is the authority trust server corresponding to the user ID identification information according to the user ID identification information. If yes, then the second collection information is sent to the authority trust server connected by the authenticated end local trust server; the authority trust server connected by the authenticated end local trust server is specifically used to obtain the second collection information, and store the second collection information.

其中,被认证端本地信任服务器,具体用于根据用户ID标识信息比对信任锚子系统中的被认证端本地信任服务器连接的权限信任服务器的地址是否为与用户ID标识信息对应的权限信任服务器;如果不是,则比对权限信任服务器连接的顶级信任服务器的地址是否为与用户ID标识信息对应的顶级信任服务器;如果不是,则向与顶级权限服务器连接的根信任服务器进行访问,根信任服务器根据用户ID标识信息找到与用户ID标识信息对应的顶级信任服务器,并从与用户ID标识信息对应的顶级信任服务器进行访问,找到与用户ID标识信息对应的权限信任服务器,将第二采集信息发送至与用户ID标识信息对应的权限信任服务器;与用户ID标识信息对应的权限信任服务器,具体用于获取第二采集信息,并存储第二采集信息。Wherein, the local trust server of the authenticated end is specifically used to compare whether the address of the authority trust server connected to the local trust server of the authenticated end in the trust anchor subsystem is the authority trust server corresponding to the user ID identification information according to the user ID identification information. ; if not, compare whether the address of the top-level trust server connected to the authority trust server is the top-level trust server corresponding to the user ID identification information; if not, access the root trust server connected to the top-level authority server, the root trust server Find the top-level trust server corresponding to the user ID identification information according to the user ID identification information, access from the top-level trust server corresponding to the user ID identification information, find the authority trust server corresponding to the user ID identification information, and send the second collection information to the authority trust server corresponding to the user ID identification information; the authority trust server corresponding to the user ID identification information is specifically used to obtain the second collection information and store the second collection information.

其中,被认证端本地信任服务器,具体用于如果没有查询到用户ID标识信息,则向信任锚子系统中的与认证端本地信任服务器连接的权限信任服务器查询用户ID标识信息,如果在权限信任服务器上查询到用户ID标识信息,则由与权限信任服务器连接的与用户ID标识信息对应的本地信任服务器对比用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端;如果在权限信任服务器上没有查询到用户ID标识信息,则向与权限信任服务器连接的顶级信任服务器查询用户ID标识信息,如果在顶级信任服务器下的权限信任服务器上查询到用户ID标识信息,则由与顶级信任服务器下的权限信任服务器连接的存有用户ID标识信息的本地信任服务器对比用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端;如果在顶级信任服务器下的权限信任服务器上没有查询到用户ID标识信息,则向与顶级信任服务器连接的根信任服务器查询用户ID标识信息,如果根信任服务器下的权限信任服务器上存有用户ID标识信息,则通过根信任服务器向与根信任服务器连接的存储有用户ID标识信息的顶级信任服务器向存储有用户ID标识信息的权限信任服务器进行查询,在存储有用户ID标识信息的权限信任服务器查询到用户认证生物特征信息时,由与存储有用户ID标识信息的权限信任服务器连接的本地信任服务器对比用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端。Among them, the local trust server of the authenticated end is specifically used to query the user ID identification information from the authority trust server in the trust anchor subsystem connected to the local trust server of the authenticating end if the user ID identification information is not queried. If the user ID identification information is queried on the server, the local trust server connected to the authority trust server and corresponding to the user ID identification information compares whether the biometric information of the user to be authenticated is consistent with the biometric information for authentication of the user, and obtains the comparison result. The result is sent to the authentication terminal; if the user ID identification information is not queried on the authority trust server, the user ID identification information is queried from the top-level trust server connected to the authority trust server. To the user ID identification information, the local trust server that is connected with the authority trust server under the top-level trust server and has the user ID identification information compares whether the biometric information of the user to be authenticated is consistent with the user authentication biometric information, and obtains the comparison result, Send the comparison result to the authentication terminal; if the user ID identification information is not queried on the authority trust server under the top-level trust server, query the user ID identification information from the root trust server connected to the top-level trust server. The user ID identification information is stored on the authority trust server, then the top-level trust server that stores the user ID identification information connected to the root trust server is queried to the authority trust server that stores the user ID identification information through the root trust server. When the authority trust server with the user ID identification information queries the user authentication biometric information, the local trust server connected to the authority trust server storing the user ID identification information compares whether the user biometric information to be authenticated is consistent with the user authentication biometric information. , get the comparison result, and send the comparison result to the authentication terminal.

其中,被认证端本地信任服务器,具体用于如果没有查询到用户ID标识信息,则通过迭代查询,向被认证端本地信任服务器上级的根信任服务器请求查询用户ID标识信息,如果在根信任服务器上查询到用户ID标识信息,则返回用户ID标识信息所属的顶级信任服务器的地址,被认证端本地信任服务器向用户ID标识信息所属的顶级信任服务器请求查询用户ID标识信息,如果在顶级信任服务器上查询到用户ID标识信息,则返回用户ID标识信息所属的权限信任服务器的地址,被认证端本地信任服务器向用户ID标识信息所属的权限信任服务器请求查询用户ID标识信息,如果在权限信任服务器上查询到用户ID标识信息,则返回给被认证端本地信任服务器与用户ID标识信息对应的用户认证生物特征信息,被认证端本地信任服务器对比用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端。Among them, the local trust server of the authenticated end is specifically used to request the root trust server of the upper level of the local trust server of the authenticated end to query the user ID identification information through iterative query if the user ID identification information is not queried. If the user ID identification information is queried on the Internet, the address of the top-level trust server to which the user ID identification information belongs is returned, and the local trust server of the authenticated end requests the top-level trust server to which the user ID identification information belongs to query the user ID identification information. If the user ID identification information is queried on the Internet, the address of the authority trust server to which the user ID identification information belongs is returned, and the local trust server of the authenticated end requests the authority trust server to which the user ID identification information belongs to query the user ID identification information. If the user ID identification information is queried, the user authentication biometric information corresponding to the user ID identification information is returned to the authenticated local trust server, and the authenticated local trust server compares the user biometric information to be authenticated with the user authentication biometric information. If they are consistent, the comparison result is obtained, and the comparison result is sent to the authentication terminal.

由上述本发明提供的技术方案可以看出,通过本发明实施例提供的基于生物特征识别的全网统一身份认证方法及系统,可以基于生物特征来进行全网统一的身份认证,从而有效的避免交叉认证等诸多问题,而通过用户的生物特征信息能够更加方便、可靠进行认证,同时,用户的生物特征信息在认证时,认证端无法获取到生物特征信息,只能获取到对比是否一致的信息,对比工作在信任锚子系统中的本地信任服务器中进行,保证隐私信息(用户生物特征信息)的安全性。It can be seen from the technical solutions provided by the present invention that, through the method and system for unified identity authentication of the whole network based on biometric identification provided by the embodiments of the present invention, the unified identity authentication of the whole network can be performed based on the biometric characteristics, thereby effectively avoiding There are many problems such as cross-certification, and the user's biometric information can be authenticated more conveniently and reliably. At the same time, when the user's biometric information is authenticated, the authentication end cannot obtain the biometric information, but can only obtain the information about whether the comparison is consistent. , the comparison work is carried out in the local trust server in the trust anchor subsystem to ensure the security of private information (user biometric information).

附图说明Description of drawings

为了更清楚地说明本发明实施例的技术方案,下面将对实施例描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域的普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他附图。In order to illustrate the technical solutions of the embodiments of the present invention more clearly, the following briefly introduces the accompanying drawings used in the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can also be obtained from these drawings without any creative effort.

图1为本发明实施例提供的基于生物特征识别的全网统一身份认证系统的结构示意图;1 is a schematic structural diagram of a network-wide unified identity authentication system based on biometric identification provided by an embodiment of the present invention;

图2为本发明实施例提供的基于生物特征识别的全网统一身份认证方法的流程图;FIG. 2 is a flowchart of a method for unified identity authentication for the entire network based on biometric identification provided by an embodiment of the present invention;

图3为本发明实施例提供的基于生物特征识别的全网统一身份认证方法中的生物特征采集的一种示意图;3 is a schematic diagram of biometric feature collection in a method for unified identity authentication based on biometric identification provided by an embodiment of the present invention;

图4为本发明实施例提供的基于生物特征识别的全网统一身份认证方法中的生物特征采集的另一种示意图;Fig. 4 is another schematic diagram of biometric feature collection in the method for unified identity authentication based on biometric identification provided by an embodiment of the present invention;

图5为本发明实施例提供的基于生物特征识别的全网统一身份认证方法中的认证的一种示意图;5 is a schematic diagram of authentication in a method for unified identity authentication based on biometric identification provided by an embodiment of the present invention;

图6为本发明实施例提供的基于生物特征识别的全网统一身份认证方法中的认证的另一种示意图。FIG. 6 is another schematic diagram of authentication in the method for unified identity authentication for the entire network based on biometric identification according to an embodiment of the present invention.

具体实施方式Detailed ways

下面结合附图对本发明的实施方式进行详细说明。The embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

图1为本发明实施例提供的基于生物特征识别的全网统一身份认证系统的结构示意图,参见图1,本发明实施例提供的基于生物特征识别的全网统一身份认证系统包括:FIG. 1 is a schematic structural diagram of a network-wide unified identity authentication system based on biometric identification provided by an embodiment of the present invention. Referring to FIG. 1 , the entire network unified identity authentication system based on biometric identification provided by an embodiment of the present invention includes:

信任锚子系统:用于管理各终端及其他网络设备的生物特征采集信息,生成用户ID标识信息,各终端的标识地址信息,同时可以为网络设备提供查询服务等功能。Trust Anchor Subsystem: It is used to manage the biometric collection information of each terminal and other network devices, generate user ID identification information, and the identification address information of each terminal, and at the same time, it can provide functions such as query services for network devices.

认证端:认证方需在认证端登录设备,进行被认证端的认证工作,被认证端只有在认证端通过身份认证才能被允许操作。Authentication end: The authenticating party needs to log in to the device at the authenticating end to perform the authentication of the authenticated end. The authenticated end can only be allowed to operate after passing the identity authentication at the authenticating end.

被认证端:包含带有生物特征采集器的网元设备,例如该生物特征采集器可以为指纹采集器,对用户的生物特征信息进行采集,通过本地信任服务器发送至信任锚子系统中的权限服务器进行存储。Authenticated end: includes a network element device with a biometric collector. For example, the biometric collector can be a fingerprint collector, which collects the user's biometric information and sends it to the authority in the trust anchor subsystem through the local trust server server for storage.

本发明中,生物特征可以为指纹、脸部、虹膜、声音特征的一种或其任意组合。In the present invention, the biometric feature can be one of fingerprint, face, iris, voice feature or any combination thereof.

