[go: up one dir, main page]

CN100583734C - Method for realizing volatile secret key and separated checking module by collecting human characteristic - Google Patents

Method for realizing volatile secret key and separated checking module by collecting human characteristic Download PDF

Info

Publication number
CN100583734C
CN100583734C CN200580030854A CN200580030854A CN100583734C CN 100583734 C CN100583734 C CN 100583734C CN 200580030854 A CN200580030854 A CN 200580030854A CN 200580030854 A CN200580030854 A CN 200580030854A CN 100583734 C CN100583734 C CN 100583734C
Authority
CN
China
Prior art keywords
password
unit
key
human body
verification module
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Expired - Fee Related
Application number
CN200580030854A
Other languages
Chinese (zh)
Other versions
CN101019366A (en
Inventor
王锐勋
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Shenzhen Nano Science And Technology Co Ltd
Original Assignee
Individual
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Priority claimed from CNB2004100516793A external-priority patent/CN1272519C/en
Application filed by Individual filed Critical Individual
Publication of CN101019366A publication Critical patent/CN101019366A/en
Application granted granted Critical
Publication of CN100583734C publication Critical patent/CN100583734C/en
Anticipated expiration legal-status Critical
Expired - Fee Related legal-status Critical Current

Links

Images

Landscapes

  • Lock And Its Accessories (AREA)
  • Alarm Systems (AREA)

Abstract

A method for implementing volatile cipher key and separate verification module by collecting physical features includes: physical features sensor (11) is set on the handset (10), and control module (30) can be set separately; physical features sensor can collect physical features information of every user in advance, and said physical features can be transmitted to control module (30), and stored in user database (32); after physical features sensor (11) went away said user's body or cipher sent successfully, cipher temporary storage unit (14) reset; when registered user is operating again by using handset (10), control unit (31) can retrieve cipher data in said user database (32), and check whether same records exist or not; if same records exist, control unit (31) give a instruction to lower-stage controlled object (40); if not, control unit (31) delivers a warning information, and store an error record. Thus, potential safety hazard as a result of handset missing can be avoided, and a handset can be shared with multi-user and multi-task, thereby reduces system cost.

Description

通过采集人体特征实现易失性密钥及分离式验证模块的方法 Method for Realizing Volatile Key and Separate Verification Module by Collecting Human Body Characteristics

技术领域 technical field

本发明涉及保密或安全通信方法,特别涉及用于检验系统用户的身份或凭证的方法和装置,尤其涉及用于阅读识别印刷、书写字符或用户图形的方法和装置。The present invention relates to secure or secure communication methods, and more particularly to methods and devices for verifying the identity or credentials of system users, especially to methods and devices for reading and identifying printed, written characters or user graphics.

背景技术 Background technique

现有技术中通过验证用户身份进行下一步操作的方法,多是用不同形式的IC卡来实现,近来又有采集人体特征信息来实现上述目的的技术方案,例如中国发明专利申请号99815820,PCT/US99/29036,所公开的一种名为《利用人体部位的连续变化特征作为密钥的安全系统》的技术方案,说的是一种依赖于用户身体部分的连续变化的密钥,系统获得用户指纹的图像并且根据随机数发生器将其结合,图像仅有一部分而非全部进行发送,随机的分段确保发送的图像部分不断变化,因此未授权的接收者只能接收到一部分而非整个图像,指纹图像由远程代理者验证。In the prior art, the method of verifying the user's identity for the next step is mostly realized by using different forms of IC cards. Recently, there are technical solutions for collecting human body feature information to achieve the above purpose, such as Chinese invention patent application No. 99815820, PCT /US99/29036, discloses a technical solution called "Security System Using Continuously Changing Features of Human Body Parts as Keys", which refers to a key that depends on the continuously changing body parts of the user. The system obtains An image of the user's fingerprint and combines it according to a random number generator. Only a part of the image is sent instead of the whole. Random segmentation ensures that the part of the image sent is constantly changing, so unauthorized recipients receive only a part and not the whole image, the fingerprint image is verified by the remote agent.

再如中国发明专利申请号98812158,PCT/US98/23327,公开的名称为《利用生物统计数据生成密码密钥》的技术方案,该方案提供一种利用生物统计数据生成密码密钥的方法和设备。接收指纹并从指纹提取特征组。这些特征组可包括下述特征中的一个或多个:根据指纹的该特征组建立一个消息。对于实施例一,该消息是包括该特征组的一个样板。对于实施例二,该消息是该样板中未包括的一个特征子集。对该消息施以消息消化操作以建立一个密码密钥。再一种实施例是利用指纹图象的特征组生成一个数字证书。数字证书所使用的公用密钥基于指纹图象。Another example is Chinese Invention Patent Application No. 98812158, PCT/US98/23327, a technical scheme with the title of "Using Biometric Data to Generate Cryptographic Keys", which provides a method and device for generating cryptographic keys using biometric data . A fingerprint is received and a feature set is extracted from the fingerprint. These feature sets may include one or more of the features from which a message is built from the fingerprint. For the first embodiment, the message is a template including the feature group. For the second embodiment, the message is a feature subset not included in the template. A message digest operation is applied to the message to create a cryptographic key. Yet another embodiment uses the feature set of the fingerprint image to generate a digital certificate. The public key used by the digital certificate is based on the fingerprint image.

上述两技术方案都是每一最终的验证模块都要配置相应的人体特征采集设备,造成了资源的浪费,而且手持设备中的密码一旦设定就得以保存,不利于安全。In the above two technical solutions, each final verification module must be equipped with a corresponding human body feature collection device, resulting in a waste of resources, and the password in the handheld device can be saved once set, which is not conducive to security.

发明内容 Contents of the invention

本发明所要解决的技术问题是为了避免现有技术的不足之处而提出一种通过采集人体特征实现易失性密钥及分离式验证模块的方法,本发明在手持设备上设置一人体特征传感器,每次使用手持设备操作时,都通过该传感器把自己的人体特征信息录入到手持设备内,通过随机加密的算法,加以复合时钟数据、附加密码、唯一的设备ID(序列号)等信息做加密运算,并将加密算法的公式一起,生成密码数据。这样,即使是同一人的同一人体部位,每次生成的密码数据都是不相同的,当每次完成密码数据的传送后,即时将存储在手持设备上采集的人体特征数据及相关信息清除,该密码数据传递到验证模块中之后,进行解码,先提取设备ID码和附加密码,将设备ID码和附加密码与验证模块内黑名单数据库比对,如该设备ID码和附加密码在黑名单数据库内,将拒绝所有操作并报警,或同时存储报警信息备查。如不在黑名单数据库内,则查找注册设备ID码和附加密码数据库以确认该密钥的合法性,如此设备ID码未注册,需要验证附加密码码,通过则继续后续操作,否则报警;如此设备ID码和附加密码已注册,便将数据解码,并将人体特征的数据与时钟的数据一起比对,由于时钟不可能完全同步,在比对时,对于时钟应设置相应容限。生物特征数据验证通过后,时钟数据也在相应的设定容限内验证通过了才去执行操作指令,如果是已授权用户,就执行后续操作,否则就报警。如果同一ID的密钥连续数次,如三次报警,则将该ID数据保存于黑名单数据库中。由于引入了时钟的信息,因此即使在传送中被人截取了数据,此数据被克隆的同时,也克隆了时钟信息,再用此克隆的数据传递给比对端的时候,由于截取时的时钟与现在比对验证的时钟不一致,此数据在比对端就不能通过验证,要解码此克隆的数据,必须知道时钟信息是如何加载在数据链里的,加密算法又是怎样的,解密难度极高,几乎不可能被破解,从而进一步保证了此系统的数据传送和最终操作的安全。有了设备ID码和附加密码,也进一步保证了最终操作的安全。唯一的设备ID码在一些特殊应用场合甚至可以用来作为对使用者的跟踪和管理,如金融保险柜和其操作者、危险物品的控制和管理、军事用途、国家安全等需要增加唯一设备ID码识别功能,即密码发送时同时发送了该密钥唯一的设备ID码。当某一密钥连续数次被拒(如三次)后,该执行端验证模块将该ID保存于黑名单数据库中,并永久拒绝该密钥,直至超级用户通过操作将该ID从黑名单数据库中删除。附加密码用来在使用他人的手持设备时使用。因他人的手持设备ID未注册,所以需要合法操作者才知道的附加密码输入以确认该手持设备的临时操作合法性。The technical problem to be solved by the present invention is to propose a method for realizing a volatile key and a separate verification module by collecting human body characteristics in order to avoid the deficiencies of the prior art. The present invention sets a human body characteristic sensor on the handheld device , every time you use the handheld device to operate, you will enter your own human body feature information into the handheld device through the sensor, and use the random encryption algorithm to add composite clock data, additional passwords, unique device ID (serial number) and other information to make Encryption operation, and the formula of the encryption algorithm together to generate password data. In this way, even if it is the same human body part of the same person, the password data generated each time is different. When the transmission of the password data is completed each time, the human body characteristic data and related information collected on the handheld device will be immediately cleared. After the password data is transmitted to the verification module, it is decoded, and the device ID code and additional password are extracted first, and the device ID code and additional password are compared with the blacklist database in the verification module. If the device ID code and additional password are in the blacklist In the database, all operations will be rejected and an alarm will be issued, or the alarm information will be stored for future reference. If it is not in the blacklist database, search the registered device ID code and the additional password database to confirm the legitimacy of the key. If the device ID code is not registered, the additional password code needs to be verified. If it passes, continue the follow-up operation, otherwise alarm; After the ID code and additional password have been registered, the data will be decoded, and the data of human body characteristics will be compared with the data of the clock. Since the clock cannot be completely synchronized, a corresponding tolerance should be set for the clock when comparing. After the biometric data verification is passed, the clock data is also verified within the corresponding set tolerance before the operation command is executed. If it is an authorized user, the follow-up operation will be executed, otherwise the alarm will be reported. If the key of the same ID is consecutive for several times, such as three alarms, the ID data is saved in the blacklist database. Due to the introduction of clock information, even if the data is intercepted during transmission, the clock information is also cloned when the data is cloned. Now the clocks of the comparison verification are inconsistent, and this data cannot pass the verification at the comparison end. To decode the cloned data, one must know how the clock information is loaded in the data chain, what is the encryption algorithm, and the decryption is extremely difficult. , It is almost impossible to be cracked, thus further ensuring the security of data transmission and final operation of this system. With the device ID code and additional password, the security of the final operation is further guaranteed. The unique device ID code can even be used to track and manage users in some special applications, such as financial safes and their operators, control and management of dangerous goods, military use, national security, etc. need to add a unique device ID Code identification function, that is, when the password is sent, the unique device ID code of the key is sent at the same time. When a certain key is rejected several times in a row (such as three times), the execution terminal verification module saves the ID in the blacklist database, and permanently rejects the key until the super user operates the ID from the blacklist database Deleted in . Additional passwords are used when using other people's handheld devices. Because other people's handheld device ID is not registered, so the additional password input that legal operator just knows is needed to confirm the legality of the temporary operation of the handheld device.

