指纹扫描仪如何保护其指纹数据存储? [英] How does a fingerprint scanner protect its store of fingerprint data?

查看:72
本文介绍了指纹扫描仪如何保护其指纹数据存储?的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧!

问题描述

在我的指纹扫描仪上,指纹存储在设备本身中.我确定这与大多数人相同.

On my fingerprint scanner, the fingerprints are stored in the device itself. I'm sure that this is the same as most of them.

扫描仪如何保护/加密指纹数据,以使某人无法直接从扫描仪中提取此信息并使用它进行身份验证?我知道这需要认真的技巧,但是我确定我不是唯一想到这种可能性的人.

How do the scanners protect/encrypt the fingerprint data, so that someone can't extract this information directly from the scanner and use it to authenticate? I know that this would require serious skill, but I'm sure that I'm not the only one who has thought of the possibility.

推荐答案

指纹设备通常不加密或存储您的指纹数据.通常会发生以下情况:

Fingerprint devices typically do not encrypt or store your fingerprint data. What usually happens is as follows:

  • 分析指尖的扫描以了解某些控制点
  • 这些位置生成令牌
  • 此令牌的用法类似于密码哈希,并传递给身份验证应用
  • 可以使用特定于时间的密钥对与应用程序的通信进行加密,以避免重播攻击
  • the scan of your fingertip is analysed for certain control points
  • the position of these generates a token
  • this token is used similarly to a password hash and is passed to the authentication app
  • communication with the app may be encrypted with a key which is time specific, to avoid replay attacks

根据@Wiso的回答,这类似于在Windows的影子密码文件或SAM文件中存储密码哈希的方式.

Which is similar to how a password hash is stored , as per @Wiso's answer, in a shadow password file, or in a SAM file under Windows.

因此,如果您正在查看控件,则关键要素是设备用于生成令牌的算法,设备与应用程序之间的逗号以及应用程序使用的存储.

So if you are looking at controls, the key elements are the algorithm the device uses to generate the token, the comms between the device and the application, and the storage used by the application.

这篇关于指纹扫描仪如何保护其指纹数据存储?的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持IT屋!

查看全文
登录 关闭
扫码关注1秒登录
发送“验证码”获取 | 15天全站免登陆