在图1所示的基于生物特征识别的全网统一身份认证系统的架构下,图2示出了本发明实施例提供的基于生物特征识别的全网统一身份认证方法的流程图,参见图2,本发明实施例提供的基于生物特征识别的全网统一身份认证方法,包括:Under the framework of the network-wide unified identity authentication system based on biometric identification shown in FIG. 1 , FIG. 2 shows a flowchart of a biometric-based unified identity authentication method for the entire network provided by an embodiment of the present invention, see FIG. 2 , the biometric identification-based unified identity authentication method for the entire network provided by the embodiment of the present invention includes:

S201,被认证端通过生物特征采集器采集用户的生物特征,得到用户待认证生物特征信息,并向认证端发送认证请求。S201, the authenticated end collects the biometrics of the user through the biometrics collector, obtains the biometrics information of the user to be authenticated, and sends an authentication request to the authenticating end.

具体地,在被认证端请求认证的过程中,如图1所示,用户A可以通过生物特征采集器对生物特征进行采集。将采集到的生物特征信息转化为数字形式。例如:用户A可以通过指纹采集器采集用户的指纹。Specifically, in the process of requesting authentication by the authenticated end, as shown in FIG. 1 , user A can collect biometric features through a biometric feature collector. Convert the collected biometric information into digital form. For example, user A can collect the user's fingerprint through a fingerprint collector.

作为本发明实施例的一个可选实施方式中,在进行认证之前,还需获取与用户ID标识信息对应的真实的用户的生物特征信息。本发明实施例提供的基于生物特征识别的全网统一身份认证方法还包括:被认证端通过生物特征采集器采集用户的生物特征,得到用户认证生物特征信息;被认证端将第二采集信息发送至被认证端本地信任服务器,其中,第二采集信息包括用户ID标识信息、被认证端标识地址信息和用户认证生物特征信息;被认证端本地信任服务器将第二采集信息发送至信任锚子系统;信任锚子系统中的权限信任服务器获取第二采集信息,并存储第二采集信息。通过此种方式,可以将真实的用户的生物特征信息存储在信任锚子系统中的权限信任服务器中,保护真实的用户的生物特征信息的安全性。而权限信任服务器上存储的数据示例可以参考表1。As an optional implementation manner of the embodiment of the present invention, before authentication is performed, the biometric information of the real user corresponding to the user ID identification information needs to be obtained. The method for unified network-wide identity authentication based on biometric identification provided by the embodiment of the present invention further includes: the authenticated end collects the user's biometrics through a biometric collector to obtain user authentication biometric information; the authenticated end sends the second collected information to the authenticated end local trust server, wherein the second collection information includes user ID identification information, authenticated end identification address information and user authentication biometric information; the authenticated end local trust server sends the second collection information to the trust anchor subsystem ; the authority trust server in the trust anchor subsystem acquires the second collection information, and stores the second collection information. In this way, the biometric information of the real user can be stored in the authority trust server in the trust anchor subsystem, so as to protect the security of the biometric information of the real user. For an example of the data stored on the authority trust server, please refer to Table 1.

编号Numbering 用户ID标识信息User ID identification information 被认证端标识地址信息The identity address information of the authenticated terminal 用户的生物特征信息User's biometric information 11 D1D1 addr1addr1 Fingerprint1Fingerprint1 22 D2D2 addr2addr2 Fingerprint2Fingerprint2 33 ……... ……...

表1权限信任服务器上存储的数据示例Table 1 Examples of data stored on the authority trust server

如果被认证端用户ID标识信息与需要存储该用户生物特征信息的权限信任服务器属于上下级时,作为本发明实施例的一个可选实施方式,被认证端本地信任服务器将第二采集信息发送至信任锚子系统;信任锚子系统中的权限信任服务器获取第二采集信息,并存储第二采集信息包括:被认证端本地信任服务器根据用户ID标识信息比对信任锚子系统中的被认证端本地信任服务器连接的权限信任服务器的地址是否为与用户ID标识信息对应的权限信任服务器;如果是,则被认证端本地信任服务器将第二采集信息发送至被认证端本地信任服务器连接的权限信任服务器;被认证端本地信任服务器连接的权限信任服务器获取第二采集信息,并存储第二采集信息。由此可见,在被认证端本地信任服务器连接的权限信任服务器为被认证端本地信任服务器的上级权限信任服务器时,被认证端本地信任服务器可以在获取与用户ID标识信息对应的真实的用户的生物特征信息后,直接将与用户ID标识信息对应的真实的用户的生物特征信息存储在该上级权限信任服务器上。If the user ID identification information of the authenticated end and the authority trust server that needs to store the biometric information of the user belong to the upper and lower levels, as an optional implementation of the embodiment of the present invention, the local trust server of the authenticated end sends the second collection information to trust anchor subsystem; the authority trust server in the trust anchor subsystem obtains the second collection information, and stores the second collection information, including: the local trust server of the authenticated end compares the authenticated end in the trust anchor subsystem according to the user ID identification information Whether the address of the authority trust server connected to the local trust server is the authority trust server corresponding to the user ID identification information; if so, the authenticated end local trust server sends the second collection information to the authority trust server connected to the authenticated end local trust server server; the authority trust server connected to the local trust server of the authenticating end acquires the second collection information, and stores the second collection information. It can be seen that when the authority trust server connected to the local trust server of the authenticated side is the superior authority trust server of the local trust server of the authenticated side, the local trust server of the authenticated side can obtain the real user's ID information corresponding to the user ID identification information. After the biometric information is obtained, the biometric information of the real user corresponding to the user ID identification information is directly stored on the superior authority trust server.

具体地,以下提供一种具体的生物特征采集流程,参见图3,若被认证端生成的ID标识信息与需要存储该用户信息的权限信任服务器属于上下级时,执行如下流程:Specifically, a specific biometric collection process is provided below. Referring to FIG. 3, if the ID identification information generated by the authenticated terminal and the authority trust server that needs to store the user information belong to the upper and lower levels, the following process is performed:

1、用户A通过生物特征采集器将生物特征进行采集,例如通过指纹采集器采集用户的指纹。将采集到的生物特征信息转化为数字形式,信任锚子系统生成的用户ID标识信息、被认证端标识地址信息发送给本地信任服务器。1. User A collects biometric features through a biometric collector, for example, collects the user's fingerprint through a fingerprint collector. The collected biometric information is converted into a digital form, and the user ID identification information and the identification address information of the authenticated terminal generated by the trust anchor subsystem are sent to the local trust server.

2、本地信任服务器将用户ID标识信息、被认证端标识地址信息以及对应的用户认证生物特征信息发送至上级权限信任服务器中,将其保存至权限信任服务器。2. The local trust server sends the user ID identification information, the identification address information of the authenticated terminal, and the corresponding user authentication biometric information to the superior authority trust server, and saves them to the authority trust server.

3、保存成功后,逐级返回成功信息,返回给被认证端采集通过信息。3. After the saving is successful, the success information is returned step by step, and the information is returned to the authenticated end to collect the passed information.

如果被认证端用户ID标识信息与需要存储该用户生物特征信息的权限信任服务器不属于上下级时,作为本发明实施例的一个可选实施方式,被认证端本地信任服务器将第二采集信息发送至信任锚子系统;信任锚子系统中的权限信任服务器获取第二采集信息,并存储第二采集信息包括:被认证端本地信任服务器根据用户ID标识信息比对信任锚子系统中的被认证端本地信任服务器连接的权限信任服务器的地址是否为与用户ID标识信息对应的权限信任服务器;如果不是,被认证端则比对权限信任服务器连接的顶级信任服务器的地址是否为与用户ID标识信息对应的顶级信任服务器;如果不是,则向与顶级权限服务器连接的根信任服务器进行访问,根信任服务器根据用户ID标识信息找到与用户ID标识信息对应的顶级信任服务器,并从与用户ID标识信息对应的顶级信任服务器进行访问,找到与用户ID标识信息对应的权限信任服务器,将第二采集信息发送至与用户ID标识信息对应的权限信任服务器;与用户ID标识信息对应的权限信任服务器获取第二采集信息,并存储第二采集信息。由此可见,在被认证端本地信任服务器连接的权限信任服务器不是被认证端本地信任服务器的上级权限信任服务器时,被认证端本地信任服务器可以在获取与用户ID标识信息对应的真实的用户的生物特征信息后,通过向与其连接的权限信任服务器的上级顶级信任服务器进行查询,进而向上级根信任服务器进行查询,直到查询到与用户ID标识信息对应的权限信任服务器后,将与用户ID标识信息对应的真实的用户的生物特征信息存储在该权限信任服务器上。If the user ID identification information of the authenticated end and the authority trust server that needs to store the biometric information of the user do not belong to the upper and lower levels, as an optional implementation of the embodiment of the present invention, the local trust server of the authenticated end sends the second collection information to to the trust anchor subsystem; the authority trust server in the trust anchor subsystem obtains the second collection information, and stores the second collection information including: the local trust server of the authenticated end compares the authenticated data in the trust anchor subsystem according to the user ID identification information Whether the address of the authority trust server connected to the local trust server of the terminal is the authority trust server corresponding to the user ID identification information; if not, the authenticated end compares whether the address of the top-level trust server connected to the authority trust server is the authority trust server corresponding to the user ID identification information. The corresponding top-level trust server; if not, access to the root trust server connected to the top-level authority server, the root trust server finds the top-level trust server corresponding to the user ID identification information according to the user ID identification information, and from the user ID identification information. The corresponding top-level trust server accesses, finds the authority trust server corresponding to the user ID identification information, and sends the second collection information to the authority trust server corresponding to the user ID identification information; the authority trust server corresponding to the user ID identification information obtains the first Second, collect information, and store the second collected information. It can be seen that when the authority trust server connected to the local trust server of the authenticated side is not the superior authority trust server of the local trust server of the authenticated side, the local trust server of the authenticated side can obtain the real user's identity information corresponding to the user ID identification information. After the biometric information, query the upper-level top-level trust server of the authority trust server connected to it, and then query the upper-level root trust server until the authority trust server corresponding to the user ID identification information is queried. The biometric information of the real user corresponding to the information is stored on the authority trust server.

具体地,以下提供另一种具体的生物特征采集流程,参见图4,若被认证端生成的ID标识信息与需要存储该用户信息的权限信任服务器不属于上下级时,执行如下流程:Specifically, another specific biometric collection process is provided below. Referring to FIG. 4, if the ID identification information generated by the authenticated terminal and the authority trust server that needs to store the user information do not belong to the upper and lower levels, the following process is performed:

1、用户A通过生物特征采集器将生物特征进行采集,例如通过指纹采集器采集用户的指纹。将采集到的生物特征信息转化为数字形式,信任锚子系统生成的用户ID标识信息、被认证端标识地址信息发送给本地信任服务器。1. User A collects biometric features through a biometric collector, for example, collects the user's fingerprint through a fingerprint collector. The collected biometric information is converted into a digital form, and the user ID identification information and the identification address information of the authenticated terminal generated by the trust anchor subsystem are sent to the local trust server.

2、本地信任服务器访问上级权限信任服务器,根据用户ID标识信息,比对上级权限信任服务器地址,若不一致则继续向顶级信任服务器访问。2. The local trust server accesses the superior authority trust server, compares the address of the superior authority trust server according to the user ID identification information, and continues to access the top-level trust server if it is inconsistent.

3、权限信任服务器访问上级顶级信任服务器,根据用户ID标识信息,比对上级权限信任服务器地址,若不一致则向根信任服务器进行访问。3. The authority trust server accesses the upper-level top-level trust server, compares the address of the upper-level authority trust server according to the user ID identification information, and accesses the root trust server if it is inconsistent.