本发明通过采用以下的技术方案来实现:The present invention realizes by adopting following technical scheme:

实施一种通过采集人体特征实现易失性密钥及分离式验证模块的方法,基于手持设备、信号传递通道,所述方法包括步骤:Implement a method for realizing volatile keys and separate verification modules by collecting human body characteristics, based on handheld devices and signal transmission channels, the method includes steps:

a.在手持设备上设置人体特征传感器、钥微处理器单元、密码生成单元、密码暂存单元、和钥密码数据发送单元;a. A human body feature sensor, a key microprocessor unit, a password generating unit, a password temporary storage unit, and a key password data sending unit are arranged on the handheld device;

b.设置密码数据接收单元,及包括验证单元和用户数据库的验证模块;b. Set the password data receiving unit, and the verification module including the verification unit and the user database;

c.首先,人体特征传感器单独采集每一用户的人体特征信息时,在密码生成单元生成为对应的密码,暂存于密码暂存单元之中,并通过钥密码数据发送单元经信号传递通道传输到密码数据接收单元,然后该密码经注册确认,存储在用户数据库;在人体特征传感器离开该用户人体或密码传送成功后,密码暂存单元清空;c. First, when the human body feature sensor separately collects the human body feature information of each user, it generates a corresponding password in the password generation unit, temporarily stores it in the password temporary storage unit, and transmits it through the signal transmission channel through the key password data sending unit to the password data receiving unit, and then the password is registered and confirmed, and stored in the user database; after the human body feature sensor leaves the user's body or the password is successfully transmitted, the password temporary storage unit is emptied;

d.当用户持带有人体特征传感器的手持设备操作时,通过人体特征传感器采集自己的人体特征信息,密码生成单元生成对应的密码,并暂存于密码暂存单元之中,然后注册用户将密码数据通过钥密码数据发送单元经信号传递通道传输到密码数据接收单元,验证单元就该密码数据检索用户数据库,比对是否有相同的记录;比对操作在验证单元中进行;d. When the user holds a hand-held device with a human body characteristic sensor to operate, collect his own human body characteristic information through the human body characteristic sensor, the password generation unit generates a corresponding password, and temporarily stores it in the password temporary storage unit, and then the registered user will The password data is transmitted to the password data receiving unit through the signal transmission channel through the key password data sending unit, and the verification unit searches the user database for the password data, and compares whether there is the same record; the comparison operation is carried out in the verification unit;

e.经比对,如果用户数据库内有相同的记录,则确认该用户为已注册的用户,验证单元则发出指令给下一级受控对象;如果经比对数据库内没有相同的记录,则验证单元发出警告信息,或同时存储一条错误记录。e. After comparison, if there is the same record in the user database, it is confirmed that the user is a registered user, and the verification unit sends an instruction to the next-level controlled object; if there is no identical record in the compared database, then The verification unit issues a warning message, or stores an error record at the same time.

下面是对上述方案的细化描述:The following is a detailed description of the above scheme:

所述手持设备上还包括时钟单元、钥按键组、显示单元、主密码运算器、设备ID和附加密码存储器,在执行步骤c和步骤d所述的密码生成与验证操作时,按如下步骤运行:The handheld device also includes a clock unit, a key button group, a display unit, a master password operator, a device ID and an additional password storage, and when performing the password generation and verification operations described in step c and step d, it operates as follows :

a.首先,主密码运算器将人体特征信息进行处理,形成多字节的主密码;a. First, the master password calculator processes the human body characteristic information to form a multi-byte master password;

b.将设备出厂ID、当前时钟、通过键盘输入的附加密码一同形成附加密码存于附加密码存储器;b. Combine the factory ID of the device, the current clock, and the additional password input through the keyboard to form an additional password and store it in the additional password memory;

c.然后,钥微处理器单元将附加密码存储器中的附加密码调出,将主密码与附加密码合成,合成密码暂存于密码暂存单元之中,然后向验证模块发出数据;c. Then, the key microprocessor unit calls out the additional password in the additional password memory, synthesizes the main password and the additional password, temporarily stores the synthesized password in the password temporary storage unit, and then sends data to the verification module;

d.钥微处理器单元根据操作步骤的进行,检测用户人体是否与人体特征传感器脱离,再决定延时时间后,将密码暂存单元清空,或钥微处理器单元在通过传送通道接收到验证模块返回的传送成功的确认信息后,将密码暂存单元清空。在所述手持设备上还设置钥按键组和钥显示屏,所述钥按键组受钥微处理器单元控制录入附加密码和录入临时ID码,然后存入附加密码存储器之中,钥显示屏受钥微处理器单元控制显示操作信息。d. The key microprocessor unit detects whether the user’s body is separated from the human body characteristic sensor according to the operation steps, and then clears the password temporary storage unit after determining the delay time, or the key microprocessor unit receives the verification through the transmission channel After the module returns the confirmation message of successful transmission, clear the password temporary storage unit. A key button group and a key display screen are also set on the handheld device, and the key button group is controlled by the key microprocessor unit to input an additional password and a temporary ID code, which are then stored in the additional password memory, and the key display screen is controlled by the key microprocessor unit. The key microprocessor unit controls the display of operating information.

将加密数据传送到不同的目的终端的时候,在钥显示屏上有文字、图形显示方式供选择。When transmitting encrypted data to different destination terminals, there are text and graphic display modes for selection on the key display screen.

本发明还可以通过以下的技术方案进一步得到实施:The present invention can also be further implemented through the following technical solutions:

设计制造一种通过采集人体特征实现的易失性密钥及验证模块,包括手持设备、信号传递通道、密码数据接收单元和验证模块,尤其是所述手持设备上还包括人体特征传感器、钥微处理器单元、密码生成单元、密码暂存单元和钥密码数据发送单元;所述人体特征传感器连接钥微处理器单元和密码生成单元,所述密码暂存单元连接密码生成单元和钥密码数据发送单元;人体特征传感器采集每一用户的人体特征信息,在密码生成单元生成为对应的密码,暂存于密码暂存单元之中,并通过钥密码数据发送单元经信号传递通道传输到密码数据接收单元,然后该密码经注册确认,存储在用户数据库;人体特征传感器离开该用户人体后或密码传送成功,密码暂存单元清空。Design and manufacture a volatile key and verification module realized by collecting human body characteristics, including a handheld device, a signal transmission channel, a password data receiving unit and a verification module, especially the handheld device also includes a human body characteristic sensor, a key micro Processor unit, password generation unit, password temporary storage unit, and key password data transmission unit; the human body feature sensor is connected to the key microprocessor unit and the password generation unit, and the password temporary storage unit is connected to the password generation unit and the key password data transmission unit unit; the human body characteristic sensor collects the human body characteristic information of each user, generates a corresponding password in the password generating unit, temporarily stores it in the password temporary storage unit, and transmits it to the password data receiving unit through the signal transmission channel through the key password data sending unit unit, and then the password is registered and confirmed, and stored in the user database; after the human body feature sensor leaves the user's body or the password is successfully transmitted, the password temporary storage unit is emptied.