4、向根信任服务器访问,根据用户ID标识信息,找到与用户ID标识信息对应的顶级信任服务器。4. Access the root trust server, and find the top-level trust server corresponding to the user ID identification information according to the user ID identification information.

5、从根信任服务器向对应的顶级信任服务器进行访问。5. Access from the root trust server to the corresponding top-level trust server.

6、根据用户ID标识信息,找到与用户ID标识信息对应的权限服务器。将用户ID标识信息、被认证端标识地址信息以及对应的用户认证生物特征信息发送至权限信任服务器中,将其保存至权限信任服务器。6. According to the user ID identification information, find the authority server corresponding to the user ID identification information. The user ID identification information, the identification address information of the authenticated terminal, and the corresponding user authentication biometric information are sent to the authority trust server, and stored in the authority trust server.

7、保存成功后,逐级返回成功信息,返回给被认证端采集通过信息。7. After the saving is successful, the success information is returned step by step, and returned to the authenticated end to collect the passed information.

S202,被认证端将第一采集信息发送至被认证端本地信任服务器,其中,第一采集信息包括用户ID标识信息、被认证端标识地址信息和用户待认证生物特征信息。S202, the authenticated end sends first collection information to the authenticated end local trust server, where the first collection information includes user ID identification information, authenticated end identification address information, and user biometric feature information to be authenticated.

具体地,被认证端可以将信任锚子系统为其生成的用户ID标识信息,被认证端标识地址信息,发送给本地信任服务器,同时将采集得到的用户待认证生物特征信息也发送至本地信任服务器,以便本地信任服务器对生物特征信息进行比对。由于用户的生物特征信息在认证时,无法被认证端获取,对比工作在信任锚子系统中的本地信任服务器中进行,可以保证隐私信息(用户生物特征)的安全性。Specifically, the authenticated terminal can send the user ID identification information generated for it by the trust anchor subsystem, and the identification address information of the authenticated terminal to the local trust server, and at the same time, the collected biometric information of the user to be authenticated can also be sent to the local trust server. server so that the local trusted server can compare the biometric information. Since the user's biometric information cannot be obtained by the authentication terminal during authentication, the comparison work is carried out in the local trust server in the trust anchor subsystem, which can ensure the security of private information (user biometrics).

S203,被认证端本地信任服务器如果查询到用户ID标识信息,则比对用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果通过信任锚子系统发送至认证端,其中,用户认证生物特征信息为与用户ID标识信息对应的真实的用户的生物特征信息。S203, if the local trust server of the authenticated end queries the user ID identification information, it compares whether the biometric information of the user to be authenticated is consistent with the biometric information for authentication of the user, obtains a comparison result, and sends the comparison result through the trust anchor subsystem to The authentication terminal, wherein the user authentication biometric information is the real user biometric information corresponding to the user ID identification information.

具体地,如果本地信任服务器可以查询到用户ID标识信息,则说明与其连接的权限信任服务器中存储有用户认证生物特征信息,即真实的用户的生物特征信息,因此,该本地信任服务器可以直接获取到用户认证生物特征信息,以便比对用户待认证生物特征信息与用户认证生物特征信息是否一致。Specifically, if the local trust server can query the user ID identification information, it means that the user authentication biometric information, that is, the biometric information of the real user, is stored in the authority trust server connected to it. Therefore, the local trust server can directly obtain the information. to the user authentication biometric information, so as to compare whether the user biometric information to be authenticated is consistent with the user authentication biometric information.

S204,被认证端本地信任服务器如果没有查询到用户ID标识信息,则向信任锚子系统查询用户ID标识信息,如果信任锚子系统查询到用户ID标识信息,则信任锚子系统中的权限信任服务器将用户认证生物特征信息发送至被认证端本地信任服务器,被认证端本地信任服务器比对用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端。S204, if the local trust server of the authenticated end does not query the user ID identification information, it queries the trust anchor subsystem for the user ID identification information, and if the trust anchor subsystem queries the user ID identification information, the authority trusts in the trust anchor subsystem The server sends the user authentication biometric information to the local trust server of the authenticated side, and the local trust server of the authenticated side compares the biometric information of the user to be authenticated with the user authentication biometric information, obtains the comparison result, and sends the comparison result to Authentication side.

具体地,如果被认证端本地信任服务器没有查询到用户ID标识信息,则说明被认证端本地信任服务器并未存储过用户认证生物特征信息,此时则需要向信任锚子系统请求获取该用户认证生物特征信息,从而根据获取到的用户认证生物特征信息进行比对。Specifically, if the local trust server of the authenticated end does not query the user ID identification information, it means that the local trust server of the authenticated end has not stored the biometric information for user authentication. At this time, it is necessary to request the trust anchor subsystem to obtain the user authentication information. Biometric information, so as to perform comparison according to the obtained user authentication biometric information.

作为本发明实施例的一个可选实施方式,被认证端本地信任服务器如果没有查询到用户ID标识信息,则向信任锚子系统查询用户ID标识信息,如果信任锚子系统查询到用户ID标识信息,则信任锚子系统中的权限信任服务器将用户认证生物特征信息发送至被认证端本地信任服务器,被认证端本地信任服务器比对用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端包括:被认证端本地信任服务器如果没有查询到用户ID标识信息,则向信任锚子系统中的与认证端本地信任服务器连接的权限信任服务器查询用户ID标识信息,如果在权限信任服务器上查询到用户ID标识信息,则由与权限信任服务器连接的与用户ID标识信息对应的本地信任服务器对比用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端;如果在权限信任服务器上没有查询到用户ID标识信息,则向与权限信任服务器连接的顶级信任服务器查询用户ID标识信息,如果在顶级信任服务器下的权限信任服务器上查询到用户ID标识信息,则由与顶级信任服务器下的权限信任服务器连接的存有用户ID标识信息的本地信任服务器对比用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端;如果在顶级信任服务器下的权限信任服务器上没有查询到用户ID标识信息,则向与顶级信任服务器连接的根信任服务器查询用户ID标识信息,如果根信任服务器下的权限信任服务器上存有用户ID标识信息,则通过根信任服务器向与根信任服务器连接的存储有用户ID标识信息的顶级信任服务器向存储有用户ID标识信息的权限信任服务器进行查询,在存储有用户ID标识信息的权限信任服务器查询到用户认证生物特征信息时,由与存储有用户ID标识信息的权限信任服务器连接的本地信任服务器对比用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端。由此可以通过层次树型认证方式进行认证。As an optional implementation of the embodiment of the present invention, if the local trust server of the authenticated end does not query the user ID identification information, it queries the trust anchor subsystem for the user ID identification information, and if the trust anchor subsystem queries the user ID identification information , then the authority trust server in the trust anchor subsystem sends the user authentication biometric information to the authenticated end local trust server, and the authenticated end local trust server compares whether the user biometric information to be authenticated is consistent with the user authentication biometric information, and obtains The comparison result, sending the comparison result to the authenticating end includes: if the local trust server of the authenticated end does not query the user ID identification information, then query the authority trust server in the trust anchor subsystem connected with the local trust server of the authenticating end to query the user. ID identification information, if the user ID identification information is queried on the authority trust server, the local trust server connected to the authority trust server and corresponding to the user ID identification information compares the user's biometric information to be authenticated and the user authentication biometric information. , obtain the comparison result, and send the comparison result to the authentication terminal; if the user ID identification information is not queried on the authority trust server, query the user ID identification information from the top-level trust server connected to the authority trust server. The user ID identification information is queried on the authority trust server under the server, and the local trust server that stores the user ID identification information connected to the authority trust server under the top-level trust server compares the biometric information of the user to be authenticated and the user authentication biometric information. Check whether it is consistent, get the comparison result, and send the comparison result to the authentication terminal; if the user ID identification information is not queried on the authority trust server under the top-level trust server, query the user ID from the root trust server connected to the top-level trust server. Identification information, if user ID identification information is stored on the authority trust server under the root trust server, then through the root trust server to the top-level trust server that stores the user ID identification information connected to the root trust server to the top-level trust server that stores the user ID identification information. The authority trust server performs a query. When the authority trust server storing the user ID identification information queries the user authentication biometric information, the local trust server connected to the authority trust server storing the user ID identification information compares the user's biometric information to be authenticated. Whether it is consistent with the user authentication biometric information, the comparison result is obtained, and the comparison result is sent to the authentication terminal. Therefore, authentication can be performed through a hierarchical tree authentication method.

具体地,以下提供另一种具体的认证流程,参见图5,通过层次树型认证方式的认证执行如下流程:Specifically, another specific authentication process is provided below. Referring to FIG. 5 , the authentication through the hierarchical tree authentication method executes the following process:

1、在被认证端,用户A通过生物特征采集器将生物特征进行采集,例如通过指纹采集器采集用户的指纹。向认证端发出认证请求。1. At the authenticated end, user A collects the biometrics through a biometric collector, for example, collects the user's fingerprint through a fingerprint collector. Send an authentication request to the authenticator.

2、将被认证端的用户ID标识信息,被认证端标识地址信息和用户待认证生物特征信息发送给本地信任服务器。若在本地信任服务器上查询到用户ID标识信息,则对比生物特征信息,返回给认证端对比结果。若在本地信任服务器上没有查询到用户ID标识信息,则继续向权限信任服务器上查询用户ID标识信息。2. Send the user ID identification information of the authenticated end, the identification address information of the authenticated end and the biometric information of the user to be authenticated to the local trust server. If the user ID identification information is queried on the local trust server, the biometric information is compared, and the comparison result is returned to the authentication terminal. If the user ID identification information is not queried on the local trust server, continue to query the user ID identification information on the authority trust server.

3、由本地服务器向上级权限信任服务器请求查询用户ID标识信息。若在权限信任服务器上查询到用户ID标识信息,则由该下级对应的本地信任服务器对比生物特征信息,返回给认证端对比结果。若在权限信任服务器上没有查询到用户ID标识信息,则继续向顶级信任服务器上查询用户ID标识信息。3. The local server requests to query the user ID identification information from the superior authority trust server. If the user ID identification information is queried on the authority trust server, the local trust server corresponding to the lower level compares the biometric information, and returns the comparison result to the authentication end. If the user ID identification information is not queried on the authority trust server, continue to query the user ID identification information on the top-level trust server.

4、再由权限信任服务器向顶级信任服务器请求查询用户ID标识信息。若在顶级信任服务器上查询到用户ID标识信息,则由该下级存有用户ID标识信息的本地信任服务器对比生物特征信息,返回给认证端对比结果。若在顶级信任服务器上没有查询到用户ID标识信息,则继续向根信任服务器上查询用户ID标识信息。4. The authority trust server then requests the top-level trust server to query the user ID identification information. If the user ID identification information is queried on the top-level trust server, the local trust server that stores the user ID identification information at the lower level compares the biometric information, and returns the comparison result to the authentication end. If the user ID identification information is not queried on the top-level trust server, continue to query the user ID identification information on the root trust server.

5、再由顶级信任服务器向根信任服务器请求查询用户ID标识信息。5. The top-level trust server then requests the root trust server to query the user ID identification information.

6、根信任服务器向存有用户ID标识信息所在的顶级信任服务器以及权限信任服务器查询,查询到用户A的生物特征信息。6. The root trust server queries the top-level trust server and the authority trust server where the user ID identification information is stored, and finds the biometric information of user A.

7、由该下级用户ID标识信息对应的本地信任服务器进行对比生物特征信息。7. The local trust server corresponding to the subordinate user ID identification information compares the biometric information.

8、将比对结果(是否一致)返回给认证端。8. Return the comparison result (whether it is consistent) to the authentication terminal.

9、认证端根据权限信任服务器返回的对比结果做出判断,若一致则通过认证,反之则拒绝。9. The authentication end makes a judgment according to the comparison result returned by the authority trust server. If they are consistent, the authentication is passed; otherwise, the authentication is rejected.

作为本发明实施例的一个可选实施方式,被认证端本地信任服务器如果没有查询到用户ID标识信息,则向信任锚子系统查询用户ID标识信息,如果信任锚子系统查询到用户ID标识信息,则信任锚子系统中的权限信任服务器将用户认证生物特征信息发送至被认证端本地信任服务器,被认证端本地信任服务器比对用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端包括:被认证端本地信任服务器如果没有查询到用户ID标识信息,则通过迭代查询,向被认证端本地信任服务器上级的根信任服务器请求查询用户ID标识信息,如果在根信任服务器上查询到用户ID标识信息,则返回用户ID标识信息所属的顶级信任服务器的地址,被认证端本地信任服务器向用户ID标识信息所属的顶级信任服务器请求查询用户ID标识信息,如果在顶级信任服务器上查询到用户ID标识信息,则返回用户ID标识信息所属的权限信任服务器的地址,被认证端本地信任服务器向用户ID标识信息所属的权限信任服务器请求查询用户ID标识信息,如果在权限信任服务器上查询到用户ID标识信息,则返回给被认证端本地信任服务器与用户ID标识信息对应的用户认证生物特征信息,被认证端本地信任服务器对比用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端。由此可以通过迭代递归认证方式进行认证。As an optional implementation of the embodiment of the present invention, if the local trust server of the authenticated end does not query the user ID identification information, it queries the trust anchor subsystem for the user ID identification information, and if the trust anchor subsystem queries the user ID identification information , then the authority trust server in the trust anchor subsystem sends the user authentication biometric information to the authenticated end local trust server, and the authenticated end local trust server compares whether the user biometric information to be authenticated is consistent with the user authentication biometric information, and obtains The comparison result, sending the comparison result to the authenticating end includes: if the local trust server of the authenticated end does not query the user ID identification information, then through an iterative query, request the root trust server of the upper level of the local trust server of the authenticated end to query the user ID. Identification information, if the user ID identification information is queried on the root trust server, the address of the top-level trust server to which the user ID identification information belongs is returned, and the local trust server of the authenticated end requests to query the user ID from the top-level trust server to which the user ID identification information belongs. Identification information, if the user ID identification information is queried on the top-level trust server, the address of the authority trust server to which the user ID identification information belongs is returned, and the local trust server of the authenticated end requests the authority trust server to which the user ID identification information belongs to query the user ID Identification information, if the user ID identification information is queried on the authority trust server, it is returned to the user authentication biometric information corresponding to the user ID identification information on the local trust server of the authenticated end, and the local trust server of the authenticated end compares the biometric characteristics of the user to be authenticated Whether the information is consistent with the user authentication biometric information, the comparison result is obtained, and the comparison result is sent to the authentication terminal. Thereby, authentication can be performed through an iterative recursive authentication method.

具体地,以下提供另一种具体的认证流程,参见图6,通过迭代递归认证方式的认证执行如下流程:Specifically, another specific authentication process is provided below. Referring to FIG. 6 , the authentication by iterative recursive authentication method performs the following process:

1、在被认证端,用户A通过生物特征采集器将生物特征进行采集,例如通过指纹采集器采集用户的指纹。向认证端发出认证请求。1. At the authenticated end, user A collects the biometrics through a biometric collector, for example, collects the user's fingerprint through a fingerprint collector. Send an authentication request to the authenticator.

2、将被认证端的用户ID标识信息,被认证端标识地址信息和用户待认证生物特征信息发送给本地信任服务器。若在本地信任服务器上查询到用户ID标识信息,则对比生物特征信息,返回给认证端对比结果。2. Send the user ID identification information of the authenticated end, the identification address information of the authenticated end and the biometric information of the user to be authenticated to the local trust server. If the user ID identification information is queried on the local trust server, the biometric information is compared, and the comparison result is returned to the authentication terminal.

3、若在本地信任服务器上没有查询到用户ID标识信息,则通过迭代查询,再由本地服务器向根信任服务器请求查询用户ID标识信息。3. If the user ID identification information is not queried on the local trust server, through an iterative query, the local server requests the root trust server to query the user ID identification information.

4、若在根信任服务器上没有查询到用户ID标识信息,则终止查询并返回给本地信任服务器没有找到的信息。若在根信任服务器上查询到用户ID标识信息,则返回该用户ID标识信息所属顶级信任服务器的地址。4. If the user ID identification information is not queried on the root trust server, the query is terminated and the information not found by the local trust server is returned. If the user ID identification information is queried on the root trust server, the address of the top-level trust server to which the user ID identification information belongs is returned.

5、再由本地服务器向所属顶级信任服务器请求查询用户ID标识信息。5. The local server then requests to query the user ID identification information from the top-level trust server to which it belongs.

6、若在顶级信任服务器上没有查询到用户ID标识信息,则终止查询并返回给本地信任服务器没有找到的信息。若在顶级信任服务器上查询到用户ID标识信息,则返回该用户ID标识信息所属权限信任服务器的地址。6. If the user ID identification information is not queried on the top-level trust server, the query is terminated and the information not found by the local trust server is returned. If the user ID identification information is queried on the top-level trust server, the address of the authority trust server to which the user ID identification information belongs is returned.

7、最后由本地服务器向所属权限信任服务器请求查询用户ID标识信息。7. Finally, the local server requests to query the user ID identification information from the affiliated authority trust server.

8、若在权限信任服务器上没有查询到用户ID标识信息,则终止查询并返回给本地信任服务器没有找到的信息。若在权限信任服务器上查询到用户ID标识信息,则返回给本地信任服务器与之对应的用户A的生物特征信息。8. If the user ID identification information is not queried on the authority trust server, the query is terminated and the information not found by the local trust server is returned. If the user ID identification information is queried on the authority trust server, the biometric information of the user A corresponding to it is returned to the local trust server.

9、本地信任服务器进行对比生物特征信息,将比对结果(是否一致)返回给认证端。9. The local trust server compares the biometric information, and returns the comparison result (whether it is consistent) to the authentication terminal.

10、认证端根据权限信任服务器返回的对比结果做出判断,若一致则通过认证,反之则拒绝。10. The authentication end makes a judgment according to the comparison result returned by the authority trust server. If they are consistent, the authentication is passed; otherwise, the authentication is rejected.

S205,认证端根据认证请求以及比对结果进行是否认证通过的判断。S205, the authentication end judges whether the authentication is passed according to the authentication request and the comparison result.

具体地,比对结果可以包括比对成功和比对不成功的信息,这些比对结果可以发送至认证端,使得认证端确定认证是否通过,在比对成功的情况下,认证通过,在比对不成功的情况下,认证不通过。Specifically, the comparison result may include information about successful comparison and unsuccessful comparison, and these comparison results may be sent to the authentication terminal, so that the authentication terminal can determine whether the authentication is passed. If the comparison is successful, the authentication is passed. In the case of unsuccessful, the authentication is not passed.

由此可见,通过本发明实施例提供的基于生物特征识别的全网统一身份认证方法,可以基于生物特征来进行全网统一的身份认证,从而有效的避免交叉认证等诸多问题,而通过用户的生物特征信息能够更加方便、可靠进行认证,同时,用户的生物特征信息在认证时,认证端无法获取到生物特征信息,只能获取到对比是否一致的信息,对比工作在信任锚子系统中的本地信任服务器中进行,保证隐私信息(用户生物特征)的安全性。It can be seen that, through the unified identity authentication method based on biometric identification provided in the embodiment of the present invention, unified identity authentication of the entire network can be performed based on biometrics, thereby effectively avoiding many problems such as cross-authentication. The biometric information can be authenticated more conveniently and reliably. At the same time, when the user's biometric information is authenticated, the authentication end cannot obtain the biometric information, but can only obtain the information about whether the comparison is consistent, and the comparison works in the trust anchor subsystem. It is carried out in the local trust server to ensure the security of private information (user biometrics).

以下提供了本发明实施例提供的基于生物特征识别的全网统一身份认证系统,该系统利用如图1所示的系统,采用上述相关方法,以下仅对本发明实施例提供的基于生物特征识别的全网统一身份认证系统的功能进行简要说明,其他未尽事宜,请参照上述方法的相关描述,具体地,本发明实施例提供的基于生物特征识别的全网统一身份认证系统,包括:被认证端、认证端以及信任锚子系统;其中:信任锚子系统至少包括被认证端本地信任服务器;被认证端,用于通过生物特征采集器采集用户的生物特征,得到用户待认证生物特征信息,并向认证端发送认证请求;被认证端,还用于将第一采集信息发送至被认证端本地信任服务器,其中,第一采集信息包括用户ID标识信息、被认证端标识地址信息和用户待认证生物特征信息;被认证端本地信任服务器,用于如果查询到用户ID标识信息,则比对用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果通过信任锚子系统发送至认证端,其中,用户认证生物特征信息为与用户ID标识信息对应的真实的用户的生物特征信息;被认证端本地信任服务器,还用于如果没有查询到用户ID标识信息,则向信任锚子系统查询用户ID标识信息,如果信任锚子系统查询到用户ID标识信息,则信任锚子系统中的权限信任服务器将用户认证生物特征信息发送至被认证端本地信任服务器,被认证端本地信任服务器比对用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端;认证端,用于根据认证请求以及比对结果进行是否认证通过的判断。The following provides a network-wide unified identity authentication system based on biometric identification provided by the embodiment of the present invention. The system utilizes the system shown in FIG. 1 and adopts the above-mentioned related methods. The functions of the network-wide unified identity authentication system are briefly described. For other unresolved matters, please refer to the relevant description of the above method. A terminal, an authentication terminal and a trust anchor subsystem; wherein: the trust anchor subsystem includes at least a local trust server of the authenticated terminal; the authenticated terminal is used to collect the biometrics of the user through the biometric collector to obtain the biometric information of the user to be authenticated, and send an authentication request to the authenticating end; the authenticated end is also used to send the first collection information to the local trust server of the authenticated end, wherein the first collection information includes the user ID identification information, the identification address information of the authenticated end, and the user waiting list. Authentication biometric information; the local trust server of the authenticated end is used to compare whether the user's biometric information to be authenticated is consistent with the user's authentication biometric information if the user ID identification information is queried, obtain the comparison result, and pass the comparison result The trust anchor subsystem is sent to the authentication terminal, wherein the user authentication biometric information is the real user's biometric information corresponding to the user ID identification information; the local trust server of the authenticated terminal is also used if the user ID identification information is not queried. , then query the trust anchor subsystem for the user ID identification information, if the trust anchor subsystem queries the user ID identification information, the authority trust server in the trust anchor subsystem sends the user authentication biometric information to the authenticated end local trust server, The local trust server of the authenticated end compares whether the biometric information of the user to be authenticated is consistent with the biometric information of the user authentication, obtains the comparison result, and sends the comparison result to the authentication end; Judgment of whether to pass the certification.