进一步详述所述的装置:Further detailing the described device:

所述验证模块包括密码数据接收单元、验证单元、用户数据库;所述验证模块与手持设备是分开的,中间的物理联系是通过有线或无线的方式建立连接,所述验证单元连接密码数据接收单元并连接用户数据库,还连接输出接口,接收到手持设备发来的数据,验证单元对其进行比对操作,所述验证单元不仅可以在验证模块中独立设置,还可以嵌入到下一级受控对象之中。所述密码数据接收单元或独立设置,或嵌入到验证模块之中。The verification module includes a password data receiving unit, a verification unit, and a user database; the verification module is separated from the handheld device, and the physical connection in the middle is to establish a connection by wired or wireless means, and the verification unit is connected to the password data receiving unit And connect the user database, and also connect the output interface, receive the data sent by the handheld device, and the verification unit will compare it. The verification unit can not only be set independently in the verification module, but also can be embedded in the next level of controlled among the objects. The password data receiving unit is either set independently, or embedded in the verification module.

与现有技术相比较,本发明在手持设备上设置了人体特征传感器,对不同的使用者采集不同的人体信息,从而可形成不同的密码数据,该密码数据事先在验证模块内数据库进行注册,以后每次操作时,手持设备上的密码数据传输到验证模块内与数据库内的记录进行比较,有相同记录就执行后续操作,找不到已注册的记录就报警。本发明每次在手持设备内生成的密码数据,在人体离开人体特征传感器一定时间后自动清除,或数据发送成功后自动清除或在设定的时限内未发送自动清除,这样就避免了手持设备丢失而造成的安全隐患。而且,一只手持设备可以多用户多任务应用,降低了系统造价。本发明在使用者受到胁迫时有报警功能,比如可以通过操作的特殊性,如多指纹认证的顺序或附加码的特殊码段实现胁迫状态下的报警功能。Compared with the prior art, the present invention is equipped with a human body characteristic sensor on the handheld device to collect different human body information for different users, thereby forming different password data, which is registered in the database in the verification module in advance, During each operation in the future, the password data on the handheld device is transmitted to the verification module for comparison with the records in the database. If there is the same record, follow-up operations will be performed, and if the registered record cannot be found, the alarm will be reported. The password data generated in the handheld device each time in the present invention is automatically cleared after the human body leaves the human body characteristic sensor for a certain period of time, or automatically cleared after the data is successfully sent or not sent within the set time limit, so that the handheld device is avoided. Security risks caused by loss. Moreover, a handheld device can be used by multiple users and multiple tasks, which reduces the system cost. The present invention has an alarm function when the user is under duress. For example, the alarm function under duress can be realized through the particularity of the operation, such as the order of multi-fingerprint authentication or the special code segment of the additional code.

附图说明 Description of drawings

图1是本发明通过采集人体特征实现易失性密钥及分离式验证模块方法的原理方框图;Fig. 1 is the principle block diagram that the present invention realizes volatile key and separate verification module method by collecting human body characteristics;

图2是本发明所述方法中验证模块实施例二的方框图;Fig. 2 is the block diagram of verification module embodiment two in the method for the present invention;

图3是本发明所述方法中给用户授权的方法流程图;Fig. 3 is a flow chart of a method for authorizing a user in the method of the present invention;

图4是本发明所述方法中给注销用户的方法流程图;Fig. 4 is the flow chart of the method for logout user in the method of the present invention;

图5是本发明所述方法中用户在银行系统中应用的示意图;Fig. 5 is a schematic diagram of the user's application in the banking system in the method of the present invention;

图6是本发明所述方法中用户在出入境身份管理系统中应用的示意图。Fig. 6 is a schematic diagram of the user's application in the entry-exit identity management system in the method of the present invention.

具体实施方式 Detailed ways

下面参照各附图以及最佳实施例对本发明做进一步详尽的描述。The present invention will be further described in detail with reference to the accompanying drawings and preferred embodiments.

如图1所示,实施一种通过采集人体特征实现易失性密钥及验证模块的方法,基于手持设备 10、信号传递通道20,所述方法最佳实施方式包括步骤:As shown in Figure 1, implement a kind of method that realizes volatile key and verification module by collecting human body characteristics, based on handheld device 10, signal transmission channel 20, the best implementation mode of described method comprises steps:

a.在手持设备 10 上设置人体特征传感器 11、钥微处理器单元 12、密码生成单元13、密码暂存单元 14、时钟单元 19 和钥密码数据发送单元 18;a. A human body feature sensor 11, a key microprocessor unit 12, a password generation unit 13, a password temporary storage unit 14, a clock unit 19 and a key password data sending unit 18 are set on the handheld device 10;

b.设置密码数据接收单元 38,及包括验证单元 31、用户数据库 32 的验证模块 30;b. set password data receiving unit 38, and include verification module 30 of verification unit 31, user database 32;

c.首先人体特征传感器 11 采集每一用户的人体特征信息时,在密码生成单元 13生成为对应的密码,暂存于密码暂存单元14之中,并通过钥密码数据发送单元 18 经信号传递通道 20 传输到密码数据接收单元 38,然后该密码经注册确认,存储在用户数据库 32;在人体特征传感器 11 离开该用户人体或密码传送成功后,密码暂存单元 14 清空;c. First, when the human body characteristic sensor 11 collects the human body characteristic information of each user, the corresponding password is generated in the password generation unit 13, temporarily stored in the password temporary storage unit 14, and transmitted by a signal through the key password data sending unit 18 The channel 20 is transmitted to the password data receiving unit 38, and then the password is registered and confirmed and stored in the user database 32; after the human body characteristic sensor 11 leaves the user's body or the password is successfully transmitted, the password temporary storage unit 14 is emptied;

d.当用户持带有人体特征传感器 11 的手持设备 10 操作时,通过人体特征传感器11采集自己的人体特征信息,密码生成单元13再次生成对应的密码,并暂存于密码暂存单元14之中,然后用户将密码数据通过钥密码数据发送单元18经信号传递通道 20 传输到密码数据接收单元 38,验证单元 31 就该密码数据检索用户数据库 32,比对是否有相同的记录;比对操作在验证单元 31 中进行;所述验证单元 31 也可以嵌入到下一级受控对象40之中;d. When the user holds the hand-held device 10 with the human body characteristic sensor 11 to operate, collect his human body characteristic information through the human body characteristic sensor 11, the password generation unit 13 generates the corresponding password again, and temporarily stores it in the password temporary storage unit 14 , then the user transmits the password data to the password data receiving unit 38 through the signal transmission channel 20 through the key password data sending unit 18, and the verification unit 31 searches the user database 32 for the password data, and compares whether there is the same record; the comparison operation It is carried out in the verification unit 31; the verification unit 31 can also be embedded in the next-level controlled object 40;

e.经比对,如果用户数据库32内有相同的记录,验证单元31则发出指令给下一级受控对象40;如果经比对数据库内没有相同的记录,则验证单元31发出警告信息,或同时存储一条错误记录。e. After comparison, if there is the same record in the user database 32, the verification unit 31 then sends an instruction to the next-level controlled object 40; if there is no identical record in the compared database, then the verification unit 31 sends a warning message, Or store an error record at the same time.

所述手持设备10上还包括主密码运算器 131、设备ID 134和附加密码存储器133,在执行步骤c和步骤d所述的密码生成操作时,按如下步骤运行:The handheld device 10 also includes a master password calculator 131, a device ID 134 and an additional password memory 133. When performing the password generation operation described in step c and step d, it operates as follows:

a.首先,主密码运算器131将人体特征信息进行处理,形成多字节的主密码;a. First, the master password calculator 131 processes the human body characteristic information to form a multi-byte master password;

b.将设备出厂ID、当前时间、通过键盘输入的附加密码一同形成附加密码存于附加密码存储器133;b. The device factory ID, the current time, and the additional password input through the keyboard together form an additional password and store it in the additional password memory 133;

c.然后,钥微处理器单元12将附加密码存储器133中的附加密码调出,将主密码与附加密码合成,合成密码暂存于密码暂存单元14之中,然后向验证模块30发出数据;c. Then, the key microprocessor unit 12 calls out the additional password in the additional password memory 133, synthesizes the master password and the additional password, temporarily stores the synthesized password in the password temporary storage unit 14, and then sends data to the verification module 30 ;

d.钥微处理器单元 12 根据操作步骤的进行,确认数据发出后,检测用户人体是否与人体特征传感器 11 脱离,再决定延时时间后,将密码暂存单元 14 清空,或钥微处理器单元 12 在接收到验证模块 30 的确认信息后,将密码暂存单元 14清空。d. According to the operation steps, the key microprocessor unit 12 detects whether the user's body is separated from the human body characteristic sensor 11 after confirming the data is sent, and then decides the delay time, clears the password temporary storage unit 14, or the key microprocessor unit Unit 12 clears password temporary storage unit 14 after receiving confirmation information from verification module 30.

上述方法中,在所述手持设备 10 上还设置钥按键组 15 和钥显示屏 16,所述钥按键组 15 受钥微处理器单元 12 控制录入附加密码,然后存入附加密码存储器 133 之中,钥显示屏 16 受钥微处理器单元 12 控制显示操作信息。In the above method, a key button group 15 and a key display screen 16 are also set on the handheld device 10, and the key button group 15 is controlled by the key microprocessor unit 12 to input an additional password, and then stored in the additional password memory 133 , the key display screen 16 is controlled by the key microprocessor unit 12 to display operation information.

上述方法中,验证模块 30 还包括验证模块时钟单元 36 和黑名单数据库 37,步骤e所述经查询,如果经查询数据库内没有相同的记录,或接收数据中时间信息超出允许范围,则验证单元31发出警告信息,或同时存储一条错误记录之后,同一ID的密码数据连续两次以上报警时,则将该ID数据保存于黑名单数据库37中。In the above method, the verification module 30 also includes a verification module clock unit 36 and a blacklist database 37. After querying as described in step e, if there is no identical record in the query database, or the time information in the received data exceeds the allowable range, the verification unit 31 sends a warning message, or after storing an error record at the same time, when the password data of the same ID reports to the police more than twice in a row, then the ID data is saved in the blacklist database 37.

所述信号传递通道20包括借助连通的有线传输、无线传输以及红外线传输等;所述的钥密码数据发送单元18、密码数据接收单元38也包括相互匹配的有触点传输、无线传输以及红外线传输单元。The signal transmission channel 20 includes connected wired transmission, wireless transmission and infrared transmission, etc.; the key password data sending unit 18 and password data receiving unit 38 also include contact transmission, wireless transmission and infrared transmission that match each other. unit.

所述下一级受控对象40包括各类型锁具、电脑、移动电话、电子身份认证、信息管理入口、通道门禁、金融交易、网络防火墙,安全管理、授权操作。The next-level controlled objects 40 include various types of locks, computers, mobile phones, electronic identity authentication, information management entrances, channel access control, financial transactions, network firewalls, security management, and authorized operations.

所述手持设备10包括嵌入在移动电话、PDA、POS机或者移动存储盘内的手持设备及单独的手持设备,以及固定在一个有人或无人值守的场所的固定设备。The handheld device 10 includes a handheld device embedded in a mobile phone, a PDA, a POS machine or a mobile storage disk, a separate handheld device, and a fixed device fixed in a manned or unattended place.

人体特征传感器11包括指纹鉴别传感器或掌纹、掌形、面形、DNA、声波传感器或虹膜传感器或其组合。The human body feature sensor 11 includes a fingerprint identification sensor or a palm print, a palm shape, a face shape, DNA, an acoustic wave sensor or an iris sensor or a combination thereof.

本发明还可以通过采用以下的技术方案进一步来实现。The present invention can also be further realized by adopting the following technical solutions.

如图1、2所示,设计制造一种通过采集人体特征实现的易失性密钥及验证模块,包括手持设备10、信号传递通道20和验证模块30,尤其是所述手持设备10上还包括人体特征传感器11、钥微处理器单元12、密码生成单元13、密码暂存单元14和钥密码数据发送单元18;所述人体特征传感器11连接钥微处理器单元12和密码生成单元13,所述密码暂存单元14连接密码生成单元13和钥密码数据发送单元18;As shown in Figures 1 and 2, a volatile key and verification module realized by collecting human body characteristics is designed and manufactured, including a handheld device 10, a signal transmission channel 20 and a verification module 30, especially on the handheld device 10. Comprising a human body feature sensor 11, a key microprocessor unit 12, a password generation unit 13, a password temporary storage unit 14 and a key password data sending unit 18; the human body feature sensor 11 is connected to the key microprocessor unit 12 and the password generation unit 13, The password temporary storage unit 14 is connected to the password generation unit 13 and the key password data sending unit 18;

人体特征传感器11采集每一用户的人体特征信息,在密码生成单元13生成为对应的密码,暂存于密码暂存单元14之中,并通过钥密码数据发送单元18经信号传递通道20传输到验证模块30,然后该密码经注册确认,存储在用户数据库32;人体特征传感器11离开该用户人体后或密码传送成功,密码暂存单元14清空。The human body characteristic sensor 11 collects the human body characteristic information of each user, generates a corresponding password in the password generation unit 13, temporarily stores it in the password temporary storage unit 14, and transmits it to Verification module 30, then the password is registered and confirmed, and stored in the user database 32; after the human body feature sensor 11 leaves the user's body or the password is successfully transmitted, the password temporary storage unit 14 is emptied.

密码数据接收单元38或独立设置或嵌入到验证模块30之中,所述验证模块30包括验证单元31、用户数据库32;所述验证单元31连接密码数据接收单元38并连接用户数据库32,还连接输出接口39;所述验证模块30接收到手持设备10发来的数据,验证单元31对其进行比对操作。Password data receiving unit 38 or independent setting or be embedded among verification module 30, described verification module 30 comprises verification unit 31, user database 32; Described verification unit 31 connects password data receiving unit 38 and connects user database 32, also connects Output interface 39; the verification module 30 receives the data sent by the handheld device 10, and the verification unit 31 performs a comparison operation on it.

所述验证单元31也可以嵌入到下一级受控对象40之中。The verification unit 31 can also be embedded in the next-level controlled object 40 .

在所述手持设备10上还包括钥按键组15和钥显示屏16,所述钥按键组15连接钥微处理器单元12录入附加密码;并存入钥微处理器单元12连接的附加密码存储器133;钥显示屏16连接钥微处理器单元12显示操作信息。Also comprise key button group 15 and key display screen 16 on described handheld device 10, described key button group 15 connects key microprocessor unit 12 and enters additional password; And store in the additional password memory that key microprocessor unit 12 connects 133 ; the key display screen 16 is connected to the key microprocessor unit 12 to display operation information.

在所述手持设备10上还包括时钟单元19、主密码运算器131、设备出厂ID134和附加密码存储器133,主密码运算器131将人体特征信息进行处理,形成多字节的主密码,与设备出厂ID、当前时间、通过键盘输入的附加密码一同形成附加密码。The handheld device 10 also includes a clock unit 19, a master password calculator 131, a device factory ID 134, and an additional password memory 133. The master password calculator 131 processes the human body characteristic information to form a multi-byte master password, which is compatible with the device. The factory ID, the current time, and the additional password input through the keyboard together form an additional password.

所述信号传递通道20包括有触点传输、无线传输以及红外线传输;所述的钥密码数据发送单元18、密码数据接收单元38为相互匹配的有触点传输,或为无线传输以及或为红外线传输模式。The signal transmission channel 20 includes contact transmission, wireless transmission and infrared transmission; the key password data sending unit 18 and password data receiving unit 38 are contact transmission that match each other, or wireless transmission and or infrared transmission. transfer mode.

所述人体特征传感器11包括指纹鉴别传感器或掌纹、掌形、面形、DNA、声波传感器或虹膜传感器或其组合。The human body feature sensor 11 includes a fingerprint identification sensor or a palm print, a palm shape, a face shape, DNA, an acoustic wave sensor or an iris sensor or a combination thereof.

如图2所示:在本发明实施例二之中,在所述验证模块30上还设置验证模块按键组33、验证模块显示器34和验证模块报警器35,所述验证模块按键组33连接验证单元31,用于输入操作指令;所述验证模块显示器34亦受验证单元31控制,用于显示操作结果、报警信息,在此实施例中,液晶显示器的驱动器选用EA V-D2004OAR,当然在其他的实施方式中可以有不同的显示器和驱动器的选择。所述验证模块报警器35亦受验证单元31控制发出音响报警信号。As shown in Figure 2: in the second embodiment of the present invention, a verification module button group 33, a verification module display 34 and a verification module alarm 35 are also set on the verification module 30, and the verification module button group 33 is connected to verify Unit 31 is used to input operation instructions; the verification module display 34 is also controlled by the verification unit 31, and is used to display operation results and alarm information. In this embodiment, the driver of the liquid crystal display is selected from EAV-D2004OAR, certainly in other The implementation may have different display and driver options. The verification module alarm 35 is also controlled by the verification unit 31 to send out an audible alarm signal.