由此可见,通过本发明实施例提供的基于生物特征识别的全网统一身份认证系统,可以基于生物特征来进行全网统一的身份认证,从而有效的避免交叉认证等诸多问题,而通过用户的生物特征信息能够更加方便、可靠进行认证,同时,用户的生物特征信息在认证时,认证端无法获取到生物特征信息,只能获取到对比是否一致的信息,对比工作在信任锚子系统中的本地信任服务器中进行,保证隐私信息(用户生物特征)的安全性。It can be seen that, through the unified identity authentication system based on biometric identification provided by the embodiment of the present invention, the unified identity authentication of the entire network can be performed based on biometrics, thereby effectively avoiding many problems such as cross-authentication. The biometric information can be authenticated more conveniently and reliably. At the same time, when the user's biometric information is authenticated, the authentication end cannot obtain the biometric information, but can only obtain the information about whether the comparison is consistent, and the comparison works in the trust anchor subsystem. It is carried out in the local trust server to ensure the security of private information (user biometrics).

作为本发明实施例的一个可选实施方式,信任锚子系统还包括:权限信任服务器;被认证端,还用于通过生物特征采集器采集用户的生物特征,得到用户认证生物特征信息;被认证端,还用于将第二采集信息发送至被认证端本地信任服务器,其中,第二采集信息包括用户ID标识信息、被认证端标识地址信息和用户认证生物特征信息;被认证端本地信任服务器,还用于将第二采集信息发送至信任锚子系统;信任锚子系统中的权限信任服务器,用于获取第二采集信息,并存储第二采集信息。通过此种方式,可以将真实的用户的生物特征信息存储在信任锚子系统中的权限信任服务器中,保护真实的用户的生物特征信息的安全性。As an optional implementation manner of the embodiment of the present invention, the trust anchor subsystem further includes: an authority trust server; the authenticated terminal is further configured to collect the biometrics of the user through the biometrics collector to obtain user authentication biometrics information; the authenticated end The terminal is also used to send the second collection information to the local trust server of the authenticated terminal, wherein the second collection information includes the user ID identification information, the identification address information of the authenticated terminal and the user authentication biometric information; the local trust server of the authenticated terminal is also used to send the second collection information to the trust anchor subsystem; the authority trust server in the trust anchor subsystem is used to obtain the second collection information and store the second collection information. In this way, the biometric information of the real user can be stored in the authority trust server in the trust anchor subsystem, so as to protect the security of the biometric information of the real user.

作为本发明实施例的一个可选实施方式,被认证端本地信任服务器,具体用于根据用户ID标识信息比对信任锚子系统中的被认证端本地信任服务器连接的权限信任服务器的地址是否为与用户ID标识信息对应的权限信任服务器;如果是,则将第二采集信息发送至被认证端本地信任服务器连接的权限信任服务器;被认证端本地信任服务器连接的权限信任服务器,具体用于获取第二采集信息,并存储第二采集信息。由此可见,在被认证端本地信任服务器连接的权限信任服务器为被认证端本地信任服务器的上级权限信任服务器时,被认证端本地信任服务器可以在获取与用户ID标识信息对应的真实的用户的生物特征信息后,直接将与用户ID标识信息对应的真实的用户的生物特征信息存储在该上级权限信任服务器上。As an optional implementation of the embodiment of the present invention, the local trust server of the authenticated end is specifically configured to compare, according to the user ID identification information, whether the address of the authority trust server connected to the local trust server of the authenticated end in the trust anchor subsystem is The authority trust server corresponding to the user ID identification information; if so, the second collection information is sent to the authority trust server connected to the local trust server of the authenticated end; the authority trust server connected to the local trust server of the authenticated end is specifically used to obtain The second collection information is stored, and the second collection information is stored. It can be seen that when the authority trust server connected to the local trust server of the authenticated side is the superior authority trust server of the local trust server of the authenticated side, the local trust server of the authenticated side can obtain the real user's ID information corresponding to the user ID identification information. After the biometric information is obtained, the biometric information of the real user corresponding to the user ID identification information is directly stored on the superior authority trust server.

作为本发明实施例的一个可选实施方式,被认证端本地信任服务器,具体用于根据用户ID标识信息比对信任锚子系统中的被认证端本地信任服务器连接的权限信任服务器的地址是否为与用户ID标识信息对应的权限信任服务器;如果不是,则比对权限信任服务器连接的顶级信任服务器的地址是否为与用户ID标识信息对应的顶级信任服务器;如果不是,则向与顶级权限服务器连接的根信任服务器进行访问,根信任服务器根据用户ID标识信息找到与用户ID标识信息对应的顶级信任服务器,并从与用户ID标识信息对应的顶级信任服务器进行访问,找到与用户ID标识信息对应的权限信任服务器,将第二采集信息发送至与用户ID标识信息对应的权限信任服务器;与用户ID标识信息对应的权限信任服务器,具体用于获取第二采集信息,并存储第二采集信息。由此可见,在被认证端本地信任服务器连接的权限信任服务器不是被认证端本地信任服务器的上级权限信任服务器时,被认证端本地信任服务器可以在获取与用户ID标识信息对应的真实的用户的生物特征信息后,通过向与其连接的权限信任服务器的上级顶级信任服务器进行查询,进而向上级根信任服务器进行查询,直到查询到与用户ID标识信息对应的权限信任服务器后,将与用户ID标识信息对应的真实的用户的生物特征信息存储在该权限信任服务器上。As an optional implementation of the embodiment of the present invention, the local trust server of the authenticated end is specifically configured to compare, according to the user ID identification information, whether the address of the authority trust server connected to the local trust server of the authenticated end in the trust anchor subsystem is The authority trust server corresponding to the user ID identification information; if not, compare whether the address of the top-level trust server connected to the authority trust server is the top-level trust server corresponding to the user ID identification information; if not, connect to the top-level authority server The root trust server to access, the root trust server finds the top-level trust server corresponding to the user ID identification information according to the user ID identification information, and accesses from the top-level trust server corresponding to the user ID identification information, and finds the corresponding user ID identification information. The authority trust server sends the second collection information to the authority trust server corresponding to the user ID identification information; the authority trust server corresponding to the user ID identification information is specifically used to obtain the second collection information and store the second collection information. It can be seen that when the authority trust server connected to the local trust server of the authenticated side is not the superior authority trust server of the local trust server of the authenticated side, the local trust server of the authenticated side can obtain the real user's identity information corresponding to the user ID identification information. After the biometric information, query the upper-level top-level trust server of the authority trust server connected to it, and then query the upper-level root trust server until the authority trust server corresponding to the user ID identification information is queried. The biometric information of the real user corresponding to the information is stored on the authority trust server.

作为本发明实施例的一个可选实施方式,被认证端本地信任服务器,具体用于如果没有查询到用户ID标识信息,则向信任锚子系统中的与认证端本地信任服务器连接的权限信任服务器查询用户ID标识信息,如果在权限信任服务器上查询到用户ID标识信息,则由与权限信任服务器连接的与用户ID标识信息对应的本地信任服务器对比用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端;如果在权限信任服务器上没有查询到用户ID标识信息,则向与权限信任服务器连接的顶级信任服务器查询用户ID标识信息,如果在顶级信任服务器下的权限信任服务器上查询到用户ID标识信息,则由与顶级信任服务器下的权限信任服务器连接的存有用户ID标识信息的本地信任服务器对比用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端;如果在顶级信任服务器下的权限信任服务器上没有查询到用户ID标识信息,则向与顶级信任服务器连接的根信任服务器查询用户ID标识信息,如果根信任服务器下的权限信任服务器上存有用户ID标识信息,则通过根信任服务器向与根信任服务器连接的存储有用户ID标识信息的顶级信任服务器向存储有用户ID标识信息的权限信任服务器进行查询,在存储有用户ID标识信息的权限信任服务器查询到用户认证生物特征信息时,由与存储有用户ID标识信息的权限信任服务器连接的本地信任服务器对比用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端。由此可以通过层次树型认证方式进行认证。As an optional implementation of the embodiment of the present invention, the local trust server of the authenticated end is specifically configured to, if the user ID identification information is not queried, send to the authority trust server in the trust anchor subsystem that is connected to the local trust server of the authenticating end Query the user ID identification information, if the user ID identification information is queried on the authority trust server, the local trust server connected to the authority trust server and corresponding to the user ID identification information compares the user's biometric information to be authenticated and the user authentication biometric information. Whether it is consistent, get the comparison result, and send the comparison result to the authentication terminal; if the user ID identification information is not queried on the authority trust server, query the user ID identification information from the top-level trust server connected to the authority trust server. The user ID identification information is queried on the authority trust server under the top-level trust server, and the local trust server that stores the user ID identification information connected to the authority trust server under the top-level trust server compares the user's biometric information to be authenticated with the user's authentication biometric information. Whether the feature information is consistent, get the comparison result, and send the comparison result to the authentication terminal; if the user ID identification information is not queried on the authority trust server under the top-level trust server, query the root trust server connected to the top-level trust server. User ID identification information, if user ID identification information is stored on the authority trust server under the root trust server, then the top-level trust server that stores the user ID identification information connected to the root trust server sends the user ID identification information to the top-level trust server that stores the user ID identification information through the root trust server. The authority trust server for the information is queried. When the authority trust server storing the user ID identification information queries the user authentication biometric information, the local trust server connected to the authority trust server storing the user ID identification information compares the user's biometrics to be authenticated. Whether the feature information is consistent with the user authentication biometric information, a comparison result is obtained, and the comparison result is sent to the authentication terminal. Therefore, authentication can be performed through a hierarchical tree authentication method.

作为本发明实施例的一个可选实施方式,被认证端本地信任服务器,具体用于如果没有查询到用户ID标识信息,则通过迭代查询,向被认证端本地信任服务器上级的根信任服务器请求查询用户ID标识信息,如果在根信任服务器上查询到用户ID标识信息,则返回用户ID标识信息所属的顶级信任服务器的地址,被认证端本地信任服务器向用户ID标识信息所属的顶级信任服务器请求查询用户ID标识信息,如果在顶级信任服务器上查询到用户ID标识信息,则返回用户ID标识信息所属的权限信任服务器的地址,被认证端本地信任服务器向用户ID标识信息所属的权限信任服务器请求查询用户ID标识信息,如果在权限信任服务器上查询到用户ID标识信息,则返回给被认证端本地信任服务器与用户ID标识信息对应的用户认证生物特征信息,被认证端本地信任服务器对比用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将比对结果发送至认证端。由此可以通过迭代递归认证方式进行认证。As an optional implementation of the embodiment of the present invention, the local trust server of the authenticated end is specifically configured to request a query from the root trust server of the upper level of the local trust server of the authenticated end through an iterative query if the user ID identification information is not queried. User ID identification information, if the user ID identification information is queried on the root trust server, the address of the top-level trust server to which the user ID identification information belongs is returned, and the local trust server of the authenticated end requests the query from the top-level trust server to which the user ID identification information belongs. User ID identification information, if the user ID identification information is queried on the top-level trust server, the address of the authority trust server to which the user ID identification information belongs is returned, and the local trust server of the authenticated side requests the query to the authority trust server to which the user ID identification information belongs. User ID identification information, if the user ID identification information is queried on the authority trust server, it is returned to the authenticated local trust server and the user authentication biometric information corresponding to the user ID identification information, and the authenticated local trust server compares the user to be authenticated Whether the biometric information is consistent with the user authentication biometric information, a comparison result is obtained, and the comparison result is sent to the authentication terminal. Thereby, authentication can be performed through an iterative recursive authentication method.