验证模块30还包括验证模块时钟单元36和黑名单数据库37,在查询后数据库内没有与接收数据相同的记录,或接收数据中时间信息超出允许范围,则验证单元31发出警告信息,或同时存储一条错误记录;在一密码数据连续三次报警时,则将该密码数据保存于黑名单数据库37中。The verification module 30 also includes a verification module clock unit 36 and a blacklist database 37. After the query, there is no record identical to the received data in the database, or the time information in the received data exceeds the allowable range, then the verification unit 31 sends a warning message, or stores simultaneously An error record; when a password data reports to the police three times in a row, then this password data is saved in the blacklist database 37.

所述验证模块30,可以是物理上单独的模块,也可以由运行计算机程序来实现。The verification module 30 may be a physically separate module, or may be implemented by running a computer program.

所述输出接口39受验证单元31控制,与下一级受控对象40的通讯可以采用RS485通讯,也可以采用CAN总线方式或其他总线方式,还可以是局域网、互联网,可以采用有线连接,或无线传输。而且在形成网络控制之后,每个下一级受控对象40都接受网络系统的控制指令,并将本设备数据传输到网络控制的主计算机。The output interface 39 is controlled by the verification unit 31, and the communication with the next-level controlled object 40 can adopt RS485 communication, can also adopt CAN bus mode or other bus modes, can also be local area network, Internet, can adopt wired connection, or Wireless transmission. And after the network control is formed, each next-level controlled object 40 accepts the control command of the network system, and transmits the data of the device to the host computer of the network control.

在最佳实施例中,人体特征传感器11采用指纹鉴别传感器。在其他实施方式中可以采用DNA传感器、面形、掌形或其它的生物传感器。In a preferred embodiment, the human body feature sensor 11 is a fingerprint authentication sensor. In other embodiments DNA sensors, face, palm or other biosensors may be used.

如图3所示,本发明具有密码授权功能及授权密码管理功能。密码的存储,采用加密存储的方法,即必须使用解密算法才能读出正确的密码或读出的数据经解密算法才能恢复为正确的密码。密码可以分为三级:超级密码(一级)、管理员密码(二级)、用户密码(三级)。验证模块30在初始状态下不具备任何密码,第一次使用的会有一个系统设定的默认的超级密码,在第一次使用的时候要修改这个默认的超级密码为自己设定的。在非群组使用时,其它密码的设定除有超级密码外还必须有在未执行操作状态下两种以上的组合,以进一步提高密码授权的安全性。As shown in FIG. 3 , the present invention has a password authorization function and an authorization password management function. The storage of the password adopts the method of encrypted storage, that is, the correct password must be read out only by using the decryption algorithm or the read data can be restored to the correct password by the decryption algorithm. The password can be divided into three levels: super password (level 1), administrator password (level 2), user password (level 3). The verification module 30 does not have any password in the initial state, and there will be a default super password set by the system when used for the first time, and this default super password should be modified to set for oneself when used for the first time. In non-group use, the setting of other passwords must have two or more combinations in the non-executed state in addition to the super password, so as to further improve the security of password authorization.

其中,超级密码可以授权或注销管理员密码、用户密码,可以执行下一步操作;如有必要,超级密码可以授权多个与其一样的超级密码。Among them, the super password can authorize or cancel the administrator password and user password, and the next operation can be performed; if necessary, the super password can authorize multiple super passwords that are the same as it.

管理员密码可以授权或注销用户密码,可以执行下一步操作,但不可以授权或注销超级密码、管理员密码;用户密码只可以执行下一步操作。The administrator password can authorize or cancel the user password, and can perform the next operation, but cannot authorize or cancel the super password and administrator password; the user password can only perform the next operation.

验证模块30在不需要联网使用时,可以不设管理员密码。超级密码和管理员密码可以查看授权用户列表的用户名,所有操作都不能查看到用户密码。When the verification module 30 does not need to be used through networking, the administrator password may not be set. The super password and administrator password can view the user name of the authorized user list, and all operations cannot view the user password.

如图4所示,注销某一用户时,按图示流程操作。As shown in Figure 4, when logging out a certain user, operate according to the process shown in the figure.

通过网络接口,可以有多台终端共同管理,甚至通过Internet或专用网络实现异地管理。服务器或一体化终端与终端的联接可以通过公知的技术来实现,如使用基于双绞线的各种总线及网络技术(例如RS485、CAN,以太网等)。这样的系统通常用于宾馆饭店等需要集团管理的领域,家庭如有需要也可使用,如实现家内各门锁、家具锁等的集中管理及报警等。Through the network interface, multiple terminals can be managed together, and even remote management can be realized through the Internet or a dedicated network. The connection between the server or the integrated terminal and the terminal can be realized through known technologies, such as using various bus and network technologies based on twisted pairs (such as RS485, CAN, Ethernet, etc.). Such a system is usually used in areas requiring group management, such as hotels and restaurants, and can also be used by families if necessary, such as realizing centralized management and alarming of door locks and furniture locks in the home.

验证模块30本身可以有验证模块报警器35,也可以不设置,这时报警可以通过通信口来实现,如通过一个接口来自动拨打电话给主人或大厦/小区管理处或治安部门等。Verification module 30 itself can have verification module annunciator 35, also can not be provided with, and at this moment alarm can be realized by communication port, as automatically dialing a phone to owner or building/community management office or public security department etc. by an interface.

本发明的再一个实施例结合了移动电话的手持设备10,通过移动电话的按键可以方便的设定附加密码,在针对不同的操作对象,可以将密码数据直接通过有线或无线方式直接传递给验证模块,也可以通过手机的GSM或CDMA网络将密码数据中转传送给验证端,将授权设定时的手指放于人体特征传感器11的指纹检测区,并输入相应的附加信息后按下发送按钮,如果是直接发送给近距离的验证模块,就需要将钥密码数据发送单元18贴近验证模块30的密码数据接收单元38接受部位,密码数据即送入确认后,密码自动清除,等待下一次操作。还可以通过专设的服务网站对委托用户提供24小时值班防盗监控,如汽车的防盗监控并通过授权对报警车遥控断开电路、油路,配合定位系统定位等。在使用的时候,汽车内的密码数据接收单元38将收到的数据传输到验证单元31进行解码、解码后的指纹数据与已录入登记的用户数据库32的指纹数据比对,当一致的时候,再对附加码进行解码,解码的数据与码表进行比对,根据比对结果去驱动相应的电路去执行,如可以完成汽车驾驶者的身份验证,从而可以控制汽车锁的开闭、空调的起停、温度调节等。Yet another embodiment of the present invention combines the handheld device 10 of the mobile phone, and the additional password can be conveniently set through the buttons of the mobile phone. For different operation objects, the password data can be directly transmitted to the verification device directly by wired or wireless means. The module can also transfer the password data to the verification terminal through the GSM or CDMA network of the mobile phone, place the finger during the authorization setting on the fingerprint detection area of the human body feature sensor 11, and input the corresponding additional information and press the send button. If it is directly sent to the verification module at close range, it is necessary to put the key password data sending unit 18 close to the password data receiving unit 38 acceptance position of the verification module 30, after the password data is sent into confirmation, the password is automatically cleared and waits for the next operation. It is also possible to provide 24-hour on-duty anti-theft monitoring to entrusted users through a dedicated service website, such as anti-theft monitoring for cars, and through authorization to remotely disconnect the circuit and oil circuit of the alarm car, and coordinate with the positioning system for positioning. When in use, the password data receiving unit 38 in the car transmits the received data to the verification unit 31 for decoding, the fingerprint data after decoding is compared with the fingerprint data of the registered user database 32, and when consistent, Then decode the additional code, compare the decoded data with the code table, and drive the corresponding circuit to execute according to the comparison result. Start and stop, temperature adjustment, etc.

由于手持设备10本身没有任何密码,因此,手持设备10的遗失仅意味着手持设备10本身经济价值的损失,而不会有其它恶果。只需找到本发明的任意一手持设备10,如从邻居、保安等处借取,即可执行自己的操作。被借取人不需担心自己的密码外泄,借取人也不用担心自己的密码外泄。作为服务的提供方式,大厦管理处、保安及其它服务部门均可提供公钥便利服务。Since the handheld device 10 itself does not have any password, the loss of the handheld device 10 only means the loss of the economic value of the handheld device 10 itself, without other evil consequences. You only need to find any handheld device 10 of the present invention, such as borrowing from neighbors, security guards, etc., to perform your own operations. The borrowee does not need to worry about his password leaking, and the borrower does not need to worry about his password leaking either. As a way of providing services, the building management office, security and other service departments can provide public key convenience services.

移动电话作为手持设备10支付费用与代付的实施例:首先在银行将用户的指纹登记,再与用户的账户联系起来,在数据库内形成记录。交易时,在交易商的POS端,用移动电话的短信方式或GPRS方式或CDMA1X等方式将消费金额及POS机的信息传送给银行方面,发送的时候在移动电话的指纹采集器中输入指纹,此时,用户输入的消费金额及指纹信息一并发送到了银行方面,或者是通过设在交易商处的有线采集设备,将客户的指纹信息传输到银行进行身份验证,验证端存储有客户的指纹信息,验证无误后,银行方面回馈信息到该交易商的POS机上打印交易成功的凭证并将相应货款划给交易商,交易即告完成。该功能不仅能为自己的消费带来方便,也可以为他人的消费进行支付。The mobile phone is used as the embodiment of the hand-held device 10 to pay the fee and pay on behalf: first register the user's fingerprint in the bank, then link it with the user's account, and form a record in the database. During the transaction, on the POS terminal of the dealer, the consumption amount and the information of the POS machine are sent to the bank by means of SMS, GPRS or CDMA1X of the mobile phone, and the fingerprint is input into the fingerprint collector of the mobile phone when sending. At this time, the consumption amount and fingerprint information entered by the user are sent to the bank together, or the customer's fingerprint information is transmitted to the bank through a wired acquisition device installed at the dealer for identity verification, and the verification terminal stores the customer's fingerprint After the information is verified to be correct, the bank will feed back the information to the dealer's POS machine to print a successful transaction certificate and transfer the corresponding payment to the dealer, and the transaction will be completed. This function can not only bring convenience to your own consumption, but also pay for other people's consumption.

本发明的再一个实施例,银行用系统如图5所示,此时的信号传递通道20属于有线传输,手持设备10类似于POS的密码录入器与计算机连接,用来进行用户注册,其注册过程与使用分离的手持设备10相同。信息数据存入数据库之后,手持设备10上不保存密码信息。还可以将无线传输的密码数据接收单元38设置在此设备之内,用来无线接收分离的手持设备10的操作,还可以将此实施例应用于自动提款机ATM或商场收银POS机。银行用系统200通过网络500可以与第三方网络信息经营商或与更多的系统交换信息,扩展更多的功能。In yet another embodiment of the present invention, the banking system is as shown in Figure 5, the signal transmission channel 20 at this time belongs to wired transmission, and the handheld device 10 is similar to a POS password entry device connected to a computer for user registration. The procedure is the same as using a separate handheld device 10 . After the information data is stored in the database, the password information is not saved on the handheld device 10 . The password data receiving unit 38 for wireless transmission can also be set in this device to wirelessly receive the operation of the separate handheld device 10, and this embodiment can also be applied to automatic teller machines (ATMs) or POS machines in shopping malls. The banking system 200 can exchange information with third-party network information operators or with more systems through the network 500 to expand more functions.

本发明的再一个实施例,出入境管理系统如图6所示,此时的信号传递通道20也属于有线传输,手持设备10与计算机连接,用来进行入境者注册。其注册过程与使用分离的手持设备10相同。信息数据存入数据库之后,手持设备10上不保存密码信息。出入境管理系统300通过网络500与银行用系统200及其他的安全系统交换信息,可以监控入境者是否有违法交易及记录,以实现安全的管理和监控。In yet another embodiment of the present invention, the entry-exit management system is shown in Figure 6. At this time, the signal transmission channel 20 also belongs to wired transmission, and the handheld device 10 is connected to a computer for registration of immigrants. The registration process is the same as using a separate handheld device 10 . After the information data is stored in the database, the password information is not saved on the handheld device 10 . The entry-exit management system 300 exchanges information with the bank system 200 and other security systems through the network 500, and can monitor whether the immigrants have illegal transactions and records, so as to realize security management and monitoring.

本发明还可以应用于身份认证、电脑开机及数字签名。The invention can also be applied to identity authentication, computer startup and digital signature.

实践证明,本发明在手持设备上设置了人体特征传感器,对不同的使用者采集不同的人体信息,从而可形成不同的密码数据,该密码数据事先在验证模块的数据库进行注册,以后每次使用时,手持设备上的密码数据传输到验证模块中与数据库内的记录进行比较,有相同记录就执行对应操作,找不到已注册的记录就报警。本发明每次在手持设备内生成的密码数据及人体生物特征信息,在人体离开手持设备时都自动清除,这样就避免了手持设备丢失而造成的安全隐患。而且,一个手持设备可以多人多场所通用,降低了系统造价,有利于扩展更多的使用功能。Practice has proved that the present invention is equipped with a human body characteristic sensor on the handheld device to collect different human body information for different users, thereby forming different password data, which is registered in the database of the verification module in advance, and can be used every time , the password data on the handheld device is transmitted to the verification module for comparison with the records in the database, and if there is the same record, the corresponding operation will be executed, and if the registered record cannot be found, the alarm will be called. The invention automatically clears the password data and human body biometric information generated in the hand-held device each time when the human body leaves the hand-held device, thus avoiding potential safety hazards caused by loss of the hand-held device. Moreover, a handheld device can be used by multiple people and places, which reduces the system cost and facilitates the expansion of more functions.

Claims (16)