流程图中或在此以其他方式描述的任何过程或方法描述可以被理解为,表示包括一个或更多个用于实现特定逻辑功能或过程的步骤的可执行指令的代码的模块、片段或部分,并且本发明的优选实施方式的范围包括另外的实现,其中可以不按所示出或讨论的顺序,包括根据所涉及的功能按基本同时的方式或按相反的顺序,来执行功能,这应被本发明的实施例所属技术领域的技术人员所理解。Any description of a process or method in the flowcharts or otherwise described herein may be understood to represent a module, segment or portion of code comprising one or more executable instructions for implementing a specified logical function or step of the process , and the scope of the preferred embodiments of the invention includes alternative implementations in which the functions may be performed out of the order shown or discussed, including performing the functions substantially concurrently or in the reverse order depending upon the functions involved, which should It is understood by those skilled in the art to which the embodiments of the present invention belong.

本技术领域的普通技术人员可以理解实现上述实施例方法携带的全部或部分步骤是可以通过程序来指令相关的硬件完成,所述的程序可以存储于一种计算机可读存储介质中,该程序在执行时,包括方法实施例的步骤之一或其组合。Those skilled in the art can understand that all or part of the steps carried by the methods of the above embodiments can be completed by instructing the relevant hardware through a program, and the program can be stored in a computer-readable storage medium, and the program can be stored in a computer-readable storage medium. When executed, one or a combination of the steps of the method embodiment is included.

在本说明书的描述中,参考术语“一个实施例”、“一些实施例”、“示例”、“具体示例”、或“一些示例”等的描述意指结合该实施例或示例描述的具体特征、结构、材料或者特点包含于本发明的至少一个实施例或示例中。在本说明书中,对上述术语的示意性表述不一定指的是相同的实施例或示例。而且,描述的具体特征、结构、材料或者特点可以在任何的一个或多个实施例或示例中以合适的方式结合。In the description of this specification, description with reference to the terms "one embodiment," "some embodiments," "example," "specific example," or "some examples", etc., mean specific features described in connection with the embodiment or example , structure, material or feature is included in at least one embodiment or example of the present invention. In this specification, schematic representations of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the particular features, structures, materials or characteristics described may be combined in any suitable manner in any one or more embodiments or examples.

以上的实施例仅是对本发明的优选实施方式进行描述,并非对本发明的范围进行限定,在不脱离本发明设计精神的前提下,本领域普通工程技术人员对本发明的技术方案做出的各种变形和改进,均应落入本发明的权利要求书确定的保护范围内。The above embodiments are only to describe the preferred embodiments of the present invention, and do not limit the scope of the present invention. Variations and improvements should fall within the protection scope determined by the claims of the present invention.

Claims (8)