1.一种通过采集人体特征实现易失性密钥及分离式验证模块的方法,基于手持设备(10)、信号传递通道(20),其特征在于,所述方法包括步骤:1. a method of realizing volatile key and separate verification module by collecting human body characteristics, based on handheld device (10), signal transmission channel (20), it is characterized in that, described method comprises steps: a.在手持设备(10)上设置人体特征传感器(11)、钥微处理器单元(12)、密码生成单元(13)、密码暂存单元(14)和钥密码数据发送单元(18);A. Human body feature sensor (11), key microprocessor unit (12), password generation unit (13), password temporary storage unit (14) and key password data sending unit (18) are set on handheld device (10); b.设置密码数据接收单元(38),及包括验证单元(31)、用户数据库(32)的验证模块(30);B. password data receiving unit (38) is set, and comprises the verification module (30) of verification unit (31), user database (32); c.首先人体特征传感器(11)单独采集每一用户的人体特征信息时,在密码生成单元(13)生成为对应的密码,暂存于密码暂存单元(14)之中,并通过钥密码数据发送单元(18)经信号传递通道(20)传输到密码数据接收单元(38),然后该密码经注册确认,存储在用户数据库(32);在人体特征传感器(11)离开该用户人体或密码传送成功后,密码暂存单元(14)清空;c. First, when the human body feature sensor (11) separately collects the human body feature information of each user, the corresponding password is generated in the password generation unit (13), temporarily stored in the password temporary storage unit (14), and passed through the key password The data transmission unit (18) is transmitted to the password data receiving unit (38) through the signal transfer channel (20), and then the password is confirmed through registration and stored in the user database (32); After the password is transmitted successfully, the password temporary storage unit (14) is emptied; d.当用户持带有人体特征传感器(11)的手持设备(10)操作时,通过人体特征传感器(11)采集自己的人体特征信息,密码生成单元(13)生成对应的密码,并暂存于密码暂存单元(14)之中,然后该用户将密码数据通过钥密码数据发送单元(18)经信号传递通道(20)传输到密码数据接收单元(38),验证单元(31)就该密码数据检索用户数据库(32),比对是否有相同的记录;比对操作在验证单元(31)中进行;d. When the user holds the hand-held device (10) with the human body characteristic sensor (11) to operate, the human body characteristic information of himself is collected by the human body characteristic sensor (11), and the password generating unit (13) generates a corresponding password, and temporarily stores In the password temporary storage unit (14), then the user transmits the password data to the password data receiving unit (38) through the signal transmission channel (20) through the key password data sending unit (18), and the verification unit (31) Password data retrieval user database (32), compare whether identical record is arranged; Compare operation and carry out in verification unit (31); e.经比对,如果用户数据库(32)内有相同的记录,则确认该用户为已注册的用户,验证单元(31)则发出指令给下一级受控对象(40);如果经比对数据库内没有相同的记录,则验证单元(31)发出警告信息,或同时存储一条错误记录。e. After comparison, if there is the same record in the user database (32), then confirm that the user is a registered user, and the verification unit (31) then sends an instruction to the next-level controlled object (40); If there is no identical record in the database, the verification unit (31) will issue a warning message, or store an error record at the same time. 2.根据权利要求1所述的通过采集人体特征实现易失性密钥及分离式验证模块的方法,其特征在于:所述手持设备(10)上还包括时钟单元(19)、密码生成单元(13)、主密码运算器(131)、设备ID(134)和附加密码存储器(133),在执行步骤c和步骤d所述的密码生成操作时,按如下步骤运行:2. the method for realizing volatile key and separate verification module by collecting human body characteristics according to claim 1, is characterized in that: also comprise clock unit (19), password generation unit on described handheld device (10) (13), master password operator (131), equipment ID (134) and additional password memory (133), when performing the password generation operation described in step c and step d, operate as follows: a.首先,主密码运算器(131)将人体特征信息进行处理,形成多字节的主密码;a. First, the master password operator (131) processes the human body characteristic information to form a multi-byte master password; b.将设备出厂ID、当前时间、通过键盘输入的附加密码一同形成附加密码存于附加密码存储器(133);b. form the additional password together with the device factory ID, the current time, and the additional password input through the keyboard and store it in the additional password memory (133); c.然后,钥微处理器单元(12)将附加密码存储器(133)中的附加密码调出,将主密码与附加密码合成,合成密码暂存于密码暂存单元(14)之中,然后向验证模块(30)发出数据;c. Then, the key microprocessor unit (12) calls out the additional password in the additional password memory (133), synthesizes the master password and the additional password, and temporarily stores the composite password in the password temporary storage unit (14), and then Send data to the verification module (30); d.钥微处理器单元(12)根据操作步骤的进行,确认数据发出后,检测用户人体是否与人体特征传感器(11)脱离,再决定延时时间后,将密码暂存单元(14)清空,或钥微处理器单元(12)在接收到验证模块(30)的确认信息后,将密码暂存单元(14)清空。d. The key microprocessor unit (12) is carried out according to the operation steps. After confirming that the data is sent, it detects whether the user's human body is separated from the human body characteristic sensor (11), and after deciding the delay time, the password temporary storage unit (14) is emptied , or the key microprocessor unit (12) clears the password temporary storage unit (14) after receiving the confirmation information from the verification module (30). 3.根据权利要求1所述的通过采集人体特征实现易失性密钥及分离式验证模块的方法,其特征在于:在所述手持设备(10)上还设置钥按键组(15)和钥显示屏(16),所述钥按键组(15)用作录入附加密码,然后受钥微处理器单元(12)控制存入附加密码存储器(133)之中,钥显示屏(16)受钥微处理器单元(12)控制显示操作信息。3. the method for realizing the volatile key and the separate verification module by collecting human body characteristics according to claim 1, is characterized in that: the key button group (15) and key key group (15) are also set on the handheld device (10). Display screen (16), described key button group (15) is used as input additional password, is controlled by key microprocessor unit (12) and is stored among the additional password memory (133) then, and key display screen (16) is controlled by key The microprocessor unit (12) controls the display of operation information. 4.根据权利要求1所述的通过采集人体特征实现易失性密钥及分离式验证模块的方法,其特征在于:验证模块(30)还包括验证模块时钟单元(36)和黑名单数据库(37),步骤e所述比对后数据库内没有相同的记录,或接收数据中时间信息超出允许范围,则验证单元(31)发出警告信息,或同时存储一条错误记录;同一ID的密码数据连续两次或以上报警时,则将该ID数据保存于黑名单数据库(37)中。4. the method for realizing volatile key and separate verification module by collecting human body characteristics according to claim 1, is characterized in that: verification module (30) also comprises verification module clock unit (36) and blacklist database ( 37), there is no identical record in the database after the comparison described in step e, or the time information in the received data exceeds the allowable range, then the verification unit (31) sends a warning message, or stores an error record at the same time; the password data of the same ID is continuous When reporting to the police twice or more, then this ID data is saved in the blacklist database (37). 5.根据权利要求1所述的通过采集人体特征实现易失性密钥及分离式验证模块的方法,其特征在于:所述信号传递通道(20)包括借助触点连通的有线传输、无线传输以及红外线传输;所述的钥密码数据发送单元(18)、密码数据接收单元(38)也包括相互匹配的有触点传输、无线传输以及红外线传输单元。5. The method for realizing volatile keys and separate verification modules by collecting human body characteristics according to claim 1, characterized in that: the signal transmission channel (20) includes wired transmission and wireless transmission connected by contacts And infrared transmission; the key password data sending unit (18) and password data receiving unit (38) also include contact transmission, wireless transmission and infrared transmission units that match each other. 6.根据权利要求1所述的通过采集人体特征实现易失性密钥及分离式验证模块的方法,其特征在于:所述下一级受控对象(40)包括各类型锁具、电脑、移动电话、电子身份认证、信息管理入口、通道门禁、金融交易、网络防火墙,安全管理、授权操作。6. The method for realizing volatile keys and separate verification modules by collecting human body characteristics according to claim 1, characterized in that: said next-level controlled objects (40) include various types of locks, computers, mobile Telephone, electronic identity authentication, information management entrance, channel access control, financial transaction, network firewall, security management, authorized operation. 7.根据权利要求1所述的通过采集人体特征实现易失性密钥及分离式验证模块的方法,其特征在于:所述手持设备(10)包括嵌入在移动电话、PDA、POS机或者移动存储盘内的手持设备或是一个单独的手持设备,以及固定在一个有人或无人值守的场所的固定设备。7. The method for realizing volatile keys and separate verification modules by collecting human body characteristics according to claim 1, characterized in that: said handheld device (10) includes a mobile phone, PDA, POS machine or mobile A handheld device within a storage disk or a stand-alone handheld device, and a fixed device that is fixed in a manned or unattended location. 8.根据权利要求1所述的通过采集人体特征实现易失性密钥及分离式验证模块的方法,其特征在于:人体特征传感器(11)包括指纹鉴别传感器或掌纹、掌形、面形、DNA、声波传感器或汗液传感器或虹膜传感器或其组合。8. the method for realizing volatile key and separate verification module by collecting human body characteristics according to claim 1, is characterized in that: human body characteristic sensor (11) comprises fingerprint identification sensor or palmprint, palm shape, face shape , DNA, sonic sensor or sweat sensor or iris sensor or a combination thereof. 9.根据权利要求1所述的通过采集人体特征实现易失性密钥及分离式验证模块的方法,其特征在于:采集人体的生物特征与数据信息的比对由物理上分开的两个或以上设备完成。9. The method for realizing volatile keys and separate verification modules by collecting human body characteristics according to claim 1, characterized in that: the comparison between collecting human body's biological characteristics and data information is performed by physically separated two or The above equipment is completed. 10.一种通过采集人体特征实现的易失性密钥及分离式验证模块,包括手持设备(10)、信号传递通道(20)、密码数据接收单元(38)和验证模块(30),其特征在于:所述手持设备(10)上还包括人体特征传感器(11)、钥微处理器单元(12)、密码生成单元(13)、密码暂存单元(14)和钥密码数据发送单元(18);所述钥微处理器单元(12)连接人体特征传感器(11)和密码生成单元(13),所述密码暂存单元(14)连接密码生成单元(13)和钥密码数据发送单元(18);人体特征传感器(11)采集每一用户的人体特征信息,在密码生成单元(13)生成为对应的密码,暂存于密码暂存单元(14)之中,并通过钥密码数据发送单元(18)经信号传递通道(20)传输到密码数据接收单元(38),然后该密码经注册确认,存储在用户数据库(32);人体特征传感器(11)离开该用户人体后一定时间或密码传送成功,密码暂存单元(14)清空;10. A volatile key and a separate verification module realized by collecting human body characteristics, comprising a handheld device (10), a signal transmission channel (20), a password data receiving unit (38) and a verification module (30), its It is characterized in that: the handheld device (10) also includes a human body feature sensor (11), a key microprocessor unit (12), a password generating unit (13), a password temporary storage unit (14) and a key password data sending unit ( 18); the key microprocessor unit (12) connects the human body feature sensor (11) and the password generation unit (13), and the password temporary storage unit (14) connects the password generation unit (13) and the key password data transmission unit (18); the human body feature sensor (11) collects the human body feature information of each user, generates corresponding passwords at the password generation unit (13), temporarily stores in the password temporary storage unit (14), and passes the key password data The sending unit (18) is transmitted to the password data receiving unit (38) through the signal transmission channel (20), and then the password is confirmed through registration and stored in the user database (32); Or the password transmission is successful, and the password temporary storage unit (14) is emptied; 所述验证模块(30)包括验证单元(31)、用户数据库(32);所述验证单元(31)连接密码数据接收单元(38)并连接用户数据库(32),还连接输出接口(39);所述密码数据接收单元(38)接收到手持设备(10)发来的数据,传输到验证单元(31),由验证单元(31)对其进行比对操作。The verification module (30) includes a verification unit (31), a user database (32); the verification unit (31) is connected to a password data receiving unit (38) and connected to a user database (32), and is also connected to an output interface (39) ; The password data receiving unit (38) receives the data sent by the handheld device (10), transmits it to the verification unit (31), and performs a comparison operation on it by the verification unit (31). 11.根据权利要求10所述的通过采集人体特征实现的易失性密钥及分离式验证模块,其特征在于:所述密码数据接收单元(38)或独立设置,或嵌入到验证模块(30)之中。11. The volatile key and the separate verification module realized by collecting human body characteristics according to claim 10, characterized in that: the password data receiving unit (38) is either independently arranged, or embedded in the verification module (30 ) among. 12.根据权利要求10所述的通过采集人体特征实现的易失性密钥及分离式验证模块,其特征在于:在所述手持设备(10)上还包括钥按键组(15)和钥显示屏(16),所述钥按键组(15)连接钥微处理器单元(12)录入附加密码;并存入钥微处理器单元(12)连接的附加密码存储器(133);钥显示屏(16)连接钥微处理器单元(12)显示操作信息。12. The volatile key and separate verification module realized by collecting human body characteristics according to claim 10, characterized in that: the handheld device (10) also includes a key button group (15) and a key display screen (16), the key button group (15) is connected to the key microprocessor unit (12) to input additional passwords; and stored in the additional password memory (133) that the key microprocessor unit (12) connects; the key display screen ( 16) Connection key microprocessor unit (12) displays operation information. 13.根据权利要求12所述的通过采集人体特征实现的易失性密钥及分离式验证模块,其特征在于:在所述手持设备(10)上还包括时钟单元(19)、主密码运算器(131)、设备出厂ID(134)和附加密码存储器(133),主密码运算器(131)将人体特征信息进行处理,形成多字节的主密码,与设备出厂ID、当前时间、通过键盘输入的附加密码一同形成附加密码。13. The volatile key and the separate verification module realized by collecting human body characteristics according to claim 12, characterized in that: the handheld device (10) also includes a clock unit (19), a master password operation device (131), equipment factory ID (134) and additional password memory (133), the master password operator (131) processes the human body characteristic information, forms a multi-byte master password, and equipment factory ID, current time, pass The additional passwords entered from the keyboard together form the additional passwords. 14.根据权利要求10所述的通过采集人体特征实现的易失性密钥及分离式验证模块,其特征在于:所述信号传递通道(20)包括有触点传输、无线传输以及红外线传输;所述的钥密码数据发送单元(18)、密码数据接收单元(38)为相互匹配的有触点传输,或为无线传输以及或为红外线传输模式。14. The volatile key and separate verification module realized by collecting human body characteristics according to claim 10, characterized in that: the signal transmission channel (20) includes contact transmission, wireless transmission and infrared transmission; The key cipher data sending unit (18) and cipher data receiving unit (38) are in contact transmission mode matched with each other, or in wireless transmission mode and or in infrared transmission mode. 15.根据权利要求10所述的通过采集人体特征实现的易失性密钥及分离式验证模块,其特征在于:所述人体特征传感器(11)包括指纹鉴别传感器或掌纹、掌形、面形、DNA、声波传感器或虹膜传感器或其组合。15. The volatile key and separate verification module realized by collecting human body features according to claim 10, characterized in that: the human body feature sensor (11) includes a fingerprint identification sensor or palmprint, palm shape, face shape, DNA, sonic sensor or iris sensor or a combination thereof. 16.根据权利要求10所述的通过采集人体特征实现的易失性密钥及分离式验证模块,其特征在于:验证模块(30)还包括验证模块时钟单元(36)和黑名单数据库(37),在查询后数据库内没有与接收数据相同的记录,或接收数据中时间信息超出允许范围,则验证单元(31)发出警告信息,或同时存储一条错误记录;同一ID的密码数据连续两次以上报警时,则将该ID数据保存于黑名单数据库(37)中。16. The volatile key and the separate verification module realized by collecting human body characteristics according to claim 10, is characterized in that: the verification module (30) also includes a verification module clock unit (36) and a blacklist database (37 ), there is no record identical with the received data in the database after the query, or the time information in the received data exceeds the allowable range, then the verification unit (31) sends a warning message, or stores an error record at the same time; the password data of the same ID is consecutively twice When above reporting to the police, then this ID data is preserved in the blacklist database (37).
CN200580030854A 2004-09-22 2005-08-29 Method for realizing volatile secret key and separated checking module by collecting human characteristic Expired - Fee Related CN100583734C (en)

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
CNB2004100516793A CN1272519C (en) 2004-09-22 2004-09-22 Instant clearing electronic lock system after key cipher use and realizing method
CN200410051679.3 2004-09-22
PCT/CN2005/001348 WO2006032186A1 (en) 2004-09-22 2005-08-29 Interleaving and deinterleaving method for preventing periodic position interference

Publications (2)

Publication Number Publication Date
CN101019366A CN101019366A (en) 2007-08-15
CN100583734C true CN100583734C (en) 2010-01-20

Family

ID=38727292

Family Applications (1)

Application Number Title Priority Date Filing Date
CN200580030854A Expired - Fee Related CN100583734C (en) 2004-09-22 2005-08-29 Method for realizing volatile secret key and separated checking module by collecting human characteristic

Country Status (1)

Country Link
CN (1) CN100583734C (en)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103366423A (en) * 2012-03-31 2013-10-23 深圳光启创新技术有限公司 Light-operated access control system based on cellphone fingerprint identification
CN104952135A (en) * 2015-07-10 2015-09-30 徐林 Intelligent terminal light-operated door lock system and application method
CN105427418A (en) * 2015-11-11 2016-03-23 张时春 Human body biological information identification laser encryption verification system
CN105719131A (en) * 2016-01-27 2016-06-29 努比亚技术有限公司 Server, client and paying-for-another method of e-payment

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101938558B (en) * 2010-08-30 2014-11-19 宇龙计算机通信科技(深圳)有限公司 Mode switching method and system of a mobile terminal and mobile terminal
CN103538561A (en) * 2012-07-12 2014-01-29 鸿富锦精密工业(深圳)有限公司 Automobile starting control system and method
CN108512657B (en) * 2017-02-28 2021-05-14 中兴通讯股份有限公司 Password generation method and device
CN110443699A (en) * 2018-05-03 2019-11-12 阿里巴巴集团控股有限公司 Method for processing resource and system
CN111489474A (en) * 2020-04-07 2020-08-04 科莱因(苏州)智能科技有限公司 Intelligent visual tracking permission system

Cited By (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103366423A (en) * 2012-03-31 2013-10-23 深圳光启创新技术有限公司 Light-operated access control system based on cellphone fingerprint identification
CN103366423B (en) * 2012-03-31 2015-09-09 深圳光启创新技术有限公司 Based on the light-operated gate control system of mobile fingerprint identification
CN104952135A (en) * 2015-07-10 2015-09-30 徐林 Intelligent terminal light-operated door lock system and application method
CN105427418A (en) * 2015-11-11 2016-03-23 张时春 Human body biological information identification laser encryption verification system
CN105719131A (en) * 2016-01-27 2016-06-29 努比亚技术有限公司 Server, client and paying-for-another method of e-payment

Also Published As

Publication number Publication date
CN101019366A (en) 2007-08-15

Similar Documents

Publication Publication Date Title
US12015913B2 (en) Security system for handheld wireless devices using time-variable encryption keys
WO2006032186A1 (en) Interleaving and deinterleaving method for preventing periodic position interference
US10616198B2 (en) Apparatus, system and method employing a wireless user-device
US8397988B1 (en) Method and system for securing a transaction using a card generator, a RFID generator, and a challenge response protocol
US9542542B2 (en) Single step transaction authentication using proximity and biometric input
EP2774098B1 (en) Authentication method
US20060107067A1 (en) Identification card with bio-sensor and user authentication method
US20150113616A1 (en) Mobile device-based authentication with enhanced security measures
US20170180361A1 (en) Mobile device-based authentication with enhanced security measures providing feedback on a real time basis
WO2008006290A1 (en) Method, device, server and system for authenticating identity with biological character
CN105447688A (en) Using ce device record of e-card transactions to reconcile bank record
CN100583734C (en) Method for realizing volatile secret key and separated checking module by collecting human characteristic
US20030014642A1 (en) Security arrangement
JP2005036394A (en) User authentication system
WO2018006322A1 (en) Mobile terminal-based alarm method and system
CN110223420A (en) A kind of fingerprint unlocking system
JP2010286936A (en) Semiconductor element, authentication device, authentication system
RU2260840C2 (en) Protection means
KR20170082307A (en) System and method for Notifying Certificate Authentication Use through Multiple Agencies
JP2967456B2 (en) Authentication system
KR100657577B1 (en) Authentication system and method using user information set
CN105447695A (en) Customer's ce device interrogating customer's e-card for transaction information
WO2018006321A1 (en) Response method and system
AR et al. SIXTH SENSE IMAGE PROCESSING ATM USING COLOR RECOGNITION AND GESTURE RECOGNITION

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant
ASS Succession or assignment of patent right

Owner name: SHENZHEN WEINA SCIENCE AND TECHNOLOGY CO., LTD.

Free format text: FORMER OWNER: WANG RUIXUN

Effective date: 20150626

C41 Transfer of patent application or patent right or utility model
TR01 Transfer of patent right

Effective date of registration: 20150626

Address after: Baoan District Songgang Yanchuan Street Chaoyang Road Shenzhen city in Guangdong province 518105 Industrial Park B District No. 4 North Yongfa Technology Park Building

Patentee after: Shenzhen nano science and Technology Co., Ltd.

Address before: 553000 room 82, No. 501 West Zhongshan Road, Zhongshan District, Guizhou, Liupanshui

Patentee before: Wang Ruixun

CF01 Termination of patent right due to non-payment of annual fee
CF01 Termination of patent right due to non-payment of annual fee

Granted publication date: 20100120

Termination date: 20190829