1.一种基于生物特征识别的全网统一身份认证方法,其特征在于,包括:1. a network-wide unified identity authentication method based on biometric identification, is characterized in that, comprises: 被认证端通过生物特征采集器采集用户的生物特征,得到用户待认证生物特征信息,并向认证端发送认证请求;The authenticated end collects the user's biometrics through the biometrics collector, obtains the user's biometrics information to be authenticated, and sends an authentication request to the authenticating end; 被认证端将第一采集信息发送至被认证端本地信任服务器,其中,所述第一采集信息包括用户ID标识信息、被认证端标识地址信息和所述用户待认证生物特征信息;The authenticated end sends the first collection information to the authenticated end local trust server, wherein the first collection information includes user ID identification information, the authenticated end identification address information and the user's biometric feature information to be authenticated; 所述被认证端本地信任服务器如果查询到所述用户ID标识信息,则比对所述用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将所述比对结果通过信任锚子系统发送至认证端,其中,所述用户认证生物特征信息为与所述用户ID标识信息对应的真实的用户的生物特征信息;If the authenticated end local trust server finds the user ID identification information, it compares whether the biometric information of the user to be authenticated is consistent with the user authentication biometric information, obtains a comparison result, and passes the comparison result. The trust anchor subsystem is sent to the authentication terminal, wherein the user authentication biometric information is the real user biometric information corresponding to the user ID identification information; 所述被认证端本地信任服务器如果没有查询到所述用户ID标识信息,则向所述信任锚子系统查询所述用户ID标识信息,如果所述信任锚子系统查询到所述用户ID标识信息,则所述信任锚子系统中的权限信任服务器将所述用户认证生物特征信息发送至所述被认证端本地信任服务器,所述被认证端本地信任服务器比对所述用户待认证生物特征信息与所述用户认证生物特征信息是否一致,得到比对结果,将所述比对结果发送至认证端;If the local trust server of the authenticated end does not query the user ID identification information, it queries the trust anchor subsystem for the user ID identification information, if the trust anchor subsystem queries the user ID identification information , the authority trust server in the trust anchor subsystem sends the user authentication biometric information to the authenticated end local trust server, and the authenticated end local trust server compares the biometric information of the user to be authenticated Whether it is consistent with the user authentication biometric information, a comparison result is obtained, and the comparison result is sent to the authentication terminal; 所述认证端根据所述认证请求以及所述比对结果进行是否认证通过的判断;The authentication terminal judges whether the authentication is passed according to the authentication request and the comparison result; 其中:in: 所述被认证端本地信任服务器如果没有查询到所述用户ID标识信息,则向信任锚子系统查询所述用户ID标识信息,如果所述信任锚子系统查询到所述用户ID标识信息,则所述信任锚子系统中的权限信任服务器将所述用户认证生物特征信息发送至所述被认证端本地信任服务器,所述被认证端本地信任服务器比对所述用户待认证生物特征信息与所述用户认证生物特征信息是否一致,得到比对结果,将所述比对结果发送至认证端包括:If the local trust server of the authenticated end does not query the user ID identification information, it queries the trust anchor subsystem for the user ID identification information, and if the trust anchor subsystem queries the user ID identification information, then The authority trust server in the trust anchor subsystem sends the user authentication biometric information to the authenticated end local trust server, and the authenticated end local trust server compares the biometric information of the user to be authenticated with the user authentication information. Check whether the user authentication biometric information is consistent, obtain a comparison result, and send the comparison result to the authentication terminal including: 所述被认证端本地信任服务器如果没有查询到所述用户ID标识信息,则向所述信任锚子系统中的与所述认证端本地信任服务器连接的权限信任服务器查询所述用户ID标识信息,如果在所述权限信任服务器上查询到所述用户ID标识信息,则由与所述权限信任服务器连接的与所述用户ID标识信息对应的本地信任服务器对比所述用户待认证生物特征信息与所述用户认证生物特征信息是否一致,得到比对结果,将所述比对结果发送至认证端;如果在所述权限信任服务器上没有查询到所述用户ID标识信息,则向与所述权限信任服务器连接的顶级信任服务器查询所述用户ID标识信息,如果在所述顶级信任服务器下的权限信任服务器上查询到所述用户ID标识信息,则由与所述顶级信任服务器下的权限信任服务器连接的存有所述用户ID标识信息的本地信任服务器对比所述用户待认证生物特征信息与所述用户认证生物特征信息是否一致,得到比对结果,将所述比对结果发送至认证端;如果在所述顶级信任服务器下的权限信任服务器上没有查询到所述用户ID标识信息,则向与所述顶级信任服务器连接的根信任服务器查询所述用户ID标识信息,如果所述根信任服务器下的权限信任服务器上存有所述用户ID标识信息,则通过所述根信任服务器向与所述根信任服务器连接的存储有所述用户ID标识信息的顶级信任服务器向存储有所述用户ID标识信息的权限信任服务器进行查询,在存储有所述用户ID标识信息的权限信任服务器查询到所述用户认证生物特征信息时,由与存储有所述用户ID标识信息的权限信任服务器连接的本地信任服务器对比所述用户待认证生物特征信息与所述用户认证生物特征信息是否一致,得到比对结果,将所述比对结果发送至认证端;If the authenticated end local trust server does not query the user ID identification information, then query the user ID identification information from the authority trust server in the trust anchor subsystem that is connected to the authenticating end local trust server, If the user ID identification information is queried on the authority trust server, the local trust server connected to the authority trust server and corresponding to the user ID identification information compares the biometric information of the user to be authenticated with the user ID information. Whether the biometric information of the user authentication is consistent, obtain the comparison result, and send the comparison result to the authentication terminal; The top-level trust server connected to the server queries the user ID identification information, and if the user ID identification information is queried on the authority trust server under the top-level trust server, it will be connected to the authority trust server under the top-level trust server. The local trust server that has the user ID identification information compares whether the biometric information to be authenticated of the user is consistent with the biometric information for authentication of the user, obtains a comparison result, and sends the comparison result to the authentication terminal; if If the user ID identification information is not queried on the authority trust server under the top-level trust server, the user ID identification information is queried from the root trust server connected to the top-level trust server. The user ID identification information is stored on the authority trust server of When the authority trust server storing the user ID identification information queries the user authentication biometric information, the local trust server connected to the authority trust server storing the user ID identification information is queried. The server compares whether the biometric information of the user to be authenticated is consistent with the biometric information for authentication of the user, obtains a comparison result, and sends the comparison result to the authentication terminal; 所述被认证端本地信任服务器如果没有查询到所述用户ID标识信息,则向信任锚子系统查询所述用户ID标识信息,如果所述信任锚子系统查询到所述用户ID标识信息,则所述信任锚子系统中的权限信任服务器将所述用户认证生物特征信息发送至所述被认证端本地信任服务器,所述被认证端本地信任服务器比对所述用户待认证生物特征信息与所述用户认证生物特征信息是否一致,得到比对结果,将所述比对结果发送至认证端包括:If the local trust server of the authenticated end does not query the user ID identification information, it queries the trust anchor subsystem for the user ID identification information, and if the trust anchor subsystem queries the user ID identification information, then The authority trust server in the trust anchor subsystem sends the user authentication biometric information to the authenticated end local trust server, and the authenticated end local trust server compares the biometric information of the user to be authenticated with the user authentication information. Check whether the user authentication biometric information is consistent, obtain a comparison result, and send the comparison result to the authentication terminal including: 所述被认证端本地信任服务器如果没有查询到所述用户ID标识信息,则通过迭代查询,向所述被认证端本地信任服务器上级的根信任服务器请求查询所述用户ID标识信息,如果在所述根信任服务器上查询到所述用户ID标识信息,则返回所述用户ID标识信息所属的顶级信任服务器的地址,被认证端本地信任服务器向所述用户ID标识信息所属的顶级信任服务器请求查询所述用户ID标识信息,如果在顶级信任服务器上查询到所述用户ID标识信息,则返回所述用户ID标识信息所属的权限信任服务器的地址,所述被认证端本地信任服务器向所述用户ID标识信息所属的权限信任服务器请求查询所述用户ID标识信息,如果在所述权限信任服务器上查询到所述用户ID标识信息,则返回给所述被认证端本地信任服务器与所述用户ID标识信息对应的所述用户认证生物特征信息,所述被认证端本地信任服务器对比所述用户待认证生物特征信息与所述用户认证生物特征信息是否一致,得到比对结果,将所述比对结果发送至认证端。If the authenticated end local trust server does not query the user ID identification information, then through the iterative query, request to query the user ID identification information from the root trust server of the upper level of the authenticated end local trust server. If the user ID identification information is queried on the root trust server, the address of the top-level trust server to which the user ID identification information belongs is returned, and the local trust server of the authenticated end requests a query from the top-level trust server to which the user ID identification information belongs. For the user ID identification information, if the user ID identification information is queried on the top-level trust server, the address of the authority trust server to which the user ID identification information belongs is returned, and the authenticated local trust server reports to the user. The authority trust server to which the ID identification information belongs requests to query the user ID identification information. If the user ID identification information is queried on the authority trust server, it returns to the authenticated local trust server and the user ID. The user authentication biometric information corresponding to the identification information, the authenticated end local trust server compares the user biometric information to be authenticated with the user authentication biometric information, obtains a comparison result, and compares the The result is sent to the authenticator. 2.根据权利要求1所述的方法,其特征在于,还包括:2. The method of claim 1, further comprising: 所述被认证端通过生物特征采集器采集所述用户的生物特征,得到所述用户认证生物特征信息;The authenticated end collects the biometrics of the user through a biometrics collector to obtain the user authentication biometrics information; 所述被认证端将第二采集信息发送至所述被认证端本地信任服务器,其中,所述第二采集信息包括所述用户ID标识信息、所述被认证端标识地址信息和所述用户认证生物特征信息;The authenticated end sends second collection information to the authenticated end local trust server, wherein the second collection information includes the user ID identification information, the authenticated end identification address information and the user authentication biometric information; 所述被认证端本地信任服务器将所述第二采集信息发送至所述信任锚子系统;The authenticated end local trust server sends the second collection information to the trust anchor subsystem; 所述信任锚子系统中的权限信任服务器获取所述第二采集信息,并存储所述第二采集信息。The authority trust server in the trust anchor subsystem acquires the second collection information and stores the second collection information. 3.根据权利要求2所述的方法,其特征在于,所述被认证端本地信任服务器将所述第二采集信息发送至所述信任锚子系统;所述信任锚子系统中的权限信任服务器获取所述第二采集信息,并存储所述第二采集信息包括:3. The method according to claim 2, wherein the local trust server of the authenticated end sends the second collection information to the trust anchor subsystem; the authority trust server in the trust anchor subsystem Acquiring the second collection information and storing the second collection information includes: 所述被认证端本地信任服务器根据所述用户ID标识信息比对所述信任锚子系统中的所述被认证端本地信任服务器连接的权限信任服务器的地址是否为与所述用户ID标识信息对应的权限信任服务器;The authenticated end local trust server compares, according to the user ID identification information, whether the address of the authority trust server connected to the authenticated end local trust server in the trust anchor subsystem is corresponding to the user ID identification information The authority trust server; 如果是,则所述被认证端本地信任服务器将所述第二采集信息发送至所述被认证端本地信任服务器连接的权限信任服务器;If yes, then the authenticated end local trust server sends the second collection information to the authority trust server connected to the authenticated end local trust server; 所述被认证端本地信任服务器连接的权限信任服务器获取所述第二采集信息,并存储所述第二采集信息。The authority trust server connected to the local trust server of the authenticated terminal acquires the second collection information, and stores the second collection information. 4.根据权利要求2所述的方法,其特征在于,所述被认证端本地信任服务器将所述第二采集信息发送至所述信任锚子系统;所述信任锚子系统中的权限信任服务器获取所述第二采集信息,并存储所述第二采集信息包括:4. The method according to claim 2, wherein the local trust server of the authenticated end sends the second collection information to the trust anchor subsystem; the authority trust server in the trust anchor subsystem Acquiring the second collection information and storing the second collection information includes: 所述被认证端本地信任服务器根据所述用户ID标识信息比对所述信任锚子系统中的所述被认证端本地信任服务器连接的权限信任服务器的地址是否为与所述用户ID标识信息对应的权限信任服务器;The authenticated end local trust server compares, according to the user ID identification information, whether the address of the authority trust server connected to the authenticated end local trust server in the trust anchor subsystem is corresponding to the user ID identification information The authority trust server; 如果不是,所述被认证端则比对所述权限信任服务器连接的顶级信任服务器的地址是否为与所述用户ID标识信息对应的顶级信任服务器;如果不是,则向与所述顶级权限服务器连接的根信任服务器进行访问,所述根信任服务器根据所述用户ID标识信息找到与所述用户ID标识信息对应的顶级信任服务器,并从所述与所述用户ID标识信息对应的顶级信任服务器进行访问,找到与所述用户ID标识信息对应的权限信任服务器,将所述第二采集信息发送至所述与所述用户ID标识信息对应的权限信任服务器;If not, the authenticated end compares whether the address of the top-level trust server connected to the authority trust server is the top-level trust server corresponding to the user ID identification information; if not, it connects to the top-level authority server The root trust server to access, the root trust server finds the top-level trust server corresponding to the user ID identification information according to the user ID identification information, and from the top-level trust server corresponding to the user ID identification information. Access, find the authority trust server corresponding to the user ID identification information, and send the second collection information to the authority trust server corresponding to the user ID identification information; 与所述用户ID标识信息对应的权限信任服务器获取所述第二采集信息,并存储所述第二采集信息。The authority trust server corresponding to the user ID identification information acquires the second collection information, and stores the second collection information. 5.一种基于生物特征识别的全网统一身份认证系统,其特征在于,包括:被认证端、认证端以及信任锚子系统;其中:所述信任锚子系统至少包括被认证端本地信任服务器;5. A network-wide unified identity authentication system based on biometric identification, comprising: an authenticated end, an authenticating end and a trust anchor subsystem; wherein: the trust anchor subsystem at least includes a local trust server of the authenticated end ; 被认证端,用于通过生物特征采集器采集用户的生物特征,得到用户待认证生物特征信息,并向认证端发送认证请求;The authenticated end is used to collect the user's biometrics through the biometrics collector, obtain the user's biometrics information to be authenticated, and send an authentication request to the authenticating end; 被认证端,还用于将第一采集信息发送至被认证端本地信任服务器,其中,所述第一采集信息包括用户ID标识信息、被认证端标识地址信息和所述用户待认证生物特征信息;The authenticated terminal is also used to send the first collection information to the local trust server of the authenticated terminal, wherein the first collection information includes user ID identification information, the identification address information of the authenticated terminal, and the biometric feature information of the user to be authenticated ; 所述被认证端本地信任服务器,用于如果查询到所述用户ID标识信息,则比对所述用户待认证生物特征信息与用户认证生物特征信息是否一致,得到比对结果,将所述比对结果通过信任锚子系统发送至认证端,其中,所述用户认证生物特征信息为与所述用户ID标识信息对应的真实的用户的生物特征信息;The local trust server of the authenticated end is used to compare whether the biometric information of the user to be authenticated is consistent with the biometric information of the user authentication if the user ID identification information is queried, obtain a comparison result, and compare the biometric information of the user to be authenticated. Sending the result to the authentication terminal through the trust anchor subsystem, wherein the user authentication biometric information is the biometric information of the real user corresponding to the user ID identification information; 所述被认证端本地信任服务器,还用于如果没有查询到所述用户ID标识信息,则向所述信任锚子系统查询所述用户ID标识信息,如果所述信任锚子系统查询到所述用户ID标识信息,则所述信任锚子系统中的权限信任服务器将所述用户认证生物特征信息发送至所述被认证端本地信任服务器,所述被认证端本地信任服务器比对所述用户待认证生物特征信息与所述用户认证生物特征信息是否一致,得到比对结果,将所述比对结果发送至认证端;The authenticated end local trust server is further configured to query the trust anchor subsystem for the user ID identification information if the user ID identification information is not queried, and if the trust anchor subsystem queries the user ID identification information, user ID identification information, the authority trust server in the trust anchor subsystem sends the user authentication biometric information to the authenticated local trust server, and the authenticated local trust server compares the user Whether the authentication biometric information is consistent with the user authentication biometric information, a comparison result is obtained, and the comparison result is sent to the authentication terminal; 所述认证端,用于根据所述认证请求以及所述比对结果进行是否认证通过的判断;the authentication terminal, configured to judge whether the authentication is passed according to the authentication request and the comparison result; 其中:in: 所述被认证端本地信任服务器,具体用于如果没有查询到所述用户ID标识信息,则向所述信任锚子系统中的与所述认证端本地信任服务器连接的权限信任服务器查询所述用户ID标识信息,如果在所述权限信任服务器上查询到所述用户ID标识信息,则由与所述权限信任服务器连接的与所述用户ID标识信息对应的本地信任服务器对比所述用户待认证生物特征信息与所述用户认证生物特征信息是否一致,得到比对结果,将所述比对结果发送至认证端;如果在所述权限信任服务器上没有查询到所述用户ID标识信息,则向与所述权限信任服务器连接的顶级信任服务器查询所述用户ID标识信息,如果在所述顶级信任服务器下的权限信任服务器上查询到所述用户ID标识信息,则由与所述顶级信任服务器下的权限信任服务器连接的存有所述用户ID标识信息的本地信任服务器对比所述用户待认证生物特征信息与所述用户认证生物特征信息是否一致,得到比对结果,将所述比对结果发送至认证端;如果在所述顶级信任服务器下的权限信任服务器上没有查询到所述用户ID标识信息,则向与所述顶级信任服务器连接的根信任服务器查询所述用户ID标识信息,如果所述根信任服务器下的权限信任服务器上存有所述用户ID标识信息,则通过所述根信任服务器向与所述根信任服务器连接的存储有所述用户ID标识信息的顶级信任服务器向存储有所述用户ID标识信息的权限信任服务器进行查询,在存储有所述用户ID标识信息的权限信任服务器查询到所述用户认证生物特征信息时,由与存储有所述用户ID标识信息的权限信任服务器连接的本地信任服务器对比所述用户待认证生物特征信息与所述用户认证生物特征信息是否一致,得到比对结果,将所述比对结果发送至认证端;The authenticated-end local trust server is specifically configured to query the user for the authority trust server in the trust anchor subsystem connected to the authenticating-end local trust server if the user ID identification information is not queried ID identification information, if the user ID identification information is queried on the authority trust server, the local trust server connected to the authority trust server and corresponding to the user ID identification information compares the user's biological creature to be authenticated Whether the feature information is consistent with the user authentication biometric information, obtain a comparison result, and send the comparison result to the authentication terminal; if the user ID identification information is not queried on the authority trust server, send the comparison result to the The top-level trust server connected to the authority trust server queries the user ID identification information, and if the user ID identification information is queried on the authority trust server under the top-level trust server, the user ID identification information will be queried by the user ID identification information under the top-level trust server. The local trust server that is connected to the authority trust server and stores the user ID identification information compares whether the biometric information to be authenticated of the user is consistent with the biometric information for authentication of the user, obtains a comparison result, and sends the comparison result to Authentication end; if the user ID identification information is not queried on the authority trust server under the top-level trust server, query the user ID identification information from the root trust server connected to the top-level trust server, if the The user ID identification information is stored on the authority trust server under the root trust server, then the top-level trust server that stores the user ID identification information connected to the root trust server sends the user ID identification information to the storage device through the root trust server. The authority trust server that stores the user ID identification information queries the authority trust server that stores the user ID identification information, and when the authority trust server that stores the user ID identification information queries the user authentication biometric information, the authority trust server that stores the user ID identification information The connected local trust server compares whether the biometric information of the user to be authenticated is consistent with the biometric information for authentication of the user, obtains a comparison result, and sends the comparison result to the authentication terminal; 所述被认证端本地信任服务器,具体用于如果没有查询到所述用户ID标识信息,则通过迭代查询,向所述被认证端本地信任服务器上级的根信任服务器请求查询所述用户ID标识信息,如果在所述根信任服务器上查询到所述用户ID标识信息,则返回所述用户ID标识信息所属的顶级信任服务器的地址,被认证端本地信任服务器向所述用户ID标识信息所属的顶级信任服务器请求查询所述用户ID标识信息,如果在顶级信任服务器上查询到所述用户ID标识信息,则返回所述用户ID标识信息所属的权限信任服务器的地址,所述被认证端本地信任服务器向所述用户ID标识信息所属的权限信任服务器请求查询所述用户ID标识信息,如果在所述权限信任服务器上查询到所述用户ID标识信息,则返回给所述被认证端本地信任服务器与所述用户ID标识信息对应的所述用户认证生物特征信息,所述被认证端本地信任服务器对比所述用户待认证生物特征信息与所述用户认证生物特征信息是否一致,得到比对结果,将所述比对结果发送至认证端。The local trust server of the authenticated end is specifically used to request the root trust server of the upper level of the local trust server of the authenticated end to query the user ID identification information through an iterative query if the user ID identification information is not queried. , if the user ID identification information is queried on the root trust server, the address of the top-level trust server to which the user ID identification information belongs is returned, and the local trust server of the authenticated end reports to the top-level trust server to which the user ID identification information belongs. The trust server requests to query the user ID identification information, and if the user ID identification information is queried on the top-level trust server, the address of the authority trust server to which the user ID identification information belongs is returned, and the authenticated end local trust server Request to query the user ID identification information from the authority trust server to which the user ID identification information belongs, if the user ID identification information is queried on the authority trust server, then return to the authenticated end local trust server and The user authentication biometric information corresponding to the user ID identification information, the authenticated end local trust server compares the user biometric information to be authenticated and the user authentication biometric information whether the biometric information is consistent, obtains a comparison result, and sets the The comparison result is sent to the authentication terminal. 6.根据权利要求5所述的系统,其特征在于,所述信任锚子系统还包括:权限信任服务器;6. The system according to claim 5, wherein the trust anchor subsystem further comprises: an authority trust server; 所述被认证端,还用于通过生物特征采集器采集所述用户的生物特征,得到所述用户认证生物特征信息;The authenticated end is further configured to collect the biometrics of the user through a biometrics collector to obtain the user authentication biometrics information; 所述被认证端,还用于将第二采集信息发送至所述被认证端本地信任服务器,其中,所述第二采集信息包括所述用户ID标识信息、所述被认证端标识地址信息和所述用户认证生物特征信息;The authenticated end is further configured to send second collection information to the authenticated end local trust server, wherein the second collection information includes the user ID identification information, the authenticated end identification address information and the user authentication biometric information; 所述被认证端本地信任服务器,还用于将所述第二采集信息发送至所述信任锚子系统;The authenticated end local trust server is further configured to send the second collection information to the trust anchor subsystem; 所述信任锚子系统中的权限信任服务器,用于获取所述第二采集信息,并存储所述第二采集信息。The authority trust server in the trust anchor subsystem is configured to acquire the second collection information and store the second collection information. 7.根据权利要求6所述的系统,其特征在于,7. The system of claim 6, wherein: 所述被认证端本地信任服务器,具体用于根据所述用户ID标识信息比对所述信任锚子系统中的所述被认证端本地信任服务器连接的权限信任服务器的地址是否为与所述用户ID标识信息对应的权限信任服务器;如果是,则将所述第二采集信息发送至所述被认证端本地信任服务器连接的权限信任服务器;The authenticated end local trust server is specifically configured to compare, according to the user ID identification information, whether the address of the authority trust server connected to the authenticated end local trust server in the trust anchor subsystem is the same as that of the user. The authority trust server corresponding to the ID identification information; if so, send the second collection information to the authority trust server connected to the local trust server of the authenticated terminal; 所述被认证端本地信任服务器连接的权限信任服务器,具体用于获取所述第二采集信息,并存储所述第二采集信息。The authority trust server connected to the local trust server of the authenticated end is specifically configured to acquire the second collection information and store the second collection information. 8.根据权利要求6所述的系统,其特征在于,8. The system of claim 6, wherein: 所述被认证端本地信任服务器,具体用于根据所述用户ID标识信息比对所述信任锚子系统中的所述被认证端本地信任服务器连接的权限信任服务器的地址是否为与所述用户ID标识信息对应的权限信任服务器;如果不是,则比对所述权限信任服务器连接的顶级信任服务器的地址是否为与所述用户ID标识信息对应的顶级信任服务器;如果不是,则向与所述顶级权限服务器连接的根信任服务器进行访问,所述根信任服务器根据所述用户ID标识信息找到与所述用户ID标识信息对应的顶级信任服务器,并从所述与所述用户ID标识信息对应的顶级信任服务器进行访问,找到与所述用户ID标识信息对应的权限信任服务器,将所述第二采集信息发送至所述与所述用户ID标识信息对应的权限信任服务器;The authenticated end local trust server is specifically configured to compare, according to the user ID identification information, whether the address of the authority trust server connected to the authenticated end local trust server in the trust anchor subsystem is the same as that of the user. The authority trust server corresponding to the ID identification information; if not, compare whether the address of the top-level trust server connected to the authority trust server is the top-level trust server corresponding to the user ID identification information; The top-level authority server is connected to the root trust server for access, and the root trust server finds the top-level trust server corresponding to the user ID identification information according to the user ID identification information, and obtains the top-level trust server corresponding to the user ID identification information from the user ID identification information. The top-level trust server accesses, finds the authority trust server corresponding to the user ID identification information, and sends the second collection information to the authority trust server corresponding to the user ID identification information; 与所述用户ID标识信息对应的权限信任服务器,具体用于获取所述第二采集信息,并存储所述第二采集信息。The authority trust server corresponding to the user ID identification information is specifically configured to acquire the second collection information and store the second collection information.
CN201910027728.6A 2019-01-11 2019-01-11 A network-wide unified identity authentication method and system based on biometric identification Active CN109753779B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201910027728.6A CN109753779B (en) 2019-01-11 2019-01-11 A network-wide unified identity authentication method and system based on biometric identification

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN201910027728.6A CN109753779B (en) 2019-01-11 2019-01-11 A network-wide unified identity authentication method and system based on biometric identification

Publications (2)

Publication Number Publication Date
CN109753779A CN109753779A (en) 2019-05-14
CN109753779B true CN109753779B (en) 2020-10-30

Family

ID=66404650

Family Applications (1)

Application Number Title Priority Date Filing Date
CN201910027728.6A Active CN109753779B (en) 2019-01-11 2019-01-11 A network-wide unified identity authentication method and system based on biometric identification

Country Status (1)

Country Link
CN (1) CN109753779B (en)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110189136A (en) * 2019-05-20 2019-08-30 中国银联股份有限公司 Transaction processing method, device, equipment, medium and system

Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108881471A (en) * 2018-07-09 2018-11-23 北京信息科技大学 A kind of the whole network based on alliance uniformly trusts anchor system and construction method
CN109145540A (en) * 2018-08-24 2019-01-04 广州大学 A kind of intelligent terminal identity identifying method and device based on block chain

Family Cites Families (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20080021866A1 (en) * 2006-07-20 2008-01-24 Heather M Hinton Method and system for implementing a floating identity provider model across data centers
US8196177B2 (en) * 2008-10-16 2012-06-05 International Business Machines Corporation Digital rights management (DRM)-enabled policy management for a service provider in a federated environment

Patent Citations (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108881471A (en) * 2018-07-09 2018-11-23 北京信息科技大学 A kind of the whole network based on alliance uniformly trusts anchor system and construction method
CN109145540A (en) * 2018-08-24 2019-01-04 广州大学 A kind of intelligent terminal identity identifying method and device based on block chain

Also Published As

Publication number Publication date
CN109753779A (en) 2019-05-14

Similar Documents

Publication Publication Date Title
US10659236B2 (en) Method for superseding log-in of user through PKI-based authentication by using blockchain database of UTXO-based protocol, and server employing same
US10554421B2 (en) Method for superseding log-in of user through PKI-based authentication by using smart contact and blockchain database, and server employing same
CN111031074B (en) Authentication method, server and client
EP4002758A1 (en) Security token validation
CN108777684B (en) Identity authentication method, system and computer readable storage medium
WO2020134942A1 (en) Identity verification method and system therefor
CN1859096B (en) Safety verifying system and method
RU2434340C2 (en) Infrastructure for verifying biometric account data
JP2010501103A (en) Method and system for authentication
CN1274105C (en) Dynamic password authentication method based on digital certificate implement
CN109474437B (en) A method for applying digital certificate based on biometric information
CN108259438A (en) A kind of method and apparatus of the certification based on block chain technology
WO2022016842A1 (en) Method for concealing user information in decentralized identity system, and computer-readable medium
US20070234054A1 (en) System and method of network equipment remote access authentication in a communications network
CN112231366B (en) A blockchain-based enterprise credit report query method, device and system
WO2025001468A1 (en) Decentralized identity authentication method and related device
CN113259311A (en) Decentralized identity authentication system based on block chain
CN114499876A (en) IoT data storage method based on blockchain and NB-IoT chip
CN109753779B (en) A network-wide unified identity authentication method and system based on biometric identification
CN110647553B (en) A method and system for managing electricity transaction contracts based on blockchain
CN111383110A (en) Cross-block-chain evidence transfer method and device and hardware equipment
CN112115442B (en) Power terminal digital identity management method and system
CN115841330B (en) System and method for managing and controlling block chain cross-domain identity
CN112000937A (en) Unified login platform based on enterprise multi-application system
CN114268445A (en) Authentication method, device and system for cloud mobile phone application, authentication module and terminal

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant
OL01 Intention to license declared
OL01 Intention to license declared